Security tooling splits into four buckets that teams adopt across, not from. Static analysis (semgrep, CodeQL, Bearer, language-specific linters). Software composition analysis (Trivy, Grype, OSV-Scanner, Syft). Secret scanners (Gitleaks, TruffleHog, detect-secrets). And the security-automation layer — SBOM builders, policy engines, IaC linters, the red-team toolbox. Signal patterns are weird here. A critical CVE drop drives huge traffic to whichever scanner detects it first, then settles. Project usage routinely outpaces star counts because enterprises adopt scanners without publicly contributing love. The ranking smooths the spikes by counting sustained mentions alongside GitHub velocity. The unflashy security tools are usually the best ones — projects with a decade of incremental release notes outperform the viral newcomer over any horizon longer than a quarter. When evaluating, signal-to-noise ratio matters more than feature count: every scanner produces false positives, and how the project triages them tells you what working with it will feel like.
| # | Repository | Stars | 24h | 7d | 30d | Trend | Mentions | Actions |
|---|---|---|---|---|---|---|---|---|
| 01 | TecharoHQ/anubis Weighs the soul of incoming HTTP requests to stop AI crawlers | 19.9K | -14-0.1% | +114+0.6% | +629+3.3% |
| 02 | betterleaks/betterleaks Scan the world (for secrets) | 1.2K | +1+0.1% | +65+5.8% | +282+31.2% |
| 03 | zizmorcore/zizmor Static analysis for GitHub Actions | 5.6K | +1+0.0% | +121+2.2% | +925+19.7% |
| 04 | yv1ing/Z3r0 AI-native red-team workbench for authorized penetration testing and vulnerability research, with specialist agents, sandboxed tooling, evidence records, and replayable timelines. | 392 | — | +117+42.5% | +390+19500.0% |
| 05 | trailofbits/skills Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows | 5.7K | — | +92+1.7% | +514+10.0% |
| 06 | sheeki03/tirith Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute. | 2.4K | — | +24+1.0% | +120+5.2% |
| 07 | ramonvermeulen/whosthere Local Area Network discovery tool with an interactive Terminal User Interface (TUI) written in Go. Discover, explore, and understand your LAN in an intuitive way. Knock Knock.. who's there? 🚪 | 2.3K | — | +5+0.2% | +103+4.7% |
| 08 | gitleaks/gitleaks Find secrets with Gitleaks 🔑 | 27.7K | +1+0.0% | +139+0.5% | +768+2.9% |
| 09 | phanen/nvim-suspicious-plugin-scanner Scan and flag suspicious neovim plugins | 62 | — | +2+3.3% | +61+6100.0% |
| 10 | Rain-kl/OpenFlare OpenFlare is an open-source CDN orchestration and edge security platform. It supports reverse proxies, centralized configuration synchronization, secure intranet penetration (Tunnels), dynamic WAF protection, and anti-CC challenges. | 188 | — | +51+37.2% | +129+218.6% |
| 11 | MSNightmare/GreatXML GreatXML bitlocker bypass vulnerability | 268 | — | — | — |
| 12 | scadastrangelove/awesome-ai-security-tools A curated list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity — autotriage, agent security, AI/ML supply chain, pentest agents, AI SAST, LLM-driven fuzzing, threat intelligence, SOC/SIEM triage, reverse engineering, LLM red-teaming, and more. | 20 | — | +2+11.1% | +19+1900.0% |
| 13 | dockmockingbirdstove/Activtrak-Crack-2026 ⭐️ Acunetix 2026 | Web Vulnerability Scanner | Security Testing Tool | Full Version Installer | License Key Pre-Activated | Latest Build Pro | Setup Activation Keygen | Patch Mod Loader | Desktop Windows 10/11 | Get Genuine Original Software | Premium Version Download ⭐️ | 10 | — | +10 | +10 |
| 14 | zmn-hamid/sni-spoofing-scanner SNI-Spoofing Scanner | 18 | — | +1+5.9% | +18 |
| 15 | mani5717/hwid-spoofer-utility Spoof hardware identifiers to bypass system-level bans and restrictions. | 119 | — | +47+65.3% | +124 |
| 16 | qiuqiuxiao930/AD-kill-bot A bot that filters scam ads in Telegram groups. | 14 | — | — | +14 |
| 17 | Islagagnon365287/top-5-vpn-5-apex-legends-30-05-2026-2026  | 2 | — | — | +2 |
| 18 | myagagne362541/top-6-vpn-discord-2026 ТОП-6 рабочих VPN для России на 30.05.2026 — обзор рабочих протоколов для обхода блокировок Discord, YouTube и Telegram. Тестирование голоса, стримов и RTC Connecting. | 1 | — | — | +1 |
| 19 | GaleSectorDetonate92/Acunetix-Crack-Windows-2026 ⭐️ Acunetix 2026 | Web Vulnerability Scanner | Security Testing Tool | Full Version Installer | License Key Pre-Activated | Latest Build Pro | Setup Activation Keygen | Patch Mod Loader | Desktop Windows 10/11 | Get Genuine Original Software | Premium Version Download ⭐️ | 9 | — | — | — |
| 20 | Islagagnon365287/top-6-vpn-6-vpn-windows-macos-28-05-2026-2026  | 2 | — | — | +2 |
| 21 | myagagne362541/top-4-vpn-4-maks-27-05-2026-2026  | 2 | — | — | +2 |
| 22 | zakirkun/ice-tea AI-Powered Static Application Security Testing (SAST) — written in Go. | 34 | — | — | +3+9.7% |