domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| yuanyuanxiang/SimpleRemoter SimpleRemoter (YAMA) is a C++ remote control suite derived from the Gh0st RAT codebase, providing remote desktop, file transfer, terminal, … | 60 | 1347 | active |
| cecio/USBvalve USBvalve is a firmware application for cheap RP2040-based hardware (Raspberry Pi Pico) that emulates a fake USB mass-storage filesystem and… | 93 | 1345 | active |
| appneta/tcpreplay Tcpreplay is a suite of GPLv3 command-line utilities for editing and replaying captured network traffic (pcap files) back onto the network … | 98 | 1344 | active |
| JoySafety/JoySafety JoySafety is an open-source large language model safety framework from JD.com, written in Java, providing prompt injection detection, conte… | 47 | 1344 | active |
| projectdiscovery/nuclei-burp-plugin A Burp Suite plugin that helps generate Nuclei vulnerability scanner templates from HTTP requests and responses captured in Burp's Proxy, R… | 44 | 1344 | active |
| WKL-Sec/HiddenDesktop Hidden Desktop is a Cobalt Strike BOF implementation of HVNC (Hidden Virtual Network Computing), letting red team operators interact with a… | 20 | 1343 | active |
| palantir/windows-event-forwarding A Palantir-maintained repository of Windows Event Forwarding (WEF) subscriptions and guidance for centrally collecting security-relevant ev… | 51 | 1342 | active |
| urbanadventurer/Android-PIN-Bruteforce A shell script that turns a rooted Android device running Kali NetHunter into a USB HID keyboard that bruteforces the lockscreen PIN of a l… | 32 | 4782 | maintenance |
| wotschofsky/domain-digger Domain Digger is a web application for in-depth domain analysis, offering DNS lookups across global resolvers, WHOIS queries, IP geolocatio… | 75 | 1340 | active |
| yeswehack/PwnFox PwnFox is a Firefox extension paired with a Burp Suite extension that provides tools for web security audits, such as one-click Burp proxy … | 23 | 1339 | active |
| llm-attacks/llm-attacks Official research code for 'Universal and Transferable Adversarial Attacks on Aligned Language Models', implementing the GCG algorithm for … | 28 | 4769 | maintenance |
| ltb-project/self-service-password Self Service Password is a PHP web application that lets users change and reset their own passwords in an LDAP directory, including Active … | 91 | 1338 | stable |
| MomenSherif/react-oauth A collection of React libraries for OAuth2 authentication, including @react-oauth/google built on Google Identity Services and @react-oauth… | 82 | 1338 | active |
| adamyaxley/Obfuscate A header-only C++14 library that obfuscates string literals at compile time using constexpr XOR encryption with a random 64-bit key, preven… | 63 | 1338 | stable |
| mikker/passwordless Passwordless is a Rails engine that adds magic-link (email-based) authentication to Rails applications without passwords. It provides a ses… | 72 | 1337 | active |
| x364e3ab6/DudeSuite DudeSuite is a lightweight, integrated web penetration testing toolkit distributed as a desktop application for Windows and macOS. It bundl… | 85 | 1336 | active |
| warrant-dev/warrant Warrant is a highly scalable, centralized fine-grained authorization service inspired by Google Zanzibar, written in Go. It lets applicatio… | 46 | 1336 | active |
| php-casbin/php-casbin PHP-Casbin is a powerful and efficient open-source access control library for PHP projects that enforces authorization based on models like… | 98 | 1335 | active |
| CERT-Polska/drakvuf-sandbox DRAKVUF Sandbox is an automated, agentless malware analysis system that runs suspicious files inside a hypervisor-level sandbox powered by … | 87 | 1334 | active |
| F6JO/RouteVulScan RouteVulScan is a Burp Suite extension written in Java that passively and recursively probes each path layer of web traffic for vulnerable … | 82 | 1334 | active |
| ION28/BLUESPAWN BLUESPAWN is an open-source active defense and endpoint detection and response (EDR) tool for Windows. It helps blue teams detect, identify… | 69 | 1334 | active |
| ZupIT/horusec Horusec is an open-source SAST (static application security testing) CLI that scans a project for vulnerabilities across many languages wit… | 67 | 1333 | active |
| qdhenry/Claude-Command-Suite A collection of 216+ slash commands, 12 Claude Code Skills, and 54 specialized AI agents that add structured development workflows to Claud… | 63 | 1333 | active |
| dafthack/GraphRunner GraphRunner is a post-exploitation toolset for interacting with the Microsoft Graph API, written in PowerShell. It enables reconnaissance, … | 62 | 1333 | active |
