Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Security Automation GitHub Repositories
Explore popular GitHub repositories tagged “security-automation”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
🐚 Python-powered shell. Full-featured, cross-platform and AI-friendly.
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
Go security checker
Automated Adversary Emulation Platform
Infection Monkey - An open-source adversary emulation platform
Open Source Vulnerability Management Platform
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
👀👮🐢🔥Performs a privacy & security check of Windows 10
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.
Security automation content in SCAP, Bash, Ansible, and other formats
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Automated Security Testing For REST API's
Automation to assess the state of your M365 tenant against CISA's baselines
🕵️ OSINT Tools for gathering information and actions forensics 🕵️
Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.
A AI general-purpose state-space search engine, validated first on autonomous penetration testing.
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.
Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.
A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.