Infosec Open Source Projects
Browse 436 Infosec open source projects, ranked by GitHub stars. Find the most popular Infosec tools and libraries.
smicallef/spiderfoot
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
Metrics details
| Stars | 19,767 |
ffuf/ffuf
Fast web fuzzer written in Go
Metrics details
| Stars | 16,399 |
wazuh/wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Metrics details
| Stars | 16,214 |
maurosoria/dirsearch
Web path scanner
Metrics details
| Stars | 14,521 |
digininja/DVWA
Damn Vulnerable Web Application (DVWA)
Metrics details
| Stars | 13,383 |
threat9/routersploit
Exploitation Framework for Embedded Devices
Metrics details
| Stars | 13,189 |
dstotijn/hetty
An HTTP toolkit for security research.
Metrics details
| Stars | 11,908 |
infosecn1nja/Red-Teaming-Toolkit
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
Metrics details
| Stars | 10,499 |
samratashok/nishang
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
Metrics details
| Stars | 10,007 |
yogeshojha/rengine
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
Metrics details
| Stars | 8,746 |
trickest/cve
Gather and update all available and newest CVEs with their PoC.
Metrics details
| Stars | 7,953 |
jakejarvis/awesome-shodan-queries
🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
Metrics details
| Stars | 7,577 |
0xInfection/Awesome-WAF
Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥
Metrics details
| Stars | 7,553 |
liamg/traitor
:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
Metrics details
| Stars | 7,160 |
daffainfo/AllAboutBugBounty
All about bug bounty (bypasses, payloads, and etc)
Metrics details
| Stars | 6,809 |
ihebski/DefaultCreds-cheat-sheet
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
Metrics details
| Stars | 6,678 |
infobyte/faraday
Open Source Vulnerability Management Platform
Metrics details
| Stars | 6,660 |
fr0gger/Awesome-GPT-Agents
A curated list of GPT agents for cybersecurity
Metrics details
| Stars | 6,555 |
EdOverflow/bugbounty-cheatsheet
A list of interesting payloads, tips and tricks for bug bounty hunters.
Metrics details
| Stars | 6,513 |
decalage2/awesome-security-hardening
A collection of awesome security hardening guides, tools and other resources
Metrics details
| Stars | 6,469 |
rmusser01/Infosec_Reference
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
Metrics details
| Stars | 5,978 |
EdOverflow/can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
Metrics details
| Stars | 5,755 |
onlurking/awesome-infosec
A curated list of awesome infosec courses and training resources.
Metrics details
| Stars | 5,710 |
ffffffff0x/1earn
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
Metrics details
| Stars | 5,702 |
Pennyw0rth/NetExec
The Network Execution Tool
Metrics details
| Stars | 5,702 |
fabacab/awesome-cybersecurity-blueteam
:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
Metrics details
| Stars | 5,469 |
Ullaakut/cameradar
Cameradar hacks its way into RTSP videosurveillance cameras
Metrics details
| Stars | 5,129 |
jassics/security-study-plan
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
Metrics details
| Stars | 5,009 |
GerbenJavado/LinkFinder
A python script that finds endpoints in JavaScript files
Metrics details
| Stars | 4,423 |
skerkour/black-hat-rust
Applied offensive security with Rust - https://kerkour.com/black-hat-rust
Metrics details
| Stars | 4,366 |
0x90n/InfoSec-Black-Friday
All the deals for InfoSec related software/tools this Black Friday
Metrics details
| Stars | 4,362 |
PaulSec/awesome-sec-talks
A collected list of awesome security talks
Metrics details
| Stars | 4,224 |
giuliacassara/awesome-social-engineering
A curated list of awesome social engineering resources.
Metrics details
| Stars | 4,174 |
snooppr/snoop
Snoop — инструмент разведки на основе открытых данных (OSINT world)
Metrics details
| Stars | 3,970 |
0xsyr0/Awesome-Cybersecurity-Handbooks
A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.
Metrics details
| Stars | 3,870 |
arainho/awesome-api-security
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
Metrics details
| Stars | 3,854 |
KuroLabs/stegcloak
Hide secrets with invisible characters in plain text securely using passwords 🧙🏻♂️⭐
Metrics details
| Stars | 3,849 |
ysrc/xunfeng
巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。
Metrics details
| Stars | 3,598 |
e-m-b-a/emba
EMBA - The firmware security analyzer
Metrics details
| Stars | 3,553 |
edoardottt/cariddi
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
Metrics details
| Stars | 3,460 |
ignis-sec/Pwdb-Public
A collection of all the data i could extract from 1 billion leaked credentials from internet.
Metrics details
| Stars | 3,277 |
MaximeBeasse/KeyDecoder
KeyDecoder app lets you use your smartphone or tablet to decode your mechanical keys in seconds.
Metrics details
| Stars | 3,189 |
sa7mon/S3Scanner
Scan for misconfigured S3 buckets across S3-compatible APIs!
Metrics details
| Stars | 3,154 |
lirantal/awesome-nodejs-security
Awesome Node.js Security resources
Metrics details
| Stars | 3,022 |
Roave/SecurityAdvisories
:closed_lock_with_key: Security advisories as a simple composer exclusion list, updated daily
Metrics details
| Stars | 2,913 |
pwndoc/pwndoc
Pentest Report Generator
Metrics details
| Stars | 2,864 |
Integration-IT/Active-Directory-Exploitation-Cheat-Sheet
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
Metrics details
| Stars | 2,750 |
redhuntlabs/Awesome-Asset-Discovery
List of Awesome Asset Discovery Resources
Metrics details
| Stars | 2,737 |
danieldurnea/FBI-tools
🕵️ OSINT Tools for gathering information and actions forensics 🕵️
Metrics details
| Stars | 2,573 |
cisagov/Malcolm
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
Metrics details
| Stars | 2,457 |
Idov31/Nidhogg
Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.
Metrics details
| Stars | 2,441 |
Ph055a/OSINT_Collection
Maintained collection of OSINT related resources. (All Free & Actionable)
Metrics details
| Stars | 2,380 |
jaeles-project/jaeles
The Swiss Army knife for automated Web Application Testing
Metrics details
| Stars | 2,365 |
cider-security-research/cicd-goat
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
Metrics details
| Stars | 2,279 |
inonshk/31-days-of-API-Security-Tips
This challenge is Inon Shkedy's 31 days API Security Tips.
Metrics details
| Stars | 2,240 |
lkarlslund/Adalanche
Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?
Metrics details
| Stars | 2,188 |
haccer/subjack
DNS Takeover tool written in Go
Metrics details
| Stars | 2,101 |
yeti-platform/yeti
Your Everyday Threat Intelligence
Metrics details
| Stars | 2,008 |
Bashfuscator/Bashfuscator
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
Metrics details
| Stars | 1,984 |
securitytxt/security-txt
A proposed standard that allows websites to define security policies.
Metrics details
| Stars | 1,866 |
