domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Ascotbe/Medusa Medusa is a self-hosted red team arsenal platform written in Python that bundles tools such as an XSS platform, collaborative platform, CVE… | 23 | 2235 | maintenance |
| asLody/SandHook SandHook is an Android ART runtime hooking library supporting Java method hooks and native inline hooks on Android 4.4 through 11.0 for bot… | 23 | 2229 | maintenance |
| evilcos/xssor2 XSS'OR is a self-hostable web application for penetration testers that provides XSS/CSRF payload generation, encoding/decoding utilities, a… | 32 | 2222 | maintenance |
| HatBoy/Struts2-Scan A Python CLI tool that scans and exploits known Apache Struts2 vulnerabilities (S2-001 through S2-057) using publicly disclosed exploits. I… | 32 | 2220 | maintenance |
| diafygi/gethttpsforfree A browser-based web application (source for gethttpsforfree.com) that walks users through obtaining free TLS certificates from Let's Encryp… | 44 | 2215 | maintenance |
| M2TeamArchived/NSudo NSudo is a Windows system administration toolkit whose launcher lets users run programs with TrustedInstaller, SYSTEM, or elevated user tok… | 10 | 2208 | maintenance |
| LionSec/xerosploit Xerosploit is a Ruby-based penetration testing toolkit that wraps bettercap and nmap to perform man-in-the-middle attacks, port scanning, a… | 23 | 2201 | maintenance |
| thehackingsage/hacktronian Hacktronian is a Python-based, menu-driven collection of penetration testing tools that bundles popular utilities for information gathering… | 32 | 2198 | maintenance |
| codingo/Reconnoitre Reconnoitre is a Python CLI tool for multithreaded information gathering and service enumeration of target hosts and ranges, built original… | 23 | 2195 | maintenance |
| SystemRage/py-kms py-kms is a Python-based KMS (Key Management Service) server emulator that responds to v4, v5, and v6 KMS requests to activate volume-licen… | 32 | 2191 | maintenance |
| iamj0ker/bypass-403 A shell script that attempts to bypass HTTP 403 Forbidden responses using 24 known bypass techniques via curl. It also compares responses u… | 32 | 2190 | maintenance |
| peewpw/Invoke-PSImage Invoke-PSImage is a PowerShell tool that encodes a PowerShell script into the pixels of a PNG image using steganography, then generates a o… | 32 | 2188 | maintenance |
| Quip Network Quip Network SDK is a TypeScript SDK plus a set of EVM smart contracts (Deployer, WOTSPlus, QuipFactory) for interacting with the Quip Netw… | 63 | 11346 | experimental |
| IAmBlackHacker/Facebook-BruteForce A Python script that performs brute-force password attacks against Facebook accounts using wordlists, intended for educational purposes. It… | 23 | 2184 | maintenance |
| hexway/apple_bleee A collection of experimental Python PoC scripts for sniffing and injecting Apple Bluetooth Low Energy (BLE) and AWDL (AirDrop) traffic. It … | 23 | 2184 | maintenance |
| bats3c/shad0w SHAD0W is a modular post-exploitation C2 (command and control) framework written in Python and C, designed to operate covertly in heavily m… | 23 | 2176 | maintenance |
| mjrussell/redux-auth-wrapper redux-auth-wrapper is a React Higher Order Component (HOC) library for handling authentication and authorization in React + Redux applicati… | 32 | 2174 | maintenance |
| CedArctic/DigiSpark-Scripts A collection of hand-written Arduino IDE sketches for the DigiSpark ATtiny85 board that turn it into a USB HID keyboard for executing autom… | 32 | 2172 | maintenance |
| Dliv3/Venom Venom is a multi-hop proxy tool written in Go for penetration testers, connecting multiple nodes to build chained proxies through internal … | 23 | 2165 | maintenance |
| panique/huge HUGE is a simple user-authentication solution embedded in a minimal PHP framework skeleton, using PHP's official bcrypt password hashing. I… | 23 | 2159 | maintenance |
