Open source infosec projects

Every project in the registry tagged infosec, ranked by real GitHub adoption.

projects 8 combined stars ★ 57K refresh nightly
01 maigret ★ 38K

🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

last push7 hours ago languagePython licenseMIT
02 faraday ★ 6.7K

Open Source Vulnerability Management Platform

last push13 days ago languagePython licenseGPL-3.0
03 black-hat-rust ★ 4.4K

Applied offensive security with Rust - https://kerkour.com/black-hat-rust

last push12 months ago languageRust licenseMIT
04 pwndoc ★ 2.9K

Pentest Report Generator

last push7 days ago languageJavaScript licenseMIT
05 pentest-ai-agents ★ 2.2K

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, r

last push1 months ago languageShell licenseMIT
06 reconmap ★ 981

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance throu

last push4 days ago languageJavaScript licenseApache-2.0
07 threagile ★ 780

Agile Threat Modeling Toolkit

last push5 months ago languageGo licenseMIT
08 MasterParser ★ 760

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

last push8 months ago languagePowerShell licenseMIT

Related tags

← all tags

Frequently asked questions

How many open source infosec projects are there?

This registry tracks 8 projects tagged infosec, with 56,538 GitHub stars between them. The most-adopted is maigret at 37,735 stars.

Are these infosec projects free to use?

Yes — 8 of the 8 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which infosec project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these infosec projects still maintained?

5 of the 8 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.