domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Keybase Keybase is an open-source end-to-end encrypted messaging, file-sharing, and identity-verification platform with clients for macOS, Windows,… | 91 | 9242 | maintenance |
| david942j/one_gadget A Ruby command-line tool that finds one-gadget RCE candidates (execve('/bin/sh',...) call sites) in libc binaries for CTF pwn challenges. I… | 67 | 2346 | active |
| MegaManSec/SSH-Snake SSH-Snake is a self-propagating, file-less bash script that automatically discovers SSH private keys on a system, attempts to connect to re… | 10 | 2342 | active |
| AabyssZG/SpringBoot-Scan SpringBoot-Scan is an open-source penetration testing framework targeting Spring Boot applications, written in Python. It scans for sensiti… | 53 | 2340 | active |
| dnakov/little-rat A small Chrome extension that monitors and optionally blocks network calls made by other browser extensions. It requires the extensions-on-… | 34 | 2340 | active |
| sddm/sddm SDDM is a QML-based display manager (login screen) for Linux supporting both X11 and Wayland sessions. It is highly themeable via QtQuick, … | 67 | 2335 | active |
| hzqst/VmwareHardenedLoader A Windows kernel driver that mitigates VMware VM detection by filtering VMware-related firmware strings and blocking VMware PnP registry en… | 87 | 2334 | active |
| rabobank-cdc/DeTTECT DeTT&CT is a Python CLI tool and framework that helps blue teams score and map data source quality, visibility, detection coverage, and thr… | 75 | 2334 | active |
| googleprojectzero/fuzzilli Fuzzilli is a coverage-guided fuzzer for JavaScript engines, built in Swift by Google Project Zero. It generates test programs via a custom… | 67 | 2334 | active |
| BeichenDream/GodPotato GodPotato is a C# Windows privilege escalation tool that abuses a DCOM/RPCSS oxid resolution defect to elevate from a service account with … | 22 | 2334 | stable |
| nfcgate/nfcgate NFCGate is an Android application for capturing, analyzing, modifying, relaying, replaying, and cloning NFC traffic. It is a security resea… | 84 | 2333 | active |
| kubernetes-sigs/aws-iam-authenticator A tool that lets users authenticate to Kubernetes clusters using AWS IAM credentials instead of separate certificates or tokens. It runs as… | 99 | 2332 | active |
| Ch0pin/medusa MEDUSA is a modular automation framework and script repository for runtime testing and investigating Android and iOS apps, built on FRIDA. … | 84 | 2332 | active |
| googleprojectzero/sandbox-attacksurface-analysis-tools A suite of PowerShell tools and .NET libraries from Google Project Zero for analyzing Windows sandbox attack surfaces. It includes NtCoreLi… | 56 | 2332 | active |
| bigbrodude6119/flipper-zero-evil-portal A Flipper Zero application that turns the Wi-Fi dev board (ESP32) into an open access point serving a fake captive portal login page. Captu… | 19 | 2332 | active |
| crev-dev/cargo-crev cargo-crev is a cryptographically verifiable, distributed code review system for the Rust cargo package manager. It lets developers review … | 85 | 2330 | active |
| ssl/ezXSS ezXSS is a self-hosted PHP application that helps penetration testers and bug bounty hunters detect and exploit (blind) cross-site scriptin… | 64 | 2330 | active |
| websanova/vue-auth A lightweight, plugin-based authentication library for Vue.js (Vue 2 and Vue 3) that handles login, registration, and token management in s… | 10 | 2329 | active |
| onury/accesscontrol A Node.js library implementing Role-Based Access Control (RBAC) merged with Attribute-Based Access Control (ABAC), including role inheritan… | 96 | 2327 | active |
| rancher/rke2 RKE2 (RKE Government) is Rancher's fully conformant, next-generation Kubernetes distribution focused on security and compliance, particular… | 94 | 2325 | active |
