domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| mgeeky/cobalt-arsenal A collection of battle-tested Aggressor Scripts (CNA) for Cobalt Strike 4.0+ that extend and enhance the red team operator's workflow. It i… | 32 | 1107 | active |
| dromara/dongle Dongle is a simple, semantic, and developer-friendly cryptography library for Go, offering a fluent API for encryption, hashing, and encodi… | 83 | 1106 | active |
| amruth-sn/kong Kong is an LLM-orchestrated reverse engineering CLI that plugs AI into Ghidra's analysis engine to recover function names, types, and struc… | 63 | 1105 | active |
| D00Movenok/BounceBack BounceBack is a stealth reverse proxy with WAF-like filtering designed to hide red team C2 and phishing infrastructure from blue teams, san… | 73 | 1104 | active |
| cameraui/camera.ui camera.ui is a self-hosted, local-first video surveillance (NVR) platform for security cameras with live viewing, 24/7 recording, and on-de… | 100 | 1103 | active |
| safedep/vet vet is an open-source CLI tool for software composition analysis that scans open-source dependencies for malicious packages and vulnerabili… | 93 | 1103 | active |
| immanuwell/dockerfile-roast droast is a Dockerfile linter written in Rust with 85 opinionated rules that report bad practices using snarky, humorous messages. It runs … | 80 | 1103 | active |
| hakluke/hakoriginfinder hakoriginfinder is a Go CLI tool that discovers the origin host behind a reverse proxy or WAF. It sends requests with the original Host hea… | 75 | 1101 | active |
| rhboot/shim shim is a small first-stage UEFI bootloader written in C that loads and validates a second-stage bootloader, enabling Secure Boot on Linux … | 69 | 1101 | active |
| lepture/captcha A Python library that generates image and audio CAPTCHAs with customizable fonts, colors, and voice data. It provides simple APIs (ImageCap… | 56 | 1101 | stable |
| dafthack/MSOLSpray MSOLSpray is a PowerShell-based password spraying tool for Microsoft Online (Azure AD/O365) accounts. It leverages Azure AD OAuth2 error co… | 32 | 1101 | stable |
| Loki LOKI is a free, open-source IOC and YARA scanner written in Python for triaging compromised systems. It detects indicators of compromise vi… | 51 | 3788 | maintenance |
| yourtablecloth/TableCloth TableCloth is a Windows application that launches Windows Sandbox to run security programs required by internet banking and e-government si… | 99 | 1100 | active |
| EnableSecurity/sipvicious SIPVicious OSS is a Python-based toolset for auditing SIP-based VoIP systems, including tools to scan for SIP servers (svmap), enumerate ex… | 89 | 1100 | active |
| mgeeky/ProtectMyTooling A multi-packer wrapper script that daisy-chains various packers, obfuscators, and shellcode loaders to produce obfuscated Red Team implants… | 53 | 1098 | active |
| prompt-security/clawsec ClawSec is an AGPL-licensed suite of security skills for AI agent runtimes such as OpenClaw, NanoClaw, Hermes, and Picoclaw. It verifies sk… | 80 | 1097 | active |
| c3c/ADExplorerSnapshot A Python CLI tool that parses AD Explorer snapshot (.dat) files and converts them to BOFHound, BloodHound-compatible JSON, or NDJSON format… | 73 | 1097 | active |
| GamehunterKaan/AutoPWN-Suite AutoPWN Suite is a Python-based automated vulnerability scanning and exploitation framework that wraps nmap for host discovery, version-bas… | 94 | 1096 | active |
| k8spacket/k8spacket k8spacket is a Kubernetes tool that collects TCP traffic and TLS connection metadata using eBPF (tracepoints and traffic-control filters) a… | 93 | 1096 | active |
| projectdiscovery/wappalyzergo A high-performance Go library that ports the Wappalyzer technology detection stack, identifying web technologies from HTTP headers and HTML… | 95 | 1094 | active |
| apache/mina-sshd Apache MINA SSHD is a pure-Java library implementing the SSH protocol on both client and server sides, with pluggable I/O back-ends (built-… | 89 | 1094 | stable |
| mcginty/snow Snow is a pure-Rust implementation of the Noise Protocol Framework for building encrypted, authenticated channel handshakes. It supports No… | 64 | 1094 | stable |
| OpenIDC/mod_auth_openidc An OpenID Certified™ Apache HTTPd module implementing OpenID Connect 1.x and FAPI 2.x Relying Party functionality. It lets an Apache web se… | 99 | 1093 | stable |
| memflow/memflow memflow is a Rust library providing a modular framework for physical memory introspection of machines, including live hardware, virtual mac… | 58 | 1093 | active |
| andrew-d/static-binaries A collection of common *nix tools (nmap, tcpdump, strace, socat, python, etc.) prebuilt as statically-linked binaries, with the Dockerfiles… | 32 | 3755 | maintenance |
