domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| s0md3v/Corsy Corsy is a lightweight Python 3 CLI tool that scans websites for known CORS (Cross-Origin Resource Sharing) misconfigurations. It tests for… | 23 | 1537 | maintenance |
| idapython/src IDAPython is the Python scripting SDK and plugin framework for Hex-Rays' IDA Pro binary analysis suite, exposing IDA's disassembler, decomp… | 10 | 1536 | maintenance |
| mattrajca/sudo-touchid A fork of the Unix sudo utility that adds Touch ID biometric authentication support on macOS via the LocalAuthentication framework. It lets… | 32 | 1534 | maintenance |
| Ha3MrX/InstaBrute InstaBrute is a shell script that performs brute-force password attacks against Instagram accounts, exploiting password-guessing vectors co… | 71 | 1533 | maintenance |
| GhostPack/SharpUp SharpUp is a C# port of common Windows privilege escalation checks from the PowerUp PowerShell script. It audits a system for misconfigurat… | 32 | 1533 | maintenance |
| ExpertAnonymous/PhoneInfoga A Termux-oriented shell-script distribution of PhoneInfoga, an OSINT reconnaissance tool for scanning international phone numbers using fre… | 32 | 1531 | maintenance |
| Battelle/movfuscator The M/o/Vfuscator is a C compiler that compiles programs into x86 'mov' instructions only, performing all arithmetic, control flow, and fun… | 32 | 1531 | maintenance |
| galkan/crowbar Crowbar is a Python-based brute forcing tool for penetration testing that supports protocols often missing from other brute force tools, su… | 23 | 1530 | maintenance |
| gtxaspec/wz_mini_hacks A firmware modification toolkit for Ingenic T20/T31 based Wyze IP cameras that provides root access and extra features via a micro-SD card,… | 71 | 1529 | maintenance |
| harleyQu1nn/AggressorScripts A curated collection of Aggressor scripts (.cna) for Cobalt Strike 3.0+, aggregated from multiple community sources. The scripts automate r… | 32 | 1528 | maintenance |
| Yaxser/Backstab Backstab is a Windows command-line tool that kills antimalware/EDR-protected processes by abusing the Microsoft-signed Sysinternals Process… | 23 | 1528 | maintenance |
| callicoder/spring-boot-react-oauth2-social-login-demo A demo application showing how to implement OAuth2 social login (Google, Facebook, GitHub) with a Spring Boot backend and React frontend. I… | 32 | 1522 | maintenance |
| gentilkiwi/kekeo kekeo is a C-based command-line toolbox for manipulating Microsoft Kerberos, from the author of mimikatz. It supports operations like ticke… | 23 | 1522 | maintenance |
| oauth-io/oauthd oauthd is the open source core of OAuth.io, a Node.js server that lets you self-host an OAuth integration layer supporting 100+ providers l… | 23 | 1520 | maintenance |
| CTF-MissFeng/bayonet Bayonet is a self-hosted web-based IT asset management and attack-surface platform for penetration testers, integrating subdomain enumerati… | 23 | 1519 | maintenance |
| chaitin/rad Rad (Radium) is a browser-based web crawler built for security scanning, driving a real Chrome browser to discover URLs and requests across… | 23 | 1515 | maintenance |
| outmoded/oz Oz is a web authorization protocol and Node.js library for granting and authenticating third-party access to an API on behalf of a user or … | 10 | 1514 | maintenance |
| HummerRisk/HummerRisk HummerRisk is an open-source, agentless cloud-native security platform for hybrid cloud security governance and Kubernetes/container securi… | 23 | 1512 | maintenance |
| gwen001/github-search A collection of Python, PHP, and Bash scripts that perform targeted searches on GitHub via its search API to find secrets, keys, private re… | 23 | 1511 | maintenance |
| chip-red-pill/MicrocodeDecryptor A set of Python scripts for decrypting Intel Atom CPU microcode updates, using encryption keys extracted via the Red Unlock debugging techn… | 32 | 1510 | maintenance |
