6 个仓库
Using signature-based matching to identify specific vulnerabilities or software patterns across assets.
Distinct from Vulnerability Scanning: Focuses on YARA-style pattern matching across discovered assets rather than general image or package scanning
Explore 6 awesome GitHub repositories matching security & cryptography · Pattern-Based Detection. Refine with filters or upvote what's useful.
This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions as a containerized security scanner designed to map public-facing infrastructure, perform subdomain enumeration, and automate the gathering of open-source intelligence. The system employs a recursive discovery engine to iteratively explore target infrastructure, utilizing a plugin-based module architecture to extend scanning capabilities. It integrates third-party APIs for data enrichment and applies YARA rules across discovered assets to identify specific vulnerability patte
Applies YARA rules to scan the discovered attack surface for specific files, patterns, or known software vulnerabilities.
MySQLTuner-perl is a diagnostic utility and Perl script designed for optimizing database configurations, auditing security, monitoring resources, and analyzing performance. It functions as a configuration optimizer and performance tuning tool that analyzes server variables to provide specific recommendations for increasing system stability and speed. The tool acts as a database auditor by evaluating security settings, SSL configurations, and schema integrity to identify vulnerabilities. It also serves as a resource monitor that forecasts capacity needs and calculates health scores based on di
Identifies the underlying hosting environment by scanning system metadata and network signatures for cloud provider patterns.
testssl.sh is a suite of diagnostic tools and a network security auditor used to scan network ports for supported encryption protocols, ciphers, and vulnerabilities in TLS and SSL configurations. It functions as a security scanner that evaluates the cryptographic strength of a server by testing all available cipher suites. The tool analyzes server encryption strength and identifies security vulnerabilities or weak settings through TLS and SSL security auditing. It verifies that encryption is properly implemented on specific network ports and evaluates whether only strong and modern encryption
Uses signature-based pattern matching to identify specific SSL and TLS vulnerabilities in server responses.
Canta 是一个 Android 系统的非 Root 应用管理器和臃肿软件(bloatware)移除工具。它通过利用特权系统服务来识别并删除非必要的系统软件。 该工具使用一份经过整理的安全移除包列表来识别臃肿软件,防止系统不稳定。它利用 Shizuku 服务进行特权命令执行,无需完全获取设备 Root 权限即可执行这些移除操作。 该项目提供了通过包过滤和 ADB 驱动的进程执行进行无 Root 应用卸载、非破坏性应用禁用以及系统优化的功能。
Provides a system to identify pre-installed bloatware by matching installed packages against curated safe-to-delete lists.
RyTuneX is a utility suite designed for managing operating system features, removing bloatware, and controlling data privacy settings. It functions as a system optimizer and debloater that allows users to uninstall preinstalled applications and tune system configurations to improve performance and reliability. The project includes a privacy manager to disable telemetry and block data collection tracking. It provides a dashboard for modifying system behaviors and hardware specifications through a simplified interface, including toggle switches for native operating system features. The suite c
Identifies preinstalled applications by matching package names and paths against a known bloatware database.
nodejsscan is a static analysis security tool and vulnerability detection engine designed to scan Node.js source code for security flaws and common coding vulnerabilities. It functions as a static application security testing tool that analyzes code without executing the program. The tool operates as a security linter that can be integrated into continuous integration pipelines to block insecure code from merging into main branches. It automates the auditing process through rule-based detection and pattern-based static analysis. The project provides capabilities for vulnerability alert autom
Matches specific code patterns against a library of security flaws to flag risks.