Infosec Open Source Projects

Browse 436 Infosec open source projects, ranked by GitHub stars. Find the most popular Infosec tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 436 projects
19,767 stars

smicallef/spiderfoot

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

Metrics details
Stars19,767
16,399 stars

ffuf/ffuf

Fast web fuzzer written in Go

Metrics details
Stars16,399
16,214 stars

wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Metrics details
Stars16,214
14,521 stars

maurosoria/dirsearch

Web path scanner

Metrics details
Stars14,521
13,383 stars

digininja/DVWA

Damn Vulnerable Web Application (DVWA)

Metrics details
Stars13,383
13,189 stars

threat9/routersploit

Exploitation Framework for Embedded Devices

Metrics details
Stars13,189
11,908 stars

dstotijn/hetty

An HTTP toolkit for security research.

Metrics details
Stars11,908
10,499 stars

infosecn1nja/Red-Teaming-Toolkit

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Metrics details
Stars10,499
10,007 stars

samratashok/nishang

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Metrics details
Stars10,007
8,746 stars

yogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

Metrics details
Stars8,746
7,953 stars

trickest/cve

Gather and update all available and newest CVEs with their PoC.

Metrics details
Stars7,953
7,577 stars

jakejarvis/awesome-shodan-queries

🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩‍💻

Metrics details
Stars7,577
7,553 stars

0xInfection/Awesome-WAF

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Metrics details
Stars7,553
7,160 stars

liamg/traitor

:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

Metrics details
Stars7,160
6,809 stars

daffainfo/AllAboutBugBounty

All about bug bounty (bypasses, payloads, and etc)

Metrics details
Stars6,809
6,678 stars

ihebski/DefaultCreds-cheat-sheet

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Metrics details
Stars6,678
6,660 stars

infobyte/faraday

Open Source Vulnerability Management Platform

Metrics details
Stars6,660
6,555 stars

fr0gger/Awesome-GPT-Agents

A curated list of GPT agents for cybersecurity

Metrics details
Stars6,555
6,513 stars

EdOverflow/bugbounty-cheatsheet

A list of interesting payloads, tips and tricks for bug bounty hunters.

Metrics details
Stars6,513
6,469 stars

decalage2/awesome-security-hardening

A collection of awesome security hardening guides, tools and other resources

Metrics details
Stars6,469
5,978 stars

rmusser01/Infosec_Reference

An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

Metrics details
Stars5,978
5,755 stars

EdOverflow/can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Metrics details
Stars5,755
5,710 stars

onlurking/awesome-infosec

A curated list of awesome infosec courses and training resources.

Metrics details
Stars5,710
5,702 stars

ffffffff0x/1earn

ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup

Metrics details
Stars5,702
5,702 stars

Pennyw0rth/NetExec

The Network Execution Tool

Metrics details
Stars5,702
5,469 stars

fabacab/awesome-cybersecurity-blueteam

:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Metrics details
Stars5,469
5,129 stars

Ullaakut/cameradar

Cameradar hacks its way into RTSP videosurveillance cameras

Metrics details
Stars5,129
5,009 stars

jassics/security-study-plan

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...

Metrics details
Stars5,009
4,423 stars

GerbenJavado/LinkFinder

A python script that finds endpoints in JavaScript files

Metrics details
Stars4,423
4,366 stars

skerkour/black-hat-rust

Applied offensive security with Rust - https://kerkour.com/black-hat-rust

Metrics details
Stars4,366
4,362 stars

0x90n/InfoSec-Black-Friday

All the deals for InfoSec related software/tools this Black Friday

Metrics details
Stars4,362
4,224 stars

PaulSec/awesome-sec-talks

A collected list of awesome security talks

Metrics details
Stars4,224
4,174 stars

giuliacassara/awesome-social-engineering

A curated list of awesome social engineering resources.

Metrics details
Stars4,174
3,970 stars

snooppr/snoop

Snoop — инструмент разведки на основе открытых данных (OSINT world)

Metrics details
Stars3,970
3,870 stars

0xsyr0/Awesome-Cybersecurity-Handbooks

A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.

Metrics details
Stars3,870
3,854 stars

arainho/awesome-api-security

A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.

Metrics details
Stars3,854
3,849 stars

KuroLabs/stegcloak

Hide secrets with invisible characters in plain text securely using passwords 🧙🏻‍♂️⭐

Metrics details
Stars3,849
3,598 stars

ysrc/xunfeng

巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。

Metrics details
Stars3,598
3,553 stars

e-m-b-a/emba

EMBA - The firmware security analyzer

Metrics details
Stars3,553
3,460 stars

edoardottt/cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Metrics details
Stars3,460
3,277 stars

ignis-sec/Pwdb-Public

A collection of all the data i could extract from 1 billion leaked credentials from internet.

Metrics details
Stars3,277
3,189 stars

MaximeBeasse/KeyDecoder

KeyDecoder app lets you use your smartphone or tablet to decode your mechanical keys in seconds.

Metrics details
Stars3,189
3,154 stars

sa7mon/S3Scanner

Scan for misconfigured S3 buckets across S3-compatible APIs!

Metrics details
Stars3,154
3,022 stars

lirantal/awesome-nodejs-security

Awesome Node.js Security resources

Metrics details
Stars3,022
2,913 stars

Roave/SecurityAdvisories

:closed_lock_with_key: Security advisories as a simple composer exclusion list, updated daily

Metrics details
Stars2,913
2,864 stars

pwndoc/pwndoc

Pentest Report Generator

Metrics details
Stars2,864
2,750 stars

Integration-IT/Active-Directory-Exploitation-Cheat-Sheet

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Metrics details
Stars2,750
2,737 stars

redhuntlabs/Awesome-Asset-Discovery

List of Awesome Asset Discovery Resources

Metrics details
Stars2,737
2,573 stars

danieldurnea/FBI-tools

🕵️ OSINT Tools for gathering information and actions forensics 🕵️

Metrics details
Stars2,573
2,457 stars

cisagov/Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

Metrics details
Stars2,457
2,441 stars

Idov31/Nidhogg

Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

Metrics details
Stars2,441
2,380 stars

Ph055a/OSINT_Collection

Maintained collection of OSINT related resources. (All Free & Actionable)

Metrics details
Stars2,380
2,365 stars

jaeles-project/jaeles

The Swiss Army knife for automated Web Application Testing

Metrics details
Stars2,365
2,279 stars

cider-security-research/cicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Metrics details
Stars2,279
2,240 stars

inonshk/31-days-of-API-Security-Tips

This challenge is Inon Shkedy's 31 days API Security Tips.

Metrics details
Stars2,240
2,188 stars

lkarlslund/Adalanche

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

Metrics details
Stars2,188
2,101 stars

haccer/subjack

DNS Takeover tool written in Go

Metrics details
Stars2,101
2,008 stars

yeti-platform/yeti

Your Everyday Threat Intelligence

Metrics details
Stars2,008
1,984 stars

Bashfuscator/Bashfuscator

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

Metrics details
Stars1,984
1,866 stars

securitytxt/security-txt

A proposed standard that allows websites to define security policies.

Metrics details
Stars1,866
1-60 of 436 projects
Get A Weekly Email With Trending Infosec Projects
Stay updated on Infosec plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.