domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| inbug-team/InScan InScan is a Go-based automated intranet penetration testing tool designed for use after breaching a network boundary. It provides port scan… | 32 | 1887 | maintenance |
| positive-security/send-my Send My is a research tool that transmits arbitrary data through Apple's Find My network by encoding it in BLE public-key broadcasts from a… | 23 | 1884 | maintenance |
| atmos/camo Camo is an HTTP image proxy that routes insecure HTTP images through SSL to prevent mixed-content warnings on HTTPS pages. It authenticates… | 10 | 1883 | maintenance |
| cobbr/SharpSploit SharpSploit is a .NET post-exploitation library written in C# that highlights the .NET attack surface for red teamers. It ports and extends… | 32 | 1882 | maintenance |
| google/security-research-pocs A collection of proof-of-concept exploit code produced during security research by the Google Security Team. It serves as a reference repos… | 10 | 1881 | maintenance |
| droe/sslsplit SSLsplit is a transparent SSL/TLS interception proxy for man-in-the-middle attacks against encrypted network connections. It terminates TLS… | 54 | 1875 | maintenance |
| SpoofMAC SpoofMAC is a Python command-line tool that changes (spoofs) your computer's MAC address in one command, handling the Wi-Fi disassociation … | 32 | 1868 | maintenance |
| 0xInfection/TIDoS-Framework TIDoS is a Python-based offensive web application penetration testing framework with a Metasploit-like console interface and an optional Qt… | 23 | 1868 | maintenance |
| orlyjamie/mimikittenz mimikittenz is a post-exploitation PowerShell tool that uses the Windows ReadProcessMemory() function to extract plain-text passwords and o… | 32 | 1867 | maintenance |
| maliceio/malice Malice is an open-source malware analysis framework that acts as a self-hosted VirusTotal alternative, scanning files with Docker-based plu… | 10 | 1863 | maintenance |
| trimstray/sandmap sandmap is a shell-based CLI wrapper around the Nmap engine that simplifies network and system reconnaissance. It offers 31 modules with 45… | 32 | 1862 | maintenance |
| DanMcInerney/net-creds A Python command-line tool that sniffs passwords, hashes, and other sensitive data from a live network interface or a pcap file. It reassem… | 32 | 1862 | maintenance |
| eldraco/domain_analyzer Domain Analyzer is a Python-based security analysis tool that automatically discovers and reports information about a given domain, includi… | 32 | 1861 | maintenance |
| jaykali/hackerpro HackerPro is an all-in-one penetration testing tool collection for Linux and Android (Termux) that bundles popular security tools like Nmap… | 32 | 1858 | maintenance |
| winauth/winauth WinAuth is a portable, open-source Windows desktop application that acts as a software two-factor authenticator, supporting RFC 6238 TOTP a… | 10 | 1857 | maintenance |
| n0a/telegram-get-remote-ip A Python CLI script that reveals the IP address of a Telegram voice call interlocutor by capturing and analyzing traffic with tshark. It ex… | 32 | 1855 | maintenance |
| Defi-Cartel/salmonella Salmonella is a demonstration project that deploys a malicious ERC-20 token contract designed to detect and punish sandwich traders on Ethe… | 32 | 1853 | maintenance |
| glmcdona/Process-Dump Process Dump is a Windows command-line reverse-engineering tool that dumps unpacked malware PE files and loose code chunks from process mem… | 23 | 1853 | maintenance |
| awake1t/linglong Linglong is a self-hosted asset reconnaissance and scanning system written in Go that continuously discovers network assets using masscan+n… | 32 | 1848 | maintenance |
| kozmer/log4j-shell-poc A proof-of-concept exploit tool for the Log4Shell vulnerability (CVE-2021-44228) in the Java log4j logging library. It automates setting up… | 10 | 1848 | maintenance |
