Giter Site home page Giter Site logo

jbchassy / nsacyber.github.io Goto Github PK

View Code? Open in Web Editor NEW

This project forked from nsacyber/nsacyber.github.io

0.0 0.0 0.0 104 KB

NSA Cybersecurity. Formerly known as NSA Information Assurance and the Information Assurance Directorate

Home Page: https://nsacyber.github.io

License: Creative Commons Zero v1.0 Universal

nsacyber.github.io's Introduction

This page lists open source software released by the Cybersecurity mission at NSA and also hosts a code.gov code inventory file. See the NSA github.io web site and the NSA Technology Transfer Program web site for more information about open source software released by NSA.

AppLocker Guidance

Configuration guidance for implementing application whitelisting with AppLocker.

Atomic Watch

Intel Atom C2000 series discovery tool that parses log files and returns results if a positive match is found

BitLocker Guidance

Configuration guidance for implementing BitLocker.

Certificate Authority Situational Awareness (CASA)

Identifies unexpected and prohibited certificate authority certificates on Windows systems.

CodeGov

Creates a code.gov code inventory JSON file based on GitHub repository information

Control Flow Integrity

A proposed hardware-based method for stopping known memory corruption exploitation techniques.

Detect CVE-2017-15361 TPM

Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361

Driver Collider

Blocks drivers from loading by using a name collision technique

Event Forwarding Guidance

Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding.

goSecure

An easy to use and portable Virtual Private Network (VPN) system built with Linux and a Raspberry Pi.

GRASSMARLIN

Provides situational awareness of Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) networks in support of network security assessments.

Hardware and Firmware Security Guidance

Guidance for the Spectre, Meltdown, Speculative Store Bypass, Rogue System Register Read, Lazy FP State Restore, Bounds Check Bypass Store, TLBleed, and L1TF/Foreshadow vulnerabilities as well as general hardware and firmware security guidance.

Host Integrity at Runtime and Start-up (HIRS)

Trusted Computing based services supporting TPM provisioning and supply chain validation concepts.

HTTP Connectivity Tester

Aids in discovering HTTP and HTTPS connectivity issues

Java PathFinder Mango (JPF-Mango)

A static code analysis tool, part of the NASA Ames Java PathFinder project, that uses formal methods to verify executable Java bytecode.

LOCKLEVEL

A prototype that demonstrates a method for scoring how well Windows systems have implemented some of the top 10 Information Assurance mitigation strategies.

MAPLESYRUP

Assesses CPU security of embedded devices.

netfil

A kernel network manager with monitoring and limiting capabilities for macOS.

netman

A userland network manager with monitoring and limiting capabilities for macOS.

OpenAttestation

Verifies system integrity by establishing a baseline measurement of a system's Trusted Platform Module (TPM) and monitors for changes in that measurement. OpenAttestion was originally based on NSA's National Information Assurance Research Laboratory (NIARL) Host Integrity at Startup (HIS) software.

paccor

The Platform Attribute Certificate Creator can gather component details, create, sign, and validate the TCG-defined Platform Credential.

Pass-the-Hash Guidance

Configuration guidance for implementing Pass-the-Hash mitigations.

SCAP Security Guide (SSG)

Security guidance, baselines, and compliance mechanisms using the Security Content Automation Protocol (SCAP) for hardening Linux systems and applications.

Security-Enhanced Linux (SELinux)

A mandatory access control mechanism for the Linux kernel.

Security Enhancements (SE) for Android

A mandatory access control mechanism for Android.

serial2pcap

Converts serial IP data, typically collected from Industrial Control System devices, to the more commonly used Packet Capture (PCAP) format.

Simon and Speck

Fast implementations of the Simon and Speck lightweight block ciphers for the SUPERCOP benchmark toolkit.

Splunk Assessment of Mitigation Implementations (SAMI)

Automatically scores how well Windows systems have implemented some of the top 10 Information Assurance mitigation strategies.

Unfetter

Identifies defensive gaps in security posture by leveraging Mitre's ATT&CK framework.

WALKOFF

A flexible, easy to use, automation framework allowing users to integrate their capabilities and devices to cut through the repetitive, tedious tasks slowing them down.

Windows Event Log Messages

Retrieves the definitions of Windows Event Log messages embedded in Windows binaries and provides them in discoverable formats.

Windows Secure Host Baseline (SHB)

Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings.

License

See INTENT (see code.mil for more information) and LICENSE.

Contributing

See CONTRIBUTING

Disclaimer

See DISCLAIMER.

nsacyber.github.io's People

Contributors

iadgovuser1 avatar iadgovadmin avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.