Seismograph

What’s gaining stars on GitHub right now

Security: what’s taking off on GitHub

The fastest-growing repositories in “Security”: plain-language summaries, use cases and a check on star quality. Updated every 30 minutes.

  1. 7.0
    SnailSploit/Claude-Red

    A curated library of drop-in SKILL.md files for the Claude Skills system that primes Claude with offensive security methodology, from SQL injection to EDR evasion and exploit development.

    BreakoutSecurityPython+387 stars in a day

  2. 6.2
    vxcontrol/pentagi

    Autonomous multi-agent system in Go for automated penetration testing: AI agents plan and execute steps in an isolated Docker sandbox with 20+ tools (nmap, metasploit, sqlmap).

    BreakoutSecurityGo+390 stars in a day

  3. 5.0
    hezhanleiok/freesub

    Automatically tests and publishes subscription pools of free proxy nodes (VLESS, VMess, Trojan, Shadowsocks, Hysteria2, TUIC, AnyTLS), filtering out dead and hijacked nodes via real HTTPS handshakes and TLS validation.

    Early signalSecurityPython+50 stars in a day

  4. 4.9
    tsymbaluyk/maskgate

    PII masking service that detects passports, tax IDs, SNILS, bank cards, phones, medical data and secrets in text and files and masks them before they reach ChatGPT, Claude, Gemini. Source code is proprietary; this repo…

    Early signalSecurity+44 stars in a day

  5. 4.3
    zhihui-hu/one-ip

    Web tool for IP lookups: identifies datacenter, VPN, Tor and proxy usage, rates reputation from 0 to 100, shows ASN, WHOIS, DNS, CDN, geolocation and checks AI service reachability.

    Early signalSecurityTypeScript+17 stars in a day

  6. 4.2
    realchendahuang/feedsieve

    A Chrome extension that flags spam accounts on X (Twitter) with a yellow border and lets you block them manually or in bulk via the native API, synced across all devices.

    Early signalSecurityTypeScript+46 stars in a day

  7. 4.1
    angusdevgo/IDM_Pro_Tool

    A C# tool for activating and maintaining Internet Download Manager: patches IDMan.exe, freezes the trial via ACL, edits registry and hosts. Presented as a learning project on reverse engineering and PE structure.

    CoolingSecurityC#+74 stars in a day

  8. 3.8
    martin-olivier/airgorah

    Airgorah is a WiFi security auditing tool written in Rust with a GTK4 GUI, built on the aircrack-ng suite. It can capture nearby WiFi traffic, discover clients, perform deauthentication attacks, capture handshakes, and…

    BreakoutSecurityRust+91 stars in a day

  9. 3.4
    SyntaxMethod/CVE-2026-41089-Netlogon-RCE-PoC

    Repository for controlled validation of the Netlogon RCE vulnerability (CVE-2026-41089) and defensive telemetry collection in an isolated lab.

    Early signalSecurity+14 stars in a day

  10. 3.4
    Sadpainy/Stuxnet

    An educational reconstruction of the Stuxnet worm's source code in C, derived from decompiled 2010 binaries. Intended for studying APT attack logic against ICS and developing defensive tools.

    CoolingSecurityC+9 stars in a day

  11. 3.4
    SyntaxMethod/CVE-2026-42978-PoC-Research

    Module for AI Security Tool covering CVE-2026-42978, a use-after-free and race condition in Windows Push Notifications (WpnService), with a safe check profile and detection pack for local privilege-escalation audits.

    Early signalSecurity+13 stars in a day

  12. 3.3
    LYiHub/pub-dsh-privacy-router

    A DeepSeek Harness plugin that routes each request to a local or cloud model based on a local privacy check, sending only requests classified as public to the cloud. Ships the host-side routing only.

    Early signalSecurityJavaScript+11 stars in a day

  13. 3.2
    lkimuk/ReArk

    Desktop reverse engineering and AI-assisted analysis tool for HarmonyOS (HAP/APP/ABC) and Android (APK/AAB) apps: static analysis, disassembly, device workflows, and ReArk Agent.

    Early signalSecurityC+++10 stars in a day

  14. 3.1
    xiaYuTian11/maskit

    Local privacy gateway that masks sensitive data (keys, PII, internal IPs) in LLM requests and streams responses back with originals restored. Works with any tool that lets you change the Base URL.

    Early signalSecurityPython+5 stars in a day

  15. 3.0
    Flowseal/zapret-discord-youtube

    A Windows bundle of the zapret utility packaged as batch scripts: bypasses DPI blocking of Discord and YouTube via WinDivert, with service autostart and a set of ready-made strategies.

    SteadySecurityBatchfile+53 stars in a day

  16. 2.9
    sherlock-project/sherlock

    Python CLI tool that hunts down accounts by one or more usernames across 400+ social networks. Used in OSINT and reconnaissance to check a user's online presence.

    SteadySecurityPython+54 stars in a day

  17. 2.7
    henryzawadzki6542/cloudflare-turnstile-bypass

    Dependency-free Python library and CLI that bypasses Cloudflare Turnstile: finds the sitekey on a page and obtains a valid cf-turnstile-response token via the Peak service. Built for CI pipelines, QA automation, and…

    CoolingSecurityPython+1 stars in a day

  18. 2.7
    guillaumemeyer/watermarks-remover

    A Python service and agent skill that strips AI provenance marks (invisible Unicode, statistical watermarks, C2PA/EXIF/XMP metadata) from text and files you own.

    CoolingSecurityPython+63 stars in a day

  19. 2.5
    trufflesecurity/trufflehog

    TruffleHog is a Go tool for finding leaked credentials: it scans Git, chats, wikis, logs and filesystems, classifies secrets across 800+ types, and verifies whether they are still live. It is aimed at security teams…

    SteadySecurityGo+19 stars in a day

  20. 2.4
    forefy/reburp

    A Burp Suite extension that exposes the full Montoya API over a local REST server with an OpenAPI spec and Swagger UI, for automating Burp.

    Early signalSecurityKotlin+17 stars in a day

  21. 2.4
    nicocha30/ligolo-ng

    A tunneling/pivoting tool for pentesters that creates a TUN-interface tunnel into a remote network instead of using a SOCKS proxy. The agent runs unprivileged, while the relay side uses a Gvisor-based userland network…

    SteadySecurityGo+11 stars in a day

  22. 2.4
    Minglink/dsh-infinite-gen-4

    A DeepSeek Harness plugin that injects system prompts to jailbreak DeepSeek V4.1/V4 Flash models, bundled with a deterministic regression test suite and benchmarks for red-team robustness evaluation against prompt…

    SteadySecurityJavaScript+28 stars in a day

  23. 2.0
    furkan-bayrak/lg-tv-blocklist

    A curated DNS blocklist for LG webOS TV telemetry, ads and phone-home traffic, with SAFE and STRICT tiers. For LG TV owners running Pi-hole, AdGuard Home or NextDNS who want to limit what the TV reports home.

    CoolingSecurityPython+20 stars in a day

  24. 1.9
    QuiteAFancyEmerald/InvisiProxy

    A web proxy for bypassing network and client-side blocks directly in the browser with no install: lets you open blocked sites and Tor/Onion resources while hiding activity. Designed for self-hosting.

    SteadySecurityJavaScript+2 stars in a day

  25. 1.5
    openai/codex-security

    OpenAI's CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in code, and for drafting SECURITY.md security policy.

    CoolingSecurityTypeScript+9 stars in a day

  26. 1.5
    authelia/authelia

    Authelia is an authentication and authorization server providing SSO, 2FA and OpenID Connect, acting as a companion for reverse proxies to allow, deny or redirect requests.

