domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| The404Hacking/AndroRAT AndroRAT is a Remote Administration Tool (RAT) for Android, consisting of a Java Android client that runs as a background service and a Jav… | 32 | 1702 | maintenance |
| dynup/kpatch kpatch is a Linux dynamic kernel patching infrastructure that lets sysadmins apply critical security patches to a running kernel without re… | 72 | 1696 | maintenance |
| irsdl/IIS-ShortName-Scanner A Java-based scanner that detects and exploits the Microsoft IIS short file name (8.3) disclosure vulnerability using tilde (~) character r… | 32 | 1694 | maintenance |
| Cybereason/Logout4Shell A Java-based proof-of-concept tool by Cybereason that exploits the Log4Shell vulnerability (CVE-2021-44228) to 'vaccinate' a vulnerable ser… | 32 | 1692 | maintenance |
| swisskyrepo/GraphQLmap GraphQLmap is a Python scripting engine and interactive CLI for interacting with GraphQL endpoints during penetration testing. It supports … | 32 | 1688 | maintenance |
| eladshamir/Internal-Monologue A C# post-exploitation tool that retrieves NTLM hashes by inducing NetNTLM challenge-response computations in-process, without touching the… | 32 | 1685 | maintenance |
| natemcmaster/LettuceEncrypt LettuceEncrypt is a NuGet library for ASP.NET Core that integrates with certificate authorities like Let's Encrypt via the ACME protocol to… | 10 | 1685 | maintenance |
| zhengjim/camille Camille is a Frida-based auxiliary tool for detecting Android app privacy compliance. It hooks sensitive Android APIs to reveal whether the… | 32 | 1682 | maintenance |
| ianstormtaylor/permit Permit is an unopinionated authentication library for Node.js APIs, supporting bearer token and username/password schemes. It works with an… | 32 | 1682 | maintenance |
| TryCatchHCF/Cloakify CloakifyFactory is a Python-based text-based steganography toolset that converts any file type into lists of innocuous everyday strings (e.… | 23 | 1682 | maintenance |
| Ghr07h/Heimdallr Heimdallr is a fully passive Chrome extension for security professionals that identifies high-risk vulnerability framework fingerprints in … | 23 | 1682 | maintenance |
| marin-m/pbtk pbtk (Protobuf toolkit) is a Python-based set of scripts with a unified GUI for extracting Protobuf data structures from programs (Java run… | 99 | 1680 | maintenance |
| threatexpress/domainhunter Domain Hunter is a Python CLI tool that finds expired or available domains with prior benign usage history via ExpiredDomains.net, then che… | 32 | 1680 | maintenance |
| rasta-mouse/Watson Watson is a .NET console tool that enumerates missing Windows KB patches and suggests exploits for known privilege escalation vulnerabiliti… | 10 | 1678 | maintenance |
| krisnova/boopkit boopkit is a Linux rootkit and backdoor written in C that uses eBPF to enable remote command execution over raw TCP. It requires prior priv… | 23 | 1677 | maintenance |
| tornadocash/tornado-core Tornado Cash is a non-custodial privacy protocol for Ethereum and ERC20 tokens built on zkSNARKs, implemented as smart contracts with JavaS… | 10 | 1677 | maintenance |
| noob-hackers/kalimux Kalimux is a bash script that automatically installs Kali Linux with a GUI inside Termux on Android, without requiring root. It uses proot … | 32 | 1674 | maintenance |
| noob-hackers/grabcam Grabcam is a bash-based Termux script that generates a fake offer page and an ngrok link to trick a victim into granting camera access, cap… | 32 | 1674 | maintenance |
| Chainfire/libsuperuser A Java library for Android that simplifies executing shell commands and root (su) operations from apps, with interactive shells, threading … | 32 | 1673 | maintenance |
| PAGalaxyLab/YAHFA YAHFA is a hook framework for Android ART that enables efficient Java method hooking and replacement. It is distributed as an Android libra… | 23 | 1672 | maintenance |
