Zero-trust-beveiliging
154 projecten in Beveiliging & identiteit
Hasura
@hasuraFast, instant realtime GraphQL APIs on Postgres with fine grained access control, also trigger webhooks on database events.
Pi.Alert
@leiweibauScan the devices connected to your WIFI / LAN and alert you the connection of unknown devices. It also warns if a "always connected" device disconnects. In addition, it is possible to check web services for availability. For this purpose HTTP status codes and the response time of the service are evaluated.
scapy
@secdevScapy: the Python-based interactive packet manipulation program & library.
ScaleTail
@tailscale-devTailscale Sidecar Configurations for Docker
Firezone
@firezoneSecure remote access gateway that supports the WireGuard protocol. It offers a Web GUI, 1-line install script, multi-factor auth (MFA), and SSO.
AppInfoScanner
@kelvinBen一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
OpenZiti
@openzitiFully-featured, zero trust, full mesh overlay network. Includes a 2FA support out of the box, clients for all major desktop/mobile OS'es.
opennhp
@OpenNHPA lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the AI-driven world.
Smap
@s0md3va drop-in replacement for Nmap powered by shodan.io
next-terminal
@next-terminalA simple, secure, easy-to-use bastion and session auditing system. Supports RDP, SSH, VNC, Telnet, HTTP, records and replays sessions for auditing and compliance.
Aether
@CluvexStudioA Rust userspace WARP core for censored networks, built around MASQUE over HTTP/3 and HTTP/2.
Data-Shield_IPv4_Blocklist
@duggytuxyData-Shield IPv4 Blocklist Community provides an official, curated registry of IPv4 addresses identified as malicious. Updated continuously, this resource offers vital threat intelligence to bolster your Firewall and WAF instances,...
Bjorn
@infinitionBjorn is a powerful network scanning and offensive security tool for the Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers network targets, identifies open ports, exposed services, and potential vulnerabilities. Bjorn can perform brute force attacks, file stealing, host zombification, and supports custom attack scripts.
zrok
@openzitiSecure internet sharing made simple.
harden-runner
@step-securityHarden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
agent-governance-toolkit
@microsoftAI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Boundary
@hashicorpBoundary enables identity-based access management for dynamic infrastructure.
networking-toolbox
@lissy93🛜 100+ offline-first networking tools and utilities
MicroWARP
@ccbkkb🚀 An 800KB RAM ultra-lightweight Cloudflare WARP SOCKS5 proxy in Docker. 仅需 800KB 内存的纯内核态 Cloudflare WARP 代理 - Docker
nono
@nolabs-aiagent runtime security - zero trust, zero setup, zero latency.
DockFlare
@ChrispyBacon-devDockFlare: Automate Cloudflare Tunnels with Docker Labels
ipranges
@lord-alfred🔨 List all IP ranges from: Google (Cloud & GoogleBot), Bing (Bingbot), Amazon (AWS), Microsoft, Oracle (Cloud), GitHub, Facebook (Meta), OpenAI (GPTBot) and other with daily updates.
refpolicy
@SELinuxProjectSELinux Reference Policy v2
brook
@txthinkingA cross-platform programmable network tool
iDefender
@wecooperateiDefender - The Infinite Potential Host Intrusion Prevention System (HIPS) & Real-time Endpoint Detection and Response for Home
fapolicyd
@linux-application-whitelistingFile Access Policy Daemon
gittuf
@gittufA security layer for Git repositories
ivre
@ivreNetwork recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.
sam
@googleSAM
lantunnel
@lantunnelYour private network, wherever you work. Peer-to-peer first, end-to-end encrypted access to your own LANs — no port forwarding, no public URLs.
pywarp
@saeedmasoudiePywarp is a powerful replacement for the official Cloudflare WARP app, offering an intuitive UI and extended options, including advanced DNS settings, custom endpoints, and support for change protocols like masque and WireGuard.
netbird
@netbirdioConnect your devices, users, and agents into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.
batfish
@batfishBatfish is a network configuration analysis tool that can find bugs and guarantee the correctness of (planned or current) network configurations. It enables network engineers to rapidly and safely evolve their network, without fear of outages or security breaches.
tpotce
@telekom-security🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
huginn-net
@biandrattiMulti-protocol passive fingerprinting library: TCP/HTTP (p0f-style) + TLS (JA4-style) analysis in Rust
zerotier-docker
@zycloniteZeroTier One as Docker Image
Wireshark-MCP
@bx33661Wireshark-MCP,Give your AI assistant a packet analyzer. Drop a .pcap file, ask questions in plain English — get answers backed by real tshark data.
nassh-relay
@zycloniteRelay Server for the Secure Shell Chromium plugin
llm-gateway
@openzitiZero trust LLM gateway. OpenAI-compatible proxy with semantic routing and load balancing across OpenAI, Anthropic, Ollama, vLLM, and any compatible backend. Identity-based access, virtual API keys, and end-to-end encryption via OpenZiti
lan-file-transfer
@NextWeb4Local LAN file transfer desktop app with user/group permissions and audit logs.
DriveLite
@DriveLiteDriveLite: The Supabase for File Storage. A modular, self-hostable backend with end-to-end encryption.
nest-access-control
@nestjsxRole and Attribute based Access Control for Nestjs 🔐
Sara
@caster0x00MikroTik RouterOS Security Inspector
warden
@stephnangueThe secure gateway connecting AI agents to enterprise systems.
LingFrame
@LingFrameLingFrame: A JVM Runtime Security Governance Solution for Long-Running Systems. It implements modular isolation and zero-trust permission control to deliver automatic method-level full-link tracing, security auditing, and zero-downtime canary releases.
Above
@caster0x00Network Security Sniffer
sigwood
@helixmapLocal-first threat hunting for the logs you already have: Zeek, Pi-hole, syslog or the systemd journal, CloudTrail. Every run names the technique behind each detector. No agent, no daemon, no black box - between grep and a SIEM.
zerotrust-your-home
@lucadibello🔐 Securing Your Digital Sanctuary, Trust None, Protect Everything.
gonids
@googlegonids is a library to parse IDS rules, with a focus primarily on Suricata rule compatibility. There is a discussion forum available that you can join on Google Groups: https://groups.google.com/forum/#!topic/gonids/
hass-unifi-access
@imhotepUnifi Access Integration for Home Assistant
netpwn
@Andromeda1957Tool made to automate tasks of pentesting.
sdk-golang
@openzitiZiti SDK for Golang
PyPCAPKit
@JarryShawPython-based Comprehensive Network Packet Analysis Library
onioncat
@rahraOfficial repository of OnionCat, the VPN adapter for Tor and I2P.
exograph
@exographBuild production-ready backends in minutes
nucypher
@nucypherThreshold Access Control (TACo) Node Runtime
scirius
@StamusNetworksScirius is a web application for Suricata ruleset management and threat hunting.
BrowserBox
@BrowserBox💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.
pydivert
@ffalcinelliA Python binding for WinDivert driver
netchecks
@hardbyteTool to validate assumptions about the network
Malcolm
@cisagovMalcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
puresnitch
@momenbaselFree, open-source application firewall for macOS. Little Snitch alternative with zero telemetry. Native SwiftUI world map, rules manager, DNS over HTTPS, pf-based blocking. Signed, notarized, MIT licensed.
usque-app
@GeorgeXie2333User-friendly cross-platform GUI for Cloudflare WARP client's MASQUE protocol.
advanced-policy-firewall
@rfxniptables/netfilter firewall for Linux servers with stateful filtering, trust system, ipset block lists, SYN flood protection, VNET per-IP policies, and Docker support
couper
@coupergatewayCouper is a lightweight API gateway designed to support developers in building and operating API-driven Web projects
ziti-sdk-c
@openzitiA C-based sdk for delivering secure applications over a Ziti Network
p2panda
@p2pandaAll the things a panda needs
ai-playground
@tuhinsharma121I put all my exploration around AI in reproducible notebooks in this repository
ziti-sdk-py
@openzitiZiti SDK for Python
OpenDJ
@OpenIdentityPlatformOpenDJ is an open-source LDAP directory server written in Java. It provides robust, scalable, and secure directory services for identity management, access control, and authentication in enterprise environments. OpenDJ supports LDAPv3 standard, replication, REST APIs, and high-performance
PoW-Shield
@RuiSiangProject dedicated to fight Layer 7 DDoS with proof of work, with an additional WAF and controller. Completed with full set of features and containerized for rapid and lightweight deployment.
