Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Security Tools

Security Tools

294 projects

Showing 36 of 287 projects

TorBot
TorBotPython

An open-source intelligence (OSINT) tool for crawling and analyzing websites on the dark web and beyond.

#python-web-crawler#spider#osint
Stars4.1k
Forks675
Last commit4 months ago
vulscan
vulscanLua

An Nmap NSE script that transforms nmap into a vulnerability scanner using offline vulnerability databases.

#vulnerability-assessment#vulnerability#nmap
Stars3.8k
Forks695
Last commit3 months ago
awesome-cve-poc
awesome-cve-poc

A curated collection of proof-of-concept exploits for Common Vulnerabilities and Exposures (CVEs).

#cve#exploit-development#penetration-testing
Stars3.5k
Forks720
Last commit4 years ago
emba
embaShell

An open-source firmware security analyzer for embedded Linux devices, performing extraction, static/dynamic analysis, SBOM generation, and vulnerability reporting.

#iot#sbom#embedded-systems
Stars3.5k
Forks305
Last commit4 days ago
Awesome PCAP Tools
Awesome PCAP Tools

A curated list of open-source tools for capturing, analyzing, and processing network packet captures (PCAP files).

#pcap-tools#open-source#network-forensics
Stars3.4k
Forks473
Last commit9 months ago
BruteShark
BruteSharkC#

A Network Forensic Analysis Tool (NFAT) for deep inspection of PCAP files and live traffic, extracting credentials, building network maps, and reconstructing sessions.

#cyber#network-mapping#session-reconstruction
Stars3.4k
Forks355
Last commit3 years ago
NoSQLMap
NoSQLMapPython

An automated Python tool for auditing and exploiting NoSQL database vulnerabilities and web application injection attacks.

#python-tool#enumeration#vulnerability-assessment
Stars3.3k
Forks626
Last commit3 months ago
DIE
DIEC++

GUI and console sources for Detect It Easy (DiE), a program for determining file types and packers.

#signature#hacktoberfest#gui-tools
Stars3.1k
Forks386
Last commit12 hours ago
sysmon-modular
sysmon-modularPowerShell

A modular repository of Sysmon configuration modules for customizable endpoint detection and logging.

#modular#windows-security#endpoint-detection
Stars3.1k
Forks644
Last commit1 year ago
bundle-audit
bundle-auditRuby

A security audit tool for Ruby projects that checks Gemfile.lock for vulnerable gem versions and insecure sources.

#dependency-checker#patch-management#bundler-audit
Stars2.8k
Forks245
Last commit2 days ago
Bearer
BearerGo

Static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.7k
Forks142
Last commit3 days ago
Bearer
BearerGo

A static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.7k
Forks142
Last commit3 days ago
KICS
KICSOpen Policy Agent

KICS is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code.

#hacktoberfest#kubernetes#security-scanning
Stars2.6k
Forks371
Last commit7 days ago
Keywhiz
KeywhizJava

A system for distributing and managing secrets, now deprecated in favor of HashiCorp Vault.

#enterprise-software#crypto#infrastructure-security
Stars2.6k
Forks213
Last commit2 years ago
APKiD
APKiDYARA

Identifies compilers, packers, obfuscators, and other characteristics in Android APK and DEX files.

#dex#apk-analysis#malware-detection
Stars2.5k
Forks338
Last commit15 days ago
Diamorphine
DiamorphineC

A Linux Kernel Module (LKM) rootkit for hiding processes, granting root privileges, and making files invisible.

#loadable-kernel-module#kernel-module#file-hiding
Stars2.4k
Forks482
Last commit1 month ago
silenttrinity
silenttrinityBoo

A modern, asynchronous, multiplayer command and control (C2) framework for post-exploitation using Python and .NET's DLR.

#red-teams#multi-user-collaboration#boolang
Stars2.3k
Forks427
Last commit2 years ago
xssor2
xssor2JavaScript

A web-based toolkit for XSS (Cross-Site Scripting) testing, encoding/decoding, and payload generation.

#pentest#pentest-tool#web-security
Stars2.2k
Forks381
Last commit4 years ago
Krakatau
KrakatauRust

A Java bytecode assembler, disassembler, and decompiler designed to handle obfuscated code and support the latest JVM specifications.

#java-bytecode#disassembler#assembler
Stars2.2k
Forks235
Last commit2 months ago
PowerTools
PowerToolsPowerShell

A deprecated collection of PowerShell tools for offensive security operations and penetration testing.

