A curated, auto-updating collection of security, AI, and development tools. Updated weekly.
803 tools across 6 categories • Last updated: 2026-03-29
🌐 Browse online: blacktemple.net/vault
- 🗡️ Offensive Security
- 🛡️ Defensive Security
- 🔧 DevSecOps
- 🤖 AI & Agents
- 💻 Development
- 📚 Research & Learning
| Tool | Stars | Language | Description |
|---|---|---|---|
| metasploit-framework | ⭐ 37.8k | Ruby | The legendary Metasploit penetration testing and exploitation framework |
| awesome-pentest | ⭐ 25.6k | — | Comprehensive penetration testing tools and resources collection |
| beef | ⭐ 10.8k | JavaScript | Browser exploitation framework for testing web application security vulnerabilities |
| PoC-in-GitHub | ⭐ 7.6k | — | Automated collection of proof-of-concept exploits and CVE research from GitHub |
| RsaCtfTool | ⭐ 6.8k | Python | RSA attack tool for CTF challenges and cryptographic exploitation |
| linux-exploit-suggester | ⭐ 6.4k | Shell | Linux privilege escalation auditing tool that suggests applicable kernel exploits |
| reverse-shell-generator | ⭐ 3.9k | JavaScript | Web-based reverse shell generator with multiple payload types for pentesting and CTFs |
| SSRFmap | ⭐ 3.5k | Python | Automatic SSRF fuzzer and exploitation tool for pentesting |
| pypykatz | ⭐ 3.3k | Python | Pure Python implementation of Mimikatz for credential extraction |
| SUDO_KILLER | ⭐ 2.4k | Shell | Sudo privilege escalation exploitation tool for pentesting |
| one_gadget | ⭐ 2.3k | Ruby | Tool for finding one gadget RCE exploits in libc libraries |
| metasploit-payloads | ⭐ 2.0k | C | Unified repository for Metasploit Framework payloads and exploits |
| bypass-mdm | ⭐ 1.4k | Shell | Tool for bypassing macOS Mobile Device Management (MDM) setup restrictions |
| jok3r | ⭐ 1.1k | HTML | Network and web pentest automation framework with vulnerability exploitation |
| Aggressor | ⭐ 1.1k | — | Cobalt Strike extension with large network penetration scanning capabilities |
| pyhtools | ⭐ 624 | Python | Comprehensive Python hacking library with network and malware tools |
| Tool | Stars | Language | Description |
|---|---|---|---|
| hackrf | ⭐ 7.8k | C | Software-defined radio platform for RF security research and wireless testing |
| aircrack-ng | ⭐ 7.1k | C | Complete WiFi security auditing suite for wireless network penetration testing |
| Responder | ⭐ 6.4k | Python | LLMNR/NBT-NS poisoner with rogue authentication server for credential harvesting |
| mayhem-firmware | ⭐ 5.0k | C | Portable SDR firmware for HackRF enabling mobile RF testing and analysis |
| IMSI-catcher | ⭐ 3.9k | Python | Tool for capturing IMSI numbers from nearby cellular devices using SDR hardware |
| pwnagotchi | ⭐ 2.6k | Python | Raspberry Pi WiFi penetration testing device using Bettercap |
| hping | ⭐ 1.7k | C | Network tool for packet crafting, firewall testing, and port scanning |
| BTLE | ⭐ 876 | Jupyter Notebook | BLE packet sniffer/transmitter for wireless security testing and protocol analysis |
| gattacker | ⭐ 815 | JavaScript | Bluetooth Low Energy security testing tool with MITM attack capabilities |
| pentmenu | ⭐ 528 | Shell | Bash script for network reconnaissance and DoS attacks |
| Tool | Stars | Language | Description |
|---|---|---|---|
| hashcat | ⭐ 25.6k | C | World's fastest GPU-accelerated password recovery utility |
| john | ⭐ 12.9k | C | Advanced offline password cracker supporting hundreds of hash types |
| thc-hydra | ⭐ 11.8k | C | Fast network password cracker supporting many protocols and services |
| cupp | ⭐ 5.8k | Python | Generates custom wordlists based on user profiling for password attacks |
| Auto_Wordlists | ⭐ 1.3k | Python | Automated wordlist generation tool for security testing and brute force |
| TREVORspray | ⭐ 1.3k | Python | Modular password spraying tool with threading and proxy support for Office 365 |
| pandora | ⭐ 790 | C++ | Red team tool for extracting and dumping credentials from password managers |
| Tool | Stars | Language | Description |
|---|---|---|---|
| sherlock | ⭐ 74.2k | Python | Social media account hunting by username across multiple platforms |
| CyberChef | ⭐ 34.4k | JavaScript | Swiss Army knife for data analysis, encryption, encoding - essential security tool |
| web-check | ⭐ 32.5k | TypeScript | All-in-one website analysis tool for OSINT investigations and reconnaissance |
| PEASS-ng | ⭐ 19.5k | C# | Privilege escalation enumeration scripts suite for Linux and Windows with colors |
| RustScan | ⭐ 19.5k | Rust | High-speed Rust port scanner with modern features and Docker support |
| maigret | ⭐ 19.2k | Python | Username enumeration across thousands of sites for OSINT investigations |
| GHunt | ⭐ 18.6k | Python | Offensive Google OSINT framework for gathering intelligence from Google services |
| katana | ⭐ 16.2k | Go | Next-gen web crawling and spidering framework for reconnaissance and asset discovery |
| amass | ⭐ 14.3k | Go | Comprehensive attack surface mapping and asset discovery platform by OWASP |
| gobuster | ⭐ 13.6k | Go | Fast directory/file, DNS and VHost enumeration tool for discovering hidden resources |
| subfinder | ⭐ 13.3k | Go | Fast passive subdomain enumeration for reconnaissance and bug bounties |
| nmap | ⭐ 12.6k | C | Essential network discovery and port scanning tool for reconnaissance activities |
| Osintgram | ⭐ 12.5k | Python | Instagram OSINT tool with interactive shell for account analysis |
| awesome-hacker-search-engines | ⭐ 10.3k | Shell | Search engines for penetration testing and OSINT operations |
| httpx | ⭐ 9.7k | Go | Multi-purpose HTTP toolkit for probing and SSL certificate analysis |
| Sn1per | ⭐ 9.6k | Shell | Comprehensive attack surface management platform with OSINT and pentesting tools |
| bbot | ⭐ 9.5k | Python | Recursive internet scanner for attack surface management and reconnaissance |
| GhostTrack | ⭐ 8.2k | Python | Mobile number and location tracking tool for OSINT gathering |
| osint_stuff_tool_collection | ⭐ 7.7k | HTML | Curated collection of hundreds of online OSINT tools |
| reconftw | ⭐ 7.4k | Shell | Automated reconnaissance tool that runs multiple security scanners on target domains |
| awesome-shodan-queries | ⭐ 7.3k | — | Collection of Shodan search queries for discovering exposed systems and services |
| osmedeus | ⭐ 6.2k | Go | Modern orchestration engine combining AI workflows for security testing |
| blackbird | ⭐ 5.9k | Python | Social media account discovery by username and email |
| naabu | ⭐ 5.8k | Go | Fast Go-based port scanner for attack surface discovery in pentests |
| mosint | ⭐ 5.8k | Go | Automated email OSINT tool with data breach hunting capabilities |
| dnstwist | ⭐ 5.6k | Python | Domain permutation engine for detecting phishing and brand impersonation |
| can-i-take-over-xyz | ⭐ 5.6k | Python | Comprehensive list of services vulnerable to subdomain takeover attacks |
| hakrawler | ⭐ 5.0k | Go | Fast web crawler for discovering endpoints and assets in web applications |
| h8mail | ⭐ 4.9k | Python | Email breach hunting with premium service integration support |
| robin | ⭐ 4.6k | Python | AI-powered dark web investigation and OSINT tool |
| LinkFinder | ⭐ 4.3k | Python | JavaScript endpoint discovery tool for web application reconnaissance |
| ivre | ⭐ 4.0k | Python | Self-hosted network recon framework - alternative to Shodan/ZoomEye with Nmap/Masscan |
| TorBot | ⭐ 3.9k | Python | Dark web crawler and OSINT tool for Tor network investigation |
| linux-smart-enumeration | ⭐ 3.9k | Shell | Linux enumeration tool for pentesting and CTF privilege escalation |
| toutatis | ⭐ 3.8k | Python | Instagram account information extraction tool for OSINT |
| PrivescCheck | ⭐ 3.8k | PowerShell | PowerShell privilege escalation enumeration script specifically for Windows systems |
| Findomain | ⭐ 3.7k | Rust | Fast subdomain discovery with port scanning and monitoring features |
| sdrangel | ⭐ 3.7k | C++ | Feature-rich SDR software for RF reception and transmission across multiple platforms |
| gqrx | ⭐ 3.6k | C++ | GUI SDR receiver for RF signal analysis and monitoring |
| assetfinder | ⭐ 3.5k | Go | Simple tool for finding domains and subdomains related to a target domain |
| OSINT | ⭐ 3.4k | Python | Collection of OSINT tools and methodologies for intelligence gathering |
| cariddi | ⭐ 3.3k | Go | Domain crawler for endpoint discovery, secrets, and API key detection |
| Mr.Holmes | ⭐ 3.1k | Python | Comprehensive OSINT framework with multiple information gathering modules |
| httprobe | ⭐ 3.1k | Go | Probe domains for working HTTP/HTTPS servers during reconnaissance |
| uncover | ⭐ 2.8k | Go | Multi-engine search tool for discovering exposed hosts across the internet |
| Snaffler | ⭐ 2.8k | C# | File discovery tool for penetration testers to find sensitive data and credentials |
| dnsx | ⭐ 2.7k | Go | Fast DNS toolkit for enumeration and resolution with wildcard filtering |
| email2phonenumber | ⭐ 2.6k | Python | Phone number discovery through email address OSINT techniques |
| waymore | ⭐ 2.6k | Python | Enhanced web archive data collection from Wayback Machine and other sources |
| pwnedOrNot | ⭐ 2.5k | Python | Email breach checking using HaveIBeenPwned API integration |
| cloudfox | ⭐ 2.3k | Go | Automated situational awareness tool for cloud penetration testing |
| Awesome-OSINT-For-Everything | ⭐ 2.3k | Shell | Curated collection of OSINT tools for information gathering and recon |
| dnsReaper | ⭐ 2.2k | Python | Subdomain takeover tool for attackers, bug bounty hunters, and blue teams |
| smbmap | ⭐ 2.0k | Python | SMB enumeration tool for network reconnaissance and share discovery |
| octosuite | ⭐ 1.9k | Python | Terminal toolkit for analyzing GitHub data and conducting OSINT investigations |
| OSINT-Cheat-sheet | ⭐ 1.8k | HTML | OSINT cheat sheet with tools, datasets, and resources for red team operations |
| gitjacker | ⭐ 1.6k | Go | Extracts git repositories from misconfigured websites to find exposed source code |
| hakrevdns | ⭐ 1.6k | Go | Fast tool for performing bulk reverse DNS lookups during reconnaissance |
| enum4linux-ng | ⭐ 1.6k | Python | Next-gen Windows/Samba enumeration tool for CTF and pentesting |
| xnLinkFinder | ⭐ 1.5k | Python | Discovers endpoints, parameters, and secrets from web applications for recon |
| SharpHound | ⭐ 1.2k | C# | C# data collector for BloodHound Active Directory attack path analysis |
| qscan | ⭐ 1.2k | Go | Lightning-fast internal network scanner for reconnaissance activities |
| goscan | ⭐ 1.0k | Go | Interactive network scanner built with Go for pentesting activities |
| hakoriginfinder | ⭐ 987 | Go | Discovers origin hosts behind reverse proxies to bypass cloud WAFs |
| skanuvaty | ⭐ 923 | Rust | High-performance DNS/network/port scanner with subdomain enumeration capabilities |
| goscan | ⭐ 798 | Go | Efficient IPv4 network scanner for discovering active devices on LANs |
| tlosint-live | ⭐ 794 | HTML | OSINT-focused Linux distribution based on Kali for open source intelligence gathering |
| rtl-sdr-scanner-cpp | ⭐ 762 | C++ | SDR scanner for RF reconnaissance and signal analysis |
| dnsvalidator | ⭐ 730 | Python | Maintains and validates list of reliable IPv4 DNS servers for reconnaissance |
| evilscan | ⭐ 545 | JavaScript | Simple NodeJS network scanner for port scanning and reconnaissance |
| CloudScraper | ⭐ 534 | Python | Cloud storage enumeration tool for S3 buckets, Azure blobs, and DigitalOcean |
| toolkit | ⭐ 502 | JavaScript | OSINT toolkit from Bellingcat for open source intelligence investigations |
| MMLanScan | ⭐ 496 | Objective-C | iOS library for LAN network scanning and device discovery |
| xmap | ⭐ 479 | C | Fast IPv4/IPv6 network scanner for Internet-wide research scanning |
