Subcategories
Packages
Constructs and parses NTLM authentication messages (LM, NTLMv1, NTLMv2) for HTTP authentication, handling message signing and sealing with support for channel binding tokens.
No—not for new projects.
angr is a binary analysis framework that performs symbolic execution, disassembly, control-flow analysis, and decompilation on binaries across multiple architectures.
django-guardian adds per-object permission checks to Django, letting you grant or deny specific users and groups access to individual model instances rather than just model-wide permissions.
Securesystemslib provides a cryptography interface for creating and verifying digital signatures, with support for ed25519, RSA, ECDSA, and hardware security modules, designed for TUF and in-toto metadata formats.
Generates short-term bearer tokens for AWS Bedrock API authentication, eliminating the need to expose long-term credentials in client code.
However, it is still in Beta (first release 2025-07-01) and marked as aging (381 days since latest release), so verify token expiry and refresh behavior matches your…
Sigstore is a Python tool for generating and verifying keyless signatures on files and Python package distributions using OpenID Connect identities and Sigstore's transparency log infrastructure.
Install it if supply chain security and keyless identity-based signing align with your workflow; skip it if you prefer traditional key-based signing or have no need…
Provides command-line tools to encrypt and decrypt files using GPG with AES256 cipher, supporting single files, directories, and optional tar archiving before encryption.
However, verify Python and GPG compatibility first, since the package has not been actively maintained since 2015 and may have undiscovered issues with modern…
ROPGadget searches for ROP (Return-Oriented Programming) gadgets in binaries across multiple architectures and file formats to support exploit development and security research.
Python SDK for OpenFGA that wraps the OpenFGA API, enabling fine-grained authorization checks, relationship tuple management, and authorization model operations through an async client.
PyMacaroons implements macaroons—bearer credentials with embedded authorization caveats that can be created, serialized, and cryptographically verified.
However, if you require active development, recent Python version support beyond 3.9, or performance-critical use, consider whether libmacaroons bindings or an…
Implements the JOSE family of IETF standards (JWS, JWK, JWA, JWT, JWE) for signing, encrypting, and validating JSON Web Tokens and cryptographic keys in Python.
Fickling is a decompiler, static analyzer, and bytecode rewriter for Python pickle serializations that detects, analyzes, and can reverse-engineer or create malicious pickle and pickle-based files including PyTorch models.
Install it if you load pickle or PyTorch files from any untrusted source.
TUF is a Python reference implementation of The Update Framework specification for securing software update systems against supply chain attacks and repository compromise.
Install it if you need to secure software updates or validate update metadata according to the TUF specification.
Identifies and maps the semantic and syntactic structure of files, including polyglots and embedded files, with a pure-Python libmagic implementation that can replace the `file` command and recursively extract embedded content.
However, the aging maintenance status (204 days since last release, minimal repository activity) and 14 runtime dependencies warrant caution for production use—verify…
An OAuth 2.x client for Python that obtains, refreshes, and revokes tokens from any OAuth2.x/OIDC-compliant Authorization Server, built on top of the requests HTTP library.
However, verify that the specific grant types and extensions you need are supported, and test token refresh behavior in your concurrency model before deploying to…
Pwntools is a CTF framework and exploit development library providing tools for writing exploits, assembling/disassembling code, interacting with remote services, and analyzing binaries.
Install it if you work on exploit development, security research, or CTF challenges; skip it if you don't need those capabilities.
PyMISP is a Python library that connects to MISP platforms via their REST API to fetch, create, update, and search threat intelligence events and attributes.
Install it if you need to automate threat intelligence workflows or integrate MISP into a larger security system.
A Python client library for reading and writing secrets to Cerberus, Nike's secrets management service, with support for AWS IAM and user authentication over HTTPS.
Install only if Cerberus is your organization's active secrets platform.
Implements the W3C PROV Data Model in Python, enabling creation, import, and export of provenance documents in multiple formats including PROV-O, PROV-XML, PROV-JSON, and PROV-JSONLD.
