awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

15 repositorios

Awesome GitHub RepositoriesSecurity Testing

Tools for identifying vulnerabilities and performing penetration testing.

Explore 15 awesome GitHub repositories matching part of an awesome list · Security Testing. Refine with filters or upvote what's useful.

Awesome Security Testing GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • projectdiscovery/nucleiAvatar de projectdiscovery

    projectdiscovery/nuclei

    29,189Ver en GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Automated scanner for identifying common site vulnerabilities.

    Goattack-surfacecve-scannerdast
    Ver en GitHub↗29,189
  • shieldfy/api-security-checklistAvatar de shieldfy

    shieldfy/API-Security-Checklist

    23,258Ver en GitHub↗

    This project is a comprehensive API security audit checklist and vulnerability audit framework. It provides a structured guide of security countermeasures for designing, testing, and deploying secure APIs across various protocols. The framework includes specialized guides for securing OAuth 2.0 authorization flows, implementing zero trust networking for service-to-service communication, and protecting GraphQL endpoints from resource exhaustion and information leakage. It also provides standards for integrating static analysis, dynamic scanning, and secret detection into CI/CD delivery pipelin

    Checklist for securing API implementations.

    apijwtoauth2
    Ver en GitHub↗23,258
  • zaproxy/zaproxyAvatar de zaproxy

    zaproxy/zaproxy

    15,293Ver en GitHub↗

    OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

    Intercepting proxy for HTTP manipulation and security scanning.

    Java
    Ver en GitHub↗15,293
  • sbilly/awesome-securityAvatar de sbilly

    sbilly/awesome-security

    14,022Ver en GitHub↗

    This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen

    Curated list of security-focused learning resources.

    awesome-listsecurity
    Ver en GitHub↗14,022
  • qazbnm456/awesome-web-securityAvatar de qazbnm456

    qazbnm456/awesome-web-security

    13,097Ver en GitHub↗

    This project serves as a comprehensive cybersecurity training platform and resource repository focused on web application security. It functions as a centralized hub for security practitioners, providing both a curated collection of technical documentation and research, and a system for deploying isolated, containerized environments to practice security analysis and exploitation techniques. The platform distinguishes itself by integrating automated data aggregation with hands-on, container-based orchestration. It maintains a current knowledge base of industry research and digital threats whil

    Collection of web security research and tools.

    awesomeawesome-listlist
    Ver en GitHub↗13,097
  • owasp/wstgAvatar de OWASP

    OWASP/wstg

    9,473Ver en GitHub↗

    The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software. The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerab

    Comprehensive guide for web application security testing.

    application-securityappsecbest-practices
    Ver en GitHub↗9,473
  • infoslack/awesome-web-hackingAvatar de infoslack

    infoslack/awesome-web-hacking

    6,909Ver en GitHub↗

    A list of web application security

    Resources for learning web application penetration testing.

    appsechackinghacking-tools
    Ver en GitHub↗6,909
  • paragonie/awesome-appsecAvatar de paragonie

    paragonie/awesome-appsec

    6,831Ver en GitHub↗

    Curated list of application security resources.

    PHPapplication-securitycuratedowasp
    Ver en GitHub↗6,831
  • sottlmarek/devsecopsAvatar de sottlmarek

    sottlmarek/DevSecOps

    6,596Ver en GitHub↗

    Learning path for DevSecOps practices.

    automationawesomeawesome-list
    Ver en GitHub↗6,596
  • microsoft/security-101Avatar de microsoft

    microsoft/Security-101

    6,203Ver en GitHub↗

    Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do

    Foundational security learning materials.

    HTMLappseccia-triaddata-protection
    Ver en GitHub↗6,203
  • arainho/awesome-api-securityAvatar de arainho

    arainho/awesome-api-security

    3,644Ver en GitHub↗

    Collection of API security testing resources.

    api-hackingapi-hacksapi-hardening
    Ver en GitHub↗3,644
  • vaib25vicky/awesome-mobile-securityAvatar de vaib25vicky

    vaib25vicky/awesome-mobile-security

    3,502Ver en GitHub↗

    An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.

    Guides and tools for mobile application security.

    Ver en GitHub↗3,502
  • wtsxdev/penetration-testingAvatar de wtsxDev

    wtsxDev/Penetration-Testing

    2,766Ver en GitHub↗

    List of awesome penetration testing resources, tools and other shiny things

    Resources for learning penetration testing techniques.

    Ver en GitHub↗2,766
  • dolevf/damn-vulnerable-graphql-applicationAvatar de dolevf

    dolevf/Damn-Vulnerable-GraphQL-Application

    1,691Ver en GitHub↗

    Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

    Vulnerable GraphQL endpoint for testing security exploits.

    JavaScript
    Ver en GitHub↗1,691
  • erev0s/vampiAvatar de erev0s

    erev0s/VAmPI

    1,245Ver en GitHub↗

    Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

    Vulnerable API for practicing security testing and exploitation.

    Python
    Ver en GitHub↗1,245
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Security Testing