03 Aug 2026
Python
★ 12
Cataam is an open-source security toolset that provides a variety of scripts and templates aimed at enhancing security and compliance practices for organizations. It features practical functionalities such as hardening scripts, CVE detection tools, and compliance documentation, making it suitable for security teams, DevOps, and compliance engineers. Notable offerings include a local-first prompt hygiene tool, CVE detection scripts updated promptly after disclosures, and a comprehensive collection of CIS Benchmark guides and compliance templates.
03 Aug 2026
Python
★ 21
BitrixProbe is a Python-based vulnerability assessment tool specifically designed for CMS 1C-Bitrix/Bitrix24 installations. It offers dual modes of operation: `pentest` for external HTTP/HTTPS scans and `audit` for authenticated SSH scans, enabling comprehensive evaluation of both public exposure and server configurations. Notable features include integration with vulnerability databases, enumeration modules, and the ability to generate standardized reports, thus facilitating effective security assessments and audits.
03 Aug 2026
Python
★ 14
Awesome Security Pipeline is a comprehensive guide designed for selecting and implementing open-source security tools within CI/CD pipelines. It features a pre-configured baseline that integrates multiple tools such as Gitleaks, Semgrep, and Trivy, enabling continuous security validation and machine-readable evidence generation. The repository is actively maintained, with weekly status checks and regular updates to ensure the effectiveness of the security controls and methodologies provided.
03 Aug 2026
Rust
★ 52
auditor-skill is an open-source AI-driven security audit tool designed for auditing Solana programs and applications. It leverages AI agents to evaluate codebases against 1,346 verification items across 20 security domains and 131 known attack vectors, producing detailed reports that include executable proofs of vulnerabilities and suggested fixes. Notable features include a comprehensive audit lifecycle, token efficiency through pre-scanning, and deep coverage of Solana-specific methodologies.
03 Aug 2026
Rust
★ 989
Artifact Keeper is an enterprise-grade open-source artifact registry designed to support over 45 package formats, including Maven, NPM, Docker, and more. It features a WASM plugin system for custom format handling, automated security scanning for vulnerabilities, and a robust architecture with multi-auth support, full-text search capabilities, and artifact signing functionalities. Built in Rust, it emphasizes security with hardened container images and advanced replication features for scalable deployment.
03 Aug 2026
Python
★ 15
APISCAN is an advanced API vulnerability scanner that systematically evaluates APIs against the OWASP API Security Top 10 (2023) by utilizing OpenAPI/Swagger specifications. Notable features include automatic form login detection, deep scan modes for comprehensive testing, real-world attack pattern detection, and a user-friendly cross-platform GUI for enhanced usability. The tool is designed to proactively identify and model security vulnerabilities, providing actionable insights with detailed evidence.
03 Aug 2026
Rust
★ 24
ApiHunter is an asynchronous, modular API security scanner designed for baseline testing and regression detection in APIs. It facilitates both offensive and defensive use cases, enabling red-team activities like pentesting and exploit validation, as well as providing CI/CD regression gating and early misconfiguration detection. Notable features include adaptive concurrency, support for a variety of API security checks (such as CORS, CSP, GraphQL), and the ability to scan large numbers of targets rapidly with integrated threat intelligence capabilities.
03 Aug 2026
Python
★ 371
The Vulners Python SDK is a comprehensive client for accessing Vulners' vast vulnerability intelligence database, facilitating queries on CVEs, exploits, and advisories enriched with risk metrics like CVSS and EPSS. It enables users to assess vulnerabilities across various software and systems, stream data for integration into custom pipelines, and set alerts for new matching vulnerabilities, all while supporting asynchronous operations for enhanced performance. Notably, it incorporates features for tracking active exploits and provides an AI-ready infrastructure for real-time data processing.
03 Aug 2026
Go
★ 14
AIROM is a tool designed for scanning filesystems, git repositories, container images, and Kubernetes workloads to identify and document AI components in software. It generates an AI Bill of Materials that includes models, datasets, and frameworks used in the code, providing line-by-line evidence for each entry. Notable features include support for various scan targets, output formats like CycloneDX and SPDX, and the ability to gate builds based on identified risks.
03 Aug 2026
JavaScript
★ 121
The agent-security-scanner-mcp is a comprehensive security scanning tool designed for AI coding agents, providing functionalities to audit code, servers, prompts, and AI-generated packages for vulnerabilities. Key features include the ability to grade agent security, identify risks like SQL injection and package hallucinations, generate Software Bill of Materials (SBOMs), and facilitate semantic reviews using project context. The tool supports various AI platforms, ensuring robust integration and security checks before code execution.
03 Aug 2026
Python
★ 225
Agent Audit is a security tool designed to identify vulnerabilities in AI agent code prior to production deployment. Its primary use case involves scanning for risks associated with unsafe inputs, command execution, and configuration errors, utilizing a framework of 72 rules aligned with the OWASP Agentic Top 10. Notable features include tool-boundary taint tracking, configuration auditing, and the ability to enforce security measures within continuous integration workflows.
03 Aug 2026
Python
★ 19
AEM Dispatcher Security Scan is a command-line tool designed to perform security assessments on Adobe Experience Manager (AEM) Dispatcher configurations. It consolidates known security-sensitive URLs for AEM Dispatcher, allowing users to specify target websites and customize scan parameters while leveraging Docker for deployment. Notable features include configurable HTTP request timeouts, support for custom test paths, and an easy-to-use interface via command-line options.
03 Aug 2026
TypeScript
★ 46
Ghostint Tracker is an advanced web-based OSINT investigation and mapping tool designed to centralize, visualize, and enrich investigations through a dynamic graph interface and synchronized global mapping capabilities. Key features include a hybrid AI mode for enhanced data processing, a comprehensive catalog of over 450 external OSINT tools for one-click access, and robust data export options for tracking and reporting progress.
03 Aug 2026
Python
★ 58
ZettelForge is an agentic memory system specifically designed for cyber threat intelligence (CTI) that captures and maintains critical contextual knowledge from analysts. It automates the extraction of CVEs, IOCs, threat actors, and MITRE ATT&CK techniques from analyst notes, resolves naming aliases, and constructs a comprehensive STIX 2.1 knowledge graph, facilitating intent-aware searches without the need for external APIs. This tool aims to mitigate the knowledge loss associated with analyst turnover, enhancing investigation continuity and effectiveness within security operations centers.
03 Aug 2026
★ 106
YouTube-Video-OSINT is a tool designed for conducting open-source intelligence (OSINT) investigations on YouTube and other video platforms. It provides various resources and features for fetching deleted content, analyzing video metadata, and leveraging speech recognition and subtitle extraction tools. Notable functionalities include the ability to search for archived videos, manage channels, and utilize AI-driven tools for enhanced data extraction.
03 Aug 2026
Rust
★ 27
xint-rs is a command-line interface (CLI) tool designed for efficient and comprehensive real-time monitoring, search, and analysis of X (formerly Twitter) data. Built in Rust, it offers notable features such as full-text search, user and follower tracking, AI analysis, and a terminal user interface (TUI), all while ensuring minimal runtime overhead with a compact binary size of 2.5MB and startup time under 5ms. This tool requires X API access and supports myriad functionalities ranging from profile analysis to trend monitoring and tweet management.
03 Aug 2026
TypeScript
★ 249
`xint` is a TypeScript CLI tool designed for interacting with the X API, enabling users to search, monitor, analyze, and export data directly from the terminal. Key features include support for real-time filtered streams, comprehensive account analysis, and local data management while utilizing OAuth for secure operations. Like its predecessor twint, `xint` prioritizes the use of official APIs over scraping to facilitate research and automation tasks within the X ecosystem.
03 Aug 2026
Python
★ 335
WhatsOSINT is a tool designed to retrieve and display information associated with a WhatsApp number, such as status and profile photo, utilizing data from an API. Its primary use case is for OSINT (Open Source Intelligence) investigations, allowing users to toggle between live checks or cached data to manage API costs effectively. The project includes customizable settings for check modes and data providers, making it adaptable to various user needs while ensuring compatibility with multiple operating systems.
03 Aug 2026
Go
★ 13
Watson is a tool designed for searching social media accounts across various platforms by checking for availability of specified usernames. Its primary use case is to assist users in verifying the existence of usernames on multiple sites simultaneously, utilizing features such as custom output folders, timeout settings for requests, and adjustable request speeds. Additionally, it supports querying multiple usernames and provides options for detailed output management and configurations.
03 Aug 2026
Python
★ 10
Visualize-External-Addresses is a Python tool that enables real-time visualization of external IP address connections for Windows devices, integrating netstat output with Whois data and displaying it through Google Earth. The tool allows users to monitor and analyze network connections by generating KML files for external addresses, which can be updated every few seconds for continuous tracking. Notable features include easy setup via Anaconda, location-based monitoring with latitude and longitude inputs, and the requirement of Google Earth for graphical representation.
03 Aug 2026
Python
★ 10
Project Akasha is a modular Telegram UserBot utilizing the Telethon framework, designed for context-aware interaction and automation. It features advanced capabilities such as localized voice synthesis through Edge-TTS, a two-stage music downloader, and various group management tools, making it suitable for users looking to enhance their Telegram experience with AI-driven functionalities. Importantly, caution is advised due to its heavy scraping and growth modules, which can lead to user bans if misused.
03 Aug 2026
Go
★ 3044
Uncover is a Go-based tool designed to automate the discovery of exposed hosts on the internet by leveraging the APIs of multiple search engines like Shodan, Censys, and FOFA. Its primary use case centers around efficiently querying these services in tandem, allowing for input via standard input and stdout, while supporting multiple API keys and automatic key randomization for enhanced security and operational efficiency. Notable features include the ability to utilize awesome search queries and a broad array of supported search engines, making it versatile for cybersecurity professionals.
03 Aug 2026
Python
★ 14
Tornado-demix is a forensic research toolkit designed for the de-anonymization of Tornado.Cash ETH transactions by leveraging public on-chain data. It utilizes a probabilistic heuristic to correlate deposit and withdrawal patterns based on transaction timing and fixed-denomination amounts, outputting likely exit addresses for further investigation. Key features include support for single and multiple wallet analysis, denomination-profile matching, and cluster tracing, all performed without compromising cryptographic integrity.
03 Aug 2026
Python
★ 91
TokIntel is an advanced TikTok OSINT framework designed to extract comprehensive profile information, including bios, creation dates, and full metadata from TikTok usernames. Notable features include fast API-based data retrieval using Apify's TikTok Profile Scraper, batch processing for multiple usernames, and the generation of JSON and text reports for structured data output. Its user-friendly CLI interface allows for efficient profile reconnaissance and secure API key handling.
03 Aug 2026
Python
★ 18
tempolocus is a time-series analysis tool designed to infer geographical location based on activity patterns observed over time. Its primary use case involves processing JSON-formatted data, including weekly and yearly activity buckets or timestamp lists, to generate probabilistic outputs that classify activity types and suggest probable countries and timezones. Notable features include support for various holiday profiles, comparative analysis against holiday calendars, and the ability to handle multiple input formats for versatile applicability.