Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Security Automation

Security Automation

76 projects

Showing 36 of 76 projects

PSRecon
PSReconPowerShell

A PowerShell script for live forensic data acquisition and endpoint lockdown during Windows incident response.

#digital-forensics#windows-security#security-automation
Stars495
Forks106
Last commit9 years ago
cloud-inquisitor
cloud-inquisitorPython

A security tool for AWS that enforces resource ownership, detects domain hijacking, and verifies security services.

#cloudtrail#aws-security#multi-account-management
Stars446
Forks38
Last commit6 years ago
SOC Multi-tool
SOC Multi-toolJavaScript

A browser extension that streamlines security investigations by providing quick lookups for IPs, domains, hashes, and other indicators.

#security-investigation#browser-extension#ioc-analysis
Stars422
Forks55
Last commit
Safe
SafeGo

A command-line interface for HashiCorp Vault that simplifies secret generation, management, and secure credential handling.

#vault-cli#security-automation#cli-tool
Stars421
Forks33
Last commit2 years ago
Cuckoo-modified
Cuckoo-modifiedPython

A modified fork of Cuckoo Sandbox with enhanced malware analysis capabilities, improved stability, and additional features.

#sandbox#behavioral-analysis#security-automation
Stars406
Forks175
Last commit
Hashview
HashviewPython

A web-based platform for organizing, automating, and analyzing password cracking tasks using Hashcat.

#security-analytics#distributed#flask
Stars397
Forks52
Last commit1 day ago
malsub
malsubPython

A Python RESTful API framework for querying multiple online malware analysis and threat intelligence services.

#virustotal#multi-threading#security-automation
Stars366
Forks78
Last commit2 years ago
crowdsec-blocklist-import
crowdsec-blocklist-importPython

Import 28+ threat intelligence feeds into CrowdSec with automatic deduplication, normalization, and real-time sync.

#self-hosted-security#security-automation#tor-exit-nodes
Stars348
Forks13
Last commit
Detection and Response Pipeline
Detection and Response Pipeline

A curated reference hub of tools and real-world examples for designing effective threat detection and response pipelines.

#security-reference#self-hosted-security#security-automation
Stars298
Forks25
Last commit2 years ago
File Scanning Framework
File Scanning FrameworkPython

A modular, recursive file scanning framework that extends Yara signatures to extract and analyze file objects for malware analysis and intelligence.

#file-analysis#security-automation#file-scanning
Stars294
Forks46
Last commit
PSHunt
PSHuntPowerShell

A PowerShell module for remote endpoint threat hunting, scanning for indicators of compromise and collecting system state information.

#digital-forensics#windows-security#security-automation
Stars293
Forks63
Last commit10 years ago
Hostintel
HostintelPython

A modular Python tool that collects threat intelligence for hosts (IPs, domains, FQDNs) from multiple sources and outputs CSV data.

#csv-output#osint#security-automation
Stars274
Forks54
Last commit5 years ago
AutoTTP
AutoTTPPython

A framework for automating offensive security testing by scripting security tool APIs like Empire and Metasploit.

#procedure#cobalt-strike#ttp-automation
Stars262
Forks65
Last commit3 years ago
CIFv2
CIFv2Perl

A deprecated threat intelligence platform for collecting, processing, and sharing security indicators.

#security-automation#open-source-intel#ioc-management
Stars230
Forks60
Last commit8 years ago
ioc_writer
ioc_writerPython

Python library for creating, editing, and managing OpenIOC objects for threat intelligence indicators.

#python-library#security-automation#ioc-management
Stars207
Forks60
Last commit3 years ago
gonids
gonidsGo

A Go library for parsing and manipulating Snort and Suricata IDS/IPS rules with Suricata compatibility focus.

#parse#suricata#ids
Stars198
Forks50
Last commit1 month ago
SpiderFoot
SpiderFootPython

SpiderFoot is an open-source intelligence (OSINT) automation platform that integrates with 309+ data sources for threat intelligence and attack surface mapping.

#fastapi#osint#graphql
Stars195
Forks31
Last commit2 months ago
SDLC Infrastructure Threat Framework (SITF)
SDLC Infrastructure Threat Framework (SITF)HTML

A framework for analyzing and defending against supply chain attacks targeting Software Development Lifecycle infrastructure.

#supply-chain-security#attack-framework#vcs-security
Stars179
Forks18
Last commit
Phishing Intelligence Engine (PIE)
Phishing Intelligence Engine (PIE)PowerShell

An Active Defense PowerShell framework for detecting and responding to phishing attacks in Office 365 environments.

