domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| laverdet/isolated-vm A Node.js library providing access to V8 isolates to create completely isolated JavaScript environments. It lets you run untrusted or sandb… | 79 | 2911 | maintenance |
| lastpass/lastpass-cli lastpass-cli is an official command line interface to the LastPass password manager, written in C. It lets users log in, list, add, edit, c… | 30 | 2911 | maintenance |
| matthewpalmer/Locksmith Locksmith is a protocol-oriented Swift library for interacting with the iOS, macOS, watchOS, and tvOS keychain. It provides a simple API fo… | 23 | 2911 | maintenance |
| biometrics/openbr OpenBR is an open-source biometrics library and command-line tool focused on face recognition, written in C++ on top of Qt and OpenCV. It p… | 50 | 2903 | maintenance |
| mrd0x/BITB A collection of HTML/JavaScript templates implementing the Browser In The Browser (BITB) phishing technique, which renders fake browser win… | 32 | 2900 | maintenance |
| airbnb/streamalert StreamAlert is a serverless, real-time data analysis framework from Airbnb for ingesting, analyzing, and alerting on log data from any envi… | 23 | 2890 | maintenance |
| seemoo-lab/nexmon Nexmon is a C-based firmware patching framework for Broadcom/Cypress WiFi chips that enables custom firmware modifications such as monitor … | 64 | 2885 | maintenance |
| Bitmessage/PyBitmessage PyBitmessage is the reference client for Bitmessage, a peer-to-peer protocol for sending encrypted, authenticated messages without central … | 61 | 2881 | maintenance |
| pentestmonkey/php-reverse-shell A PHP script that opens an interactive reverse shell connection back to an attacker-controlled listener. It is a well-known utility for pen… | 32 | 2861 | maintenance |
| AntSwordProject/AntSword-Loader AntSword Loader is the official Electron-based launcher for AntSword, a cross-platform webshell management and post-exploitation tool used … | 23 | 2837 | maintenance |
| seclab-ucr/INTANG INTANG is a Linux daemon that evades the Great Firewall of China's TCP reset attacks by desynchronizing the TCP Control Block on censorship… | 44 | 2833 | maintenance |
| tiagorlampert/CHAOS CHAOS is a free and open-source Remote Administration Tool written in Go that generates cross-platform binaries (Windows and Linux) for con… | 23 | 2833 | maintenance |
| grayddq/GScan GScan is a Python-based CLI security tool that automates comprehensive Linux host security checks for incident response. It scans for backd… | 23 | 2828 | maintenance |
| welk1n/JNDI-Injection-Exploit A Java-based penetration testing tool that generates workable JNDI links and starts RMI, LDAP, and HTTP servers to exploit JNDI injection v… | 23 | 2827 | maintenance |
| ohpe/juicy-potato Juicy Potato is a C++ Windows local privilege escalation tool that abuses COM/DCOM activation and impersonation privileges (SeImpersonate/S… | 23 | 2822 | maintenance |
| aydinnyunus/Keylogger A Python-based keylogger that captures keyboard, mouse, screenshot, and microphone inputs from a target computer and emails the data via SM… | 32 | 2819 | maintenance |
| esc0rtd3w/wifi-hacker A shell script that automates attacking wireless connections using the built-in tools of Kali Linux. It supports WEP, WPS, WPA, and WPA2 se… | 23 | 2803 | maintenance |
| bhavsec/reconspider ReconSpider is an open-source OSINT framework written in Python for scanning IP addresses, emails, websites, and organizations to gather in… | 23 | 2791 | maintenance |
| lifting-bits/mcsema McSema is a framework that lifts native x86, amd64, aarch64, sparc32, and sparc64 executable binaries (ELF and PE) into LLVM bitcode. It wo… | 10 | 2787 | maintenance |
| Ettercap/ettercap Ettercap is a comprehensive open-source suite for man-in-the-middle attacks on local networks. It supports live connection sniffing, on-the… | 81 | 2785 | maintenance |
