domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| securing/IOSSecuritySuite iOS Security Suite is a Swift library for iOS platform security and anti-tampering checks. It detects jailbroken devices, attached debugger… | 86 | 2712 | active |
| zinja-coder/jadx-ai-mcp A JADX plugin that bundles an MCP server, allowing LLM clients like Claude to interact with the JADX decompiler for Android APK analysis. I… | 84 | 2711 | active |
| altcha-org/altcha ALTCHA is an open-source, privacy-first CAPTCHA alternative that protects websites, forms, and APIs from bots and spam using a proof-of-wor… | 93 | 2708 | active |
| hfiref0x/KDU KDU (Kernel Driver Utility) is a Windows command-line tool that abuses known vulnerable drivers to load unsigned kernel drivers, bypass Dri… | 91 | 2704 | active |
| dirkjanm/ROADtools ROADtools is a Python framework for interacting with Azure AD/Entra ID, comprising the roadlib authentication library, the ROADrecon explor… | 75 | 2704 | active |
| sepinf-inc/IPED IPED is an open source digital forensic tool developed by the Brazilian Federal Police for processing and analyzing digital evidence from d… | 83 | 2701 | active |
| MetapriseAI/OrgKernel OrgKernel is an open-source trust layer for AI agents providing cryptographic agent identity (Ed25519), scoped execution tokens, SHA-256 ha… | 55 | 2700 | active |
| Checkmarx/kics KICS (Keeping Infrastructure as Code Secure) is an open-source static analysis tool by Checkmarx that scans IaC files for security vulnerab… | 98 | 2695 | active |
| patterniha/SNI-Spoofing A Python CLI tool that bypasses Deep Packet Inspection (DPI) by manipulating IP and TCP headers, such as spoofing SNI fields. It is used to… | 53 | 2687 | active |
| i2p/i2p.i2p I2P (Invisible Internet Project) is the reference Java implementation of a decentralized, anonymizing peer-to-peer overlay network that rou… | 89 | 2685 | stable |
| sheeki03/tirith Tirith is a Rust-based terminal security tool that intercepts shell commands, pasted content, and files to block threats like homograph URL… | 78 | 2683 | active |
| Bouncy Castle Bouncy Castle is a comprehensive open-source cryptographic library for Java (and C#/.NET) implementing a wide range of algorithms, a JCA/JC… | 77 | 2683 | stable |
| sunscrapers/djoser Djoser is a Python library providing REST endpoints for Django's authentication system via Django REST Framework. It offers views for regis… | 88 | 2681 | active |
| aforensics/HiddenVM HiddenVM is a free, open-source Linux application that lets you run Oracle VirtualBox on the Tails operating system, so almost any desktop … | 23 | 2677 | active |
| nuver-labs/vps-audit A dependency-free Bash script that audits Linux VPS security and performance, running 18 graded checks covering SSH configuration, firewall… | 86 | 2676 | active |
| scambra/devise_invitable A Ruby gem that extends the Devise authentication framework for Rails with invitation functionality. It lets authenticated users invite oth… | 75 | 2676 | active |
| bytedance/Elkeid Elkeid is an open-source cloud workload protection platform from ByteDance that provides host intrusion detection (HIDS), runtime applicati… | 70 | 2672 | active |
| rthalley/dnspython dnspython is a DNS toolkit for Python supporting nearly all record types, queries, zone transfers, dynamic updates, TSIG, EDNS0, DNSSEC, an… | 69 | 2670 | stable |
| openai/privacy-filter OpenAI Privacy Filter is a small bidirectional token-classification model (1.5B total, 50M active parameters) for detecting and masking per… | 49 | 2670 | active |
| dannagle/PacketSender Packet Sender is a free, open-source cross-platform utility for sending and receiving TCP, UDP, SSL, and DTLS packets, plus HTTP/HTTPS requ… | 88 | 2668 | active |
| ankit0183/Wifi-Hacking A Python-based menu-driven CLI tool that automates Wi-Fi penetration testing by wrapping built-in Kali Linux wireless tools. It supports mo… | 59 | 2667 | active |
| outflanknl/RedELK RedELK is a self-hosted SIEM built on the Elastic stack (Elasticsearch, Logstash, Kibana) tailored for red team operations. It aggregates a… | 58 | 2665 | active |
| OnionBrowser/OnionBrowser Onion Browser is a free, open-source privacy-focused web browser for iPhone and iPad that tunnels web traffic through the Tor anonymity net… | 98 | 2663 | active |
| Moham3dRiahi/Th3inspector Th3inspector is an all-in-one Perl CLI tool for information gathering (OSINT reconnaissance). It bundles lookups such as website info, whoi… | 40 | 2662 | active |
| 0x6d69636b/windows_hardening HardeningKitty is a PowerShell module that audits and hardens Windows systems against security baselines such as CIS Benchmarks, Microsoft … | 86 | 2655 | active |
