Refolk

Top Python Security repositories on GitHub

Offensive and defensive security tools and libraries. Filtered to projects whose primary language is Python.

Ranked by stars across 1,653 Python repositories tagged security. Refreshed daily.

  1. 1
    swisskyrepo/PayloadsAllTheThings80,987 · ⑂ 17,384

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    • pentest
    • payload
    • bypass
    • web-application
    • hacking
    • vulnerability
  2. 2
    usestrix/strix63,757 · ⑂ 6,975

    Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

    • agents
    • artificial-intelligence
    • cybersecurity
    • penetration-testing
    • ai-penetration-testing
    • ai-pentesting
  3. 3
    mitmproxy/mitmproxy45,097 · ⑂ 4,736

    An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

    • python
    • security
    • man-in-the-middle
    • tls
    • ssl
    • http
  4. 4
    The-Vibe-Company/quivr39,543 · ⑂ 3,731

    Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.

    • ai
    • llm
    • api
    • chatbot
    • chatgpt
    • database
  5. Live search

    Find the people behind these repos

    Stars rank the projects. I can rank the engineers - maintainers, top contributors, and the people they work with. Fire one of these to see how it works.

    500 free credits on sign-up, no card needed.

  6. 5
    OWASP/CheatSheetSeries33,228 · ⑂ 4,628

    The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

    • owasp
    • code
    • security
    • cheatsheets
    • best-practices
    • appsec
  7. 6

    817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

    • ai-agents
    • claude-code
    • cybersecurity
    • incident-response
    • mitre-attack
    • penetration-testing
  8. 7
    StevenBlack/hosts31,081 · ⑂ 2,441

    🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

    • python
    • unified-hosts
    • malware
    • ad-blocker
    • porn-filter
    • social-media-filter
  9. 8
    trailofbits/algo30,388 · ⑂ 2,366

    Set up a personal VPN in the cloud

    • vpn-server
    • strongswan
    • ansible
    • vpn
    • ikev2
    • security
  10. 9
    goauthentik/authentik25,648 · ⑂ 2,030

    The authentication glue you need.

    • saml
    • saml-idp
    • saml-sp
    • oauth2
    • oauth2-server
    • oauth2-client
  11. 10
    eosphoros-ai/DB-GPT20,016 · ⑂ 2,936

    open-source agentic AI data assistant for the next generation of AI + Data products.

    • database
    • gpt-4
    • vicuna
    • private
    • security
    • llm
  12. Live search

    Who is hiring in this space?

    I read hiring signals across LinkedIn, GitHub, and the open web - so a topic list becomes a warm outreach list. Try one live.

    500 free credits on sign-up, no card needed.

  13. 11
    fail2ban/fail2ban18,656 · ⑂ 1,499

    Daemon to ban hosts that cause multiple authentication errors

    • linux
    • macos
    • security
    • intrusion-prevention
    • fail2ban
    • bsd
  14. 12
    wifiphisher/wifiphisher14,852 · ⑂ 2,744

    The Rogue Access Point Framework

    • wifiphisher
    • wifi
    • rogue
    • access-point
    • python
    • security
  15. 13
    prowler-cloud/prowler14,838 · ⑂ 2,392

    Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

    • security
    • security-tools
    • security-audit
    • security-hardening
    • hardening
    • aws
  16. 14
    maurosoria/dirsearch14,740 · ⑂ 2,441

    Web path scanner

    • fuzzer
    • fuzzing
    • python
    • security
    • dirsearch
    • hacking
  17. 15
    evilsocket/opensnitch14,080 · ⑂ 665

    OpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch.

    • application-firewall
    • firewall
    • linux
    • networking
    • security
    • data-breach
  18. 16
    qazbnm456/awesome-web-security13,812 · ⑂ 1,820

    🐶 A curated list of Web Security materials and resources.

    • awesome-list
    • awesome
    • list
    • web
    • security
    • websecurity
  19. Live search

    Turn any brief into a list like this

    I run natural-language searches across GitHub, LinkedIn, and the open web. Describe who you want and I'll build the shortlist.

    500 free credits on sign-up, no card needed.

  20. 17
    threat9/routersploit13,244 · ⑂ 2,396

    Exploitation Framework for Embedded Devices

    • python
    • security
    • infosec
    • router-exploitation-framework
    • routersploit-framework
    • exploits
  21. 18
    mvt-project/mvt13,134 · ⑂ 1,298

    MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

    • forensics
    • mobile
    • security
    • android
    • ios
    • forensics-tools
  22. 19
    jopohl/urh12,576 · ⑂ 1,051

    Universal Radio Hacker: Investigate Wireless Protocols Like A Boss

    • security
    • wireless
    • iot
    • hacking
    • hackrf
    • rtl-sdr

Find Python engineers shipping Security

The list above ranks the most-starred public Python repositories tagged with the Security topic, drawn from the public GitHub graph. Across 1,653 matching repositories, the contributors are a tight cluster of engineers with both Python chops and real Security experience.

That overlap is rare. Most Python engineers haven’t shipped Security, and most Security maintainers don’t write Python. The people on this list’s contributor graph are the ones who do both.

Refolk turns this list into a search. Ask for Python Security maintainers hiring” or Python engineers shipping Security in 2025” and Refolk returns a ranked shortlist with the commits, profiles, and projects behind each name.

How this list is built

Refolk searched GitHub for public Python repositories tagged with the Security topic, ranked them by stargazer count, and kept those with at least 25 stars. The list refreshes once a day.

Last refreshed: Sun, 20 Sep 2026 07:43:59 GMT

Search this list

Need a more specific search?

Refolk runs natural-language searches across GitHub, LinkedIn, and the open web. Try one of these:

500 free credits on sign-up, no card needed.

Related lists

See all repository lists.

Or zoom out

Common questions

How are these repositories ranked?

By stars, with forks and recent activity as tiebreakers, read from the public GitHub API. The methodology section above has the details.

How fresh is the data?

The ranking re-renders at least daily. Last refreshed: Sun, 20 Sep 2026 07:43:59 GMT.

Can I find the maintainers and contributors behind these repos?

Yes. Stars rank the projects; I can rank the engineers - maintainers, top contributors, and the people they work with. You start with 500 free credits, no card required.

Can I use this list for hiring?

That's the point. I read hiring signals across GitHub, LinkedIn, and the open web, so a repo list turns into a shortlist of engineers worth talking to.

Try it on the search you came here for

Stop building boolean strings. Just describe the person.

Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.

  1. 01Describe them

    One plain sentence. Role, city, stack, stage, whatever matters to you.

  2. 02I read the web live

    GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.

  3. 03You read the shortlist

    Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.

  • No boolean, no filters, no seat to buy. One box.
  • Read at search time, so a profile updated yesterday counts today.
  • Every step visible as it runs, every name with its reason.

500 free credits on sign-up. No card, no demo call. See real searches.

Keep exploring