domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| dwisiswant0/crlfuzz CRLFuzz is a fast command-line tool written in Go that scans websites for CRLF (carriage return/line feed) injection vulnerabilities. It su… | 66 | 1560 | active |
| palkan/action_policy Action Policy is an authorization framework for Ruby and Rails applications, built around resource-specific policy classes with composable … | 65 | 1560 | stable |
| lqqyt2423/go-mitmproxy A Golang implementation of mitmproxy that intercepts, parses, monitors, and tampers with HTTP/HTTPS traffic via a man-in-the-middle proxy. … | 88 | 1559 | active |
| OWASP/QRLJacking QRLJacking is an OWASP project documenting and exploiting the Quick Response Code Login Jacking attack vector, which hijacks user sessions … | 48 | 1559 | active |
| kubernetes-sigs/secrets-store-csi-driver A Kubernetes CSI driver that mounts secrets, keys, and certificates from external secrets stores (Vault, Azure Key Vault, AWS Secrets Manag… | 86 | 1557 | stable |
| newaetech/chipwhisperer ChipWhisperer is an open-source toolchain for hardware security research, providing capture hardware designs, FPGA/USB firmware, and a Pyth… | 79 | 1557 | active |
| AndyFul/ConfigureDefender ConfigureDefender is a small portable Windows GUI utility for viewing and configuring Windows Defender antivirus settings on Windows 10/11 … | 74 | 1555 | active |
| v-byte-cpu/sx sx is a fast, UNIX-philosophy command-line network scanner written in Go that supports ARP/NDP host discovery, ICMP, TCP SYN/FIN/NULL/Xmas,… | 83 | 1553 | active |
| AeonLucid/AndroidNativeEmu A Python library that partially emulates Android native (.so) libraries on a host machine using the Unicorn CPU emulator. It emulates the J… | 26 | 1549 | active |
| sidebase/nuxt-auth @sidebase/nuxt-auth is a Nuxt 3+ module that adds authentication to universal Nuxt applications via OAuth providers, credentials, or email … | 91 | 1548 | active |
| samwafgo/SamWaf SamWaf is a lightweight, open-source web application firewall (WAF) written in Go, designed for small companies, studios, and personal webs… | 89 | 1547 | active |
| dfir-iris/iris-web IRIS is a self-hosted, collaborative web platform for incident responders to share technical details and manage investigations. It ships as… | 98 | 1546 | active |
| homeassistant-apps/app-cloudflared A Home Assistant add-on that runs Cloudflared to create a secure Cloudflare Tunnel to your Home Assistant instance. It enables remote acces… | 99 | 1543 | active |
| ServenScorpion/VirtualApp A fork of VirtualApp, an Android virtualization framework that runs apps inside a virtual container supporting app cloning (multi-instance)… | 74 | 1540 | active |
| system-linux/FazJammer FazJammer is an ESP8266-based firmware project that turns a NodeMCU plus an NRF24L01+ radio module into a device that jams Wi-Fi, BLE, and … | 42 | 1539 | active |
| WildKernels/GKI_KernelSU_SUSFS Prebuilt Android GKI (Generic Kernel Image) kernels for Android 5.10+ devices with KernelSU root support and SUSFS root-hiding patches inte… | 85 | 1537 | active |
| BLE-Research-Group/MetaRadar MetaRadar (BLE Radar) is an Android application for monitoring Bluetooth Low Energy environments. It scans for nearby BLE devices, analyzes… | 71 | 1537 | active |
| Clats97/ClatScope ClatScope Info Tool is a Python-based OSINT utility offering 70+ reconnaissance features including geolocation, DNS, WHOIS, phone, email, a… | 48 | 1537 | active |
| ProtonMail/proton-bridge Proton Mail Bridge is a desktop application that runs local IMAP and SMTP servers, allowing standard email clients to send and receive encr… | 94 | 1536 | active |
| guacsec/guac GUAC (Graph for Understanding Artifact Composition) is an OpenSSF incubating project that ingests software security metadata such as SBOMs,… | 90 | 1534 | active |
