domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| drakkan/sftpgo SFTPGo is a full-featured, highly configurable file transfer server supporting SFTP, SCP, FTP/S, HTTP/S, and WebDAV, with pluggable storage… | 93 | 12456 | active |
| future-architect/vuls Vuls is an agent-less vulnerability scanner written in Go that detects CVEs on Linux, FreeBSD, Windows, macOS, containers, WordPress, progr… | 98 | 12243 | active |
| JingMatrix/Vector Vector is a Zygisk module providing a high-performance ART hooking framework for modern Android, maintaining API compatibility with the ori… | 86 | 12237 | active |
| vanhauser-thc/thc-hydra THC-Hydra is a parallelized network login cracker supporting dozens of protocols (SSH, FTP, HTTP forms, SMB, RDP, databases, and more). It … | 80 | 12200 | active |
| rtyley/bfg-repo-cleaner BFG Repo-Cleaner is a command-line tool for removing large files, passwords, credentials, and other unwanted data from Git repository histo… | 24 | 12175 | active |
| open-policy-agent/opa Open Policy Agent (OPA) is a general-purpose, open-source policy engine that unifies policy enforcement across the stack using a high-level… | 99 | 12164 | stable |
| justcallmekoko/ESP32Marauder ESP32 Marauder is a suite of WiFi and Bluetooth offensive and defensive security tools distributed as firmware for ESP32-based hardware. It… | 99 | 12134 | active |
| kubeshark/kubeshark Kubeshark is an eBPF-powered network observability tool for Kubernetes that indexes cluster-wide L4/L7 traffic with full Kubernetes context… | 98 | 12059 | active |
| dstotijn/hetty Hetty is an open source HTTP toolkit for security research, serving as an alternative to Burp Suite Pro. It provides a MITM HTTP proxy with… | 65 | 12007 | active |
| gravitl/netmaker Netmaker is an open-source platform that automates the creation and management of WireGuard-based virtual mesh networks, from homelab to en… | 91 | 11763 | active |
| jason5ng32/MyIP MyIP (IPCheck.ing) is an open-source, self-hostable web application that acts as an all-in-one IP toolbox. It shows your IPv4/IPv6 and geol… | 94 | 11756 | active |
| BishopFox/sliver Sliver is an open-source cross-platform adversary emulation and red team framework written in Go. It generates dynamically compiled implant… | 90 | 11729 | active |
| chaitin/xray xray is a security assessment tool from Chaitin that scans web applications for common vulnerabilities like XSS and SQL injection, supporti… | 23 | 11720 | active |
| kubescape/kubescape Kubescape is an open-source Kubernetes security platform (a CNCF incubating project) offering misconfiguration scanning, vulnerability asse… | 98 | 11692 | active |
| mrexodia/ida-pro-mcp An MCP server and IDA Pro plugin that connects IDA Pro's binary analysis capabilities to language models, enabling AI-assisted reverse engi… | 61 | 11616 | active |
| calesthio/Crucix Crucix is a self-hosted OSINT intelligence terminal that aggregates 27 open-source data feeds (satellite fire detection, flight tracking, r… | 52 | 11566 | active |
| tymondesigns/jwt-auth A PHP library providing JSON Web Token (JWT) authentication for Laravel and Lumen applications. It handles token issuance, refresh, and val… | 66 | 11495 | stable |
| Detect It Easy Detect It Easy (DiE) is a cross-platform file type identification tool that uses signature-based and heuristic analysis to detect compilers… | 81 | 11420 | active |
| 0x4m4/hexstrike-ai HexStrike AI is an MCP server that bridges LLM agents (Claude, GPT, Copilot) with 150+ cybersecurity tools for autonomous penetration testi… | 61 | 11381 | active |
| veracrypt/VeraCrypt VeraCrypt is a free, open-source disk encryption application based on TrueCrypt 7.1a with security enhancements. It creates encrypted volum… | 84 | 11377 | stable |
| apereo/cas Apereo CAS is an enterprise open-source identity provider and single sign-on server implemented in Java on Spring Boot. It centralizes auth… | 99 | 11360 | stable |
| TencentCloud/CubeSandbox CubeSandbox is a high-performance sandbox service for AI agents built on RustVMM and KVM, creating hardware-isolated MicroVM sandboxes in u… | 81 | 11354 | active |
| angristan/wireguard-install A bash script that installs and configures a WireGuard VPN server on Linux with NAT and IPv4/IPv6 support. Re-running the script lets you a… | 68 | 11247 | active |
| hashsigs A Rust library implementing hash-based post-quantum digital signatures (WOTS+ and SHRINCS primitives) with an account policy wrapper. It co… | 62 | 11217 | active |
| QuipNetwork/hashsigs-solidity A Solidity implementation of the Winternitz One-Time Signature Plus (WOTS+) scheme, a hash-based post-quantum signature algorithm. It enabl… | 63 | 11216 | active |
