Exploring innovative GitHub projects to follow
As I’ve been cleaning up my digital workspace and organising my notes, I stumbled upon a rapidly expanding collection of fascinating github projects that I currently follow. While I actively deploy some of these tools in my daily professional endeavours, I merely observe others out of profound technical curiosity.
Why share this collection of GitHub projects?
Indeed, I firmly believe in the power of knowledge sharing within the technology community. Specifically, these github projects have captured my attention for various reasons. For instance, they offer an innovative approach, practical applications, or massive potential for future integration.
Furthermore, this remains very much a “work in progress” collection. Consequently, as I continue to explore and experiment with different frameworks, I will constantly update and refine this list. While some repositories are well-established, others undoubtedly represent emerging stars in their respective domains.
The structure of this collection
Previously, this list was an intentionally unordered, raw collection of projects. However, to make it more accessible, I have now organised these repositories into meaningful categories below. Moving forward, I still plan to:
- First, add them to Not The Hidden Wiki‘ Github repo
- Second, provide even more detailed context for each specific project.
- Finally, share my direct experiences with the tools I have actively implemented.
Therefore, consider this a peek into my professional bookmarks. Overall, it serves as a curated collection of github projects worth keeping an eye on.
Categorised GitHub Projects List
Security, SOC & Threat Hunting
- Not The Hidden Wiki – the largest repository of links related to cybersecurity. We believe that knowledge should be free! So we collected many valuable links from various specialists in their fields and created this wiki. Regardless of whether you are just starting your adventure with cybersecurity or you have been in this world for a long time, you will definitely find something for yourself on this wiki – https://github.com/notthehiddenwiki/nthw
- Security lists for SOC/DFIR detections – Awesome Security lists for SOC/CERT/CTI – https://github.com/mthcht/awesome-lists
- Advanced Threat Hunting: Ransomware Groups & Affiliates – this repository documents ransomware arsenals and exploited CVEs. It details associated TTPs used by ransomware groups. It focuses heavily on lesser-known threats – GitHub – CTI-Driven/Advanced-Threat-Hunting-Ransomware-Groups-Affiliates: Advanced Threat Hunting: Ransomware Group
- KQL Cheat Sheet for Real Time Intelligence – a community-driven reference for Kusto Query Language. It is tailored for Real Time Intelligence scenarios. It provides practical examples and best practices – GitHub – kustonaut/kql-cheat-sheet: Kustonaut’s KQL Cheat Sheet
- KQL queries by Sergio Albea – GitHub – Sergio-Albea-Git/Threat-Hunting-KQL-Queries
- Sample KQL queries for Advanced hunting in Microsoft 365 Defender – GitHub – microsoft/Microsoft-365-Defender-Hunting-Queries: Sample queries for Advanced hunting in Microsoft 365 Defender
- Must Learn KQL – this includes a blog series, completion certificate, and a book. You will also find a video channel and workshop here – https://github.com/rod-trent/MustLearnKQL
- Hunting Queries Detection Rules – KQL queries for Microsoft Defender, Microsoft Sentinel – https://github.com/SlimKQL/Hunting-Queries-Detection-Rules/
- Just another Kusto hacker (“JAKH”) contest – https://github.com/microsoft/just-another-kusto-hacker
- KQLIntel – a browser-based tool that uses LLMs to convert threat intelligence reports into actionable Kusto Query Language (KQL) queries by extracting IOCs from URLs or raw text – https://github.com/Var5h1l/KQLIntel
- sKaleQL – an opinionated template repository for managing, executing, and organizing Kusto Query Language (KQL) queries against Azure Log Analytics Workspaces – https://github.com/mthcht/awesome-lists
- 𝗦𝗹𝗶𝗺𝗞𝗤𝗟 – GitHub – SlimKQL/Hunting-Queries-Detection-Rules: KQL Queries. Microsoft Defender, Microsoft Sentinel
- SOC-RESSOURCES – GitHub – DXC-0/SOC-Ressources: Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IOC and monitoring.
