03 Aug 2026
Makefile
★ 42
The "fucking-android-security-awesome" repository is a comprehensive catalog of resources and tools focused on Android security. It serves as a reference for security professionals, offering links to various online analyzers, academic resources, and vulnerability exploits relevant to Android applications. Notable features include extensive listings of tools for both static and dynamic analysis, along with continual updates and validations to ensure the links and resources are current.
03 Aug 2026
Python
★ 13
FinalThreatFeed is a high-performance automated threat intelligence aggregation engine designed for continuous collection and fusion of global open-source intelligence. Its architecture supports asynchronous operations to enhance data throughput, while features such as intelligent cleaning, deduplication, and full lifecycle management ensure high-quality, relevant threat data. The tool also offers flexible extension configurations and advanced IOC identification, making it suitable for enterprise security defense systems.
03 Aug 2026
Shell
★ 10
Delebetor is a utility designed for installing and managing penetration testing tools by organizing them based on their installation methods, such as `apt` packages and `git` repositories. Notable features include detailed per-tool installation status reporting, a dedicated toolset for web assessments, and a secure deletion option that requires confirmation to clean up installed tools and history. The tool is intended for interactive or command-line use on `apt`-based distributions like Kali Linux, Debian, or Ubuntu.
03 Aug 2026
★ 25
Darkelf is a comprehensive ecosystem that offers a suite of privacy-focused browsers and security tools for cybersecurity professionals, researchers, and privacy-conscious users. It features enterprise-grade browsing capabilities, AI-assisted analysis tools, OSINT utilities, and extensive documentation to support both users and developers in utilizing and contributing to its projects. Notable technologies include post-quantum cryptography readiness, anti-fingerprinting research, and local AI security analysis.
03 Aug 2026
Python
★ 252
Keeper Commander serves as a versatile command-line interface for managing access to the Keeper® Password Manager and KeeperPAM, facilitating tasks such as user and role administration, password rotation, and session management. Notably, it offers an interactive terminal UI, supports REST service operations, and enables features like biometric authentication and persistent login sessions, making it suitable for both individual users and enterprises seeking to integrate secure password management within their workflows. As an open-source tool, it encourages community contributions, enhancing its capabilities and usability.
03 Aug 2026
PHP
★ 114
Checkpoint is a Laravel security scanner designed to audit applications for common vulnerabilities, encompassing checks for known CVEs, hardcoded secrets, and potential misconfigurations through a single Artisan command (`php artisan checkpoint:scan`). It performs a comprehensive analysis, including Composer and NPM CVE audits, environment configuration validation, file permissions checks, and scans for risks like SQL injection and XSS vulnerabilities. Notable features include the ability to detect sensitive data exposure and misconfigured security settings, making it an essential tool for securing Laravel applications.
03 Aug 2026
TypeScript
★ 370
Bramble is a decentralized password manager that securely stores user passwords on their own devices without relying on a central server or third-party accounts. It features a browser extension for Chromium-based browsers and mobile apps for iOS and Android, utilizing a peer-to-peer syncing mechanism for vaults that ensures end-to-end encryption across devices. The tool emphasizes security with its Rust-based cryptographic core and offers easy backup options through encrypted files.
03 Aug 2026
Go
★ 1834
Betterleaks is a configurable and efficient secrets scanner designed for detecting sensitive information across various platforms, including Git repositories, GitHub, GitLab, and S3. It offers notable features such as advanced rule-based filtering using Expr for reduced false positives, validation of detected secrets via asynchronous HTTP requests, and support for numerous data sources, making it a versatile tool in ensuring code security. With built-in parallel processing and optimization for fast scans, it can be integrated easily into any system, enhancing its practicality in diverse development environments.
03 Aug 2026
TypeScript
★ 10
BaseSec is a Static Application Security Testing (SAST) CLI tool specifically designed for JavaScript and TypeScript applications, including Node.js backends and various frontend frameworks. It features 65 security rules across multiple categories, automated framework detection, and advanced capabilities such as taint analysis, dependency checking, and support for AI-powered insights. With zero configuration required for initial use, BaseSec offers multiple output formats and optimized performance through caching and multi-core processing.
03 Aug 2026
Python
★ 101
AutoFyn is a long-horizon agent designed to find vulnerabilities in software by utilizing a clean context and verifiable feedback mechanism. It operates by proposing exploits against live systems, ensuring objective outcomes that enhance its learning through expert iteration across multiple domains, including security audits and mathematical research. Notable features include its ability to conduct thorough security audits on popular repositories, yielding significant vulnerability reports, and effectively managing context to avoid the pitfalls of accumulating errors.
03 Aug 2026
Python
★ 28
Argus is a comprehensive security scanning tool that integrates Static Application Security Testing (SAST), container security, Infrastructure as Code (IaC) scanning, and dynamic application security testing (DAST) into a single command-line interface (CLI) or GitHub Actions workflow. It supports various scanners such as Bandit, Gitleaks, and Trivy, enabling users to detect vulnerabilities, secrets, and security weaknesses across code, containers, and cloud configurations. Notable features include an interactive terminal UI for triaging scan findings, customizable integration with CI pipelines, and export options for results.
03 Aug 2026
Rust
★ 12
Ward is a local-first secret firewall designed for development environments, ensuring that project environment variables are securely encrypted in a `.env.vault` file while allowing seamless terminal workflows and scoped access for AI agents. Notable features include a simple recovery flow that keeps plaintext secrets off servers, human mode for terminal session protection, and support for agent workflows through generated instructions, all while maintaining local metadata storage for added security.
