TypeScript · JavaScript★ 9,861↓ 2.6M/月2026年8月28日

intuitem/ciso-assistant-communityCISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 200+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
Python · Svelte★ 4,3802026年8月28日

MISP/MISPMISP (core software) - Open Source Threat Intelligence and Sharing Platform
PHP · JavaScript★ 6,4902026年8月28日
Python★ 4582026年7月20日

projectdiscovery/httpxhttpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
Go · HTML★ 10.3K2026年8月28日
theopenlane/coreOpen source compliance automation for SOC 2, GDPR, ISO27001, NIST 800-53, and more
Go★ 2802026年7月21日
Python · Cypher★ 5,348↓ 7,794/月2026年8月28日
Python · HTML · JavaScript★ 10.9K2026年8月28日

gchq/CyberChefThe Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
JavaScript★ 35.5K↓ 14.5K/月2026年8月5日
hack23/cia-compliance-managerThe CIA Compliance Manager is an application that helps organizations assess and manage the availability, integrity, and confidentiality of their systems and data based on customizable security levels, providing real-time cost estimates, business impact assessments, and technical implementation details.
TypeScript · HTML★ 20↓ 3,879/月2026年7月17日
Python · Jupyter Notebook★ 1,6532026年7月17日

node-opcua/node-opcuaUnlocking the Full Potential of OPC UA with Typescript and NodeJS - http://node-opcua.github.io/
TypeScript★ 1,657↓ 2.8M/月2026年9月5日
crates.io · Go · npm +192优秀健康指数
Rust★ 1,266↓ 154.3K/月2026年9月5日
CyberStrikeus/CyberStrikeOpen-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/月2026年7月23日

usestrix/strixOpen-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Python · Go · TypeScript★ 48.3K2026年8月5日

cynative/cynativeOpen-source framework for security agents with live, read-only access to your infrastructure. Audit AWS, GCP, Azure, Kubernetes, GitHub and GitLab as one system for privilege escalation, public exposure, leaked credentials and more, with agents you write in one markdown file.
Go · Shell★ 1972026年9月5日
NuGuardAI/nuguardopensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
Python★ 10↓ 4,954/月2026年7月18日

soxoj/maigret🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Python · HTML★ 36.1K↓ 99.4K/月2026年8月5日

beenuar/AiSOCOpen-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
Python · TypeScript★ 2,3672026年9月5日
Python★ 72026年7月31日
Python★ 88.2K↓ 111.4K/月2026年8月4日
cmu-sei/GHOSTSGHOSTS (General Human-Oriented Synthetic Teammates and Systems) is a realistic user simulation framework for cyber experimentation, simulation, training, and exercise
C# · TypeScript★ 7062026年8月4日

pensarai/apexAI-powered offensive security testing using autonomous agents, directly in your terminal.
TypeScript★ 307↓ 7,921/月2026年9月6日

praetorian-inc/brutusFast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.
Go★ 3042026年8月7日
biandratti/huginn-netMulti-protocol passive fingerprinting library: TCP/HTTP (p0f-style) + TLS (JA4-style) analysis in Rust
Rust★ 199↓ 7,674/月2026年7月26日
kaifcodec/user-scanner🕵️♂️ (2-in-1) Email & Username OSINT suite for deep data extraction. Analyzes 310+ scan vectors (120+ email / 190+ username) for security research, investigations, and digital footprinting.
Python★ 2,718↓ 19.2K/月2026年7月16日

KeygraphHQ/shannonShannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
TypeScript★ 46.4K↓ 3,414/月2026年8月5日

squid-protocol/gitgalaxyDeep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 502026年8月22日
FunnyWolf/agentic-soc-platformAgentic SOC Platform: A powerful, flexible, open-source, and agent-centric automated security operations platform (AI SOC)
Python · TypeScript★ 1,069↓ 443/月2026年8月4日
Python★ 6,698↓ 917/月2026年8月29日