awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

45 repository-uri

Awesome GitHub RepositoriesSecurity Lab Environments

Infrastructure and platforms for testing security tools and attack scenarios.

Explore 45 awesome GitHub repositories matching part of an awesome list · Security Lab Environments. Refine with filters or upvote what's useful.

Awesome Security Lab Environments GitHub Repositories

Găsește cele mai bune repo-uri cu AI.Vom căuta cele mai potrivite repository-uri folosind AI.
  • ansible/ansibleAvatar ansible

    ansible/ansible

    68,968Vezi pe GitHub↗

    Ansible is an agentless infrastructure automation engine designed to manage remote servers and network devices. It functions as a cross-platform orchestration tool that coordinates system updates, software installations, and service configurations from a centralized management workstation. By utilizing a declarative approach, it allows users to define desired system states through human-readable configuration files, ensuring consistency across distributed environments. The platform operates by establishing secure shell connections to target nodes, eliminating the need for persistent agent sof

    Automation tool for configuring and managing security infrastructure.

    Pythonansiblepython
    Vezi pe GitHub↗68,968
  • semgrep/semgrepAvatar semgrep

    semgrep/semgrep

    15,603Vezi pe GitHub↗

    Semgrep is a static analysis security testing tool designed to identify vulnerabilities and logic errors by matching source code against declarative patterns. It functions as an automated scanner that integrates into development workflows to detect insecure code patterns and enforce coding standards before deployment. The engine utilizes a language-agnostic intermediate representation and a modular parser architecture to normalize diverse programming languages into a unified format. This allows for consistent rule execution across different codebases, enabling users to perform custom structur

    Static analysis tool for finding vulnerabilities in source code.

    OCamlcgojava
    Vezi pe GitHub↗15,603
  • gojue/ecaptureG

    gojue/ecapture

    15,283Vezi pe GitHub↗

    Ecapture is a suite of specialized auditing tools designed to capture plaintext database queries, log executed shell commands, forward packet captures, and decrypt TLS traffic. The system extracts plaintext content from encrypted communications and TLS master secrets without requiring CA certificates. It further monitors data interactions by capturing SQL queries from database instances and recording commands from shell environments for host-level auditing. The toolset includes capabilities for network traffic analysis, exporting captured data to pcapng files, and forwarding events to extern

    Tool for capturing encrypted traffic using eBPF.

    C
    Vezi pe GitHub↗15,283
  • cisofy/lynisAvatar CISOfy

    CISOfy/lynis

    15,284Vezi pe GitHub↗

    Lynis is an automated security auditing and system hardening framework designed for UNIX-based operating systems. It functions as a command-line utility that inspects local system configurations to identify security vulnerabilities, configuration weaknesses, and compliance gaps. By executing a series of modular tests, the tool generates actionable reports and remediation suggestions to assist in strengthening system defenses. The project distinguishes itself through a highly modular architecture that relies on shell-script-based execution and native system inspection. Users can define custom

    Security auditing and hardening tool for Unix-based systems.

    Shellauditingcompliancedevops
    Vezi pe GitHub↗15,284
  • wazuh/wazuhAvatar wazuh

    wazuh/wazuh

    14,779Vezi pe GitHub↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Unified XDR and SIEM platform for threat detection and response.

    Ccloud-securitycomplianceconfiguration-assessement
    Vezi pe GitHub↗14,779
  • xpipe-io/xpipeAvatar xpipe-io

    xpipe-io/xpipe

    14,212Vezi pe GitHub↗

    Xpipe is a remote infrastructure management tool and cross-platform terminal orchestrator. It provides a centralized desktop interface for managing remote server connections, shell sessions, and secure tunneling. The system functions as a remote application gateway, streaming graphical applications to a local desktop via RDP, VNC, or X11. It also implements a Model Context Protocol server, which exposes server infrastructure and remote command execution capabilities to external AI agents. The tool covers several operational areas, including hierarchical connection management, remote file sys

    Tool for managing and connecting to remote systems.

