Open-source disassembly framework written in pure C, supporting 20+ architectures including x86, ARM, AArch64, RISC-V, MIPS and PowerPC, with a clean architecture-neutral API, multi-language bindings, and detailed instruction semantics for binary analysis and reverse engineering.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONSniffnet is a free, cross-platform, open-source application for comfortably monitoring network traffic, with real-time charts, host geolocation, service identification, PCAP import/export and customizable notifications.
x64dbg is an open-source user-mode debugger for Windows, aimed at reverse engineering and malware analysis of executables whose source code is unavailable. It ships 32-bit and 64-bit builds, a plugin system, and can be compiled from source by users.
Iris is a local-first MCP server that scores AI agent runs for quality, safety, and cost using 20 built-in deterministic rules, an optional LLM judge, and a web dashboard — all on your machine with no account or telemetry.
Sophia Stack is a modern, atomic X11 desktop system designed to replace ambient trust with explicit authority boundaries and isolated namespaces.
Web-Check is an open-source, self-hostable OSINT dashboard for analysing any website. It gathers IP, DNS, SSL, headers, cookies, crawl rules, ports, traceroute, server location, redirects, trackers, performance and carbon footprint data.
GitHub profile README for Sachin, a self-described applied AI architect and engineer. It points to selected open-source projects covering agents, retrieval (RAG), evaluation and reliability tooling, and lists skills, working style, engagement terms and contact details.
Trivy is a comprehensive security scanner used to detect vulnerabilities, misconfigurations, secrets, and SBOMs across various targets including containers, Kubernetes, and code repositories.
A curated collection of Web Application Security payloads and bypasses for pentesting and CTFs, covering vulnerability descriptions, exploitation techniques, and Burp Intruder file sets.
Template-driven vulnerability scanner with a YAML DSL, community templates, and support for HTTP, DNS, TCP, SSL, WHOIS, JavaScript, headless browser, fuzzing, CI/CD integration, and multiple report formats.
AgentLeak is an open-source privacy testing tool for AI agents. It detects data leaks across tool calls, memory, and logs using a local Python SDK, CLI, and MCP tools, providing redacted reports and CI gates without cloud dependencies.
Web of Flaws is a structured, markdown-first catalog of web security vulnerabilities and secure code replacements designed for developers, security engineers, and AI coding agents.
A curated list of Android security resources including tools for static/dynamic analysis, reverse engineering, fuzzing, and vulnerability scanning.
MCP Arcade is a command-line testing tool that runs a small catalog of experiments, called atoms, against MCP servers, judging results by the JSON-RPC wire and sandbox file changes rather than by tool descriptions or model prose.
Strix is an open-source AI-powered penetration testing tool that uses autonomous agents to identify, validate, and fix application vulnerabilities through real proof-of-concept exploits.
PyFlow is a research-oriented static analysis framework for Python, offering IRs, program analysis, optimization passes, security checking, supply-chain analysis, and CLI/LSP/MCP tooling.
SkillGuard is a local-first security scanner for coding-agent skills and MCP servers. It detects prompt injection, credential theft, data exfiltration and unsafe downloads, then blocks unscanned or risky tools via Claude Code and Codex hooks.
A curated collection of awesome GitHub lists covering cybersecurity topics for hackers, pentesters, and security researchers — including bug bounty, OSINT, reverse engineering, CTF, malware analysis, web security, IoT, AI security, and more.
objection is a Frida-powered runtime mobile exploration toolkit for iOS and Android, enabling security assessment of mobile apps without jailbreak, including SSL pinning bypass, keychain dumping, and heap manipulation.
VibeCoder is an automated GitHub issue worker that monitors repositories, picks up issues, writes code using AI agents (Claude, Codex, Gemini), runs quality checks, and opens pull requests. It supports review feedback loops, self-healing, and cost optimization.