domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| hotyue/IP-Sentinel IP-Sentinel is a lightweight, modular Master-Agent distributed system for maintaining VPS IP assets. It detects IP geolocation misclassific… | 81 | 1738 | active |
| samyk/poisontap PoisonTap is a USB-based attack tool built on a Raspberry Pi Zero and Node.js that exploits locked, password-protected computers by emulati… | 32 | 6475 | maintenance |
| MatheuZSecurity/Singularity Singularity is a stealthy Linux kernel module (LKM) rootkit targeting modern 6.x kernels, using ftrace-based syscall hooking to hide proces… | 56 | 1736 | active |
| j3ssie/metabigor Metabigor is a Go-based command-line OSINT tool that maps a target's infrastructure—IP ranges, subdomains, related domains, open ports, and… | 86 | 1735 | active |
| awslabs/aws-config-rules A community repository of sample custom AWS Config rules written in Python, Node.js, and Java. These Lambda-based rules evaluate AWS resour… | 70 | 1735 | active |
| polymorf/findcrypt-yara An IDA Pro plugin that uses YARA rules to scan binaries for known cryptographic constants and other recognizable byte patterns. It helps re… | 32 | 1735 | active |
| i12bp8/TagTinker TagTinker is a Flipper Zero application for researching infrared electronic shelf label (ESL) protocols, letting users transmit custom imag… | 50 | 1734 | active |
| Fr4nkFletcher/ESP32-Marauder-Cheap-Yellow-Display A port of the ESP32-Marauder WiFi/Bluetooth testing firmware to the Cheap Yellow Display (CYD) family of ESP32 boards with ILI9341/ST7789/S… | 47 | 1734 | active |
| succinctlabs/sp1 SP1 is a zero-knowledge virtual machine (zkVM) that proves the correct execution of arbitrary programs compiled to RISC-V, written in Rust … | 93 | 1732 | active |
| veops/oneterm OneTerm is a lightweight, flexible enterprise bastion host (jump server) built on the 4A model: authentication, authorization, account, and… | 59 | 1732 | active |
| cleverhans-lab/cleverhans CleverHans is a Python library for benchmarking machine learning systems' vulnerability to adversarial examples, providing reference implem… | 23 | 6450 | maintenance |
| hwdsl2/openvpn-install A Bash script that automates setting up an OpenVPN server on a wide range of Linux distributions, including Ubuntu, Debian, CentOS, Fedora,… | 77 | 1728 | active |
| revng/revng rev.ng is an open-source binary analysis framework and decompiler built on LLVM and QEMU, supporting over 20 CPU architectures. It automati… | 77 | 1728 | active |
| mandatoryprogrammer/CursedChrome CursedChrome is a Chrome extension implant that converts a victim's Chrome browser into a fully-functional HTTP proxy, letting an operator … | 32 | 1728 | active |
| CodingGay/BlackDex BlackDex is an Android app that unpacks DEX files from installed or uninstalled APKs on Android 5.0-12 without requiring root, Xposed, Frid… | 23 | 6439 | maintenance |
| ghostery/ghostery-extension Ghostery is a browser extension that blocks ads, trackers, and cookie pop-ups across Firefox, Chrome, Opera, Edge, Safari, and Yandex. It p… | 95 | 1726 | active |
| vfsfitvnm/frida-il2cpp-bridge A Frida module written in TypeScript for dumping, tracing, and hijacking IL2CPP (Unity) applications at runtime without needing the global-… | 93 | 1726 | active |
| Tokeii0/LovelyMem Lovelymem V2 is a Windows desktop memory forensics workbench built with Rust, Tauri 2, and TypeScript. It integrates MemProcFS, Volatility … | 87 | 1725 | active |
| AikidoSec/safe-chain Aikido Safe Chain is a free, tokenless CLI tool that wraps package managers (npm, yarn, pnpm, npx, pip, uv, poetry, and more) to block mali… | 84 | 1725 | active |
| davrodpin/mole Mole is a Go-based CLI application for creating SSH tunnels with a focus on resiliency and user experience. It supports automatic port sele… | 23 | 1725 | stable |
| theupdateframework/python-tuf Python reference implementation of The Update Framework (TUF), a CNCF-graduated specification for securing software update systems against … | 83 | 1724 | stable |
| GrimAnticheat/Grim GrimAC is an open-source Minecraft anticheat plugin that detects cheats by simulating real client movement with fully asynchronous, multith… | 82 | 1724 | active |
| cmu-sei/pharos Pharos is a static binary analysis framework from Carnegie Mellon's Software Engineering Institute built on the ROSE compiler infrastructur… | 75 | 1723 | active |
| kdrag0n/safetynet-fix A Magisk module (Zygisk-based, with an older Riru version) that works around Google's SafetyNet and Play Integrity hardware attestation che… | 23 | 6412 | maintenance |
| upspin/upspin Upspin is an experimental framework of protocols and reference implementations providing a secure, global naming system for sharing files a… | 46 | 6399 | maintenance |
