security-tools
Tracked open-source repos tagged security-tools, sorted by stars.
- #241
Make production Rust binaries auditable
★ 849+3Star change over the last 7 days - #242★ 848-1Star change over the last 7 days
- #243
The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API key needed, JSON and SARIF output.
★ 842+13Star change over the last 7 days - #244
Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.
★ 839+11Star change over the last 7 days - #245
Caddy WAF (Regex Rules, IP and DNS filtering, Rate Limiting, GeoIP, Tor, Anomaly Detection)
★ 814+7Star change over the last 7 days - #246
This repo contains a comprehensive list of smart contract auditor tools and techniques that can be utilized by both smart contract auditors and blockchain developers for developing secure smart contracts
★ 813+1Star change over the last 7 days - #247
AI-native red-team workbench for authorized penetration testing and vulnerability research, with specialist agents, sandboxed tooling, evidence records, and replayable timelines.
★ 797+106Star change over the last 7 days - #248
Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK
★ 785+192Star change over the last 7 days - #249
An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
★ 775+0Star change over the last 7 days - #250
Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.
★ 769+53Star change over the last 7 days - #251
The Official Hak5 Shark Jack Payload Repository
★ 766+5Star change over the last 7 days - #252
Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.
★ 759+0Star change over the last 7 days - #253
Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of code, exploits, payloads, etc, via 3rd-party git repositories.
★ 756+0Star change over the last 7 days - #254
A modern, cross-platform OpenPGP tool with a unique dual-engine core: switch freely between the battle-tested GnuPG and a modern, memory-safe Rust rPGP backend. It makes encryption, signing, and key management easier and more trustworthy in everyday privacy workflows.
★ 754+3Star change over the last 7 days - #255
Weaponize DLL hijacking easily. Backdoor any function in any DLL.
★ 753+0Star change over the last 7 days - #256
Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)
★ 748+0Star change over the last 7 days - #257
Professional network monitoring & visualization tool. L0P4Map combines high-speed ARP discovery with full nmap integration and a real-time interactive network topology engine. Works on both local networks and custom IPs/websites.
★ 748+139Star change over the last 7 days - #258★ 747+0Star change over the last 7 days
- #259★ 745+1Star change over the last 7 days
- #260
A tool that allows you to convert NMAP results to html, csv, json, markdown, graphviz (dot), sqlite, excel and d2-lang. Simply put it's nmap converter.
★ 738+0Star change over the last 7 days - #261★ 738+1Star change over the last 7 days
- #262
基于ARL v2.6.2版本源码,生成docker镜像进行快速部署,同时提供七千多条指纹
★ 732+1Star change over the last 7 days - #263
BlueToolkit is an extensible Bluetooth Classic vulnerability testing framework that helps uncover new and old vulnerabilities in Bluetooth-enabled devices. Could be used in the vulnerability research, penetration testing and bluetooth hacking. We also collected and classified Bluetooth vulnerabilities in an "Awesome Bluetooth Security" way
★ 731+2Star change over the last 7 days - #264
一款证据驱动的 FOFA 资产测绘智能体:支持自然语言侦察、AI 反思、CLI / MCP / Skill / REST API,以及经人工审批的 Nuclei 扫描。
★ 722+6Star change over the last 7 days - #265
Repository with the scripts that I have used in my blogs on https://powershellisfun.com. If you like these, please sponsor this project using the Sponsor button below or buy me a coffee :) https://www.buymeacoffee.com/powershellisfun
★ 719-1Star change over the last 7 days - #266
Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.
★ 717+7Star change over the last 7 days - #267
Disassemble ANY files including .so (NDK, JNI), Windows PE(EXE, DLL, SYS, etc), linux binaries, libraries, and any other files such as pictures, audios, etc(for fun)files on Android. Capstone-based disassembler application on android. 안드로이드 NDK 공유 라이브러리, Windows 바이너리, etc,... 리버싱 앱
★ 713+2Star change over the last 7 days - #268
A repository for maintaining lists of things like malicious URLs, fake token addresses, and so forth. We love lists.
★ 710+1Star change over the last 7 days - #269
Make your GenAI Apps Safe & Secure :rocket: Test & harden your system prompt
★ 707+1Star change over the last 7 days - #270
A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
★ 703+4Star change over the last 7 days