Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
-
Updated
Jan 28, 2026 - Shell
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring, quarantine, and multi-channel alerting
🔥 Professional Penetration Testing Framework v4.0 - Automated subdomain enumeration, vulnerability scanning with Nuclei, port scanning, and comprehensive HTML reports. Features parallel scanning, resume capability, and real-time progress tracking.
A script for credentials-based attack surface enumeration and general reconnaissance of massive networks
A collection of security related Python and Bash shell scripts. Analyze hosts on generic security vulnerabilities. Wrapper around popular tools like nmap (portscanner), nikto (webscanner) and testssl.sh (SSL/TLS scanner)
Run a security scan on your server and identify common gaps. Get your VPS ready for production.
Sandfly Security Agentless Compromise and Intrusion Detection System For Linux
This script is designed to help expedite a web application assessment by automating some of the assessment steps (e.g., running nmap, sublist3r, metasploit, etc.)
Detection scripts for MDM deployment to identify OpenClaw installations on managed devices.
The DNS Hunt will make your life easier, and of course faster.
This GitHub Action allows you to run Gitleaks in your GitHub workflow.
DeConfigro is a tool that scans WordPress websites for the WordPress Setup Config Vulnerability. If exposed, this page indicates an incomplete installation and can be exploited, posing a security risk.
DeVAIC (Detection of Vulnerabilities in AI-generated Code) is a static code analyzer for security issues in Python code snippets. It detects vulnerabilities belonging to the OWASP categories listed in the Top 10 of 2021.
Vision One Container Security Scan Action
Convenience wrapper around the Hydra brute force password cracking tool to help with automation
dockerized-cloudsplot, CloudSploit is a security and configuration scanner that can detect hundreds of threats in your AWS account. Don't let a single misstep compromise your entire infrastructure.
SADA Webapplication Scanner
Jenkins Pipeline for security scanning with owasp zap
Run n0s1 as Github action to scan Slack, Jira, Confluence, Asana, Wrike, Linear, Zendesk and GitHub for secret leaks
CI/CD Jenkins pipeline with SourceGuard integration for source code and docker image scanning.
Add a description, image, and links to the security-scanner topic page so that developers can more easily learn about it.
To associate your repository with the security-scanner topic, visit your repo's landing page and select "manage topics."