GitStar
GitHub TrendingTopicsLanguages
/

Blue Team GitHub Repositories

Explore popular GitHub repositories tagged “blue-team”.

Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.

RepositoriesGitHub topic
Ranked by:Stars

Trending Repositories

decalage2/awesome-security-hardening

A collection of awesome security hardening guides, tools and other resources

6,511681
Trusted-AI/adversarial-robustness-toolbox

Adversarial Robustness Toolbox (ART) - Python Library for Machine Learning Security - Evasion, Poisoning, Extraction, Inference - Red and Blue Teams

Python6,1821,336
fabacab/awesome-cybersecurity-blueteam

:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

5,521833
A-poc/BlueTeam-Tools

Tools and Techniques for Blue Team / Incident Response

4,435686
Bashfuscator/Bashfuscator

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

Python1,992201
mytechnotalent/Hacking-Windows

A FREE Windows C development course where we will learn the Win32API and reverse engineer each step utilizing IDA Free in both an x86 and x64 environment.

C1,615145
Viralmaniar/BigBountyRecon

BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.

C#1,563290
ION28/BLUESPAWN

An Active Defense and EDR software to empower Blue Teams

C++1,334178
edoardogerosa/sentinel-attack

Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK

1,076201
TryCatchHCF/DumpsterFire

"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.

Python1,038150
atenreiro/opensquat

openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.

Python982160
satan1a/awesome-cybersecurity-blueteam-cn

网络安全 · 攻防对抗 · 蓝队清单,中文版

HTML967120
JoasASantos/n8n-CyberSecurity-Workflows

Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.

948186
Puliczek/awesome-list-of-secrets-in-environment-variables

🦄🔒 Awesome list of secrets in environment variables 🖥️

90977
dolevf/graphql-cop

Security Auditor Utility for GraphQL APIs

Python685102
BlessedRebuS/Krawl

Krawl is a customizable, lightweight, cloud-native web deception server and anti-crawler that creates fake web applications with low-hanging vulnerabilities using realistic, randomly generated decoy data and AI-generated HTML templates.

Python63361
activecm/rita

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Go62467
awslabs/aws-cloudsaga

AWS CloudSaga - Simulate security events in AWS

Python47538
Karib0u/rustinel

Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

Rust45357
PaperMtn/slack-watchman

Slack enumeration and exposed secrets detection tool

Python40348
joeavanzato/Trawler

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

PowerShell34038
codeexpress/respounder

Respounder detects presence of responder in the network.

Go32341
F2u0a0d3/goodboy-framework

15-stage Windows malware development & analysis course in Rust. Red team builds it, blue team detects it. All 15 binaries achieved 0/76 on VirusTotal.

29435
awslabs/assisted-log-enabler-for-aws

Assisted Log Enabler for AWS - Find AWS resources that are not logging, and turn them on.

Python27633
Idov31/NovaHypervisor

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with VMware and Hyper-V.

C++27225
Kirtar22/Litmus_Test

Detecting ATT&CK techniques & tactics for Linux

Roff25853
telagod/code-abyss

Give your AI coding agent a personality. Composable persona + style + skills for Claude Code, Codex, Gemini CLI & OpenClaw. Ships Tech Persona Card v1.0 spec.

JavaScript23730
cybercdh/kitphishr

A tool designed to hunt for Phishing Kit source code

Go23538
AdvDebug/NoMoreCookies

Browser Protector against various stealers, written in C# & C/C++.

C#22667
Viralmaniar/Remote-Desktop-Caching-

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to extract juicy information such as LAPS passwords or any sensitive information on the screen. Blue Team member can reconstruct PNG files to see what an attacker did on a compromised host. It is extremely useful for a forensics team to extract timestamps after an attack on a host to collect evidences and perform further analysis.

Python21858
GitStar

See what the GitStar community is most excited about today.

Trending

GitHub Trending TodayGitHub Trending WeeklyGitHub Trending Monthly

Languages

Browse all languagesTrending PythonTrending JavaScript

Explore

Browse GitHub topicsAI repositoriesDeveloper tools
© 2026 GitStarGitHub Trending source