| QuipNetwork/hashsigs-ts A TypeScript library implementing hash-based digital signatures, specifically the WOTS+ (Winternitz One-Time Signature Plus) scheme. It is … | 62 | 11199 | active |
| podman-container-tools/skopeo Skopeo is a command line utility for performing operations on container images and image registries, such as copying, inspecting, deleting,… | 98 | 11194 | stable |
| ifixai-ai/iFixAi iFixAi is an open-source CLI diagnostic tool that independently audits AI agents for misalignment, hallucination, manipulation, deception, … | 81 | 11173 | active |
| daniulive/SmarterStreaming SmarterStreaming (大牛直播SDK/SmartMediaKit) is a proprietary cross-platform low-latency streaming SDK for Windows, Linux, Android, iOS, Harmon… | 67 | 11171 | active |
| dexidp/dex Dex is a federated OpenID Connect (OIDC) and OAuth 2.0 identity provider that issues signed ID tokens (JWTs) for applications. It acts as a… | 86 | 11062 | stable |
| quay/clair Clair is an open-source service for static analysis of vulnerabilities in container images (OCI and Docker). It indexes image contents via … | 74 | 11052 | active |
| 1N3/Sn1per Sn1per is an open-source automated penetration testing and attack surface management platform that chains reconnaissance, scanning, exploit… | 63 | 11043 | active |
| beefproject/beef BeEF (Browser Exploitation Framework) is a penetration testing tool focused on the web browser, hooking one or more browsers and using them… | 72 | 10983 | active |
| BigBodyCobain/Shadowbroker ShadowBroker is a self-hosted OSINT platform that aggregates 60+ real-time public intelligence feeds—aircraft, ships, satellites, CCTV, GPS… | 81 | 10971 | active |
| NopeCHA NopeCHA is an AI-powered CAPTCHA solving service distributed as a browser extension (Chrome/Firefox/Edge) plus Python and Node.js client li… | 93 | 10968 | active |
| AlessandroZ/LaZagne LaZagne is an open-source Python application that recovers passwords stored locally by common software such as browsers, mail clients, WiFi… | 42 | 10963 | active |
| SonarQube SonarQube is a continuous code inspection platform that performs static analysis to track code quality, security vulnerabilities, and techn… | 98 | 10928 | stable |
| google/osv-scanner OSV-Scanner is Google's official CLI and Go library frontend to the OSV.dev vulnerability database, scanning project dependencies across ma… | 99 | 10924 | active |
| bunkerity/bunkerweb BunkerWeb is an open-source, cloud-native Web Application Firewall (WAF) built on NGINX that acts as a reverse proxy to protect web service… | 95 | 10865 | active |
| Monero Monero is the reference implementation of the Monero (XMR) privacy-focused cryptocurrency, including the full node daemon (monerod), wallet… | 93 | 10803 | active |
| pwndbg/pwndbg Pwndbg is a Python-based plug-in for GDB and LLDB that enhances low-level debugging with features tailored to reverse engineering and explo… | 94 | 10801 | active |
| Chia-Network/chia-blockchain The official Python implementation of the Chia blockchain, including full node, farmer, harvester, timelord, and wallet components. It uses… | 93 | 10798 | active |
| yokoffing/Betterfox Betterfox is a curated user.js preference file that hardens Mozilla Firefox for privacy, security, and speed via about:config tweaks. It bu… | 93 | 10795 | active |
| elder-plinius/G0DM0D3 G0DM0D3 is an open-source, multi-model AI chat interface designed for red-teaming, cognition research, and unrestricted LLM interaction. It… | 56 | 10790 | active |
| helmetjs/helmet Helmet is a Node.js middleware library that secures Express and Connect apps by setting HTTP response headers such as Content-Security-Poli… | 75 | 10729 | stable |
| sullo/nikto Nikto is a Perl-based command-line web server scanner that tests servers for dangerous files, outdated software, misconfigurations, and kno… | 89 | 10684 | active |
| rofl0r/proxychains-ng ProxyChains-NG is a UNIX CLI tool that uses LD_PRELOAD to hook socket-related libc functions in dynamically linked programs and redirect th… | 58 | 10672 | active |
| data-privacy-stack/presidio Presidio is an open-source Python SDK for detecting, redacting, masking, and anonymizing sensitive data (PII) in text, images, and structur… | 93 | 10644 | active |
| krzyzanowskim/CryptoSwift CryptoSwift is a pure Swift library providing standard cryptographic algorithms including AES, ChaCha20, SHA family hashes, HMAC, and CRC. … | 81 | 10568 | active |
| blacklanternsecurity/bbot BBOT is a recursive, multipurpose internet scanner built in Python for automating OSINT reconnaissance, bug bounty hunting, and attack surf… | 99 | 10508 | active |
