163 lines
30 KiB
Markdown
163 lines
30 KiB
Markdown
<div align="center">
|
||
<img width="260" height="260" alt="Kali dragon icon" src="https://github.com/user-attachments/assets/d911b71f-6ad9-45b7-9513-237f83377023"/>
|
||
<h1>Cybersecurity Projects</h1>
|
||
<p>70 hands-on security tools — from first-time programmers to advanced engineers</p>
|
||
</div>
|
||
|
||
<div align="center">
|
||
|
||
[](https://github.com/CarterPerez-dev/Cybersecurity-Projects)
|
||
[](https://github.com/CarterPerez-dev/Cybersecurity-Projects)
|
||
[](https://github.com/CarterPerez-dev/Cybersecurity-Projects)
|
||
[](LICENSE)
|
||
[](./PROJECTS)
|
||
[](https://github.com/sponsors/CarterPerez-dev)
|
||
|
||
</div>
|
||
|
||
<p align="center">Made possible by <a href="https://certgames.com"><strong>CertGames</strong></a></p>
|
||
|
||
A curated collection of cybersecurity projects organized by skill level. Each project includes full source code, documentation, and learning materials.
|
||
|
||
Browse the [certification roadmaps](./ROADMAPS/README.md) for career guidance or the [learning resources](./RESOURCES/README.md) for tools, courses, and communities.
|
||
|
||
> Currently building: **Self-Hosted Shodan Clone**
|
||
|
||
## Projects
|
||
|
||
<div align="center">
|
||
<img src="https://img.shields.io/badge/Foundations-5DEFD0?style=for-the-badge&logo=bookstack&logoColor=black&labelColor=5DEFD0" alt="Foundations"/>
|
||
<img src="https://img.shields.io/badge/Beginner-2EA44F?style=for-the-badge&logo=leaflet&logoColor=white" alt="Beginner"/>
|
||
<img src="https://img.shields.io/badge/Intermediate-D4A017?style=for-the-badge&logo=target&logoColor=white" alt="Intermediate"/>
|
||
<img src="https://img.shields.io/badge/Advanced-C73E3A?style=for-the-badge&logo=shield&logoColor=white" alt="Advanced"/>
|
||
</div>
|
||
|
||
### Foundations Projects
|
||
|
||
> **Start here if this is your first time coding.** The Foundations tier is *pre-beginner* — for someone who has never written Python, has barely used a terminal, and is new to cybersecurity. Source files are heavily commented as a teaching aid, and every `learn/` folder explains concepts from zero.
|
||
>
|
||
> **What makes Foundations different:**
|
||
> - **Single-file projects** — the entire tool lives in one readable Python file
|
||
> - **Heavy teaching comments** — every new concept is annotated inline
|
||
> - **Numpy-style docstrings** — every function documents what, why, and each parameter
|
||
> - **Extra-deep `learn/` folders** — Python features and security concepts explained from zero
|
||
> - **Production-quality code** — written to real standards, explained for beginners
|
||
|
||
| Project | Info | What You'll Learn |
|
||
|---------|------|-------------------|
|
||
| **[Hash Identifier](./PROJECTS/foundations/hash-identifier)**<br>Identify hash types by prefix, length, and charset |    | Hash families (MD5, SHA, bcrypt, Argon2) • PHC string format • Pattern matching • Pure-function design |
|
||
| **[HTTP Headers Scanner](./PROJECTS/foundations/http-headers-scanner)**<br>Audit a URL's response headers for missing or weak security controls |    | HTTP fundamentals • Security headers (CSP, HSTS, X-Frame-Options) • httpx requests • Scored audits |
|
||
| **[Password Manager](./PROJECTS/foundations/password-manager)**<br>Encrypted local vault with master password unlock |    | Argon2id key derivation • AES-GCM authenticated encryption • Secure on-disk vaults • Master-password workflows |
|
||
|
||
### Beginner Projects
|
||
|
||
| Project | Info | What You'll Learn |
|
||
|---------|------|-------------------|
|
||
| **[Simple Port Scanner](./PROJECTS/beginner/simple-port-scanner)**<br>Async TCP port scanner in C++ [@deniskhud](https://github.com/deniskhud) |   | TCP socket programming • Async I/O patterns • Service detection |
