03 Aug 2026
Python
★ 529
h1domains is a Python tool that retrieves and lists domains approved for bug bounty programs on HackerOne, focusing specifically on those marked as "in-scope." Its primary use case is to assist security researchers in identifying valid targets for vulnerability testing while providing a regularly updated repository of domains. Notable features include an automated script to fetch the latest data and a comprehensive list of domains across various companies and services.
03 Aug 2026
Go
★ 85
ferret-scan is a command-line tool that enables the detection and redaction of sensitive data, such as personally identifiable information (PII) and secrets, from files and streams. Its features include context-aware confidence scoring for detected data, format-preserving redaction, and an intuitive web UI, all while ensuring no data leaves the host machine. The tool is designed for seamless integration into CI/CD pipelines and provides multiple installation methods, being lightweight with no runtime dependencies.
03 Aug 2026
TypeScript
★ 247
Drain is an open-source EVM wallet rescue and token migration tool designed to streamline the process of transferring native gas tokens and ERC-20 assets between wallets. It offers a user-friendly interface that connects to your wallet, identifies balances, and facilitates selective asset transfers while handling gas fees intelligently through atomic batched or sequential transfers. Notable features include the ability to resolve ENS names, display token logos and estimated USD values, and a non-custodial approach that ensures user control over private keys and transactions.
03 Aug 2026
Go
★ 564
DNS-collector is a lightweight tool designed for capturing and intelligently processing DNS queries and responses from various DNS servers, including BIND and PowerDNS. Its primary use case is to filter and enrich DNS data by removing noise such as health checks and spam before forwarding the refined data to monitoring systems or databases. Notable features include support for multiple input sources via the DNStap protocol or live network capture, flexible output formats to various logging and monitoring systems, and enhanced data processing capabilities for improved operational insights.
03 Aug 2026
TypeScript
★ 13
A security-as-code tool for making a difference in cybersecurity
03 Aug 2026
TypeScript
★ 22
Codependence is a tool designed to manage and enforce dependency versions across multiple programming environments—including Node, Python, Go, Rust, Docker, and GitHub Actions—using a single configuration file. Its primary use case is to maintain intentional versioning policies, ensuring that critical versions are both checked and updated according to specified rules, thus differentiating itself from traditional package managers and automated bots by running locally in scripts or CI environments. Notable features include the ability to pin specific dependencies while updating others, and a straightforward command-line interface for executing dependency checks and updates.
03 Aug 2026
TypeScript
★ 287
Clawdstrike is a robust policy engine and endpoint detection and response (EDR) tool designed for advanced security management, featuring a signed audit chain that records a wide array of system events. It integrates seamlessly with diverse environments, offering a Rust crate, TypeScript SDK, Python package, and CLI functionality, while ensuring policy evaluations are both comprehensive and consistently audited. Notable features include support for varying platforms (macOS, Linux), a formal verification mechanism for policy consistency, and a fail-closed design principle that enhances security posture.
03 Aug 2026
Python
★ 1392
AutoCVE is an automated tool designed for end-to-end CVE discovery, encompassing project screening, source code auditing, vulnerability verification, and report generation. Its notable features include a multi-agent collaborative auditing system and flexible auditing modes tailored for different objectives, enabling efficient management of vulnerability assessment through structured automated workflows. The tool simplifies the CVE reporting process, allowing users to easily submit their findings after a comprehensive auditing experience.
03 Aug 2026
Python
★ 13
The ScamGuard AntiScam Bot is a Discord bot designed to identify and ban scammers who target users with unsolicited commission offers. Its primary use case is to safeguard Discord communities by leveraging a shared ban list of verified scammers, supported by community reporting and a transparent operational framework. Notable features include the ability to configure the bot for local use with essential environment variables and the option to activate a publicly accessible API endpoint for custom bot instances.
03 Aug 2026
Python
★ 132
Wildbox is a self-hosted, open-source security operations platform designed for comprehensive threat monitoring, analysis, and automated responses, allowing users to maintain full control over their data. It features aggregated threat intelligence from over 50 sources, cloud security posture management for major providers, and utilizes YAML-based playbooks for incident automation, alongside advanced LLM capabilities for enhanced threat analysis and reporting. The architecture is built on microservices, providing flexibility and scalability through a robust API gateway, identity management, and integrated data management tools.
03 Aug 2026
Python
★ 700
VulnerableCode is an open-source database designed to catalog software package vulnerabilities, accessible through a Web UI and a comprehensive API. Its primary use case is to provide detailed information on vulnerabilities affecting software packages, including upstream and downstream impact analysis, thereby facilitating better vulnerability management. Notable features include its focus on Package URLs (PURLs) for easy identification of packages, along with the ability to build custom instances of the database.
03 Aug 2026
Go
★ 127
Vespasian is an API discovery and specification generation tool that observes real HTTP traffic to identify API endpoints and automatically generates specifications in OpenAPI, GraphQL SDL, and WSDL formats. Designed for penetration testers and security engineers, it captures traffic through headless browsers or imports data from existing traffic dumps, utilizing classification heuristics and active probing to effectively map the API surface of applications where documentation is scarce. Notable features include REST, GraphQL, WSDL, and gRPC discovery, automatic API type detection, and support for dynamic content generated by single-page applications.
03 Aug 2026
Go
★ 37764
Trivy is a versatile security scanner designed for identifying vulnerabilities and misconfigurations across various targets, including container images, filesystems, Git repositories, virtual machine images, and Kubernetes environments. It can detect OS packages, known vulnerabilities, infrastructure as code (IaC) issues, sensitive data, and software licenses. Trivy is easily integrable with popular tools and platforms, supporting a wide range of programming languages and systems, making it a comprehensive choice for security assessments.
