Open Source Security Projects
Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.
166 repositories · updated October 4, 2026

RustScan: Find Open Network Ports Quickly
RustScan is a Rust-based port scanner for quickly identifying open ports on hosts and networks. It can pass results to Nmap and run scripts, making it useful for authorized security testing and network assessment workflows.

IMSI-catcher: Identify Nearby GSM Subscriber Signals
IMSI-catcher uses GSM decoding tools and a software-defined radio receiver to display IMSI values and related carrier details from nearby cellphone signals. It is intended for GSM learning and authorized radio research, not casual use.

evilginx2: Test Reverse-Proxy Phishing Defenses
Evilginx2 is a Go-based reverse-proxy phishing framework that can capture credentials and session cookies, exposing weaknesses in some multifactor authentication setups. It is intended for authorized security testing and defensive research, not for use without written permission.

pyre-check: Check Python Types and Find Data Flows
Pyre is an incremental, performant type checker for Python, with Pysa for security-focused data-flow analysis. The repository is archived: type checking has moved to Pyrefly, and Pysa is maintained in a separate repository.

darkflare: Tunnel TCP Traffic Through a CDN
DarkFlare is a Go client-server tool that carries TCP connections through HTTP(S) requests routed via a CDN. It is intended for authorized access to TCP services across restrictive networks, with encryption for sensitive traffic supplied separately.

mantis: Automate Attack Surface Discovery and Security Scanning
Mantis is a Python command-line framework for discovering assets, running reconnaissance, and scanning for vulnerabilities, secrets, misconfigurations, and phishing domains. It is suited to product security teams managing organization-wide attack surfaces.

OpenArchiver: Archive and Search Email for Compliance
OpenArchiver is a self-hosted platform for importing, preserving, and searching email from major providers and common archive formats. It suits organizations that need searchable records and retention controls, with deployment and storage managed on their own infrastructure.

wiredoor: Expose Private Services Through Secure Tunnels
Wiredoor is a self-hosted ingress platform that routes HTTP, TCP, and UDP traffic to services on private networks through WireGuard tunnels. It suits teams and individuals who want to manage their own public entry point and service access.

NPMplus: Manage Self-Hosted Nginx Reverse Proxies
NPMplus is a Docker-oriented fork of nginx-proxy-manager that combines a web interface for managing proxy hosts with a hardened, feature-rich Nginx build. It suits self-hosters who want more protocol, authentication, and security options than the upstream project provides.

netmaker: Automate WireGuard Virtual Networks
Netmaker automates WireGuard networks across cloud, data center, and edge devices. It suits teams and self-hosters who need managed mesh, site-to-site, or remote-access connectivity without configuring every peer by hand.

forwardemail.net: Operate a Privacy-Focused Email Service
Forward Email is an email service codebase for domain-based forwarding and hosted mail, with web, SMTP, IMAP, POP3, CalDAV, and CardDAV services. It suits teams seeking to run or develop a privacy-focused email platform.

EasyTier: Build Decentralized Mesh VPNs
EasyTier connects devices across networks through a decentralized virtual private network, with NAT traversal and optional relay nodes. It suits people who need private connectivity between remote devices or subnets without relying on a centralized VPN service.