-
Updated
May 18, 2022 - Shell
#
auditing
Here are 247 public repositories matching this topic...
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
linux
shell
auditing
devops
unix
security-audit
pci-dss
compliance
hardening
security-vulnerability
security-hardening
devops-tools
hipaa
vulnerability-detection
vulnerability-scanners
security-scanner
vulnerability-assessment
gdpr
security-tools
system-hardening
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
security
auditing
cloud
aws-lambda
incident-response
iam
dfir
cloudtrail
aws-infrastructure
security-tools
aws-inventory
-
Updated
May 30, 2022 - Shell
本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。
-
Updated
Apr 10, 2020 - Python
Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings. #nsacyber
windows
auditing
certificates
chrome-browser
audit
windows-10
windows-server
compliance
nessus
group-policy
applocker
internet-explorer
windows-firewall
microsoft-office
windows-server-2016
adobe-reader
-
Updated
Sep 12, 2018 - HTML
The missing reverse proxy for ssh scp
ssh
golang
bastion
auditing
reverse-proxy
scp
google-authenticator
two-factor-authentication
ssh-connection
azuread
bastion-server
-
Updated
May 14, 2022 - Go
A Django app that keeps a log of changes made to an object.
-
Updated
May 31, 2022 - Python
woodruffw
commented
Jan 27, 2020
.well-known (RFC) is becoming an increasingly popular destination for stashing site-wide metadata. Some of that metadata is relevant to site security or may unintentionally leak information, so we should scan it.
Some starting points:
- Presence of/interesting things in an MTA-STS policy (RFC)
- This might be
enhancement
New feature or request
help wanted
Extra attention is needed
good first issue
Good for newcomers
Open
WAF detection
7
The best way to scan for weak ssh passwords on your network
-
Updated
Apr 22, 2022 - Go
Yet another Django audit log app, hopefully the simplest one.
-
Updated
May 25, 2022 - Python
Open source security auditing tool to search and dump system configuration. It allows you to generate reports in HTML or RAW-HTML formats.
linux
auditing
security-audit
system
reporting
cybersecurity
system-information
dump
pentesting
html-report
system-config
information-gathering
security-tools
system-analysis
-
Updated
Mar 24, 2020 - Shell
Rudder is a configuration and security automation platform. Manage your Cloud, hybrid or on-premises infrastructure in a simple, scalable and dynamic way.
auditing
devops
automation
configuration-management
compliance
continuous-configuration
continous-auditing
-
Updated
Jun 2, 2022 - Scala
Find interesting and potentially hazardous commits in git projects
rails
docker
auditing
database
watch
regular-expression
security-vulnerability
rds
email-notification
favor
-
Updated
Sep 6, 2018 - Ruby
Modern alternative to dirbuster/dirb
security
auditing
dictionaries
dictionary
thread
bruteforce
enumeration
pentest
hacktoberfest
dirbuster
dirb
bruteforce-wordlist
url-bruteforcer
web-content-scanner
-
Updated
Jun 1, 2022 - Go
A simple auditing utility for macOS
-
Updated
Mar 20, 2021 - C
Penetration testing and auditing toolkit for Android apps.
-
Updated
Jun 25, 2020 - Java
Tracker-enabled DbContext offers you to implement full auditing in your database
-
Updated
Mar 29, 2021 - C#
Wordpress Vulnerability Scanner
-
Updated
Mar 29, 2016 - PHP
This repository is created only for infosec professionals whom work day to day basis to equip ourself with uptodate skillset, We can daily contribute daily one hour for day to day tasks and work on problem statements daily, Please contribute by providing problem statements and solutions
auditing
osint
incident-response
forensics
steganography
pentesting
compliance
malware-analysis
information-security
blueteam
redteam
-
Updated
May 17, 2022 - HTML
Python implementation of Benford's Law tests.
python
auditing
research
numpy
accounting
pandas
python3
matplotlib
compliance
financial-analysis
digit
fraud-detection
benford
benfords-law
benford-compliant
simon-newcomb
-
Updated
Aug 14, 2021 - Jupyter Notebook
Extensions, Auditing, Concurrency Checks, JSON properties and Transaction Logs for EntityFramework and EFCore
auditing
json
entity-framework
specification
specification-pattern
ef6
efcore
entityframework
entity-framework-core
extension-methods
ef-core
change-tracker
entityframeworkcore
transaction-log
complex-types
concurrency-checks
-
Updated
Jul 26, 2019 - C#
GCP CIS 1.1.0 Benchmark InSpec Profile
-
Updated
May 20, 2022 - Ruby
-
Updated
Nov 3, 2021 - Python
Improve this page
Add a description, image, and links to the auditing topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the auditing topic, visit your repo's landing page and select "manage topics."


The https://github.com/nccgroup/ScoutSuite/blob/master/ScoutSuite/providers/gcp/rules/findings/iam-lack-of-service-account-key-rotation.json finding should only flag
USER_MANAGEDkeys (https://cloud.google.com/iam/docs/reference/rest/v1/projects.serviceAccounts.keys), asSYSTEM_MANAGEDkeys are "managed and rotated by Google"