Open highlighted repo slot
Put your repository first
Promote a GitHub repo at the top of Awesome repository list views for 7 days.
GitHub projects from awesome lists
Search names, descriptions, topics, tags, and stacks, then tune results by ecosystem, freshness, health, and cross-list signal.
Open highlighted repo slot
Promote a GitHub repo at the top of Awesome repository list views for 7 days.
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
Comfortably monitor your network traffic 🕵️♂️
Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.
Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.
Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
🕵️♂️ All-in-one OSINT tool for analysing any website
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
The official NGINX Open Source repository.
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Set up a personal VPN in the cloud
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Find secrets with Gitleaks 🔑
The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™
KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.
⚙️ NGINX config generator on steroids 💉
Find, verify, and analyze leaked credentials
The authentication glue you need.
UNIX-like reverse engineering framework and command-line toolset
SQL powered operating system instrumentation, monitoring, and analytics.
Slim(toolkit): Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)
Checklist of the most important security countermeasures when designing, testing, and releasing your API
Simple and flexible tool for managing secrets
Community guide to securing and improving privacy on macOS.
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.