| 1N3/Findsploit Findsploit is a simple bash script that instantly searches local and online exploit databases, including Exploit-DB, Metasploit modules, an… | 23 | 1847 | maintenance |
| wavestone-cdt/EDRSandblast EDRSandBlast is a C-based offensive security tool that weaponizes vulnerable signed drivers to bypass EDR detections on Windows, including … | 32 | 1846 | maintenance |
| CCob/SweetPotato SweetPotato is a C# command-line tool that collects multiple native Windows privilege escalation techniques (RottenPotato, PrintSpoofer, Ef… | 32 | 1839 | maintenance |
| sleventyeleven/linuxprivchecker A single-file Python script that enumerates a local Linux system and searches for common privilege escalation vectors such as world-writabl… | 32 | 1839 | maintenance |
| Hackertrackersj/Instabruteforce A Python CLI tool that brute-forces Instagram account passwords using a wordlist and a rotating proxy list, with proxy scoring and pruning … | 32 | 1838 | maintenance |
| cyweb/hammer A Python 3 command-line script for performing DDoS (denial-of-service) flood attacks against target servers. It is a simple offensive secur… | 48 | 1836 | maintenance |
| neex/phuip-fpizdam A Go-based exploit tool for CVE-2019-11043, a remote code execution vulnerability in php-fpm when used behind certain nginx configurations.… | 32 | 1831 | maintenance |
| p3nt4/PowerShdll PowerShdll is a C# tool that runs PowerShell commands and scripts without invoking powershell.exe, by loading PowerShell automation DLLs vi… | 23 | 1830 | maintenance |
| perlin-network/noise noise is an opinionated, easy-to-use peer-to-peer networking stack for decentralized applications and cryptographic protocols, written in G… | 23 | 1830 | maintenance |
| SysWhispers SysWhispers is a Python CLI tool that generates header and assembly files for making direct system calls on Windows, bypassing user-mode AP… | 32 | 1829 | maintenance |
| fsociety-team/fsociety fsociety is a modular penetration testing framework written in Python that wraps and organizes popular security tools (nmap, sqlmap, Sherlo… | 67 | 1824 | maintenance |
| mm0r1/exploits A collection of PHP 'pwn' exploits that bypass the disable_functions restriction in PHP using known interpreter bugs (e.g., bug #81705, #72… | 32 | 1824 | maintenance |
| x0rz/phishing_catcher A Python CLI tool that monitors TLS certificate issuances in near real time via the CertStream API and flags suspicious domains using a con… | 32 | 1823 | maintenance |
| klezVirus/inceptor Inceptor is a template-driven PE packer and AV/EDR evasion framework for Windows, aimed at penetration testers and red teamers. It automate… | 32 | 1821 | maintenance |
| Matrix07ksa/Brute_Force A Python CLI tool that performs brute-force password attacks against Gmail, Hotmail, Twitter, Facebook, and Netflix accounts, with optional… | 32 | 1820 | maintenance |
| newbit1/rootAVD A shell script that roots Android Studio Virtual Devices (AVDs) running on the QEMU emulator by installing Magisk, patching fstab, and opti… | 10 | 1820 | maintenance |
| whid-injector/WHID WHID Injector is an open-source WiFi HID injection tool that combines an ESP8266 with an ATmega32u4 to remotely deliver BadUSB keystroke at… | 32 | 1818 | maintenance |
| smarques84/MockLocationDetector An Android library written in Java that detects whether a device's location data comes from a mock (spoofed) provider. It offers static met… | 32 | 1817 | maintenance |
| InteliSecureLabs/Linux_Exploit_Suggester A Perl script that suggests possible Linux kernel exploits based on the operating system release number (uname -r). It matches the kernel v… | 32 | 1812 | maintenance |
| Yvesssn/DetectDee DetectDee is a Go CLI tool for OSINT that hunts down social media accounts by username, email, or phone number across many social networks.… | 20 | 1812 | maintenance |
