domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| davidaurelio/hashids-python A Python implementation of the hashids algorithm that generates short, URL-friendly, obfuscated hashes from integers. It lets you hide data… | 32 | 1411 | maintenance |
| m4ll0k/Atlas Atlas is a Python CLI tool that suggests SQLMap tamper scripts to bypass WAF/IDS/IPS protections during SQL injection testing. It works by … | 32 | 1411 | maintenance |
| davidtavarez/pwndb pwndb.py is a Python command-line tool for searching leaked credentials via the pwndb Onion service through a Tor proxy. It supports search… | 10 | 1410 | maintenance |
| LinusHenze/Fugu14 Fugu14 is an untethered jailbreak for iOS 14.3-14.5.1 targeting arm64e devices, including a kernel exploit, PAC bypass, PPL bypass, and boo… | 10 | 1410 | maintenance |
| symfony/security-guard The Symfony Security Guard component, part of the Symfony framework, lets developers build custom multi-step authentication systems with fu… | 10 | 1410 | maintenance |
| c0ny1/FastjsonExploit A Java CLI framework for quickly exploiting Fast deserialization vulnerabilities. It generates exploit payloads with one command and bundle… | 32 | 1407 | maintenance |
| moeiscool/Shinobi Shinobi CE is a free, open-source CCTV/NVR platform written in Node.js for recording and managing IP security cameras. It supports RTSP/ONV… | 23 | 1407 | maintenance |
| google/conscrypt Conscrypt is a Java Security Provider implementing parts of the Java Cryptography Extension (JCE) and Java Secure Socket Extension (JSSE), … | 100 | 1406 | maintenance |
| antonioribeiro/firewall A Laravel package acting as a soft-firewall that controls route access by IP address, country, or host via blacklists and whitelists. It al… | 32 | 1406 | maintenance |
| hakluke/weaponised-XSS-payloads A collection of weaponised XSS payloads - JavaScript files that perform sensitive actions (like creating admin users) on popular CMS platfo… | 32 | 1405 | maintenance |
| advboxes/AdvBox AdvBox is a Baidu open-source toolbox for generating adversarial examples that fool neural networks across frameworks like PaddlePaddle, Py… | 32 | 1404 | maintenance |
| ele7enxxh/Android-Inline-Hook A C library for inline hooking of native functions on 32-bit Android, supporting ARM, Thumb16, and Thumb32 instruction sets. It lets you re… | 32 | 1402 | maintenance |
| corneliusweig/rakkess rakkess is a kubectl plugin that displays an access matrix showing the current user's permissions across all Kubernetes server resources, s… | 23 | 1402 | maintenance |
| sham00n/buster Buster is a Python command-line OSINT tool for email reconnaissance. It finds social accounts linked to an email, data breaches, pastes, re… | 32 | 1401 | maintenance |
| susam/mintotp MinTOTP is a minimal TOTP (time-based one-time password) generator written in about 20 lines of Python, usable as a CLI tool or as importab… | 32 | 1400 | maintenance |
| tandasat/DdiMon DdiMon is a hypervisor-based research tool that performs stealth inline hooking of Windows kernel API calls using Intel VT-x EPT memory sha… | 32 | 1397 | maintenance |
| 0xgalz/Virtuailor Virtuailor is an IDAPython plugin for IDA Pro that reconstructs C++ virtual tables (vtables) for Intel x86/x64 and AArch64 binaries. It com… | 32 | 1397 | maintenance |
| 649/Memcrashed-DDoS-Exploit A Python CLI exploit tool that finds exposed Memcached servers via the Shodan API and sends forged UDP packets to them to amplify DDoS atta… | 32 | 1396 | maintenance |
| HASecuritySolutions/VulnWhisperer VulnWhisperer is a vulnerability management tool and report aggregator that pulls scan reports from scanners like Nessus, Qualys, OpenVAS, … | 10 | 1396 | maintenance |
| maK-/parameth parameth is a Python command-line tool that brute-forces GET and POST parameter names on web endpoints by comparing response differences. I… | 10 | 1396 | maintenance |
