domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| anthropics/defending-code-reference-harness A reference implementation from Anthropic for autonomous vulnerability discovery and remediation using Claude, including Claude Code skills… | 57 | 7368 | maintenance |
| evilsocket/legba Legba is a fast, multiprotocol credentials bruteforcer, password sprayer, and enumerator written in Rust on top of the Tokio async runtime.… | 84 | 1934 | active |
| Azure/Microsoft-Defender-for-Cloud The official Microsoft Defender for Cloud community repository containing PowerShell scripts, Azure Policy definitions, Logic App templates… | 73 | 1930 | active |
| Aorimn/dislocker Dislocker is a FUSE-based driver and library that reads and writes Windows BitLocker-encrypted partitions (including BitLocker-To-Go) from … | 76 | 1929 | stable |
| deepfence/PacketStreamer PacketStreamer is a distributed, high-performance remote packet capture tool that runs lightweight sensors on target hosts to stream filter… | 10 | 1929 | active |
| OP-TEE/optee_os OP-TEE Trusted OS is the secure-world operating system implementation of the OP-TEE project, running on ARM TrustZone-enabled hardware. It … | 77 | 1927 | active |
| 1Password/for-open-source 1Password for Open Source is a program that grants eligible open source projects a free 1Password Teams account for securely storing and sh… | 67 | 1927 | active |
| nitefood/asn A Bash-based command-line tool and self-hostable server for looking up ASN, RPKI validity, BGP stats, IP prefixes, AS paths, IP reputation,… | 87 | 1926 | active |
| bee-san/pyWhat pyWhat is a Python CLI tool that identifies what arbitrary text, files, or pcap network captures contain - emails, IP addresses, API keys, … | 23 | 7313 | maintenance |
| jdx/aube aube is a fast Node.js package manager written in Rust that auto-installs dependencies when you run scripts, with secure defaults like a li… | 77 | 1925 | active |
| SleepingBag945/dddd dddd is a Go-based batch information gathering and supply-chain vulnerability detection CLI tool designed to streamline red team workflows.… | 19 | 1924 | active |
| fideloper/TrustedProxy A Laravel package that configures trusted proxies so applications behind load balancers or reverse proxies correctly interpret X-Forwarded … | 23 | 7307 | maintenance |
| dchest/tweetnacl-js TweetNaCl.js is a JavaScript port of the TweetNaCl/NaCl cryptographic library, providing high-level APIs for secret-key and public-key auth… | 39 | 1921 | stable |
| JustasMasiulis/lazy_importer A header-only C++ library for resolving Windows DLL exports at runtime in a way that hides imports from static analysis tools. It uses comp… | 32 | 1920 | stable |
| jeremyevans/rodauth Rodauth is Ruby's most advanced authentication framework, providing a comprehensive set of composable authentication features built on the … | 77 | 1919 | stable |
| hackerschoice/gsocket Global Socket (gsocket) is a C-based toolkit that lets two machines behind NAT or firewalls establish secure, end-to-end encrypted TCP conn… | 67 | 1918 | active |
| KasperskyLab/hrtng An IDA Pro plugin (C++) providing a rich toolkit for reverse engineering: string/data decryption, deobfuscation of Hex-Rays pseudocode, unf… | 87 | 1916 | active |
| nymtech/nym Nym is a decentralized privacy platform built in Rust, centered on a mixnet that shuffles Sphinx packets to protect network-level metadata,… | 99 | 1912 | active |
| mainmatter/ember-simple-auth Ember Simple Auth is a lightweight library for implementing authentication and authorization in Ember.js applications. It maintains a clien… | 91 | 1908 | active |
| atmoz/sftp A Docker image providing an easy-to-use SFTP server based on OpenSSH. Users can be defined via command arguments, environment variables, or… | 60 | 1907 | active |
