45 repository-uri
Infrastructure and platforms for testing security tools and attack scenarios.
Explore 45 awesome GitHub repositories matching part of an awesome list · Security Lab Environments. Refine with filters or upvote what's useful.
Ansible is an agentless infrastructure automation engine designed to manage remote servers and network devices. It functions as a cross-platform orchestration tool that coordinates system updates, software installations, and service configurations from a centralized management workstation. By utilizing a declarative approach, it allows users to define desired system states through human-readable configuration files, ensuring consistency across distributed environments. The platform operates by establishing secure shell connections to target nodes, eliminating the need for persistent agent sof
Automation tool for configuring and managing security infrastructure.
Semgrep is a static analysis security testing tool designed to identify vulnerabilities and logic errors by matching source code against declarative patterns. It functions as an automated scanner that integrates into development workflows to detect insecure code patterns and enforce coding standards before deployment. The engine utilizes a language-agnostic intermediate representation and a modular parser architecture to normalize diverse programming languages into a unified format. This allows for consistent rule execution across different codebases, enabling users to perform custom structur
Static analysis tool for finding vulnerabilities in source code.
Ecapture is a suite of specialized auditing tools designed to capture plaintext database queries, log executed shell commands, forward packet captures, and decrypt TLS traffic. The system extracts plaintext content from encrypted communications and TLS master secrets without requiring CA certificates. It further monitors data interactions by capturing SQL queries from database instances and recording commands from shell environments for host-level auditing. The toolset includes capabilities for network traffic analysis, exporting captured data to pcapng files, and forwarding events to extern
Tool for capturing encrypted traffic using eBPF.
Lynis is an automated security auditing and system hardening framework designed for UNIX-based operating systems. It functions as a command-line utility that inspects local system configurations to identify security vulnerabilities, configuration weaknesses, and compliance gaps. By executing a series of modular tests, the tool generates actionable reports and remediation suggestions to assist in strengthening system defenses. The project distinguishes itself through a highly modular architecture that relies on shell-script-based execution and native system inspection. Users can define custom
Security auditing and hardening tool for Unix-based systems.
Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito
Unified XDR and SIEM platform for threat detection and response.
Xpipe is a remote infrastructure management tool and cross-platform terminal orchestrator. It provides a centralized desktop interface for managing remote server connections, shell sessions, and secure tunneling. The system functions as a remote application gateway, streaming graphical applications to a local desktop via RDP, VNC, or X11. It also implements a Model Context Protocol server, which exposes server infrastructure and remote command execution capabilities to external AI agents. The tool covers several operational areas, including hierarchical connection management, remote file sys
Tool for managing and connecting to remote systems.
Flare-VM este un mediu de analiză a malware-ului pentru Windows, constând în scripturi de instalare care automatizează provizionarea unei mașini virtuale. Oferă o suită cuprinzătoare de instrumente de reverse engineering, inclusiv decompile-ere și debuggere, alături de configurațiile de sistem necesare și variabilele de mediu pentru cercetarea în securitate. Proiectul funcționează ca un orchestrator de imagini de mașini virtuale, permițând crearea, gestionarea și exportul automatizat al unor appliance-uri de analiză specializate. Dispune de selecție de instrumente bazată pe configurație și capacitatea de a extinde logica de instalare prin modificări personalizate de registru și definiții de layout de sistem. Sistemul include capabilități pentru configurarea rețelei izolate pentru a preveni comunicarea externă prin modul host-only. De asemenea, gestionează întregul ciclu de viață al stărilor de analiză prin gestionarea stărilor bazată pe snapshot-uri, inclusiv capacitatea de a curăța sau exporta snapshot-uri ca fișiere appliance verificate.
Windows-based distribution for malware analysis and reverse engineering.
OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide
Platform for managing and sharing cyber threat intelligence.
Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o
Malicious traffic detection system using public blacklists.
GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including
Automated lab environment for testing Active Directory attacks.
MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish
Platform for sharing indicators of compromise and threat intelligence.
.. SPDX-FileCopyrightText: 2014 Upi Tamminen .. SPDX-FileCopyrightText: 2014-2025 Michel Oosterhof .. .. SPDX-License-Identifier: BSD-3-Clause
Medium-to-high interaction SSH and Telnet honeypot.
