296 karma · joined October 1, 2012

I'm a computer scientist, intensely interested in computer security and privacy. I contribute to many open source projects since more than 20 years.
* You can read more [about me](https://www.cedricbonhomme.org/about). * Some notable [projects](https://www.cedricbonhomme.org/software) to which I contributed. * More on [https://www.cedricbonhomme.org/blog](https://www.cedricbonhomme.org/blog) * [Fosstodon](https://fosstodon.org/@cedric)
""" Vulnerability Lookup facilitates quick correlation of vulnerabilities from various sources (NIST, GitHub, CSAF, PySec, VARIoT, etc.), independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD). """
https://github.com/cedricbonhomme/IP-Link
(there is a link to the documentation with some nice chord diagrams.) This one is quite impressive: https://github.com/cedricbonhomme/IP-Link/blob/master/docs/_... nut not easy to read !
I stopped reading here. But this will definitely make my day. I won't even start to list examples of companies (private sector, public sector, research, etc.) that are not in this "only entities".
No but seriously I admit it's not a good choice. We will change it to something else. I personally never used Telegram, I do not even know how their Website looks like.
It's the most recent, really in development. It's about scanning IP ranges, looking for vulnerabilities (in MS Exchange Servers and various things) and sending notifications. Some parts are already used for operational stuff (NMAP Script Engines for example).
An other really interesting project, under AGPL as well: https://opensource.nc3.lu/projects/monarc/
"MONARC is an iterative and qualitative method of risk analysis in four stages, broadly inspired by ISO/IEC 27005." ;-)
And maybe this project: https://github.com/NC3-LU/MOSP As you can see it's a collaborative platform to share security related JSON objects. The nice thing is the object editing user interface automatically generated thanks to the JSON schemas. The project provides an API and is connected to every MONARC instances.
This is partly why I did Freshermeat [1]. I am operating an instance dedicated to security projects [2] where you can submit projects.
[1] https://github.com/cedricbonhomme/freshermeat [2] https://open-source-security-software.net
It is now possible to import these items in the MONARC security assessment software:
It is a decentralized service, here is more information: https://www.monarc.lu/documentation/stats-service/master/arc...
And yes, there is an API, which is already integrated with tools such as MONARC (https://github.com/monarc-project/MonarcAppFO).
The API is really easy to use. There is also a client: https://github.com/CASES-LU/PyMOSP
Versioning is planed for the next release.
Some explanations: https://dashboard.monarc.lu/help