Awesome List

Awesome Security

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

sbilly/awesome-security #awesome-list #security 7 repo(s) failed to sync.
List stars
14,440
README repos
189
Indexed repos
140
List commits
515
Forks
2,267
Open issues
240

Tracked list growth

GitHub stars and default-branch commits for sbilly/awesome-security.

Latest scan 2026-06-22 13:13

Likes history

GitHub stars

Commits history

Default branch commits

Indexed repositories

59 repos matching these filters.

Latest repo push 2026-06-22

Filter this list

Search within Awesome Security or narrow by ecosystem and project health.

Clear 1 refinement
Search mode
Tune results
More filters Topics, generated tags, stack, files, age, archive status, and growth.
Ecosystem
Files

Choose a suggestion or use commas to require multiple files.

Health

Uses known first-commit dates.

Momentum
Filters by observed commit-count growth over the repository's latest 7-day capture window. Repositories without a recent baseline are excluded.
Filters by observed GitHub star growth over the repository's latest 7-day capture window. Repositories without a recent baseline are excluded.
Reset filters
Highlighted

Open highlighted repo slot

Put your repository first

Promote a GitHub repo at the top of Awesome repository list views for 7 days.

aquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Updated
2026-06-22
Lists
1 list mention
First commit
2019-03-27
License
Apache-2.0
Issues
241 open
Forks
487
Commits
4,118 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Updated
2026-06-22
Lists
3 list mentions
First commit
2005-09-23
License
NOASSERTION
Issues
2,869 open
Forks
2,349
Commits
47,737 commits
Star growth, last 7 days
+24 +0.2%
Commit velocity, last 7 days
+65 +0.1%
OWASP/mastg

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

AI dev
Updated
2026-06-22
Lists
1 list mention
First commit
2016-10-01
License
CC-BY-SA-4.0
Issues
228 open
Forks
2,758
Commits
10,702 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
aboul3la/Sublist3r

Fast subdomains enumeration tool for penetration testers

Stack
Updated
2024-08-02
Lists
1 list mention
First commit
2015-12-15
License
GPL-2.0
Issues
252 open
Forks
2,215
Commits
138 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
bridgecrewio/checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

Updated
2026-06-15
Lists
1 list mention
First commit
2019-11-27
License
Apache-2.0
Issues
140 open
Forks
1,353
Commits
17,390 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
guardicore/monkey

Infection Monkey - An open-source adversary emulation platform

Updated
2025-05-01
Lists
1 list mention
First commit
2015-08-30
License
GPL-3.0
Issues
239 open
Forks
820
Commits
19,752 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
trustedsec/ptf

The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.

Stack
Updated
2024-09-22
Lists
1 list mention
First commit
2015-05-12
License
Unknown
Issues
9 open
Forks
1,283
Commits
1,517 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
dev-sec/ansible-collection-hardening

This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL

Updated
2026-06-18
Lists
1 list mention
First commit
2015-04-23
License
Apache-2.0
Issues
76 open
Forks
828
Commits
2,545 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
google/grr

GRR Rapid Response: remote live forensics for incident response

Updated
2026-05-12
Lists
1 list mention
First commit
2011-08-21
License
Apache-2.0
Issues
189 open
Forks
797
Commits
1,463 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
nbs-system/naxsi

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

Archived
Stack
C pip
GitHub topics
Updated
2023-11-08
Lists
1 list mention
First commit
2011-07-28
License
GPL-3.0
Issues
0 open
Forks
598
Commits
761 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
Bearer/bearer

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Updated
2026-06-22
Lists
1 list mention
First commit
2022-09-27
License
NOASSERTION
Issues
27 open
Forks
142
Commits
1,411 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
cider-security-research/cicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Updated
2024-07-14
Lists
1 list mention
First commit
2022-04-11
License
Apache-2.0
Issues
0 open
Forks
414
Commits
69 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
cossacklabs/themis

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14 platforms.

Updated
2026-04-24
Lists
4 list mentions
First commit
2014-09-13
License
Apache-2.0
Issues
31 open
Forks
159
Commits
1,832 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
matanolabs/matano

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Updated
2025-01-08
Lists
2 list mentions
First commit
2022-07-14
License
Apache-2.0
Issues
55 open
Forks
120
Commits
576 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
cossacklabs/acra

Database security suite. Database proxy with field-level encryption, search through encrypted data, SQL injections prevention, intrusion detection, honeypots. Supports client-side and proxy-side ("transparent") encryption. SQL, NoSQL.

Updated
2026-04-23
Lists
1 list mention
First commit
2016-11-21
License
Apache-2.0
Issues
20 open
Forks
137
Commits
1,059 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
lunasec-io/lunasec

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

Updated
2024-05-02
Lists
2 list mentions
First commit
2021-03-15
License
NOASSERTION
Issues
98 open
Forks
167
Commits
3,454 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
CERT-Polska/Artemis

A modular vulnerability scanner with automatic report generation capabilities.

Updated
2026-06-22
Lists
1 list mention
First commit
2020-11-06
License
BSD-3-Clause
Issues
50 open
Forks
140
Commits
2,356 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
Abacus-Group-RTO/legion

Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance and exploitation of information systems.

Archived
Stack
Updated
2024-11-04
Lists
1 list mention
First commit
2018-09-19
License
GPL-3.0
Issues
73 open
Forks
185
Commits
545 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
tijme/angularjs-csti-scanner

Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x.

Updated
2021-10-20
Lists
1 list mention
First commit
2017-02-01
License
MIT
Issues
1 open
Forks
94
Commits
206 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
ironbee/ironbee

Universal web application security sensor intended for real-time monitoring and defense.

Stack
Updated
2016-01-07
Lists
1 list mention
First commit
2011-01-18
License
Apache-2.0
Issues
6 open
Forks
60
Commits
7,991 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
karimhabush/cyberowl

Aggregates security advisories from 10 international CERTs daily and provides an AI skill that cross-references alerts against your project's tech stack.

Updated
2026-06-21
Lists
1 list mention
First commit
2022-02-15
License
MIT
Issues
16 open
Forks
21
Commits
3,831 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%