03 Aug 2026
TypeScript
★ 51
1time.io is a zero-knowledge one-time secret sharing tool that allows users to securely share passwords, API keys, and sensitive text via self-destructing links, utilizing end-to-end encryption. Key features include browser-based encryption with AES-GCM, self-destructing links post-read, encrypted file sharing, and support for a command-line interface, all without requiring user accounts. The tool can also be self-hosted using Docker Compose, enhancing flexibility for individual or organizational use.
03 Aug 2026
Go
★ 632
YAK is a cybersecurity technology stack built around a domain-specific language (CDSL) designed for enhancing security infrastructure and vulnerability analysis. Notable features include a dedicated virtual machine (YakVM), strong typing with dynamic characteristics, and the ability to execute scripts across multiple platforms without extensive boilerplate code. This tool aims to simplify the development of security products and improve usability for non-specialists in the cybersecurity domain.
03 Aug 2026
Go
★ 27673
TruffleHog is a powerful tool for discovering, classifying, validating, and analyzing leaked credentials across various platforms, including Git repositories, chat applications, and logs. It can identify over 800 types of secrets, confirm their validity by checking if they are live, and provide in-depth analysis of commonly leaked credentials. Notable features include its comprehensive secret classification and validation capabilities, making it essential for maintaining secure access credentials.
03 Aug 2026
★ 11
SysPulse is a lightweight Windows security monitor designed to provide instant alerts via Telegram for critical system events such as new processes, USB activity, and changes to Windows Defender status. It operates efficiently in the background, consuming under 30MB of RAM, and focuses on essential monitoring without unnecessary features or resource consumption. Notable functionalities include a startup checker, USB detection, and process monitoring, making it a useful complement to traditional antivirus solutions.
03 Aug 2026
JavaScript
★ 830
Ship Safe is an AI-driven security scanner designed for modern software teams, operating locally within projects to identify vulnerabilities in application code, AI agents, configuration files, and supply chains. Its notable features include offline scanning capabilities, an interactive REPL for real-time scanning and fixing, and comprehensive audits that cover secrets, dependencies, and CI/CD configurations. Moreover, it allows for configuration of AI-backed red-team modes for deeper analysis, all without requiring user signups or API keys.
03 Aug 2026
Go
★ 988
secureCodeBox is a Kubernetes-based toolchain designed for continuous security scanning of software projects, automating various security testing tools to facilitate ongoing application security. Its primary use case is to integrate into the development pipeline, allowing for early identification of security vulnerabilities, thereby enabling developers to address issues regularly rather than relying solely on periodic penetration testing. Notable features include its modular architecture, which offers flexibility in tool selection, and its ability to orchestrate automated security tests, making it suitable for projects with continuous delivery practices.
03 Aug 2026
Python
★ 23
Scapy UsbBluetooth is a Python library that integrates Bluetooth communication capabilities into Scapy, enabling it to interact with Bluetooth controllers through UsbBluetooth. Its primary use case is for network and device analysis, providing functionality to list devices, establish sockets, and send command packets, like HCI commands. Notable features include easy installation via pip and support for specific platform requirements, facilitating access on Windows and Linux systems.
03 Aug 2026
PHP
★ 11
PermCheck is a lightweight tool designed for verifying proper executable permissions on files within a PHP project. By utilizing a customizable XML configuration file, it allows users to specify which directories and files should be executable, thus enhancing project consistency and security. Notable features include support for various PHP versions, minimal dependencies, and integration with the Symfony Console Component for ease of use.
03 Aug 2026
TypeScript
★ 107
Pastoralist is a tool designed to manage and document package manager overrides, specifically for npm and Yarn, by creating an audit trail of why each override is necessary. Its primary use case is to help developers maintain clarity on override decisions, ensuring that the reasons for such changes, their dependencies, and related security information are well-documented and accessible. Notable features include tracking the history of overrides, linking CVEs and severity details, and integrating with `patch-package` to enhance package maintenance.
03 Aug 2026
PHP
★ 549
Mercator is an open source web application designed for dynamic mapping of information systems, providing IT professionals with a comprehensive overview of their digital environments. It enables users to visualize dependencies, track compliance, generate architectural reports, and facilitate risk management through features like graphical representations, compliance monitoring, and integration with security tools. Notably, Mercator supports multi-user collaboration and offers a REST API for seamless system integration, making it a valuable asset for organizations aiming to enhance information system governance.
03 Aug 2026
★ 34
The marichu-kt repository showcases a collection of personal projects mainly focused on various programming languages and technologies, including Python, Java, C#, and web development tools. The repository features projects such as cryptographic algorithms (ChaCha20-Poly1305-X25519) and interactive applications like a CAPTCHA system, vending machines, and slot machines. Notable features include detailed statistics on the creator's language proficiency and active calls for community support through stargazing.
03 Aug 2026
TypeScript
★ 1278
LuaN1aoAgent is an advanced cognitive-driven autonomous security agent that enables authorized security research through its distinct Planner, Executor, and Observer roles. The tool operates using a robust graph memory system that ensures traceability of actions and decisions based on permanent artifacts and events, fostering an environment of observability and accountability. Key features include its separation of responsibilities for effective task management and the capability to perform autonomous actions while preserving evidence and insights from operations.
03 Aug 2026
TypeScript
★ 287
JS-X-Ray is a static application security testing (SAST) tool designed for JavaScript and TypeScript, focusing on detecting malicious patterns, security vulnerabilities, and code anomalies. It leverages an Abstract Syntax Tree (AST) approach for variable tracing and dynamic import resolution, enabling the identification of sophisticated obfuscation and malicious constructs such as data exfiltration and vulnerable coding practices. Notable features include the ability to detect various forms of obfuscated code, flag weak cryptographic algorithms, and provide configurable sensitivity modes for tailored analysis.