Open Source Cybersecurity Projects
Discover 47 open source Cybersecurity repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Cybersecurity projects here are most often combined with Security, Python and Security Tools. Last updated October 4, 2026.
47 repositories · updated October 4, 2026

vuln-bank: Practice Web, API, and AI Security Testing
Vuln Bank is an intentionally vulnerable banking web app for learning application security testing and secure code review. It offers hands-on scenarios across web, API, GraphQL, and AI features, and should only run in an isolated educational environment.

theProtector: Monitor Linux Hosts for Security Threats
theProtector is a Bash-based Linux host monitoring tool that combines process, file, and network checks with optional eBPF and YARA detection. It is aimed at administrators who want a configurable, self-managed security monitor and can support its system requirements.

Threat_Model_Examples: Browse Threat Modeling References
A curated collection of threat model examples and guidance for systems ranging from web applications and cloud services to AI, IoT, and medical devices. Use it to see how threat models are presented and find references relevant to your work.

QDoctor: Inspect Windows Systems for Rootkits and Threats
QDoctor is a Windows incident-response and anti-rootkit utility for examining system, process, kernel, network, and file activity. Responders can export structured host data for offline review or import it for investigation.

Ghosting-AMSI: Intercept AMSI Scans Through RPC
Ghosting-AMSI is a PowerShell proof of concept for intercepting AMSI scan requests at the Windows RPC layer. It is aimed at security researchers studying AMSI and antivirus-provider communication, not routine application development.

Harden-Windows-Security: Apply Supported Windows Security Controls
A Windows security project with apps and guidance for hardening devices through built-in Microsoft security features. It covers system configuration, compliance checks, and application control for personal users and managed environments.

subwiz: Discover Subdomains with a Lightweight GPT Model
subwiz uses a small transformer model to predict candidate subdomains from known subdomains, then can check whether predictions resolve. It is aimed at security teams and researchers who want an additional discovery step after passive enumeration.

evilginx2: Test Reverse-Proxy Phishing Defenses
Evilginx2 is a Go-based reverse-proxy phishing framework that can capture credentials and session cookies, exposing weaknesses in some multifactor authentication setups. It is intended for authorized security testing and defensive research, not for use without written permission.

FuncVul: Detect Vulnerabilities in Code Functions
FuncVul is a research model for detecting vulnerable code chunks within C/C++ and Python functions. It uses fine-tuned GraphCodeBERT and provides six labeled datasets for evaluating function-level vulnerability detection.

awesome-api-security: Find API Security Tools and Resources
A curated directory of API security tools, guidance, and learning materials for developers and security practitioners. Use it to find resources for API testing, hardening, research, and hands-on training.

Argus: Gather Information for Security Reconnaissance
Argus is a Python toolkit that combines network, web application, and threat-intelligence reconnaissance modules in an interactive CLI. It suits analysts who want to run and manage varied checks from one tool, with explicit authorization for every target.

opengrep: Find Security Issues with Static Code Analysis
Opengrep is an OCaml static analysis engine that searches code for patterns and security issues using customizable rules. It suits developers and security teams who want Semgrep-compatible scanning, taint analysis, and JSON or SARIF output under an LGPL-2.1 license.