Showing 29 open source projects for "security audit"

View related business solutions
  • Veeam Data Platform v13.1 - Get Your Free Trial Icon
    Veeam Data Platform v13.1 - Get Your Free Trial

    Secure by design, portable by default. Recover clean, fast, anywhere. Start a free trial.

    Try Veeam Data Platform today. Experience the unified platform that's secure by design, portable by default, and proven to recover clean, fast, and anywhere.
    Try it Free
  • Train ML Models With SQL You Already Know Icon
    Train ML Models With SQL You Already Know

    BigQuery automates data prep, analysis, and predictions with built-in AI assistance.

    Build and deploy ML models using familiar SQL. Automate data prep with built-in Gemini. Query 1 TB and store 10 GB free monthly.
    Start Free
  • 1
    Sippts

    Sippts

    Set of tools to audit SIP based VoIP Systems

    Sippts is a set of tools to audit VoIP servers and devices using SIP protocol. Sippts is programmed in Python and it allows us to check the security of a VoIP server using SIP protocol. You can freely use, modify and distribute. If modified, please put a reference to this site. Most security tools can be used for illegal purposes, but the purpose of this tool is to check the security of your own servers and not to use to do bad things.
    Downloads: 4 This Week
    Last Update:
    See Project
  • 2
    HOL Guard

    HOL Guard

    Open-source antivirus for AI agents

    HOL Guard is an open-source security layer designed to protect AI agents and their local tool ecosystems at runtime. It evaluates supported actions for secret exposure, prompt injection, unsafe commands, malicious packages, and risky MCP interactions. Safe operations can proceed automatically, while known threats are blocked and ambiguous actions can require human approval. The platform also examines plugins, skills, hooks, package installs, and agent configurations before they are trusted....
    Downloads: 114 This Week
    Last Update:
    See Project
  • 3
    Watcher

    Watcher

    Open Source Cybersecurity Threat Hunting Platform

    Watcher is a file integrity monitoring tool that detects unauthorized changes to files, helping organizations maintain compliance and security.
    Downloads: 2 This Week
    Last Update:
    See Project
  • 4
    SSH-MITM

    SSH-MITM

    Server for security audits supporting public key authentication

    ssh man-in-the-middle (ssh-mitm) server for security audits supporting publickey authentication, session hijacking and file manipulation. SSH-MITM is a man in the middle SSH Server for security audits and malware analysis. Password and publickey authentication are supported and SSH-MITM is able to detect, if a user is able to login with publickey authentication on the remote server. This allows SSH-MITM to accept the same key as the destination server. If publickey authentication is not...
    Downloads: 3 This Week
    Last Update:
    See Project
  • MongoDB Atlas runs apps anywhere Icon
    MongoDB Atlas runs apps anywhere

    Deploy in 115+ regions with the modern database for every enterprise.

    MongoDB Atlas gives you the freedom to build and run modern applications anywhere—across AWS, Azure, and Google Cloud. With global availability in over 115 regions, Atlas lets you deploy close to your users, meet compliance needs, and scale with confidence across any geography.
    Start Free
  • 5
    JumpServer

    JumpServer

    Manage assets on different clouds at the same time

    The JumpServer bastion machine complies with the 4A specification of operation and maintenance security audit. Zero threshold, fast online acquisition and installation. Just a browser, the ultimate Web Terminal experience. Easily support massive concurrent access. One system manages assets on different clouds at the same time. Audit recordings are stored in the cloud and will never be lost. One system, is used by multiple subsidiaries and departments at the same time. ...
    Downloads: 5 This Week
    Last Update:
    See Project
  • 6
    Claude Ads

    Claude Ads

    Comprehensive paid advertising audit & optimization skill

    Claude Ads is an AI-powered auditing and optimization tool designed to analyze paid advertising campaigns across multiple platforms using Claude Code. It processes user-provided data such as exports or screenshots and evaluates campaigns using hundreds of predefined checks. The system generates structured reports, identifies inefficiencies, and suggests optimization strategies based on industry benchmarks. It supports platforms like Google Ads, Meta Ads, TikTok, LinkedIn, and more, offering...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 7
    SIPVicious

    SIPVicious

    Security tools that can be used to audit SIP based VoIP systems

    SIPVicious OSS has been around since 2007 and is actively updated to help security teams, QA and developers test SIP-based VoIP systems and applications. Open-source security suite for auditing SIP based VoIP systems. Also known as friendly-scanner, it is freely available to help pentesters, security teams and developers quickly test their SIP systems. Download the latest source code from git or the latest release, send pull requests and open issues. Install the latest and greatest release...
    Downloads: 2 This Week
    Last Update:
    See Project
  • 8
    HexStrike AI MCP Agents

