Open Source Cybersecurity Projects
Cybersecurity is the practice of protecting systems, networks, applications, and data from unauthorized access, disruption, and misuse. It combines prevention, detection, response, and recovery to reduce risk and help organizations understand and address vulnerabilities, malicious activity, and changing threats. Open source work in this field makes techniques and code available for inspection, adaptation, and learning.
The category includes tools for vulnerability assessment, network and application testing, threat intelligence, malware analysis, digital investigation, and security education. When choosing a tool, consider its license, documentation, maintenance activity, compatibility with your environment, data handling, and the expertise needed to use it safely. These resources can support security professionals, developers, researchers, students, and organizations building or improving their security practices.
47 repositories · updated October 4, 2026

awesome-ai-agent-attacks: Track Documented AI Agent Security Incidents
A sourced timeline of real AI agent security incidents, breaches, and vulnerabilities from 2024 to 2026. Useful for security researchers, incident responders, and teams assessing risks in agentic systems.

ADR: Secure and Monitor Enterprise AI Agents
ADR is an enterprise security toolkit for discovering AI tools, collecting agent activity, benchmarking defenses, and detecting risky behavior. It is aimed at security teams evaluating or monitoring AI agents across employee endpoints and customer-facing systems.

awesome-web-security: Find Web Security Learning Resources
A curated directory of web security articles, tools, and references covering vulnerability classes, testing techniques, and browser security. Useful for security learners and practitioners who need a starting point for research or authorized testing.

llm-guard: Add Security Checks to LLM Interactions
LLM Guard is a Python toolkit for screening prompts and model outputs for risks such as prompt injection, harmful content, and sensitive data. It is archived, so consider it for existing integrations or evaluation, not as a maintained security layer.

Anthropic-Cybersecurity-Skills: Give AI Agents Security Playbooks
A library of structured cybersecurity workflows for AI agents, covering 34 security domains and mapped to six industry frameworks. Use it to provide compatible agents with practical guidance for authorized security work.

waymore: Find and Download Archived URLs
waymore collects historical URLs from web archives and threat-intelligence sources, and can download archived responses for further analysis. It is aimed at security researchers and bug bounty hunters who value broad coverage over speed.

NoDPI: Bypass Some Deep Packet Inspection Blocking
NoDPI is a desktop proxy utility that fragments HTTPS ClientHello traffic to help bypass some DPI-based website blocking. It is suited to users who can configure a local proxy and understand that it does not provide VPN-style privacy.

fixinventory: Find Security Risks Across Cloud Infrastructure
Fix Inventory collects cloud and Kubernetes asset data, normalizes it into a shared model, and helps teams find security and compliance risks. It suits engineers who need cross-cloud inventory, policy checks, and relationship-aware investigation.

osv-scanner: Find Vulnerabilities in Project Dependencies
OSV-Scanner checks project dependencies, container images, and Linux packages for known vulnerabilities using the OSV database. It is a Go CLI for development and security teams that need actionable findings across multiple ecosystems.

sshpot: Log SSH Login Attempts with a Honeypot
sshpot is a small SSH honeypot that never authenticates users and records attempted usernames, passwords, source IP addresses, and times. It is suited to security researchers or administrators who want to observe SSH login attempts in a controlled environment.

citadel: Analyze Windows Payloads and Malware Samples
Citadel is a self-hosted framework for static analysis of Windows payloads and malware samples. It combines PE parsing, capability mapping, and sample similarity analysis in a web interface for malware researchers and red teams.

malwoverview: Triage Malware and Hunt Threat Intelligence
Malwoverview is a Python first-response tool for investigating malware, indicators of compromise, IPs, domains, and vulnerabilities across threat-intelligence services. Use it to consolidate lookups, local file triage, and YARA scanning in CLI, REPL, or TUI workflows.