domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| cdxgen/cdxgen cdxgen is a CLI tool, library, and server that creates CycloneDX Bill of Materials (SBOM) documents from source code and container images, … | 95 | 1060 | active |
| rogue-security/rogue Rogue is an open-source AI agent evaluator and red teaming platform that stress-tests agents against business policies and simulated advers… | 78 | 1060 | active |
| ovh/debian-cis A set of modular shell scripts that audit and harden Debian 11/12/13 systems according to CIS security benchmarks, used in production at OV… | 78 | 1060 | active |
| echo094/decode-js A Node.js CLI tool built on Babel that analyzes and reverses obfuscated JavaScript back into readable source. It supports common obfuscatio… | 77 | 1060 | active |
| bitsadmin/nopowershell NoPowerShell is a C# implementation of PowerShell-like commands that avoids using System.Management.Automation.dll, making execution invisi… | 59 | 1060 | active |
| lijiejie/subDomainsBrute A fast DNS subdomain brute-forcing tool for penetration testers, written in Python with multi-process and coroutine support. It enumerates … | 23 | 3620 | maintenance |
| duo-labs/py_webauthn A Python 3 library implementing the server-side of the WebAuthn API for verifying FIDO2 credential registration and authentication. It supp… | 88 | 1059 | active |
| cisco-ai-defense/mcp-scanner MCP Scanner is a Python tool and SDK from Cisco AI Defense that scans Model Context Protocol (MCP) servers, tools, prompts, and resources f… | 83 | 1059 | active |
| vigolium/vigolium Vigolium is a high-fidelity web vulnerability scanner written in Go that combines deterministic multi-phase scanning (317 modules for conte… | 82 | 1059 | active |
| Cloxl/xhshow A pure-algorithm Python library that generates Xiaohongshu (XHS/RedNote) request signature headers such as x-s, x-s-common, x-t, and x-rap-… | 76 | 1059 | active |
| MatthewKuKanich/CAN_Commander CAN Commander is a tool for reverse engineering and analyzing CAN bus systems, pairing a Flipper Zero app with ESP32 firmware to interact w… | 63 | 1059 | active |
| darkk/redsocks redsocks is a transparent TCP-to-proxy redirector written in C that uses firewall rules (iptables, pf, ipfw) to redirect any TCP connection… | 32 | 3618 | maintenance |
| auth0/auth0.js Auth0's client-side JavaScript SDK for browser-based authentication and authorization against the Auth0 platform. It provides WebAuth, Auth… | 94 | 1058 | active |
| lachlan2k/React2Shell-CVE-2025-55182-original-poc A collection of original proof-of-concept exploits for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server … | 41 | 1058 | active |
| chainreactors/spray Spray is a high-performance HTTP directory fuzzing and content discovery tool written in Go, positioned as a next-generation alternative to… | 93 | 1057 | active |
| YeeZTech/YeeZ-Privacy-Computing Fidelius is a privacy computing middleware built on Intel SGX trusted execution environments, enabling secure data collaboration where orig… | 69 | 1057 | active |
| vitoplantamura/BugChecker BugChecker is a SoftICE-like kernel and user-mode debugger for Windows (XP through 11, x86 and x64) that runs entirely on the machine being… | 22 | 1057 | active |
| jjolano/shadow Shadow is a jailbreak detection bypass tweak for jailbroken iOS devices, hooking detection APIs so apps cannot detect the jailbreak. It sup… | 88 | 1056 | active |
| Fahrj/reverse-ssh A statically-linked SSH server written in Go with reverse connection functionality, designed for remote access during CTFs, HackTheBox chal… | 65 | 1056 | active |
| ziesha-network/bazuka Bazuka is the wallet and node software for the Ziesha Protocol, a layer-1 proof-of-stake cryptocurrency that uses zero-knowledge proofs (Ze… | 32 | 1056 | active |
| madneal/gshark GShark is a self-hosted sensitive information detection and management platform that scans repositories exposed by providers like GitHub, G… | 100 | 1055 | active |
| Zarcolio/sitedorks A Python CLI tool that runs Google dork-style searches across multiple search engines (Google, Bing, DuckDuckGo, Yandex, Yahoo, Ecosia, Bra… | 76 | 1055 | active |
| NetSPI/PowerHuntShares PowerHuntShares is a PowerShell audit tool that inventories, analyzes, and reports excessive privileges on SMB share ACLs across Active Dir… | 53 | 1055 | active |
| shadowsocks/ChinaDNS ChinaDNS is a C-based local DNS server that prevents DNS poisoning by routing Chinese domain queries to local DNS servers and foreign domai… | 23 | 3603 | maintenance |
| mwiede/jsch JSch (Java Secure Channel) is a pure Java implementation of the SSH2 protocol, maintained as an actively updated fork of the original JCraf… | 99 | 1054 | active |