    HexStrike AI MCP Agents

    HexStrike AI MCP Agents is an advanced MCP server

    HexStrike AI is an MCP server that lets LLM agents autonomously operate a large catalog of offensive-security tools. Its goal is to bridge “language models” and practical pentest workflows—enumeration, exploitation, vulnerability discovery, and bug bounty reconnaissance—under safe, auditable controls. The server exposes typed tools and guardrails so agent prompts translate to concrete, parameterized actions rather than brittle shell strings. It ships with curated tool adapters, task...
    Downloads: 9 This Week
    Last Update:
    See Project
  • 9
    AutoCVE

    AutoCVE

    Agent-driven automated CVE discovery platform for source code auditing

    AutoCVE is an agent-driven platform for automating authorized source-code auditing and CVE discovery. It covers the workflow from project selection and repository import to vulnerability verification and submission-ready report generation. An orchestrator coordinates specialized agents for reconnaissance, scanning, triage, deep analysis, verification, and final consolidation. Users can choose enhanced scanning, intelligent auditing, or comprehensive auditing based on speed and depth...
    Downloads: 0 This Week
    Last Update:
    See Project
  • Build Agents and Models on One Platform Icon
    Build Agents and Models on One Platform

    Everything you need to build production-ready agents and models. Access 200+ Google and third-party AI models and tools.

    Gemini Enterprise Agent Platform is Google Cloud's comprehensive platform for developers to build, scale, govern, and optimize agents and models. Choose from Google's most advanced models and third-party models like Anthropic's Claude Model Family.
    Start Free
  • 10
    DeepAudit

    DeepAudit

    AI multi-agent platform for automated code security auditing system

    DeepAudit is an open source code security auditing platform that uses a multi-agent architecture to analyze and identify vulnerabilities in software projects. Instead of relying solely on traditional static analysis, it simulates the reasoning process of security experts through coordinated agents responsible for orchestration, reconnaissance, analysis, and verification.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 11
    Kiro Crew

    Kiro Crew

    A persistent workspace for development work that self-improves

    ...The system supports subagents, reusable skills, MCP tools, scheduled jobs, reactive webhooks, and installable workflow-specific apps. Users can interact through a desktop app, web dashboard, CLI, or messaging services such as Slack, Discord, Telegram, Teams, and WeChat. Security controls include approvals, sandboxing, sensitive-path protection, credential redaction, deny rules, audit events, and governance policies.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 12
    Flan Scan

    Flan Scan

    A pretty sweet vulnerability scanner

    Flan Scan is a lightweight open-source network vulnerability scanner designed to make it easy to detect exposed services, open ports, and associated vulnerabilities across IP ranges or network segments as part of security audit and compliance workflows. It is essentially a thin wrapper around the widely-used Nmap scanner, augmenting it with scripts and tooling that transform raw Nmap output into vulnerability-focused reports that map detected services to known CVEs, making results more actionable for administrators and auditors. Flan Scan supports automated builds via Docker and can be deployed in containers or Kubernetes clusters, allowing organizations to run scans consistently across distributed environments. ...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 13
    Timesketch

    Timesketch

    Collaborative forensic timeline analysis

    Timesketch is a collaborative forensic timeline analysis platform used to investigate security incidents by turning diverse evidence into a single, searchable chronology. Analysts ingest logs and artifacts from many sources—endpoints, servers, cloud services—and Timesketch normalizes them into events on a unified timeline. Powerful search, aggregations, and saved views help you pivot quickly, highlight anomalies, and preserve investigative steps for later review.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 14
    Sentry

    Sentry

    Cross-platform application monitoring and error tracking software

    Sentry is a cross-platform, self-hosted error monitoring solution that helps software teams discover, monitor and fix errors in real-time. The most users and logs will have to provide are the clues, and Sentry provides the answers. Sentry offers enhanced application performance monitoring through information-laden stack traces. It lets you build better software faster and more efficiently by showing you all issues in one place and providing the trail of events that lead to errors. It also...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 15

    kavach

    Self-hosted, multi-user password manager that tells you which secrets

    Downloads: 1 This Week
    Last Update:
    See Project
  • 16
    FlowBench

    FlowBench

    Network stress testing & monitoring tool with legal compliance

    NetPulse is a Windows app for network stress testing and performance monitoring, built with Python + PySide6. Features: - Stress Test: HTTP/HTTPS/TCP/UDP/ICMP; live QPS, latency percentiles, traffic stats - Collaborative Testing: invite-code based host/node modes; LAN direct or MQTT relay - Real-time monitoring of CPU/memory/network - Plugin System: built-in marketplace, one-click install/publish, extend with your own plugins - Dark/light theme, custom theme color, Chinese-English...
    Downloads: 18 This Week
    Last Update:
    See Project
  • 17
    STAYZER

