domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| lukechilds/reverse-shell A hosted service (reverse-shell.sh) that generates reverse shell payloads on demand; piping its URL output into sh on a target spawns a she… | 63 | 2055 | active |
| massgravel/TSforge TSforge is a C# command-line tool implementing a collection of activation and evaluation extension methods for Windows Vista through 11, in… | 46 | 2053 | active |
| CYB3RMX/Qu1cksc0pe Qu1cksc0pe is an all-in-one malware analysis tool that statically and dynamically analyzes many file types, including Windows/Linux/macOS e… | 77 | 2049 | active |
| openpubkey/opkssh opkssh is a Go CLI tool that enables SSH authentication via OpenID Connect identities instead of long-lived SSH keys. It generates SSH publ… | 85 | 2048 | active |
| Leon406/ToolsFx ToolsFx is a cross-platform desktop cryptography toolbox built with Kotlin. It bundles encoding/decoding, hash and MAC computation, symmetr… | 73 | 2048 | active |
| berdav/CVE-2021-4034 A proof-of-concept exploit and vulnerability checker for CVE-2021-4034 (PwnKit), a polkit pkexec local privilege escalation vulnerability i… | 32 | 2048 | stable |
| mcu-tools/mcuboot MCUboot is a secure bootloader for 32-bit microcontrollers that defines common infrastructure for bootloaders and flash layout, enabling se… | 80 | 2045 | stable |
| sipt/shuttle Shuttle is a cross-platform network proxy tool written in Go supporting SOCKS5, SOCKS5 over TLS, and shadowsocks protocols. It offers rule-… | 48 | 2045 | active |
| ine-labs/AWSGoat AWSGoat is a deliberately vulnerable AWS infrastructure deployed via Terraform, featuring OWASP Top 10 web vulnerabilities and cloud miscon… | 42 | 2044 | active |
| SAP/macOS-enterprise-privileges Privileges is a free macOS application from SAP that lets enterprise users temporarily elevate their accounts to administrator rights for a… | 89 | 2043 | active |
| stacklok/toolhive ToolHive is an open-source platform for running, securing, and managing Model Context Protocol (MCP) servers. It wraps MCP servers in isola… | 83 | 2043 | active |
| CyberStrikeus/CyberStrike CyberStrike is an open-source AI-powered offensive security harness that runs automated penetration testing from the terminal. It orchestra… | 81 | 2043 | active |
| kaikramer/keystore-explorer KeyStore Explorer is a free, open-source Java desktop application that provides a graphical interface replacing the keytool and jarsigner c… | 88 | 2042 | active |
| eugene1g/agent-safehouse Agent Safehouse is a macOS-native sandboxing tool that runs local LLM coding agents (Claude Code, Codex, Gemini CLI, Aider, etc.) inside a … | 80 | 2037 | active |
| mandiant/speakeasy Speakeasy is a Windows user-mode and kernel-mode emulation framework that runs binaries, drivers, and shellcode inside a modeled Windows ru… | 91 | 2036 | active |
| iden3/snarkjs A JavaScript and pure WebAssembly implementation of zkSNARK schemes including Groth16, PLONK, and FFLONK. It provides all tooling for gener… | 77 | 2036 | active |
| lirantal/is-website-vulnerable A Node.js CLI tool that scans a website's frontend JavaScript libraries for publicly known security vulnerabilities using the Snyk database… | 97 | 2035 | active |
| ainfosec/FISSURE FISSURE is an open-source RF and reverse engineering framework built around software-defined radios, supporting signal detection, classific… | 76 | 2033 | active |
| PlakarKorp/plakar Plakar is an open-source backup engine written in Go that creates encrypted, deduplicated, independently verifiable snapshots of files, dat… | 96 | 2032 | active |
| sahat/satellizer Satellizer is a token-based authentication module for AngularJS with built-in support for major OAuth providers (Google, Facebook, Twitter,… | 23 | 7791 | maintenance |
| brightio/penelope Penelope is a modern reverse shell handler for penetration testers and CTF players, serving as a more capable alternative to basic netcat l… | 92 | 2031 | active |
| certsocietegenerale/FIR FIR (Fast Incident Response) is a self-hosted cybersecurity incident management platform built with Django. It enables CSIRTs, CERTs, and S… | 66 | 2030 | active |
| megadose/ignorant Ignorant is a Python CLI tool and library that checks whether a phone number is registered on sites like Instagram, Snapchat, and Amazon wi… | 32 | 2030 | active |
| jtsylve/LiME LiME (Linux Memory Extractor) is a loadable kernel module that acquires volatile memory from Linux and Android devices, writing captures to… | 81 | 2028 | active |
| TrianguloY/URLCheck URLCheck is an open-source Android app that acts as an intermediary when opening URLs, letting users inspect, clean, and modify links befor… | 87 | 2027 | active |