traefik-tunnel-expose
@zenkietExposing internal services securely via Traefik Proxy & Cloudflare Tunnel
Network-segmentation-cheat-sheet
@sergiomarotcoBest practices for segmentation of the corporate network of any company
violent-python3
@EONRaiderSource code for the book "Violent Python" by TJ O'Connor. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards and refactored to eliminate dependency issues involving the implementation of deprecated libraries.
H.Pipes
@HavenDVA simple, easy to use, strongly-typed, async wrapper around .NET named pipes.
amass
@owasp-amassIn-depth attack surface mapping and asset discovery
esp-rfid
@esprfidESP8266 RFID (RC522, PN532, Wiegand, RDM6300) Access Control system featuring WebSocket, JSON, NTP Client, Javascript, SPIFFS
enterprise-system-design
@DrHazemAliA source-grounded course and architectural reference for engineers designing systems that must survive real traffic, partial failure, security review, and changing requirements, spanning enterprise system design, distributed systems, AI systems, cybersecurity, reliability, cloud, HPC, edge, and mission-critical infrastructure.
mercury
@ciscoMercury: network metadata capture and analysis
user-rbac
@SamAthanasUser based access control middleware component for Home Assistant
anubis
@jonlucaSubdomain enumeration tool
masscanned
@ivreLet's be scanned. A low-interaction honeypot focused on network scanners and bots. It integrates very well with IVRE to build a self-hosted alternative to GreyNoise.
mcp-trust-plane
@abluvaComposable data security plane for Model Context Protocol. Pluggable layers — collect, analyze, guard — across 50+ enterprise providers. Open architecture.
pritunl-zero
@pritunlZero trust system
access-control
@leosacLeosac Access Control - Open Source Physical Access Control System
asset-intel-orchestration-engine
@Kronova-Intelligent-SystemsOpen-source platform for multi-agent AI orchestration, real-world asset tokenization, workflow automation. Includes OAuth 2.1 MCP agent management, a 44-field RWA schema, Stripe, designed to integrate with AetherNet QUAS & KVS sovereign, post quantum, architecture agnostic omni-substrate, semantic memory, & institutional settlement system.
Network-Covert-Channels-A-University-level-Course
@cdpxeA free online class on network information hiding/steganography/covert channels.
ngx-permissions
@AlexKhymenkoPermission and roles based access control for your angular(angular 2,4,5,6,7,9+) applications(AOT, lazy modules compatible
react-native-template-new-architecture
@leotmReact Native 0.88 ⚡ Hardened JS 🔒 LavaMoat 🌋 Ubuntu 26 🐧 Xcode 27 🍎 Hermes V1 ⚙️ Fiber / Fabric / Yoga 🏎️ Turbo / Nitro 💨 TS 7 ✅ Kotlin 2.2, JDK 25, NDK 27 🤖 Ruby 3.4 💎 Yarn 4 📦 ESLint 🧹 Prettier ✨ Babel 🗼 Hardened GHA + deps 🔒 Storybook 10 🚧 Node 22 ⬢ Buck2 🚧 Renovate 🛠️ Socket ⚡ for curious early adopters :suspect: #RNEU #APPJS
beyond
@presbreyBeyondCorp-inspired HTTPS/SSO Access Proxy. Secure internal services outside your VPN/perimeter network during a zero-trust transition.
ika
@dwallet-labsIka is the fastest zero-trust MPC network. Its 2PC-MPC protocol powers dWallets: programmable signing mechanisms that let smart contracts natively control assets on any chain (Bitcoin, Ethereum, Solana, and more) with no bridging or wrapping. Live beta on Sui; pre-alpha for builders on Solana.