| ustayready/CredSniper CredSniper is a phishing framework built on Python's Flask micro-framework and Jinja2 templating that launches realistic phishing sites wit… | 32 | 1393 | maintenance |
| saucxs/watermark-dom watermark-dom is a lightweight JavaScript library that adds configurable text watermarks to web pages using DOM elements, Shadow DOM, and p… | 32 | 1391 | maintenance |
| NytroRST/NetRipper NetRipper is a Windows post-exploitation tool that uses API hooking to intercept network traffic, capturing both plain-text and encrypted d… | 32 | 1390 | maintenance |
| BastilleResearch/mousejack A collection of device discovery and research tools for the MouseJack vulnerabilities affecting wireless mice and keyboards using nRF24LU1+… | 32 | 1390 | maintenance |
| importCTF/Instagram-Hacker A Python command-line script that performs brute-force password attacks against Instagram accounts, using mechanize and requests with optio… | 32 | 1389 | maintenance |
| aritraroy/PinLockView A customizable Android custom view library for implementing PIN lock screens, with an optional indicator dots view and dial pad usage. Writ… | 32 | 1388 | maintenance |
| bytedance/AabResGuard AabResGuard is a tool from ByteDance's Douyin Android team that obfuscates resources inside Android App Bundle (AAB) files to shrink packag… | 10 | 1386 | maintenance |
| 3ndG4me/AutoBlue-MS17-010 A semi-automated, standalone Python exploit for the MS17-010 (EternalBlue) SMB vulnerability that generates kernel shellcode and handles li… | 32 | 1382 | maintenance |
| screetsec/Dracnmap Dracnmap is a shell-based menu tool that wraps nmap to simplify network scanning and information gathering. It exposes nmap's advanced scri… | 23 | 1382 | maintenance |
| lijiejie/swagger-exp A Python-based Swagger REST API information disclosure exploitation tool. It enumerates API endpoints, auto-fills parameters, tests for una… | 32 | 1381 | maintenance |
| freelan-developers/freelan FreeLAN is an open-source, peer-to-peer VPN application written in C++ that creates secure virtual networks over the internet. It supports … | 23 | 1379 | maintenance |
| fnmsd/MySQL_Fake_Server A pure Python3 fake MySQL server used in penetration testing to exploit MySQL client file reading and trigger Java deserialization attacks … | 32 | 1378 | maintenance |
| bitsadmin/fakelogonscreen FakeLogonScreen is a red-team utility that displays a fake Windows logon screen to capture a user's password, validating it against Active … | 23 | 1378 | maintenance |
| TideSec/Mars Mars is a self-hosted security platform for asset discovery, subdomain enumeration, port and web fingerprinting, and change monitoring of i… | 32 | 1377 | maintenance |
| sickcodes/dock-droid Dock-Droid is a Docker-based tool that runs Android x86 and Android ARM systems inside a container using QEMU with KVM acceleration. It sup… | 32 | 1376 | maintenance |
| sighupio/permission-manager A web UI application for managing Kubernetes RBAC and users. It lets admins create users, assign namespace permissions via templates, and d… | 23 | 1373 | maintenance |
| grayhatacademy/ida A collection of IDA Python plugins, scripts, and modules for the IDA Pro disassembler. It provides reusable tooling for binary analysis and… | 32 | 1368 | maintenance |
| cisco/joy Joy is a libpcap-based C package that captures network traffic and extracts flow and intraflow features (packet timing, byte distributions,… | 10 | 1367 | maintenance |
| MegatronKing/NetBare-Android NetBare is an Android library for capturing, blocking, and injecting network packets using a VPN-based local proxy with a customizable Virt… | 32 | 1366 | maintenance |
| spacehuhn/esp8266_beaconSpam An Arduino sketch for the ESP8266 that broadcasts fake WiFi beacon frames, making scanners show up to a thousand access points with custom … | 23 | 1366 | maintenance |
