-
cargo-auditable
Make production Rust binaries auditable
-
rustsec
Client library for the RustSec security advisory database
-
zizmor
Static analysis for GitHub Actions
-
cargo-vet
Supply-chain security for Rust
-
clamav-client
ClamAV client library with optional support for async-std, smol, and Tokio
-
nyx-scanner
A CLI security scanner for automating vulnerability checks
-
cosmian_kmip
Cosmian KMIP library
-
dz6
A vim-inspired, TUI-based hexadecimal editor
-
rustdllproxy
ease the development of proxy DLLs in Rust
-
walker-common
Common functionality for SBOM and CSAF walker
-
periodic-audit
run cargo-audit periodically and send email reports
-
gigacode
Sandbox Agent CLI with OpenCode attach by default
-
polycvss
CVSS v2, v3, and v4 vector string parser and score calculator
-
sbom-tools
Semantic SBOM diff and analysis tool
-
ureld
& fast URLs de-cluttering tool written in Rust
-
idalib
Idiomatic bindings to IDA SDK
-
dinvk
Dynamically invoke arbitrary code in Rust (Dinvoke)
-
ghidra-version-manager
Ghidra Version Manager
-
libscemu
x86 32/64bits and system internals emulator, for securely emulating malware and other stuff
-
cargo-ddd
A cargo subcommand for inspecting what changes brings dependency version update into your project
-
stealth-scanner
A Solidity security scanner that detects common vulnerabilities through static analysis with intelligent pattern recognition
-
cargo-crev
Distibuted Code REView system for verifying security and quality of Cargo dependencies
-
pyscan
python dependency vulnerability scanner
-
endpoint-sec
High-level Rust wrappers around the Endpoint Security Framework
-
auditable-extract
Extract the dependency trees embedded in binaries by
cargo auditable -
aws-sdk-codegurusecurity
AWS SDK for Amazon CodeGuru Security
-
aws-sdk-inspector2
AWS SDK for Inspector2
-
hakoniwa
Process isolation for Linux using namespaces, resource limits, cgroups, landlock and seccomp
-
rhabdomancer
Vulnerability research assistant that locates calls to potentially insecure API functions in a binary file
-
cve-data
Request CVE data from different sources
-
frida-build
Rust bindings for Frida
-
lazynmap
A TUI for interactively generating nmap commands
-
process_hollowing
Creates a process and overwrites the entry point with shellcode (default to a reverse shell on localhost:4444)
-
attestation-validator
Validates attestation certificate chains and inspects attestation certificates
-
get-cve
Tools for CVE managing, exploring and collect some data about their weaknesses and classifications
-
dearxan
Static analyzer and patcher for the Arxan anti-debug/DRM as found in FromSoftware titles
-
osv
parsing the OSV schema and client API
-
injectum
The modern, type-safe process injection framework for Red Teams and Offensive Security in Rust
-
cosmian_kms_interfaces
exposing APIs for plugins to the Cosmian KMS
-
hipcheck
Automatically assess and score software packages for supply chain risk
-
virustotal-rs
Rust SDK for VirusTotal API v3
-
cargo-sbom
Create software bill of materials (SBOM) for Rust
-
codemode-rs
A secure V8 JavaScript sandbox with MCP (Model Context Protocol) tool integration
-
rma-indexer
Tantivy/Sled based indexing for Qryon
-
secure-types
Secure data types that protect sensitive data in memory via locking and zeroization
-
frida
Rust bindings for Frida
-
ntoseye
Windows kernel debugger for Linux hosts running Windows under KVM/QEMU
-
firewall_audit
Cross-platform firewall audit tool (YAML/JSON rules, CSV/HTML/JSON export)
-
dmg-cracker
performing dictionary attacks on encrypted DMG images on OSX
-
rattler_sandbox
run executables in a sandbox
-
cvssrust
Common Vulnerability Scoring System (v2 / v3.0 / v3.1)
-
spotspoof-cli
Domain spoofing & IDN/Punycode detection for security automation workflows
-
project-absence
👁️ Uncover the unseen
-
mewt
Mutation testing framework with multi-language support
-
crevette
Converter for using cargo-crev reviews with cargo-vet
