Refolk

Top Python Security repositories on GitHub

Offensive and defensive security tools and libraries. Filtered to projects whose primary language is Python.

Ranked by stars across 1,474 Python repositories tagged security. Refreshed daily.

  1. 1
    swisskyrepo/PayloadsAllTheThings77,519 · ⑂ 16,934

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    • pentest
    • payload
    • bypass
    • web-application
    • hacking
    • vulnerability
  2. 2
    mitmproxy/mitmproxy43,430 · ⑂ 4,548

    An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

    • python
    • security
    • man-in-the-middle
    • tls
    • ssl
    • http
  3. 3
    QuivrHQ/quivr39,133 · ⑂ 3,752

    Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.

    • ai
    • llm
    • api
    • chatbot
    • chatgpt
    • database
  4. 4
    OWASP/CheatSheetSeries31,931 · ⑂ 4,440

    The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

    • owasp
    • code
    • security
    • cheatsheets
    • best-practices
    • appsec
  5. 5
    StevenBlack/hosts30,316 · ⑂ 2,409

    🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

    • python
    • unified-hosts
    • malware
    • ad-blocker
    • porn-filter
    • social-media-filter
  6. 6
    trailofbits/algo30,216 · ⑂ 2,363

    Set up a personal VPN in the cloud

    • vpn-server
    • strongswan
    • ansible
    • vpn
    • ikev2
    • security
  7. 7
    goauthentik/authentik21,350 · ⑂ 1,587

    The authentication glue you need.

    • saml
    • saml-idp
    • saml-sp
    • oauth2
    • oauth2-server
    • oauth2-client
  8. 8
    eosphoros-ai/DB-GPT18,677 · ⑂ 2,677

    open-source agentic AI data assistant for the next generation of AI + Data products.

    • database
    • gpt-4
    • vicuna
    • private
    • security
    • llm
  9. 9
    fail2ban/fail2ban17,712 · ⑂ 1,475

    Daemon to ban hosts that cause multiple authentication errors

    • linux
    • macos
    • security
    • intrusion-prevention
    • fail2ban
    • bsd
  10. 10
    wifiphisher/wifiphisher14,571 · ⑂ 2,728

    The Rogue Access Point Framework

    • wifiphisher
    • wifi
    • rogue
    • access-point
    • python
    • security
  11. 11
    maurosoria/dirsearch14,242 · ⑂ 2,433

    Web path scanner

    • fuzzer
    • fuzzing
    • python
    • security
    • dirsearch
    • hacking
  12. 12
    prowler-cloud/prowler13,748 · ⑂ 2,118

    Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

    • security
    • security-tools
    • security-audit
    • security-hardening
    • hardening
    • aws
  13. 13
    evilsocket/opensnitch13,588 · ⑂ 628

    OpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch.

    • application-firewall
    • firewall
    • linux
    • networking
    • security
    • data-breach
  14. 14
    threat9/routersploit13,105 · ⑂ 2,393

    Exploitation Framework for Embedded Devices

    • python
    • security
    • infosec
    • router-exploitation-framework
    • routersploit-framework
    • exploits
  15. 15
    jopohl/urh12,394 · ⑂ 1,000

    Universal Radio Hacker: Investigate Wireless Protocols Like A Boss

    • security
    • wireless
    • iot
    • hacking
    • hackrf
    • rtl-sdr
  16. 16
    mvt-project/mvt12,378 · ⑂ 1,209

    MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

    • forensics
    • mobile
    • security
    • android
    • ios
    • forensics-tools
  17. 17
    secdev/scapy12,270 · ⑂ 2,210

    Scapy: the Python-based interactive packet manipulation program & library.

    • scapy
    • python
    • network
    • network-analysis
    • network-visualization
    • network-discovery
  18. 18
    bunkerity/bunkerweb10,450 · ⑂ 603

    🛡️ Open-source and cloud-native Web Application Firewall (WAF)

    • nginx
    • modsecurity
    • docker
    • security
    • dnsbl
    • reverse-proxy
  19. 19
    SigmaHQ/sigma10,409 · ⑂ 2,607

    Main Sigma Rule Repository

    • security
    • monitoring
    • siem
    • logging
    • signatures
    • elasticsearch
  20. 20
    frappe/frappe10,048 · ⑂ 4,903

    Low code web framework for real world applications, in Python and Javascript

    • frappe
    • erpnext
    • python
    • javascript
    • web-framework
    • full-stack
  21. 21
    sensepost/objection9,075 · ⑂ 969

    📱 objection - runtime mobile exploration

    • mobile
    • pentest
    • framework
    • ios
    • instrumentation
    • frida
  22. 22
    mailpile/Mailpile8,844 · ⑂ 1,012

    A free & open modern, fast email client with user-friendly encryption and privacy features

    • e-mail
    • security
    • pgp
    • search-engine
    • tags
    • imap-client
  23. 23
    jofpin/trape8,664 · ⑂ 1,342

    People tracker on the Internet: OSINT analysis and research tool by Jose Pino

    • tracking
    • osint
    • footprint
    • hacking-tool
    • recognition
    • phising
  24. 24
    stamparm/maltrail8,429 · ⑂ 1,253

    Malicious traffic detection system

    • security
    • malware
    • intrusion-detection
    • sensor
    • python
    • network-monitoring
  25. 25
    PyCQA/bandit8,002 · ⑂ 756

    Bandit is a tool designed to find common security issues in Python code.

    • linter
    • bandit
    • security-tools
    • security-scanner
    • security
    • static-code-analysis

Find Python engineers shipping Security

The list above ranks the most-starred public Python repositories tagged with the Security topic, drawn from the public GitHub graph. Across 1,474 matching repositories, the contributors are a tight cluster of engineers with both Python chops and real Security experience.

That overlap is rare. Most Python engineers haven’t shipped Security, and most Security maintainers don’t write Python. The people on this list’s contributor graph are the ones who do both.

Refolk turns this list into a search. Ask for Python Security maintainers hiring” or Python engineers shipping Security in 2025” and Refolk returns a ranked shortlist with the commits, profiles, and projects behind each name.

How this list is built

Refolk searched GitHub for public Python repositories tagged with the Security topic, ranked them by stargazer count, and kept those with at least 25 stars. The list refreshes once a day.

Last refreshed: Thu, 07 May 2026 06:52:14 GMT

Need a more specific search?

Refolk runs natural-language searches across GitHub, LinkedIn, and the open web. Try one of these:

Related lists

See all repository lists.

Or zoom out