| BorealisAI/advertorch AdverTorch is a Python toolbox for adversarial robustness research built on PyTorch. It provides modules for generating adversarial perturb… | 32 | 1364 | maintenance |
| Katana Katana is a Python CLI tool by John Hammond that automates common low-hanging-fruit checks for CTF challenges, paired with ctf-katana, a cu… | 32 | 1363 | maintenance |
| Rafficer/linux-cli-community A community-maintained Linux command-line client for ProtonVPN, rewritten in Python from the original bash version. It manages OpenVPN-base… | 10 | 1362 | maintenance |
| danigargu/CVE-2020-0796 A proof-of-concept exploit for CVE-2020-0796 (SMBGhost), a local privilege escalation vulnerability in Windows 10's SMBv3 client driver. Wr… | 23 | 1359 | maintenance |
| kingkool68/generate-ssl-certs-for-local-development A bash script that generates trusted self-signed SSL certificates for local HTTPS development on macOS. It creates a local certificate auth… | 32 | 1358 | maintenance |
| hokaccha/node-jwt-simple A small Node.js library for encoding and decoding JWT (JSON Web Token) strings with a simple encode/decode API. It supports HS256, HS384, H… | 32 | 1357 | maintenance |
| ReversecLabs/SharpGPOAbuse SharpGPOAbuse is a C# .NET command-line tool that abuses a user's edit rights on a Group Policy Object to compromise objects controlled by … | 32 | 1353 | maintenance |
| yampelo/beagle Beagle is an incident response and digital forensics tool that transforms security logs and data sources such as EVTX files, SysMon logs, F… | 23 | 1352 | maintenance |
| GoSSIP-SJTU/Armariris Armariris is an LLVM-based code obfuscation framework maintained by Shanghai Jiao Tong University's cryptography and computer security lab.… | 32 | 1350 | maintenance |
| wbenny/hvpp hvpp is a lightweight Intel VT-x hypervisor written in modern C++ that virtualizes an already-running operating system, primarily targeting… | 32 | 1349 | maintenance |
| jeffzh3ng/fuxi Fuxi is a self-hosted penetration testing platform written in Python that provides a web interface for organizing and running security asse… | 32 | 1347 | maintenance |
| LittleBear4/OA-EXPTOOL A Python-based exploitation framework targeting Chinese OA (Office Automation) systems, bundling nearly 20 batch vulnerability scanners for… | 23 | 1346 | maintenance |
| trustedsec/trevorc2 TrevorC2 is a client/server command-and-control framework that tunnels communications through a browsable, legitimate-looking website to ev… | 32 | 1345 | maintenance |
| gdabah/distorm diStorm3 is a lightweight, fast disassembler library for x86/AMD64 machine code, licensed under BSD. It acts as a decomposer, returning bin… | 23 | 1344 | maintenance |
| cr4n5/XiaoYuanKouSuan A Python-based automation tool that cheats at the XiaoYuanKouSuan (小猿口算) math app by capturing packets to obtain answers and using ADB to s… | 22 | 1344 | maintenance |
| blackberry/pe_tree PE Tree is a Python module and standalone GUI application for viewing Portable Executable (PE) files in a tree-view, built on pefile and Py… | 10 | 1343 | maintenance |
| OmerYa/Invisi-Shell Invisi-Shell is a proof-of-concept tool that bypasses PowerShell security features (ScriptBlock logging, Module logging, Transcription, AMS… | 32 | 1340 | maintenance |
| enzymefinance/oyente Oyente is a static analysis tool for Ethereum smart contracts that detects security vulnerabilities using symbolic execution of EVM bytecod… | 10 | 1338 | maintenance |
| tobefuturer/restore-symbol A command-line reverse engineering tool that restores stripped Objective-C symbol tables in iOS Mach-O binaries. It injects OC method and b… | 32 | 1337 | maintenance |
| fransr/postMessage-tracker A Chrome extension that tracks postMessage listener usage across a page and its subframes, showing listener counts via the extension icon a… | 32 | 1336 | maintenance |