| Google Authenticator The open-source implementations of Google Authenticator, generating one-time passcodes using the OATH HOTP (RFC 4226) and TOTP (RFC 6238) s… | 10 | 1672 | maintenance |
| SECFORCE/sparta SPARTA is a Python GUI application that simplifies network infrastructure penetration testing by streamlining the scanning and enumeration … | 23 | 1671 | maintenance |
| Dheerajmadhukar/4-ZERO-3 4-ZERO-3 is a Bash-based security testing script that automates a wide range of techniques for bypassing HTTP 403/401 access restrictions o… | 32 | 1669 | maintenance |
| TheKingOfDuck/burpFakeIP A Burp Suite extension written in Java that forges IP addresses in HTTP request headers (X-Forwarded-For and similar) to test servers with … | 23 | 1669 | maintenance |
| securesocketfunneling/ssf Secure Socket Funneling (SSF) is a cross-platform network tool and toolkit that multiplexes TCP and UDP traffic through a single TLS-encryp… | 23 | 1669 | maintenance |
| Ekultek/WhatBreach WhatBreach is a Python CLI OSINT tool that searches email addresses against known data breaches via services like HIBP, dehashed, hunter.io… | 48 | 1667 | maintenance |
| taviso/ctftool An interactive command-line tool for exploring the CTF (Clipboard/Text Services Framework) protocol used by Windows Text Services. It suppo… | 23 | 1667 | maintenance |
| asLody/whale Whale is a cross-platform hook framework written in C++ that runs on Android, iOS, Linux, and macOS, supporting ARM/THUMB, ARM64, X86, and … | 32 | 1665 | maintenance |
| opensec-cn/kunpeng Kunpeng is an open-source vulnerability POC (proof-of-concept) detection framework written in Go, bundling POCs for databases, middleware, … | 23 | 1665 | maintenance |
| pydantic/monty Monty is a minimal, secure Python interpreter written in Rust designed for safely executing LLM-generated code without container-based sand… | 95 | 8158 | experimental |
| Mr-Un1k0d3r/SCShell SCShell is a fileless lateral movement tool that executes commands on remote Windows systems by modifying a service's binary path via Chang… | 32 | 1661 | maintenance |
| davehull/Kansa Kansa is a modular incident response framework written in PowerShell that uses PowerShell Remoting to run data-collection modules across ma… | 23 | 1661 | maintenance |
| ius/rsatool A Python command-line tool that computes RSA and RSA-CRT parameters (p, q, n, d, e, dP, dQ, qInv) from either two primes or a modulus and p… | 74 | 1659 | maintenance |
| Dec0ne/KrbRelayUp KrbRelayUp is a C# command-line tool that wraps Rubeus and KrbRelay to automate a Kerberos relay-based local privilege escalation in Window… | 32 | 1657 | maintenance |
| mdp/rotp A Ruby library for generating and validating one-time passwords (HOTP and TOTP) according to RFC 4226 and RFC 6238. It is compatible with G… | 47 | 1656 | maintenance |
| Adminisme/ServerScan ServerScan is a high-concurrency network scanning and service detection tool written in Go, designed for intranet lateral information gathe… | 23 | 1655 | maintenance |
| facebookresearch/CrypTen CrypTen is a PyTorch-based library for privacy-preserving machine learning built on secure multiparty computation. It exposes a CrypTensor … | 10 | 1649 | maintenance |
| d3vilbug/HackBar A Burp Suite plugin that adds a HackBar panel for quickly injecting common payloads like SQLi and XSS during manual web application testing… | 23 | 1633 | maintenance |
| opauth/opauth Opauth is a multi-provider authentication framework for PHP, inspired by OmniAuth for Ruby. It provides a standardized API for interfacing … | 23 | 1632 | maintenance |
| androidmalware/android_hid A set of shell scripts that turn a rooted Android device into a USB HID keyboard (Rubber Ducky style) to inject keystroke payloads into tar… | 32 | 1631 | maintenance |
