domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| trimstray/multitor A shell-based CLI tool that spins up multiple TOR instances and load-balances traffic across them through a single endpoint using HAProxy, … | 32 | 1190 | maintenance |
| bats3c/DarkLoadLibrary DarkLoadLibrary is a C library implementing an alternative to the Windows LoadLibrary API designed for offensive security operations. It lo… | 32 | 1190 | maintenance |
| olafhartong/ThreatHunting A Splunk app with dashboards and over 130 pre-built search reports mapped to the MITRE ATT&CK framework to guide threat hunting. It require… | 32 | 1188 | maintenance |
| CellularPrivacy/Android-IMSI-Catcher-Detector AIMSICD is an open-source Android application that detects IMSI-Catchers (fake cell towers, also known as StingRays) which perform man-in-t… | 64 | 5414 | experimental |
| DanMcInerney/icebreaker A PowerShell-based penetration testing tool that automates five internal network attacks against Active Directory to obtain plaintext crede… | 32 | 1185 | maintenance |
| lihaoyi/Metascala Metascala is a tiny metacircular Java Virtual Machine written in about 3000 lines of Scala, including a bytecode interpreter, a stack-machi… | 32 | 1185 | maintenance |
| jaliss/securesocial SecureSocial is an authentication module for Play Framework applications supporting OAuth, OAuth2, OpenID, and username/password login, wit… | 32 | 1184 | maintenance |
| yggdrasil-network/yggdrasil-go Yggdrasil is a lightweight userspace software router implementing an experimental, fully end-to-end encrypted IPv6 overlay network with a s… | 86 | 5391 | experimental |
| Ekultek/BlueKeep A Python proof-of-concept exploit for CVE-2019-0708 (BlueKeep), a pre-authentication remote code execution vulnerability in Microsoft RDP a… | 64 | 1183 | maintenance |
| timwhitez/crawlergo_x_XRAY A Python glue script that combines the crawlergo dynamic crawler with the XRAY passive vulnerability scanner, replaying crawled URLs throug… | 32 | 1182 | maintenance |
| snovvcrash/usbrip usbrip is a Python command-line forensics tool that tracks USB device connection history on GNU/Linux by parsing journalctl and syslog data… | 10 | 1182 | maintenance |
| Spooks4576/Ghost_ESP Ghost ESP is open-source ESP32 firmware (written in C on ESP-IDF) that turns 45+ ESP32 boards into a wireless security testing platform cov… | 10 | 1180 | maintenance |
| umpox/zero-width-detection A demo application and utility library that invisibly encodes usernames into text using zero-width Unicode characters, and decodes them bac… | 50 | 1179 | maintenance |
| lmammino/jwt-cracker jwt-cracker is a Node.js command-line tool that brute-forces the signing secrets of HS256, HS384, and HS512 JWT tokens. It supports custom … | 23 | 1179 | maintenance |
| antonioCoco/RoguePotato RoguePotato is a Windows local privilege escalation tool written in C that elevates from a service account to SYSTEM by abusing the DCOM/NT… | 23 | 1179 | maintenance |
| BuffaloWill/oxml_xxe A Ruby/Sinatra web tool for embedding XXE/XML exploits into document file formats like DOCX, XLSX, ODT, SVG, and XML. It is used to test XX… | 32 | 1178 | maintenance |
| strazzere/android-unpacker A collection of Android unpacking tools presented at Defcon 22, including gdb-based scripts and a native unpacker for packers like APKProte… | 23 | 1178 | maintenance |
| ywdblog/certbot-letencrypt-wildcardcertificates-alydns-au A certbot manual hook tool that automates DNS-01 challenge TXT record creation and cleanup for Let's Encrypt wildcard certificates. It supp… | 32 | 1177 | maintenance |
| master131/ExtremeInjector A Windows GUI tool for injecting DLLs into running processes, supporting multiple injection methods such as manual mapping, thread hijackin… | 23 | 1177 | maintenance |
| p2/OAuth2 A Swift framework implementing the OAuth2 protocol for macOS, iOS, and tvOS apps. It supports all OAuth2 flows including code grant, with k… | 23 | 1177 | maintenance |
