domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| m13253/dns-over-https A high-performance DNS-over-HTTPS (DoH) client and server written in Go, supporting both the Google DoH JSON API and IETF RFC 8484 wire for… | 62 | 2204 | active |
| qwj/python-proxy pproxy is a lightweight asynchronous tunnel proxy implemented in pure Python 3 asyncio, supporting HTTP, HTTP2, HTTP3/QUIC, SOCKS4/5, Shado… | 32 | 2204 | active |
| yandex/gixy Gixy is a Python-based static analyzer for Nginx configuration files that detects security misconfigurations and flaws. It ships as a CLI t… | 23 | 8566 | maintenance |
| AdventDevInc/kudu Kudu is a free, open-source (MIT) system maintenance suite for Windows, macOS, and Linux offering 15+ tools including a system cleaner, mal… | 77 | 2201 | active |
| lefayjey/linWinPwn linWinPwn is a bash script that wraps and streamlines a large set of Active Directory penetration testing tools such as impacket, bloodhoun… | 77 | 2200 | active |
| alangrainger/immich-public-proxy A stateless proxy that sits in front of a self-hosted Immich instance and serves only explicitly shared photos, videos, and albums to the p… | 84 | 2198 | active |
| TheMythologist/GenP GenP is an open-source AutoIt patcher that applies binary hex patches to Adobe Creative Cloud applications on Windows to modify their licen… | 78 | 2196 | active |
| lkarlslund/Adalanche Adalanche is an open-source Active Directory attack graph visualizer and explorer written in Go. It collects data via LDAP and SYSVOL, anal… | 67 | 2195 | active |
| jwt-dotnet/jwt Jwt.Net is a C# library for generating, encoding, decoding, and validating JSON Web Tokens (JWT) per RFC 7519. It includes fluent builder A… | 92 | 2194 | stable |
| ghostunnel/ghostunnel Ghostunnel is a simple TLS proxy written in Go that adds mutual TLS authentication in front of (or behind) non-TLS backend services, in cli… | 99 | 2192 | active |
| MatthewKuKanich/FindMyFlipper A FlipperZero application that turns the device into a BLE tracker beacon emulating Apple AirTags, Samsung SmartTags, or Tile trackers. It … | 22 | 2192 | active |
| bytecode77/r77-rootkit r77 is a fileless ring 3 (userland) rootkit for Windows that hides files, processes, registry keys, services, and network connections using… | 75 | 2191 | active |
| ReClassNET/ReClass.NET ReClass.NET is a .NET-based memory inspection and class structure reconstruction tool for analyzing remote processes, a modernized port of … | 23 | 2187 | active |
| o-gs/dji-firmware-tools A collection of C command-line tools for extracting, modifying, and repacking firmware of DJI drones such as Phantom, Mavic, Inspire, and S… | 74 | 2186 | active |
| NeilFraser/JS-Interpreter A sandboxed JavaScript interpreter written in JavaScript that executes arbitrary ES5 code in isolation and safety. It supports line-by-line… | 72 | 2185 | active |
| ZerBea/hcxdumptool hcxdumptool is a C-based command-line tool that captures packets from WLAN devices and runs layer 2 attacks against the WPA protocol to fin… | 79 | 2184 | active |
| mandiant/flare-fakenet-ng FakeNet-NG is a dynamic network analysis tool that intercepts and redirects network traffic while simulating legitimate network services. I… | 63 | 2183 | active |
| ranisalt/node-argon2 Node.js bindings to the reference Argon2 password-hashing implementation, supporting Argon2i, Argon2d, and Argon2id. It provides a simple a… | 93 | 2182 | stable |
| rofl0r/microsocks MicroSocks is a tiny, multithreaded SOCKS5 proxy server written in C with minimal resource usage and no config file required. It supports I… | 67 | 2181 | active |
| DigitalRuby/IPBan IPBan is a free, open-source security service that monitors failed login attempts from event logs and log files on Windows and Linux server… | 84 | 2180 | active |
| 0vercl0k/rp rp++ is a fast C++ command-line tool that finds ROP (Return-Oriented Programming) gadgets in PE, ELF, and Mach-O binaries for x86, x64, ARM… | 44 | 2180 | active |
| ruby-oauth/oauth2 A Ruby gem implementing OAuth 2.0 and 2.1 client functionality, including OpenID Connect (OIDC) support. It handles token requests, grant t… | 97 | 2179 | active |
| risc0/risc0 RISC Zero is a zero-knowledge verifiable general computing platform built on zk-STARKs and a RISC-V-based zkVM. It lets developers prove th… | 94 | 2179 | active |
| ovh/the-bastion The Bastion is a self-hosted SSH bastion/gateway that acts as the single entry point for operational teams to access infrastructure devices… | 90 | 2177 | stable |
| Harry24k/adversarial-attacks-pytorch Torchattacks is a PyTorch library providing implementations of adversarial attacks to generate adversarial examples against deep learning m… | 23 | 2177 | active |
