domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| projectdiscovery/pdtm pdtm is a Go-based CLI tool manager for installing, updating, and removing ProjectDiscovery's open-source security tools. It downloads rele… | 98 | 1149 | active |
| random-robbie/My-Shodan-Scripts A collection of Python 3 scripts for querying the Shodan search engine to find exposed devices and services on the internet. It bundles man… | 60 | 1149 | active |
| ichason/CPosed CPosed is an Android hooking framework forked from LSPosed that enables Xposed-style module injection on rooted devices running Android 8.1… | 47 | 1149 | active |
| ben-sb/javascript-deobfuscator A general-purpose JavaScript deobfuscator that removes common obfuscation techniques such as array unpacking, proxy functions, expression o… | 46 | 1149 | active |
| jsocol/django-ratelimit A Django library providing a decorator to rate-limit views based on IP address or request fields, using Django's cache backend. It is a lig… | 23 | 1147 | stable |
| IJHack/QtPass QtPass is a multi-platform GUI front-end for pass, the standard Unix password manager, built with Qt. It manages GPG-encrypted password sto… | 93 | 1146 | active |
| JusticeRage/Manalyze Manalyze is a static analyzer for PE (Windows executable) files written in C++. It performs primary malware assessment by parsing PE struct… | 87 | 1146 | active |
| Netflix/repokid Repokid is a Python tool from Netflix that enforces least privilege on AWS IAM roles by removing permissions for unused services from inlin… | 47 | 1146 | active |
| 0xsha/CloudBrute CloudBrute is a Go CLI tool that enumerates a company's infrastructure, files, and applications across major cloud providers (Amazon, Googl… | 27 | 1146 | active |
| eclipse-biscuit/biscuit Biscuit is a specification and reference implementation for a delegated, decentralized, capability-based authorization token, written in Ru… | 44 | 1145 | active |
| ExeinfoASL/ASL Exeinfo Pe is a free Windows GUI tool that detects packers, protectors, compilers, .NET obfuscators, and packed binary data formats in PE e… | 93 | 1144 | active |
| iagox86/dnscat2 dnscat2 is an encrypted DNS tunneling tool designed to create a command-and-control (C&C) channel over the DNS protocol. It consists of a C… | 23 | 3962 | maintenance |
| savoirfairelinux/opendht OpenDHT is a lightweight C++17 distributed hash table (DHT) library providing an easy-to-use distributed in-memory data store with redundan… | 86 | 1143 | active |
| pureqh/Hyacinth Hyacinth is a Java-based GUI tool that bundles detection and exploitation modules for common Java vulnerabilities such as Struts2, Fast, We… | 55 | 1143 | active |
| auth0/lock Auth0 Lock is an embeddable, configurable login form widget for web applications that integrates with the Auth0 identity platform. It suppo… | 91 | 1142 | stable |
| Flyrell/axios-auth-refresh A TypeScript library that adds automatic authorization token refresh to Axios via interceptors. When a request fails with an authorization … | 82 | 1142 | active |
| simplesamlphp/simplesamlphp SimpleSAMLphp is a native PHP application for handling authentication, primarily as a SAML 2.0 Service Provider and Identity Provider. It a… | 98 | 1141 | stable |
| GJDuck/e9patch E9Patch is a static binary rewriting tool for x86_64 Linux ELF executables and shared objects, producing patched binaries that work as drop… | 83 | 1141 | active |
| TheHive-Project/TheHive TheHive is a collaborative security incident response and case management platform for SOC teams, supporting alert triage, case investigati… | 10 | 3949 | maintenance |
| hackademix/noscript NoScript Security Suite is a free open-source browser extension that lets users decide which websites are trusted to run JavaScript and oth… | 98 | 1139 | active |
| thumbmarkjs/thumbmarkjs ThumbmarkJS is a free, MIT-licensed JavaScript browser fingerprinting library that generates a unique visitor identifier entirely client-si… | 93 | 1139 | active |
| MinaMichita/AntiAntiDefraud An Xposed/LSPosed module for MIUI 14 that prevents Xiaomi's Security app (GuardProvider/AntiDefraud) from silently uploading the user's ins… | 21 | 1139 | active |
| pendulum-project/ntpd-rs ntpd-rs is a memory-safe Rust implementation of the Network Time Protocol (NTP) with support for the authenticated NTS extension, providing… | 91 | 1138 | stable |
| kevthehermit/PasteHunter PasteHunter is a Python 3 application that queries public pastebin-style sites (pastebin.com, GitHub gists, slexy, stackexchange, etc.) and… | 50 | 1138 | active |
| tesseral-labs/tesseral Tesseral is open-source, multi-tenant authentication infrastructure designed for B2B SaaS applications, runnable as a cloud service or self… | 43 | 1138 | active |