| webscan | ⭐ 471 | JavaScript | Browser-based network scanner with local IP detection capabilities |
| PowerShell_IPv4NetworkScanner | ⭐ 431 | PowerShell | Asynchronous IPv4 network scanner written in PowerShell |
| back-me-up | ⭐ 229 | Shell | Scans wayback data for sensitive data leaks using regex patterns |
| SIGpi | ⭐ 228 | Shell | SIGINT toolkit for radio frequency analysis and amateur radio operations |
| Tool | Stars | Language | Description |
|---|---|---|---|
| sliver | ⭐ 10.9k | Go | Modern C2 framework for adversary emulation and red team operations |
| Red-Teaming-Toolkit | ⭐ 10.2k | — | Curated collection of open-source security tools for red teamers |
| RedTeam-Tools | ⭐ 8.6k | — | Comprehensive collection of red team and penetration testing tools and techniques |
| caldera | ⭐ 6.8k | Python | MITRE's automated adversary emulation platform for red team operations |
| Empire | ⭐ 5.1k | PowerShell | Post-exploitation PowerShell framework for red team and penetration testing |
| Mythic | ⭐ 4.4k | JavaScript | Multi-platform collaborative red teaming framework for advanced operations |
| Stowaway | ⭐ 3.3k | Go | Multi-hop proxy tool for red team operations and pentesting |
| Penetration-Testing-Tools | ⭐ 2.9k | PowerShell | Comprehensive penetration testing tools collection with 170+ security tools |
| RedELK | ⭐ 2.6k | Python | Red Team SIEM for tracking Blue Team activities and improving long-term operations |
| USBArmyKnife | ⭐ 2.4k | C++ | USB-based close access penetration testing tool for red teamers |
| RedTeam-OffensiveSecurity | ⭐ 2.3k | Python | Collection of tools and resources for red team operations and offensive security |
| The-Hackers-Hardware-Toolkit | ⭐ 2.2k | — | Hardware toolkit compilation for red team pentesters and security researchers |
| Bashfuscator | ⭐ 1.9k | Python | Configurable Bash obfuscation framework for red/blue team evasion testing |
| Stormspotter | ⭐ 1.7k | Python | Azure red team tool for graphing Azure and Azure Active Directory objects |
| Starkiller | ⭐ 1.6k | Vue | Web-based GUI frontend for managing PowerShell Empire C2 operations |
| RedGuard | ⭐ 1.6k | Go | C2 front flow control tool to avoid Blue Teams, AVs, and EDRs detection |
| RedTeamTools | ⭐ 1.5k | Python | Collection of red team tools including AV bypass and privilege escalation |
| redsnarf | ⭐ 1.2k | PowerShell | Windows-focused pen-testing and red-teaming tool with Active Directory features |
| red-team-scripts | ⭐ 1.1k | PowerShell | Collection of red team focused tools, scripts, and notes for operations |
| Shr3dKit | ⭐ 1.1k | Shell | Red team toolkit with various offensive security capabilities |
| Beginners-Guide-to-Obfuscation | ⭐ 1.1k | PowerShell | Educational guide on obfuscation techniques for security professionals |
| ProtectMyTooling | ⭐ 1.1k | PowerShell | Multi-packer wrapper for red team implant obfuscation and evasion |
| DumpsterFire | ⭐ 1.0k | Python | Modular tool for building customized security events and red team scenarios |
| awesome-command-control | ⭐ 957 | — | Curated collection of command & control frameworks for post-exploitation |
| OffensivePipeline | ⭐ 818 | C# | Automated C# tool building and modification pipeline for red team evasion |
| GhostStrike | ⭐ 810 | C++ | Stealthy reverse shell deployment using advanced process hollowing techniques |
| Forensia | ⭐ 783 | C++ | Anti-forensics tool for red teamers to erase footprints post-exploitation |
| Tool | Stars | Language | Description |
|---|---|---|---|
| ghidra | ⭐ 66.0k | Java | NSA's powerful software reverse engineering framework and disassembler |
| ImHex | ⭐ 52.9k | C++ | Feature-rich hex editor with pattern analysis for reverse engineering |
| awesome-flipperzero | ⭐ 23.1k | — | Flipper Zero resources for hardware hacking and RF analysis |
| Flipper | ⭐ 16.8k | C | Custom modifications and tools for Flipper Zero hardware hacking device |
| flipperzero-firmware | ⭐ 15.7k | C | Flipper Zero firmware for multi-tool hardware hacking and RF analysis |
| mitmproxy2swagger | ⭐ 9.3k | HTML | Automatically generates API docs from captured HTTP traffic using mitmproxy |
| FISSURE | ⭐ 1.9k | Python | Comprehensive RF and reverse engineering framework for wireless protocol analysis |
| flipper-application-catalog | ⭐ 1.0k | Python | Application catalog for Flipper Zero security research and penetration testing |
| Flipper-iOS-App | ⭐ 905 | Swift | iOS app for managing Flipper Zero hardware security testing device |
| samytools | ⭐ 614 | Perl | Simple tools for reverse engineering and data manipulation on *nix systems |
| Tool | Stars | Language | Description |
|---|---|---|---|
| social-engineer-toolkit | ⭐ 14.7k | Python | Comprehensive social engineering toolkit for security testing and red team operations |
| trape | ⭐ 8.6k | Python | Internet people tracker combining OSINT analysis with social engineering |
| Tool | Stars | Language | Description |
|---|---|---|---|
| trivy | ⭐ 33.5k | Go | Comprehensive vulnerability scanner for containers, Kubernetes, code, and clouds |
| nuclei | ⭐ 27.6k | Go | Fast YAML-based vulnerability scanner for apps, APIs, networks, and cloud |
| nuclei-templates | ⭐ 12.1k | JavaScript | Community-curated vulnerability templates for Nuclei scanner |
| vuls | ⭐ 12.1k | Go | Agent-less vulnerability scanner for Linux, containers, and network devices |
| nikto | ⭐ 10.2k | Perl | Classic web server scanner for identifying vulnerabilities and misconfigurations |
| AFLplusplus | ⭐ 6.4k | C | Advanced fuzzing framework with enhanced coverage and mutation techniques |
| syzkaller | ⭐ 6.1k | Go | Kernel fuzzer for discovering security vulnerabilities in system calls |
| scan4all | ⭐ 6.0k | Go | All-in-one security scanner with extensive vulnerability detection |
| kube-hunter | ⭐ 5.0k | Python | Kubernetes cluster security weakness scanner and penetration testing tool |
| afrog | ⭐ 4.2k | Go | Bug bounty and red teaming vulnerability scanner with PoC capabilities |
| sslyze | ⭐ 3.7k | Python | Fast SSL/TLS scanning library for security assessments and vulnerability testing |
| Raccoon | ⭐ 3.5k | Python | High-performance reconnaissance and vulnerability scanning platform |
| honggfuzz | ⭐ 3.3k | C | Coverage-guided fuzzer for security testing with hardware and software support |
| echidna | ⭐ 3.1k | Haskell | Smart contract fuzzer for finding vulnerabilities in Ethereum/Solidity code |
| Artemis | ⭐ 1.1k | Python | Modular vulnerability scanner with automatic report generation capabilities |
| Silver | ⭐ 1.0k | Python | Mass IP scanner for identifying vulnerable services across networks |
| Tool | Stars | Language | Description |
|---|---|---|---|
| PayloadsAllTheThings | ⭐ 76.3k | Python | Curated payload collection for web app security testing and CTF challenges |
| SecLists | ⭐ 69.6k | PHP | Comprehensive collection of security testing wordlists and payloads for pentesting |
| sqlmap | ⭐ 36.9k | Python | Automated SQL injection detection and database takeover tool |
| ffuf | ⭐ 15.8k | Go | High-performance web application fuzzing tool written in Go |
| zaproxy | ⭐ 14.9k | Java | OWASP ZAP core project - comprehensive web application security scanner |
| dirsearch | ⭐ 14.1k | Python | Directory and path enumeration tool for web application testing |
| FlareSolverr | ⭐ 13.2k | Python | Proxy server to bypass Cloudflare protection for testing purposes |
| fuzzDicts | ⭐ 8.3k | Python | Comprehensive collection of fuzzing dictionaries and wordlists |
| feroxbuster | ⭐ 7.6k | Rust | Fast Rust-based recursive web content discovery and URL bruteforcer |
| WhatWeb | ⭐ 6.5k | Ruby | Web application fingerprinting scanner for identifying technologies and versions |
| wfuzz | ⭐ 6.5k | Python | Versatile web application fuzzing and testing framework |
| Arjun | ⭐ 6.2k | Python | HTTP parameter discovery suite for API fuzzing and web application testing |
| awesome-bugbounty-tools | ⭐ 5.9k | — | Bug bounty tools collection for web security testing |
| commix | ⭐ 5.7k | Python | Automated OS command injection detection and exploitation tool |
| dalfox | ⭐ 4.9k | Go | Powerful automated XSS scanner with CI/CD integration for security testing |
| interactsh | ⭐ 4.2k | Go | Out-of-band interaction server for detecting blind vulnerabilities |
| IntruderPayloads | ⭐ 3.9k | BlitzBasic | Collection of Burp Suite payloads and web penetration testing resources |
| awesome-api-security | ⭐ 3.7k | — | Curated collection of API security tools and resources for testing and hardening |
| Packer-Fuzzer | ⭐ 3.2k | Python | Specialized fuzzer for detecting security issues in webpack-bundled JavaScript apps |
| schemathesis | ⭐ 3.2k | Python | Property-based API testing tool for OpenAPI/GraphQL with fuzzing capabilities |
| OneListForAll | ⭐ 3.1k | Go | Comprehensive wordlist collection optimized for web application fuzzing |
| php-reverse-shell | ⭐ 2.7k | PHP | PHP reverse shell script for web application penetration testing |
| snallygaster | ⭐ 2.1k | Python | Scanner for discovering secret files and sensitive information on web servers |
| smuggler | ⭐ 2.1k | Python | HTTP request smuggling and desync testing tool for finding protocol vulnerabilities |
| owtf | ⭐ 1.9k | TypeScript | Offensive Web Testing Framework for efficient penetration testing workflows |
| wordlists | ⭐ 1.7k | CSS | Curated wordlists for content discovery and web application penetration testing |
| nomore403 | ⭐ 1.6k | Go | Advanced HTTP 403 bypass tool for security researchers |
| GAP-Burp-Extension | ⭐ 1.5k | Python | Burp extension for finding potential endpoints and generating custom wordlists |
| zap-extensions | ⭐ 922 | HTML | ZAP add-ons collection for the popular web application security scanner |
| skipfish | ⭐ 848 | C | Web application security scanner by lcamtuf for finding vulnerabilities |
| hakcheckurl | ⭐ 403 | Go | Go tool that takes URLs and returns HTTP response codes for web enumeration |
| Tool | Stars | Language | Description |
|---|---|---|---|
| macOS-Security-and-Privacy-Guide | ⭐ 22.5k | — | Comprehensive macOS security hardening and privacy configuration guide |
| Atlas | ⭐ 20.0k | Batchfile | Windows hardening and privacy modification toolkit for secure configurations |
| Big-Ass-Data-Broker-Opt-Out-List | ⭐ 6.3k | — | Comprehensive list for opting out of data broker services to protect privacy |
| awesome-security-hardening | ⭐ 6.2k | — | Curated collection of security hardening guides and best practices |
| ansible-collection-hardening | ⭐ 5.3k | Jinja | Ansible collection for hardening Linux, SSH, nginx, and MySQL systems |
| Harden-Windows-Security | ⭐ 4.2k | C# | Comprehensive Windows security hardening toolkit with official Microsoft methods |
| securedrop | ⭐ 3.8k | Python | Secure whistleblower platform for anonymous document submission |
| AttackSurfaceAnalyzer | ⭐ 2.9k | C# | Microsoft tool for analyzing OS security configuration changes during software installs |
| hardening | ⭐ 1.7k | Shell | Ubuntu hardening scripts with systemd integration for security compliance |
| UBUNTU22-CIS | ⭐ 248 | YAML | Automated CIS benchmark compliance remediation for Ubuntu 22 using Ansible |
| Tool | Stars | Language | Description |
|---|---|---|---|
| authelia | ⭐ 27.3k | Go | Multi-factor SSO portal with OpenID certification and passkey support |
| ungoogled-chromium | ⭐ 26.1k | Python | Privacy-focused Chromium browser with Google integrations and tracking removed |
| ente | ⭐ 25.3k | Dart | End-to-end encrypted cloud storage with zero-knowledge privacy protection |
| authentik | ⭐ 20.6k | Python | Identity provider with SAML, OAuth2, and OIDC support for authentication |
| teleport | ⭐ 20.1k | Go | Zero-trust access platform for infrastructure with certificate-based auth |
| hydra | ⭐ 17.0k | Go | Enterprise OAuth2/OIDC provider for identity management and secure authentication |