| igogo-x86/HexRaysPyTools An IDA Pro plugin that enhances the Hex-Rays decompiler workflow. It assists in reconstructing structures and classes, detecting virtual ta… | 32 | 1533 | active |
| occlum/occlum Occlum is a memory-safe, multi-process library OS (LibOS) written in Rust for Intel SGX enclaves. It lets legacy applications run inside se… | 52 | 1532 | active |
| ssoready/ssoready SSOReady is an open-source service and set of SDKs for adding enterprise SAML single sign-on and SCIM directory sync to any product. It exp… | 42 | 1532 | active |
| xnl-h4ck3r/GAP-Burp-Extension GAP is a Burp Suite extension written in Python (Jython) that extracts potential endpoints, parameters, and links from Burp's site map, pro… | 66 | 1530 | active |
| MikeWang000000/FakeHTTP FakeHTTP is a Linux command-line tool that obfuscates TCP connections by disguising them as HTTP traffic using Netfilter Queue (NFQUEUE). I… | 34 | 1527 | active |
| BlackSnufkin/LitterBox LitterBox is a self-hosted payload-analysis sandbox for red teams that runs static, dynamic, and EDR-based analysis on samples and produces… | 62 | 1526 | active |
| cartalyst/sentinel Sentinel is a PHP 8.3+ framework-agnostic authentication and authorization library by Cartalyst. It provides user authentication, roles, pe… | 61 | 1526 | active |
| janmojzis/tinyssh TinySSH (tinysshd) is a minimalistic SSHv2 server written in C with under 100,000 words of code, implementing only a secure subset of the p… | 89 | 1524 | active |
| zquestz/omniauth-google-oauth2 An OmniAuth strategy gem that enables Google OAuth2 authentication in Ruby applications. It integrates as Rack middleware (e.g., in Rails o… | 73 | 1523 | active |
| mysk-research/loupe Loupe is an open-source iOS and iPadOS app that demonstrates device fingerprinting by showing raw values from public iOS APIs that any thir… | 53 | 1522 | active |
| Tongsuo-Project/Tongsuo Tongsuo (铜锁) is an open-source cryptographic library providing modern cryptographic primitives and secure communication protocols, includin… | 84 | 1521 | active |
| Tencent/TFace TFace is a research platform from Tencent Youtu Lab for trusty face analysis, covering face recognition, face security (anti-spoofing), fac… | 57 | 1521 | active |
| nemesida-waf/waf-bypass WAF Bypass Tool is an open-source Python CLI tool that tests web application firewalls for false positives and false negatives using predef… | 83 | 1520 | active |
| mushorg/conpot Conpot is a low-interaction ICS/SCADA honeypot written in Python that emulates industrial control system protocols and devices. It collects… | 66 | 1519 | active |
| Danny-Dasilva/CycleTLS CycleTLS is a Go library with a JavaScript/TypeScript wrapper that lets clients spoof TLS/JA3 (and JA4) fingerprints when making HTTP reque… | 73 | 1518 | active |
| gobysec/Goby Goby is a network security assessment tool that maps an organization's attack surface and scans for known vulnerabilities and weak password… | 23 | 1517 | active |
| fossas/fossa-cli FOSSA CLI is a zero-configuration, language-agnostic dependency analysis tool that detects dependencies in any codebase across 20+ build sy… | 95 | 1516 | active |
| overspace-labs/CaA CaA is a BurpSuite extension (Montoya API) that analyzes HTTP traffic to extract parameters, paths, files, and parameter values with freque… | 83 | 1516 | active |
| ztgrace/changeme changeme is a Python CLI tool that scans networks for devices and services using default or backdoor credentials. Credential definitions ar… | 36 | 1516 | active |
| globaleaks/globaleaks-whistleblowing-software GlobaLeaks is a free, open-source whistleblowing platform that lets any organization set up and maintain a secure, anonymous reporting syst… | 94 | 1514 | stable |
