Ross ROSS = Recommend OSS · open-source software intelligence for agents

domain: security

4787 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
yuanyuanxiang/SimpleRemoter
SimpleRemoter (YAMA) is a C++ remote control suite derived from the Gh0st RAT codebase, providing remote desktop, file transfer, terminal, …
601347active
cecio/USBvalve
USBvalve is a firmware application for cheap RP2040-based hardware (Raspberry Pi Pico) that emulates a fake USB mass-storage filesystem and…
931345active
appneta/tcpreplay
Tcpreplay is a suite of GPLv3 command-line utilities for editing and replaying captured network traffic (pcap files) back onto the network …
981344active
JoySafety/JoySafety
JoySafety is an open-source large language model safety framework from JD.com, written in Java, providing prompt injection detection, conte…
471344active
projectdiscovery/nuclei-burp-plugin
A Burp Suite plugin that helps generate Nuclei vulnerability scanner templates from HTTP requests and responses captured in Burp's Proxy, R…
441344active
WKL-Sec/HiddenDesktop
Hidden Desktop is a Cobalt Strike BOF implementation of HVNC (Hidden Virtual Network Computing), letting red team operators interact with a…
201343active
palantir/windows-event-forwarding
A Palantir-maintained repository of Windows Event Forwarding (WEF) subscriptions and guidance for centrally collecting security-relevant ev…
511342active
urbanadventurer/Android-PIN-Bruteforce
A shell script that turns a rooted Android device running Kali NetHunter into a USB HID keyboard that bruteforces the lockscreen PIN of a l…
324782maintenance
wotschofsky/domain-digger
Domain Digger is a web application for in-depth domain analysis, offering DNS lookups across global resolvers, WHOIS queries, IP geolocatio…
751340active
yeswehack/PwnFox
PwnFox is a Firefox extension paired with a Burp Suite extension that provides tools for web security audits, such as one-click Burp proxy …
231339active
llm-attacks/llm-attacks
Official research code for 'Universal and Transferable Adversarial Attacks on Aligned Language Models', implementing the GCG algorithm for …
284769maintenance
ltb-project/self-service-password
Self Service Password is a PHP web application that lets users change and reset their own passwords in an LDAP directory, including Active …
911338stable
MomenSherif/react-oauth
A collection of React libraries for OAuth2 authentication, including @react-oauth/google built on Google Identity Services and @react-oauth…
821338active
adamyaxley/Obfuscate
A header-only C++14 library that obfuscates string literals at compile time using constexpr XOR encryption with a random 64-bit key, preven…
631338stable
mikker/passwordless
Passwordless is a Rails engine that adds magic-link (email-based) authentication to Rails applications without passwords. It provides a ses…
721337active
x364e3ab6/DudeSuite
DudeSuite is a lightweight, integrated web penetration testing toolkit distributed as a desktop application for Windows and macOS. It bundl…
851336active
warrant-dev/warrant
Warrant is a highly scalable, centralized fine-grained authorization service inspired by Google Zanzibar, written in Go. It lets applicatio…
461336active
php-casbin/php-casbin
PHP-Casbin is a powerful and efficient open-source access control library for PHP projects that enforces authorization based on models like…
981335active
CERT-Polska/drakvuf-sandbox
DRAKVUF Sandbox is an automated, agentless malware analysis system that runs suspicious files inside a hypervisor-level sandbox powered by …
871334active
F6JO/RouteVulScan
RouteVulScan is a Burp Suite extension written in Java that passively and recursively probes each path layer of web traffic for vulnerable …
821334active
ION28/BLUESPAWN
BLUESPAWN is an open-source active defense and endpoint detection and response (EDR) tool for Windows. It helps blue teams detect, identify…
691334active
ZupIT/horusec
Horusec is an open-source SAST (static application security testing) CLI that scans a project for vulnerabilities across many languages wit…
671333active
qdhenry/Claude-Command-Suite
A collection of 216+ slash commands, 12 Claude Code Skills, and 54 specialized AI agents that add structured development workflows to Claud…
631333active
dafthack/GraphRunner
GraphRunner is a post-exploitation toolset for interacting with the Microsoft Graph API, written in PowerShell. It enables reconnaissance, …
621333active
silverhack/monkey365
Monkey365 is an open-source PowerShell-based security assessment framework for Microsoft 365, Azure, and Microsoft Entra ID. It collects te…
971332active
SAML-Toolkits/php-saml
A PHP library that adds SAML 2.0 support to PHP applications, enabling them to act as a Service Provider for single sign-on with identity p…
921331stable
stripe/smokescreen
Smokescreen is an HTTP CONNECT egress proxy written in Go, developed by Stripe to proxy outbound traffic such as webhooks. It enforces host…
771331active
apache/casbin-Casbin.NET
Casbin.NET is the .NET (C#) implementation of Apache Casbin, an open-source authorization library that enforces access control via models s…
951330stable
neuvector/neuvector
NeuVector is an open-source full lifecycle container security platform providing vulnerability management and automated runtime security wi…
941330active
Shopify/remote-dom
Remote DOM is a TypeScript library that synchronizes a tree of DOM elements created in a sandboxed JavaScript environment (like an iframe o…
891330active
cobbr/Covenant
Covenant is a collaborative .NET command and control (C2) framework for red teamers, built as an ASP.NET Core cross-platform application wi…
324730maintenance
samyk/evercookie
Evercookie is a JavaScript API that creates extremely persistent, respawning 'super' cookies by storing identifiers across a dozen-plus bro…
394726maintenance
backslashxx/mountify
Mountify is a shell-based module for rooted Android that mounts other root modules globally via OverlayFS instead of Magic Mount. It works …
881328active
bugbasesecurity/pentest-copilot
Pentest Copilot is an open-source, AI-driven penetration testing agent that connects to a Kali attack box, autonomously runs security tools…
641327active
wafinfo/DecryptTools
A comprehensive encryption/decryption tool for penetration testers, supporting 22+ decryption schemes for Chinese enterprise software (OA s…
221327active
ly4k/PwnKit
A self-contained exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec. It ships as a prebuilt …
321326stable
beakthoven/TrickyStoreOSS
A fully open-source Magisk module that spoofs Android hardware keystore attestation, serving as a FOSS rewrite of the proprietary TrickySto…
851325active
sockysec/Telerecon
Telerecon is a Python-based OSINT reconnaissance framework for researching and investigating Telegram. It scrapes user profiles, messages, …
281324active
cseroad/Webshell_Generate
A JavaFX desktop tool that generates evasive (antivirus-bypassing) webshells in multiple languages, supporting cmd shells and clients like …
591323active
zalando/go-keyring
A cross-platform Go library for setting, getting, and deleting secrets in the operating system's native keyring (macOS Keychain, Windows Cr…
781321active
DNSCrypt/encrypted-dns-server
A high-performance Rust proxy that lets anyone run their own encrypted DNS server supporting DNSCrypt v2 (including post-quantum), Anonymiz…
921320active
platomav/MEAnalyzer
ME Analyzer is a Python command-line tool that parses and identifies Intel Engine (CSME, TXE, SPS, GSC) and Graphics firmware images, repor…
791320active
maqp/tfc
Tinfoil Chat (TFC) is a peer-to-peer, end-to-end encrypted messaging system built on Tor onion services and high-assurance hardware archite…
741320active
MrTuxx/SocialPwned
SocialPwned is a Python-based OSINT tool that harvests emails published on Instagram, LinkedIn, and Twitter to find credential leaks via Pw…
101320active
msasanmh/DNSveil
DNSveil is a Windows-only secure DNS client supporting DNSCrypt, Anonymized DNSCrypt, DoH, DoT, and plain DNS over UDP/TCP, with built-in D…
601319active
kspearrin/Otp.NET
Otp.NET is a C# library implementing TOTP (RFC 6238) and HOTP (RFC 4226) one-time password algorithms, available on NuGet. It supports conf…
541319stable
gorhill/uMatrix
uMatrix is a browser extension that lets users point-and-click filter network requests by source, destination, and type, acting as a firewa…
104686maintenance
go-webauthn/webauthn
A FIDO2-conformant WebAuthn and passkey backend library for Go applications. It implements the Web Authentication specification to enable m…
941318active
test502git/awvs14-scan
A Python batch-scanning script built on the Acunetix (AWVS) 14/15 API that automates bulk URL scanning with specialized templates for log4j…
481318active
0x727/BypassPro
BypassPro is a Burp Suite extension written in Java that automates bypass attempts against authorization controls (401/403) and WAFs. It co…
791317active
malaohu/MobaXterm-GenKey
A small Python web application that generates license key files to activate MobaXterm, a commercial SSH/terminal client for Windows. It can…
481317active
riverrun/comeonin
Comeonin is a specification (behaviours) for password hashing libraries in Elixir, defining Comeonin and Comeonin.PasswordHash behaviours. …
341317stable
iGio90/Dwarf
Dwarf is a full-featured multi-architecture, multi-OS debugger built on PyQt5 and Frida, aimed at reverse engineers, security analysts, and…
321317active
sharkdp/binocle
Binocle is a graphical tool that visualizes binary data by colorizing bytes according to configurable rules and rendering them as pixels in…
241317stable
cseroad/Exp-Tools
A Java-based integrated exploitation tool that bundles proof-of-concept exploits for high-risk vulnerabilities in Chinese enterprise softwa…
211316active
getprobo/probo
Probo is an open-source, self-hostable governance, risk, and compliance (GRC) platform for engineering and security teams, covering risk ma…
841315active
nccgroup/singularity
Singularity of Origin is a DNS rebinding attack framework that includes a DNS server, a web server, a management UI, and sample attack payl…
741315active
hvac/hvac
hvac is a Python 3.x client library for the HashiCorp Vault HTTP API. It lets Python applications authenticate to Vault and read, write, an…
551315active
microsoft/win32-app-isolation
Microsoft's repository of tools and documentation for Win32 app isolation, a Windows security feature that contains damage from compromised…
291315active
getdnsapi/stubby
Stubby is a local DNS Privacy stub resolver daemon that encrypts DNS queries using DNS-over-TLS (RFC 7858), built on the getdns library. It…
371314active
miscusi-peek/cheatengine-mcp-bridge
A bridge that connects AI coding assistants (Claude, Cursor, Copilot) to Cheat Engine via the Model Context Protocol, letting agents read/w…
601313active
colonelpanichacks/flock-you
Flock-You is ESP32-S3 firmware that turns a Seeed XIAO ESP32-S3 into a passive 2.4 GHz promiscuous-mode WiFi sniffer for detecting Flock su…
621312active
HXSecurity/DongTai
DongTai IAST is an open-source Interactive Application Security Testing platform that detects vulnerabilities in Java (and some Python) app…
331312active
CalebFenton/simplify
Simplify is a generic Android deobfuscator that virtually executes Dalvik methods in a sandbox (smalivm) and applies optimizations like con…
234657maintenance
erev0s/VAmPI
VAmPI is a deliberately vulnerable REST API built with Flask that implements the OWASP Top 10 vulnerabilities for APIs. It is designed for …
661311active
docker/docker-credential-helpers
A suite of Go programs that store Docker login credentials in native platform keystores (e.g., macOS Keychain, Windows Credential Manager, …
951310active
PlumHound/PlumHound
PlumHound is a Python CLI reporting engine that wraps BloodHoundAD's Neo4j Cypher queries into consumable security reports for Blue and Pur…
631310active
JailbrokenAI/wallbreaker
Wallbreaker is a Claude-Code-style terminal harness for red-teaming LLMs, driving an autonomous agent loop that runs jailbreak attacks (PAI…
571310active
pass-with-high-score/universal-installer
Universal Installer is an open-source Android package manager app built with Kotlin and Jetpack Compose that installs APK, APKS, XAPK, and …
841309active
codingo/VHostScan
VHostScan is a Python-based virtual host scanner that discovers hidden vhosts on a web server using wordlists, reverse lookups, and catch-a…
391309active
AliyunContainerService/pouch
PouchContainer is an open-source, OCI-compliant enterprise-class container engine created by Alibaba Group. It packs, delivers, and runs ap…
234644maintenance
sulab999/AppMessenger
AppMessenger is a free cross-platform (Windows/Mac/Linux, Java-based) GUI tool for analyzing mobile application packages including APK (And…
861308active
devise-two-factor/devise-two-factor
A minimalist Ruby gem extending Devise with two-factor authentication via TOTP. It integrates with authenticator apps like Google Authentic…
721308active
PentesterFlow/agent
PentesterFlow is a terminal-based agentic AI CLI assistant for penetration testers and bug bounty hunters. It orchestrates LLM-driven recon…
711308active
ReSukiSU/ReSukiSU
ReSukiSU is a KernelSU-based root solution for Android, forked from SukiSU Ultra with a focus on enhanced stability. It provides kernel-lev…
691308active
davewasmer/devcert
A Node.js library that generates trusted SSL/TLS certificates for local HTTPS development. It creates a local certificate authority, regist…
571308active
mozilla/policy-templates
A collection of policy templates for centrally deploying and managing Firefox in enterprise environments such as businesses, schools, and p…
981307active
stackrox/stackrox
StackRox is a Kubernetes security platform that performs risk analysis of container environments, delivers visibility and runtime alerts, a…
951306active
freelabz/secator
secator is a task and workflow runner for security assessments that unifies dozens of well-known security tools (subfinder, httpx, ffuf, nm…
931306active
hephaest0s/usbkill
usbkill is a Python-based anti-forensic kill-switch daemon that monitors USB ports and immediately shuts down the computer when any USB cha…
324631maintenance
Albert-Weasker/niubi_guard
An open-source defense system that protects GitHub repositories from spam, harassment, and coordinated abuse via configurable detection sig…
651305active
tg123/sshpiper
sshpiper is a reverse proxy for SSH that routes incoming SSH/SCP connections to upstream servers, with pluggable authentication mapping and…
941304active
demisto/content
The official content repository for Cortex XSOAR (formerly Demisto), a security orchestration, automation and response (SOAR) platform. It …
681304active
Vector35/binaryninja-api
The public API, examples, and documentation for Binary Ninja, a commercial reverse engineering platform. It provides C++, Python, and Rust …
951303active
jamesmcm/vopono
Vopono is a Rust CLI tool that runs individual applications through VPN tunnels using temporary network namespaces on Linux. It supports mu…
951303active
JFreegman/toxic
Toxic is a terminal-based (ncurses) instant messaging client for the Tox peer-to-peer network, offering end-to-end encrypted text chat, fil…
861303active
google/longfellow-zk
A C++ library from Google implementing zero-knowledge proof protocols for identity verification, supporting standards like ISO MDOC, JWT, a…
751303active
codingo/Interlace
Interlace is a Python CLI tool that wraps single-threaded command-line applications and runs them in parallel across many targets, adding C…
411303active
GoogleCloudPlatform/berglas
Berglas is a command line tool and Go library for managing secrets on Google Cloud, encrypting them with Cloud KMS and storing them in Clou…
941302active
lanyi1998/DNSlog-GO
DNSLog-GO is a self-hosted tool written in Go that monitors DNS resolution records, with a built-in web interface and API mode. It supports…
831302active
0xInfection/XSRFProbe
XSRFProbe is a Python-based Cross Site Request Forgery (CSRF/XSRF) audit and exploitation toolkit. It crawls web applications, runs systema…
821302stable
Bitcoin-ABC/bitcoin-abc
Bitcoin ABC is the reference full-node software implementation for the eCash (XEC) cryptocurrency, forked from Bitcoin Core. It enables pee…
1001301active
Marven11/Fenjing
Fenjing is an automated Jinja2 SSTI (server-side template injection) exploitation tool designed for CTF competitions. It automatically anal…
871301active
dwisiswant0/go-dork
go-dork is a fast command-line dork scanner written in Go that automates Google dorking across multiple search engines. It supports Google,…
231301stable
sighook/pixload
pixload is a set of Perl CLI tools for creating and injecting payloads into image files (BMP, GIF, JPG, PNG, WebP). It is used in offensive…
231300active
rootless-containers/rootlesskit
RootlessKit is a Linux-native 'fake root' tool that uses user and mount namespaces to let unprivileged users run container engines like Doc…
941299active
RedTeamPentesting/pretender
Pretender is a Go-based penetration testing tool that gains machine-in-the-middle positions via spoofed local name resolution (mDNS, LLMNR,…
921299active
httpsok/httpsok
httpsok is a shell-based SSL/TLS certificate auto-renewal tool designed for Nginx, OpenResty, and Apache servers, paired with a hosted web …
601298active
LSPosed/DisableFlagSecure
An LSPosed/Xposed module that enables screenshots in apps that block them via FLAG_SECURE and disables screenshot and screen-record detecti…
831297active
dromara/orion-visor
Orion Visor is a modern, self-hosted automation operations and lightweight bastion host platform built with Java and Vue. It provides unifi…
701297active

← prev page 24 / 48 next →