Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Open Source Security

Open Source Security

40 projects

Showing 36 of 40 projects

Nuclei
NucleiGo

A fast, customizable vulnerability scanner with a YAML-based DSL, powered by a global security community.

#subdomain-takeover#hacktoberfest#vulnerability-assessment
Stars29.1k
Forks3.5k
Last commit4 days ago
truffleHog
truffleHogGo

A secrets scanning tool that discovers, classifies, validates, and analyzes leaked credentials across multiple sources.

#docker-security#secret#secrets
Stars26.7k
Forks2.4k
Last commit3 days ago
truffleHog
truffleHogGo

A secrets scanning tool that discovers, classifies, validates, and analyzes leaked credentials across multiple sources.

#docker-security#secret#secrets
Stars26.7k
Forks2.4k
Last commit3 days ago
osquery
osqueryC++

A SQL-powered framework for instrumenting, monitoring, and analyzing operating systems across Linux, macOS, and Windows.

#fleet-management#hacktoberfest#thrift-api
Stars23.3k
Forks2.6k
Last commit27 days ago
Cryptomator
CryptomatorJava

A multi-platform desktop application that provides client-side encryption for cloud storage files, ensuring privacy and control.

#crypto#virtual-drive#transparent-encryption
Stars15.2k
Forks1.3k
Last commit3 days ago
setoolkit
setoolkitPython

An open-source penetration testing framework for social engineering with custom attack vectors to create believable attacks quickly.

#attack-framework#social-engineering#kali-linux
Stars14.9k
Forks3.4k
Last commit4 days ago
John The Jumbo
John The JumboC

An advanced offline password cracker supporting hundreds of hash and cipher types across multiple platforms.

#digital-forensics#jtr#john
Stars13.2k
Forks2.5k
Last commit2 days ago
Nmap
NmapC

A free and open-source network discovery and security auditing tool for mapping networks and identifying services.

#vulnerability-assessment#osx#network-discovery
Stars13.0k
Forks2.8k
Last commit5 days ago
Grype
GrypeGo

A vulnerability scanner for container images, filesystems, and SBOMs to detect known security issues.

#container-security#vulnerability#sbom-analysis
Stars12.3k
Forks805
Last commit3 days ago
Clair
ClairGo

Open-source vulnerability static analysis tool for container images (OCI/Docker) via API-based indexing and matching.

#container-security#vulnerabilities#oci
Stars11.0k
Forks1.2k
Last commit5 days ago
Honeypots
HoneypotsPython

A curated list of awesome honeypot resources, tools, and related components for cybersecurity research and defense.

#honeypot#awesome-list#malware-analysis
Stars10.3k
Forks1.3k
Last commit7 days ago
awesome-honeypots
awesome-honeypotsPython

A curated list of free and open-source honeypot resources, tools, and related components for cybersecurity research.

#honeypot#awesome-list#malware-analysis
Stars10.3k
Forks1.3k
Last commit7 days ago
syft
syftGo

A CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems.

#sbom#container-security#cyclonedx
Stars9.1k
Forks869
Last commit1 day ago
Tsunami Security Scanner
Tsunami Security ScannerJava

A general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities.

#high-severity-detection#infrastructure-security#plugin-system
Stars8.6k
Forks922
Last commit3 days ago
OnionShare
OnionSharePython

Securely and anonymously share files, host websites, and chat via the Tor network.

#open-source#tor-onion-service#privacy
Stars7.0k
Forks702
Last commit5 days ago
AFL++
AFL++C

AFL++ is a community-enhanced, high-performance fork of the AFL fuzzer with advanced instrumentation, mutators, and speed improvements.

#software-testing#fuzzer#fuzzer-afl
Stars6.6k
Forks1.3k
Last commit1 day ago
scorecard
scorecardGo

Automated security health metrics for open source projects, assessing security best practices and risks.

#supply-chain-security#security-scanning#openssf-scorecard
Stars5.5k
Forks659
Last commit7 days ago
rayhunter
rayhunterRust

A Rust tool for detecting IMSI catchers (cell-site simulators) on mobile hotspots like the Orbic RC400L.

#imsi-catcher-detection#mobile-hotspot#privacy-tools
Stars5.3k
Forks431
Last commit4 days ago
W3af
W3afPython

An open-source web application security scanner that identifies and exploits 200+ vulnerabilities for developers and penetration testers.