| kimci86/bkcrack bkcrack is a command-line tool that cracks legacy ZIP encryption (ZipCrypto/PKWARE) using Biham and Kocher's known plaintext attack. Given … | 73 | 2176 | active |
| Ylarod/Florida Florida is an automatically patched, anti-detection build of frida-server for Android, tracking the upstream FRIDA project. It rebuilds fri… | 89 | 2175 | active |
| a16z/helios Helios is a fast, trustless multichain light client for Ethereum written in Rust that turns an untrusted centralized RPC endpoint into a ve… | 85 | 2175 | active |
| assafdori/bypass-mdm A shell script that bypasses Mobile Device Management (MDM) enrollment during macOS setup, supporting versions up to macOS Tahoe 26.3. It r… | 55 | 2175 | active |
| safe-fndn/safe-smart-account Safe Smart Account is the set of audited Solidity smart contracts implementing Safe's multisig smart account (contract wallet) for Ethereum… | 69 | 2174 | active |
| AhmetCanArslan/ShizuWall ShizuWall is a lightweight Android firewall app that controls per-app network access without using a VPN tunnel. It works on Android 11+ by… | 83 | 2172 | active |
| Baseflow/flutter-permission-handler A Flutter plugin providing a cross-platform API to request and check device permissions on iOS and Android. It follows the federated plugin… | 76 | 2171 | stable |
| lenucksi/aur-malware-check A Python CLI tool that detects compromised AUR packages from the June 2026 atomic-lockfile supply-chain attack and other historical campaig… | 54 | 2168 | active |
| zmap/zgrab2 ZGrab2 is a fast, modular application-layer network scanner written in Go, designed for large Internet-wide surveys in tandem with ZMap. It… | 75 | 2167 | active |
| salesforce/policy_sentry Policy Sentry is a Python CLI tool and library that generates least-privilege AWS IAM policies. It automates writing security-conscious IAM… | 88 | 2166 | stable |
| beelzebub-labs/beelzebub Beelzebub is an open-source deception runtime framework written in Go that deploys adaptive, LLM-powered honeypot decoy services across SSH… | 98 | 2165 | active |
| zhzyker/dismap Dismap is a Go-based asset discovery and identification tool that fingerprints web, TCP, UDP, and TLS services using a rule base of 4500+ w… | 23 | 2163 | active |
| BishopFox/unredacter Unredacter is an Electron-based desktop tool that demonstrates how pixelated redactions in images can be reversed by brute-force guessing t… | 32 | 8382 | maintenance |
| dronesploit/dronesploit DroneSploit is a Metasploit-style console framework for pentesting commercial drones, built on sploitkit. It gathers drone-focused hacking … | 23 | 2161 | active |
| jar-analyzer/jar-analyzer A free, open-source GUI tool for analyzing Java JAR files, offering method call relationship search, DFS call chain analysis, taint analysi… | 94 | 2158 | active |
| ffffffff0x/f8x f8x is a Bash-based automation deployment script that installs 100+ security and development tools for red team, blue team, CTF, and cloud-… | 65 | 2156 | active |
| microsoft/SysmonForLinux Sysmon for Linux is a Sysinternals tool that monitors and logs system activity such as process lifetime, network connections, and file syst… | 86 | 2153 | active |
| vulhub/java-chains Java Chains is a self-hosted web platform for generating Java exploitation payloads, aimed at security researchers. It supports common Java… | 89 | 2152 | active |
| RichardKnop/go-oauth2-server A standalone, specification-compliant OAuth 2.0 authorization server written in Go. It implements the standard grant types (authorization c… | 48 | 2148 | active |
| 0Chencc/CTFCrackTools CTFCrackTools X is a cross-platform desktop CTF toolkit built with Rust and Tauri, featuring a visual node-based workflow for composing enc… | 80 | 2146 | active |
| bit4woo/domain_hunter_pro Domain Hunter Pro is a Burp Suite plugin (Java jar) for automated domain and subdomain collection, web title fetching, and target managemen… | 63 | 2145 | active |
| sashs/Ropper Ropper is a Python CLI tool that displays information about binary files (ELF, PE, Mach-O, RAW) and finds ROP/JOP gadgets to build exploit … | 77 | 2144 | active |
| 7723mod/NPatch NPatch is a rootless Xposed framework forked from LSPatch, based on LSPosed, that injects Xposed modules into target APKs by inserting dex … | 84 | 2143 | active |
| Infisical/agent-vault Agent Vault is an open-source HTTP credential proxy and vault by Infisical that sits between AI agents and the APIs they call. It stores cr… | 80 | 2141 | active |
| python-social-auth/social-app-django The Django integration component of the python-social-auth ecosystem, providing social authentication and registration via OAuth2 and other… | 93 | 2140 | active |
