domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| chromium/badssl.com badssl.com is a hosted collection of test subdomains, each deliberately configured with a broken or unusual TLS/SSL setup (expired certific… | 70 | 3043 | active |
| projectdiscovery/uncover uncover is a Go CLI tool that queries multiple internet search engines (Shodan, Censys, FOFA, ZoomEye, and others) via their APIs to quickl… | 84 | 3042 | active |
| Qianlitp/crawlergo crawlergo is a Go-based browser crawler that uses headless Chrome to discover URLs for web vulnerability scanners. It renders pages, fills … | 27 | 3034 | active |
| chaterm/Chaterm Chaterm is an open-source AI-native terminal application for cloud and infrastructure management, letting engineers deploy, troubleshoot, a… | 80 | 3029 | active |
| SharpAI/DeepCamera DeepCamera is an open-source AI camera skills platform that runs local VLM scene analysis, object detection, face recognition, and person r… | 86 | 3019 | active |
| Kevin-Robertson/Inveigh Inveigh is a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers, with a primary C# version and a legacy Power… | 53 | 3014 | active |
| evgenyneu/keychain-swift A Swift library providing simple helper functions for securely storing and retrieving text, boolean, and Data values in the Apple Keychain.… | 32 | 3012 | stable |
| GH05TCREW/pentestagent PentestAgent is a Python-based AI agent framework for black-box penetration testing that orchestrates LLM-driven security testing workflows… | 62 | 3010 | active |
| thinkst/opencanary OpenCanary is a modular, multi-protocol network honeypot daemon written in Python, designed to detect attackers after they breach internal … | 86 | 3003 | active |
| mgeeky/Penetration-Testing-Tools A curated collection of 170+ penetration testing tools, scripts, and cheatsheets developed by the author over years of red teaming and IT s… | 32 | 3001 | active |
| Netw0rkNoob/VulnClaw VulnClaw is an AI-driven penetration testing CLI tool that combines an LLM agent, MCP toolchain, and curated pentest skills to automate the… | 80 | 2997 | active |
| aws-actions/configure-aws-credentials A GitHub Action that configures AWS credential environment variables for use in subsequent workflow steps. It supports OIDC federation for … | 97 | 2996 | active |
| opengrep/opengrep Opengrep is an open-source static application security testing (SAST) engine forked from Semgrep under LGPL-2.1, supporting pattern-based c… | 84 | 2995 | active |
| adryfish/fingerprint-chromium A fingerprint browser built on Ungoogled Chromium that lets users spoof or control browser fingerprint characteristics to avoid detection. … | 76 | 2991 | active |
| tegal1337/CiLocks CiLocks is a menu-driven Linux CLI toolkit for Android and iOS security testing, bundling lockscreen brute-force/bypass, ADB data extractio… | 23 | 2991 | active |
| Manisso/fsociety Fsociety is a Python-based penetration testing framework that bundles a menu of hacking tools covering information gathering, password atta… | 74 | 12275 | maintenance |
| baidu/openrasp OpenRASP is Baidu's open-source Runtime Application Self-Protection (RASP) solution that embeds a protection engine directly into the appli… | 43 | 2987 | stable |
| oauthlib/oauthlib OAuthLib is a Python framework implementing the OAuth 1.0 (RFC 5849) and OAuth 2.0 (RFC 6749) request-signing and authorization logic in a … | 75 | 2980 | stable |
| laravel/sanctum Laravel Sanctum is a featherweight authentication package for Laravel that issues API tokens and authenticates single-page applications, mo… | 96 | 2977 | stable |
| appleboy/gin-jwt A JWT authentication middleware for the Gin web framework in Go, built on golang-jwt/jwt. It provides login handling, token refresh, and ro… | 91 | 2973 | active |
| bethgelab/foolbox Foolbox is a Python library for generating adversarial examples that fool deep neural networks, with state-of-the-art gradient-based and de… | 48 | 2972 | active |
| makoto56/penetration-suite-toolkit A preconfigured Windows 11 penetration testing toolkit distributed as a VM image, bundling a large curated collection of security tools wit… | 34 | 2970 | active |
| frknkrc44/HMA-OSS HMA-OSS is a Zygisk module that hides your app list, settings, and package installers from other apps on rooted Android devices. It is a Ko… | 83 | 2968 | active |
| xiv3r/Burpsuite-Professional A shell-based installer that deploys Burp Suite Professional (a commercial web security testing toolkit) on Linux and NixOS, bundled with a… | 66 | 2968 | active |
| bytenode/bytenode Bytenode is a minimalist bytecode compiler that compiles JavaScript into V8 bytecode (.jsc files) to protect source code. It works with Nod… | 72 | 2966 | active |