| apple/swift-crypto Swift Crypto is an open-source Swift library implementing a substantial portion of Apple CryptoKit's API for use on Linux, Windows, and oth… | 97 | 1718 | active |
| ueberauth/ueberauth Ueberauth is an Elixir authentication framework for Plug-based web applications, providing a two-phase authentication API inspired by Omnia… | 65 | 1716 | stable |
| ev-flow/quark-engine Quark Engine is an Android malware scoring and analysis system that inspects APKs using rule-based behavioral detection on Dalvik bytecode.… | 98 | 1713 | active |
| lasting-yang/frida_hook_libart A collection of Frida hook scripts for intercepting Android ART JNI functions, most notably RegisterNatives. It reveals native method regis… | 54 | 1713 | active |
| jimmy201602/webterminal A Django-based web bastion (jump server) that lets users connect to servers via SSH, SFTP, RDP, VNC, and Telnet directly from the browser. … | 44 | 1713 | active |
| Rob--W/crxviewer A browser add-on and web app for viewing the source code of Chrome, Firefox, Opera, Edge, and Thunderbird extensions without installing the… | 72 | 1712 | active |
| cloudflare/circl CIRCL is Cloudflare's Go library of cryptographic primitives covering post-quantum algorithms (ML-KEM/Kyber, ML-DSA/Dilithium, SIKE/CSIDH),… | 94 | 1710 | active |
| cr0hn/dockerscan DockerScan is a comprehensive Docker security scanner written in Go that scans containers, images, and registries using multiple techniques… | 93 | 1710 | active |
| apache/guacamole-client Apache Guacamole client is the Maven-based superproject containing the HTML5 web application, official authentication extensions, and JavaS… | 77 | 1710 | active |
| Septrum101/zteOnu A Go CLI tool that opens factory/telnet mode on ZTE ONU (fiber optic modem) devices via their webFac interface. It authenticates with facto… | 94 | 1708 | active |
| elasticdog/transcrypt A single Bash script that configures transparent encryption of sensitive files in a Git repository using Git's clean/smudge filters and Ope… | 80 | 1708 | stable |
| S3cur3Th1sSh1t/PowerSharpPack PowerSharpPack wraps many useful offensive C# security projects (Seatbelt, Rubeus, SharpUp, winPEAS, etc.) into PowerShell scripts for easy… | 39 | 1708 | active |
| mganss/HtmlSanitizer A .NET library for cleaning HTML fragments and documents of constructs that can lead to XSS attacks, built on the AngleSharp parser. It is … | 98 | 1707 | active |
| SVF-tools/SVF SVF is a C++ static analysis framework built on LLVM that provides scalable and precise value-flow analysis and pointer analysis for source… | 86 | 1705 | active |
| dolevf/Damn-Vulnerable-GraphQL-Application Damn Vulnerable GraphQL Application (DVGA) is an intentionally insecure GraphQL service built for learning and practicing GraphQL security … | 33 | 1705 | active |
| Watfaq/clash-rs ClashRS is a rule-based network proxy written in Rust supporting many custom protocols (Shadowsocks, VMess, VLESS, Trojan, Hysteria2, WireG… | 97 | 1704 | active |
| better-auth-ui/better-auth-ui Better Auth UI is a collection of beautiful, ready-to-use authentication UI components and data utilities built specifically for the Better… | 84 | 1704 | active |
| Safe3/uusec-waf UUSEC WAF is a free, high-performance web application firewall and API security gateway (WAAP) that combines AI/semantic detection engines … | 98 | 1703 | active |
| symfony/security-http The Symfony Security HTTP component provides HTTP integration of the Symfony Security Core component. It secures (parts of) applications us… | 95 | 1701 | stable |
| project-copacetic/copacetic Copa (Project Copacetic) is a Go CLI tool built on BuildKit that directly patches OS package vulnerabilities in container images without re… | 91 | 1700 | active |
| jazzband/django-axes django-axes is a Django plugin that tracks failed login attempts and blocks brute-force attacks on Django-powered sites. It supports monito… | 84 | 1700 | stable |
| webprofusion/certify Certify The Web is an ACME v2 certificate management application with a Windows desktop UI and background renewal service, plus a cross-pla… | 77 | 1700 | stable |
| sudo-project/sudo Sudo is a Unix utility that allows a system administrator to delegate limited root or other-user privileges to users on a per-command basis… | 78 | 1699 | stable |
| utkusen/urlhunter urlhunter is a Go-based recon CLI tool that searches URLs exposed via shortener services like bit.ly and goo.gl. It downloads daily URLTeam… | 24 | 1697 | active |
| bromite/bromite Bromite is a Chromium fork for Android with a built-in ad-blocking engine and privacy enhancements such as anti-fingerprinting flags, DNS-o… | 23 | 6299 | maintenance |