| apache/casbin-jcasbin jCasbin is an Apache-licensed Java authorization library that enforces access control using models such as ACL, RBAC, and ABAC defined in c… | 88 | 2652 | stable |
| lissy93/networking-toolbox Networking Toolbox is a collection of 100+ free, open-source networking utilities for system administrators and network engineers, covering… | 58 | 2652 | active |
| cisagov/ScubaGear ScubaGear is a PowerShell-based assessment tool that checks whether a Microsoft 365 tenant's configuration conforms to CISA's Secure Config… | 85 | 2650 | active |
| ryfineZ/codex-session-patcher A Python tool that cleans AI refusal responses from Codex CLI, Claude Code, and OpenCode session files so conversations can be resumed, wit… | 79 | 2649 | active |
| arthaud/git-dumper git-dumper is a Python CLI tool that reconstructs a full git repository from a website that exposes its .git directory, even when directory… | 64 | 2645 | stable |
| cve-search/cve-search cve-search is a tool-set that imports CVE and CPE data into a local MongoDB to enable fast, private searching of known software vulnerabili… | 84 | 2642 | active |
| decompiler-explorer/decompiler-explorer A web service (like Compiler Explorer in reverse) that lets users upload small binaries and compare the decompiled C-like output from many … | 77 | 2639 | active |
| REhints/HexRaysCodeXplorer HexRaysCodeXplorer is a Hex-Rays Decompiler plugin written in C++ that improves code navigation during reverse engineering. It automates re… | 47 | 2637 | active |
| projectdiscovery/vulnx vulnx is a Go-based command-line tool from ProjectDiscovery for searching, filtering, and analyzing vulnerability data such as CVEs. It sup… | 83 | 2634 | active |
| musana/CF-Hero CF-Hero is a Go-based reconnaissance CLI tool that discovers the real origin IP addresses of Cloudflare-protected web applications. It aggr… | 66 | 2632 | active |
| thewhiteh4t/pwnedOrNot pwnedOrNot is a Python command-line OSINT tool that checks email addresses against the HaveIBeenPwned v3 API for past breaches and then sea… | 66 | 2628 | active |
| libkrun/libkrun libkrun is a dynamic library that lets programs run processes in partially isolated environments using KVM virtualization on Linux and HVF … | 96 | 2627 | active |
| TermuxHackz/X-osint X-osint is an open-source Python-based OSINT framework for gathering information about phone numbers, email addresses, IP addresses, VINs, … | 72 | 2627 | active |
| worawit/blutter Blutter is a reverse engineering tool for Flutter mobile applications that compiles the Dart AOT runtime to extract symbols and objects fro… | 72 | 2627 | active |
| Keystone Assembler Engine Keystone is a lightweight multi-platform, multi-architecture assembler framework implemented in C/C++ with bindings for many languages. It … | 65 | 2625 | active |
| auth0/angular2-jwt An Angular library that provides an HttpInterceptor to automatically attach JSON Web Tokens to HttpClient requests. It handles token attach… | 67 | 2624 | active |
| confident-ai/deepteam DeepTeam is an open-source Python framework for red teaming LLM systems, AI agents, RAG pipelines, and chatbots. It simulates adversarial a… | 67 | 2623 | active |
| AFLplusplus/LibAFL LibAFL is a Rust library of reusable building blocks for constructing custom coverage-guided fuzzers, developed by the AFL++ team. It scale… | 94 | 2622 | active |
| TrackerControl/tracker-control-android TrackerControl is an Android app that monitors and blocks hidden tracking and ads in mobile apps using a local VPN to analyze network traff… | 98 | 2620 | active |
| SummerSec/ShiroAttack2 A Java-based exploitation tool for the Apache Shiro-550 rememberMe deserialization vulnerability, offering both a JavaFX GUI and a CLI. It … | 88 | 2619 | active |
| rbsec/sslscan sslscan is a command-line tool that tests SSL/TLS enabled services to discover supported cipher suites, protocols, key exchange groups, and… | 75 | 2618 | active |
| segmentio/chamber Chamber is a Go CLI tool for managing application secrets by storing them in AWS SSM Parameter Store (with S3 backend support). It lets tea… | 77 | 2614 | active |
| alexedwards/scs SCS is an HTTP session management library for Go that automatically loads and saves session data via middleware. It supports 19 server-side… | 47 | 2613 | stable |
| aboutcode-org/scancode-toolkit ScanCode Toolkit is a command-line tool and Python library that scans codebases to detect licenses, copyrights, package manifests, dependen… | 94 | 2612 | active |
| ory/fosite Fosite is a security-first, extensible OAuth 2.0 and OpenID Connect SDK for Go, implementing RFC 6749, RFC 6819, PKCE, and OpenID Connect C… | 58 | 2612 | active |