| ntop/PF_RING PF_RING is a Linux kernel module and user-space framework for high-speed packet capture and processing, offering a consistent API for netwo… | 73 | 2965 | stable |
| TheOfficialFloW/PPPwn PPPwn is a proof-of-concept kernel remote code execution exploit for PlayStation 4 consoles up to firmware 11.00, exploiting CVE-2006-4304 … | 24 | 2960 | active |
| strongswan/strongswan strongSwan is an open-source, modular IPsec-based VPN solution implementing the IKEv2 (and IKEv1) key exchange protocols for securing IP tr… | 87 | 2954 | stable |
| thewhiteh4t/FinalRecon FinalRecon is an all-in-one automatic web reconnaissance tool written in Python that provides a fast overview of a web target. It bundles h… | 70 | 2953 | active |
| eteran/edb-debugger edb is a cross-platform AArch32/x86/x86-64 debugger inspired by OllyDbg, built with Qt and Capstone. It provides a graphical interface for … | 66 | 2952 | active |
| microsoft/AttackSurfaceAnalyzer Attack Surface Analyzer is a Microsoft open-source security tool that scans an operating system's security configuration before and after s… | 82 | 2950 | active |
| achillean/shodan-python The official Python library and command-line interface for the Shodan search engine, which indexes Internet-connected devices and services.… | 23 | 2950 | stable |
| RfidResearchGroup/ChameleonUltra ChameleonUltra is the open-source firmware for an RFID/NFC card emulation device based on the NRF52840, capable of reading, writing, decryp… | 84 | 2949 | active |
| pquerna/otp A Go library implementing Time-based (TOTP, RFC 6238) and HMAC-based (HOTP, RFC 4228) one-time password algorithms for adding two-factor au… | 39 | 2944 | stable |
| microsoft/restler-fuzzer RESTler is the first stateful REST API fuzzing tool, automatically testing cloud services through their REST APIs to find security and reli… | 71 | 2939 | active |
| netwrix/pingcastle PingCastle is a C# tool that assesses the security posture of Active Directory and Entra ID environments, producing risk scores, health che… | 98 | 2937 | active |
| scottyab/rootbeer RootBeer is an Android library that detects whether a device has been rooted using multiple Java and native checks such as scanning for su … | 67 | 2937 | active |
| kamailio/kamailio Kamailio is an open source SIP signaling server (RFC3261) written in C, designed for large-scale VoIP and real-time communication platforms… | 95 | 2928 | stable |
| padloc/padloc Padloc is an open-source, end-to-end encrypted password manager for individuals and teams, built as a monorepo with a Node.js backend serve… | 29 | 2923 | active |
| wolfSSL/wolfssl wolfSSL is a lightweight, portable SSL/TLS library written in ANSI C, supporting TLS 1.3 and DTLS 1.3, powered by the wolfCrypt cryptograph… | 92 | 2919 | stable |
| calebstewart/pwncat pwncat is a post-exploitation platform and handler for reverse and bind shells, written in Python. It wraps raw shell communication with an… | 10 | 2917 | active |
| apache/casbin-node-casbin Node-Casbin is an open-source authorization library for Node.js and Browser that enforces access control based on configurable models such … | 95 | 2916 | stable |
| SnaffCon/Snaffler Snaffler is a C# command-line tool for pentesters and red teamers that enumerates Windows/AD environments to find sensitive files (mostly c… | 76 | 2915 | active |
| Roave/SecurityAdvisories A Composer package that acts as an exclusion list of known security vulnerabilities, preventing installation of dependency versions with do… | 77 | 2914 | active |
| palahsu/DDoS-Ripper DDoS-Ripper (DRipper) is a Python command-line tool that floods a target IP with traffic to simulate a distributed denial-of-service attack… | 72 | 2914 | active |
| onetimesecret/onetimesecret A self-hostable web service for sharing sensitive information like passwords via single-use, self-destructing links. Written in Ruby with R… | 95 | 2912 | active |
| firecracker-microvm/firecracker-containerd firecracker-containerd is a set of components that lets containerd manage containers running inside Firecracker microVMs, combining fast co… | 76 | 2910 | active |
| FiloSottile/yubikey-agent yubikey-agent is a seamless ssh-agent that stores SSH keys on YubiKey hardware via the PIV smartcard interface. It runs in the background, … | 32 | 2903 | stable |
| google/osv.dev OSV (Open Source Vulnerabilities) is Google's open, distributed vulnerability database and triage service that aggregates security advisori… | 84 | 2901 | stable |
| tale/headplane Headplane is a feature-complete web UI for Headscale, the self-hosted alternative to Tailscale's WireGuard-based VPN coordination server. I… | 85 | 2897 | active |
| LukeZGD/Legacy-iOS-Kit An all-in-one shell-based tool for restoring, downgrading, jailbreaking, and saving SHSH blobs on legacy iOS devices vulnerable to bootrom … | 67 | 2895 | active |
| pyllyukko/user.js A hardened user.js configuration template for Mozilla Firefox that enforces security and privacy settings. It limits tracking, fingerprinti… | 66 | 2891 | active |
| verus-lang/verus Verus is a verification tool for statically proving the correctness of Rust code against developer-written specifications, using SMT solver… | 95 | 2890 | active |
| jayofelony/pwnagotchi Pwnagotchi is a Raspberry Pi-based Wi-Fi penetration-testing gadget that leverages Bettercap to passively sniff or actively attack nearby W… | 93 | 2886 | active |
| pwndoc/pwndoc PwnDoc is a self-hosted web application for writing penetration test findings and generating customizable Docx reports. It supports multi-u… | 98 | 2882 | active |
| i-am-shodan/USBArmyKnife USB Army Knife is firmware for ESP32-based USB devices (like the T-Dongle-S3) that turns them into a close-access penetration testing tool.… | 71 | 2870 | active |
| gdbinit/MachOView A macOS GUI application for viewing and exploring Mach-O binary files, revived as a maintained fork with a universal x86_64/arm64 build. It… | 32 | 2868 | active |
| flozz/p0wny-shell p0wny@shell is a single-file PHP webshell that provides a browser-based terminal for executing commands on a remote server. It is designed … | 39 | 2860 | active |
| projectdiscovery/dnsx dnsx is a fast, multi-purpose DNS toolkit from ProjectDiscovery for running DNS queries (A, AAAA, CNAME, PTR, NS, MX, TXT, SRV, SOA) with u… | 86 | 2846 | active |
| glauth/glauth GLAuth is a lightweight, secure LDAP authentication server written in Go with configurable backends. It serves as a simple alternative to O… | 91 | 2842 | active |
| Alfredredbird/tookie-osint Tookie-OSINT is an open-source Python OSINT tool that finds social media accounts and gathers information based on user inputs. It offers a… | 82 | 2841 | active |
| mrexodia/TitanHide TitanHide is a Windows kernel driver that hides debuggers from selected processes by hooking Nt* kernel functions via SSDT hooks and alteri… | 72 | 2840 | active |
| LimerBoy/Impulse Impulse is a Python-based denial-of-service toolkit that bundles multiple attack methods including SYN, UDP, ICMP, HTTP floods, Slowloris, … | 39 | 2840 | active |
| elseif/MikroTikPatch A Python-based tool that patches MikroTik RouterOS public keys and generates licenses, enabling shell access, container mode, and highest-l… | 87 | 2833 | active |
| bezhanSalleh/filament-shield A Filament plugin that adds role and permission-based access management to Filament admin panels, built on spatie/laravel-permission. It ge… | 96 | 2826 | active |
| quay/quay Project Quay is an open-source container image registry that builds, stores, and distributes container images. It implements the Docker Reg… | 94 | 2821 | active |
| eycorsican/leaf Leaf is a versatile and efficient proxy framework written in Rust, supporting multiple proxy protocols such as Shadowsocks, Trojan, VMess, … | 85 | 2820 | active |
| gkbrk/slowloris A Python rewrite of the Slowloris low-bandwidth HTTP Denial of Service attack tool. It holds many connections open to threaded web servers … | 32 | 2820 | stable |
| openalpr/openalpr OpenALPR is an open-source Automatic License Plate Recognition (ALPR) library written in C++ that analyzes images and video streams to dete… | 23 | 11452 | maintenance |
| screetsec/TheFatRat TheFatRat is a menu-driven exploiting tool that automates MSFvenom and Metasploit to generate backdoors and payloads for Windows, Linux, Ma… | 23 | 11444 | maintenance |
| acme-dns/acme-dns acme-dns is a simplified DNS server with a RESTful HTTP API designed to automate ACME DNS challenges for Let's Encrypt and other ACME certi… | 83 | 2814 | active |
| opencve/opencve OpenCVE is a self-hostable Vulnerability Intelligence Platform that aggregates CVE data from sources like MITRE, NVD, CISA KEV, Vulnrichmen… | 94 | 2810 | active |
| DefGuard/defguard Defguard is a self-hosted zero-trust access management platform combining WireGuard VPN with built-in MFA/2FA, identity and access manageme… | 98 | 2809 | active |
| jedisct1/minisign Minisign is a dead simple command-line tool for signing files and verifying digital signatures using the Ed25519 public-key signature syste… | 67 | 2808 | stable |
| digininja/CeWL CeWL is a Ruby command-line tool that spiders a target website to a specified depth and collects unique words into a custom wordlist for us… | 63 | 2801 | stable |