| apkunpacker/MagiskDetection A curated collection of publicly available proof-of-concept Android apps that detect root, Magisk, Zygisk, and hooking frameworks like Frid… | 68 | 1054 | active |
| 61418/aws-sso-util aws-sso-util is a Python command-line tool and library that smooths out rough edges of AWS IAM Identity Center (formerly AWS SSO). It provi… | 40 | 1054 | active |
| robotshell/magicRecon MagicRecon is a Bash shell script that automates reconnaissance and vulnerability scanning of target domains, including subdomain enumerati… | 23 | 1054 | active |
| ysrc/xunfeng Xunfeng is a self-hosted web application for rapid vulnerability emergency response and continuous scanning of enterprise internal networks… | 23 | 3597 | maintenance |
| christiaangoossens/hass-oidc-auth A Home Assistant custom integration that adds OpenID Connect (OIDC) single sign-on authentication. It acts as a standards-compliant relying… | 99 | 1053 | active |
| endojs/endo Endo is a JavaScript framework for building secure plugin systems and resisting supply chain attacks, built on the SES (Secure ECMAScript) … | 95 | 1053 | stable |
| D0n9X1n/hexo-blog-encrypt A Hexo plugin that encrypts blog posts with passwords so only readers with the correct password can view the content. It works with the Hex… | 89 | 1053 | active |
| secure-software-engineering/phasar PhASAR is a LLVM-based static analysis framework written in C++20 that solves user-specified data-flow problems automatically on LLVM IR. I… | 81 | 1053 | active |
| TypeError/secure A lightweight, dependency-free Python library for defining and applying HTTP security headers across Python web frameworks via ASGI/WSGI mi… | 79 | 1053 | active |
| securisec/chepy Chepy is a Python library and CLI tool that mirrors many capabilities of CyberChef, allowing data transformations like encoding, decoding, … | 75 | 1053 | active |
| authomatic/authomatic Authomatic is a framework-agnostic Python library that simplifies user authentication and authorization via third-party providers like Face… | 57 | 1053 | active |
| nshalabi/ATTACK-Tools A collection of utilities for working with the MITRE ATT&CK framework, including a relational SQLite data model of ATT&CK data enriched wit… | 50 | 1053 | active |
| emanuele-em/proxelar Proxelar is a scriptable local MITM proxy workbench written in Rust for inspecting, intercepting, replaying, and rewriting HTTP, HTTPS, and… | 96 | 1052 | active |
| p0dalirius/smbclient-ng smbclient-ng is a Python command-line tool providing a fast, user-friendly interactive shell for interacting with SMB shares on remote Wind… | 82 | 1052 | active |
| 0xZDH/o365spray o365spray is a Python CLI tool for username enumeration and password spraying against Microsoft Office 365 domains. It implements multiple … | 32 | 1052 | active |
| smoochiee/Bluetooth-jammer-esp32 An ESP32 firmware project that uses NRF24L01 radio modules to generate 2.4GHz noise signals that jam Bluetooth and WiFi devices. It include… | 10 | 1052 | active |
| liujingxing/XmlClassGuard A Gradle plugin that obfuscates Android classes referenced in XML files, such as the four major components and custom Views, which ProGuard… | 23 | 1051 | active |
| projectdiscovery/cloudlist Cloudlist is a multi-cloud CLI tool written in Go that lists assets from multiple cloud providers such as AWS, GCP, and Azure. It is intend… | 89 | 1050 | active |
| ac3ss0r/obfusheader.h Obfusheader.h is a portable, header-only C++14 library providing compile-time obfuscation via metaprogramming, including string and constan… | 27 | 1050 | active |
| smxiazi/NEW_xp_CAPTCHA xp_CAPTCHA is a Burp Suite extension (Java plugin) that automatically recognizes CAPTCHAs during brute-force attacks, using a companion Pyt… | 23 | 1050 | active |
| google/fuzztest FuzzTest is a C++ testing framework for writing fuzz tests, which are property-based tests executed with coverage-guided fuzzing under the … | 88 | 1049 | active |
| chAng-L19/codex-redteam-mode An opt-in red-team mode plugin for OpenAI Codex App and Codex CLI that compiles offensive-security objectives into GoalContracts and execut… | 80 | 1049 | active |
| jeremykenedy/laravel-roles A Laravel package for managing roles, permissions, and user levels with Eloquent integration, including Blade extensions, middleware, and a… | 76 | 1048 | stable |
| wh201906/Proxmark3GUI A cross-platform Qt5 graphical interface for the Proxmark3 RFID research tool, wrapping the official and Iceman fork clients. It provides a… | 57 | 1048 | active |
| paradiseduo/appdecrypt A Swift CLI tool that decrypts FairPlay-encrypted Mach-O application binaries on macOS (SIP-enabled, macOS 11.3 or below, with newer suppor… | 56 | 1048 | active |