| zhizhuodemao/js-reverse-mcp An MCP server that gives AI coding agents (Claude, Cursor, Copilot) tools for JavaScript reverse engineering in a headed Chrome browser, in… | 83 | 2608 | active |
| lexik/LexikJWTAuthenticationBundle A Symfony bundle that provides JSON Web Token (JWT) authentication for Symfony APIs. It handles token creation, validation, and integration… | 71 | 2608 | stable |
| Ericsson/codechecker CodeChecker is an analyzer tooling, defect database and viewer extension for static and dynamic analyzer tools like Clang Static Analyzer a… | 99 | 2606 | active |
| googleprojectzero/winafl WinAFL is a Windows fork of American Fuzzy Lop (AFL) for coverage-guided fuzzing of Windows binaries, including closed-source black-box tar… | 65 | 2604 | active |
| WalletWasabi/WalletWasabi Wasabi Wallet is an open-source, non-custodial, privacy-focused Bitcoin desktop wallet built in C# on .NET. It routes all traffic through T… | 93 | 2603 | active |
| visa/visa-vulnerability-agentic-harness VVAH is Visa's open-source agentic harness for autonomous vulnerability discovery, remediation, and validation using frontier AI models. It… | 67 | 2601 | active |
| uxmal/reko Reko is a general-purpose binary decompiler that translates machine code executables back into high-level language source. It supports mult… | 89 | 2600 | active |
| mas-bandwidth/netcode A C library implementing a secure, connection-oriented client/server protocol on top of UDP for real-time multiplayer games. It handles enc… | 99 | 2595 | active |
| MeowDump/Integrity-Box Integrity Box is a Magisk module toolkit for rooted Android devices that manages Play Integrity attestation and system environment signals.… | 87 | 2591 | active |
| matthart1983/netwatch NetWatch is a zero-config terminal TUI for real-time network diagnostics, written in Rust and distributed as a single static binary. It sho… | 77 | 2590 | active |
| botswin/BotBrowser BotBrowser is a privacy-focused browser core (Chromium-based) that unifies and controls browser fingerprint signals across platforms, integ… | 85 | 2589 | active |
| shaka-project/shaka-packager Shaka Packager is a media packaging tool and SDK for preparing video content for online streaming via DASH and HLS. It supports VOD and liv… | 97 | 2588 | active |
| kubearmor/KubeArmor KubeArmor is a cloud-native runtime security enforcement system that restricts process execution, file access, and networking behavior of p… | 97 | 2588 | active |
| libpnet/libpnet libpnet is a cross-platform Rust library for low-level networking, providing safe packet construction and parsing, transport protocol imple… | 59 | 2588 | stable |
| mewebstudio/captcha A Laravel service provider package that generates CAPTCHA images for form protection, supporting Laravel 5 through 12. It offers session-ba… | 85 | 2583 | active |
| honmashironeko/ProxyCat ProxyCat is a self-hosted tunnel proxy pool middleware that turns short-lived proxy IPs into a stable fixed tunnel endpoint over HTTP/SOCKS… | 66 | 2581 | active |
| snake-4/Zygisk-Assistant A Zygisk module written in C++ that hides the existence of root and Zygisk from apps on Android 5.0 and above. It works with KernelSU, Magi… | 52 | 2581 | active |
| gaasedelen/lighthouse Lighthouse is a code coverage explorer plugin for IDA Pro and Binary Ninja that lets reverse engineers interactively visualize execution co… | 53 | 2577 | stable |
| nelenkov/android-backup-extractor A Java command-line utility that extracts and repacks Android backup archives created with adb backup, based on AOSP's BackupManagerService… | 86 | 2576 | active |
| FreeRADIUS/freeradius-server FreeRADIUS is a high-performance, highly configurable multi-protocol policy server supporting RADIUS, DHCPv4/v6, DNS, TACACS+, and VMPS, wr… | 87 | 2574 | stable |
| oxsecurity/megalinter MegaLinter is an open-source code quality tool that runs over 50 linters and formatters covering 50 languages, 22 formats, and 21 tooling f… | 94 | 2570 | active |
| ajinabraham/nodejsscan nodejsscan is a static application security testing (SAST) scanner for Node.js applications, built on libsast and semgrep. It provides a we… | 44 | 2570 | active |
| pythops/oryx Oryx is a terminal user interface (TUI) application for sniffing and inspecting network traffic in real time using eBPF on Linux. It also p… | 76 | 2568 | active |
| rednaga/APKiD APKiD is a command-line tool that identifies how an Android APK was built, detecting compilers, packers, obfuscators, and app-shielding/RAS… | 78 | 2565 | active |
| BishopFox/cloudfox CloudFox is an open-source command line tool by Bishop Fox that automates situational awareness and enumeration in cloud environments, prim… | 90 | 2563 | active |
