awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टMCP सर्वरहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेस
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

25 रिपॉजिटरी

Awesome GitHub RepositoriesScanning Template Libraries

Collections of structured configurations for identifying security vulnerabilities across web and network services.

Distinct from Vulnerability Scanning: Distinct from Vulnerability Scanning: focuses on the library of reusable templates rather than the scanning engine.

Explore 25 awesome GitHub repositories matching security & cryptography · Scanning Template Libraries. Refine with filters or upvote what's useful.

Awesome Scanning Template Libraries GitHub Repositories

AI के साथ बेहतरीन रिपॉजिटरी खोजें।हम AI का उपयोग करके सबसे सटीक रिपॉजिटरी खोजेंगे।
  • rustscan/rustscanRustScan का अवतार

    RustScan/RustScan

    19,932GitHub पर देखें↗

    RustScan is a high-speed TCP network scanner written in Rust, designed for security reconnaissance and network mapping. It functions as an automated port discovery engine that identifies open ports on remote hosts using IPv6 addresses, CIDR ranges, or bulk input files. The tool is built for rapid surface area discovery, utilizing parallel port processing and OS-aware performance optimizations to identify active services. It allows for scan precision tuning through adjustable connection timeout thresholds and concurrent request controls to balance speed and accuracy. The system integrates wit

    Supports automatically triggering external scripts to handle results or alerts after a scanning process.

    Rust
    GitHub पर देखें↗19,932
  • ultimatehackers/xsstrikeUltimateHackers का अवतार

    UltimateHackers/XSStrike

    15,027GitHub पर देखें↗

    XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web response analysis. It functions as a web application fuzzer and vulnerability scanner that identifies injection points and security flaws. The project includes a specialized utility for detecting blind XSS, where payloads execute asynchronously or on separate pages. It also features a JavaScript library auditor to identify outdated libraries with known vulnerabilities and a dedicated tool for identifying and bypassing web application firewalls using various evasion techniques.

    Matches JavaScript library version strings against a database of known vulnerable releases.

    Python
    GitHub पर देखें↗15,027
  • maurosoria/dirsearchmaurosoria का अवतार

    maurosoria/dirsearch

    14,403GitHub पर देखें↗

    dirsearch is a command-line security tool and web path scanner used for discovering hidden directories and files on web servers. It functions as a recursive directory fuzzer and brute-force utility that identifies undocumented paths and sensitive files using wordlists and HTTP status codes. The tool distinguishes itself through template-driven path generation and an automated HTTP response filter that uses status codes, content length, and regex patterns to isolate valid targets. It supports recursive directory crawling to map complex web structures and provides state-persistence serializatio

    Provides programmatic interfaces to trigger automated security scans within larger discovery workflows.

    Python
    GitHub पर देखें↗14,403
  • toniblyx/prowlertoniblyx का अवतार

    toniblyx/prowler

    14,005GitHub पर देखें↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Implements systems for automatically initiating security assessments based on infrastructure changes or discovery events.

    Python
    GitHub पर देखें↗14,005
  • projectdiscovery/subfinderprojectdiscovery का अवतार

    projectdiscovery/subfinder

    13,105GitHub पर देखें↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Automatically triggers security scans based on asset discovery and infrastructure changes to maintain continuous coverage.

    Gobugbountyhackinghacktoberfest
    GitHub पर देखें↗13,105
  • projectdiscovery/nuclei-templatesprojectdiscovery का अवतार

    projectdiscovery/nuclei-templates

    12,518GitHub पर देखें↗

    Nuclei-templates is a security automation framework and vulnerability scanning library designed for the continuous assessment of distributed infrastructure. It functions as a collection of structured configuration files that define how to identify security flaws and misconfigurations across web applications and network services. The project utilizes a declarative domain-specific language to decouple detection logic from the underlying execution engine. This approach allows for the creation of modular, protocol-agnostic scanning rules that can be updated independently of the core software. By

    Provides a collection of structured YAML configurations for identifying security vulnerabilities and misconfigurations.

    JavaScriptbugbountyexploit-developmentexploits
    GitHub पर देखें↗12,518
  • kubescape/kubescapekubescape का अवतार

    kubescape/kubescape

    11,489GitHub पर देखें↗

    Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance risks. It functions as a comprehensive security suite incorporating a compliance scanner, a container image vulnerability scanner, an admission controller for policy enforcement, and a runtime security monitor. The platform distinguishes itself through runtime-aware vulnerability filtering, which maps libraries loaded in memory to determine if vulnerabilities are actually reachable. It also integrates with AI assistants via a Mo

    Automatically initiates security scans triggered by external providers and infrastructure changes.

    Gobest-practicedevopskubernetes
    GitHub पर देखें↗11,489
  • 1n3/sn1per1N3 का अवतार

    1N3/Sn1per

    10,049GitHub पर देखें↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Provides an API to automatically trigger reconnaissance and vulnerability scans using configurable logic gates.

    Shellattack-surfaceattack-surface-managementattacksurface
    GitHub पर देखें↗10,049
  • wpscanteam/wpscanwpscanteam का अवतार

    wpscanteam/wpscan

    9,636GitHub पर देखें↗

    WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the

    Matches detected WordPress plugins and themes against a database of known vulnerable versions.

    Ruby
    GitHub पर देखें↗9,636
  • google/tsunami-security-scannergoogle का अवतार

    google/tsunami-security-scanner

    8,584GitHub पर देखें↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    Provides a mechanism to toggle whether automated action scanning remains active for a specific repository.

