Best Go Tools & Libraries
293 curated Go tools, libraries, and open-source projects β hand-picked and ranked by the community.
bluemonday
githubbluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
meshbird
githubDistributed private networking
Stowaway
githubπ»Stowaway -- Multi-hop Proxy Tool for pentesters
cariddi
githubTake a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
SecretScanner
github:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:
dockle
githubContainer Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
sso
githubsso, aka S.S.Octopus, aka octoboi, is a single sign-on solution for securing internal services
hardentools
githubHardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.
kube-score
githubKubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your Kubernetes YAML and Charts. Static code analysis for Kubernetes.
ContainerSSH
githubContainerSSH: Launch containers on demand
glauth
githubA lightweight LDAP server for development, home use, or CI
memguard
githubSoftware sandbox for storage of sensitive information in memory.
osv.dev
githubOpen source vulnerability DB and triage service.
bearer
githubCode security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Elkeid
githubElkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices.
fosite
githubExtensible security first OAuth 2.0 and OpenID Connect SDK for Go.
agent-deck
githubTerminal session manager for AI coding agents. One TUI for Claude, Gemini, OpenCode, Codex, and more.
piknik
githubCopy/paste anything over the network.
rita-legacy
githubReal Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
Picocrypt
githubA very small, very simple, yet very secure encryption tool.
fibratus
githubAdversary tradecraft detection, protection, and hunting
brutespray
githubFast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
cloudfox
githubAutomating situational awareness for cloud penetration tests.
secure
githubHTTP middleware for Go that facilitates some quick security wins.