Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Security Tools

Security Tools

386 projects

Showing 36 of 386 projects

galah
galahGo

An LLM-powered web honeypot that dynamically crafts realistic HTTP responses to mimic various applications and detect malicious traffic.

#api-caching#http-server#suricata
Stars656
Forks67
Last commit1 year ago
MultiScanner
MultiScannerPython

A modular file scanning and analysis framework that automates running a suite of tools and aggregates their output.

#scanning#file-analysis#malware-analytics
Stars620
Forks127
Last commit6 years ago
CuckooDroid
CuckooDroidPython

An extension of Cuckoo Sandbox that adds automated Android malware analysis capabilities for executing and analyzing Android applications.

#mobile-security#android-security#cuckoo-sandbox
Stars608
Forks134
Last commit5 years ago
Awesome Bluetooth Security
Awesome Bluetooth Security

A curated list of Bluetooth security resources covering vulnerabilities, tools, research, and conference talks for BR/EDR, LE, and Mesh.

#conference-talks#bluetooth-hacking#bluetooth-security
Stars607
Forks60
Last commit9 months ago
owasp-threat-dragon-desktop
owasp-threat-dragon-desktopCSS

A free, open-source, cross-platform desktop application for threat modeling with system diagramming and automated threat generation.

#desktop-application#automated-threats#owasp
Stars591
Forks88
Last commit
graphql-armor
graphql-armorTypeScript

A customizable security middleware for Apollo GraphQL, Yoga, and Envelop GraphQL servers.

#hacktoberfest#dos-protection#graphql
Stars586
Forks51
Last commit1 day ago
binbloom
binbloomC

Analyzes raw binary firmware to automatically detect loading address, endianness, and UDS command databases.

#embedded-systems#uds-protocol#endianness-detection
Stars583
Forks61
Last commit2 years ago
Nauz File Detector
Nauz File DetectorC++

A portable utility that identifies linkers, compilers, and packers used to create executable files across Windows, Linux, and macOS.

#signature#hacktoberfest#portable-utility
Stars578
Forks83
Last commit1 day ago
RAUDI
RAUDIPython

Automatically generates and updates Docker images for tools lacking official images using GitHub Actions.

#netsec#containerization#devops
Stars559
Forks33
Last commit3 days ago
Insider CLI
Insider CLIGo

A static application security testing (SAST) CLI tool that scans source code for OWASP Top 10 vulnerabilities across multiple programming languages.

#multi-language#owasp#ios-security
Stars552
Forks80
Last commit4 years ago
rshijack
rshijackRust

A TCP connection hijacking tool written in Rust, enabling packet injection into established connections.

#tcp-hijacking#ctf-tools#tcp
Stars540
Forks44
Last commit1 year ago
PortEx
PortExScala

A Java library for static malware analysis of Portable Executable files with robust handling of malformations.

#java-library#portable-executable#entropy-calculation
Stars532
Forks91
Last commit3 months ago
JShell
JShellPython

A tool that creates a JavaScript shell payload for exploiting XSS vulnerabilities to execute code in a victim's browser.

#web-security#javascript-shell#penetration-testing
Stars531
Forks133
Last commit7 years ago
Androwarn
AndrowarnHTML

A static code analyzer that detects and reports potential malicious behaviors in Android applications.

#androguard#privacy-audit#apk-analysis
Stars531
Forks164
Last commit6 years ago
VMCloak
VMCloakPython

Automated tool for creating and preparing virtual machines for Cuckoo Sandbox malware analysis.

#windows-vms#virtual-machine#cuckoo-sandbox
Stars520
Forks128
Last commit2 years ago
FastIR Collector
FastIR CollectorPython

Collects Windows forensic artifacts to detect early system compromises through analysis of live data.

#digital-forensics#python-tool#csv-output
Stars520
Forks129
Last commit5 years ago
FwAnalyzer
FwAnalyzerGo

a tool to analyze filesystem images for security

#filesystem#security-automation#android
Stars516
Forks78
Last commit2 years ago
CCF-VM
CCF-VMShell

An open-source platform for collecting, processing, and analyzing forensic artifacts from macOS, Windows, and Linux systems.

#digital-forensics#dfir#forensic-analysis
Stars514
Forks81
Last commit3 years ago
princeprocessor
princeprocessorC

A standalone password candidate generator implementing the PRINCE algorithm for advanced password cracking attacks.

