前阵子,我发布了一份甲方安全开源清单,不少朋友帮忙反馈,得到了大大的补充,重新整理了一份项目清单。
GitHub项目地址:
https://github.com/Bypass007/Safety-Project-Collection
根据企业安全能力建设的需求,大致可以分为如下几种类型:
资产管理
https://github.com/Tencent/bk-cmdb
https://github.com/bongmu/OpsManage
https://github.com/Cryin/AssetsView
https://www.ansible.com/
https://docs.saltstack.com/en/latest/
漏洞管理
https://github.com/creditease-sec/insight
https://github.com/ysrc/xunfeng
https://github.com/martinzhou2015/SRCMS
https://github.com/233sec/laravel-src
https://github.com/DefectDojo/django-DefectDojo
https://github.com/jeffzh3ng/Fuxi-Scanner
https://gitee.com/gy071089/SecurityManageFramwork
安全开发
https://github.com/momosecurity/rhizobia_J
https://github.com/momosecurity/rhizobia_P
自动化代码审计
http://www.fortify.net/
http://rips-scanner.sourceforge.net/
https://github.com/openstack/bandit/releases/
https://github.com/WhaleShark-Team/cobra
https://github.com/yingshang/banruo
https://sourceforge.net/projects/visualcodegrepp/
https://find-sec-bugs.github.io/
WAF
https://github.com/loveshell/ngx_lua_waf
https://rasp.baidu.com/
http://www.modsecurity.org/
http://www.jxwaf.com/
https://github.com/xsec-lab/x-waf
堡垒机
https://github.com/jumpserver/jumpserver
https://tp4a.com/
https://github.com/triaquae/CrazyEye
https://github.com/liftoff/GateOne
https://www.tosec.com.cn/
https://github.com/jx-sec/jxotp
HIDS
https://www.ossec.net/
http://wazuh.com/
https://suricata-ids.org/
https://www.snort.org/
https://osquery.io/
https://www.la-samhna.de/
http://www.scaramanga.co.uk/firestorm/
https://github.com/mozilla/MozDef
https://github.com/ysrc/yulong-hids
https://github.com/DianrongSecurity/AgentSmith-HIDS
http://www.codeforge.cn/article/331327
https://securityonion.net/
http://openwips-ng.org/
https://www.dictionary.com/browse/moloch
网络流量分析
https://www.zeek.org/
https://www.kismetwireless.net/
SIEM/SOC
https://www.alienvault.com/products/ossim
https://github.com/apache/metron
https://siemonster.com/
https://github.com/smarttang/w3a_SOC
http://opensoc.github.io/
https://www.prelude-siem.org/
https://github.com/jeffbryner/MozDef
企业云盘
https://kodcloud.com/
https://www.seafile.com/home/
https://nextcloud.com/
https://owncloud.com/products/
http://www.godeye.org/code/ibarn
http://cloudreve.org/
https://github.com/filebrowser/filebrowser/releases/latest
https://filerun.com/
https://github.com/KOHGYLW/kiftd
钓鱼网站系统
https://github.com/SecurityPaper/mail_fishing
https://github.com/gophish/gophish
https://github.com/thelinuxchoice/blackeye
https://github.com/p1r06u3/phishing
安全运维
https://github.com/HandsomeOne/Scout
https://github.com/qunarcorp/open_dnsdb
https://github.com/cuckoosandbox/cuckoo
https://github.com/ytisf/theZoo
https://code.google.com/archive/p/opendlp/
GitHub监控
https://github.com/FeeiCN/GSIL
https://github.com/0xbug/Hawkeye
https://github.com/MiSecurity/x-patrol
https://github.com/VKSRC/Github-Monitor
https://github.com/neal1991/gshark
https://www.gitguardian.com/
蜜罐技术
https://github.com/dtag-dev-sec/tpotce/
https://github.com/p1r06u3/opencanary_web
http://www.honeyd.org/
http://threatstream.github.io/mhn/
https://github.com/mushorg/glastopf
https://github.com/cowrie/cowrie
https://github.com/desaster/kippo
https://github.com/DinoTools/dionaea
https://github.com/mushorg/conpot
https://github.com/gbrindisi/wordpot
https://github.com/jordan-wright/elastichoney
https://github.com/honeynet/beeswarm
https://github.com/threatstream/shockpot
风控系统
https://github.com/threathunterX/nebula
https://github.com/ysrc/Liudao
https://github.com/momosecurity/aswan
https://www.drools.org/