#logrhythm-integration#sandbox-analysis#active-defense
Stars179
Forks53
Last commit
Aleph
AlephCSS

An open-source malware analysis pipeline system that automates sample collection, processing, and JSON-based artifact storage.

#sample-processing#security-automation#python
Stars158
Forks53
Last commit5 years ago
CIRTKit
CIRTKitPython

A unified console for digital forensics and incident response built on the Viper Framework.

#digital-forensics#viper-framework#security-automation
Stars153
Forks23
Last commit9 years ago
autocrack
autocrackPython

A Python wrapper for Hashcat that automates password cracking workflows with wordlist management and brute-force attacks.

#security-automation#penetration-testing#wordlist-management
Stars128
Forks34
Last commit
Posh-VirusTotal
Posh-VirusTotalPowerShell

A PowerShell module for interacting with VirusTotal's API to analyze suspicious files, URLs, domains, and IP addresses.

#security-automation#file-scanning#malware-analysis
Stars124
Forks29
Last commit6 years ago
MalPipe
MalPipePython

A modular malware and IOC ingestion framework that collects, enriches, and exports threat intelligence from multiple feeds.

#security-automation#security-tools#malware-analysis
Stars110
Forks22
Last commit7 years ago
DATA
DATAPython

A toolkit for analyzing credential phishing sites by automating screenshot capture, file scraping, form interaction, and PDF URL extraction.

#pdf-analysis#screenshot-capture#security-automation
Stars99
Forks28
Last commit8 years ago
Honeypot (Dionaea and kippo) setup script
Honeypot (Dionaea and kippo) setup scriptShell

Automated script to install and configure Dionaea and Kippo honeypots as system services on Ubuntu.

#system-services#honeypot#kippo
Stars83
Forks34
Last commit9 years ago
modpot
modpotHTML

A modular web application honeypot framework written in Go and Gin for detecting web attacks through deceptive applications.

#honeypot#web-security#cyber-threat-intelligence
Stars63
Forks2
Last commit2 years ago
MutableSecurity
MutableSecurityPython

A CLI program for automating the deployment, configuration, and monitoring of cybersecurity solutions across multiple hosts.

#devops#security-automation#incident-response-tooling
Stars50
Forks7
Last commit3 years ago
PowerSponse
PowerSponsePowerShell

A PowerShell module for targeted containment and remediation during incident response, enabling remote cleanup of malware artifacts.

#windows-security#security-automation#powershell
Stars40
Forks7
Last commit4 years ago
IOCmite
IOCmitePython

Synchronizes threat intelligence indicators from MISP to Suricata datasets and sends alert sightings back to MISP.

#suricata#security-automation#sightings
Stars37
Forks3
Last commit3 years ago
suricataparser
suricataparserPython

A pure Python parser and generator for Snort and Suricata intrusion detection rules.

#suricata#suricata-rule#ids
Stars35
Forks12
Last commit2 years ago
terraform-provider-sigsci
terraform-provider-sigsciGo

A Terraform provider for managing Signal Sciences web application firewall and security monitoring resources.

#devops-security#security-automation#terraform-provider
Stars26
Forks35
Last commit
cuckoo-modified-api
cuckoo-modified-apiPython

A Python library for interfacing with the cuckoo-modified malware sandbox via its API.

#digital-forensics#python-library#security-automation
Stars23
Forks8
Last commit9 years ago
simpleserver
simpleserverShell

Zsh plugin providing shortcuts for Metasploit Framework payload generation and Python HTTP server setup.

#oh-my-zsh-plugin#command-line-tools#security-automation
Stars14
Forks1
Last commit8 years ago
detection
detectionYARA

A collection of open-source threat detection rules for Snort, Sigma, and Yara security tools.

#yara-rules#sigma-rules#security-automation
Stars14
Forks1
Last commit2 years ago
go-suricata
go-suricataGo

A Go client library for interacting with Suricata's Unix socket to execute commands and retrieve data.

#suricata#unix-socket#client
Stars13
Forks1
Last commit6 years ago
PreviousPage 2 of 3

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
1 year ago
8 years ago
4 days ago
5 years ago
1 month ago
6 years ago
8 years ago
2 months ago
Next
#Incident Response30
#Cybersecurity25
#Threat Intelligence21
#Python18
#Security Tools18
#Malware Analysis14
#Security13
#Security Operations11
#Threat Hunting10
#Penetration Testing10
#Network Security9
#Intrusion Detection8