Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: vulnerability-scanning

447 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
WyAtu/Perun
Perun is a Python-based network asset vulnerability scanner and scanning framework designed for penetration testers and red teams, primaril…
321051abandoned
utkusen/leviathan
Leviathan is a Python-based mass audit toolkit that combines masscan, ncrack, and DSSS to discover services, brute-force credentials, detec…
101041abandoned
MicrosoftEdge/static-code-scan
A deprecated Node.js static code scanner from Microsoft Edge (formerly modern.IE) that analyzes a URL's HTML, CSS, and JavaScript for issue…
101038abandoned
AndroidVTS/android-vts
An on-device Android app that scans a device for known vulnerabilities such as kernel and framework bugs (e.g., Towelroot, Master Keys). It…
231034abandoned
usestrix/strix
Strix is an open-source AI penetration testing tool that deploys autonomous agents to find, validate, and fix application vulnerabilities. …
8458564active
promptfoo/promptfoo
Promptfoo is an open-source CLI and library for evaluating and red-teaming LLM applications, prompts, agents, and RAG pipelines. It support…
9224603active
Wazuh
Wazuh is a free, open source security platform that unifies XDR and SIEM capabilities for threat prevention, detection, and response across…
9816691stable
Semgrep
Semgrep is a fast, open-source static analysis tool that searches code, finds bugs, and enforces secure coding standards using rules that l…
9516409active
google/oss-fuzz
OSS-Fuzz is Google's free continuous fuzzing service for open source software, combining fuzzing engines like libFuzzer, AFL++, and Honggfu…
7712594active
0x4m4/hexstrike-ai
HexStrike AI is an MCP server that bridges LLM agents (Claude, GPT, Copilot) with 150+ cybersecurity tools for autonomous penetration testi…
6111381active
six2dez/reconftw
reconFTW is an open-source (MIT) automated reconnaissance framework written in Shell that orchestrates 80+ security tools to perform full r…
868025active
simplifaisoul/osiris
OSIRIS is an open-source, real-time global intelligence (OSINT) dashboard that aggregates live flight tracking, maritime, CCTV, seismic, fi…
587992active
superagent-ai/superagent
Superagent is an open-source SDK and platform for securing AI applications and agents, offering runtime guardrails that block prompt inject…
786719active
google/syzkaller
syzkaller is an unsupervised coverage-guided kernel fuzzer originally built for the Linux kernel and now supporting FreeBSD, Fuchsia, gViso…
776309active
aidlearning/AidLearning-FrameWork
AidLux (originally AidLearning) is an AIoT development platform that runs a native Ubuntu Linux environment with GUI, deep learning tooling…
705797active
gadievron/raptor
RAPTOR is an autonomous offensive/defensive security research framework built on top of Claude Code, chaining static analysis, binary analy…
663672active
crytic/echidna
Echidna is a Haskell-based fuzzer for Ethereum smart contracts that performs property-based testing by generating sequences of contract cal…
893170active
microsoft/restler-fuzzer
RESTler is the first stateful REST API fuzzing tool, automatically testing cloud services through their REST APIs to find security and reli…
712939active
google/osv.dev
OSV (Open Source Vulnerabilities) is Google's open, distributed vulnerability database and triage service that aggregates security advisori…
842901stable
sheeki03/tirith
Tirith is a Rust-based terminal security tool that intercepts shell commands, pasted content, and files to block threats like homograph URL…
782683active
cve-search/cve-search
cve-search is a tool-set that imports CVE and CPE data into a local MongoDB to enable fast, private searching of known software vulnerabili…
842642active
MegaManSec/SSH-Snake
SSH-Snake is a self-propagating, file-less bash script that automatically discovers SSH private keys on a system, attempts to connect to re…
102342active
lz520520/railgun
Railgun is a GUI-based penetration testing tool that automates common tasks from manual pentesting experience. It integrates port scanning,…
352289active
learnhouse/learnhouse