| laluka/bypass-url-parser A Python CLI tool (usable as a library) that generates and tests many URL bypass payloads to access 40X-protected pages, using curl as its … | 74 | 1137 | active |
| vec2text/vec2text A Python library for text embedding inversion: training and running models that reconstruct text sequences from their sentence embeddings. … | 57 | 1137 | active |
| meganz/webclient The official MEGA (mega.nz) web client, a browser-based front end for MEGA's zero-knowledge encrypted cloud storage service. It implements … | 77 | 1136 | active |
| greatscottgadgets/luna LUNA is an Amaranth HDL (Python) framework providing FPGA gateware and software for working with USB, from passive protocol analysis to bui… | 75 | 1136 | active |
| projectdiscovery/tlsx TLSX is a fast and configurable TLS grabber written in Go that collects and analyzes TLS-based data from hosts. It supports multiple TLS co… | 90 | 1135 | active |
| apache/casbin-rs Casbin-RS is the Rust implementation of Apache Casbin, an authorization library that enforces access control based on configurable models s… | 88 | 1135 | active |
| david942j/seccomp-tools A Ruby-based CLI toolkit for analyzing seccomp BPF filters, supporting dumping, disassembling, assembling, emulating, and auditing seccomp … | 88 | 1135 | active |
| AloneMonkey/frida-ios-dump A Python CLI script that uses Frida to dump decrypted iOS app binaries from a jailbroken device and packages them into an IPA. It connects … | 32 | 3925 | maintenance |
| GameTec-live/ChameleonUltraGUI A cross-platform GUI application for the Chameleon Ultra and Chameleon Lite RFID emulation devices, written in Flutter. It lets users manag… | 78 | 1134 | active |
| certtools/intelmq IntelMQ is an open-source solution for IT security teams (CERTs, CSIRTs, SOCs) for collecting and processing security feeds using a message… | 63 | 1134 | active |
| the-useless-one/pywerview PywerView is a partial Python rewrite of PowerSploit's PowerView for Active Directory enumeration, built on impacket. It lets pentesters ru… | 76 | 1133 | active |
| Arinerron/CVE-2022-0847-DirtyPipe-Exploit A C-based root privilege escalation exploit for CVE-2022-0847 (Dirty Pipe), a Linux kernel vulnerability. It modifies Max Kellermann's proo… | 32 | 1133 | stable |
| ricochet-im/ricochet Ricochet is a cross-platform desktop instant messaging application that provides anonymous, metadata-resistant chat over Tor hidden service… | 23 | 3919 | maintenance |
| samyk/pwnat pwnat is a C-based command-line tool that enables clients and servers behind separate NATs to communicate directly without port forwarding,… | 49 | 3917 | maintenance |
| zmap/zdns ZDNS is a high-speed DNS resolver library and CLI tool written in Go for performing large-scale DNS measurements and lookups. It includes i… | 95 | 1131 | active |
| jertel/elastalert2 ElastAlert 2 is a standalone Python tool that runs rule-based alerting on anomalies, spikes, and patterns in data stored in Elasticsearch o… | 91 | 1131 | active |
| PortSwigger/mcp-server A Burp Suite extension by PortSwigger that exposes Burp's capabilities to AI clients via the Model Context Protocol (MCP). It includes an S… | 70 | 1131 | active |
| moloch--/RootTheBox Root the Box is a self-hosted, real-time capture the flag (CTF) scoring engine and game manager for computer wargames. It provides animated… | 58 | 1131 | active |
| open-obfuscator/o-mvll O-MVLL is an LLVM-based code obfuscator for native code that integrates with Clang and the Swift compiler via the LLVM pass manager, with o… | 97 | 1130 | active |
| SabyasachiRana/WebMap WebMap is a self-hosted web dashboard for visualizing and reporting on Nmap scan results stored as XML files. It provides charts, host insp… | 76 | 1130 | active |
| mrphrazer/reverser_ai ReverserAI is a Binary Ninja plugin that provides automated reverse engineering assistance using locally-hosted large language models runni… | 68 | 1130 | active |
| hasanfirnas/symbiote Symbiote is a Python-based social engineering tool that generates a phishing page to trick a target into granting camera permission, then c… | 37 | 1130 | active |
| desowin/usbpcap USBPcap is an open-source USB packet capture tool for Windows, consisting of a filter driver and a command-line capture application (USBPca… | 25 | 1130 | active |
| XmirrorSecurity/OpenSCA-cli OpenSCA-cli is an open-source Software Composition Analysis (SCA) command-line tool that scans projects to detect third-party open-source d… | 82 | 1129 | active |
| spyboy-productions/CamXploit CamXploit is a Python-based security reconnaissance tool that checks whether an IP address hosts a potentially exposed IP camera or CCTV se… | 48 | 1129 | active |