#sql-injection#web-security#cross-site-scripting
Stars4.9k
Forks1.2k
Last commit3 years ago
Santa
SantaObjective-C++

A binary and file access authorization system for macOS that monitors and controls application execution.

#fleet-management#certificate-validation#macos-security
Stars4.5k
Forks287
Last commit1 year ago
scans
scansJavaScript

An open-source Cloud Security Posture Management (CSPM) tool that scans AWS, Azure, GCP, Oracle, and GitHub for security misconfigurations.

#aws-security#compliance-auditing#infrastructure-security
Stars3.7k
Forks744
Last commit3 months ago
Roave Security Advisories
Roave Security Advisories

A Composer package that blocks installation of PHP dependencies with known security vulnerabilities.

#supply-chain-security#composer#devops
Stars2.9k
Forks109
Last commit3 days ago
Bearer
BearerGo

Static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.7k
Forks142
Last commit1 day ago
King Phisher
King PhisherPython

A phishing campaign toolkit for simulating real-world attacks to test and promote user security awareness.

#security-training#social-engineering#self-hosted-security
Stars2.5k
Forks581
Last commit1 month ago
malice.io
malice.ioGo

An open-source malware analysis framework that functions as a self-hosted alternative to VirusTotal.

#virustotal#infosec#malice
Stars1.9k
Forks284
Last commit3 years ago
openscap
openscapXSLT

A command-line toolkit for validating, scanning, and managing SCAP (Security Content Automation Protocol) documents.

#scanning#scap-toolkit#command-line-tool
Stars1.7k
Forks438
Last commit6 days ago
Gatekeeper
GatekeeperC

An open-source, scalable DDoS protection system designed for network operators to withstand high-bandwidth attacks.

#ddos-protection#ddos-mitigation#traffic-management
Stars1.6k
Forks249
Last commit7 months ago
.NET Deobfuscator
.NET Deobfuscator

A curated list of open-source .NET deobfuscators and unpackers for reversing protected assemblies.

#unpacker#dnlib#deobfuscator
Stars1.5k
Forks295
Last commit1 year ago
LunaSec
LunaSecTypeScript

Open-source supply chain security scanner that automatically detects vulnerabilities like Log4Shell in dependencies and notifies via GitHub pull requests.

#supply-chain-security#zero-trust#web-security
Stars1.5k
Forks167
Last commit2 years ago
pip-audit
pip-auditPython

Audits Python environments, requirements files, and dependency trees for known security vulnerabilities and can automatically fix them.

#sbom#vulnerability-management#security
Stars1.3k
Forks99
Last commit10 days ago
SafeDep/vet
SafeDep/vetGo

A CLI tool for real-time malicious package detection and software supply chain security across multiple ecosystems.

#pypi#rubygems#supply-chain-security
Stars1.1k
Forks101
Last commit3 days ago
Terraform cost estimation
Terraform cost estimationjq

Anonymized, secure, and free cost estimation for Terraform infrastructure based on Terraform plan or state files.

#terraform-plans#infrastructure costs#devops-tools
Stars730
Forks63
Last commit3 years ago
Real Intelligence Threat Analysis (RITA)
Real Intelligence Threat Analysis (RITA)Go

An open-source framework for detecting command and control communication through network traffic analysis using Zeek logs.

#security-analytics#beacons#dns-tunneling
Stars573
Forks63
Last commit5 days ago
Starbase
StarbaseTypeScript

Collects assets and relationships from cloud, SaaS, and security systems into a Neo4j graph for security analysis.

#hacktoberfest#graph#security-analysis
Stars359
Forks41
Last commit3 months ago
Apache Spot (incubating)
Apache Spot (incubating)Python

Open-source platform for network security analytics using flow and packet analysis to detect unknown threats at cloud scale.

#security-analytics#telemetry#spot
Stars356
Forks226
Last commit3 years ago
Artillery
Artillery

An open-source blue team tool that protects Linux and Windows operating systems through multiple security methods.

#windows-security#security-hardening#linux-security
Stars339
Forks301
Last commit5 years ago
Page 1 of 2Next

Related Tags

#Security18#Devsecops12#Penetration Testing7#Cybersecurity7#Vulnerability Scanner6#Network Security6#Security Tools6#Cloud Security5#Static Analysis5#Threat Detection5#Docker5#Ci Cd Security5
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub