Open Source Security Projects

Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.

166 repositories · updated October 4, 2026

awesome-threat-modelling: Find Threat Modeling Learning Resources

awesome-threat-modelling: Find Threat Modeling Learning Resources

A curated directory of threat modeling books, courses, videos, tutorials, examples, and tools. It helps developers and security practitioners find learning material and practical references for security reviews.

Awesome ListResourcesSecurity
Added Feb 26, 2026 View details
openresty-manager: Manage Reverse Proxies and Servers

openresty-manager: Manage Reverse Proxies and Servers

OpenResty Manager is a web control panel for managing OpenResty reverse proxies, hosts, certificates, and containers. It suits self-hosters and administrators who want centralized site security and multi-node CDN management without configuring everything by hand.

GoSelf HostedProxy
Added Feb 23, 2026 View details
awesome-osint: Find Open-Source Intelligence Tools and Resources

awesome-osint: Find Open-Source Intelligence Tools and Resources

A curated directory of OSINT tools and resources for security researchers, threat hunters, and investigators. Browse categories spanning search, social networks, people research, geospatial intelligence, and threat intelligence.

Awesome ListSecurityCybersecurity
Added Feb 23, 2026 View details
openaev: Plan and Run Cyber Adversary Simulations

openaev: Plan and Run Cyber Adversary Simulations

OpenAEV helps security teams plan, schedule, and run adversary simulation campaigns and exercises. Use it to coordinate teams, monitor activity, and review security gaps in relation to current threats.

CybersecuritySecurityJava
Added Feb 22, 2026 View details
supertokens-core: Build Authentication Into Your Applications

supertokens-core: Build Authentication Into Your Applications

SuperTokens Core is a self-hostable authentication service that handles core login, user, and session operations for backend SDKs. It suits teams that want managed auth features while keeping user data in their own database and deployment.

JavaAuthenticationSecurity
Added Feb 10, 2026 View details
authelia: Add SSO and Multi-Factor Authentication to Web Apps

authelia: Add SSO and Multi-Factor Authentication to Web Apps

Authelia is a self-hosted authentication and authorization server that protects web applications through reverse proxies. It provides SSO, configurable access rules, and multiple second-factor and passwordless authentication methods.

GoGolangSecurity
Added Feb 9, 2026 View details
Disposable Email Validator: Block Disposable Emails and Plus Addressing

Disposable Email Validator: Block Disposable Emails and Plus Addressing

The `disposable-email-validator` library helps prevent fake signups by blocking disposable email addresses and optional plus addressing. It offers flexible, environment-specific rules, making it ideal for production applications while allowing development flexibility. This TypeScript-based tool provides a robust solution for email validation.

TypeScriptEmail ValidationSecurity
Added Feb 6, 2026 View details
Damn-Vulnerable-RESTaurant-API-Game: Practice API Security

Damn-Vulnerable-RESTaurant-API-Game: Practice API Security

A deliberately insecure Python API for practicing vulnerability discovery, exploitation, and remediation. Developers, ethical hackers, and security engineers can run it locally with Docker as a controlled training environment.

PythonAPISecurity
Added Feb 1, 2026 View details
giskard-oss: Test and Red-Team LLM Agents

giskard-oss: Test and Red-Team LLM Agents

Giskard is a Python toolkit for evaluating agent behavior and probing AI systems for vulnerabilities. It suits teams building LLM agents or RAG applications that need repeatable checks, safety testing, and adversarial evaluation.

PythonLLMAI Agents
Added Jan 30, 2026 View details
microsandbox: Run Untrusted Workloads in Local MicroVMs

microsandbox: Run Untrusted Workloads in Local MicroVMs

Microsandbox runs untrusted code in local microVMs and provides a CLI and SDKs for managing isolated workloads. It suits developers and agent builders who need disposable, programmable sandboxes without a separate infrastructure service.

RustMicrovmSandbox
Added Jan 28, 2026 View details
PayloadsAllTheThings: Find Web Security Payloads and Bypass Techniques

PayloadsAllTheThings: Find Web Security Payloads and Bypass Techniques

A community-maintained reference of payloads and bypass techniques for web application security testing. Use it to research vulnerability scenarios, support authorized penetration tests, and find ready-to-use Burp Intruder files.

SecurityCybersecuritySecurity Tools
Added Jan 28, 2026 View details
slim: Analyze and Minify Container Images

slim: Analyze and Minify Container Images

Slim inspects container images and uses runtime analysis to create smaller images with a reduced attack surface. It is for developers and platform teams who want to optimize containers without manually rebuilding their Dockerfiles.

GoGolangDocker
Added Jan 27, 2026 View details

Related topics

OS
OSRepos

Analysis and discovery of open source repositories. Find interesting projects and follow their updates.

Monitor your website with YourWebsiteScore

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of third-party repository code is at your own risk. Always review source code, dependencies, licenses, and security implications before running anything.

© 2025 OSRepos. Built with Nuxt 3 and lots of ❤️