| zema1/suo5 Suo5 is a high-performance HTTP tunneling tool that creates a local SOCKS5 forward proxy by tunneling traffic through a compromised web ser… | 85 | 2796 | active |
| engineer-man/piston Piston is a high performance general purpose code execution engine that safely runs untrusted and potentially malicious code in isolated en… | 66 | 2796 | active |
| hasherezade/pe_to_shellcode A C++ command-line tool that converts Windows PE executables into shellcode-compatible form, adding a reflective loading stub post-compilat… | 40 | 2793 | active |
| destan19/OpenAppFilter OpenAppFilter (OAF) is a parental control and application filtering plugin for OpenWrt routers, built as a kernel module, service daemon, a… | 88 | 2786 | active |
| panda-re/panda PANDA is an open-source Platform for Architecture-Neutral Dynamic Analysis built on the QEMU whole-system emulator, supporting record and r… | 93 | 2778 | active |
| authpass/authpass AuthPass is a free, open-source password manager built with Flutter that is compatible with KeePass 2.x (KDBX 3 and KDBX 4) databases. It r… | 67 | 2767 | active |
| ascending-llc/jarvis-registry Jarvis Registry is an open-source, enterprise-grade MCP and A2A agent gateway and workflow orchestration platform that gives AI copilots an… | 84 | 2757 | active |
| Gedsh/InviZible InviZible Pro is an Android application that combines Tor, DNSCrypt, and Purple I2P modules to provide online privacy, anonymity, and acces… | 98 | 2756 | active |
| rubysec/bundler-audit bundler-audit is a command-line tool that audits a Ruby project's Gemfile.lock for gems with known vulnerabilities using the ruby-advisory-… | 73 | 2756 | active |
| awnumar/memguard MemGuard is a pure Go library that securely stores sensitive information in memory, encrypting it with XSalsa20Poly1305 and bypassing the g… | 72 | 2756 | active |
| protectai/vulnhuntr Vulnhuntr is a Python CLI tool that uses large language models combined with static code analysis to autonomously discover exploitable vuln… | 24 | 2747 | active |
| checkra1n/PongoOS PongoOS is a pre-boot execution environment for Apple boards, built on top of the checkra1n jailbreak tool. It provides an interactive shel… | 36 | 2746 | active |
| pucherot/Pi.Alert Pi.Alert is a self-hosted WIFI/LAN intruder detector that scans the local network for connected devices using arp-scan, Pi-hole, and dnsmas… | 23 | 2743 | active |
| Bearer/bearer Bearer CLI is an open-source static application security testing (SAST) tool written in Go that scans source code and analyzes data flows t… | 95 | 2739 | active |
| calebmadrigal/trackerjacker A Python CLI tool that maps nearby WiFi networks and their connected devices via raw 802.11 monitor-mode packet capture, similar to nmap bu… | 56 | 2739 | active |
| asLody/VirtualApp VirtualApp is an Android virtualization/sandbox engine that lets apps run inside a host app without being installed on the system, acting a… | 75 | 11070 | maintenance |
| Impact-I/reFlutter reFlutter is a Python CLI framework for reverse engineering Flutter mobile apps by repacking APK/IPA files with a specially patched, precom… | 95 | 2738 | active |
| NetSPI/PowerUpSQL PowerUpSQL is a PowerShell toolkit for attacking and auditing SQL Server instances, supporting discovery, weak configuration auditing, priv… | 32 | 2737 | active |
| xnl-h4ck3r/waymore waymore is a Python CLI tool that retrieves URLs from multiple web archive and intelligence sources (Wayback Machine, Common Crawl, Alien V… | 90 | 2732 | active |
| Tecnativa/docker-socket-proxy A security-enhanced HAProxy-based proxy that sits in front of the Docker socket and restricts which Docker API requests are allowed. It ret… | 87 | 2729 | active |
| aboul3la/Sublist3r Sublist3r is a Python command-line tool that enumerates subdomains of a target domain using OSINT sources such as Google, Bing, Yahoo, Baid… | 23 | 11023 | maintenance |
| salarcode/SmartProxy SmartProxy is a Firefox, Chrome, and Edge browser extension that automatically enables or disables proxy usage per website based on customi… | 90 | 2726 | active |
| f0rb1dd3n/Reptile Reptile is a Linux kernel module (LKM) rootkit written in C that provides privilege escalation, file/process/network connection hiding, per… | 67 | 2718 | active |
| AxtMueller/Windows-Kernel-Explorer Windows Kernel Explorer (WKE) is a free Windows kernel research and inspection tool supporting Windows XP through Windows 11. It loads a ke… | 58 | 2717 | active |
| ComodoSecurity/openedr OpenEDR is an open-source Endpoint Detection and Response (EDR) agent written in C++ that records endpoint telemetry, process hierarchies, … | 60 | 2716 | active |