awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

320 个仓库

Awesome GitHub RepositoriesVulnerability Assessment and Testing

Methodologies and tools for identifying security flaws, testing robustness, and auditing system compliance.

Explore 320 awesome GitHub repositories matching security & cryptography · Vulnerability Assessment and Testing. Refine with filters or upvote what's useful.

Awesome Vulnerability Assessment and Testing GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • sindresorhus/awesomesindresorhus 的头像

    sindresorhus/awesome

    476,211在 GitHub 上查看↗

    这是一个由社区维护的目录,作为软件工具、框架和教育资源的综合索引。它充当开源知识库,将不同的工程领域和技术资源组织成结构化的分类体系,以帮助开发者发现高质量内容。 该目录通过去中心化的同行评审模型脱颖而出,由独立贡献者策划、验证和更新条目,以确保准确性和相关性。所有信息均以版本控制的纯文本 Markdown 格式存储,确保了整个集合的平台独立性、透明度和可审计性。 该项目涵盖了广泛的能力领域,包括技术资源发现、职业发展和软件开发知识管理。它提供结构化的学习路径、基础设施和安全工具、数据管理实用程序,以及从医疗保健到数字人文等领域的专业资源。 该仓库作为公共版本控制集合进行维护,支持程序化访问和社区驱动的数据更新。

    Covers methodologies and tools for identifying security flaws and testing application robustness.

    awesomeawesome-listlists
    在 GitHub 上查看↗476,211
  • trimstray/the-book-of-secret-knowledgetrimstray 的头像

    trimstray/the-book-of-secret-knowledge

    228,641在 GitHub 上查看↗

    该项目作为一个中心化的、社区驱动的技术知识和管理资源仓库。它提供了一个结构化的分类体系,将分散的信息聚合到一个可搜索的框架中,支持系统管理员和网络安全从业者的持续学习和快速问题解决。通过映射跨越进攻性安全、基础设施管理和软件开发的资源,它为技能获取和专业参考提供了统一路径。 该项目由命令行优先的设计理念定义,优先考虑基于终端的实用程序和可脚本化的接口,以促进高效的系统管理和可重复的安全工作流。它通过平台无关的方法脱颖而出,维护在不同类 Unix 和云环境中保持适用的文档和操作指南。这种模块化的工具链集成允许用户组合针对特定管理或安全任务定制的自定义环境。 该仓库涵盖了广泛的能力领域,包括用于系统审计、网络管理和基础设施加固的综合工具包。它为网络安全技能发展提供了结构化的学习路径,范围从道德黑客实验室和渗透测试标准到漏洞评估和系统配置最佳实践。该集合还包含广泛的生产力工具、诊断实用程序和教育材料,旨在简化日常维护并增强整体安全态势。

    Identifies locally deployable web applications intentionally designed with security flaws for practicing exploitation and defensive techniques.

    awesomeawesome-listbsd
    在 GitHub 上查看↗228,641
  • garrytan/gstackgarrytan 的头像

    garrytan/gstack

    110,596在 GitHub 上查看↗

    gstack is an AI agent framework and development workflow system designed to automate the software development lifecycle. It coordinates specialized AI personas to manage tasks across product design, engineering management, and quality assurance, transforming product intent into technical specifications and final releases. The project is distinguished by its deep integration of headless browser automation and semantic code memory. It utilizes a persistent Chromium daemon for web scraping and visual auditing, and implements a searchable knowledge base that logs architectural decisions and repos

    Performs structural audits to identify complex race conditions and broken invariants that pass standard tests.

    TypeScript
    在 GitHub 上查看↗110,596
  • swisskyrepo/payloadsallthethingsswisskyrepo 的头像

    swisskyrepo/PayloadsAllTheThings

    78,434在 GitHub 上查看↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Supplies a diverse library of payloads tailored for testing vulnerabilities where applications improperly process remote file inclusions.

    Pythonbountybugbountybypass
    在 GitHub 上查看↗78,434
  • z4nzu/hackingtoolZ4nzu 的头像

    Z4nzu/hackingtool

    77,515在 GitHub 上查看↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    Audits system robustness and identifies security flaws using a centralized, multi-purpose toolkit.

    Pythonallinonehackingtoolbesthackingtoolctf-tools
    在 GitHub 上查看↗77,515
  • openhands/openhandsOpenHands 的头像

    OpenHands/OpenHands

    77,330在 GitHub 上查看↗

    OpenHands is an autonomous agent framework designed for software engineering workflows. It provides a modular platform for orchestrating AI agents that reason, plan, and execute tasks within isolated, containerized development environments. By integrating with standard version control and development tools, the system enables agents to autonomously navigate codebases, implement features, and resolve issues through iterative reasoning and tool execution. The platform distinguishes itself through a model-agnostic orchestrator that connects diverse language models to a unified tool registry. It

    Validates security risks by requiring language models to embed analysis parameters directly within tool calls.

    Pythonagentartificial-intelligencechatgpt
    在 GitHub 上查看↗77,330
  • danielmiessler/seclistsdanielmiessler 的头像

    danielmiessler/SecLists

    71,596在 GitHub 上查看↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    Provides a comprehensive collection of usernames, passwords, and sensitive data patterns for security assessment.