| mttaggart/OffensiveNotion OffensiveNotion is a command-and-control (C2) platform that abuses the Notion notetaking app as its communication channel. It ships a cross… | 10 | 1177 | maintenance |
| wwwtyro/cryptico A JavaScript library providing easy-to-use public-key encryption combining RSA and AES, with support for message signing and public key ide… | 10 | 1177 | maintenance |
| dionach/CMSmap CMSmap is a Python open-source CLI scanner that automates detection of security flaws in popular CMSs, integrating common vulnerabilities f… | 32 | 1176 | maintenance |
| Lucifer1993/SatanSword SatanSword is a Python-based red team penetration testing framework that integrates web fingerprinting, PoC-based vulnerability detection, … | 32 | 1172 | maintenance |
| FDX100/Auto_Tor_IP_changer A Python CLI tool that automatically rotates your IP address at configurable intervals by leveraging the Tor network's SOCKS proxy (127.0.0… | 32 | 1172 | maintenance |
| CCob/SharpBlock SharpBlock is a C# command-line tool that blocks EDR (Endpoint Detection and Response) protection DLLs from executing their entry points in… | 32 | 1171 | maintenance |
| yangyangwithgnu/bypass_disablefunc_via_LD_PRELOAD A small PHP exploit script plus compiled shared object that bypasses PHP's disable_functions restriction to execute OS commands via LD_PREL… | 32 | 1171 | maintenance |
| DarkCoderSc/win-brute-logon A Windows command-line proof-of-concept tool that brute-forces local user account passwords without requiring any privileges, exploiting th… | 32 | 1171 | maintenance |
| n0b0dyCN/redis-rogue-server A Python-driven exploit tool that achieves remote code execution on unpatched Redis servers (<=5.0.5) by loading a malicious Redis module f… | 32 | 1171 | maintenance |
| 4w4k3/BeeLogger BeeLogger is a Python-based penetration testing tool that generates Windows keylogger executables which exfiltrate captured keystrokes via … | 32 | 1169 | maintenance |
| SpiderLabs/HostHunter HostHunter is a Python CLI recon tool that maps IPv4/IPv6 targets to virtual hostnames using OSINT and active reconnaissance techniques suc… | 23 | 1169 | maintenance |
| ghidraninja/ghidra_scripts A collection of scripts for the Ghidra software reverse engineering suite, adding features like crypto constant detection via YARA, binwalk… | 32 | 1168 | maintenance |
| JunioJsv/mtk-easy-su An Android application that grants bootless superuser (root) access on MediaTek devices by leveraging the mtk-su exploit together with Magi… | 29 | 1168 | maintenance |
| sh4hin/Androl4b AndroL4b is an Ubuntu MATE-based virtual machine preloaded with Android security, reverse engineering, and malware analysis tools such as R… | 32 | 1167 | maintenance |
| tongcheng-security-team/NextScan NextScan (飞刃) is an enterprise-grade distributed black-box vulnerability scanning platform built in Go, composed of Server, Agent, and Web … | 21 | 1167 | maintenance |
| siyujie/OkHttpLogger-Frida A Frida script that hooks OkHttp's RealCall class in Android apps to intercept and log HTTP requests and responses, including headers and b… | 32 | 1165 | maintenance |
| 18601949127/DiDiCallCar An Android ride-hailing demo app modeled on Didi, built end-to-end by one developer including the Apache+PHP+MySQL backend. It adds RFID/NF… | 32 | 1165 | maintenance |
| aircrack-ng/rtl8188eus An out-of-tree Linux/Android kernel driver for Realtek RTL8188eus/eu/etv WiFi chipsets, maintained under the Aircrack-ng organization. It a… | 34 | 1162 | maintenance |
| chenjj/CORScanner CORScanner is a fast Python tool for detecting CORS misconfiguration vulnerabilities in websites, using gevent for high-concurrency network… | 23 | 1161 | maintenance |
| kbandla/dpkt dpkt is a Python library for fast, simple network packet creation and parsing, with definitions for basic TCP/IP protocols. It is commonly … | 23 | 1161 | maintenance |
