Cybersecurity-Projects/README.md

30 KiB

Kali dragon icon

Cybersecurity Projects

70 hands-on security tools — from first-time programmers to advanced engineers

Stars Forks Issues License Source Code Sponsor

Made possible by CertGames

A curated collection of cybersecurity projects organized by skill level. Each project includes full source code, documentation, and learning materials.

Browse the certification roadmaps for career guidance or the learning resources for tools, courses, and communities.

Currently building: Self-Hosted Shodan Clone

Projects

Foundations Beginner Intermediate Advanced

Foundations Projects

Start here if this is your first time coding. The Foundations tier is pre-beginner — for someone who has never written Python, has barely used a terminal, and is new to cybersecurity. Source files are heavily commented as a teaching aid, and every learn/ folder explains concepts from zero.

What makes Foundations different:

  • Single-file projects — the entire tool lives in one readable Python file
  • Heavy teaching comments — every new concept is annotated inline
  • Numpy-style docstrings — every function documents what, why, and each parameter
  • Extra-deep learn/ folders — Python features and security concepts explained from zero
  • Production-quality code — written to real standards, explained for beginners
Project Info What You'll Learn
Hash Identifier
Identify hash types by prefix, length, and charset
Step 1/3 2-4h Python Hash families (MD5, SHA, bcrypt, Argon2) • PHC string format • Pattern matching • Pure-function design
HTTP Headers Scanner
Audit a URL's response headers for missing or weak security controls
Step 2/3 3-5h Python HTTP fundamentals • Security headers (CSP, HSTS, X-Frame-Options) • httpx requests • Scored audits
Password Manager
Encrypted local vault with master password unlock
Step 3/3 6-8h Python Argon2id key derivation • AES-GCM authenticated encryption • Secure on-disk vaults • Master-password workflows

Beginner Projects

Project Info What You'll Learn
Simple Port Scanner
Async TCP port scanner in C++ @deniskhud
4-5h C++ TCP socket programming • Async I/O patterns • Service detection
Keylogger
Capture keyboard events with timestamps
4-5h Python Event handling • File I/O • Ethical considerations
Caesar Cipher
CLI encryption/decryption tool
4-5h Python Classical cryptography • Brute force attacks • CLI design
DNS Lookup CLI Tool
Query DNS records with WHOIS
6-7h Python DNS protocols • WHOIS queries • Reverse DNS lookup
Simple Vulnerability Scanner
Check software against CVE databases
12-14h Go CVE databases • Dependency scanning • Vulnerability assessment
Metadata Scrubber Tool
Remove EXIF and privacy metadata @Heritage-XioN
10-12h Python EXIF data • Privacy protection • Batch processing
Network Traffic Analyzer
Capture and analyze packets
10-12h Python C++ Packet capture • Protocol analysis • Traffic visualization
Hash Cracker
Dictionary and brute-force cracking
5-6h C++ Hash algorithms • Dictionary attacks • Password security
Steganography Multi-Tool
Hide data in images, audio, QR, PDFs, text
8-10h Python Multi-format steganography • Zero-width Unicode • Audio LSB • QR exploitation
Ghost on the Wire
L2 attack & defense: MAC spoofing + ARP detection
6-8h Python ARP protocol • MAC spoofing • MITM detection • L2 trust mapping
Canary Token Generator
Self-hosted honeytokens that alert on access
8-10h Go React Deception defense • Honeytokens • MySQL wire protocol • PDF/DOCX patching
Live Demo
Security News Scraper
Aggregate cybersecurity news
10-14h Python Web scraping • CVE parsing • Database storage
Phishing Domain Generator & Quishing Scanner
Typosquat generation + QR phishing detection
6-8h Python Homoglyph attacks • Typosquatting • QR code analysis • Domain intelligence
SSH Brute Force Detector
Monitor and block SSH attacks
2-4h Python Log parsing • Attack detection • Firewall automation
Simple C2 Beacon
Command and Control beacon/server
10-12h Python React Docker C2 architecture • MITRE ATT&CK • WebSocket protocol • XOR encoding
Base64 Encoder/Decoder
Multi-format encoding tool
2h Python Base64/32 encoding • URL encoding • Auto-detection
Linux CIS Hardening Auditor
CIS benchmark compliance checker
6-8h Bash CIS benchmarks • System hardening • Compliance scoring • Shell scripting
Systemd Persistence Scanner
Hunt Linux persistence mechanisms
6-8h Go Persistence techniques • Systemd internals • Cron analysis • Threat hunting
Linux eBPF Security Tracer
Real-time syscall tracing with eBPF
10-12h Python C eBPF programs • Syscall tracing • BCC framework • Security observability
Trojan Application Builder
Educational malware lifecycle demo
8-10h Python Trojan anatomy • Data exfiltration • File encryption • Attack lifecycle
DNS Sinkhole
Pi-hole-style malware domain blocker
10-12h Go DNS protocol • Blocklist management • Query logging • Network defense
Firewall Rule Engine
Parse and validate iptables/nftables rules
6-8h V Firewall internals • Rule parsing • iptables/nftables
LLM Prompt Injection Firewall
Detect and block prompt injection attacks
8-10h Python AI security • Prompt injection • Input sanitization • LLM defense

