Trending Security repositories
Security tooling splits into four buckets that teams adopt across, not from. Static analysis (semgrep, CodeQL, Bearer, language-specific linters). Software composition analysis (Trivy, Grype, OSV-Scanner, Syft). Secret scanners (Gitleaks, TruffleHog, detect-secrets). And the security-automation layer — SBOM builders, policy engines, IaC linters, the red-team toolbox. Signal patterns are weird here. A critical CVE drop drives huge traffic to whichever scanner detects it first, then settles. Project usage routinely outpaces star counts because enterprises adopt scanners without publicly contributing love. The ranking smooths the spikes by counting sustained mentions alongside GitHub velocity. The unflashy security tools are usually the best ones — projects with a decade of incremental release notes outperform the viral newcomer over any horizon longer than a quarter. When evaluating, signal-to-noise ratio matters more than feature count: every scanner produces false positives, and how the project triages them tells you what working with it will feel like.
Live · top 27 repos · sorted by momentum across 24H
LIVE · 36m| # | Repository | Stars | 24h | 7d | 30d | Trend | Mentions | Actions |
|---|---|---|---|---|---|---|---|---|
| 01 | TecharoHQ/anubis Weighs the soul of incoming HTTP requests to stop AI crawlers | 21K | +5+0.0% | +138+0.7% | +699+3.5% | |||
| 02 | scadastrangelove/awesome-ai-security-tools A curated list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity — autotriage, agent security, AI/ML supply chain, pentest agents, AI SAST, LLM-driven fuzzing, threat intelligence, SOC/SIEM triage, reverse engineering, LLM red-teaming, and more. | 842 | +3+0.4% | +717+573.6% | +817+3268.0% | |||
| 03 | zizmorcore/zizmor Static analysis for GitHub Actions | 5.9K | +5+0.1% | +38+0.6% | +186+3.2% | |||
| 04 | betterleaks/betterleaks Scan the world (for secrets) | 1.5K | +4+0.3% | +46+3.1% | +200+15.0% | |||
| 05 | gitleaks/gitleaks Find secrets with Gitleaks 🔑 | 28.3K | +11+0.0% | +107+0.4% | +414+1.5% | |||
| 06 | trailofbits/skills Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows | 6.3K | +9+0.1% | +86+1.4% | +365+6.2% | |||
| 07 | sheeki03/tirith Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute. | 2.6K | — | +14+0.5% | +141+5.7% | |||
| 08 | Rain-kl/OpenFlare OpenFlare is an open-source CDN orchestration and edge security platform. It supports reverse proxies, centralized configuration synchronization, secure intranet penetration (Tunnels), dynamic WAF protection, and anti-CC challenges. | 231 | +1+0.4% | +9+4.1% | +30+14.9% | |||
| 09 | An0nUD4Y/Offensive-COM Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, DCOM lateral movement, and persistence primitives with exploitation steps. Notes were generated by Kimi K3 Swarm may contain inaccuracies. | 131 | +1+0.8% | +58+79.5% | +130+13000.0% | |||
| 10 | yellowkeys/YellowKey-Bitlocker-CVE-2026-45585 YellowKey BitLocker CVE-2026-45585 is an open-source utility to extract, backup, and organize BitLocker recovery keys on Windows encrypted drives. Automate volume decryption, manage drive encryption states via command-line tools, export secure configuration files, and track recovery key logs. Download direct repository setup files. | 16 | +2+14.3% | +16 | +16 | |||
| 11 | phanen/nvim-suspicious-plugin-scanner Scan and flag suspicious neovim plugins | 69 | — | — | +4+6.2% | |||
| 12 | yv1ing/Z3r0 AI-native red-team workbench for authorized penetration testing and vulnerability research, with specialist agents, sandboxed tooling, evidence records, and replayable timelines. | 575 | — | +21+3.8% | +116+25.3% | |||
| 13 | ramonvermeulen/whosthere Local Area Network discovery tool with an interactive Terminal User Interface (TUI) written in Go. Discover, explore, and understand your LAN in an intuitive way. Knock Knock.. who's there? 🚪 | 2.4K | +1+0.0% | +6+0.3% | +62+2.7% | |||
| 14 | pazo01/awesome-cyber-ai-arsenal A curated collection of offensive, defensive and AI/LLM security tools. | 119 | — | — | — | |||
| 15 | okasi/bot-signal TypeScript bot detection: catch WebDriver, headless Chrome, Playwright/Puppeteer, robotic mouse/typing, datacenter IPs, JA3 TLS mismatch & timezone spoofing — browser + Node. | 668 | — | — | — | |||
| 16 | dinosn/fastjson-jsontype-rce-lab Docker lab + one-payload exploit + defensive scanner for the fastjson 1.2.66-1.2.83 @JSONType remote-class-load RCE (SSRF->defineClass under Spring Boot LaunchedURLClassLoader; autoType OFF; parseObject binding is not a mitigation) | 169 | — | — | — | |||
| 17 | m-novotny/memguard-rs Secure memory handling primitives for Rust — zeroization on drop, mlock-protected regions, constant-time comparison, and compile-time enforced memory safety boundaries | 131 | — | — | +131 | |||
| 18 | armourinfosec/Enterprise-Windows-Infrastructure-Security An Obsidian-based knowledge base for Windows Server administration and defensive hardening. | 81 | — | — | — | |||
| 19 | itshamzabendelladj/AIGuardSIEM A production-grade SIEM/XDR platform for 1M+ EPS ingestion with sub-15ms detection latency. Built with C++, Go, and Python. Features DPDK capture, ONNX ML inference, Sigma rules, eBPF monitoring, and SOAR. | 75 | — | — | — | |||
| 20 | mani5717/hwid-spoofer-utility Spoof hardware identifiers to bypass system-level bans and restrictions. | 97 | — | +4+4.3% | +97 | |||
| 21 | zmn-hamid/sni-spoofing-scanner SNI-Spoofing Scanner | 18 | — | — | — | |||
| 22 | qiuqiuxiao930/AD-kill-bot A bot that filters scam ads in Telegram groups. | 14 | — | — | — | |||
| 23 | Islagagnon365287/top-5-vpn-5-apex-legends-30-05-2026-2026  | 2 | — | — | — | |||
| 24 | Islagagnon365287/top-6-vpn-6-vpn-windows-macos-28-05-2026-2026  | 2 | — | — | — | |||
| 25 | myagagne362541/top-6-vpn-discord-2026 ТОП-6 рабочих VPN для России на 30.05.2026 — обзор рабочих протоколов для обхода блокировок Discord, YouTube и Telegram. Тестирование голоса, стримов и RTC Connecting. | 1 | — | — | — | |||
| 26 | myagagne362541/top-4-vpn-4-maks-27-05-2026-2026  | 2 | — | — | — | |||
| 27 | zakirkun/ice-tea AI-Powered Static Application Security Testing (SAST) — written in Go. | 36 | — | — | +1+2.9% |