Skip to main content
buildradar
Sign in
Topic · security-tools

security-tools

Tracked open-source repos tagged security-tools, sorted by stars.

331 repos
  • cherrybomb@blst-security

    Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

    1,236+0Star change over the last 7 days
  • shortscan@bitquark

    An IIS short filename enumeration tool

    1,217+0Star change over the last 7 days
  • Artemis@CERT-Polska

    A modular vulnerability scanner with automatic report generation capabilities.

    1,203+0Star change over the last 7 days
  • Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).

    1,202+0Star change over the last 7 days
  • Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.

    1,200+0Star change over the last 7 days
  • leaky-paths@ayoubfathi

    A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.

    1,193+0Star change over the last 7 days
  • Whaler@P3GLEG

    Program to reverse Docker images into Dockerfiles

    1,191+0Star change over the last 7 days
  • MailAccess@KatrielMoses

    Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

    1,182+0Star change over the last 7 days
  • dexcalibur@reversenseorg

    Reversense (Dexcalibur2) is a fully rewriting and rethinking of Dexcalibur. Reversense is a binary intelligence platform that automates the reverse engineering of mobile and embedded applications.

    1,168+0Star change over the last 7 days
  • DeimosC2@DeimosC2

    DeimosC2 is a Golang command and control framework for post-exploitation.

    1,160+0Star change over the last 7 days
  • AppVerifier@soupslurpr

    Verify apps easily.

    1,153+0Star change over the last 7 days
  • dpt-shell@luoyesiqiu

    An android Dex protection shell implementation

    1,124+6Star change over the last 7 days
  • stride-gpt@mrwadams

    An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE methodology.

    1,116+4Star change over the last 7 days
  • sipvicious@EnableSecurity

    SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks against PBX systems especially through identification, scanning, extension enumeration and password cracking.

    1,101+2Star change over the last 7 days
  • AutoPWN-Suite@GamehunterKaan

    AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

    1,095+0Star change over the last 7 days
  • jok3r@koutto

    Jok3r v3 BETA 2 - Network and Web Pentest Automation Framework

    1,089+1Star change over the last 7 days
  • reverify@2akouwu

    Stop your AI from making things up — it proposes, deterministic tools decide, every claim checked against ground truth with evidence. Grounded facts and context survive resets. Reverse engineering is the proving ground. MCP server + CLI.

    1,089+475Star change over the last 7 days
  • sentinel-attack@edoardogerosa

    Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK

    1,077+0Star change over the last 7 days
  • keychain@danielrobbins

    A manager for ssh-agent and gpg-agent, now in Python.

    1,077+0Star change over the last 7 days
  • lonkero@bountyyfi

    Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

    1,075+23Star change over the last 7 days
  • Slack@qiwentaidi

    安全服务集成化工具集

    1,072+0Star change over the last 7 days
  • spray@chainreactors

    最好用最智能最可控的目录Fuzz工具 | The most powerful, user-friendly, intelligent, and precise HTTP Fuzzer.

    1,059+2Star change over the last 7 days
  • Statically-linked ssh server with reverse shell functionality for CTFs and such

    1,056+0Star change over the last 7 days
  • o365spray@0xZDH

    Username enumeration and password spraying tool aimed at Microsoft O365.

    1,053+1Star change over the last 7 days
  • agentic-radar@splx-ai

    A security scanner for your LLM agentic workflows

    1,048+3Star change over the last 7 days
  • ElectricEye@jonrau1

    ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

    1,045+0Star change over the last 7 days
  • thug@buffer

    Python low-interaction honeyclient

    1,043+2Star change over the last 7 days
  • mantis@PhonePe

    Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning.

    1,038+0Star change over the last 7 days
  • DedSec@dedsec1121fk

    Official repository of the DedSec Project.

    1,011+5Star change over the last 7 days
  • 基于ARL-V2.6.2修改后的版本

    1,005+0Star change over the last 7 days
← Back to topics