| zodiacon/WindowsInternals Source code for custom tools written by Pavel Yosifovich and Alex Ionescu to accompany the Windows Internals 7th edition book. The tools de… | 23 | 2780 | maintenance |
| ShadowsocksR-Live/shadowsocksr-native A lightweight ShadowsocksR (SSRoT) proxy client and server written in pure C, adding TLS-based obfuscation to evade deep packet inspection … | 53 | 2774 | maintenance |
| cisagov/RedEye RedEye is an open-source visual analytic tool from CISA and PNNL for visualizing and reporting Red Team command-and-control activities. It … | 10 | 2767 | maintenance |
| NextronSystems/APTSimulator APT Simulator is a Windows Batch script toolset that makes a system look as if it was the victim of an APT attack, using tools and output f… | 42 | 2765 | maintenance |
| 1y0n/AV_Evasion_Tool YanRi (AV_Evasion_Tool) is a Windows GUI tool for red teams that generates loaders to evade antivirus detection of shellcode payloads, supp… | 39 | 2762 | maintenance |
| martinvigo/email2phonenumber A Python OSINT tool that discovers a target's phone number from just their email address by abusing password reset flows that leak masked p… | 32 | 2754 | maintenance |
| rootm0s/WinPwnage WinPwnage is a Python tool and library that implements UAC bypass, privilege elevation, and persistence techniques for Windows. It can scan… | 32 | 2753 | maintenance |
| google/enjarify Enjarify is a Python 3 tool that translates Dalvik bytecode from Android APK/DEX files into equivalent Java bytecode (JAR), enabling Java a… | 10 | 2747 | maintenance |
| shack2/SNETCracker A Windows GUI tool for auditing weak passwords across many network services such as SSH, RDP, SMB, MySQL, Redis, and FTP. It supports batch… | 23 | 2741 | maintenance |
| FuzzySecurity/PowerShell-Suite A collection of PowerShell utilities for interacting with low-level Windows APIs, covering tasks like process creation, runas-style credent… | 32 | 2733 | maintenance |
| patrickfav/uber-apk-signer A Java-based command-line tool that signs, zipaligns, and verifies Android APK files using debug or release certificates, supporting v1-v4 … | 23 | 2728 | maintenance |
| hanbinglengyue/FART FART is an automated Android app unpacking (dex dumping) tool for ART environments, based on active invocation, implemented on Android 6.0/… | 33 | 2724 | maintenance |
| aritraroy/PatternLockView PatternLockView is an Android UI library providing a customizable, Material Design ready pattern lock view. It supports listener callbacks … | 32 | 2710 | maintenance |
| y9nhjy/Proxifier-Keygen A Python CLI keygen that generates registration keys for Proxifier (setup, portable, and Mac variants), based on a reverse-engineering anal… | 28 | 2696 | maintenance |
| DominicBreuker/stego-toolkit A Docker image bundling many popular steganography tools and screening scripts for solving CTF challenges. It provides CLI scripts like che… | 32 | 2689 | maintenance |
| m0rtem/CloudFail CloudFail is a Python 3 command-line reconnaissance tool that attempts to discover the real IP address of servers hidden behind Cloudflare.… | 32 | 2683 | maintenance |
| k4m4/kickthemout KickThemOut is a Python command-line tool that kicks devices off a local network by performing an ARP spoofing attack against selected targ… | 23 | 2675 | maintenance |
| everdox/InfinityHook InfinityHook is a Windows kernel library that hooks system calls, context switches, page faults, and DPCs by abusing ETW trace mechanics, r… | 32 | 2674 | maintenance |
| snyk/driftctl driftctl is a free and open-source CLI that scans cloud providers (AWS, GitHub, Azure, GCP), maps resources against Terraform code, and det… | 66 | 2663 | maintenance |
| flipkart-incubator/Astra Astra is an automated REST API security testing tool from Flipkart that detects vulnerabilities like SQL injection, XSS, broken authenticat… | 32 | 2661 | maintenance |
