Open Source Cybersecurity Projects

Discover 47 open source Cybersecurity repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Cybersecurity projects here are most often combined with Security, Python and Security Tools. Last updated October 4, 2026.

47 repositories · updated October 4, 2026

vuln-bank: Practice Web, API, and AI Security Testing

vuln-bank: Practice Web, API, and AI Security Testing

Vuln Bank is an intentionally vulnerable banking web app for learning application security testing and secure code review. It offers hands-on scenarios across web, API, GraphQL, and AI features, and should only run in an isolated educational environment.

SecurityCybersecurityWeb App
Added Dec 26, 2025 View details
theProtector: Monitor Linux Hosts for Security Threats

theProtector: Monitor Linux Hosts for Security Threats

theProtector is a Bash-based Linux host monitoring tool that combines process, file, and network checks with optional eBPF and YARA detection. It is aimed at administrators who want a configurable, self-managed security monitor and can support its system requirements.

ShellLinuxCybersecurity
Added Dec 24, 2025 View details
Threat_Model_Examples: Browse Threat Modeling References

Threat_Model_Examples: Browse Threat Modeling References

A curated collection of threat model examples and guidance for systems ranging from web applications and cloud services to AI, IoT, and medical devices. Use it to see how threat models are presented and find references relevant to your work.

CybersecuritySecurityResources
Added Dec 23, 2025 View details
QDoctor: Inspect Windows Systems for Rootkits and Threats

QDoctor: Inspect Windows Systems for Rootkits and Threats

QDoctor is a Windows incident-response and anti-rootkit utility for examining system, process, kernel, network, and file activity. Responders can export structured host data for offline review or import it for investigation.

SecurityCybersecurityWindows
Added Dec 12, 2025 View details
Ghosting-AMSI: Intercept AMSI Scans Through RPC

Ghosting-AMSI: Intercept AMSI Scans Through RPC

Ghosting-AMSI is a PowerShell proof of concept for intercepting AMSI scan requests at the Windows RPC layer. It is aimed at security researchers studying AMSI and antivirus-provider communication, not routine application development.

PowershellWindowsCybersecurity
Added Dec 5, 2025 View details
Harden-Windows-Security: Apply Supported Windows Security Controls

Harden-Windows-Security: Apply Supported Windows Security Controls

A Windows security project with apps and guidance for hardening devices through built-in Microsoft security features. It covers system configuration, compliance checks, and application control for personal users and managed environments.

WindowsSecurityCybersecurity
Added Dec 2, 2025 View details
subwiz: Discover Subdomains with a Lightweight GPT Model

subwiz: Discover Subdomains with a Lightweight GPT Model

subwiz uses a small transformer model to predict candidate subdomains from known subdomains, then can check whether predictions resolve. It is aimed at security teams and researchers who want an additional discovery step after passive enumeration.

PythonAIMachine Learning
Added Nov 27, 2025 View details
evilginx2: Test Reverse-Proxy Phishing Defenses

evilginx2: Test Reverse-Proxy Phishing Defenses

Evilginx2 is a Go-based reverse-proxy phishing framework that can capture credentials and session cookies, exposing weaknesses in some multifactor authentication setups. It is intended for authorized security testing and defensive research, not for use without written permission.

GoSecurityCybersecurity
Added Nov 18, 2025 View details
FuncVul: Detect Vulnerabilities in Code Functions

FuncVul: Detect Vulnerabilities in Code Functions

FuncVul is a research model for detecting vulnerable code chunks within C/C++ and Python functions. It uses fine-tuned GraphCodeBERT and provides six labeled datasets for evaluating function-level vulnerability detection.

PythonMachine LearningLLM
Added Nov 10, 2025 View details
awesome-api-security: Find API Security Tools and Resources

awesome-api-security: Find API Security Tools and Resources

A curated directory of API security tools, guidance, and learning materials for developers and security practitioners. Use it to find resources for API testing, hardening, research, and hands-on training.

SecurityCybersecurityAPI
Added Nov 5, 2025 View details
Argus: Gather Information for Security Reconnaissance

Argus: Gather Information for Security Reconnaissance

Argus is a Python toolkit that combines network, web application, and threat-intelligence reconnaissance modules in an interactive CLI. It suits analysts who want to run and manage varied checks from one tool, with explicit authorization for every target.

PythonCLICybersecurity
Added Nov 4, 2025 View details
opengrep: Find Security Issues with Static Code Analysis

opengrep: Find Security Issues with Static Code Analysis

Opengrep is an OCaml static analysis engine that searches code for patterns and security issues using customizable rules. It suits developers and security teams who want Semgrep-compatible scanning, taint analysis, and JSON or SARIF output under an LGPL-2.1 license.

SecurityCode AnalysisDeveloper Tools
Added Nov 3, 2025 View details

Related topics

OS
OSRepos

Analysis and discovery of open source repositories. Find interesting projects and follow their updates.

Monitor your website with YourWebsiteScore

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of third-party repository code is at your own risk. Always review source code, dependencies, licenses, and security implications before running anything.

© 2025 OSRepos. Built with Nuxt 3 and lots of ❤️