Open Source Security Projects
Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.
166 repositories · updated October 4, 2026

coraza: Add a Go Web Application Firewall to Your Stack
Coraza is a Go library for building web application firewalls that process ModSecurity-compatible SecLang rules. It supports OWASP Core Rule Set v4 and can be embedded in Go applications or used through server integrations.

shellhub: Remotely Access Linux Devices over SSH
ShellHub provides a centralized SSH gateway for remotely managing Linux servers, embedded systems, and containers. Use it to reach devices without exposing their public IPs or configuring network access individually.

PatchMon: Manage and Patch Linux Server Fleets
PatchMon is a self-hosted platform for monitoring, securing, and patching server fleets from one interface. Its outbound-only agents support Linux, FreeBSD, and Windows, with patch approvals, compliance scans, inventory, and audit history.

1Panel: Manage Linux Servers and AI Services
1Panel is a web-based control panel for managing Linux servers, containers, websites, databases, backups, and AI agents. It suits self-hosters and administrators who want a visual interface for common operations and app deployment.

docker-tinyauth: Run Tinyauth as a Rootless Container
A Docker image for Tinyauth, an authentication middleware for protecting apps behind popular reverse proxies. It emphasizes a small, distroless, rootless runtime for self-hosted deployments.

Red-Team-Playbooks: Plan and Reference Red Team Assessments
A collection of notes and tools organized around stages of red team operations, from reconnaissance through actions on objectives. It is intended for security practitioners who need a browsable reference while planning or conducting authorized assessments.

awesome-list: Browse Cybersecurity Research and Write-Ups
A curated, year-organized collection of cybersecurity blog posts, write-ups, and papers. Useful for researchers, practitioners, and learners exploring exploitation, reverse engineering, vulnerability research, and related topics.

wBlock: Block Ads and Trackers in Safari
wBlock is a free Safari content blocker for Mac, iPhone, iPad, and Apple Vision Pro. It combines filter lists with a scripts extension for userscripts, userstyles, and page-level controls.

buffer-overflow-lab: Demonstrate Web Application Buffer Overflows
A Python and Flask lab for safely demonstrating buffer overflow vulnerabilities in web applications. It combines a manual testing interface with an automated exploit script for secure software development training.

OpenSign: Create and Manage Electronic Signatures
OpenSign is a self-hostable document-signing platform for creating, sending, and tracking electronic signatures on PDFs. It supports multiple signers, reusable templates, audit trails, and API integrations.

disposable-email-domains: Block Disposable Email Addresses
A maintained domain list for identifying disposable and temporary email addresses during account registration and other validation workflows. Use it as data for your own checks, with matching logic that accounts for public-suffix domains.

Zero: Self-Host an AI-Powered Email App
Zero is a self-hostable email app that connects accounts such as Gmail and Outlook in a unified inbox, with AI agents to modernize email workflows. It suits people who want an extensible alternative to closed email apps and are prepared to configure and operate the services it needs.