domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| controlplaneio/kubesec Kubesec is a static analysis tool that performs security risk analysis on Kubernetes resource manifests, assigning a security score and det… | 64 | 1477 | active |
| LionSec/katoolin A Python CLI tool that lets users add or remove Kali Linux repositories on other Debian-based systems (like Ubuntu) and install Kali Linux … | 32 | 5348 | maintenance |
| jvoisin/php-malware-finder PHP Malware Finder is a command-line tool that scans filesystems for potentially malicious PHP files using YARA rules. It detects obfuscate… | 10 | 1475 | active |
| ioi/isolate Isolate is a Linux sandbox for securely executing untrusted programs, originally built for programming contest judges. It uses kernel featu… | 77 | 1473 | stable |
| lengjibo/RedTeamTools A collection of red team tools written and modified by the author, primarily in C++ and Python. It includes utilities for AV bypass, privil… | 53 | 1472 | active |
| shuanx/BurpAPIFinder BurpAPIFinder is a Burp Suite extension written in Java that passively analyzes HTTP traffic (HTML and JS files) to discover hidden API end… | 15 | 1472 | active |
| JJTech0130/TrollRestore TrollRestore is a Python-based installer that installs TrollStore on iOS/iPadOS 15.2 through 16.7 RC and 17.0 by exploiting CVE-2024-44252 … | 13 | 1472 | active |
| digitalbazaar/forge Forge is a pure-JavaScript implementation of the TLS protocol plus a broad set of cryptographic utilities including AES, RSA, X.509 certifi… | 66 | 5330 | maintenance |
| hectorm/otpauth A JavaScript One-Time Password library implementing HOTP (RFC 4226) and TOTP (RFC 6238) for generating and validating 2FA tokens. It runs i… | 86 | 1471 | stable |
| OpenOSINT/OpenOSINT OpenOSINT is an AI-powered OSINT framework offering 19 investigation tools behind a natural-language agent, usable as an interactive REPL, … | 81 | 1470 | active |
| Greenwolf/ntlm_theft ntlm_theft is a Python3 CLI tool that generates 21 different types of NTLMv2 hash theft files (e.g., .url, .scf, .docx, .pdf, .jnlp) that t… | 52 | 1470 | active |
| napi-rs/node-rs A collection of Node.js native addons written in Rust using napi-rs, providing packages like @node-rs/bcrypt, @node-rs/argon2, @node-rs/crc… | 98 | 1469 | active |
| meganz/sdk The official MEGA C++ SDK providing client access to MEGA's end-to-end encrypted cloud storage, including a low-level API, an intermediate … | 95 | 1469 | active |
| rooootdev/lara LARA is an iOS customization toolbox application that leverages the DarkSword kernel exploit to modify system behavior on supported devices… | 73 | 1467 | active |
| infrahq/infra Infra is an open-source authentication and access management service for servers, Kubernetes clusters, and databases. It provides identity-… | 66 | 1467 | active |
| t3l3machus/psudohash psudohash is a Python CLI tool that generates millions of keyword-based password mutations for brute-force attacks and hash cracking. It mi… | 34 | 1467 | active |
| VirusTotal/vt-cli The official VirusTotal command-line interface, written in Go, that lets users interact with VirusTotal's API from the terminal. It support… | 82 | 1464 | active |
| Sorcery/sorcery Sorcery is a stripped-down authentication library for Ruby on Rails supporting ActiveRecord, Mongoid, and other ORMs. It provides core auth… | 71 | 1464 | active |
| ssh-mitm/ssh-mitm SSH-MITM is an open-source man-in-the-middle SSH server for authorized security audits and malware analysis. It proxies SSH client-server c… | 66 | 1464 | active |
| iliyami/MacSai Mac Sai is a free, open-source macOS application that cleans junk files, scans for malware, uninstalls apps completely, and visualizes disk… | 79 | 1463 | active |