Intermediate Projects

Project Info What You'll Learn
Payload Obfuscation Engine
Multi-layer payload obfuscation toolkit
3-5d Go Obfuscation techniques • Polymorphism • AV evasion • Signature detection
SIEM Dashboard
Log aggregation with correlation
3-5d React Flask SIEM concepts • Log correlation • Full-stack development
Live Demo
Token Abuse Playground
15+ token vulnerabilities to exploit and fix
3-5d FastAPI React JWT exploitation • OAuth attacks • Session security • Token forensics
Supply Chain Attack Simulator
Fake PyPI package dependency confusion demo
2-4d Python Supply chain attacks • Dependency confusion • Package security • PyPI internals
DDoS Mitigation Tool
Detect traffic spikes
2-4d Go DDoS detection • Rate limiting • Anomaly detection
Secrets Scanner
Scan codebases and git history for leaked secrets
1-2d Go Secret detection • Shannon entropy • HIBP k-anonymity • SARIF output
API Security Scanner
Enterprise API vulnerability scanner
3-5d FastAPI React Docker OWASP API Top 10 • ML fuzzing • GraphQL/SOAP testing
Wireless Deauth Detector
Monitor WiFi deauth attacks
2-4d Rust Wireless security • Packet sniffing • Attack detection
Credential Enumeration
Post-exploitation credential collection
2-4d Nim Credential extraction • Browser forensics • Red team tooling
Binary Analysis Tool
Disassemble and analyze executables
3-5d Rust Binary analysis • String extraction • Malware detection
Live Demo
Chaos Engineering Security Tool
Inject security failures to test resilience
3-5d Go Chaos engineering • Security resilience • Credential spraying • Auth testing
Credential Rotation Enforcer
Track and enforce credential rotation policies
2-4d Python Credential hygiene • Secret rotation • Compliance dashboards • API integration
Race Condition Exploiter
TOCTOU race condition attack & defense lab
3-5d FastAPI React TOCTOU attacks • Double-spend bugs • Concurrent exploitation • Race visualization
Self-Hosted Shodan Clone
Internet-connected device search engine
3-5d Go React Service fingerprinting • Network scanning • OSINT • Search engine design
JA3/JA4 TLS Fingerprinting Tool
Fingerprint TLS clients by handshake
2-4d Rust TLS handshake analysis • JA3/JA4 hashing • Bot detection • Malware C2 identification
Live Demo
Mobile App Security Analyzer
Decompile and analyze mobile apps
3-5d Python APK/IPA analysis • Reverse engineering • OWASP Mobile
DLP Scanner
Data Loss Prevention for files, DBs, and traffic
2-4d Python PII detection • GDPR/HIPAA compliance • Pattern matching • Data classification
Lua/Nginx Edge Backend
Full CRUD backend via Lua in Nginx
3-5d Lua Nginx Edge computing • OpenResty • Lua scripting • WAF • JWT at the edge
Privesc Playground
20+ privilege escalation paths to exploit
3-5d Python SUID exploitation • Sudo abuse • Cron hijacking • GTFOBins • Capability abuse
SBOM Generator & Vulnerability Matcher
Software Bill of Materials with CVE matching
2-4d Go SPDX/CycloneDX formats • Dependency analysis • CVE databases • EO 14028 compliance
Subdomain Takeover Scanner
Detect dangling DNS records
2-4d Go DNS enumeration • CNAME analysis • Cloud resource claiming • Bug bounty
GraphQL Security Tester
Automated GraphQL vulnerability testing
2-4d Python Introspection attacks • Query depth DoS • Authorization bypass • Batching abuse
Docker Security Audit
CIS Docker Benchmark scanner
1-2d Go CIS benchmarks • Container security • Multiple output formats

