domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| simsong/bulk_extractor bulk_extractor is a high-performance digital forensics tool that rapidly scans disk images, files, and directories to extract structured in… | 87 | 1415 | active |
| Metarget/metarget Metarget is a Python-based framework that automatically builds vulnerable cloud-native infrastructures, installing vulnerable versions of D… | 65 | 1415 | active |
| wetox-team/flipperzero-goodies A collection of useful data and scripts for the Flipper Zero multi-tool device, including intercom keys and Python scripts. It is maintaine… | 44 | 1415 | active |
| outflanknl/C2-Tool-Collection A collection of C-based offensive security tools that integrate with Cobalt Strike and other C2 frameworks via Beacon Object Files (BOF) an… | 32 | 1415 | active |
| RythmStick/AMSITrigger AMSITrigger is a C# command-line tool that identifies the specific strings in PowerShell scripts that trigger Microsoft's Antimalware Scan … | 32 | 1415 | active |
| anonvector/SlipNet SlipNet is an open-source anti-censorship VPN client for Android (Kotlin/Jetpack Compose) with a cross-platform Go CLI companion, supportin… | 77 | 1414 | active |
| Dropnation/contract-fuzzer A Python-based fuzzer for Ethereum smart contracts that compiles Solidity sources and executes random sequences of public/external calls to… | 71 | 1414 | active |
| cr-marcstevens/sha1collisiondetection A C library and command-line tool that computes SHA-1 hashes while detecting known cryptanalytic collision attacks against SHA-1 with proba… | 45 | 1414 | stable |
| omegaee/my-fingerprint A lightweight browser extension built on Manifest V3 that protects against browser fingerprinting across Chrome, Edge, and Firefox. It spoo… | 94 | 1413 | active |
| BlendLog/MinerSearch A free Windows utility that scans for and removes hidden cryptocurrency miners by checking processes, files, registry, WMI, services, and s… | 91 | 1413 | active |
| Jayy001/Search-That-Hash Search-That-Hash is a Python CLI tool that automatically submits hashes to popular online hash-cracking APIs to crack them in seconds. If n… | 27 | 1413 | active |
| Bitwise-01/Instagram- A Python CLI tool that performs brute-force password attacks against Instagram accounts using a supplied password list and rotating proxies… | 32 | 5081 | maintenance |
| Gezine/Y2JB Y2JB is a PS5 exploit that achieves userland code execution through the console's YouTube app. It supports firmware 4.03+ via a payload del… | 78 | 1412 | active |
| ct-Open-Source/tuya-convert A collection of Python scripts that flash Tuya-based smart home IoT devices (mostly ESP8266-based) with alternative open-source firmware ov… | 23 | 5073 | maintenance |
| Dryxio/auto-re-agent auto-re-agent is an open-source AI reverse-engineering agent that combines Ghidra binary analysis with LLMs (Claude, Codex, OpenAI-compatib… | 78 | 1410 | active |
| nuvious/pam-duress A Linux Pluggable Authentication Module (PAM) that lets users configure alternate 'duress' passwords which, when used under coercion, authe… | 74 | 1410 | active |
| primihub/primihub PrimiHub is an open-source privacy-preserving computing platform built by a team of cryptography experts, supporting secure multi-party com… | 44 | 1408 | active |
| cachix/secretspec SecretSpec is a declarative tool and library for defining the secrets an application needs in a secretspec.toml manifest and resolving them… | 84 | 1407 | active |
| blacklanternsecurity/MANSPIDER MANSPIDER is a Python CLI tool that crawls SMB shares across entire networks to find files by filename or content, with regex support and t… | 77 | 1406 | active |
| mufeedvh/pdfrip pdfrip is a multithreaded PDF password cracking utility written in Rust. It supports dictionary attacks, mask and pattern-based brute force… | 68 | 1406 | active |
| tihanyin/PSSW100AVB A curated collection of PowerShell scripts demonstrating antivirus evasion techniques, most notably reverse shells that go undetected by AV… | 70 | 1405 | active |
| superhedgy/AttackSurfaceMapper AttackSurfaceMapper is a Python CLI reconnaissance tool that expands a target's attack surface using OSINT and active techniques like subdo… | 32 | 1405 | active |
| fabriziosalmi/certmate CertMate is a self-hosted certificate lifecycle management platform that issues and renews TLS certificates via ACME/Let's Encrypt across 2… | 81 | 1404 | active |
| googleapis/google-auth-library-php Google's officially supported PHP client library for OAuth 2.0 authentication and authorization with Google APIs. It implements Application… | 97 | 1403 | stable |
| karma9874/AndroRAT AndroRAT is an Android remote administration tool (RAT) with a Java-based Android client APK and a Python server, communicating over socket… | 32 | 5037 | maintenance |
| rosenpass/rosenpass Rosenpass is a post-quantum-secure key exchange tool written in Rust that establishes symmetric keys and feeds them to WireGuard via its pr… | 85 | 1401 | active |
| corna/me_cleaner A Python script that modifies Intel ME/TXE firmware images to reduce the co-processor's ability to interact with the system, disabling it d… | 23 | 5030 | maintenance |
| elder-plinius/V3SP3R V3SP3R (Vesper) is an Android application that turns a Flipper Zero into an AI-controlled hardware hacking tool, driven by natural language… | 48 | 1400 | active |
| Flangvik/TeamFiltration TeamFiltration is a cross-platform penetration testing framework for enumerating, password spraying, exfiltrating data from, and backdoorin… | 55 | 1399 | active |
| cisco/libsrtp libSRTP is Cisco's open-source C library implementing the Secure Real-time Transport Protocol (SRTP, RFC 3711) along with a supporting cryp… | 78 | 1397 | stable |
| PeculiarVentures/PKI.js PKI.js is a pure TypeScript library implementing the common formats and protocols used in PKI applications, including X.509 certificates, P… | 90 | 1396 | stable |
| bindhosts/bindhosts A systemless hosts manager for rooted Android devices that works with APatch, KernelSU, and Magisk. It provides ad-blocking and hostname re… | 93 | 1391 | active |
| rmyndharis/antigravity-skills A curated vault of 300+ Agent Skills for Google Antigravity, ported from the Claude Code Agents ecosystem. Each skill is a directory-based … | 80 | 1391 | active |
| INotGreen/XiebroC2 XiebroC2 is an open-source command-and-control (C2) framework for penetration testing, written in Go with a .NET teamserver. It supports Lu… | 27 | 1391 | active |
| WireGuard/wireguard-apple The official WireGuard VPN client application for iOS and macOS, written in Swift, including the WireGuardKit Swift package for integrating… | 32 | 1390 | active |
| simeononsecurity/Windows-Optimize-Harden-Debloat A PowerShell script that automates optimization, hardening, and debloating of Windows 10 and Windows 11 systems. It applies security and pr… | 31 | 1387 | active |
| fuatakgun/eufy_security A Home Assistant integration that connects Eufy Security devices (cameras, doorbells, home base stations, motion and contact sensors) to Ho… | 87 | 1386 | active |
| RedByte1337/GraphSpy GraphSpy is an initial access and post-exploitation tool for Microsoft Entra ID (Azure AD) and Microsoft 365, offering a browser-based GUI … | 70 | 1386 | active |
| aws-cloudformation/cloudformation-guard AWS CloudFormation Guard (cfn-guard) is a general-purpose policy-as-code evaluation tool with an expressive DSL for defining rules. It vali… | 88 | 1385 | active |
| hasherezade/libpeconv libPeConv is a C++ library for loading, manipulating, and dumping Windows PE (Portable Executable) files. It provides a 'swiss army knife' … | 67 | 1385 | active |
| owasp-noir/noir OWASP Noir is a static analysis (SAST) CLI tool that scans source code to extract every endpoint an application exposes, including shadow A… | 99 | 1383 | active |
| rzcoder/node-rsa A pure TypeScript RSA cryptography library for Node.js and browsers supporting key generation, encryption/decryption, and signing/verificat… | 81 | 1381 | active |
| Jackalope Jackalope is a customizable, coverage-guided fuzzer for black-box binaries built on the TinyInst instrumentation library by Google Project … | 77 | 1380 | active |
| ChiChou/grapefruit Grapefruit is an open-source mobile security testing suite for iOS and Android that provides a browser-based GUI over Frida for runtime ins… | 91 | 1379 | active |
| Brandon7CC/mac-monitor Mac Monitor is a stand-alone macOS application that uses Apple's Endpoint Security and System Extension APIs to collect and enrich system e… | 80 | 1379 | active |
| xaitax/SploitScan SploitScan is a Python CLI cybersecurity utility that aggregates detailed vulnerability information for CVEs from sources like EPSS, CISA K… | 77 | 1379 | active |
| blacklanternsecurity/TREVORspray TREVORspray is a modular password spraying tool with threading, SSH/subnet proxy rotation, and loot modules targeting identity providers li… | 70 | 1379 | active |
| reveny/Android-Native-Root-Detector An Android application that detects whether a device is rooted, using native code checks. It is written in Kotlin and distributed as a down… | 71 | 1378 | active |
| CIRCL/AIL-framework AIL framework is an open-source Python platform for collecting, crawling, processing, and analyzing unstructured data from the clear web, T… | 67 | 1378 | active |
| guidedhacking/GuidedHacking-Injector A C++ DLL injection library supporting x86, WOW64, and x64 injection with five injection methods and six shellcode execution techniques. It… | 32 | 1377 | active |
| jazzband/django-auditlog django-auditlog is a reusable Django app that logs changes made to model objects, including the user (actor) who made them. It stores chang… | 82 | 1376 | active |
| jonluca/anubis Anubis is a Python CLI tool for subdomain enumeration and information gathering that aggregates results from sources like HackerTarget, Vir… | 66 | 1375 | active |
| ClownQq/YDArk YDArk is a free x64 Windows kernel inspection tool similar to PCHunter, providing GUI views of processes, threads, handles, drivers, kernel… | 32 | 1375 | active |
| facebook/ThreatExchange A collection of Trust & Safety tools from Meta for fighting digital harms, including perceptual hashing algorithms (PDQ for images, TMK and… | 95 | 1373 | active |
| overtrue/socialite A framework-agnostic PHP OAuth2 authentication library inspired by laravel/socialite, supporting 20+ providers including GitHub, Google, Fa… | 88 | 1373 | active |
| hasherezade/exe_to_dll A command-line tool that converts a Windows EXE into a DLL that can be loaded like a library, exporting the original entry point as a 'Star… | 55 | 1373 | stable |
| USBGuard/usbguard USBGuard is a C++ software framework for implementing USB device authorization policies on Linux, protecting against rogue USB devices (Bad… | 52 | 1373 | active |
| thalesgroup-cert/Watcher Watcher is an open-source, self-hosted cyber threat intelligence and hunting platform built with Django and React JS. It uses AI to analyze… | 97 | 1372 | active |
| twoone-3/AdGuardHomeForRoot A Magisk/KernelSU/APatch module that runs AdGuardHome on rooted Android devices, providing a local DNS server that blocks ads, malware, and… | 94 | 1371 | active |
| google-github-actions/auth A GitHub Action that authenticates GitHub Actions workflows to Google Cloud, supporting Workload Identity Federation and Service Account Ke… | 78 | 1371 | active |
| glitchedgitz/cook COOK is a Go-based wordlist framework that generates, splits, merges, and finds wordlists, with support for permutations, combinations, and… | 66 | 1371 | active |
| 0xacb/recollapse REcollapse is a Python CLI helper tool that generates fuzzing payloads for black-box regex fuzzing against web applications. It helps bypas… | 46 | 1371 | active |
| simondankelmann/Bluetooth-LE-Spam An Android app that uses built-in Bluetooth Low Energy to send phantom device advertisements mimicking services like Apple popups, Microsof… | 61 | 4903 | maintenance |
| cesanta/docker_auth A standalone authentication and authorization server implementing the Docker Registry 2 token-based auth protocol. It issues tokens for Doc… | 57 | 1370 | active |
| andresriancho/w3af w3af is an open source web application attack and audit framework that scans web applications for over 200 vulnerability types, including X… | 23 | 4900 | maintenance |
| emalderson/ThePhish ThePhish is an automated phishing email analysis web application built on TheHive, Cortex, and MISP. It extracts observables from email hea… | 32 | 1368 | stable |
| SpiderLabs/Responder Responder is a Python-based LLMNR, NBT-NS, and mDNS poisoner with built-in rogue authentication servers (SMB, HTTP/S, MSSQL, FTP, LDAP, POP… | 10 | 4890 | maintenance |
| Endava/cats CATS (Contract API Testing and Security) is a REST API fuzzer and negative testing tool for OpenAPI endpoints. It automatically generates, … | 85 | 1367 | active |
| aws/s2n-quic s2n-quic is a Rust implementation of the IETF QUIC transport protocol, offering a simple API with configurable providers for TLS (s2n-tls o… | 99 | 1366 | active |
| Yubico/yubioath-flutter Yubico Authenticator is a companion desktop and Android app for managing YubiKey hardware security keys and accessing OATH one-time passwor… | 93 | 1366 | stable |
| fasnow/fine Fine is a Chinese-language cyberspace asset mapping and reconnaissance tool integrating FOFA, Hunter, Quake, ZoomEye, and Shodan APIs, plus… | 82 | 1366 | active |
| syssec-utd/pylingual PyLingual is a CPython bytecode decompiler that recovers Python source code from .pyc files for all Python versions since 3.6. It can be ru… | 63 | 1365 | active |
| NotRequiem/VMAware VMAware is a cross-platform, header-only C++ library for detecting virtual machines, hypervisors, emulators, containers, and sandboxes usin… | 90 | 1364 | active |
| Cracked5pider/Stardust Stardust is a modern 32/64-bit position independent shellcode (implant) template written in C++20. It provides compile-time FNV-1a hashing … | 70 | 1364 | active |
| Morsmalleo/AhMyth AhMyth is a cross-platform Android Remote Administration Tool (RAT) used to build APK payloads and remotely control Android devices through… | 66 | 1364 | active |
| alphasoc/flightsim flightsim is a lightweight Go CLI utility that safely generates malicious network traffic patterns such as DNS tunneling, DGA domains, C2 c… | 23 | 1363 | active |
| 61106960/adPEAS adPEAS is a single-file PowerShell tool that automates Active Directory security assessment, enumerating misconfigurations, vulnerabilities… | 99 | 1361 | active |
| Authing/Guard Authing Guard is an embeddable SSO login form widget and UI component library from Authing, an enterprise identity provider. It ships frame… | 67 | 1361 | active |
| aserto-dev/topaz Topaz is an open-source, cloud-native authorization service that provides fine-grained, real-time, policy-based access control for applicat… | 99 | 1360 | active |
| mullvad/gotatun GotaTun is a userspace WireGuard implementation in Rust, forked from Cloudflare's BoringTun, providing both a library and a standalone tunn… | 93 | 1360 | active |
| boku7/Loki Loki is a stage-1 command and control (C2) framework written in Node.js that exploits script-jacking vulnerabilities in Electron applicatio… | 50 | 1360 | active |
| zalexdev/strykerapp StrykerOSS is a free, open-source mobile penetration testing suite for rooted Android devices that bundles network, wireless, and web secur… | 98 | 1359 | active |
| AEPKILL/devtools-detector A TypeScript browser library that detects whether browser DevTools is open. It lets developers trigger actions like crashing the page or lo… | 40 | 1358 | active |
| ossf/best-practices-badge The OpenSSF Best Practices Badge is a web application (BadgeApp) that lets Free/Libre and Open Source Software projects self-certify that t… | 95 | 1357 | active |
| chili-chips-ba/wireguard-fpga An open-source, wire-speed hardware implementation of the WireGuard VPN protocol on a low-cost Artix-7 FPGA, written in Verilog with an ope… | 68 | 1355 | active |
| partout-io/passepartout Passepartout is an OpenVPN and WireGuard VPN client app for iPhone, iPad, Mac, and Apple TV, built on the Partout tunnel framework. It offe… | 95 | 1354 | active |
| xihan123/SignHook SignHook is an Xposed/LSPosed module for Android that spoofs app signature checks by returning a user-configured fake signature when a host… | 83 | 1354 | active |
| pypa/pip-audit pip-audit is a command-line tool that scans Python environments, requirements files, and dependency trees for packages with known security … | 83 | 1354 | active |
| google/nftables A pure Go library for programmatically interacting with Linux nftables, the iptables successor, without wrapping libnftnl. It provides data… | 73 | 1354 | active |
| openconnect/openconnect-gui A graphical VPN client built on the OpenConnect library, supporting Cisco AnyConnect-compatible VPNs. It is a Qt5-based desktop application… | 10 | 1354 | active |
| BullsEye0/shodan-eye Shodan Eye is a Python command-line tool that queries the Shodan search engine to collect information about all devices directly connected … | 75 | 1352 | active |
| fkie-cad/cwe_checker cwe_checker is a Rust-based suite of checks that detects common bug classes (CWEs) such as null pointer dereferences and buffer overflows i… | 67 | 1352 | active |
| LegacyUpdate/LegacyUpdate Legacy Update is a Windows application and companion web service that restores Windows Update functionality, online activation, and Interne… | 86 | 1350 | active |
| MhmRdd/NoHello NoHello is a Zygisk module written in C++ that hides root and Zygisk from Android apps. It supports Magisk, KernelSU, KernelSU Next, and AP… | 33 | 1350 | active |
| koajs/jwt koa-jwt is a Koa middleware for authenticating HTTP requests using JSON Web Tokens. It validates JWTs from headers or cookies and exposes t… | 23 | 1350 | stable |
| go-pkgz/auth A Go library providing authentication via multiple oauth2 providers (GitHub, Google, Facebook, Discord, Telegram, and more), direct credent… | 99 | 1349 | active |
| roottusk/vapi vAPI is a self-hostable deliberately vulnerable API that mimics the OWASP API Security Top 10 scenarios through hands-on exercises. It ship… | 23 | 1349 | active |
| mishakorzik/UserFinder UserFinder is a shell-based OSINT tool that searches for user profiles across social networks and other sites by username. It runs as a sim… | 56 | 1348 | active |
| JoasASantos/NeuroSploit NeuroSploit is an AI-powered penetration testing framework written in Rust that turns a URL, repository, app, or host into an autonomous se… | 85 | 1347 | active |
| moyuwa/ApkCheckPack A Go-based CLI tool that detects APK hardening/packing features from 40+ vendors, plus third-party SDKs, anti-environment checks (ROOT, emu… | 82 | 1347 | active |