An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
Security Tools GitHub Repositories
Explore popular GitHub repositories tagged “security-tools”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
🕵️♂️ All-in-one OSINT tool for analysing any website
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Find secrets with Gitleaks 🔑
Find, verify, and analyze leaked credentials
API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites
🔒 A compiled checklist of 300+ tips for protecting digital security and privacy in 2026
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
Loads environment variables from .env for nodejs projects.
🤖 The Modern Port Scanner 🤖
Daemon to ban hosts that cause multiple authentication errors
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment. Connect your agents now and build on the Agentic Cloud Defender.
一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)
Scapy: the Python-based interactive packet manipulation program & library.
Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
Adversary Emulation Framework
The best IP Toolbox. Check your IP address & geolocation, test IP for WebRTC and DNS IP leaks, run an IP quality check, browser fingerprint check, website availability check, network speed test, global latency test, MTR test, Whois search, and more.
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
Vulnerability scanner written in Go which uses the data provided by https://osv.dev
Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.
Tools and Techniques for Red Team / Penetration Testing
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
Go security checker
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.