21 个仓库
Tools for verifying security configurations, checking for data breaches, and analyzing network-level security.
Distinct from Infrastructure and Network Security: Shortlist candidates are mostly general 'Networking and Security' lists rather than specific auditing tools.
Explore 21 awesome GitHub repositories matching security & cryptography · Network Security Auditing. Refine with filters or upvote what's useful.
RustScan is a high-speed TCP network scanner written in Rust, designed for security reconnaissance and network mapping. It functions as an automated port discovery engine that identifies open ports on remote hosts using IPv6 addresses, CIDR ranges, or bulk input files. The tool is built for rapid surface area discovery, utilizing parallel port processing and OS-aware performance optimizations to identify active services. It allows for scan precision tuning through adjustable connection timeout thresholds and concurrent request controls to balance speed and accuracy. The system integrates wit
Facilitates automated network auditing by running scheduled scans and piping results to custom scripts.
Micro8 is a security auditing knowledge base and penetration testing resource library. It serves as a curated collection of guides and documentation focused on vulnerability assessment. The project provides educational content and study guides for manual source code review, domain escalation, and internal network auditing. It includes a toolkit of reference materials for analyzing network traffic logs and identifying brute-force patterns. The library covers technical domains including web penetration testing and privilege escalation. It organizes these materials through PDF-based knowledge r
Contains resources for verifying security configurations and auditing internal network infrastructure.
Amass is a network attack surface mapper and reconnaissance framework designed to discover and map the external, internet-facing infrastructure of a target organization. It functions as an open source intelligence tool that identifies public network boundaries and locates hidden or forgotten subdomains to define an organization's total reachable footprint. The project utilizes passive-source data aggregation from external APIs and public databases alongside active DNS brute-forcing and recursive subdomain expansion. It employs a graph-based asset mapping system to visualize the relationships
Maps all reachable public assets to ensure total coverage of entry points for network security reviews.
Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit
Identifies known vulnerabilities in network hardware and devices through platform enumeration and version checking.
This project is a collection of bash automation scripts and command-line utilities designed to automate common tasks and retrieve information from web APIs. It serves as a toolkit for developer references, network diagnostics, and media access directly from the terminal. A central component of the suite is a GitHub Gist manager that handles the full lifecycle of code snippets. This includes cloning and syncing Gists into local directories for offline access, organizing content through hashtags, and searching through snippet descriptions and file contents using regular expressions. The toolki
Provides utilities for analyzing SSL ciphers, verifying email breaches, and retrieving detailed IP geolocation data.
gosec is a static analysis security tool designed to scan Go source code for vulnerabilities and common coding flaws. It functions as a security analyzer that inspects the abstract syntax tree to identify insecure function calls, API usage, and potential security risks. The tool distinguishes itself by mapping detected vulnerabilities to Common Weakness Enumeration identifiers for standardized reporting and integrating with external AI models to suggest code fixes for identified issues. Its capabilities cover the detection of injection vulnerabilities, hardcoded credentials, weak cryptograph
Identifies insecure network settings such as binding to all interfaces and unsafe redirect policies.
testssl.sh is a network security tool and SSL/TLS security scanner used to audit server configurations. It functions as a diagnostic utility that validates supported ciphers and protocols to identify cryptographic vulnerabilities and flaws in encrypted communication. The tool is available as both a command-line utility and a dockerized security scanner, allowing for execution in isolated environments without the need for local dependency installation. Its capabilities cover SSL configuration auditing and TLS server security analysis. The system exports scan results into structured reports a
Produces detailed reports on server encryption standards to document security compliance for audits.
Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet
Provides a specialized engine for scanning network environments to identify critical weaknesses and report vulnerabilities.
Simplewall is an application firewall manager and network traffic filter that provides a graphical interface for the Windows Filtering Platform. It controls inbound and outbound network access for individual programs and services by intercepting and filtering traffic at the kernel level. The project identifies specific binaries using file hashes to prevent spoofing and allows users to define custom firewall rules based on IP addresses, CIDR ranges, and port numbers. It includes a system for blocking operating system telemetry and managing blocklists of known malicious IP addresses. The tool
Logs dropped packets and monitors blocked attempts to audit network security and refine rules.
该项目是一款移动网络安全审计工具和 IMSI 捕获器检测器,旨在识别试图拦截移动流量的伪基站和监控硬件。它作为无线电接口分析器和蜂窝塔映射工具,监控连接以检测未经授权的网络基础设施。 该系统结合了实时威胁级别监控与识别静默短信(Silent SMS)及用于设备追踪的隐蔽通信的能力。它分析加密状态以检测强制网络降级到较弱加密标准的情况,并通过将基站数据与公共数据库进行交叉比对来验证基站身份。 该工具涵盖了移动网络审计的广泛功能,包括信号异常追踪、无线电硬件数据提取,以及防止基于 SIM 卡的远程攻击或未经授权的应用程序安装。它还提供基站连接可视化,以及允许用户定义自定义检测字符串以监控可疑消息的机制。 通过在 root 终端执行 AT 指令来获取详细的网络遥测数据,从而实现底层硬件交互。
Analyzes radio signal strength, ciphering status, and tower IDs to verify the legitimacy of cellular network infrastructure.