| liftoff/GateOne Gate One is an HTML5 web-based terminal emulator and SSH client that runs in the browser without plugins. It supports many simultaneous use… | 32 | 6298 | maintenance |
| SiriusScan/Sirius Sirius is an open-source vulnerability scanner that automates network discovery via Nmap and performs CVE-based detection with CVSS scoring… | 88 | 1695 | active |
| pgaudit/pgaudit pgAudit is a PostgreSQL extension written in C that provides detailed session and object audit logging through the standard PostgreSQL logg… | 80 | 1695 | stable |
| matanolabs/matano Matano is an open-source, cloud-native security data lake that runs in your AWS account, normalizing unstructured security logs into a stru… | 23 | 1694 | active |
| duo-labs/cloudmapper CloudMapper is a tool for analyzing Amazon Web Services (AWS) environments, originally built to generate interactive network diagrams in th… | 23 | 6288 | maintenance |
| cedar-policy/cedar Cedar is a purpose-built policy language and Rust implementation for writing and enforcing fine-grained authorization policies in applicati… | 95 | 1693 | stable |
| AdguardTeam/AdguardForiOS AdGuard for iOS is an open-source ad-blocking and privacy app for iPhone and iPad that blocks ads in Safari via content blocking rules. It … | 95 | 1692 | active |
| hasherezade/tiny_tracer A Pin Tool built on Intel Pin for dynamic binary instrumentation that traces API calls, syscalls, selected instructions, and section transi… | 80 | 1692 | active |
| dafthack/MFASweep MFASweep is a PowerShell script that attempts to log in to multiple Microsoft services with provided credentials to detect whether MFA is e… | 67 | 1692 | active |
| almeidapaulopt/tsdproxy TSDProxy is a self-hosted service that automatically exposes Docker containers on a Tailscale network via a single reverse proxy. Container… | 85 | 1690 | active |
| openappsec/openappsec open-appsec is an open-source machine learning security engine that provides preemptive web application and API threat protection against O… | 99 | 1689 | active |
| murraco/spring-boot-jwt A JWT authentication service built with Spring Boot and Spring Security, backed by MySQL, featuring short-lived access tokens and rotating,… | 76 | 1688 | active |
| wireghoul/graudit graudit is a shell-based source code auditing tool that uses GNU grep with signature databases of extended regular expressions to find pote… | 59 | 1688 | active |
| raodv/captcha AjPlus Captcha is an open-source behavioral CAPTCHA library providing sliding puzzle and click-word verification challenges with frontend U… | 39 | 1685 | active |
| BC-SECURITY/Starkiller Starkiller is a web-based graphical frontend for PowerShell Empire, a post-exploitation C2 framework. It is written in VueJS and ships prep… | 93 | 1684 | active |
| trailofbits/buttercup Buttercup is a Cyber Reasoning System (CRS) developed by Trail of Bits for the DARPA AI Cyber Challenge that automatically finds and patche… | 56 | 1683 | active |
| Gerenios/AADInternals AADInternals is a PowerShell module for administering and hacking Entra ID (Azure AD), Office 365, and related endpoints. It includes tools… | 52 | 1683 | active |
| whwlsfb/JDumpSpider JDumpSpider is a Java CLI tool that extracts sensitive information (datasource credentials, config properties, Redis configs, Shiro keys, u… | 70 | 1680 | active |
| fastapi-users/fastapi-users FastAPI Users is a ready-to-use and customizable user management library for FastAPI applications. It provides registration, login, passwor… | 87 | 6227 | maintenance |
| inverse-inc/packetfence PacketFence is a free and open source network access control (NAC) solution with a captive portal for registration and remediation, 802.1X … | 88 | 1678 | stable |
| palark/ovpn-admin A self-hosted web UI for managing OpenVPN users, certificates, and client routes on Linux servers. It is written in Go with a Vue.js fronte… | 78 | 1677 | active |
| MorDavid/BruteForceAI BruteForceAI is a Python-based penetration testing tool that uses LLMs (via Ollama or Groq) to automatically analyze login page HTML and id… | 60 | 1677 | active |
| sickcodes/osx-serial-generator A shell-based tool that generates valid macOS serial numbers, UUIDs, and board serials for use with OpenCore, OSX-KVM, and Docker-OSX. It i… | 39 | 1677 | stable |
| Ge0rg3/requests-ip-rotator A Python library that mounts AWS API Gateway as a proxy onto requests sessions, rotating source IPs on every request using AWS's large IP p… | 90 | 1675 | active |
| fire-keeper/BlindWatermark A Python library and CLI/GUI tool that embeds invisible blind watermarks into images using discrete wavelet transforms, protecting creators… | 23 | 1675 | active |