| Signal-Desktop | ⭐ 16.1k | TypeScript | Cross-platform encrypted messaging client for secure desktop communications |
| cryptomator | ⭐ 14.8k | Java | Client-side encryption tool for securing cloud storage files |
| systeminformer | ⭐ 13.8k | C | Advanced system monitor and debugging tool for Windows security analysis |
| Signal-iOS | ⭐ 11.9k | Swift | Open-source encrypted messenger for iOS providing secure communications |
| Betterfox | ⭐ 10.2k | JavaScript | Optimized Firefox configuration for enhanced privacy, security, and performance |
| VeraCrypt | ⭐ 9.4k | C | Open-source disk encryption tool for securing data at rest with strong crypto algorithms |
| falco | ⭐ 8.8k | C++ | Cloud-native runtime security monitoring with eBPF and container support |
| PrivateBin | ⭐ 8.1k | PHP | Zero-knowledge encrypted pastebin for secure data sharing with client-side encryption |
| app | ⭐ 6.6k | Python | Privacy-focused email aliasing service to protect email addresses |
| spicedb | ⭐ 6.5k | Go | Zanzibar-inspired authorization database for fine-grained access control |
| permify | ⭐ 5.8k | Go | Google Zanzibar-inspired authorization service for fine-grained permissions |
| tetragon | ⭐ 4.5k | C | eBPF-based runtime security observability and enforcement for Kubernetes |
| IOSSecuritySuite | ⭐ 2.6k | Swift | iOS anti-tampering and security detection library for mobile app protection |
| Elkeid | ⭐ 2.6k | Go | ByteDance open-source CWPP/EDR for hosts, containers, K8s, and serverless |
| HidHide | ⭐ 1.3k | C++ | Windows input device firewall for controlling gaming peripheral access |
| thiss.link | ⭐ 596 | TypeScript | Privacy-focused encrypted link shortener with password protection and self-hosting |
| Tool | Stars | Language | Description |
|---|---|---|---|
| volatility3 | ⭐ 4.0k | Python | Advanced memory forensics framework for analyzing RAM dumps and malware |
| BlueTeam-Tools | ⭐ 4.0k | — | Comprehensive collection of blue team tools and incident response techniques |
| timesketch | ⭐ 3.3k | Python | Collaborative forensic timeline analysis platform for incident response |
| medicat_installer | ⭐ 2.7k | Batchfile | Medicat installer for IT support and system recovery tools |
| PCredz | ⭐ 2.4k | Python | Extracts credentials and sensitive data from pcap files or live network interfaces |
| plaso | ⭐ 2.0k | Python | Timeline analysis tool for digital forensics investigations and incident response |
| FIR | ⭐ 2.0k | JavaScript | Fast incident response platform for security teams and forensic investigations |
| hindsight | ⭐ 1.4k | Python | Browser forensics tool for Chrome/Chromium analyzing browsing history and artifacts |
| artifacts | ⭐ 1.2k | Python | Comprehensive repository of digital forensics artifacts and definitions |
| dfiq | ⭐ 301 | Python | Collection of investigative questions and approaches for digital forensics |
| Tool | Stars | Language | Description |
|---|---|---|---|
| al-khaser | ⭐ 6.9k | C++ | Collection of anti-analysis techniques used by malware in the wild |
| dangerzone | ⭐ 5.3k | Python | Converts potentially dangerous documents to safe PDFs for malware mitigation |
| BlueTeamTools | ⭐ 1.8k | — | Blue team analysis toolkit for memory horses, payload decryption, and forensics |
| BlueTeamTools | ⭐ 545 | Python | Blue team toolbox for malware analysis and incident response in Chinese |
| Tool | Stars | Language | Description |
|---|---|---|---|
| pi-hole | ⭐ 56.2k | Shell | Network-wide ad blocker with DNS server and DHCP capabilities |
| AdGuardHome | ⭐ 33.1k | Go | Network-wide DNS server blocking ads and trackers with privacy focus |
| algo | ⭐ 30.3k | Python | Automated personal VPN deployment with strong encryption and modern protocols |
| cilium | ⭐ 24.0k | Go | eBPF-based container networking and security for Kubernetes environments |
| netbird | ⭐ 23.9k | Go | Secure WireGuard-based mesh network with SSO and access controls |
| nebula | ⭐ 17.2k | Go | High-performance overlay networking tool for secure mesh networking |
| ZeroTierOne | ⭐ 16.6k | C++ | Decentralized VPN creating secure virtual networks with peer-to-peer architecture |
| gluetun | ⭐ 13.5k | Go | Multi-provider VPN client container with DNS-over-TLS and proxy support |
| dnscrypt-proxy | ⭐ 13.1k | Go | Encrypted DNS proxy supporting DoH, DNSCrypt for secure DNS resolution |
| portmaster | ⭐ 12.1k | Go | Application firewall and privacy protection tool for blocking network surveillance |
| docker-pi-hole | ⭐ 10.9k | Shell | Official Pi-hole Docker image for DNS-based ad blocking |
| wireshark | ⭐ 9.1k | C | Industry standard network packet analyzer for traffic monitoring and analysis |
| firezone | ⭐ 8.5k | Elixir | Zero-trust network access platform built on WireGuard with enterprise features |
| ntopng | ⭐ 7.7k | Lua | Web-based network traffic monitoring and analysis with real-time visibility |
| calico | ⭐ 7.1k | Go | Cloud-native networking and network security solution with identity-aware policies |
| nextdns | ⭐ 4.0k | Go | NextDNS CLI client providing DNS-over-HTTPS proxy functionality |
| NextDNS-Config | ⭐ 2.9k | — | DNS-over-HTTPS proxy configuration guide with ad/malware blocking capabilities |
| Signal-TLS-Proxy | ⭐ 1.2k | Shell | TLS proxy for Signal messaging service network security |
| Pi.Alert | ⭐ 1.1k | PHP | Network device discovery and monitoring for detecting unauthorized connections |
| dns | ⭐ 284 | Go | Secure DNS server with DNS-over-TLS support from multiple privacy providers |
| Tool | Stars | Language | Description |
|---|---|---|---|
| prometheus | ⭐ 63.3k | Go | Industry-standard time series database and monitoring system for infrastructure metrics |
| changedetection.io | ⭐ 30.7k | Python | Website change detection and monitoring tool for content tracking and alerts |
| wazuh | ⭐ 15.0k | C++ | Open source unified XDR and SIEM platform for endpoint and cloud protection |
| node_exporter | ⭐ 13.3k | Go | System metrics exporter for Prometheus monitoring - essential for infrastructure visibility |
| atomic-red-team | ⭐ 11.7k | C | Portable detection tests based on MITRE ATT&CK framework for threat detection |
| sigma | ⭐ 10.2k | Python | Main repository for Sigma detection rules for SIEM and security monitoring |
| healthchecks | ⭐ 10.0k | Python | Open-source cron job and background task monitoring service |
| alertmanager | ⭐ 8.4k | Go | Alert management for Prometheus - handles deduplication and routing to notification channels |
| Azure-Sentinel | ⭐ 5.6k | Python | Microsoft's cloud-native SIEM platform for enterprise security analytics |
| VECTR | ⭐ 1.6k | — | Red and blue team testing activity tracker for measuring detection capabilities |
| FalconHound | ⭐ 820 | Go | Blue team multi-tool enhancing BloodHound automation with SIEM integration |
| CyberBlue | ⭐ 511 | Shell | Containerized blue team platform combining SIEM, DFIR, CTI, and SOAR tools |
| Tool | Stars | Language | Description |
|---|---|---|---|
| dns-blocklists | ⭐ 21.0k | Text | Comprehensive DNS blocklists for malware, ads, and malicious domain filtering |
| crowdsec | ⭐ 12.9k | Go | Crowdsourced threat detection with shared CTI and malicious IP blocking |
| tpotce | ⭐ 8.9k | C | All-in-one multi honeypot platform for deception and threat detection |
| MISP | ⭐ 6.2k | PHP | Open source threat intelligence platform for sharing IOCs and malware analysis |
| IntelOwl | ⭐ 4.5k | Python | Scalable threat intelligence platform for IOC enrichment and malware analysis |
| APT_REPORT | ⭐ 3.0k | Python | Curated collection of APT reports and IOCs for threat hunting and analysis |
| AIL-framework | ⭐ 1.4k | Python | Analysis framework for information leaks and privacy security incidents |
| misp-galaxy | ⭐ 613 | Python | MISP threat actor clusters and attack patterns for structured threat intelligence |
| misp-modules | ⭐ 363 | Python | MISP expansion modules for threat intelligence enrichment and data import/export |
| Tool | Stars | Language | Description |
|---|---|---|---|
| bunkerweb | ⭐ 10.2k | Python | Next-generation open-source Web Application Firewall with container support |
| simplewall | ⭐ 8.2k | C | Simple Windows firewall configuration tool for network activity control |
| coraza | ⭐ 3.4k | Go | OWASP web application firewall library compatible with ModSecurity |
| crowdsec-bouncer-traefik-plugin | ⭐ 732 | Go | Traefik plugin integrating CrowdSec for WAF and IP protection |
| Tool | Stars | Language | Description |
|---|---|---|---|
| actions-runner-controller | ⭐ 6.1k | Go | Kubernetes controller for managing GitHub Actions self-hosted runners at scale |
| Tool | Stars | Language | Description |
|---|---|---|---|
| prowler | ⭐ 13.4k | Python | Multi-cloud security platform for automated compliance and security auditing |
| netmaker | ⭐ 11.5k | Go | WireGuard-based mesh networking platform for secure distributed virtual networks |
| my-arsenal-of-aws-security-tools | ⭐ 9.4k | Shell | Curated list of open-source AWS security tools for defense and auditing |
| steampipe | ⭐ 7.7k | Go | SQL-based cloud security posture management and compliance tool |
| ScoutSuite | ⭐ 7.6k | Python | Multi-cloud security auditing tool for AWS, Azure, and GCP environments |
| cloudquery | ⭐ 6.3k | Go | Cloud asset inventory and CSPM data pipeline for security posture |
| cloudmapper | ⭐ 6.3k | JavaScript | AWS environment analyzer for security assessment and infrastructure mapping |
| cloud-custodian | ⭐ 6.0k | Python | Multi-cloud policy engine for security, compliance, and cost optimization |
| cloudsploit | ⭐ 3.7k | JavaScript | Cloud Security Posture Management tool for multi-cloud environments |
| cloud-nuke | ⭐ 3.1k | Go | Tool for cleaning up cloud resources by deleting all resources in accounts |
| cloudsplaining | ⭐ 2.2k | JavaScript | AWS IAM privilege escalation and least privilege violation assessment tool |
| PurplePanda | ⭐ 719 | Python | Multi-cloud privilege escalation path discovery tool for GCP, GitHub, Kubernetes |
| Tool | Stars | Language | Description |
|---|---|---|---|
| harbor | ⭐ 27.8k | Go | Enterprise container registry with security scanning and content signing |
| slim | ⭐ 23.1k | Go | Container image minification tool that reduces size by 30x while improving security |
| grype | ⭐ 11.9k | Go | Vulnerability scanner for container images and filesystems with SBOM support |
| kubescape | ⭐ 11.3k | Go | Kubernetes security platform with risk analysis, compliance, and misconfiguration scanning |
| docker-bench-security | ⭐ 9.6k | Shell | Security benchmark script checking Docker container deployment best practices |
| kube-bench | ⭐ 8.0k | Go | CIS Kubernetes benchmark compliance checker for security best practices |
| kata-containers | ⭐ 7.7k | Rust | Lightweight VMs that provide container-like performance with VM security isolation |
| x11docker | ⭐ 6.2k | Shell | Security-focused tool to run GUI applications in isolated Docker containers |
| kubernetes-network-policy-recipes | ⭐ 6.1k | — | Ready-to-use Kubernetes Network Policy examples for microsegmentation |
| pouch | ⭐ 4.7k | Go | Enterprise container engine focused on efficiency, isolation, and security |
| CDK | ⭐ 4.6k | Go | Kubernetes, Docker, and Containerd security testing toolkit with container escapes |
| dockle | ⭐ 3.2k | Go | Docker image linter for security best practices and compliance checking |
| container-security-checklist | ⭐ 1.6k | — | Comprehensive container security checklist for DevSecOps practices |
| copacetic | ⭐ 1.6k | Go | CLI tool for direct container image patching and vulnerability remediation |
| stackrox | ⭐ 1.3k | Go | Kubernetes security platform with runtime monitoring and risk analysis |
| images | ⭐ 664 | HCL | Distroless container images with minimal attack surface and security hardening |