|
||
| **[Keylogger](./PROJECTS/beginner/keylogger)**<br>Capture keyboard events with timestamps |   | Event handling • File I/O • Ethical considerations |
|
||
| **[Caesar Cipher](./PROJECTS/beginner/caesar-cipher)**<br>CLI encryption/decryption tool |   | Classical cryptography • Brute force attacks • CLI design |
|
||
| **[DNS Lookup CLI Tool](./PROJECTS/beginner/dns-lookup)**<br>Query DNS records with WHOIS |   | DNS protocols • WHOIS queries • Reverse DNS lookup |
|
||
| **[Simple Vulnerability Scanner](./PROJECTS/beginner/simple-vulnerability-scanner)**<br>Check software against CVE databases |   | CVE databases • Dependency scanning • Vulnerability assessment |
|
||
| **[Metadata Scrubber Tool](./PROJECTS/beginner/metadata-scrubber-tool)**<br>Remove EXIF and privacy metadata [@Heritage-XioN](https://github.com/Heritage-XioN) |   | EXIF data • Privacy protection • Batch processing |
|
||
| **[Network Traffic Analyzer](./PROJECTS/beginner/network-traffic-analyzer)**<br>Capture and analyze packets |    | Packet capture • Protocol analysis • Traffic visualization |
|
||
| **[Hash Cracker](./PROJECTS/beginner/hash-cracker)**<br>Dictionary and brute-force cracking |   | Hash algorithms • Dictionary attacks • Password security |
|
||
| **[Steganography Multi-Tool](./SYNOPSES/beginner/Steganography.Multi.Tool.md)**<br>Hide data in images, audio, QR, PDFs, text |   | Multi-format steganography • Zero-width Unicode • Audio LSB • QR exploitation |
|
||
| **[Ghost on the Wire](./SYNOPSES/beginner/Ghost.On.The.Wire.md)**<br>L2 attack & defense: MAC spoofing + ARP detection |   | ARP protocol • MAC spoofing • MITM detection • L2 trust mapping |
|
||
| **[Canary Token Generator](./PROJECTS/beginner/canary-token-generator)**<br>Self-hosted honeytokens that alert on access |    | Deception defense • Honeytokens • MySQL wire protocol • PDF/DOCX patching<br>[Live Demo](https://iglowinthedark.com/) |
|
||
| **[Security News Scraper](./SYNOPSES/beginner/Security.News.Scraper.md)**<br>Aggregate cybersecurity news |   | Web scraping • CVE parsing • Database storage |
|
||
| **[Phishing Domain Generator & Quishing Scanner](./SYNOPSES/beginner/Phishing.Domain.Generator.And.Quishing.Scanner.md)**<br>Typosquat generation + QR phishing detection |   | Homoglyph attacks • Typosquatting • QR code analysis • Domain intelligence |
|
||
| **[SSH Brute Force Detector](./SYNOPSES/beginner/SSH.Brute.Force.Detector.md)**<br>Monitor and block SSH attacks |   | Log parsing • Attack detection • Firewall automation |
|
||
| **[Simple C2 Beacon](./PROJECTS/beginner/c2-beacon)**<br>Command and Control beacon/server |     | C2 architecture • MITRE ATT&CK • WebSocket protocol • XOR encoding |
|
||
| **[Base64 Encoder/Decoder](./SYNOPSES/beginner/Base64.Encoder.Decoder.md)**<br>Multi-format encoding tool |   | Base64/32 encoding • URL encoding • Auto-detection |
|
||
| **[Linux CIS Hardening Auditor](./PROJECTS/beginner/linux-cis-hardening-auditor)**<br>CIS benchmark compliance checker |   | CIS benchmarks • System hardening • Compliance scoring • Shell scripting |
|
||
| **[Systemd Persistence Scanner](./PROJECTS/beginner/systemd-persistence-scanner)**<br>Hunt Linux persistence mechanisms |   | Persistence techniques • Systemd internals • Cron analysis • Threat hunting |
|
||
| **[Linux eBPF Security Tracer](./PROJECTS/beginner/linux-ebpf-security-tracer)**<br>Real-time syscall tracing with eBPF |    | eBPF programs • Syscall tracing • BCC framework • Security observability |
|
||
| **[Trojan Application Builder](./SYNOPSES/beginner/Trojan.Application.Builder.md)**<br>Educational malware lifecycle demo |   | Trojan anatomy • Data exfiltration • File encryption • Attack lifecycle |
|
||
