awesome-repositories.com
博客
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Open-Source Security Tools

排名更新于 2026年7月13日

For an open source tool for network security, the strongest matches are wazuh/wazuh (Wazuh is a comprehensive security platform that provides vulnerability), anchore/grype (Grype is a specialized vulnerability scanner focused on container) and future-architect/vuls (Vuls is a specialized vulnerability scanner that provides automated). armosec/kubescape and aquasecurity/trivy round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

我们为您精选了匹配 “best open source security tools” 的开源 GitHub 仓库。结果按与您查询的相关性进行排名 — 您可以使用下方筛选器缩小范围,或通过 AI 进行优化。

Open-Source Security Tools

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • wazuh/wazuhwazuh 的头像

    wazuh/wazuh

    14,779在 GitHub 上查看↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Wazuh is a comprehensive security platform that provides vulnerability scanning, infrastructure hardening, and continuous monitoring, making it a robust solution for auditing and managing security across distributed environments.

    CContainer SecurityInfrastructure and System HardeningVulnerability Scanners
    在 GitHub 上查看↗14,779
  • anchore/grypeanchore 的头像

    anchore/grype

    12,423在 GitHub 上查看↗

    Grype is a command-line security scanner designed to identify known vulnerabilities within container images, filesystems, and software manifests. It functions as a software composition analysis tool that detects security flaws in application components and open-source libraries to support supply chain security. The tool distinguishes itself by reconstructing the final state of container images through layered filesystem inspection and normalizing diverse package formats into a unified dependency graph. It maintains a local cache of security advisories synchronized from multiple upstream sourc

    Grype is a specialized vulnerability scanner focused on container images and software dependencies, providing essential scanning and reporting capabilities that fit within the broader security auditing category.

    GoContainer SecurityContainer Security ScannersSecurity Reporting Tools
    在 GitHub 上查看↗12,423
  • future-architect/vulsfuture-architect 的头像

    future-architect/vuls

    12,185在 GitHub 上查看↗

    Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit

    Vuls is a specialized vulnerability scanner that provides automated security auditing for operating systems, containers, and dependencies, fitting the core requirements of the category despite lacking integrated network monitoring or infrastructure hardening features.

    GoContainer Security ScannersVulnerability ScannersVulnerability Scanning
    在 GitHub 上查看↗12,185
  • armosec/kubescapearmosec 的头像

    armosec/kubescape

    11,482在 GitHub 上查看↗

    Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and container images against industry compliance and security benchmarks. It functions as a suite of security utilities, including a compliance auditor, a misconfiguration scanner, and a container vulnerability scanner. The project differentiates itself through automated remediation and active enforcement. It can automatically patch operating system vulnerabilities in images and fix security errors within manifest files. It also utilizes an admission controller to block the deployment of

    Kubescape is a specialized security platform for Kubernetes that provides vulnerability scanning, infrastructure hardening, and compliance auditing, making it a highly relevant tool for securing containerized environments.

    GoVulnerability ScannersKubernetes SecurityVulnerability Scanning
    在 GitHub 上查看↗11,482
  • aquasecurity/trivyaquasecurity 的头像

    aquasecurity/trivy

    36,462在 GitHub 上查看↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Trivy is a specialized security scanner that excels at vulnerability detection, container security, and infrastructure-as-code hardening, making it a highly effective tool for the auditing and management aspects of your security suite.

    GoContainer Security ScannersVulnerability Scanners
    在 GitHub 上查看↗36,462
  • cisofy/lynisCISOfy 的头像

    CISOfy/lynis

    15,284在 GitHub 上查看↗

    Lynis is an automated security auditing and system hardening framework designed for UNIX-based operating systems. It functions as a command-line utility that inspects local system configurations to identify security vulnerabilities, configuration weaknesses, and compliance gaps. By executing a series of modular tests, the tool generates actionable reports and remediation suggestions to assist in strengthening system defenses. The project distinguishes itself through a highly modular architecture that relies on shell-script-based execution and native system inspection. Users can define custom

    Lynis is a specialized security auditing and system hardening framework that provides automated vulnerability scanning and configuration analysis for Unix-based systems, though it lacks the broader network monitoring and container-specific security features of a full-suite management platform.

    ShellInfrastructure and System HardeningInfrastructure Hardening
    在 GitHub 上查看↗15,284
  • docker/docker-bench-securitydocker 的头像

    docker/docker-bench-security

    9,655在 GitHub 上查看↗

    This project is a security compliance tool and configuration auditor designed to evaluate Docker deployments against industry security benchmarks. It functions as a script-based scanner that identifies misconfigurations and vulnerabilities within both the host operating system and container settings. The tool specifically implements the Center for Internet Security standards for Docker to verify host and container configurations. It enables a hardening workflow by comparing system states against these standards to identify security gaps and document compliance status. The audit engine suppor

    This tool provides automated configuration auditing and hardening specifically for Docker environments, serving as a specialized component for infrastructure security and compliance within the broader vulnerability management category.

