domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| zarfadev/MobaXterm-Keygen A browser-based web tool that generates MobaXterm license key files (.mxtpro) and merges custom MobaXterm settings, running entirely client… | 60 | 1819 | active |
| nix-community/lanzaboote Lanzaboote is Rust tooling that brings UEFI Secure Boot and Measured Boot support to NixOS. Its lzbt tool signs boot components, builds Uni… | 84 | 1818 | active |
| ntop/nProbe nProbe is a high-performance NetFlow/IPFIX probe and network sensor from ntop that captures traffic and exports flow data for monitoring an… | 73 | 1816 | active |
| QBDI/QBDI QBDI (QuarkslaB Dynamic binary Instrumentation) is a modular, cross-platform, cross-architecture DBI framework built on LLVM, supporting x8… | 83 | 1815 | active |
| Chleba/netscanner netscanner is a terminal-based network scanner and diagnostic tool with a modern TUI, written in Rust. It supports WiFi network scanning, C… | 83 | 1815 | active |
| Gregwar/Captcha A PHP library for generating CAPTCHA images to protect web forms from bots and spam. It builds distorted text images, exposes the phrase fo… | 83 | 1814 | active |
| vulnersCom/getsploit A Python command-line tool that searches and downloads public exploits from the Vulners database, aggregating sources like Exploit-DB, Meta… | 90 | 1813 | active |
| trezor/trezor-firmware The official open-source firmware monorepo for Trezor hardware wallets, containing firmware for Trezor One and Trezor T/Safe devices, a sta… | 77 | 1813 | active |
| guardianproject/haven Haven is an open-source Android application that turns a spare phone into a physical security monitor using its on-device sensors (motion, … | 23 | 6814 | maintenance |
| cifertech/RF-Clown RF-Clown is an open-source BLE and Bluetooth jammer built on ESP32 and multiple nRF24L01 radio modules, with an OLED display, NeoPixel feed… | 66 | 1810 | active |
| unicodeveloper/globalthreatmap A real-time global threat and event intelligence map that plots security events, conflicts, military bases, and geopolitical developments o… | 56 | 1810 | active |
| tdragon6/Supershell Supershell is a web-accessible C2 remote control platform that establishes reverse SSH tunnels to targets, yielding fully interactive shell… | 54 | 1810 | active |
| AloneMonkey/MonkeyDev MonkeyDev is an Xcode-integrated framework (an upgraded fork of iOSOpenDev) for developing iOS tweaks and command-line tools using CaptainH… | 32 | 6799 | maintenance |
| wagiro/BurpBounty Burp Bounty (Scan Check Builder) is a Burp Suite extension that lets users improve Burp's active and passive web vulnerability scanners wit… | 23 | 1809 | active |
| google/gopacket GoPacket is a Go library that provides packet decoding and processing capabilities, originally forked from the gopcap project. It enables G… | 38 | 6795 | maintenance |
| lifting-bits/remill Remill is a C++ library that statically translates machine code instructions (x86, amd64, AArch64, SPARC32/64) into LLVM bitcode. It is des… | 80 | 1808 | active |
| mschwager/fierce Fierce is a Python 3 DNS reconnaissance tool that locates non-contiguous IP space and hostnames for specified domains. It enumerates subdom… | 32 | 1808 | active |
| antrea-io/antrea Antrea is a Kubernetes-native CNI plugin that provides pod networking and NetworkPolicy enforcement using Open vSwitch as the data plane. I… | 99 | 1807 | stable |
| bogdanfinn/tls-client A Go HTTP client library with a net/http-like interface that lets you select specific browser TLS fingerprints (Chrome, Firefox, Safari, et… | 90 | 1807 | active |
| core-lib/xjar XJar is a Java library and Maven-integrated tool that encrypts Spring Boot and plain JAR files (e.g., with AES) and provides a custom class… | 23 | 1807 | active |
| OpenSCAP/openscap OpenSCAP is a NIST-certified open-source toolkit providing both a C library and the 'oscap' command-line tool for parsing, validating, edit… | 87 | 1806 | stable |
| Lojii/Knot Knot is a full-featured iOS app for capturing and analyzing HTTP/HTTPS network traffic using MITM (man-in-the-middle) techniques, built ent… | 74 | 1806 | active |
| dreadl0ck/netcap Netcap is a Go framework that converts network packets into structured, type-safe Protocol Buffer audit records for security monitoring, fo… | 92 | 1805 | active |
| marin-m/vmlinux-to-elf A Python CLI (with optional GUI) that recovers a fully analyzable ELF file from raw or stripped Linux kernel images (vmlinux, vmlinuz, bzIm… | 88 | 1805 | stable |
| Tai-e Tai-e is an easy-to-learn, developer-friendly static analysis framework for Java and Android programs, offering pointer analysis, taint ana… | 84 | 1804 | active |
