Open Source Security Tools
Security tools help people find, assess, and reduce risks in software, networks, cloud environments, and digital services. They support tasks such as reviewing source code, detecting known vulnerabilities, mapping exposed assets, gathering public information, and testing defenses. Used throughout development and security operations, these tools can reveal weaknesses earlier and help teams understand their exposure, provided testing is authorized and findings are handled responsibly.
Open source options include static analyzers, dependency and vulnerability scanners, reconnaissance utilities, threat-detection tools, and penetration-testing frameworks. When choosing one, consider its license, maintenance activity, documentation, supported platforms, data handling, and fit with existing workflows. Check whether its findings are actionable and whether it requires specialist knowledge or infrastructure. These tools are useful to developers, security researchers, administrators, and organizations building or maintaining digital systems.
24 repositories · updated October 3, 2026

llm-guard: Add Security Checks to LLM Interactions
LLM Guard is a Python toolkit for screening prompts and model outputs for risks such as prompt injection, harmful content, and sensitive data. It is archived, so consider it for existing integrations or evaluation, not as a maintained security layer.

PYAS: Layered Endpoint Security for Windows
PYAS is a Windows endpoint security application that combines local machine-learning and YARA scanning with real-time monitoring, optional cloud analysis, and kernel-level controls. It suits security researchers and Windows users evaluating layered protection, with driver and remediation features best tested in an isolated environment.

GHunt: Investigate Google Accounts and Assets with OSINT
GHunt is a Python framework for investigating Google-related data, including email addresses, Gaia IDs, Drive files, and BSSIDs. It suits OSINT researchers and authorized investigators who need CLI or library workflows with JSON export.

waymore: Advanced URL and Archived Response Collection for Reconnaissance
waymore is a powerful Python tool designed to find an extensive collection of URLs from various web archiving and intelligence sources. Unlike other tools, it can also download archived responses, allowing for deeper analysis and discovery of hidden links or parameters. This makes waymore an essential asset for bug bounty hunters and security researchers focused on comprehensive reconnaissance.

Meta-GraphQL-Beautifier: Enhance Burp Suite for GraphQL Requests
Meta-GraphQL-Beautifier is a Burp Suite extension designed to improve the readability and analysis of Meta GraphQL requests. It provides beautification and highlighting features, making it easier for security professionals to work with complex GraphQL traffic. This tool streamlines the process of identifying and understanding potential vulnerabilities within GraphQL endpoints.

OSV-Scanner: Comprehensive Vulnerability Scanning for Your Projects
OSV-Scanner is a powerful vulnerability scanner developed by Google, written in Go. It leverages the comprehensive OSV.dev database to identify security flaws across a wide range of project types, including various languages, package managers, and container images. The tool also provides advanced features like guided remediation, license scanning, and offline scanning capabilities.

citadel: Analyze Windows Payloads and Malware Samples
Citadel is a self-hosted framework for static analysis of Windows payloads and malware samples. It combines PE parsing, capability mapping, and sample similarity analysis in a web interface for malware researchers and red teams.

malwoverview: Triage Malware and Hunt Threat Intelligence
Malwoverview is a Python first-response tool for investigating malware, indicators of compromise, IPs, domains, and vulnerabilities across threat-intelligence services. Use it to consolidate lookups, local file triage, and YARA scanning in CLI, REPL, or TUI workflows.

PayloadsAllTheThings: Find Web Security Payloads and Bypass Techniques
A community-maintained reference of payloads and bypass techniques for web application security testing. Use it to research vulnerability scenarios, support authorized penetration tests, and find ready-to-use Burp Intruder files.

Darkus: Search Onion Websites Across Search Engines
Darkus is a Python tool that sends a search term to deep- and dark-web search engines and returns matching links. It also offers a local database and an Ahmia blacklist check for research and educational use.

CloakQuest3r: Check for Exposed Origin IP Addresses
CloakQuest3r is a Python security research tool that checks whether websites behind Cloudflare or similar proxies may expose their origin IP. It combines subdomain scanning with historical IP and SSL certificate analysis for authorized defensive assessments.

CertoraProver: Formally Verify Smart Contracts
Certora Prover checks smart contracts against formal specifications to find violations before deployment. It targets developers and security teams working with EVM-based chains, Solana, or Stellar who need automated verification.