This is your work, valued
Atuo como Analista de Segurança da Informação, com foco em defesa. Aqui terá um pouco da minha evolução, com Phyton e scripts focados em CyberSecurity.
juice-shop-ctf. Tool to export Juice Shop challenges and hints in data format compatible with CTFd, RootTheBox or FBCTF
★ 474juice-shop. OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
★ 14kwhisper.cpp. Port of OpenAI's Whisper model in C/C++
★ 52kmountpoint-s3. A simple, high-throughput file client for mounting an Amazon S3 bucket as a local file system.
★ 1aws-nuke. Nuke a whole AWS account and delete all its resources.
★ 1cloudgoat. CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
★ 1manifesto. The OpenTF Manifesto expresses concern over HashiCorp's switch of the Terraform license from open-source to the Business Source License (BSL) and calls for the tool's return to a truly open-source license.
★ 1secDevLabs. A laboratory for learning secure web and mobile development in a practical manner.
★ 1DevOpsDays_Goiania. PHP
★ 13porch-pirate. Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API endpoints and secrets committed to workspaces, collections, requests, users and teams. Porch Pirate can be used as a client or be incorporated into your own applications.
★ 2owasp-go-2024. Python
★ 3OpenFixAI. Python
★ 7AWS_COMMUNITY_DAY_2024. Java
★ 3optscale. FinOps, MLOps and cloud cost optimization tool. Supports AWS, Azure, GCP, Alibaba Cloud and Kubernetes.
★ 1prowler. Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.
★ 1aws-finops-dashboard. A terminal-based AWS cost and resource dashboard built with Python and the Rich library. It provides an overview of AWS spend by account, service-level breakdowns, budget tracking, and EC2 instance summaries.
★ 1Loki. LOKI (Leverage Offensive Knowledge Intelligently) is an AI-powered tool that creates pull requests with realistic code and dependency vulnerabilities to test and benchmark SAST/SCA tools.
★ 1cloud_summit_cerrado_2025. Shell
★ 4SecBridge. Python
★ 14mcp. AWS MCP Servers — helping you get the most out of AWS, wherever you use MCP.
★ 1linuxsecmonitor. Shell
★ 1automated-security-helper. ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.
★ 1pacu. The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
★ 1crypto-br.
★ 1sqs_admin_painel. TypeScript
★ 352-weeks-of-aws-engineer.
★ 12sample-kiro-study-buddy. A Kiro power that turns Kiro into a personal study companion for any AWS certification exam
★ 46wordlist-br. Wordlist para auditoria de senhas, construída com foco em usuários Brasileiros.
★ 74dadoware. Brazilian-Portuguese word list and instructions booklet for Diceware
★ 210rails-erd. Generate Entity-Relationship Diagrams for Rails applications
★ 4.1klocalemu. LocalEmu: a free, open-source AWS emulator. Run 132 AWS services locally with one pip install. No account, no token, no telemetry. The drop-in LocalStack alternative for the AWS CLI, boto3, Terraform and CDK.
★ 166cli-agent-orchestrator. Python
★ 965Claude-BugHunter. A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
★ 3.3krack-attack. Rack middleware for blocking & throttling
★ 5.8kScanner_CVE_2026-42945. Script Python para detecção de instâncias Nginx vulneráveis ao CVE-2026-42945 em IPs, CIDRs e ASNs.
★ 18automated-security-helper. ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.
★ 669AWS. Shell
★ 7oauthimap. Oauth authentication for Imap receivers of GLPI
★ 17strong_migrations. Catch unsafe migrations in development
★ 4.4ksuspenders. A Rails application template with our standard defaults, optimized for deployment on Heroku.
★ 4kawesome-opensource-email. Awesome Opensource Email Resources
★ 1.2kfalcon-scripts. Scripts to streamline the deployment and use of the CrowdStrike Falcon sensor
★ 233helpful-links. List of helpful publicly available CrowdStrike material.
★ 61aws-network-firewall. How to integrate CrowdStrike Threat Intelligence with AWS Network Firewall
★ 1container-image-scan. Code to scan a container with CrowdStrike and return response codes indicating pass/fail status.
★ 42container-image-scan-action. CrowdStrike Container Image Scan Github Action
★ 17.github. Default Community Health files, Policies, and Workflows for the CrowdStrike organization on GitHub
★ 1slsdaysp-2025. JavaScript
★ 2fcs-action. CrowdStrike FCS CLI GitHub action
★ 20Linux4CyberSec. Linux para Profissionais de CyberSec
★ 170windows. Windows inside a Docker container.
★ 53kprompts.chat. f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
★ 167kCAPEv2. Malware Configuration And Payload Extraction
★ 3.4kcuckoo-modified. Modified edition of cuckoo
★ 407labs. Labs is a platform to learn and improve Application Security skills by working with ephemerous and secure laboratories
★ 12cap. Free, open-source and self-hosted CAPTCHA alternative to reCAPTCHA. Privacy-first and powered by proof-of-work and instrumentation challenges.
★ 7.4ktrivy. Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
★ 37kTorBot. Dark Web OSINT Tool
★ 4.5kpadroes-de-commits. Padrões de commits
★ 9.6kESP32-Bit-Pirate. A Hardware Hacking Tool with Web-Based CLI That Speaks Every Protocol
★ 5.2ktalks. My talks
★ 1ohmyzsh. 🙃 A delightful community-driven (with 2,500+ contributors) framework for managing your zsh configuration. Includes 300+ optional plugins (rails, git, macOS, hub, docker, homebrew, node, php, python, etc), 140+ themes to spice up your morning, and an auto-update tool that makes it easy to keep up with the latest updates from the community.
★ 189kowasp-vuln-mngmnt. The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.
★ 17Red-Infra-Craft. RedInfraCraft automates the deployment of powerful red team infrastructures! It streamlines the setup of C2s, makes it easy to create advanced phishing & payload infras
★ 233carreira-em-cyber. Repositório para disponibilização de conteúdo para auxiliar profissionais e estudantes de cyber que estão iniciando na área
★ 141iam-lens. Google Maps for AWS IAM
★ 276reference. ⭕ Share quick reference cheat sheet for developers.
★ 11ksnyk-cicd-integration-examples. Examples of integrating the Snyk CLI into a CI/CD system
★ 106Loki. LOKI (Leverage Offensive Knowledge Intelligently) is an AI-powered tool that creates pull requests with realistic code and dependency vulnerabilities to test and benchmark SAST/SCA tools.
★ 13aws-certified-cloud-practitioner. Compilado de anotações usadas na preparação para a certificação AWS Certified Cloud Practitioner (CLF-C01).
★ 193arch-cli. Shell
★ 6ghidra. Ghidra is a software reverse engineering (SRE) framework
★ 72kopensearch-start-local. Script que sobe localmente o OpenSearch para uso com LLMs
★ 20redesocial. Projeto do Curso de Sistemas de Informação sobre Rede Social
★ 44