Refolk

Top Security repositories on GitHub

Offensive and defensive security tools and libraries.

Ranked by stars across 5,336 repositories tagged security. Refreshed daily.

  1. 1

    A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

    • awesome
    • awesome-list
    • lists
    • manuals
    • resources
    • howtos
  2. 2
    Hack-with-Github/Awesome-Hacking120,675 · ⑂ 10,758

    A collection of various awesome lists for hackers, pentesters and security researchers

    • hacking
    • security
    • bug-bounty
    • awesome
    • android
    • fuzzing
  3. 3
    Developer-Y/cs-video-courses83,530 · ⑂ 11,492

    List of Computer Science courses with video lectures.

    • computer-science
    • algorithms
    • systems
    • databases
    • machine-learning
    • web-development
  4. 4
    swisskyrepo/PayloadsAllTheThings80,950 · ⑂ 17,378

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    • pentest
    • payload
    • bypass
    • web-application
    • hacking
    • vulnerability
  5. Live search

    Find the people behind these repos

    Stars rank the projects. I can rank the engineers - maintainers, top contributors, and the people they work with. Fire one of these to see how it works.

    500 free credits on sign-up, no card needed.

  6. 5
    caddyserver/caddy75,837 · ⑂ 4,968

    Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

    • go
    • web-server
    • caddyfile
    • http
    • http-server
    • reverse-proxy
  7. 6
    usestrix/strix63,419 · ⑂ 6,923

    Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

    • agents
    • artificial-intelligence
    • cybersecurity
    • penetration-testing
    • ai-penetration-testing
    • ai-pentesting
  8. 7
    x64dbg/x64dbg49,544 · ⑂ 2,842

    An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

    • debugger
    • windows
    • x64
    • disassembler
    • reverse-engineering
    • security
  9. 8
    KeygraphHQ/shannon48,124 · ⑂ 5,518

    Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

    • penetration-testing
    • pentesting
    • security-audit
    • security-automation
    • security-tools
    • ai-penetration-testing
  10. 9
    mitmproxy/mitmproxy45,083 · ⑂ 4,731

    An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

    • python
    • security
    • man-in-the-middle
    • tls
    • ssl
    • http
  11. 10
    GyulyVGC/sniffnet41,148 · ⑂ 1,959

    Comfortably monitor your network traffic 🕵️‍♂️

    • networking
    • packet-sniffer
    • rust-crate
    • linux
    • macos
    • packet-capture
  12. Live search

    Who is hiring in this space?

    I read hiring signals across LinkedIn, GitHub, and the open web - so a topic list becomes a warm outreach list. Try one live.

    500 free credits on sign-up, no card needed.

  13. 11
    The-Vibe-Company/quivr39,532 · ⑂ 3,731

    Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.

    • ai
    • llm
    • api
    • chatbot
    • chatgpt
    • database
  14. 12
    aquasecurity/trivy37,971 · ⑂ 693

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

    • security
    • security-tools
    • docker
    • containers
    • vulnerability-scanners
    • vulnerability-detection
  15. 13
    lissy93/web-check34,852 · ⑂ 2,859

    🕵️‍♂️ All-in-one OSINT tool for analysing any website

    • osint
    • privacy
    • security
    • security-tools
    • sysadmin
  16. 14
    OWASP/CheatSheetSeries33,206 · ⑂ 4,625

    The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

    • owasp
    • code
    • security
    • cheatsheets
    • best-practices
    • appsec
  17. 15

    817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

    • ai-agents
    • claude-code
    • cybersecurity
    • incident-response
    • mitre-attack
    • penetration-testing
  18. 16
    nginx/nginx31,673 · ⑂ 8,303

    The official NGINX Open Source repository.

    • content-cache
    • load-balancer
    • reverse-proxy
    • web-server
    • http
    • https
  19. Live search

    Turn any brief into a list like this

    I run natural-language searches across GitHub, LinkedIn, and the open web. Describe who you want and I'll build the shortlist.

    500 free credits on sign-up, no card needed.

  20. 17

    An evolving how-to guide for securing a Linux server.

    • linux
    • hardening
    • hardening-steps
    • security
    • security-hardening
    • server
  21. 18
    projectdiscovery/nuclei31,281 · ⑂ 3,874

    Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

    • cve-scanner
    • subdomain-takeover
    • nuclei-engine
    • vulnerability-detection
    • vulnerability-assessment
    • vulnerability-scanner
  22. 19
    StevenBlack/hosts31,071 · ⑂ 2,442

    🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

    • python
    • unified-hosts
    • malware
    • ad-blocker
    • porn-filter
    • social-media-filter

Find engineers shipping Security

The list above ranks the most-starred public repositories tagged with the Security topic, drawn from the public GitHub graph. Across 5,336 repositories tagged this way, the maintainers and top contributors are a tight cluster of the people actually building Security.

Looking for engineers who’ve worked on Security for real, not just listed it on LinkedIn? The fastest path is the contributor list of these repos. Their commits, issues, and READMEs are public proof of depth.

Refolk turns this list into a search. Ask for “maintainers of top Security repos who are hiring”, Security engineers in San Francisco”, or “founders shipping Security” and Refolk returns a ranked shortlist with sources.

How this list is built

Refolk searched GitHub for public repositories tagged with the Security topic, ranked them by stargazer count, and kept those with at least 50 stars. The list refreshes once a day.

Last refreshed: Fri, 18 Sep 2026 07:54:39 GMT

Search this list

Need a list like this for any search?

Refolk runs natural-language searches across GitHub, LinkedIn, and the open web. Try one of these:

500 free credits on sign-up, no card needed.

Browse other topics

See all repository lists.

Security by language

Common questions

How are these repositories ranked?

By stars, with forks and recent activity as tiebreakers, read from the public GitHub API. The methodology section above has the details.

How fresh is the data?

The ranking re-renders at least daily. Last refreshed: Fri, 18 Sep 2026 07:54:39 GMT.

Can I find the maintainers and contributors behind these repos?

Yes. Stars rank the projects; I can rank the engineers - maintainers, top contributors, and the people they work with. You start with 500 free credits, no card required.

Can I use this list for hiring?

That's the point. I read hiring signals across GitHub, LinkedIn, and the open web, so a repo list turns into a shortlist of engineers worth talking to.

Try it on the search you came here for

Stop building boolean strings. Just describe the person.

Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.

  1. 01Describe them

    One plain sentence. Role, city, stack, stage, whatever matters to you.

  2. 02I read the web live

    GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.

  3. 03You read the shortlist

    Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.

  • No boolean, no filters, no seat to buy. One box.
  • Read at search time, so a profile updated yesterday counts today.
  • Every step visible as it runs, every name with its reason.

500 free credits on sign-up. No card, no demo call. See real searches.

Keep exploring