Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
-
Updated
Aug 19, 2025 - Shell
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
grep rough audit - source code auditing tool
Wazuh - Docker containers
Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and vulnerability assessments too.
EternalView is an all in one basic information gathering and vulnerability assessment tool
Wazuh - Tools for packages creation
ScanPro - NMap Scanning Scripts ~ Network Mapper
fsp - Firestore Database Vulnerability Scanner Using APKs
Wazuh - Amazon AWS Cloudformation
Gixposed is a powerful command-line tool designed to search the commit history of Git repositories for sensitive information, such as API keys and access tokens. Its purpose is to help developers and security professionals quickly identify and remediate exposed sensitive informations in their codebases.
A collection of awesome security hardening software, libraries, learning tutorials & documents, e-books, best practices, checklists, benchmarks about hardening in Cybersecurity
An Automated Mass Network Vulnerability Scanner and Recon Tool
Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be vulnerable, and this script aids in detecting them and optionally downgrading to a stable, un-compromised version (5.4.6) or upgrading to latest version. Added Ansible Playbook
A complete security assessment tool that supports common web security issues scanning and custom POC | Be sure to read the document before using.
🐍📊 Jenkins-based DevSecOps pipeline for Python3 web applications (SAST, DAST, SCA).
Official OSSEC docker container
CVE-2024-6387 Checker is a fast, efficient tool for detecting OpenSSH servers vulnerable to the regreSSHion exploit. It quickly scans multiple IPs, domain names, and CIDR ranges to identify risks and help secure your infrastructure.
Wazuh - Release for Bosh.io
SADA Webapplication Scanner
Automatic script for subdomain enumeration and vulnerability scanning using Acunetix API.
Add a description, image, and links to the vulnerability-detection topic page so that developers can more easily learn about it.
To associate your repository with the vulnerability-detection topic, visit your repo's landing page and select "manage topics."