SaaSHub helps you find the best software and product alternatives Learn more →
Top 23 Security Open-Source Projects
-
the-book-of-secret-knowledge
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
-
-
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
if you've never worked on SQL injection that's fine there is a PWNSOME REPOSITORY(get it? pwn + awesome) called[ Payload All The Things (https://github.com/swisskyrepo/PayloadsAllTheThings) it has different payloads for different web vulnerabilities.
-
Project mention: I got tired of setting up SSL for every side project, so I made a 60-second Docker deploy kit | dev.to | 2026-05-19
The secret is Caddy. Unlike Nginx, Caddy handles SSL automatically — it requests certificates from Let's Encrypt and renews them without any configuration. The entire reverse proxy config is 3 lines:
-
x64dbg
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
-
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
Project mention: How to audit what your IDE extension actually sends to the cloud | dev.to | 2026-05-22mitmproxy is the gold standard here. It's free, open source, and Python-scriptable.
-
quivr
Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.
-
Project mention: GSoC 2026 Predictions: 30 NEW AI/ML/Security Organizations You Should Start Contributing to NOW! | dev.to | 2026-02-06
Framework: https://github.com/rapid7/metasploit-framework ⭐ 34k+
-
Project mention: Announcing Sniffnet v1.4: introduced PCAP files import — it’s 2X faster than Wireshark! | dev.to | 2025-06-28
For those of you that still don't know it, Sniffnet is an open-source, cross-platform, Rust-based application enabling you to comfortably monitor Internet traffic (official website | GitHub repository).
-
SQLMap Project
-
trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Project mention: trivy VS onequery - a user suggested alternative | libhunt.com/r/trivy | 2026-06-01 -
Project mention: Secure Your Frontend Application (SPA) Login with OAuth 2.1 PKCE | dev.to | 2026-03-28
If your frontend application (SPA) is using Keycloak, Laravel Passport, or any OAuth-based solution—and you have not yet implemented the PKCE flow for login—you should do it as soon as possible. This is essential to make your application more secure against attackers.
-
-
CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Project mention: CSRF Protection Without Tokens or Hidden Form Fields | news.ycombinator.com | 2025-12-22Again, the maintainer eventually came around.
Our confusion might be due to the fact that an erroneous PR (by seemingly an AI-wielding student...) was somehow recently accepted that completely reverted the changes we collectively worked on, which effectively made Fetch Metadata a full solution. So, it is back to showing as defense in depth. I've raised an issue about it, which wouldn't have happened if I didn't see your article!
Here's the previous language:
> If your software targets only modern browsers, you may rely on [Fetch Metadata headers](#fetch-metadata-headers) together with the fallback options described below to block cross-site state-changing requests
We then detailed some fallbacks (eg Origin header). Full text can be viewed in the original PR
https://github.com/OWASP/CheatSheetSeries/pull/1875
or
https://github.com/OWASP/CheatSheetSeries/blob/7fc3e6b8fde65...
-
Not ideal.
This appears to be fixed as of April (at least for Apache). [0].
[0] - https://github.com/nginx/nginx/commit/365694160a85229a7cb006...
-
hosts
🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.
For those who don't use it already, the following is a great compilation of curated block lists you can put into your etc/hosts file to block traffic :)
https://github.com/StevenBlack/hosts
-
-
nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Let's look at an example of such an error in the Nuclei project, a vulnerability scanner that allows creating user-defined templates.
-
-
-
-
setup-ipsec-vpn
Set up your own IPsec VPN server in just a few minutes, with IPsec/L2TP, Cisco IPsec and IKEv2. Supports Ubuntu, Debian, CentOS/RHEL, Amazon Linux, Alpine and Raspberry Pi. Includes client config and management scripts.
Security discussion
Security related posts
-
Anthropic's open-source framework for AI-powered vulnerability discovery
-
Cargo-Auditable Support on Ubuntu
-
Preparing for KDE Plasma's Last X11-Supported Release
-
Capstone – lightweight multi-platform, multi-architecture disassembly framework
-
Gmail Thinks I'm Stupid, So I Left
-
Ask HN: How do people secure their Linux computer?
-
my one-line PowerShell installer downloaded the script twice, and the second one was the weak spot
-
A note from our sponsor - SaaSHub
www.saashub.com | 7 Jun 2026
Index
What are some of the best open-source Security projects? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | the-book-of-secret-knowledge | 220,519 |
| 2 | Awesome-Hacking | 110,323 |
| 3 | cs-video-courses | 81,704 |
| 4 | PayloadsAllTheThings | 78,176 |
| 5 | Caddy | 73,224 |
| 6 | x64dbg | 48,564 |
| 7 | mitmproxy | 43,808 |
| 8 | quivr | 39,171 |
| 9 | Metasploit | 38,332 |
| 10 | sniffnet | 37,930 |
| 11 | SQLMap | 37,563 |
| 12 | trivy | 35,597 |
| 13 | Keycloak | 34,763 |
| 14 | web-check | 33,307 |
| 15 | CheatSheetSeries | 32,169 |
| 16 | Nginx | 30,595 |
| 17 | hosts | 30,496 |
| 18 | algo | 30,256 |
| 19 | nuclei | 29,060 |
| 20 | ProxmoxVE | 28,411 |
| 21 | nginxconfig.io | 28,346 |
| 22 | authelia | 27,974 |
| 23 | setup-ipsec-vpn | 27,968 |