03 Aug 2026
Go
★ 832
Pipelock is an open-source AI agent firewall that provides verifiable egress control by inspecting and mediating HTTP, WebSocket, and other network traffic to prevent secret exfiltration, prompt injections, and various security threats. It features content-aware boundary decisions with mediator-signed action receipts for verification, enhancing transparency in security operations. Additionally, it supports TLS interception for thorough analysis and is integrated with the public agent-egress-bench corpus for robust detection validation.
03 Aug 2026
Python
★ 157
PCAP Hunter is an AI-enhanced threat hunting workbench designed for SOC analysts, enabling seamless integration of manual packet analysis with automated security monitoring. It features a user-centric interface for geographic flow aggregation, linked visual analysis, and a durable analysis workflow, while also providing optional Large Language Model assistance for enriched analysis. The tool supports visualization and investigation of packet captures through advanced filtering and responsive dashboard capabilities, ensuring comprehensive threat detection and evidence management.
03 Aug 2026
Python
★ 581
OXO is a security scanning framework designed for modularity and scalability, enabling users to efficiently combine various specialized agents to conduct comprehensive vulnerability assessments across a wide range of assets, including IPs, domains, mobile applications, and APIs. Key features include an extensible agent store for community and official tools, a Python-based framework for creating custom agents, and an API-first design that facilitates integration into CI/CD workflows. The tool supports Docker for containerized execution, simplifying deployment and management of security scans.
03 Aug 2026
JavaScript
★ 44
The Malicious IP Address List repository provides a continuously updated list of IP addresses associated with malicious activities, such as DDoS attacks and misuse through VPNs or proxies. Its primary use case is for threat identification, allowing users to recognize potentially harmful sources without directly blocking them at the firewall level. Notable features include regular updates every two hours, availability in both TXT and CSV formats, and a focus on long-term reputation blacklisting.
03 Aug 2026
Go
★ 210
Kontext CLI is a runtime governance tool designed for AI agents, enabling local policy evaluations and pre-action enforcement to enhance security during tool usage. Its primary use case involves recording policy decisions and actions in an authorization ledger while blocking or allowing actions based on predefined rules. Notable features include support for self-serve setup on macOS, an observe mode for testing policies without interruptions, and compatibility with various agent environments to ensure secure operation across different platforms.
03 Aug 2026
TypeScript
★ 29103
Infisical is an open-source secret management platform designed to centralize and synchronize secrets and configurations across teams and infrastructures, thereby preventing leaks. Notable features include a user-friendly dashboard for managing secrets, integration for syncing with popular platforms like GitHub and AWS, versioning, rotation, and the capability for dynamic secret generation. The tool aims to enhance accessibility and usability in security for development teams, streamlining the process of handling sensitive information.
03 Aug 2026
Go
★ 306
Hijagger is a cybersecurity tool designed to identify hijackable packages in NPM and Python PyPI registries by checking for unregistered domains or MX records associated with package maintainers. Its primary use case is to facilitate the discovery of potential security vulnerabilities that can be reported to bug bounty programs. Notable features include automatic output logging, DNS and WHOIS checks, and a color-coded output based on download activity for NPM packages, though this feature is not available for PyPI due to API limitations.
03 Aug 2026
Go
★ 75
Hadrian is an open-source API security testing framework designed to detect OWASP API Top 10 vulnerabilities in REST, GraphQL, and gRPC APIs, focusing specifically on authorization-related flaws. It features role-based authorization testing using YAML-driven templates, which enables users to define roles with permissions once and automatically conduct cross-role access checks. Additionally, Hadrian employs mutation testing methodologies to confirm the existence of write/delete vulnerabilities and offers multiple output formats for reporting findings.