Install it if you need to work with provenance data in a standards-compliant way or integrate with systems that consume PROV documents.
Signs HTTP requests destined for the Veracode API Gateway, handling authentication credentials and request signing automatically.
Certbot is a command-line client that automatically obtains TLS certificates from Let's Encrypt and deploys them to web servers, handling certificate renewal and HTTPS configuration.
Install it if you operate a web server and need to manage HTTPS certificates.
txtorcon is a client library for controlling and monitoring Tor instances via the Tor control protocol, enabling Python programs to manage circuits, streams, relays, and onion services.
Provides read and write access to secrets stored in Robocorp Control Room's Vault, enabling retrieval and management of sensitive values like passwords and credentials.
cedarpy binds the Cedar Policy authorization engine to Python, letting you evaluate access-control policies and validate them against schemas from Python code.
Collects and exports Active Directory information via LDAP in human-readable HTML, JSON, CSV, and greppable formats for domain reconnaissance.
Impacket provides low-level Python classes for constructing and parsing network protocol packets, with particular depth in SMB, MSRPC, LDAP, and Kerberos implementations for Windows network interaction.
However, the maintainers explicitly disclaim production use; apply proper security practices if you use it in any real environment.
Pyarmor obfuscates Python scripts to protect source code, and can bind obfuscated scripts to specific machines or set expiration dates.
However, verify the 'Free To Use But Restricted' license carefully before using it in commercial or open-source projects, and test obfuscated output thoroughly in…
TgCrypto provides fast C-based implementations of AES-256 encryption in IGE, CTR, and CBC modes, designed specifically for Telegram's MTProto protocol and related cryptographic needs.
Python client library for Duo Security's authentication, admin, accounts, and activity APIs, enabling integration with Duo's two-factor authentication and identity management services.
Install it if you need to integrate Duo authentication or identity management into a Python application.
Provides a single function to check whether a hostname is in the Chromium HSTS Preload list, returning True if the host should only be accessed via HTTPS.
Provides prebuilt extension modules required by Pyarmor to obfuscate Python scripts, bind them to specific machines, or set expiration dates on obfuscated code.
However, review the 'Free To Use But Restricted' license terms before using it in production, especially if you plan to distribute obfuscated code commercially.
Integrates bandit security checks into flake8 linting, reporting security issues as flake8 violations with 'S' prefixes instead of the default 'B' codes.
However, the dormant maintenance status (last release August 2022) means you should verify compatibility with your current flake8 and bandit versions before relying…
dissect.target provides a unified API and command-line tools to parse and query data from disk images, file collections, and forensic evidence formats, abstracting away the complexity of multiple underlying Dissect modules.
Official Python client for the VirusTotal REST API v3, enabling file and URL scanning, threat intelligence queries, and security workflow automation.
Wraps Django model fields with transparent encryption using the cryptography library, storing encrypted data in the database while allowing normal field access in Python code.
Parses and analyzes AWS IAM and Resource Policies, extracts principals and conditions, detects internet accessibility, and expands or minifies policy wildcards.
However, note the dormant maintenance status—last release was 988 days ago—so verify compatibility with your AWS policy version and consider whether you need active…
ggshield is a CLI tool that scans files, repositories, Docker images, and PyPI packages to detect more than 500+ types of secrets and potential vulnerabilities using GitGuardian's API.
Install it if your team needs automated secrets detection.
Integrates SAML2 single sign-on authentication into Django applications using the pysaml2 library, enabling federated identity and SSO workflows.
Install it if you need SAML2 SSO integration; skip it if your authentication requirements are simpler (e.g., OAuth2, OIDC, or local users).
CredStash stores and retrieves secrets using AWS KMS for encryption and DynamoDB for storage, providing a simple credential management system for applications and infrastructure.
Scans a project's dependencies to extract their licenses and checks compatibility with the project's own license, reporting results in multiple formats.