security-tools
Tracked open-source repos tagged security-tools, sorted by stars.
- #211★ 1,000+1Star change over the last 7 days
- #212
A Blazing fast Security Auditing tool for Kubernetes
★ 999+0Star change over the last 7 days - #213★ 996+2Star change over the last 7 days
- #214
secureCodeBox (SCB) - continuous secure delivery out of the box
★ 989+1Star change over the last 7 days - #215★ 985+2Star change over the last 7 days
- #216
openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.
★ 985+3Star change over the last 7 days - #217
A curated list of tools officially presented at Black Hat events
★ 981+6Star change over the last 7 days - #218
AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an always-on AI attack-signature scanner and native Rust & PHP rules. Also: medusa scan --git to vet any repo, medusa secrets scan for leaked API keys. 40,000+ patterns, zero setup.
★ 979+5Star change over the last 7 days - #219
SpiderSuite (web security crawler) releases, wiki and roadmap
★ 976+4Star change over the last 7 days - #220
APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.
★ 974+0Star change over the last 7 days - #221
Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP callbacks · TLS · Auth · Share links. A powerful python3 -m http.server replacement.
★ 970+2Star change over the last 7 days - #222
Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
★ 970+16Star change over the last 7 days - #223★ 943+2Star change over the last 7 days
- #224
CatSniffer is an original multiprotocol and multiband board for sniffing, communicating, and attacking IoT (Internet of Things) devices using the latest radio IoT protocols. It is a highly portable USB stick that integrates TI CC1352, Semtech SX1262, and an RP2040 for V3 or a Microchip SAMD21E17 for V2
★ 940+4Star change over the last 7 days - #225
Open Source Tripwire®
★ 939+2Star change over the last 7 days - #226
ZipCracker是Hx0战队出品的一款功能强大的Zip密码破解工具。它集成了字典攻击、掩码攻击、短明文 CRC32 枚举恢复、已知明文攻击等多种破解模式,并能自动修复伪加密文件。凭借其高性能与多功能的特点,ZipCracker已成为CTF比赛中的一把利器。(ZipCracker by Hx0 team is a tool for cracking passwords on Zip files, great for CTF competitions.)
★ 937+6Star change over the last 7 days - #227
Offensive Security OSCP+, OSEP, OSWP, OSWA, OSWE, OSED, OSMR, OSEE, OSDA, OSIR, OSTH Exam and Lab Reporting / Note-Taking Tool
★ 934-1Star change over the last 7 days - #228
Extract and aggregate threat intelligence.
★ 925-1Star change over the last 7 days - #229
My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.
★ 921+1Star change over the last 7 days - #230
强大的 Frida 重打包工具,用于 iOS 和 Android。轻松修改 Frida 特征,增强隐蔽性,绕过检测。简化逆向工程和安全测试。Powerful Frida repackaging tool for iOS and Android. Easily modify Frida servers to enhance stealth and bypass detection. Streamlines reverse engineering and security testing.
★ 916+9Star change over the last 7 days - #231★ 915+3Star change over the last 7 days
- #232
SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS
★ 911+0Star change over the last 7 days - #233
Autonomous AI pentesting engine across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes, IoT firmware and AI/LLM endpoints (OWASP LLM Top 10). Real exploits with proof for every finding. Privacy gateway: the LLM never sees your real IPs, hosts or creds; nothing leaves your perimeter.
★ 907+20Star change over the last 7 days - #234
Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text
★ 904+1Star change over the last 7 days - #235
A deauth attack that disconnects all devices from the target wifi network (2.4Ghz & 5Ghz), WPA3 also supported (PMF not tested)
★ 903+3Star change over the last 7 days - #236★ 892+41Star change over the last 7 days
- #237
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
★ 882+67Star change over the last 7 days - #238★ 871+2Star change over the last 7 days
- #239
Curated List of Best DevOps Tools
★ 869+0Star change over the last 7 days - #240
One wifi password per device. Ad Blocking & Privacy Blocklists. Policy Based Network Access
★ 858+2Star change over the last 7 days