-
symbi-dsl
Symbi DSL - AI-native programming language with Tree-sitter integration
-
skeld
a TUI tool for opening projects inside a restricted sandbox
-
security-mcp
MCP (Model Context Protocol) server providing security screening, injection detection, and threat analysis
-
birdcage
Cross-platform embeddable sandbox
-
drupal_cracker
This project is a very basic password cracker that cracks Drupal 7, 8, 9, 10, and 11 password hashes from a dictionary of passwords
-
cargo-audit
Audit Cargo.lock for crates with security vulnerabilities
-
hash-hunter
Find files with specified hashes
-
llm-security
Comprehensive LLM security layer to prevent prompt injection and manipulation attacks
-
miss-demeanor
Fast, parallel, pluggable process compliance checker
-
process_migration
Overwrites a running process' next instruction(s) with shellcode (default to a reverse shell on localhost:4444)
-
floss-cli
在 Rust 中以子进程方式调用 FLARE FLOSS CLI,并可选解析 -j JSON 输出
-
ocsf-types
Strongly typed Rust structs for the OCSF (Open Cybersecurity Schema Framework)
-
subhunter
Ferramenta avançada de enumeração de subdomínios para Bug Bounty e Pentest
-
nessus-parser
A parser for
.nessus(v2) XML reports -
aimds-response
Adaptive response layer with meta-learning for AIMDS threat mitigation
-
dicgen
Generate a list with all combinations for given characters, like in brute force attacks
-
passcore
lightweight Rust library that scores password strength
-
judger
A sandboxed environment for running untrusted code safely
-
xmtool
Binding
-
ghastoolkit
GitHub Advanced Security Toolkit in Rust
-
assemblyline-markings
using access control strings with the Assemblyline malware analysis platform
-
goran
CLI tool for analyzing domains and IP addresses
-
orcs-app
ORCS Application Layer - Re-exports and AppError
-
linux-audit-parser
Parser for Linxu Audit logs
-
fsm_governance_engine_lib
Declarative, validation-only FSM library with invariants and deterministic auditability
-
hypnus
Memory Obfuscation in Rust
-
csaf-validator
A validator for the CSAF standard written in Rust
-
sbom-walker
work with SBOM data
-
rsrp-proof-engine
Deterministic proof engine for high-integrity Rust applications
-
vaas
Check files and hashes for malicious content
-
whad
Wireless hacking framework (Pre-alpha)
-
cargo-caps
Audit what a crate is capable of by analyzing what linker symbols it emits
-
antivirus
not enough! you need PROTOGENT
-
xgadget
Fast, parallel, cross-variant ROP/JOP gadget search for x86/x64 binaries
-
utimaco_pkcs11_loader
Utimaco HSM PKCS#11 loader
-
touched
writing fuzzing harnesses of callback-style and trait-style Rust crates
-
microsandbox
Rust SDK for microsandbox - secure self-hosted sandboxes for your AI agents
-
kindly-guard-cli
Command-line security scanner and monitoring tool for threat detection
-
leucite
sandboxing and limiting command execution
-
panic-analyzer
an audit tool to scan your crate or workspace searching for potential panic points in your codebase
-
threat-intel
Comprehensive threat intelligence framework with multi-source aggregation, CVE integration, and risk assessment
-
haruspex
Vulnerability research assistant that extracts pseudocode from IDA Hex-Rays decompiler
-
cf-credstore-sdk
SDK for credstore module: API traits, models, and error definitions
-
unicop
scanning source code for potentially malicious unicode code points. Helps prevent Trojan source bidi attacks, homoglyph attacks, invisible character attacks etc. Intended to run manually…
-
malwaredb-virustotal-bin
VirusTotal command line client
-
ssec-cli
command-line interface for reading and writing the SSEC file format
-
get-capec
Tools for CVE managing, exploring and collect some data about their weaknesses and classifications
-
mine
High-assurance IPC and private Unix Domain Socket (UDS) orchestration. Provides exclusive data ownership and sandboxing for the Honest-Classified security ecosystem.