| log2timeline/plaso Plaso (log2timeline) is a Python-based engine for automatically creating super timelines from timestamped events found in logs and files on… | 87 | 2140 | active |
| thinkst/canarytokens Canarytokens is a self-hostable service by Thinkst that generates tripwire tokens (URLs, DNS names, AWS keys, files, etc.) which alert you … | 76 | 2140 | active |
| last-byte/PersistenceSniper PersistenceSniper is a PowerShell module for hunting persistence mechanisms implanted in Windows machines. It is aimed at Blue Teams, Incid… | 34 | 2139 | active |
| tomnomnom/gf gf is a Go-based command-line wrapper around grep that lets you save and reuse named regex patterns and flags as JSON files. It simplifies … | 32 | 2139 | stable |
| datatheorem/TrustKit TrustKit is an open-source Objective-C framework that simplifies deploying SSL public key pinning and reporting in iOS, macOS, tvOS, and wa… | 78 | 2138 | active |
| fortra/nanodump NanoDump is a C-based tool that creates minidumps of the Windows LSASS process using a variety of stealthy handle-acquisition and dumping t… | 32 | 2137 | active |
| PowerShell/Win32-OpenSSH A Win32 port of OpenSSH for Windows, now serving as a release and issue tracker plus wiki for the project. Active development has moved to … | 53 | 8252 | maintenance |
| nettitude/PoshC2 PoshC2 is a proxy-aware Command and Control (C2) framework written in Python3 that aids penetration testers with red teaming, post-exploita… | 47 | 2132 | active |
| phra/PEzor PEzor is an open-source shellcode and PE packer that wraps executables or raw shellcode into new binaries with evasion features like unhook… | 32 | 2129 | active |
| martin-ger/esp32_nat_router Open-source firmware that turns an ESP32 into a WiFi NAT router and firewall, routing between an AP interface and a STA or Ethernet uplink.… | 72 | 2126 | active |
| motioneye-project/motioneyeos motionEyeOS is a Linux distribution that turns single-board computers like the Raspberry Pi into a video surveillance system with camera mo… | 26 | 8210 | maintenance |
| a13xp0p0v/kernel-hardening-checker A Python CLI tool that checks the security hardening options of the Linux kernel across Kconfig options, boot command line arguments, and s… | 76 | 2123 | active |
| 0xsdeo/AntiDebug_Breaker A Chrome browser extension built on the Hook_JS library that assists with JavaScript reverse engineering and penetration testing reconnaiss… | 76 | 2122 | active |
| chainreactors/gogo gogo is a high-performance, highly configurable automated scanning engine written in pure Go for red team operations. It combines port scan… | 91 | 2118 | active |
| MinaProtocol/mina Mina is a layer-1 cryptocurrency protocol implemented in OCaml featuring a constant-sized (~22KB) blockchain built with recursive zero-know… | 95 | 2116 | active |
| Leanmcp/superview.sh A shell-based setup for the LeanMCP AI Gateway, a hosted proxy that routes Claude Code (and other AI coding tools) requests through a singl… | 48 | 2112 | active |
| paragonie/random_compat A PHP 5.x polyfill providing the random_bytes() and random_int() CSPRNG functions that were introduced in PHP 7. It fails with an exception… | 54 | 8154 | maintenance |
| hannob/snallygaster Snallygaster is a Python command-line scanner that probes HTTP servers for files that should not be publicly accessible, such as exposed gi… | 54 | 2110 | active |
| haccer/subjack Subjack is a DNS takeover scanner written in Go that concurrently scans lists of subdomains to identify ones vulnerable to hijacking. It de… | 87 | 2109 | active |
| virtualabs/btlejack BtleJack is a Python CLI tool for sniffing, jamming, and hijacking Bluetooth Low Energy (BLE) connections. It relies on BBC Micro:Bit, Blue… | 23 | 2107 | active |
| sparrowwallet/sparrow Sparrow is a free, open-source desktop Bitcoin wallet application built in Java with a focus on security, privacy, and transparency. It sup… | 98 | 2106 | active |
| yjeanrenaud/yj_nearbyglasses Nearby Glasses is a mobile app that scans Bluetooth LE advertisements to detect smart glasses (like Ray-Ban Meta) nearby and warns the user… | 80 | 2099 | active |
| topjohnwu/libsu libsu is an Android library providing a complete solution for apps that need root (superuser) permissions. It wraps the Unix root shell pro… | 56 | 2099 | active |
| jdx/fnox fnox is a Rust CLI tool for managing secrets via encryption or cloud secret providers, storing them in a git-committed fnox.toml file. It s… | 84 | 2098 | active |
| Wifite Wifite is a Python command-line tool that automates wireless network security auditing by running existing tools like the Aircrack-ng suite… | 66 | 8084 | maintenance |