| hashtopolis/server Hashtopolis is a multi-platform client-server application for distributing hashcat password cracking tasks across multiple computers. It pr… | 90 | 1802 | active |
| redasm-dev/redasm REDasm is an open-source disassembler and binary analysis tool with a native Qt6 GUI, supporting many CPU architectures and executable form… | 94 | 1801 | active |
| doyensec/inql InQL is an open-source Burp Suite extension for advanced GraphQL security testing. It provides schema introspection, vulnerability detectio… | 76 | 1801 | active |
| wgpsec/fofa_viewer Fofa Viewer is a JavaFX desktop client for the FOFA internet asset search engine, wrapping its API in a tabbed GUI. It helps security profe… | 57 | 1800 | active |
| h44z/wg-portal WireGuard Portal is a self-hosted, web-based configuration portal for managing WireGuard VPN servers and peers. It is a single Go binary wi… | 95 | 1799 | active |
| wallarm/gotestwaf GoTestWAF is a Go-based tool that simulates OWASP and API attacks (SQL injection, XSS, etc.) across REST, GraphQL, gRPC, SOAP, and XMLRPC p… | 41 | 1799 | active |
| netyouli/WHC_ConfuseSoftware A macOS (and Windows for some helpers) GUI application that obfuscates and 'renovates' mobile and game project source code across Objective… | 76 | 1797 | active |
| PortSwigger/turbo-intruder Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests at exceptional speed and analyzing the results. It uses… | 66 | 1796 | active |
| OpenVPN/openvpn-gui OpenVPN GUI is a graphical frontend for OpenVPN on Windows 10 and 11, providing a notification-area icon to start and stop VPN tunnels, vie… | 77 | 1793 | active |
| 0vercl0k/wtf wtf (what the fuzz) is a distributed, code-coverage guided, snapshot-based fuzzer for attacking user- and kernel-mode targets on Windows an… | 74 | 1793 | active |
| betterleaks/betterleaks Betterleaks is a fast, configurable secrets scanner for finding leaked credentials in git repositories, filesystems, and platforms like Git… | 82 | 1792 | active |
| nccgroup/sobelow Sobelow is a security-focused static analysis tool for Elixir and the Phoenix framework, detecting common vulnerability classes like SQL in… | 23 | 1791 | active |
| lirantal/npq npq is a command-line tool that audits npm packages for security risks before installing them, checking CVE databases and applying syntacti… | 95 | 1789 | active |
| libtom/libtomcrypt LibTomCrypt is a comprehensive, modular and portable cryptographic toolkit written in C, providing block ciphers, hash functions, chaining … | 66 | 1788 | stable |
| Heavrnl/nexus-terminal Nexus Terminal is a modern web-based SSH/RDP/VNC client with a self-hosted Node.js backend and an optional standalone desktop app. It offer… | 34 | 1788 | active |
| R4gd0ll/I-Wanna-Get-All A comprehensive Java post-exploitation vulnerability exploitation tool integrating 470 exploit modules for detection and attack of known vu… | 59 | 1787 | active |
| fulldecent/system-bus-radio A C program that transmits AM radio signals from computers and phones that lack radio transmitting hardware by generating precisely timed e… | 55 | 6697 | maintenance |
| PabloLec/RecoverPy RecoverPy is a Python TUI tool that scans raw partitions and disk images for byte patterns to locate and recover deleted or overwritten fil… | 83 | 1785 | active |
| ReversecLabs/C3 C3 (Custom Command and Control) is a C++ framework for rapidly prototyping custom command and control (C2) channels for red team operations… | 67 | 1785 | active |
| microsoft/CyberBattleSim CyberBattleSim is a Python-based experimentation and research platform from Microsoft that simulates abstract enterprise network environmen… | 77 | 1784 | active |
| kost/dvcs-ripper dvcs-ripper is a set of Perl command-line tools that download (rip) web-accessible version control repositories such as GIT, SVN, Mercurial… | 32 | 1784 | stable |
| D4Vinci/One-Lin3r One-Lin3r is a lightweight, modular Python framework that provides a searchable database of over 176 one-liner commands for penetration tes… | 57 | 1783 | active |
| metlo-labs/metlo Metlo is an open-source API security platform that inventories API endpoints, detects malicious traffic in real time, and can automatically… | 38 | 1783 | active |
| OpenAEV-Platform/openaev OpenAEV is an open-source platform for planning, scheduling, and running cyber adversary simulation campaigns and security exercises, from … | 95 | 1782 | active |
| GoSecure/pyrdp PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library. It intercepts RDP connections to capture cre… | 60 | 1780 | active |