| dpnishant/appmon AppMon is an automated framework for monitoring and tampering with system API calls of native macOS, iOS, and Android apps, built on Frida.… | 10 | 1631 | maintenance |
| JohnHammond/msdt-follina A Python CLI tool that generates malicious Microsoft Word documents exploiting the MS-MSDT 'Follina' vulnerability (CVE-2022-30190) and sta… | 32 | 1630 | maintenance |
| jivoi/pentest A collection of Python and shell scripts for offensive security and penetration testing tasks, including host discovery, port scanning, and… | 32 | 1630 | maintenance |
| veo/vscan vscan is an open-source, lightweight, fast, cross-platform website vulnerability scanner written in Go, built for red team reconnaissance. … | 23 | 1630 | maintenance |
| huangyz0918/AndroidWM AndroidWM is a lightweight Java library for Android that adds visible or invisible (steganographic) watermarks to images. It supports text … | 32 | 1628 | maintenance |
| malfunkt/hyperfox Hyperfox is a Go-based security auditing tool that acts as a man-in-the-middle proxy for HTTP and HTTPS traffic, recording all intercepted … | 23 | 1628 | maintenance |
| bdamele/icmpsh icmpsh is a simple reverse ICMP shell tool with a Windows slave (client) written in C and a portable master (server) implemented in C, Perl… | 32 | 1625 | maintenance |
| firesunCN/BlueLotus_XSSReceiver BlueLotus_XSSReceiver is a self-hosted XSS data receiving platform written in PHP and JavaScript, designed for CTF practice and security le… | 32 | 1624 | maintenance |
| zed-0xff/zsteg zsteg is a Ruby CLI tool that detects steganography-hidden data in PNG and BMP images, including LSB steganography, zlib-compressed payload… | 61 | 1621 | maintenance |
| sweetsoftware/Ares Ares is a Python-based remote access tool (RAT) consisting of a web-based command-and-control server and a lightweight agent that runs on t… | 32 | 1621 | maintenance |
| TheHive-Project/Cortex Cortex is an open-source observable analysis and active response engine for SOCs, CSIRTs, and security researchers. It lets analysts analyz… | 84 | 1619 | maintenance |
| wfh45678/radar Radar is a lightweight real-time risk control and decision engine built with Java (Spring Boot), MongoDB, Redis, Elasticsearch, and a Groov… | 23 | 1619 | maintenance |
| ispysoftware/iSpy iSpy is an open source video surveillance application for Windows that connects to webcams and IP cameras, providing live viewing, motion d… | 62 | 1618 | maintenance |
| byt3bl33d3r/DeathStar DeathStar is a Python CLI tool that automates gaining Domain and Enterprise Admin privileges in Active Directory environments by chaining c… | 32 | 1618 | maintenance |
| martinmarinov/TempestSDR A software toolkit for remotely eavesdropping on video monitors by capturing compromising electromagnetic emanations from video cables usin… | 32 | 1617 | maintenance |
| nccgroup/Winpayloads Winpayloads is a Python 2.7 tool for generating undetectable Windows payloads with extras like UAC bypass, persistence, and PowerShell stag… | 32 | 1616 | maintenance |
| dstmath/frida-unpack A Frida-based unpacking tool for Android apps that hooks libart.so's OpenMemory (or OpenCommon on Android 10) to dump decrypted DEX files f… | 44 | 1613 | maintenance |
| shuhongfan/NavicatCracker A keygen and patcher for activating Navicat 16 database client software without a paid license. It patches the installed Navicat binary and… | 32 | 1610 | maintenance |
| HACK3RY2J/Anon-SMS A shell-based tool for Linux and Termux that sends anonymous SMS messages via a third-party service, limited to one message per day. It is … | 32 | 1608 | maintenance |
| google/highwayhash A C++ library providing fast, strong (well-distributed and unpredictable) hash functions: a portable SipHash implementation and HighwayHash… | 10 | 1605 | maintenance |