    PHP
    在 GitHub 上查看↗71,596
  • nationalsecurityagency/ghidraNationalSecurityAgency 的头像

    NationalSecurityAgency/ghidra

    69,740在 GitHub 上查看↗

    Ghidra is a software reverse engineering suite designed to analyze compiled binaries and reconstruct program logic without access to original source code. It provides an interactive environment for disassembly and decompilation, utilizing a platform-independent intermediate representation to maintain consistency across diverse hardware architectures. The framework supports automated binary analysis through programmatic routines, enabling the investigation of complex code patterns and security indicators. The platform distinguishes itself through a modular architecture that allows for extensiv

    Automates the scanning of compiled binaries to detect security indicators, patterns, and potential logic vulnerabilities.

    Javadisassemblerreverse-engineeringsoftware-analysis
    在 GitHub 上查看↗69,740
  • addyosmani/agent-skillsaddyosmani 的头像

    addyosmani/agent-skills

    60,849在 GitHub 上查看↗

    Agent-skills is a collection of structured instructions and behavioral personas designed to standardize how AI coding agents perform engineering tasks. It functions as a workflow orchestrator that maps natural language intent to repeatable technical sequences and verification checklists. The project distinguishes itself through the use of specialized markdown-defined roles, such as security auditors or test engineers, to apply targeted domain expertise. It employs an evidence-based verification model that requires runtime data or passing tests as mandatory exit criteria to ensure AI-generated

    Categorizes security findings by risk level based on exploitability and impact to prioritize remediation.

    Shellagent-skillsantigravityantigravity-ide
    在 GitHub 上查看↗60,849
  • rails/railsrails 的头像

    rails/rails

    58,690在 GitHub 上查看↗

    This project is a full-stack web framework designed for building database-backed applications through a standardized architectural pattern. It provides a comprehensive suite of integrated libraries that manage the entire request-response lifecycle, from routing incoming web traffic to rendering dynamic server-side templates. By utilizing an object-relational mapping layer, the framework allows developers to define domain models that map database tables directly to application objects, simplifying data persistence, schema migrations, and complex relationship management. The framework is distin

    Maintains a transparent disclosure process for managing and reviewing reported security vulnerabilities.

    Rubyactivejobactiverecordframework
    在 GitHub 上查看↗58,690
  • narkoz/hacker-scriptsNARKOZ 的头像

    NARKOZ/hacker-scripts

    49,734在 GitHub 上查看↗

    hacker-scripts is a multi-purpose toolkit comprising a security vulnerability testing suite, a keyword-driven email automator, and a TCP remote hardware controller. It provides a collection of scripts for identifying security weaknesses and conducting controlled hacking experiments across multiple programming language environments. The system automates email workflows by scanning headers and bodies for specific strings to trigger server responses and sends randomized text and email alerts based on system activity. It also enables remote hardware control by sending binary commands over network

    Provides a suite of multi-language scripts for identifying security weaknesses and conducting controlled hacking experiments.

    JavaScript
    在 GitHub 上查看↗49,734
  • minimaxir/big-list-of-naughty-stringsminimaxir 的头像

    minimaxir/big-list-of-naughty-strings

    47,686在 GitHub 上查看↗

    This project is a standardized repository of malicious and malformed character sequences designed to stress-test data parsing and sanitization routines. It serves as a security testing corpus and a language-neutral reference for auditing software robustness against injection flaws and unexpected data handling errors across diverse platforms. The dataset functions as a benchmark for input validation, providing a curated collection of edge-case strings that allow developers to identify potential crashes and security vulnerabilities. By decoupling these test vectors from application logic, the r

    Serves as a language-neutral reference for auditing software robustness against injection flaws and data handling errors.

    Python
    在 GitHub 上查看↗47,686
  • keygraphhq/shannonKeygraphHQ 的头像

    KeygraphHQ/shannon

    44,672在 GitHub 上查看↗

    Shannon is an integrated security platform designed for autonomous penetration testing, static and dynamic analysis, and automated vulnerability remediation within self-hosted, private infrastructure. It functions as a unified security suite that orchestrates the entire lifecycle of vulnerability management, from initial discovery and reachability prioritization to the generation and verification of code-level patches. The platform distinguishes itself through its agentic approach to security, deploying autonomous agents to execute both black-box and white-box exploits against running applica

    Correlates static code analysis with dynamic runtime exploitation to provide a unified view of reachable security risks.

    TypeScriptpenetration-testingpentestingsecurity-audit
    在 GitHub 上查看↗44,672
  • filamentphp/filamentfilamentphp 的头像

    filamentphp/filament

    31,215在 GitHub 上查看↗

    Filament is a full-stack framework for building administrative panels and management interfaces within the Laravel ecosystem. It provides a declarative, component-based architecture that allows developers to construct complex, data-driven applications using server-side configuration objects rather than manual HTML. By inspecting database model structures and relationships, the framework automates the generation of CRUD interfaces, forms, and data tables, significantly reducing boilerplate code. The project distinguishes itself through a highly modular and extensible design that supports custo

    Scans codebases for vulnerabilities and misconfigurations to provide actionable security remediation.

