Stars
The OWASP Secure Headers Project
Fast and Lightweight Logs, Metrics and Traces processor for Linux, BSD, OSX and Windows
Updated lists of IP addresses/whitelists of good bots and crawlers. Includes GoogleBot, BingBot, DuckDuckBot, etc.
Bot detection library that runs in the browser. Detects automation tools and frameworks. No server required, runs 100% on the client. MIT license, no usage restrictions.
Nginx module that calcuates fingerprints from the JA4+ suite
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
A curated list of awesome Nginx distributions, 3rd party modules, Active developers, etc.
tiny subprocess/shell library to use with OpenResty application server
One of the fastest alternative JSON parser for Go that does not require schema
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …
This is a plugin that brings blocking of bots faking User-Agent to CRS.
Production-ready detection & response queries for osquery
A repository for using osquery for incident detection and response
an SSO and OAuth / OIDC login solution for Nginx using the auth_request module
Go-blueprint allows users to spin up a quick Go project using a popular framework
Go package for reading from continously updated files (tail -f)
Cross-platform filesystem notifications for Go.
Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab
Compiled Binaries for Ghostpack
Impacket is a collection of Python classes for working with network protocols.
Active Directory and Internal Pentest Cheatsheets