domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| esig/dss DSS (Digital Signature Service) is an open-source Java library from the European Commission for creating, extending, and validating advance… | 85 | 1027 | stable |
| osohq/oso Oso is an embedded authorization framework with a declarative policy language (Polar) for building RBAC, relationships, and collection filt… | 26 | 3490 | maintenance |
| AKCodez/hackingtool-plugin A Claude Code plugin that wraps 183+ pentesting and OSINT tools from Z4nzu/hackingtool, letting Claude automatically select and run securit… | 50 | 1026 | active |
| AsjadOooO/Zero-attacker Zero-attacker is a multipurpose Python-based hacking toolkit bundling 15+ tools for ethical hacking and Discord operations, including DDoS,… | 45 | 1026 | active |
| techchipnet/hound Hound is a lightweight PHP-based information gathering tool that captures a target device's exact GPS coordinates along with system and ISP… | 30 | 1026 | active |
| GrapheneOS/PdfViewer A minimal, permission-free Android PDF viewer built on pdf.js and content providers, developed by the GrapheneOS project. It renders PDFs i… | 98 | 1024 | active |
| fossology/fossology FOSSology is an open source license compliance system and toolkit that scans software for licenses, copyrights, and export control data. It… | 87 | 1024 | active |
| nowsecure/fsmon fsmon is a low-level, cross-platform filesystem monitoring CLI tool written in C that reports real-time file operations (create, delete, mo… | 57 | 1024 | active |
| Dheerajmadhukar/karma_v2 karma_v2 is a Bash-based passive OSINT reconnaissance framework that automates Shodan queries to enumerate assets, exposed services, CVEs, … | 42 | 1024 | active |
| krzyzanowskim/OpenSSL A multiplatform distribution of the OpenSSL C libraries packaged for Swift Package Manager, CocoaPods, and Carthage, targeting iOS, macOS (… | 92 | 1023 | active |
| net-ssh/net-ssh Net::SSH is a pure-Ruby implementation of the SSH2 client protocol, packaged as a Ruby gem. It lets Ruby programs open SSH connections to r… | 75 | 1023 | active |
| SafeAI-Lab-X/ClawKeeper ClawKeeper is a host-agnostic safety middleware layer that sits between AI agents and their tools, blocking risky tool calls, redacting sen… | 59 | 1023 | active |
| openmls/openmls OpenMLS is a Rust implementation of the Messaging Layer Security (MLS) protocol as specified in RFC 9420. It is a library providing safe, e… | 95 | 1022 | active |
| cisagov/thorium Thorium is a scalable, distributed file analysis and data generation platform that orchestrates arbitrary Docker, VM, or shell-based tools … | 74 | 1022 | active |
| dvsekhvalnov/jose-jwt A zero-dependency .NET library implementing the full JOSE suite: JWT generation/decoding, JWE encryption, JWS signatures, and JWK key handl… | 72 | 1022 | active |
| bnoguchi/everyauth everyauth is a Node.js authentication and authorization library supporting password login and many OAuth/OpenID providers (Facebook, Twitte… | 32 | 3471 | maintenance |
| gcarmix/HexWalk HexWalk is a cross-platform GUI hex editor, viewer, and binary analyzer built on qhexedit2, Capstone, and Qt. It combines hex editing with … | 84 | 1021 | active |
| maxcountryman/axum-login A Rust crate providing user identification, authentication, and authorization as tower middleware for the Axum web framework. It supports a… | 65 | 1021 | active |
| jpr5/ngrep ngrep is a PCAP-based command-line tool that applies GNU grep-style regular or hexadecimal expression matching to network packet payloads. … | 74 | 1020 | active |
| 0x6rss/matkap Matkap is a self-hosted web application for hunting malicious Telegram bots used as malware command-and-control infrastructure. It validate… | 65 | 1020 | active |
