Refolk

Top Security repositories on GitHub

Offensive and defensive security tools and libraries.

Ranked by stars across 4,955 repositories tagged security. Refreshed daily.

  1. 1

    A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

    • awesome
    • awesome-list
    • lists
    • manuals
    • resources
    • howtos
  2. 2
    Hack-with-Github/Awesome-Hacking111,743 · ⑂ 10,254

    A collection of various awesome lists for hackers, pentesters and security researchers

    • hacking
    • security
    • bug-bounty
    • awesome
    • android
    • fuzzing
  3. 3
    Developer-Y/cs-video-courses81,033 · ⑂ 11,213

    List of Computer Science courses with video lectures.

    • computer-science
    • algorithms
    • systems
    • databases
    • machine-learning
    • web-development
  4. 4
    swisskyrepo/PayloadsAllTheThings77,518 · ⑂ 16,934

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    • pentest
    • payload
    • bypass
    • web-application
    • hacking
    • vulnerability
  5. 5
    caddyserver/caddy72,135 · ⑂ 4,714

    Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

    • go
    • web-server
    • caddyfile
    • http
    • http-server
    • reverse-proxy
  6. 6
    x64dbg/x64dbg48,293 · ⑂ 2,727

    An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

    • debugger
    • windows
    • x64
    • disassembler
    • reverse-engineering
    • security
  7. 7
    mitmproxy/mitmproxy43,430 · ⑂ 4,548

    An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

    • python
    • security
    • man-in-the-middle
    • tls
    • ssl
    • http
  8. 8
    QuivrHQ/quivr39,134 · ⑂ 3,752

    Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.

    • ai
    • llm
    • api
    • chatbot
    • chatgpt
    • database
  9. 9
    GyulyVGC/sniffnet37,278 · ⑂ 1,499

    Comfortably monitor your Internet traffic 🕵️‍♂️

    • network-analysis
    • networking
    • packet-sniffer
    • rust-crate
    • linux
    • macos
  10. 10
    aquasecurity/trivy34,879 · ⑂ 348

    Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

    • security
    • security-tools
    • docker
    • containers
    • vulnerability-scanners
    • vulnerability-detection
  11. 11
    Lissy93/web-check33,023 · ⑂ 2,664

    🕵️‍♂️ All-in-one OSINT tool for analysing any website

    • osint
    • privacy
    • security
    • security-tools
    • sysadmin
  12. 12
    OWASP/CheatSheetSeries31,932 · ⑂ 4,440

    The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

    • owasp
    • code
    • security
    • cheatsheets
    • best-practices
    • appsec
  13. 13
    StevenBlack/hosts30,315 · ⑂ 2,409

    🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

    • python
    • unified-hosts
    • malware
    • ad-blocker
    • porn-filter
    • social-media-filter
  14. 14
    trailofbits/algo30,216 · ⑂ 2,363

    Set up a personal VPN in the cloud

    • vpn-server
    • strongswan
    • ansible
    • vpn
    • ikev2
    • security
  15. 15
    nginx/nginx30,195 · ⑂ 7,886

    The official NGINX Open Source repository.

    • content-cache
    • load-balancer
    • reverse-proxy
    • web-server
    • http
    • https
  16. 16
    digitalocean/nginxconfig.io28,308 · ⑂ 2,060

    ⚙️ NGINX config generator on steroids 💉

    • nginx
    • nginx-configuration
    • php-fpm
    • ssl
    • letsencrypt
    • cdn
  17. 17
    projectdiscovery/nuclei28,249 · ⑂ 3,387

    Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

    • cve-scanner
    • subdomain-takeover
    • nuclei-engine
    • vulnerability-detection
    • vulnerability-assessment
    • vulnerability-scanner
  18. 18
    community-scripts/ProxmoxVE27,926 · ⑂ 2,666

    Proxmox VE Helper-Scripts (Community Edition)

    • home-assistant
    • home-automation
    • homelab
    • homelab-setup
    • lxc
    • proxmox
  19. 19
    hwdsl2/setup-ipsec-vpn27,774 · ⑂ 6,514

    Set up your own IPsec VPN server in just a few minutes, with IPsec/L2TP, Cisco IPsec and IKEv2. Supports Ubuntu, Debian, CentOS/RHEL, Amazon Linux, Alpine and Raspberry Pi. Includes client config and management scripts.

    • vpn
    • ipsec
    • l2tp
    • ikev2
    • security
    • vpn-server
  20. 20
    authelia/authelia27,716 · ⑂ 1,396

    The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™

    • totp
    • ldap
    • sso-authentication
    • yubikey
    • two-factor-authentication
    • docker
  21. 21
    OpenZeppelin/openzeppelin-contracts27,088 · ⑂ 12,408

    OpenZeppelin Contracts is a library for secure smart contract development.

    • ethereum
    • solidity
    • evm
    • security
    • smart-contracts
  22. 22
    keepassxreboot/keepassxc26,992 · ⑂ 1,781

    KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.

    • keepassxc
    • keepass
    • password-manager
    • linux
    • windows
    • cross-platform
  23. 23
    Infisical/infisical26,661 · ⑂ 1,867

    Infisical is the open-source platform for secrets, certificates, and privileged access management.

    • cli
    • environment-variables
    • secret-management
    • secrets
    • security
    • open-source
  24. 24
    gitleaks/gitleaks26,615 · ⑂ 2,021

    Find secrets with Gitleaks 🔑

    • security
    • security-tools
    • git
    • golang
    • go
    • secret
  25. 25
    trufflesecurity/trufflehog26,068 · ⑂ 2,371

    Find, verify, and analyze leaked credentials

    • secret
    • trufflehog
    • credentials
    • security
    • devsecops
    • dynamic-analysis

Find engineers shipping Security

The list above ranks the most-starred public repositories tagged with the Security topic, drawn from the public GitHub graph. Across 4,955 repositories tagged this way, the maintainers and top contributors are a tight cluster of the people actually building Security.

Looking for engineers who’ve worked on Security for real, not just listed it on LinkedIn? The fastest path is the contributor list of these repos. Their commits, issues, and READMEs are public proof of depth.

Refolk turns this list into a search. Ask for “maintainers of top Security repos who are hiring”, Security engineers in San Francisco”, or “founders shipping Security” and Refolk returns a ranked shortlist with sources.

How this list is built

Refolk searched GitHub for public repositories tagged with the Security topic, ranked them by stargazer count, and kept those with at least 50 stars. The list refreshes once a day.

Last refreshed: Thu, 07 May 2026 05:54:55 GMT

Need a list like this for any search?

Refolk runs natural-language searches across GitHub, LinkedIn, and the open web. Try one of these:

Browse other topics

See all repository lists.

Security by language