Skip to content

Latest commit

Β 

History

39 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Java Forge Banner

A Professional Collection of Cybersecurity Tools for Education, Research & Defense

License: MIT Python 3.11+ PRs Welcome Status: Active


SecOps-Arsenal is a curated collection of 20+ hands-on cybersecurity tools, scripts, and services designed for education, research, defensive engineering, and authorized security testing. Each tool is a standalone project that teaches essential security concepts through real, runnable implementations.

Getting Started Β· Tool Catalog Β· Contributing Β· Security Policy


πŸ“‹ Table of Contents


πŸ” Overview

SecOps-Arsenal provides practical, code-driven cybersecurity education organized in a progressive learning path from Beginner to Expert. Unlike theoretical resources, every tool in this repository is a working implementation that you can run, modify, extend, and integrate into your own security lab.

What You'll Get

  • πŸ”§ Learn by building β€” each tool implements a real cybersecurity concept
  • 🧠 Understand internals β€” see how detection engines, SOAR platforms, and offensive tools actually work
  • πŸ’» Portfolio-ready projects β€” polished, documented tools you can showcase
  • πŸ“ Progressive difficulty β€” structured path from DNS lookups to SOAR orchestration
  • πŸ›‘οΈ Defensive-first mindset β€” offensive tools exist to improve your defenses

🎯 Repository Scope

This repository is intended for:

  • Cybersecurity Education β€” learning security concepts through implementation
  • Defensive Engineering β€” building detection, monitoring, and response tools
  • Research β€” experimenting with security techniques in controlled environments
  • Laboratory Environments β€” testing tools in isolated security labs
  • Authorized Security Assessments β€” supporting legitimate penetration testing engagements

🧰 Tool Catalog

🟒 Beginner

# Tool Description
1 basic-recon/ DNS lookup, IP geolocation, WHOIS queries, Nmap wrapper
2 credential-check/ Password complexity tester + Have I Been Pwned breach lookup
3 file-integrity/ SHA-256 file hashing + integrity monitoring (FIM)
4 url-scanner/ URL safety checker with regex analysis + VirusTotal API

🟑 Intermediate

# Tool Description
5 log-parser/ Apache/Nginx log parser + Streamlit visualization dashboard
6 packet-sniffer/ Live network capture via Scapy with protocol inspection
7 siem-ingest/ ELK stack ingestion scripts + Docker Compose setup
8 alerts/ YAML rule-based alert engine (IDS/IPS logic)
9 windows-monitor/ Real-time Windows Event ID monitoring (PowerShell)

πŸ”΅ Advanced

# Tool Description
10 automations/ Security playbooks: IP blocking, account locking, email alerts
11 forensics/ Metadata extractor + forensic timeline builder
12 red-team/ SMB enumeration + phishing template generator (educational)
13 threat-intel/ IOC enrichment via AbuseIPDB + AlienVault OTX
14 web-scanner/ HTTP header audit, TLS inspection, common exposure checks
15 api-security/ Automated OWASP API Top 10 security tests

πŸ”΄ Expert

# Tool Description
16 blue-team/ Host hardening auditor for Windows & Linux baselines
17 correlation-engine/ Multi-source log correlation for brute-force + exfiltration detection
18 incident-response/ Automated live-response evidence collector + IR report generator
19 recon-framework/ Multi-threaded subdomain enumeration + directory brute-forcing
20 orchestration/ Dockerized SOAR-lite engine with YAML playbooks

πŸš€ Quick Start

# Clone the repository
git clone https://github.com/Aakash02A/SecOps-Arsenal.git
cd SecOps-Arsenal

# Create a virtual environment
python -m venv venv
source venv/bin/activate    # Linux/macOS
.\venv\Scripts\activate     # Windows

# Install all dependencies
pip install -r requirements.txt

# Run a tool β€” for example, check a password
python credential-check/credential_checker.py "MyP@ssw0rd!"

# Or build a file integrity baseline
python file-integrity/fim.py build ./some-directory

πŸ“¦ Installation

Prerequisites

  • Python 3.11+
  • pip (Python package manager)
  • Git

Optional Prerequisites

Tool Required For
Nmap basic-recon/nmap_scanner.py
Npcap (Windows) packet-sniffer/sniffer.py
Docker orchestration/, siem-ingest/

Install All Dependencies

pip install -r requirements.txt

Install Development Dependencies

pip install -r requirements-dev.txt
pre-commit install

Each tool's README.md lists its specific dependencies if you prefer to install only what you need.