| LyraVoid/FolkPatch FolkPatch is an Android root management application built on KernelPatch that grants root access by patching the boot partition, without re… | 80 | 1091 | active |
| softhsm/SoftHSMv2 SoftHSMv2 is a software implementation of a cryptographic store accessible through the PKCS#11 interface, originally developed as part of t… | 74 | 1091 | active |
| google/trillian Trillian is a transparent, cryptographically verifiable append-only data store built on Merkle trees, backed by scalable storage like MySQL… | 83 | 3747 | maintenance |
| Tuhinshubhra/RED_HAWK RED_HAWK is a PHP-based all-in-one reconnaissance and vulnerability scanning tool for websites. It performs information gathering (whois, D… | 32 | 3746 | maintenance |
| laserlemon/figaro Figaro is a Ruby gem that provides simple, Heroku-friendly configuration for Rails applications using environment variables and a single Gi… | 45 | 3745 | maintenance |
| wisk/medusa Medusa is an open-source, modular, interactive disassembler written in C++, organized as a library with frontends including a GUI (qMedusa)… | 57 | 1090 | active |
| builtbybel/privatezilla Privatezilla is a Windows 10 desktop application that performs a privacy and security check against about 60 critical privacy settings, let… | 23 | 3737 | maintenance |
| DSE-MSU/DeepRobust DeepRobust is a PyTorch library for adversarial robustness research, providing implementations of attack and defense methods for both image… | 45 | 1086 | active |
| aeternity/aeternity The reference node implementation of the æternity blockchain, a scalable public blockchain platform written in Erlang. It supports smart co… | 88 | 1085 | active |
| 7thSamurai/steganography A C++ command-line tool that encrypts files with password-protected AES-256-CBC and hides them inside images using Least-Significant-Bit pi… | 32 | 1085 | stable |
| builtbybel/xd-AntiSpy xd-AntiSpy is a Windows 11 privacy utility that lets users disable telemetry and spy-related settings through a simple interface, continuin… | 14 | 1085 | active |
| kunai-project/kunai Kunai is an eBPF-based threat-hunting and security-monitoring tool for Linux, often described as the Linux counterpart to Sysmon on Windows… | 81 | 1084 | active |
| bitdefender/bddisasm bddisasm is a fast, lightweight x86/x64 instruction decoder library written in C with no external dependencies, no memory allocation, and t… | 74 | 1084 | active |
| dozoisch/react-google-recaptcha A React component wrapper around Google reCAPTCHA v2, supporting normal, compact, and invisible captcha modes. It handles async loading of … | 32 | 1084 | stable |
| alcideio/rbac-tool A kubectl plugin and standalone CLI that simplifies Kubernetes RBAC by visualizing, analyzing, generating, and querying RBAC policies. It h… | 26 | 1084 | active |
| HZJQF/help_tool A PyQt5-based Windows GUI tool that uses inference models to identify the encryption or hashing algorithm behind a given ciphertext and att… | 24 | 1084 | active |
| mtrojnar/osslsigncode osslsigncode is a small C tool that implements Microsoft Authenticode signing and timestamping, based on OpenSSL and cURL. It signs, verifi… | 93 | 1083 | active |
| bhattsameer/Bombers A curated collection of Python scripts that flood phone numbers and email addresses with repeated SMS, email, WhatsApp, Twitter, and Instag… | 10 | 3716 | maintenance |
| semaphore-protocol/semaphore Semaphore is a zero-knowledge protocol and toolkit for proving group membership anonymously, letting users cast signals like votes or endor… | 93 | 1082 | active |
| platomav/BIOSUtilities A collection of Python-based BIOS/UEFI utilities for extracting, unpacking, and analyzing firmware images from vendors like AMI, Insyde, Ph… | 45 | 1082 | active |
| mbechler/marshalsec marshalsec is a Java tool and research project that generates exploitation payloads for insecure unmarshalling across many Java marshalling… | 32 | 3709 | maintenance |
| maester365/maester Maester is a PowerShell-based test automation framework that monitors and validates the security configuration of Microsoft 365 and Entra I… | 88 | 1081 | active |
| jazzband/django-defender A Django reusable app that blocks brute-force login attempts by rate limiting on username and IP address, using Redis as a fast cache backe… | 52 | 1081 | active |
| Gameye98/Lazymux Lazymux is a Python-based menu-driven installer for Termux that lets users install and run many penetration testing and hacking tools (e.g.… | 32 | 3705 | maintenance |
| TimothyYe/skm SKM is a command-line SSH key manager written in Go that lets users create, list, alias, switch, back up, and audit multiple SSH keys. It a… | 92 | 1080 | active |
