Zero-trust-beveiliging
87 projecten in Beveiliging & identiteit
Hasura
@hasuraFast, instant realtime GraphQL APIs on Postgres with fine grained access control, also trigger webhooks on database events.
scapy
@secdevScapy: the Python-based interactive packet manipulation program & library.
Pi.Alert
@leiweibauScan the devices connected to your WIFI / LAN and alert you the connection of unknown devices. It also warns if a "always connected" device disconnects. In addition, it is possible to check web services for availability. For this purpose HTTP status codes and the response time of the service are evaluated.
Firezone
@firezoneSecure remote access gateway that supports the WireGuard protocol. It offers a Web GUI, 1-line install script, multi-factor auth (MFA), and SSO.
ScaleTail
@tailscale-devTailscale Sidecar Configurations for Docker
OpenZiti
@openzitiFully-featured, zero trust, full mesh overlay network. Includes a 2FA support out of the box, clients for all major desktop/mobile OS'es.
AppInfoScanner
@kelvinBen一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
opennhp
@OpenNHPA lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the AI-driven world.
next-terminal
@next-terminalA simple, secure, easy-to-use bastion and session auditing system. Supports RDP, SSH, VNC, Telnet, HTTP, records and replays sessions for auditing and compliance.
Bjorn
@infinitionBjorn is a powerful network scanning and offensive security tool for the Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers network targets, identifies open ports, exposed services, and potential vulnerabilities. Bjorn can perform brute force attacks, file stealing, host zombification, and supports custom attack scripts.
zrok
@openzitiSecure internet sharing made simple.
Smap
@s0md3va drop-in replacement for Nmap powered by shodan.io
boundary
@hashicorpBoundary enables identity-based access management for dynamic infrastructure.
Aether
@CluvexStudioA Rust userspace WARP core for censored networks, built around MASQUE over HTTP/3 and HTTP/2.
nono
@nolabs-aiagent runtime security - zero trust, zero setup, zero latency.
networking-toolbox
@lissy93🛜 100+ offline-first networking tools and utilities
harden-runner
@step-securityHarden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
DockFlare
@ChrispyBacon-devDockFlare: Automate Cloudflare Tunnels with Docker Labels
clodex-ide
@mereyabdenbekuly-ctrlLocal-first, zero-trust agentic IDE for verifiable autonomous software development.
MicroWARP
@ccbkkb🚀 An 800KB RAM ultra-lightweight Cloudflare WARP SOCKS5 proxy in Docker. 仅需 800KB 内存的纯内核态 Cloudflare WARP 代理 - Docker
proxelar
@emanuele-emScriptable local traffic workbench for inspecting, intercepting, replaying, and rewriting HTTP/HTTPS and WebSocket traffic.
Data-Shield_IPv4_Blocklist
@duggytuxyData-Shield IPv4 Blocklist Community provides an official, curated registry of IPv4 addresses identified as malicious. Updated continuously, this resource offers vital threat intelligence to bolster your Firewall and WAF instances,...
ipranges
@lord-alfred🔨 List all IP ranges from: Google (Cloud & GoogleBot), Bing (Bingbot), Amazon (AWS), Microsoft, Oracle (Cloud), GitHub, Facebook (Meta), OpenAI (GPTBot) and other with daily updates.
tpotce
@telekom-security🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
ivre
@ivreNetwork recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.
batfish
@batfishBatfish is a network configuration analysis tool that can find bugs and guarantee the correctness of (planned or current) network configurations. It enables network engineers to rapidly and safely evolve their network, without fear of outages or security breaches.
freeipa
@freeipaMirror of FreeIPA, an integrated security information management solution
Zephyr
@Juwan-HwangZephyr: A modern, lightweight, and secure Mihomo / Clash Meta GUI client built with Tauri and Rust.
refpolicy
@SELinuxProjectSELinux Reference Policy v2
sam
@googleSAM
gittuf
@gittufA security layer for Git repositories
cybersecurity-roadmap
@jassicsSkills and career roadmap for various security roles like application security, cloud security, DevSecOps, security engineer, security researchers, pentesting, api security, network security, mobile security and so on with helpful resources, guidelines
iDefender
@wecooperateiDefender - The Infinite Potential Host Intrusion Prevention System (HIPS) & Real-time Endpoint Detection and Response for Home
vortix
@Harry-kpTerminal UI for WireGuard and OpenVPN with real-time telemetry and leak guarding.