| ivanilves/xiringuito Xiringuito is a shell-script-based SSH tunneling tool that provides VPN-like access to remote networks without running a VPN server. It use… | 23 | 1160 | maintenance |
| Ch0pin/AVIator AV|Ator is a GUI backdoor generator that encrypts shellcode with AES and produces Windows executables that decrypt and inject the payload u… | 10 | 1160 | maintenance |
| SkrewEverything/Swift-Keylogger A keylogger for macOS written in Swift using the low-level HID API to capture keystrokes. It logs keystrokes grouped by application, along … | 23 | 1159 | maintenance |
| techjacker/repo-security-scanner A Go CLI tool that scans a git repository's history for accidentally committed secrets such as passwords and private keys. It processes the… | 23 | 1159 | maintenance |
| loseys/BlackMamba BlackMamba is a Python/Qt-based Command and Control (C2) framework for post-exploitation that manages multiple client connections simultane… | 10 | 1159 | maintenance |
| Lucifer1993/TPscan TPscan is a one-click vulnerability detection tool for ThinkPHP applications, written in Python 3. It scans ThinkPHP-based web services for… | 32 | 1158 | maintenance |
| ideawu/Objective-C-RSA A small Objective-C library for performing RSA encryption and decryption on iOS, using PEM-formatted public and private keys. It provides s… | 32 | 1157 | maintenance |
| d3ckx1/Fvuln Fvuln (Find-Vulnerability) is an automated security scanning tool for penetration testers and red teams. It combines live IP detection, por… | 23 | 1157 | maintenance |
| crypto2011/IDR IDR (Interactive Delphi Reconstructor) is a Windows decompiler for EXE and DLL files compiled with Delphi 2 through Delphi XE4. It performs… | 23 | 1155 | maintenance |
| MiSecurity/x-patrol A GitHub leak scanning system written in Go that monitors GitHub for leaked secrets and sensitive code. It provides a web management consol… | 23 | 1152 | maintenance |
| deepzec/Bad-Pdf Bad-PDF is a Python tool that generates malicious PDF files exploiting CVE-2018-4993 to steal NTLMv1/NTLMv2 hashes from Windows machines vi… | 44 | 1151 | maintenance |
| Telefonica/Eternalblue-Doublepulsar-Metasploit A Metasploit module that exploits the EternalBlue/DoublePulsar SMB vulnerability in Windows systems. It integrates the leaked NSA exploit i… | 32 | 1150 | maintenance |
| s045pd/DarkNet_ChineseTrading A Python-based real-time crawler that monitors Chinese-language darknet marketplaces over Tor, with automatic account registration, login, … | 10 | 1150 | maintenance |
| mdmsoft/yii2-admin A GUI-based RBAC (Role-Based Access Control) manager extension for the Yii2 PHP framework. It provides an administrative interface for mana… | 23 | 1149 | maintenance |
| threatexpress/red-team-scripts A collection of red team focused tools, PowerShell scripts, and notes for offensive security engagements, including host and domain enumera… | 32 | 1146 | maintenance |
| uber-common/metta Metta is an information security preparedness tool that runs adversarial simulations to test host-based and network detection instrumentati… | 32 | 1146 | maintenance |
| FuzzySecurity/Sharp-Suite Sharp-Suite is a collection of C# security tooling samples for Windows threat emulation, including techniques like process command-line spo… | 32 | 1146 | maintenance |
| romanbican/roles A Laravel 5 package for managing user roles and permissions, including role levels, permission inheritance, Blade template extensions, and … | 10 | 1146 | maintenance |
| pinauten/Fugu15 Fugu15 is a semi-untethered, permasigned jailbreak for iOS 15 that combines a code-signing bypass, kernel exploit, kernel PAC bypass, and P… | 10 | 1146 | maintenance |
| morrownr/8821au-20210708 An out-of-kernel Linux driver (kernel module) for USB WiFi adapters based on the Realtek RTL8811AU and RTL8821AU chipsets, based on Realtek… | 77 | 1144 | maintenance |