| WooyunDota/DroidSSLUnpinning A collection of Frida hook scripts (ObjectionUnpinningPlus) that bypass Android certificate pinning so HTTPS traffic can be intercepted wit… | 32 | 1510 | maintenance |
| nidem/kerberoast A collection of Python and PowerShell tools for attacking Microsoft Kerberos implementations, including requesting service tickets, crackin… | 32 | 1510 | maintenance |
| mitreid-connect/OpenID-Connect-Java-Spring-Server A certified OpenID Connect reference implementation in Java on the Spring platform, providing an identity provider server, OAuth 2.0 author… | 32 | 1508 | maintenance |
| ViRb3/TrustMeAlready An Xposed module for rooted Android devices that disables SSL certificate verification and pinning system-wide. It hooks Java trust-check m… | 10 | 1507 | maintenance |
| hatRiot/zarp Zarp is a Python-based network attack tool focused on exploiting local networks by abusing networking protocols rather than systems. It pro… | 23 | 1506 | maintenance |
| gonzalo-bulnes/simple_token_authentication A Ruby gem that adds simple token authentication to Rails applications or APIs using Devise. It packages José Valim's recommended safe toke… | 23 | 1504 | maintenance |
| Kevin-Robertson/Powermad Powermad is a set of PowerShell functions for exploiting Active Directory's default MachineAccountQuota and Active Directory-Integrated DNS… | 32 | 1502 | maintenance |
| pentestmonkey/windows-privesc-check A standalone Windows executable (built from Python with PyInstaller) that audits systems for privilege escalation vectors such as weak serv… | 32 | 1500 | maintenance |
| ChiChou/bagbak bagbak is a Node.js CLI tool that uses Frida to decrypt iOS App Store binaries on a jailbroken device, dumping decrypted IPAs including app… | 90 | 1499 | maintenance |
| ricmoo/aes-js A pure JavaScript implementation of the AES block cipher supporting all common modes of operation (CBC, CFB, CTR, ECB, OFB) and all key siz… | 23 | 1496 | maintenance |
| ptrkrysik/gr-gsm A set of GNU Radio blocks and tools for receiving and decoding GSM transmissions using software-defined radios. It is based on the Airprobe… | 37 | 1494 | maintenance |
| happylishang/AntiFakerAndroidChecker An Android library that detects whether the app is running on an emulator and retrieves relatively authentic device identifiers (IMEI, Andr… | 23 | 1491 | maintenance |
| veo/wsMemShell A Java-based WebSocket memory webshell (memshell) tool that injects WebSocket endpoints into running application servers like Tomcat, Sprin… | 32 | 1489 | maintenance |
| anttiviljami/browser-autofill-phishing A simple JavaScript demo showing how hidden form fields can be silently filled by browser autofill to phish user data. It demonstrates the … | 32 | 1489 | maintenance |
| mufeedvh/moonwalk moonwalk is a single-binary Rust CLI tool that covers tracks during Linux penetration testing by saving and reverting system log state, she… | 23 | 1487 | maintenance |
| jasny/sso A PHP library implementing simple Single Sign-On (SSO), allowing users to log in once at a central server and be automatically authenticate… | 23 | 1486 | maintenance |
| 0x00-0x00/ShellPop ShellPop is a Python CLI tool that generates ready-to-use reverse and bind shell commands for penetration testing, with obfuscation, encode… | 23 | 1484 | maintenance |
| CYRUS-STUDIO/ApkToolPlus ApkToolPlus is a visual, cross-platform desktop application for Android APK reverse analysis built in Java. It bundles APK decompilation/re… | 40 | 1476 | maintenance |
| Consensys/eth-lightwallet A lightweight JavaScript HD wallet for Ethereum that stores private keys encrypted in the browser or Node.js. It generates BIP32/BIP39 addr… | 32 | 1476 | maintenance |
| optiv/Freeze Freeze is a Go-based payload creation toolkit that generates Windows shellcode loaders designed to bypass EDR security controls. It uses su… | 10 | 1475 | maintenance |