AdGuard-WireGuard-Unbound-DNScrypt
@trinibLinux ultimate self-hosted network security guide ║ Linux 终极自托管网络安全指南 ║ Guía definitiva de seguridad de red autohospedada de Linux ║ लिनक्स परम स्व-होस्टेड नेटवर्क सुरक्षा गाइड ║ Окончательное руководство по безопасности собственной сети Linux
pywarp
@saeedmasoudiePywarp is a powerful replacement for the official Cloudflare WARP app, offering an intuitive UI and extended options, including advanced DNS settings, custom endpoints, and support for change protocols like masque and WireGuard.
nest-access-control
@nestjsxRole and Attribute based Access Control for Nestjs 🔐
BrowserBox
@BrowserBox💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.
Above
@caster0x00Network Security Sniffer
zerotier-docker
@zycloniteZeroTier One as Docker Image
Malcolm
@cisagovMalcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
clawdhome
@ThinkInAIXYZClawdHome securely isolates and manages multiple OpenClaw gateway instances on one Mac.
amass
@owasp-amassIn-depth attack surface mapping and asset discovery
nucypher
@nucypherThreshold Access Control (TACo) Node Runtime
scirius
@StamusNetworksScirius is a web application for Suricata ruleset management and threat hunting.
Sara
@caster0x00MikroTik RouterOS Security Inspector
Network-segmentation-cheat-sheet
@sergiomarotcoBest practices for segmentation of the corporate network of any company
Hacking-Tools
@aw-junaidThis Repository is a collection of different ethical hacking tools and malware's for penetration testing and research purpose written in python, ruby, rust, c++, go and c.
esp-rfid
@esprfidESP8266 RFID (RC522, PN532, Wiegand, RDM6300) Access Control system featuring WebSocket, JSON, NTP Client, Javascript, SPIFFS
violent-python3
@EONRaiderSource code for the book "Violent Python" by TJ O'Connor. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards and refactored to eliminate dependency issues involving the implementation of deprecated libraries.
OpenDJ
@OpenIdentityPlatformOpenDJ is an open-source LDAP directory server written in Java. It provides robust, scalable, and secure directory services for identity management, access control, and authentication in enterprise environments. OpenDJ supports LDAPv3 standard, replication, REST APIs, and high-performance
anubis
@jonlucaSubdomain enumeration tool
p2panda
@p2pandaAll the things a panda needs
mercury
@ciscoMercury: network metadata capture and analysis
PoW-Shield
@RuiSiangProject dedicated to fight Layer 7 DDoS with proof of work, with an additional WAF and controller. Completed with full set of features and containerized for rapid and lightweight deployment.
enterprise-system-design
@DrHazemAliA source-grounded course and architectural reference for engineers designing systems that must survive real traffic, partial failure, security review, and changing requirements, spanning enterprise system design, distributed systems, AI systems, cybersecurity, reliability, cloud, HPC, edge, and mission-critical infrastructure.
H.Pipes
@HavenDVA simple, easy to use, strongly-typed, async wrapper around .NET named pipes.