    Java
    Vezi pe GitHub↗14,212
  • mandiant/flare-vmAvatar mandiant

    mandiant/flare-vm

    8,799Vezi pe GitHub↗

    Flare-VM este un mediu de analiză a malware-ului pentru Windows, constând în scripturi de instalare care automatizează provizionarea unei mașini virtuale. Oferă o suită cuprinzătoare de instrumente de reverse engineering, inclusiv decompile-ere și debuggere, alături de configurațiile de sistem necesare și variabilele de mediu pentru cercetarea în securitate. Proiectul funcționează ca un orchestrator de imagini de mașini virtuale, permițând crearea, gestionarea și exportul automatizat al unor appliance-uri de analiză specializate. Dispune de selecție de instrumente bazată pe configurație și capacitatea de a extinde logica de instalare prin modificări personalizate de registru și definiții de layout de sistem. Sistemul include capabilități pentru configurarea rețelei izolate pentru a preveni comunicarea externă prin modul host-only. De asemenea, gestionează întregul ciclu de viață al stărilor de analiză prin gestionarea stărilor bazată pe snapshot-uri, inclusiv capacitatea de a curăța sau exporta snapshot-uri ca fișiere appliance verificate.

    Windows-based distribution for malware analysis and reverse engineering.

    PowerShell
    Vezi pe GitHub↗8,799
  • opencti-platform/openctiAvatar OpenCTI-Platform

    OpenCTI-Platform/opencti

    8,812Vezi pe GitHub↗

    OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide

    Platform for managing and sharing cyber threat intelligence.

    TypeScriptcticybercybersecurity
    Vezi pe GitHub↗8,812
  • stamparm/maltrailAvatar stamparm

    stamparm/maltrail

    8,498Vezi pe GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Malicious traffic detection system using public blacklists.

    Pythonattack-detectionintrusion-detectionmalware
    Vezi pe GitHub↗8,498
  • orange-cyberdefense/goadAvatar Orange-Cyberdefense

    Orange-Cyberdefense/GOAD

    7,464Vezi pe GitHub↗

    GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including

    Automated lab environment for testing Active Directory attacks.

    PowerShellactive-directoryansibleinfrastructure-as-code
    Vezi pe GitHub↗7,464
  • misp/mispAvatar MISP

    MISP/MISP

    6,360Vezi pe GitHub↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    Platform for sharing indicators of compromise and threat intelligence.

    PHP
    Vezi pe GitHub↗6,360
  • cowrie/cowrieAvatar cowrie

    cowrie/cowrie

    6,181Vezi pe GitHub↗

    .. SPDX-FileCopyrightText: 2014 Upi Tamminen .. SPDX-FileCopyrightText: 2014-2025 Michel Oosterhof .. .. SPDX-License-Identifier: BSD-3-Clause

    Medium-to-high interaction SSH and Telnet honeypot.

    Pythonattackercowriecowrie-ssh
    Vezi pe GitHub↗6,181
  • cuckoosandbox/cuckooAvatar cuckoosandbox

    cuckoosandbox/cuckoo

    5,959Vezi pe GitHub↗

    Cuckoo is an open-source automated malware analysis system that executes suspicious files inside isolated virtual machines and produces structured behavioral reports. The platform captures system calls, file operations, and network activity during execution, compiling them into comprehensive analysis documents for programmatic consumption. The system operates through a modular analysis pipeline that processes behavioral data, applying YARA signature patterns against captured artifacts to identify known malware families. Each analysis run starts from a clean virtual machine snapshot to ensure

    Automated malware analysis system for observing malicious behavior.

    JavaScript
    Vezi pe GitHub↗5,959
  • lionsec/katoolinAvatar LionSec

    LionSec/katoolin

    5,302Vezi pe GitHub↗

    Katoolin este un manager de repository-uri software Debian și un automatizator de seturi de instrumente de securitate. Funcționează ca un script pentru a automatiza adăugarea de repository-uri și instalarea instrumentelor de securitate din Kali Linux pe alte sisteme bazate pe Debian. Proiectul se concentrează pe automatizarea implementării software-ului de testare a penetrării și criminalistică. Oferă o metodă pentru gestionarea surselor software third-party și aprovizionarea laboratoarelor de securitate cu instrumente pentru testarea rețelei și a sistemului fără a necesita o instalare completă a sistemului de operare. Instrumentul include o interfață interactivă de linie de comandă pentru navigarea categoriilor de instrumente și gestionarea pachetelor software printr-un proces condus de shell. Organizează software-ul în grupări modulare pentru a permite instalarea unor subseturi specifice sau a unor suite complete de instrumente.

    Quickly configures Linux environments with necessary software for ethical hacking and security research.