| Syslifters/sysreptor SysReptor is a customizable pentest reporting platform for penetration testers and red teamers, supporting report design in HTML, writing i… | 99 | 2560 | active |
| caido/caido Caido is a lightweight web security auditing toolkit and HTTP proxy for intercepting, viewing, and modifying traffic between browsers and w… | 99 | 2558 | active |
| keycloakify/keycloakify Keycloakify is a TypeScript build tool that generates Keycloak themes (login, register, email pages) using modern web frameworks like React… | 92 | 2554 | active |
| s0lst1c3/eaphammer EAPHammer is a toolkit for performing targeted evil twin attacks against WPA2-Enterprise networks, including credential stealing and hostil… | 23 | 2552 | active |
| cgsecurity/testdisk TestDisk and PhotoRec are free, open-source data recovery utilities written in C. TestDisk recovers lost partitions and repairs boot sector… | 76 | 2550 | stable |
| YeQing17-2026/OmniAgent OmniAgent is an open-source Python agent framework that self-evolves across skills, context, memory, and its underlying model during intera… | 56 | 2549 | active |
| NVISOsecurity/AlwaysTrustUserCerts A Magisk/KernelSU module that automatically copies user-installed certificates into the Android system root CA store. It enables TLS traffi… | 47 | 2549 | active |
| lgandx/PCredz PCredz is a Python CLI tool that extracts credentials and authentication tokens (NTLM, Kerberos, HTTP Basic, FTP, SMTP, IMAP, POP3, LDAP, S… | 64 | 2548 | active |
| bkerler/edl A Python CLI tool for communicating with Qualcomm devices in EDL (Emergency Download) mode via the Sahara, Firehose, Streaming, and Diag pr… | 66 | 2547 | active |
| monoxgas/sRDI sRDI is a shellcode implementation of Reflective DLL Injection that converts DLL files into position-independent shellcode via a compiled P… | 32 | 2547 | stable |
| splunk/attack_range Splunk Attack Range is a tool that builds instrumented, vulnerable lab environments in the cloud (AWS, Azure, GCP) or locally using Terrafo… | 84 | 2545 | active |
| onekey-sec/unblob unblob is an extraction suite that parses unknown binary blobs for 78+ archive, compression, and file-system formats, recursively extractin… | 91 | 2544 | active |
| Wire Wire is an open-source, end-to-end encrypted messaging and collaboration platform whose server components are written primarily in Haskell.… | 59 | 2544 | active |
| 7h30th3r0n3/Evil-M5Project Evil-M5Project is a C++ firmware/tool for M5Stack devices (Cardputer, AtomS3, Fire, Core2) that scans, monitors, and interacts with WiFi ne… | 70 | 2543 | active |
| evi0s/WMPFDebugger A debugger tweak for WeChat's Mini-Program Framework (WMPF) that exploits the remote debug feature of WeChat devtools to enable full Chrome… | 65 | 2542 | active |
| refraction-networking/utls uTLS is a fork of Go's crypto/tls library that provides low-level access to the TLS ClientHello message, enabling fingerprint mimicry and r… | 81 | 2539 | active |
| rabbitstack/fibratus Fibratus is a Windows security sensor that performs realtime threat detection by analyzing kernel and system telemetry (including ETW event… | 90 | 2537 | active |
| mubeng/mubeng mubeng is a fast CLI tool written in Go that checks the availability of proxies from a list and rotates your IP address per request via a l… | 78 | 2537 | active |
| Barre/privaxy Privaxy is a MITM HTTP(S) proxy written in Rust that blocks ads and trackers at the network level, supporting Adblock Plus and uBlock Origi… | 23 | 2530 | active |
| sidex15/susfs4ksu-module A KernelSU addon module that installs userspace helpers (ksu_susfs, sus_su) to communicate with a SUSFS-patched kernel for kernel-level roo… | 86 | 2527 | active |
| x90skysn3k/brutespray Brutespray is a fast, multi-protocol credential brute-forcing tool written in Go. It parses scan output from Nmap, Nessus, Nexpose, JSON, a… | 95 | 2525 | active |
| DidierStevens/DidierStevensSuite A bundled collection of Didier Stevens' security research tools, distributed as a ZIP and GitHub repository of Python scripts and utilities… | 75 | 2525 | active |
| v0id4real/Void-Tools Void-Tools is a Python terminal multitool with a Rich TUI dashboard bundling 150+ utilities for OSINT research, network diagnostics, and Di… | 54 | 2524 | active |
| Mattiwatti/EfiGuard EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager, boot loader, and kernel at boot time to disable PatchGuard a… | 62 | 2523 | active |
| pac4j/pac4j pac4j is a Java security engine for authenticating users, managing profiles, and enforcing authorizations across web applications and servi… | 77 | 2521 | stable |