| TongchengOpenSource/AppScan AppScan is a free, enterprise-grade automated privacy compliance detection tool for Android apps, based on dynamic analysis. It identifies … | 26 | 1129 | active |
| bkerler/mtkclient A Python utility for exploiting, reading, and writing flash memory on MediaTek (MTK) smartphones via the BootROM or preloader. It supports … | 72 | 1127 | active |
| CodingGay/BlackObfuscator BlackObfuscator is a Java-based obfuscator for Android DEX files that applies control flow flattening to make decompiled code hard to analy… | 31 | 1127 | active |
| protofire/solhint Solhint is an open-source linter for Solidity smart contracts that provides both security and style guide validations. It runs as an npm-di… | 93 | 1126 | active |
| REhints/efiXplorer efiXplorer is an IDA Pro plugin and loader that automates static analysis of UEFI firmware. It recovers EFI service function calls, identif… | 90 | 1126 | active |
| qmonnet/rbpf rbpf is a Rust crate providing a user-space virtual machine for executing eBPF programs. It includes an interpreter, an x86_64 JIT compiler… | 70 | 1126 | active |
| cybercog/laravel-ban Laravel Ban is a PHP package that adds banning and blocking capabilities to any Laravel Eloquent model via traits and a BanService. It supp… | 66 | 1126 | stable |
| Endermanch/XPKeygen A C++ tool that generates valid Windows XP and Windows Server 2003 VLK product keys from a raw product key, based on reverse-engineered ell… | 62 | 1126 | active |
| ErosZy/sablejs sablejs is a JavaScript sandbox library that safely executes untrusted, user-authored, or AI-generated JavaScript by AOT-compiling ES5.1 pr… | 99 | 1125 | active |
| RedSiege/C2concealer C2concealer is a Python command line tool that generates randomized Cobalt Strike malleable C2 profiles. It builds profile blocks from rand… | 67 | 1125 | active |
| projectdiscovery/asnmap asnmap is a Go CLI tool and library that maps organizations to their network ranges (CIDR blocks) using ASN information. It supports lookup… | 67 | 1125 | active |
| tejado/android-usb-gadget An Android app that uses the Linux kernel's ConfigFS API to create and activate arbitrary USB gadget device roles, such as keyboard, mouse,… | 23 | 1125 | active |
| genotrance/px Px is an HTTP/HTTPS proxy server that automatically handles NTLM and Kerberos proxy authentication, typically in corporate environments, us… | 87 | 1124 | active |
| cloudflare/sandbox-sdk A TypeScript SDK for running secure, sandboxed code execution environments on Cloudflare Workers. It lets developers execute commands, mana… | 82 | 1124 | active |
| sigstore/gitsign Gitsign is a CLI tool that signs Git commits and tags using Sigstore's keyless signing, backed by your GitHub or other OIDC identity instea… | 94 | 1123 | active |
| Adversis/tailsnitch Tailsnitch is a Go-based CLI security auditor for Tailscale configurations that scans a tailnet for 50+ misconfigurations, overly permissiv… | 74 | 1123 | active |
| defuse/php-encryption A PHP library for symmetric encryption of strings and files using a key or password, built on OpenSSL. Its API is deliberately designed to … | 23 | 3876 | maintenance |
| luoyesiqiu/dpt-shell dpt-shell is an Android Dex protection shell that hollows out DEX method implementations and reconstructs them at runtime to protect APK/AA… | 100 | 1122 | active |
| duo-labs/parliament Parliament is a Python library and CLI tool that lints AWS IAM policies, detecting malformed JSON, invalid actions and resources, type mism… | 50 | 1122 | active |
| RuoJi6/CACM CACM is a Linux post-exploitation and privilege persistence tool that bundles port scanning, sensitive information gathering, EDR/AV identi… | 85 | 1121 | active |
| fiddyschmitt/File-Tunnel File Tunnel is a C# CLI tool that tunnels TCP connections through files on a shared file server, letting two hosts exchange traffic via rea… | 98 | 1120 | active |
| pashov/skills A collection of AI-powered Solidity security skills built by Pashov Audit Group, packaged for use with AI coding assistants like Claude Cod… | 75 | 1120 | active |
| Washi1337/AsmResolver AsmResolver is a .NET library for reading, modifying, and writing Portable Executable (PE) files, including those with .NET metadata. It pr… | 94 | 1119 | active |
| microsoft/avml AVML is a portable X86_64 userland volatile memory acquisition tool for Linux, written in Rust and distributed as a static binary. It captu… | 92 | 1119 | active |
| burghardt/easy-wg-quick A shell script that generates WireGuard VPN configurations for a hub (VPN concentrator) and its peers, including QR codes for mobile client… | 91 | 1119 | active |