WatchYourPorts
@acebergOpen ports inventory for local servers. Exports data to InfluxDB2/Grafana
onesixtyone
@trailofbitsFast SNMP Scanner
Python_for_Network_Engineers
@network-evolutionThis repo contains Scripts which are explained in the youtube Channel https://www.youtube.com/c/NetworkEvolution/videos?sub_confirmation=1
CloudFlareAssistant
@a422015028Manage Cloudflare from your Android phone — deploy Workers, build Pages (no CI/CD), edit DNS, query D1, browse R2. Built-in code editor, multi-account, offline-first. Kotlin · MVVM · Material 3.
react-abac
@rikhoffbauerAttribute Based Access Control for React
accesscontroltool
@NetcentricRights and roles management for AEM made easy
AzureOpenAI-with-APIM
@microsoftDeploy APIM. Auto-configure it to work with your Azure Open AI.
recht
@dasherswA concise rule engine to express and enforce rules for selections, permissions and the like
react-secure-state
@ibeizhuReact Secure State
fhir-gateway
@ohs-foundationA generic proxy server for applying access-control policies for a FHIR-store.
TheTick
@jkramarzThe Tick is the next evolution in covert access control system implants for simulating adversary-in-the-middle attacks.
AISecOps
@cybermaxluo📚【更新中】AISecOps: AI-Driven Enterprise Security|AI 驱动的安全体系。一套将 AI 能力嵌入企业安全体系的方法论框架,以及支撑它落地的完整工程实践——从安全架构、GRC、云原生、数据隐私到 SOC 运营、身份治理与 AI 系统安全。开源中文技术专著,CC BY-NC-SA 4.0。/*⚡🌊🛡️*/
bit-sender
@jarbozhangCross-platform network packet crafting, sending & capturing — Rust + Tauri, type-safe protocol builders with real checksums.
OpenIDM
@OpenIdentityPlatformOpenIDM is an open-source identity management solution that automates user provisioning, synchronization, and lifecycle management. It supports integration with diverse systems, enabling secure, centralized control over user identities and access.
Preferred-Network-List-Sniffer
@AleksaMCodeA reconnaissance tool for capturing and displaying SSIDs from device's Preferred Network List.
ufw-blocklist
@poddmoIP blocklist extension for Ubuntu ufw firewall
bypass-firewalls-by-DNS-history
@vincentcoxFirewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters.
lists.d
@greyhat-academyList of useful things
policy-machine-core
@usnistgovCore components of the Policy Machine, a NGAC reference implementation.
role_core
@rails-engine🔐A Rails engine providing essential industry of Role-based access control.
ESPKey
@octosavviWiegand data logger, replay device and micro door-controller
CaptfEncoder
@guyoungCaptfencoder is opensource a rapid cross platform network security tool suite, providing network security related code conversion, classical cryptography, cryptography, asymmetric encryption, miscellaneous tools, and aggregating all kinds of online tools.
WinRing0
@GermanAizekWinRing0 is a hardware access library for Windows.
PSKracker
@andrewjlamarcheAn all-in-one WPA/WPS toolkit
scanme
@CyberRouteA Golang package for scanning private and public IPs for open TCP ports 👁️
fpnd
@freepnPython package for freepn network daemon
matrix
@mypdnsMy Privacy DNS #Matrix lists for blacklisting
ESP-RFID-Tool
@rfidtoolA tool for logging data/testing devices with a Wiegand Interface. Can be used to create a portable RFID reader or installed directly into an existing installation. Provides access to a web based interface using WiFi in AP or Client mode. Will work with nearly all devices that contain a standard 5V Wiegand interface. Primary target group is 26-37bit HID Cards. Similar to the Tastic RFID Thief, Blekey, and ESPKey.
discord-oidc-worker
@ErisaSign into Discord on Cloudflare Access, powered by Cloudflare Workers!
