03 Aug 2026
Kotlin
★ 121
Password Monitor is a cybersecurity tool that checks the integrity of user passwords against known data breaches by utilizing the Have I Been Pwned? service. It emphasizes privacy by ensuring that passwords are never shared and offers a user-friendly interface with support for material design, dark themes, and ad-free usage. Notable features include being fully open source, the avoidance of personal data collection, and reproducible builds for easy installation.
03 Aug 2026
Python
★ 56
OpenShield is an open-source Cloud Security Posture Management (CSPM) tool designed specifically for Azure environments, enabling users to detect misconfigurations and improve security compliance by mapping issues to frameworks like CIS, NIST, and ISO 27001. Notable features include a comprehensive misconfiguration scanner, which evaluates over fifty security rules across various Azure services, and the ability to identify classical cryptographic assets that require migration to quantum-safe alternatives. The tool facilitates remediation through a single command, providing a user-friendly approach to enhancing cloud security for startups and small to medium-sized enterprises.
03 Aug 2026
Go
★ 33
OpenRisk is an enterprise-grade risk management platform designed to streamline the identification, assessment, mitigation, and monitoring of IT and security risks through a scalable microservices architecture. Its key features include automated risk assessment, interactive real-time dashboards, and native integration with tools like Elastic and Splunk, making it suitable for CTOs, CISOs, and DevSecOps teams. With capabilities such as mitigation tracking and advanced analytics, OpenRisk enhances organizational risk oversight and compliance while enabling easy deployment via Docker and Kubernetes.
03 Aug 2026
JavaScript
★ 18
npm-scan is an advanced supply chain threat detection tool designed to identify sophisticated attacks that typical tools like npm audit, Snyk, and Socket often overlook. It excels at detecting obfuscated payloads, credential theft, eBPF kernel rootkits, and various AI-targeted attacks, boasting over 95% confidence in real-world threat scenarios. Key features include comprehensive behavioral pattern recognition and a dual detection approach that enhances compliance and reduces financial liability associated with data breaches.
03 Aug 2026
C
★ 382
Minijail is a sandboxing tool designed to enhance security by isolating and containing processes, primarily used in ChromeOS and Android environments. It allows users to launch and sandbox executables securely, mitigating risks associated with compromised services through robust containment strategies. Notable features include an executable for sandboxing known binaries and a library that enables developers to integrate sandboxing capabilities directly into their applications.
03 Aug 2026
Python
★ 29
Masscan as a Service is a Python-based tool designed to facilitate rapid port scanning across whole IPv4 ranges using the high-speed masscan utility, allowing users to quickly identify open TCP or UDP ports on their servers. Its primary use case is for security monitoring, alerting users when previously unseen ports become active, thus helping to mitigate the risk of unauthorized access or malicious activity. Notable features include seamless integration into deployment pipelines via scheduling systems, easy installation as a Python package, and upcoming support for nmap to enhance its scanning capabilities for IPv6.
03 Aug 2026
Go
★ 43
Layerleak is an OCI image secret scanner that leverages OCI image internals to analyze public images from various OCI-compliant registries without relying on a local Docker daemon. It offers read-only scanning capabilities, detecting over 60 types of secrets while deduplicating findings by secret fingerprint and collapsing duplicate context snippets. Notable features include support for scanning image layers, config metadata, and history, as well as a built-in HTTP API for integration.
03 Aug 2026
Rust
★ 500
honggfuzz-rs is a Rust binding for the Honggfuzz fuzzer, enabling feedback-driven and evolutionary fuzz testing for Rust code. It offers features like fuzzing with runtime instrumentation, crash replay in a debugging environment, and support for various sanitizers, making it suitable for security-oriented software testing across multiple operating systems and architectures. The tool can be easily integrated into Rust projects by adding it as a dependency and utilizing its provided macros for fuzzing functionality.
03 Aug 2026
HTML
★ 12
`geol` is a Go-based command-line interface tool designed to manage end-of-life (EOL) information for software, offering an enhanced user experience compared to its Python counterpart, `norwegianblue`. It provides a terminal-based interface that facilitates safer and easier delivery while incorporating additional features for improved security management related to EOLs. Notable features include a strong focus on user experience, straightforward installation, and innovative management methods for software lifecycle tracking.
03 Aug 2026
Rust
★ 19
FerroCrypt is a specialized Rust library, CLI, and desktop application designed for secure file and directory encryption and decryption using both password-based and key-pair encryption methods. It allows users to create encrypted `.fcr` files that can securely be accessed by designated recipients through specific passphrase or public-key decryption methods. Notable features include an interactive command-line interface, support for multiple encryption methods, and an easy-to-use desktop application for end-users.
03 Aug 2026
Python
★ 99
ExtensionShield is a Chrome extension security scanner and governance platform that audits browser extensions, producing comprehensive, evidence-linked reports focusing on security, privacy, and governance. It operates in an open-source mode using SQLite, allowing scans of extensions from the Chrome Web Store or local files, with features such as manifest and permission reviews, SAST findings, entropy checks, and integration with VirusTotal for enhanced analysis. Notably, it offers a customizable scoring system to evaluate extensions across critical security and governance dimensions.
03 Aug 2026
Go
★ 320
Dalec is a tool designed for securely building system packages and containers using a declarative configuration format, with a particular emphasis on supply chain security. It supports multiple package formats (DEB, RPM, and Windows containers) while ensuring minimal image sizes to reduce vulnerabilities, along with features like signed packages and build-time Software Bill of Materials (SBOMs) for provenance attestations. The tool operates with Docker as its sole dependency, simplifying the usage for various target operating systems.
