awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

45 个仓库

Awesome GitHub RepositoriesSecurity Lab Environments

Infrastructure and platforms for testing security tools and attack scenarios.

Explore 45 awesome GitHub repositories matching part of an awesome list · Security Lab Environments. Refine with filters or upvote what's useful.

Awesome Security Lab Environments GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • ansible/ansibleansible 的头像

    ansible/ansible

    68,968在 GitHub 上查看↗

    Ansible is an agentless infrastructure automation engine designed to manage remote servers and network devices. It functions as a cross-platform orchestration tool that coordinates system updates, software installations, and service configurations from a centralized management workstation. By utilizing a declarative approach, it allows users to define desired system states through human-readable configuration files, ensuring consistency across distributed environments. The platform operates by establishing secure shell connections to target nodes, eliminating the need for persistent agent sof

    Automation tool for configuring and managing security infrastructure.

    Pythonansiblepython
    在 GitHub 上查看↗68,968
  • semgrep/semgrepsemgrep 的头像

    semgrep/semgrep

    15,603在 GitHub 上查看↗

    Semgrep is a static analysis security testing tool designed to identify vulnerabilities and logic errors by matching source code against declarative patterns. It functions as an automated scanner that integrates into development workflows to detect insecure code patterns and enforce coding standards before deployment. The engine utilizes a language-agnostic intermediate representation and a modular parser architecture to normalize diverse programming languages into a unified format. This allows for consistent rule execution across different codebases, enabling users to perform custom structur

    Static analysis tool for finding vulnerabilities in source code.

    OCamlcgojava
    在 GitHub 上查看↗15,603
  • gojue/ecaptureG

    gojue/ecapture

    15,283在 GitHub 上查看↗

    Ecapture is a suite of specialized auditing tools designed to capture plaintext database queries, log executed shell commands, forward packet captures, and decrypt TLS traffic. The system extracts plaintext content from encrypted communications and TLS master secrets without requiring CA certificates. It further monitors data interactions by capturing SQL queries from database instances and recording commands from shell environments for host-level auditing. The toolset includes capabilities for network traffic analysis, exporting captured data to pcapng files, and forwarding events to extern

    Tool for capturing encrypted traffic using eBPF.

    C
    在 GitHub 上查看↗15,283
  • cisofy/lynisCISOfy 的头像

    CISOfy/lynis

    15,284在 GitHub 上查看↗

    Lynis is an automated security auditing and system hardening framework designed for UNIX-based operating systems. It functions as a command-line utility that inspects local system configurations to identify security vulnerabilities, configuration weaknesses, and compliance gaps. By executing a series of modular tests, the tool generates actionable reports and remediation suggestions to assist in strengthening system defenses. The project distinguishes itself through a highly modular architecture that relies on shell-script-based execution and native system inspection. Users can define custom

    Security auditing and hardening tool for Unix-based systems.

    Shellauditingcompliancedevops
    在 GitHub 上查看↗15,284
  • wazuh/wazuhwazuh 的头像

    wazuh/wazuh

    14,779在 GitHub 上查看↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Unified XDR and SIEM platform for threat detection and response.

    Ccloud-securitycomplianceconfiguration-assessement
    在 GitHub 上查看↗14,779
  • xpipe-io/xpipexpipe-io 的头像

    xpipe-io/xpipe

    14,212在 GitHub 上查看↗

    Xpipe is a remote infrastructure management tool and cross-platform terminal orchestrator. It provides a centralized desktop interface for managing remote server connections, shell sessions, and secure tunneling. The system functions as a remote application gateway, streaming graphical applications to a local desktop via RDP, VNC, or X11. It also implements a Model Context Protocol server, which exposes server infrastructure and remote command execution capabilities to external AI agents. The tool covers several operational areas, including hierarchical connection management, remote file sys

    Tool for managing and connecting to remote systems.

    Java
    在 GitHub 上查看↗14,212
  • mandiant/flare-vmmandiant 的头像

    mandiant/flare-vm

    8,799在 GitHub 上查看↗

    Flare-VM 是一个 Windows 恶意软件分析环境,由自动化虚拟机配置的安装脚本组成。它提供了一套全面的逆向工程工具,包括反编译器和调试器,以及用于安全研究的必要系统配置和环境变量。 该项目作为一个虚拟机镜像编排器,允许自动化创建、管理和导出专门的分析设备。它具有配置驱动的工具选择功能,以及通过自定义注册表修改和系统布局定义扩展安装逻辑的能力。 该系统包括用于通过仅主机模式防止外部通信的隔离网络配置功能。它还通过基于快照的状态管理来管理分析状态的完整生命周期,包括清理或将快照导出为已验证设备文件的能力。

    Windows-based distribution for malware analysis and reverse engineering.

    PowerShell
    在 GitHub 上查看↗8,799
  • opencti-platform/openctiOpenCTI-Platform 的头像

    OpenCTI-Platform/opencti

    8,812在 GitHub 上查看↗

    OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide

    Platform for managing and sharing cyber threat intelligence.

    TypeScriptcticybercybersecurity
    在 GitHub 上查看↗8,812
  • stamparm/maltrailstamparm 的头像

    stamparm/maltrail

    8,498在 GitHub 上查看↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Malicious traffic detection system using public blacklists.

    Pythonattack-detectionintrusion-detectionmalware
    在 GitHub 上查看↗8,498
  • orange-cyberdefense/goadOrange-Cyberdefense 的头像

    Orange-Cyberdefense/GOAD

    7,464在 GitHub 上查看↗

    GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including

    Automated lab environment for testing Active Directory attacks.

