Highlights
- Pro
Stars
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
The Browser Exploitation Framework Project
Cloud replacement for vacuum robots enabling local-only operation
Arkime is an open source, large scale, full packet capturing, indexing, and database system.
OS X Auditor is a free Mac OS X computer forensics tool
Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.
A collection of my Frida.re instrumentation scripts to facilitate reverse engineering of mobile apps.
SimplE RePort wrIting and COllaboration tool
An open source threat modeling tool from OWASP
Sleepy Puppy XSS Payload Management Framework
A collection of ZAP scripts and tips provided by the community - pull requests very welcome!
BtleJuice Bluetooth Smart (LE) Man-in-the-Middle framework
mozilla / doctorjs
Forked from evilpie/jsctagsA set of static analysis tools for JavaScript
An agile, distributed, and secure alternative to the Certificate Authority system.
A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.
SPDY forwarding proxy - fast and secure
A desktop application that checks security-related settings and makes recommendations for improvements without requiring central device management or automated reporting.
Lair is a reactive attack collaboration framework and web application built with meteor.
Dashboard of Fail. A application to carve out images/accounts/vulns on conference networks and display them for general entertainment.
This is a legacy repo. Please find the maintained sal repo here: https://github.com/salopensource/sal
Duo two-factor authentication for PHP web applications
Command line utilities for analyzing CANbus traffic
Content-Security-Policy report aggregator/analyzer
CANBus protection used to isolate third party systems requiring OBDII access.
dimvar / doctorjs
Forked from evilpie/jsctagsA set of static analysis tools for JavaScript