domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| brandonlw/Psychson A toolkit for creating custom firmware and firmware patches for Phison 2251-03 (2303) USB controller chips, enabling BadUSB attacks via HID… | 23 | 4181 | maintenance |
| internetwache/GitTools GitTools is a collection of three shell/Python scripts for finding and exploiting websites that publicly expose their .git directory. It in… | 64 | 4180 | maintenance |
| DataDog/guarddog GuardDog is a CLI tool from Datadog that identifies malicious packages on PyPI, npm, Go modules, Rust crates, RubyGems, GitHub Actions, and… | 99 | 1196 | active |
| niudaii/zpscan zpscan is a Go-based command-line information gathering and reconnaissance tool for security assessments. It bundles subdomain enumeration,… | 23 | 1196 | active |
| symfony/security The Symfony Security Component provides a complete authentication and authorization system for PHP web applications. It supports HTTP basic… | 10 | 1196 | stable |
| isec-tugraz/meltdown A collection of proof-of-concept applications demonstrating the Meltdown CPU vulnerability, built on the libkdump library. It includes demo… | 10 | 4170 | maintenance |
| openfheorg/openfhe-development OpenFHE is an open-source C++ library for fully homomorphic encryption (FHE), implementing all major schemes (BFV, BGV, CKKS, FHEW/TFHE, LM… | 88 | 1194 | active |
| cloudflare/flan Flan Scan is a lightweight network vulnerability scanner from Cloudflare that wraps Nmap and the vulners script to detect open ports, servi… | 10 | 4165 | maintenance |
| deepfence/FlowMeter FlowMeter is a Go utility that analyzes network packet headers, groups packets into flows, and uses machine learning to classify flows as b… | 10 | 1193 | active |
| myfanhua/turb-gpt-free-register A Python tool that bulk-registers ChatGPT/OpenAI accounts using pure-protocol requests or anti-fingerprint browser automation (RoxyBrowser,… | 58 | 1192 | active |
| huntergregal/mimipenguin MimiPenguin is a post-exploitation tool that dumps the current Linux desktop user's cleartext login password from process memory, inspired … | 41 | 4159 | maintenance |
| WhiteNightShadow/hello_js_reverse_skill An AI-powered 'Skill' package for JavaScript reverse engineering that plugs into AI coding tools like Claude Code, Cursor, and Codex. It pr… | 78 | 1191 | active |
| P3GLEG/Whaler Whaler is a Go CLI tool that reverse engineers Docker images back into the Dockerfiles that created them. It also extracts files added via … | 57 | 1191 | active |
| dalek-cryptography/curve25519-dalek A pure-Rust library providing group operations on the Curve25519 and ristretto255 elliptic curves, along with related crates for Ed25519 si… | 68 | 1190 | stable |
| samyk/magspoof MagSpoof is a portable Arduino-based device that spoofs and emulates magnetic stripe cards (credit cards, hotel keys, etc.) wirelessly by g… | 32 | 4148 | maintenance |
| suzuki-shunsuke/pinact pinact is a Go CLI that pins GitHub Actions and Reusable Workflows to full commit SHAs in workflow and composite action files, adding versi… | 96 | 1188 | active |
| goretk/redress Redress is a command-line tool for analyzing stripped Go binaries, reconstructing symbols and extracting information such as compiler versi… | 94 | 1188 | active |
| jayus0821/swagger-hack A Python CLI tool that automatically crawls all endpoints exposed by leaked Swagger/OpenAPI documentation and sends configured test request… | 57 | 1188 | active |
| chaitin/xpoc xpoc is a fast emergency-response vulnerability scanner from Chaitin's xray community, designed for supply chain vulnerability scanning. It… | 20 | 1188 | active |
| abrignoni/iLEAPP iLEAPP is an open-source iOS and iPadOS forensic artifact parser that extracts logs, events, and plists from device extractions and iTunes … | 100 | 1187 | active |
| meziantou/Meziantou.Analyzer Meziantou.Analyzer is a C# Roslyn analyzer distributed as a NuGet package that performs static analysis to detect bugs, security issues, an… | 96 | 1187 | active |
| RobThree/TwoFactorAuth A PHP library for implementing two-factor (multi-factor) authentication using TOTP time-based one-time passwords and QR codes. It supports … | 58 | 1187 | stable |
| FiloSottile/passage passage is a fork of the password-store (pass) CLI password manager that uses age encryption instead of GnuPG. It stores secrets as age-enc… | 23 | 1187 | active |
| yazgx97/frida-ios-hook A Python/JavaScript CLI tool that wraps Frida to make it easy to trace classes and functions, hook methods, and modify return values on iOS… | 69 | 1186 | active |
| Enginex0/tricky-addon-enhanced A native Rust daemon distributed as a root module (Magisk/KernelSU/APatch) that automatically manages TrickyStore and TEESimulator on roote… | 68 | 1186 | active |