| jordanpotti/AWSBucketDump AWSBucketDump is a Python CLI security tool that enumerates AWS S3 buckets using wordlists, similar to a subdomain bruteforcer but for S3. … | 32 | 1473 | maintenance |
| matterpreter/OffensiveCSharp A collection of standalone C# tools and proof-of-concept programs for offensive security operations, each compiled individually in Visual S… | 32 | 1472 | maintenance |
| antonioCoco/RemotePotato0 RemotePotato0 is a Windows privilege escalation exploit that abuses the DCOM activation service to trigger NTLM authentication from privile… | 23 | 1471 | maintenance |
| doy/rbw rbw is an unofficial command line client for Bitwarden written in Rust. It runs a background agent that holds decryption keys in memory (li… | 69 | 1469 | maintenance |
| 0x09AL/RdpThief RdpThief is a standalone DLL that, when injected into the mstsc.exe (Remote Desktop client) process, uses API hooking to extract clear-text… | 32 | 1469 | maintenance |
| lunasec-io/lunasec LunaSec is an open-source supply chain security suite whose main product, LunaTrace, scans project dependencies for vulnerabilities like Lo… | 23 | 1469 | maintenance |
| psecio/iniscan A command-line tool that scans a php.ini file against common security best practices and reports pass/fail results per setting. It is insta… | 32 | 1468 | maintenance |
| psypanda/hashID hashID is a Python CLI tool that identifies over 220 hash types using regular expressions, working on single hashes, files, or directories.… | 23 | 1468 | maintenance |
| rootclay/WMIHACKER WMIHACKER is a VBScript-based command-line tool for lateral movement on Windows hosts via WMI (port 135), avoiding the commonly detected 44… | 33 | 1465 | maintenance |
| woj-ciech/LeakLooker A Python CLI tool that uses the Binaryedge.io API to find publicly exposed databases and services such as MongoDB, Elasticsearch, CouchDB, … | 10 | 1465 | maintenance |
| nccgroup/house House is a runtime mobile application analysis toolkit with a web GUI, powered by Frida and written in Python. It simplifies dynamic functi… | 32 | 1464 | maintenance |
| twelvesec/gasmask GasMasK is an all-in-one open source OSINT and reconnaissance tool written in Python 3. It aggregates information about a target domain fro… | 23 | 1464 | maintenance |
| woodpecker-framework/woodpecker-framework-release Woodpecker-framework is a Java-based vulnerability detection and deep exploitation framework focused on precisely targeting high-risk vulne… | 23 | 1463 | maintenance |
| ptswarm/reFlutter A Python-based framework that repacks Flutter Android and iOS apps with a patched Flutter engine library to enable dynamic analysis. It red… | 10 | 1463 | maintenance |
| fingerprintjs/BotD BotD is a free, MIT-licensed browser library that detects automation tools and frameworks such as Puppeteer, Selenium, Playwright, and head… | 72 | 1462 | maintenance |
| Synzvato/decentraleyes Decentraleyes is a browser extension that emulates content delivery networks by serving popular CDN-hosted libraries (like JavaScript frame… | 10 | 1462 | maintenance |
| jesparza/peepdf peepdf is a Python tool for analyzing PDF files to determine whether they are malicious, offering object inspection, filter/encoding decodi… | 32 | 1461 | maintenance |
| wyzxxz/heapdump_tool A Java-based CLI tool that parses JVM heapdump files (via jhat) to search for sensitive information such as plaintext passwords, cloud acce… | 32 | 1456 | maintenance |
| DaGenix/rust-crypto A mostly pure-Rust library implementing many common cryptographic algorithms such as AES, SHA-2, ChaCha20, and Ed25519. It aims for practic… | 23 | 1456 | maintenance |
| airbnb/binaryalert BinaryAlert is an open-source serverless AWS pipeline that scans every file uploaded to an S3 bucket against a configurable set of YARA rul… | 23 | 1455 | maintenance |
