domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| jedisct1/piknik Piknik is a command-line tool that securely copies and pastes clipboard content between arbitrary hosts over the network, using end-to-end … | 57 | 2516 | stable |
| kpcyrd/sn0int sn0int is a semi-automatic OSINT framework and package manager written in Rust that enumerates attack surface by processing public informat… | 60 | 2515 | active |
| rspamd/rspamd Rspamd is an advanced spam filtering system and email processing framework written in C with an extensive Lua plugin API. It evaluates mess… | 99 | 2514 | active |
| wardencommunity/warden Warden is a general-purpose authentication framework for Rack-based Ruby web applications. It provides a flexible middleware layer for hand… | 41 | 2514 | active |
| tobiabocchi/flipperzero-bruteforce A Python script that generates .sub files for brute-forcing fixed OOK code subghz protocols using a Flipper Zero device. It supports multip… | 32 | 2512 | active |
| CTurt/FreeDVDBoot FreeDVDBoot is a PlayStation 2 DVD Player exploit written in C that lets users burn homebrew discs which boot on unmodified PS2 consoles. I… | 32 | 2511 | stable |
| epsylon/ufonet UFONet is a free, P2P and cryptographic 'disruptive toolkit' written in Python for performing DoS and DDoS attacks at Layer 7 (HTTP) via Op… | 76 | 2509 | active |
| aspnet-contrib/AspNet.Security.OAuth.Providers A collection of ASP.NET Core authentication middleware providing OAuth 2.0 social login providers such as GitHub, Twitter/X, and Dropbox. I… | 80 | 2508 | active |
| taamarin/box_for_magisk Box for Root (BFR) is a Magisk/KernelSU/APatch module that bundles proxy cores such as clash, sing-box, v2ray, hysteria, and xray to set up… | 58 | 2507 | active |
| gcla/termshark Termshark is a terminal user interface for tshark, the Wireshark command-line packet analyzer, offering Wireshark-like packet inspection in… | 23 | 9970 | maintenance |
| SPIFFE SPIFFE is a framework and set of standards for issuing cryptographic identities to workloads, and SPIRE (the SPIFFE Runtime Environment) is… | 99 | 2500 | stable |
| m4ll0k/SecretFinder SecretFinder is a Python CLI script based on LinkFinder that discovers sensitive data like API keys, access tokens, and JWTs in JavaScript … | 32 | 2500 | active |
| cisagov/Malcolm Malcolm is a containerized network traffic analysis tool suite that ingests full packet capture (PCAP) files, Zeek logs, and Suricata alert… | 99 | 2497 | active |
| mullvad/mullvad-browser Mullvad Browser is a privacy-focused desktop web browser developed jointly by Mullvad VPN and the Tor Project, essentially a Tor Browser de… | 98 | 2497 | active |
| axiomatic-systems/Bento4 Bento4 is a C++ class library and set of command-line tools for reading, writing, inspecting, encrypting, and packaging ISO-MP4 files, incl… | 72 | 2493 | stable |
| quasar/Quasar Quasar is a free, open-source remote administration tool (RAT) for Windows written in C#, offering remote desktop, shell, file management, … | 10 | 9908 | maintenance |
| weggli-rs/weggli weggli is a fast semantic search tool for C and C++ codebases that performs pattern matching on abstract syntax trees using a query languag… | 23 | 2492 | active |
| nil0x42/phpsploit PhpSploit is a full-featured command-and-control (C2) framework that persists on a webserver via a stealthy single-line PHP backdoor. It is… | 23 | 2491 | active |
| symfony/security-bundle SecurityBundle is the official Symfony bundle that integrates the Security component into the Symfony full-stack framework. It provides con… | 97 | 2489 | stable |
| HACKERALERT/Picocrypt Picocrypt is a very small, simple, and secure file encryption tool written in Go, using modern cryptography like XChaCha20, Argon2, and SHA… | 10 | 2488 | active |
| abrahamjuliot/creepjs CreepJS is a web application that performs advanced device and browser fingerprinting to expose weaknesses in anti-fingerprinting browsers … | 71 | 2486 | active |
| mCaptcha/mCaptcha mCaptcha is a self-hosted, privacy-respecting CAPTCHA system that uses SHA-256 proof-of-work to rate-limit users instead of image puzzles. … | 43 | 2486 | active |
| 0xd4d/dnlib dnlib is a C# library that reads and writes .NET assemblies and modules, including method bodies and IL code. It supports loading modules f… | 61 | 2483 | stable |
| SheepChef/Abracadabra Abracadabra is an open-source text encryption tool that transforms encrypted data into realistic Classical Chinese (wenyan) prose, using AE… | 87 | 2482 | active |
| QIN2DIM/hcaptcha-challenger A Python library that solves hCaptcha challenges using multimodal large language models and ONNX vision models (YOLO, CLIP, ResNet) integra… | 86 | 2482 | active |