| thoughtworks/talisman Talisman is a Go-based CLI tool that installs a git pre-commit/pre-push hook to scan outgoing changesets for potential secrets such as toke… | 66 | 2096 | active |
| al0ne/LinuxCheck A shell-based Linux emergency response and information gathering tool that performs 70+ security checks across 13 categories, including roo… | 23 | 2096 | active |
| defparam/smuggler Smuggler is a Python 3 command-line tool that tests web servers and proxies for HTTP request smuggling and desync vulnerabilities. It fires… | 32 | 2093 | active |
| Sh1Yo/x8 x8 is a hidden parameter discovery suite written in Rust for security testing of web applications. It brute-forces parameter names against … | 23 | 2093 | active |
| Keats/jsonwebtoken A Rust library for creating and decoding JSON Web Tokens (JWTs) in a strongly typed way, supporting HS256/384/512, RS256/384/512, PS256/384… | 75 | 2089 | active |
| vvb2060/KeyAttestation An Android app for generating, parsing, and verifying Android key and ID attestation data. It performs self-testing locally with no network… | 43 | 2088 | active |
| pivpn/pivpn PiVPN is a set of shell scripts that turn a Raspberry Pi or any Debian/Ubuntu server into a WireGuard or OpenVPN VPN server with a one-comm… | 81 | 8037 | maintenance |
| hanc00l/nemo_go Nemo is an automated information-gathering platform for penetration testing that integrates common recon tools (Masscan, Nmap, Subfinder, H… | 88 | 2086 | active |
| GrapheneOS/Vanadium Vanadium is a privacy and security hardened variant of Chromium that serves as the standard browser and WebView provider on GrapheneOS. It … | 95 | 2085 | active |
| 520coding/confuse A Mac application that performs source-to-source obfuscation of iOS projects, simulating human-style renaming with context awareness includ… | 88 | 2085 | active |
| mkhorasani/Streamlit-Authenticator A Python library providing secure authentication widgets and credential management for Streamlit applications. It supports login, registrat… | 66 | 2083 | active |
| rebootuser/LinEnum LinEnum is a shell script that performs scripted local Linux enumeration and privilege escalation checks. It gathers system, user, network,… | 32 | 8012 | maintenance |
| Trail of Bits Claude Code Config A Claude Code plugin marketplace from Trail of Bits offering skills for AI-assisted security analysis, code auditing, and vulnerability det… | 60 | 2079 | active |
| oss-review-toolkit/ort The OSS Review Toolkit (ORT) is a FOSS policy automation toolkit that analyzes project dependencies, scans licenses and copyrights, checks … | 95 | 2075 | active |
| someengineering/fixinventory Fix Inventory is an open-source cloud asset inventory and security tool that collects metadata from cloud providers (AWS, GCP, Azure, Digit… | 56 | 2074 | active |
| AzizKpln/Moriarty-Project Moriarty Project is a web-based phone number investigation tool written in Python that gathers information about a given phone number. It a… | 23 | 2074 | active |
| hashicorp/envconsul Envconsul is a Go CLI tool that launches a subprocess with environment variables populated from HashiCorp Consul key-value data and Vault s… | 82 | 2071 | active |
| microsoft/sbom-tool Microsoft's SBOM Tool is a scalable, enterprise-ready CLI that generates SPDX 2.2 and SPDX 3.0 compatible Software Bill of Materials docume… | 81 | 2068 | active |
| redballoonsecurity/ofrak OFRAK is a binary analysis and modification platform that identifies, unpacks, analyzes, modifies, and repacks binaries, with first-class s… | 67 | 2067 | active |
| lasting-yang/frida_dump A collection of Frida scripts for dumping DEX files and native shared libraries (.so) from running Android processes. It includes SoFixer-b… | 49 | 2067 | active |
| CorentinTh/enclosed Enclosed is a minimalistic self-hostable web application for sharing end-to-end encrypted notes and file attachments. Notes are encrypted c… | 69 | 2066 | active |
| SamueleAmato/sosec sosec is a Python command-line toolkit with a terminal UI for automated credential testing and HTTP request orchestration against social me… | 63 | 2065 | active |
| haad/proxychains ProxyChains is a UNIX command-line tool that forces TCP connections and DNS lookups of any dynamically linked program through SOCKS4/5 or H… | 32 | 7938 | maintenance |
| erocarrera/pefile pefile is a multi-platform Python module for parsing and working with Portable Executable (PE) files such as EXE and DLL binaries. It expos… | 67 | 2064 | stable |
| ipinfo/cli The official command-line client for the IPinfo.io API, written in Go. It lets users look up IP geolocation, ASN, privacy detection, and re… | 73 | 2058 | active |