| hwdsl2/wireguard-install A Bash script that automates setting up a WireGuard VPN server on various Linux distributions, with interactive and fully automatic install… | 77 | 2325 | active |
| safebuffer/vulnerable-AD A PowerShell script that configures a Windows Server domain controller into a deliberately vulnerable Active Directory environment for prac… | 32 | 2325 | active |
| keepassxreboot/keepassxc-browser KeePassXC-Browser is a WebExtension that integrates the KeePassXC password manager with Firefox, Chrome/Chromium, and Edge via native messa… | 95 | 2320 | active |
| UMSKT/UMSKT UMSKT (Universal MS Key Toolkit) is an open-source C++ CLI toolkit for researching and experimenting with Microsoft's pre-Vista (pre-2012) … | 78 | 2318 | active |
| kylemanna/docker-openvpn A Docker image and shell tooling that runs an OpenVPN server in a container, bundled with an EasyRSA PKI certificate authority. It automate… | 33 | 9089 | maintenance |
| MasterKale/SimpleWebAuthn SimpleWebAuthn is a collection of TypeScript-first libraries (@simplewebauthn/server and @simplewebauthn/browser) that simplify adding WebA… | 95 | 2316 | active |
| ps5-linux/ps5-linux-loader A Linux payload that uses hypervisor (HV) exploits to boot a custom Linux bootloader on PS5 Phat and Slim consoles running firmware 3.00-7.… | 78 | 2315 | active |
| p0dalirius/Coercer Coercer is a Python CLI tool that automatically coerces Windows servers to authenticate to an arbitrary machine via multiple RPC methods ov… | 58 | 2310 | active |
| h9zdev/WireTapper WireTapper is a wireless OSINT tool that passively detects and maps nearby radio-emitting devices such as Wi-Fi access points, Bluetooth de… | 51 | 2310 | active |
| JingMatrix/TEESimulator TEESimulator is an Android module that defeats hardware-backed key attestation by running AOSP's reference KeyMint trusted application insi… | 83 | 2307 | active |
| benedmunds/CodeIgniter-Ion-Auth Ion Auth is a simple and lightweight authentication library for the CodeIgniter 4 PHP framework. It provides user registration, login, grou… | 32 | 2307 | stable |
| LuckPerms/LuckPerms LuckPerms is a permissions plugin for Minecraft servers that lets admins control player access by creating groups and assigning permissions… | 77 | 2306 | stable |
| auth0/nextjs-auth0 The Auth0 Next.js SDK is a TypeScript library for adding user authentication to Next.js applications via Auth0. It handles sign-in, sign-ou… | 99 | 2305 | active |
| a466350665/smart-sso Smart-SSO is a lightweight single sign-on (SSO) authentication and authorization center built on Spring Boot, implementing the OAuth2 autho… | 57 | 2303 | active |
| owerdogan/whoami-project Whoami is a user-friendly privacy and anonymity CLI tool for Debian and Arch-based Linux distributions. It bundles 9+ modules such as IP ch… | 44 | 2303 | active |
| ggerganov/kbd-audio A collection of command-line and GUI tools that capture and analyze microphone audio to recover keyboard keystrokes acoustically. Its Keyta… | 23 | 9024 | maintenance |
| bjdgyc/anylink AnyLink is an enterprise-grade SSL VPN server written in Go that supports many concurrent remote-access users. It implements the OpenConnec… | 88 | 2301 | active |
| 1N3/BruteX BruteX is a shell-based CLI tool that automatically brute forces all services running on a target, enumerating open ports, usernames, and p… | 23 | 2299 | active |
| n1nj4sec/pupy Pupy is an open-source, cross-platform (Windows, Linux, macOS, Android) command-and-control and post-exploitation framework written in Pyth… | 10 | 8999 | maintenance |
| Exa-Networks/exabgp ExaBGP is a Python-based BGP protocol implementation that lets network engineers control and interact with BGP sessions through a JSON API … | 99 | 2296 | active |