| praetorian-inc/gokart GoKart is a static analysis (SAST) tool for Go that detects vulnerabilities using SSA-form source-to-sink taint tracing. It reduces false p… | 10 | 2157 | maintenance |
| noob-hackers/ipdrone Ipdrone is a simple Python script for IP lookup that retrieves information about a target IP address, including live location with address … | 32 | 2149 | maintenance |
| FeeiCN/GSIL GSIL is a Python tool that monitors GitHub for sensitive information leaks, such as leaked credentials, internal domains, and proprietary c… | 10 | 2146 | maintenance |
| hmaverickadams/breach-parse Breach-Parse is a shell-based command-line tool for searching breached password compilations (like the BreachCompilation torrent) for crede… | 32 | 2143 | maintenance |
| anouarbensaad/vulnx VulnX is a Python CLI tool that detects CMS types (WordPress, Joomla, Drupal, etc.), gathers target information like subdomains and DNS rec… | 23 | 2143 | maintenance |
| Kkevsterrr/geneva Geneva is a research tool from the University of Maryland that uses a genetic algorithm to automatically evolve packet-manipulation strateg… | 32 | 2142 | maintenance |
| noob-hackers/ighack A bash-based Termux script that attempts to brute-force Instagram account passwords using wordlists, routing traffic through Tor for anonym… | 50 | 2141 | maintenance |
| initstring/cloud_enum A Python command-line OSINT tool that enumerates publicly exposed resources across AWS, Azure, and Google Cloud using keyword mutations and… | 79 | 2138 | maintenance |
| D4Vinci/Cr3dOv3r Cr3dOv3r is a Python command-line pentesting tool for investigating credential reuse attacks. Given an email, it searches public breach dat… | 57 | 2136 | maintenance |
| fossabot/clash Clash is a rule-based network proxy written in Go that supports HTTP/HTTPS and SOCKS proxies with Surge-like configuration and GeoIP rule r… | 32 | 2132 | maintenance |
| skavngr/rapidscan RapidScan is a Python CLI tool that automates web vulnerability scanning by orchestrating multiple security tools (nmap, nikto, wafw00f, ss… | 23 | 2130 | maintenance |
| greatscottgadgets/ubertooth Ubertooth is an open source wireless development platform for Bluetooth experimentation, providing host software, firmware, and hardware de… | 56 | 2127 | maintenance |
| armon/go-socks5 A Go library that implements a SOCKS5 proxy server, supporting No-Auth and User/Password authentication and the CONNECT command. It offers … | 32 | 2125 | maintenance |
| UnaPibaGeek/ctfr CTFR is a Python command-line tool that enumerates HTTPS website subdomains by querying Certificate Transparency logs (via crt.sh) instead … | 32 | 2117 | maintenance |
| quericy/one-key-ikev2-vpn A one-click bash script that installs and configures an IKEv2/L2TP VPN server using strongSwan on Ubuntu, CentOS, or Debian. It handles cer… | 32 | 2106 | maintenance |
| firmadyne/firmadyne FIRMADYNE is an automated, scalable platform for emulating and dynamically analyzing Linux-based embedded firmware using QEMU with instrume… | 32 | 2105 | maintenance |
| s0md3v/ReconDog ReconDog is a Python-based reconnaissance 'Swiss Army Knife' that gathers information about targets (domains, IPs) using third-party APIs l… | 23 | 2104 | maintenance |
| TideSec/WDScanner WDScanner is a self-hosted distributed web vulnerability scanning platform written in PHP with Python backend workers. It combines customer… | 32 | 2099 | maintenance |
| hlandau/acmetool acmetool is a command-line tool for automatically acquiring and renewing TLS certificates from ACME servers such as Let's Encrypt. It works… | 23 | 2092 | maintenance |
| TideSec/TideFinger TideFinger is a Python web fingerprinting tool that merges rule sets from multiple open-source fingerprint databases (Wappalyzer, webanalyz… | 32 | 2087 | maintenance |
