Top Security repositories on GitHub
Offensive and defensive security tools and libraries.
Ranked by stars across 4,955 repositories tagged security. Refreshed daily.
- 1trimstray/the-book-of-secret-knowledge★ 219,052 · ⑂ 13,146
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
- awesome
- awesome-list
- lists
- manuals
- resources
- howtos
- 2Hack-with-Github/Awesome-Hacking★ 111,743 · ⑂ 10,254
A collection of various awesome lists for hackers, pentesters and security researchers
- hacking
- security
- bug-bounty
- awesome
- android
- fuzzing
- 3Developer-Y/cs-video-courses★ 81,033 · ⑂ 11,213
List of Computer Science courses with video lectures.
- computer-science
- algorithms
- systems
- databases
- machine-learning
- web-development
- 4swisskyrepo/PayloadsAllTheThings★ 77,518 · ⑂ 16,934
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
- pentest
- payload
- bypass
- web-application
- hacking
- vulnerability
- 5caddyserver/caddy★ 72,135 · ⑂ 4,714
Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS
- go
- web-server
- caddyfile
- http
- http-server
- reverse-proxy
- 6x64dbg/x64dbg★ 48,293 · ⑂ 2,727
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
- debugger
- windows
- x64
- disassembler
- reverse-engineering
- security
- 7mitmproxy/mitmproxy★ 43,430 · ⑂ 4,548
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
- python
- security
- man-in-the-middle
- tls
- ssl
- http
- 8QuivrHQ/quivr★ 39,134 · ⑂ 3,752
Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.
- ai
- llm
- api
- chatbot
- chatgpt
- database
- 9GyulyVGC/sniffnet★ 37,278 · ⑂ 1,499
Comfortably monitor your Internet traffic 🕵️♂️
- network-analysis
- networking
- packet-sniffer
- rust-crate
- linux
- macos
- 10aquasecurity/trivy★ 34,879 · ⑂ 348
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
- security
- security-tools
- docker
- containers
- vulnerability-scanners
- vulnerability-detection
- 11Lissy93/web-check★ 33,023 · ⑂ 2,664
🕵️♂️ All-in-one OSINT tool for analysing any website
- osint
- privacy
- security
- security-tools
- sysadmin
- 12OWASP/CheatSheetSeries★ 31,932 · ⑂ 4,440
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
- owasp
- code
- security
- cheatsheets
- best-practices
- appsec
- 13StevenBlack/hosts★ 30,315 · ⑂ 2,409
🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.
- python
- unified-hosts
- malware
- ad-blocker
- porn-filter
- social-media-filter
- 14trailofbits/algo★ 30,216 · ⑂ 2,363
Set up a personal VPN in the cloud
- vpn-server
- strongswan
- ansible
- vpn
- ikev2
- security
- 15nginx/nginx★ 30,195 · ⑂ 7,886
The official NGINX Open Source repository.
- content-cache
- load-balancer
- reverse-proxy
- web-server
- http
- https
- 16digitalocean/nginxconfig.io★ 28,308 · ⑂ 2,060
⚙️ NGINX config generator on steroids 💉
- nginx
- nginx-configuration
- php-fpm
- ssl
- letsencrypt
- cdn
- 17projectdiscovery/nuclei★ 28,249 · ⑂ 3,387
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
- cve-scanner
- subdomain-takeover
- nuclei-engine
- vulnerability-detection
- vulnerability-assessment
- vulnerability-scanner
- 18community-scripts/ProxmoxVE★ 27,926 · ⑂ 2,666
Proxmox VE Helper-Scripts (Community Edition)
- home-assistant
- home-automation
- homelab
- homelab-setup
- lxc
- proxmox
- 19hwdsl2/setup-ipsec-vpn★ 27,774 · ⑂ 6,514
Set up your own IPsec VPN server in just a few minutes, with IPsec/L2TP, Cisco IPsec and IKEv2. Supports Ubuntu, Debian, CentOS/RHEL, Amazon Linux, Alpine and Raspberry Pi. Includes client config and management scripts.
- vpn
- ipsec
- l2tp
- ikev2
- security
- vpn-server
- 20authelia/authelia★ 27,716 · ⑂ 1,396
The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™
- totp
- ldap
- sso-authentication
- yubikey
- two-factor-authentication
- docker
- 21OpenZeppelin/openzeppelin-contracts★ 27,088 · ⑂ 12,408
OpenZeppelin Contracts is a library for secure smart contract development.
- ethereum
- solidity
- evm
- security
- smart-contracts
- 22keepassxreboot/keepassxc★ 26,992 · ⑂ 1,781
KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.
- keepassxc
- keepass
- password-manager
- linux
- windows
- cross-platform
- 23Infisical/infisical★ 26,661 · ⑂ 1,867
Infisical is the open-source platform for secrets, certificates, and privileged access management.
- cli
- environment-variables
- secret-management
- secrets
- security
- open-source
- 24gitleaks/gitleaks★ 26,615 · ⑂ 2,021
Find secrets with Gitleaks 🔑
- security
- security-tools
- git
- golang
- go
- secret
- 25trufflesecurity/trufflehog★ 26,068 · ⑂ 2,371
Find, verify, and analyze leaked credentials
- secret
- trufflehog
- credentials
- security
- devsecops
- dynamic-analysis
Find engineers shipping Security
The list above ranks the most-starred public repositories tagged with the Security topic, drawn from the public GitHub graph. Across 4,955 repositories tagged this way, the maintainers and top contributors are a tight cluster of the people actually building Security.
Looking for engineers who’ve worked on Security for real, not just listed it on LinkedIn? The fastest path is the contributor list of these repos. Their commits, issues, and READMEs are public proof of depth.
Refolk turns this list into a search. Ask for “maintainers of top Security repos who are hiring”, “Security engineers in San Francisco”, or “founders shipping Security” and Refolk returns a ranked shortlist with sources.
How this list is built
Last refreshed: Thu, 07 May 2026 05:54:55 GMT
Need a list like this for any search?
Refolk runs natural-language searches across GitHub, LinkedIn, and the open web. Try one of these:
Browse other topics
- Top Embeddings repos
- Top RAG repos
- Top GraphQL repos
- Top Docker repos
- Top LLM repos
- Top Speech recognition repos
- Top REST APIs repos
- Top Computer vision repos
See all repository lists.