Open Source Security Projects
Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.
166 repositories · updated October 4, 2026

awesome-threat-modelling: Find Threat Modeling Learning Resources
A curated directory of threat modeling books, courses, videos, tutorials, examples, and tools. It helps developers and security practitioners find learning material and practical references for security reviews.

openresty-manager: Manage Reverse Proxies and Servers
OpenResty Manager is a web control panel for managing OpenResty reverse proxies, hosts, certificates, and containers. It suits self-hosters and administrators who want centralized site security and multi-node CDN management without configuring everything by hand.

awesome-osint: Find Open-Source Intelligence Tools and Resources
A curated directory of OSINT tools and resources for security researchers, threat hunters, and investigators. Browse categories spanning search, social networks, people research, geospatial intelligence, and threat intelligence.

openaev: Plan and Run Cyber Adversary Simulations
OpenAEV helps security teams plan, schedule, and run adversary simulation campaigns and exercises. Use it to coordinate teams, monitor activity, and review security gaps in relation to current threats.

supertokens-core: Build Authentication Into Your Applications
SuperTokens Core is a self-hostable authentication service that handles core login, user, and session operations for backend SDKs. It suits teams that want managed auth features while keeping user data in their own database and deployment.

authelia: Add SSO and Multi-Factor Authentication to Web Apps
Authelia is a self-hosted authentication and authorization server that protects web applications through reverse proxies. It provides SSO, configurable access rules, and multiple second-factor and passwordless authentication methods.

Disposable Email Validator: Block Disposable Emails and Plus Addressing
The `disposable-email-validator` library helps prevent fake signups by blocking disposable email addresses and optional plus addressing. It offers flexible, environment-specific rules, making it ideal for production applications while allowing development flexibility. This TypeScript-based tool provides a robust solution for email validation.

Damn-Vulnerable-RESTaurant-API-Game: Practice API Security
A deliberately insecure Python API for practicing vulnerability discovery, exploitation, and remediation. Developers, ethical hackers, and security engineers can run it locally with Docker as a controlled training environment.

giskard-oss: Test and Red-Team LLM Agents
Giskard is a Python toolkit for evaluating agent behavior and probing AI systems for vulnerabilities. It suits teams building LLM agents or RAG applications that need repeatable checks, safety testing, and adversarial evaluation.

microsandbox: Run Untrusted Workloads in Local MicroVMs
Microsandbox runs untrusted code in local microVMs and provides a CLI and SDKs for managing isolated workloads. It suits developers and agent builders who need disposable, programmable sandboxes without a separate infrastructure service.

PayloadsAllTheThings: Find Web Security Payloads and Bypass Techniques
A community-maintained reference of payloads and bypass techniques for web application security testing. Use it to research vulnerability scenarios, support authorized penetration tests, and find ready-to-use Burp Intruder files.

slim: Analyze and Minify Container Images
Slim inspects container images and uses runtime analysis to create smaller images with a reduced attack surface. It is for developers and platform teams who want to optimize containers without manually rebuilding their Dockerfiles.