| b374k/b374k b374k is a single-file PHP webshell providing browser-based remote server management, including a file manager, command and script executio… | 23 | 2658 | maintenance |
| betterlockscreen/betterlockscreen Betterlockscreen is a shell-based lockscreen utility for Linux that wraps i3lock to provide fast, visually appealing lock screens with imag… | 53 | 2652 | maintenance |
| DarthTon/Xenos Xenos is a Windows DLL injector built on the Blackbone library, supporting x86/x64 processes, manual image mapping, managed image injection… | 23 | 2651 | maintenance |
| pointbiz/bitaddress.org A single-file, client-side Bitcoin wallet generator that creates addresses and private keys entirely in the browser with no network request… | 23 | 2639 | maintenance |
| ParrotSec/mimikatz mimikatz is a well-known Windows security tool that extracts plaintext passwords, hashes, PINs, and Kerberos tickets from memory, and suppo… | 32 | 2638 | maintenance |
| matterpreter/DefenderCheck A C# command-line tool that takes a binary as input and splits it iteratively to pinpoint the exact bytes that Microsoft Defender flags on.… | 59 | 2626 | maintenance |
| AlessandroZ/BeRoot BeRoot is a post-exploitation tool that checks common misconfigurations on Windows, Linux, and macOS hosts to identify potential privilege … | 23 | 2623 | maintenance |
| thewhiteh4t/nexfil Nexfil is an OSINT command-line tool written in Python that finds social media profiles by username across 350+ websites in seconds. It sup… | 32 | 2615 | maintenance |
| xoreaxeaxeax/rosenbridge Rosenbridge is a security research project that documents a hardware backdoor in some VIA C3 x86 processors, allowing userland code to bypa… | 32 | 2615 | maintenance |
| open-keychain/open-keychain OpenKeychain is an open-source OpenPGP implementation for Android that manages encryption keys and encrypts, decrypts, and signs messages a… | 32 | 2610 | maintenance |
| DavidBuchanan314/tweetable-polyglot-png A Python tool that packs up to 3MB of arbitrary data into a PNG polyglot file that survives upload to Twitter and other image hosts. It exp… | 32 | 2607 | maintenance |
| OptimalBits/node_acl A minimalistic access control list (ACL) library for Node.js applications, inspired by Zend_ACL. It manages users, roles, hierarchies, and … | 32 | 2604 | maintenance |
| obheda12/GitDorker GitDorker is a Python CLI tool that uses the GitHub Search API with a curated list of over 200 dorks to find sensitive information exposed … | 32 | 2578 | maintenance |
| dfd-tud/deda DEDA is a Python toolkit for extracting, decoding, and anonymising the yellow tracking dots that colour laser printers embed in printouts. … | 32 | 2578 | maintenance |
| Tuhinshubhra/CMSeeK CMSeeK is a Python 3 command-line suite that detects the content management system (CMS) powering a website, supporting over 180 CMSs inclu… | 65 | 2573 | maintenance |
| gloxec/CrossC2 CrossC2 is a framework that generates cross-platform Cobalt Strike beacon payloads for Linux, macOS, and other Unix-like targets, extending… | 23 | 2570 | maintenance |
| Swizec/useAuth useAuth is a React hook library that adds authentication to React apps with minimal setup, supporting Auth0 and Netlify Identity via a prov… | 23 | 2567 | maintenance |
| brendan-rius/c-jwt-cracker A multi-threaded JWT brute-force secret key cracker written in C using OpenSSL. It attempts to recover the HMAC signing key of a JWT token … | 32 | 2561 | maintenance |
| chrisk44/Hijacker Hijacker is an Android GUI wrapper for wireless penetration testing tools including Aircrack-ng, Airodump-ng, MDK3, and Reaver. It lets use… | 10 | 2546 | maintenance |
| x2on/OpenSSL-for-iPhone A shell script and example Xcode project for compiling the OpenSSL library for Apple platforms including iPhone, iPad, Apple Watch, Apple T… | 23 | 2529 | maintenance |