| zs1083339604/FaceWinUnlock-Tauri A Windows face-recognition unlock application built with Tauri, Vue 3, and OpenCV that injects a custom Credential Provider DLL into the Wi… | 76 | 1906 | active |
| FGRibreau/mailchecker MailChecker is a cross-language library for validating email format and detecting temporary/disposable email addresses, backed by a databas… | 77 | 1905 | active |
| joaoviictorti/RustRedOps RustRedOps is a collection of red team tools and technique implementations written in Rust, primarily targeting Windows. It provides workin… | 53 | 1900 | active |
| netero1010/EDRSilencer A C-based Windows command-line tool that uses Windows Filtering Platform (WFP) APIs to block outbound traffic of running EDR agents, preven… | 17 | 1899 | active |
| ECTO-1A/AppleJuice AppleJuice is a Python proof-of-concept tool that spoofs Apple BLE proximity pairing messages to trigger pairing popups on nearby Apple dev… | 28 | 1897 | active |
| trycompai/comp Comp AI is an open-source, AI-native compliance platform that automates evidence collection, policy generation, and continuous monitoring f… | 81 | 1896 | active |
| tgalal/yowsup Yowsup is a Python library that implements the WhatsApp protocol, enabling developers to build custom applications and clients that communi… | 23 | 7172 | maintenance |
| GhostManager/Ghostwriter Ghostwriter is an open-source Django-based platform from SpecterOps for managing offensive security engagements, including client/project t… | 94 | 1893 | active |
| liamg/traitor Traitor is a Go-based CLI tool that automatically exploits common Linux misconfigurations and known vulnerabilities (GTFOBins, pwnkit, dirt… | 23 | 7160 | maintenance |
| stevemk14ebr/PolyHook_2_0 PolyHook 2.0 is a C++20 library for hooking functions at runtime on x86 and x64 architectures. It supports multiple hooking techniques (inl… | 73 | 1890 | active |
| sleeyax/burp-awesome-tls A Burp Suite extension that hijacks Burp's HTTP and TLS stack to spoof any browser's TLS fingerprint (JA3). It helps evade WAF bot detectio… | 89 | 1889 | active |
| federicodotta/Brida Brida is a Burp Suite extension that bridges Burp Suite and Frida, letting testers invoke and manipulate an application's own methods while… | 49 | 1889 | active |
| rust-fuzz/cargo-fuzz cargo-fuzz is a Cargo subcommand that makes it easy to fuzz test Rust code with libFuzzer. It scaffolds fuzz targets, runs them, minimizes … | 81 | 1888 | active |
| evildevill/instahack Instahack is a Bash and Python-based brute-force tool for testing Instagram account password strength, routing traffic through Tor for anon… | 62 | 1888 | active |
| pentestfunctions/BlueDucky BlueDucky is a Python tool that exploits CVE-2023-45866, an unauthenticated Bluetooth peering vulnerability, to execute keystroke injection… | 56 | 1888 | active |
| tuya-cloudcutter/tuya-cloudcutter Tuya Cloudcutter is a Python-based toolchain that exploits a wireless vulnerability in Tuya smart devices using Beken BK7231 and Realtek ch… | 70 | 1887 | active |
| cisagov/cset CSET is a free desktop application from CISA and Idaho National Laboratory that guides organizations through step-by-step cybersecurity ass… | 69 | 1887 | active |
| nsonaniya2010/SubDomainizer SubDomainizer is a Python CLI tool that discovers hidden subdomains and secrets in webpages, external JavaScript files, GitHub, and local f… | 66 | 1886 | active |
| zema1/watchvuln WatchVuln is a self-hosted Go service that scrapes high-quality vulnerability sources (Aliyun AVD, Chaitin, OSCS, Qianxin TI, Seebug, CISA … | 62 | 1885 | active |
| googleapis/google-auth-library-nodejs Google's officially supported Node.js client library for OAuth 2.0 authentication and authorization with Google APIs. It supports Applicati… | 10 | 1883 | stable |