Advanced Projects

Project Info What You'll Learn
API Rate Limiter
Distributed rate limiting middleware
1w Python Redis Token bucket algorithm • Distributed systems • Redis backend
Encrypted Chat Application
Real-time E2EE messaging
1-2w FastAPI SolidJS PostgreSQL Signal Protocol • Double Ratchet • WebAuthn • WebSockets
Exploit Development Framework
Modular exploitation framework
3-4w C++ Exploit development • Payload generation • Plugin architecture
AI Threat Detection
ML-powered nginx threat detection
3-4w FastAPI React PyTorch ML ensemble (AE + RF + IF) • ONNX inference • Real-time detection
Bug Bounty Platform
Full vulnerability disclosure platform
2-3w FastAPI React PostgreSQL Full-stack development • CVSS scoring • Workflow automation
Live Demo
Cloud Security Compliance Dashboard
Multi-cloud compliance with CIS, SOC2, HIPAA
2-3w Go React CIS benchmarks • SOC2/HIPAA compliance • Cost-security optimization • Drift detection
Malware Analysis Platform
Automated sandbox analysis
2-3w Rust Docker Malware analysis • Sandboxing • YARA rules • IOC extraction
Quantum Resistant Encryption
Post-quantum cryptography
3-4w Python Post-quantum algorithms • Hybrid encryption • Kyber/Dilithium
Zero Day Vulnerability Scanner
Coverage-guided fuzzing
2-3w Rust C Fuzzing • Vulnerability research • Crash triage
Distributed Password Cracker
GPU-accelerated cracking
3-4w C++ CUDA Distributed systems • GPU computing • Hash cracking
Kernel Rootkit Detection
Detect kernel-level rootkits
2-3w Rust Kernel internals • Memory forensics • Rootkit detection
Blockchain Smart Contract Auditor
Solidity vulnerability analysis
3-4w Python Solidity Smart contracts • Static analysis • Solidity security
Adversarial ML Attacker
Generate adversarial examples
3-4w Python TensorFlow Adversarial ML • FGSM/DeepFool • Model robustness
Advanced Persistent Threat Simulator
Multi-stage APT simulation
3-4w Go APT techniques • C2 infrastructure • Lateral movement
Hardware Security Module Emulator
Software HSM that compiles to a real PKCS#11 .so
2-3w Zig PKCS#11/Cryptoki C ABI • AES-GCM/CBC • RSA/ECDSA/ECDH • Argon2id + encrypted-at-rest
Network Covert Channel
Data exfiltration techniques
3-4w Rust Covert channels • Data exfiltration • Steganography
Automated Penetration Testing
Full pentest automation
3-4w Python Pentest automation • Recon to exploitation • Report generation
Haskell Reverse Proxy
Functional reverse proxy with security middleware
2-3w Haskell Functional programming • Reverse proxy design • Security middleware
"Monitor the Situation" Dashboard
Real-time cyber threat situational awareness
3-4w Go React PostgreSQL Threat intel feeds • EPSS/KEV/CVE velocity • BGP hijacks • WebSocket fan-out • 3D globe SOC view
Live Demo
Honeypot Network
Multi-service honeypot deployment & analysis
2-3w Go React Docker Honeypot deployment • Attacker behavior analysis • IOC extraction • MITRE mapping
Live Demo
Supply Chain Security Analyzer
Dependency vulnerability analysis
2-3w Go Supply chain security • Dependency analysis • Malicious packages

Getting Started

Each project lives in its own directory under PROJECTS/ with its own README, source code, and learn/ documentation. To explore a project:

cd PROJECTS/<tier>/<project-name>
# Then follow that project's README for setup and usage

Projects marked with a synopsis (under SYNOPSES/) have detailed design documents available. Source-code-complete projects are indicated by the blue badge count above.

Roadmaps & Resources

  • Certification Roadmaps — 10 career paths for SOC Analyst, Pentester, Security Engineer, GRC Analyst, and more
  • Learning Resources — Curated tools, courses, certifications, YouTube channels, Reddit communities, and security frameworks

Contributing

Contributions are welcome. If you want to add a project, improve existing code, or fix documentation:

  1. Fork the repository
  2. Create a feature branch
  3. Open a pull request

See the open issues for ideas on what to work on.

License

AGPL 3.0