| anshumanbh/git-all-secrets git-all-secrets is a Go CLI tool that clones GitHub/GitHub Enterprise repositories, gists, and organization or team repos, then scans them … | 32 | 1144 | maintenance |
| ChrisTheCoolHut/Zeratool Zeratool is an Automatic Exploit Generation (AEG) tool that uses angr to concolically analyze binaries for buffer overflow and format strin… | 23 | 1144 | maintenance |
| leechristensen/SpoolSample SpoolSample is a C# proof-of-concept tool that coerces Windows hosts to authenticate to arbitrary machines via the MS-RPRN Print System Rem… | 32 | 1143 | maintenance |
| Bhaviktutorials/shark Shark is a shell-based phishing toolkit that automates hosting fake login pages with port forwarding via ngrok and Cloudflare tunnels. It i… | 23 | 1142 | maintenance |
| christophetd/log4shell-vulnerable-app A deliberately vulnerable Spring Boot web application demonstrating the Log4Shell vulnerability (CVE-2021-44228) using Log4j 2.14.1. It shi… | 32 | 1141 | maintenance |
| cw1997/NATBypass NATBypass is a Go implementation of the lcx/htran port-forwarding tool that establishes TCP reverse tunnels for NAT traversal. It supports … | 63 | 1140 | maintenance |
| chvancooten/follina.py A proof-of-concept Python script that replicates the 'Follina' MS-MSDT Microsoft Office remote code execution vulnerability for local testi… | 32 | 1139 | maintenance |
| Sentinel-One/CobaltStrikeParser A Python parser that extracts Cobalt Strike Beacon configuration from stageless PE files, memory dumps, or C2 URLs. It heuristically finds … | 10 | 1138 | maintenance |
| nccgroup/featherduster FeatherDuster is an automated, modular cryptanalysis tool from NCC Group that identifies and exploits weak cryptosystems from supplied ciph… | 23 | 1137 | maintenance |
| anthropic-experimental/sandbox-runtime A lightweight CLI tool and library that enforces filesystem and network restrictions on arbitrary processes at the OS level without contain… | 84 | 5132 | experimental |
| anestisb/vdexExtractor A command-line tool written in C that decompiles and extracts Android Dex bytecode from Vdex files produced by the ART runtime's dex2oat co… | 32 | 1136 | maintenance |
| med0x2e/GadgetToJScript GadgetToJScript is a C# tool that generates .NET BinaryFormatter serialized gadget payloads embedded in JS/VBS/VBA/HTA scripts, triggering … | 23 | 1136 | maintenance |
| JPaulMora/Pyrit Pyrit is a WPA/WPA2-PSK precomputed cracker that builds massive databases of pre-computed Pairwise Master Keys using multi-core CPUs and GP… | 67 | 1134 | maintenance |
| stephenbradshaw/vulnserver Vulnserver is a deliberately vulnerable multithreaded Windows TCP server containing multiple subtly different buffer overflow bugs. It is d… | 32 | 1132 | maintenance |
| kelp404/CocoaSecurity An Objective-C library for iOS and macOS providing AES encryption/decryption, MD5 and SHA-family hashing (including HMAC variants), and Bas… | 23 | 1132 | maintenance |
| shr3ddersec/Shr3dKit Shr3dKit is a shell script that installs a large curated collection of red team and offensive security tools onto a Kali Linux system (hard… | 32 | 1131 | maintenance |
| gianlucaborello/libprocesshider A small shared library that hides a specified process from tools like ps and lsof on Linux by hooking libc functions via the ld.so preloade… | 32 | 1131 | maintenance |
| mgeeky/ShellcodeFluctuation A C++ proof-of-concept implementing an in-memory evasion technique that encrypts shellcode and fluctuates its memory protection between RW/… | 23 | 1131 | maintenance |
| Kuingsmile/clash-core A backup fork of Clash, a rule-based network tunnel written in Go that proxies traffic through protocols like Shadowsocks, VMess, Trojan, a… | 18 | 1131 | maintenance |
| samyk/keysweeper KeySweeper is an open-source, open-hardware Arduino-based device disguised as a USB wall charger that passively sniffs, decrypts, and logs … | 32 | 1128 | maintenance |
