Open Source Security Projects
Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.
166 repositories · updated October 4, 2026

fixinventory: Find Security Risks Across Cloud Infrastructure
Fix Inventory collects cloud and Kubernetes asset data, normalizes it into a shared model, and helps teams find security and compliance risks. It suits engineers who need cross-cloud inventory, policy checks, and relationship-aware investigation.

DnsServer: Run a Self-Hosted DNS Server
Technitium DNS Server is a cross-platform DNS server for recursive resolution, authoritative hosting, and network-wide filtering. It suits home labs and organizations that want control over DNS, encrypted upstreams, and a browser-based management console.

graphql-engine: Build GraphQL APIs Across Your Data
Hasura GraphQL Engine turns connected data sources into a composable GraphQL API with fine-grained access control. It suits teams that want to expose database-backed data through a managed API layer rather than build each resolver and access rule by hand.

wush: Transfer Files and Open Shells Over WireGuard
wush is a command-line tool for transferring files and opening remote shells over peer-to-peer WireGuard connections. It suits people who need a direct, authenticated connection without setting up a relay or relying on a third-party authentication server.

edb: Debug Ethereum Smart Contracts at the Source Level
EDB is a source-level debugger for replaying Ethereum transactions and inspecting Solidity execution. It offers step controls, variable inspection, expression evaluation, breakpoints, watchpoints, and browser or terminal interfaces.

Meta-GraphQL-Beautifier: Format and Highlight Meta GraphQL Requests
A Burp Suite extension for making Meta GraphQL requests easier to inspect. It beautifies request content and highlights it in Burp, helping security testers and developers review traffic.

osv-scanner: Find Vulnerabilities in Project Dependencies
OSV-Scanner checks project dependencies, container images, and Linux packages for known vulnerabilities using the OSV database. It is a Go CLI for development and security teams that need actionable findings across multiple ecosystems.

sshpot: Log SSH Login Attempts with a Honeypot
sshpot is a small SSH honeypot that never authenticates users and records attempted usernames, passwords, source IP addresses, and times. It is suited to security researchers or administrators who want to observe SSH login attempts in a controlled environment.

netgoat: Self-Host a Reverse Proxy and Traffic Policy Agent
NetGoat is a Go-based reverse proxy for routing traffic through local or cloud deployments, with controls for authentication, caching, rate limits, and security rules. It suits operators who want self-hosted traffic management and optional Cloudflare integrations.

authkit: Add Hosted or Custom Authentication to Your App
AuthKit is a WorkOS authentication example project showing how to use a hosted sign-in experience or build a custom UI with headless User Management APIs. It is aimed at developers adding WorkOS-backed authentication to an application.

tailpipe: Query Cloud and Application Logs with SQL
Tailpipe is a local, terminal-based log analytics and SIEM tool powered by DuckDB. It collects logs from cloud, container, and application sources so developers and security teams can query events and use prebuilt detections without sending data to a hosted analytics service.

tailscale: Connect Devices with Private WireGuard Networks
Tailscale provides private networks that connect devices using WireGuard, with authentication features such as two-factor authentication. Its Go-based daemon and CLI support several desktop and server platforms, making it useful for secure access without managing a traditional VPN setup.