| silverhack/monkey365 Monkey365 is an open-source PowerShell-based security assessment framework for Microsoft 365, Azure, and Microsoft Entra ID. It collects te… | 97 | 1332 | active |
| SAML-Toolkits/php-saml A PHP library that adds SAML 2.0 support to PHP applications, enabling them to act as a Service Provider for single sign-on with identity p… | 92 | 1331 | stable |
| stripe/smokescreen Smokescreen is an HTTP CONNECT egress proxy written in Go, developed by Stripe to proxy outbound traffic such as webhooks. It enforces host… | 77 | 1331 | active |
| apache/casbin-Casbin.NET Casbin.NET is the .NET (C#) implementation of Apache Casbin, an open-source authorization library that enforces access control via models s… | 95 | 1330 | stable |
| neuvector/neuvector NeuVector is an open-source full lifecycle container security platform providing vulnerability management and automated runtime security wi… | 94 | 1330 | active |
| Shopify/remote-dom Remote DOM is a TypeScript library that synchronizes a tree of DOM elements created in a sandboxed JavaScript environment (like an iframe o… | 89 | 1330 | active |
| cobbr/Covenant Covenant is a collaborative .NET command and control (C2) framework for red teamers, built as an ASP.NET Core cross-platform application wi… | 32 | 4730 | maintenance |
| samyk/evercookie Evercookie is a JavaScript API that creates extremely persistent, respawning 'super' cookies by storing identifiers across a dozen-plus bro… | 39 | 4726 | maintenance |
| backslashxx/mountify Mountify is a shell-based module for rooted Android that mounts other root modules globally via OverlayFS instead of Magic Mount. It works … | 88 | 1328 | active |
| bugbasesecurity/pentest-copilot Pentest Copilot is an open-source, AI-driven penetration testing agent that connects to a Kali attack box, autonomously runs security tools… | 64 | 1327 | active |
| wafinfo/DecryptTools A comprehensive encryption/decryption tool for penetration testers, supporting 22+ decryption schemes for Chinese enterprise software (OA s… | 22 | 1327 | active |
| ly4k/PwnKit A self-contained exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec. It ships as a prebuilt … | 32 | 1326 | stable |
| beakthoven/TrickyStoreOSS A fully open-source Magisk module that spoofs Android hardware keystore attestation, serving as a FOSS rewrite of the proprietary TrickySto… | 85 | 1325 | active |
| sockysec/Telerecon Telerecon is a Python-based OSINT reconnaissance framework for researching and investigating Telegram. It scrapes user profiles, messages, … | 28 | 1324 | active |
| cseroad/Webshell_Generate A JavaFX desktop tool that generates evasive (antivirus-bypassing) webshells in multiple languages, supporting cmd shells and clients like … | 59 | 1323 | active |
| zalando/go-keyring A cross-platform Go library for setting, getting, and deleting secrets in the operating system's native keyring (macOS Keychain, Windows Cr… | 78 | 1321 | active |
| DNSCrypt/encrypted-dns-server A high-performance Rust proxy that lets anyone run their own encrypted DNS server supporting DNSCrypt v2 (including post-quantum), Anonymiz… | 92 | 1320 | active |
| platomav/MEAnalyzer ME Analyzer is a Python command-line tool that parses and identifies Intel Engine (CSME, TXE, SPS, GSC) and Graphics firmware images, repor… | 79 | 1320 | active |
| maqp/tfc Tinfoil Chat (TFC) is a peer-to-peer, end-to-end encrypted messaging system built on Tor onion services and high-assurance hardware archite… | 74 | 1320 | active |
| MrTuxx/SocialPwned SocialPwned is a Python-based OSINT tool that harvests emails published on Instagram, LinkedIn, and Twitter to find credential leaks via Pw… | 10 | 1320 | active |
| msasanmh/DNSveil DNSveil is a Windows-only secure DNS client supporting DNSCrypt, Anonymized DNSCrypt, DoH, DoT, and plain DNS over UDP/TCP, with built-in D… | 60 | 1319 | active |
| kspearrin/Otp.NET Otp.NET is a C# library implementing TOTP (RFC 6238) and HOTP (RFC 4226) one-time password algorithms, available on NuGet. It supports conf… | 54 | 1319 | stable |
| gorhill/uMatrix uMatrix is a browser extension that lets users point-and-click filter network requests by source, destination, and type, acting as a firewa… | 10 | 4686 | maintenance |
| go-webauthn/webauthn A FIDO2-conformant WebAuthn and passkey backend library for Go applications. It implements the Web Authentication specification to enable m… | 94 | 1318 | active |
| test502git/awvs14-scan A Python batch-scanning script built on the Acunetix (AWVS) 14/15 API that automates bulk URL scanning with specialized templates for log4j… | 48 | 1318 | active |
| 0x727/BypassPro BypassPro is a Burp Suite extension written in Java that automates bypass attempts against authorization controls (401/403) and WAFs. It co… | 79 | 1317 | active |
| malaohu/MobaXterm-GenKey A small Python web application that generates license key files to activate MobaXterm, a commercial SSH/terminal client for Windows. It can… | 48 | 1317 | active |
| riverrun/comeonin Comeonin is a specification (behaviours) for password hashing libraries in Elixir, defining Comeonin and Comeonin.PasswordHash behaviours. … | 34 | 1317 | stable |
| iGio90/Dwarf Dwarf is a full-featured multi-architecture, multi-OS debugger built on PyQt5 and Frida, aimed at reverse engineers, security analysts, and… | 32 | 1317 | active |
| sharkdp/binocle Binocle is a graphical tool that visualizes binary data by colorizing bytes according to configurable rules and rendering them as pixels in… | 24 | 1317 | stable |
| cseroad/Exp-Tools A Java-based integrated exploitation tool that bundles proof-of-concept exploits for high-risk vulnerabilities in Chinese enterprise softwa… | 21 | 1316 | active |
| getprobo/probo Probo is an open-source, self-hostable governance, risk, and compliance (GRC) platform for engineering and security teams, covering risk ma… | 84 | 1315 | active |
| nccgroup/singularity Singularity of Origin is a DNS rebinding attack framework that includes a DNS server, a web server, a management UI, and sample attack payl… | 74 | 1315 | active |
| hvac/hvac hvac is a Python 3.x client library for the HashiCorp Vault HTTP API. It lets Python applications authenticate to Vault and read, write, an… | 55 | 1315 | active |
| microsoft/win32-app-isolation Microsoft's repository of tools and documentation for Win32 app isolation, a Windows security feature that contains damage from compromised… | 29 | 1315 | active |
| getdnsapi/stubby Stubby is a local DNS Privacy stub resolver daemon that encrypts DNS queries using DNS-over-TLS (RFC 7858), built on the getdns library. It… | 37 | 1314 | active |
| miscusi-peek/cheatengine-mcp-bridge A bridge that connects AI coding assistants (Claude, Cursor, Copilot) to Cheat Engine via the Model Context Protocol, letting agents read/w… | 60 | 1313 | active |
| colonelpanichacks/flock-you Flock-You is ESP32-S3 firmware that turns a Seeed XIAO ESP32-S3 into a passive 2.4 GHz promiscuous-mode WiFi sniffer for detecting Flock su… | 62 | 1312 | active |
| HXSecurity/DongTai DongTai IAST is an open-source Interactive Application Security Testing platform that detects vulnerabilities in Java (and some Python) app… | 33 | 1312 | active |
| CalebFenton/simplify Simplify is a generic Android deobfuscator that virtually executes Dalvik methods in a sandbox (smalivm) and applies optimizations like con… | 23 | 4657 | maintenance |
| erev0s/VAmPI VAmPI is a deliberately vulnerable REST API built with Flask that implements the OWASP Top 10 vulnerabilities for APIs. It is designed for … | 66 | 1311 | active |
| docker/docker-credential-helpers A suite of Go programs that store Docker login credentials in native platform keystores (e.g., macOS Keychain, Windows Credential Manager, … | 95 | 1310 | active |
| PlumHound/PlumHound PlumHound is a Python CLI reporting engine that wraps BloodHoundAD's Neo4j Cypher queries into consumable security reports for Blue and Pur… | 63 | 1310 | active |
| JailbrokenAI/wallbreaker Wallbreaker is a Claude-Code-style terminal harness for red-teaming LLMs, driving an autonomous agent loop that runs jailbreak attacks (PAI… | 57 | 1310 | active |
| pass-with-high-score/universal-installer Universal Installer is an open-source Android package manager app built with Kotlin and Jetpack Compose that installs APK, APKS, XAPK, and … | 84 | 1309 | active |
| codingo/VHostScan VHostScan is a Python-based virtual host scanner that discovers hidden vhosts on a web server using wordlists, reverse lookups, and catch-a… | 39 | 1309 | active |
| AliyunContainerService/pouch PouchContainer is an open-source, OCI-compliant enterprise-class container engine created by Alibaba Group. It packs, delivers, and runs ap… | 23 | 4644 | maintenance |
| sulab999/AppMessenger AppMessenger is a free cross-platform (Windows/Mac/Linux, Java-based) GUI tool for analyzing mobile application packages including APK (And… | 86 | 1308 | active |
| devise-two-factor/devise-two-factor A minimalist Ruby gem extending Devise with two-factor authentication via TOTP. It integrates with authenticator apps like Google Authentic… | 72 | 1308 | active |
| PentesterFlow/agent PentesterFlow is a terminal-based agentic AI CLI assistant for penetration testers and bug bounty hunters. It orchestrates LLM-driven recon… | 71 | 1308 | active |
| ReSukiSU/ReSukiSU ReSukiSU is a KernelSU-based root solution for Android, forked from SukiSU Ultra with a focus on enhanced stability. It provides kernel-lev… | 69 | 1308 | active |
| davewasmer/devcert A Node.js library that generates trusted SSL/TLS certificates for local HTTPS development. It creates a local certificate authority, regist… | 57 | 1308 | active |
| mozilla/policy-templates A collection of policy templates for centrally deploying and managing Firefox in enterprise environments such as businesses, schools, and p… | 98 | 1307 | active |
| stackrox/stackrox StackRox is a Kubernetes security platform that performs risk analysis of container environments, delivers visibility and runtime alerts, a… | 95 | 1306 | active |
| freelabz/secator secator is a task and workflow runner for security assessments that unifies dozens of well-known security tools (subfinder, httpx, ffuf, nm… | 93 | 1306 | active |
| hephaest0s/usbkill usbkill is a Python-based anti-forensic kill-switch daemon that monitors USB ports and immediately shuts down the computer when any USB cha… | 32 | 4631 | maintenance |
| Albert-Weasker/niubi_guard An open-source defense system that protects GitHub repositories from spam, harassment, and coordinated abuse via configurable detection sig… | 65 | 1305 | active |
| tg123/sshpiper sshpiper is a reverse proxy for SSH that routes incoming SSH/SCP connections to upstream servers, with pluggable authentication mapping and… | 94 | 1304 | active |
| demisto/content The official content repository for Cortex XSOAR (formerly Demisto), a security orchestration, automation and response (SOAR) platform. It … | 68 | 1304 | active |
| Vector35/binaryninja-api The public API, examples, and documentation for Binary Ninja, a commercial reverse engineering platform. It provides C++, Python, and Rust … | 95 | 1303 | active |
| jamesmcm/vopono Vopono is a Rust CLI tool that runs individual applications through VPN tunnels using temporary network namespaces on Linux. It supports mu… | 95 | 1303 | active |
| JFreegman/toxic Toxic is a terminal-based (ncurses) instant messaging client for the Tox peer-to-peer network, offering end-to-end encrypted text chat, fil… | 86 | 1303 | active |
| google/longfellow-zk A C++ library from Google implementing zero-knowledge proof protocols for identity verification, supporting standards like ISO MDOC, JWT, a… | 75 | 1303 | active |
| codingo/Interlace Interlace is a Python CLI tool that wraps single-threaded command-line applications and runs them in parallel across many targets, adding C… | 41 | 1303 | active |
| GoogleCloudPlatform/berglas Berglas is a command line tool and Go library for managing secrets on Google Cloud, encrypting them with Cloud KMS and storing them in Clou… | 94 | 1302 | active |
| lanyi1998/DNSlog-GO DNSLog-GO is a self-hosted tool written in Go that monitors DNS resolution records, with a built-in web interface and API mode. It supports… | 83 | 1302 | active |
| 0xInfection/XSRFProbe XSRFProbe is a Python-based Cross Site Request Forgery (CSRF/XSRF) audit and exploitation toolkit. It crawls web applications, runs systema… | 82 | 1302 | stable |
| Bitcoin-ABC/bitcoin-abc Bitcoin ABC is the reference full-node software implementation for the eCash (XEC) cryptocurrency, forked from Bitcoin Core. It enables pee… | 100 | 1301 | active |
| Marven11/Fenjing Fenjing is an automated Jinja2 SSTI (server-side template injection) exploitation tool designed for CTF competitions. It automatically anal… | 87 | 1301 | active |
| dwisiswant0/go-dork go-dork is a fast command-line dork scanner written in Go that automates Google dorking across multiple search engines. It supports Google,… | 23 | 1301 | stable |
| sighook/pixload pixload is a set of Perl CLI tools for creating and injecting payloads into image files (BMP, GIF, JPG, PNG, WebP). It is used in offensive… | 23 | 1300 | active |
| rootless-containers/rootlesskit RootlessKit is a Linux-native 'fake root' tool that uses user and mount namespaces to let unprivileged users run container engines like Doc… | 94 | 1299 | active |
| RedTeamPentesting/pretender Pretender is a Go-based penetration testing tool that gains machine-in-the-middle positions via spoofed local name resolution (mDNS, LLMNR,… | 92 | 1299 | active |
| httpsok/httpsok httpsok is a shell-based SSL/TLS certificate auto-renewal tool designed for Nginx, OpenResty, and Apache servers, paired with a hosted web … | 60 | 1298 | active |
| LSPosed/DisableFlagSecure An LSPosed/Xposed module that enables screenshots in apps that block them via FLAG_SECURE and disables screenshot and screen-record detecti… | 83 | 1297 | active |
| dromara/orion-visor Orion Visor is a modern, self-hosted automation operations and lightweight bastion host platform built with Java and Vue. It provides unifi… | 70 | 1297 | active |