| den4uk/andriller Andriller CE is a Python-based forensic toolkit for Android smartphones that performs read-only, non-destructive data acquisition from devi… | 23 | 1601 | maintenance |
| tenta-browser/tenta-dns Tenta DNS is a Go-based DNS server suite combining an authoritative DNS server, a recursive resolver with DNSSEC and DNS-over-TLS support, … | 32 | 1600 | maintenance |
| litl/rauth Rauth is a Python library for consuming OAuth 1.0/a, OAuth 2.0, and Ofly APIs, built on top of Requests. It provides service wrapper classe… | 10 | 1600 | maintenance |
| stark0de/nginxpwner Nginxpwner is a Python command-line tool that scans Nginx servers for common misconfigurations and known vulnerabilities, such as CRLF inje… | 10 | 1599 | maintenance |
| tokyoneon/Chimera Chimera is a PowerShell obfuscation script that transforms malicious PS1 payloads using string substitution and variable concatenation to b… | 32 | 1598 | maintenance |
| savio-code/fern-wifi-cracker Fern Wifi Cracker is a Python/Qt GUI application for wireless security auditing that can crack and recover WEP, WPA/WPA2, and WPS keys. It … | 70 | 1597 | maintenance |
| outflanknl/Dumpert Dumpert is a proof-of-concept LSASS memory dumper written in C and assembly that uses direct system calls and API unhooking to evade AV/EDR… | 32 | 1597 | maintenance |
| maciejczyzewski/libchaos A C++ library implementing randomization, hashing, and statistical analysis algorithms based on the concept of chaos machines. It aims to r… | 23 | 1597 | maintenance |
| Squalr/Squalr-Sharp Squalr is a high-performance memory editor for Windows desktop games, written in C#, supporting memory scanning, pointer scanning, and x86/… | 23 | 1596 | maintenance |
| Lotus6/ThinkphpGUI A Java-based GUI vulnerability exploitation tool targeting the ThinkPHP framework, supporting detection of vulnerabilities across ThinkPHP … | 23 | 1595 | maintenance |
| wyzxxz/shiro_rce_tool A Java-based command-line tool that assists in detecting and exploiting Apache Shiro rememberMe deserialization vulnerabilities. It brute-f… | 32 | 1594 | maintenance |
| sairson/Yasso Yasso is a Go-based intranet penetration testing toolkit that combines service brute-forcing (RDP, SSH, Redis, PostgreSQL, MongoDB, MSSQL, … | 23 | 1593 | maintenance |
| omadahealth/LolliPin LolliPin is a Material design styled Android library that adds PIN code lock protection to apps, storing only a SHA-1 hash of the PIN. It a… | 10 | 1590 | maintenance |
| braitsch/node-login A Node.js and MongoDB template application providing a complete user account management system with signup, login, session tracking, and em… | 32 | 1589 | maintenance |
| lelinhtinh/de4js de4js is a web-based JavaScript deobfuscator and unpacker that transforms obfuscated code (Eval, Array, JSFuck, JJencode, AAencode, Packer,… | 10 | 1580 | maintenance |
| 0xHJK/dumpall dumpall is a Python command-line tool for exploiting information disclosure vulnerabilities on web servers. It reconstructs source code fro… | 23 | 1579 | maintenance |
| strongdm/comply Comply is an open-source SOC2-focused compliance automation CLI written in Go. It generates auditor-friendly policy documents from Markdown… | 23 | 1578 | maintenance |
| zidansec/CloudPeler CrimeFlare is a PHP command-line OSINT tool that attempts to reveal the real origin IP address behind websites protected by Cloudflare's WA… | 10 | 1576 | maintenance |
| unixpickle/gobfuscate A command-line tool that obfuscates Go binaries by compiling from obfuscated source code. It hashes package names, global identifiers, meth… | 32 | 1574 | maintenance |
| XiphosResearch/exploits A collection of miscellaneous proof-of-concept exploit scripts written by Xiphos Research for security testing purposes, covering CVEs acro… | 32 | 1573 | maintenance |
