domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| 0xdea/frida-scripts A collection of Frida instrumentation scripts for reverse engineering mobile apps and native binaries, including tracers and enumerators fo… | 80 | 1653 | active |
| klezVirus/SysWhispers3 SysWhispers3 is a Python command-line tool that generates header and assembly (ASM) file pairs for direct system calls to the Windows kerne… | 32 | 1653 | active |
| chaitin/veinmind-tools veinmind-tools is a container security toolkit by Chaitin Tech built on the veinmind-sdk, providing scanners for malicious files, weak pass… | 23 | 1652 | active |
| Air14/HyperHide HyperHide is a hypervisor-based anti-anti-debug plugin for x64dbg/x32dbg that hides debuggers from detection. It uses Intel EPT to hook sys… | 23 | 1652 | active |
| zardus/preeny Preeny is a collection of LD_PRELOAD libraries written in C that help with binary exploitation and CTF-style challenges. It disables functi… | 54 | 1650 | active |
| whwlsfb/BurpCrypto BurpCrypto is a Burp Suite extension that encrypts Intruder payloads with algorithms like AES, RSA, and DES, or by executing arbitrary Java… | 23 | 1648 | active |
| scito/extract_otp_secrets A Python CLI tool that extracts one-time password (TOTP/HOTP) secrets from QR codes exported by two-factor authentication apps like Google … | 93 | 1647 | active |
| zama-ai/tfhe-rs TFHE-rs is a pure Rust implementation of the TFHE fully homomorphic encryption scheme, enabling boolean and integer arithmetic over encrypt… | 97 | 1646 | active |
| mssun/passforios Pass for iOS is an iOS password manager client compatible with ZX2C4's Pass command line application. It encrypts password entries with GPG… | 78 | 1645 | active |
| collinbarrett/FilterLists FilterLists is an independent, comprehensive web directory and REST API cataloging filter and host lists for blocking advertisements, track… | 77 | 1645 | active |
| lelylan/simple-oauth2 simple-oauth2 is a Node.js client library for the OAuth 2.0 authorization framework. It supports the authorization code, resource owner pas… | 32 | 1645 | active |
| cddmp/enum4linux-ng enum4linux-ng is a Python rewrite of the enum4linux.pl Windows/Samba enumeration tool, wrapping Samba utilities like nmblookup, net, rpccli… | 75 | 1644 | active |
| shekyan/slowhttptest SlowHTTPTest is a highly configurable command-line tool that simulates Application Layer Denial of Service attacks by prolonging HTTP conne… | 67 | 1644 | active |
| tevador/RandomX RandomX is a proof-of-work algorithm optimized for general-purpose CPUs that uses random code execution and memory-hard techniques to resis… | 92 | 1643 | stable |
| hyprwm/hyprlock hyprlock is a GPU-accelerated, multi-threaded screen locking utility built for the Hyprland Wayland compositor. It uses the ext-session-loc… | 89 | 1643 | active |
| geiger-rs/cargo-geiger cargo-geiger is a cargo plugin that scans a Rust crate and its dependency tree to report statistics on unsafe Rust code usage. It provides … | 67 | 1643 | active |
| P1sec/QCSuper QCSuper is a Python CLI tool that communicates with Qualcomm-based phones and modems via the Diag (QCDM) protocol to capture raw 2G/3G/4G (… | 91 | 1642 | active |
| rust-openssl/rust-openssl Rust bindings to the OpenSSL cryptography and TLS library, exposing its APIs (certificates, keys, hashing, SSL/TLS connections) to Rust pro… | 95 | 1641 | stable |
| cloudfoundry/uaa Cloud Foundry's User Account and Authentication (UAA) server, a multi-tenant identity management service that acts as an OAuth2 provider an… | 99 | 1638 | active |
| outtable/confuse-9live A macOS GUI application (distributed as a DMG, not source code) that obfuscates iOS app binaries and resources to bypass App Store review i… | 57 | 1636 | active |
| monkeyWie/proxyee Proxyee is a Java library built on Netty that implements an HTTP proxy server supporting HTTP, HTTPS, and WebSocket protocols. It provides … | 30 | 1634 | active |
| AltraMayor/gatekeeper Gatekeeper is the first open-source DDoS protection system, built on DPDK for high-performance packet processing. It uses a geographically … | 45 | 1633 | active |
| ADD-SP/ngx_waf ngx_waf is a high-performance Nginx firewall module written in C that provides web application firewall capabilities. It is compatible with… | 24 | 1631 | active |
| Pentest AI pentest-ai is an MIT-licensed local CLI and MCP server that turns Claude Code (or any LLM) into an offensive security assistant, pairing 50… | 80 | 1629 | active |
| C0nw0nk/Nginx-Lua-Anti-DDoS A Lua-based Anti-DDoS script for Nginx that presents a Cloudflare-style JavaScript authentication puzzle to filter out bots and mitigate La… | 98 | 1628 | active |