-
oneiromancer
Reverse engineering assistant that uses a locally running LLM to aid with pseudocode analysis
-
rusty-sandbox
-
mwemu
x86 32/64bits and system internals emulator, for securely emulating malware and other stuff
-
fw-rs
A forensic-grade file destruction utility for securely overwriting and deleting files/directories
-
sublime_pkg_tools
Package and version management toolkit for Node.js projects with changeset support
-
falco_plugin_api
Autogenerated bindings for the Falco plugin API
-
actix-web-ratelimit
highly customizable rate limiter for actix-web 4
-
passgenz
A secure password generator CLI tool for macOS with clipboard integration
-
ripgen
A rust-based version of the popular dnsgen python utility
-
tauri-dumper
dump assets from a Tauri app
-
threatflux-string-analysis
Advanced string analysis and categorization library for security applications
-
swage-spoiler
SPOILER allocator module for Swage
-
yedad_entropy
Deterministic wallet entropy pipeline for Yadad with full security features
-
fugue-fspec
A binary analysis framework written in Rust
-
reaction-plugin
Plugin interface for reaction, a daemon that scans logs and takes action (alternative to fail2ban)
-
idalib-build
Idiomatic bindings to IDA SDK
-
krater
Reconnaissance orchestrator for offensive security
-
shellcode-loader
shellcode加载器,通过多种方式加载shellcode并对抗EDR检测
-
leguichet
One way diodes with antiviral and yara scanning
-
parascope
Weggli ruleset scanner for source code and binaries
-
reoxide
Rust-bindings for the ReOxide decompiler extension framework
-
coffeeldr
A COFF (Common Object File Format) loader written in Rust
-
euvd
API for querying recent vulnerabilities from the ENISA EUVD database
-
cvss
Common Vulnerability Scoring System parser/serializer
-
hexora
Static analysis of malicous Python scripts
-
deepterra
parse terraform and generate a resource dependency graph
-
catsploit
An open-source modern exploitation framework inspired by Metasploit
-
owi
Bindings to the C symbolic API of the owi bug finding tool
-
rotaryoss-core
Core types and traits for the Rotary secret health auditor
-
rust-metasploit
Rust wrapper for metasploit
-
steve
Search Technical Evidence Very Easily
-
cf-credstore
credstore gateway module
-
cosmian_kms_client
Cosmian KMS REST Client
-
lockb-xray
CLI tool to audit Bun bun.lockb for supply chain risks
-
wpscan-analyze
Analyzes wpscan json output and checks for vulnerabilities
-
scope
A high-assurance framework for scoped lifetimes and deterministic execution boundaries. Part of the Honest-Classified security suite.
-
jsrs
fast and flexible command-line tool for scanning JavaScript files
-
smith-protocol
Shared protocol definitions for agent execution system
-
mini-vet
A client for the cargo-vet registry. Fetches security reviews for Rust/Cargo crates.
-
clamav-async
Async ClamAV bindings for Rust
-
falco_plugin_runner
Pure-Rust runner for Falco plugins
-
ppfuzz
| x | x | / _..___ | | | | | |/ // / || || ||`//_/ Prototype Pollution Fuzzer @dwisiswant0
-
hakoniwa-cli
Process isolation for Linux using namespaces, resource limits, cgroups, landlock and seccomp
-
assemblyline-filestore
A blob storage layer for the Assemblyline malware analysis platform
-
lancelot-bin
binary analysis tools for x32/x64 PE files
-
http_desync_guardian
HTTP/1.1 request analysis to prevent HTTP Desync attacks
-
sandbox-agent-opencode-adapter
Universal API for automatic coding agents in sandboxes. Supports Claude Code, Codex, OpenCode, and Amp.
