Back to Topics Directory
Topic Hub

#security-tools (30 Repositories)

Ranked open-source repositories tagged with #security-tools, scored by pull request acceptance likelihood and maintainer engagement velocity.

Topic Avg Merge Rate

86.5%

Avg Review Latency

56.6h

Filter by language

30 repositories tagged #security-tools

S TierRust 458 1 GFIs

Karib0u/rustinel

Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

95.7%
Merge Rate
11h
First Review
100%
1st-Timers
3
Maintainers
S TierJavaScript 827 12 GFIs

asamassekou10/ship-safe

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.

92.5%
Merge Rate
12h
First Review
80%
1st-Timers
9
Maintainers
S TierTypeScript 286 1 GFIs

NodeSecure/js-x-ray

JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

93.5%
Merge Rate
14h
First Review
83%
1st-Timers
3
Maintainers
S TierShell 4.9k

Security-Onion-Solutions/securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

94.4%
Merge Rate
4d
First Review
100%
1st-Timers
6
Maintainers
S TierJavaScript 145 8 GFIs

antropos17/Aegis

OS-level monitor for AI agents: observes processes, file access, and network activity on the local machine and attributes each event to an agent instance.

84.7%
Merge Rate
2d
First Review
100%
1st-Timers
2
Maintainers
S TierPython 249

Keeper-Security/Commander

Keeper Commander is a python-based CLI and SDK interface to the Keeper Security platform. Provides administrative controls, reporting, import/export and vault management.

87.1%
Merge Rate
5h
First Review
82%
1st-Timers
3
Maintainers
A TierGo 319

Asymptote-Labs/agent-beacon

Agent Beacon is the world's first open-source telemetry layer for AI agents wherever they run: locally, in CI, in the browser, or in the cloud.

90.3%
Merge Rate
7d
First Review
100%
1st-Timers
4
Maintainers
A TierGo 2.9k 1 GFIs

google/osv.dev

Open source vulnerability DB and triage service.

87.6%
Merge Rate
1d
First Review
68%
1st-Timers
24
Maintainers
B TierRust 208

biandratti/huginn-net

Multi-protocol passive fingerprinting library: TCP/HTTP (p0f-style) + TLS (JA4-style) analysis in Rust

95.0%
Merge Rate
2d
First Review
100%
1st-Timers
1
Maintainers
A TierPython 294

SecObserve/SecObserve

SecObserve is an open source vulnerability and license management system for software development teams and cloud environments. It supports a variety of open source vulnerability scanners and integrates easily into CI/CD pipelines.

96.1%
Merge Rate
6d
First Review
100%
1st-Timers
3
Maintainers
A TierGo 632

yaklang/yaklang

A programming language exclusively designed for cybersecurity

90.0%
Merge Rate
3d
First Review
77%
1st-Timers
7
Maintainers
A TierRust 6.4k 1 GFIs

zizmorcore/zizmor

Static analysis for GitHub Actions

84.3%
Merge Rate
3d
First Review
63%
1st-Timers
23
Maintainers
B TierPHP 546

sourcentis/mercator

Mapping the information system / Cartographie du système d'information

99.2%
Merge Rate
7d
First Review
100%
1st-Timers
0
Maintainers
A TierKotlin 146

seqra/opentaint

The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.

88.0%
Merge Rate
5d
First Review
71%
1st-Timers
5
Maintainers
B TierTypeScript 106

yowainwright/pastoralist

A CLI for automatically shepherding package.json overrides 👩🏽‍🌾

97.9%
Merge Rate
3d
First Review
100%
1st-Timers
0
Maintainers
B TierGo 328

duggytuxy/syswarden

Active Defense and HIDS/HIPS/WAAP Out-of-Band Orchestration for Critical Linux Infrastructure

90.6%
Merge Rate
2d
First Review
50%
1st-Timers
0
Maintainers
B TierRust 428

kpcyrd/rebuilderd

Independent verification of binary packages - Reproducible Builds

83.3%
Merge Rate
<1h
First Review
100%
1st-Timers
1
Maintainers
A TierShell 3.6k 12 GFIs

e-m-b-a/emba

EMBA - The firmware security analyzer

89.8%
Merge Rate
2d
First Review
67%
1st-Timers
5
Maintainers
A TierPython 14.7k 26 GFIs

prowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

79.6%
Merge Rate
3d
First Review
54%
1st-Timers
34
Maintainers
B TierGo 524

edoardottt/csprecon

Discover new target domains using Content Security Policy

81.8%
Merge Rate
1d
First Review
100%
1st-Timers
1
Maintainers
A TierGo 6.3k

google/syzkaller

syzkaller is an unsupervised coverage-guided kernel fuzzer

85.0%
Merge Rate
4d
First Review
70%
1st-Timers
18
Maintainers
B TierJavaScript 835

spr-networks/super

One wifi password per device. Ad Blocking & Privacy Blocklists. Policy Based Network Access

84.1%
Merge Rate
4d
First Review
100%
1st-Timers
0
Maintainers
A TierGo 126

praetorian-inc/vespasian

API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs

82.1%
Merge Rate
2d
First Review
70%
1st-Timers
6
Maintainers
A TierJavaScript 5.7k

dotenvx/dotenvx

a secure dotenv–from the creator of `dotenv`

91.4%
Merge Rate
3d
First Review
50%
1st-Timers
2
Maintainers
A TierPython 1.2k

CERT-Polska/Artemis

A modular vulnerability scanner with automatic report generation capabilities.

79.9%
Merge Rate
2d
First Review
56%
1st-Timers
7
Maintainers
B TierGo 934

Chocapikk/wpprobe

A fast WordPress plugin enumeration tool

85.7%
Merge Rate
11h
First Review
100%
1st-Timers
1
Maintainers
B TierGo 7.0k

authzed/spicedb

Open Source, Google Zanzibar-inspired database for scalably storing and querying fine-grained authorization data

76.2%
Merge Rate
3d
First Review
53%
1st-Timers
16
Maintainers
B TierZig 338

The-Z-Labs/bof-launcher

[ BOF-LAUNCHER ] -> an API for loading, executing and in-memory masking BOFs on Windows and Linux for use in C/Zig/Go/Rust agents/implants. [ Z-BEAC0N ] -> a custom-written stage-1 (aka pre-C2) solution engineered with a small footprint, stealth and modularity in mind. [ DEVELOPED BOFS ] -> cross-platform (12), Linux-only (10), Win-only (2)

100.0%
Merge Rate
22h
First Review
100%
1st-Timers
1
Maintainers
B TierC++ 49.4k

x64dbg/x64dbg

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

68.6%
Merge Rate
21h
First Review
77%
1st-Timers
22
Maintainers
B TierGo 10.9k 2 GFIs

google/osv-scanner

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

40.0%
Merge Rate
<1h
First Review
33%
1st-Timers
28
Maintainers
Best Security-tools Open Source Repositories & C-Rank™ | GetMerged