Top #audit Tools & Software

Explore 24 hand-picked tools and software tagged with audit — ranked by popularity and community signals.

shannon

github

Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

Security TypeScript
★ 39,084

lighthouse

github

Automated auditing, performance metrics, and best practices for the web.

Developer Tools JavaScript
★ 30,097

teleport

github

The easiest, and most secure way to access and protect all of your infrastructure.

DevOps Go
★ 20,240

vuls

github

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

Security Go
★ 12,131

the-practical-linux-hardening-guide

github

This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).

Security
★ 10,503

Yearning

github

🐳 A most popular sql audit platform for mysql

Database Go
★ 8,940

DependencyCheck

github

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Security Java
★ 7,530

brakeman

github

A static analysis security vulnerability scanner for Ruby on Rails applications

Security Ruby
★ 7,230

aircrack-ng

github

WiFi security auditing tools suite

Security C
★ 7,188

rundeck

github

Enable Self-Service Operations: Give specific users access to your existing tools, services, and scripts

DevOps
★ 6,095

DeepAudit

github

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。​让安全不再昂贵,让审计不再复杂。

AI Tools Python
★ 5,849

black-hat-rust

github

Applied offensive security with Rust - https://kerkour.com/black-hat-rust

Security Rust
★ 4,323

Harden-Windows-Security

github

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Personal, Enterprise, Government and Military security levels | SLSA Level 3 Compliant for Secure Development and Build Process | Apps Available on MS Store✨

Security C#
★ 4,262

ciso-assistant-community

github

CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, Privacy, and Reporting. It supports 130+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.

Security Python
★ 4,012

xunfeng

github

巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。

Security Python
★ 3,596

pentest-tools

github

A collection of custom security tools for quick needs.

Security Python
★ 3,293

dockle

github

Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start

Security Go
★ 3,250

inspec

github

InSpec: Auditing and Testing Framework

DevOps Ruby
★ 3,066

GScan

github

本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。

Security Python
★ 2,818

pwndoc

github

Pentest Report Generator

Security JavaScript
★ 2,814

bundler-audit

github

Patch-level verification for Bundler

Security Ruby
★ 2,748

windows_hardening

github

HardeningKitty and Windows Hardening Settings

Security Shell
★ 2,618

find-sec-bugs

github

The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)

Security Java
★ 2,422

masvs

github

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

Security Python
★ 2,367