| joaomatosf/jexboss JexBoss is a Python command-line tool for testing and exploiting JBoss Application Server and Java deserialization vulnerabilities. It supp… | 32 | 2520 | maintenance |
| seemoo-lab/openhaystack OpenHaystack is a framework and macOS application for creating custom Bluetooth tracking tags that leverage Apple's Find My (offline findin… | 67 | 13492 | experimental |
| sekey/sekey SeKey is a macOS SSH agent that lets users authenticate to SSH servers using keys stored in the Apple Secure Enclave, unlocked via Touch ID… | 23 | 2517 | maintenance |
| infosec-au/altdns Altdns is a Python CLI tool for DNS reconnaissance that generates permutations, alterations, and mutations of known subdomains using a word… | 32 | 2504 | maintenance |
| KimiNewt/pyshark A Python wrapper around tshark that lets you parse packets from capture files or live captures using all installed Wireshark dissectors. It… | 56 | 2496 | maintenance |
| vuvuzela/vuvuzela Vuvuzela is a metadata-private messaging system written in Go that hides who is talking to whom, even against nation-state adversaries, usi… | 32 | 2485 | maintenance |
| oasisfeng/condom Project Condom is an ultra-lightweight Android library that wraps the app Context before passing it to third-party SDKs, blocking harmful b… | 23 | 2480 | maintenance |
| pwnlandia/mhn Modern Honey Network (MHN) is a centralized Flask-based server for managing honeypot sensors and collecting their attack data. It exposes a… | 32 | 2464 | maintenance |
| ory/ladon Ladon is a Go SDK for policy-based access control (authorization), inspired by AWS IAM policies. It provides fine-grained, condition-based … | 44 | 2457 | maintenance |
| ciaranj/node-oauth A simple OAuth client library for Node.js that lets applications act as OAuth consumers against OAuth 1.0 and OAuth 2.0 providers. It suppo… | 37 | 2434 | maintenance |
| RootMyTV/RootMyTV.github.io RootMyTV is a user-friendly browser-based exploit for rooting/jailbreaking LG webOS smart TVs, leveraging CVE-2022-23727 and CVE-2020-9759.… | 23 | 2433 | maintenance |
| sans-blue-team/DeepBlueCLI DeepBlueCLI is a PowerShell module for threat hunting that analyzes Windows Event Logs (Security, System, Application, PowerShell, Sysmon) … | 32 | 2429 | maintenance |
| screetsec/Sudomy Sudomy is a Bash-based subdomain enumeration and reconnaissance framework that collects subdomains via active brute-forcing and passive thi… | 23 | 2429 | maintenance |
| Chora10/Cknife Cknife (China Chopper Knife) is a Java-based cross-platform webshell management tool, an open-source client compatible with the China Chopp… | 32 | 2422 | maintenance |
| secretsquirrel/SigThief SigThief is a Python CLI tool that rips the Authenticode signature off a signed PE file and appends it to another binary, patching the cert… | 32 | 2420 | maintenance |
| knownsec/ksubdomain ksubdomain is a stateless subdomain enumeration tool written in Go that performs extremely fast DNS brute-forcing by separating packet send… | 23 | 2393 | maintenance |
| besimorhino/powercat powercat is a PowerShell reimplementation of netcat supporting TCP, UDP, and DNS (dnscat2) connections, file transfer, and shell serving. I… | 32 | 2389 | maintenance |
| solokeys/solo1 Solo 1 is the open-source C firmware for the Solo security key, implementing FIDO2 (CTAP2) and U2F (CTAP) over USB and NFC on an STM32L432 … | 23 | 2382 | maintenance |
| FiloSottile/Heartbleed A command-line tool and former web service for detecting the Heartbleed vulnerability (CVE-2014-0160) in TLS servers. Written in Go, it tes… | 32 | 2380 | maintenance |
| tr0uble-mAker/POC-bomber POC-bomber is a Python-based offensive security tool that bundles a large arsenal of high-impact POCs and EXPs (RCE, deserialization, file … | 23 | 2368 | maintenance |