| Zizaco/entrust Entrust is a Laravel package that adds role-based permissions (RBAC) to Laravel applications, providing Role and Permission models, migrati… | 23 | 6003 | maintenance |
| zhaodice/qemu-anti-detection A collection of patches for various QEMU versions that modify emulator-reported data (device names, serial numbers, UEFI VM bit, BGRT) to p… | 58 | 1627 | active |
| illera88/Ponce Ponce is an IDA Pro plugin that adds one-click symbolic execution and taint analysis over binaries, built on the Triton engine and written … | 34 | 1627 | active |
| za515217965/OKBrowser OKBrowser is a free Chromium-based anti-fingerprint browser for Windows that lets users create and manage multiple isolated browser profile… | 50 | 1624 | active |
| JesseCHale/HaleHound-CYD HaleHound-CYD is a multi-protocol offensive security toolkit firmware for the ESP32 Cheap Yellow Display, offering 40+ attack modules acros… | 80 | 1623 | active |
| alexazhou/VeryNginx VeryNginx is an enhanced Nginx distribution built on lua-nginx-module (OpenResty) that adds a web application firewall, request routing, ra… | 23 | 5979 | maintenance |
| vladko312/SSTImap SSTImap is a Python-based penetration testing tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code i… | 88 | 1621 | active |
| wiredoor/wiredoor Wiredoor is a self-hosted ingress-as-a-service platform that exposes services running in private or local networks to the internet via reve… | 84 | 1620 | active |
| SELinuxProject/selinux The upstream userspace repository for Security Enhanced Linux (SELinux), providing the libraries and tools that complement SELinux support … | 88 | 1619 | stable |
| michenriksen/aquatone Aquatone is a Go CLI tool for visual inspection of websites across many hosts, taking screenshots via headless Chrome/Chromium and generati… | 10 | 5961 | maintenance |
| Finbuckle/Finbuckle.MultiTenant Finbuckle.MultiTenant is an open source multi-tenancy library for modern .NET, primarily targeting ASP.NET Core and Entity Framework Core a… | 98 | 1617 | stable |
| cathugger/mkp224o mkp224o is a C command-line tool that generates vanity ed25519 onion service (Tor hidden service v3) addresses by brute-forcing keypairs ma… | 23 | 1616 | active |
| DuendeSoftware/products Duende Products is a suite of identity and access management SDKs for ASP.NET Core, centered on Duende IdentityServer, a standards-complian… | 93 | 1614 | stable |
| ghostop14/sparrow-wifi Sparrow-WiFi is a Python 3 GUI-based WiFi and Bluetooth analyzer for Linux that combines 2.4/5 GHz scanning, BLE/Classic discovery, SDR spe… | 74 | 1614 | active |
| Permify/permify Permify is an open-source authorization-as-a-service inspired by Google Zanzibar, providing a permission database and policy decision point… | 95 | 5940 | maintenance |
| ProtonMail/ios-mail Proton Mail's official iOS client for end-to-end encrypted email, written in Swift/SwiftUI with core business logic in a Rust-based SDK. Th… | 66 | 1613 | active |
| coffinxp/loxs Loxs is a Python-based multi-vulnerability scanner for web applications that detects SQL injection, XSS, LFI, open redirect, and CRLF injec… | 52 | 1612 | active |
| SecurityRiskAdvisors/VECTR VECTR is a self-hosted web application for tracking red and blue team testing activities to measure detection and prevention capabilities a… | 98 | 1611 | active |
| ankane/lockbox Lockbox is a Ruby gem providing modern encryption for database fields, files, and strings in Ruby and Rails applications. It integrates wit… | 66 | 1609 | stable |
| hashcat/hashcat-utils A collection of small standalone C utilities that assist with advanced password cracking tasks, complementing the hashcat tool. Each utilit… | 48 | 1609 | active |
| fofapro/fapro FaPro is a free, cross-platform, single-file mass network protocol server simulator written in Python. It can start or stop many fake netwo… | 23 | 1609 | active |
| projectdiscovery/notify Notify is a Go-based CLI tool that streams the output of other tools (or reads from a file or pipe) and publishes it to messaging platforms… | 67 | 1607 | active |
| liamg/gitjacker Gitjacker is a Go CLI tool that downloads and reconstructs git repositories from websites where the .git directory has been mistakenly expo… | 48 | 1607 | active |
| jakehildreth/Locksmith Locksmith is a PowerShell module and script that audits Active Directory Certificate Services (AD CS) for common misconfigurations. It can … | 75 | 1606 | active |
| FireHOL FireHOL is a Linux firewall management tool built on iptables/ipsets, paired with a repository of IP blocklists dynamically updated via the… | 56 | 1603 | active |
