20 Most Popular Open-Source Security & Penetration Testing Tools

The most-starred open-source security and penetration-testing tools — scanners, exploit frameworks, secret detectors and network analyzers — with GitHub links and star counts.

By The DevFixPro Editorial Team · independent editorial research project

Star counts retrieved from the GitHub API on 2026-08-17. Open-source projects grow daily, so treat the numbers as a snapshot — always check the linked repository for the latest figures, license, and activity.

Security work runs on open-source tooling. Below are 20 of the most popular open-source security and penetration-testing tools on GitHub, ranked by stars (fetched 2026-08-17). They cover exploitation, web scanning, network analysis, secret detection and container hardening — each linking to its repository.

Use responsibly: these tools are for authorized testing, your own infrastructure, and bug-bounty programs. Always confirm scope and legality before you scan.

  1. 1Metasploit Framework on GitHub
    By Rapid7

    Penetration-testing framework with exploit development and payloads.

    View on GitHub →
  2. 2OWASP ZAP on GitHub
    OWASP ZAP15,621
    By ZAP Dev Team

    Free, open-source web-application security scanner.

    View on GitHub →
  3. 3Wireshark on GitHub
    Wireshark9,730
    By Wireshark Foundation

    World's foremost network protocol analyzer.

    View on GitHub →
  4. 4Nmap on GitHub
    Nmap13,367
    By Nmap Project

    Network discovery and security auditing scanner.

    View on GitHub →
  5. 5sqlmap on GitHub
    sqlmap38,202
    By sqlmap developers

    Automatic SQL injection and database takeover tool.

    View on GitHub →
  6. 6Hydra on GitHub
    Hydra12,159
    By van Hauser / THC

    Fast network logon cracker supporting many protocols.

    View on GitHub →
  7. 7John the Ripper on GitHub
    John the Ripper13,505
    By OpenWall

    Free password cracker for many hash types.

    View on GitHub →
  8. 8Hashcat on GitHub
    Hashcat26,557
    By Hashcat Team

    World's fastest password recovery and cracking tool.

    View on GitHub →
  9. 9Aircrack-ng on GitHub
    Aircrack-ng7,500
    By Aircrack-ng Team

    Wi-Fi security auditing suite for 802.11.

    View on GitHub →
  10. 10Suricata on GitHub
    Suricata6,551
    By OISF

    High-performance network threat detection engine (IDS/IPS/NSM).

    View on GitHub →
  11. 11Snort on GitHub
    Snort3,403
    By Cisco / Sourcefire

    Lightweight network intrusion detection and prevention system.

    View on GitHub →
  12. 12MobSF on GitHub
    MobSF21,601
    By MobSF Team

    Mobile security framework for Android/iOS static and dynamic analysis.

    View on GitHub →
  13. 13Nuclei on GitHub
    Nuclei30,554
    By ProjectDiscovery

    Template-based vulnerability scanner for fast detection.

    View on GitHub →
  14. 14Gitleaks on GitHub
    Gitleaks28,771
    By Zachary Rice / GitLeaks

    Detect and prevent hardcoded secrets in git repos.

    View on GitHub →
  15. 15TruffleHog on GitHub
    TruffleHog27,492
    By Truffle Security

    Find and verify leaked credentials across git and sources.

    View on GitHub →
  16. 16Trivy on GitHub
    Trivy37,441
    By Aqua Security

    Comprehensive scanner for vulnerabilities, misconfig and secrets.

    View on GitHub →
  17. 17Semgrep on GitHub
    Semgrep16,250
    By Semgrep Inc.

    Fast static analysis (SAST) to find bug and security patterns.

    View on GitHub →
  18. 18WPScan on GitHub
    WPScan9,731
    By WPScan Team

    Black-box security scanner for WordPress installations.

    View on GitHub →
  19. 19BetterCAP on GitHub
    BetterCAP19,811
    By BetterCAP Team

    Swiss-army knife for network attacks and monitoring.

    View on GitHub →
  20. 20Impacket on GitHub
    Impacket16,000
    By Fortra

    Collection of Python classes for working with network protocols.

    View on GitHub →

← Back to Open Source Top Lists