OPEN SOURCE, OPEN TO EVERYONE

Open source. Open possibilities.

Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.

Human-curated · Discover open source3941discovered

A little curiosity. A world of open source.

THE FIRST COLLECTION
Topic: security-tools清除
ADDED

A curated collection of 150+ tools and techniques for red teaming and penetration testing, organized by MITRE ATT&CK framework categories covering reconnaissance, initial access, execution, privilege escalation, defense evasion, credential access, lateral movement, command and control, exfiltration, and impact.

Developer toolsSelf-hostedTesting & debugging
x64dbgx64dbg
ADDED

x64dbg is an open-source user-mode debugger for Windows, aimed at reverse engineering and malware analysis of executables whose source code is unavailable. It ships 32-bit and 64-bit builds, a plugin system, and can be compiled from source by users.

Developer toolsTesting & debugging
web-checklissy93
ADDED

Web-Check is an open-source, self-hostable OSINT dashboard for analysing any website. It gathers IP, DNS, SSL, headers, cookies, crawl rules, ports, traceroute, server location, redirects, trackers, performance and carbon footprint data.

Self-hostedDeveloper toolsMonitoring & security
trivyaquasecurity
ADDED

Trivy is a comprehensive security scanner used to detect vulnerabilities, misconfigurations, secrets, and SBOMs across various targets including containers, Kubernetes, and code repositories.

Developer toolsSelf-hostedTesting & debugging
ADDED

BitCurrents Log Analyzer is a lightweight single-page web application that turns raw Nginx access and error logs into actionable insights. Using the IP2Location API, it provides geolocation, intelligent bot detection, and bot impersonator flagging across three dashboard modes: General traffic overview, Security threat analysis, and Error diagnosis.

Self-hostedDeveloper toolsMonitoring & security
infisicalInfisical
ADDED

Infisical is an open-source platform for secrets management, certificate/PKI lifecycle, key management, and privileged access management. Features include a dashboard, CLI, SDKs and API, secret syncs and rotation, leak scanning, a Kubernetes operator, and self-hosting via Docker.

Self-hostedDeveloper toolsMonitoring & security

A curated list of open source tools for AWS security covering defensive hardening, offensive testing, auditing, DFIR, and more.

Developer toolsSelf-hostedCLI & terminal
secureflowdanielcadev
ADDED

SecureFlow is a local-first application security platform in Rust. It combines deterministic source-to-sink analysis, human validation workflows, and offline API inventorying. The tool prioritizes reproducible evidence, maintaining strict separation between automated candidates and final human judgments, with no automatic vulnerability validation.

Developer toolsAI & MLTesting & debugging
terrasecureJashwanthMU
ADDED

TerraSecure is an ML-powered security scanner for Terraform and HCL Infrastructure as Code across AWS, Azure, and GCP. It detects cloud misconfigurations at build time using a multi-cloud rule engine, an XGBoost ML model for AWS, and AI analysis for contextual remediation, integrating with CI/CD workflows.

Developer toolsAI & MLBuild & DevOps
fail2banfail2ban
ADDED

Fail2Ban is a daemon that scans log files and bans IPs with repeated authentication failures by updating firewall rules, supporting IPv6 and many services.

Self-hostedDeveloper toolsMonitoring & security
shannonKeygraphHQ
ADDED

Shannon is an open-source, autonomous AI pentester for web applications and APIs. It analyzes your source code to find attack paths, then executes real exploits against a running app, reporting only vulnerabilities proven with a working proof of concept.

Developer toolsAI & MLTesting & debugging
anakrisisNot-SockPuppet
ADDED

Anakrisis is an ethics-aware OSINT investigation planning and risk evaluation MCP server. It classifies investigations, scores risk against local YAML doctrine, flags prohibited actions, and scaffolds case documentation, supporting both cloud and local AI models.

Self-hostedDeveloper toolsServer management
gitleaksgitleaks
ADDED

Gitleaks is an open-source secret detection tool for scanning git repositories, directories, files and stdin for passwords, API keys and tokens, with pre-commit hook and CI action integrations.

Developer toolsAutomationTesting & debugging
ADDED

Reticle is a proxy and desktop UI for debugging MCP integrations. It intercepts, visualizes, and profiles MCP JSON-RPC traffic in real time with microsecond-level overhead, letting developers inspect messages, correlate request-response pairs, profile latency, capture server errors, and record sessions for export.

Developer toolsTesting & debugging
ipscoutjonhadfield
ADDED

IPScout enriches IP addresses from 67 sources (cloud, CDN, threat feeds) via command line, providing threat ratings, caching, and configurable output formats.

Developer toolsSelf-hostedCLI & terminal
trufflehogtrufflesecurity
ADDED

TruffleHog is a Go-based CLI that scans Git, GitHub, GitLab, Docker, S3, GCS, filesystems, CI logs and other sources for leaked credentials; it classifies, verifies and analyzes secrets, with JSON/SARIF output.

Developer toolsAutomationBuild & DevOps
zentrajohannus22
ADDED

Zentra is an AI-powered CLI security scanner for developers, combining SAST, DAST, supply-chain, API, and IaC analysis with LLM orchestration, CI integration, and an authorized pentest mode.

Developer toolsAI & MLTesting & debugging