    STAYZER

    SSH Trust Analyzer for Linux Infrastructure

    ...It discovers who can access each machine, detects shared SSH keys, identifies potentially risky trust relationships, and generates detailed reports in both human-readable and machine-readable formats. Designed for Linux administrators, DevOps engineers, and security professionals, STAyzer makes it easy to audit SSH trust across dozens or hundreds of servers.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 18
    AAD-50

    AAD-50

    Zero-trust storage erasure. Hardware-verified data destruction.

    AAD-50 is an open-source NVMe sanitization framework that closes a 15-year verification gap in Linux nvme-cli. The standard nvme sanitize command returns immediately after acceptance without confirming the drive actually completed the background erasure. AAD-50 fixes this by polling NVMe Log Page 0x81 (Sanitize Status) after every cycle and refusing to advance until SSTAT=0x1 confirms hardware completion. Implements a 50-cycle B→C→A phase matrix: 40 cycles NAND overwrite, 5 FTL block...
    Downloads: 9 This Week
    Last Update:
    See Project
  • 19

    SENTINEL

    Open-source behavioral intelligence platform for detecting child groom

    SENTINEL is an open-source behavioral intelligence platform for detecting child grooming on digital platforms. Released by Sentinel Foundation in April 2026, it analyzes patterns of user behavior over time rather than scanning message content for keywords, identifying grooming sequences before direct harm occurs. Key capabilities: - Behavioral scoring across four signal types: linguistic register shifts, relationship graph evolution, temporal escalation patterns, and fairness gates -...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 20
    REDACT

    REDACT

    Erase everything. Leave nothing.

    REDACT 4.0.0 is an open-source Windows anti-forensics & artifact sanitization suite that permanently destroys 285 system artifacts — browser history, registry traces, NTFS change journals, Windows Recall AI snapshots, live RAM, and encrypted volume key material. New in 4.0.0: Auto-Trigger Engine — 7 triggers: USB Panic, Login Failure, Dead Man's Switch, VPN Disconnect, WiFi Change, Time Window, Forensic Tool Detection. BitLocker and VeraCrypt header destruction renders encrypted...
    Downloads: 4 This Week
    Last Update:
    See Project
  • 21
    wpa-dictionary

    wpa-dictionary

    WPA/WPA2 password dictionary for Wi-Fi password brute force cracking

    ...The README is written as a bilingual Chinese and English security-testing guide around Aircrack-ng-style workflows. Because the project is directly related to password cracking, it should only be used for networks the tester owns or is explicitly authorized to audit.
    Downloads: 18 This Week
    Last Update:
    See Project
  • 22
    DepHell

    DepHell

    Python project management. Manage packages

    DepHell is a Python packaging and dependency management tool that aims to unify and simplify the Python packaging ecosystem. It can convert between various formats (Pipfile, poetry, setup.py, etc.), manage virtual environments, and ensure reproducible builds. It's a powerful tool for Python developers juggling complex dependencies.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 23
    privacyidea

    privacyidea

    two factor authentication management system

    privacyIDEA is a management and authentication system for two factor authentication. You can use OTP tokens, OTP cards, SMS, Smartphone Apps to incorparte the second factor. It can even manage SSH keys and supports Offline OTP. The latest version can manage and enroll user certificates. Its modular design makes it easily enhancable. It runs on Linux. Applications and workflows can be connected to privacyIDEA hence enabling two factor authentication in your system logon, web...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 24
    w3af
    w3af, is a Web Application Attack and Audit Framework. The w3af core and it's plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross site scripting (xss), local and remote file inclusion and much more. This project has been migrated to github! See details in our project site: http://w3af.org/
    Downloads: 16 This Week
    Last Update:
    See Project
  • 25
    ... aims to be a library providing access to a base of extensions related to specific computer security tasks (scanning, vulnerability checks etc) implemented as Extensions (in Python for now), which are interdependent due to the provide/require mechanism
    Downloads: 0 This Week
    Last Update:
    See Project
  • Previous
  • You're on page 1
  • 2
  • Next