    SteadySecurityGo+11 stars in a day

  27. 1.5
    kangleyao/slider-captcha-lab

    A toolkit for automatically solving AliyunCaptcha slider puzzles: YOLO gap detection, human-like drag trajectory generation, and CDP event injection. Aimed at captcha robustness research and testing in owned…

    CoolingSecurityPython+1 stars in a day

  28. 1.4
    wazuh/wazuh

    Open source security platform with endpoint agents and a management server: intrusion detection, log analysis, file integrity monitoring, vulnerability detection and incident response.

    SteadySecurityC+++10 stars in a day

  29. 1.4
    elder-plinius/T3MP3ST

    Multi-agent red-teaming platform that turns an existing AI coding agent into a vulnerability-hunting harness, automating the recon → exploit → report kill chain for web apps, CTFs, smart contracts, and source code.

    CoolingSecurityTypeScript+10 stars in a day

  30. 1.4
    Atomburstofficial/geiger

    A tool that inventories every AI agent, MCP server, plugin, and extension on a machine: one read-only command shows what is installed and what it can reach. Built for auditing and governing what actually runs on a…

    CoolingSecurityJavaScript+3 stars in a day

  31. 1.3
    nmatt0/moria

    IoT firmware identification and extraction tool: locates filesystems, kernels, bootloaders, archives and keys inside firmware images and unpacks them without root, reporting offsets, types and confidence in JSON.

    CoolingSecurityC+++5 stars in a day

  32. 1.2
    nmatt0/mithril

    C++ static scanner for firmware and IoT software: finds embedded secrets and keys, builds an SBOM, matches components against CVEs, and detects licenses, fully offline and emitting JSON.

    CoolingSecurityC+++4 stars in a day

  33. 1.1
    anthropics/defending-code-reference-harness

    A reference implementation for autonomous vulnerability discovery and remediation in source code using Claude: skills for threat modeling, scanning, triage, and patching, plus a pipeline with gVisor sandboxing.

    SteadySecurityPython+10 stars in a day

  34. 1.1
    MSNightmare/ShieldCrash

    PoC exploit for Windows Defender that bypasses the ShieldBreak patch (CVE-2026-69414), demonstrating arbitrary file read as SYSTEM on all supported Windows versions.

    CoolingSecurityC+++3 stars in a day

  35. 1.1
    perplexityai/bumblebee

    A Go tool that scans developer machines for supply-chain exposure by reading on-disk package, extension, and MCP config metadata and matching it against a catalog of known compromises.

    SteadySecurityGo+4 stars in a day

  36. 1.1
    bikini/exploitarium

    An archive of public proof-of-concept exploits and vulnerability research writeups covering browsers, archivers, SSH, Docker and other widely used software. Collected by a researcher to teach and attract people into…

    CoolingSecurityPython+5 stars in a day

  37. 1.0
    Sophomoresty/turnstile-bypass

    Python tool that drives headed Chrome to solve Cloudflare Turnstile widgets and interstitial "Just a moment" pages, returning a token or cf_clearance cookie. Useful for automating access to Cloudflare-protected sites.

    CoolingSecurityPython+2 stars in a day

  38. 0.8
    Supersonic/TLPE

    PoC and writeup for CVE-2026-49881, a logic flaw in Android 17's Telecom InCallController that lets an unprivileged app execute code as UID 1000 system_server with no user interaction.

    CoolingSecurityKotlin+2 stars in a day

  39. 0.3
    N4darae/anti-mage

    A Go server that checks browser environment coherence across 23 independent readings and returns a score from 0 to 90 based on how much the browser contradicts itself. It detects anti-detect browsers and spoofed…

    CoolingSecurityGo+0 stars in a day

  40. 0.2
    LuckinSven/8086-xcheck-system

    Self-hosted IP reputation investigation system: accepts IP lists and logs, filters through a whitelist, and submits public addresses to the ThreatBook API at a controlled rate.

    SteadySecurityPython+0 stars in a day

  41. 0.0
    sashyo/minidauth

    Decentralised auth layer that moves the signing/encryption key out of your server into the Tide network, where it exists only as shares reconstructed by a threshold of independent nodes. Aimed at teams holding…

    CoolingSecurityJava+0 stars in a day