03 Aug 2026
Python
★ 48
CryptoLyzer is a comprehensive security auditing tool that analyzes various cryptographic protocols, including TLS, SSL, SSH, IKE, and DNSSEC. It uniquely identifies over 400 cipher suites and cryptographic algorithms using a custom implementation that operates independently of OpenSSL, enabling the detection of vulnerabilities often missed by traditional tools. With both command-line and API interfaces, CryptoLyzer offers versatile output formats and a unified approach, making it an essential solution for security assessments across multiple cryptographic attack surfaces.
03 Aug 2026
Python
★ 29
Cortado is a Python-based framework designed for executing Red Team Automations (RTAs) which emulate attacker behaviors or reference specific binary samples to evaluate detection rules in Elastic's security products. It features a command-line interface for running RTAs in a minimal dependency environment, as well as utilities for assessing RTA coverage against defined detection rules. The tool facilitates seamless integration and deployment within security operations, enhancing the verification process of alert generation.
03 Aug 2026
Python
★ 55
compose-lint is a security-focused linter designed to analyze Docker Compose files for dangerous misconfigurations and enforce best practices. It conducts static analysis to identify issues such as privilege flaws, network exposure, and supply chain vulnerabilities, and can automatically fix unambiguous findings. Grounded in OWASP guidelines and the CIS Docker Benchmark, it serves as a pre-merge gate for infrastructure-as-code, making it essential for production environments and CI/CD workflows.
03 Aug 2026
Python
★ 3298
CHIPSEC is a comprehensive platform security assessment framework designed to analyze the security of PC platforms, focusing on hardware, system firmware (BIOS/UEFI), and associated components. It features a variety of security tests, access tools for low-level interfaces, and forensic capabilities, and supports operation across Windows, Linux, and UEFI shell environments. This tool is particularly geared for security professionals seeking to identify vulnerabilities in firmware, hypervisors, and hardware configurations.
03 Aug 2026
Nim
★ 438
Chalk is a software provenance and attestation tool designed to offer a cryptographically verifiable chain of custody for production software with minimal configuration effort. It facilitates the automatic insertion of a tamperproof identifier into various software artifacts, allowing for easy integrity checks and correlation of provenance data. Notable features include support for build signature modes using Sigstore, integration with Docker’s SBOM tooling, and a continuous attestation model that aids in incident response, compliance, and tech stack visibility.
03 Aug 2026
Go
★ 661
AWS SSO CLI is a secure command-line interface tool designed to simplify the management of AWS IAM Identity Center access for organizations with multiple AWS accounts and IAM roles. It enhances security by auto-discovering available roles, supporting both interactive and CLI-based role selection, and allowing for the sharing of AWS STS token credentials. Notable features include support for multiple active AWS Console sessions, guided setup, customizable profiles, and a user-friendly experience focused on improving AWS SSO interactions.
03 Aug 2026
Go
★ 166
Amazing Sandbox (AS) is a versatile tool designed to execute various programming environments in a secure, containerized format. It primarily mitigates risks associated with running potentially malicious packages by limiting their access to the file system and network, facilitating safer development practices. Key features include configurable access permissions, support for multiple programming languages, and the option to air-gap execution environments for enhanced security.
03 Aug 2026
Python
★ 364
The Agentic Threat Hunting Framework (ATHF) is a markdown-based tool that structures and preserves threat hunting investigations, enhancing their accessibility and utility through automation. It utilizes the LOCK pattern for documentation, providing a framework that integrates with any SIEM/EDR platform while incorporating AI-driven research and hypothesis generation capabilities. By retaining context and enabling AI assistants to leverage past hunts, ATHF aims to enrich and streamline the threat hunting process.
03 Aug 2026
Dockerfile
★ 10
The konstruktoid/action-pylint is a GitHub Action designed for linting and testing Python code with the tools ruff and ty. Its primary use case is to automate code quality checks during the CI/CD process by integrating seamlessly with GitHub workflows. Notable features include support for customizable linting configurations and the ability to run on various triggers such as pushes and pull requests.
03 Aug 2026
Python
★ 65
The `zizmor-pre-commit` tool integrates the `zizmor` linter with the pre-commit framework, allowing users to enforce code quality checks before commits. Its notable features include easy configuration via `.pre-commit-config.yaml`, support for running the linter with autofix capabilities, and distribution as a standalone repository for seamless installation through prebuilt wheels from PyPI.
03 Aug 2026
Python
★ 37
Yoda is a passive RF monitoring tool designed for home environments, capable of tracking Bluetooth (BLE) devices and WiFi access points and clients in real time. It features a terminal user interface (TUI) that displays live data, push notifications for device and connection events via ntfy.sh, and advanced jamming detection using an asymmetric exponentially weighted moving average (EWMA). Users benefit from the ability to customize alert topics and monitor device stability, making it an effective solution for managing home network security and device presence.
03 Aug 2026
TypeScript
★ 581
UTMStack is an open-source unified threat management platform that combines SIEM (Security Information and Event Management) and XDR (Extended Detection and Response) functionalities for real-time correlation of log data, threat intelligence, and malware activity patterns. Its notable features include advanced threat detection and response, log management, AI-powered analysis, and security compliance support, allowing organizations to effectively identify and mitigate complex threats efficiently. By enabling correlation prior to data ingestion, UTMStack enhances the overall threat prevention capabilities and response times within cybersecurity infrastructures.
03 Aug 2026
Rust
★ 135
Twistr is a Rust-based domain name permutation library that serves as a direct port of the well-known dnstwist tool, enabling fast and flexible permutational analysis of domain names. Its primary use case involves generating variations of a given domain to aid in identifying potential squatting or phishing attempts. Notable features include granular control over permutation algorithms, an allocation-free API for high throughput, and a core library designed for easy extensibility for command-line interfaces and other integrations.