| trustedsec/CS-Remote-OPs-BOF A collection of Beacon Object Files (BOFs) by TrustedSec implementing remote operations commands for Cobalt Strike, covering tasks like use… | 94 | 1185 | active |
| plabayo/rama Rama is a modular service framework for Rust for building network clients, servers, proxies, and traffic inspection tools from composable s… | 88 | 1185 | active |
| dirkjanm/adidnsdump A Python CLI tool that enumerates and exports all DNS records in Active Directory Integrated DNS zones using any authenticated domain user'… | 29 | 1184 | active |
| google/end-to-end A JavaScript crypto library implementing OpenPGP (RFC 4880) and OTR for encrypting, decrypting, digitally signing, and verifying messages. … | 10 | 4125 | maintenance |
| leiweibau/Pi.Alert Pi.Alert is a self-hosted network monitoring application that scans Wi-Fi and LAN for connected devices and alerts on unknown or missing de… | 99 | 1183 | active |
| Yubico/yubikey-manager A Python library and command line tool (ykman) for configuring YubiKey hardware security keys over all USB interfaces. It supports managing… | 92 | 1183 | active |
| adorsys/keycloak-config-cli A Java-based CLI tool (also distributed as a Docker image and Helm chart) that imports YAML/JSON configuration files into Keycloak via the … | 90 | 1183 | active |
| N0rz3/Phunter Phunter is a Python CLI OSINT tool that gathers information about phone numbers, including operator, line type, location, reputation, spam … | 26 | 1182 | active |
| austin-weeks/miasma Miasma is a lightweight Rust web server that traps AI web scrapers in an endless pit of poisoned training data and self-referential links. … | 82 | 1181 | active |
| runZeroInc/sshamble SSHamble is a Go-based research and scanning tool for probing SSH server implementations. It enumerates SSH capabilities and tests for auth… | 68 | 1180 | active |
| bitcoinjs/bip39 A JavaScript library implementing Bitcoin BIP39 mnemonic code for generating deterministic keys from entropy. It supports multiple language… | 61 | 1180 | stable |
| JoelGMSec/EvilnoVNC EvilnoVNC is a ready-to-run phishing platform that gives victims a real Chromium browser session over a noVNC connection inside Docker, whi… | 41 | 1180 | active |
| wuyoscar/Internal-Safety-Collapse ISC-Bench/TVD is a research framework for studying 'Internal Safety Collapse' in frontier LLMs, where agents placed in adversarial codespac… | 59 | 1179 | active |
| briansmith/ring ring is a Rust library providing safe, fast cryptographic primitives (hashing, AEAD, signatures, key agreement) built largely on BoringSSL'… | 75 | 4106 | maintenance |
| data61/MP-SPDZ MP-SPDZ is a versatile C++ framework for secure multi-party computation (MPC) supporting many protocols across various security models, inc… | 85 | 1178 | active |
| PKRoma/ProcessHacker System Informer (formerly Process Hacker) is a free, open-source, multi-purpose Windows tool for monitoring system resources, debugging sof… | 77 | 1178 | active |
| OpenVPN/openvpn3 OpenVPN 3 is a C++20 class library implementing an OpenVPN client that is protocol-compatible with OpenVPN 2.x, with a minimal command-line… | 77 | 1178 | active |
| google/capslock Capslock is a capability analysis CLI for Go packages that classifies which privileged operations a package can access via transitive calls… | 73 | 1177 | active |
| denisbrodbeck/machineid A Go library and small CLI that reads the operating system's native machine ID (machine UUID/GUID) on Windows, Linux, macOS, and BSD withou… | 32 | 1177 | stable |
| patriksimek/vm2 vm2 is a Node.js library that provides an in-process sandbox for running untrusted JavaScript code with whitelisted access to built-in modu… | 99 | 4095 | maintenance |
| akitaonrails/ai-jail ai-jail is a Rust CLI that runs AI coding agents inside an OS-level sandbox using bubblewrap with Landlock, seccomp, and resource limits on… | 83 | 1176 | active |
| jenish-sojitra/JSAnalyzer A Burp Suite extension written in Python (Jython) that performs static analysis on JavaScript files proxied through Burp. It extracts API e… | 44 | 1176 | active |
| canix1/ADACLScanner A PowerShell script (ADACLScan.ps1) with both CLI and GUI interfaces for reporting on discretionary and system access control lists (DACLs/… | 89 | 1175 | active |
| google/certificate-transparency-go Google's Go implementation of Certificate Transparency (RFC 6962), providing libraries for parsing and auditing TLS certificates, client li… | 82 | 1174 | active |
| vlm/asn1c asn1c is an open-source ASN.1 to C compiler that generates C/C++-compatible source code from ASN.1 module files. The generated code seriali… | 80 | 1174 | stable |