| googlesamples/easypermissions EasyPermissions is a Java wrapper library that simplifies Android runtime (M+) system permission requests and handling in Activities and Fr… | 10 | 9856 | maintenance |
| TH3xACE/SUDO_KILLER SUDO_KILLER is a Shell-based security tool that audits Linux systems for sudo-related privilege escalation vectors, including misconfigurat… | 64 | 2481 | active |
| voidauth/voidauth VoidAuth is an open-source single sign-on (SSO) and user management provider for self-hosted applications, acting as an OIDC provider, prox… | 85 | 2478 | active |
| bitcoin-core/secp256k1 libsecp256k1 is a high-performance, high-assurance C library for elliptic curve cryptography on the secp256k1 curve, including ECDSA and Sc… | 87 | 2477 | stable |
| Proton VPN Official open-source Proton VPN client apps for Android and Windows, built by Proton AG to route traffic through Proton's VPN servers. The … | 91 | 2476 | active |
| solemnwarning/rehex Rehex is a cross-platform hex editor designed for reverse engineering binary files, with features like large file support, inline disassemb… | 85 | 2476 | active |
| VirusTotal/yara YARA is a pattern matching tool used to identify and classify malware families and other files based on textual or binary pattern rules. It… | 94 | 9831 | maintenance |
| unode/firefox_decrypt Firefox Decrypt is a Python command-line tool that extracts saved passwords from Mozilla product profiles (Firefox, Waterfox, Thunderbird, … | 77 | 2474 | active |
| coreos/go-oidc go-oidc is a mature Go client library for OpenID Connect, built on top of golang.org/x/oauth2. It enables verifying ID tokens and identifyi… | 89 | 2473 | stable |
| sabri-zaki/EasY_HaCk EasY_HaCk is a Termux-based penetration testing menu tool that bundles and installs tools like Metasploit, Nmap, SQLmap, and recon-ng for n… | 43 | 2471 | active |
| archerysec/archerysec ArcherySec is an open-source application security orchestration and correlation (ASOC) and vulnerability management platform that integrate… | 34 | 2471 | active |
| seemoo-lab/AirGuard AirGuard is an Android app that protects users from unwanted tracking via AirTags and other Apple Find My accessories. It periodically scan… | 92 | 2468 | active |
| ryantm/agenix Agenix is a Nix library and CLI tool for managing age-encrypted secrets in NixOS and Home Manager using existing SSH public/private key pai… | 52 | 2468 | active |
| Idov31/Nidhogg Nidhogg is an open-source Windows x64 kernel rootkit written in C++ that demonstrates a wide range of rootkit techniques such as process, t… | 83 | 2463 | active |
| cisco-ai-defense/skill-scanner A security scanner for AI agent skills that detects prompt injection, data exfiltration, and malicious code patterns using pattern-based de… | 80 | 2460 | active |
| assetnote/react2shell-scanner A Python command-line scanner that detects RCE vulnerabilities CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server… | 41 | 2459 | active |
| Notselwyn/CVE-2024-1086 A proof-of-concept local privilege escalation exploit for CVE-2024-1086, a double-free vulnerability in the Linux kernel's nf_tables subsys… | 16 | 2457 | stable |
| mandiant/flare-ida A collection of IDA Pro plugins and IDAPython scripts from Mandiant's FLARE team for reverse engineering and malware analysis. It includes … | 10 | 2453 | active |
| square/certstrap certstrap is a Go-based CLI tool for bootstrapping your own certificate authorities and managing a simple public key infrastructure. It ini… | 52 | 2452 | active |
| Peergos/Peergos Peergos is a peer-to-peer, end-to-end encrypted global filesystem with fine-grained cryptographic access control, built on IPFS/libp2p with… | 77 | 2451 | active |
| DNSCrypt/SimpleDnsCrypt Simple DNSCrypt is a Windows GUI management tool for configuring dnscrypt-proxy. It simplifies setting up encrypted DNS on Windows systems. | 56 | 2450 | active |
| usnistgov/macos_security The macOS Security Compliance Project (mSCP) is an open-source tool from NIST that generates security baselines, configuration profiles, co… | 96 | 2449 | active |
| mitre-attack/attack-navigator A web application for navigating and annotating MITRE ATT&CK matrices, letting users create custom 'layers' that color-code, comment on, an… | 88 | 2448 | active |
| go-ldap/ldap A Go library providing basic LDAP v3 client functionality, implementing RFC 4511 and related specifications. It supports connecting to LDAP… | 88 | 2448 | stable |
| noob-hackers/hacklock Hacklock is a bash-based Termux tool that generates pattern phishing pages to capture an Android victim's unlock pattern via a shared link … | 53 | 2445 | active |
