Open Source Security Projects
Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.
166 repositories · updated October 4, 2026

sshx: Share a Collaborative Terminal Over the Web
sshx lets people share a live terminal through a web link, with real-time collaboration and end-to-end encryption. It suits remote troubleshooting, pairing, and temporary access to a terminal, including from CI jobs.

Threat_Model_Examples: Browse Threat Modeling References
A curated collection of threat model examples and guidance for systems ranging from web applications and cloud services to AI, IoT, and medical devices. Use it to see how threat models are presented and find references relevant to your work.

simplex-chat: Private Messaging Without User Identifiers
SimpleX Chat is an end-to-end encrypted messaging platform designed to work without persistent user identifiers. It offers mobile and desktop apps, plus a terminal client, for people who want to reduce exposure of their contacts and messaging metadata.

wassette: Run WebAssembly Tools Through MCP
Wassette lets AI agents load and use WebAssembly Components through the Model Context Protocol. It is aimed at developers who want reusable tools running in Wasmtime’s security sandbox, but the project warns that it is not production-ready.

QDoctor: Inspect Windows Systems for Rootkits and Threats
QDoctor is a Windows incident-response and anti-rootkit utility for examining system, process, kernel, network, and file activity. Responders can export structured host data for offline review or import it for investigation.

magic-wormhole: Transfer Files Safely Between Computers
Magic Wormhole is a Python library and command-line tool for sending files, directories, or short text between computers using a one-time, human-readable code. It is useful when you want a simple transfer without exchanging a permanent account or memorizing credentials.

MyIP: Diagnose IP, Privacy, and Network Issues
MyIP is a self-hostable web toolbox for checking IP addresses, privacy leaks, connectivity, and network routes. It suits privacy-conscious users and administrators who want a broad set of diagnostics in one interface.

gunnery: Run Tasks Across Remote Servers
Gunnery is a web-based tool for running shell tasks across servers and environments. It suits teams that repeat operational work such as deployments, service restarts, backups, and health checks, and need centralized access controls and notifications.

Harden-Windows-Security: Apply Supported Windows Security Controls
A Windows security project with apps and guidance for hardening devices through built-in Microsoft security features. It covers system configuration, compliance checks, and application control for personal users and managed environments.

auth-sdk: Add Authentication to Saleor Storefronts
Saleor Auth SDK provides token-based authentication and authorization for storefronts using the Saleor API. It connects auth flows with React and GraphQL clients, with helpers for Next.js server-side cookie storage and OpenID Connect.

subwiz: Discover Subdomains with a Lightweight GPT Model
subwiz uses a small transformer model to predict candidate subdomains from known subdomains, then can check whether predictions resolve. It is aimed at security teams and researchers who want an additional discovery step after passive enumeration.

trident: Fuzz Test Solana Programs
Trident is a Rust framework for fuzz testing Solana programs through guided, stateful transaction sequences. It helps Solana developers and auditors explore edge cases and check program behavior beyond conventional unit tests.