domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| griffinmartin/opencode-claude-auth An OpenCode plugin that authenticates Anthropic API requests using existing Claude Code OAuth credentials, eliminating the need for a separ… | 79 | 1239 | active |
| brainfucksec/kalitorify kalitorify is a shell script for Kali Linux that uses iptables rules to create a transparent proxy through the Tor network, redirecting all… | 32 | 1238 | active |
| mrwadams/attackgen AttackGen is a Streamlit-based cybersecurity tool that uses large language models to generate tailored incident response testing scenarios … | 95 | 1237 | active |
| pmacct/pmacct pmacct is a set of multi-purpose passive network monitoring daemons written in C that collect, aggregate, replicate and export IP traffic a… | 67 | 1237 | active |
| HotBoy-java/PotatoTool PotatoTool is a comprehensive Java-based network security GUI tool for security professionals, red/blue team members, and enthusiasts. It i… | 29 | 1237 | active |
| PortSwigger/http-request-smuggler A Burp Suite extension that automatically detects and exploits HTTP Request Smuggling vulnerabilities, including HTTP/1.1 CL.TE/TE.CL desyn… | 76 | 1236 | active |
| rdbo/libmem A cross-platform game hacking library for C, C++, Rust, and Python providing process and memory manipulation, function hooking/detouring, c… | 74 | 1236 | active |
| alexhude/uEmu uEmu is an IDA Pro plugin built on the Unicorn engine that lets you emulate code directly inside the IDA disassembler. It supports x86, x64… | 76 | 1235 | active |
| arismelachroinos/lscript A shell script for Kali Linux that automates common WiFi penetration testing and hacking procedures through an interactive menu. It bundles… | 10 | 4330 | maintenance |
| uunicorn/python-validity A Python driver and DBus service for Validity fingerprint sensors on Linux, integrating with fprintd for biometric authentication. It suppo… | 44 | 1231 | active |
| danielbohannon/Invoke-Obfuscation Invoke-Obfuscation is a PowerShell command and script obfuscation framework compatible with PowerShell 2.0+. It generates obfuscated varian… | 32 | 4320 | maintenance |
| horsicq/XPEViewer XPEViewer is a cross-platform GUI application for viewing and editing PE (Portable Executable) files, the executable format used on Windows… | 76 | 1230 | active |
| EliasKotlyar/Xiaomi-Dafang-Hacks Custom firmware (CFW) for the Xiaomi Dafang, Xiaofang 1S, Wyzecam V2/Pan, and other Ingenic T10/T20-based IP cameras. It replaces the stock… | 32 | 4316 | maintenance |
| HemmeligOrg/Hemmelig.app Hemmelig is a self-hostable web application for sharing sensitive information via encrypted, self-destructing secret links with client-side… | 82 | 1229 | active |
| apache/teaclave-sgx-sdk Apache Teaclave SGX SDK (Rust SGX SDK) is a Rust-based software development kit for building Intel SGX enclave applications with memory saf… | 62 | 1229 | active |
| saeeddhqan/Maryam OWASP Maryam is a modular open-source OSINT framework for harvesting data from open sources, search engines, and social networks. It provid… | 10 | 1228 | active |
| ThunderCls/xAnalyzer xAnalyzer is a plugin for the x64dbg debugger that performs extended static code analysis on debugged applications. It detects API function… | 51 | 1227 | active |
| RUB-NDS/PRET PRET is a Python command-line toolkit for printer security testing that connects to devices via network (port 9100) or USB and exploits pri… | 32 | 4301 | maintenance |
| passportxyz/passport Passport is an identity verification application that lets users build collections of verifiable credentials to prove unique humanity in a … | 98 | 1226 | active |
| EvotecIT/GPOZaurr GPOZaurr is a PowerShell module for gathering, analyzing, and fixing issues in Active Directory Group Policies. A single command (Invoke-GP… | 94 | 1226 | active |
| cloudflare/cloudflare-blog A collection of code samples accompanying posts on the Cloudflare Blog, covering topics like networking, security, performance, and edge co… | 67 | 1226 | active |
| cisagov/decider Decider is a self-hosted web application from CISA that helps network defenders, analysts, and researchers map adversary behaviors to the M… | 52 | 1226 | active |
| RubberDuck-com/rubberduck-use-case-playground A hands-on training playground for RubberDuck MCP, consisting of a local hub dashboard and a deliberately vulnerable restaurant demo app (R… | 54 | 1224 | active |
| DanMcInerney/wifijammer A Python script that continuously jams Wi-Fi clients and access points within range by sending deauthentication packets. It hops channels, … | 32 | 4291 | maintenance |
| cherriesandmochi/gdmaim GDMaim is a Godot Engine plugin that obfuscates all GDScript source code when exporting a project, renaming identifiers, hardcoding constan… | 79 | 1223 | active |
| ipa-lab/hackingBuddyGPT HackingBuddyGPT is a Python framework that helps ethical hackers and security researchers use LLMs and LLM-based autonomous agents for pene… | 67 | 1223 | active |
| xchwarze/wifi-pineapple-cloner A set of shell scripts that port the WiFi Pineapple NANO/TETRA penetration-testing firmware onto generic routers and other hardware. It inc… | 64 | 1223 | active |
| pfelk/pfelk pfelk is an open-source deployment toolkit that integrates pfSense/OPNsense firewall logs with the Elastic Stack (Elasticsearch, Logstash, … | 47 | 1223 | active |
| transmissions11/solmate Solmate is a collection of gas-optimized, opinionated Solidity smart contract building blocks including token standards (ERC20, ERC721, ERC… | 37 | 4288 | maintenance |
| lcvvvv/kscan Kscan is an all-in-one reconnaissance scanner written in pure Go that combines port scanning, protocol detection, service/application finge… | 23 | 4287 | maintenance |
| projectdiscovery/mapcidr mapCIDR is a Go utility for performing multiple operations on subnet/CIDR ranges, such as expansion, slicing, aggregation, filtering, sorti… | 83 | 1221 | active |
| GaloisInc/cryptol Cryptol is a domain-specific language and interpreter for specifying cryptographic algorithms, developed by Galois. It provides an executab… | 80 | 1220 | active |
| BehiSecc/VibeSec-Skill VibeSec-Skill is an AI skill (prompt/instruction pack) that teaches LLM coding assistants like Claude Code, Cursor, Codex, Copilot, and Ant… | 46 | 1220 | active |
| Tylous/SourcePoint SourcePoint is a Go-based polymorphic C2 profile generator for Cobalt Strike command and control servers. It generates unique malleable C2 … | 30 | 1220 | active |
| nmap/ncrack Ncrack is a high-speed network authentication cracking tool from the Nmap project, designed to audit hosts and network devices for weak pas… | 23 | 1220 | active |
| jx-sec/jxwaf JXWAF is an open-source web application firewall powered by an AI large language model, combining an AI security model, a semantic analysis… | 67 | 1219 | active |
| RamboRogers/rfhunter RFHunter is a DIY hardware device built on an ESP32 and AD8317 RF power detector that scans for RF signals to help locate hidden cameras, w… | 22 | 1219 | active |
| LavaMoat/LavaMoat LavaMoat is a suite of tools for securing JavaScript projects against software supply chain attacks by sandboxing the dependency graph. It … | 92 | 1218 | active |
| nfstream/nfstream NFStream is a multiplatform Python framework for fast, flexible network flow data analysis from live interfaces or pcap files. It provides … | 81 | 1218 | stable |
| pinax/django-user-accounts django-user-accounts is a reusable Django app providing extensible infrastructure for user account management, including signup, login, ema… | 44 | 1218 | stable |
| coreos/go-iptables A Go library that wraps the iptables command-line utility, providing functions to append and delete rules and to create, clear, and delete … | 23 | 1218 | stable |
| swaywm/swaylock swaylock is a screen locking utility for Wayland compositors, compatible with any compositor implementing the ext-session-lock-v1 protocol.… | 85 | 1215 | active |
| bitquark/shortscan Shortscan is a Go CLI tool that enumerates files with short (8.3) filenames on IIS web servers and attempts to recover their full filenames… | 29 | 1215 | active |
| mongodb/kingfisher Kingfisher is an open-source, Rust-based secret scanner that detects leaked credentials in code, Git history, cloud storage, and developer … | 82 | 1214 | active |
| sogonov/anubis An Android app manager that freezes and unfreezes groups of apps based on VPN connection state using system-level `pm disable-user` via Shi… | 67 | 1214 | active |
| privacytests/privacytests PrivacyTests is an open-source testing program that runs automated privacy audits against popular web browsers, measuring leaks like state … | 77 | 1213 | active |
| martijnvanbrummelen/nwipe nwipe is a secure disk eraser for Linux, a fork of DBAN's dwipe command, that wipes entire block devices using multiple erasure methods. It… | 89 | 1212 | active |
| boy-hack/ksubdomain KSubdomain is a fast, stateless subdomain enumeration and DNS verification tool written in Go. It uses raw sockets via pcap to bypass the k… | 68 | 1212 | active |
| cfal/shoes A high-performance multi-protocol proxy server written in Rust supporting HTTP, SOCKS5, VMess, VLESS, Shadowsocks, Trojan, Snell, Hysteria2… | 82 | 1210 | active |
| jxy-s/herpaderping A proof-of-concept tool and technical write-up demonstrating Process Herpaderping, a Windows technique that maps a process image from a fil… | 32 | 1210 | active |
| paralus/paralus Paralus is an open source, CNCF Sandbox zero-trust Kubernetes access manager that provides controlled, audited access to Kubernetes cluster… | 71 | 1209 | active |
| mgeeky/PackMyPayload PackMyPayload is a Python CLI proof-of-concept tool that packages files or directories into container formats (ZIP, 7zip, PDF, ISO, IMG, CA… | 32 | 1209 | active |
| gorilla/csrf gorilla/csrf is a Go HTTP middleware library that provides cross-site request forgery (CSRF) protection for web applications and services. … | 30 | 1209 | stable |
| strozfriedberg/Windows-Exploit-Suggester A Python CLI tool that compares a Windows host's patch level (from systeminfo output) against the Microsoft security bulletin database to d… | 10 | 4229 | maintenance |
| darktohka/clean-flash-builds A repository of clean, spyware-free builds of Adobe Flash Player, stripped of the bundled adware and telemetry found in the Chinese Flash v… | 80 | 1208 | active |
| emn178/online-tools A collection of browser-based online tools for hashing (md2, md5, sha1, sha2, sha512), base64, and HTML encode/decode operations. It runs e… | 77 | 1208 | active |
| Veil-Framework/Veil Veil is a Python-based command-line tool that generates Metasploit payloads designed to bypass common antivirus solutions. It supports mult… | 10 | 4226 | maintenance |
| taranis-ai/taranis-ai Taranis AI is a self-hosted open-source OSINT platform that collects news articles from web sources and uses NLP/AI to enrich, cluster, and… | 95 | 1207 | active |
| bivlked/amneziawg-installer A one-command Bash installer that turns a fresh Ubuntu or Debian VPS (x86_64, ARM64, Raspberry Pi) into a self-hosted AmneziaWG 2.0/3.x VPN… | 83 | 1207 | active |
| qi4L/qscan Qscan is an extremely fast internal network scanner written in Go, offering port scanning, protocol detection, service fingerprinting, brut… | 72 | 1206 | active |
| auth0/go-jwt-middleware A Go middleware library by Auth0 that validates JSON Web Tokens (JWTs) on incoming HTTP requests, with a framework-agnostic core validator.… | 94 | 1205 | active |
| pyca/pynacl PyNaCl is a Python binding to libsodium, a fork of the Networking and Cryptography (NaCl) library. It provides high-level access to modern … | 77 | 1205 | stable |
| google/fuzzbench FuzzBench is a free Google-run service and framework that rigorously evaluates fuzzers on real-world benchmarks at large scale. It provides… | 61 | 1205 | active |
| SciresM/boot9strap Boot9strap is a custom firmware bootloader for the Nintendo 3DS that achieves Boot9/Boot11 code execution via a bootrom exploit. It loads a… | 48 | 1205 | stable |
| HamedAp/ShahanPanel ShahanPanel is a self-hosted web panel for managing SSH and VPN proxy users on a server, supporting protocols like V2Ray, VLESS, VMess, Wir… | 91 | 1204 | active |
| zxcvbn-ts/zxcvbn A TypeScript rewrite of Dropbox's zxcvbn password strength estimator that scores passwords based on pattern matching against common passwor… | 76 | 1204 | active |
| CERT-Polska/Artemis Artemis is a modular, open-source vulnerability scanner developed by CERT Polska that checks website security at scale. It automatically ge… | 74 | 1204 | active |
| topiam/eiam TOPIAM is an open-source IAM/IDaaS identity and access management platform for centrally managing employee accounts, permissions, authentic… | 40 | 1204 | active |
| opengnb/opengnb OpenGNB is an open-source decentralized Software Defined Virtual Network (SDVN) that creates a layer-3 P2P VPN with strong NAT traversal, l… | 93 | 1203 | active |
| JonasAlfredsson/docker-nginx-certbot A Docker image wrapping the official Nginx images with automatic Let's Encrypt certificate creation and renewal via certbot. It supports RS… | 92 | 1203 | active |
| ramosbugs/oauth2-rs An extensible, strongly-typed Rust implementation of the OAuth2 protocol (RFC 6749). It provides a client library for OAuth2 authorization … | 53 | 1203 | stable |
| google/AFL American Fuzzy Lop (AFL) is a security-oriented, coverage-guided fuzzer that uses compile-time instrumentation and genetic algorithms to di… | 10 | 4205 | maintenance |
| ksdme/ut A fast, lightweight Rust CLI utility toolkit that bundles many common developer utilities (encoding, hashing, JWT, UUID generation, and mor… | 72 | 1202 | active |
| maoabc/nmmp nmmp is an APK/AAB/AAR hardening tool that converts Dalvik bytecode from classes.dex into native C code executed by a custom dex virtual ma… | 40 | 1202 | active |
| floating/frame Frame is a system-wide Web3 wallet platform for macOS, Windows, and Linux that exposes local JSON-RPC endpoints so any browser, CLI, or nat… | 39 | 1202 | active |
| marvinvr/docktail DockTail is a Go-based Docker sidecar that watches container events, reads docktail.* labels, and exposes matching containers as native Tai… | 81 | 1201 | active |
| x64dbg/GleeBug GleeBug is a debugging framework for Windows written in C, designed to make building debuggers and debugging tools complete and easy to use… | 76 | 1201 | active |
| dromara/tianai-captcha TianaiCAPTCHA is a Java-based behavioral CAPTCHA library supporting slider, rotation, slide-restore, and text-click CAPTCHA types. It ships… | 65 | 1201 | active |
| mbrg/power-pwn Power Pwn is an offensive and defensive security toolset for Microsoft 365 Power Platform and AI services, including Copilot Studio, custom… | 63 | 1201 | active |
| zgjx6/SocialEngineeringDictionaryGenerator A browser-based social engineering password dictionary generator that builds candidate password lists from personal information such as nam… | 48 | 1201 | active |
| epinna/tplmap Tplmap is a Python command-line tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code injection vulne… | 23 | 4197 | maintenance |
| facebookincubator/fizz Fizz is a C++14 implementation of the TLS 1.3 protocol, supporting all major handshake modes including PSK resumption, early data, client a… | 96 | 1200 | active |
| Janusec/janusec Janusec Application Gateway is a Go-based application gateway providing secure access for web applications, including reverse proxy, WAF, C… | 83 | 1200 | active |
| DragonOS-Community/DragonOS DragonOS is a 64-bit operating system with a fully independent kernel written from scratch in Rust, offering Linux binary compatibility. It… | 82 | 1200 | active |
| Hackmanit/Web-Cache-Vulnerability-Scanner A fast, Go-based CLI scanner for detecting web cache poisoning and web cache deception vulnerabilities. It supports many attack techniques,… | 60 | 1200 | active |
| pielco11/fav-up Fav-up is a Python CLI tool and library that finds the real IP address behind services like Cloudflare by hashing a website's favicon and s… | 25 | 1199 | active |
| notmarek/LanguageBreak LanguageBreak is a software jailbreak for Amazon Kindle e-readers running firmware 5.16.2.1.1 or lower, exploiting a demo-mode vulnerabilit… | 19 | 1199 | active |
| 7h30th3r0n3/Raspyjack RaspyJack is a portable offensive security toolkit for Raspberry Pi (with Waveshare LCD HAT) and Cardputer Zero, offering 231 payloads acro… | 78 | 1198 | active |
| ycdxsb/PocOrExp_in_Github A Python CLI tool that automatically aggregates proof-of-concept (POC) and exploit (EXP) code from GitHub by CVE ID, using CVE information … | 77 | 1198 | active |
| ozguralp/gmapsapiscanner A Python CLI tool that tests whether a leaked or discovered Google Maps API key is vulnerable to unauthorized usage across many Google Maps… | 70 | 1198 | active |
| The-Viper-One/PsMapExec PsMapExec is a PowerShell-based post-exploitation framework inspired by CrackMapExec/NetExec for assessing Active Directory environments. I… | 61 | 1198 | active |
| petoolse/petools PE Tools is a Windows GUI toolkit for researching and manipulating Portable Executable (PE) files and running processes. It bundles a PE he… | 44 | 1197 | active |
| brandonlw/Psychson A toolkit for creating custom firmware and firmware patches for Phison 2251-03 (2303) USB controller chips, enabling BadUSB attacks via HID… | 23 | 4181 | maintenance |
| internetwache/GitTools GitTools is a collection of three shell/Python scripts for finding and exploiting websites that publicly expose their .git directory. It in… | 64 | 4178 | maintenance |
| yezz123/authx AuthX is a Python library providing ready-to-use, customizable authentication and OAuth2 management for FastAPI applications. It offers JWT… | 92 | 1196 | active |
| aydinnyunus/ai-captcha-bypass A Python command-line tool that uses multimodal LLMs (GPT-4o, Gemini) to automatically solve various CAPTCHA types, including text, reCAPTC… | 61 | 1196 | active |
| vanhauser-thc/thc-ipv6 A comprehensive IPv6 attack toolkit written in C, providing dozens of tools for spoofing, man-in-the-middle, denial-of-service, scanning, a… | 58 | 1196 | active |
| niudaii/zpscan zpscan is a Go-based command-line information gathering and reconnaissance tool for security assessments. It bundles subdomain enumeration,… | 23 | 1196 | active |
| symfony/security The Symfony Security Component provides a complete authentication and authorization system for PHP web applications. It supports HTTP basic… | 10 | 1196 | stable |
| isec-tugraz/meltdown A collection of proof-of-concept applications demonstrating the Meltdown CPU vulnerability, built on the libkdump library. It includes demo… | 10 | 4172 | maintenance |