Open-source repositories gaining traction right now.
170 repositories

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

SimpleX - the first messaging network operating without user identifiers of any kind - 100% private by design! iOS, Android and desktop apps 📱!

ALL IN ONE Hacking Tool For Hackers

Hunt down social media accounts by username across social networks

Fast and accurate AI powered file content types detection

Amnezia VPN Client (Desktop+Mobile)

The Destructive Command Guard (dcg) is for blocking dangerous git and shell commands from being executed by agents.

Easily and securely send things from one computer to another 🐊 📦

holehe allows you to check if the mail is used on different sites like twitter, instagram and will retrieve information on sites with the forgotten password function.

754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 26 security domains · Apache 2.0

ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.

Free, open-source Windows optimization tool for performance, privacy, and simplicity.

uBlock Origin - An efficient blocker for Chromium and Firefox. Fast and lean.

The authentication glue you need.

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

Star OpenCTI-Platform / opencti Open Cyber Threat Intelligence Platform

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by law enforcement or in a corporate investigation by private examiners.

Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs

CyberStrikeAI is an AI-native security testing platform built in Go. It integrates 100+ security tools, an intelligent orchestration engine, role-based testing with predefined security roles, a skills system with specialized testing skills, and comprehensive lifecycle management capabilities.

Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

A black hole for Internet advertisements

Disk encryption with strong security based on TrueCrypt

Common User Passwords Profiler (CUPP)

Open-source intelligence for the global theater. Track everything from the corporate/private jets of the wealthy, and spy satellites, to seismic events in one unified interface. Hook an AI agent up to have it parse through data and find previously unseen correlations. The knowledge is available to all but rarely aggregated in the open, until now.

Cross-platform GUI written in Rust using ADB to debloat non-rooted Android devices. Improve your privacy, the security and battery life of your device.

An open-source remote desktop application designed for self-hosting, as an alternative to TeamViewer.

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Multi-platform auto-proxy client, supporting Sing-box, X-ray, TUIC, Hysteria, Reality, Trojan, SSH etc. It’s an open-source, secure and ad-free.

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

🛜 ESPectre 👻 - Motion detection system based on Wi-Fi spectre analysis (CSI), with Home Assistant integration.

A list of OSINT tools & resources for (fraud-)investigators, CTI-analysts, KYC, AML and more.

A Hardware Hacking Tool with Web-Based CLI That Speaks Every Protocol

Xray, Penetrates Everything. Also the best v2ray-core. Where the magic happens. An open platform for various uses.

Policy-driven, layered isolation and containment

AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.

Star 0x4m4 / hexstrike-ai HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.

Star kaifcodec / user-scanner 🕵️ (2-in-1) Emaill and Username OSINT tool that analyzes username and email presence across multiple platforms, intended for security research, investigations, legitimate analysis

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

The Secure CommsOS™ for mission-critical operations

Useful tool to track location or mobile number

Star GH05TCREW / pentestagent PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.

Sponsor Star martin-olivier / airgorah A WiFi security auditing software mainly based on aircrack-ng tools suite

Star thalesgroup-cert / Watcher Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.

Star XTLS / RealiTLScanner A TLS server scanner for Reality

Star projectdiscovery / nuclei-templates Community curated list of templates for the nuclei engine to find security vulnerabilities.

Star NationalSecurityAgency / ghidra Ghidra is a software reverse engineering (SRE) framework

Sponsor Star GyulyVGC / sniffnet Comfortably monitor your Internet traffic 🕵️♂️

Sponsor Star keycloak / keycloak Open Source Identity and Access Management For Modern Applications and Services

Star hashicorp / vault A tool for secrets management, encryption as a service, and privileged access management

Star tailscale / tailscale The easiest, most secure way to use WireGuard and 2FA.

Sponsor Star netbirdio / netbird Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.

Sponsor Star qeeqbox / social-analyzer API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

Star EasyTier / EasyTier A simple, decentralized mesh VPN with WireGuard support.

Star signalapp / Signal-Server Server supporting the Signal Private Messenger applications on Android, Desktop, and iOS

Star fleetdm / fleet Open device management

Star signalapp / libsignal Home to the Signal Protocol as well as other cryptographic primitives which make Signal possible.

Your browser catches homograph attacks. Your terminal doesn't. Tirith guards the gate — intercepts suspicious URLs, ANSI injection, and pipe-to-shell attacks before they execute.

Security Scanner for Agent Skills
Paste a github.com URL. Submissions are reviewed before they are tracked.