| cs01/termpair TermPair is a Rust-based tool that lets you share and control a terminal from a browser with end-to-end encryption. A single static binary … | 80 | 1778 | active |
| Dyneteq/reconya reconYa is a self-hosted network reconnaissance and asset discovery tool written in Go that scans local networks via ICMP, TCP, and ARP to … | 87 | 1777 | active |
| pass-with-high-score/blockads-android BlockAds is a free, open-source Android app that blocks ads, trackers, and malware system-wide using local VPN-based DNS filtering, with no… | 79 | 1777 | active |
| m4b/bingrep bingrep is a cross-platform command-line binary parser and colorizer written in Rust, supporting ELF, Mach-O, PE, and Unix/BSD archives. It… | 59 | 1777 | active |
| ShenaniganDApp/brightid-discord-bot A Discord bot that integrates BrightID identity verification into Discord servers, letting communities verify users are unique humans and m… | 23 | 1777 | active |
| hjdhjd/homebridge-unifi-protect A Homebridge plugin that provides complete native HomeKit integration for the UniFi Protect ecosystem, including cameras, doorbells, sensor… | 94 | 1776 | active |
| ron190/jsql-injection jSQL Injection is a free, open-source Java application for automatic SQL database injection, used to find and extract database information … | 84 | 1776 | active |
| quentinhardy/odat ODAT (Oracle Database Attacking Tool) is an open-source Python penetration testing tool for assessing the security of remote Oracle Databas… | 57 | 1776 | active |
| requests/requests-oauthlib A Python library that adds OAuth 1 and OAuth 2 authentication support to the Requests HTTP library. It wraps OAuthlib to provide simple ses… | 35 | 1775 | stable |
| simsong/tcpflow tcpflow is a C++ command-line tool that captures TCP connection data and demultiplexes it into per-flow files, one per direction, for proto… | 52 | 1774 | active |
| mozilla/fx-private-relay Firefox Relay is a Mozilla service that generates email aliases (masks) which forward messages to your real inbox, hiding your personal add… | 94 | 1773 | active |
| andrivet/ADVobfuscator ADVobfuscator is a C++20 header-only library that obfuscates and encrypts strings and data blocks at compile time using metaprogramming, wi… | 73 | 1772 | active |
| un1cum/Beast_Bomber A Python CLI script that floods targets with SMS, email, Discord, and Telegram messages, and performs basic DDoS attacks. It runs on deskto… | 26 | 1772 | active |
| bellingcat/telegram-phone-number-checker A Python CLI tool by Bellingcat that checks whether phone numbers are registered with Telegram accounts, retrieving usernames, names, and I… | 87 | 1771 | active |
| pwn20wndstuff/Undecimus Undecimus is the open-source iOS app behind the unc0ver jailbreak, supporting iOS 11.0 through 12.4 on ARM64 devices. It applies kernel and… | 23 | 6621 | maintenance |
| etesync/server The Etebase (EteSync 2.0) server, a Django-based backend that lets you self-host end-to-end encrypted synchronization of contacts, calendar… | 32 | 1766 | stable |
| tchx84/Flatseal Flatseal is a graphical utility for reviewing and modifying permissions of Flatpak applications on Linux. It lets users select an installed… | 77 | 1765 | active |
| HackUnderway/SearchPhone SearchPhone is a Python CLI OSINT toolkit for investigating phone numbers across multiple sources, including Google (SerpAPI), DuckDuckGo, … | 66 | 1765 | active |
| fwdcloudsec/granted Granted is a Go-based CLI application that simplifies finding and assuming AWS IAM roles across multiple accounts. It encrypts cached SSO c… | 90 | 1764 | active |
| apache/casbin-pycasbin PyCasbin is the Python implementation of Apache Casbin, an authorization library that enforces access control via configurable models such … | 87 | 1764 | stable |
| j3ers3/Hello-Java-Sec A deliberately vulnerable Java Spring Boot application demonstrating common web vulnerabilities (SQLi, XSS, RCE, deserialization, SSTI, SSR… | 27 | 1763 | active |
| xaitax/Chrome-App-Bound-Encryption-Decryption A Windows post-exploitation research tool that bypasses Chromium's App-Bound Encryption using direct syscall-based reflective process hollo… | 63 | 1762 | active |
| symfony/security-csrf The Symfony Security CSRF component provides a CsrfTokenManager class for generating and validating cross-site request forgery (CSRF) token… | 93 | 1761 | stable |
| qi4L/JYso JYso is a Java-based offensive security tool that combines the capabilities of ysoserial (Java deserialization gadget generation) and JNDIE… | 83 | 1761 | active |
| privacyidea/privacyidea privacyIDEA is an open-source, self-hosted multi-factor authentication (MFA) server that centrally manages authentication tokens—OTP (HOTP/… | 93 | 1759 | stable |