| imgcrypt | ⭐ 424 | Go | OCI container image encryption package for securing container workloads |
| Tool | Stars | Language | Description |
|---|---|---|---|
| aws-cdk | ⭐ 12.7k | TypeScript | AWS CDK framework for defining cloud infrastructure as code in TypeScript |
| checkov | ⭐ 8.5k | Python | Multi-cloud misconfiguration scanner for IaC, containers, and packages |
| kyverno | ⭐ 7.5k | Go | Policy-as-code engine for Kubernetes security and compliance management |
| tfsec | ⭐ 7.0k | Go | Terraform security scanner now integrated into Trivy for IaC analysis |
| awesome-tf | ⭐ 6.3k | — | Terraform and OpenTofu resources for infrastructure as code |
| Tool | Stars | Language | Description |
|---|---|---|---|
| gosec | ⭐ 8.7k | Go | Static analysis security scanner specifically designed for Go applications |
| syft | ⭐ 8.6k | Go | Generate Software Bill of Materials (SBOM) from container images and filesystems |
| osv-scanner | ⭐ 8.6k | Go | OSV.dev vulnerability scanner for finding security issues in dependencies |
| bandit | ⭐ 7.9k | Python | Static analysis tool for finding common security issues in Python code |
| DependencyCheck | ⭐ 7.5k | Java | OWASP dependency checker for finding vulnerabilities in application dependencies |
| faraday | ⭐ 6.3k | Python | Open source vulnerability management platform with tool integration and reporting |
| django-DefectDojo | ⭐ 4.6k | HTML | Comprehensive vulnerability management platform with DevSecOps integration |
| retire.js | ⭐ 4.1k | JavaScript | Scanner for JavaScript libraries with known vulnerabilities and SBOM generation |
| threat-dragon | ⭐ 1.4k | JavaScript | OWASP threat modeling tool for identifying security risks in application design |
| trivy-action | ⭐ 1.3k | Shell | GitHub Action for Trivy vulnerability scanning of Docker containers |
| dagda | ⭐ 1.2k | Python | Docker image vulnerability scanner with malware detection and runtime monitoring |
| Tool | Stars | Language | Description |
|---|---|---|---|
| vaultwarden | ⭐ 57.1k | Rust | Self-hosted password manager, essential for secrets management |
| vault | ⭐ 35.3k | Go | Enterprise secrets management and privileged access management platform |
| gitleaks | ⭐ 25.5k | Go | Fast secrets detection tool with AI-powered analysis for Git repositories |
| trufflehog | ⭐ 25.1k | Go | Find, verify, and analyze leaked credentials in code repositories and files |
| sops | ⭐ 21.3k | Go | Flexible secrets encryption tool supporting multiple cloud providers and PGP |
| git-credential-manager | ⭐ 8.7k | C# | Cross-platform Git credential manager with secure auth for major Git services |
| external-secrets | ⭐ 6.5k | Go | Kubernetes operator that syncs secrets from external providers like AWS Secrets Manager |
| SecretScanner | ⭐ 3.3k | Go | Container secret scanner for passwords and API keys in images and filesystems |
| yopass | ⭐ 2.7k | TypeScript | Secure one-time sharing of secrets and passwords with encryption |
| traefik-forward-auth | ⭐ 2.4k | Go | OAuth-based forward authentication service for Traefik reverse proxy |
| ggshield | ⭐ 1.9k | Python | Advanced secrets detection with 500+ validators for CI/CD pipelines |
| git-hound | ⭐ 1.4k | Go | GitHub-wide secret scanning tool for credential leak detection |
| Hemmelig.app | ⭐ 1.1k | TypeScript | Encrypted secret sharing platform for secure information exchange |
| shell-plugins | ⭐ 650 | Go | Shell plugins providing seamless authentication for terminal tools via 1Password |
| op-vscode | ⭐ 253 | TypeScript | 1Password integration for VS Code enabling secure credential management |
| connect-sdk-python | ⭐ 223 | Python | Python SDK for 1Password Connect API for programmatic secrets management |
| connect | ⭐ 206 | — | 1Password Connect server for programmatic access to 1Password secrets in automation |
| Tool | Stars | Language | Description |
|---|---|---|---|
| renovate | ⭐ 21.1k | TypeScript | Automated dependency updates across multiple platforms and package managers |
| oss-fuzz | ⭐ 12.0k | Shell | Continuous fuzzing infrastructure for open source software security |
| cosign | ⭐ 5.7k | Go | Keyless code signing and verification for containers and software artifacts |
| clusterfuzz | ⭐ 5.5k | Python | Google's scalable fuzzing infrastructure for vulnerability discovery |
| dependency-track | ⭐ 3.7k | Java | OWASP component analysis platform for software supply chain risk reduction |
| slsa | ⭐ 1.8k | HTML | Framework defining supply-chain security levels for software artifacts |
| murphysec | ⭐ 1.8k | Go | Open source SCA tool for dependency vulnerability detection |
| OpenSCA-cli | ⭐ 1.1k | Go | Open source SCA with SBOM generation and license compliance checking |
| rekor | ⭐ 1.1k | Go | Transparency log for software supply chain provenance and security verification |
| gitsign | ⭐ 1.1k | Go | Keyless Git commit signing using Sigstore for secure software development |
| in-toto | ⭐ 982 | Python | Framework for protecting software supply chain integrity with attestations |
| fulcio | ⭐ 814 | Go | OIDC-based PKI certificate authority for keyless code signing infrastructure |
| cargo-vet | ⭐ 798 | Rust | Mozilla's supply-chain security auditing tool for Rust dependencies |
| chain-bench | ⭐ 770 | Go | CIS-based compliance auditing for software supply chain security |
| npm-security-best-practices | ⭐ 765 | — | Best practices guide for NPM supply chain attack prevention |
| go-tuf | ⭐ 698 | Go | Go implementation of The Update Framework for secure software updates |
| packj | ⭐ 685 | Python | Malicious dependency detection for preventing supply chain attacks |
| chainloop | ⭐ 539 | Go | SDLC evidence store with SBOM management and supply chain attestations |
| witness | ⭐ 519 | Go | Pluggable framework for software artifact provenance verification |
| minder | ⭐ 380 | Go | Comprehensive software supply chain security management platform |
| sigstore-python | ⭐ 316 | Python | Python client for Sigstore software supply chain security and code signing |
| malicious-software-packages-dataset | ⭐ 315 | Python | Human-vetted dataset of malicious software packages for supply chain security research |
| chains | ⭐ 270 | Go | Supply chain security integration for Tekton CI/CD pipelines |
| sbomnix | ⭐ 248 | Python | Nix-focused SBOM generation and supply chain security utilities |
| Tool | Stars | Language | Description |
|---|---|---|---|
| openclaw | ⭐ 328.9k | TypeScript | Cross-platform personal AI assistant framework with data ownership focus |
| langflow | ⭐ 146.0k | Python | Visual workflow builder for creating and deploying AI agents with drag-and-drop interface |
| langchain | ⭐ 131.4k | Python | Leading agent engineering platform for building AI applications with LLMs |
| everything-claude-code | ⭐ 115.3k | JavaScript | Agent harness optimization system for Claude Code with skills and memory management |
| superpowers | ⭐ 103.6k | Shell | Agentic skills framework for software development methodology with practical approach |
| skills | ⭐ 99.4k | Python | Official Anthropic repository for agent skills development and examples |
| whisper | ⭐ 96.4k | Python | OpenAI's robust speech recognition system using large-scale supervision |
| MetaGPT | ⭐ 66.4k | Python | Multi-agent framework for AI software company simulation and development |
| agency-agents | ⭐ 58.5k | Shell | Complete AI agency framework with specialized agents for different business roles |
| autogen | ⭐ 56.4k | Python | Programming framework for building agentic AI systems with collaborative agents |
| nanoGPT | ⭐ 55.4k | Python | Karpathy's minimal GPT training implementation, perfect for learning and experimentation |
| ui-ux-pro-max-skill | ⭐ 47.7k | Python | AI skill for professional UI/UX design intelligence across multiple platforms |
| crewAI | ⭐ 47.5k | Python | Framework for orchestrating role-playing autonomous AI agents in teams |
| MiroFish | ⭐ 45.1k | Python | Multi-agent swarm intelligence engine for prediction and social analysis |
| awesome-openclaw-skills | ⭐ 42.8k | — | Curated collection of 5400+ OpenClaw agent skills categorized and filtered |
| claude-mem | ⭐ 39.2k | TypeScript | Claude Code plugin for AI-powered memory and context injection in coding |
| learn-claude-code | ⭐ 35.5k | TypeScript | Educational Claude Code agent harness built from scratch for learning AI agents |
| AstrBot | ⭐ 28.1k | Python | Multi-platform agentic chatbot infrastructure with LLM integration and plugins |
| langgraph | ⭐ 27.8k | Python | Build resilient language agents as graphs, part of LangChain ecosystem |
| haystack | ⭐ 24.6k | MDX | Production-ready LLM orchestration framework for RAG and agent workflows |
| Open-AutoGLM | ⭐ 24.6k | Python | Open-source phone agent model and framework for AI phone applications |
| mastra | ⭐ 22.4k | TypeScript | TypeScript framework for building AI agents and applications from Gatsby team |
| ruflo | ⭐ 22.3k | TypeScript | Agent orchestration platform for Claude with multi-agent swarms and RAG integration |
| serve | ⭐ 21.9k | Python | Cloud-native framework for multimodal AI applications with microservice support |
| SuperClaude_Framework | ⭐ 21.8k | Python | Configuration framework enhancing Claude Code with specialized commands |
| openai-agents-python | ⭐ 20.4k | Python | Official OpenAI lightweight framework for multi-agent workflows in Python |
| 12-factor-agents | ⭐ 19.0k | TypeScript | 12-factor principles framework for production-ready LLM-powered software |
| eliza | ⭐ 18.0k | Rust | Rust-based autonomous agent framework with plugins and multi-platform support |
| parlant | ⭐ 17.9k | Python | Conversational control layer framework for customer-facing AI agents |
| OpenViking | ⭐ 17.6k | Python | Context database for AI agents with hierarchical memory and skill management |
| SuperAGI | ⭐ 17.4k | Python | Dev-first autonomous AI agent framework for building and managing agents |
| NeMo | ⭐ 17.0k | Python | NVIDIA's scalable generative AI framework for LLMs, multimodal, and speech AI |
| camel | ⭐ 16.5k | Python | Multi-agent framework focusing on communicative AI and agent scaling laws |
| agent-zero | ⭐ 16.5k | Python | Autonomous AI agent framework with Linux integration and zero-config approach |
| pydantic-ai | ⭐ 15.9k | Python | AI agent framework built with Pydantic for type-safe agent development |
| agentskills | ⭐ 13.8k | Python | Specification and documentation framework for standardizing AI agent skills |
| WeKnora | ⭐ 13.6k | Go | Go-based RAG framework for document understanding and semantic retrieval |
| univer | ⭐ 12.7k | TypeScript | AI-native spreadsheet framework with natural language processing capabilities |
| Personal_AI_Infrastructure | ⭐ 10.3k | TypeScript | Agentic AI infrastructure platform for augmenting human productivity and capabilities |
| MONAI | ⭐ 8.0k | Python | Healthcare imaging AI toolkit from Project MONAI for medical image processing |
| craft-agents-oss | ⭐ 3.3k | TypeScript | Open-source AI agent crafting framework (minimal description available) |
| metorial | ⭐ 3.2k | TypeScript | AI model integration platform with 600+ services using Model Context Protocol |
| Maestro | ⭐ 2.6k | TypeScript | Command center for orchestrating and managing multiple AI agents |
| MetaClaw | ⭐ 2.3k | Python | Conversational agent that learns and evolves through continual learning and meta-learning |
| agentic-context-engine | ⭐ 2.1k | Python | Context engine enabling agents to learn from experience with memory management |
| mcp-memory-service | ⭐ 1.6k | Python | Persistent memory service for AI agents with knowledge graph and vector storage |
| Telos | ⭐ 1.2k | — | Framework for creating deep context about human-relevant topics |
| Substrate | ⭐ 765 | TypeScript | Framework for creating deep contextual understanding using AI |
| DreamDojo | ⭐ 634 | Python | NVIDIA's robot world model from large-scale human video data for generalist robotics |
| Tool | Stars | Language | Description |
|---|---|---|---|
| system_prompts_leaks | ⭐ 34.8k | HTML | Collection of extracted system prompts from popular AI chatbots for research |
| promptfoo | ⭐ 18.1k | TypeScript | Comprehensive testing and red teaming framework for AI prompts and agents |
| L1B3RT4S | ⭐ 18.1k | — | AI jailbreak prompts for red teaming and adversarial testing of AI systems |
| heretic | ⭐ 16.4k | Python | Automatic censorship removal tool for language models using abliteration techniques |
| NemoClaw | ⭐ 15.0k | JavaScript | Secure OpenClaw execution within NVIDIA OpenShell runtime with managed inference |
| CL4R1T4S | ⭐ 13.9k | — | Leaked system prompts from major AI systems for transparency and security research |
| PentestGPT | ⭐ 12.2k | Python | LLM-powered automated penetration testing framework for security assessments |
| cai | ⭐ 7.5k | Python | AI Security framework for cybersecurity applications and LLM pentesting |
| adversarial-robustness-toolbox | ⭐ 5.9k | Python | Python library for ML security testing including adversarial attacks and defenses |
| microsandbox | ⭐ 5.0k | Rust | Secure local-first sandboxes for AI agents with cross-platform support |
| Anthropic-Cybersecurity-Skills | ⭐ 3.6k | Python | Structured cybersecurity skills dataset for AI agents mapped to MITRE ATT&CK |
| OpenShell | ⭐ 3.0k | Rust | NVIDIA's secure runtime environment for autonomous AI agents with safety controls |
| validation-benchmarks | ⭐ 528 | PHP | AI security validation benchmarks for testing AI model safety and security |
| model-transparency | ⭐ 225 | Python | Machine learning model supply chain security with Sigstore integration |
| h1-brain | ⭐ 211 | Python | MCP server connecting AI assistants to HackerOne for automated bug bounty hunting |
| watchtower | ⭐ 202 | PureBasic | AI model vulnerability scanner for ML supply chain security |
| Tool | Stars | Language | Description |
|---|---|---|---|
| Deep-Live-Cam | ⭐ 80.2k | Python | Real-time deepfake and face swap tool using AI for video manipulation |
| Tool | Stars | Language | Description |
|---|---|---|---|
| n8n | ⭐ 180.4k | TypeScript | Visual workflow automation platform with native AI capabilities and 400+ integrations |
| autoresearch | ⭐ 48.5k | Python | Karpathy's autonomous research AI agents for single-GPU training experiments |
| agents | ⭐ 31.9k | Python | Multi-agent orchestration framework for Claude Code with intelligent automation |
| paperclip | ⭐ 31.3k | TypeScript | Open-source orchestration platform for autonomous business operations |
| Jobs_Applier_AI_Agent_AIHawk | ⭐ 29.6k | Python | AI-powered job application automation agent using GPT and web scraping |
| browser | ⭐ 25.7k | Zig | Headless browser specifically designed for AI automation and web scraping tasks |
| CLI-Anything | ⭐ 24.5k | Python | Framework for making all software accessible to AI agents via CLI interfaces |
| agent-browser | ⭐ 24.1k | Rust | Browser automation CLI specifically designed for AI agent workflows in Rust |
| stagehand | ⭐ 21.7k | TypeScript | AI-powered browser automation framework using Playwright and Puppeteer |
| page-agent | ⭐ 13.1k | TypeScript | JavaScript in-page GUI agent for controlling web interfaces with natural language |
| AutoResearchClaw | ⭐ 7.4k | Python | Autonomous research agent generating complete papers from ideas with self-evolution |
| Tool | Stars | Language | Description |
|---|---|---|---|
| opencode | ⭐ 132.1k | TypeScript | Open source coding agent for automated software development tasks |
| claude-code | ⭐ 81.0k | Shell | Terminal-based AI coding assistant that understands codebases and handles git workflows |
| codex | ⭐ 68.2k | Rust | Lightweight terminal-based coding agent from OpenAI |
| cline | ⭐ 59.2k | TypeScript | Autonomous coding agent for IDEs with file creation and command execution |
| get-shit-done | ⭐ 38.2k | JavaScript | Meta-prompting framework for Claude Code with spec-driven development approach |
| pi-mono | ⭐ 26.7k | TypeScript | AI agent toolkit with coding CLI, unified LLM API, and web interfaces |
| nanoclaw | ⭐ 24.8k | TypeScript | Containerized AI assistant with multi-messenger support and memory |
| vibe-kanban | ⭐ 23.6k | Rust | Kanban-style task manager for enhancing Claude Code and coding agents |
| Roo-Code | ⭐ 22.8k | TypeScript | AI-powered development team integrated directly into code editors for assistance |
| GitNexus | ⭐ 18.6k | TypeScript | Client-side code intelligence engine creating knowledge graphs with RAG agent |
| DesktopCommanderMCP | ⭐ 5.8k | TypeScript | MCP server giving Claude terminal control and file system capabilities |
| agent-os | ⭐ 4.2k | Shell | System for injecting codebase standards and improving spec-driven development |
| nanocoder | ⭐ 1.5k | TypeScript | Local-first coding agent running in terminal with community focus |
| Tool | Stars | Language | Description |
|---|---|---|---|
| ollama | ⭐ 166.4k | Go | Local LLM runtime supporting multiple models including Qwen, Gemma, and DeepSeek |
| servers | ⭐ 81.7k | TypeScript | Official collection of Model Context Protocol servers for AI applications |
| ChatGPT | ⭐ 54.4k | Rust | Cross-platform ChatGPT desktop app with note-taking features |
| nanochat | ⭐ 49.9k | Python | Budget-conscious ChatGPT alternative optimized for cost efficiency |
| litellm | ⭐ 39.9k | Python | Universal LLM API gateway with cost tracking and guardrails for 100+ providers |
| quivr | ⭐ 39.1k | Python | Opiniated RAG framework for integrating GenAI with customizable LLM support |
| gstack | ⭐ 35.8k | TypeScript | Opinionated Claude Code setup for CEO, Designer, Eng Manager roles |
| LibreChat | ⭐ 35.0k | TypeScript | Enhanced ChatGPT clone with multiple AI providers and agent capabilities |
| github-mcp-server | ⭐ 28.1k | Go | GitHub's official Model Context Protocol server for AI integration |
| Awesome-LLM | ⭐ 26.5k | — | Comprehensive curated list of LLM resources, papers, and tools |
| RagaAI-Catalyst | ⭐ 16.1k | Python | Python SDK for AI agent observability, monitoring and evaluation with tracing |
| shell_gpt | ⭐ 11.9k | Python | Command-line productivity tool powered by GPT and other LLMs for task automation |
| imaginAIry | ⭐ 8.1k | Python | Pythonic AI tool for generating images and videos with AI models |
| claude-code-hooks-mastery | ⭐ 3.4k | Python | Educational resource for mastering Claude Code Hooks functionality |
| SimpleMem | ⭐ 3.3k | Python | Efficient lifelong memory system for LLM agents with compression and retrieval |
| godot-mcp | ⭐ 2.7k | JavaScript | MCP server for Godot integration, enables AI agents to control game engine workflows |
| Tool | Stars | Language | Description |
|---|---|---|---|
| prompts.chat | ⭐ 153.7k | HTML | Community platform for sharing and discovering AI prompts and techniques |
| system-prompts-and-models-of-ai-tools | ⭐ 132.6k | — | Collection of AI system prompts and models from popular coding tools |
| Fabric | ⭐ 40.1k | Go | Modular AI framework with crowdsourced prompts for human augmentation |
| claude-code-best-practice | ⭐ 20.1k | HTML | Best practices and patterns for Claude AI coding and prompt engineering |
| impeccable | ⭐ 14.5k | JavaScript | Design language framework for improving AI design capabilities and outputs |
| gsd-2 | ⭐ 2.6k | TypeScript | Meta-prompting and context engineering system for long-running autonomous agents |
| Tool | Stars | Language | Description |
|---|---|---|---|
| RSSHub | ⭐ 42.9k | TypeScript | Universal RSS hub converting various platforms to RSS feeds for content aggregation |
| ccxt | ⭐ 41.6k | Python | Comprehensive cryptocurrency trading API library supporting 100+ exchanges |
| cli | ⭐ 37.8k | Python | Modern command-line HTTP client with JSON support, colors, and developer features |
| ntfy | ⭐ 29.3k | Go | Self-hosted notification service for developers to send push notifications via HTTP |
| hurl | ⭐ 18.7k | Rust | Plain text HTTP testing tool for API testing and integration testing |
| star-history | ⭐ 8.8k | TypeScript | Visualize GitHub star growth history — great for evaluating project momentum |
| shlink | ⭐ 4.8k | PHP | Self-hosted URL shortener with REST API for link management |
| notion-py | ⭐ 4.4k | Python | Python API client for Notion workspace automation and integration |
| Tool | Stars | Language | Description |
|---|---|---|---|
| uv | ⭐ 81.7k | Rust | Extremely fast Python package manager written in Rust for efficient dependency management |
| pnpm | ⭐ 34.4k | TypeScript | Fast, disk-efficient package manager alternative to npm for Node.js development |
| packer | ⭐ 15.6k | Go | Multi-platform machine image builder for consistent deployment environments |
| obsidian-git | ⭐ 10.1k | TypeScript | Git integration plugin for Obsidian with auto-commit and sync features |
| Tool | Stars | Language | Description |
|---|---|---|---|
| ohmyzsh | ⭐ 185.6k | Shell | Community-driven zsh configuration framework with plugins and themes |
| nvm | ⭐ 92.5k | Shell | POSIX-compliant Node.js version manager for switching between Node versions |
| lazygit | ⭐ 74.8k | Go | Simple terminal UI for Git commands with visual interface |
| nerd-fonts | ⭐ 62.2k | CSS | Massive collection of developer-focused patched fonts with programming icons |
| ladybird | ⭐ 61.4k | C++ | Independent web browser engine built from scratch for security and performance |
| starship | ⭐ 55.5k | Rust | Fast, customizable shell prompt that works across multiple shells |
| powerlevel10k | ⭐ 53.4k | Shell | Fast and feature-rich zsh theme for enhanced terminal experience |
| winutil | ⭐ 50.5k | PowerShell | Windows system administration utility for tweaks, updates, and software management |
| Files | ⭐ 42.6k | C# | Modern Windows file manager with developer-friendly features and Git integration |
| desktop | ⭐ 40.8k | JavaScript | Privacy-focused Firefox-based browser for secure web browsing and development |
| it-tools | ⭐ 37.9k | Vue | Collection of handy online tools for developers with great UX |
| croc | ⭐ 34.4k | Go | Secure peer-to-peer file transfer tool with end-to-end encryption |
| k9s | ⭐ 33.1k | Go | Terminal-based Kubernetes cluster management tool with intuitive interface |
| Scoop | ⭐ 23.8k | PowerShell | Command-line package installer for Windows with bucket-based management |
| UniGetUI | ⭐ 22.0k | C# | Universal GUI for Windows package managers (winget, chocolatey, pip, scoop, npm) |
| fastfetch | ⭐ 20.9k | C | Fast system information tool, maintained alternative to neofetch with better performance |
| Handy | ⭐ 18.8k | Rust | Open source offline speech-to-text application with accessibility features |
| awesome-zsh-plugins | ⭐ 17.5k | Shell | ZSH plugins and themes for enhanced terminal productivity |
| Seelen-UI | ⭐ 16.2k | Rust | Customizable Windows desktop environment with tiling window manager and modern UI |
| distrobox | ⭐ 12.2k | Shell | Run any Linux distro in containers for development flexibility |
| awesome-bash | ⭐ 9.6k | Shell | Bash scripts and resources for shell scripting and automation |
| windhawk | ⭐ 7.4k | C++ | Windows program customization marketplace and modding platform |
| Winhance | ⭐ 7.1k | C# | Windows system optimization and debloat tool for improving performance and privacy |
| lolcat | ⭐ 6.5k | Ruby | Ruby CLI tool that adds rainbow colors to terminal output - fun terminal utility |
| playwright-cli | ⭐ 6.0k | TypeScript | Microsoft's CLI for Playwright browser automation, code generation and debugging |
| xxh | ⭐ 5.9k | Python | Portable shell environment over SSH with support for multiple shell types |
| kubectl | ⭐ 3.2k | Go | Command-line interface tool for managing Kubernetes clusters and resources |
| StreamController | ⭐ 975 | Python | Elegant Linux app for Stream Deck with plugin support |
| streamdeck-linux-gui | ⭐ 405 | Python | Linux UI for Elgato Stream Deck hardware control |
| Tool | Stars | Language | Description |
|---|---|---|---|
| supabase | ⭐ 99.4k | TypeScript | Open-source Postgres development platform with auth, real-time, and AI capabilities |
| elasticsearch | ⭐ 76.4k | Java | Distributed RESTful search and analytics engine for enterprise data solutions |
| cockroach | ⭐ 32.0k | Go | Cloud-native distributed SQL database designed for high availability |
| sled | ⭐ 9.0k | Rust | High-performance embedded database with extensive testing and fuzzing |
| GRDB.swift | ⭐ 8.3k | Swift | Swift SQLite toolkit with focus on application development and database observation |
| Tool | Stars | Language | Description |
|---|---|---|---|
| zed | ⭐ 77.6k | Rust | High-performance multiplayer code editor built in Rust by Atom creators |
| code-server | ⭐ 76.8k | TypeScript | VS Code running in browser for remote development environments |
| helix | ⭐ 43.7k | Rust | Modern modal text editor in Rust, alternative to Vim with improved ergonomics |
| vscodium | ⭐ 30.6k | Shell | VS Code without Microsoft telemetry and licensing restrictions |
| catppuccin | ⭐ 18.6k | TypeScript | Meta repository for popular pastel theme across multiple development tools |
| gitpod | ⭐ 13.6k | TypeScript | Cloud-based development environments for faster and more secure coding |
| openvscode-server | ⭐ 5.9k | TypeScript | Remote VS Code server accessible through web browser from any device |
| vscode | ⭐ 2.1k | TypeScript | Soothing pastel theme for Visual Studio Code editor |
| Tool | Stars | Language | Description |
|---|---|---|---|
| next.js | ⭐ 138.4k | JavaScript | Popular React framework for production web apps with SSR and static generation |
| excalidraw | ⭐ 119.3k | TypeScript | Collaborative virtual whiteboard for sketching diagrams and visual planning |
| ui | ⭐ 110.3k | TypeScript | Modern React component library with accessible design and framework flexibility |
| godot | ⭐ 108.3k | C++ | Multi-platform 2D/3D game engine for cross-platform development |
| playwright | ⭐ 84.7k | TypeScript | Cross-browser testing framework for web automation and E2E testing |
| spec-kit | ⭐ 83.3k | Python | GitHub toolkit for spec-driven development with AI integration |
| tesseract | ⭐ 73.0k | C++ | Industry-standard OCR engine for extracting text from images and documents |
| astro | ⭐ 57.7k | TypeScript | Modern web framework for content-driven static and hybrid sites |
| html5-boilerplate | ⭐ 57.4k | JavaScript | Professional HTML5 boilerplate with best practices for robust web development |
| serverless | ⭐ 46.9k | JavaScript | Popular framework for building auto-scaling serverless applications on cloud platforms |
| BMAD-METHOD | ⭐ 41.7k | JavaScript | Agile AI-driven development methodology framework |
| cal.com | ⭐ 40.7k | TypeScript | Open-source scheduling platform built with modern TypeScript stack |
| reactive-resume | ⭐ 35.9k | TypeScript | Privacy-focused resume builder with modern tech stack, useful dev tool |
| Trilium | ⭐ 35.2k | TypeScript | Self-hosted personal knowledge management system with note-taking features |
| Scrapling | ⭐ 33.6k | Python | Adaptive web scraping framework with AI capabilities and stealth features |
| posthog | ⭐ 32.3k | Python | All-in-one developer platform with analytics, feature flags, and AI product assistant |
| sharp | ⭐ 32.0k | JavaScript | High-performance Node.js image processing library using libvips |
| mkdocs-material | ⭐ 26.4k | Python | Material Design theme and framework for MkDocs documentation sites |
| kratos | ⭐ 25.6k | Go | Go microservices framework for cloud-native applications with gRPC/HTTP |
| wasp | ⭐ 18.2k | TypeScript | Full-stack React/Node.js framework with AI features and declarative config |
| linkwarden | ⭐ 17.6k | TypeScript | Self-hosted collaborative bookmark manager with annotation capabilities |
| codon | ⭐ 16.7k | Python | High-performance Python compiler with zero-overhead and GPU support |
| aiohttp | ⭐ 16.4k | Python | Asynchronous HTTP client/server framework for Python asyncio applications |
| answer | ⭐ 15.4k | Go | Open-source Q&A platform for building community forums and knowledge bases |
| iii | ⭐ 15.2k | Rust | Rust backend framework unifying stack with Function, Trigger, Worker primitives |
| faker | ⭐ 15.0k | TypeScript | JavaScript library for generating realistic fake data for testing and development |
| awesome-microservices | ⭐ 14.2k | — | Microservices architecture principles and technologies collection |
| open-saas | ⭐ 13.7k | TypeScript | Full-featured React/Node SaaS boilerplate with auth, payments, and AI features |
| examples | ⭐ 11.5k | JavaScript | Collection of serverless architecture examples and boilerplates |
| foundry | ⭐ 10.3k | Rust | Ethereum development toolkit with built-in security testing capabilities |
| SpringCloud | ⭐ 9.0k | — | Enterprise microservices platform with integrated Spring Security and OAuth2 |
| hypothesis | ⭐ 8.6k | Python | Property-based testing framework for Python with fuzzing capabilities |
| Wallos | ⭐ 7.6k | PHP | Self-hosted subscription tracking and budget management application |
| thelounge | ⭐ 6.2k | TypeScript | Modern self-hosted web IRC client for team communication |
| go-fuzz | ⭐ 4.8k | Go | Randomized testing framework specifically designed for Go applications |
| fast-check | ⭐ 4.8k | TypeScript | Property-based testing framework for JavaScript with fuzzing support |
| littlelink | ⭐ 2.9k | HTML | Lightweight self-hosted link aggregation tool, alternative to Linktree for developers |
| wizarr | ⭐ 2.8k | Python | User invitation and management system for media servers like Plex/Jellyfin |
| awesome-functional-python | ⭐ 2.5k | — | Functional programming resources and libraries for Python developers |
| plugins | ⭐ 992 | JavaScript | Community plugins extending Serverless Framework functionality |
| Tool | Stars | Language | Description |
|---|---|---|---|
| kubernetes | ⭐ 121.4k | Go | Production-grade container orchestration platform for modern applications |
| free-for-dev | ⭐ 120.2k | HTML | Free tier services for DevOps, development, and infrastructure |
| rustdesk | ⭐ 110.2k | Rust | Self-hosted remote desktop alternative to TeamViewer with cross-platform support |
| frp | ⭐ 105.5k | Go | Fast reverse proxy for exposing local servers through NAT and firewalls |
| immich | ⭐ 95.9k | TypeScript | High-performance self-hosted photo/video management and backup solution |
| Ventoy | ⭐ 75.4k | C | Multi-boot USB solution supporting various OS images and secure boot |
| moby | ⭐ 71.6k | Go | Core Docker project for container-based system development and deployment |
| caddy | ⭐ 71.2k | Go | Fast multi-platform web server with automatic HTTPS and reverse proxy capabilities |
| ansible | ⭐ 68.4k | Python | Agentless IT automation platform for configuration management and deployment |
| localstack | ⭐ 64.7k | Python | Local AWS cloud stack emulator for offline development and testing |
| traefik | ⭐ 62.3k | Go | Cloud-native application proxy and load balancer with automatic service discovery |
| Docker-OSX | ⭐ 52.3k | Shell | Run macOS VM in Docker containers for CI/CD and security research |
| lazydocker | ⭐ 50.3k | Go | Simple terminal UI for managing Docker containers and images |
| terraform | ⭐ 48.0k | Go | Infrastructure as code tool for safely managing cloud resources |
| awesome-compose | ⭐ 44.5k | HTML | Collection of Docker Compose examples for development and deployment |
| paperless-ngx | ⭐ 37.5k | Python | Document management system with OCR and machine learning capabilities |
| headscale | ⭐ 36.7k | Go | Open source self-hosted Tailscale control server implementation |
| server | ⭐ 34.4k | PHP | Self-hosted cloud platform for file sharing and collaboration |
| filebrowser | ⭐ 34.1k | Go | Web-based file browser for server management and file operations |
| CasaOS | ⭐ 33.5k | Go | Self-hosted personal cloud OS with Docker containerization and home automation |
| nginx-proxy-manager | ⭐ 32.2k | TypeScript | Docker container for managing Nginx proxy hosts with web interface |
| glances | ⭐ 32.1k | Python | Cross-platform system monitoring tool with web API and terminal interface |
| dokku | ⭐ 31.9k | Shell | Docker-powered PaaS for building and managing application lifecycles, Heroku alternative |
| minikube | ⭐ 31.6k | Go | Local Kubernetes development environment for testing and learning |
| podman | ⭐ 31.1k | Go | Daemonless container engine - secure Docker alternative for managing OCI containers |
| helm | ⭐ 29.6k | Go | The standard package manager for Kubernetes - essential for application deployment |
| ProxmoxVE | ⭐ 27.2k | Shell | Community scripts for Proxmox VE virtualization platform management |
| searxng | ⭐ 27.0k | Python | Privacy-focused metasearch engine aggregating results without tracking |
| wg-easy | ⭐ 25.1k | TypeScript | Easy WireGuard VPN deployment with web-based admin interface |
| dashy | ⭐ 24.3k | Vue | Self-hosted personal dashboard with monitoring widgets for homelab management |
| dockge | ⭐ 22.6k | TypeScript | Self-hosted Docker Compose stack manager with reactive web interface |
| containerd | ⭐ 20.5k | Go | Industry-standard container runtime powering Docker and Kubernetes |
| netbox | ⭐ 20.1k | Python | Network automation and infrastructure management platform, essential for DevOps |
| ingress-nginx | ⭐ 19.5k | Go | Official NGINX ingress controller for Kubernetes - handles external traffic routing |
| docker-mailserver | ⭐ 18.0k | Shell | Production-ready containerized mail server with antispam and antivirus |
| open-gpu-kernel-modules | ⭐ 16.8k | C | Open source NVIDIA GPU kernel modules for Linux development environments |
| nomad | ⭐ 16.3k | Go | Flexible workload orchestrator for deploying diverse application types at scale |
| awx | ⭐ 15.3k | Python | Web UI and REST API for Ansible automation platform management |
| kind | ⭐ 15.1k | Go | Local Kubernetes clusters in Docker for testing and development workflows |
| logstash | ⭐ 14.8k | Java | Data processing pipeline for logs, events, and real-time streaming ETL operations |
| coredns | ⭐ 14.0k | Go | Modular DNS server with plugin architecture for service discovery and resolution |
| cert-manager | ⭐ 13.7k | Go | Automated TLS certificate provisioning and management for Kubernetes clusters |
| rook | ⭐ 13.4k | Go | Storage orchestration operator for Kubernetes - manages Ceph and other storage systems |
| semaphore | ⭐ 13.4k | Go | Modern UI and API for Ansible, Terraform, and other DevOps tools |
| nitter | ⭐ 12.7k | Nim | Privacy-focused Twitter frontend alternative |
| dozzle | ⭐ 12.1k | Go | Real-time Docker/K8s log viewer with web UI for container monitoring and debugging |
| netboot.xyz | ⭐ 11.5k | Jinja | Network-based OS installer and provisioning tool using iPXE |
| whoogle-search | ⭐ 11.4k | Python | Self-hosted ad-free privacy-respecting search engine alternative |
| linkerd2 | ⭐ 11.3k | Go | Lightweight service mesh providing security and observability for Kubernetes |
| terraform-provider-aws | ⭐ 10.8k | Go | Official AWS provider for Terraform infrastructure as code deployments |
| umbrel | ⭐ 10.8k | TypeScript | Self-hosted home server OS with 300+ apps including Bitcoin and cloud storage |
| mRemoteNG | ⭐ 10.7k | C# | Multi-protocol remote connection manager for SSH, RDP, and other protocols |
| skopeo | ⭐ 10.6k | Go | Utility for working with container registries - inspect, copy, and sign images |
| Signal-Server | ⭐ 10.4k | Java | Backend server implementation for Signal encrypted messaging platform |
| linkding | ⭐ 10.4k | Python | Self-hosted bookmark manager for developers and researchers |
| buildkit | ⭐ 9.8k | Go | Advanced Docker builder toolkit with caching and concurrent build capabilities |
| terragrunt | ⭐ 9.4k | Go | Orchestration tool for scaling Terraform/OpenTofu infrastructure as code |
| v2 | ⭐ 8.9k | Go | Minimalist self-hosted RSS feed reader with PostgreSQL backend |
| external-dns | ⭐ 8.9k | Go | Kubernetes controller for automatically managing DNS records from ingress resources |
| autoscaler | ⭐ 8.8k | Go | Kubernetes autoscaling components for dynamic resource management |
| Virtual-Display-Driver | ⭐ 8.7k | C++ | Virtual display driver for Windows - useful for VR, streaming, and remote desktop setups |
| buildah | ⭐ 8.7k | Go | Tool for building OCI container images without Docker daemon - rootless builds |
| anteon | ⭐ 8.5k | Go | eBPF-based Kubernetes monitoring and performance testing platform |
| NETworkManager | ⭐ 8.1k | C# | Network management GUI tool with port scanning, monitoring, and troubleshooting |
| flux2 | ⭐ 8.0k | Go | GitOps continuous delivery platform for Kubernetes with Helm and Kustomize support |
| tubearchivist | ⭐ 7.7k | Python | Self-hosted YouTube media server for content archiving and management |
| podman-desktop | ⭐ 7.4k | TypeScript | Desktop GUI for managing containers and Kubernetes - developer-friendly Docker alternative |
| homarr | ⭐ 7.1k | TypeScript | Customizable homeserver dashboard for managing Docker containers and services |
| mac-dev-playbook | ⭐ 6.9k | Shell | Ansible playbook for automated Mac developer environment setup |
| k3d | ⭐ 6.3k | Go | Helper tool to run k3s Kubernetes clusters in Docker containers |
| Prowlarr | ⭐ 6.3k | C# | Indexer manager/proxy for torrent trackers and Usenet integration |
| k0s | ⭐ 5.8k | Go | Zero friction Kubernetes distribution for simplified cluster deployment |
| Cosmos-Server | ⭐ 5.8k | JavaScript | Secure self-hosted server platform with built-in authentication and DDoS protection |
| Organizr | ⭐ 5.7k | PHP | Homelab services dashboard organizer with service management interface |
| webmin | ⭐ 5.7k | HTML | Web-based server management control panel for system administration |
| guide | ⭐ 5.7k | — | Cost-effective Kubernetes cluster setup guide for hobbyists and small-scale |
| cloud-hypervisor | ⭐ 5.4k | Rust | Security-focused hypervisor for modern cloud workloads written in Rust |
| cinnamon | ⭐ 5.4k | JavaScript | Linux desktop environment with traditional layout and modern features |
| libreddit | ⭐ 5.2k | Rust | Privacy-focused Reddit frontend for secure browsing |
| raspap-webgui | ⭐ 5.2k | PHP | Full-featured wireless router web interface for Raspberry Pi and Debian devices |
| mimir | ⭐ 5.0k | Go | Scalable long-term storage backend for Prometheus metrics and observability data |
| diun | ⭐ 4.5k | Go | Docker registry monitoring tool for automated update notifications |
| JimsGarage | ⭐ 4.5k | Shell | Collection of homelab configuration files and scripts for self-hosting enthusiasts |
| kvm | ⭐ 4.5k | C | Remote KVM solution for controlling computers over network connections |
| caddy-docker-proxy | ⭐ 4.4k | Go | Caddy web server configured as reverse proxy for Docker containers |
| unifios-utilities | ⭐ 4.3k | Shell | UniFi Dream Machine utilities for enhanced network management and security tools |
| docker-webtop | ⭐ 4.1k | Shell | Containerized Linux desktop environments accessible through web browsers |
| Tdarr | ⭐ 4.0k | Makefile | Distributed video/audio transcoding automation with health checking |
| warehouse | ⭐ 4.0k | Python | Official Python Package Index (PyPI) warehouse implementation |
| nut | ⭐ 3.9k | C | Network UPS management tools for monitoring and controlling power systems |
| chartmuseum | ⭐ 3.8k | Go | Helm chart repository server for managing Kubernetes application packages |
| yarr | ⭐ 3.8k | Go | Lightweight self-hosted RSS reader for personal content management |
| feedbin | ⭐ 3.7k | Ruby | Web-based RSS reader platform for content aggregation and management |
| composerize | ⭐ 3.7k | JavaScript | Converts docker run commands to docker-compose format for easier management |
| ansible-nas | ⭐ 3.7k | Jinja | Ansible playbook for building full-featured home server and NAS systems |
| docker-swag | ⭐ 3.6k | Dockerfile | Nginx reverse proxy with Let's Encrypt and fail2ban intrusion prevention |
| unikraft | ⭐ 3.5k | C | Cloud-native unikernel for high-performance, secure microservices |
| docker-volume-backup | ⭐ 3.4k | Go | Backup Docker volumes to S3, WebDAV, Azure, Dropbox, and other storage |
| dashdot | ⭐ 3.4k | TypeScript | Modern server dashboard for monitoring system resources and services |
| ContainerSSH | ⭐ 3.0k | Go | On-demand container launcher over SSH for development and testing |
| ddns-updater | ⭐ 2.9k | Go | Containerized dynamic DNS updater with web UI for multiple providers |
| selfhosted-apps-docker | ⭐ 2.8k | Shell | Guide for self-hosting applications with Docker examples |
| portainer-templates | ⭐ 2.8k | Python | Curated collection of 500+ one-click Portainer application templates |
| home-ops | ⭐ 2.8k | YAML | Complete GitOps homelab setup with Kubernetes, Flux, and infrastructure automation |
| cluster-template | ⭐ 2.7k | YAML | Complete Kubernetes cluster template with Talos, Flux GitOps, and security best practices |
| PacketSender | ⭐ 2.6k | C++ | Cross-platform network utility for sending/receiving TCP, UDP, SSL, HTTP packets |
| cloudflare-ddns | ⭐ 2.4k | Go | Feature-rich Cloudflare DDNS updater with Docker support |
| awesome-cloud-native | ⭐ 2.4k | HTML | Curated cloud native tools and tutorials for modern infrastructure |
| ansible-role-docker | ⭐ 2.2k | — | Ansible role for automated Docker installation and configuration |
| borgmatic | ⭐ 2.2k | Python | Configuration-driven backup automation for servers with deduplication and monitoring |
| unmanic | ⭐ 2.2k | Python | Media library optimization tool for automated file conversion and management |
| AutomatedLab | ⭐ 2.2k | PowerShell | PowerShell framework for automated Windows/Linux lab deployment on HyperV/Azure |
| hub | ⭐ 2.0k | TypeScript | Cloud Native package discovery and management platform for Kubernetes ecosystem |
| Maintainerr | ⭐ 1.8k | TypeScript | Library maintenance tool for Plex and Jellyfin media servers |
| launchpad | ⭐ 1.7k | Dockerfile | HomeLab automation collection with Docker, Kubernetes, and Ansible templates |
| docker-mods | ⭐ 1.5k | — | Documentation and examples for modifying LinuxServer base containers |
| harbor-helm | ⭐ 1.5k | Mustache | Official Helm chart for deploying Harbor container registry on Kubernetes |
| nebula-sync | ⭐ 1.4k | Go | Synchronization tool for managing multiple Pi-hole DNS instances across networks |
| stash | ⭐ 1.4k | Go | Kubernetes stateful application backup solution using Restic |
| PeaNUT | ⭐ 1.4k | TypeScript | Network UPS monitoring dashboard for infrastructure management |
| docker-pihole-unbound | ⭐ 1.3k | Shell | Docker setup for Pi-Hole DNS blocking with Unbound recursive DNS |
| mash-playbook | ⭐ 1.0k | Python | Comprehensive Ansible playbook for self-hosting multiple services |
| SoftRF | ⭐ 963 | C | Multi-platform aviation proximity awareness system for DIY aircraft tracking |
| volsync | ⭐ 947 | Go | Kubernetes operator for asynchronous data replication and disaster recovery |
| goaccess-for-nginxproxymanager | ⭐ 691 | Shell | GoAccess analytics Docker image specifically for Nginx Proxy Manager logs |
| Pulsarr | ⭐ 627 | TypeScript | Real-time Plex watchlist monitoring with automated media library management |
| traefik-kop | ⭐ 462 | Go | Dynamic service discovery agent for Docker containers with Traefik and Redis |
| docker-kasm | ⭐ 451 | Shell | Containerized Kasm Workspaces for browser-based virtual desktop environments |
| nautical-backup | ⭐ 430 | Python | Simple Docker volume backup tool for automated data protection |
| kubelet | ⭐ 401 | Go | Kubelet component configurations for Kubernetes node management |
| ansible_homelab | ⭐ 382 | HCL | Ansible playbooks for automated homelab setup with Docker deployment |
| source-controller | ⭐ 273 | Go | GitOps toolkit for managing source code repositories in Kubernetes deployments |
| community.docker | ⭐ 254 | Python | Ansible collection for Docker container management and orchestration |
| npmGrafStats | ⭐ 203 | Python | Exports Nginx Proxy Manager logs to InfluxDB for Grafana visualization |
| Tool | Stars | Language | Description |
|---|---|---|---|
| free-programming-books | ⭐ 384.4k | Python | Massive collection of free programming books and educational resources |
| cs-video-courses | ⭐ 77.4k | — | Curated list of computer science courses with video lectures covering various topics |
| terraform-best-practices | ⭐ 2.4k | HCL | Comprehensive Terraform best practices ebook translated into multiple languages |
| Tool | Stars | Language | Description |
|---|---|---|---|
| pwntools | ⭐ 13.3k | Python | Popular CTF framework and exploit development library with extensive tooling |
| juice-shop | ⭐ 12.8k | TypeScript | OWASP Juice Shop - intentionally insecure web app for security training and CTFs |
| ctf-tools | ⭐ 9.3k | Shell | Setup scripts for security research and CTF tools collection |
| kubernetes-goat | ⭐ 5.4k | HTML | Vulnerable by design Kubernetes cluster for hands-on security training |
| stego-toolkit | ⭐ 2.6k | Shell | Collection of steganography tools for CTF challenges |
| f8x | ⭐ 2.1k | Shell | Red/blue team environment automation deployment tool |
| CTFCrackTools | ⭐ 2.1k | Rust | Next-generation CTF Swiss Army Knife with visual workflow |
| ToolsFx | ⭐ 2.0k | Kotlin | Cross-platform crypto toolbox for CTF and cryptography challenges |
| resources | ⭐ 1.8k | — | General collection of CTF information, tools, and tips |
| ctftool | ⭐ 1.7k | C | Interactive CTF exploration tool for reverse engineering |
| Name-That-Hash | ⭐ 1.6k | Python | Hash identification tool for CTF and security research |
| CaptfEncoder | ⭐ 1.3k | JavaScript | Cross-platform network security tool suite for CTF and crypto |
| Tool | Stars | Language | Description |
|---|---|---|---|
| mdBook | ⭐ 21.4k | Rust | Generate technical books from markdown files, Rust-based Gitbook alternative |
| awesome-readme | ⭐ 20.6k | — | Examples of excellent README documentation for projects |
| Badges4-README.md-Profile | ⭐ 13.0k | Markdown | Badge collection for improving GitHub profile documentation |
| jekyll-theme-chirpy | ⭐ 9.9k | HTML | Responsive Jekyll theme optimized for technical writing and documentation |
| webauthn | ⭐ 1.4k | HTML | W3C Web Authentication API specification for public key credential access |
| Tool | Stars | Language | Description |
|---|---|---|---|
| awesome | ⭐ 447.7k | — | Meta collection of awesome lists covering all tech topics |
| awesome-python | ⭐ 288.4k | Python | Comprehensive list of Python frameworks, libraries and development resources |
| awesome-selfhosted | ⭐ 281.4k | — | Comprehensive list of self-hostable network services and web applications |
| Python | ⭐ 219.1k | Python | Educational algorithm implementations for computer science and interview preparation |
| awesome-go | ⭐ 168.0k | Go | Curated list of Go frameworks, libraries and development resources |
| Awesome-Hacking | ⭐ 109.3k | — | Curated collection of hacking and penetration testing resources |
| awesome-mac | ⭐ 100.6k | JavaScript | Comprehensive collection of high-quality macOS software and tools |
| open-source-mac-os-apps | ⭐ 48.0k | — | Curated list of open source macOS applications for developers |
| awesome-docker | ⭐ 35.7k | Makefile | Comprehensive list of Docker resources, tools and projects |