Nettacker 是一个自动化渗透测试框架,旨在编排侦察、端口扫描和漏洞检测。它作为一个网络侦察工具和漏洞扫描器,能够识别开放端口、指纹识别服务,并根据已知安全漏洞数据库检查系统。 该框架的独特之处在于结合了用于通过模糊测试发现隐藏路径的 Web 应用爬虫,以及一个将扫描结果持久化到数据库以跟踪历史评估的漏洞管理系统。它还包含子域名枚举、凭据暴力破解以及通过代理路由流量以实现匿名化的专业功能。 该系统涵盖了广泛的安全能力,包括网络资产发现、多协议服务审计和配置审计。它支持跨 IP 范围和 CIDR 块的多目标扫描,并提供多种格式的安全报告生成工具。 通过基于 REST 的接口可实现程序化控制,从而将该框架集成到安全流水线和自动化流程中。
Audits network services and server configurations for misconfigurations, outdated patches, and weak credentials.
Cameradar is a network scanning tool designed to discover publicly accessible IP cameras. It identifies active Real Time Streaming Protocol services by scanning IP ranges and using device fingerprints to determine specific hardware models. The tool performs security auditing through dictionary-based probing and brute force attacks to uncover valid streaming paths and authentication credentials. It validates discovered streams by verifying the receipt of real-time transport protocol data packets to eliminate false positives. The system supports a multi-stage discovery pipeline and can export
Tests IP cameras for weak credentials and open access via dictionary attacks and brute force probing.
kscan 是一款网络安全扫描器和服务指纹识别工具,用于发现活跃主机和开放端口。它作为网络协议分析器和内网映射工具,能够识别可达网关并分析目标环境的网络攻击面。 该工具通过外部情报服务检索目标主机并验证其可用性,从而集成外部资产发现功能。它还可用作凭据爆破工具,利用自动化的用户名和密码字典测试多种协议的身份验证强度。 该项目涵盖了通过识别软件版本、操作系统和通信协议进行网络安全审计的功能。它支持导入包括 IP 地址和 URL 在内的多种目标格式,并可编译为独立二进制文件以实现便携式执行。
Scans for open ports and probes network segments to identify potential entry points and security vulnerabilities.
PRET 是一个网络打印机利用框架和安全实用程序,旨在发现打印硬件并审计固件。它作为一个工具包,通过操纵打印机特定的控制语言和协议来渗透打印基础设施。 该项目提供了通过缓冲区溢出触发远程代码执行以及使用打印机作业语言 (Printer Job Language) 管理打印机文件系统的专门功能。它允许提取设备元数据(如固件版本和内存资源),并修改硬件行为和系统参数。 该框架涵盖了广泛的安全测试面,包括网络设备发现、通过输入泛洪进行的漏洞评估以及打印工作流的拦截。它还包括用于系统信息提取和硬件级拒绝服务测试的工具。
Scans local networks to identify printing devices and audit them for common security vulnerabilities.
Hubble 是一个基于 eBPF 的 Kubernetes 可观测性平台,专为网络监控、安全审计和流量检查而设计。它利用内核级钩子收集网络事件,从而深入了解容器化流量和集群安全。 该系统具有用于可视化微服务与外部端点之间通信模式和依赖关系的服务地图。它结合了基于身份的流量标记,使用 Kubernetes 标签而非易变的 IP 地址来跟踪网络流量。 该平台涵盖了广泛的监控功能,包括对 TCP 连接和 DNS 查询的细粒度检查、流量过滤以及系统性能指标的跟踪。它还提供用于审计安全策略执行和检测集群内未经授权访问的工具。
Tracks network flows and policy enforcement to detect unauthorized access and verify security rules in clusters.
Vulscan is a network service auditor and vulnerability scanner that utilizes the Nmap Scripting Engine to identify security flaws. It functions as a version-based flaw detector, matching detected software banners against an offline vulnerability database to identify potential security risks without requiring a constant internet connection. The tool provides mechanisms for refining identification accuracy, including an interactive mode for manual version overriding and configurable matching logic to filter results. It manages security data through a system for loading local datasets and synchr
Performs structured scans of network services to identify outdated software and critical vulnerabilities.
Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe
Audits router configurations to determine permitted level 4 protocols.
RealiTLScanner is a TLS configuration scanner and network security auditor designed to identify security settings across IP addresses and domains. It functions as a target discovery tool that analyzes TLS configurations to find compatible endpoints and evaluate server security postures. The project distinguishes itself as a geolocation-enhanced network scanner, appending geographic location data and country codes to discovered security configurations using a local location database. This allows for the geographic mapping of servers by combining TLS scan results with GeoIP data. The tool supp
Audits network security postures by detecting TLS configurations across wide network blocks and domain lists.
Bearer is a static analysis security testing tool and privacy compliance auditor. It identifies security vulnerabilities, hard-coded secrets, and privacy risks in source code through static analysis and data flow tracing. The tool distinguishes itself by tracking the movement of sensitive data through code to identify leaks and by mapping personal and health-related information flows to generate evidence for privacy impact assessments. It also provides differential scanning for pull requests and uses fingerprint-based suppression to exclude known false positives from reports. The platform co
Identifies insecure protocols and missing SSL verification in network settings.
PCredz is a network credential extraction tool and traffic analyzer designed to intercept passwords, hashes, and tokens from IPv4 and IPv6 traffic. It functions as both a real-time monitor for live network interfaces and a parser for saved packet capture files. The tool identifies sensitive information, including credit card numbers and authentication tokens, using protocol-aware parsing. It further acts as a password hash recovery utility by normalizing captured authentication hashes into specific syntaxes compatible with external recovery software. Capabilities include real-time traffic in
Monitors IPv4 and IPv6 traffic in real time to detect insecure protocols and unauthorized credential transmission.