| S3cur3Th1sSh1t/Creds A collection of PowerShell scripts and executables useful for penetration testing and forensics, mostly Windows and Active Directory domain… | 76 | 1174 | active |
| mobilecoinfoundation/mobilecoin MobileCoin is a privacy-preserving cryptocurrency payments network designed for mobile devices, implemented in Rust. The repository contain… | 66 | 1174 | active |
| kuizuo/js-deobfuscator An automated JavaScript deobfuscation tool built on Babel AST transforms, offering a CLI, a TypeScript API, and an online playground. It re… | 89 | 1173 | active |
| SSLMate/certspotter Cert Spotter is an open-source Certificate Transparency log monitor written in Go that alerts you when SSL/TLS certificates are issued for … | 75 | 1173 | active |
| jasonxtn/Kraken Kraken is a Python-based menu-driven toolkit that centralizes brute-force attacks across network protocols (SSH, FTP, LDAP, Telnet, WiFi), … | 23 | 1173 | active |
| NH-RED-TEAM/RustHound RustHound is a cross-platform Active Directory data collector for BloodHound Legacy 4.x, written in Rust. It enumerates users, groups, comp… | 23 | 1173 | active |
| ConsenSysDiligence/surya Surya is a command-line utility for inspecting Solidity smart contract systems, providing structural summaries, inheritance information, an… | 45 | 1172 | active |
| rverton/webanalyze webanalyze is a Go port of Wappalyzer that detects the technologies used on websites, built for performant mass scanning of large host list… | 71 | 1171 | active |
| dark-kingA/cloudTools A cross-platform desktop tool for cloud asset management and cloud security assessment, built with Electron, Vue, Node.js, and Go. It manag… | 59 | 1171 | active |
| reversenseorg/dexcalibur Reversense (Dexcalibur 2) is a binary intelligence platform that automates reverse engineering of mobile and embedded applications. It comb… | 68 | 1170 | active |
| geohot/qira QIRA is a QEMU-based interactive runtime analyser that traces program execution and presents it in a web UI, acting as a competitor to stra… | 23 | 4070 | maintenance |
| Quitten/Autorize Autorize is a Burp Suite extension, written in Jython, that automatically detects authorization and authentication enforcement flaws in web… | 56 | 1169 | active |
| FunnyWolf/agentic-soc-platform Agentic SOC Platform (ASP) is an open-source, agent-centric security operations platform that ingests SIEM/webhook alerts, correlates them … | 81 | 1168 | active |
| XMR-Stak xmr-stak is a free, open-source, high-performance miner for Monero (RandomX) and unified CryptoNight-based cryptocurrencies, supporting CPU… | 23 | 4060 | maintenance |
| P1sec/hermes-dec hermes-dec is a Python-based reverse engineering tool that disassembles and decompiles React Native applications compiled to the Hermes VM … | 98 | 1166 | active |
| CodePlato3721/shiro-redis A Java library that provides a Redis-based cache and session manager implementation for Apache Shiro, which otherwise only supports ehcache… | 60 | 1166 | active |
| nccgroup/Sniffle Sniffle is an open-source sniffer for Bluetooth 5 and 4.x LE that runs on TI CC1352/CC26x2 hardware with a Python host-side tool. It captur… | 42 | 1166 | active |
| 0xthirteen/SharpRDP SharpRDP is a C# console application that executes authenticated commands on remote Windows hosts via the Remote Desktop Protocol, using th… | 75 | 1165 | active |
| saintedlama/passport-local-mongoose A Mongoose plugin that simplifies building username and password login with Passport for Node.js applications. It adds username, hash, and … | 91 | 1164 | stable |
| citronneur/pamspy pamspy is a Linux credentials dumper that uses eBPF to hook the pam_get_authtok function in libpam.so, capturing passwords from processes l… | 23 | 1162 | active |
| Fanju6/NetProxy-Magisk NetProxy is a system-level transparent proxy module for rooted Android devices built on the sing-box core, distributed as a Magisk/KernelSU… | 86 | 1161 | active |
| formal-land/rocq-of-rust rocq-of-rust is a formal verification tool that translates Rust programs (from the compiler's THIR representation) into the Rocq proof assi… | 76 | 1161 | active |
| Thalhammer/jwt-cpp jwt-cpp is a header-only C++11 library for creating and validating JSON Web Tokens (JWT). It supports all standard signature algorithms (HM… | 67 | 1161 | stable |
| arthepsy/CVE-2021-4034 A proof-of-concept exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec utility. It is a small… | 32 | 1161 | stable |
| JuneAndGreen/sm-crypto A pure JavaScript implementation of the Chinese national cryptography (Guomi) algorithms SM2 (elliptic curve encryption/signatures), SM3 (h… | 77 | 1160 | active |