| SySS-Research/Seth Seth is a Python and Bash proof-of-concept tool that performs a man-in-the-middle attack on RDP connections via ARP spoofing, downgrading t… | 56 | 1454 | maintenance |
| programa-stic/barf-project BARF is an open-source Python framework for binary analysis and reverse engineering. It lifts instructions from x86 and ARM binaries into a… | 32 | 1452 | maintenance |
| QAX-A-Team/BrowserGhost BrowserGhost is a C# command-line tool for red team operators that extracts saved browser credentials, cookies, history, and bookmarks from… | 23 | 1452 | maintenance |
| unixhot/waf A lightweight Web Application Firewall (WAF) implemented with Nginx + Lua (OpenResty). It provides IP black/white lists, URL and User-Agent… | 23 | 1450 | maintenance |
| oddcod3/Phantom-Evasion Phantom-Evasion is a Python-based antivirus evasion tool that generates obfuscated executables and payloads designed to bypass antivirus de… | 10 | 1450 | maintenance |
| HADB/GetWeixinCode A single HTML page deployed under a WeChat OAuth2.0 authorized callback domain that forwards authorization codes to arbitrary redirect URIs… | 23 | 1449 | maintenance |
| mrash/fwknop fwknop implements Single Packet Authorization (SPA), a next-generation port knocking scheme that conceals services behind a default-drop fi… | 61 | 1447 | maintenance |
| lepture/flask-oauthlib Flask-OAuthlib is a Flask extension for interacting with remote OAuth-enabled applications, supporting OAuth 1.0a/1.0/1.1 and OAuth2 client… | 32 | 1446 | maintenance |
| SamJoan/droopescan Droopescan is a plugin-based command-line scanner that helps security researchers identify the CMS, version, plugins, themes, and interesti… | 32 | 1446 | maintenance |
| Invoke-IR/PowerForensics PowerForensics is a PowerShell module built on a C# class library that provides an all-in-one framework for live disk forensic analysis. It… | 23 | 1444 | maintenance |
| JustasMasiulis/xorstr A header-only C++17 library that encrypts string literals at compile time using XOR with 64-bit keys and vectorized (SSE/AVX) inlined decry… | 32 | 1442 | maintenance |
| cisagov/LME CISA's Logging Made Easy (LME) is a free, open-source log management and threat detection platform that bundles Elasticsearch, Kibana, Wazu… | 10 | 1442 | maintenance |
| L4ys/LazyIDA LazyIDA is an IDA Pro plugin written in Python (IDAPython) that adds convenience features like data format conversion with clipboard copy, … | 62 | 1441 | maintenance |
| syvaidya/openstego OpenStego is a Java-based steganography application that hides data inside image files and embeds invisible watermarks to detect unauthoriz… | 23 | 1441 | maintenance |
| dxa4481/Pastejacking A proof-of-concept demo of pastejacking: using JavaScript to override a user's clipboard contents when they copy text from a webpage, trick… | 32 | 1437 | maintenance |
| Raikia/FiercePhish FiercePhish is a self-hosted PHP web application for managing full phishing engagements, including campaign tracking, scheduled email sendi… | 23 | 1437 | maintenance |
| spacehuhn/wifi_ducky WiFi Ducky is a Wi-Fi controlled BadUSB device built from an ESP8266 and ATmega32U4 that uploads, saves, and remotely executes Ducky Script… | 23 | 1437 | maintenance |
| jweny/pocassist Pocassist is an open-source vulnerability PoC testing framework written in Go that lets users edit, run, and batch-test PoCs through a web … | 10 | 1436 | maintenance |
| kmackay/micro-ecc A small, fast C library implementing ECDH key exchange and ECDSA signatures for 8-bit, 32-bit, and 64-bit processors, with optional inline … | 23 | 1435 | maintenance |
| BugScanTeam/DNSLog DNSLog is a self-hosted tool that monitors DNS resolution records and HTTP access logs, built on Django with an integrated DNS server. It i… | 10 | 1435 | maintenance |