AzureOpenAI-with-APIM
@microsoftDeploy APIM. Auto-configure it to work with your Azure Open AI.
ngx-permissions
@AlexKhymenkoPermission and roles based access control for your angular(angular 2,4,5,6,7,9+) applications(AOT, lazy modules compatible
pritunl-zero
@pritunlZero trust system
fhir-gateway
@ohs-foundationA generic proxy server for applying access-control policies for a FHIR-store.
onesixtyone
@trailofbitsFast SNMP Scanner
vigil
@Vigil-SOCVigil: The leading open source AI SOC. Apache 2.0. Runs against your own LLM, local or remote.
react-native-template-new-architecture
@leotmReact Native 0.88 ⚡ Hardened JS 🔒 LavaMoat 🌋 Ubuntu 26 🐧 Xcode 27 🍎 Hermes V1 ⚙️ Fiber / Fabric / Yoga 🏎️ Turbo / Nitro 💨 TS 7 ✅ Kotlin 2.2, JDK 25, NDK 27 🤖 Ruby 3.4 💎 Yarn 4 📦 ESLint 🧹 Prettier ✨ Babel 🗼 Hardened GHA + deps 🔒 Storybook 10 🚧 Node 22 ⬢ Buck2 🚧 Renovate 🛠️ Socket ⚡ for curious early adopters :suspect: #RNEU #APPJS
aws-gate
@xen0lBetter AWS SSM Session manager CLI client
bypass-firewalls-by-DNS-history
@vincentcoxFirewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters.
CaptfEncoder
@guyoungCaptfencoder is opensource a rapid cross platform network security tool suite, providing network security related code conversion, classical cryptography, cryptography, asymmetric encryption, miscellaneous tools, and aggregating all kinds of online tools.
yasuo
@0xsaubyA ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network
WinRing0
@GermanAizekWinRing0 is a hardware access library for Windows.
ESPKey
@octosavviWiegand data logger, replay device and micro door-controller
role_core
@rails-engine🔐A Rails engine providing essential industry of Role-based access control.
ESP-RFID-Tool
@rfidtoolA tool for logging data/testing devices with a Wiegand Interface. Can be used to create a portable RFID reader or installed directly into an existing installation. Provides access to a web based interface using WiFi in AP or Client mode. Will work with nearly all devices that contain a standard 5V Wiegand interface. Primary target group is 26-37bit HID Cards. Similar to the Tastic RFID Thief, Blekey, and ESPKey.
PSKracker
@andrewjlamarcheAn all-in-one WPA/WPS toolkit
fpnd
@freepnPython package for freepn network daemon
vue-quasar-admin
@wjkangVue 2.0 admin-dashboard based on Quasar-Framework
respounder
@codeexpressRespounder detects presence of responder in the network.
ZXRequestBlock
@SmileZXLee基于NSURLProtocol一句话实现iOS应用底层所有网络请求拦截(含网页ajax请求拦截【不支持WKWebView】)、一句话实现防抓包(使Thor,Charles,Burp等代理抓包方式全部失效,且即使开启了代理,也不影响App内部的正常请求)。包含http-dns解决方法,有效防止DNS劫持。用于分析http,https请求等
Digital-Forensics-Guide
@mikeroyalDigital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
zBang
@cyberarkzBang is a risk assessment tool that detects potential privileged account threats
blackhat-python3
@EONRaiderSource code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards and refactored to eliminate dependency issues involving the implementation of deprecated libraries.
lunasec
@lunasec-ioLunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
iMonitorSDK
@wecooperateThe world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发
FireKylin
@MountCloud🔥火麒麟-网络安全应急响应工具(系统痕迹采集)Cybersecurity emergency response tool.👍👍👍
awesome-zero-trust
@pomeriumA curated collection of awesome resources for the zero-trust security model.
qnsm
@iqiyiQNSM is network security monitoring framework based on DPDK.
3YAdmin
@wjkang基于react全家桶+antd构建的专注通用权限控制与表单的后台管理系统模板
chai
@DO-SAY-GOchai - Experience Zero Trust security with Chai! Convert and view documents as vivid images right in your browser. No mandatory downloads, no hassle—just pure, joyful security! 🌈