#windows-security#red-teaming#penetration-testing
Stars2.2k
Forks815
Last commit4 years ago
gokart
gokartGo

A static analysis tool for Go that finds vulnerabilities using SSA form and source-to-sink tracing to reduce false positives.

#false-positive-reduction#source-to-sink-tracing#static-code-analysis
Stars2.2k
Forks108
Last commit2 years ago
GSIL
GSILPython

Monitor GitHub for sensitive information leaks in near real-time and send alert notifications.

#python-tool#sensitive-data#sensitive-data-detection
Stars2.1k
Forks484
Last commit2 years ago
FakeNet-NG
FakeNet-NGPython

A dynamic network analysis tool that intercepts and simulates network services for malware analysis and penetration testing.

#traffic-interception#gsoc-2026#penetration-testing
Stars2.1k
Forks376
Last commit8 days ago
ReconDog
ReconDogPython

A reconnaissance tool that gathers information about targets using APIs without direct contact.

#honeypot-detector#information-gathering#subdomain-enumeration
Stars2.1k
Forks358
Last commit5 years ago
ghorg
ghorgGo

A CLI tool to clone or backup all repositories from a GitHub/GitLab/Bitbucket organization or user into a single directory.

#go-application#devops#git-cloning
Stars2.1k
Forks182
Last commit3 days ago
reverse-shell
reverse-shellGo

A service that provides easy-to-remember reverse shell payloads for Unix-like systems, automatically detecting available software on the target.

#vulnerability#exploit#unix-shell
Stars2.0k
Forks249
Last commit3 months ago
Pefile
PefilePython

A Python module for parsing and working with Portable Executable (PE) files, providing access to headers, sections, and embedded data.

#portable-executable#python#security-tools
Stars2.0k
Forks537
Last commit21 hours ago
Rekall
RekallPython

An open-source memory forensic framework for extracting and analyzing digital artifacts from Windows, Linux, and OSX memory images.

#digital-forensics#osx-forensics#python
Stars2.0k
Forks403
Last commit5 years ago
Industrial Control System Security
Industrial Control System SecurityPython

A curated collection of tools, data, literature, and resources for Industrial Control System (ICS) and SCADA security.

#industrial-automation#hacktoberfest#vulnerability-assessment
Stars2.0k
Forks475
Last commit
JA4+
JA4+Rust

A suite of network fingerprinting standards for TLS, TCP, HTTP, SSH, and other protocols to facilitate threat detection and security analysis.

#ja3-fingerprint#traffic-analysis#ja4-fingerprint
Stars2.0k
Forks171
Last commit2 days ago
Deepfence PacketStreamer
Deepfence PacketStreamerGo

Distributed tcpdump for cloud native environments, capturing and streaming network packets from multiple hosts to a central receiver.

#suricata#pcap#observability
Stars1.9k
Forks246
Last commit1 year ago
Lockpicking
Lockpicking

A curated list of awesome guides, tools, and resources related to lockpicking, physical security, and locksport.

#physical-security#locksport#locksmith
Stars1.9k
Forks123
Last commit3 years ago
InQL Scanner
InQL ScannerKotlin

A Burp Suite extension for advanced GraphQL security testing, featuring vulnerability scanning, batch attacks, and schema analysis.

#burpsuite#graphql#penetration-testing
Stars1.8k
Forks184
Last commit1 month ago
Hashtopolis
HashtopolisPHP

A multi-platform client-server tool for distributing Hashcat password cracking tasks across multiple computers.

#cracking#hashlist#passwords
Stars1.8k
Forks250
Last commit1 day ago
Awesome Threat Modelling
Awesome Threat ModellingDockerfile

A curated list of threat modeling resources including books, courses, videos, tools, tutorials, and examples for learning and practicing threat modeling.

#owasp#awesome-list#risk-assessment
Stars1.8k
Forks303
Last commit
DevSecOps
DevSecOps

A curated list of DevSecOps tools, resources, and training materials for integrating security into the development lifecycle.

#supply-chain-security#hacktoberfest#security-training
Stars1.7k
Forks241
Last commit1 year ago
PreviousPage 3 of 8

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
7 months ago
1 year ago
Next
#Security84
#Penetration Testing69
#Reverse Engineering65
#Malware Analysis64
#Cybersecurity54
#Python44
#Incident Response39
#Docker34
#Static Analysis34
#Devsecops33
#Binary Analysis29
#Digital Forensics27