| nccgroup/demiguise Demiguise is a Python CLI tool from NCC Group that generates HTML files containing RC4-encrypted HTA payloads, which are decrypted dynamica… | 32 | 1429 | maintenance |
| bpellin/keepassdroid KeePassDroid is an Android port of the KeePass Password Safe, allowing users to open and manage KeePass password databases (.kdb and .kdbx,… | 42 | 1427 | maintenance |
| nfc-tools/mfoc MFOC is an open-source C implementation of the offline nested attack for recovering authentication keys from MIFARE Classic NFC cards. It r… | 32 | 1427 | maintenance |
| FunnyWolf/pystinger Pystinger is a Python tool that establishes a SOCKS4a proxy and port mapping through a webshell (PHP, JSP, or ASPX) on a compromised server… | 23 | 1426 | maintenance |
| atom/node-keytar A native Node.js module (written in C++) for storing, retrieving, replacing, and deleting passwords in the operating system's credential st… | 10 | 1426 | maintenance |
| dgrubelic/vue-authenticate vue-authenticate is an easily configurable authentication library for Vue.js supporting local email/password login and registration plus so… | 23 | 1424 | maintenance |
| 7kbstorm/7kbscan-WebPathBrute 7kbscan-WebPathBrute is a Windows GUI tool for brute-forcing web paths and directories using dictionaries. It supports multithreaded scanni… | 23 | 1424 | maintenance |
| paranoidninja/CarbonCopy A Python CLI tool that downloads a website's TLS certificate, creates a spoofed version of it, and uses it to sign Windows executables for … | 32 | 1423 | maintenance |
| NtQuery/Scylla Scylla is a Windows x86/x64 tool for reconstructing import tables (IAT) of unpacked or dumped binaries. It supports dumping processes, fixi… | 23 | 1422 | maintenance |
| ptoomey3/Keychain-Dumper A command-line tool for jailbroken iOS devices that dumps Keychain items (passwords, certificates, identities) accessible to an attacker. I… | 23 | 1421 | maintenance |
| 易开发 (DeveloperHelper) DeveloperHelper (易开发) is an Android developer/analysis tool app with an Xposed module that dumps DEX files from packed (hardened) APKs, plu… | 39 | 1420 | maintenance |
| 0xnobody/vmpdump VMPDump is a dynamic dumper and import fixer for binaries protected with VMProtect 3.x (x64), built on the VTIL intermediate language. It s… | 23 | 1417 | maintenance |
| Mr-Un1k0d3r/DKMC DKMC (Don't Kill My Cat) is a Python CLI tool that embeds obfuscated shellcode inside valid BMP images, producing polyglot files that are b… | 10 | 1417 | maintenance |
| signalapp/libsignal-protocol-c A C implementation of the Signal Protocol, a ratcheting forward-secrecy encryption protocol for synchronous and asynchronous messaging. It … | 10 | 1417 | maintenance |
| brannondorsey/naive-hashcat A plug-and-play shell script wrapper around hashcat that cracks password hashes using pre-configured, empirically tested attack parameters.… | 23 | 1416 | maintenance |
| looterz/grimd Grimd is a fast DNS proxy server written in Go that blackholes advertisement and malware domains using configurable blocklists. It runs any… | 23 | 1416 | maintenance |
| cube0x0/noPac A C# tool that scans for and exploits the CVE-2021-42287/CVE-2021-42278 Active Directory vulnerability chain, allowing a standard domain us… | 32 | 1414 | maintenance |
| google/firing-range Firing Range is a deliberately vulnerable Java web application that serves as a test bed for web application security scanners. It provides… | 10 | 1413 | maintenance |
| CiscoCXSecurity/enum4linux enum4Linux is a Perl-based CLI tool that enumerates information from Windows and Samba hosts, serving as a Linux alternative to enum.exe. I… | 71 | 1412 | maintenance |
| Lucifer1993/struts-scan A Python2 command-line tool that detects and exploits Apache Struts2 remote code execution vulnerabilities across all major versions (ST2-0… | 32 | 1412 | maintenance |