#prince-algorithm#password-recovery#security-tools
Stars500
Forks106
Last commit2 years ago
ir-rescue
ir-rescueBatchfile

A Windows Batch and Unix Bash script suite for comprehensive host forensic data collection during incident response.

#batch-script#digital-forensics#sysinternals
Stars489
Forks92
Last commit5 years ago
Bitscout
BitscoutShell

A customizable live OS constructor tool written in Bash for remote forensics, malware hunting, and incident response.

#digital-forensics#bootable-media#remote-forensics
Stars480
Forks109
Last commit1 year ago
clem9669 rules
clem9669 rules

A collection of hashcat and John the Ripper rules for password cracking, optimized for common password generation patterns.

#john#john-rules#penetration-testing
Stars471
Forks47
Last commit1 year ago
ArduinoPcap
ArduinoPcapC++

An Arduino library for creating and sending .pcap files from ESP8266/ESP32 to Wireshark for WiFi packet capture and analysis.

#embedded-systems#library#esp32
Stars461
Forks96
Last commit2 years ago
nano
nanoPHP

A family of extremely stealthy, code-golfed PHP webshells designed for undetectable remote command execution.

#code-golf#mini-shell#tiny-shell
Stars449
Forks91
Last commit6 years ago
Puma Scan
Puma ScanC#

A Visual Studio extension for real-time .NET secure code analysis that displays vulnerabilities as compiler warnings.

#secure-coding#static-code-analysis#vulnerability-detection
Stars449
Forks78
Last commit10 days ago
Webshell-Sniper
Webshell-SniperPython

A command-line tool for managing webshells on compromised web servers via terminal.

#webshell-sniper#pentest#terminal-utility
Stars423
Forks110
Last commit28 days ago
drltrace
drltraceHTML

A dynamic API calls tracer for Windows and Linux applications, built on DynamoRIO for transparent malware analysis.

#dynamorio#dbi#malware-detection
Stars419
Forks71
Last commit6 years ago
Awesome Kubernetes (K8s) Threat Detection
Awesome Kubernetes (K8s) Threat Detection

A curated list of resources for detecting threats and defending Kubernetes systems.

#container-security#cloud-native-security#security-hardening
Stars409
Forks44
Last commit2 years ago
pantagrule
pantagrule

Large hashcat rulesets generated from real-world compromised passwords to improve password cracking effectiveness.

#passwords#rulesets#penetration-testing
Stars401
Forks56
Last commit5 years ago
Pyew
PyewPython

A command-line Python tool for malware analysis with hex viewing, disassembly, file format support, and plugin architecture.

#python-tool#disassembly#command-line-tool
Stars395
Forks94
Last commit6 years ago
Heralding
HeraldingPython

Credentials catching honeypot

#honeypot#security#security-tools
Stars394
Forks78
Last commit2 years ago
go-yara
go-yaraGo

Go bindings for the YARA pattern matching library, providing a Go-native interface to YARA's C API.

#hacktoberfest#cgo#go-bindings
Stars389
Forks113
Last commit1 year ago
Polichombr
PolichombrPython

A collaborative malware analysis framework for storing samples, automating analysis, and sharing insights via IDA Pro integration.

#flask#ida#python
Stars383
Forks60
Last commit7 years ago
crackerjack
crackerjackPython

A web GUI for Hashcat that provides session management, notifications, and a multi-user interface for password cracking.

#penetration-testing#python#security-tools
Stars378
Forks93
Last commit2 years ago
DarunGrim
DarunGrim

A binary diffing and patch analysis tool for reverse engineering and vulnerability research.

#binary-diffing#vulnerability-research#security-tools
Stars365
Forks66
Last commit6 years ago
Credential Digger
Credential DiggerPython

A GitHub scanning tool that identifies hardcoded credentials and filters false positives using machine learning models.

#hardcoded-credentials#regex#vscode-extension
Stars365
Forks54
Last commit4 months ago
PreviousPage 6 of 11

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
5 months ago
Next
#Security101
#Penetration Testing90
#Malware Analysis84
#Reverse Engineering78
#Cybersecurity65
#Python64
#Incident Response46
#Docker38
#Binary Analysis37
#Static Analysis36
#Devsecops35
#Digital Forensics32