Open Source Security Tools
Discover 26 open source Security Tools repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security Tools projects here are most often combined with Cybersecurity, Security and Python. Last updated October 4, 2026.
26 repositories · updated October 4, 2026

theProtector: Monitor Linux Hosts for Security Threats
theProtector is a Bash-based Linux host monitoring tool that combines process, file, and network checks with optional eBPF and YARA detection. It is aimed at administrators who want a configurable, self-managed security monitor and can support its system requirements.

QDoctor: Inspect Windows Systems for Rootkits and Threats
QDoctor is a Windows incident-response and anti-rootkit utility for examining system, process, kernel, network, and file activity. Responders can export structured host data for offline review or import it for investigation.

Ghosting-AMSI: Intercept AMSI Scans Through RPC
Ghosting-AMSI is a PowerShell proof of concept for intercepting AMSI scan requests at the Windows RPC layer. It is aimed at security researchers studying AMSI and antivirus-provider communication, not routine application development.

Harden-Windows-Security: Apply Supported Windows Security Controls
A Windows security project with apps and guidance for hardening devices through built-in Microsoft security features. It covers system configuration, compliance checks, and application control for personal users and managed environments.

RustScan: Find Open Network Ports Quickly
RustScan is a Rust-based port scanner for quickly identifying open ports on hosts and networks. It can pass results to Nmap and run scripts, making it useful for authorized security testing and network assessment workflows.

evilginx2: Test Reverse-Proxy Phishing Defenses
Evilginx2 is a Go-based reverse-proxy phishing framework that can capture credentials and session cookies, exposing weaknesses in some multifactor authentication setups. It is intended for authorized security testing and defensive research, not for use without written permission.

mantis: Automate Attack Surface Discovery and Security Scanning
Mantis is a Python command-line framework for discovering assets, running reconnaissance, and scanning for vulnerabilities, secrets, misconfigurations, and phishing domains. It is suited to product security teams managing organization-wide attack surfaces.

Argus: Gather Information for Security Reconnaissance
Argus is a Python toolkit that combines network, web application, and threat-intelligence reconnaissance modules in an interactive CLI. It suits analysts who want to run and manage varied checks from one tool, with explicit authorization for every target.

hexora: Scan Python Code for Malicious Patterns
Hexora analyzes Python source for suspicious behavior using static rules and a machine-learned file score. It is intended for security teams and developers reviewing packages, dependencies, and scripts for potential threats.

Red-Team-Playbooks: Plan and Reference Red Team Assessments
A collection of notes and tools organized around stages of red team operations, from reconnaissance through actions on objectives. It is intended for security practitioners who need a browsable reference while planning or conducting authorized assessments.

matkap: Investigate Malicious Telegram Bots
Matkap is a self-hosted web tool for authorized investigations of Telegram bots used for malware command and control. It helps security researchers find exposed bot credentials, examine bot activity, and correlate indicators with threat-intelligence sources.

hexstrike-ai: Connect AI Agents to Security Testing Tools
HexStrike AI is an MCP server that connects compatible AI agents to cybersecurity tools for authorized penetration testing, vulnerability discovery, and security research. It combines tool execution with specialized agents and workflow support.