| NationalSecurityAgency/SIMP SIMP (System Integrity Management Platform) is an open-source system automation and configuration management framework built on Puppet, pro… | 10 | 1336 | maintenance |
| pwnesia/ssb SSB (Secure Shell Bruteforcer) is a fast, concurrent SSH password brute-forcing tool written in Go. It attempts to authenticate against an … | 23 | 1335 | maintenance |
| Arvanaghi/SessionGopher SessionGopher is a PowerShell tool that extracts and decrypts saved session information for remote access tools like WinSCP, PuTTY, SuperPu… | 32 | 1334 | maintenance |
| g0tmi1k/msfpc MSFPC is a shell-based wrapper around msfvenom that generates Meterpreter payloads with minimal input, such as just a platform name or file… | 23 | 1333 | maintenance |
| GhostPack/SafetyKatz SafetyKatz is a C# tool that combines a modified Mimikatz with a .NET PE loader to dump LSASS memory and extract credentials. It minidumps … | 32 | 1332 | maintenance |
| tyranid/DotNetToJScript A C# command-line tool that generates JScript (or VBScript/VBA/scriptlet) files which bootstrap and load a .NET assembly entirely from memo… | 23 | 1332 | maintenance |
| w-digital-scanner/w12scan w12scan is a self-hosted network asset discovery engine that aggregates scan results into a searchable web interface backed by Elasticsearc… | 23 | 1332 | maintenance |
| Cur10s1tyByt3/GenP An archival repository preserving the source materials and documentation of GenP, an AutoIt-based patcher tool targeting Adobe software on … | 56 | 1330 | maintenance |
| tfhe/tfhe TFHE is a C++ library implementing fast fully homomorphic encryption over the torus, based on the CGGI16 scheme with gate-by-gate bootstrap… | 41 | 1328 | maintenance |
| myzxcg/RealBlindingEDR A Windows offensive security tool that uses arbitrary kernel read/write via a signed driver to remove AV/EDR kernel callbacks (ObRegisterCa… | 18 | 1328 | maintenance |
| infobyte/evilgrade Evilgrade is a modular penetration testing framework that exploits poor software update implementations by injecting fake updates via DNS m… | 23 | 1326 | maintenance |
| sorah/envchain envchain is a command-line tool that stores environment variables like API credentials in macOS Keychain or the D-Bus Secret Service (gnome… | 23 | 1326 | maintenance |
| microsoft/agent-governance-toolkit A Microsoft open-source toolkit providing policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for au… | 78 | 6186 | experimental |
| stampery/mongoaudit mongoaudit is a Python CLI tool that audits MongoDB servers for poor security configurations, known vulnerabilities, and misconfigurations.… | 23 | 1324 | maintenance |
| 4ra1n/super-xray Super Xray is a Java-based GUI launcher for the xray web vulnerability scanner, wrapping its command-line interface and config.yaml setup i… | 10 | 1324 | maintenance |
| jbangert/trapcc trapcc is a proof-by-construction that Intel MMU fault handling is Turing complete: an assembler translates 'Move, Branch if Zero, Decremen… | 32 | 1323 | maintenance |
| p0pr0ck5/lua-resty-waf lua-resty-waf is a high-performance web application firewall (WAF) library built on the OpenResty/ngx_lua stack. It inspects HTTP requests … | 32 | 1323 | maintenance |
| dirkjanm/CVE-2020-1472 A proof-of-concept exploit for CVE-2020-1472 (Zerologon), a critical Netlogon privilege escalation vulnerability in Windows domain controll… | 32 | 1323 | maintenance |
| Qianlitp/WatchAD WatchAD is an open-source Active Directory security intrusion detection system that analyzes Windows event logs (and optionally Kerberos ne… | 10 | 1321 | maintenance |
| MetaMask/eth-phishing-detect A TypeScript utility and curated blocklist of malicious domains targeting Web3 and Ethereum users, maintained by MetaMask. It provides CLI … | 68 | 1320 | maintenance |
