Other PDF SDKs promise a lot - then break. Laggy scrolling, poor mobile UX, tons of bugs, and lack of support cost you endless frustrations. Nutrient’s SDK handles billion-page workloads - so you don’t have to debug PDFs. Used by ~1 billion end users in more than 150 different countries. Learn more →
Top 23 Python Security Projects
-
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Project mention: PayloadsAllTheThings: Essential Payloads and Bypass for Web Security and CTFs | news.ycombinator.com | 2024-08-11 -
Nutrient
Nutrient – The #1 PDF SDK Library, trusted by 10K+ developers. Other PDF SDKs promise a lot - then break. Laggy scrolling, poor mobile UX, tons of bugs, and lack of support cost you endless frustrations. Nutrient’s SDK handles billion-page workloads - so you don’t have to debug PDFs. Used by ~1 billion end users in more than 150 different countries.
-
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
Enter mitmproxy - this beautiful Python program can act as a proxy and logs all network requests. It even comes with a devtool like web UI. Just what I needed.
-
quivr
Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.
-
SQL MAP, learning SQL
-
CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Just for fun, I cloned the OWASP repo https://github.com/OWASP/CheatSheetSeries.git and am waiting for the indexing process to finish. I then asked the model (on the left side) and included all files from the cloned project (on the right side). As you can see below, the right side contains more useful information
-
hosts
🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.
Project mention: Show HN: A blocklist to remove spam and bad websites from search results | news.ycombinator.com | 2025-01-14You could get a step closer to that and integrate it into your DNS: https://github.com/StevenBlack/hosts
The upside is that it would go beyond your browser to anything on your machine that makes a DNS request.
> Another great function (not for this plugin) should be the option to "bundle" all search results from the same domain. Stuff them under one collapsible entry.
That would be really cool. Just zip it up if you don't want to see that domain for that specific search.
-
-
CodeRabbit
CodeRabbit: AI Code Reviews for Developers. Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.
-
DB-GPT
AI Native Data App Development framework with AWEL(Agentic Workflow Expression Language) and Agents
-
-
Project mention: One-Click Setup for SSH Login, Password Policy, IP Ban Configuration, and Custom Admin User Creation | dev.to | 2025-02-06
IP Ban: Fail2ban
-
-
-
You don't need a license to explore and have fun.
Cheap, firmware hackable HTs are hawt, in particular the Quansheng UV-K5,K6.
Tons of SDR receivers out there to explore, and many extremely exiting transceiver projects out there also. Just so much:
https://github.com/jopohl/urh
http://websdr.org/
http://kiwisdr.com/public/
https://meshtastic.org/docs/hardware/devices/
-
There is OpenSnitch [0] on Linux, but it us a bit clumsy to setup. I tried it once and didn't get far, but have it again on my todo list. Not aware of something similar on Linux.
On Android there is NetGuard [1] which is awesome (not affiliated, just a happy customer).
[0] https://github.com/evilsocket/opensnitch
[1] https://netguard.me/
-
prowler
Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.
11. Prowler
-
-
mvt
MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.
-
-
-
-
📂 GitHub Repository 🌐 Website
-
Objection is a runtime mobile exploration toolkit, powered by Frida. I wrote a blog post that explains what Frida is and how it can be setup on Android. You can find it from here.
-
Project mention: Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF) | news.ycombinator.com | 2024-12-06
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
Python Security discussion
Python Security related posts
-
BleachBit is a free and open-source disk space cleaner
-
10 Must-Have AI Tools to Supercharge Your Software Development
-
Invariant: A security and bug scanner for agent traces
-
I turned GitHub Copilot into OpenAI API compatible provider
-
Sniffnet – monitor your Internet traffic
-
When Postgres index meets Bcrypt
-
How I automated my fitness goals
-
A note from our sponsor - Nutrient
www.nutrient.io | 16 Feb 2025
Index
What are some of the best open-source Security projects in Python? This list will help you:
# | Project | Stars |
---|---|---|
1 | PayloadsAllTheThings | 63,195 |
2 | mitmproxy | 37,871 |
3 | quivr | 37,264 |
4 | SQLMap | 33,296 |
5 | CheatSheetSeries | 28,810 |
6 | hosts | 27,461 |
7 | macOS-Security-and-Privacy-Guide | 21,497 |
8 | DB-GPT | 14,553 |
9 | wifiphisher | 13,375 |
10 | Fail2Ban | 13,179 |
11 | dirsearch | 12,528 |
12 | routersploit | 12,345 |
13 | urh | 11,253 |
14 | opensnitch | 11,248 |
15 | prowler | 11,220 |
16 | scapy | 11,061 |
17 | mvt | 10,711 |
18 | Mailpile | 8,821 |
19 | sigma | 8,693 |
20 | trape | 8,203 |
21 | frappe | 7,939 |
22 | objection | 7,805 |
23 | BunkerWeb | 7,543 |