11 个仓库
Provides credentials and focus areas to tailor vulnerability research.
Distinct from Vulnerability Scanning: Distinct from general vulnerability scanning: focuses on user-provided guidance and context.
Explore 11 awesome GitHub repositories matching security & cryptography · Scan Contextualization. Refine with filters or upvote what's useful.
Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno
Provides context, credentials, and focus areas to the analysis engine to tailor the scope of vulnerability research.
OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.
Implements an active scanning engine that sends malicious payloads to identify web vulnerabilities.
Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove
Ships a modular scanning engine that executes a library of security checks to identify multi-cloud misconfigurations.
testssl.sh is a suite of diagnostic tools and a network security auditor used to scan network ports for supported encryption protocols, ciphers, and vulnerabilities in TLS and SSL configurations. It functions as a security scanner that evaluates the cryptographic strength of a server by testing all available cipher suites. The tool analyzes server encryption strength and identifies security vulnerabilities or weak settings through TLS and SSL security auditing. It verifies that encryption is properly implemented on specific network ports and evaluates whether only strong and modern encryption
Implements a modular engine to execute sequential security checks for protocol and vulnerability detection.
Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet
Utilizes a modular engine that executes interchangeable detection plugins for vulnerability identification.
Nettacker 是一个自动化渗透测试框架,旨在编排侦察、端口扫描和漏洞检测。它作为一个网络侦察工具和漏洞扫描器,能够识别开放端口、指纹识别服务,并根据已知安全漏洞数据库检查系统。 该框架的独特之处在于结合了用于通过模糊测试发现隐藏路径的 Web 应用爬虫,以及一个将扫描结果持久化到数据库以跟踪历史评估的漏洞管理系统。它还包含子域名枚举、凭据暴力破解以及通过代理路由流量以实现匿名化的专业功能。 该系统涵盖了广泛的安全能力,包括网络资产发现、多协议服务审计和配置审计。它支持跨 IP 范围和 CIDR 块的多目标扫描,并提供多种格式的安全报告生成工具。 通过基于 REST 的接口可实现程序化控制,从而将该框架集成到安全流水线和自动化流程中。
Implements a network scanning tool that identifies active devices and services across a target network.
Hooker 是一个用于 Android 应用程序动态插桩、内存分析和去混淆的工具包。它作为一个逆向工程框架,使用 Frida 将脚本注入正在运行的进程中,监控原生调用并提取可执行的 DEX 文件。 该项目提供了用于绕过安全控制的专用工具,包括禁用 SSL 证书验证和 BoringSSL 固定以实现 HTTPS 流量拦截。它包括检测应用程序加固、通过 Hook 加密算法提取加密密钥以及规避 Root 或调试环境检查的功能。 该框架涵盖了广泛的分析功能,包括用于检测活动组件的内存扫描、用于网络流量路由的 SOCKS5 代理配置以及 UI 交互分析。它还支持收集设备指纹和调试嵌入式 WebView。
A toolkit for scanning application memory to detect active services and map component addresses.
Kube-hunter 是一个用于 Kubernetes 集群的安全扫描器和漏洞猎手。它作为一个云原生渗透工具运行,旨在通过模拟攻击者技术来识别安全弱点、基础设施配置错误和可利用的漏洞。 该工具以其双模式扫描引擎而著称,该引擎既执行远程外部探测,也执行内部网络扫描。它具有基于身份的模拟功能,允许它使用服务账户令牌和 Pod 身份来模拟来自特定集群角色的安全访问,并确定容器受损的潜在影响范围。 该项目涵盖了广泛的安全评估能力,包括集群漏洞扫描、内部网络拓扑映射和合规性验证。它可以检测暴露的密钥、分析基础设施模板中的配置错误,并执行主动利用尝试以验证发现的漏洞是否可被利用。 该应用程序被打包为独立的可执行文件,以在部署期间消除运行时依赖。
Implements an active scanning engine that executes both remote probes and internal network scans to identify vulnerabilities.
Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t
Injects cookies or custom headers to scan protected or stateful application areas.
ShuiZe_0x727 是一个开源情报收集框架和攻击面管理工具。它作为一个资产发现引擎和网络情报聚合器,旨在识别面向互联网的资产、映射网络基础设施并可视化总网络暴露情况。 该项目集成了漏洞扫描和敏感数据泄露检测,以识别安全弱点和未经授权的访问点。它结合了网络空间 API 查询、证书日志分析和公共存储库扫描,以提取泄露的凭据、API 密钥和内部管理路径。 该框架提供了自动化信息收集和网络情报研究的功能,利用基于插件的扫描引擎来检测跨 Web 服务和开放端口的漏洞。收集到的资产数据和安全发现被导出为格式化的电子表格,以便进行离线分析和审计。
Employs a modular scanning engine to execute isolated vulnerability tests and port scanning routines.
Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource
Uses a modular engine to execute a library of security check plugins across cloud environments.