| awesome-claude-code | ⭐ 33.8k | Python | Curated list of Claude Code skills, hooks, and agent orchestration resources |
| awesome-sysadmin | ⭐ 33.3k | — | Curated collection of open-source system administration tools and resources |
| CheatSheetSeries | ⭐ 31.6k | Python | OWASP cheat sheets covering essential application security topics and best practices |
| SpringAll | ⭐ 29.0k | Java | Comprehensive Spring framework learning resources with security components |
| awesome-falsehood | ⭐ 27.2k | — | Educational resource about programming pitfalls and common misconceptions |
| awesome-osint | ⭐ 25.4k | — | Comprehensive curated list of Open Source Intelligence (OSINT) tools and resources |
| API-Security-Checklist | ⭐ 23.2k | — | Essential security checklist for API design, testing, and deployment |
| awesome-tunneling | ⭐ 20.6k | — | Curated list of tunneling and self-hosted networking alternatives to ngrok |
| awesome-privacy | ⭐ 18.3k | — | Curated list of privacy-respecting services and alternatives |
| awesome-hacking | ⭐ 16.0k | — | General hacking tutorials, tools and educational security resources |
| awesome-security | ⭐ 14.1k | — | Comprehensive collection of security tools, resources, and documentation |
| awesome-malware-analysis | ⭐ 13.5k | — | Malware analysis tools, frameworks and threat intelligence resources |
| awesome-web-security | ⭐ 13.2k | — | Curated web security materials and penetration testing resources |
| GTFOBins.github.io | ⭐ 12.8k | YAML | Curated list of Unix binaries for bypassing security restrictions and privilege escalation |
| hacktricks | ⭐ 11.1k | CSS | Comprehensive wiki of hacking techniques, CTF tricks, and pentesting knowledge |
| awesome-threat-intelligence | ⭐ 10.0k | — | Curated collection of threat intelligence resources and tools |
| devops-resources | ⭐ 9.5k | Groovy | Comprehensive DevOps resources covering cloud, containers, and security |
| awesome-privacy | ⭐ 9.1k | Astro | Comprehensive curated list of privacy and security-focused tools and services |
| wstg | ⭐ 9.0k | — | OWASP's comprehensive guide to testing web application and service security |
| awesome-incident-response | ⭐ 8.9k | — | Incident response tools and DFIR resources for security operations teams |
| awesome-home-assistant | ⭐ 7.5k | Shell | Curated Home Assistant resources for IoT and smart home development |
| awesome-appsec | ⭐ 6.9k | PHP | Curated collection of application security learning resources and references |
| awesome-web-hacking | ⭐ 6.8k | — | Curated list of web application security resources and hacking tools |
| DevSecOps | ⭐ 6.7k | — | Ultimate DevSecOps resource library and tool collection |
| Awesome-Fuzzing | ⭐ 5.8k | — | Comprehensive fuzzing learning resources and vulnerability research guide |
| Top10 | ⭐ 5.4k | HTML | Official OWASP Top 10 security risks documentation for web applications |
| awesome-uses | ⭐ 5.2k | JavaScript | Curated list of developer setups and configurations for workspace optimization |
| awesome-cybersecurity-blueteam | ⭐ 5.2k | — | Comprehensive blue team cybersecurity resources and defensive security tools |
| WebHackersWeapons | ⭐ 4.5k | Ruby | Curated collection of web hacking tools and resources for bug bounty |
| awesome-threat-detection | ⭐ 4.5k | — | Curated list of threat detection and hunting resources for security analysts |
| awesome-newsletters | ⭐ 4.3k | — | Tech newsletters for staying updated on industry developments |
| awesome-devops | ⭐ 4.0k | Python | Curated DevOps tools, platforms, and best practices resource collection |
| privacyguides.org | ⭐ 3.9k | Markdown | Privacy and security guidance resource for protection against surveillance |
| Pentest-Cheat-Sheets | ⭐ 2.9k | Shell | Penetration testing command reference and code snippet collection |
| awesome-game-security | ⭐ 2.8k | Python | Game security resources covering anti-cheat, reverse engineering, and protection |
| Awesome-Telegram-OSINT | ⭐ 2.6k | — | Curated resources for Telegram-focused OSINT investigations |
| hackingthe.cloud | ⭐ 2.6k | Dockerfile | Encyclopedia of offensive and defensive cloud security techniques and knowledge |
| BurpSuite-For-Pentester | ⭐ 2.5k | — | Comprehensive BurpSuite cheatsheet for bug bounty hunters and pentesters |
| FBI-tools | ⭐ 2.4k | — | Curated collection of OSINT and digital forensics tools |
| awesome-engineering-team-management | ⭐ 2.4k | — | Engineering management transition guide for developers moving to leadership roles |
| hacking-resources | ⭐ 2.4k | — | Comprehensive hacking resources and cheat sheets for offensive/defensive security |
| awesome-iam | ⭐ 2.2k | — | Comprehensive identity and access management knowledge base for cloud security |
| awesome-lockpicking | ⭐ 1.8k | — | Physical security resources covering lockpicking and lock bypass techniques |
| awesome-soc | ⭐ 1.7k | — | Curated knowledge base for building and running Security Operations Centers |
| secure-ios-app-dev | ⭐ 1.4k | — | Collection of common iOS app vulnerabilities for security assessment reference |
| The-Hacker-Recipes | ⭐ 1.0k | — | Comprehensive technical guides and documentation for cybersecurity practitioners |
| Linux-Privilege-Escalation | ⭐ 870 | — | Linux privilege escalation cheatsheet for OSCP and CTF preparation |
| hacktricks-cloud | ⭐ 738 | CSS | Cloud-focused security knowledge base and penetration testing guide |
| thgtoa | ⭐ 680 | — | Comprehensive guide for online anonymity, OpSec, and privacy practices |
| awesome-software-supply-chain-security | ⭐ 350 | — | Comprehensive resource compilation for supply chain security |
| wiki | ⭐ 321 | — | Community wiki dedicated to digital forensics knowledge and techniques |
| Tool | Stars | Language | Description |
|---|---|---|---|
| build-your-own-x | ⭐ 482.2k | Markdown | Hands-on tutorials for recreating popular technologies from scratch |
| freeCodeCamp | ⭐ 439.0k | TypeScript | Comprehensive free coding curriculum and learning platform for programming fundamentals |
| Reverse-Engineering | ⭐ 13.4k | Assembly | Comprehensive reverse engineering tutorial covering multiple architectures |
| security-study-plan | ⭐ 4.9k | — | Comprehensive cybersecurity career study plans for various security roles |
| OSCE3-Complete-Guide | ⭐ 3.8k | — | Complete study guide for OSCE3 certification tracks (OSWE, OSEP, OSED, OSEE) |
| Fuzzing101 | ⭐ 3.7k | — | Step-by-step fuzzing tutorial covering AFL, fuzzilli and other fuzzing techniques |
| cloudgoat | ⭐ 3.5k | Python | Vulnerable AWS environment deployment tool for cloud security training |
| mutillidae | ⭐ 1.5k | PHP | Deliberately vulnerable web application for security training |
These projects have not been updated in over 2 years. They may still be useful but should be evaluated carefully.
| Tool | Stars | Last Updated | Note |
|---|---|---|---|
| awesome-termux-hacking | ⭐ 4.5k | 2026-03-29 | Curated list of Termux-based hacking and OSINT tools |
| nexfil | ⭐ 2.5k | 2026-03-28 | Fast username enumeration across multiple social platforms |
| windows-privesc-check | ⭐ 1.5k | 2026-03-29 | Windows privilege escalation checker identifying common attack vectors |
| bane | ⭐ 1.2k | 2026-03-01 | Custom AppArmor profile generator for enhanced Docker container security |
| log4j2burpscanner | ⭐ 840 | 2026-03-05 | BurpSuite extension for detecting CVE-2021-44228 Log4j2 vulnerabilities |
| HellRaiser | ⭐ 573 | 2026-03-19 | Nmap-based vulnerability scanner correlating CPEs with CVE database |
These projects are no longer actively maintained.
| Tool | Stars | Note |
|---|---|---|
| chatgpt-mac | ⭐ 6.3k | MenuBar ChatGPT client for quick AI access on macOS |
| PyRIT | ⭐ 3.6k | Risk identification framework for red teaming and testing generative AI systems |
| fhe-toolkit-linux | ⭐ 1.5k | IBM homomorphic encryption toolkit for secure computation on encrypted data |
| overseerr | ⭐ 5.0k | Request management and media discovery tool for Plex ecosystem |
| blackmagic | ⭐ 3.7k | In-application debugger for ARM Cortex and RISC-V processor development |
| datree | ⭐ 6.3k | Kubernetes policy enforcement to prevent misconfigurations in production |
| terrascan | ⭐ 5.2k | Multi-cloud IaC security scanner for compliance and vulnerability detection |
| runtime | ⭐ 2.1k | Kata Containers v1.x runtime for secure container virtualization |
| twint | ⭐ 16.4k | Advanced Twitter OSINT tool for scraping user data without API limits |
| gitrob | ⭐ 6.1k | GitHub organization reconnaissance tool for security assessment |
| aquatone | ⭐ 5.9k | Domain reconnaissance tool with headless Chrome for flyovers |
| xray | ⭐ 2.3k | Network reconnaissance and OSINT gathering tool with Shodan integration |
| PrintSpoofer | ⭐ 2.2k | Windows privilege escalation tool exploiting Print Spooler service impersonation |
| DumpsterDiver | ⭐ 1.0k | Secret discovery tool for scanning various file types for sensitive data |
| exitmap | ⭐ 460 | Fast modular scanner specifically designed for Tor exit relays |
| Pentest-Tools-Framework | ⭐ 459 | Comprehensive pentest framework with exploits, scanners, and tools |
| awesome-linux | ⭐ 4.9k | Linux projects and resources for system administration |
| ssc-reading-list | ⭐ 365 | Curated reading list for software supply-chain security topics |
The Vault is fully automated — no manual curation needed after initial setup.
Every Sunday 8AM UTC
└─ GitHub Actions workflow runs
├─ Discovers new repos (GitHub topic search + starred repos)
├─ Deduplicates against existing tools.json
├─ Categorizes new finds via Claude API
├─ Refreshes star counts & flags archived repos
├─ Generates this README from tools.json
├─ Commits & pushes to this repo
└─ Triggers Vercel redeploy of blacktemple.net
└─ Prebuild fetches latest tools.json
└─ blacktemple.net/vault shows fresh data
| Component | Description |
|---|---|
| Discovery | Searches GitHub API across 30 security/AI/dev topic queries (≥500 stars), plus syncs starred repos (≥250 stars) |
| Deduplication | Checks against existing tools.json by repo full name |
| Quality gate | Star thresholds filter out unvetted repos: 500+ for search, 250+ for starred, 200+ for existing |
| Categorization | Claude API (claude-sonnet-4-20250514) assigns category, subcategory, and editorial note |
| Metadata refresh | Rotates through 1/4 of all tools per run, updating star counts, archived/stale status, and pruning sub-threshold entries |
| Rate limiting | 15s between Claude API batches, 60s backoff + retry on 429s, 3s between GitHub search calls |
| Website sync | Vercel deploy hook triggers rebuild; prebuild fetches tools.json from this repo |
Each entry in tools.json:
{
"name": "hashcat",
"repo": "hashcat/hashcat",
"url": "https://github.com/hashcat/hashcat",
"description": "World's fastest password recovery utility",
"category": "offensive-security",
"subcategory": "password-cracking",
"language": "C",
"stars": 25618,
"note": "GPU-accelerated, supports 300+ hash types",
"added": "2026-03-21",
"updated": "2026-03-22",
"status": "active"
}| Category | Scope |
|---|---|
| 🗡️ Offensive Security | Recon, exploitation, password cracking, web testing, red team, reverse engineering |
| 🛡️ Defensive Security | SIEM, WAF, forensics, malware analysis, threat intel, compliance |
| 🔧 DevSecOps | SAST/DAST/SCA, container & cloud security, supply chain, secrets management |
| 🤖 AI & Agents | Coding agents, LLM tools, AI frameworks, prompt engineering, AI security |
| 💻 Development | CLI tools, frameworks, infrastructure, databases, editors |
| 📚 Research & Learning | CTF platforms, training, knowledge bases, documentation |
This list is maintained by @defconxt and updated weekly via automated pipeline.
Suggestions? Open an issue or submit a PR adding entries to tools.json.
CC0 1.0 Universal — see LICENSE