| c0ny1/passive-scan-client A Burp Suite extension written in Java that forwards passive scanning traffic to external passive vulnerability scanners (like xray, w13sca… | 23 | 1462 | stable |
| epsylon/xsser XSSer is an automatic penetration testing framework for detecting, exploiting, and reporting cross-site scripting (XSS) vulnerabilities in … | 82 | 1461 | active |
| terraform-compliance/cli terraform-compliance is a lightweight, security-focused BDD test framework for Terraform that enables negative testing of infrastructure-as… | 81 | 1461 | active |
| fkie-cad/FACT_core FACT (Firmware Analysis and Comparison Tool) is a self-hosted Python application that automates firmware security analysis for devices like… | 92 | 1460 | active |
| PortSwigger/param-miner Param Miner is a Burp Suite extension that identifies hidden, unlinked HTTP parameters, headers, and cookies using diffing logic and binary… | 78 | 1460 | active |
| batfish/batfish Batfish is an open-source network configuration analysis tool that builds complete models of network behavior from device configurations to… | 67 | 1460 | active |
| duty1g/x64dbg-mcp-server A native MCP (Model Context Protocol) plugin for x64dbg written in Zig that exposes the debugger's full functionality over HTTP with Stream… | 57 | 1460 | active |
| coder/wush wush is a command-line tool for transferring files and opening remote shells between computers over peer-to-peer WireGuard connections. It … | 41 | 1460 | active |
| openclarity/openclarity OpenClarity is an open-source platform for agentless detection and management of Virtual Machine SBOMs and security threats such as vulnera… | 10 | 1460 | active |
| OWASP/wrongsecrets OWASP WrongSecrets is a deliberately vulnerable Java application containing 50+ challenges that demonstrate how secrets are commonly miscon… | 94 | 1459 | active |
| momosecurity/FindSomething FindSomething is a passive browser extension for Chrome and Firefox that extracts potentially sensitive information (like emails, API keys,… | 32 | 1458 | active |
| urbanadventurer/username-anarchy Username Anarchy is a Ruby command-line tool that generates lists of likely usernames from people's first and last names for use in penetra… | 23 | 1458 | stable |
| khast3x/h8mail h8mail is a Python CLI tool for email OSINT and password breach hunting. It queries breach services like HaveIBeenPwned and Hunter.io, or s… | 23 | 5273 | maintenance |
| AhMyth/AhMyth-Android-RAT AhMyth is an open-source Android Remote Administration Tool (RAT) consisting of an Electron-based desktop control panel and an Android back… | 10 | 5273 | maintenance |
| OWASP/SecurityShepherd OWASP Security Shepherd is a self-hosted web and mobile application security training platform built in Java. It presents lessons and chall… | 66 | 1456 | active |
| qpoint-io/qtap Qtap is an eBPF agent that hooks TLS/SSL functions in the Linux kernel to capture network traffic before and after encryption, with full pr… | 64 | 1456 | active |
| p2r3/beheader A command-line tool that generates polyglot files - single files that are simultaneously valid images, videos, PDFs, ZIP archives, and HTML… | 48 | 1455 | active |
| NullArray/AutoSploit AutoSploit is a Python CLI tool that automates mass exploitation of remote hosts by combining target discovery from Shodan, Censys, and Zoo… | 23 | 5253 | maintenance |
| NHAS/reverse_ssh A Go-based SSH server and client that enables SSH-based reverse shells, letting operators manage and connect to remote targets with native … | 98 | 1453 | active |
| strongbox-password-safe/Strongbox Strongbox is a native password manager client for iOS and macOS that opens KeePass (KDB/KDBX) and Password Safe (v3) vault files. It encryp… | 74 | 1453 | active |
| ossf/criticality_score A Go CLI tool from the OpenSSF that computes a criticality score (0 to 1) for open source projects based on parameters like contributor cou… | 67 | 1452 | active |
| tillson/git-hound GitHound is a Go-based CLI tool that hunts for exposed API keys, secrets, and credentials across all of GitHub using GitHub dorks, pattern … | 70 | 1451 | active |
| hudikhq/hoodik Hoodik is a self-hosted, end-to-end encrypted cloud storage server written in Rust with a Vue 3 frontend, where all encryption happens in t… | 98 | 1450 | active |
| ViRb3/magisk-frida A Magisk/KernelSU/APatch module that automatically installs and runs frida-server on boot on rooted Android devices. It stays up to date by… | 93 | 1450 | active |
| ergrelet/unlicense A Python 3 command-line tool that dynamically unpacks executables protected with Themida/WinLicense 2.x and 3.x. It automatically recovers … | 23 | 1450 | active |
| intel/confidential-computing.sgx Intel Software Guard Extensions (SGX) software stack for Linux, comprising the SGX driver, SDK, and Platform Software (PSW). It enables dev… | 93 | 1449 | active |
| GhostPack/SharpDPAPI SharpDPAPI is a C# port of Mimikatz's Windows DPAPI functionality, allowing triage of DPAPI masterkeys, credentials, vaults, certificates, … | 32 | 1449 | active |
| passwordless-lib/fido2-net-lib A battle-tested .NET library implementing a FIDO2 server / WebAuthn relying party for passkey registration (attestation) and authentication… | 71 | 1448 | active |
| SeeFlowerX/stackplz stackplz is an eBPF-based stack tracing tool for Android (arm64). It supports syscall tracing, uprobe hooking of 64-bit userspace libraries… | 64 | 1447 | active |
| polhenarejos/pico-fido Open-source firmware that turns a Raspberry Pi Pico (RP2040/RP2350) or ESP32-S3 microcontroller into a FIDO2 passkey authenticator, support… | 95 | 1446 | active |
| pritunl/pritunl-client Pritunl Client is a free, open-source cross-platform OpenVPN and WireGuard client with both graphical and command-line interfaces. It suppo… | 99 | 1445 | active |
| harmony-one/harmony The core protocol implementation of the Harmony blockchain, a sharded proof-of-stake network written in Go. It implements consensus (PBFT-b… | 90 | 1445 | active |
| Safe3/openresty-manager OpenResty Manager is a modern, web-based server control panel for managing OpenResty/Nginx reverse proxies, free SSL certificates, security… | 85 | 1444 | active |
| ossf/allstar Allstar is a GitHub App from OpenSSF that continuously monitors GitHub organizations and repositories for adherence to security best practi… | 74 | 1444 | active |
| superpoweredSDK/Low-Latency-Android-iOS-Linux-Windows-tvOS-macOS-Interactive-Audio-Platform Superpowered is a commercial cross-platform C++ SDK suite providing low-latency interactive audio processing, HTTP/HTTPS networking, and cr… | 76 | 1443 | active |
| One-Fox-Security-Team/One-Fox-T00ls One-Fox-T00ls is a curated collection of penetration testing and security toolboxes from the One-Fox security team, covering information ga… | 56 | 1443 | active |
| denandz/sourcemapper Sourcemapper is a Go CLI tool that parses JavaScript sourcemap (.map) files, whether from URLs or local directories, and reconstructs the o… | 75 | 1442 | stable |
| EgeBalci/amber Amber is a reflective PE packer that converts Windows PE files (EXE, DLL, SYS) into position-independent shellcode payloads for in-memory e… | 23 | 1442 | active |
| secretlint/secretlint Secretlint is a pluggable linting tool that scans projects for committed credentials and secrets, reporting matches with explanations. It r… | 99 | 1441 | active |
| ThoughtfulDev/EagleEye EagleEye is a Python-based OSINT tool that identifies social media profiles (Instagram, Facebook, Twitter, YouTube) of a person using face … | 32 | 5197 | maintenance |
| tuneinsight/lattigo Lattigo is a pure Go library implementing lattice-based (RLWE) homomorphic encryption schemes such as BFV/BGV and CKKS, along with their mu… | 72 | 1440 | active |
| zodiacon/AllTools A collection of Pavel Yosifovich's reasonably stable Windows system tools, including process/driver monitors, kernel object viewers, PE fil… | 71 | 1440 | active |
| t3l3machus/toxssin toxssin is an open-source penetration testing CLI tool that automates exploitation of Cross-Site Scripting (XSS) vulnerabilities. It pairs … | 33 | 1440 | active |
| tclahr/uac UAC (Unix-like Artifacts Collector) is a portable, dependency-free shell-based incident response tool that automates forensic artifact coll… | 84 | 1437 | active |
| tahoe-lafs/tahoe-lafs Tahoe-LAFS is a free and open-source decentralized storage system that distributes encrypted, erasure-coded file shares across multiple unt… | 62 | 1435 | active |
| nowsecure/r2frida r2frida is a radare2 plugin that integrates the Frida dynamic instrumentation toolkit, letting users inspect and manipulate local or remote… | 94 | 1434 | active |
| crazy-max/WindowsSpyBlocker WindowsSpyBlocker is a Go application delivered as a single Windows executable that blocks spying and tracking on Windows systems. It captu… | 67 | 5168 | maintenance |
| bacher09/pwgen-for-bios A collection of master password generators for various BIOS/UEFI firmware from vendors like Dell, HP, Asus, Samsung, and Sony. It powers th… | 62 | 1433 | active |
| jawj/IKEv2-setup A Bash script that configures a fresh Ubuntu Server LTS install as an IKEv2 VPN server using strongSwan, with Let's Encrypt certificates an… | 57 | 1433 | active |
| eljojo/rememory ReMemory is a tool that encrypts your files with age and splits the key using Shamir's Secret Sharing among trusted people, who each receiv… | 74 | 1432 | active |
| sw33tLie/bbscope bbscope is a Go CLI tool that fetches, stores, and manages bug bounty program scopes from HackerOne, Bugcrowd, Intigriti, YesWeHack, and Im… | 73 | 1432 | active |
| redacted/XKCD-password-generator xkcdpass is a Python CLI tool and library that generates secure multi-word passphrases inspired by XKCD 936. It supports customizable wordl… | 61 | 1432 | stable |
| GoogleCloudPlatform/cloud-sql-proxy The Cloud SQL Auth Proxy is a Go utility that provides secure, IAM-authorized, TLS 1.3-encrypted connections to Google Cloud SQL instances … | 98 | 1431 | active |
| xtclovver/RKNHardering An Android application that detects VPN and proxy configurations on a device, implementing the methodology used by Roskomnadzor (RKN) to id… | 78 | 1431 | active |
| google/oss-fuzz-gen A Google framework that uses large language models to automatically generate fuzz targets for real-world C/C++, Java, and Python projects, … | 58 | 1431 | active |
| cyberark/KubiScan KubiScan is a Python CLI tool that scans Kubernetes clusters for risky permissions in the RBAC authorization model. It identifies risky rol… | 33 | 1431 | active |
| boku7/BokuLoader BokuLoader is a proof-of-concept User-Defined Reflective Loader (UDRL) for Cobalt Strike written in C and assembly. It recreates, integrate… | 32 | 1431 | active |
| tilfinltd/aws-extend-switch-roles A browser extension for Chrome, Firefox, and Edge that extends the AWS Management Console's built-in IAM role switching. It lets users conf… | 92 | 1428 | active |
| dockovpn/dockovpn DockOvpn is a stateless, out-of-the-box OpenVPN server packaged as a Docker image that starts in under two seconds and requires no persiste… | 23 | 1428 | active |
| rubyzip/rubyzip Rubyzip is a Ruby library (gem) for reading and writing zip archives, including support for AES encryption. It provides both high-level Zip… | 98 | 1427 | stable |
| six2dez/burp-ai-agent Custom AI Agent (formerly Burp AI Agent) is a Burp Suite extension written in Kotlin that integrates LLMs into web security workflows via l… | 82 | 1427 | stable |
| ankane/pretender Pretender is a lightweight Ruby gem that lets admins log in as (impersonate) another user in Rails applications. It works with any authenti… | 66 | 1427 | stable |
| enarx/enarx Enarx is an open-source command-line tool and runtime for running applications inside hardware Trusted Execution Environments (TEEs) such a… | 52 | 1425 | active |
| dirkjanm/ldapdomaindump A Python CLI tool that dumps Active Directory information (users, groups, computers, policies, trusts) via LDAP and renders it as human-rea… | 30 | 1425 | stable |
| f0ng/autoDecoder A Burp Suite extension (written in Java) that lets users plug in custom encryption/decryption logic so intercepted HTTP traffic can be view… | 78 | 1424 | active |
| BiZken/PhishMailer A Python CLI tool that generates professional-looking phishing email templates for popular services like Instagram, PayPal, and Discord, ou… | 41 | 1424 | active |
| rebrowser/rebrowser-patches A collection of source-code patches for Puppeteer and Playwright that fix automation leaks and help avoid bot detection systems like Cloudf… | 34 | 1424 | active |
| antonioCoco/RunasCs RunasCs is an open-source C# utility for running processes with explicit credentials on Windows, serving as an improved alternative to the … | 23 | 1424 | stable |
| Isaacdelly/Plutus Plutus is a Python CLI tool that brute-forces Bitcoin private keys by generating sequential keys via elliptic curve point addition and chec… | 59 | 1423 | active |
| SamuelTulach/VirusTotalUploader An open-source C# WinForms desktop application for uploading files to VirusTotal for malware scanning. It serves as a maintained replacemen… | 23 | 1422 | active |
| mbi/django-simple-captcha A Django application that adds customizable captcha image challenges to any Django form. It supports custom challenge generators, image sty… | 85 | 1421 | stable |
| netsniff-ng/netsniff-ng netsniff-ng is a free, high-performance Linux networking toolkit written in C, often described as a Swiss army knife for network packets. I… | 34 | 1421 | stable |
| WPeace-HcH/WPeGPT WPeGPT is an IDA Pro plugin that integrates LLM models (OpenAI, DeepSeek, or any OpenAI-compatible API) into binary analysis workflows. It … | 75 | 1418 | active |
| openwpm/OpenWPM OpenWPM is a web privacy measurement framework built on Firefox with Selenium automation, designed to collect data from thousands to millio… | 95 | 1417 | active |
| login-securite/DonPAPI DonPAPI is a Python CLI tool that remotely dumps DPAPI-protected secrets (browser credentials, certificates, WiFi passwords, and more) from… | 29 | 1417 | active |
| ahmedkhlief/APT-Hunter APT-Hunter is a Python-based threat hunting tool that analyzes Windows event logs (EVTX) to detect APT activity using predefined detection … | 23 | 1417 | active |
| tyranid/oleviewdotnet OleView.NET is a .NET application that merges the classic SDK tools OleView and Test Container into one COM/OLE viewer and inspector. It le… | 23 | 1417 | active |
| jesseduffield/horcrux A Go CLI tool that splits a file into encrypted fragments using Shamir's Secret Sharing, requiring only a threshold of fragments to reconst… | 23 | 5097 | maintenance |
| danny0838/content-farm-terminator Content Farm Terminator is a cross-platform browser extension that identifies content farms by marking hyperlinks pointing to them and bloc… | 77 | 1416 | active |
| proyecto26/react-native-inappbrowser A React Native library providing an in-app browser using Chrome Custom Tabs on Android and SafariServices/AuthenticationServices on iOS. It… | 68 | 1416 | active |