Awesome

GitHub projects from awesome lists

Search awesome repositories

Search names, descriptions, topics, tags, and stacks, then tune results by ecosystem, freshness, health, and cross-list signal.

Repos indexed
18,423
Awesome lists tracked
132
Current results
17

Find repositories

Start broad, then narrow by ecosystem, freshness, health, and growth.

Clear 1 refinement
Search mode
Tune results
More filters Topics, generated tags, stack, files, age, archive status, and growth.
Ecosystem
Files

Choose a suggestion or use commas to require multiple files.

Health

Uses known first-commit dates.

Momentum
Filters by observed commit-count growth over the repository's latest 7-day capture window. Repositories without a recent baseline are excluded.
Filters by observed GitHub star growth over the repository's latest 7-day capture window. Repositories without a recent baseline are excluded.
Reset filters
Highlighted

Open highlighted repo slot

Put your repository first

Promote a GitHub repo at the top of Awesome repository list views for 7 days.

usestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

AI dev
Updated
2026-09-15
Lists
1 list mention
First commit
2025-08-09
History
105 history points
License
Apache-2.0
Issues
387 open
Forks
6,867
Commits
805 commits
Star growth, last 7 days
+1,250 +2.0%
Commit velocity, last 7 days
+3 +0.4%
KeygraphHQ/shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

AI dev
Updated
2026-09-08
Lists
0 list mentions
First commit
2025-10-04
History
106 history points
License
AGPL-3.0
Issues
18 open
Forks
5,503
Commits
294 commits
Star growth, last 7 days
+158 +0.3%
Commit velocity, last 7 days
0 0.0%
mukul975/Anthropic-Cybersecurity-Skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

AI dev
Updated
2026-08-31
Lists
2 list mentions
First commit
2026-02-25
History
1 history point
License
Apache-2.0
Issues
45 open
Forks
3,899
Commits
245 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Updated
2026-08-21
Lists
4 list mentions
First commit
2005-09-23
History
8 history points
License
NOASSERTION
Issues
2,975 open
Forks
2,452
Commits
49,327 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
future-architect/vuls

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

Updated
2026-08-27
Lists
2 list mentions
First commit
2016-03-27
History
7 history points
License
GPL-3.0
Issues
87 open
Forks
1,240
Commits
1,912 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
xonsh/xonsh

🐚 Python-powered shell. Full-featured, cross-platform and AI-friendly.

AI dev
Updated
2026-09-01
Lists
3 list mentions
First commit
2015-01-21
History
8 history points
License
NOASSERTION
Issues
74 open
Forks
735
Commits
11,961 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
guardicore/monkey

Infection Monkey - An open-source adversary emulation platform

Updated
2025-05-01
Lists
2 list mentions
First commit
2015-08-30
History
5 history points
License
GPL-3.0
Issues
240 open
Forks
829
Commits
19,752 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
DefectDojo/django-DefectDojo

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

AI dev
Updated
2026-08-28
Lists
1 list mention
First commit
2015-03-13
History
4 history points
License
BSD-3-Clause
Issues
216 open
Forks
1,940
Commits
15,171 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
GH05TCREW/pentestagent

PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.

AI dev
Updated
2026-09-07
Lists
2 list mentions
First commit
2025-05-15
History
7 history points
License
MIT
Issues
30 open
Forks
613
Commits
391 commits
Star growth, last 7 days
0 0.0%
Commit velocity, last 7 days
0 0.0%
Bearer/bearer

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Updated
2026-08-20
Lists
1 list mention
First commit
2022-09-27
History
4 history points
License
NOASSERTION
Issues
16 open
Forks
148
Commits
1,434 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
oritera/Cairn

A AI general-purpose state-space search engine, validated first on autonomous penetration testing.

AI dev
Updated
2026-09-07
Lists
1 list mention
First commit
2026-04-19
History
1 history point
License
AGPL-3.0
Issues
10 open
Forks
364
Commits
70 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
aress31/burpgpt

A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.

Updated
2024-06-09
Lists
1 list mention
First commit
2023-04-08
History
6 history points
License
Apache-2.0
Issues
Disabled
Forks
284
Commits
79 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
bountyyfi/lonkero

Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

Updated
2026-08-16
Lists
2 list mentions
First commit
2025-12-05
History
4 history points
License
NOASSERTION
Issues
12 open
Forks
86
Commits
969 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
insidersec/insider

Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code, focused on a agile and easy to implement software inside your DevOps pipeline. Support the following technologies: Java (Maven and Android), Kotlin (Android), Swift (iOS), .NET Full Framework, C#, and Javascript (Node.js).

Updated
2022-04-10
Lists
1 list mention
First commit
2019-11-12
History
4 history points
License
MIT
Issues
21 open
Forks
80
Commits
163 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
cynative/cynative

Deep research for your infra. Cynative runs frontier models across your code, cloud and runtime - reasoning through GitHub, GitLab, AWS, GCP, Azure and Kubernetes as one system - and comes back with verified answers.

AI dev
Updated
2026-08-05
Lists
2 list mentions
First commit
2026-06-24
History
2 history points
License
Apache-2.0
Issues
18 open
Forks
28
Commits
156 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history
MutableSecurity/mutablesecurity

CLI program for automating the setup, configuration, and use of cybersecurity solutions

Archived
Updated
2023-02-12
Lists
1 list mention
First commit
2022-03-15
History
4 history points
License
MIT
Issues
7 open
Forks
7
Commits
65 commits
Star growth, last 7 days
No 7-day history
Commit velocity, last 7 days
No 7-day history