| ydkhatri/mac_apt mac_apt is a Python-based DFIR framework that parses macOS and iOS disk images or live systems to extract forensic artifacts like Safari hi… | 92 | 1080 | stable |
| mandiant/GoReSym GoReSym is a cross-platform CLI tool that extracts symbols, function metadata, types, and program metadata from Go binaries, including stri… | 91 | 1080 | active |
| EchoHS/GeekezBrowser GeekEZ Browser is an anti-detect (fingerprint spoofing) browser built on Electron and Puppeteer with integrated Xray-core proxy support. It… | 83 | 1080 | active |
| tophant-ai/ClawVault ClawVault is a security vault plugin for OpenClaw AI agents that provides fine-grained, composable 'atomic' controls over what agents can a… | 76 | 1080 | active |
| muraenateam/muraena Muraena is an almost-transparent reverse proxy written in Go that automates phishing and post-phishing activities by dynamically proxying a… | 66 | 1080 | active |
| Junyi-99/ChatGPT-API-Scanner A Python CLI tool that scans GitHub for publicly leaked OpenAI API keys using Selenium browser automation. It is intended for security rese… | 58 | 1080 | active |
| Windscribe/Desktop-App The open-source (GPL-2.0) desktop VPN client for the Windscribe service, built in C++ for Windows, macOS, and Linux. It supports multiple V… | 96 | 1079 | active |
| soxoj/socid-extractor socid_extractor is a Python library and CLI that extracts structured account metadata and stable internal identifiers (usernames, UIDs, GAI… | 92 | 1079 | active |
| APTRS/APTRS APTRS (Automated Penetration Testing Reporting System) is a Python/Django and TypeScript web application that automates generation of PDF a… | 72 | 1078 | active |
| hrbrmstr/pewpew IPew is a customizable D3/Datamaps-based HTML/JavaScript visualization for building your own animated IP 'cyber attack' world map, complete… | 50 | 1078 | active |
| AlephNullSK/dnsgen DNSGen is a Python CLI tool that generates intelligent permutations of domain names to aid subdomain discovery during security assessments.… | 32 | 1078 | active |
| danielrobbins/keychain Keychain is a Python-based CLI manager for ssh-agent and gpg-agent that maintains a single long-running agent per user and host, so passphr… | 100 | 1077 | stable |
| m-sec-org/EZ EZ is a cross-platform vulnerability scanner that combines information gathering, port scanning, service brute-forcing, URL crawling, finge… | 24 | 1077 | active |
| semihalev/sdns SDNS is a high-performance recursive DNS resolver server written in Go, with DNSSEC validation and a privacy-first design supporting DNS-ov… | 100 | 1076 | active |
| hahwul/jwt-hack jwt-hack is a fast, single-binary Rust CLI toolkit for testing, analyzing, and attacking JSON Web Tokens (JWT) and JWE tokens. It supports … | 91 | 1076 | active |
| trailofbits/anamorpher Anamorpher is a tool for crafting and visualizing image scaling attacks that hide multi-modal prompt injections in images, revealed only wh… | 55 | 1076 | active |
| xiaogang000/XG_NTAI A Java-based GUI tool for generating obfuscated webshell payloads (ASP, PHP, JSP, JSPX) that evade WAF and antivirus detection, compatible … | 37 | 1076 | active |
| apache/ranger Apache Ranger is a framework to enable, monitor, and manage comprehensive data security across the Hadoop platform and beyond. It provides … | 77 | 1075 | stable |
| zmartzone/lua-resty-openidc A Lua library for NGINX/OpenResty implementing an OpenID Connect Relying Party and OAuth 2.0 Resource Server. It authenticates users via Op… | 81 | 1074 | stable |
| lico-n/ZygiskFrida A Zygisk (and Riru) module for rooted Android devices that injects the Frida gadget into application processes in a stealthy manner. It avo… | 52 | 1074 | active |
| thehackingsage/hackdroid HackDroid is a curated collection of 364+ pentesting and security-related Android apps organized into categories like MITM, forensics, snif… | 32 | 1074 | active |
| knownsec/Kunyu Kunyu is a Python command-line tool for efficient corporate asset collection using cyberspace mapping engines like ZoomEye and Seebug. It h… | 25 | 1074 | active |
| h9zdev/GeoSentinel GeoSentinel is a geospatial monitoring platform that tracks global movement in real time, aggregating ship and flight routes, live coordina… | 57 | 1073 | active |
| rednblkx/HomeKey-ESP32 Firmware for ESP32 boards that implements Apple HomeKit lock functionality with support for Apple Home Key, enabling NFC-based door unlocki… | 79 | 1072 | active |
| qiwentaidi/Slack Slack is an integrated security services toolkit built with Go and the Wails desktop framework, bundling website fingerprinting and vulnera… | 78 | 1072 | active |
