Open Source Cybersecurity Projects
Discover 47 open source Cybersecurity repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Cybersecurity projects here are most often combined with Security, Python and Security Tools. Last updated October 4, 2026.
47 repositories · updated October 4, 2026

vulnapi: Scan APIs for Security Vulnerabilities
VulnAPI is a Go-based dynamic security scanner for APIs. It can discover exposed API-related resources and scan targets using curl-like requests or OpenAPI contracts, helping developers and security teams identify common weaknesses.

coraza: Add a Go Web Application Firewall to Your Stack
Coraza is a Go library for building web application firewalls that process ModSecurity-compatible SecLang rules. It supports OWASP Core Rule Set v4 and can be embedded in Go applications or used through server integrations.

SWE-agent: Use Language Models to Fix GitHub Issues
SWE-agent gives a language model tools to work on real software repositories, including diagnosing and attempting to fix GitHub issues. It is designed for software engineering research and configurable coding tasks, though its maintainers now recommend mini-SWE-agent for new use.

Red-Team-Playbooks: Plan and Reference Red Team Assessments
A collection of notes and tools organized around stages of red team operations, from reconnaissance through actions on objectives. It is intended for security practitioners who need a browsable reference while planning or conducting authorized assessments.

awesome-list: Browse Cybersecurity Research and Write-Ups
A curated, year-organized collection of cybersecurity blog posts, write-ups, and papers. Useful for researchers, practitioners, and learners exploring exploitation, reverse engineering, vulnerability research, and related topics.

matkap: Investigate Malicious Telegram Bots
Matkap is a self-hosted web tool for authorized investigations of Telegram bots used for malware command and control. It helps security researchers find exposed bot credentials, examine bot activity, and correlate indicators with threat-intelligence sources.

hexstrike-ai: Connect AI Agents to Security Testing Tools
HexStrike AI is an MCP server that connects compatible AI agents to cybersecurity tools for authorized penetration testing, vulnerability discovery, and security research. It combines tool execution with specialized agents and workflow support.

buffer-overflow-lab: Demonstrate Web Application Buffer Overflows
A Python and Flask lab for safely demonstrating buffer overflow vulnerabilities in web applications. It combines a manual testing interface with an automated exploit script for secure software development training.

maigret: Find a Person’s Accounts by Username
Maigret searches thousands of websites for accounts matching a username and gathers public profile information into reports. It is an OSINT tool for investigators, researchers, and developers who need to check username reuse across platforms.

linux-persistence: Demonstrate Linux Persistence Techniques
A Go project presenting Linux persistence and covert-access techniques for security research and authorized testing. Its README describes a broad set of mechanisms, including scheduled tasks, authentication changes, and network-based access.

Awesome-Blackhat-Tools: Find Tools Presented at Black Hat
A curated index of cybersecurity tools officially presented at Black Hat events worldwide. Browse by event region, year, or security category to find tools relevant to offensive, defensive, and research work.