| nullpo-head/WSL-Hello-sudo A Linux PAM module plus companion Windows CLI app that lets WSL users authenticate sudo and other PAM-based logins via Windows Hello biomet… | 23 | 1320 | maintenance |
| redhuntlabs/RedHunt-OS RedHunt OS is a pre-configured Linux virtual machine (OVA) bundling adversary emulation and threat hunting tools such as Caldera, Atomic Re… | 33 | 1319 | maintenance |
| TermuxHackz/wifi-hacker A shell script that automates attacking wireless connections using built-in Kali Linux tools, supporting WEP, WPS, WPA, and WPA2 securities… | 32 | 1319 | maintenance |
| salesforce/jarm JARM is an active TLS server fingerprinting tool that generates unique fingerprints of TLS server configurations. It is used to group and i… | 75 | 1318 | maintenance |
| laramies/metagoofil Metagoofil is a Python command-line OSINT tool that searches Google for public documents (pdf, doc, xls, ppt) on target websites, downloads… | 32 | 1317 | maintenance |
| 0xrawsec/whids WHIDS is an open-source Endpoint Detection and Response (EDR) tool for Windows, built on the Gene detection engine to match Sysmon/ETW even… | 23 | 1314 | maintenance |
| Netflix/hubcommander HubCommander is a user-extendable Slack bot for chat-ops style GitHub organization management, letting users perform privileged tasks like … | 57 | 1313 | maintenance |
| RUB-SysSec/DroneSecurity A proof-of-concept receiver and decoder for DJI's Drone-ID protocol broadcast over OcuSync 2.0, developed for an NDSS 2023 paper. It decode… | 31 | 1313 | maintenance |
| vanhoefm/fragattacks A security testing tool that tests Wi-Fi clients and access points for the FragAttacks fragmentation and aggregation vulnerabilities affect… | 40 | 1312 | maintenance |
| tmobile/pacbot PacBot is a platform for continuous compliance monitoring, compliance reporting, and security automation for the cloud, where security and … | 23 | 1310 | maintenance |
| honeytrap/honeytrap Honeytrap is an extensible open-source honeypot framework written in Go for running, monitoring, and managing honeypots. It supports low- t… | 32 | 1308 | maintenance |
| stelligent/cfn_nag cfn_nag is a command-line linting tool that scans AWS CloudFormation templates for insecure infrastructure patterns such as overly permissi… | 23 | 1308 | maintenance |
| c4tcom/Katana Katana-ds is a Python CLI tool that automates advanced Google queries known as Google Dorks (Google Dorking), with optional Tor support for… | 10 | 1307 | maintenance |
| vincentcox/bypass-firewalls-by-DNS-history A shell script that attempts to bypass web application firewalls (like Cloudflare, Incapsula, SUCURI) by finding the origin server IP throu… | 32 | 1306 | maintenance |
| mandiant/ThreatPursuit-VM ThreatPursuit-VM is an open-source Windows-based virtual machine distribution from Mandiant preloaded with tools for threat intelligence an… | 10 | 1306 | maintenance |
| k8gege/K8CScan K8CScan is a high-concurrency, plugin-based scanner designed for large internal network penetration testing. It bundles information gatheri… | 32 | 1305 | maintenance |
| TakeScoop/SwiftyRSA SwiftyRSA is a Swift library for RSA public/private key encryption and decryption on Apple platforms. It supports loading keys from PEM, DE… | 23 | 1303 | maintenance |
| Viralmaniar/Passhunt Passhunt is a Python-based command-line tool for searching default credentials across 523 vendors and 2084 default passwords for network de… | 23 | 1303 | maintenance |
| nccgroup/SocksOverRDP A SOCKS4/4a/5 proxy implementation that tunnels traffic over RDP or Citrix (XenApp/XenDesktop) connections using Dynamic Virtual Channels. … | 23 | 1301 | maintenance |
| devanshbatham/FavFreak A Python CLI tool that fetches favicon.ico files from lists of URLs, computes their mmh3 hashes, and groups domains/subdomains/IPs by match… | 23 | 1300 | maintenance |