| spruceid/siwe A TypeScript library implementing Sign-In with Ethereum (EIP-4361), a standard message format for Ethereum accounts to authenticate with of… | 34 | 1119 | active |
| RavenProject/Ravencoin Raven Core is the full-node reference implementation of Ravencoin, a Bitcoin-forked peer-to-peer blockchain optimized for issuing and trans… | 94 | 1118 | active |
| dokku/dokku-letsencrypt The official Dokku plugin for automatically retrieving and installing free Let's Encrypt TLS certificates using the lego ACME client. It ke… | 93 | 1118 | active |
| vndee/llm-sandbox LLM Sandbox is a lightweight Python library for safely executing LLM-generated code in isolated container environments with support for Doc… | 90 | 1118 | active |
| r3nt0n/bopscrk bopscrk is a Python CLI tool that generates smart, targeted wordlists for password cracking, combining user-provided words with transformat… | 23 | 1118 | active |
| io12/pwninit pwninit is a Rust CLI tool that automates the setup of binary exploitation challenges, typically for CTF competitions. It detects the chall… | 84 | 1117 | stable |
| AvillaDaniel/AvillaForensics Avilla Forensics is a free Windows-based mobile forensic application for logical data extraction from Android and iOS devices, built in C# … | 70 | 1117 | active |
| mittwald/kubernetes-replicator A custom Kubernetes controller written in Go that synchronizes Secrets, ConfigMaps, Roles, RoleBindings, and ServiceAccounts across namespa… | 85 | 1115 | active |
| moshowgame/Navicat_Keygen_Patch A collection of keygen, patch, and trial-reset tools for bypassing activation of Navicat database client versions 15-17, distributed as DLL… | 47 | 1114 | active |
| vet-run/vet vet is a command-line tool that acts as a safety net for the risky `curl | bash` pattern. It fetches remote scripts, diffs them against pre… | 37 | 1114 | active |
| libriscv/libriscv libriscv is an embeddable C++20 RISC-V (RVA23) userspace emulator and sandboxing library focused on ultra-low-latency VM function calls and… | 95 | 1113 | active |
| diffblue/cbmc CBMC (C Bounded Model Checker) is a formal verification tool for C and C++ programs that explores all possible execution paths on bounded i… | 94 | 1113 | active |
| tracelabs/tlosint-vm Trace Labs OSINT VM is a Kali Linux-based virtual machine distribution pre-loaded with open-source intelligence (OSINT) tools and Firefox h… | 87 | 1112 | active |
| mrwadams/stride-gpt STRIDE GPT is an AI-powered threat modeling tool that uses LLMs to generate STRIDE-based threat models, attack trees, and MITRE ATT&CK/ATLA… | 84 | 1112 | active |
| bolkedebruin/rdpgw An open-source implementation of the Microsoft Remote Desktop Gateway protocol (MS-TSGU) written in Go, allowing official Microsoft RDP cli… | 81 | 1112 | active |
| kerberos-io/agent Kerberos Agent is an open-source, scalable video surveillance application written in Go with a React frontend, designed to connect to IP ca… | 95 | 1111 | active |
| crewjam/saml A Go library providing a partial implementation of the SAML standard for identity federation. It supports building both Service Providers (… | 61 | 1111 | stable |
| outlaws-bai/Galaxy Galaxy is a Burp Suite extension that automatically decrypts and re-encrypts HTTP traffic whose payloads are encrypted, letting testers wor… | 88 | 1110 | active |
| fuzzland/ityfuzz ItyFuzz is a blazing-fast bytecode-level hybrid fuzzer for EVM and MoveVM smart contracts that combines symbolic (concolic) execution with … | 55 | 1110 | active |
| KJCracks/Clutch Clutch is a fast iOS executable decryption and dumping tool that extracts decrypted binaries and .ipa files from installed apps on jailbrok… | 23 | 3824 | maintenance |
| itsreyi/BlockSuite Block-Suite is a modular JavaFX desktop application for authorized Minecraft server security assessments. It deploys a transparent MITM pro… | 67 | 1109 | active |
| TheOfficialFloW/h-encore h-encore is a fully chained kernel exploit (jailbreak) for the PlayStation Vita on firmwares 3.65-3.68. It enables kernel and user modifica… | 23 | 1109 | stable |
| wstrange/GoogleAuth GoogleAuth is a Java server-side library implementing the Time-based One-Time Password (TOTP) algorithm from RFC 6238, compatible with Goog… | 66 | 1108 | stable |
| CuriousLearnerDev/Online_tools A security tool marketplace application that lets users download, update, and automatically install a large catalog of penetration testing … | 96 | 1107 | active |
| sandialabs/wiretap Wiretap is a transparent, VPN-like proxy server written in Go that tunnels traffic through WireGuard without requiring special privileges o… | 78 | 1107 | active |