Aroma
@Sakura-sxEvery TCP Proxy Is Detectable With RTT Fingerprinting
respounder
@codeexpressRespounder detects presence of responder in the network.
vue-quasar-admin
@wjkangVue 2.0 admin-dashboard based on Quasar-Framework
meshnet
@Safe3一款社区驱动的高速、稳定、安全的内网穿透、网络隔离、P2P传输、零信任网络ZTNA、堡垒机、异地组网SD-WAN,打破传统网络边界的Mesh网格网络安全产品。
nsec3map
@anonion0a tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain
payload-tools
@teunmooijCollection of payload plugins and tools: payload-openapi, payload-swagger, create-payload-api-docs, payload-rbac
ZXRequestBlock
@SmileZXLee基于NSURLProtocol一句话实现iOS应用底层所有网络请求拦截(含网页ajax请求拦截【不支持WKWebView】)、一句话实现防抓包(使Thor,Charles,Burp等代理抓包方式全部失效,且即使开启了代理,也不影响App内部的正常请求)。包含http-dns解决方法,有效防止DNS劫持。用于分析http,https请求等
zBang
@cyberarkzBang is a risk assessment tool that detects potential privileged account threats
sandworm-guard-js
@sandworm-hqEasy auditing & sandboxing for your JavaScript dependencies 🪱
license-gate
@DevLeokoLicense and API key management tool and validation API for developers
AIVPN
@stratosphereipsThe AI VPN provides an security assessment of VPN clients' network traffic to identify cyber security threats.
laravel-surveillance
@neelkanthkPut malicious users, IP addresses and anonymous browser fingerprints under surveillance, log the URLs they visit and block malicious ones from accessing the Laravel app.
go-role
@PermifyOpen source RBAC library. Associate users with roles and permissions.
MirageServer
@MirageNetwork蜃境:基于Headscale修改的带WebUI开源版本Tailscale控制器
fastapi-authz
@pycasbinUse Casbin in FastAPI, Casbin is a powerful and efficient open-source access control library.
community-id-spec
@corelightAn open standard for hashing network flows into identifiers, a.k.a "Community IDs".
Fortigate-Firewall-Complete-Guide
@hegdepavankumarFortiGate is the world's most deployed network firewall, delivering networking and security capabilities in a single platform, managed by FortiGate Cloud.Master the art of Fortigate Firewall with our free comprehensive guide on GitHub! From interface configurations to advanced VPN setups, this repository covers it all.
RealIP
@TCPShieldThe Spigot, Bungee and Velocity plugin that parses client IP addresses passed from the TCPShield network.
TrafficWatch
@HalilDenizTrafficWatch, a packet sniffer tool, allows you to monitor and analyze network traffic from PCAP files
netsec-ps-scripts
@thom-sCollection of PowerShell network security scripts for system administrators.
what-vpn
@dlenskiIdentify servers running various SSL VPNs based on protocol-specific behaviors
Iptables_Semantics
@diekmannVerified iptables Firewall Ruleset Analysis
blackhat-python3
@EONRaiderSource code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards and refactored to eliminate dependency issues involving the implementation of deprecated libraries.
NetDeflect
@0vmEasy to use DDoS mitigation with real-time traffic analysis, automatic attack pattern detection, IP blocking via iptables/blackhole routing, and Discord alerts. Detects and mitigates network floods, reflection attacks, and protocol abuse.
complete-networking-guide-osi-tcpip-subnetting-security
@MaheshShukla1This repository covers computer networking fundamentals and advanced concepts including the OSI model, TCP/IP protocols, IP addressing & subnetting, NAT, VPNs, firewalls, IDS/IPS, network redundancy, and wireless security. Perfect for students, IT professionals, and certification candidates (CCNA, CompTIA Network+, AWS Networking, and Security+).
Project-Tauro
@k0r0ptA Router WiFi key recovery/cracking tool with a twist.
ethical-hacking-tools-python
@x4nth055Python programs & tools built in the Ethical Hacking with Python EBook
lunasec
@lunasec-ioLunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
FireKylin
@MountCloud🔥火麒麟-网络安全应急响应工具(系统痕迹采集)Cybersecurity emergency response tool.👍👍👍
awesome-zero-trust
@pomeriumA curated collection of awesome resources for the zero-trust security model.
leaks
@xanwzCompromised SSH servers and scraped mirror sites leaked scripts intended for malicious use.
qnsm
@iqiyiQNSM is network security monitoring framework based on DPDK.
3YAdmin
@wjkang基于react全家桶+antd构建的专注通用权限控制与表单的后台管理系统模板
chai
@DO-SAY-GOchai - Experience Zero Trust security with Chai! Convert and view documents as vivid images right in your browser. No mandatory downloads, no hassle—just pure, joyful security! 🌈