Subcategories
Packages
Policy Sentry generates least-privilege AWS IAM policies from resource ARNs and access levels, automating the creation of security-scoped policies that would otherwise require manual AWS documentation review.
Cloudsplaining scans AWS IAM policies to identify violations of least privilege and generates a risk-prioritized HTML report highlighting dangerous permissions without resource constraints.
Provides Python client access to the Akeyless API for secrets management and key operations.
However, verify the undeclared license terms and Python version compatibility before adopting in production or commercial contexts.
django-axes tracks failed login attempts to Django sites and blocks attackers who exceed a configured attempt limit, supporting IP address, username, user agent, and combination-based tracking.
Install it if you operate a Django site with user authentication and want straightforward, configurable login-attempt monitoring and blocking.
Provides Pydantic models and schemas for Safety tools, enabling structured validation and serialization of safety policy files and configuration data.
Encodes and decodes JSON Web Tokens (JWTs) with signature verification, supporting symmetric and asymmetric algorithms including RS256, HS256, and PS256.
Encrypts and decrypts data using AWS KMS keys and keyrings, implementing the AWS Encryption SDK specification for Python.
Install it if you need to encrypt/decrypt data with AWS KMS in Python.
Capstone is a disassembly engine that decodes binary machine code into human-readable assembly instructions across multiple CPU architectures including ARM, ARM64, MIPS, PPC, Sparc, SystemZ, XCore, and X86.
Parses raw email messages into structured Python objects with RFC compliance, extracting headers, bodies, attachments, routing information, and defects for security analysis and forensics.
Install it if you need reliable, RFC-compliant email parsing with security-focused defect detection; the optional Outlook support makes it versatile for mixed email…
Provides Python bindings to the Windows SSPI API for authentication and message protection, with experimental support for Linux and macOS via sspi-rs.
However, the project is aging (254 days since last release, 8 stars), so adoption is limited and you should verify that the specific authentication protocols and…
Provides a modern, easy-to-use wrapper for hashing and verifying passwords using secure algorithms, designed as a contemporary alternative to older password hashing libraries.
Install it if you want a simple, secure alternative; skip it only if you need legacy algorithm support or broader feature coverage.
Adds complete two-factor authentication to Django projects, supporting authentication via one-time passwords, SMS, call, token generator apps, and hardware tokens like YubiKey.
Caches AWS Secrets Manager secrets in-process to reduce API calls and improve application performance when retrieving secrets repeatedly.
Retrieves cloud identity tokens from AWS, GCP, and Azure for use in authentication workflows, automatically discovering credentials from the default cloud provider session when available.
Casbin enforces access control policies (ACL, RBAC, ABAC) by evaluating requests against a configurable model and policy rules, returning allow or deny decisions.
Install it if you need flexible, model-driven authorization; skip it if your access control is trivial or if you prefer inline permission checks.
ast-grep-cli is a command-line tool for searching, linting, and rewriting code using abstract syntax tree patterns instead of text matching.
Generates Software Bill of Materials (SBOM) documents in CycloneDX format from Python projects, virtual environments, and dependency manifests (Poetry, Pipenv, requirements.txt, PDM, uv).
Install it if you need to produce CycloneDX documents for supply-chain security, regulatory compliance, or vulnerability tracking workflows.
Python wrapper for Linux PAM (Pluggable Authentication Modules) that authenticates users against system credentials using ctypes bindings.
Provides AWS CodeArtifact authentication for pip and twine by extending the keyring library to automatically inject time-limited access tokens.
Programmatic Python interface to read and manage secrets, items, and vaults in 1Password via local desktop app or service account authentication.
Androguard is a Python tool for analyzing, disassembling, and decompiling Android application files (APK, DEX, ODEX) and extracting metadata from Android binary resources.
Parses APK files according to the zip specification, extracts contents, decodes AndroidManifest.xml, and identifies static analysis evasion techniques without external library dependencies.
PyCasbin enforces access control policies using models like ACL, RBAC, and ABAC, determining whether a subject can perform an action on an object based on configurable rules.
Install it if your application requires authorization beyond simple role checks or if you anticipate changing authorization rules frequently.
Implements the JOSE (JSON Object Signing and Encryption) protocol in Python, providing cryptographic signing and encryption for JSON-based message authentication and integrity.
Install it if you need JOSE functionality in Python.
Django Hijack lets administrators impersonate other users in a Django application, allowing support staff and admins to log in as another user without needing their password.
Parses and scores CVSS v2, v3, and v4 vulnerability severity vectors, returning standardized numeric scores and severity ratings from 0 to 10.
pyseccomp provides a pure-Python interface to libseccomp via ctypes, allowing you to define and enforce system call filtering policies.
Provides a Python client library for the OpenCTI API, enabling developers to programmatically interact with OpenCTI threat intelligence platform instances through standardized methods and utilities.
Install it if you need to integrate with OpenCTI; the main consideration is ensuring your OpenCTI instance is accessible and that the 18 runtime dependencies align…
Implements an RFC 6960 compliant OCSP Responder framework for validating certificate status over HTTP, using custom Python functions to determine certificate revocation state and retrieve certificates.
Validates the syntax of STIX 2 Pattern expressions used in cyber threat intelligence to describe observable conditions, available as both a command-line tool and Python library.
However, the aging maintenance status (184 days since last release) and Alpha development status mean you should verify that it handles your specific pattern syntax…
yara-python provides a Python interface to YARA, enabling you to compile pattern-matching rules, scan files and strings for matches, and extract detailed information about what was matched.
Serializes and deserializes STIX 2 JSON content, providing Python APIs for creating, parsing, and manipulating cyber threat intelligence objects with support for data markings, versioning, and ID resolution across multiple sources.
Install it if you need to produce, consume, or transform STIX 2 JSON in a Python application; skip it if you don't work with CTI standards.
Landlock provides a Python interface to Linux's Landlock security module, enabling rule-based file system access restrictions to harden applications against unauthorized file access.
FalconPy is the official CrowdStrike Falcon SDK for Python, providing abstracted access to the entire CrowdStrike Falcon API through service classes or a unified Uber Class, with automatic token management and support for multiple cloud regions.
Install it if you need to integrate CrowdStrike Falcon APIs into a Python application; it eliminates boilerplate OAuth2 and token management code.
Provides type stubs for the oauthlib package, enabling type checkers like mypy and pyright to validate code that uses oauthlib for OAuth protocol implementation.
Defusedcsv is a drop-in replacement for Python's standard csv module that mitigates CSV injection attacks by escaping cells that start with formula-triggering characters.
Parses and validates OpenSSH public keys, extracting key type, bit length, and computing cryptographic hashes for ssh-rsa, ssh-dss, ssh-ed25519, and NIST-curve ecdsa keys.
Install it if your use case is straightforward key parsing; consider alternatives if you need support for newer OpenSSH certificate formats or active maintenance.
Fetch and manage secrets from Infisical, an open source secret management platform, directly within Python applications.
However, verify the license terms before use in proprietary contexts, and confirm that your Python version is supported (the metadata does not specify a minimum…
clamd is a Python interface to the ClamAV antivirus daemon, allowing you to scan files and streams for malware on Windows, Linux, macOS, and other platforms.
However, verify compatibility with your ClamAV daemon version and Python release first, and be aware that no active development means bugs or incompatibilities will…
ast-grep-py is a Python binding for ast-grep, a tool that searches, lints, and rewrites code using precise abstract syntax tree patterns.