Dockerscan
Enterprise-grade security scanner for Docker containers. Detects vulnerabilities, analyzes configurations, and prevents secret leaks in real-time. +1,400 stars. Used by Fortune 500 companies.
Open source
I’ve published +100 open source tools over the years.
Here are just a few. The ones with the most GitHub stars.
They’re focused on REST APIs, security, and high performance.
Enterprise-grade security scanner for Docker containers. Detects vulnerabilities, analyzes configurations, and prevents secret leaks in real-time. +1,400 stars. Used by Fortune 500 companies.
High-performance distributed task manager for Python Asyncio. Massive real-time event processing with horizontal scaling. Modern Celery alternative without overhead. +400 stars.
Enterprise payload collection for NoSQL database pentesting (MongoDB, Cassandra, CouchDB, Redis). Used in bug bounties with critical findings up to $50K. +370 stars. Global reference.
Enterprise scanner for misconfigured S3 buckets. Prevents data leaks and multi-million GDPR fines. Detects exposed medical records, backups, and confidential data. +230 stars.
Automatic OpenAPI/Swagger documentation generation for high-performance aiohttp APIs. Reduces documentation time by 90%. Used in APIs handling millions of daily requests. +180 stars.
Specialized pentesting framework for Message Queues (RabbitMQ, Redis, Kafka). Detects insecure configurations in critical financial systems. Prevents malicious message injection. +150 stars.
Static security analysis for Dockerfiles in seconds. Detects hardcoded secrets, excessive privileges, and outdated software before build. CI/CD integration. +95 stars.
Intentionally vulnerable web application for testing security tools
Self-hosted URL shortener with no external dependencies. Lightweight, fast, easy to deploy. 43 stars.
Anti-hacking tool for Redis. Detects and blocks attacks against exposed Redis instances. 31 stars.
Simple, agnostic and lightweight logging dashboard. No stack dependencies, works with any application. 26 stars.
Anti-hacking Docker configuration for WordPress. Automated hardening with nmap, wpscan and plecost. 13 stars.
Lightweight API Specification for Intelligent Systems. Reduces LLM token overhead by 85% compared to OpenAPI. Published paper on arXiv. 12 stars.
Secure Nginx configuration for WordPress on Docker. Anti-hacking tools deployed automatically. 12 stars.
Realtime Redis data backup to S3. Uses asyncio to avoid performance impact. 11 stars.