    ShellContainer SecurityContainer Security Scanners
    在 GitHub 上查看↗9,655
  • security-onion-solutions/securityonionSecurity-Onion-Solutions 的头像

    Security-Onion-Solutions/securityonion

    4,661在 GitHub 上查看↗

    Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive

    Security Onion is a comprehensive platform for network security monitoring and intrusion detection, providing the core infrastructure for security auditing and threat hunting, though it focuses more on monitoring and incident response than on static application security testing or infrastructure hardening.

    ShellIntrusion Detection SystemsNetwork Intrusion Detection
    在 GitHub 上查看↗4,661
  • shadow1ng/fscanshadow1ng 的头像

    shadow1ng/fscan

    13,421在 GitHub 上查看↗

    Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor

    This tool functions as a comprehensive security assessment and vulnerability scanning framework for internal networks, though it focuses more on active reconnaissance and penetration testing than on infrastructure hardening or static application security testing.

    GoVulnerability ScannersVulnerability Scanning
    在 GitHub 上查看↗13,421
  • zan8in/afrogzan8in 的头像

    zan8in/afrog

    4,182在 GitHub 上查看↗

    afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points. The project provides a framework for out-of-band security testing, detecting blind vulnerabilities by triggering and verifying external DNS or HTTP callbacks. Beyond web traffic, it includes a protocol fuzzer capable of executing multi-step read and write sequences over raw TCP and SSL sockets to identify

    This tool is a specialized vulnerability scanner that focuses on web-based flaws and protocol fuzzing, making it a relevant component for security auditing despite lacking broader infrastructure hardening or static application security testing features.

    GoVulnerability ScannersVulnerability Scanning
    在 GitHub 上查看↗4,182
  • usestrix/strixusestrix 的头像

    usestrix/strix

    20,138在 GitHub 上查看↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Strix is an automated security research and vulnerability scanning platform that provides a framework for penetration testing and continuous security integration, fitting the category by orchestrating complex security analysis and vulnerability scanning tasks.

    PythonContainer Security ScannersSecurity Reporting ToolsVulnerability Scanners
    在 GitHub 上查看↗20,138
  • bearer/bearerBearer 的头像

    Bearer/bearer

    2,566在 GitHub 上查看↗

    Bearer is a static analysis security testing tool and privacy compliance auditor. It identifies security vulnerabilities, hard-coded secrets, and privacy risks in source code through static analysis and data flow tracing. The tool distinguishes itself by tracking the movement of sensitive data through code to identify leaks and by mapping personal and health-related information flows to generate evidence for privacy impact assessments. It also provides differential scanning for pull requests and uses fingerprint-based suppression to exclude known false positives from reports. The platform co

    Bearer is a specialized static application security testing tool that focuses on code-level vulnerability scanning and privacy compliance, making it a strong component for an auditing suite even though it does not provide network monitoring or infrastructure hardening.

    GoSource Code Security AnalysisStatic Code AnalysisCompliance Reporting
    在 GitHub 上查看↗2,566
  • infinition/bjorninfinition 的头像

    infinition/Bjorn

    5,656在 GitHub 上查看↗

    Bjorn is a penetration testing framework that automates network scanning, credential brute-forcing, vulnerability assessment, and data exfiltration, all coordinated through an event-driven task pipeline and controlled via a web-based dashboard. Its modular plugin architecture allows independent security modules to be loaded and chained together, with an asynchronous network scanner discovering live hosts and open ports without blocking the main execution flow. The framework distinguishes itself by integrating a credential brute-force engine that systematically attempts login combinations agai

    Bjorn is a penetration testing and vulnerability assessment framework that provides automated scanning and security management, though it focuses more on active exploitation and testing than on infrastructure hardening or static application security testing.

    PythonVulnerability Scanning
    在 GitHub 上查看↗5,656
  • projectdiscovery/nucleiprojectdiscovery 的头像

    projectdiscovery/nuclei

    29,189在 GitHub 上查看↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Nuclei is a powerful, template-driven vulnerability scanner that excels at automated security detection and reconnaissance, though it functions primarily as a specialized scanning engine rather than a full-suite infrastructure hardening platform.

    GoVulnerability ScannersVulnerability Scanning
    在 GitHub 上查看↗29,189
  • snyk/clisnyk 的头像

    snyk/cli

    5,428在 GitHub 上查看↗

    The Snyk CLI is a command-line security scanner that detects known vulnerabilities across open-source dependencies, proprietary application code, container images, and infrastructure-as-code configuration files. It also serves as a platform management tool, allowing users to configure organizations, users, SSO, and reporting from the terminal rather than the web dashboard. The CLI integrates directly into development workflows, enabling scanning within IDEs, build pipelines, and version control systems. It implements static analysis with interfile data flow analysis to find complex security f

    This tool provides vulnerability scanning for dependencies, containers, and infrastructure-as-code, making it a relevant component for security auditing despite being a CLI-focused scanner rather than a full-suite security management platform.

