Skip to main content

Category · 150 repos

Security & Pentesting

Offensive and defensive security: pentesting, scanning, crypto, auth and OSINT. Ranked by star velocity over the last 24 hours.

Showing 101–150 of 150

101
oioio-space/maldev

Pure-Go offensive-security primitives library: syscalls, evasion (AMSI/ETW/unhook/sleepmask), injection, PE packer, credentials, post-ex, C2. MITRE ATT&CK mapped. Authorized research only.

GoSecurity & Pentesting
102
ramyar89068-code/Cyber-shield1

“Python-based cybersecurity project for detecting and blocking malicious websites.”

PythonSecurity & Pentesting
103
samugit83/redamon

Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and opens PRs that fix what it finds. MCP both ways: plug in any MCP server as a tool, or drive RedAmon from Claude Code or your o

PythonSecurity & PentestingMCP Servers & Tools
104
sdushantha/dora

Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

PythonSecurity & Pentesting
105
thesp0nge/dawnscanner

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

RubySecurity & PentestingWeb Frameworks & Backend
106
xm1k3/cent

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place

GoSecurity & Pentesting
107
InfoSecWarrior/Offensive-Pentesting-Web

A proper approach to pentest a Web application with the mixture of all useful payloads and complete testing guidance of attacks. Designed as a quick reference cheat sheet for your pentesting and bug bounty engagement.

Security & PentestingAwesome Lists & Learning
108
NuGuardAI/nuguard

AI red-teaming tool and LLM security framework to evaluate agentic AI applications. Tests prompt injections, handles vulnerability assessment, SBOM generation, and static analysis.

PythonSecurity & PentestingAI Safety & Red Teaming
109
chaos-03x/dsh-agy

Google Antigravity (agy) OAuth auth + model access plugin for DeepSeek Harness: multi-account pool, 429 rotation, device fingerprinting, CLI and web login.

TypeScriptSecurity & PentestingCLI & Developer Tools
110
hxyz486/dsh-forensics-preset

DSH digital forensics agent preset - based on Liang Shen mode, designed specifically for the Honglian Huoyan GoldenEyes V4 forensics competition

JavaScriptSecurity & Pentesting
111
injekt666/Bypass-AMSI9000

Bypasses Microsoft's Anti-Malware Scan Interface for a PowerShell session process started through the "Start-Job" cmdlet, the PID of which is accessed using "Enter-PSHostProcess".

PowerShellSecurity & Pentesting
112
l3montree-dev/devguard

DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project

GoSecurity & PentestingWeb Frameworks & Backend
113
mukul975/cve-mcp-server

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.

PythonSecurity & PentestingMCP Servers & Tools
114
owasp-noir/noir

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

CrystalSecurity & Pentesting
115
HunxByts/INSTA-OSINT

is a tool to find as much information as possible on Instagram accounts, such as username, full username, post target, account type, number of followers, number of followings and so on.

PythonSecurity & PentestingMobile & Desktop Apps
116
anasansari01/oAuth

Authentication system implementing OAuth for secure third-party login and authorization.

JavaScriptSecurity & Pentesting
117
djkurlander/knock-knock

Knock-Knock: A Live, Multi-Protocol Honeypot Dashboard of Internet Break-in Attempts - 13 Protocols, an Extensible Framework, and a Threat-Intelligence Database Serving a Public IP Blocklist Feed

PythonSecurity & Pentesting
118
wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

C++Security & PentestingMonitoring & Observability
119
Anime4000/RTL960x

Hacking & Reverse Engineering RTL960x-based xPON ONTs to suit your OLT

Classic ASPSecurity & PentestingSystems, Compilers & Build Tools
120
HacxGPT-Official/HacxGPT-CLI

Open-source CLI for unrestricted AI - Access powerful models without censorship

PythonSecurity & PentestingCLI & Developer Tools
121
devsecops/awesome-devsecops

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

Security & PentestingDevOps & CI/CD
122
emmanuelygr/network-recon-toolkit

Beginner-friendly network reconnaissance tool using Python and Nmap for educational port scanning.

PythonSecurity & Pentesting
123
fosrl/pangolin

Modern networking and security platform providing secure access and connectivity to apps, infrastructure, and AI workloads. Connect and protect your users.

TypeScriptSecurity & PentestingSelf-Hosted Apps
124
misiektoja/instagram_monitor

Track Instagram users' activities, profile changes and capture content with beautiful dashboards and instant notifications

PythonSecurity & PentestingMonitoring & Observability
125
phishdestroy/destroylist

Real-time phishing & scam domain blocklist - 205k+ curated threats, 1M+ community, free API, multiple formats

HTMLSecurity & PentestingAPIs & SDKs
126
pralab/secml_malware

Create adversarial attacks against machine learning Windows malware detectors

PythonSecurity & PentestingMachine Learning & Data Science
127
GhostESP-Revival/GhostESP

The open-source wireless research platform for ESP32.

