Stars
Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readines…
Got Your Back (GYB) is a command line tool for backing up your Gmail messages to your computer using Gmail's API over HTTPS.
A minimalist risk management program!
Python library to carry out DFIR analysis on the Cloud
A KeePass/Password Safe Client for iOS and OS X
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
This is a collection of legal wording and documentation used for physical security assessments. The goal is to hopefully allow this as a template for other companies to use and to protect themselve…
Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet
Python Script to access ATT&CK content available in STIX via a public TAXII server
A few scripts I put together for testing purposes and to automate a few capabilities while doing IR. These scripts are also part of my blog https://cyberwardog.blogspot.com/
Web app that provides basic navigation and annotation of ATT&CK matrices
Actionable analytics designed to combat threats
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
The Secure Coding Dojo is a platform for delivering secure coding knowledge.
Getting a handle on container security
OWASP Benchmark is a test suite designed to verify the speed and accuracy of software vulnerability detection tools. A fully runnable web app written in Java, it supports analysis by Static (SAST),…
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
In-depth attack surface mapping and asset discovery
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
Protect and discover secrets using Gitleaks 🔑
An enterprise friendly way of detecting and preventing secrets in code.