awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to activecm/rita

Open-source alternatives to Rita

30 open-source projects similar to activecm/rita, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Rita alternative.

  • stamparm/maltrailstamparm avatar

    stamparm/maltrail

    8,498View on GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    View on GitHub↗8,498
  • zeek/zeekzeek avatar

    zeek/zeek

    7,735View on GitHub↗

    Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level semantic logs. It functions as an application protocol analyzer and network intrusion detection system designed to extract meaning from network traffic and monitor for malicious activity. The system focuses on archiving network activity and maintaining historical records of application-layer state for forensic investigation and auditing. It utilizes a combination of modular protocol analyzers and customizable detection policies to perform deep semantic analysis of numerous app

    C++brodfirndr
    View on GitHub↗7,735
  • security-onion-solutions/securityonionSecurity-Onion-Solutions avatar

    Security-Onion-Solutions/securityonion

    4,661View on GitHub↗

    Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive

    Shell
    View on GitHub↗4,661

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • ntop/ndpintop avatar

    ntop/nDPI

    4,506View on GitHub↗

    nDPI is a deep packet inspection toolkit and network protocol classifier designed to identify protocols and detect security threats through packet payload inspection. It functions as a network security monitor and a traffic analysis framework used to determine the services originating network flows. The system utilizes a modular dissector architecture and a sequence-based dissector chain to interpret network traffic. It supports custom protocol definition and protocol dissector extensions, allowing for the identification of proprietary or new network protocols. The toolkit provides capabilit

    Ccybersecuritydeep-packet-inspectiondpi
    View on GitHub↗4,506
  • skeeto/endlesshskeeto avatar

    skeeto/endlessh

    8,477View on GitHub↗

    Endlessh is an SSH tarpit and network honeypot designed to mitigate automated SSH brute force attacks. It acts as a defensive layer that protects servers by diverting malicious connection attempts into a slow-motion trap. The project implements a tarpit by sending endless, throttled banners to clients, which keeps connections open indefinitely to occupy attacker resources and slow down network scans. The service includes connection rate limiting to prevent system resource exhaustion and provides monitoring through connection activity and diagnostic data logging to system logs. Process manage

    C
    View on GitHub↗8,477
  • alexandreborges/malwoverviewalexandreborges avatar

    alexandreborges/malwoverview

    3,882View on GitHub↗

    This project is a Python command-line security tool and malware analysis framework designed for threat intelligence aggregation and incident triage. It functions as an aggregator that orchestrates queries across multiple security services and sandboxes to analyze hashes, IP addresses, and domains. The tool distinguishes itself by incorporating an intelligence layer that uses language models to provide automated risk assessments and framework mappings. It also includes specialized capabilities for extracting indicators of compromise from unstructured text, documents, and web pages, as well as

    Pythonalienvaultcvecve-search
    View on GitHub↗3,882
  • akamai/ludaA

    akamai/luda

    0View on GitHub↗
    View on GitHub↗0
  • adamtaguirov/ida-practical-cheatsheetA

    AdamTaguirov/IDA-practical-cheatsheet

    0View on GitHub↗
    View on GitHub↗0
  • blacksnufkin/litterboxBlackSnufkin avatar

    BlackSnufkin/LitterBox

    1,469View on GitHub↗

    A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.

    YARAaidocker-composemalware-analysis
    View on GitHub↗1,469
  • ashishb/android-malwareashishb avatar

    ashishb/android-malware

    1,209View on GitHub↗

    Collection of android malware samples

    Shell
    View on GitHub↗1,209
  • buffer/libemubuffer avatar

    buffer/libemu

    156View on GitHub↗

    x86 emulation and shellcode detection

    C
    View on GitHub↗156
  • buffer/pylibemubuffer avatar

    buffer/pylibemu

    129View on GitHub↗

    A Libemu Cython wrapper

    Python
    View on GitHub↗129
  • capacitorset/box-jsCapacitorSet avatar

    CapacitorSet/box-js

    673View on GitHub↗

    A tool for studying JavaScript malware.

    JavaScript
    View on GitHub↗673
  • captaingeech42/ransomwatchC

    captainGeech42/ransomwatch

    0View on GitHub↗
    View on GitHub↗0
  • advanced-threat-research/iocsadvanced-threat-research avatar

    advanced-threat-research/IOCs

    83View on GitHub↗

    Repository containing IOCs, CSV and MISP JSON from our blogs

    HTML
    View on GitHub↗83
  • cert-polska/mwdb-coreC

    CERT-Polska/mwdb-core

    0View on GitHub↗
    View on GitHub↗0
  • cert-polska/kartonC

    CERT-Polska/karton

    0View on GitHub↗
    View on GitHub↗0
  • arkime/arkimearkime avatar

    arkime/arkime

    7,399View on GitHub↗

    Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures. The platform distinguishes itself through its ability to manage distributed capture clusters from a centralized administrative dashboard. It integrates external data feeds with internal traffic logs to identify known threats and provides a pro

    C
    View on GitHub↗7,399
  • checkpointsw/showstopperCheckPointSW avatar

    CheckPointSW/showstopper

    223View on GitHub↗

    Contributed by Check Point Software Technologies LTD. Programmed by Yaraslau Harakhavik

    C++
    View on GitHub↗223
  • cmu-sei/cyobstractC

    cmu-sei/cyobstract

    0View on GitHub↗
    View on GitHub↗0
  • codeexpress/respoundercodeexpress avatar

    codeexpress/respounder

    323View on GitHub↗

    Respounder detects presence of responder in the network.

    Go
    View on GitHub↗323
  • countercept/snakeC

    countercept/snake

    0View on GitHub↗
    View on GitHub↗0
  • cred-club/artifC

    CRED-CLUB/ARTIF

    0View on GitHub↗
    View on GitHub↗0
  • criticalpathsecurity/zeek-intelligence-feedsC

    CriticalPathSecurity/Zeek-Intelligence-Feeds

    0View on GitHub↗
    View on GitHub↗0
  • csvl/sema-toolchainC

    csvl/SEMA-ToolChain

    0View on GitHub↗
    View on GitHub↗0
  • cybercentrecanada/cccs-yaraCybercentreCanada avatar

    CybercentreCanada/CCCS-Yara

    119View on GitHub↗

    YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA

    Python
    View on GitHub↗119
  • d4stiny/spectreD

    D4stiny/spectre

    0View on GitHub↗
    View on GitHub↗0
  • doctorwebltd/malware-iocsDoctorWebLtd avatar

    DoctorWebLtd/malware-iocs

    242View on GitHub↗
    View on GitHub↗242
  • droidefense/enginedroidefense avatar

    droidefense/engine

    480View on GitHub↗

    droidefense (originally named atom: a nalysis t hrough o bservation m achine)* is the codename for android apps/malware analysis/reversing tool. It was built focused on security issues and tricks that malware researcher have on they every day work. For those situations on where the malware has…

    Java
    View on GitHub↗480
  • cert-polska/drakvuf-sandboxCERT-Polska avatar

    CERT-Polska/drakvuf-sandbox

    1,305View on GitHub↗

    DRAKVUF Sandbox - automated hypervisor-level malware analysis system

    Pythonmalwaremalware-analysismalware-research
    View on GitHub↗1,305