CSecurity & Pentesting
128
BurnoutDecomp/BP-Decomp_Workflow

The orchestration repository for the Burnout 5 / Burnout Paradise decompilation. Includes tools, IDA databases, and reference files to assist agentic reconstruction of the game's C++ source code.

C++Security & PentestingAI Agents
129
OpenKH/OpenKh

Kingdom Hearts libraries, tools, game engine and documentation

C#Security & PentestingGame Development
130
bunkerity/bunkerweb

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

PythonSecurity & PentestingCloud & Kubernetes
131
grisuno/LazyOwn

LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featuring rootkits to conceal campaigns, undetectable malleable implants compatible with Windows/Linux/Mac OSX, and self-configuring backdoors. With its Web interface and powerful Console Client, it is the best comb

HTMLSecurity & Pentesting
132
mbenachour/crucible

Crucible — model-agnostic, self-hostable vulnerability discovery harness (Recon → Hunt → Validate → Report)

PythonSecurity & Pentesting
133
projectdiscovery/nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud config

GoSecurity & Pentesting
134
AdityaBhatt3010/Dork-Like-a-Demon-FOFA-Edition-for-Hackers-Bug-Bounty-Hunters

A hacker’s guide to FOFA dorking, packed with powerful queries and tips for bug bounty, red teaming and proactive defense - dork smart, find fast, report big.

Security & PentestingAI Safety & Red Teaming
135
Python-roborock/local_roborock_server

Local HTTPS and MQTT cloud emulator for Roborock vacuums without rooting or hardware modifications

PythonSecurity & PentestingSelf-Hosted Apps
136
TheWWWorm/galaxian

Galaxy On Fire 3D engine

GDScriptSecurity & Pentesting
137
UvejsGj/WinDrop

An AirDrop implementation for Windows, built from scratch by reverse-engineering the protocol. Interoperates with opendrop in both directions.

C#Security & Pentesting
138
chasmlol/skate3clone

Source-only Rust/Bevy Skate 3 preservation project with owned-ISO asset setup

RustSecurity & PentestingGame Development
139
logto-io/logto

🧑🚀 Authentication and authorization infrastructure for SaaS and AI apps, built on OIDC and OAuth 2.1 with multi-tenancy, SSO, and RBAC.

TypeScriptSecurity & PentestingChatbots & LLM Apps
140
swisskyrepo/PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

PythonSecurity & PentestingAwesome Lists & Learning
141
G4MEOVER18/usb-army-penetrator

USB/WiFi penetration-testing platform on ESP32 — BadUSB, HID, mass storage, WiFi Marauder, remote agent, VNC. Fork of USBArmyKnife with LilyGO T-Dongle and CYD support.

C++Security & PentestingSystems, Compilers & Build Tools
142
arthurspk/guiadecybersecurity

Cyber Security Guide: learning paths, courses, books, channels, tools, and communities to help you enter and advance in the field.

Security & PentestingAwesome Lists & Learning
143
web3daemon/jsrecon

🐚 Map a web app's JavaScript to its API — endpoints, GraphQL, routes and leaked keys from bundles and source maps, plus an OpenAPI skeleton. tree-sitter, not regex.

PythonSecurity & PentestingAPIs & SDKs
144
BaalNetbek/DeepOpen

Abyss Engine 2.0 reconstruction

JavaSecurity & Pentesting
145
NangoHQ/nango

Connect your agents & product to 1,000 APIs.

TypeScriptSecurity & PentestingAPIs & SDKs
146
Cytlan/openbgi

Ethornell Buriko General Interpreter open source reimplementation

CSecurity & PentestingSystems, Compilers & Build Tools
147
Mafifrizi/ARES

ARES - authorized red-team engagement automation with dashboard, campaign scope, module orchestration, OPSEC controls, encrypted vault, and reporting.

PythonSecurity & PentestingWorkflow Automation & No-Code
148
NVIDIA-AI-Blueprints/vulnerability-analysis

Rapidly identify and mitigate container security vulnerabilities with generative AI.

PythonSecurity & Pentesting
149
kaifcodec/user-scanner

🕵️♂️ (2-in-1) Email & Username OSINT suite featuring native MCP support for deep data extraction just from a single Email/Username. Analyzes 2720+ actively maintained scan vectors (210+ email / 2510+ username) for security research, investigations, and digital footprinting.

PythonSecurity & PentestingMCP Servers & Tools
150
tracelabs/tlosint-vm

Trace Labs OSINT VM

ShellSecurity & Pentesting