| omrilotan/isbot isbot is a lightweight TypeScript library that identifies bots, crawlers, and spiders by matching user agent strings against a maintained r… | 76 | 1160 | active |
| loveshell/ngx_lua_waf A lightweight, high-performance web application firewall (WAF) built on lua-nginx-module (OpenResty) for Nginx. It filters requests using r… | 23 | 4023 | maintenance |
| nestjsx/nest-access-control A NestJS module providing role- and attribute-based access control (RBAC/ABAC), built on top of onury's accesscontrol library. It offers de… | 58 | 1158 | active |
| 0x727/ShuiZe_0x727 ShuiZe_0x727 is a Python-based automated information gathering (reconnaissance) tool for red team operators. Given a root domain, C-segment… | 23 | 4021 | maintenance |
| polymind-inc/acmebot Acmebot is an Azure-native application that automates ACME SSL/TLS certificate issuance and renewal using DNS-01 validation, storing privat… | 100 | 1157 | active |
| AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet Microsoft's IdentityModel extensions for .NET, a library for working with OpenID Connect, OAuth 2.0, and JSON Web Tokens (JWT) in .NET appl… | 98 | 1157 | active |
| paragonie/halite Halite is a high-level, misuse-resistant cryptography library for PHP built on top of libsodium. It simplifies encryption, decryption, digi… | 55 | 1157 | active |
| cloudflare/wirefilter A Rust library implementing an execution engine for Wireshark-like filter expressions, including parsing, compilation, and fast evaluation.… | 76 | 1156 | active |
| evyatarmeged/Raccoon Raccoon is a Python-based offensive security CLI tool for reconnaissance and information gathering. It performs DNS lookups, WHOIS, TLS ana… | 67 | 4011 | maintenance |
| OWASP/pytm pytm is a Pythonic framework from OWASP for threat modeling systems as code. Developers define their architecture in Python and it automati… | 85 | 1155 | active |
| mmalmi/nostr-vpn nostr-vpn is a Tailscale-style private mesh VPN written in Rust, built around a FIPS-backed data plane with a `nvpn` CLI/daemon, a shared n… | 77 | 1155 | active |
| soupslurpr/AppVerifier AppVerifier is an Android app that views and verifies app signing certificate hashes to confirm apps are genuine. Users can compare package… | 37 | 1155 | active |
| milesj/interweave A React library for safely rendering HTML strings without dangerouslySetInnerHTML, with XSS protection, attribute filtering, and text match… | 35 | 1155 | active |
| ElementsProject/elements Elements is an open-source C++ implementation of a blockchain platform extending the Bitcoin protocol with advanced features like Confident… | 88 | 1154 | active |
| EmilStenstrom/justhtml JustHTML is a pure Python HTML5 parser with browser-style error recovery, safe-by-default sanitization, CSS selector querying, and serializ… | 83 | 1154 | active |
| naim94a/lumen Lumen is a self-hosted, open-source replacement for Hex-Rays' Lumina server that stores and shares IDA Pro function signatures, comments, a… | 67 | 1154 | active |
| Daninet/hash-wasm hash-wasm is a fast hash function library for browsers and Node.js implemented with hand-tuned WebAssembly binaries. It supports a wide ran… | 23 | 1154 | stable |
| nashaofu/shell360 Shell360 is a cross-platform SSH and SFTP client built with Tauri, React, and Rust, supporting Windows, macOS, Linux, Android, and iOS. It … | 91 | 1153 | active |
| orhanobut/hawk Hawk is a secure, simple key-value storage library for Android that encrypts data before persisting it. It supports storing any object type… | 23 | 3996 | maintenance |
| fox-it/dissect Dissect is a modular digital forensics and incident response (DFIR) framework and toolset by Fox-IT that parses forensic artefacts from man… | 72 | 1151 | active |
| ameshkov/dnslookup dnslookup is a simple command line utility for making DNS lookups against a specified server. It supports all major DNS protocols including… | 80 | 1150 | active |
| expressjs/cookie-session A simple cookie-based session middleware for Express and Connect that stores session data on the client within a signed cookie, requiring n… | 66 | 1150 | stable |
| yunginnanet/HellPot HellPot is a cross-platform HTTP honeypot that punishes bots ignoring robots.txt by streaming an infinite Markov-chain-generated page of ps… | 49 | 1150 | active |
| WeBankBlockchain/WeIdentity WeIdentity is a blockchain-based distributed identity solution implementing W3C DID and Verifiable Credential specifications, developed by … | 30 | 1150 | active |
| typetools/checker-framework The Checker Framework is a framework for pluggable type-checking in Java, enhancing Java's type system to detect and prevent bugs like null… | 100 | 1149 | stable |