x64dbg is an open-source user-mode debugger for Windows, aimed at reverse engineering and malware analysis of executables whose source code is unavailable. It ships 32-bit and 64-bit builds, a plugin system, and can be compiled from source by users.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONWeb-Check is an open-source, self-hostable OSINT dashboard for analysing any website. It gathers IP, DNS, SSL, headers, cookies, crawl rules, ports, traceroute, server location, redirects, trackers, performance and carbon footprint data.
Trivy is a comprehensive security scanner used to detect vulnerabilities, misconfigurations, secrets, and SBOMs across various targets including containers, Kubernetes, and code repositories.
BitCurrents Log Analyzer is a lightweight single-page web application that turns raw Nginx access and error logs into actionable insights. Using the IP2Location API, it provides geolocation, intelligent bot detection, and bot impersonator flagging across three dashboard modes: General traffic overview, Security threat analysis, and Error diagnosis.
Infisical is an open-source platform for secrets management, certificate/PKI lifecycle, key management, and privileged access management. Features include a dashboard, CLI, SDKs and API, secret syncs and rotation, leak scanning, a Kubernetes operator, and self-hosting via Docker.
SecureFlow is a local-first application security platform in Rust. It combines deterministic source-to-sink analysis, human validation workflows, and offline API inventorying. The tool prioritizes reproducible evidence, maintaining strict separation between automated candidates and final human judgments, with no automatic vulnerability validation.
TerraSecure is an ML-powered security scanner for Terraform and HCL Infrastructure as Code across AWS, Azure, and GCP. It detects cloud misconfigurations at build time using a multi-cloud rule engine, an XGBoost ML model for AWS, and AI analysis for contextual remediation, integrating with CI/CD workflows.
Fail2Ban is a daemon that scans log files and bans IPs with repeated authentication failures by updating firewall rules, supporting IPv6 and many services.
Shannon is an open-source, autonomous AI pentester for web applications and APIs. It analyzes your source code to find attack paths, then executes real exploits against a running app, reporting only vulnerabilities proven with a working proof of concept.
TurkeyBite is an open-source domain and host context analysis pipeline that analyzes client network traffic to categorize requested domains (e.g. adult content, gambling, shopping). It uses a Docker-based stack with Packetbeat/Browserbeat, Valkey, OpenSearch and Bind9, is non-intrusive (does not block client requests), and outputs analysis results to OpenSearch Dashboards or Syslog.
Anakrisis is an ethics-aware OSINT investigation planning and risk evaluation MCP server. It classifies investigations, scores risk against local YAML doctrine, flags prohibited actions, and scaffolds case documentation, supporting both cloud and local AI models.
Gitleaks is an open-source secret detection tool for scanning git repositories, directories, files and stdin for passwords, API keys and tokens, with pre-commit hook and CI action integrations.
Prowler is an open-source cloud security platform that automates security and compliance assessments across multiple cloud environments.
Reticle is a proxy and desktop UI for debugging MCP integrations. It intercepts, visualizes, and profiles MCP JSON-RPC traffic in real time with microsecond-level overhead, letting developers inspect messages, correlate request-response pairs, profile latency, capture server errors, and record sessions for export.
IPScout enriches IP addresses from 67 sources (cloud, CDN, threat feeds) via command line, providing threat ratings, caching, and configurable output formats.
TruffleHog is a Go-based CLI that scans Git, GitHub, GitLab, Docker, S3, GCS, filesystems, CI logs and other sources for leaked credentials; it classifies, verifies and analyzes secrets, with JSON/SARIF output.
Zentra is an AI-powered CLI security scanner for developers, combining SAST, DAST, supply-chain, API, and IaC analysis with LLM orchestration, CI integration, and an authorized pentest mode.
A curated collection of 150+ tools and techniques for red teaming and penetration testing, organized by MITRE ATT&CK framework categories covering reconnaissance, initial access, execution, privilege escalation, defense evasion, credential access, lateral movement, command and control, exfiltration, and impact.