domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Rurik/Noriben Noriben is a Python script that wraps Sysinternals Procmon to automatically collect, analyze, and report runtime indicators of malware, pro… | 56 | 1297 | stable |
| XiaoliChan/wmiexec-Pro wmiexec-Pro is a Python CLI tool built on Impacket that provides an enhanced version of wmiexec.py for remote command execution on Windows … | 67 | 1295 | active |
| pillarjs/cookies A Node.js module for getting and setting HTTP(S) cookies, with optional signing to prevent tampering via Keygrip. It works with the built-i… | 61 | 1295 | stable |
| pahaz/sshtunnel A pure Python library for creating SSH tunnels and TCP port forwarding through remote servers, built on paramiko. It lets applications prog… | 40 | 1295 | stable |
| h4r5h1t/webcopilot WebCopilot is a Bash-based automation script for bug bounty reconnaissance that enumerates subdomains using multiple tools, filters paramet… | 23 | 1295 | active |
| n0xa/m5stick-nemo NEMO is a firmware for M5Stack ESP32 devices (M5StickC, Cardputer) that implements high-tech pranks and digital self-defense tools such as … | 89 | 1294 | active |
| qwqdanchun/Pillager Pillager is a C# post-exploitation information gathering tool that exports and decrypts sensitive data from target Windows machines, includ… | 20 | 1294 | active |
| hausec/PowerZure PowerZure is a PowerShell framework for assessing and exploiting resources in Microsoft Azure and Entra ID. It provides both reconnaissance… | 53 | 1293 | active |
| waiting-for-dev/devise-jwt A Ruby gem that extends Devise to authenticate Rails users with JWT tokens instead of cookies, built as a thin layer over warden-jwt_auth. … | 72 | 1292 | active |
| sebadob/rauthy Rauthy is a lightweight, Rust-based Identity Provider offering Single Sign-On via OpenID Connect, OAuth 2, and PAM, with strong emphasis on… | 95 | 1291 | active |
| passff/passff PassFF is a Mozilla Firefox extension that provides browser access to a zx2c4 pass password store. It can list, fill, and submit login form… | 60 | 1291 | active |
| nette/latte Latte is a secure, intuitive templating engine for PHP featuring context-sensitive escaping that automatically protects against XSS vulnera… | 96 | 1290 | stable |
| google/crosvm crosvm is a secure, lightweight Virtual Machine Monitor (VMM) written in Rust, originally built for ChromeOS to run Linux and Android guest… | 77 | 1290 | active |
| BishopFox/eyeballer Eyeballer is a convolutional neural network tool that classifies screenshots of web hosts taken during large-scope penetration tests. It la… | 55 | 1290 | active |
| knavesec/CredMaster CredMaster is a Python CLI tool for password spraying and brute-force attacks that rotates the source IP address on every authentication at… | 38 | 1290 | active |
| HaveIBeenPwned/PwnedPasswordsDownloader A .NET global tool that downloads the complete Pwned Passwords SHA1 and NTLM hash ranges for offline use, removing the need to query the k-… | 76 | 1289 | active |
| miguelgrinberg/Flask-HTTPAuth Flask-HTTPAuth is a Flask extension that adds HTTP authentication to routes, supporting Basic, Digest, and Token schemes. It provides decor… | 73 | 1289 | stable |
| Te-k/harpoon Harpoon is a Python CLI tool that aggregates open source intelligence and threat intelligence lookups across many services (Censys, crt.sh,… | 70 | 1289 | active |
| a2o/snoopy Snoopy is a small C library that logs every program execution on Linux/BSD systems, typically via a shared library loaded through the dynam… | 55 | 1289 | stable |
| utkusen/sast-skills A collection of LLM agent skills that turn coding assistants like Claude Code, Codex, Opencode, and Cursor into a SAST (static application … | 49 | 1289 | active |
| royhills/arp-scan arp-scan is a command-line network scanning tool that uses ARP requests to discover and fingerprint IPv4 hosts on a local network. It is wr… | 27 | 1289 | active |
| blueimp/JavaScript-MD5 A zero-dependency JavaScript implementation of the MD5 hash algorithm, supporting hex-encoded and raw MD5 as well as HMAC-MD5. It works in … | 10 | 4559 | maintenance |
| P1-Team/AlliN AlliN is a flexible, dependency-free Python scanner designed to assist penetration testing projects, especially lateral movement and intran… | 40 | 1288 | active |
| RickdeJager/stegseek Stegseek is a lightning-fast command-line cracker for steghide steganography, built as a fork of the original steghide project that can tes… | 23 | 1288 | stable |
| tiann/epic Epic is a dynamic Java method AOP hooking library for Android, continuing Dexposed on the ART runtime and supporting Android 5.0 through 11… | 23 | 4554 | maintenance |
| domainaware/parsedmarc parsedmarc is a Python module and CLI utility for parsing aggregate (rua), failure (ruf), and SMTP TLS reporting email authentication repor… | 99 | 1286 | active |
| shizunge/endlessh-go A Go implementation of endlessh, an SSH tarpit that traps brute-force attackers by sending an endless SSH banner, while exporting Prometheu… | 87 | 1286 | active |
| corkami/mitra Mitra is a Python CLI tool that generates weird files such as binary polyglots, near-polyglots, polymocks, parasites, and zippers across ma… | 32 | 1286 | active |
| ProbiusOfficial/CTF-OS CTF-OS is a preconfigured virtual machine image purpose-built for Capture The Flag (CTF) competitions, bundling a curated set of security a… | 32 | 1286 | active |
| jvdsn/crypto-attacks A collection of Python implementations of cryptographic attacks and utilities, built on SageMath and PyCryptodome. It covers attacks agains… | 60 | 1285 | active |
| owenthereal/upterm Upterm is an open-source CLI tool for instantly sharing terminal sessions over secure SSH tunnels to the public internet. It supports remot… | 92 | 1284 | active |
| SafeBreach-Labs/PoolParty PoolParty is a C++ command-line tool implementing eight novel, fully-undetectable process injection techniques that abuse Windows Thread Po… | 20 | 1284 | active |
| juliansteenbakker/flutter_secure_storage A Flutter plugin for securely storing sensitive key-value data using platform-specific encrypted storage such as iOS/macOS Keychain, Androi… | 98 | 1282 | active |
| bit4woo/Fiora Fiora is a graphical interface for the Nuclei vulnerability PoC framework, enabling quick PoC search and one-click execution of Nuclei scan… | 57 | 1282 | active |
| verida/verida-js The official TypeScript SDK monorepo for the Verida Network, a decentralized network for self-sovereign identity and encrypted personal dat… | 39 | 1282 | active |
| google/secrets-gradle-plugin A Gradle plugin by Google that injects secrets from a properties file (like local.properties) not checked into version control into BuildCo… | 23 | 1282 | stable |
| owasp-dep-scan/dep-scan OWASP dep-scan is a security and risk audit CLI tool that scans project dependencies in local repositories and container images for known C… | 97 | 1281 | active |
| larlarua/AutoCVE AutoCVE is a self-hosted multi-agent platform that automates CVE discovery: it filters target projects, imports repositories, audits source… | 77 | 1280 | active |
| keepassx/keepassx KeePassX is a cross-platform desktop password manager that stores credentials and other sensitive data in an encrypted database compatible … | 10 | 4523 | maintenance |
| 520CCC/AIGenerateCode A Java-based tool suite for Android that generates junk code (Java, drawables, layouts, strings, manifests) and ProGuard obfuscation files … | 37 | 1279 | active |
| gaasedelen/patching An interactive binary patching plugin for IDA Pro that adds a robust in-disassembler workflow for editing assembly instructions. It support… | 23 | 1279 | active |
| roro2239/Stellar Stellar is a deeply customized fork of Shizuku, an Android framework that lets apps use system-level APIs via ADB wireless debugging or Roo… | 82 | 1277 | active |
| SanMuzZzZz/LuaN1aoAgent LuaN1aoAgent is an autonomous AI-driven penetration testing agent built in TypeScript on the Pi SDK, using graph-based cognitive reasoning … | 81 | 1276 | active |
| sardanioss/httpcloak httpcloak is a Go HTTP client library that reproduces browser-identical TLS, HTTP/2, and HTTP/3 fingerprints (JA3/JA4, Akamai, header order… | 61 | 1276 | active |
| icyguider/Shhhloader Shhhloader is a Python-based builder that compiles C++ shellcode loader stubs designed to bypass AV/EDR on Windows. It supports multiple sh… | 32 | 1276 | active |
| zhuifengshaonianhanlu/pikachu Pikachu is a deliberately vulnerable PHP/MySQL web application designed as a practice range for learning web security and penetration testi… | 71 | 4504 | maintenance |
| jenssegers/optimus A PHP library that obfuscates internal integer IDs using Knuth's multiplicative hashing, producing reversible obfuscated integers instead o… | 23 | 1275 | stable |
| freeipa/freeipa FreeIPA is an integrated security information management solution providing centralized identity, authentication, and access control for Li… | 77 | 1274 | stable |
| mategol/PySilon PySilon is an open-source remote access trojan (RAT) written in Python that is controlled through Discord as its command-and-control channe… | 61 | 1271 | active |
| W01fh4cker/VcenterKit A comprehensive penetration testing toolkit targeting VMware vCenter, bundling exploitation modules for known CVEs such as CVE-2021-21972, … | 42 | 1270 | active |
| macadmins/nudge Nudge is a Swift/SwiftUI macOS application that strongly encourages users to install macOS security updates through customizable, multiling… | 86 | 1269 | active |
| tklengyel/drakvuf DRAKVUF is a virtualization-based, agentless black-box binary analysis system that traces execution of arbitrary binaries, kernels, and fir… | 66 | 1268 | active |
| pinterest/knox Knox is a self-hosted secret management service written in Go that stores, serves, and rotates secrets, keys, and credentials used by other… | 64 | 1268 | active |
| xploitstech/Xteam Xteam is an all-in-one, menu-driven hacking toolkit written in Python and launched via bash scripts, bundling Instagram information gatheri… | 42 | 1268 | active |
| DimitarPetrov/stegify stegify is a Go command line tool and library for LSB (Least Significant Bit) steganography that hides any file inside images such as PNG a… | 23 | 1267 | stable |
| UndeadSec/EvilURL EvilURL is a Python CLI tool that generates Unicode (IDN) domain permutations used in homograph attacks, where look-alike characters trick … | 10 | 1267 | active |
| Athena-OS/athena Athena OS is an Arch/Nix-based Linux distribution focused on cybersecurity and penetration testing, available as ISO, Docker images, and WS… | 83 | 1266 | active |
| netlify/gotrue GoTrue is a small open-source API written in Go that handles user registration, authentication, and user management for APIs and Jamstack p… | 65 | 4462 | maintenance |
| kpcyrd/sniffglue A secure multithreaded network packet sniffer written in Rust that parses packets concurrently across all CPU cores. It is hardened with se… | 72 | 1265 | active |
| mozillazg/ptcpdump ptcpdump is a tcpdump-compatible packet analyzer built on eBPF that automatically annotates captured packets with process, container, and K… | 77 | 1264 | active |
| edoardottt/scilla Scilla is a Go-based command-line information gathering (recon) tool for penetration testers and bug bounty hunters. It enumerates DNS reco… | 80 | 1262 | active |
| starkscan/starkscan-verifier A command-line tool (npm package 'starkscan') that verifies Cairo smart contract ABIs on the Starkscan block explorer for Starknet. Verific… | 32 | 1261 | active |
| VirusTotal/yara-x YARA-X is a pure Rust rewrite of YARA, the pattern matching swiss knife for malware researchers, designed to be faster, safer, and more use… | 99 | 1260 | stable |
| jazzband/django-rest-knox django-rest-knox is a token-based authentication library for Django REST Framework that improves on DRF's built-in TokenAuthentication. It … | 86 | 1259 | active |
| selfxyz/self Self is an open-source monorepo for a privacy-preserving identity verification platform that lets users generate zero-knowledge proofs from… | 73 | 1259 | active |
| 3xpl01tc0d3r/ProcessInjection A C# command-line tool that demonstrates and performs multiple Windows process injection techniques, including DLL injection, process hollo… | 48 | 1259 | active |
| step-security/harden-runner Harden-Runner is a CI/CD security agent that acts like an EDR for GitHub Actions runners, monitoring network egress, file integrity, and pr… | 98 | 1258 | active |
| cybersecsi/houdini HOUDINI is a curated catalog of hundreds of Docker images for network security and intrusion testing tools, presented through a searchable … | 47 | 1258 | active |
| WICG/webpackage A collection of IETF/WICG specifications and Go tooling for packaging websites into portable bundles, including Signed HTTP Exchanges (SXG)… | 72 | 1257 | active |
| btcsuite/btcwallet btcwallet is a secure hierarchical deterministic (HD) bitcoin wallet daemon written in Go. It acts as an RPC client to a btcd full node and… | 67 | 1256 | active |
| RoganDawes/P4wnP1_aloa P4wnP1 A.L.O.A. is a framework that turns a Raspberry Pi Zero W into a low-cost offensive security appliance for pentesting, red teaming, a… | 23 | 4422 | maintenance |
| google/re2j RE2/J is a pure Java port of Google's RE2 regular expression engine that guarantees linear-time matching using a nondeterministic finite au… | 60 | 1255 | active |
| SychicBoy/NETReactorSlayer NETReactorSlayer is an open-source (GPLv3) deobfuscator and unpacker targeting assemblies protected with Eziriz .NET Reactor. It is availab… | 23 | 1255 | active |
| CodeIntelligenceTesting/jazzer Jazzer is a coverage-guided, in-process fuzz testing engine for the JVM, based on libFuzzer. It integrates with JUnit 5 and build tools lik… | 86 | 1254 | active |
| roryclear/clearcam Clearcam is a self-hosted Python NVR that adds AI object detection, tracking, mobile notifications, and semantic search to any RTSP securit… | 86 | 1254 | active |
| utkusen/promptmap promptmap2 is an automated prompt injection scanner for custom LLM applications, supporting white-box testing of system prompts and black-b… | 53 | 1254 | active |
| pry0cc/axiom Axiom is a dynamic infrastructure framework for spinning up disposable multi-cloud instances pre-loaded with security scanning tools like n… | 23 | 4415 | maintenance |
| retlehs/quien quien is a Go CLI and interactive TUI that replaces whois with a tabbed domain and IP intelligence tool covering WHOIS/RDAP, DNS, mail auth… | 74 | 1253 | active |
| genodelabs/genode Genode is an open-source C++ framework for building highly secure, component-based operating systems using capability-based security and a … | 10 | 1253 | active |
| Nerzal/gocloak gocloak is a Go client library for the Keycloak Admin and authentication APIs. It lets Go applications log in users and admins, manage user… | 96 | 1251 | active |
| relative/synchrony Synchrony is a JavaScript deobfuscator and cleaner focused on undoing obfuscation from javascript-obfuscator/obfuscator.io. It works as a C… | 82 | 1250 | active |
| facebook/mariana-trench Mariana Trench is a security-focused static analysis platform for Android and Java applications, built by Meta on the SPARTA and Redex infr… | 77 | 1250 | active |
| markets/invisible_captcha A Ruby gem providing unobtrusive spam protection for Rails applications using honeypot techniques. It adds hidden form fields that bots fil… | 74 | 1250 | active |
| psanford/wormhole-william A Go implementation of the magic wormhole protocol providing end-to-end encrypted transfer of text, files, and directories between computer… | 39 | 1248 | active |
| obfuscator-llvm/obfuscator Obfuscator-LLVM is a fork of the LLVM compiler infrastructure that adds code obfuscation passes for software protection. It transforms comp… | 32 | 4389 | maintenance |
| wh1t3p1g/ysomap Ysomap is a Java deserialization exploit framework that lets users dynamically configure gadget chain payloads with different execution eff… | 26 | 1247 | active |
| f4rih/websploit Websploit is a high-level man-in-the-middle (MITM) security framework written in Python with a modular console interface similar to Metaspl… | 23 | 1247 | stable |
| bareos/bareos Bareos is an open-source (AGPLv3) network backup and recovery solution for mixed IT environments, supporting Linux, Windows, FreeBSD and ma… | 99 | 1246 | active |
| latchset/clevis Clevis is a pluggable framework for automated encryption and decryption, producing JWE ciphertexts that can be decrypted without user inter… | 80 | 1246 | active |
| lemono0/FastJsonParty FastJsonParty is a collection of Dockerized vulnerable environments covering multiple FastJson versions (1.2.47, 1.2.68, 1.2.80) for practi… | 28 | 1246 | active |
| antonioCoco/ConPtyShell ConPtyShell is a fully interactive reverse shell for Windows that leverages the Windows Pseudo Console (ConPTY) API to turn a remote PowerS… | 23 | 1246 | stable |
| RoganDawes/P4wnP1 P4wnP1 is a highly customizable USB attack platform built on a Raspberry Pi Zero or Zero W, providing features like a Windows LockPicker an… | 23 | 4383 | maintenance |
| SeedSigner/seedsigner SeedSigner is a FOSS application that turns a Raspberry Pi Zero with a camera and screen into an air-gapped, stateless Bitcoin signing devi… | 86 | 1244 | active |
| dovecot/core Dovecot is an open-source mail server for Linux/UNIX-like systems written in C, providing IMAP, POP3, LMTP, and ManageSieve protocols with … | 85 | 1244 | stable |
| delight-im/PHP-Auth A lightweight, secure authentication library for PHP that handles registration, login, email verification, password resets, and session man… | 44 | 1244 | stable |
| dnsviz/dnsviz DNSViz is a Python tool suite for analysis and visualization of DNS behavior, including DNSSEC security extensions. It provides command-lin… | 30 | 1244 | active |
| merkletreejs/merkletreejs A JavaScript/TypeScript library for constructing Merkle Trees and generating and verifying cryptographic inclusion proofs. It supports mult… | 47 | 1241 | stable |
| Jacalz/rymdport Rymdport is a cross-platform GUI application for securely sharing files, folders, and text between devices using end-to-end encryption. It … | 61 | 1240 | active |
| damienbod/angular-auth-oidc-client An npm library for securing Angular applications with OpenID Connect and OAuth2, supporting Code Flow with PKCE, refresh tokens, and the Im… | 95 | 1239 | active |
| ProtonMail/gopenpgp GopenPGP is a high-level OpenPGP wrapper library for Go, developed by Proton Mail and built on a fork of the golang crypto library. It prov… | 91 | 1239 | stable |