| v3n0m-Scanner/V3n0M-Scanner V3n0M is an offensive security framework and vulnerability scanner written in Python 3.6+ using asyncio. It scans for SQLi, XSS, LFI/RFI vu… | 23 | 1573 | maintenance |
| BishopFox/GitGot GitGot is a semi-automated, feedback-driven CLI tool for searching public GitHub data (code and gists) for exposed sensitive secrets. Users… | 32 | 1572 | maintenance |
| grafeas/grafeas Grafeas is an open-source artifact metadata API and reference server (written in Go) that defines a uniform spec for storing, querying, and… | 65 | 1571 | maintenance |
| DeEpinGh0st/Erebus Erebus is a post-exploitation plugin for Cobalt Strike written in PowerShell and Sleep (Aggressor Script). It bundles information gathering… | 23 | 1570 | maintenance |
| javiersantos/PiracyChecker An Android library that helps prevent app piracy by verifying Google Play Licensing (LVL), APK signatures, and other tampering checks. It t… | 61 | 1569 | maintenance |
| Viralmaniar/BigBountyRecon BigBountyRecon is a C# Windows GUI tool that automates initial reconnaissance on a target organisation using 58 techniques, including Googl… | 23 | 1567 | maintenance |
| koush/Superuser An open-source Superuser management app and su binary for rooted Android devices, written in C and Java. It grants and manages root permiss… | 32 | 1562 | maintenance |
| google/log4jscanner A Go-based filesystem scanner and library that detects JAR files containing the vulnerable Log4j classes behind the Log4Shell vulnerability… | 10 | 1562 | maintenance |
| Mr-Un1k0d3r/PowerLessShell PowerLessShell is a Python CLI tool that generates MSBuild project files capable of executing PowerShell scripts or raw shellcode without s… | 66 | 1559 | maintenance |
| csujedihy/proximac Proximac is an open-source command-line alternative to Proxifier that forces any application's traffic through a SOCKS5 proxy on macOS. It … | 23 | 1559 | maintenance |
| th3unkn0n/osi.ig A Python CLI tool that gathers OSINT information about Instagram accounts, including profile details, tags, mentions, emails, and post meta… | 32 | 1554 | maintenance |
| Picocrypt/Picocrypt Picocrypt is a small, simple, and secure file encryption tool built in Go, using XChaCha20 and Argon2id. It offers a portable GUI applicati… | 10 | 1554 | maintenance |
| Cn33liz/p0wnedShell p0wnedShell is a C# offensive PowerShell host application that runs PowerShell commands and modules within a runspace environment without r… | 32 | 1550 | maintenance |
| orta/cocoapods-keys A CocoaPods plugin that stores per-developer environment and application keys securely in the macOS keychain instead of source code. On pod… | 32 | 1548 | maintenance |
| w5teams/w5 W5 is an open-source, low-code Security Orchestration, Automation and Response (SOAR) platform built in Python with a visual playbook edito… | 23 | 1548 | maintenance |
| gaasedelen/tenet Tenet is an IDA Pro plugin for exploring and navigating execution traces of binaries. It provides a timeline widget and bidirectional execu… | 23 | 1546 | maintenance |
| SharadKumar97/OSINT-SPY OSINT-SPY is a Python command-line tool that performs open-source intelligence scans on emails, domains, IP addresses, organizations, Bitco… | 23 | 1544 | maintenance |
| zboxfs/zbox ZboxFS is a zero-details, privacy-focused embedded file system written in Rust that encrypts everything, including metadata and directory s… | 10 | 1543 | maintenance |
| mandiant/SharPersist SharPersist is a Windows persistence toolkit written in C# that can add, remove, check, and list various persistence techniques such as reg… | 10 | 1541 | maintenance |
| xiecat/goblin Goblin is a phishing simulation system for red team/blue team security exercises, built in Go. It works as a reverse proxy that transparent… | 23 | 1537 | maintenance |