SaaSHub helps you find the best software and product alternatives Learn more →
Top 23 Rust Security Projects
-
Project mention: Announcing Sniffnet v1.4: introduced PCAP files import — it’s 2X faster than Wireshark! | dev.to | 2025-06-28
For those of you that still don't know it, Sniffnet is an open-source, cross-platform, Rust-based application enabling you to comfortably monitor Internet traffic (official website | GitHub repository).
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
-
Project mention: Testing Geo-Blocked Features with Docker on a Zero-Budget Setup | dev.to | 2026-02-03
To mimic different geographic locations, leverage free proxies or proxy chains. Some options include Free Proxy List or Shadowsocks, which can often be set up with minimal effort.
-
kata-containers
Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs. https://katacontainers.io/
Project mention: Kubelet Metrics: How cAdvisor and CRI Collect Kubernetes Stats | dev.to | 2026-05-20container-stats exporter to the Kata Containers
-
Project mention: Microsandbox – local-first programmable micro VMs | news.ycombinator.com | 2026-06-06
-
Project mention: Show HN: Pangolin – OSS tunneled reverse proxy (self-hosted Cloudflare Tunnels) | news.ycombinator.com | 2025-07-10
> So I am wondering if I can reduce attack surface by making "management" services (Keycloak admin console, the headless CMS admin interface etc.) accessible only to me...
The answer to this is YES. Of course there are a variety of ways to implement. In your case I would start simple with something like wireguard. Keycloak won't be easy to install and configure as a beginner. If your needs are simple, check out https://github.com/lldap/lldap for authentication (and user management).
-
Project mention: innernet: Simple, free and open-source infrastructure for WireGuard | news.ycombinator.com | 2026-02-02
-
Project mention: GitHub is investigating unauthorized access to their internal repositories | news.ycombinator.com | 2026-05-19
-
-
-
-
Ockam
Orchestrate end-to-end encryption, cryptographic identities, mutual authentication, and authorization policies between distributed applications – at massive scale.
-
aya
Aya is an eBPF library for the Rust programming language, built with a focus on developer experience and operability.
Project mention: Io_uring, kTLS and Rust for zero syscall HTTPS server | news.ycombinator.com | 2025-08-21Btw, I feel the pain with the unsafe io_uring.
[1] - https://github.com/aya-rs/aya
-
-
Project mention: Sōzune – a reverse proxy built on Sōzu, with Traefik-style autodiscovery | news.ycombinator.com | 2026-05-19
Hi HN,
Sōzune is a reverse proxy I've been building on top of Sōzu (https://github.com/sozu-proxy/sozu), the Rust proxy from Clever Cloud. Sōzu is fast and reload-without-downtime, but it's a low-level building block — you talk to it over a socket and
-
-
OpenSK
OpenSK is an open-source implementation for security keys written in Rust that supports both FIDO U2F and FIDO2 standards.
-
OxiCloud
☁️ Ultra-fast, secure & lightweight self-hosted cloud storage — your files, photos, calendars & contacts, all in one place. Built in Rust.
-
hayabusa
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
-
-
nono
Capability-based agent runtime with fine-grained policies . Brokering access directly within the agent's operating context, with zero setup and zero latency
Project mention: Anthropic, please ship an official Claude Desktop for Linux | news.ycombinator.com | 2026-06-07There are a number of utilities for this. I use jai: https://jai.scs.stanford.edu/ but also have seen nono: https://github.com/always-further/nono smolvm: https://github.com/smol-machines/smolvm zerobox https://github.com/afshinm/zerobox and matchlock https://github.com/jingkaihe/matchlock
They all have pros and cons. Pick the one that suits you best. Then you're also agent harness flexible (I use opencode).
-
Project mention: Show HN: Nano PDF – A CLI Tool to Edit PDFs with Gemini's Nano Banana | news.ycombinator.com | 2025-11-29
-
Rust Security discussion
Rust Security related posts
-
Sōzune – a reverse proxy built on Sōzu, with Traefik-style autodiscovery
-
Static Analysis for GitHub Actions
-
Static Analysis for GitHub Actions
-
How I cut my OpenAI Agent latency by replacing cloud sandboxes with a local microVM
-
Show HN: I built an open source and secure infrastructure for internal apps
-
RootCX: A Supabase alternative for internal software
-
Supply chain nightmare: How Rust will be attacked and what we can do to mitigate
-
A note from our sponsor - SaaSHub
www.saashub.com | 9 Jun 2026
Index
What are some of the best open-source Security projects in Rust? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | sniffnet | 37,930 |
| 2 | RustScan | 19,886 |
| 3 | shadowsocks-rust | 10,678 |
| 4 | kata-containers | 8,017 |
| 5 | microsandbox | 6,426 |
| 6 | lldap | 6,275 |
| 7 | innernet | 5,490 |
| 8 | zizmor | 5,482 |
| 9 | libreddit | 5,192 |
| 10 | dalfox | 5,045 |
| 11 | kanidm | 5,028 |
| 12 | Ockam | 4,625 |
| 13 | aya | 4,583 |
| 14 | black-hat-rust | 4,341 |
| 15 | sozu | 3,679 |
| 16 | chainsaw | 3,560 |
| 17 | OpenSK | 3,354 |
| 18 | OxiCloud | 3,200 |
| 19 | hayabusa | 3,189 |
| 20 | defguard | 2,738 |
| 21 | nono | 2,566 |
| 22 | oryx | 2,483 |
| 23 | sn0int | 2,431 |