| lowRISC/ibex Ibex is a production-quality, open-source 32-bit RISC-V CPU core written in SystemVerilog, originally developed as 'Zero-riscy' in the PULP… | 76 | 2026 | active |
| jkroepke/helm-secrets helm-secrets is a Helm plugin that transparently encrypts and decrypts Helm value files using sops, allowing secrets to be safely stored in… | 95 | 2025 | active |
| Tencent/soter TENCENT SOTER is a biometric authentication standard and platform for Android, developed by Tencent and used in WeChat fingerprint payment.… | 53 | 2025 | active |
| openid/AppAuth-iOS AppAuth-iOS is an Objective-C client SDK for iOS, macOS, and tvOS that implements OAuth 2.0 and OpenID Connect authorization flows. It foll… | 91 | 2024 | stable |
| GhostPack/Certify Certify is a C# command-line tool for enumerating and abusing misconfigurations in Active Directory Certificate Services (AD CS). It was re… | 76 | 2023 | active |
| sc0tfree/mentalist Mentalist is a graphical Python tool for generating custom password wordlists based on common human password-construction patterns. It can … | 63 | 2021 | active |
| wyzxxz/jndi_tool A Java-based JNDI exploitation tool that runs malicious RMI/LDAP reference servers to test and exploit JNDI injection vulnerabilities, incl… | 32 | 2021 | active |
| usbarmory/tamago TamaGo is a framework that enables compilation and execution of Go applications directly on bare metal processors, without any underlying o… | 99 | 2020 | active |
| yeti-platform/yeti Yeti is a self-hosted threat intelligence platform that stores and links observables, entities, and indicators to answer questions like 'wh… | 99 | 2020 | active |
| zarf-dev/zarf Zarf is a free, open-source CLI package manager for declaratively packaging and deploying Kubernetes applications and cloud-native workload… | 95 | 2019 | active |
| daymade/Twitter-Block-Porn A Tampermonkey/Greasemonkey userscript that batch-blocks Twitter/X accounts from shared blocklists of porn-spam scammers. It simulates Twit… | 73 | 2019 | active |
| attr-encrypted/attr_encrypted A Ruby gem that generates attr_accessors which transparently encrypt and decrypt attributes on any Ruby class. It integrates with ActiveRec… | 46 | 2018 | active |
| ASHWIN990/ADB-Toolkit ADB-Toolkit is a Bash script wrapping the Android Debug Bridge with 28 options plus a Metasploit section for testing and exploiting Android… | 23 | 2016 | active |
| opsre/go-ldap-admin A modern web-based admin panel for managing OpenLDAP servers, built with a Go (Gin + Gorm) backend and Vue frontend. It also syncs organiza… | 84 | 2013 | active |
| xuxueli/xxl-sso XXL-SSO is a lightweight, distributed single sign-on (SSO) framework for Java/Spring applications. It supports login, permission, and role … | 93 | 2011 | active |
| Kritt-ai/open-kritt open·kritt is an open-source, self-hosted AI vulnerability research platform that decomposes a codebase into focused security tasks, runs A… | 79 | 2011 | active |
| authgear/authgear-server Authgear is an open-source customer identity and access management (CIAM) platform serving as a self-hostable alternative to Auth0, Clerk, … | 95 | 2010 | active |
| endrazine/wcc The Witchcraft Compiler Collection (WCC) is a set of compilation tools for performing binary manipulation on ELF executables across POSIX p… | 90 | 2010 | active |
| dqzg12300/fridaUiTools fridaUiTools is a PyQt5 desktop workbench that wraps Frida into a unified GUI for attaching to processes, managing hook script templates, v… | 86 | 2010 | active |
| admindroid-community/powershell-scripts A collection of over 100 self-contained PowerShell scripts for managing, reporting on, and auditing Microsoft 365 (Office 365) tenants. Eac… | 77 | 2010 | active |
| Google2FA A PHP library implementing Google-compatible two-factor authentication via HMAC-based (HOTP, RFC 4226) and time-based (TOTP, RFC 6238) one-… | 69 | 2007 | stable |
| bitbrute/evillimiter A Python command-line tool that monitors, analyzes, and limits the bandwidth of devices on a local network using ARP spoofing and traffic s… | 56 | 2007 | active |
| Runnin4ik/dpi-detector A Python CLI tool that detects and classifies Deep Packet Inspection (DPI) based internet censorship, including TCP 16-20KB connection drop… | 82 | 2005 | active |
| ambethia/recaptcha A Ruby gem providing helper methods for Google's reCAPTCHA API, supporting v2 checkbox, invisible, and v3 score-based verification. It offe… | 72 | 2005 | stable |
| shivaya-dav/DogeRat DogeRat is a Telegram-controlled Android remote access tool (RAT) consisting of a Node.js/Express/Socket.IO server and a Kotlin Android APK… | 42 | 2005 | active |