LearnHouse is a next-generation open-source learning management system (LMS) for creating, sharing, and selling educational content. It com…
992203active
nsonaniya2010/SubDomainizer
SubDomainizer is a Python CLI tool that discovers hidden subdomains and secrets in webpages, external JavaScript files, GitHub, and local f…
661886active
metlo-labs/metlo
Metlo is an open-source API security platform that inventories API endpoints, detects malicious traffic in real time, and can automatically…
381783active
quentinhardy/odat
ODAT (Oracle Database Attacking Tool) is an open-source Python penetration testing tool for assessing the security of remote Oracle Databas…
571776active
project-copacetic/copacetic
Copa (Project Copacetic) is a Go CLI tool built on BuildKit that directly patches OS package vulnerabilities in container images without re…
911700active
Pentest AI
pentest-ai is an MIT-licensed local CLI and MCP server that turns Claude Code (or any LLM) into an offensive security assistant, pairing 50…
801629active
guacsec/guac
GUAC (Graph for Understanding Artifact Composition) is an OpenSSF incubating project that ingests software security metadata such as SBOMs,…
901534active
akto-api-security/akto
Akto is an open-source API and AI security platform that discovers and inventories APIs, AI agents, MCP servers, and LLM usage, then contin…
941505active
Jackalope
Jackalope is a customizable, coverage-guided fuzzer for black-box binaries built on the TinyInst instrumentation library by Google Project …
771380active
ION28/BLUESPAWN
BLUESPAWN is an open-source active defense and endpoint detection and response (EDR) tool for Windows. It helps blue teams detect, identify…
691334active
stackrox/stackrox
StackRox is a Kubernetes security platform that performs risk analysis of container environments, delivers visibility and runtime alerts, a…
951306active
adminsyspro/proxcenter-ui
ProxCenter is a self-hosted, open-core datacenter management platform that acts as a centralized control plane for Proxmox VE clusters and …
831293active
CodeIntelligenceTesting/jazzer
Jazzer is a coverage-guided, in-process fuzz testing engine for the JVM, based on libFuzzer. It integrates with JUnit 5 and build tools lik…
861254active
BehiSecc/VibeSec-Skill
VibeSec-Skill is an AI skill (prompt/instruction pack) that teaches LLM coding assistants like Claude Code, Cursor, Codex, Copilot, and Ant…
461220active
Quitten/Autorize
Autorize is a Burp Suite extension, written in Jython, that automatically detects authorization and authentication enforcement flaws in web…
561169active
fuzzland/ityfuzz
ItyFuzz is a blazing-fast bytecode-level hybrid fuzzer for EVM and MoveVM smart contracts that combines symbolic (concolic) execution with …
551108active
GamehunterKaan/AutoPWN-Suite
AutoPWN Suite is a Python-based automated vulnerability scanning and exploitation framework that wraps nmap for host discovery, version-bas…
941094active
w-digital-scanner/w12scan
w12scan is a self-hosted network asset discovery engine that aggregates scan results into a searchable web interface backed by Elasticsearc…
231331maintenance
yhy0/github-cve-monitor
A Python application that monitors GitHub every few minutes for newly published CVEs, security tool updates, and activity on watched reposi…
321195maintenance
sh4hin/Androl4b
AndroL4b is an Ubuntu MATE-based virtual machine preloaded with Android security, reverse engineering, and malware analysis tools such as R…
321166maintenance
Abacus-Group-RTO/legion
Legion is an open-source, semi-automated network penetration testing framework with a graphical interface, forked from Sparta. It orchestra…
101057maintenance
quentinhardy/msdat
MSDAT is an open-source Python penetration testing tool for remotely testing the security of Microsoft SQL Server databases. It supports cr…
321016maintenance
aliasrobotics/cai
Cybersecurity AI (CAI) is an open-source Python framework of specialized AI agents for offensive security tasks such as penetration testing…
109810abandoned
yahoo/gryffin
Gryffin is a large-scale web security scanning platform written in Go, built on a publisher-subscriber architecture for horizontal scaling.…
102052abandoned

← prev page 5 / 5