Trending
All collections

Security

Pentest, defense, crypto

100 repositories

1
#166
soxoj/maigret avatar
soxoj/maigret

🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

29.9k
100
2
#190
KeygraphHQ/shannon avatar
KeygraphHQ/shannon

Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

43.5k
86
3
#213
Hack-with-Github/Awesome-Hacking avatar
Hack-with-Github/Awesome-Hacking

A collection of various awesome lists for hackers, pentesters and security researchers

112.8k
78
4
#231
PurpleAILAB/Decepticon avatar
PurpleAILAB/Decepticon

Autonomous Hacking Agent for Red Team

4.0k
73
5
#284
zoicware/RemoveWindowsAI avatar
zoicware/RemoveWindowsAI

Force Remove Copilot, Recall and More in Windows 11

11.8k
61
6
#298
OpenCTI-Platform/opencti avatar
OpenCTI-Platform/opencti

Open Cyber Threat Intelligence Platform

9.4k
59
7
#306
OpenVPN/openvpn avatar
OpenVPN/openvpn

OpenVPN is an open source VPN daemon

13.9k
57
8
#311
bountyyfi/lonkero avatar
bountyyfi/lonkero

Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

915
56
9
#524
usestrix/strix avatar
usestrix/strix

Open-source AI hackers to find and fix your app’s vulnerabilities.

25.5k
35
10
#545
chaterm/Chaterm avatar
chaterm/Chaterm

Open source AI terminal for cloud and infrastructure management, enabling you to deploy, troubleshoot, and automate services using natural language and intelligent agents.

3.0k
34
11
#596
mukul975/Anthropic-Cybersecurity-Skills avatar
mukul975/Anthropic-Cybersecurity-Skills

754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 26 security domains · Apache 2.0

6.6k
31
12
#601
promptfoo/promptfoo avatar
promptfoo/promptfoo

Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.

21.5k
31
13
#605
DependencyTrack/dependency-track avatar
DependencyTrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

3.8k
31
14
#629
mytechnotalent/Reverse-Engineering avatar
mytechnotalent/Reverse-Engineering

A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.

13.6k
30
15
#640
Infisical/infisical avatar
Infisical/infisical

Infisical is the open-source platform for secrets, certificates, and privileged access management.

27.0k
30
16
#664
sherlock-project/sherlock avatar
sherlock-project/sherlock

Hunt down social media accounts by username across social networks

83.6k
29
17
#668
Developer-Y/cs-video-courses avatar
Developer-Y/cs-video-courses

List of Computer Science courses with video lectures.

81.5k
29
18
#677
yaklang/yakit avatar
yaklang/yakit

Cyber Security ALL-IN-ONE Platform

7.3k
28
19
#739
simplex-chat/simplex-chat avatar
simplex-chat/simplex-chat

SimpleX - the first messaging network operating without user identifiers of any kind - 100% private by design! iOS, Android and desktop apps 📱!

11.1k
27
20
#754
aquasecurity/trivy avatar
aquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

35.1k
26
21
#755
ory/hydra avatar
ory/hydra

Internet-scale OpenID Certified™ OpenID Connect and OAuth2.1 provider that integrates with your user management through headless APIs. Solve OIDC/OAuth2 user cases over night. Consume as a service on Ory Network or self-host. Trusted by OpenAI and many others for scale and security. Written in Go.

17.2k
26
22
#793
gitleaks/gitleaks avatar
gitleaks/gitleaks

Find secrets with Gitleaks 🔑

27.2k
25
23
#824
wpscanteam/wpscan avatar
wpscanteam/wpscan

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com

9.6k
24
24
#838
keepassxreboot/keepassxc avatar
keepassxreboot/keepassxc

KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.

27.3k
24
25
#839
caddyserver/caddy avatar
caddyserver/caddy

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

72.6k
24
26
#874
freenet/freenet-core avatar
freenet/freenet-core

Declare your digital independence

2.7k
23
27
#892
trufflesecurity/trufflehog avatar
trufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

26.4k
23
28
#900
ThinkWatchProject/ThinkWatch avatar
ThinkWatchProject/ThinkWatch

Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.

971
23
29
#952
prowler-cloud/prowler avatar
prowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

13.9k
22
30
#964
TecharoHQ/anubis avatar
TecharoHQ/anubis

Weighs the soul of incoming HTTP requests to stop AI crawlers

19.5k
22
31
#970
goauthentik/authentik avatar
goauthentik/authentik

The authentication glue you need.

21.6k
22
32
#981
projectdiscovery/nuclei avatar
projectdiscovery/nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

28.8k
22
33
#1114
twpayne/chezmoi avatar
twpayne/chezmoi

Manage your dotfiles across multiple diverse machines, securely.