    Java
    GitHub पर देखें↗8,584
  • yaklang/yakityaklang का अवतार

    yaklang/yakit

    7,386GitHub पर देखें↗

    Yakit is a comprehensive cybersecurity all-in-one platform designed for security assessments. It integrates a suite of core tools including an HTTP interception proxy for real-time traffic modification, an out-of-band interaction detector for verifying remote command execution via TCP, DNSLog, and ICMP, and a reverse shell manager for controlling remote server connections. The platform is distinguished by its dedicated security scripting environment, which allows for the development and execution of custom logic and plugins using a specialized high-performance language. It further extends fun

    Integrates a library of proof-of-concept templates to automate the detection of known security flaws.

    TypeScriptblueteamburpsuiteexploit
    GitHub पर देखें↗7,386
  • six2dez/reconftwsix2dez का अवतार

    six2dez/reconftw

    7,226GitHub पर देखें↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Matches target URLs against a library of predefined patterns to detect known CVEs and misconfigurations.

    Shellbug-bountybugbountybugbounty-tool
    GitHub पर देखें↗7,226
  • infobyte/faradayinfobyte का अवतार

    infobyte/faraday

    6,523GitHub पर देखें↗

    Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings from multiple scanners into a single dashboard. It utilizes a relational security database to catalog hosts, services, and security flaws, enabling users to track remediation and analyze organizational risk. The platform distinguishes itself through a plugin-based system that normalizes diverse security tool outputs into a unified data model. It supports deep integration with a wide array of scanners and CLI tools, intercepting shell command output or parsing report files to ag

    Executes security scans based on predefined YAML templates for consistent vulnerability detection.

    Python
    GitHub पर देखें↗6,523
  • trailofbits/slithertrailofbits का अवतार

    trailofbits/slither

    6,299GitHub पर देखें↗

    Static Analyzer for Solidity and Vyper

    Scans Solidity and Vyper smart contracts for vulnerabilities, generates test cases, and produces code summaries.

    Python
    GitHub पर देखें↗6,299
  • crytic/slithercrytic का अवतार

    crytic/slither

    6,141GitHub पर देखें↗

    Identifies common security patterns like unprotected selfdestruct and delegatecall misuse in Solidity contracts.

    Pythonethereumsoliditystatic-analysis
    GitHub पर देखें↗6,141
  • autorecon/autoreconAutoRecon का अवतार

    AutoRecon/AutoRecon

    5,905GitHub पर देखें↗

    AutoRecon is an automated network reconnaissance tool that performs concurrent port scanning and service enumeration across multiple targets. It operates as a multi-target port scanner, probing IP addresses, CIDR ranges, or hostnames in parallel, and automatically dispatches service-specific enumeration tools after port detection to gather detailed information about each open service. The tool distinguishes itself through a plugin-based scanning system that allows extending or replacing default port and service scans via a flexible plugin architecture. It provides real-time pattern-based outp

    Adjusts the verbosity of live scan output during execution using keyboard controls.

    Python
    GitHub पर देखें↗5,905
  • projectdiscovery/naabuprojectdiscovery का अवतार

    projectdiscovery/naabu

    5,766GitHub पर देखें↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Automatically scans assets when new vulnerability templates are added to protect against emerging threats.

    Gocdn-exclusionhacktoberfestnmap
    GitHub पर देखें↗5,766
  • ossf/scorecardossf का अवतार

    ossf/scorecard

    5,527GitHub पर देखें↗

    Scorecard is an open source security scanner and software supply chain analysis tool that evaluates the security posture of projects by calculating risk metrics based on best practices. It functions as a security health dashboard, visualizing security gaps through scores and badges to help maintainers identify vulnerabilities. The project provides a system for monitoring repository security through a GitHub Action security auditor that alerts maintainers when security scores drop. It also offers a mechanism for vulnerability remediation guidance, mapping identified security gaps to prescripti

    Automates security scans on every code commit through CI pipelines to alert maintainers of regressions.

    Go
    GitHub पर देखें↗5,527
  • owasp/nettackerOWASP का अवतार

    OWASP/Nettacker

    5,258GitHub पर देखें↗

    Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and vulnerability detection. It functions as a network reconnaissance tool and vulnerability scanner that identifies open ports, fingerprints services, and checks systems against databases of known security flaws. The framework distinguishes itself by combining a web application crawler for discovering hidden paths via fuzzing with a vulnerability management system that persists scan results in a database to track historical assessments. It also includes specialized capabilities for

    Provides a mechanism to automatically trigger vulnerability assessments using defined modules and custom arguments.

    Pythonautomationbruteforcecve
    GitHub पर देखें↗5,258
  • andresriancho/w3afandresriancho का अवतार

    andresriancho/w3af

    4,850GitHub पर देखें↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Enables triggering vulnerability scans via API requests using target URLs and configuration profiles.

    Pythonappseccross-site-scriptingscanner
    GitHub पर देखें↗4,850
पिछला12अगला
  1. Home
  2. Security & Cryptography
  3. Vulnerability Scanning
  4. Scanning Template Libraries

सब-टैग एक्सप्लोर करें

  • Automated Security Scan Triggers3 सब-टैग्सSystems for automatically initiating vulnerability assessments based on discovery or infrastructure changes. **Distinct from Scanning Template Libraries:** Distinct from Scanning Template Libraries: focuses on the automation and triggering logic rather than the template library itself.
  • Excluded Templates1 सब-टैगLists of security templates or targets blocked from execution during scanning. **Distinct from Scanning Template Libraries:** Distinct from Scanning Template Libraries: focuses on the exclusion list management rather than the library collection itself.
  • Vulnerable Library Detectors1 सब-टैगTools that identify the use of outdated software libraries with known security vulnerabilities. **Distinct from Scanning Template Libraries:** Focuses on the active detection of vulnerable versions rather than the template libraries used for scanning.