    PHPadminalpine-jsbuilder
    在 GitHub 上查看↗31,215
  • honojs/honohonojs 的头像

    honojs/hono

    30,994在 GitHub 上查看↗

    Hono is a lightweight web framework built on Web Standard APIs that executes across JavaScript runtimes including Cloudflare Workers, Deno, Bun, and Node.js.

    Verifies JSON Web Tokens from headers or cookies and exposes decoded payloads to the application context.

    TypeScriptframeworkedgecloudflare-workers
    在 GitHub 上查看↗30,994
  • projectdiscovery/nucleiprojectdiscovery 的头像

    projectdiscovery/nuclei

    29,189在 GitHub 上查看↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Provides a high-performance engine for identifying security weaknesses and misconfigurations across large-scale network environments.

    Goattack-surfacecve-scannerdast
    在 GitHub 上查看↗29,189
  • yamadashy/repomixyamadashy 的头像

    yamadashy/repomix

    26,498在 GitHub 上查看↗

    Repomix is an AI-focused development utility designed to prepare local and remote codebases for analysis, review, and automated interaction. It functions as a codebase context bundler and a Model Context Protocol server, aggregating project files into structured documents that are optimized for ingestion by large language models. By serving as a bridge between local repositories and external intelligence agents, the tool facilitates real-time codebase inspection and automated development workflows. The system distinguishes itself through rigorous repository token management and security-consc

    Examines code for vulnerabilities, insecure patterns, and dependency safety to provide actionable remediation steps.

    TypeScriptaianthropicartificial-intelligence
    在 GitHub 上查看↗26,498
  • hashcat/hashcathashcat 的头像

    hashcat/hashcat

    26,200在 GitHub 上查看↗

    Hashcat is a high-performance hash cracking software and OpenCL compute application used to recover plain-text passwords from hashed data. It functions as a GPU-accelerated recovery tool and distributed password cracker, leveraging CPUs and GPUs to perform intensive cryptographic computations. The system differentiates itself through a distributed cracking workflow that coordinates tasks across multiple machines via an overlay network to share computational load. It further optimizes recovery speed using Markov chain keyspace optimization to prioritize the most likely password candidates. Th

    Iterates through all possible combinations of characters based on a specified mask to find a matching hash.

    C
    在 GitHub 上查看↗26,200
  • docker-slim/docker-slimdocker-slim 的头像

    docker-slim/docker-slim

    23,311在 GitHub 上查看↗

    This project is a suite of specialized tools for linting, minifying, analyzing, and managing container images and their associated registries. It provides a set of utilities including an image minifier to reduce image size, a security profiler to harden running containers, an image analyzer for static inspection, and a registry manager for organizing multi-architecture indices. The toolset distinguishes itself through behavior-based optimization and security. It uses dynamic analysis to track executed instructions and file access to remove unused binary data, and records kernel interactions t

    Retrieves and filters risk information for specific security IDs to assess threat levels within container images.

    Go
    在 GitHub 上查看↗23,311
  • shieldfy/api-security-checklistshieldfy 的头像

    shieldfy/API-Security-Checklist

    23,258在 GitHub 上查看↗

    This project is a comprehensive API security audit checklist and vulnerability audit framework. It provides a structured guide of security countermeasures for designing, testing, and deploying secure APIs across various protocols. The framework includes specialized guides for securing OAuth 2.0 authorization flows, implementing zero trust networking for service-to-service communication, and protecting GraphQL endpoints from resource exhaustion and information leakage. It also provides standards for integrating static analysis, dynamic scanning, and secret detection into CI/CD delivery pipelin

    Provides a comprehensive framework and checklist for auditing API security during design and release.

    apijwtoauth2
    在 GitHub 上查看↗23,258
上一个123456…16下一个
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing

探索子标签

  • CPU Vulnerability AssessmentsSystematic evaluation of CPU hardware and kernel settings to identify transient execution risks. **Distinct from Vulnerability Assessment and Testing:** Focuses on CPU-specific hardware vulnerabilities, unlike general vulnerability assessment methodologies.
  • Digital Forensics2 个子标签Methods for investigating and analyzing digital evidence.
  • Firmware Security MethodologiesStructured frameworks specifically designed for auditing and testing the security of embedded device firmware.
  • IoT Vulnerable FirmwareFirmware images for IoT devices containing known vulnerabilities for training and research.
  • Network Reconnaissance Tools2 个子标签Tools used to scan networks and identify active services, potential entry points, or vulnerabilities in infrastructure.
  • Penetration Testing FrameworksSoftware environments used to simulate cyber attacks for identifying system vulnerabilities.
  • Security Testing and Auditing13 个子标签Frameworks and tools used to evaluate, audit, and identify security weaknesses within software and systems.
  • Vulnerability Reporting2 个子标签Platforms and processes that allow researchers and users to disclose discovered security flaws to developers.