| **[DNS Sinkhole](./SYNOPSES/beginner/DNS.Sinkhole.md)**<br>Pi-hole-style malware domain blocker |   | DNS protocol • Blocklist management • Query logging • Network defense |
|
||
| **[Firewall Rule Engine](./PROJECTS/beginner/firewall-rule-engine)**<br>Parse and validate iptables/nftables rules |   | Firewall internals • Rule parsing • iptables/nftables |
|
||
| **[LLM Prompt Injection Firewall](./SYNOPSES/beginner/LLM.Prompt.Injection.Firewall.md)**<br>Detect and block prompt injection attacks |   | AI security • Prompt injection • Input sanitization • LLM defense |
|
||
|
||
### Intermediate Projects
|
||
|
||
| Project | Info | What You'll Learn |
|
||
|---------|------|-------------------|
|
||
| **[Payload Obfuscation Engine](./SYNOPSES/intermediate/Payload.Obfuscation.Engine.md)**<br>Multi-layer payload obfuscation toolkit |   | Obfuscation techniques • Polymorphism • AV evasion • Signature detection |
|
||
| **[SIEM Dashboard](./SYNOPSES/intermediate/SIEM.Dashboard.md)**<br>Log aggregation with correlation |    | SIEM concepts • Log correlation • Full-stack development<br>[Live Demo](https://siem.carterperez-dev.com/) |
|
||
| **[Token Abuse Playground](./SYNOPSES/intermediate/Token.Abuse.Playground.md)**<br>15+ token vulnerabilities to exploit and fix |    | JWT exploitation • OAuth attacks • Session security • Token forensics |
|
||
| **[Supply Chain Attack Simulator](./SYNOPSES/intermediate/Supply.Chain.Attack.Simulator.md)**<br>Fake PyPI package dependency confusion demo |   | Supply chain attacks • Dependency confusion • Package security • PyPI internals |
|
||
| **[DDoS Mitigation Tool](./SYNOPSES/intermediate/DDoS.Mitigation.Tool.md)**<br>Detect traffic spikes |   | DDoS detection • Rate limiting • Anomaly detection |
|
||
| **[Secrets Scanner](./PROJECTS/intermediate/secrets-scanner)**<br>Scan codebases and git history for leaked secrets |   | Secret detection • Shannon entropy • HIBP k-anonymity • SARIF output |
|
||
| **[API Security Scanner](./PROJECTS/intermediate/api-security-scanner)**<br>Enterprise API vulnerability scanner |     | OWASP API Top 10 • ML fuzzing • GraphQL/SOAP testing |
|
||
| **[Wireless Deauth Detector](./SYNOPSES/intermediate/Wireless.Deauth.Detector.md)**<br>Monitor WiFi deauth attacks |   | Wireless security • Packet sniffing • Attack detection |
|
||
| **[Credential Enumeration](./PROJECTS/intermediate/credential-enumeration)**<br>Post-exploitation credential collection |   | Credential extraction • Browser forensics • Red team tooling |
|
||
| **[Binary Analysis Tool](./PROJECTS/intermediate/binary-analysis-tool)**<br>Disassemble and analyze executables |   | Binary analysis • String extraction • Malware detection<br>[Live Demo](https://axumortem.carterperez-dev.com/) |
|
||
| **[Chaos Engineering Security Tool](./SYNOPSES/intermediate/Chaos.Engineering.Security.Tool.md)**<br>Inject security failures to test resilience |   | Chaos engineering • Security resilience • Credential spraying • Auth testing |
|
||
| **[Credential Rotation Enforcer](./PROJECTS/intermediate/credential-rotation-enforcer)**<br>Track and enforce credential rotation policies |   | Credential hygiene • Secret rotation • Compliance dashboards • API integration |
|
||
| **[Race Condition Exploiter](./SYNOPSES/intermediate/Race.Condition.Exploiter.md)**<br>TOCTOU race condition attack & defense lab |    | TOCTOU attacks • Double-spend bugs • Concurrent exploitation • Race visualization |
|
||
| **[Self-Hosted Shodan Clone](./SYNOPSES/intermediate/Self.Hosted.Shodan.Clone.md)**<br>Internet-connected device search engine |    | Service fingerprinting • Network scanning • OSINT • Search engine design |
|
||