-
u-siem-paloalto
be used to build a custom SIEM with the framework uSIEM
-
ricecoder-teams
Team collaboration system for RiceCoder - shared standards, rule promotion, and access control
-
rsrp-policy-dsl
Compiled policy DSL for deterministic access-control and proof-oriented rule execution
-
uwd
Call Stack Spoofing for Rust
-
riskcalc
risk analysis and Monte Carlo simulation
-
get-mitre
Tools for CVE managing, exploring and collect some data about their weaknesses and classifications
-
osintrs
application for OSINT (Open Source Intelligence) gathering and analysis
-
auditable2cdx
Command-line tool to recover
cargo auditabledata in CycloneDX format -
abcdict
A better customization password dictionary generator implementation by Rust
-
totally-safe
that allows you to bypass Rust's safety guarantees with totally safe patterns, featuring arbitrary lifetimes, aliasing, and more!
-
r2api
rust bindings for the radare2 native APIs
-
tayvo_clamav-client
ClamAV client library
-
swage-thp
THP allocator module for Swage
-
rustclr
Host CLR and run .NET binaries using Rust
-
revolt_clamav-client
ClamAV client library
-
cosmian_kms_server
Cosmian Key Management Service - A high-performance, FIPS 140-3 compliant Key Management System
-
soos-sample-project
SOOS ( https://soos.io ) is an independent software security company, located in Winooski, VT USA, building security software for your team. Used for testing purposes, this package…
-
envy-rs
Generate obfuscated Windows PowerShell payloads that resolve to paths by globbing environment variables
-
libsla-sys
System crate for Ghidra Sleigh library libsla
-
mantid
multitool for security research and development
-
pmsf
Polymorphic Malware Stage Framework (PMSF): a research-grade Rust framework for simulating and analyzing modular malware stages
-
keystone-cli
Quick assembler using keystone-engine for CTF
-
cvss_tools
working with CVSS
-
clamd-client
Rust async tokio client for clamd. Works with a tcp socket or with the unix socket. At the moment it will open a new socket for each command. Work in progress.
-
augur
Reverse engineering assistant that extracts strings and related pseudocode from a binary file
-
ShellcodeGenerator
A shellcode generator for quickly exploit development
-
panda-re-sys
The official *-sys library for interfacing with PANDA (Platform for Architecture-Neutral Dynamic Analysis)
-
rinzler-core
Core library for Rinzler - API scanner data models and database
-
jopcall
Dynamically executed Windows Syscalls via JOP/ROP
-
carbon_14
OSINT dating tool for web pages
-
foundyou
A powerful command-line application for OSINT and social engineering
-
Malware_Rhapsody
Small researching of Linux's security for fun and education.. don't be silly to use it in wild. Have a great day, Dear Researcher/Scholar 💯❤️
-
top_level_crate
level
-
yara-forge
A powerful Rust library for crafting, validating, and managing YARA rules
-
u-siem-sonicwall
be used to build a custom SIEM with the framework uSIEM
-
reverse_engineering_lib
reverse engineering tasks, including entropy calculation, color-based hex visualization, and PE file analysis
-
auditable
Audit Rust binaries for known bugs or vulnerabilities in production with zero bookkeeping
-
cargo-pants
cargo subcommand application that provides a bill of materials and a list of which dependencies have a vulnerability, powered by Sonatype OSSIndex
-
bw-picker
CLI tool used to fetch passwords and more from Bitwarden using their Vault API
-
pulsesecurity
Pulse Security SDK
-
debian-repro-status
Check the reproducibility status of your installed Debian packages
-
io-tubes
functionality like pwntools tube for async io in rust
-
utils_nostd
dinvoke_nostd
-
nessus
Vulnerability Scanner API client
-
secbox
Sensitive data container
-
bun-xray-core
Core parsing and security scanning logic for bun.lockb forensic analysis
-
unicode-security
Detect possible security problems with Unicode usage according to Unicode Technical Standard #39 rules
-
rsrp-immutable-ledger
Append-only immutable audit ledger with hash chaining, Merkle roots, and publication support
-
secretscan
A blazing-fast secret scanner for your codebase
-
version-checker