| jofpin/trape Trape is an OSINT analysis and research tool for tracking people online and executing real-time social engineering attacks, built in Python… | 32 | 8978 | maintenance |
| REAndroid/APKEditor APKEditor is a Java command-line tool for editing Android APK resources without depending on aapt/aapt2. It can decode binary resources to … | 89 | 2291 | active |
| sh-dv/hat.sh Hat.sh is a browser-based web application for secure local file encryption and decryption using XChaCha20-Poly1305 with chunked streaming v… | 23 | 2291 | active |
| gnuton/asuswrt-merlin.ng A fork of the Asuswrt-Merlin third-party firmware that extends support to additional ASUS routers, including DSL and WiFi 6/7 models. It pr… | 89 | 2290 | active |
| yeojz/otplib otplib is a TypeScript-first library for generating and verifying one-time passwords (HOTP and TOTP) for two-factor authentication, compati… | 99 | 2289 | active |
| lz520520/railgun Railgun is a GUI-based penetration testing tool that automates common tasks from manual pentesting experience. It integrates port scanning,… | 35 | 2289 | active |
| API-Security/APIKit APIKit is a BurpSuite extension (Java plugin) that discovers, scans, and audits leaked API documentation such as GraphQL, OpenAPI/Swagger, … | 23 | 2286 | active |
| gautamkrishnar/nothing-private Nothing Private is a proof-of-concept website demonstrating that browser fingerprinting can identify and track users even in private browsi… | 48 | 2285 | active |
| squat/kilo Kilo is a multi-cloud network overlay for Kubernetes built on WireGuard, providing an encrypted layer 3 network that connects nodes across … | 78 | 2284 | active |
| allenymt/PrivacySentry PrivacySentry is an Android privacy compliance toolkit combining a Gradle plugin with a runtime SDK, using annotations plus ASM bytecode in… | 49 | 2283 | active |
| boxlite-ai/boxlite BoxLite is an embeddable micro-VM runtime written in Rust that runs any OCI image inside hardware-isolated virtual machines (KVM on Linux, … | 80 | 2278 | active |
| bitcookies/winrar-keygen An open-source tool and educational write-up explaining the principle behind WinRAR's 'rarreg.key' license file generation, with implementa… | 96 | 2277 | active |
| CravateRouge/bloodyAD bloodyAD is a Python CLI tool for Active Directory privilege escalation that performs specific LDAP calls against domain controllers. It su… | 97 | 2275 | active |
| santigarcor/laratrust Laratrust is a PHP package for Laravel that manages roles and permissions (RBAC/ACL) for users, with support for multiple user models, team… | 73 | 2275 | active |
| Zouuup/landrun Landrun is a lightweight CLI tool that sandboxes arbitrary Linux processes using the kernel's Landlock security module, with no root privil… | 83 | 2274 | active |
| sglfree/freesky A distribution and documentation hub for free anti-censorship (circumvention) software such as Freegate, Ultrasurf, Psiphon 3, and nthLink,… | 67 | 2270 | active |
| smittix/intercept iNTERCEPT is a free, open-source, web-based signal intelligence (SIGINT) platform that unifies dozens of software-defined radio tools into … | 78 | 2269 | active |
| bank-vaults/bank-vaults Bank-Vaults is a CNCF Sandbox umbrella project of tools for cloud-native secret management with Hashicorp Vault. This repository provides t… | 86 | 2267 | active |
| httptoolkit/frida-interception-and-unpinning A collection of Frida scripts that rewrite mobile applications at runtime to bypass certificate pinning and route all HTTPS traffic through… | 76 | 2266 | active |
| Caligatio/jsSHA jsSHA is a pure TypeScript/JavaScript library implementing the complete SHA hash family (SHA-1, SHA-2, SHA-3, SHAKE, cSHAKE, KMAC) plus HMA… | 85 | 2263 | stable |