| dana-at-cp/backdoor-apk A shell script that automates injecting a Metasploit backdoor payload into any Android APK by decompiling, hooking smali code, and re-signi… | 32 | 2366 | maintenance |
| byt3bl33d3r/SILENTTRINITY SILENTTRINITY is an asynchronous, multiplayer and multiserver C2/post-exploitation framework built with Python 3 and .NET's DLR. It uses em… | 32 | 2341 | maintenance |
| lipp/login-with A stateless microservice that handles 'login-with' OAuth authentication for providers like Twitter, Google, GitHub, and Facebook. On succes… | 32 | 2341 | maintenance |
| bugcrowd/HUNT HUNT Suite is a collection of Burp Suite and OWASP ZAP proxy extensions that identify common parameters vulnerable to vulnerability classes… | 67 | 2333 | maintenance |
| noob-hackers/mrphish mrphish is a Bash-based Termux script that hosts fake social media login pages (60+ templates) with port forwarding via ngrok and OTP bypas… | 50 | 2328 | maintenance |
| Hax4us/TermuxBlack TermuXBlacK is an unofficial third-party APT repository for Termux on Android that packages hacking and penetration-testing tools not avail… | 32 | 2328 | maintenance |
| PHPGangsta/GoogleAuthenticator A PHP library implementing TOTP (RFC 6238) for Google Authenticator two-factor authentication. It generates secrets and codes, verifies cod… | 23 | 2328 | maintenance |
| sensepost/ruler Ruler is a Go-based command-line tool for interacting with and abusing Microsoft Exchange servers via MAPI/HTTP or RPC/HTTP. It enables off… | 23 | 2313 | maintenance |
| NoamB/sorcery Sorcery is a Ruby authentication library for Rails 3 & 4 providing simple, modular authentication features. This original repository has mo… | 32 | 2299 | maintenance |
| ustayready/fireprox FireProx is a Python CLI tool that uses AWS API Gateway to create on-the-fly HTTP pass-through proxies that rotate the source IP address wi… | 32 | 2283 | maintenance |
| xtr4nge/FruityWifi FruityWiFi is an open-source wireless network auditing tool with a web-based control panel for deploying advanced WiFi attacks. It is modul… | 23 | 2278 | maintenance |
| kgretzky/pwndrop pwndrop is a self-deployable file hosting service aimed at red teamers, letting users upload and share payloads over HTTP, HTTPS, and WebDA… | 23 | 2277 | maintenance |
| topotam/PetitPotam PetitPotam is a proof-of-concept tool that coerces Windows hosts to authenticate to attacker-controlled machines via the MS-EFSRPC protocol… | 32 | 2270 | maintenance |
| itm4n/PrintSpoofer PrintSpoofer is a Windows privilege escalation tool that abuses SeImpersonatePrivilege via the Print Spooler 'Printer Bug' to escalate from… | 10 | 2268 | maintenance |
| davidprowe/BadBlood BadBlood is a PowerShell tool that populates a Microsoft Active Directory domain with thousands of randomized users, groups, computers, and… | 32 | 2267 | maintenance |
| rabbitmask/WeblogicScan A one-click Python vulnerability scanner for Oracle WebLogic servers, covering nearly all historical WebLogic CVEs (SSRF, Java deserializat… | 32 | 2260 | maintenance |
| worawit/MS17-010 A collection of Python exploit scripts and proof-of-concepts for the MS17-010 Windows SMB vulnerabilities, including Eternalblue, Eternalch… | 32 | 2260 | maintenance |
| outflanknl/EvilClippy Evil Clippy is a cross-platform C# command-line assistant for crafting malicious MS Office documents with hidden or stomped VBA macros. It … | 32 | 2257 | maintenance |
| ldpreload/BlackLotus An open-source UEFI bootkit targeting Windows that implements a Secure Boot bypass, kernel-level persistence, and an HTTP-based C2 loader w… | 29 | 2243 | maintenance |
| shmilylty/netspy netspy is a fast, cross-platform Go CLI tool for discovering reachable intranet network segments from a compromised host. It supports ICMP,… | 23 | 2238 | maintenance |