19.9k
20
34
#1146
Tencent/AI-Infra-Guard avatar
Tencent/AI-Infra-Guard

A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

3.8k
19
35
#1150
GyulyVGC/sniffnet avatar
GyulyVGC/sniffnet

Comfortably monitor your Internet traffic 🕵️‍♂️

37.7k
19
36
#1181
WerWolv/ImHex avatar
WerWolv/ImHex

🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

53.7k
19
37
#1230
blacklanternsecurity/bbot avatar
blacklanternsecurity/bbot

The recursive internet scanner for hackers. 🧡

9.7k
18
38
#1302
crowdsecurity/crowdsec avatar
crowdsecurity/crowdsec

CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.

13.4k
17
39
#1347
BlackArch/blackarch avatar
BlackArch/blackarch

An ArchLinux based distribution for penetration testers and security researchers.

3.4k
17
40
#1493
kanidm/kanidm avatar
kanidm/kanidm

Kanidm: A simple, secure, and fast identity management platform

5.0k
16
41
#1496
projectdiscovery/subfinder avatar
projectdiscovery/subfinder

Fast passive subdomain enumeration tool.

13.7k
16
42
#1515
chaitin/SafeLine avatar
chaitin/SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

21.3k
15
43
#1518
HackTricks-wiki/hacktricks avatar
HackTricks-wiki/hacktricks

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

11.3k
15
44
#1520
nomi-sec/PoC-in-GitHub avatar
nomi-sec/PoC-in-GitHub

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

7.8k
15
45
#1524
kata-containers/kata-containers avatar
kata-containers/kata-containers

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs. https://katacontainers.io/

8.0k
15
46
#1552
adysec/ARL avatar
adysec/ARL

ARL 资产侦察灯塔系统(可运行,添加指纹,提高并发,升级工具及系统,无限制修改版) | ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。

886
15
47
#1586
StevenBlack/hosts avatar
StevenBlack/hosts

🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

30.4k
15
48
#1588
mitmproxy/mitmproxy avatar
mitmproxy/mitmproxy

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

43.6k
15
49
#1598
intuitem/ciso-assistant-community avatar
intuitem/ciso-assistant-community

CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.

4.1k
15
50
#1650
ffuf/ffuf avatar
ffuf/ffuf

Fast web fuzzer written in Go

16.1k
15
51
#1678
bitcoin/bitcoin avatar
bitcoin/bitcoin

Bitcoin Core integration/staging tree

89.2k
15
52
#1710
wazuh/wazuh avatar
wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

15.7k
14
53
#1773
authelia/authelia avatar
authelia/authelia

The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™

27.9k
14
54
#1774
swisskyrepo/PayloadsAllTheThings avatar
swisskyrepo/PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

77.8k
14
55
#1800
lissy93/web-check avatar
lissy93/web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

33.1k
14
56
#1808
anchore/grype avatar
anchore/grype

A vulnerability scanner for container images and filesystems

12.3k
14
57
#1818
cryptomator/cryptomator avatar
cryptomator/cryptomator

Cryptomator for Windows, macOS, and Linux: Secure client-side encryption for your cloud storage, ensuring privacy and control over your data.

15.1k
14
58
#1843
superradcompany/microsandbox avatar
superradcompany/microsandbox

🧱 secure, local and programmable sandboxes for AI agents

6.2k
13
59
#1855
eosphoros-ai/DB-GPT avatar
eosphoros-ai/DB-GPT

open-source agentic AI data assistant for the next generation of AI + Data products.

18.8k
13
60
#1874
shadow1ng/fscan avatar
shadow1ng/fscan

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

13.8k
13
61
#1877
leonlatsch/Photok avatar
leonlatsch/Photok

Private photo vault for Android

896
13
62
#1927
bytebase/bytebase avatar
bytebase/bytebase

World's most advanced database DevSecOps solution for Developer, Security, DBA and Platform Engineering teams. The GitHub/GitLab for database DevSecOps.

14.0k
13
63
#1953
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance avatar
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO 27701, DORA, CSRD, India's DPDPA, CMMC 2.0, NIST AI Risk, SWIFT, Australia's ISM, EU NIS2, and CCPA/CPRA. Benchmark 96% (with skills) vs 82% (without skills).

464
13
64
#1997
pabpereza/pabpereza avatar
pabpereza/pabpereza

Website, courses, documentation, blog and youtube video tracker.

419
13
65
#2040
getsops/sops avatar
getsops/sops

Simple and flexible tool for managing secrets

21.9k
13
66
#2045
ivre/ivre avatar
ivre/ivre

Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.