| google/boringssl BoringSSL is Google's fork of OpenSSL, serving as the TLS/SSL library in Chrome, Chromium, and Android. It is open source but explicitly no… | 99 | 2262 | active |
| SafeGroceryStore/MDUT MDUT is a cross-platform desktop application for managing and exploiting multiple databases (MySQL, MSSQL, PostgreSQL, Oracle, Redis) built… | 95 | 2262 | active |
| ory/polis Ory Polis (formerly BoxyHQ Jackson) is an open-source Enterprise SSO service that bridges SAML and OpenID Connect login flows to OAuth 2.0/… | 89 | 2261 | active |
| mailpile/Mailpile Mailpile is a free, open-source, privacy-focused email client with built-in PGP encryption, a fast custom search engine, and tag-based orga… | 23 | 8822 | maintenance |
| RustCrypto/hashes A collection of cryptographic hash function implementations written in pure Rust, organized as separate crates built on the digest crate's … | 77 | 2258 | active |
| FormidableLabs/react-native-app-auth A React Native bridge around the native AppAuth-iOS and AppAuth-Android SDKs for communicating with OAuth 2.0 and OpenID Connect providers.… | 89 | 2254 | active |
| BinaryAnalysisPlatform/bap CMU Binary Analysis Platform (BAP) is a suite of OCaml libraries and a plugin-extensible CLI tool for analyzing binary programs. It lifts b… | 59 | 2253 | active |
| ARM-software/arm-trusted-firmware Trusted Firmware-A (TF-A) is a reference implementation of secure world software (EL3 firmware, trusted boot, and a small trusted runtime) … | 77 | 2251 | active |
| spyboy-productions/CloakQuest3r CloakQuest3r is a Python-based open-source security research tool that identifies potential origin IP exposure of websites protected by Clo… | 54 | 2250 | active |
| julian-klode/dns66 DNS66 is an open-source Android app that blocks ads and malicious hosts by intercepting DNS queries through a local VPN service. It uses co… | 10 | 2248 | active |
| Foxboron/sbctl sbctl is a user-friendly Secure Boot key manager for Linux written in Go. It creates and enrolls UEFI Secure Boot keys, tracks files that n… | 72 | 2247 | active |
| neurobin/shc shc is a generic shell script compiler that converts shell scripts (bash, sh, zsh, ksh, etc.) into C source code, which is then compiled in… | 23 | 2246 | stable |
| pydio/cells Pydio Cells is a self-hosted, open-core document sharing, collaboration and management platform written in Go with a microservice architect… | 96 | 2244 | active |
| salesforce/cloudsplaining Cloudsplaining is an AWS IAM security assessment tool that identifies violations of least privilege in IAM policies. It generates a risk-pr… | 86 | 2244 | active |
| Storyyeller/Krakatau Krakatau is a Rust-based CLI tool for assembling, disassembling, and decompiling Java bytecode. It is specifically designed to handle obfus… | 66 | 2244 | active |
| irungentoo/toxcore Toxcore is the core C library implementing the Tox protocol, a fully encrypted, peer-to-peer, serverless communication platform for instant… | 32 | 8748 | maintenance |
| Versent/saml2aws saml2aws is a Go CLI tool that authenticates against SAML-based identity providers such as ADFS and PingFederate and exchanges the SAML ass… | 49 | 2241 | active |
| gsliepen/tinc Tinc is a peer-to-peer VPN daemon that creates encrypted private networks over the Internet with automatic full-mesh routing and NAT traver… | 80 | 2239 | stable |
| ckcr4lyf/EvilAppleJuice-ESP32 An ESP32 firmware written in C++ that spams Apple Continuity BLE advertisements to flood nearby iPhones with pop-up notifications. It is ba… | 66 | 2236 | active |
| d3mondev/puredns Puredns is a fast command-line domain resolver and subdomain bruteforcing tool written in Go. It uses massdns for bulk DNS lookups and appl… | 54 | 2234 | active |