| Dewalt-arch/pimpmykali A shell script that applies a collection of fixes and configuration tweaks to freshly imported Kali Linux virtual machines. It offers an in… | 45 | 2444 | active |
| dromara/domain-admin Domain Admin is a self-hosted web platform for monitoring domain and SSL certificate expiration, built with Python (Flask) and Vue3. It als… | 89 | 2443 | active |
| m0nad/Diamorphine Diamorphine is a loadable kernel module (LKM) rootkit for Linux kernels 2.6.x through 6.x on x86/x86_64 and ARM64. It demonstrates rootkit … | 68 | 2442 | active |
| XSS Hunter XSS Hunter Express is a self-hosted service for tracking and detecting blind cross-site scripting (XSS) vulnerabilities via injected payloa… | 32 | 2440 | active |
| find-sec-bugs/find-sec-bugs Find Security Bugs is a SpotBugs plugin that performs static security analysis of Java bytecode, detecting 144 vulnerability patterns inclu… | 56 | 2437 | active |
| dirkjanm/BloodHound.py BloodHound.py is a Python-based data ingestor for BloodHound that enumerates Active Directory domains, collecting users, groups, computers,… | 54 | 2437 | active |
| ramonvermeulen/whosthere Whosthere is a Local Area Network discovery tool with an interactive Terminal User Interface, written in Go. It discovers devices via mDNS,… | 83 | 2435 | active |
| nz-m/SocialEcho SocialEcho is a full-featured social networking platform built on the MERN stack (MongoDB, Express.js, React.js, Node.js) with automated co… | 31 | 2435 | active |
| cloudflare/gokey gokey is a vaultless password manager written in Go that deterministically derives passwords and cryptographic keys on the fly from a maste… | 80 | 2431 | stable |
| ZerBea/hcxtools A set of C command-line tools that convert WiFi packet captures (pcap/pcapng) into hash formats compatible with Hashcat and John the Ripper… | 79 | 2431 | active |
| drk1wi/Portspoof Portspoof is a lightweight C++ tool that emulates open TCP ports and convincing service signatures across all 65535 ports, making port scan… | 85 | 2427 | active |
| jherrodthomas/automotive-skills-suite A suite of 152 installable Claude skills (76 builder + 76 reviewer pairs) that generate structured automotive engineering deliverables as x… | 58 | 2427 | active |
| ballerine-io/ballerine Ballerine is an open-source infrastructure and data orchestration platform for identity verification (KYC/KYB), fraud prevention, and merch… | 74 | 2426 | active |
| NetSPI/MicroBurst MicroBurst is a PowerShell toolkit for assessing Microsoft Azure security, including service discovery, weak configuration auditing, and po… | 73 | 2426 | active |
| Shuffle/Shuffle Shuffle is an open source security automation, orchestration and response (SOAR) platform built for security professionals, with a visual w… | 97 | 2421 | active |
| GiacomoLaw/Keylogger A simple, bare-bones keylogger that records keystrokes and saves them to a local log file, with separate implementations for Windows, Linux… | 39 | 2421 | active |
| lestrrat-go/jwx A comprehensive Go library implementing the full JOSE family of standards (JWA, JWE, JWK, JWS, JWT) for signing, verifying, encrypting, and… | 99 | 2416 | active |
| LoRexxar/Kunlun-M Kunlun-M is an open-source static code analysis (SAST) tool that detects security vulnerabilities in PHP, JavaScript/Node.js, Python, Golan… | 96 | 2413 | active |
| RevylAI/greenlight Greenlight is an offline CLI compliance scanner that checks mobile apps against Apple App Store Review Guidelines and Google Play Developer… | 71 | 2413 | active |
| wenlng/go-captcha GoCaptcha is a high-performance, modular behavioral CAPTCHA library for Go that generates interactive challenges including click, slide, dr… | 69 | 2411 | active |
| beenuar/AiSOC AiSOC is an open-source, self-hostable AI-powered Security Operations Center that fuses alerts, performs agent-assisted triage, purple-team… | 80 | 2408 | active |
| EmbarkStudios/cargo-deny cargo-deny is a Cargo plugin (cargo subcommand) for linting Rust dependency graphs. It checks crate licenses against allow/deny lists, bans… | 97 | 2407 | active |
| ChrispyBacon-dev/DockFlare DockFlare is a self-hosted Python/Flask application that watches Docker container events and automatically manages Cloudflare Tunnel ingres… | 85 | 2407 | active |
| hasherezade/hollows_hunter Hollows Hunter is a Windows command-line tool built on the PE-sieve passive memory scanner that scans running processes for malicious impla… | 71 | 2401 | active |
| JayBizzle/Crawler-Detect CrawlerDetect is a zero-dependency PHP library that detects bots, crawlers, and spiders by matching User-Agent and HTTP_FROM headers agains… | 95 | 2400 | active |