| dafthack/DomainPasswordSpray DomainPasswordSpray is a PowerShell tool that performs password spray attacks against domain user accounts, automatically generating a user… | 32 | 2086 | maintenance |
| gurnec/HashCheck HashCheck is a Windows Explorer shell extension that lets users verify and generate file checksums (MD5, SHA-1, SHA-2, SHA-3, and more) dir… | 23 | 2078 | maintenance |
| iSafeBlue/TrackRay TrackRay (溯光) is an open-source penetration testing framework written in Java on SpringBoot that implements its own vulnerability scanning … | 23 | 2078 | maintenance |
| 0xn0ne/weblogicScanner A Python CLI vulnerability scanner for Oracle WebLogic servers that detects a wide range of known CVEs (2014-2020), including deserializati… | 32 | 2075 | maintenance |
| moxie0/sslstrip sslstrip is a Python command-line tool that implements Moxie Marlinspike's SSL stripping man-in-the-middle attack, downgrading HTTPS links … | 32 | 2074 | maintenance |
| Aabyss-Team/ARL ARL (Asset Reconnaissance Lighthouse) is a self-hosted asset reconnaissance system that quickly discovers internet-facing assets associated… | 29 | 2066 | maintenance |
| fugue/credstash CredStash is a Python CLI utility for managing and distributing shared credentials in the cloud, encrypting secrets with AWS KMS key wrappi… | 23 | 2064 | maintenance |
| JKornev/hidden A Windows kernel driver with a usermode library and CLI that can hide processes, files, directories, and registry keys, and protect process… | 23 | 2053 | maintenance |
| yzddmr6/WebCrack WebCrack is a Python CLI tool for batch detection of weak passwords and universal-password (SQL injection bypass) vulnerabilities on web ad… | 32 | 2048 | maintenance |
| jtblin/kube2iam kube2iam is a Kubernetes daemonset that intercepts traffic to the EC2 metadata API and returns per-pod AWS IAM credentials based on pod ann… | 85 | 2042 | maintenance |
| Cyb0r9/SocialBox SocialBox is a shell-based brute-force attack framework targeting Facebook, Gmail, Instagram, and Twitter login forms. It is a penetration-… | 32 | 2042 | maintenance |
| B-Con/crypto-algorithms A collection of from-scratch C implementations of standard cryptography algorithms such as AES and SHA-1, released into the public domain. … | 32 | 2041 | maintenance |
| wszf/androrat AndroRAT is a remote administration tool (RAT) for Android built as a client/server pair: an Android client that runs as a boot-started bac… | 32 | 2039 | maintenance |
| pfn/keepasshttp KeePassHttp is a plugin for KeePass 2.x that exposes password entries securely over HTTP using 256-bit AES/CBC encryption. It is designed t… | 32 | 2038 | maintenance |
| es3n1n/no-defender A Windows CLI tool that disables Windows Defender and the firewall by registering a fake antivirus through the undocumented Windows Securit… | 10 | 2038 | maintenance |
| 0xbug/Hawkeye Hawkeye is a self-hosted system that monitors GitHub for leaked sensitive information, such as employees pushing company code or credential… | 23 | 2034 | maintenance |
| c0ny1/chunked-coding-converter A Burp Suite extension written in Java that converts HTTP request bodies to chunked transfer encoding, including delayed (sleep) chunking, … | 23 | 2028 | maintenance |
| fin3ss3g0d/evilgophish evilgophish is a Go-based framework combining evilginx3 and GoPhish for running authorized phishing and smishing campaigns with real-time c… | 32 | 2027 | maintenance |
| MegatronKing/StringFog StringFog is a Gradle plugin for Android that automatically encrypts string literals in compiled bytecode (dex/aar/jar) at build time and d… | 32 | 2015 | maintenance |
| brannondorsey/PassGAN A Python command-line implementation of the PassGAN paper that uses a Wasserstein GAN to generate password guesses, with a pretrained model… | 23 | 2011 | maintenance |
| Nekmo/dirhunt Dirhunt is a Python CLI web crawler optimized for finding and analyzing web directories without brute-forcing paths. It detects 'index of' … | 23 | 2006 | maintenance |
| Netflix-Skunkworks/stethoscope Stethoscope is a web application that collects device data from sources like JAMF, LANDESK, and G Suite mobile management and presents empl… | 32 | 2005 | maintenance |
| cube0x0/CVE-2021-1675 A proof-of-concept exploit tool implementing the PrintNightmare vulnerabilities (CVE-2021-1675/CVE-2021-34527) in both C# and Python (Impac… | 32 | 2001 | maintenance |
| ionescu007/SimpleVisor SimpleVisor is a minimal, portable Intel VT-x hypervisor written in about 500 lines of C and 10 lines of assembly, supporting dynamic hyper… | 32 | 1998 | maintenance |
| Bashfuscator/Bashfuscator Bashfuscator is a modular, configurable Bash obfuscation framework written in Python 3 that transforms Bash commands and scripts into convo… | 32 | 1997 | maintenance |
| 411Hall/JAWS JAWS is a PowerShell enumeration script that helps penetration testers and CTF players quickly identify potential Windows privilege escalat… | 32 | 1997 | maintenance |
| weak1337/Alcatraz Alcatraz is a GUI-based x64 binary obfuscator for Windows PE files (.exe, .dll, .sys) written in C++. It applies transformations like contr… | 31 | 1995 | maintenance |
| mozilla/cipherscan Cipherscan is a command-line tool that tests which SSL/TLS ciphersuites a target server supports and in what order, wrapping the openssl s_… | 44 | 1994 | maintenance |
| mdsecactivebreach/SharpShooter SharpShooter is a payload creation framework for retrieving and executing arbitrary CSharp source code, generating payloads in formats like… | 32 | 1989 | maintenance |
| nfc-tools/libnfc libnfc is a platform-independent C library that gives userspace applications access to NFC devices and readers, supporting multiple drivers… | 27 | 1987 | maintenance |
| samyk/slipstream NAT Slipstreaming is a security research tool by Samy Kamkar that demonstrates remotely opening arbitrary firewall pinholes through a victi… | 32 | 1984 | maintenance |
| Qihoo360/poseidon Poseidon is a distributed log search platform from Qihoo 360 that builds inverted indexes over Hadoop/HDFS-stored logs and serves sub-secon… | 32 | 1981 | maintenance |
| vaguileradiaz/tinfoleak tinfoleak is an open-source Python tool for OSINT/SOCMINT analysis of Twitter accounts, extracting structured intelligence such as user act… | 32 | 1981 | maintenance |
| h3xduck/TripleCross TripleCross is a Linux eBPF rootkit demonstrating offensive capabilities of eBPF technology, including library injection, execution hijacki… | 23 | 1978 | maintenance |
| jondonas/linux-exploit-suggester-2 A Perl script that suggests Linux kernel privilege escalation exploits based on the running kernel version. It matches the kernel release a… | 32 | 1973 | maintenance |
| tjfoc/gmsm A Go library implementing the Chinese national cryptography standards SM2 (elliptic curve), SM3 (hash), and SM4 (block cipher). It supports… | 23 | 1964 | maintenance |
| D35m0nd142/LFISuite LFISuite is a fully automatic Python tool that scans for and exploits Local File Inclusion (LFI) vulnerabilities using eight different atta… | 23 | 1963 | maintenance |
| r00t-3xp10it/venom VENOM is a shell-based framework that uses msfvenom to generate, obfuscate, and compile multi-format shellcode payloads (exe, dll, apk, elf… | 23 | 1961 | maintenance |
| cytopia/pwncat pwncat is a Python-based netcat replacement and reverse/bind shell handler with firewall and IDS/IPS evasion, self-injecting shells, and po… | 23 | 1955 | maintenance |
| duckduckgo/iOS The DuckDuckGo Privacy Browser for iOS, an open-source mobile web browser with built-in private search, third-party tracker blocking, ad bl… | 10 | 1953 | maintenance |
