security-tools.md

July 15, 2021 · View on GitHub

Bookmarks tagged [security-tools]

www.codever.land/bookmarks/t/security-tools

Analyse des dépendances - Sécurisation du cycle de développement applicatif

https://blog.wescale.fr/2021/06/22/securisation-du-cycle-de-developpement-applicatif-analyse-des-dep...

La sécurité applicative est un enjeu qui doit être pris en compte dès la conception du projet, chaperonné tout au long du cycle de développement.


GitHub - Atomicorp/ossec-docker: Official OSSEC docker container

https://github.com/Atomicorp/ossec-docker

Official OSSEC docker container. Contribute to Atomicorp/ossec-docker development by creating an account on GitHub.


GitHub - Atomicorp/openvas-docker: A docker container for openvas

https://github.com/Atomicorp/openvas-docker

A docker container for openvas. Contribute to Atomicorp/openvas-docker development by creating an account on GitHub.


GitHub - Atomicorp/gvm: Greenbone Vulnerability Manager / Openvas packaging project

https://github.com/Atomicorp/gvm

Greenbone Vulnerability Manager / Openvas packaging project - Atomicorp/gvm


Threat Dragon home page

https://threatdragon.org/

Threat Dragon is a free, open-source threat modeling tool from OWASP. It can be used as a standalone desktop app for Windows and MacOS (Linux coming soon) or as a web application. The desktop app is g...


Falco home page

https://falco.org/

Falco, the cloud-native runtime security project, is the de facto Kubernetes threat detection engine


CyberChef home page

https://gchq.github.io/CyberChef/

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis


CSP Evaluator

https://csp-evaluator.withgoogle.com/

CSP Evaluator allows developers and security experts to check if a Content Security Policy (CSP) serves as a strong mitigation against cross-site scripting attacks. It assists with the process of revi...


BeEF - The Browser Exploitation Framework Project

https://beefproject.com/

BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.


HTTP Strict Transport Security Header Testing Tool

https://gf.dev/hsts-test

Check if your site is defending from cookie hijacking & protocol downgrade attack


CWE - Common Weakness Enumeration

https://cwe.mitre.org/index.html

CWE™ is a community-developed list of software and hardware weakness types. It serves as a common language, a measuring stick for security tools, and as a baseline for weakness identification, mitigat...


OWASP ZAP

https://www.zaproxy.org/

The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by a dedicated international team of volunteers. It can help you automatically find s...


mitmproxy - an interactive HTTPS proxy

https://mitmproxy.org/

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.


What do SAST, DAST, IAST and RASP mean to developers?

https://www.softwaresecured.com/what-do-sast-dast-iast-and-rasp-mean-to-developers/

It’s estimated that 90 percent of security incidents result from attackers exploiting known software bugs. Needless to say, squashing those bugs in the development phase of software could reduce the i...


arvancloud/libinjection-rs

https://github.com/arvancloud/libinjection-rs

Rust bindings for libinjection [](https://travis-ci.org/arvancloud/libinjec...


kpcyrd/badtouch

https://github.com/kpcyrd/badtouch

A scriptable network authentication cracker


kpcyrd/rshijack

https://github.com/kpcyrd/rshijack

A TCP connection hijacker, rust rewrite of shijack


kpcyrd/sniffglue

https://github.com/kpcyrd/sniffglue

A secure multithreaded packet sniffer


kpcyrd/sn0int

https://github.com/kpcyrd/sn0int

A semi-automatic OSINT framework and package manager


Gymmasssorla/anevicon

https://github.com/Gymmasssorla/anevicon

The most powerful UDP-based load generator, written in Rust


Gymmasssorla/finshir

https://github.com/Gymmasssorla/finshir

A coroutines-driven Low & Slow traffic generator, written in Rust