| EgeBalci/sgn SGN is a polymorphic binary encoder that encodes shellcode using an additive feedback loop similar to an LFSR, producing statically undetec… | 91 | 2003 | active |
| chris2511/xca XCA is a cross-platform desktop GUI application for creating and managing X.509 certificates, certificate requests, RSA/DSA/EC private keys… | 68 | 2003 | active |
| jstedfast/MimeKit MimeKit is a C#/.NET library for creating and parsing MIME email messages, with support for S/MIME, OpenPGP, DKIM, ARC, TNEF, and Unix mbox… | 76 | 2000 | stable |
| pyupio/safety Safety CLI is a Python dependency vulnerability scanner that detects packages with known vulnerabilities and malicious packages in local de… | 94 | 1995 | active |
| microsoft/msticpy msticpy is a Python library from Microsoft for security investigation and threat hunting in Jupyter notebooks. It provides data acquisition… | 92 | 1995 | active |
| bcrypt-ruby/bcrypt-ruby bcrypt-ruby is a Ruby binding to the OpenBSD bcrypt() password hashing algorithm, provided as a gem with a native C extension. It lets deve… | 82 | 1994 | stable |
| GitGuardian/ggshield ggshield is a CLI application from GitGuardian that detects over 500 types of hardcoded secrets in files, git history, and CI environments … | 99 | 1992 | active |
| cnlimiter/codex-manager A self-hosted Python web UI for managing OpenAI/ChatGPT accounts, supporting bulk registration via multiple temporary and IMAP email servic… | 63 | 1992 | active |
| mfontanini/libtins libtins is a high-level, multiplatform C++ library for network packet sniffing, parsing, and crafting. It provides an efficient, endianness… | 86 | 1991 | stable |
| authorizerdev/authorizer Authorizer is an open-source, self-hosted authentication and authorization server written in Go, providing OAuth2/OIDC, SAML SSO, MFA, soci… | 98 | 1984 | active |
| hectorm/hblock hBlock is a POSIX-compliant shell script that aggregates domains serving ads, trackers, and malware from multiple blocklist sources and gen… | 66 | 1981 | active |
| t6x/reaver-wps-fork-t6x Reaver is a C-based command-line tool that performs brute force attacks against Wi-Fi Protected Setup (WPS) registrar PINs to recover WPA/W… | 45 | 1981 | active |
| mikenicholson/passport-jwt passport-jwt is a Passport authentication strategy for Node.js that authenticates HTTP requests using JSON Web Tokens. It extracts a JWT fr… | 32 | 1980 | active |
| manfredsteyer/angular-oauth2-oidc A TypeScript library adding OAuth 2, OAuth 2.1, and OpenID Connect support to Angular applications. It handles token issuance, validation, … | 93 | 1979 | stable |
| mewebstudio/Purifier A Laravel service provider that wraps the HTMLPurifier library for sanitizing HTML input. It provides a simple clean() helper and Purifier … | 75 | 1979 | stable |
| pgkt04/defender-control An open-source Windows utility that permanently disables or re-enables Windows Defender by running as TrustedInstaller, setting disabling p… | 80 | 1978 | active |
| WireGuard WireGuard is a fast, modern, and secure VPN tunnel that uses state-of-the-art cryptography (Noise framework, Curve25519, ChaCha20) to creat… | 70 | 1978 | stable |
| dswd/vpncloud VpnCloud is a high-performance peer-to-peer mesh VPN written in Rust that runs over UDP with strong end-to-end encryption (Curve25519 and A… | 23 | 1978 | stable |
| msoedov/agentic_security Agentic Security is an open-source LLM vulnerability scanner and AI red-teaming toolkit that probes large language models and agent workflo… | 87 | 1977 | active |
| dfunckt/django-rules A Python library providing object-level permissions for Django without requiring a database, built on a generic rule-based predicate framew… | 44 | 1977 | stable |
| GrapheneOS/hardened_malloc hardened_malloc is a security-focused general purpose memory allocator implementing the malloc API with extensive hardening against heap co… | 77 | 1975 | active |
| chobits/ngx_http_proxy_connect_module An nginx module (also compatible with Tengine and OpenResty) that adds support for the HTTP CONNECT method, turning nginx into a forward pr… | 23 | 1975 | active |
| cossacklabs/themis Themis is a cross-platform, high-level cryptographic library providing ready-made building blocks for secure data storage, encrypted messag… | 76 | 1973 | stable |
| cifertech/nRFBox nRFBox is an open-source ESP32-based handheld tool that scans, analyzes, jams, and spoofs BLE, Wi-Fi, and 2.4GHz signals using an nRF24L01 … | 73 | 1971 | active |
| hfiref0x/WinObjEx64 WinObjEx64 is a 64-bit Windows utility for exploring the Windows Object Manager namespace, viewing detailed object properties, structure du… | 88 | 1969 | active |