| webpwnized/mutillidae OWASP Mutillidae II is a deliberately vulnerable PHP web application used as a target for web-security training and practice. It includes o… | 72 | 1513 | active |
| blacklanternsecurity/writehat WriteHat is a self-hosted web application for generating penetration test reports, converting Markdown to HTML to PDF without Microsoft Wor… | 66 | 1513 | active |
| deathmemory/FridaContainer FridaContainer is a modular collection of popular and custom Frida scripts written in TypeScript to speed up reverse engineering work on An… | 56 | 1512 | active |
| Bareflank/hypervisor Bareflank is an open-source hypervisor SDK written in C++ (with Rust support) for rapidly prototyping custom hypervisors on 64-bit Intel an… | 23 | 1511 | active |
| QuiteAFancyEmerald/InvisiProxy InvisiProxy LTS (formerly Holy Unblocker) is a self-hostable Node.js web proxy service that lets users access blocked websites and Tor/Onio… | 94 | 1509 | active |
| cupcakearmy/cryptgeon Cryptgeon is a secure, open-source note and file sharing service inspired by PrivNote, built with Rust and Svelte. Notes are encrypted clie… | 92 | 1508 | active |
| pallets-eco/flask-wtf Flask-WTF is a Python library that integrates WTForms with the Flask web framework, providing form rendering, validation, CSRF protection, … | 80 | 1508 | stable |
| jaraco/keyring A Python library providing a simple API to access the operating system's native keyring service for safe password storage and retrieval. It… | 70 | 1508 | stable |
| 0xsp-SRD/mortar Mortar Loader is a red team evasion tool that encrypts PE binaries and shellcode and executes them in memory using various injection techni… | 23 | 1508 | active |
| kenryu42/cc-safety-net CC Safety Net is a pre-execution hook for AI coding agent CLIs (Claude Code, Codex, Cursor, Gemini CLI, and many others) that blocks destru… | 83 | 1507 | active |
| Internet-Architecture-and-Security/PacketScope PacketScope is an open-source, eBPF-based protocol stack analysis and debugging tool for server-side network observability and defense. It … | 75 | 1507 | active |
| nikaiw/VMkatz VMkatz is a Rust CLI tool that extracts Windows credentials (NTLM hashes, DPAPI keys, Kerberos tickets, LSA secrets, BitLocker keys) direct… | 69 | 1507 | active |
| mike-engel/jwt-cli jwt-cli is a fast command-line tool written in Rust for decoding and encoding JSON Web Tokens (JWTs). It supports custom headers, arbitrary… | 67 | 1507 | active |
| DarthTon/Blackbone Blackbone is a C++ library for Windows memory hacking, providing APIs for process memory manipulation, DLL injection, manual PE image mappi… | 32 | 5479 | maintenance |
| nikitastupin/clairvoyance Clairvoyance is a Python CLI tool that recovers a GraphQL API's schema even when introspection is disabled, by probing field and type names… | 57 | 1506 | active |
| akto-api-security/akto Akto is an open-source API and AI security platform that discovers and inventories APIs, AI agents, MCP servers, and LLM usage, then contin… | 94 | 1505 | active |
| Gowtham-Darkseid/AutoPentestX AutoPentestX is a Python-based automated penetration testing toolkit that scans targets for vulnerabilities and generates security reports.… | 45 | 1504 | active |
| tirrenotechnologies/tirreno tirreno is an open-source, self-hosted security framework written in PHP/PostgreSQL that provides event tracking, threat detection, and ris… | 83 | 1503 | active |
| ChendoChap/pOOBs4 A kernel exploit for PlayStation 4 firmware 9.00 that leverages a filesystem (exfat) bug triggered via a specially formatted USB drive, com… | 32 | 1503 | stable |
| AzureAD/microsoft-authentication-library-for-dotnet Microsoft Authentication Library (MSAL) for .NET, part of the Microsoft identity platform. It enables .NET applications to acquire security… | 99 | 1502 | stable |
| assetnote/nowafpls nowafpls is a Jython-based Burp Suite plugin that bypasses web application firewalls (WAFs) by inserting junk data into HTTP request bodies… | 38 | 1502 | active |
| accounts-js/accounts A suite of TypeScript packages providing fullstack authentication and accounts management for JavaScript applications, supporting GraphQL a… | 23 | 1502 | active |
| uber/ADR ADR (Agentic AI Detection and Response) is an open-source enterprise security framework for AI agents, providing endpoint discovery of AI t… | 68 | 1501 | active |
| kkapsner/CanvasBlocker A Firefox browser extension that protects users from browser fingerprinting by blocking or faking readouts of JavaScript APIs such as canva… | 64 | 1501 | active |
| zapdos-labs/unblink Unblink is an AI-powered camera monitoring application that uses a vision language model (Qwen3-VL) to analyze camera frames, summarize act… | 50 | 1501 | active |
| ZimengXiong/tinyTouch tinyTouch is an open-source DIY hardware and software project that lets you authenticate, sudo, and log in to your computer with a fingerpr… | 69 | 1500 | active |
| pyca/bcrypt pyca/bcrypt is a Python library providing bcrypt password hashing and a bcrypt_pbkdf key derivation function. It offers salted hashing with… | 77 | 1499 | active |
| lissy93/domain-locker Domain Locker is an open-source web application for tracking and managing a portfolio of domain names across registrars. It monitors expira… | 85 | 1498 | active |
| cryptii/cryptii Cryptii is a web app and framework for modular conversion, encoding, and encryption, performed entirely in the browser with no server inter… | 34 | 1498 | active |
| RyanDFIR/hindsight Hindsight is a free Python-based browser forensics tool that parses web artifacts (history, downloads, cache, cookies, bookmarks, autofill,… | 88 | 1497 | active |
| twofas/2fas-android The official open-source Android app for 2FAS, a two-factor authentication service that generates one-time passwords (TOTP and HOTP) for se… | 86 | 1497 | active |
| T4y1oR/RingQ RingQ is a post-exploitation antivirus evasion tool that obfuscates and loads arbitrary Windows executables or shellcode (e.g., Cobalt Stri… | 27 | 1497 | active |
| project-oak/oak Oak is a Rust-based platform for building distributed systems whose components can produce externally verifiable claims about their behavio… | 77 | 1496 | active |
| pygod-team/pygod PyGOD is a Python library for graph outlier detection (anomaly detection) built on PyTorch and PyTorch Geometric. It provides 10+ graph-bas… | 23 | 1496 | active |
| salvogiangri/KnoxPatch An LSPosed/Xposed module written in Kotlin that restores Samsung apps and features (Samsung Health, Samsung Cloud, Samsung Flow, etc.) on r… | 87 | 1495 | active |
| Meckazin/ChromeKatz ChromeKatz is a set of offensive security tools (CookieKatz, ElevationKatz) written in C that dump cookies and decryption keys directly fro… | 72 | 1495 | active |
| usbarmory/usbarmory USB armory is an open source hardware design for a compact secure computer built into a USB stick form factor, based on ARM SoCs. This repo… | 66 | 1495 | active |
| GONZOsint/geowifi A Python command-line tool that queries multiple public WiFi geolocation databases (Wigle, Apple, Google, Mylnikov, WiFiDB, Combain, Freifu… | 32 | 1495 | active |
| google/go-safeweb go-safeweb is a collection of Go libraries for building secure-by-default HTTP servers. It applies security mechanisms like XSS and CSRF pr… | 10 | 1494 | active |
| duckduckgo/duckduckgo-privacy-extension DuckDuckGo Privacy Essentials is a browser extension for Firefox, Chrome, Edge, and Opera that blocks third-party trackers and ads, manages… | 99 | 1492 | active |
| spyboy-productions/r4ven R4ven is a security awareness and penetration testing tool that hosts a web page which, when a user grants browser permissions, captures GP… | 60 | 1492 | active |
| cossacklabs/acra Acra is a database security suite that provides field-level encryption, searchable encryption, tokenization, data masking, SQL firewalling,… | 58 | 1491 | active |
| rfxn/linux-malware-detect Linux Malware Detect (LMD) is a bash-based malware scanner for Linux servers featuring a multi-stage detection pipeline (MD5/SHA-256 hashin… | 86 | 1490 | active |
| libressl/portable LibreSSL Portable is the portable build of LibreSSL, a TLS and cryptography stack forked from OpenSSL 1.0.1g by the OpenBSD project. It pro… | 94 | 1489 | stable |
| Spomky-Labs/otphp A PHP library for generating one-time passwords according to RFC 4226 (HOTP) and RFC 6238 (TOTP). It is compatible with Google Authenticato… | 93 | 1488 | stable |
| restic/rest-server A high-performance HTTP server written in Go that implements restic's REST backend API, allowing the restic backup client to store backups … | 65 | 1488 | active |
| hellman/xortool xortool is a Python command-line tool for cryptanalysis of multi-byte XOR ciphers. It guesses the key length based on character frequency s… | 42 | 1488 | active |
| TheresAFewConors/Sooty Sooty is a Python CLI tool that automates routine tasks for SOC (Security Operations Center) analysts, such as URL sanitization, DNS and Wh… | 32 | 1488 | active |
| halo/LinkLiar LinkLiar is a free, open-source macOS status menu application written in Swift for spoofing the MAC addresses of Wi-Fi and Ethernet interfa… | 39 | 1486 | active |
| liuzq2002/Adguard-Home-For-Magisk-Mod A Magisk module that runs AdGuard Home on rooted Android devices to block ads by redirecting and filtering DNS requests. It ships with buil… | 85 | 1485 | active |
| kalessil/phpinspectionsea Php Inspections (EA Extended) is an open-source static code analysis tool distributed as a PhpStorm/IntelliJ IDEA plugin. It detects archit… | 73 | 1485 | active |
| pass-extension/pass-otp pass-otp is an extension for the pass password manager that stores and manages one-time-password (OTP) tokens as otpauth:// URIs. It genera… | 39 | 1485 | active |
| Schira4396/VcenterKiller A Go-based all-in-one exploitation and verification tool targeting VMware vCenter, covering major CVEs such as CVE-2021-21972, CVE-2021-219… | 23 | 1485 | active |
| securitybunker/databunker Databunker is a self-hosted, Go-based secure vault for tokenizing and storing personal records such as PII, PHI, KYC, and PCI data. It expo… | 75 | 1482 | active |
| webfactory/ssh-agent A GitHub Action that starts ssh-agent on the workflow runner, exports SSH_AUTH_SOCK, and loads one or more private SSH keys from repository… | 74 | 1482 | active |
| Shopify/ejson EJSON is a Go CLI utility for managing encrypted secrets in JSON files using asymmetric elliptic-curve (NaCl Box) encryption. It lets teams… | 86 | 1480 | stable |
| dotpcap/sharppcap SharpPcap is a fully managed, cross-platform .NET library for capturing packets from live network devices and reading/writing pcap capture … | 67 | 1479 | active |
| esprfid/esp-rfid ESP RFID is an open-source access control system that runs on the ESP8266 microcontroller and supports MFRC522, PN532, RDM6300, and Wiegand… | 62 | 1479 | active |
| Fuzion24/JustTrustMe An Xposed module for rooted Android devices that disables SSL certificate pinning in apps, enabling traffic interception during security au… | 23 | 5361 | maintenance |
| inguardians/peirates Peirates is a Go-based, interactive Kubernetes penetration testing tool that automates privilege escalation, lateral movement, and cluster … | 90 | 1477 | active |