| lijiejie/GitHack GitHack is a Python CLI exploit tool that reconstructs a website's source code from an exposed .git folder. It parses the .git/index file, … | 32 | 3574 | maintenance |
| Jacobtims/filament-breezy A Filament plugin for Laravel that adds enhanced security features to Filament admin panels, including a customizable profile page, two-fac… | 97 | 1047 | active |
| Ullaakut/nmap An idiomatic Go library that wraps the nmap network scanner by shelling out to the nmap binary and parsing its XML output. It lets Go devel… | 90 | 1047 | active |
| xm1k3/cent Cent is a Go CLI tool that aggregates and organizes community-contributed Nuclei vulnerability scanning templates into a single local folde… | 81 | 1047 | active |
| Vuemony/vue-after-free A PlayStation 4 userland code execution exploit delivered through the PlayStation Vue app, chained with kernel exploits (Lapse, Poopsploit/… | 67 | 1047 | active |
| romanz/amodem A Python library and CLI tool that transmits files between computers by modulating data into audio signals (OFDM) played through a speaker … | 55 | 1047 | active |
| secureblue/secureblue secureblue is a security-focused desktop and server Linux operating system built as OCI bootable container images on top of Fedora Atomic D… | 91 | 1046 | active |
| jonrau1/ElectricEye ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for asset management, security posture management, and attack surface monitoring. … | 62 | 1045 | active |
| apple/security-pcc Apple's source code for Private Cloud Compute (PCC), the infrastructure that runs Apple Intelligence requests in a privacy-preserving cloud… | 59 | 1045 | active |
| mandatoryprogrammer/thermoptic Thermoptic is a stealth HTTP proxy that routes requests from any HTTP client (like curl) through a containerized Chrome instance so the tra… | 51 | 1045 | active |
| splx-ai/agentic-radar Agentic Radar is an open-source security scanner that analyzes LLM agentic workflows built with popular frameworks (e.g., CrewAI, LangGraph… | 53 | 1044 | active |
| kelvinBen/AppInfoScanner A Python-based static information-gathering scanner for mobile apps (Android APK/DEX, iOS IPA/Mach-O) and static web content (HTML, JS, H5)… | 23 | 3558 | maintenance |
| brichard19/BitCrack BitCrack is a C++ command-line tool for brute-forcing Bitcoin private keys using CUDA (NVIDIA) or OpenCL (AMD/Intel) GPU acceleration. It w… | 23 | 1043 | active |
| amlweems/xzbot A research toolkit for the xz backdoor (CVE-2024-3094) containing an OpenSSH honeypot patch to detect exploit attempts, a patch script to r… | 25 | 3553 | maintenance |
| buffer/thug Thug is a Python low-interaction honeyclient that mimics the behavior of a web browser to detect and emulate malicious web content. It comp… | 87 | 1042 | active |
| aramperes/onetun onetun is a cross-platform, user-space WireGuard port-forwarder written in Rust that forwards local TCP/UDP ports to peers on a WireGuard n… | 56 | 1041 | active |
| topjohnwu/zygisk-module-sample An official template repository by the Magisk author for building Zygisk modules, which inject code into Android's Zygote process. It inclu… | 10 | 1041 | stable |
| Spade-sec/First A WeChat mini-program security debugging tool (fork/extension of WMPFDebugger) that uses Frida injection and Chrome DevTools Protocol bridg… | 74 | 1040 | active |
| bnb-chain/tss-lib A Go library implementing multi-party threshold signature schemes (TSS) for ECDSA and EdDSA, based on the Gennaro-Goldfeder CCS 2018 protoc… | 70 | 1040 | active |
| Velocidex/WinPmem WinPmem is an open-source Windows physical memory acquisition tool with a signed kernel driver and standalone imager executables. It dumps … | 44 | 1040 | active |
| firewalld/firewalld firewalld is a dynamically managed firewall daemon for Linux that provides zone-based trust levels for network connections and interfaces, … | 97 | 1039 | stable |
| mitmproxy/android-unpinner A Python CLI tool that removes certificate pinning from Android APKs so traffic can be intercepted with mitmproxy, without requiring a root… | 54 | 1039 | active |
| exein-io/pulsar Pulsar is a modular, eBPF-powered runtime security and observability tool for Linux devices, written in Rust and designed for IoT and edge … | 48 | 1039 | active |
| Anorov/cloudflare-scrape A Python module (cfscrape) built on Requests that bypasses Cloudflare's JavaScript anti-bot challenge page ('I'm Under Attack Mode') so scr… | 23 | 3536 | maintenance |
| trezor/trezor-suite Trezor Suite is the official desktop, web, and mobile application for managing Trezor hardware wallets, enabling users to send, receive, bu… | 95 | 1038 | active |