    TypeScriptStatic Code AnalysisCompliance ReportingVulnerability Scanning
    在 GitHub 上查看↗5,428
  • ossf/scorecardossf 的头像

    ossf/scorecard

    5,527在 GitHub 上查看↗

    Scorecard is an open source security scanner and software supply chain analysis tool that evaluates the security posture of projects by calculating risk metrics based on best practices. It functions as a security health dashboard, visualizing security gaps through scores and badges to help maintainers identify vulnerabilities. The project provides a system for monitoring repository security through a GitHub Action security auditor that alerts maintainers when security scores drop. It also offers a mechanism for vulnerability remediation guidance, mapping identified security gaps to prescripti

    This tool provides automated security posture assessment and supply chain vulnerability scanning for repositories, serving as a specialized component for infrastructure and project hardening rather than a full-spectrum network security monitoring suite.

    GoOpen Source Security ScannersSecurity Posture ChecklistsCI/CD Security Metrics Automation
    在 GitHub 上查看↗5,527
  • nmap/nmapnmap 的头像

    nmap/nmap

    13,065在 GitHub 上查看↗

    Nmap is a command-line network security scanner and reconnaissance framework designed for infrastructure mapping and security auditing. It functions as a packet crafting utility that probes target systems to identify active hosts, detect open ports, and determine the services and operating systems running on a network. The tool distinguishes itself through its ability to perform raw socket packet injection and stateful connection tracking, allowing it to bypass standard operating system networking stacks. It utilizes an asynchronous concurrency model to manage large-scale network scans and em

    Nmap is a foundational network security scanner and auditing tool that excels at infrastructure mapping and service discovery, though it focuses on network-level reconnaissance rather than the full suite of application-level security testing or infrastructure hardening features requested.

    CNetwork ScannersPort ScannersNetwork Device Discovery
    在 GitHub 上查看↗13,065
  • greenbone/openvas-scannergreenbone 的头像

    greenbone/openvas-scanner

    4,670在 GitHub 上查看↗

    The openvas-scanner is a vulnerability scanner designed to identify security weaknesses and outdated software in target systems. It performs network vulnerability scanning by executing security tests and network attack scripts, as well as conducting local security auditing through static version checks of installed software. The project utilizes community-managed feeds to synchronize and update local security definitions and vulnerability tests. These tests and scan configurations are loaded into the system via container images or manual transfers and stored in a persistent relational databas

    This is a specialized vulnerability scanner that performs network-based security testing and local auditing, serving as a core component for vulnerability management even though it focuses primarily on scanning rather than the full suite of infrastructure hardening tools.

    RustLocal Software AuditingAttack Script ExecutionContainerized Service Orchestration
    在 GitHub 上查看↗4,670
  • lissy93/web-checkLissy93 的头像

    Lissy93/web-check

    33,721在 GitHub 上查看↗

    Web-check is a self-hosted diagnostic platform designed to perform comprehensive technical reconnaissance and security audits on web domains. It functions as a network scanner that inspects infrastructure by querying IP addresses, DNS records, SSL certificate chains, and server headers to identify potential misconfigurations or vulnerabilities. The platform is built to run within private infrastructure, ensuring that site investigations remain independent of external tracking or third-party data logging. By utilizing server-side request proxying, the tool bypasses client-side security restric

    Web-check is a self-hosted diagnostic platform that performs reconnaissance and security audits on web domains, fitting the category as a specialized tool for identifying infrastructure misconfigurations and vulnerabilities.

    TypeScriptWebsite Diagnostic ToolsInfrastructure MonitoringSecurity Auditing
    在 GitHub 上查看↗33,721
一览前 10 名对比
仓库Star 数语言许可证最后推送
wazuh/wazuh14.8KCother2026年2月20日
anchore/grype12.4KGoApache-2.02026年6月16日
future-architect/vuls12.2KGoGPL-3.02026年6月17日
armosec/kubescape11.5KGoApache-2.02026年6月17日
aquasecurity/trivy36.5KGoApache-2.02026年6月16日
cisofy/lynis15.3KShellgpl-3.02026年1月28日
docker/docker-bench-security9.7KShellApache-2.02026年6月4日
security-onion-solutions/securityonion4.7KShellNOASSERTION2026年6月25日
shadow1ng/fscan13.4KGomit2026年1月31日
zan8in/afrog4.2KGomit2026年2月20日

Related searches

  • 开源网络监控工具
  • an open source firewall for network security
  • 网络安全与分析
  • 开源安全漏洞扫描器
  • 用于捕获和分析网络流量的工具
  • 开源渗透测试框架
  • 开源网络安全防火墙
  • 入侵检测系统