Category: Defense

pwnspoof

pwnspoof: generates realistic spoofed log files

pwnspoof pwnSpoof (from Punk Security) generates realistic spoofed log files for common web servers with customisable attack scenarios. Every log bundle is unique and completely customisable, making it perfect for generating CTF scenarios and for...

web application weakness monitoring

cumulus v0.0.2 releases: web application weakness monitoring

What’s Cumulus Cumulus is a service that helps you monitor and fix security weaknesses in real-time. The issues will be reported on a web dashboard. It’s very simple and powerful. Key features Just install...

Firezone firewall

Firezone v0.7.35 releases: WireGuard-based VPN server and firewall

firezone A self-managed WireGuard-based VPN server and Linux firewall designed for simplicity and security. Features Fast: Uses WireGuard to be 3-4 times faster than OpenVPN. No dependencies: All dependencies are bundled thanks to Chef Omnibus. Simple: Takes minutes to set up....

SysFlow Telemetry Pipeline

SysFlow: Cloud-native system telemetry pipeline

SysFlow? The SysFlow Telemetry Pipeline is a framework for monitoring cloud workloads and for creating performance and security analytics. The goal of this project is to build all the plumbing required for system telemetry...

Prevent SSRF attacks

metabadger v0.1.11 releases: Prevent SSRF attacks on AWS EC2

Metabadger Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2). Metabadger Purpose and functionality Diagnose and evaluate your current usage of the AWS Instance Metadata...

Kodex 

kodex: open-source toolkit for privacy and security engineering

Kodex (Community Edition – CE) is an open-source toolkit for privacy and security engineering. It helps you to automate data security and data protection measures in your data engineering workflows. It offers the following functionality: Read...

network data analytics framework

nfstream v6.5.3 releases: Flexible Network Data Analytics Framework

NFStream NFStream is a Python framework providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real-world network...

DDoS security assessment tool

epiphany: pre-DDoS security assessment tool

Epiphany Epiphany – is a pre-engagement \ self-assessment tool to identify weak spots of a web property from a DDoS attacker perspective. In the first stage, the tool crawls pages, enumerates POST and GET...

REW-sploit v0.5.1 releases: Dissecting Metasploit Attacks

REW-sploit Need help in analyzing Windows shellcode or attack coming from Metasploit Framework or Cobalt Strike (or maybe also other malicious or obfuscated code)? Do you need to automate tasks with simple scripting? Do you want help...

MAC security audit

lockc: eBPF-based MAC security audit for container workloads

lockc lockc is open source software for providing MAC (Mandatory Access Control) type of security audit for container workloads. The main technology behind lockc is eBPF – to be more precise, its ability to attach to LSM...