| hugsy/cemu CEmu is a lightweight assembly playground providing GUI, CLI, and library interfaces for writing, compiling, disassembling, and emulating a… | 23 | 1020 | active |
| LuckyPray/DexKit DexKit is a high-performance dex parsing and deobfuscation library implemented in C++ with Kotlin bindings, used to locate obfuscated class… | 87 | 1019 | active |
| keybase/saltpack Saltpack is a modern crypto messaging format built on the NaCl library, encoding encrypted, signed, and signcrypted messages as MessagePack… | 75 | 1019 | stable |
| mxrch/GitFive GitFive is a Python-based OSINT CLI tool for investigating GitHub user profiles. It uncovers usernames, name history, email addresses, and … | 43 | 1018 | active |
| DeedleFake/trayscale Trayscale is an unofficial GTK4/libadwaita GUI for the Tailscale daemon, built primarily for Linux desktops where no official graphical cli… | 100 | 1017 | active |
| redcode-labs/neurax Neurax is a Go framework for constructing self-spreading binaries (worms) that propagate across LAN/WAN networks without external servers. … | 32 | 1016 | active |
| RuoJi6/audit-skills A lightweight Claude/Codex skill package for AI-assisted source code security auditing, covering Java, .NET, and PHP. It provides vulnerabi… | 73 | 1015 | active |
| secretsquirrel/the-backdoor-factory The Backdoor Factory (BDF) is a Python command-line tool that patches Windows PE, Linux ELF, and macOS Mach-O executables with user-supplie… | 32 | 3442 | maintenance |
| openid/AppAuth-JS AppAuth-JS is a TypeScript client SDK for OAuth 2.0 and OpenID Connect, designed for public clients following RFC 8252 best practices. It s… | 76 | 1014 | active |
| Browserpass Browserpass is a browser extension for zx2c4's pass (the UNIX password store) that auto-fills or copies credentials for the current domain,… | 85 | 1013 | active |
| greatscottgadgets/facedancer A Python library for emulating USB devices using hardware peripherals like Cynthion or GreatFET. It also supports MITM proxying of USB conn… | 83 | 1012 | active |
| nttgin/BGPalerter BGPalerter is a self-configuring, real-time BGP and RPKI monitoring tool that detects prefix visibility loss, hijacks, RPKI invalid announc… | 77 | 1012 | active |
| JackJuly/linkook Linkook is a Python-based OSINT command-line tool that discovers linked social media accounts and associated email addresses across multipl… | 53 | 1012 | active |
| aflnet/aflnet AFLNet is a greybox fuzzer for network protocol server implementations, extending American Fuzzy Lop with state-feedback derived from serve… | 43 | 1012 | active |
| singingwolfboy/flask-dance Flask-Dance is a Python library that simplifies OAuth consumer authentication in Flask applications, built on requests and oauthlib. It pro… | 23 | 1012 | active |
| Sustainsys/Saml2 Sustainsys.Saml2 is a C# library that adds SAML2P support to ASP.NET applications, letting a web site act as a SAML2 Service Provider for s… | 60 | 1010 | active |
| BruceWind/AESJniEncrypt An Android NDK library that implements ChaCha20-Poly1305 encryption via libsodium, with keys hidden in native code to resist reverse engine… | 23 | 1010 | active |
| fullhunt/log4j-scan A Python-based automated scanner for detecting the Log4j RCE vulnerability (CVE-2021-44228, Log4Shell) and related CVEs across lists of URL… | 23 | 3422 | maintenance |
| auth0/auth0-spa-js Auth0's official JavaScript SDK for adding authentication to Single Page Applications using the Authorization Code Grant flow with PKCE. It… | 98 | 1009 | active |
| indetectables-net/toolkit A curated Windows toolkit bundling 101 applications for reverse engineering, malware analysis, and cracking, installed via an automated Inn… | 89 | 1009 | active |
| wang-rui/phishguard-scaffold PhishGuard is a Python research framework that jointly performs phishing detection and dissemination control on social media using LLaMA-ba… | 47 | 1009 | active |