    Python
    Vezi pe GitHub↗5,302
  • security-onion-solutions/securityonionAvatar Security-Onion-Solutions

    Security-Onion-Solutions/securityonion

    4,661Vezi pe GitHub↗

    Security Onion este o platformă de gestionare a informațiilor și evenimentelor de securitate (SIEM) și o suită de monitorizare a securității rețelei. Funcționează ca un sistem de detectare a intruziunilor și un instrument de analiză a traficului de rețea, conceput pentru a identifica activitățile malițioase și intruziunile prin detectare bazată pe semnături și monitorizare la nivel de host. Platforma integrează un sistem de gestionare a cazurilor de securitate pentru a organiza investigațiile prin urmărirea detecțiilor și gruparea evenimentelor de securitate conexe. Oferă capabilități pentru capturarea completă a pachetelor, extragerea metadatelor de rețea, precum și colectarea și indexarea log-urilor de securitate din surse diverse. Sistemul acoperă o gamă largă de operațiuni de securitate, inclusiv investigarea incidentelor, fluxuri de lucru pentru threat hunting și agregarea log-urilor. Utilizează o consolă web unificată pentru analiza alertelor și încorporează inteligență artificială pentru a asista în investigarea datelor de securitate.

    Linux distribution for intrusion detection and enterprise security monitoring.

    Shell
    Vezi pe GitHub↗4,661
  • zhuifengshaonianhanlu/pikachuAvatar zhuifengshaonianhanlu

    zhuifengshaonianhanlu/pikachu

    4,421Vezi pe GitHub↗

    Pikachu este o platformă de training în securitate web și un sandbox de aplicații web vulnerabile. Oferă un mediu de laborator containerizat conceput pentru exersarea testării de penetrare și identificarea defectelor comune de securitate. Proiectul servește drept laborator de practică pentru OWASP Top 10, oferind o suită de simulare pentru riscuri critice. Include scenarii specifice pentru exersarea exploatării SQL injection, cross-site scripting, remote code execution și broken access control. Mediul acoperă o gamă largă de simulări de testare a securității, inclusiv directory traversal, server-side request forgery, încărcări nesigure de fișiere și atacuri XML external entity. Dispune, de asemenea, de un backend administrativ pentru a gestiona simulările de phishing și a monitoriza payload-urile de sesiune capturate. Întreaga platformă este deployată printr-o imagine containerizată care inițializează automat schema bazei de date și populează mediul cu date de test.

    Provides an isolated testing setup deployed via containers for a consistent security research workspace.

    PHPweb
    Vezi pe GitHub↗4,421
  • aquasecurity/traceeAvatar aquasecurity

    aquasecurity/tracee

    4,377Vezi pe GitHub↗

    Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho

    Runtime security and forensics tool using eBPF.

    Gobpfdockerebpf
    Vezi pe GitHub↗4,377
  • hotcakex/harden-windows-securityAvatar HotCakeX

    HotCakeX/Harden-Windows-Security

    4,139Vezi pe GitHub↗

    Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the Windows operating system through policy enforcement. It provides a collection of security presets and templates to implement official hardening standards across multiple devices. The project distinguishes itself through a comprehensive execution control system, featuring a manager for Windows Application Control and a kernel protection suite. It implements strict trust models, including kernel-mode driver whitelisting, signed policy implementation on the EFI partition, and code inte

    Script for hardening Windows system configurations.

    C#1st-party-securityapplicationcontrolaudit
    Vezi pe GitHub↗4,139
  • kevoreilly/capev2Avatar kevoreilly

    kevoreilly/CAPEv2

    3,284Vezi pe GitHub↗

    Malware Configuration And Payload Extraction

    Automated malware analysis platform with advanced reporting capabilities.

    Python
    Vezi pe GitHub↗3,284
  • thinkst/opencanaryAvatar thinkst

    thinkst/opencanary

    2,776Vezi pe GitHub↗

    OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a security decoy that creates fake server personalities and open ports to identify unauthorized users scanning a private network. The system uses deception technology to mimic various server protocols, luring attackers into revealing their presence and activity. When a simulated service is accessed, it acts as an intrusion alerting gateway, transmitting notifications via email or webhooks. The project covers internal network monitoring and intrusion source tracking to identify the

    Deception tool for detecting unauthorized network activity.

    Python
    Vezi pe GitHub↗2,776
Înapoi123Înainte
  1. Home
  2. Part of an Awesome List
  3. DevOps & Infrastructure
  4. Security Lab Environments