Open Source Security Tools

Security tools help people find, assess, and reduce risks in software, networks, cloud environments, and digital services. They support tasks such as reviewing source code, detecting known vulnerabilities, mapping exposed assets, gathering public information, and testing defenses. Used throughout development and security operations, these tools can reveal weaknesses earlier and help teams understand their exposure, provided testing is authorized and findings are handled responsibly.

Open source options include static analyzers, dependency and vulnerability scanners, reconnaissance utilities, threat-detection tools, and penetration-testing frameworks. When choosing one, consider its license, maintenance activity, documentation, supported platforms, data handling, and fit with existing workflows. Check whether its findings are actionable and whether it requires specialist knowledge or infrastructure. These tools are useful to developers, security researchers, administrators, and organizations building or maintaining digital systems.

24 repositories · updated October 3, 2026

llm-guard: Add Security Checks to LLM Interactions

llm-guard: Add Security Checks to LLM Interactions

LLM Guard is a Python toolkit for screening prompts and model outputs for risks such as prompt injection, harmful content, and sensitive data. It is archived, so consider it for existing integrations or evaluation, not as a maintained security layer.

PythonLLMSecurity Tools
Added Jun 26, 2026 View details
PYAS: Layered Endpoint Security for Windows

PYAS: Layered Endpoint Security for Windows

PYAS is a Windows endpoint security application that combines local machine-learning and YARA scanning with real-time monitoring, optional cloud analysis, and kernel-level controls. It suits security researchers and Windows users evaluating layered protection, with driver and remediation features best tested in an isolated environment.

WindowsSecurityMachine Learning
Added Jun 13, 2026 View details
GHunt: Investigate Google Accounts and Assets with OSINT

GHunt: Investigate Google Accounts and Assets with OSINT

GHunt is a Python framework for investigating Google-related data, including email addresses, Gaia IDs, Drive files, and BSSIDs. It suits OSINT researchers and authorized investigators who need CLI or library workflows with JSON export.

PythonOsintSecurity Tools
Added May 16, 2026 View details
waymore: Advanced URL and Archived Response Collection for Reconnaissance

waymore: Advanced URL and Archived Response Collection for Reconnaissance

waymore is a powerful Python tool designed to find an extensive collection of URLs from various web archiving and intelligence sources. Unlike other tools, it can also download archived responses, allowing for deeper analysis and discovery of hidden links or parameters. This makes waymore an essential asset for bug bounty hunters and security researchers focused on comprehensive reconnaissance.

PythonBug BountyReconnaissance
Added May 15, 2026 View details
Meta-GraphQL-Beautifier: Enhance Burp Suite for GraphQL Requests

Meta-GraphQL-Beautifier: Enhance Burp Suite for GraphQL Requests

Meta-GraphQL-Beautifier is a Burp Suite extension designed to improve the readability and analysis of Meta GraphQL requests. It provides beautification and highlighting features, making it easier for security professionals to work with complex GraphQL traffic. This tool streamlines the process of identifying and understanding potential vulnerabilities within GraphQL endpoints.

PythonBurp SuiteGraphQL
Added Apr 3, 2026 View details
OSV-Scanner: Comprehensive Vulnerability Scanning for Your Projects

OSV-Scanner: Comprehensive Vulnerability Scanning for Your Projects

OSV-Scanner is a powerful vulnerability scanner developed by Google, written in Go. It leverages the comprehensive OSV.dev database to identify security flaws across a wide range of project types, including various languages, package managers, and container images. The tool also provides advanced features like guided remediation, license scanning, and offline scanning capabilities.

ScannerSecurity AuditSecurity Tools
Added Apr 3, 2026 View details
citadel: Analyze Windows Payloads and Malware Samples

citadel: Analyze Windows Payloads and Malware Samples

Citadel is a self-hosted framework for static analysis of Windows payloads and malware samples. It combines PE parsing, capability mapping, and sample similarity analysis in a web interface for malware researchers and red teams.

CybersecuritySecurity ToolsWeb App
Added Mar 20, 2026 View details
malwoverview: Triage Malware and Hunt Threat Intelligence

malwoverview: Triage Malware and Hunt Threat Intelligence

Malwoverview is a Python first-response tool for investigating malware, indicators of compromise, IPs, domains, and vulnerabilities across threat-intelligence services. Use it to consolidate lookups, local file triage, and YARA scanning in CLI, REPL, or TUI workflows.

PythonCybersecuritySecurity Tools
Added Mar 10, 2026 View details
PayloadsAllTheThings: Find Web Security Payloads and Bypass Techniques

PayloadsAllTheThings: Find Web Security Payloads and Bypass Techniques

A community-maintained reference of payloads and bypass techniques for web application security testing. Use it to research vulnerability scenarios, support authorized penetration tests, and find ready-to-use Burp Intruder files.

SecurityCybersecuritySecurity Tools
Added Jan 28, 2026 View details
Darkus: Search Onion Websites Across Search Engines

Darkus: Search Onion Websites Across Search Engines

Darkus is a Python tool that sends a search term to deep- and dark-web search engines and returns matching links. It also offers a local database and an Ahmia blacklist check for research and educational use.

PythonCybersecurityCLI
Added Jan 23, 2026 View details
CloakQuest3r: Check for Exposed Origin IP Addresses

CloakQuest3r: Check for Exposed Origin IP Addresses

CloakQuest3r is a Python security research tool that checks whether websites behind Cloudflare or similar proxies may expose their origin IP. It combines subdomain scanning with historical IP and SSL certificate analysis for authorized defensive assessments.

PythonSecurityCybersecurity
Added Jan 9, 2026 View details
CertoraProver: Formally Verify Smart Contracts

CertoraProver: Formally Verify Smart Contracts

Certora Prover checks smart contracts against formal specifications to find violations before deployment. It targets developers and security teams working with EVM-based chains, Solana, or Stellar who need automated verification.

SecuritySecurity ToolsBlockchain
Added Dec 27, 2025 View details
Previous Page 1 Next

Related topics

OS
OSRepos

Analysis and discovery of open source repositories. Find interesting projects and follow their updates.

Monitor your website with YourWebsiteScore

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of third-party repository code is at your own risk. Always review source code, dependencies, licenses, and security implications before running anything.

© 2025 OSRepos. Built with Nuxt 3 and lots of ❤️