Web-Check is an open-source, self-hostable OSINT dashboard for analysing any website. It gathers IP, DNS, SSL, headers, cookies, crawl rules, ports, traceroute, server location, redirects, trackers, performance and carbon footprint data.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONTrivy is a comprehensive security scanner used to detect vulnerabilities, misconfigurations, secrets, and SBOMs across various targets including containers, Kubernetes, and code repositories.
BitCurrents Log Analyzer is a lightweight single-page web application that turns raw Nginx access and error logs into actionable insights. Using the IP2Location API, it provides geolocation, intelligent bot detection, and bot impersonator flagging across three dashboard modes: General traffic overview, Security threat analysis, and Error diagnosis.
Infisical is an open-source platform for secrets management, certificate/PKI lifecycle, key management, and privileged access management. Features include a dashboard, CLI, SDKs and API, secret syncs and rotation, leak scanning, a Kubernetes operator, and self-hosting via Docker.
A curated list of open source tools for AWS security covering defensive hardening, offensive testing, auditing, DFIR, and more.
Fail2Ban is a daemon that scans log files and bans IPs with repeated authentication failures by updating firewall rules, supporting IPv6 and many services.
TurkeyBite is an open-source domain and host context analysis pipeline that analyzes client network traffic to categorize requested domains (e.g. adult content, gambling, shopping). It uses a Docker-based stack with Packetbeat/Browserbeat, Valkey, OpenSearch and Bind9, is non-intrusive (does not block client requests), and outputs analysis results to OpenSearch Dashboards or Syslog.
Anakrisis is an ethics-aware OSINT investigation planning and risk evaluation MCP server. It classifies investigations, scores risk against local YAML doctrine, flags prohibited actions, and scaffolds case documentation, supporting both cloud and local AI models.
Prowler is an open-source cloud security platform that automates security and compliance assessments across multiple cloud environments.
IPScout enriches IP addresses from 67 sources (cloud, CDN, threat feeds) via command line, providing threat ratings, caching, and configurable output formats.
A curated collection of 150+ tools and techniques for red teaming and penetration testing, organized by MITRE ATT&CK framework categories covering reconnaissance, initial access, execution, privilege escalation, defense evasion, credential access, lateral movement, command and control, exfiltration, and impact.