| hlldz/Phant0m Phant0m is a Windows Event Log Killer that identifies the process hosting the Windows Event Log service and terminates only its threads, so… | 10 | 1812 | maintenance |
| lockedbyte/CVE-2021-40444 A proof-of-concept exploit generator for CVE-2021-40444, a Microsoft Office Word remote code execution vulnerability. It generates maliciou… | 32 | 1806 | maintenance |
| pmiaowu/BurpShiroPassiveScan A passive BurpSuite extension written in Java that automatically detects Apache Shiro framework usage and tests for known Shiro encryption … | 23 | 1806 | maintenance |
| gtank/cryptopasta A collection of copy-and-paste-friendly cryptography snippets for Go, wrapping the standard library's best practices for encryption (AES-GC… | 32 | 1805 | maintenance |
| Kevin-Robertson/Invoke-TheHash A collection of PowerShell functions for performing pass-the-hash attacks over WMI and SMB using NTLM hash authentication. It implements ra… | 32 | 1805 | maintenance |
| minivision-ai/Silent-Face-Anti-Spoofing An open-source silent face anti-spoofing (liveness detection) project by MiniVision, providing model training code, data preprocessing, tes… | 32 | 1805 | maintenance |
| KimJun1010/WeblogicTool A GUI-based vulnerability exploitation toolkit targeting Oracle WebLogic servers, supporting detection and exploitation of numerous CVEs vi… | 20 | 1804 | maintenance |
| huolizhuminh/NetWorkPacketCapture An Android app that captures network packets using a local VPN service, showing live connections per app and parsing/saving HTTP (and parti… | 32 | 1802 | maintenance |
| enjoiz/XXEinjector XXEinjector is a Ruby command-line tool that automates exploitation of XML External Entity (XXE) vulnerabilities using direct and out-of-ba… | 32 | 1800 | maintenance |
| Ha3MrX/DDos-Attack A simple Python script for launching DDoS (denial of service) attacks against online targets. It is a command-line tool intended for learni… | 66 | 1797 | maintenance |
| gdbinit/Gdbinit A feature-rich .gdbinit configuration script that enhances GDB with custom commands, macros, and a reverse-engineering-oriented interface f… | 32 | 1796 | maintenance |
| google/stenographer Stenographer is a high-performance full-packet-capture utility that spools network packets to disk at up to ~10Gbps and manages disk usage … | 10 | 1796 | maintenance |
| pivotal/LicenseFinder LicenseFinder is a Ruby CLI tool that scans a project's dependencies via its package manager, detects each package's license, and compares … | 23 | 1795 | maintenance |
| acecilia/OpenWRTInvasion A Python/Docker-based exploit script that gains a root shell on several Xiaomi routers (4A Gigabit, 4A 100M, 4, 4C, 3Gv2, 4Q, miWifi 3C) vi… | 23 | 1795 | maintenance |
| sysdream/ligolo Ligolo is a lightweight Go tool for establishing SOCKS5 or TCP tunnels over reverse TLS connections, aimed at penetration testers pivoting … | 32 | 1788 | maintenance |
| iceyhexman/onlinetools A self-hosted web-based penetration testing toolbox written in Python that bundles common recon and scanning tasks behind a browser UI. It … | 10 | 1787 | maintenance |
| googleprojectzero/domato Domato is a grammar-based DOM fuzzer from Google Project Zero that generates HTML, CSS, and JavaScript test cases for finding browser DOM e… | 32 | 1784 | maintenance |
| megadose/OnionSearch OnionSearch is a Python 3 CLI script that scrapes URLs from multiple .onion search engines such as Ahmia, Phobos, and Deeplink. It supports… | 32 | 1783 | maintenance |
| mrh0wl/Cloudmare Cloudmare is a Python CLI tool that discovers the origin servers of websites protected by Cloudflare, Sucuri, or Incapsula when their DNS i… | 10 | 1783 | maintenance |
| 1tayH/noisy A Python script that generates random HTTP and DNS traffic noise in the background to obscure your real browsing patterns. It crawls config… | 32 | 1777 | maintenance |
