Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Security Tools

Security Tools

119 projects

Showing 36 of 119 projects

TorBot
TorBotPython

An open-source intelligence (OSINT) tool for crawling and analyzing websites on the dark web and beyond.

#python-web-crawler#spider#osint
Stars4.0k
Forks668
Last commit3 months ago
vulscan
vulscanLua

An Nmap NSE script that transforms nmap into a vulnerability scanner using offline vulnerability databases.

#vulnerability-assessment#vulnerability#nmap
Stars3.7k
Forks692
Last commit2 months ago
awesome-cve-poc
awesome-cve-poc

A curated collection of proof-of-concept exploits for Common Vulnerabilities and Exposures (CVEs).

#cve#exploit-development#penetration-testing
Stars3.5k
Forks722
Last commit4 years ago
emba
embaShell

An open-source firmware security analyzer for embedded Linux devices, performing extraction, static/dynamic analysis, SBOM generation, and vulnerability reporting.

#iot#sbom#embedded-systems
Stars3.4k
Forks299
Last commit3 days ago
Awesome PCAP Tools
Awesome PCAP Tools

A curated list of open-source tools for capturing, analyzing, and processing network packet captures (PCAP files).

#pcap-tools#open-source#network-forensics
Stars3.4k
Forks475
Last commit7 months ago
BruteShark
BruteSharkC#

A Network Forensic Analysis Tool (NFAT) for deep inspection of PCAP files and live traffic, extracting credentials, building network maps, and reconstructing sessions.

#cyber#network-mapping#session-reconstruction
Stars3.4k
Forks355
Last commit3 years ago
NoSQLMap
NoSQLMapPython

An automated Python tool for auditing and exploiting NoSQL database vulnerabilities and web application injection attacks.

#python-tool#enumeration#vulnerability-assessment
Stars3.3k
Forks624
Last commit2 months ago
DIE
DIEC++

GUI and console sources for Detect It Easy (DiE), a program for determining file types and packers.

#signature#hacktoberfest#gui-tools
Stars3.0k
Forks380
Last commit2 days ago
sysmon-modular
sysmon-modularPowerShell

A modular repository of Sysmon configuration modules for customizable endpoint detection and logging.

#modular#windows-security#endpoint-detection
Stars3.0k
Forks644
Last commit1 year ago
bundle-audit
bundle-auditRuby

A security audit tool for Ruby projects that checks Gemfile.lock for vulnerable gem versions and insecure sources.

#dependency-checker#patch-management#bundler-audit
Stars2.7k
Forks245
Last commit4 months ago
Bearer
BearerGo

A static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.6k
Forks143
Last commit4 days ago
Bearer
BearerGo

Static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.6k
Forks143
Last commit4 days ago
Keywhiz
KeywhizJava

A system for distributing and managing secrets, now deprecated in favor of HashiCorp Vault.

#enterprise-software#crypto#infrastructure-security
Stars2.6k
Forks213
Last commit2 years ago
KICS
KICSOpen Policy Agent

KICS is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code.

#hacktoberfest#kubernetes#security-scanning
Stars2.6k
Forks363
Last commit2 days ago
APKiD
APKiDYARA

Identifies compilers, packers, obfuscators, and other characteristics in Android APK and DEX files.

#dex#apk-analysis#malware-detection
Stars2.5k
Forks335
Last commit14 days ago
silenttrinity
silenttrinityBoo

A modern, asynchronous, multiplayer command and control (C2) framework for post-exploitation using Python and .NET's DLR.

#red-teams#multi-user-collaboration#boolang
Stars2.3k
Forks427
Last commit2 years ago
Diamorphine
DiamorphineC

A Linux Kernel Module (LKM) rootkit for hiding processes, granting root privileges, and making files invisible.

#loadable-kernel-module#kernel-module#file-hiding
Stars2.3k
Forks480
Last commit1 month ago
xssor2
xssor2JavaScript

A web-based toolkit for XSS (Cross-Site Scripting) testing, encoding/decoding, and payload generation.

#pentest#pentest-tool#web-security
Stars2.2k
Forks380
Last commit4 years ago
Krakatau
KrakatauRust

A Java bytecode assembler, disassembler, and decompiler designed to handle obfuscated code and support the latest JVM specifications.

#java-bytecode#disassembler#assembler
Stars2.2k
Forks235
Last commit17 days ago
PowerTools
PowerToolsPowerShell

A deprecated collection of PowerShell tools for offensive security operations and penetration testing.

