Open source cybersecurity projects

Every project in the registry tagged cybersecurity, ranked by real GitHub adoption.

projects 16 combined stars ★ 225K refresh nightly
01 strix ★ 63K

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

last push6 hours ago languagePython licenseApache-2.0
02 shannon ★ 48K

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabi

last push9 days ago languageTypeScript licenseAGPL-3.0
03 maigret ★ 38K

🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

last push10 hours ago languagePython licenseMIT
04 SafeLine ★ 23K

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

last push8 days ago languageGo licenseGPL-3.0
05 SWE-agent ★ 20K

AI agents that autonomously fix code and resolve GitHub issues

last push3 days ago languagePython licenseMIT
06 codex-security ★ 11K

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-se

last push7 hours ago languageTypeScript licenseApache-2.0
07 faraday ★ 6.7K

Open Source Vulnerability Management Platform

last push13 days ago languagePython licenseGPL-3.0
08 CyberStrike ★ 2.8K

Open-source AI-powered offensive security harness for automated penetration testing.

last push10 hours ago languageTypeScript licenseAGPL-3.0
09 AiSOC ★ 2.4K

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-host

last push4 days ago languagePython licenseMIT
10 pentest-ai-agents ★ 2.2K

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, r

last push1 months ago languageShell licenseMIT
11 beelzebub ★ 2.2K

A secure low code deception runtime framework, leveraging AI for System Virtualization.

last push4 days ago languageGo licenseGPL-3.0
12 fixinventory ★ 2.1K

Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.

last push6 months ago languagePython licenseApache-2.0
13 pentest-ai ★ 1.7K

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

last push5 days ago languagePython licenseMIT
14 stride-gpt ★ 1.1K

An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE methodology.

last push3 days ago languagePython licenseMIT
15 xalgorix ★ 1.1K

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

last push2 days ago languageGo licenseApache-2.0
16 openlane ★ 306

last push7 hours ago languageGo licenseApache-2.0

Related tags

← all tags

Frequently asked questions

How many open source cybersecurity projects are there?

This registry tracks 16 projects tagged cybersecurity, with 225,463 GitHub stars between them. The most-adopted is strix at 63,281 stars.

Are these cybersecurity projects free to use?

Yes — 16 of the 16 carry an explicit open-source licence across 4 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which cybersecurity project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these cybersecurity projects still maintained?

15 of the 16 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.