| intika/Librefox Librefox is a privacy- and security-hardened packaging of Firefox that applies 500+ settings, patches, and optional addons without forking … | 23 | 1777 | maintenance |
| Noovolari/leapp Leapp is a cross-platform Electron desktop app for managing and generating cloud credentials across multiple AWS and Azure accounts, with e… | 60 | 1775 | maintenance |
| baichengzhou/SpringMVC-Mybatis-Shiro-redis-0.2 An upgraded demo application showing Apache Shiro permission/role-based access control integrated with SpringMVC, Mybatis, Redis, and Freem… | 32 | 1775 | maintenance |
| krakenjs/lusca Lusca is web application security middleware for Express/Node.js apps. It provides configurable protections including CSRF tokens, Content … | 25 | 1775 | maintenance |
| lucasjacks0n/EggShell EggShell is a Python-based post-exploitation surveillance and remote administration tool that provides a command-line session with a target… | 32 | 1770 | maintenance |
| ssllabs/ssllabs-scan A command-line reference client for the SSL Labs APIs, written in Go, for automated and bulk SSL/TLS server assessment. It scans hosts agai… | 23 | 1768 | maintenance |
| tanweai/wooyun-legacy A Claude Code plugin that injects real-world case citations, statistics, and data-driven prioritization into AI-generated security reports,… | 57 | 1764 | maintenance |
| indutny/elliptic A fast, pure-JavaScript implementation of elliptic curve cryptography supporting ECDSA signing/verification, ECDH key exchange, and EdDSA. … | 32 | 1764 | maintenance |
| s4n7h0/xvwa XVWA (Xtreme Vulnerable Web Application) is an intentionally insecure PHP/MySQL web application for learning application security. It conta… | 10 | 1763 | maintenance |
| tandasat/HyperPlatform HyperPlatform is an Intel VT-x based hypervisor for Windows that provides a thin VM-exit filtering platform for research. It lets researche… | 10 | 1760 | maintenance |
| al0ne/Vxscan Vxscan is a Python3-based comprehensive security scanning tool for authorized penetration testing. It combines host liveness checks, port s… | 32 | 1759 | maintenance |
| Moham3dRiahi/XAttacker XAttacker is a Perl-based command-line tool that scans websites for vulnerabilities and automatically exploits them. It detects the target'… | 32 | 1758 | maintenance |
| java-deobfuscator/deobfuscator A Java-based CLI tool that deobfuscates Java JAR files produced by commercial obfuscators such as Zelix KlassMaster, Stringer, Allatori, Da… | 23 | 1757 | maintenance |
| VKSRC/Github-Monitor A self-hosted system for monitoring GitHub repositories for sensitive information leakage, such as leaked corporate code and secrets. It of… | 32 | 1751 | maintenance |
| chenjj/espoofer espoofer is a Python-based testing tool that crafts spoofed emails to bypass SPF, DKIM, and DMARC authentication, including forged DKIM sig… | 32 | 1749 | maintenance |
| knownsec/shellcodeloader A Windows shellcode loader generator written in C++ that packages raw shellcode into encrypted executables with multiple loading techniques… | 23 | 1747 | maintenance |
| DanMcInerney/xsscrapy A Python-based spider built on Scrapy that crawls a website and tests every link it finds for cross-site scripting (XSS) and basic SQL inje… | 32 | 1746 | maintenance |
| alienator88/Sentinel Sentinel is a native macOS SwiftUI application providing a GUI for managing Gatekeeper settings. It lets users unquarantine apps by drag-an… | 75 | 1741 | maintenance |
| samdenty/Wi-PWN Wi-PWN is ESP8266 firmware for performing WiFi deauthentication attacks with a fast, responsive Material Design web UI. It includes an inte… | 23 | 1741 | maintenance |
| liexusong/php-beast php-beast is a PHP extension written in C that encrypts PHP source code files so they can be distributed without exposing the original code… | 32 | 1739 | maintenance |
