# mikeroyal/Open-Source-Security-Guide

Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

Repository: https://github.com/mikeroyal/Open-Source-Security-Guide
Canonical: https://ross.abutalabs.com/products/open-source-security-guide
Language: Go
License Family: other
Topics: vulnerabilities, vulnerability-detection, privacy-protection, pentesters, network-analysis, intrusion-detection, infosec, incident-management, mitre-attack, detection-engineering, kali-linux, offensive-security, information-security, siem, compliance, cyber-security, scanning-tool, incident-response, forensics-tools, surveillance
Last push: 2025-06-27T02:09:36+00:00

## Health v2 (maintenance only)
Score: 45/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 28, release rhythm 35, longevity 100
- inputs: {"age_days": 2146, "days_push": 433, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1106, forks 104 (observed 2026-08-28T04:03:36.481701+00:00)

## What it is
A curated open-source guide to security covering standards (FIPS, CIS, FedRAMP, FISMA), frameworks, threat models, encryption, benchmarks, and security tools. It is a reference document linking tutorials, certifications, books, and tooling for securing systems and networks.

## Use cases
- learn about security standards like FIPS, CIS, FedRAMP and FISMA
- find open-source security tools for hardening systems
- study threat models and encryption basics
- prepare for security certifications
- build a SIEM or incident response workflow
- explore penetration testing and forensics resources

## When to choose
- you want a curated starting point for learning information security
- you need references to security standards, frameworks, and benchmarks
- you are compiling a toolchain for security operations or compliance

## When to avoid
- you need runnable software rather than a reading list
- you require in-depth step-by-step training for a specific certification
- you need guaranteed up-to-date or officially maintained content

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, documentation, developer-tools
- domain: security, developer-tools, awesome-lists, tutorials
- platform: cross-platform
- tags: awesome-list, infosec, cybersecurity, compliance, threat-modeling, encryption, siem, incident-response, penetration-testing, curated-guide

## Member repositories
- mikeroyal/Open-Source-Security-Guide (main) score 45

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:36.481701+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:44:15.685640+00:00, confidence not recorded.
  - readme: https://github.com/mikeroyal/Open-Source-Security-Guide (fetched 2026-08-28T04:03:36.481701+00:00, sha 845918be0003)
- Data as of 2026-08-30T08:39:29.467469+00:00.
