freedomofpress / threat-modeling
experimental threat modeling tools
☆14Updated 2 years ago
Alternatives and similar repositories for threat-modeling:
Users that are interested in threat-modeling are comparing it to the libraries listed below
- Script to check ModSecurity rules agains some WAF☆12Updated 6 years ago
- Looks for GitHub org users without 2FA turned on☆9Updated 8 years ago
- A low/zero interaction ssh authentication logging honeypot☆21Updated 8 months ago
- A standard allowing organizations to nominate security contact points and policies via DNS TXT records.☆31Updated last month
- Extract, defang, resolve names and IPs from text☆23Updated last year
- go-audit is an alternative to the auditd daemon that ships with many distros☆16Updated 6 years ago
- tamper resistant audit log☆18Updated 6 years ago
- Shell utility to list colorfully show what processes are listening on what ports.☆19Updated 5 years ago
- A Java library for programmatically calculating OWASP Risk Rating scores☆18Updated 2 years ago
- Detect Phishing fetching Certificate Transparency Logs☆20Updated 4 years ago
- Register your Kubernetes IPs to monitor.shodan.io☆18Updated 2 years ago
- BeyondCorp-style federated access proxy☆48Updated last year
- CERTITUDE - A python package to classify malicious URLs☆20Updated 2 years ago
- Markdown Version of the DHS/CISA Secure Software Development Self Attestation Form.☆21Updated last year
- CVE Builder script that generates STIX formatted Exploit Target objects☆18Updated 8 years ago
- FSL Test bench - Ansible playbook repository to setup a save environment for security auditing and testing. It can be used for teaching s…☆29Updated 4 months ago
- D4 core software (server and sample sensor client)☆42Updated last year
- Policy Pipeline : place an SDLC around your compliance documentation with a pipeline that renders policy-as-code to human friendly format…☆11Updated 4 years ago
- Data exfiltration using covert channels in the TCP/IP protocol with some basic steganography.☆13Updated 8 years ago
- Deceptive tradecraft should be fun and light, not stern and stressful. It is cool to be cute.☆13Updated last year
- Wax is a mediocre fuzzer I'm prototyping to test some ideas and get rid of others.☆18Updated 6 years ago
- ☆33Updated 2 years ago
- The Auditree data gathering and reporting tool.☆13Updated 8 months ago
- 🛡 Monitor, analyze, & report security misconfigurations across environments.☆18Updated 7 years ago
- A tool for testing continuous integration (CI) or continuous delivery (CD) system security☆23Updated 11 years ago
- WebBorer is a directory-enumeration tool written in Go.☆44Updated 2 years ago
- Command line utility for parsing certificates☆63Updated 4 years ago
- PCC's aim is to provide a high performing offline tool to easily assess which users are vulnerable to Password Reuse Attacks (a.k.a. Pass…☆18Updated 5 years ago
- A gitbook for doing a null Bangalore session on linux container security to discuss and teach namespaces, cgroups etc.☆20Updated 7 years ago
- An example of a vulnerable slack bot that runs in AWS lambda.☆19Updated 7 years ago