03 Aug 2026
Go
★ 6316
Syzkaller is an unsupervised coverage-guided kernel fuzzer designed to discover security vulnerabilities in various operating system kernels, including Linux, FreeBSD, and Windows. Its notable features include support for multiple OS environments, a focus on automated bug detection, and an extensive documentation set for setup and usage. Initially developed for Linux, Syzkaller has broadened its capabilities to include several other operating systems, enhancing its utility in kernel security research.
03 Aug 2026
Go
★ 329
SysWarden is an enterprise-grade Host Intrusion Detection and Prevention System (HIDS/HIPS) built entirely in Go, designed to protect critical Linux infrastructures. Its primary use case is to automate and enforce CIS Level 2 hardening, integrate global threat intelligence, and orchestrate dynamic network defense, enabling robust protection against both network and application-level threats. Notable features include support for advanced firewall orchestration, a memory-safe web application firewall daemon, and a focus on zero-trust execution, mitigating common vulnerabilities like OS command injection and memory corruption.
03 Aug 2026
Go
★ 32
Stave is an open-source cloud configuration verifier designed to validate AWS configurations offline and without credentials. Its primary use case is for cybersecurity assessments, allowing users to discover vulnerabilities and attack chains through intuitive commands and built-in templates. Notable features include automated assessment templates for various security jobs, a skill-based onboarding process, and the ability to evaluate snapshots and generate reports based on specified severity thresholds.
03 Aug 2026
Python
★ 299
SecObserve is an open source vulnerability and license management tool designed for software development teams and cloud environments, enabling efficient assessment and reporting of vulnerabilities across multiple scanning tools. It features a centralized dashboard for viewing and filtering scan results, as well as easy integration into CI/CD pipelines through pre-defined GitLab CI templates and GitHub Actions for streamlined vulnerability scanning. This tool aims to simplify the vulnerability management process, allowing teams to focus on addressing significant security issues.
03 Aug 2026
Python
★ 59
sbomify is a comprehensive Software Bill of Materials (SBOM) management tool that allows users to upload, manage, and share SBOMs and related documentation through a centralized platform, either self-hosted or via the provided web application. It supports multiple formats including CycloneDX and SPDX, integrates with GitHub Actions for automatic SBOM generation, and features robust compliance plugins while offering document management capabilities with version control and configurable access settings. Notably, it enables vulnerability scanning and employs workspace-based organization for efficient access and permission control.
03 Aug 2026
Python
★ 17
Rust-in-Peace is an autonomous security review tool specifically designed for Rust programming, facilitating the detection and remediation of vulnerabilities related to memory safety and panic handling in unsafe contexts. It integrates various detectors such as Miri and AddressSanitizer into a comprehensive pipeline that automates the process of finding, grading, and reporting vulnerabilities while also enabling targeted fuzzing. This tool emphasizes a structured approach by utilizing a machine-readable threat model and supports a recall-first strategy to improve detection accuracy through multiple scanning runs.
03 Aug 2026
Python
★ 168
Repo Forensics is a security tool designed to audit untrusted repositories before their integration with AI-agent plugins, skills, and MCP servers. It features a fully local and self-updating detection mechanism with zero dependencies and telemetry, ensuring a secure audit process. The tool supports live scanning against CVEs, incorporates over 800 patterns and 41 correlation rules, and operates effectively in offline environments.
03 Aug 2026
★ 14
The "references" repository serves as a compiled collection of reusable references, providing access to a variety of resources related to contemporary issues such as the Russo-Ukrainian War and political events. Notable features include links to remote documents, calendars, and an emphasis on critical themes like agnotology, which explores the social fabric of ignorance. The repository aims to facilitate informed discussions and act as a resource for understanding the implications of various socio-political phenomena.
03 Aug 2026
Java
★ 126
ReARM is a Release Governance Platform that facilitates the management of software releases by providing insights into their composition, security posture, and compliance through the storage and organization of Software Bill of Materials (SBOMs), security artifacts, and vulnerability data. Notable features include support for OCI-compatible storage, adherence to regulatory frameworks, and the introduction of a Product-Component relationship model for enhanced release metadata organization. This tool is particularly useful for organizations aiming to streamline their release processes while ensuring compliance with various security standards.
03 Aug 2026
Python
★ 23
QuicDraw is a security research tool focused on fuzzing and race-condition testing of HTTP/3 servers using the Quic-Fin-Sync technique over the QUIC transport layer. It supports advanced features such as custom HTTP headers, multiple request fuzzing with wordlists, and TLS decryption for packet analysis, making it suitable for testing the resilience of HTTP/3 applications against race conditions and security vulnerabilities. The tool is built on the aioquic library, offering a robust implementation for developers and security professionals engaged in network protocol research.
03 Aug 2026
Rust
★ 118
QuorumOS (QOS) is a specialized operating system designed for deploying applications within a Trusted Execution Environment (TEE) at cloud scale. It ensures secure computation by facilitating coordinated provisioning of a secure environment among multiple actors, employing a unique Quorum Key for data encryption and authentication. Notable features include deterministic builds using the StageX distribution and support for minimal, immutable Linux unikernel operations tailored for high-security use cases.
03 Aug 2026
Python
★ 277
Prismor is a runtime security tool designed for AI coding agents like Claude Code and Codex, providing features to block dangerous commands, prevent prompt injections, and avoid secret leaks. It also recommends safe supply chain packages and offers an observe mode to monitor agent session activities through a growing self-serve dashboard. Its primary use case is enhancing the security and reliability of AI coding interactions by addressing potential vulnerabilities.