SecureFlow is a local-first application security platform in Rust. It combines deterministic source-to-sink analysis, human validation workflows, and offline API inventorying. The tool prioritizes reproducible evidence, maintaining strict separation between automated candidates and final human judgments, with no automatic vulnerability validation.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONShannon is an open-source, autonomous AI pentester for web applications and APIs. It analyzes your source code to find attack paths, then executes real exploits against a running app, reporting only vulnerabilities proven with a working proof of concept.
Gitleaks is an open-source secret detection tool for scanning git repositories, directories, files and stdin for passwords, API keys and tokens, with pre-commit hook and CI action integrations.
Reticle is a proxy and desktop UI for debugging MCP integrations. It intercepts, visualizes, and profiles MCP JSON-RPC traffic in real time with microsecond-level overhead, letting developers inspect messages, correlate request-response pairs, profile latency, capture server errors, and record sessions for export.
Zentra is an AI-powered CLI security scanner for developers, combining SAST, DAST, supply-chain, API, and IaC analysis with LLM orchestration, CI integration, and an authorized pentest mode.
A curated collection of 150+ tools and techniques for red teaming and penetration testing, organized by MITRE ATT&CK framework categories covering reconnaissance, initial access, execution, privilege escalation, defense evasion, credential access, lateral movement, command and control, exfiltration, and impact.
x64dbg is an open-source user-mode debugger for Windows, aimed at reverse engineering and malware analysis of executables whose source code is unavailable. It ships 32-bit and 64-bit builds, a plugin system, and can be compiled from source by users.
Web-Check is an open-source, self-hostable OSINT dashboard for analysing any website. It gathers IP, DNS, SSL, headers, cookies, crawl rules, ports, traceroute, server location, redirects, trackers, performance and carbon footprint data.
Trivy is a comprehensive security scanner used to detect vulnerabilities, misconfigurations, secrets, and SBOMs across various targets including containers, Kubernetes, and code repositories.