| Dr-TSNG/ZygiskNext Zygisk Next is a standalone implementation of the Zygisk injection framework for Android, providing Zygisk API support for KernelSU and ser… | 98 | 10427 | active |
| pennersr/django-allauth django-allauth is an integrated set of Django applications covering authentication, registration, account management, and third-party (soci… | 76 | 10375 | stable |
| projectdiscovery/httpx httpx is a fast, multi-purpose HTTP toolkit written in Go that runs multiple probes (status codes, titles, TLS certificates, tech detection… | 93 | 10322 | active |
| Astrid Astrid is a portable, capability-secure operating system for composable software, where every component runs as a sealed WebAssembly capsul… | 80 | 10273 | active |
| openai/codex-security OpenAI's Codex Security is a CLI and TypeScript SDK that uses AI to find, validate, and fix security vulnerabilities in codebases. It suppo… | 80 | 10202 | active |
| xykt/IPQuality A shell-based IP quality check script that reports IP type, risk scores from multiple databases, streaming/AI service unlock status, email … | 68 | 10139 | active |
| samratashok/nishang Nishang is a framework and collection of PowerShell scripts and payloads for offensive security, penetration testing, and red teaming. It c… | 23 | 10069 | active |
| shmilylty/OneForAll OneForAll is a powerful Python-based subdomain collection and enumeration tool for reconnaissance. It gathers subdomains via brute forcing,… | 59 | 10029 | active |
| zhishile/codex-auth-helper A Chrome (Manifest V3) browser extension that extracts a logged-in ChatGPT session locally and generates a Codex-compatible auth. credentia… | 59 | 10017 | active |
| CodeQL CodeQL is a semantic code analysis engine that treats code as a queryable database, letting you write queries to find security vulnerabilit… | 77 | 10016 | active |
| thewhiteh4t/seeker Seeker is a security testing tool that hosts a fake website asking users for browser location permission, capturing GPS coordinates (longit… | 72 | 9937 | active |
| majd/ipatool A command-line tool written in Go that lets users search the iOS App Store and download app packages (ipa files) using their Apple ID. It s… | 88 | 9934 | active |
| Flipper-XFW/Xtreme-Firmware Xtreme Firmware is a feature-rich custom firmware for the Flipper Zero multitool device, written in C. It bundles many community apps, adde… | 10 | 9907 | active |
| AGWA/git-crypt git-crypt is a command-line tool that provides transparent encryption and decryption of selected files in a git repository. It lets teams s… | 45 | 9871 | active |
| LaurieWired/GhidraMCP GhidraMCP is a Model Context Protocol server implemented as a Ghidra plugin that exposes Ghidra's reverse engineering tools to LLM clients.… | 34 | 9865 | active |
| OpenCTI-Platform/opencti OpenCTI is an open-source platform for managing cyber threat intelligence knowledge, including observables, TTPs, and threat actor informat… | 95 | 9854 | active |
| paramiko/paramiko Paramiko is a pure-Python implementation of the SSHv2 protocol providing both client and server functionality, built on the cryptography li… | 69 | 9837 | stable |
| go-acme/lego Lego is an ACME client and Go library for obtaining, renewing, and revoking TLS certificates from Let's Encrypt and other ACME CAs. It supp… | 98 | 9835 | active |
| wireshark/wireshark Wireshark is the world's leading open-source network protocol analyzer (packet sniffer) with a Qt GUI, deep inspection of hundreds of proto… | 77 | 9782 | stable |
| ModSecurity ModSecurity (libmodsecurity v3) is an open source, cross-platform web application firewall (WAF) engine written in C++ that inspects HTTP(S… | 90 | 9752 | stable |
| wpscanteam/wpscan WPScan is a black-box WordPress security scanner written in Ruby, used by security professionals and site maintainers to audit WordPress in… | 93 | 9740 | active |
| docker/docker-bench-security Docker Bench for Security is a shell script that automates checks of Docker hosts and containers against the CIS Docker Benchmark best prac… | 61 | 9693 | active |
| TechnitiumSoftware/DnsServer Technitium DNS Server is an open-source, cross-platform authoritative and recursive DNS server built on .NET, designed for self-hosting wit… | 94 | 9655 | stable |
| spring-projects/spring-security Spring Security is a powerful and highly customizable authentication and access-control framework for Java applications, and the de-facto s… | 99 | 9612 | stable |
| malwaredllc/byob BYOB is an open-source post-exploitation framework written in Python, featuring a command-and-control server with a web GUI, a cross-platfo… | 76 | 9498 | active |