| panva/openid-client openid-client is a TypeScript library providing OAuth 2.0 and OpenID Connect client APIs for JavaScript runtimes including Node.js, Deno, b… | 99 | 2398 | stable |
| oritera/Cairn Cairn is a general-purpose AI state-space search engine built on a blackboard architecture with a fact-intent graph, where LLM agent worker… | 72 | 2395 | active |
| thomseddon/traefik-forward-auth A minimal forward authentication service that adds Google/OpenID Connect OAuth-based SSO login in front of any HTTP service behind the Trae… | 57 | 2391 | active |
| OpenBullet OpenBullet 2 is a cross-platform automation suite built on .NET for performing HTTP requests against target web applications and processing… | 85 | 2389 | active |
| htrgouvea/nipe Nipe is a Perl-based command-line engine that routes all of a machine's network traffic through the Tor network by manipulating iptables/ip… | 72 | 2387 | active |
| ArgeliusLabs/Chasing-Your-Tail-NG A Python application that monitors Wi-Fi probe requests via Kismet to detect whether a device is being physically followed. It correlates s… | 35 | 2386 | active |
| XZB-1248/Spark Spark is a web-based, cross-platform Remote Administration Tool (RAT) written in Go that lets you monitor and control devices from a browse… | 55 | 2381 | active |
| DataDog/stratus-red-team Stratus Red Team is a self-contained Go CLI that emulates granular, actionable cloud attack techniques mapped to MITRE ATT&CK, against AWS,… | 99 | 2379 | active |
| bootleg/ret-sync ret-sync is a set of plugins that synchronize a debugging session (WinDbg, GDB, LLDB, OllyDbg, x64dbg) with disassemblers (IDA, Ghidra, Bin… | 53 | 2378 | active |
| hisxo/gitGraber gitGraber is a Python3 command-line tool that monitors GitHub search results in real time to find leaked sensitive data such as API keys an… | 66 | 2376 | active |
| Microsoft365DSC/Microsoft365DSC Microsoft365DSC is an open-source PowerShell Desired State Configuration (DSC) module that lets organizations automate the deployment, conf… | 95 | 2375 | active |
| eslint-community/eslint-plugin-security An ESLint plugin providing security-focused linting rules for Node.js code. It flags potential security hotspots like eval usage, unsafe ch… | 86 | 2372 | active |
| bytedance/android-inline-hook Shadowhook is an Android inline hook library written in C, supporting armeabi-v7a (thumb/arm32) and arm64-v8a architectures on Android 4.1 … | 84 | 2372 | active |
| mkj/dropbear Dropbear is a small SSH server and client written in C, designed for low memory and disk footprints. It is widely used on embedded Linux sy… | 91 | 2371 | stable |
| slimm609/checksec A Go rewrite of the classic checksec tool that inspects security hardening properties (RELRO, stack canaries, NX, PIE, FORTIFY_SOURCE, CFI)… | 86 | 2371 | active |
| lijiejie/BBScan BBScan is a fast, lightweight, high-concurrency web vulnerability scanner written in Python. It helps penetration testers quickly identify … | 23 | 2371 | active |
| LSPosed/LSPatch LSPatch is a non-root implementation of the LSPosed Xposed framework that integrates the Xposed API into target Android APKs by inserting d… | 10 | 9336 | maintenance |
| mojocn/base64Captcha A Go library that generates various types of captchas (digits, strings, math, Chinese, audio) and returns them as base64-encoded image or a… | 54 | 2367 | stable |
| hwi/HWIOAuthBundle A Symfony bundle that adds OAuth 1.0a and OAuth 2.0 authentication support, with built-in support for 59 providers such as Google, GitHub, … | 77 | 2365 | active |
| FiloSottile/whoami.filippo.io A public SSH server (written in Go) that identifies visitors by enumerating the public keys their SSH client offers and matching them again… | 67 | 2361 | stable |
| jorhelp/Ingram Ingram is a Python-based vulnerability scanning framework targeting network cameras (IP/CCTV devices). It integrates known exploits for com… | 67 | 2356 | active |
| samugit83/redamon RedAmon is an AI-powered agentic red team framework that automates offensive security operations end-to-end, chaining reconnaissance, explo… | 81 | 2354 | active |
| unrolled/secure Secure is an HTTP middleware library for Go that adds quick security wins to web applications. It works as a standard net/http Handler and … | 70 | 2354 | stable |
| jtpereyda/boofuzz boofuzz is a Python-based network protocol fuzzing framework and the successor to the Sulley Fuzzing Framework. It provides data generation… | 66 | 2354 | active |
| int128/kubelogin kubelogin is a kubectl plugin (kubectl oidc-login) for Kubernetes OpenID Connect authentication, running as a client-go credential plugin. … | 93 | 2351 | active |