| jazzband/django-two-factor-auth A Django package providing complete two-factor authentication built on top of django-otp and Django's built-in auth framework. It supports … | 82 | 1878 | active |
| symfony/security-core The core library of the Symfony Security component, providing infrastructure for authentication tokens, user providers, role hierarchies, a… | 95 | 1877 | stable |
| microsoft/openvmm OpenVMM is a modular, cross-platform Virtual Machine Monitor (VMM) written in Rust, developed by Microsoft. It also hosts OpenHCL, a paravi… | 88 | 1877 | active |
| schollz/howmanypeoplearearound A Python CLI tool that estimates how many people are nearby by sniffing WiFi probe requests from smartphones using tshark. It works with mo… | 23 | 7088 | maintenance |
| srixivas/PcapXray PcapXray is a Python-based network forensics tool that visualizes PCAP files or live traffic as an annotated network diagram. It identifies… | 84 | 1874 | active |
| lazaronixon/authentication-zero A Rails generator that scaffolds a complete, pre-built authentication system directly into a Rails application (web or API-only), following… | 34 | 1873 | active |
| zitadel/oidc A Go library implementing both the OpenID Connect client (Relying Party) and server (OpenID Provider) sides of the OIDC/OAuth2 standards, c… | 98 | 1872 | active |
| airbus-seclab/bincat BinCAT is a static binary code analysis toolkit that performs value analysis, taint analysis, type reconstruction, and use-after-free/doubl… | 29 | 1872 | active |
| tanrax/maza-ad-blocking Maza is a local ad blocker written as a single Bash script that blocks ads at the DNS level by editing the operating system's hosts file, w… | 76 | 1870 | active |
| ttionya/vaultwarden-backup A Docker-based backup tool for Vaultwarden (formerly bitwarden_rs) that archives the database, config, RSA keys, attachments, and sends dir… | 97 | 1869 | active |
| keshavdv/unifi-cam-proxy A Python proxy that lets non-Ubiquiti RTSP-enabled cameras appear as native cameras in UniFi Protect NVR. It supports live streaming, full-… | 77 | 1869 | active |
| niklasb/libc-database A shell-based tool that builds a searchable database of libc symbol offsets from Ubuntu, Debian, and other distributions to simplify binary… | 75 | 1869 | active |
| emsec/ChameleonMini ChameleonMini is a freely programmable, portable NFC device that can emulate and clone contactless smartcards, read RFID tags, and sniff/lo… | 23 | 1869 | active |
| trustedsec/CS-Situational-Awareness-BOF A collection of situational awareness commands implemented as Cobalt Strike Beacon Object Files (BOFs) in C, letting operators run low-foot… | 97 | 1868 | active |
| iMerica/dj-rest-auth dj-rest-auth provides drop-in authentication and registration endpoints for Django REST Framework, including login, logout, password manage… | 81 | 1868 | active |
| cloudflare/workers-oauth-provider An OAuth 2.1 provider library for Cloudflare Workers that adds authorization-server capabilities to HTTP APIs and remote MCP servers. It ha… | 86 | 1864 | active |
| Yurii0307/yurikey YuriKey is a systemless root module (for Magisk, APatch, KernelSU and forks) that helps rooted Android devices pass Google Play Integrity's… | 79 | 1864 | active |
| aquasecurity/tfsec tfsec is a static analysis security scanner for Terraform code that detects misconfigurations across major cloud providers using hundreds o… | 59 | 7035 | maintenance |
| 0xKayala/NucleiFuzzer NucleiFuzzer is a Python-based automation tool that combines URL discovery tools (ParamSpider, Waybackurls, Gauplus, Hakrawler, Katana) wit… | 66 | 1862 | active |
| sbabic/swupdate SWUpdate is a Linux update agent for safely updating embedded Linux devices in the field, supporting local and OTA updates with multiple st… | 87 | 1860 | stable |