| srvrco/getssl A Bash-based CLI tool for obtaining and automatically renewing free SSL/TLS certificates from the Let's Encrypt ACME server. It can deploy … | 95 | 2230 | active |
| pen4uin/java-memshell-generator A highly customizable Java in-memory webshell (memshell) generator supporting multiple middleware servers, frameworks, shell types, and out… | 37 | 2230 | active |
| JingMatrix/NeoZygisk NeoZygisk is a Zygote injection module implemented via ptrace that provides Zygisk API support for APatch and KernelSU, and can replace Mag… | 87 | 2227 | active |
| greenpau/caddy-security A security app and plugin for Caddy v2 providing authentication, authorization, and accounting (AAA). It supports Form-Based, Basic, Local,… | 92 | 2225 | active |
| DanOps-1/Gpt-Agreement-Payment A Python toolkit that reverse-engineers and replays the end-to-end ChatGPT Plus/Team/Pro subscription payment flow (Stripe Checkout, PayPal… | 53 | 2225 | active |
| berthubert/googerteller A C++ command-line tool that plays audible beeps whenever your computer sends packets to Google services or known trackers, using tcpdump o… | 32 | 2225 | active |
| Resinat/Resin Resin is a high-performance proxy pool gateway written in Go that aggregates massive numbers of proxy nodes into a unified, observable prox… | 79 | 2224 | active |
| yuezk/GlobalProtect-openconnect A GlobalProtect VPN client for Linux built on OpenConnect, offering both a CLI and a Tauri-based GUI. It supports SSO authentication includ… | 98 | 2221 | active |
| grimdoomer/Xbox360BadUpdate A non-persistent, software-only hypervisor exploit for the Xbox 360 that runs unsigned code on the latest dashboard (17559) using a support… | 10 | 2221 | active |
| shwenzhang/AndResGuard AndResGuard is a tool from the WeChat team that obfuscates and shrinks Android APK resources, working like ProGuard but for resource files … | 23 | 8645 | maintenance |
| zakirkun/deep-eye Deep Eye is an AI-driven penetration testing CLI that orchestrates multiple LLM providers (OpenAI, Claude, Gemini, OLLAMA, Groq, and others… | 68 | 2219 | active |
| SysSec-KAIST/LTESniffer LTESniffer is an open-source LTE downlink/uplink eavesdropper built on FALCON and srsRAN that decodes PDCCH, PDSCH, and PUSCH channels to c… | 20 | 2219 | active |
| nielsfaber/alarmo Alarmo is a Home Assistant custom integration that turns existing sensors into a full-featured home alarm system, configurable entirely thr… | 93 | 2216 | active |
| punk-security/dnsReaper DNS Reaper is a Python CLI tool that scans DNS records for subdomain takeover vulnerabilities using over 50 signatures, at roughly 50 subdo… | 58 | 2216 | active |
| eeeeeeeeee-code/e0e1-wx A Windows GUI tool (PySide6, Python 3.10+) for analyzing and penetration-testing WeChat mini-programs locally. It automates mini-program pa… | 80 | 2214 | active |
| avast/retdec RetDec is a retargetable machine-code decompiler based on LLVM that converts native binaries back into readable C or Python-like source cod… | 61 | 8612 | maintenance |
| kismetwireless/kismet Kismet is a wireless network detector, sniffer, and intrusion detection system for Wi-Fi, Bluetooth, SDR, and other wireless protocols. It … | 77 | 2210 | active |
| login-securite/lsassy Lsassy is a Python CLI tool that remotely extracts credentials from the LSASS process memory of Windows hosts over the network. It uses imp… | 71 | 2210 | active |
| aemkei/jsfuck JSFuck is an esoteric JavaScript library that encodes and executes arbitrary JavaScript using only six characters: []()!+. It works both in… | 37 | 8597 | maintenance |
| sergiodxa/remix-auth Remix Auth is a complete open-source authentication library for Remix and React Router applications, inspired by Passport.js and built on t… | 74 | 2204 | stable |