Awesome

GitHub projects from awesome lists

Search awesome repositories

Search names, descriptions, topics, tags, and stacks, then tune results by ecosystem, freshness, health, and cross-list signal.

Repos indexed
18,423
Awesome lists tracked
132
Current results
31

Find repositories

Start broad, then narrow by ecosystem, freshness, health, and growth.

Clear 1 refinement
Search mode
Tune results
More filters Topics, generated tags, stack, files, age, archive status, and growth.
Ecosystem
Files

Choose a suggestion or use commas to require multiple files.

Health

Uses known first-commit dates.

Momentum
Filters by observed commit-count growth over the repository's latest 7-day capture window. Repositories without a recent baseline are excluded.
Filters by observed GitHub star growth over the repository's latest 7-day capture window. Repositories without a recent baseline are excluded.
Reset filters
Highlighted

Open highlighted repo slot

Put your repository first

Promote a GitHub repo at the top of Awesome repository list views for 7 days.

swisskyrepo/PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Updated
2026-08-27
Lists
3 list mentions
First commit
2016-10-18
History
5 history points
License
MIT
Issues
Disabled
Forks
17,334
Commits
2,202 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
usestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

AI dev
Updated
2026-09-15
Lists
1 list mention
First commit
2025-08-09
History
105 history points
License
Apache-2.0
Issues
387 open
Forks
6,867
Commits
805 commits
Star growth, last 7 days
+1,250 +2.0%
Commit velocity, last 7 days
+3 +0.4%
KeygraphHQ/shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

AI dev
Updated
2026-09-08
Lists
0 list mentions
First commit
2025-10-04
History
106 history points
License
AGPL-3.0
Issues
18 open
Forks
5,503
Commits
294 commits
Star growth, last 7 days
+158 +0.3%
Commit velocity, last 7 days
0 0.0%
mukul975/Anthropic-Cybersecurity-Skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

AI dev
Updated
2026-08-31
Lists
2 list mentions
First commit
2026-02-25
History
1 history point
License
Apache-2.0
Issues
45 open
Forks
3,899
Commits
245 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
GreyDGL/PentestGPT

Automated Penetration Testing Agentic Framework Powered by Large Language Models

AI dev
Updated
2026-07-14
Lists
2 list mentions
First commit
2023-02-27
History
6 history points
License
MIT
Issues
68 open
Forks
2,612
Commits
307 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
1N3/Sn1per

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

Updated
2026-07-04
Lists
1 list mention
First commit
2015-09-06
History
4 history points
License
NOASSERTION
Issues
7 open
Forks
2,181
Commits
722 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Updated
2026-08-27
Lists
1 list mention
First commit
2017-05-14
History
4 history points
License
CC-BY-SA-4.0
Issues
31 open
Forks
1,669
Commits
1,278 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
six2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

AI dev
Updated
2026-08-20
Lists
2 list mentions
First commit
2020-12-30
History
4 history points
License
MIT
Issues
3 open
Forks
1,221
Commits
2,363 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
guardicore/monkey

Infection Monkey - An open-source adversary emulation platform

Updated
2025-05-01
Lists
2 list mentions
First commit
2015-08-30
History
5 history points
License
GPL-3.0
Issues
240 open
Forks
829
Commits
19,752 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
j3ssie/osmedeus

A Modern Orchestration Engine for Security

AI dev
Updated
2026-08-08
Lists
2 list mentions
First commit
2026-01-18
History
4 history points
License
MIT
Issues
7 open
Forks
1,029
Commits
133 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
GH05TCREW/pentestagent

PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.

AI dev
Updated
2026-09-07
Lists
2 list mentions
First commit
2025-05-15
History
7 history points
License
MIT
Issues
30 open
Forks
613
Commits
391 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
rewardone/OSCPRepo

A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and reading material in 'BookmarkList' CherryTree. Reconscan Py2 and Py3. Custom ISO building.

Updated
2020-06-22
Lists
1 list mention
First commit
2017-11-12
History
4 history points
License
MIT
Issues
1 open
Forks
758
Commits
387 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
oritera/Cairn

A AI general-purpose state-space search engine, validated first on autonomous penetration testing.

AI dev
Updated
2026-09-07
Lists
1 list mention
First commit
2026-04-19
History
1 history point
License
AGPL-3.0
Issues
10 open
Forks
364
Commits
70 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
samugit83/redamon

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.

AI dev
Updated
2026-09-10
Lists
1 list mention
First commit
2025-12-29
History
7 history points
License
MIT
Issues
15 open
Forks
492
Commits
990 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
codingo/VHostScan

A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.

Updated
2025-08-18
Lists
1 list mention
First commit
2017-09-03
History
4 history points
License
GPL-3.0
Issues
1 open
Forks
238
Commits
347 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
yassineaboukir/sublert

Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.

Updated
2021-02-05
Lists
1 list mention
First commit
2019-03-08
History
4 history points
License
MIT
Issues
17 open
Forks
165
Commits
67 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
Warxim/petep

PETEP (PEnetration TEsting Proxy) is an open-source Java application for traffic analysis & modification using TCP/UDP proxies. PETEP is a useful tool for performing penetration tests of applications with various application protocols. ⚡

Updated
2023-12-01
Lists
1 list mention
First commit
2020-08-01
History
4 history points
License
GPL-3.0
Issues
0 open
Forks
23
Commits
49 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
momenbasel/htb-writeups

The most comprehensive Hack The Box writeup collection - 500+ machines, 400+ challenges, interactive knowledge graph, skill trees, attack path diagrams, ProLabs, Sherlocks, OSCP/CPTS/CRTO prep. Browse: momenbasel.github.io/htb-writeups

Updated
2026-07-18
Lists
1 list mention
First commit
2026-04-10
History
4 history points
License
MIT
Issues
0 open
Forks
44
Commits
28 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
cr0mll/cyberclopaedia

This is an aspiring project aimed at accumulating knowledge from the world of cybersecurity and presenting it in a cogent way, so it is accessible to as large an audience as possible and so that everyone has a good resource to learn hacking from.

Updated
2024-08-06
Lists
1 list mention
First commit
2021-09-06
History
4 history points
License
MIT
Issues
0 open
Forks
26
Commits
274 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history