- MS-Attack-Range – a tool for creating a small lab environment. Security teams can simulate attacks here safely. It generates data in Microsoft Sentinel for detection testing – https://github.com/oloruntolaallbert/MS-Attack-Range/
- Sigma – Generic Signature Format for SIEM Systems – GitHub – SigmaHQ/sigma: Main Sigma Rule Repository
- Tools – curated list of security tools – https://github.com/rmkanda/tools
Azure, Cloud Management & Identity
- WinTuner – GitHub – svrooij/WinTuner: Package any app from Winget to Intune – WinTune
- Autopilot Branding – this contains a sample PowerShell script. You can package it into an Intune Win32 app. It customises Windows 10 devices via Windows Autopilot (although there’s no reason it can’t be used with other deployment processes, e.g. MDT or ConfigMgr) – GitHub – mtniehaus/AutopilotBranding
- Azure samples – Azure Samples · GitHub
- Azure Cost Anomaly Alert Manager – a Python-based command-line tool for managing Azure Cost Management anomaly alerts across multiple subscriptions. This tool helps you automatically detect and create cost anomaly alerts for Azure subscriptions, ensuring you stay informed about unexpected cost spikes – GitHub – p4pryk/CostAnomalyCreator
- Azure MCP Server – implements the MCP specification to create a seamless connection between AI agents and Azure services. Azure MCP Server can be used alone or with the GitHub Copilot for Azure extension in VS Code. This project is in Public Preview and implementation may significantly change prior to our General Availability – https://github.com/Azure/azure-mcp
- Azure Vulnerability Report Generator – this application connects to Azure using the Microsoft Graph API to detect and report security vulnerabilities across your Azure resources. It provides a modern, user-friendly interface for selecting subscriptions, fetching vulnerability data, and generating detailed report in HTML – https://github.com/p4pryk/AzureVulnerabilityReport/
- Azure Security Benchmark Report (MSBReport) – a Streamlit-based web application. It analyses and visualises security recommendations for Azure resources. It helps professionals maintain compliance with best practices – https://github.com/p4pryk/MSBReport/
- Microsoft Sentinel and Microsoft 365 Defender repository – GitHub – Azure/Azure-Sentinel: Cloud-native SIEM for intelligent security analytics for your entire enterprise.
- Azure Network Security – GitHub – Azure/Azure-Network-Security: Resources for improving Customer Experience with Azure Network Security
- Intune – Microsoft Intune scripts – https://github.com/MSEndpointMgr/Intune/
- EntraGoat – a deliberately vulnerable Microsoft Entra ID infrastructure. It simulates real-world identity security misconfigurations. It provides a realistic learning platform for security professionals – https://github.com/Semperis/EntraGoat
- Get-IntuneManagementExtensionDiagnostics – this script analyzes Intune IME logs and shows events in Timeline – https://github.com/petripaavola/Get-IntuneManagementExtensionDiagnostics/
- IntuneBrew – a PowerShell-based tool that simplifies the process of uploading and managing macOS applications in Microsoft Intune. It automates the entire workflow—from downloading apps to uploading them to Intune with proper metadata and icons – https://github.com/ugurkocde/IntuneBrew/
- ScubaGear – an assessment tool for Microsoft 365 tenants. It verifies configurations against SCuBA baseline documents – https://github.com/cisagov/ScubaGear/
- Workout – Test framework for Azure Bicep with dedicated DSL – GitHub – TheCloudTheory/Workout: Test framework for Azure Bicep
- Bitcache is a solution that allows you to backup your Bitlocker recovery keys from Entra ID (aka Azure AD) to a local database – GitHub – pawellakomski/bitcache
- Cloud Security Toolkit – all-in-one destination for cutting-edge cloud security resources! Whether you’re diving into offensive strategies, mastering threat hunting, or bolstering your blue-team defenses, this repo has you covered – https://github.com/eshlomo1/CloudSec
- Microsoft Defender for Cloud (formerly known as Azure Security Center) community repository – GitHub – Azure/Microsoft-Defender-for-Cloud: Welcome to the Microsoft Defender for Cloud community repository
- Microsoft Azure training for researchers – GitHub – MSRConnections/Azure-training-course
OSINT & Vulnerability Assessment
- OSINTUI – Open Source Intelligence Terminal User Interface – GitHub – wssheldon/osintui: OSINT from your favorite services in a friendly terminal user interface – integrations for Virustotal, Shodan, and Censys
- PhoneNumber-OSINT – An OSINT tool for gathering information about phone numbers. Spider Anongreyhat (Anonspidey) created this excellent resource – GitHub – spider863644/PhoneNumber-OSINT: An OSINT tool for gathering information about phone numbers
- OSGINT – Retrieve informations about a github username/email – GitHub – hippiiee/osgint: OSINT tool to find informations about a github user (email2username, username2email, creation date …)
- Blackbird – a powerful OSINT tool. It combines fast username and email searches with AI profiling. It features smart filters and polished PDF exports – GitHub – p1ngul1n0/blackbird: An OSINT tool to search for accounts by username and email in social networks.
- cveseeker – a vulnerability assessment intelligence tool. It searches for CVEs and exploits across multiple intelligence sources – https://github.com/krystianbajno/cveseeker
- LeakBaseCTI – specialized investigative framework to investigate cases of malicious actors in the OSINT and backup LeakBase – https://github.com/VECERTUSA/LeakBaseCTI
- CVE Program – the mission of the CVE™ Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities – CVE Program · GitHub
- Advanced Port Scanner with Shodan and CVE Lookup – an advanced asynchronous port scanner written in Python. It scans a target for open ports, retrieves banners, identifies services and versions, and performs CVE lookups using the NVD API. Additionally, it can integrate with Shodan to provide extra host details – https://github.com/chrispl89/port_scanner/
Artificial Intelligence & Machine Learning
- Data & AI Platform – offers a suite of tools for Azure services. It orchestrates modern enterprise data and AI estates seamlessly – https://github.com/microsoft/Data-and-AI-Platform/
- Security Copilot – a generative AI-powered security solution. It increases defender efficiency at machine speed. It strictly remains compliant with responsible AI principles – https://github.com/Azure/Security-Copilot/
- GLIGEN – a novel way to specify the precise location of objects in text-to-image models. I present here an intuitive GUI that makes it significantly easier to use GLIGEN with ComfyUI – GitHub – mut-ex/gligen-gui: An intuitive GUI for GLIGEN that uses ComfyUI in the backend
- Azure OpenAI in a day workshop – GitHub – microsoft/azure-openai-in-a-day-workshop
- remote-mcp-apim-functions-python – Azure API Management as AI Gateway to Remote MCP servers – https://github.com/Azure-Samples/remote-mcp-apim-functions-python
- Generative AI for beginners – 21 comprehensive lessons on building Generative AI applications – GitHub – microsoft/generative-ai-for-beginners: 21 Lessons, Get Started Building with Generative AI
- ThePilot-Scramble-retro-game-by-AI – GitHub – MariuszFerdyn/ThePilot-Scramble-retro-game-by-AI: Game generated by AI based on:
- Cyber-Security-Blog-and-Linkedin-Agent (plus much more) – an Ai agent that takes a simple prompt, then uses a series of agents to conduct research and and can produce blog posts, linkedin posts or technical guides using a friendly web UI – https://github.com/Dave-gilmore-aus/Cyber-Security-Blog-and-Linkedin-Agent
- AutoGen – a framework for creating multi-agent AI applications. They can act autonomously or work alongside humans – GitHub – microsoft/autogen: A programming framework for agentic AI 🤖 PyPi: autogen-agentchat Discord: https://aka.ms/autogen-discord Office Hour: https://aka.ms/autogen-officehour
- ThreatWeaver – an advanced web application that leverages artificial intelligence for automated threat modeling and security analysis. It allows users to upload architecture diagrams and detailed application descriptions, which are then analyzed using the STRIDE and MITRE ATT&CK frameworks, generating clear threat models along with recommendations for mitigation measures – https://github.com/p4pryk/ThreatWaver/
- kotaemon – an open-source clean & customizable RAG UI for chatting with your documents. Built with both end users and developers in mind – GitHub – Cinnamon/kotaemon: An open-source RAG-based tool for chatting with your documents.
General Security, Apps & Training
- SiteSiffer – recursive directory fuzzer + file downloader with progress bars.
It fuzzes directories using a wordlist (recursively), crawls discovered pages, and downloads files that match extensions from your list. Use responsibly. Only scan targets you own or have explicit permission to test – https://github.com/A1ERTA/SiteSifter - ParaMutator is an API fuzzer that bombards entry points with unexpected inputs to cause anomalies, signifying potential security vulnerabilities – GitHub – vuusale/ParaMutator: API fuzzer that exposes security flaws by sending malformed inputs
- Saas attacks. The repository is a collection of SaaS-specific attack techniques. It is intended to be a resource for security researchers, red/blue teams, and penetration testers to learn about and share SaaS attack techniques – GitHub – pushsecurity/saas-attacks: Offensive security drives defensive security. We’re sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
- eJPT-CheatSheets – usefull info and commands for eJPT cert exam – GitHub – bpmcircuits/eJPTCert_CheatSheets
- Damn Vulnerable Restaurant is intentionally vulnerable Web API game. It is built for learning and training purposes. Developers, ethical hackers, and security engineers will find it highly useful – https://github.com/theowni/Damn-Vulnerable-Restaurant-API-Game
- A collection of materials related to JohnSavill’s certification videos hosted on Youtube (Microsoft exams) – https://github.com/johnthebrit/CertificationMaterials
- Study guide that maps the Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals – GitHub – RickKotlarz/SC-900: Study guide for the SC-900: Microsoft Security, Compliance, and Identity
- Sysops life scripts (by Michał Machniak) – GitHub – mimachniak/sysopslife-scripts
- Personal Security Checklist – the ultimate list of tips to secure your digital life – GitHub – Lissy93/personal-security-checklist: 🔒 A compiled checklist of 300+ tips for protecting digital security and privacy in 2024
- Secrets Patterns Database – GitHub – mazen160/secrets-patterns-db: Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more.
- Chef InSpec – an open-source testing framework for infrastructure with a human- and machine-readable language for specifying compliance, security and policy requirements – GitHub – inspec/inspec: InSpec: Auditing and Testing Framework
- Checkpoint Harmony EDR – this Microsoft Sentinel Workbook. It visualises key metrics from Checkpoint Harmony EDR. It leverages CEF events for a comprehensive cybersecurity overview – GitHub – chihebchebbi/CheckpointHarmonyEDR-Workbook
- Study guide that maps the Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals to the Microsoft Skills Measured PDF by Rick Kotlarz – https://github.com/RickKotlarz/SC-900
- Defender Yara – extracted Yara rules from Windows Defender mpavbase and mpasbase – https://github.com/roadwy/DefenderYara/
- Facad1ng – an open-source URL masking tool. It hides phishing URLs to look legitimate using social engineering tactics – GitHub – spyboy-productions/Facad1ng: The Ultimate URL Masking Tool – An open-source URL masking tool designed to help you Hide Phishing URLs and make them look legit using social engineering techniques.
- Wordpot – a WordPress honeypot which detects probes for plugins, themes, timthumb and other common files used to fingerprint a wordpress installation – GitHub – gbrindisi/wordpot: A WordPress Honeypot
- Awesome Honeypots – a curated list of awesome honeypots, plus related components and much more, divided into categories such as Web, services, and others, with a focus on free and open source projects – GitHub – paralax/awesome-honeypots: an awesome list of honeypot resources
- TruffleHog – secret scanner – GitHub – trufflesecurity/trufflehog: Find, verify, and analyze leaked credentials
- Organizer – an application to plan events and manage budgets. It is written in NextJS using MongoDB- GitHub – KamilSajdera/organizer: Plan, save and view your events and expenses.
- Semgrep – a fast, open-source, static analysis tool that searches code, finds bugs, and enforces secure guardrails and coding standards. Semgrep supports 30+ languages and can run in an IDE, as a pre-commit check, and as part of CI/CD workflows – https://github.com/semgrep/semgrep
- Analysis Tools – this repository lists static analysis tools for all programming languages, build tools, config files and more. The focus is on tools which improve code quality such as linters and formatters. The official website, analysis-tools.dev is based on this repository and adds rankings, user comments, and additional resources like videos for each tool – GitHub – analysis-tools-dev/static-analysis: ⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.
- Awesome Guidelines – a curated list of coding style conventions. It provides best practices for various programming languages – GitHub – Kristories/awesome-guidelines: A curated list of high quality coding style conventions and standards.
- Container Security Checklist: From the image to the workload – GitHub – krol3/container-security-checklist: Checklist for container security – devsecops practices
- Secure Coding Practices Checklist – GitHub – RedHatInsights/secure-coding-checklist: Secure Coding Checklist for Developers
- Mixeway – an OpenSource software that is meant to simplify the process of security assurance of projects which are implemented using CICD procedures – https://github.com/Mixeway/MixewayHub
Which Stay tuned for updates as I continue to organize and categorize these resources!
This post is part of my ongoing effort to contribute to the tech community by sharing useful resources and tools I discover along my professional journey. Which other projects are worth to observe? Write a comment and share your findings.