| **[JA3/JA4 TLS Fingerprinting Tool](./PROJECTS/intermediate/ja3-ja4-tls-fingerprinting)**<br>Fingerprint TLS clients by handshake |   | TLS handshake analysis • JA3/JA4 hashing • Bot detection • Malware C2 identification<br>[Live Demo](https://mkultraalumni.com/) |
|
||
| **[Mobile App Security Analyzer](./SYNOPSES/intermediate/Mobile.App.Security.Analyzer.md)**<br>Decompile and analyze mobile apps |   | APK/IPA analysis • Reverse engineering • OWASP Mobile |
|
||
| **[DLP Scanner](./PROJECTS/intermediate/dlp-scanner)**<br>Data Loss Prevention for files, DBs, and traffic |   | PII detection • GDPR/HIPAA compliance • Pattern matching • Data classification |
|
||
| **[Lua/Nginx Edge Backend](./SYNOPSES/intermediate/Lua.Nginx.Edge.Backend.md)**<br>Full CRUD backend via Lua in Nginx |    | Edge computing • OpenResty • Lua scripting • WAF • JWT at the edge |
|
||
| **[Privesc Playground](./SYNOPSES/intermediate/Privesc.Playground.md)**<br>20+ privilege escalation paths to exploit |   | SUID exploitation • Sudo abuse • Cron hijacking • GTFOBins • Capability abuse |
|
||
| **[SBOM Generator & Vulnerability Matcher](./PROJECTS/intermediate/sbom-generator-vulnerability-matcher)**<br>Software Bill of Materials with CVE matching |   | SPDX/CycloneDX formats • Dependency analysis • CVE databases • EO 14028 compliance |
|
||
| **[Subdomain Takeover Scanner](./SYNOPSES/intermediate/Subdomain.Takeover.Scanner.md)**<br>Detect dangling DNS records |   | DNS enumeration • CNAME analysis • Cloud resource claiming • Bug bounty |
|
||
| **[GraphQL Security Tester](./SYNOPSES/intermediate/GraphQL.Security.Tester.md)**<br>Automated GraphQL vulnerability testing |   | Introspection attacks • Query depth DoS • Authorization bypass • Batching abuse |
|
||
| **[Docker Security Audit](./PROJECTS/intermediate/docker-security-audit)**<br>CIS Docker Benchmark scanner |   | CIS benchmarks • Container security • Multiple output formats |
|
||
|
||
### Advanced Projects
|
||
|
||
| Project | Info | What You'll Learn |
|
||
|---------|------|-------------------|
|
||
| **[API Rate Limiter](./PROJECTS/advanced/api-rate-limiter)**<br>Distributed rate limiting middleware |    | Token bucket algorithm • Distributed systems • Redis backend |
|
||
| **[Encrypted Chat Application](./PROJECTS/advanced/encrypted-p2p-chat)**<br>Real-time E2EE messaging |     | Signal Protocol • Double Ratchet • WebAuthn • WebSockets |
|
||
| **[Exploit Development Framework](./SYNOPSES/advanced/Exploit.Development.Framework.md)**<br>Modular exploitation framework |   | Exploit development • Payload generation • Plugin architecture |
|
||
| **[AI Threat Detection](./PROJECTS/advanced/ai-threat-detection)**<br>ML-powered nginx threat detection |     | ML ensemble (AE + RF + IF) • ONNX inference • Real-time detection |
|
||
| **[Bug Bounty Platform](./PROJECTS/advanced/bug-bounty-platform)**<br>Full vulnerability disclosure platform |     | Full-stack development • CVSS scoring • Workflow automation<br>[Live Demo](https://bugbounty.carterperez-dev.com/) |
|
||
| **[Cloud Security Compliance Dashboard](./SYNOPSES/advanced/Cloud.Security.Compliance.Dashboard.md)**<br>Multi-cloud compliance with CIS, SOC2, HIPAA |    | CIS benchmarks • SOC2/HIPAA compliance • Cost-security optimization • Drift detection |
|
||
| **[Malware Analysis Platform](./SYNOPSES/advanced/Malware.Analysis.Platform.md)**<br>Automated sandbox analysis |    | Malware analysis • Sandboxing • YARA rules • IOC extraction |
|
||
| **[Quantum Resistant Encryption](./SYNOPSES/advanced/Quantum.Resistant.Encryption.md)**<br>Post-quantum cryptography |   | Post-quantum algorithms • Hybrid encryption • Kyber/Dilithium |
|
||
| **[Zero Day Vulnerability Scanner](./SYNOPSES/advanced/Zero.Day.Vulnerability.Scanner.md)**<br>Coverage-guided fuzzing |    | Fuzzing • Vulnerability research • Crash triage |
|
||