| AnonHackerr/toolss A Python script that automatically installs a collection of hacking and penetration-testing tools on Android devices running Termux. It act… | 32 | 1739 | maintenance |
| uccmawei/FingerprintIdentify An expandable Android fingerprint verification library that unifies the Android 6.0 FingerprintManagerCompat API with Samsung and MeiZu ven… | 23 | 1739 | maintenance |
| jtesta/ssh-mitm A penetration testing tool that intercepts SSH connections by running a patched OpenSSH v7.5p1 server as a proxy between a victim and their… | 10 | 1739 | maintenance |
| aahmad097/AlternativeShellcodeExec A collection of C++ examples demonstrating alternative Windows callback functions for executing position-independent shellcode, avoiding de… | 32 | 1737 | maintenance |
| mprimi/portable-secret Portable Secret is a tool that packs an encrypted payload and decryption JavaScript into a single self-contained HTML file, using the brows… | 32 | 1736 | maintenance |
| gamelinux/passivedns PassiveDNS is a network sniffer written in C that passively collects DNS server replies from a live interface or pcap files and logs them i… | 32 | 1735 | maintenance |
| citronneur/rdpy RDPY is a pure Python implementation of the Microsoft Remote Desktop Protocol (RDP) built on the Twisted event-driven network engine, suppo… | 32 | 1735 | maintenance |
| lijiejie/ds_store_exp A Python CLI exploit tool that parses exposed .DS_Store files on web servers to enumerate hidden files and directories, then recursively do… | 32 | 1734 | maintenance |
| m57/dnsteal dnsteal is a fake DNS server written in Python that enables stealthy exfiltration of files from a victim machine via DNS requests. It suppo… | 32 | 1730 | maintenance |
| EASY233/Finger Finger is a Python-based red team tool that performs liveness probing and web system fingerprint detection across large asset lists, identi… | 32 | 1723 | maintenance |
| NVIDIA/OpenShell NVIDIA OpenShell is an open-source runtime for executing autonomous AI agents (Claude Code, Codex, OpenCode, Copilot CLI) inside sandboxed … | 78 | 8501 | experimental |
| foniod/redbpf RedBPF is a Rust eBPF toolchain consisting of libraries and a cargo subcommand for writing, building, and loading eBPF programs. It provide… | 10 | 1722 | maintenance |
| Azure/Stormspotter Stormspotter is an Azure red team tool that builds an attack graph of Azure subscription and Azure Active Directory resources, storing them… | 23 | 1718 | maintenance |
| DotNetOpenAuth/DotNetOpenAuth DotNetOpenAuth is a C# library implementing the OpenID and OAuth protocols for .NET applications. It lets developers build both Identity Pr… | 10 | 1716 | maintenance |
| antirez/hping hping3 is a command-line network tool that sends custom TCP/IP packets and displays target replies, similar to ping but supporting arbitrar… | 32 | 1715 | maintenance |
| genuinetools/reg A Docker Registry v2 command line client written in Go that can list repositories, fetch manifests and digests, download layers, and delete… | 23 | 1710 | maintenance |
| Err0r-ICA/TermuxCyberArmy TermuxCyberArmy is a shell/Python-based hacking toolkit script for the Termux terminal environment on Android. It bundles a collection of s… | 43 | 1709 | maintenance |
| Paisseon/SatellaJailed Satella Jailed is an in-app purchase cracker for non-jailbroken ('jailed') iOS devices running iOS 12–16, distributed as an injectable dyli… | 32 | 1708 | maintenance |
| sting8k/BurpSuite_403Bypasser A Burp Suite extension written in Python that automatically attempts to bypass 403 Forbidden responses on restricted directories. It hooks … | 32 | 1706 | maintenance |
| vx3r/wg-gen-web A self-hosted web application that generates WireGuard client and server configuration files without managing the WireGuard service itself.… | 32 | 1704 | maintenance |