| psal/anonymouth Anonymouth is a Java-based desktop application that helps users anonymize documents by detecting and suggesting edits to stylometric patter… | 32 | 1950 | maintenance |
| w-digital-scanner/w13scan W13Scan is an open-source Python3 web vulnerability scanner supporting both passive (proxy-based) and active scanning modes. It ships with … | 32 | 1944 | maintenance |
| florianheinemann/passwordless A Node.js/Express module that enables passwordless user authentication using one-time password (OTPW) tokens delivered via email or SMS. It… | 23 | 1941 | maintenance |
| Xyntax/POC-T POC-T is a Python 2.7 plugin-based concurrent framework for penetration testing tasks such as crawling, bruteforcing, and batch PoC/EXP ver… | 23 | 1938 | maintenance |
| openshift/osin OSIN is a Go library for building your own OAuth2 authentication server, implementing the RFC 6749 specification including authorization an… | 76 | 1935 | maintenance |
| produck/svg-captcha A Node.js library that generates SVG-based CAPTCHA images without native C++ dependencies. It produces random text or math-expression captc… | 32 | 1935 | maintenance |
| Ranginang67/DarkFly-Tool DarkFly-Tool is a menu-driven installer for Termux that bundles 530 hacking and utility tools, letting users install them by number instead… | 32 | 1935 | maintenance |
| sense-of-security/ADRecon ADRecon is a PowerShell-based tool that extracts a wide range of artefacts from an Active Directory environment, including users, groups, t… | 32 | 1930 | maintenance |
| qvest-digital/loginsrv A standalone minimalistic login microservice written in Go that authenticates users against pluggable backends (htpasswd, simple config, HT… | 23 | 1930 | maintenance |
| OpenDrop OpenDrop is an open-source command-line tool written in Python that implements the Apple AirDrop protocol for sharing files directly over W… | 67 | 9730 | experimental |
| nuxt-community/auth-module A Nuxt 2 module providing zero-boilerplate authentication with configurable schemes (local, JWT, OAuth2, OpenIDConnect) and built-in provid… | 67 | 1924 | maintenance |
| Und3rf10w/kali-anonsurf A port of ParrotSec's anonsurf and pandora modules to Kali Linux, packaged as a deb installer. It routes all system traffic through TOR via… | 90 | 1919 | maintenance |
| tiann/Leoric Leoric is a proof-of-concept Android library that demonstrates a technique for keeping an app process alive against force-stop kills on And… | 32 | 1918 | maintenance |
| dirkjanm/mitm6 mitm6 is a Python pentesting tool that exploits Windows' default IPv6 configuration by answering DHCPv6 requests, assigning victims a link-… | 23 | 1918 | maintenance |
| omnigent-ai/omnigent Omnigent is an open-source meta-harness that provides a common orchestration layer over AI coding agents like Claude Code, Codex, Cursor, a… | 80 | 9660 | experimental |
| SummerSec/SpringBootExploit A Java GUI tool for quickly exploiting Spring Boot actuator/env page vulnerabilities, built from the LandGrey SpringBootVulExploit checklis… | 10 | 1895 | maintenance |
| s0md3v/Hash-Buster Hash-Buster is a Python CLI tool that identifies hash types automatically and cracks them by looking them up via online APIs. It supports M… | 23 | 1894 | maintenance |
| YelpArchive/osxcollector OSXCollector is a forensic evidence collection and analysis toolkit for macOS/OS X. It is a single-file Python script that gathers system d… | 10 | 1894 | maintenance |
| lobuhi/byp4xx byp4xx is a command-line tool written in Go that attempts to bypass HTTP 40X (access denied) responses using techniques like verb tampering… | 32 | 1891 | maintenance |
| corelan/mona mona.py is a Python plugin for debuggers (Immunity Debugger, x64dbg) that assists with exploit development tasks such as finding ROP gadget… | 10 | 1888 | maintenance |