πŸ— Architecture

SecOps-Arsenal/
β”œβ”€β”€ .github/                    # GitHub Actions templates
β”‚   β”œβ”€β”€ workflows/              # GitHub Actions workflow folder
β”‚   β”œβ”€β”€ ISSUE_TEMPLATE/         # Bug report, feature request, tool request
β”‚   β”œβ”€β”€ PULL_REQUEST_TEMPLATE.md
β”‚   └── FUNDING.yml
β”œβ”€β”€ tests/                      # Unit tests (pytest)
β”œβ”€β”€ alerts/                     # 🟑 Rule-based alert engine
β”œβ”€β”€ api-security/               # πŸ”΅ API security tester
β”œβ”€β”€ automations/                # πŸ”΅ Security playbooks
β”œβ”€β”€ basic-recon/                # 🟒 DNS, WHOIS, IP info, Nmap
β”œβ”€β”€ blue-team/                  # πŸ”΄ Host hardening auditor
β”œβ”€β”€ correlation-engine/         # πŸ”΄ Log correlation engine
β”œβ”€β”€ credential-check/           # 🟒 Password checker
β”œβ”€β”€ file-integrity/             # 🟒 File integrity monitor
β”œβ”€β”€ forensics/                  # πŸ”΅ Metadata & timeline tools
β”œβ”€β”€ incident-response/          # πŸ”΄ IR evidence collector
β”œβ”€β”€ log-parser/                 # 🟑 Log parser & dashboard
β”œβ”€β”€ orchestration/              # πŸ”΄ SOAR-lite engine (Docker)
β”œβ”€β”€ packet-sniffer/             # 🟑 Network packet sniffer
β”œβ”€β”€ recon-framework/            # πŸ”΄ Subdomain & directory enum
β”œβ”€β”€ red-team/                   # πŸ”΅ SMB enum & phishing (educational)
β”œβ”€β”€ siem-ingest/                # 🟑 ELK stack ingestion
β”œβ”€β”€ threat-intel/               # πŸ”΅ IOC enrichment
β”œβ”€β”€ url-scanner/                # 🟒 URL safety scanner
β”œβ”€β”€ web-scanner/                # πŸ”΅ Web vulnerability scanner
β”œβ”€β”€ windows-monitor/            # 🟑 Windows event monitor (PS1)
β”œβ”€β”€ requirements.txt            # Global Python dependencies
β”œβ”€β”€ requirements-dev.txt        # Development dependencies
β”œβ”€β”€ pyproject.toml              # Ruff & pytest configuration
β”œβ”€β”€ CONTRIBUTING.md
β”œβ”€β”€ CODE_OF_CONDUCT.md
β”œβ”€β”€ SECURITY.md
β”œβ”€β”€ SUPPORT.md
β”œβ”€β”€ CHANGELOG.md
└── LICENSE                     # MIT License

βš™οΈ Technologies

Category Technologies
Languages Python 3.11+ (primary), PowerShell, Bash
Core Libraries requests, scapy, pyyaml, dnspython, python-nmap
Visualization Streamlit, Plotly, Pandas
Infrastructure Docker, Docker Compose, ELK Stack
CI/CD GitHub Actions
Quality Ruff (lint + format), pytest, pre-commit, pip-audit

πŸ’» Supported Platforms

Platform Status Notes
Windows 10/11 βœ… Full support. PowerShell tools are Windows-native.
Ubuntu / Debian βœ… Full support. Tested on Ubuntu 22.04+.
macOS ⚠️ Most tools work. Some system-level scripts (firewall, account management) are Windows/Linux only.
Docker βœ… Containerized tools available for orchestration/ and siem-ingest/.

πŸ”’ Security Notice

⚠️ IMPORTANT: Responsible Use

The tools in this repository are provided for educational purposes, authorized security research, and legitimate penetration testing only. By using these tools, you agree to:

  • Only use tools against systems you own or have explicit written authorization to test
  • Comply with all applicable laws in your jurisdiction
  • Not use these tools for unauthorized access, data theft, or any malicious purpose
  • Report vulnerabilities responsibly following our Security Policy

The maintainers are not responsible for misuse of any tool in this repository.

For security vulnerability reports, see SECURITY.md.


🀝 Contributing

We welcome contributions! Whether you're fixing a bug, adding a new tool, or improving documentation, your help is appreciated.

  1. Read the Contributing Guidelines
  2. Review the Code of Conduct
  3. Check open issues for tasks labeled good first issue
  4. Fork, branch, code, test, and submit a PR

See CONTRIBUTING.md for full development environment setup and coding standards.


πŸ—Ί Roadmap

Near-term

  • Expand test coverage to all 20 tools
  • Add Malware Analysis toolkit (static analysis, YARA rules)
  • Add Cloud Security module (AWS/GCP misconfiguration scanner)
  • Add Network Security module (port knocking, ARP spoofing detection)

Medium-term

  • Interactive web dashboard consolidating all tools
  • Plugin architecture for community tool extensions
  • Integration with MITRE ATT&CK framework
  • Pre-built Docker lab environments with intentionally vulnerable targets

Long-term

  • AI-assisted threat detection module
  • Full CTF challenge platform using the tools
  • Certification-aligned learning paths (Security+, CEH, OSCP)

❓ FAQ

Is this repository safe to use?

Yes. All tools are designed for educational use and authorized testing. Offensive tools include prominent disclaimers. No tool contains malware, backdoors, or destructive payloads.

Do I need all the dependencies?

No. Each tool's README.md lists its specific requirements. The root requirements.txt installs everything for convenience, but you can install selectively.

Can I use these tools in production?

These tools are educational and not hardened for production use. They are excellent for learning, prototyping, and lab environments, but production security infrastructure should use battle-tested solutions.

What Python version do I need?

Python 3.11 or higher is recommended. The CI pipeline tests against Python 3.11 and 3.12.

How do I report a security vulnerability?

Do NOT open a public issue. Follow our Security Policy for responsible disclosure.


πŸ“„ License

This project is licensed under the MIT License β€” see the LICENSE file for details.


πŸ‘€ Maintainers

Aakash GitHub

πŸ™ Acknowledgements


Built with ❀️ for the cybersecurity community

⬆ Back to Top

About

Cybersecurity Practical tools ,script and small services.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages