Skip to main content
GitHub Community

GitHub Security Repositories

Discover the best open source security tools, frameworks, and learning resources on GitHub

Filter by Category

Showing 46 repositories

Featured Repositories

OWASP ModSecurity Core Rule Set

OWASP ModSecurity Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls

4,800 1,200PowerShell
wafmodsecurityowasp

ZAP

The OWASP Zed Attack Proxy (ZAP) is one of the world's most popular free security tools and is actively maintained by a dedicated international team of volunteers

11,700 2,500Java
scannerowaspweb-security

Nuclei

Fast and customizable vulnerability scanner based on simple YAML-based DSL

14,200 2,100Go
vulnerability-scannersecurity-toolspentesting

OWASP Amass

In-depth attack surface mapping and asset discovery

9,400 1,700Go
reconnaissanceattack-surfaceasset-discovery

More Repositories

SQLMap

Automatic SQL injection and database takeover tool

27,500 5,300Python
View

Wireshark

The world's most popular network protocol analyzer

5,300 1,900C
View

Suricata

Suricata is a network IDS, IPS and NSM engine developed by the OISF and the Suricata community

2,900 1,100C
View

Bettercap

The Swiss Army knife for 802.11, BLE, IPv4 and IPv6 networks reconnaissance and MITM attacks

14,200 1,500Go
View

Zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know

5,600 1,200C++
View

Snort

Snort 3 is the next generation Snort IPS (Intrusion Prevention System)

3,100 600C++
View

CAPE

CAPE: Config And Payload Extraction - Malware analysis automation

1,500 520Python
View

YARA

The pattern matching swiss knife

5,900 1,300C
View

Cuckoo Sandbox

Cuckoo Sandbox is an automated dynamic malware analysis system

7,800 2,100Python
View

Ghidra

Ghidra is a software reverse engineering (SRE) framework created and maintained by the NSA

41,500 5,000Java
View

Radare2

UNIX-like reverse engineering framework and command-line toolset

17,800 3,200C
View

Metasploit Framework

Metasploit Framework is the most widely used penetration testing software worldwide

29,400 13,100Ruby
View

Aircrack-ng

WiFi security auditing tools suite

7,200 1,700C
View

Nmap

Nmap - the Network Mapper. Github mirror of official SVN repository

8,100 2,000C
View

Hydra

Hydra is a parallelized login cracker which supports numerous protocols to attack

8,300 1,800C
View

John the Ripper

John the Ripper password cracker

7,200 2,000C
View

Wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads

6,800 1,200C
View

Sigma

Generic Signature Format for SIEM Systems

6,300 1,700Python
View

TheHive

TheHive: a Scalable, Open Source and Free Security Incident Response Platform

4,200 900Scala
View

Velociraptor

Velociraptor is a tool for collecting host based state information using Velocidex Query Language (VQL) queries

2,900 500Go
View

Security Onion

Security Onion is a free and open platform for threat hunting, security monitoring, and log management

3,000 600Shell
View

Prowler

Prowler is an Open Source security tool to perform AWS, GCP and Azure security best practices assessments, audits, incident response, compliance and more

7,800 1,100Python
View

ScoutSuite

Multi-Cloud Security Auditing Tool

3,800 740Python
View

CloudSploit

Cloud Security Posture Management (CSPM)

2,700 600JavaScript
View

TerraGoat

TerraGoat is Bridgecrew's 'Vulnerable by Design' Terraform repository

1,500 450HCL
View

Falco

Cloud Native Runtime Security

6,100 900C++
View

OpenSSL

TLS/SSL and crypto library

21,400 8,900C
View

Cryptography.io

A package designed to expose cryptographic primitives and recipes to Python developers

5,700 1,300Python
View

HashiCorp Vault

A tool for secrets management, encryption as a service, and privileged access management

28,500 4,100Go
View

Osquery

SQL powered operating system instrumentation, monitoring, and analytics

20,300 3,300C++
View

Grafana

The open and composable observability and data visualization platform

57,100 11,300TypeScript
View

Elasticsearch

Free and Open, Distributed, RESTful Search Engine

64,600 23,500Java
View

Prometheus

The Prometheus monitoring system and time series database

48,700 8,300Go
View

ELK Stack

Your window into the Elastic Stack

18,400 7,400TypeScript
View

Maltego

Maltego Transform Extensions Framework - Python library used to develop Maltego transforms

650 220Python
View

SpiderFoot

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface

10,300 2,100Python
View

Shodan

The official Python library for Shodan

2,100 450Python
View

Awesome Hacking

A collection of various awesome lists for hackers, pentesters and security researchers

16,400 2,600
View

Security 101

How to systematically secure anything: a repository about security engineering

10,300 860
View

OWASP Top 10

Official OWASP Top 10 Document Repository

5,300 1,000
View

Awesome Pentest

A collection of awesome penetration testing resources, tools and other shiny things

18,400 3,700
View

PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

50,200 12,500Python
View