#windows-security#red-teaming#penetration-testing
Stars2.2k
Forks815
Last commit4 years ago
gokart
gokartGo

A static analysis tool for Go that finds vulnerabilities using SSA form and source-to-sink tracing to reduce false positives.

#false-positive-reduction#source-to-sink-tracing#static-code-analysis
Stars2.2k
Forks108
Last commit2 years ago
GSIL
GSILPython

Monitor GitHub for sensitive information leaks in near real-time and send alert notifications.

#python-tool#sensitive-data#sensitive-data-detection
Stars2.1k
Forks485
Last commit2 years ago
FakeNet-NG
FakeNet-NGPython

A dynamic network analysis tool that intercepts and simulates network services for malware analysis and penetration testing.

#traffic-interception#gsoc-2026#penetration-testing
Stars2.1k
Forks379
Last commit22 days ago
reverse-shell
reverse-shellGo

A service that provides easy-to-remember reverse shell payloads for Unix-like systems, automatically detecting available software on the target.

#vulnerability#exploit#unix-shell
Stars2.0k
Forks246
Last commit2 months ago
ReconDog
ReconDogPython

A reconnaissance tool that gathers information about targets using APIs without direct contact.

#honeypot-detector#information-gathering#subdomain-enumeration
Stars2.0k
Forks354
Last commit5 years ago
Pefile
PefilePython

A Python module for parsing and working with Portable Executable (PE) files, providing access to headers, sections, and embedded data.

#portable-executable#python#security-tools
Stars2.0k
Forks540
Last commit2 days ago
ghorg
ghorgGo

A CLI tool to clone or backup all repositories from a GitHub/GitLab/Bitbucket organization or user into a single directory.

#go-application#devops#git-cloning
Stars2.0k
Forks181
Last commit2 days ago
Rekall
RekallPython

An open-source memory forensic framework for extracting and analyzing digital artifacts from Windows, Linux, and OSX memory images.

#digital-forensics#osx-forensics#python
Stars2.0k
Forks404
Last commit5 years ago
Industrial Control System Security
Industrial Control System SecurityPython

A curated collection of tools, data, literature, and resources for Industrial Control System (ICS) and SCADA security.

#industrial-automation#hacktoberfest#vulnerability-assessment
Stars1.9k
Forks471
Last commit6 months ago
Deepfence PacketStreamer
Deepfence PacketStreamerGo

Distributed tcpdump for cloud native environments, capturing and streaming network packets from multiple hosts to a central receiver.

#suricata#pcap#observability
Stars1.9k
Forks247
Last commit1 year ago
JA4+
JA4+Rust

A suite of network fingerprinting standards for TLS, TCP, HTTP, SSH, and other protocols to facilitate threat detection and security analysis.

#ja3-fingerprint#traffic-analysis#ja4-fingerprint
Stars1.9k
Forks168
Last commit4 days ago
Lockpicking
Lockpicking

A curated list of awesome guides, tools, and resources related to lockpicking, physical security, and locksport.

#physical-security#locksport#locksmith
Stars1.9k
Forks125
Last commit3 years ago
InQL Scanner
InQL ScannerKotlin

A Burp Suite extension for advanced GraphQL security testing, featuring vulnerability scanning, batch attacks, and schema analysis.

#burpsuite#graphql#penetration-testing
Stars1.8k
Forks183
Last commit2 days ago
Awesome Threat Modelling
Awesome Threat ModellingDockerfile

A curated list of threat modeling resources including books, courses, videos, tools, tutorials, and examples for learning and practicing threat modeling.

#owasp#awesome-list#risk-assessment
Stars1.7k
Forks301
Last commit1 year ago
Hashtopolis
HashtopolisPHP

A multi-platform client-server tool for distributing Hashcat password cracking tasks across multiple computers.

#cracking#hashlist#passwords
Stars1.7k
Forks249
Last commit3 days ago
Graudit
GrauditShell

A grep-based source code auditing tool that finds potential security flaws using signature databases for multiple programming languages.

#multi-language-support#code-security#security-tooling
Stars1.7k
Forks256
Last commit4 months ago
PreviousPage 3 of 4Next

Related Tags

#Security48#Penetration Testing36#Cybersecurity30#Devsecops25#Reverse Engineering22#Docker19#Static Analysis19#Awesome List17#Awesome17#Malware Analysis16#Incident Response14#Pentesting12
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub