Open-source AI-powered offensive security harness for automated penetration testing.
Best Security & Hardening GitHub Repositories
Top 357 open source projects in Security & Hardening. Ranked by stars, activity, and recorded community growth.
Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and opens PRs that fix what it finds. MCP both ways: plug in any MCP server as a tool, or drive RedAmon from Claude Code or your own agent.
Flutter Reverse Engineering Framework
Patch-level verification for Bundler
Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.
Cross-platform desktop GUI app to clean image metadata
A security-focused library OS supporting kernel- and user-mode execution
Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go and 7+ native security tools.
XERJ is the new way for AI to search data. Its autoindex capability activates agents to know your data without the token waste of grep and sed. One command indexes code, docs, logs and PDFs for search, RAG, security audits and agent memory, using 40x fewer tokens than grep. Elasticsearch compatible, so existing clients just work.
Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
Security engine for Java (authentication, authorization, multi frameworks): OpenID Connect, SAML2, CAS, OAuth, LDAP, JWT...
OAuth 2.0 social authentication providers for ASP.NET Core
Provides a tight integration of the Security component into the Symfony full-stack framework
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
Open-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue.
ESLint rules for Node Security
🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google, Facebook, Okta, etc.), SAML Authentication. MFA/2FA with App Authenticators and Yubico. 💎 Authorization with JWT/PASETO tokens. 🔐
ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.
A secure low code deception runtime framework, leveraging AI for System Virtualization.