| LoseNine/ruyipage RuyiPage is a Python browser automation framework built on Firefox and the WebDriver BiDi protocol, shipping with an anti-detection Firefox… | 79 | 1759 | active |
| githubXiaowangzi/NP-Manager NP-Manager is an Android application for APK, DEX, JAR, Smali, PDF, and media file manipulation. It provides reverse-engineering features s… | 76 | 1758 | active |
| google/sandboxed-api Google's Sandboxed API (SAPI) automatically generates sandboxes for individual C/C++ libraries, isolating them from the host program using … | 67 | 1758 | active |
| bradtraversy/node_passport_login A Node.js starter application demonstrating user registration, login, and access control using Express, Passport, MongoDB/Mongoose, EJS, an… | 75 | 1757 | active |
| josh0xA/darkdump Darkdump is an open-source OSINT tool for querying multiple dark web search engines and scraping onion site results for emails, metadata, k… | 70 | 1757 | active |
| mpdavis/python-jose python-jose is a Python implementation of the JOSE (JavaScript Object Signing and Encryption) standards, including JWS, JWE, JWK, and JWT. … | 60 | 1756 | stable |
| laravel/fortify Laravel Fortify is a frontend-agnostic authentication backend for Laravel that registers the routes and controllers needed for login, regis… | 99 | 1755 | active |
| xmendez/wfuzz Wfuzz is a Python-based command-line web application fuzzer that replaces a FUZZ keyword in HTTP requests with values from configurable pay… | 60 | 6558 | maintenance |
| orhun/gpg-tui gpg-tui is a terminal user interface for GnuPG written in Rust, built on tui-rs and GPGME bindings. It simplifies key management operations… | 81 | 1753 | active |
| philhagen/sof-elk SOF-ELK is a pre-built virtual appliance based on the Elastic stack (Elasticsearch, Logstash, Kibana, Filebeat) tailored for computer foren… | 76 | 1753 | active |
| ronf/asyncssh AsyncSSH is a Python library providing asynchronous client and server implementations of the SSHv2 protocol, including SFTP and SCP, built … | 76 | 1753 | stable |
| ossf/cve-bin-tool A Python CLI tool that scans binaries and systems for known CVEs in over 350 common open-source components like openssl, libpng, and expat.… | 67 | 1753 | active |
| murphysecurity/murphysec MurphySec CLI is an open-source software composition analysis (SCA) tool that detects vulnerable dependencies in projects from the command … | 57 | 1753 | active |
| facebookarchive/fbctf FBCTF is a self-hosted platform for running Jeopardy and King of the Hill style Capture the Flag security competitions. It supports team re… | 10 | 6548 | maintenance |
| bytedance/appshark AppShark is a static taint analysis platform written in Kotlin that scans Android APKs for security vulnerabilities and compliance issues. … | 54 | 1752 | active |
| GreenmaskIO/greenmask Greenmask is an open-source CLI utility for logical database dumping, anonymization, synthetic data generation, and restoration, production… | 93 | 1750 | active |
| justinas/nosurf nosurf is a Go HTTP package that provides CSRF protection via a CSRFHandler middleware wrapping any http.Handler. It validates tokens on un… | 32 | 1747 | stable |
| tuigreet/tuigreet tuigreet is a terminal-based graphical console greeter for greetd, providing a login interface with session management, user selection, and… | 99 | 1745 | active |
| django-hijack/django-hijack Django Hijack is a Django app that lets admins log in and work on behalf of other users without knowing their credentials. It provides secu… | 88 | 1742 | stable |
| IvanGlinkin/Fast-Google-Dorks-Scan A shell-based OSINT tool that automates Google dork searches against a target website to uncover admin panels, exposed file types, and path… | 46 | 1742 | active |
| jm33-m0/emp3r0r emp3r0r is an open-source post-exploitation framework and command-and-control (C2) system written in Go, targeting Linux and Windows hosts.… | 95 | 1741 | active |
| elder-plinius/ST3GG ST3GG is an all-in-one steganography toolkit that hides secret data inside images, audio, documents, and network packets using 100+ encodin… | 63 | 1741 | active |
| jaksi/sshesame sshesame is an SSH honeypot written in Go that runs a fake SSH server accepting any connection and logging all activity without executing a… | 23 | 1741 | active |
| wiire-a/pixiewps Pixiewps is a C command-line utility that brute-forces Wi-Fi Protected Setup (WPS) PINs offline, exploiting low- or non-entropy software im… | 57 | 1740 | active |
| sigalor/whatsapp-web-reveng A reverse-engineered description and Node.js re-implementation of the WhatsApp Web API, communicating over WebSockets with the same encrypt… | 32 | 6491 | maintenance |