Skip to content
@EnableSecurity

Enable Security

Offensive security tools and quality penetration testing to help protect your real-time communications systems against attack.

Enable Security

We specialize in security for real-time communications: VoIP and WebRTC systems.

What we do

  • Penetration testing for VoIP and WebRTC systems - toll fraud, oS, oT, oR exploitation
  • DDoS resilience testing for RTC infrastructure
  • Fuzzing and code review for SIP, RTP, and WebRTC implementations
  • Security consultancy for VoIP, WebRTC vendors and providers

Open source tools

  • SIPVicious - VoIP/SIP security testing toolset
  • WAFW00F - Web Application Firewall fingerprinting tool
  • Awesome RTC Hacking - curated security resources for VoIP, WebRTC, and VoLTE
  • DVRTC - intentionally vulnerable VoIP/WebRTC lab for security training and research

Research

We publish security advisories in https://www.enablesecurity.com/advisories/ and pentest reports in enablesecurity/reports.

The Enable Security blog covers our research and updates.

The RTCSec Newsletter covers real-time communications security news monthly.

Get in touch

Pinned Loading

  1. DVRTC DVRTC Public

    DVRTC (Damn Vulnerable Real-Time Communications) is an intentionally vulnerable VoIP/WebRTC platform for security training and research, with isolated lab scenarios covering SIP enumeration, digest…

    JavaScript 30 3

  2. sipvicious sipvicious Public

    SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks…

    Python 1.1k 186

  3. awesome-rtc-hacking awesome-rtc-hacking Public

    a list of awesome resources related to security and hacking of VoIP, WebRTC and VoLTE

    553 52

  4. wafw00f wafw00f Public

    WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

    Python 6.5k 1.1k

  5. reports reports Public

    Reports issued by Enable Security

    11

  6. Vulnerability-Disclosure-Policy Vulnerability-Disclosure-Policy Public

    How Enable Security handles security vulnerabilities

    10 2

Repositories

Showing 10 of 19 repositories
  • sipvicious Public

    SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks against PBX systems especially through identification, scanning, extension enumeration and password cracking.

    EnableSecurity/sipvicious's past year of commit activity
    Python 1,100 186 0 0 Updated Jul 10, 2026
  • awesome-rtc-hacking Public

    a list of awesome resources related to security and hacking of VoIP, WebRTC and VoLTE

    EnableSecurity/awesome-rtc-hacking's past year of commit activity
    553 CC0-1.0 52 0 0 Updated Jun 30, 2026
  • coturn-secure-config Public

    Secure configuration templates for coturn TURN server with Docker test environment

    EnableSecurity/coturn-secure-config's past year of commit activity
    Python 3 2 0 0 Updated Jun 26, 2026
  • DVRTC Public

    DVRTC (Damn Vulnerable Real-Time Communications) is an intentionally vulnerable VoIP/WebRTC platform for security training and research, with isolated lab scenarios covering SIP enumeration, digest leaks, RTP bleed, SQL injection, XSS, and TURN relay abuse.

    EnableSecurity/DVRTC's past year of commit activity
    JavaScript 30 3 0 0 Updated Jun 17, 2026
  • .github Public
    EnableSecurity/.github's past year of commit activity
    0 0 0 0 Updated Apr 21, 2026
  • wafw00f Public

    WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

    EnableSecurity/wafw00f's past year of commit activity
    Python 6,537 BSD-3-Clause 1,055 0 0 Updated Apr 19, 2026
  • ASVS Public Forked from OWASP/ASVS

    Application Security Verification Standard

    EnableSecurity/ASVS's past year of commit activity
    HTML 1 CC-BY-SA-4.0 860 0 0 Updated Feb 25, 2026
  • advisories Public

    Security advisories published by Enable Security

    EnableSecurity/advisories's past year of commit activity
    Python 44 15 0 0 Updated Feb 3, 2026
  • kamailio Public Forked from kamailio/kamailio

    Kamailio - The Open Source SIP Server for large VoIP and real-time communication platforms -

    EnableSecurity/kamailio's past year of commit activity
    C 1 1,154 0 0 Updated Nov 5, 2025
  • Vulnerability-Disclosure-Policy Public

    How Enable Security handles security vulnerabilities

    EnableSecurity/Vulnerability-Disclosure-Policy's past year of commit activity
    10 2 0 0 Updated Apr 22, 2025

Top languages

Loading…

Most used topics

Loading…