| r35tart/RW_Password A Python script that filters leaked password dictionaries with regex to extract passwords matching common corporate strength policies (leng… | 32 | 1127 | maintenance |
| hausec/ADAPE-Script A PowerShell script that automates Active Directory assessment and privilege escalation checks by bundling multiple well-known pentest modu… | 32 | 1125 | maintenance |
| decalage2/ViperMonkey ViperMonkey is a VBA parser and emulation engine written in Python for analyzing and deobfuscating malicious macros in Microsoft Office doc… | 32 | 1124 | maintenance |
| GreatSCT/GreatSCT GreatSCT is a Python-based framework that generates metasploit payloads designed to bypass antivirus and application whitelisting solutions… | 10 | 1123 | maintenance |
| mdsecactivebreach/o365-attack-toolkit A Go-based red team toolkit for performing OAuth phishing attacks against Office365 accounts. It uses stolen tokens with the Microsoft Grap… | 32 | 1121 | maintenance |
| seashell/drago Drago is a flexible configuration manager for WireGuard that provides a unified control plane for building secure network overlays across h… | 23 | 1121 | maintenance |
| Dr-TSNG/ApplistDetector A Kotlin library for Android that detects the presence of suspicious apps such as Magisk on a device. It helps apps check whether the envir… | 23 | 1121 | maintenance |
| kevthehermit/RATDecoders A Python library and CLI tool (malconf) that statically analyzes malware samples from common Remote Access Trojan (RAT) families and extrac… | 32 | 1120 | maintenance |
| 1n7erface/Template Template is a heuristic intranet scanning CLI tool built for red team operations, combining host discovery, port scanning, web fingerprinti… | 23 | 1120 | maintenance |
| google/ssl_logger A Python command-line tool that decrypts and logs a running process's SSL/TLS traffic, mimicking Echo Mirage's SSL logging on Linux and mac… | 10 | 1118 | maintenance |
| JoelGMSec/AutoRDPwn AutoRDPwn is a PowerShell post-exploitation framework that automates the RDP Shadow attack on Windows, letting an attacker view or control … | 32 | 1117 | maintenance |
| AdamLaurie/RFIDIOt A Python library and collection of command-line tools for reading, writing, and interacting with RFID and NFC tags and readers, including M… | 32 | 1117 | maintenance |
| hash3liZer/WiFiBroot WiFiBroot is a Python 2 command-line tool for wireless (WPA/WPA2) penetration testing that captures and cracks 4-way handshakes and PMKID k… | 23 | 1117 | maintenance |
| swanandx/lemmeknow lemmeknow is a fast Rust CLI tool and library that identifies mysterious text, strings, and files using regex-based pattern matching (e.g.,… | 23 | 1117 | maintenance |
| RafaelVidaurre/angular-permission angular-permission is an AngularJS library providing role and permission based access control for routes. It lets developers declaratively … | 23 | 1116 | maintenance |
| ihciah/clean-dns-bpf A Rust + eBPF/XDP tool that drops GFW DNS poisoning packets at the kernel level, allowing clean DNS resolution from 8.8.8.8 without a proxy… | 23 | 1115 | maintenance |
| francoismichel/ssh3 SSH3 is a research-driven reimplementation of the SSH protocol that runs remote terminal sessions over QUIC, TLS 1.3, and HTTP/3. It offers… | 18 | 5012 | experimental |
| wireghoul/dotdotpwn DotDotPwn is a flexible directory traversal fuzzer written in Perl that discovers path traversal vulnerabilities in HTTP, FTP, and TFTP ser… | 23 | 1114 | maintenance |
| nfc-tools/mfcuk MFCUK is a C-based command-line toolkit for recovering cryptographic keys from MIFARE Classic RFID cards using the Darkside attack, built o… | 32 | 1113 | maintenance |
| awake1t/PortBrute A compact cross-platform brute-force tool written in Go that attempts password attacks against FTP, SSH, SMB, MSSQL, MySQL, PostgreSQL, and… | 32 | 1112 | maintenance |