| nickvourd/Supernova Supernova is an open-source command-line tool written in Go for encrypting and obfuscating raw shellcode. It supports multiple ciphers incl… | 87 | 1038 | active |
| PhonePe/mantis Mantis is a command-line security framework that automates asset discovery, reconnaissance, and vulnerability scanning for given top-level … | 67 | 1038 | active |
| jaredhanson/oauth2orize OAuth2orize is a Node.js toolkit for building OAuth 2.0 authorization servers. It provides Express-compatible middleware plus a pluggable s… | 32 | 3533 | maintenance |
| dyc3/steamguard-cli A Rust command-line utility for setting up and using Steam Mobile Authenticator (2FA). It generates Steam Guard codes and handles trade, ma… | 93 | 1037 | active |
| centerforaisafety/HarmBench HarmBench is a standardized, open-source evaluation framework for automated red teaming of large language models, comparing attack methods … | 26 | 1037 | active |
| vanhoefm/krackattacks-scripts Scripts by Mathy Vanhoef to test whether Wi-Fi clients or access points are vulnerable to the KRACK attack against WPA2. They include a mod… | 23 | 3530 | maintenance |
| in-toto/in-toto in-toto is a Python framework and reference implementation of the in-toto specification for protecting software supply chain integrity. It … | 81 | 1036 | stable |
| django-recaptcha/django-recaptcha A Django app providing form fields and widgets for integrating Google reCAPTCHA (v2 checkbox, v2 invisible, and v3) into Django forms. It h… | 67 | 1036 | active |
| TheRook/subbrute SubBrute is a Python DNS meta-query spider that enumerates subdomains and arbitrary DNS record types by leveraging open resolvers to bypass… | 23 | 3527 | maintenance |
| cdklabs/cdk-nag cdk-nag is a library that checks AWS CDK applications and CloudFormation templates for best practices using pre-built rule packs such as AW… | 94 | 1035 | active |
| ZhangJinHaHaHa/AgentLens AgentLens is a trust-first AI Agent marketplace and workspace where users can discover, compare, and rent task-specific Agents backed by sm… | 59 | 1035 | active |
| zhzyker/vulmap Vulmap is a Python 3 command-line tool that scans web applications for known CVE vulnerabilities and can immediately verify or exploit them… | 23 | 3522 | maintenance |
| denoland/clawpatrol Claw Patrol is a security firewall and proxy for AI agents, written in Go, that intercepts agent traffic at the wire level and gates each a… | 80 | 1034 | active |
| googlesamples/android-testdpc Test DPC is a sample Device Policy Controller app for Android Enterprise that lets developers test how their apps behave in managed context… | 52 | 1034 | active |
| EdgeSecurityTeam/EHole EHole (棱洞) is a Go-based fingerprint identification tool for red team reconnaissance that pinpoints high-value, easily attackable systems (… | 23 | 3517 | maintenance |
| square/certigo Certigo is a Go command-line utility for examining, dumping, and validating TLS/SSL certificates in formats like X.509 (DER/PEM), PKCS7, PK… | 73 | 1033 | stable |
| carlospolop/legion Legion is a Python-based automatic enumeration tool that orchestrates well-known open-source pentesting tools (nmap, hydra, metasploit) to … | 74 | 1032 | active |
| aaugustin/django-sesame django-sesame is a Python library that adds 'Magic Links' authentication to Django projects by generating URLs containing signed authentica… | 59 | 1032 | active |
| UnnoTed/wireguird A GTK-based graphical GUI client for WireGuard on Linux, mimicking the official Windows WireGuard client. It lists tunnels from /etc/wiregu… | 59 | 1031 | active |
| Exodus-Privacy/exodus-android-app The εxodus Android app shows which trackers are embedded in the apps installed on your smartphone and lists the permissions each app requir… | 47 | 1031 | active |
| kyleavery/AceLdr AceLdr is a position-independent reflective loader (UDRL) for Cobalt Strike written in C, designed to evade memory scanners like Moneta, PE… | 23 | 1031 | active |
| google/fscrypt fscrypt is a Go command-line tool for managing Linux native filesystem encryption (fscrypt API) on filesystems like ext4 and f2fs. It handl… | 88 | 1029 | active |
| pingooio/pingoo Pingoo is a self-hosted load balancer, API gateway, and reverse proxy written in Rust, positioned as an open-source alternative to Cloudfla… | 58 | 1029 | active |
| k3yomi/Wall-of-Flippers Wall of Flippers is a Python-based tool for discovering Flipper Zero devices and detecting Bluetooth Low Energy based attacks. It provides … | 57 | 1029 | active |
| a16z/halmos Halmos is a symbolic testing tool for EVM smart contracts, primarily targeting Solidity projects via a Foundry frontend. It leverages exist… | 50 | 1028 | active |