awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetServeur MCPÀ proposNotre méthodologiePresse
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

15 dépôts

Awesome GitHub RepositoriesSecurity Testing

Tools for identifying vulnerabilities and performing penetration testing.

Explore 15 awesome GitHub repositories matching part of an awesome list · Security Testing. Refine with filters or upvote what's useful.

Awesome Security Testing GitHub Repositories

Trouvez les meilleurs dépôts grâce à l'IA.Nous recherchons les dépôts les plus pertinents grâce à l'IA.
  • projectdiscovery/nucleiAvatar de projectdiscovery

    projectdiscovery/nuclei

    29,189Voir sur GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Automated scanner for identifying common site vulnerabilities.

    Goattack-surfacecve-scannerdast
    Voir sur GitHub↗29,189
  • shieldfy/api-security-checklistAvatar de shieldfy

    shieldfy/API-Security-Checklist

    23,258Voir sur GitHub↗

    This project is a comprehensive API security audit checklist and vulnerability audit framework. It provides a structured guide of security countermeasures for designing, testing, and deploying secure APIs across various protocols. The framework includes specialized guides for securing OAuth 2.0 authorization flows, implementing zero trust networking for service-to-service communication, and protecting GraphQL endpoints from resource exhaustion and information leakage. It also provides standards for integrating static analysis, dynamic scanning, and secret detection into CI/CD delivery pipelin

    Checklist for securing API implementations.

    apijwtoauth2
    Voir sur GitHub↗23,258
  • zaproxy/zaproxyAvatar de zaproxy

    zaproxy/zaproxy

    15,293Voir sur GitHub↗

    OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

    Intercepting proxy for HTTP manipulation and security scanning.

    Java
    Voir sur GitHub↗15,293
  • sbilly/awesome-securityAvatar de sbilly

    sbilly/awesome-security

    14,022Voir sur GitHub↗

    This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen

    Curated list of security-focused learning resources.

    awesome-listsecurity
    Voir sur GitHub↗14,022
  • qazbnm456/awesome-web-securityAvatar de qazbnm456

    qazbnm456/awesome-web-security

    13,097Voir sur GitHub↗

    This project serves as a comprehensive cybersecurity training platform and resource repository focused on web application security. It functions as a centralized hub for security practitioners, providing both a curated collection of technical documentation and research, and a system for deploying isolated, containerized environments to practice security analysis and exploitation techniques. The platform distinguishes itself by integrating automated data aggregation with hands-on, container-based orchestration. It maintains a current knowledge base of industry research and digital threats whil

    Collection of web security research and tools.

    awesomeawesome-listlist
    Voir sur GitHub↗13,097
  • owasp/wstgAvatar de OWASP

    OWASP/wstg

    9,473Voir sur GitHub↗

    The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software. The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerab

    Comprehensive guide for web application security testing.

    application-securityappsecbest-practices
    Voir sur GitHub↗9,473
  • infoslack/awesome-web-hackingAvatar de infoslack

    infoslack/awesome-web-hacking

    6,909Voir sur GitHub↗

    A list of web application security

    Resources for learning web application penetration testing.

    appsechackinghacking-tools
    Voir sur GitHub↗6,909
  • paragonie/awesome-appsecAvatar de paragonie

    paragonie/awesome-appsec

    6,831Voir sur GitHub↗

    Curated list of application security resources.

    PHPapplication-securitycuratedowasp
    Voir sur GitHub↗6,831
  • sottlmarek/devsecopsAvatar de sottlmarek

    sottlmarek/DevSecOps

    6,596Voir sur GitHub↗

    Learning path for DevSecOps practices.

    automationawesomeawesome-list
    Voir sur GitHub↗6,596
  • microsoft/security-101Avatar de microsoft

    microsoft/Security-101

    6,203Voir sur GitHub↗

    Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do

    Foundational security learning materials.

    HTMLappseccia-triaddata-protection
    Voir sur GitHub↗6,203
  • arainho/awesome-api-securityAvatar de arainho

    arainho/awesome-api-security

    3,644Voir sur GitHub↗

    Collection of API security testing resources.

    api-hackingapi-hacksapi-hardening
    Voir sur GitHub↗3,644
  • vaib25vicky/awesome-mobile-securityAvatar de vaib25vicky

    vaib25vicky/awesome-mobile-security

    3,502Voir sur GitHub↗

    An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.

    Guides and tools for mobile application security.

    Voir sur GitHub↗3,502
  • wtsxdev/penetration-testingAvatar de wtsxDev

    wtsxDev/Penetration-Testing

    2,766Voir sur GitHub↗

    List of awesome penetration testing resources, tools and other shiny things

    Resources for learning penetration testing techniques.

    Voir sur GitHub↗2,766
  • dolevf/damn-vulnerable-graphql-applicationAvatar de dolevf

    dolevf/Damn-Vulnerable-GraphQL-Application

    1,691Voir sur GitHub↗

    Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

    Vulnerable GraphQL endpoint for testing security exploits.

    JavaScript
    Voir sur GitHub↗1,691
  • erev0s/vampiAvatar de erev0s

    erev0s/VAmPI

    1,245Voir sur GitHub↗

    Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

    Vulnerable API for practicing security testing and exploitation.

    Python
    Voir sur GitHub↗1,245
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Security Testing