Cuckoo is an open-source automated malware analysis system that executes suspicious files inside isolated virtual machines and produces structured behavioral reports. The platform captures system calls, file operations, and network activity during execution, compiling them into comprehensive analysis documents for programmatic consumption. The system operates through a modular analysis pipeline that processes behavioral data, applying YARA signature patterns against captured artifacts to identify known malware families. Each analysis run starts from a clean virtual machine snapshot to ensure
Automated malware analysis system for observing malicious behavior.
Katoolin este un manager de repository-uri software Debian și un automatizator de seturi de instrumente de securitate. Funcționează ca un script pentru a automatiza adăugarea de repository-uri și instalarea instrumentelor de securitate din Kali Linux pe alte sisteme bazate pe Debian. Proiectul se concentrează pe automatizarea implementării software-ului de testare a penetrării și criminalistică. Oferă o metodă pentru gestionarea surselor software third-party și aprovizionarea laboratoarelor de securitate cu instrumente pentru testarea rețelei și a sistemului fără a necesita o instalare completă a sistemului de operare. Instrumentul include o interfață interactivă de linie de comandă pentru navigarea categoriilor de instrumente și gestionarea pachetelor software printr-un proces condus de shell. Organizează software-ul în grupări modulare pentru a permite instalarea unor subseturi specifice sau a unor suite complete de instrumente.
Quickly configures Linux environments with necessary software for ethical hacking and security research.
Security Onion este o platformă de gestionare a informațiilor și evenimentelor de securitate (SIEM) și o suită de monitorizare a securității rețelei. Funcționează ca un sistem de detectare a intruziunilor și un instrument de analiză a traficului de rețea, conceput pentru a identifica activitățile malițioase și intruziunile prin detectare bazată pe semnături și monitorizare la nivel de host. Platforma integrează un sistem de gestionare a cazurilor de securitate pentru a organiza investigațiile prin urmărirea detecțiilor și gruparea evenimentelor de securitate conexe. Oferă capabilități pentru capturarea completă a pachetelor, extragerea metadatelor de rețea, precum și colectarea și indexarea log-urilor de securitate din surse diverse. Sistemul acoperă o gamă largă de operațiuni de securitate, inclusiv investigarea incidentelor, fluxuri de lucru pentru threat hunting și agregarea log-urilor. Utilizează o consolă web unificată pentru analiza alertelor și încorporează inteligență artificială pentru a asista în investigarea datelor de securitate.
Linux distribution for intrusion detection and enterprise security monitoring.
Pikachu este o platformă de training în securitate web și un sandbox de aplicații web vulnerabile. Oferă un mediu de laborator containerizat conceput pentru exersarea testării de penetrare și identificarea defectelor comune de securitate. Proiectul servește drept laborator de practică pentru OWASP Top 10, oferind o suită de simulare pentru riscuri critice. Include scenarii specifice pentru exersarea exploatării SQL injection, cross-site scripting, remote code execution și broken access control. Mediul acoperă o gamă largă de simulări de testare a securității, inclusiv directory traversal, server-side request forgery, încărcări nesigure de fișiere și atacuri XML external entity. Dispune, de asemenea, de un backend administrativ pentru a gestiona simulările de phishing și a monitoriza payload-urile de sesiune capturate. Întreaga platformă este deployată printr-o imagine containerizată care inițializează automat schema bazei de date și populează mediul cu date de test.
Provides an isolated testing setup deployed via containers for a consistent security research workspace.
Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho
Runtime security and forensics tool using eBPF.
Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the Windows operating system through policy enforcement. It provides a collection of security presets and templates to implement official hardening standards across multiple devices. The project distinguishes itself through a comprehensive execution control system, featuring a manager for Windows Application Control and a kernel protection suite. It implements strict trust models, including kernel-mode driver whitelisting, signed policy implementation on the EFI partition, and code inte
Script for hardening Windows system configurations.
Malware Configuration And Payload Extraction
Automated malware analysis platform with advanced reporting capabilities.
OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a security decoy that creates fake server personalities and open ports to identify unauthorized users scanning a private network. The system uses deception technology to mimic various server protocols, luring attackers into revealing their presence and activity. When a simulated service is accessed, it acts as an intrusion alerting gateway, transmitting notifications via email or webhooks. The project covers internal network monitoring and intrusion source tracking to identify the
Deception tool for detecting unauthorized network activity.