| dedsec1121fk/DedSec DedSec Project is an educational cybersecurity and Termux toolkit for Android that bundles scripts, utilities, local web interfaces, and pr… | 88 | 1008 | active |
| tarunkant/Gopherus Gopherus is a Python CLI tool that generates Gopher protocol payloads for exploiting SSRF vulnerabilities to achieve remote code execution.… | 32 | 3411 | maintenance |
| AthenZ/athenz Athenz is an open source platform for X.509 certificate-based service authentication and fine-grained role-based access control (RBAC) in d… | 100 | 1006 | active |
| akaunting/laravel-firewall A Web Application Firewall (WAF) package for Laravel that protects applications from attacks like XSS, SQLi, RFI, LFI, and malicious user a… | 75 | 1006 | active |
| seeden/rbac A Node.js library implementing hierarchical role-based access control (RBAC) with roles, permissions, and grant inheritance. It supports in… | 69 | 1005 | active |
| d78ui98/APKDeepLens APKDeepLens is a Python-based static analysis tool that decompiles Android APK files with JADX and scans them for security vulnerabilities … | 64 | 1005 | active |
| ki9mu/ARL-plus-docker A Docker-based fork of ARL (Asset Reconnaissance Lighthouse) v2.6.2 that performs automated asset discovery and vulnerability scanning for … | 35 | 1005 | active |
| libreswan/libreswan Libreswan is a free, GPLv2-licensed implementation of the Internet Key Exchange (IKE) protocol for setting up IPsec VPNs, supporting IKEv1 … | 99 | 1004 | active |
| microsoft/DevSkim DevSkim is a Microsoft security linting framework consisting of IDE extensions, a .NET CLI, and a rule engine that flags security issues in… | 98 | 1004 | active |
| Tencent/TencentKona-8 Tencent Kona 8 is a no-cost, production-ready distribution of OpenJDK 8 with long-term support and quarterly updates, serving as the defaul… | 92 | 1004 | stable |
| odedshimon/BruteShark BruteShark is an open-source Network Forensic Analysis Tool (NFAT) that deeply inspects network traffic from PCAP/PCAPng files or live capt… | 23 | 3396 | maintenance |
| siyuanchen0214/Scam-AI-Multi-modal-Evaluation-System A Python-based multi-modal AI system for detecting fraudulent content across text, image, audio, and video, with provenance tracing and cro… | 39 | 1001 | active |
| noraj/haiti Haiti is a CLI tool and Ruby library that identifies hash types, detecting 675+ hash formats including modern algorithms like SHA3, Keccak,… | 76 | 1000 | active |
| controlplaneio/simulator A distributed systems and infrastructure security training platform that provisions a Kubernetes cluster in your AWS account and runs scena… | 23 | 1000 | active |
| hybridauth/hybridauth Hybridauth is an open-source PHP library for social sign-on that acts as an abstract API between your application and social identity provi… | 76 | 3383 | maintenance |
| linkedin/qark QARK (Quick Android Review Kit) is a Python command-line tool from LinkedIn that scans Android applications, either as Java source code or … | 23 | 3383 | maintenance |
| ezyang/htmlpurifier HTML Purifier is a PHP library that filters HTML input using whitelists and aggressive parsing to remove XSS attacks while producing standa… | 71 | 3352 | maintenance |
| stephenfewer/ReflectiveDLLInjection A C library implementing reflective DLL injection, a technique for loading a library from memory into a host Windows process without touchi… | 32 | 3352 | maintenance |
| codingo/NoSQLMap NoSQLMap is an open-source Python command-line tool that audits, automates injection attacks against, and exploits default configuration we… | 65 | 3344 | maintenance |
| OAuthSwift/OAuthSwift OAuthSwift is a Swift framework implementing OAuth 1.0 and OAuth 2.0 client authentication for iOS and macOS apps. It provides URL-scheme-b… | 23 | 3331 | maintenance |
