A vulnerability scanner for container images and filesystems
Top SECURITY GitHub Repositories & Tools (2026)
Discover the most starred and trending open source tools tagged with #security.
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
Astrid is a portable, capability-secure operating system for composable software.
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.
Go security checker
Tuta is an email service with a strong focus on security and privacy that lets you encrypt emails, contacts and calendar entries on all your devices.
BleachBit system cleaner for Windows and Linux
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
A PHP static analysis tool for finding errors and security vulnerabilities in PHP applications
Autonomous Hacking Agent for Red Team
Kanidm: A simple, secure, and fast identity management platform
AI-safe .env files: Schemas for agents, Secrets for humans.
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library
A WiFi security auditing software
Manages application of security headers with many safe defaults
The Python Code Tutorials
Open-source AI-powered offensive security harness for automated penetration testing.
Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and opens PRs that fix what it finds. MCP both ways: plug in any MCP server as a tool, or drive RedAmon from Claude Code or your own agent.