| MichaelGrafnetter/DSInternals DSInternals is a PowerShell module and .NET framework for working with Active Directory internals, including offline NTDS.DIT database pars… | 92 | 1967 | active |
| hyperion-cs/dpi-checkers A collection of checkers (a comprehensive Go-based DPI-CH tool plus browser-based checkers) that detect whether an ISP or datacenter applie… | 85 | 1965 | active |
| bit4woo/knife Knife is a Burp Suite extension written in Java that adds useful right-click context menu functions to improve penetration testing workflow… | 63 | 1963 | active |
| rsc/2fa A command-line two-factor authentication agent written in Go that stores TOTP and HOTP keys and generates one-time authentication codes. Ke… | 32 | 1963 | stable |
| intruder-io/autoswagger Autoswagger is a Python command-line tool that discovers Swagger/OpenAPI specifications, parses their endpoints, and automatically tests th… | 34 | 1960 | active |
| dghubble/gologin gologin is a Go library providing chainable http.Handler implementations for login flows with OAuth1 and OAuth2 providers like Google, GitH… | 67 | 1959 | stable |
| guofei9987/text_blind_watermark A Python library that embeds invisible blind watermarks into plain text without changing its appearance or readability, using a password-pr… | 41 | 1956 | active |
| kkbo8005/mitan Mitan (密探) is an all-in-one penetration testing and security assessment desktop application integrating asset mapping, subdomain brute-forc… | 79 | 1955 | active |
| vmoranv/jshookmcp An MCP server exposing 600+ tools across 34 domains for JavaScript reverse engineering and security research, including browser automation,… | 59 | 1954 | active |
| de4dot/de4dot de4dot is an open-source .NET deobfuscator and unpacker written in C# that restores packed and obfuscated .NET assemblies to near-original … | 10 | 7437 | maintenance |
| owtf/owtf OWASP OWTF (Offensive Web Testing Framework) is a penetration testing framework that unites multiple security tools and aligns testing work… | 67 | 1949 | active |
| f0ng/captcha-killer-modified A modified version of the captcha-killer Burp Suite extension that intercepts captcha images from HTTP responses and recognizes them using … | 41 | 1948 | active |
| ys1231/MoveCertificate A Magisk/KernelSU/APatch root module that moves user-installed certificates into Android's system CA store, supporting Android 7 through 16… | 98 | 1947 | active |
| airsquared/blobsaver blobsaver is a cross-platform GUI and CLI application for automatically saving SHSH blobs for iOS devices, useful for future downgrades and… | 43 | 1947 | active |
| IDA-NO-MCP A collection of reverse engineering skills (prompt/plugin packages) for AI coding assistants like Claude Code, designed to work with IDA-NO… | 58 | 1946 | active |
| Ragnt/AngryOxide AngryOxide is an 802.11 WiFi attack tool written in Rust that provides a single-interface survey capability with automated attacks to captu… | 70 | 1945 | active |
| axi0mX/ipwndfu ipwndfu is an open-source Python tool that exploits iOS device bootroms, most notably via the checkm8 exploit, to put devices into pwned DF… | 32 | 7397 | maintenance |
| oidc-client-ts oidc-client-ts is a TypeScript library providing OpenID Connect (OIDC) and OAuth2 protocol support for browser-based JavaScript application… | 82 | 1944 | active |
| RustSec RustSec is the Rust ecosystem's security advisory database plus a workspace of tooling crates, including the rustsec client library, cargo-… | 97 | 1943 | stable |
| varnish/hitch Hitch is a scalable TLS/SSL termination proxy written in C by Varnish Software. It decrypts TLS connections and forwards unencrypted traffi… | 45 | 1943 | active |
| dromara/MaxKey MaxKey is an open-source IAM/IDaaS product providing Single Sign-On (SSO), identity management, and RBAC-based access control. It supports … | 92 | 1940 | active |
| moul/sshportal sshportal is a transparent SSH bastion (jump host) server written in Go that manages users, hosts, and access control without requiring a t… | 67 | 1940 | active |
| feder-cr/invisible_playwright A Python library that provides an antidetect, stealth-patched Firefox build for Playwright, with fingerprints set at the C++ engine level a… | 81 | 1938 | active |
| eth-infinitism/account-abstraction The reference implementation of ERC-4337 account abstraction for Ethereum, providing the singleton EntryPoint contract, base classes for sm… | 58 | 1938 | active |
| vxunderground/VX-API VX-API is a C++ collection of functions implementing malicious functionality to aid in malware development, maintained by vx-underground. I… | 32 | 1938 | active |