| abc123info/BlueTeamTools BlueTeamTools is a Java-based GUI toolbox that aggregates utilities for blue-team security analysts, covering memory-shell decompilation, w… | 91 | 1859 | active |
| chame1eon/jnitrace jnitrace is a Frida-based command-line tool that dynamically traces JNI API calls made by native libraries in Android apps. It works like f… | 23 | 1859 | stable |
| sourcery-ai/sourcery Sourcery is an AI-powered automated code review service that reviews pull requests on GitHub and GitLab, posting summaries, inline comments… | 97 | 1858 | active |
| AdguardTeam/AdguardForAndroid AdGuard for Android is a system-wide content blocker for Android that blocks ads, trackers, and malvertising across browsers and apps. This… | 95 | 1857 | active |
| complexorganizations/wireguard-manager A shell-based tool that automates the installation, configuration, and management of WireGuard VPN servers. It provides a user-friendly way… | 48 | 1856 | active |
| sarperavci/GoogleRecaptchaBypass A Python library that automatically solves Google reCAPTCHA v2 challenges in under five seconds using browser automation with DrissionPage … | 68 | 1855 | active |
| trustedsec/hate_crack hate_crack is a Python tool by TrustedSec that automates password cracking methodologies on top of Hashcat, orchestrating wordlists, masks,… | 95 | 1854 | active |
| zakirkun/guardian-cli Guardian is a Python CLI tool that automates penetration testing workflows using LLM providers (OpenAI, Claude, Gemini, Ollama, and others)… | 69 | 1853 | active |
| superagent-ai/vibekit VibeKit is a CLI tool that wraps AI coding agents such as Claude Code, Gemini CLI, Grok CLI, and Codex in isolated Docker sandboxes with au… | 49 | 1851 | active |
| zengzhan/qqzeng-ip A high-performance IP geolocation lookup engine (QZDB) with multi-language SDKs (Rust, C/C++, Go, Java, C#, Node.js, Python, PHP) that reso… | 77 | 1850 | active |
| Place1/wg-access-server wg-access-server is a single-binary WireGuard VPN server with a built-in web UI for managing and registering devices. It supports user auth… | 32 | 1850 | active |
| anhskohbo/no-captcha A Laravel package integrating Google's No CAPTCHA reCAPTCHA into forms. It provides Blade helpers for rendering the widget and a validation… | 70 | 1849 | active |
| selinuxG/Golin Golin is a Go-based security assessment tool combining asset discovery, port/service scanning, weak password brute-forcing for 40+ services… | 66 | 1847 | active |
| wapiti-scanner/wapiti Wapiti is an open-source black-box web vulnerability scanner written in Python that crawls deployed web applications and fuzzes scripts and… | 98 | 1846 | active |
| zhlynn/zsign zsign is a fast, cross-platform open-source alternative to Apple's codesign tool for re-signing iOS .ipa packages, Mach-O binaries, and .ap… | 98 | 1846 | active |
| ninoseki/mitaka Mitaka is a browser extension for Chrome and Firefox that simplifies OSINT (Open Source Intelligence) searches. It automatically detects an… | 94 | 1846 | active |
| sniptt-official/ots OTS is a Go CLI tool for sharing end-to-end encrypted secrets (API keys, passwords, signing secrets) via one-time URLs. Secrets are destroy… | 36 | 1845 | active |
| Tencent/CodeAnalysis Tencent Cloud Code Analysis (TCA, code-named CodeDog) is a self-hosted static code analysis platform consisting of server, web, and client … | 45 | 1843 | active |
| devploit/nomore403 NoMore403 is a Go command-line tool that automates testing of HTTP 401/403 access-control bypasses via request path, method, header, and wi… | 87 | 1842 | active |
| Eugeny/russh Russh is a low-level, Tokio-based SSH2 client and server library for Rust, forked from Thrussh. It supports a wide range of ciphers, key ex… | 99 | 1840 | active |