A clean, easy to use version checker built to help you track problems with your dependencies
-
sentinel-sdk
Rust SDK for Sentinel LLM Security Gateway
-
bp3d-os
Operating System tools designed for BlockProject3D
-
raxit-core
Core security scanning engine for AI agent applications
-
hardened-malloc
Global allocator using GrapheneOS allocator
-
vein-admin
Admin web interface for Vein RubyGems proxy server
-
path_ratchet
Prevent path traversal attacks at type level
-
u-siem-sqlite-store
be used to build a custom SIEM with the framework uSIEM
-
rust-mcp-server-syncable-cli
High-performance Model Context Protocol (MCP) server for code analysis, security scanning, and project insights
-
cargo-cola
Security static analyzer for Rust. Analyzes MIR to detect vulnerabilities. (Requires nightly)
-
rustshell
An educational project to aid in security operations and testing
-
mace
Automated extration of malware configuration, focusing on C2 communication
-
get-cwe
Tools for CVE managing, exploring and collect some data about their weaknesses and classifications
-
smtpeek
A state-of-the-art SMTP user enumeration tool that efficiently tests for valid email accounts on SMTP servers while evading detection mechanisms
-
pysentry
Security vulnerability auditing for Python packages
-
airgorah
A WiFi security auditing software mainly based on aircrack-ng tools suite
-
yara-x-cli
A command-line interface for YARA-X
-
obfustring
Procedural macro that obfuscates string literals with RNG at compile time
-
ief
Cross-platform binary import/export search
-
judge-core
A judge library for online judge system
-
burn_operation
CLI tool to securely wipe a computer, at the speed of light
-
dlna-dmr
An extensible DLNA DMR (Digital Media Renderer) implementation
-
repl-core
Core REPL engine for the Symbi platform
-
macos-config-check
Checks your macOS machine against various hardened configuration settings
-
cosmian_kms_cli
Command Line Interface used to manage the KMS server If any assistance is needed, please either visit the Cosmian technical documentation at https://docs.cosmian.com or contact the…
-
rappct
Rust AppContainer / LPAC toolkit for Windows (profiles, capabilities, process launch, diagnostics)
-
telnet-sanitizer
Telnet TCP proxy that sanitizes protocol input to mitigate CVE-class vulnerabilities
-
il2cpp_rs
interacting with il2cpp on Windows
-
swage-pfn
PFN allocator module for Swage
-
rbacrab
Rust 🦀RBAC🦀 library with some crabby🦀🧙 macro magic! Not so blazingly fast yet, but has all 🚀🚀🚀 chances
-
nvd-api
A rust implementation of the nvd-api
-
clam-client
talking to ClamD
-
ankou
An OSINT repo miner focused on high-sev security bug in JS engines
-
modseclog
Introspection of ModSecurity log files
-
thehive-client
Rust client for TheHive API, enabling programmatic management of alerts, cases, observables, tasks, and other security incident response entities
-
sddl
parse and analyse SDDL Strings
-
winaudit
Advanced Windows auditing and security assessment Crate in Rust
-
cedrus-cedar
Core library for Cedar Policy serialization and type bindings
-
reoxide-proc
Proc-macro utility create for the ReOxide Rust-bindings
-
cvss-rs
representing and deserializing CVSS (Common Vulnerability Scoring System) data
-
sublime_node_tools
Node.js bindings for Sublime Workspace CLI Tools via napi-rs
-
ExploitBuilder
A exploit builder for quick exploit development
-
skp-validator-actix
Actix Web integration for skp-validator - high-performance validation for Actix services
-
cylo
Secure multi-language code execution service
-
fosr
Fos-R (Forger Of Security Records) is an AI-based synthetic network traffic generator
-
supply_poc_again
useless code to test supply chain attacks with cargo and crates.io
-
skp-ratelimit
Advanced, modular, extensible rate limiting library with GCRA, per-route quotas, and composite keys
-
sn0int
Semi-automatic OSINT framework and package manager
-
clawbox
Sandboxed agent execution service — secure containers for externally-facing AI agents
-
purl_validator
Offline PackageURL validator using a prebuilt FST of known packages
-
path_jail
A secure filesystem sandbox. Restricts paths to a root directory, preventing traversal attacks.