| bszapp/android-wifi-pojie An Android WiFi toolbox app written in Kotlin that brute-forces WiFi passwords using password dictionaries, supporting multiple run modes (… | 73 | 1071 | active |
| tomnomnom/assetfinder A Go command-line tool that discovers domains and subdomains potentially related to a given domain by querying multiple passive sources lik… | 23 | 3667 | maintenance |
| QQBackup/qq-win-db-key A collection of Python and Frida scripts for extracting database encryption keys from QQ (Tencent's messenger) across Windows, Linux, macOS… | 72 | 1070 | active |
| nathanlopez/Stitch Stitch is a cross-platform Python Remote Administration Tool (RAT) framework for building custom payloads for Windows, macOS, and Linux. It… | 32 | 3662 | maintenance |
| slashback100/presence_simulation A Home Assistant integration that simulates occupancy while you are away by replaying historical on/off states of lights, switches, covers,… | 90 | 1069 | active |
| bountyyfi/lonkero Lonkero is a professional-grade web application security scanner written in Rust, built for real penetration testing with 125+ scan modules… | 73 | 1069 | active |
| synacktiv/php_filter_chain_generator A Python CLI tool by Synacktiv that generates PHP filter chains (php://filter gadget chains) to achieve remote code execution when an attac… | 32 | 1068 | stable |
| grapheneX/grapheneX grapheneX is an automated system hardening framework that secures Linux and Windows systems by running predefined hardening commands organi… | 27 | 1068 | active |
| margelo/react-native-quick-crypto A fast C/C++ JSI-based implementation of Node's crypto module for React Native, built on Nitro Modules. It serves as a drop-in replacement … | 98 | 1067 | active |
| LandGrey/pydictor pydictor is a Python-based wordlist (dictionary) builder for brute-force and dictionary attacks. It generates general, custom, and social-e… | 23 | 3650 | maintenance |
| mCodex/react-native-sensitive-info A React Native library for hardware-backed secure storage of sensitive data, using iOS Keychain and Android Keystore with AES-GCM encryptio… | 96 | 1066 | active |
| hyugogirubato/KeyDive KeyDive is a Python CLI tool that extracts Widevine L3 DRM keys and device credentials from rooted Android devices using Frida instrumentat… | 80 | 1066 | active |
| THU-BPM/MarkLLM MarkLLM is an open-source Python toolkit for watermarking large language model outputs, implementing multiple LLM watermarking algorithms w… | 65 | 1066 | active |
| broamski/aws-mfa aws-mfa is a Python CLI tool that automates obtaining temporary AWS credentials from the Security Token Service (STS) using MFA and writes … | 32 | 1066 | stable |
| N0rz3/Zehef Zehef is a Python command-line OSINT tool for investigating email addresses. It checks for pastes, data leaks, and linked social media acco… | 29 | 1066 | active |
| salesforce/tough-cookie Tough Cookie is a Node.js library implementing RFC6265 (and RFC6265bis features like SameSite and cookie prefixes) for parsing, storing, an… | 87 | 1065 | active |
| clr2of8/DPAT DPAT is a Python-based Domain Password Audit Tool for penetration testers that analyzes NTDS password dumps combined with cracking results … | 58 | 1065 | active |
| rpgp/rpgp rPGP is a pure Rust implementation of OpenPGP (RFC9580, RFC4880, RFC6637) with a flexible low-level API, published as the `pgp` crate. It s… | 91 | 1064 | active |
| DNSCrypt/doh-server A fast, secure DNS-over-HTTPS (DoH) and Oblivious DoH (ODoH) server proxy written in Rust, formerly known as doh-proxy. It does not resolve… | 78 | 1064 | stable |
| Lazarus-AI/clearwing Clearwing is a dual-mode autonomous offensive-security tool that combines a network-pentest ReAct agent with an LLM-driven source-code vuln… | 63 | 1063 | active |
| ZeroMemoryEx/Chaos-Rootkit Chaos-Rootkit is an x64 Ring 0 Windows kernel rootkit written in C++ as a research project to understand kernel internals and rootkit techn… | 58 | 1063 | active |
| un33k/django-ipware A Django application/library that retrieves the client's real IP address from request headers, handling proxies and load balancers with con… | 32 | 1062 | stable |
| furlongm/openvpn-monitor openvpn-monitor is a Flask web application that displays the status of OpenVPN servers, including all current client connections, their loc… | 70 | 1061 | active |
| ElevenPaths/FOCA FOCA is a Windows desktop application that finds metadata and hidden information in documents discovered via search engines (Google, Bing, … | 23 | 3624 | maintenance |
| farrokhi/dnsdiag A Python-based toolset for measuring, troubleshooting, and auditing DNS. It includes dnsping for latency measurement, dnstraceroute for tra… | 96 | 1060 | active |