03 Aug 2026
Python
★ 178
Findmytakeover is a specialized tool designed to detect dangling DNS records within multi-cloud environments, scanning all DNS zones and associated infrastructure in cloud service providers. Its primary use case is to identify potential subdomain takeovers by pinpointing DNS records without existing infrastructure, enhancing security against unauthorized access and malicious activity. Notable features include configurable cloud provider support, comprehensive reporting, and dependencies tailored to different cloud environments, ensuring effective operational capability across major platforms.
03 Aug 2026
Dockerfile
★ 14
The leplusorg/docker-kali repository provides a multi-platform Docker container for Kali Linux, facilitating the deployment of a versatile penetration testing environment. Its primary use case is to enable security professionals to easily run Kali tools in isolated containers across different operating systems. Notable features include support for varying architectures, built-in software bill of materials (SBOM) generation, provenance tracking, and Sigstore integration for enhanced supply chain security.
03 Aug 2026
Go
★ 195
Cynative is a read-only cybersecurity tool designed for deep infrastructure research, allowing users to query various systems such as GitHub, GitLab, AWS, GCP, Azure, and Kubernetes in a unified manner. It executes code in an ephemeral sandbox to provide verified insights while maintaining strict access controls, thereby ensuring that users can confidently audit their cloud environments without compromising security. Notable features include its ability to reason through code-to-runtime environments, a robust action-gate mechanism for authorization, and evidence-backed findings that trace back to their origins.
03 Aug 2026
TypeScript
★ 68
Bugsy is a command-line tool designed for automatic security vulnerability remediation in code, functioning as both a scanner and analyzer for SAST (Static Application Security Testing) reports from various vendors like Checkmarx and Snyk. Its notable features include two operational modes—Scan, which runs SAST scans and identifies vulnerabilities directly, and Analyze, which processes pre-generated SAST reports to provide automated code fixes, effectively streamlining the remediation process for developers. Additional functionality allows Bugsy to be utilized as an MCP server for enhanced integration with AI tools in vulnerability scanning and fixing.
03 Aug 2026
Swift
★ 278
Bromure is a cybersecurity tool that enables secure, ephemeral computing on macOS by running browser sessions within disposable Linux virtual machines (VMs), ensuring that all user data is isolated and destroyed after each session. Additionally, Bromure Agentic Coding provides a sandboxed environment for AI coding agents, integrating a host-side MITM proxy that obfuscates credentials, implements supply-chain scanning, and detects prompt injections, thus enhancing the security of AI interactions. The tool's notable features include robust isolation, per-use credential scoping, and comprehensive session auditing, making it suitable for privacy-conscious developers and organizations.
03 Aug 2026
Go
★ 2742
Bearer is a static application security testing (SAST) tool that scans source code for security and privacy risks by analyzing data flows. It supports a wide range of programming languages and offers features like detection of vulnerabilities in line with OWASP Top 10 and CWE Top 25, as well as identifying sensitive data flows for privacy compliance reporting. Bearer is available in both an open-source CLI version and a comprehensive commercial version, providing advanced analysis capabilities.
03 Aug 2026
DIGITAL Command Language
★ 208
AntiSamy is a Java library designed to provide fast and configurable cleansing of HTML input from untrusted sources, primarily to mitigate the risk of injecting malicious code, particularly JavaScript. It allows developers to enforce specific policy files governing allowable HTML and CSS, enhancing security when users submit content to web applications. Notable features include support for customizable policies, mandatory XML Schema validation for policy files, and deprecation of potentially hazardous features such as support for external stylesheets.
03 Aug 2026
Python
★ 22
Triager is a DFIR automation platform designed for Windows triage collections, facilitating the processing and organization of various digital artifacts into investigation-ready CSV files. It features a command-line interface (Triager CLI) for parsing and searching processed results, as well as a web console for multi-case management, enabling centralized evidence analysis, role-based access, and collaboration across multiple machines. Notable capabilities include built-in support for integrating various forensic tools, cross-machine correlation, and advanced features such as AI assistance for generating reports and findings.