    PowerShellactive-directoryansibleinfrastructure-as-code
    在 GitHub 上查看↗7,464
  • misp/mispMISP 的头像

    MISP/MISP

    6,360在 GitHub 上查看↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    Platform for sharing indicators of compromise and threat intelligence.

    PHP
    在 GitHub 上查看↗6,360
  • cowrie/cowriecowrie 的头像

    cowrie/cowrie

    6,181在 GitHub 上查看↗

    .. SPDX-FileCopyrightText: 2014 Upi Tamminen .. SPDX-FileCopyrightText: 2014-2025 Michel Oosterhof .. .. SPDX-License-Identifier: BSD-3-Clause

    Medium-to-high interaction SSH and Telnet honeypot.

    Pythonattackercowriecowrie-ssh
    在 GitHub 上查看↗6,181
  • cuckoosandbox/cuckoocuckoosandbox 的头像

    cuckoosandbox/cuckoo

    5,959在 GitHub 上查看↗

    Cuckoo is an open-source automated malware analysis system that executes suspicious files inside isolated virtual machines and produces structured behavioral reports. The platform captures system calls, file operations, and network activity during execution, compiling them into comprehensive analysis documents for programmatic consumption. The system operates through a modular analysis pipeline that processes behavioral data, applying YARA signature patterns against captured artifacts to identify known malware families. Each analysis run starts from a clean virtual machine snapshot to ensure

    Automated malware analysis system for observing malicious behavior.

    JavaScript
    在 GitHub 上查看↗5,959
  • lionsec/katoolinLionSec 的头像

    LionSec/katoolin

    5,302在 GitHub 上查看↗

    Katoolin 是一个 Debian 软件仓库管理器和安全工具集自动化工具。它作为一个脚本,用于自动化添加仓库并从 Kali Linux 安装安全工具到其他基于 Debian 的系统上。 该项目专注于自动化渗透测试和取证软件的部署。它提供了一种管理第三方软件源的方法,并为安全实验室配置用于网络和系统测试的工具,而无需安装完整的操作系统。 该工具包括一个用于导航工具类别并通过 Shell 驱动的流程管理软件包的交互式命令行界面。它将软件组织成模块化分组,以允许安装特定的子集或完整的工具套件。

    Quickly configures Linux environments with necessary software for ethical hacking and security research.

    Python
    在 GitHub 上查看↗5,302
  • security-onion-solutions/securityonionSecurity-Onion-Solutions 的头像

    Security-Onion-Solutions/securityonion

    4,661在 GitHub 上查看↗

    Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive

    Linux distribution for intrusion detection and enterprise security monitoring.

    Shell
    在 GitHub 上查看↗4,661
  • zhuifengshaonianhanlu/pikachuzhuifengshaonianhanlu 的头像

    zhuifengshaonianhanlu/pikachu

    4,421在 GitHub 上查看↗

    Pikachu 是一个 Web 安全培训平台和易受攻击的 Web 应用沙盒。它提供了一个容器化的实验环境,旨在练习渗透测试和识别常见的安全漏洞。 该项目作为 OWASP Top 10 练习实验室,提供了一套针对关键风险的模拟套件。它包括用于练习 SQL 注入、跨站脚本 (XSS)、远程代码执行和失效的访问控制等漏洞利用的具体场景。 该环境涵盖了广泛的安全测试模拟,包括目录遍历、服务端请求伪造 (SSRF)、不安全的文件上传和 XML 外部实体 (XXE) 攻击。它还具有一个管理后台,用于管理钓鱼模拟并监控捕获的会话负载。 整个平台通过容器化镜像部署,该镜像会自动初始化数据库模式并使用种子数据填充环境。

    Provides an isolated testing setup deployed via containers for a consistent security research workspace.

    PHPweb
    在 GitHub 上查看↗4,421
  • aquasecurity/traceeaquasecurity 的头像

    aquasecurity/tracee

    4,377在 GitHub 上查看↗

    Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho

    Runtime security and forensics tool using eBPF.

    Gobpfdockerebpf
    在 GitHub 上查看↗4,377
  • hotcakex/harden-windows-securityHotCakeX 的头像

    HotCakeX/Harden-Windows-Security

    4,139在 GitHub 上查看↗

    Harden-Windows-Security is a security hardening tool and framework designed to reduce the attack surface of the Windows operating system through policy enforcement. It provides a collection of security presets and templates to implement official hardening standards across multiple devices. The project distinguishes itself through a comprehensive execution control system, featuring a manager for Windows Application Control and a kernel protection suite. It implements strict trust models, including kernel-mode driver whitelisting, signed policy implementation on the EFI partition, and code inte

    Script for hardening Windows system configurations.

    C#1st-party-securityapplicationcontrolaudit
    在 GitHub 上查看↗4,139
  • kevoreilly/capev2kevoreilly 的头像

    kevoreilly/CAPEv2

    3,284在 GitHub 上查看↗

    Malware Configuration And Payload Extraction

    Automated malware analysis platform with advanced reporting capabilities.

    Python
    在 GitHub 上查看↗3,284
  • thinkst/opencanarythinkst 的头像

    thinkst/opencanary

    2,776在 GitHub 上查看↗

    OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a security decoy that creates fake server personalities and open ports to identify unauthorized users scanning a private network. The system uses deception technology to mimic various server protocols, luring attackers into revealing their presence and activity. When a simulated service is accessed, it acts as an intrusion alerting gateway, transmitting notifications via email or webhooks. The project covers internal network monitoring and intrusion source tracking to identify the

    Deception tool for detecting unauthorized network activity.

    Python
    在 GitHub 上查看↗2,776
上一个123下一个
  1. Home
  2. Part of an Awesome List
  3. DevOps & Infrastructure
  4. Security Lab Environments