| repplus/rep-chrome rep+ is a Chrome DevTools extension inspired by Burp Suite's Repeater that captures and replays HTTP requests with modified methods, header… | 54 | 1603 | active |
| Jon-Becker/heimdall-rs Heimdall is a Rust-based EVM smart contract toolkit for bytecode analysis, decompilation, disassembly, control flow graph generation, stora… | 89 | 1602 | active |
| Orange-Cyberdefense/ocd-mindmaps A collection of interactive mindmaps from Orange Cyberdefense covering offensive security and penetration testing methodologies, published … | 37 | 1602 | active |
| 4lbH4cker/ALHacking ALHacking is a shell-script-based toolkit bundling a menu of so-called ethical hacking utilities, including social media account attacks, p… | 32 | 1601 | active |
| MayersScott/rkn-block-checker A Python CLI tool that diagnoses whether your connection is in an RKN/TSPU-blocked zone and classifies the type of block (DNS poisoning, TC… | 72 | 1598 | active |
| tendermint/tendermint Tendermint Core is a Byzantine Fault Tolerant (BFT) consensus engine and blockchain application platform written in Go. It securely replica… | 67 | 5867 | maintenance |
| StamusNetworks/Clear-NDR-ISO Clear NDR Community (formerly SELKS) is a Debian-based Linux distribution for network detection and response built around Suricata, OpenSea… | 41 | 1591 | active |
| atinux/nuxt-auth-utils A Nuxt module that adds authentication to Nuxt applications using secured and sealed cookie sessions. It supports 40+ OAuth providers, pass… | 92 | 1589 | active |
| WireGuard/wireguard-android The official Android GUI application for WireGuard, a fast and modern VPN. It opportunistically uses the in-kernel WireGuard implementation… | 73 | 1589 | stable |
| LeeeSe/MessAuto MessAuto is a free macOS menu bar application, built in Rust, that automatically extracts SMS and email verification codes from the built-i… | 69 | 1589 | active |
| PentestPad/subzy Subzy is a Go-based command-line tool that checks subdomains for takeover vulnerabilities by matching HTTP response fingerprints from the c… | 32 | 1589 | active |
| Autumn-27/ScopeSentry ScopeSentry is a self-hosted attack surface and asset mapping platform that combines subdomain enumeration, port scanning, fingerprinting, … | 88 | 1587 | active |
| KindleModding/WinterBreak WinterBreak is a jailbreak tool for Amazon Kindle e-readers, built on top of the Mesquito framework. It allows users to unlock their Kindle… | 86 | 1587 | active |
| s0md3v/uro uro is a Python CLI tool that declutters URL lists for crawling and security testing without making any HTTP requests. It removes duplicate… | 29 | 1587 | stable |
| xnl-h4ck3r/xnLinkFinder xnLinkFinder is a Python CLI tool that discovers endpoints, potential parameters, target-specific wordlists, and secrets for a given target… | 78 | 1585 | active |
| linuxboot/heads Heads is an open-source firmware and OS configuration that runs a minimal Linux as a coreboot or LinuxBoot ROM payload, moving the root of … | 67 | 1585 | active |
| m3n0sd0n4ld/GooFuzz GooFuzz is a Bash-based CLI tool that performs fuzzing-style reconnaissance using advanced Google searches (Google Dorking) via the Google … | 57 | 1585 | active |
| horsicq/XELFViewer XELFViewer is a GUI application for viewing and editing ELF (Executable and Linkable Format) binary files on Windows, Linux and macOS. It i… | 67 | 1584 | active |
| AlisamTechnology/ATSCAN ATSCAN is a Perl-based command-line scanner for mass dork searching and vulnerability exploitation. It combines search engine dorking with … | 23 | 1583 | active |
| m8sec/CrossLinked CrossLinked is a Python CLI tool that enumerates LinkedIn employee names for an organization by scraping search engine results, without nee… | 23 | 1582 | active |
| attify/firmware-analysis-toolkit Firmware Analysis Toolkit (FAT) is a Python-based automation wrapper around Firmadyne that emulates IoT and embedded device firmware images… | 23 | 1582 | active |
| vimalloc/flask-jwt-extended Flask-JWT-Extended is an open source Flask extension that adds JSON Web Token (JWT) support for protecting routes, with many optional batte… | 93 | 1581 | stable |
| ReaJason/MemShellParty MemShellParty is a self-hosted, visual tool for rapidly generating Java memory shells (fileless webshells) for mainstream web middleware an… | 89 | 1581 | active |
| dyne/tomb Tomb is a minimalist command-line tool for GNU/Linux that creates and manages encrypted storage folders ('tombs') using dm-crypt and LUKS v… | 58 | 1581 | stable |
| gurnec/btcrecover btcrecover is an open-source Python command-line tool for recovering Bitcoin (and altcoin) wallet passwords and seed phrases when most of t… | 32 | 1580 | active |