| keepassium/KeePassium KeePassium is a KeePass-compatible password manager app for iOS and macOS, written in Swift. It supports all KeePass database formats (kdb,… | 67 | 1674 | active |
| mikespook/gorbac goRBAC is a lightweight role-based access control (RBAC) library for Go, supporting many-to-many role/permission mappings and hierarchical … | 65 | 1674 | active |
| michenriksen/gitrob Gitrob is a Go-based reconnaissance tool that scans GitHub users' and organizations' public repositories for potentially sensitive files by… | 10 | 6198 | maintenance |
| KeenSecurityLab/BinAbsInspector BinAbsInspector is a static analyzer for automated reverse engineering and vulnerability scanning in binaries, built on abstract interpreta… | 23 | 1672 | active |
| rebeyond/Behinder Behinder ('冰蝎') is a cross-platform Java client for managing encrypted webshells on compromised web servers running PHP, Java, or .NET. It … | 23 | 6191 | maintenance |
| chainguard-dev/apko apko is a Go CLI tool that builds and publishes OCI container images directly from Alpine apk packages using declarative YAML configuration… | 95 | 1668 | active |
| invertase/react-native-apple-authentication A well-typed React Native library providing Sign In with Apple support on iOS and Android, including all AppleButton UI variants. It suppor… | 62 | 1668 | active |
| pow-auth/pow Pow is a robust, modular, and extendable authentication and user management library for Elixir, built for Phoenix and Plug-based applicatio… | 24 | 1668 | stable |
| freeotp/freeotp-android FreeOTP is an open-source two-factor authentication app for Android that generates one-time passwords using the HOTP and TOTP standards. To… | 78 | 1666 | active |
| Asuswrt-Merlin Asuswrt-Merlin is an enhanced third-party firmware for Asus routers, based on Asus's stock Asuswrt firmware, focusing on bug fixes, tweaks,… | 77 | 6166 | maintenance |
| FairwindsOps/rbac-manager RBAC Manager is a Kubernetes operator that simplifies authorization management by allowing declarative configuration of Role Bindings and S… | 94 | 1665 | active |
| userfrosting/UserFrosting UserFrosting is a modern PHP user management framework built on Slim, Twig, Eloquent ORM, Vite, and Vue, providing login, registration, and… | 93 | 1665 | active |
| projectdiscovery/shuffledns shuffleDNS is a Go wrapper around massDNS for fast active subdomain enumeration via bruteforce and DNS resolution with smart wildcard filte… | 86 | 1664 | active |
| slackhq/go-audit go-audit is a Go-based replacement for the auditd daemon that consumes Linux kernel audit events via netlink and outputs them as JSON. It s… | 84 | 1664 | active |
| WangYihang/GitHacker GitHacker is a multi-threaded Python CLI tool that exploits exposed `.git` directories on web servers to reconstruct the entire Git reposit… | 77 | 1664 | active |
| google/atheris Atheris is a coverage-guided fuzzing engine for Python code and native CPython extensions, built on top of libFuzzer. It instruments Python… | 72 | 1664 | active |
| bee-san/Name-That-Hash Name That Hash is a Python CLI tool and web app that identifies the type of an unknown hash string, supporting 300+ hash types like MD5 and… | 48 | 1664 | active |
| summitt/Nope-Proxy NoPE Proxy is a Burp Suite extension that adds TCP and UDP traffic interception, a configurable DNS server, and a non-HTTP man-in-the-middl… | 23 | 1663 | active |
| secluso/core Secluso is an open-source, privacy-preserving home security camera system built for Raspberry Pi, featuring end-to-end encrypted remote acc… | 72 | 1661 | active |
| longld/peda PEDA is a Python plugin for GDB that enhances the debugger's display and adds exploit development commands. It provides colorized disassemb… | 23 | 6147 | maintenance |
| nshalabi/SysmonTools Sysmon Tools is a collection of utilities for analyzing, visualizing, and managing Microsoft Sysmon logs, centered on Sysmon View, an open-… | 81 | 1659 | active |
| tabby-sec/tabby Tabby is a Java static code analysis tool built on the Soot framework that converts JAR/WAR/CLASS files into a code property graph stored i… | 51 | 1659 | active |
| dirkjanm/krbrelayx A Python toolkit for abusing Kerberos in Active Directory environments, including Kerberos relaying and unconstrained delegation attacks. I… | 64 | 1657 | active |
| WangYihang/Platypus Platypus is a cross-platform reverse-shell and host management hub written in Go. Agents on managed machines dial back to a central server … | 67 | 1656 | active |
| devnied/EMV-NFC-Paycard-Enrollment A Java library for reading and extracting public data from NFC EMV credit cards over Android NFC or PCSC readers. It parses card details su… | 63 | 1654 | active |