web-security
Here are 544 public repositories matching this topic...
Language:All
Sort:Most stars
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
- Updated
Feb 5, 2025 - JavaScript
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
- Updated
Mar 14, 2025 - Go
Source code for Hacker101.com - a free online web and mobile security class.
- Updated
Feb 22, 2025 - SCSS
A list of resources for those interested in getting started in bug bounties
- Updated
Jul 23, 2024
🛡️ Open-source and next-generation Web Application Firewall (WAF)
- Updated
Mar 18, 2025 - Python
A list of web application security
- Updated
Dec 7, 2024
A curated list of various bug bounty tools
- Updated
Dec 30, 2024
Awesome Node.js Security resources
- Updated
Feb 26, 2025
DDos Ripper a Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic
- Updated
Jun 23, 2024 - Python
A container repository for my public web hacks!
- Updated
Oct 12, 2022 - JavaScript
JNDIExploit or a ysoserial.
- Updated
Mar 12, 2025 - Java
🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.
- Updated
Jan 15, 2025 - Python
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App:https://github.com/marketplace/lunatrace-by-lunasec/
- Updated
May 2, 2024 - TypeScript
A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.
- Updated
Nov 13, 2023 - Python
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
- Updated
Feb 17, 2025
Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.
- Updated
Oct 25, 2024 - Rust
Making Favicon.ico based Recon Great again !
- Updated
Aug 29, 2023 - Python
🎯 Fast CORS misconfiguration vulnerabilities scanner
- Updated
Nov 25, 2021 - Python
A Huge Learning Resources with Labs For Offensive Security Players
- Updated
Jul 13, 2022
Improve this page
Add a description, image, and links to theweb-security topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with theweb-security topic, visit your repo's landing page and select "manage topics."