| gwen001/pentest-tools A collection of small custom security scripts in Bash, Python, and PHP for penetration testing and bug bounty quick tasks, covering DNS enu… | 23 | 3328 | maintenance |
| nabla-c0d3/ssl-kill-switch2 SSL Kill Switch 2 is a blackbox Cydia Substrate tweak that disables SSL/TLS certificate validation, including certificate pinning, in iOS a… | 23 | 3314 | maintenance |
| s-rah/onionscan OnionScan is a free and open source Go CLI tool for investigating Tor hidden services (.onion sites) on the Dark Web. It scans sites for op… | 23 | 3294 | maintenance |
| EasyHook/EasyHook EasyHook is a Windows API hooking library that lets you intercept and extend unmanaged code APIs with managed (.NET) or native hook handler… | 23 | 3293 | maintenance |
| notaryproject/notary Notary is a Go implementation of The Update Framework (TUF), providing a client and server for signing and verifying trusted collections of… | 10 | 3286 | maintenance |
| SpacehuhnTech/WiFiDuck WiFi Duck is an open-source firmware for ESP8266 + ATmega32u4 hardware that emulates a USB keyboard to perform keystroke injection (BadUSB)… | 23 | 3285 | maintenance |
| Ignitetch/AdvPhishing A command-line phishing toolkit that hosts fake login pages for popular services (Facebook, Google, Paytm, Zomato, etc.) and performs real-… | 50 | 3277 | maintenance |
| jbtronics/CrookedStyleSheets A proof-of-concept demonstrating website tracking and analytics using only CSS, without any JavaScript. It detects browser type, screen res… | 32 | 3270 | maintenance |
| bshaffer/oauth2-server-php A PHP library for implementing an OAuth 2.0 authorization/token server into PHP applications. It supports pluggable storage (e.g., PDO) and… | 29 | 3270 | maintenance |
| DhavalKapil/icmptunnel icmptunnel is a C command-line tool that transparently encapsulates IP traffic inside ICMP echo and reply packets, tunneling it through a p… | 23 | 3253 | maintenance |
| MaximeBeasse/KeyDecoder KeyDecoder is a Flutter mobile app that lets pentesters and security enthusiasts measure the bitting of a mechanical key from a photo, usin… | 23 | 3194 | maintenance |
| sensepost/reGeorg reGeorg is a Python tool that creates a SOCKS proxy through a compromised bastion webserver by tunneling traffic over HTTP(S) via uploaded … | 37 | 3184 | maintenance |
| fancycode/MemoryModule A C library that loads Windows DLLs entirely from memory without writing them to disk, bypassing the filesystem-only limitation of LoadLibr… | 32 | 3157 | maintenance |
| ChatSecure/ChatSecure-iOS ChatSecure is a free and open source encrypted chat client for iOS that supports OTR and OMEMO end-to-end encryption over XMPP, with option… | 23 | 3154 | maintenance |
| Hax4us/Nethunter-In-Termux A shell script that installs Kali NetHunter (Kali Linux) inside the Termux app on Android without requiring a rooted phone. It provides com… | 32 | 3134 | maintenance |
| tomnomnom/httprobe httprobe is a Go command-line tool that takes a list of domains on stdin and probes for working HTTP and HTTPS servers, reporting which res… | 23 | 3121 | maintenance |
| salesforce/ja3 JA3 is a standard and set of scripts (Python and Zeek) for generating SSL/TLS client fingerprints that are easy to produce and share for th… | 10 | 3100 | maintenance |
| andrewyng/openworker OpenWorker is an open-source desktop AI agent application that completes real work end-to-end — code security reviews with fix branches, cl… | 80 | 17302 | experimental |
| kishikawakatsumi/UICKeyChainStore UICKeyChainStore is an Objective-C wrapper library for the Apple Keychain on iOS, watchOS, tvOS, and macOS, making Keychain APIs as simple … | 23 | 3083 | maintenance |