| nzymeorg/nzyme Nzyme is an open-source intrusion detection system that monitors WiFi, Bluetooth, and Ethernet networks for threats such as rogue access po… | 79 | 1579 | active |
| capitalone/DataProfiler DataProfiler is a Python library that loads CSV, AVRO, Parquet, JSON, text, or URL data into a pandas-compatible DataFrame and profiles it … | 79 | 1578 | active |
| GZTimeWalker/GZCTF GZ::CTF is an open-source Capture The Flag (CTF) competition platform built on ASP.NET Core with a React frontend. It supports static and d… | 97 | 1577 | active |
| nccgroup/PMapper Principal Mapper (PMapper) is a Python CLI tool and library that models AWS IAM users and roles as a directed graph to identify privilege e… | 23 | 1576 | active |
| spatie/laravel-honeypot A Laravel package that prevents spam form submissions using honeypot fields and submission-time checks. It provides a Blade component and m… | 91 | 1575 | stable |
| B16f00t/whapa Whapa is a Python-based forensic toolset for parsing and analyzing WhatsApp databases from Android and iOS devices. It includes tools for d… | 75 | 1575 | active |
| pk-fr/yakpro-po YAK Pro - Php Obfuscator is a free, open-source CLI tool that obfuscates pure PHP source code using the PHP-Parser library. It removes comm… | 65 | 1574 | active |
| zama-ai/concrete Concrete is an open-source fully homomorphic encryption (FHE) compiler built on TFHE and LLVM that converts Python programs into their FHE … | 56 | 1574 | active |
| OWASP/threat-dragon OWASP Threat Dragon is a free, open-source, cross-platform threat modeling application for drawing data flow diagrams and listing threats f… | 89 | 1572 | active |
| hakluke/hakrevdns hakrevdns is a small, fast Go CLI tool that performs reverse DNS (PTR) lookups on large batches of IP addresses. It maps IPs to hostnames, … | 75 | 1572 | stable |
| patched-codes/patchwork Patchwork is an open-source agentic AI framework and CLI that automates development chores like PR reviews, bug fixing, security patching, … | 67 | 1572 | active |
| libssh2/libssh2 libssh2 is a client-side C library implementing the SSH2 protocol, licensed under the revised BSD license. It provides session establishmen… | 67 | 1572 | stable |
| austral/austral Austral is a new systems programming language featuring linear types for provably safe resource and memory management, and linear capabilit… | 38 | 1572 | active |
| ultrasecurity/Storm-Breaker Storm-Breaker is a social engineering tool that generates phishing-style web pages to capture device information, location, webcam, and mic… | 32 | 5754 | maintenance |
| keygen-sh/keygen-api Keygen is a fair source software licensing and distribution API that lets developers add license key validation, entitlements, device activ… | 86 | 1568 | active |
| cyberark/FuzzyAI FuzzyAI is an automated LLM fuzzing tool from CyberArk that tests LLM APIs for jailbreak vulnerabilities. It ships as a Python CLI with a w… | 51 | 1568 | active |
| stealthcopter/deepce DEEPCE is a single-file pure-shell script for enumerating Docker environments and attempting privilege escalation and container escapes. It… | 58 | 1567 | active |
| wikiZ/RedGuard RedGuard is a C2 front flow control tool written in Go that acts as a filtering reverse proxy in front of command-and-control servers. It h… | 23 | 1567 | active |
| OWASP/crAPI crAPI (completely ridiculous API) is an intentionally vulnerable web application built by OWASP to demonstrate the OWASP API Security Top 1… | 63 | 1566 | active |
| drduh/pwd.sh pwd.sh is a single Bash script that manages text secrets such as passwords using GnuPG symmetric encryption. Secrets are stored in randomly… | 88 | 1564 | active |
| meskarune/i3lock-fancy A bash script wrapper around i3lock that takes a screenshot of the desktop, blurs or pixelates it, and overlays a lock icon and text to cre… | 23 | 1564 | stable |
| Tsojan/TsojanScan TsojanScan is an integrated BurpSuite plugin for vulnerability detection that bundles multiple common vulnerability POCs into a single exte… | 85 | 1563 | active |
| AD-Security/AD_Miner AD Miner is an Active Directory (on-premise and Entra ID) auditing tool that runs Cypher queries against a BloodHound Neo4j graph database … | 70 | 1562 | active |
| moom825/xeno-rat Xeno-RAT is an open-source remote access tool (RAT) written in C# for remotely controlling Windows 10/11 machines. It includes features suc… | 18 | 1562 | active |
| vergecurrency/verge Verge Core is the official full-node source code for the Verge (XVG) cryptocurrency, providing a wallet client, mining support, and blockch… | 90 | 1561 | active |