-
check_txt
A powerful file security checker for TXT and EPUB files with virus scanning capabilities
-
pdf-perm
Change the permissions of a PDF file
-
ingredients
Check ingredients of published Rust crates
-
vt3
VirusTotal REST API v3 (Public & Enterprise)
-
cargo-panic-audit
Find panic patterns that can take down production Rust services
-
ferrous-forge
System-wide Rust development standards enforcer
-
ricecoder-github
GitHub integration for repository operations
-
nvd_cve
Search for CVEs against a local cached copy of NIST National Vulnerability Database (NVD)
-
introspectme
GraphQL schema reconstruction via field suggestion error analysis
-
ancaptcha
A No-JS, stateless captcha engine designed for darknet and Tor hidden services
-
pscan
SYN Port Scanner written in Rust, with range and decoy scanning support
-
shinchina
tester
-
codedefender-config
Configuration utilities for CodeDefender, a code obfuscation and protection system
-
polarstego
Steganographic Polar Codes
-
cosmian_kms_server_database
containing the database for the Cosmian KMS server and the supported stores
-
misp-client-rs
client library for interacting with MISP (Malware Information Sharing Platform) instances via their REST API
-
obfswire
obfuscating network traffic, designed to resist deep packet inspection (DPI) and active probing of network endpoints
-
safebrowsing-api
Client for Google Safe Browsing API v4
-
radiotap-rs
no_std compatible radiotap header encoder and decoder
-
cwe-api-cli
Unofficial CLI for the CWE API
-
touched-derive
Derive macro
Touchablefortouchedcrate -
shiplog-ingest-manual
YAML-based manual event ingestor for non-GitHub work in shiplog
-
drop-root-caps
drop 'root' user capabilities on Linux
-
cosmian_kms_crypto
Cosmian KMS Crypto - cryptographic operations and algorithms
-
lazycert
ACME certificate management daemon for Vane
-
libsyd
Rust-based C library for syd interaction via /dev/syd
-
fenir
Tools for CVE managing, exploring and collect some data about their weaknesses and classifications
-
nono
Capability-based sandboxing library using Landlock (Linux) and Seatbelt (macOS)
-
swage-victim-dev-memcheck
DevMemCheck victim module for Swage
-
rsrp-security-core
Security primitives for deterministic proof systems (hashing, signatures, Merkle helpers)
-
sleigh-compiler
Rust bindings for the Ghidra SLEIGH compiler. Used to compile processor .slaspec files into .sla files
-
sigil-cli
Automated security auditing for AI agent code - quarantine-first scanning for pip, npm, git repos, and MCP servers
-
tirith-core
Terminal security analysis engine - homograph attacks, pipe-to-shell, ANSI injection
-
idalib-sys
Idiomatic bindings to IDA SDK
-
strike-security
Evidence-first CLI security validation platform
-
path-security
Comprehensive path validation and sanitization library with 85%+ attack vector coverage
-
parry-hook
Claude Code hook integration
-
win_mitigations
Windows process mitigation policies
-
cargo-report
Generate reports for integration with external software
-
rcore
Core module for Rair
-
crust-trust
An outstanding Rust crate to manage workspaces with optimal crate handling
-
symbi
AI-native agent framework for building autonomous, policy-aware agents that can safely collaborate with humans, other agents, and large language models
-
agentd
Agent daemon for secure capability execution with pluggable isolation backends
-
nvd-cwe
A rust implementation of the nvd-cwe
-
sandbox-runtime
OS-level sandboxing tool for enforcing filesystem and network restrictions
-
nmap-helper
Some utilities for working with Nmap scan results (https://nmap.org)
-
fuguex-loader
A binary analysis framework written in Rust
-
iptr-edge-analyzer
Extract edges and branches in Intel PT traces, and construct AFL++-compatible fuzzing bitmaps
-
wrkflw-runtime
Runtime execution environment for wrkflw workflow engine
-
safe-telnet-parser
Memory-safe Telnet protocol parser for defensive security and CVE mitigation