| teler-sh/teler teler is a real-time HTTP intrusion detection system that analyzes web server logs and alerts on threats using threat intelligence and cust… | 10 | 3082 | maintenance |
| plasma-disassembler/plasma Plasma is an interactive disassembler for x86/x86-64, ARM, and MIPS binaries that generates indented pseudo-code with colored syntax. It su… | 32 | 3071 | maintenance |
| WindySha/Xpatch Xpatch is a Java CLI tool that repackages and re-signs Android APK files so the resulting APK can load installed Xposed modules. It enables… | 50 | 3060 | maintenance |
| risinek/esp32-wifi-penetration-tool An extensible Wi-Fi penetration testing framework for the ESP32 microcontroller, implementing attacks such as PMKID capture, WPA/WPA2 hands… | 23 | 3058 | maintenance |
| 0x0be/yesitsme A Python CLI script for OSINT investigations that finds Instagram profiles matching a given name, e-mail, or phone number. It scrapes dumpo… | 32 | 3055 | maintenance |
| momosecurity/aswan Aswan is Momo's open-source risk-control static rule engine, a self-hosted Python/Django service for configuring blacklist/whitelist, boole… | 32 | 3046 | maintenance |
| NYAN-x-CAT/AsyncRAT-C-Sharp AsyncRAT is an open-source Remote Access Tool (RAT) written in C# that lets an operator remotely monitor and control Windows client machine… | 23 | 3020 | maintenance |
| pooler/cpuminer A multi-threaded CPU miner for Litecoin and Bitcoin, forked from Jeff Garzik's reference cpuminer. It supports SIMD optimizations (SSE2, AV… | 23 | 3011 | maintenance |
| joestump/python-oauth2 A Python library providing a fully tested, abstract interface for building OAuth 1.0 clients and servers. It is a fork of the original pyth… | 32 | 3010 | maintenance |
| arthepsy/ssh-audit ssh-audit is a dependency-free Python CLI tool that audits SSH servers by grabbing banners and enumerating key exchange, host key, encrypti… | 32 | 2995 | maintenance |
| jaeles-project/gospider GoSpider is a fast web spider/crawler written in Go that crawls sites in parallel and extracts URLs from sitemaps, robots.txt, JavaScript f… | 23 | 2995 | maintenance |
| rajkumardusad/IP-Tracer IP-Tracer is a command-line tool for Linux and Termux that retrieves geolocation and information about any IP address using the ip-api serv… | 23 | 2990 | maintenance |
| noob-hackers/infect Infect is a Bash-based Termux script that generates a link which, when opened on an Android device, executes a destructive payload that for… | 50 | 2986 | maintenance |
| ac-pm/Inspeckage Inspeckage is an Xposed module that performs dynamic analysis of Android applications by hooking Android API functions to observe runtime b… | 23 | 2983 | maintenance |
| SUSE/Portus Portus is an open-source authorization service and web UI for the Docker Registry v2 API, providing fine-grained push/pull permissions via … | 10 | 2981 | maintenance |
| christophetd/CloudFlair CloudFlair is a Python CLI tool that finds the origin servers of websites protected by Cloudflare or CloudFront by searching Censys interne… | 41 | 2975 | maintenance |
| Threezh1/JSFinder JSFinder is a Python command-line tool that crawls a website's JavaScript files and extracts URLs and subdomains using regex parsing. It su… | 32 | 2975 | maintenance |
| google/nogotofail Nogotofail is an on-path (man-in-the-middle) blackbox network traffic security testing tool built in Python. It detects weak TLS/SSL connec… | 10 | 2951 | maintenance |
| Jermic/Android-Crack-Tool A macOS GUI application that bundles common Android APK reverse-engineering tools (Apktool, Dex2Jar, JD-GUI, SignApk, Zipalign) into one in… | 23 | 2941 | maintenance |
| Ekultek/WhatWaf WhatWaf is a Python command-line tool that detects web application firewalls (WAFs) protecting a target web application and attempts to fin… | 23 | 2922 | maintenance |