| rust-fuzz/afl.rs afl.rs is a Cargo subcommand that lets you fuzz test Rust code with AFLplusplus, the coverage-guided fuzzer. It instruments Rust builds so … | 76 | 1840 | active |
| iredmail/iRedMail iRedMail is an open source, full-featured mail server solution that installs and configures SMTP, IMAP/POP3, webmail (Roundcube/SOGo), and … | 76 | 1840 | active |
| Automattic/jetpack Jetpack is a suite of WordPress plugins and packages providing security, performance, marketing, and site-management tools for WordPress si… | 67 | 1840 | active |
| mailvelope/mailvelope Mailvelope is a browser extension for Chrome and Firefox that adds OpenPGP end-to-end email encryption to arbitrary webmail providers. It u… | 85 | 1838 | active |
| hacl-star/hacl-star HACL* is a formally verified cryptographic library written in F* (Low*) and compiled to efficient standalone C code, covering algorithms li… | 62 | 1837 | active |
| DosX-dev/obfus.h A macro-only C header library that obfuscates code at compile time, designed for the Tiny C Compiler on Windows x86/x64. It provides contro… | 68 | 1836 | active |
| pandasec888/taowu-cobalt_strike Taowu is a red team automation plugin (Aggressor script) for the Cobalt Strike platform, bundling a large collection of post-exploitation m… | 56 | 1835 | active |
| valqore/valqore Valqore is a deterministic infrastructure governance engine that scans Kubernetes manifests, Terraform, Helm, and cloud resources against 1… | 81 | 1831 | active |
| 78778443/QingScan QingScan is a self-hosted, open-source security operations platform that unifies vulnerability scanning, code auditing, asset inventory, an… | 66 | 1831 | active |
| bvcyber/CVE-2020-1472 A Python CLI script that tests domain controllers for the ZeroLogon vulnerability (CVE-2020-1472) using the Impacket library. It attempts t… | 45 | 1830 | stable |
| lavabit/magma Magma is an encrypted email server daemon written in C, providing SMTP, POP, IMAP, and HTTP protocol support along with a bundled webmail s… | 37 | 1830 | active |
| White-hua/Apt_t00ls A Java-based exploitation tool that aggregates proof-of-concept and weaponized exploits for high-severity vulnerabilities in Chinese enterp… | 26 | 1830 | active |
| pirxthepilot/wtfis wtfis is a Python command-line tool that performs passive lookups of hostnames, domains, and IP addresses using OSINT services like VirusTo… | 74 | 1827 | active |
| iojw/socialscan socialscan is a Python library and CLI tool that checks whether usernames and email addresses are taken, available, or invalid across onlin… | 66 | 1826 | active |
| initstring/linkedin2username A Python OSINT tool that scrapes LinkedIn employee lists for a target company and generates multiple probable username formats (e.g., first… | 76 | 1825 | active |
| alfiecg24/TrollInstallerX TrollInstallerX is a universal TrollStore installer for iOS 14.0 through 16.6.1, supporting both arm64 and arm64e devices. It uses the kfd … | 16 | 1824 | active |
| nilsteampassnet/TeamPass TeamPass is a free, self-hosted collaborative password manager written in PHP/MySQL, offering folder-level access control, AES-256-GCM auth… | 95 | 1823 | active |
| scipag/HardeningKitty HardeningKitty is a PowerShell module that audits and hardens Windows system configurations against a predefined finding list. It reads reg… | 84 | 1822 | active |
| HoShiMin/Kernel-Bridge Kernel-Bridge is a C++20 Windows kernel driver template, development framework, and kernel-mode API with wrappers, including a hypervisor s… | 23 | 1822 | active |
| 1N3/BlackWidow BlackWidow is a Python-based web application spider that crawls a target site to collect URLs, dynamic parameters, subdomains, email addres… | 57 | 1821 | active |