4.0k
13
67
#2051
fail2ban/fail2ban avatar
fail2ban/fail2ban

Daemon to ban hosts that cause multiple authentication errors

17.8k
13
68
#2158
hahwul/dalfox avatar
hahwul/dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

5.0k
12
69
#2160
maxgoedjen/secretive avatar
maxgoedjen/secretive

Protect your SSH keys with your Mac's Secure Enclave

8.5k
12
70
#2203
sqlmapproject/sqlmap avatar
sqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

37.4k
12
71
#2241
google/osv.dev avatar
google/osv.dev

Open source vulnerability DB and triage service.

2.7k
12
72
#2243
bee-san/RustScan avatar
bee-san/RustScan

🤖 The Modern Port Scanner 🤖

19.8k
12
73
#2381
open-policy-agent/gatekeeper avatar
open-policy-agent/gatekeeper

🐊 Policy Controller for Kubernetes

4.2k
12
74
#2403
winsiderss/systeminformer avatar
winsiderss/systeminformer

A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. Brought to you by Winsider Seminars & Solutions, Inc. @ http://www.windows-internals.com

14.8k
12
75
#2408
x64dbg/x64dbg avatar
x64dbg/x64dbg

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

48.4k
12
76
#2458
projectdiscovery/nuclei-templates avatar
projectdiscovery/nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

12.4k
11
77
#2482
OJ/gobuster avatar
OJ/gobuster

Directory/File, DNS and VHost busting tool written in Go

13.7k
11
78
#2546
cilium/tetragon avatar
cilium/tetragon

eBPF-based Security Observability and Runtime Enforcement

4.7k
11
79
#2560
cerbos/cerbos avatar
cerbos/cerbos

Cerbos is the open core, language-agnostic, scalable authorization solution that makes user permissions and authorization simple to implement and manage by writing context-aware access control policies for your application resources.

4.4k
11
80
#2575
bee-san/Ciphey avatar
bee-san/Ciphey

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

21.4k
11
81
#2609
zaproxy/zaproxy avatar
zaproxy/zaproxy

The ZAP by Checkmarx Core project

15.2k
11
82
#2626
pyca/cryptography avatar
pyca/cryptography

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.

7.6k
11
83
#2687
yokoffing/Betterfox avatar
yokoffing/Betterfox

Firefox user.js for optimal privacy and security. Your favorite browser, but better.

10.4k
11
84
#2692
bettercap/bettercap avatar
bettercap/bettercap

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

19.2k
11
85
#2709
monero-project/monero avatar
monero-project/monero

Monero: the secure, private, untraceable cryptocurrency

10.6k
11
86
#2741
provos/ironcurtain avatar
provos/ironcurtain

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

449
11
87
#2769
spmedia/Threat-Actor-Usernames-Scrape avatar
spmedia/Threat-Actor-Usernames-Scrape

A collection & lists of intel and usernames scraped from various cybercrime sources & forums. DarkForums, HackForums, Patched, Cracked, BreachForums, OGUser, XSS, Dread, & more

197
11
88
#2797
TracecatHQ/tracecat avatar
TracecatHQ/tracecat

Open-source security automation platform for teams and AI agents

3.6k
11
89
#2843
moonD4rk/HackBrowserData avatar
moonD4rk/HackBrowserData

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

14.1k
11
90
#2849
firezone/firezone avatar
firezone/firezone

Enterprise-ready zero-trust access platform built on WireGuard®.

8.6k
11
91
#2884
OWASP/CheatSheetSeries avatar
OWASP/CheatSheetSeries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

32.1k
11
92
#2897
Security-Onion-Solutions/securityonion avatar
Security-Onion-Solutions/securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

4.6k
11
93
#2938
cilium/cilium avatar
cilium/cilium

eBPF-based Networking, Security, and Observability

24.4k
11
94
#2998
SWE-agent/SWE-agent avatar
SWE-agent/SWE-agent

SWE-agent takes a GitHub issue and tries to automatically fix it, using your LM of choice. It can also be employed for offensive cybersecurity or competitive coding challenges. [NeurIPS 2024]

19.3k
10
95
#3047
falcosecurity/falco avatar
falcosecurity/falco

Cloud Native Runtime Security

9.0k
10
96
#3052
DefectDojo/django-DefectDojo avatar
DefectDojo/django-DefectDojo

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

4.7k
10
97
#3069
zeek/zeek avatar
zeek/zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

7.7k
10
98
#3083
416rehman/DeepZero avatar
416rehman/DeepZero

Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands of Windows kernel drivers for exploitable IOCTLs natively using AI agents.

450
10
99
#3140
dootss/shodan-dorks avatar
dootss/shodan-dorks

An auto-updating list of shodan dorks with info on the amount of results they return!

369
10
100
#3166
GreedyBear-Project/GreedyBear avatar
GreedyBear-Project/GreedyBear

Threat Intel Platform for T-POTs

199
10