03 Aug 2026
Python
★ 172
ThreatIntel-Reports is a comprehensive repository designed for the extraction and search of content from numerous threat intelligence reports, enabling users to automatically gather data from various feeds. Its primary use case is to facilitate the exploration of threat intelligence through keyword-based searches in both a web interface and command-line interface, with capabilities to store results in JSON format for integration. Notable features include a custom search bar for predefined results and Python scripts that allow users to perform keyword searches and manage output flexibly.
03 Aug 2026
PHP
★ 79
SussyFinder is a PHP web application designed to scan directories for files with specific extensions, particularly PHP scripts, and identify potential malicious content through token and pattern analysis. It features a token-based comparison method that accounts for obfuscation techniques, allows for MD5 hash-based whitelisting and blacklisting, and presents results with color highlights for easy identification. The tool is particularly useful for web server environments but requires cautious use due to the potential for false positives and file deletion capabilities.
03 Aug 2026
★ 17
The 'suspicious_IPs' repository provides a compiled list of potentially malicious or harmful IP addresses. Its primary use case is for cybersecurity professionals to enhance threat detection and mitigation measures by identifying and blocking traffic from these suspicious IPs. Notable features include a straightforward format that allows for easy integration into firewall rules and intrusion detection systems.
03 Aug 2026
Python
★ 759
StringSifter is a machine learning tool designed for ranking strings to enhance malware analysis efficiency. It mimics GNU binutils' `strings` functionality while providing additional capabilities like ranking strings based on relevance, supporting batch processing, and offering customizable output options. Notably, it integrates with various input sources, making it adaptable for extracting insights from memory dumps and obfuscated binaries.
03 Aug 2026
Python
★ 2039
Speakeasy is a Windows malware emulation framework designed to execute binaries, drivers, and shellcode within a modeled Windows runtime environment, rather than a full virtual machine. Its primary use case is to provide realistic execution paths for malware analysis by emulating various system behaviors, including APIs, file systems, and network activity. Notable features include the ability to run from a command-line interface for quick triage and the option to integrate as a Python library that generates structured JSON reports.
03 Aug 2026
★ 232
The Rust Malware Sample Gallery is a curated collection designed to assist malware reverse engineers by providing samples of malware written in the Rust programming language. Its primary use case is to enhance the understanding and skills necessary for reversing Rust binaries, particularly as malicious software in Rust becomes increasingly prevalent. Notable features include links to downloadable samples from reputable sources and technical writeups that explore various malware families, offering insights into their characteristics and behaviors.
03 Aug 2026
Python
★ 49
PseudoNote is an AI-enhanced plugin for IDA Pro that streamlines malware reverse engineering by automating tasks such as function renaming, code explanation, and generating human-readable C code. Its key features include a markdown editor for analyst notes, customizable AI prompts for specific functions, and the capability to produce detailed forensic reports, with all generated data saved directly to the IDB file for persistent access. This tool is particularly beneficial for malware analysts seeking efficiency in their analysis workflows.
03 Aug 2026
C
★ 35
procscope is an eBPF-based process tracer for Linux that enables real-time observation of process behavior, including lifecycle events, file activity, and network connections, with minimal overhead and configuration. It is primarily designed for security researchers and incident responders to trace malware behavior and audit container workloads without the complexities of traditional monitoring tools like EDR. Notable features include support for various process-related events, file operations, and privilege transitions, allowing users to effectively monitor and analyze runtime activity.
03 Aug 2026
Rust
★ 13
PETriage is a cross-platform Portable Executable (PE) surface analysis tool designed for malware triage, implemented in Rust for efficiency on Linux, macOS, and Windows. It offers a static-only analysis approach, ensuring the PE files are not executed, making it suitable for safe malware examination. Key features include a command-line interface for batch processing, interactive and graphical interfaces for detailed analysis, and extensive detection capabilities that encompass anomaly detection, OPSEC analysis, and PE file manipulation functionalities.