| **[Distributed Password Cracker](./SYNOPSES/advanced/Distributed.Password.Cracker.md)**<br>GPU-accelerated cracking |    | Distributed systems • GPU computing • Hash cracking |
|
||
| **[Kernel Rootkit Detection](./SYNOPSES/advanced/Kernel.Rootkit.Detection.md)**<br>Detect kernel-level rootkits |   | Kernel internals • Memory forensics • Rootkit detection |
|
||
| **[Blockchain Smart Contract Auditor](./SYNOPSES/advanced/Blockchain.Smart.Contract.Auditor.md)**<br>Solidity vulnerability analysis |    | Smart contracts • Static analysis • Solidity security |
|
||
| **[Adversarial ML Attacker](./SYNOPSES/advanced/Adversarial.ML.Attacker.md)**<br>Generate adversarial examples |    | Adversarial ML • FGSM/DeepFool • Model robustness |
|
||
| **[Advanced Persistent Threat Simulator](./SYNOPSES/advanced/Advanced.Persistent.Threat.Simulator.md)**<br>Multi-stage APT simulation |   | APT techniques • C2 infrastructure • Lateral movement |
|
||
| **[Hardware Security Module Emulator](./PROJECTS/advanced/hsm-emulator)**<br>Software HSM that compiles to a real PKCS#11 `.so` |   | PKCS#11/Cryptoki C ABI • AES-GCM/CBC • RSA/ECDSA/ECDH • Argon2id + encrypted-at-rest |
|
||
| **[Network Covert Channel](./SYNOPSES/advanced/Network.Covert.Channel.md)**<br>Data exfiltration techniques |   | Covert channels • Data exfiltration • Steganography |
|
||
| **[Automated Penetration Testing](./SYNOPSES/advanced/Automated.Penetration.Testing.md)**<br>Full pentest automation |   | Pentest automation • Recon to exploitation • Report generation |
|
||
| **[Haskell Reverse Proxy](./PROJECTS/advanced/haskell-reverse-proxy)**<br>Functional reverse proxy with security middleware |   | Functional programming • Reverse proxy design • Security middleware |
|
||
| **["Monitor the Situation" Dashboard](./PROJECTS/advanced/monitor-the-situation-dashboard)**<br>Real-time cyber threat situational awareness |     | Threat intel feeds • EPSS/KEV/CVE velocity • BGP hijacks • WebSocket fan-out • 3D globe SOC view<br>[Live Demo](https://iminthewalls.com/) |
|
||
| **[Honeypot Network](./PROJECTS/advanced/honeypot-network)**<br>Multi-service honeypot deployment & analysis |     | Honeypot deployment • Attacker behavior analysis • IOC extraction • MITRE mapping<br>[Live Demo](https://honeypot-network.carterperez-dev.com/) |
|
||
| **[Supply Chain Security Analyzer](./SYNOPSES/advanced/Supply.Chain.Security.Analyzer.md)**<br>Dependency vulnerability analysis |   | Supply chain security • Dependency analysis • Malicious packages |
|
||
|
||
## Getting Started
|
||
|
||
Each project lives in its own directory under [`PROJECTS/`](./PROJECTS) with its own README, source code, and `learn/` documentation. To explore a project:
|
||
|
||
```sh
|
||
cd PROJECTS/<tier>/<project-name>
|
||
# Then follow that project's README for setup and usage
|
||
```
|
||
|
||
Projects marked with a synopsis (under [`SYNOPSES/`](./SYNOPSES)) have detailed design documents available. Source-code-complete projects are indicated by the blue badge count above.
|
||
|
||
## Roadmaps & Resources
|
||
|
||
- **[Certification Roadmaps](./ROADMAPS/README.md)** — 10 career paths for SOC Analyst, Pentester, Security Engineer, GRC Analyst, and more
|
||
- **[Learning Resources](./RESOURCES/README.md)** — Curated tools, courses, certifications, YouTube channels, Reddit communities, and security frameworks
|
||
|
||
## Contributing
|
||
|
||
Contributions are welcome. If you want to add a project, improve existing code, or fix documentation:
|
||
|
||
1. Fork the repository
|
||
2. Create a feature branch
|
||
3. Open a pull request
|
||
|
||
See the [open issues](https://github.com/CarterPerez-dev/Cybersecurity-Projects/issues) for ideas on what to work on.
|
||
|
||
## License
|
||
|
||
[AGPL 3.0](./LICENSE)
|