Skip to main content
buildradar
Sign in
Topic · security-tools

security-tools

Tracked open-source repos tagged security-tools, sorted by stars.

331 repos
  • cargo-auditable@rust-secure-code

    Make production Rust binaries auditable

    849+3Star change over the last 7 days
  • Sec-Tools@jwt1399

    🍉一款基于Python-Django的多功能Web安全渗透测试工具,包含漏洞扫描,端口扫描,指纹识别,目录扫描,旁站扫描,域名扫描等功能。

    848-1Star change over the last 7 days
  • ship-safe@asamassekou10

    The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API key needed, JSON and SARIF output.

    842+13Star change over the last 7 days
  • pipelock@luckyPipewrench

    Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.

    839+11Star change over the last 7 days
  • caddy-waf@fabriziosalmi

    Caddy WAF (Regex Rules, IP and DNS filtering, Rate Limiting, GeoIP, Tor, Anomaly Detection)

    814+7Star change over the last 7 days
  • This repo contains a comprehensive list of smart contract auditor tools and techniques that can be utilized by both smart contract auditors and blockchain developers for developing secure smart contracts

    813+1Star change over the last 7 days
  • Z3r0@yv1ing

    AI-native red-team workbench for authorized penetration testing and vulnerability research, with specialist agents, sandboxed tooling, evidence records, and replayable timelines.

    797+106Star change over the last 7 days
  • cain-agent@cdxiaodong

    Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK

    785+192Star change over the last 7 days
  • chain-bench@aquasecurity

    An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.

    775+0Star change over the last 7 days
  • Cybermes@Zyrexnn

    Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.

    769+53Star change over the last 7 days
  • The Official Hak5 Shark Jack Payload Repository

    766+5Star change over the last 7 days
  • WitnessMe@byt3bl33d3r

    Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.

    759+0Star change over the last 7 days
  • ronin@ronin-rb

    Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of code, exploits, payloads, etc, via 3rd-party git repositories.

    756+0Star change over the last 7 days
  • GpgFrontend@saturneric

    A modern, cross-platform OpenPGP tool with a unique dual-engine core: switch freely between the battle-tested GnuPG and a modern, memory-safe Rust rPGP backend. It makes encryption, signing, and key management easier and more trustworthy in everyday privacy workflows.

    754+3Star change over the last 7 days
  • DllShimmer@Print3M

    Weaponize DLL hijacking easily. Backdoor any function in any DLL.

    753+0Star change over the last 7 days
  • NativeDump@ricardojoserf

    Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)

    748+0Star change over the last 7 days
  • L0p4Map@HaxL0p4

    Professional network monitoring & visualization tool. L0P4Map combines high-speed ARP discovery with full nmap integration and a real-time interactive network topology engine. Works on both local networks and custom IPs/websites.

    748+139Star change over the last 7 days
  • raven@CycodeLabs

    CI/CD Security Analyzer

    747+0Star change over the last 7 days
  • krane@appvia

    Kubernetes RBAC static analysis & visualisation tool

    745+1Star change over the last 7 days
  • nmap-formatter@vdjagilev

    A tool that allows you to convert NMAP results to html, csv, json, markdown, graphviz (dot), sqlite, excel and d2-lang. Simply put it's nmap converter.

    738+0Star change over the last 7 days
  • aaWAF@aaPanel

    aawaf 是一款基于语义分析的Web应用防火墙

    738+1Star change over the last 7 days
  • ARL-docker@honmashironeko

    基于ARL v2.6.2版本源码,生成docker镜像进行快速部署,同时提供七千多条指纹

    732+1Star change over the last 7 days
  • BlueToolkit@sgxgsx

    BlueToolkit is an extensible Bluetooth Classic vulnerability testing framework that helps uncover new and old vulnerabilities in Bluetooth-enabled devices. Could be used in the vulnerability research, penetration testing and bluetooth hacking. We also collected and classified Bluetooth vulnerabilities in an "Awesome Bluetooth Security" way

    731+2Star change over the last 7 days
  • FofaMap@asaotomo

    一款证据驱动的 FOFA 资产测绘智能体:支持自然语言侦察、AI 反思、CLI / MCP / Skill / REST API,以及经人工审批的 Nuclei 扫描。

    722+6Star change over the last 7 days
  • Powershellisfun@HarmVeenstra

    Repository with the scripts that I have used in my blogs on https://powershellisfun.com. If you like these, please sponsor this project using the Sponsor button below or buy me a coffee :) https://www.buymeacoffee.com/powershellisfun

    719-1Star change over the last 7 days
  • zerobox@afshinm

    Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.

    717+7Star change over the last 7 days
  • Disassemble ANY files including .so (NDK, JNI), Windows PE(EXE, DLL, SYS, etc), linux binaries, libraries, and any other files such as pictures, audios, etc(for fun)files on Android. Capstone-based disassembler application on android. 안드로이드 NDK 공유 라이브러리, Windows 바이너리, etc,... 리버싱 앱

    713+2Star change over the last 7 days
  • ethereum-lists@MyEtherWallet

    A repository for maintaining lists of things like malicious URLs, fake token addresses, and so forth. We love lists.

    710+1Star change over the last 7 days
  • ps-fuzz@prompt-security

    Make your GenAI Apps Safe & Secure :rocket: Test & harden your system prompt

    707+1Star change over the last 7 days
  • vulnerablecode@aboutcode-org

    A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/

    703+4Star change over the last 7 days
← Back to topics