| anchore/syft Syft is a CLI tool and Go library that generates Software Bill of Materials (SBOM) documents from container images, filesystems, and archiv… | 98 | 9462 | active |
| cloudflare/cfssl CFSSL is Cloudflare's PKI/TLS toolkit for signing, verifying, and bundling TLS certificates, available as both a command line tool and an H… | 58 | 9462 | stable |
| telekom-security/tpotce T-Pot is an all-in-one, optionally distributed honeypot platform that bundles 20+ honeypots with the Elastic Stack for visualization, live … | 67 | 9443 | active |
| AdAway/AdAway AdAway is a free and open source ad blocker for Android that blocks ads system-wide using the hosts file or a local VPN. It supports both r… | 52 | 9367 | active |
| sensepost/objection objection is a runtime mobile exploration toolkit powered by Frida for assessing the security posture of iOS and Android applications witho… | 88 | 9347 | active |
| Il2CppDumper Il2CppDumper is a C# command-line tool that extracts type, method, and string information from Unity IL2CPP binaries and their global-metad… | 23 | 9339 | active |
| falcosecurity/falco Falco is a CNCF-graduated cloud native runtime security tool for Linux that monitors kernel events (syscalls) via eBPF or kernel modules an… | 94 | 9305 | stable |
| freebsd/freebsd-src The official publish-only Git mirror of the FreeBSD source tree, containing the complete kernel, userland, libraries, boot loader, and buil… | 77 | 9294 | stable |
| unicorn-engine/unicorn Unicorn is a lightweight, multi-architecture CPU emulator framework based on QEMU, supporting ARM, ARM64, M68K, MIPS, PowerPC, RISC-V, SPAR… | 75 | 9268 | stable |
| bitnami/sealed-secrets A Kubernetes controller plus the kubeseal CLI that lets you encrypt Kubernetes Secrets into one-way encrypted SealedSecrets that are safe t… | 99 | 9256 | active |
| git-ecosystem/git-credential-manager Git Credential Manager is a secure, cross-platform Git credential helper built on .NET that stores credentials in the OS-native secure stor… | 93 | 9227 | active |
| golang-jwt/jwt A Go library for creating, signing, parsing, and verifying JSON Web Tokens (JWTs) per RFC 7519. It is the community-maintained successor to… | 78 | 9212 | stable |
| evilsocket/pwnagotchi Pwnagotchi is an A2C deep reinforcement learning agent built on bettercap that learns from its surrounding WiFi environment to maximize cap… | 67 | 9189 | active |
| testssl/testssl.sh testssl.sh is a free, bash-based command line tool that checks any server's service on any port for TLS/SSL cipher, protocol, and cryptogra… | 88 | 9181 | active |
| Next-Flip/Momentum-Firmware Momentum Firmware is a feature-rich, stable, and highly customizable custom firmware for the Flipper Zero multitool device, written in C. I… | 75 | 9081 | active |
| certimate-go/certimate Certimate is a free, open-source, self-hosted ACME tool for managing SSL/TLS certificates with a visual web UI. It automates the full certi… | 85 | 9071 | active |
| firezone/firezone Firezone is an open-source, enterprise-ready zero-trust access platform built on WireGuard that replaces traditional VPNs with granular, po… | 95 | 9042 | active |
| angr angr is a Python 3 binary analysis framework that loads executables across many architectures and formats, providing disassembly, IR liftin… | 77 | 9039 | active |
| NVIDIA/garak garak is a command-line LLM vulnerability scanner that probes large language models for failures like hallucination, data leakage, prompt i… | 91 | 9033 | active |
| frohoff/ysoserial ysoserial is a proof-of-concept command-line tool that generates serialized Java payloads exploiting unsafe object deserialization using ga… | 48 | 9033 | active |
| pocket-id/pocket-id Pocket ID is a self-hosted, OpenID Connect Certified identity provider that lets users sign in to applications using passkeys instead of pa… | 85 | 9029 | active |
| codenotary/immudb immudb is an open-source immutable database written in Go that stores data in SQL, key-value, or document models while guaranteeing tamper-… | 88 | 9023 | stable |
| teamhanko/hanko Hanko is an open-source authentication and user management platform built in Go, offering passwords, passkeys (WebAuthn/FIDO2), MFA, OAuth … | 94 | 9015 | active |
| capstone-engine/capstone Capstone is a lightweight, multi-architecture, multi-platform disassembly framework written in pure C, designed to be the ultimate disassem… | 97 | 8976 | stable |
| bridgecrewio/checkov Checkov is a static code analysis tool for infrastructure as code (Terraform, CloudFormation, Kubernetes, Helm, Dockerfile, and more) that … | 95 | 8973 | stable |