domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| securego/gosec gosec is a security scanner for Go source code that inspects the AST and SSA representations to detect common security problems. It include… | 99 | 8933 | active |
| henrypp/simplewall Simplewall is a lightweight, open-source Windows application for configuring network activity via the Windows Filtering Platform (WFP). It … | 75 | 8885 | active |
| maxgoedjen/secretive Secretive is a native macOS app that stores and manages SSH keys inside the Mac's Secure Enclave, making them non-exportable. It adds Touch… | 85 | 8819 | active |
| yogeshojha/rengine reNgine is a self-hosted automated web reconnaissance and vulnerability scanning framework with configurable recon engines, data correlatio… | 64 | 8795 | active |
| smallstep/certificates step-ca is an online private certificate authority (X.509 and SSH) and ACME server for secure, automated certificate management in DevOps e… | 91 | 8779 | active |
| ViRb3/wgcf wgcf is an unofficial cross-platform command-line tool for Cloudflare Warp written in Go. It registers Warp accounts, binds Warp+ license k… | 93 | 8641 | active |
| Kata Containers Kata Containers is an open source container runtime that builds lightweight virtual machines which plug seamlessly into the container ecosy… | 99 | 8606 | stable |
| Tsunami Security Scanner Tsunami is a general-purpose network security scanner from Google that detects high-severity vulnerabilities with high confidence. It relie… | 74 | 8606 | active |
| stamparm/maltrail Maltrail is a malicious network traffic detection system that matches observed domains, URLs, IP addresses, and User-Agent values against o… | 98 | 8587 | active |
| PrivateBin/PrivateBin PrivateBin is a minimalist, self-hosted pastebin where the server stores only encrypted data and never learns the paste contents. Encryptio… | 98 | 8572 | active |
| spesmilo/electrum Electrum is a lightweight Bitcoin wallet client written in Python that uses SPV verification instead of downloading the full blockchain. It… | 77 | 8572 | stable |
| wangyu-/udp2raw A C++ command-line tunnel that converts UDP traffic into encrypted FakeTCP, UDP, or ICMP traffic using raw sockets, helping bypass UDP fire… | 44 | 8550 | active |
| skeeto/endlessh Endlessh is an SSH tarpit daemon written in C that slowly sends an endless, random SSH pre-authentication banner to keep malicious clients … | 23 | 8542 | stable |
| varvet/pundit Pundit is a Ruby gem that provides minimal authorization for Rails applications using plain Ruby policy classes and object-oriented design.… | 75 | 8522 | stable |
| HavocFramework/Havoc Havoc is a modern, malleable post-exploitation command and control (C2) framework with a Go teamserver, a Qt-based cross-platform client, a… | 10 | 8507 | active |
| containers/bubblewrap Bubblewrap is a low-level unprivileged sandboxing tool for Linux that uses user namespaces to let any user run processes in isolated contai… | 91 | 8490 | active |
| hugsy/gef GEF (GDB Enhanced Features) is a single-file Python plugin for GDB that adds a modern, feature-rich debugging experience for exploit develo… | 77 | 8326 | active |
| Sysdig Sysdig is a Linux system exploration and troubleshooting tool that captures system calls and OS events at the kernel level, with native sup… | 78 | 8289 | active |
| ionuttbara/windows-defender-remover A script-based tool that removes or disables Windows Defender and related security components (Windows Security app, SmartScreen, VBS, tamp… | 91 | 8274 | active |
| kishikawakatsumi/KeychainAccess KeychainAccess is a simple Swift wrapper around Apple's Keychain APIs for iOS, macOS, watchOS, tvOS, and Mac Catalyst. It provides an ergon… | 23 | 8256 | stable |
| firerpa/lamda FIRERPA (lamda) is an all-in-one Android device control platform whose server runs directly on the device (root or non-root) and exposes 16… | 98 | 8243 | active |
| PyCQA/bandit Bandit is a security-oriented static analysis tool that finds common security issues in Python code. It parses each file into an AST, runs … | 86 | 8242 | active |
| lightningnetwork/lnd A complete implementation of a Lightning Network node written in Go, capable of opening and closing payment channels, routing onion-encrypt… | 94 | 8186 | stable |
| tinyauthapp/tinyauth Tinyauth is a lightweight, OpenID Certified™ authentication and authorization server written in Go, shipped as a single static binary. It w… | 86 | 8174 | active |
| aquasecurity/kube-bench kube-bench is a Go-based tool that checks whether Kubernetes clusters are deployed securely by running the checks documented in the CIS Kub… | 98 | 8155 | active |
| Graylog2/graylog2-server Graylog is a free and open log management platform for collecting, storing, searching, and analyzing log data from across IT environments, … | 77 | 8115 | stable |
| ntop/ntopng ntopng is a web-based network traffic monitoring and cybersecurity application that provides real-time visibility into hosts, applications,… | 73 | 8114 | stable |
| omniauth/omniauth OmniAuth is a Ruby library that standardizes multi-provider authentication for web applications via Rack middleware. Developers add authent… | 69 | 8100 | stable |
| kyverno/kyverno Kyverno is a Kubernetes-native policy engine for policy as code, letting platform teams author validate, mutate, generate, and cleanup poli… | 99 | 8075 | stable |
| greatscottgadgets/hackrf HackRF is an open source, low-cost software-defined radio (SDR) hardware platform from Great Scott Gadgets, with this repository containing… | 88 | 8057 | stable |
| epi052/feroxbuster feroxbuster is a fast, recursive content discovery tool written in Rust that performs forced browsing against web servers. It brute-forces … | 72 | 8035 | active |
| six2dez/reconftw reconFTW is an open-source (MIT) automated reconnaissance framework written in Shell that orchestrates 80+ security tools to perform full r… | 86 | 8025 | active |
| robinmoisson/staticrypt StatiCrypt is a CLI tool and browser-based utility that encrypts static HTML files with AES-256 using a password, producing a self-containe… | 64 | 8019 | active |
| simplifaisoul/osiris OSIRIS is an open-source, real-time global intelligence (OSINT) dashboard that aggregates live flight tracking, maritime, CCTV, seismic, fi… | 58 | 7992 | active |
| yarrick/iodine iodine is a C client/server tool that tunnels IPv4 traffic through DNS queries, letting you get network access on firewalled connections wh… | 50 | 7956 | active |
| v1s1t0r1sh3r3/airgeddon A multi-use bash script for auditing wireless networks on Linux, wrapping tools like aircrack-ng to automate attacks such as evil twin, WPS… | 93 | 7952 | active |
| superradcompany/microsandbox Microsandbox is a local-first microVM runtime and library for running untrusted workloads (AI agents, user code, plugins, CI jobs) inside f… | 89 | 7943 | active |
| turbot/steampipe Steampipe is a zero-ETL CLI tool that exposes APIs and cloud services as relational database tables so they can be queried live with standa… | 98 | 7934 | active |
| cilium/ebpf ebpf-go is a pure-Go library for loading, modifying, and attaching eBPF programs to hooks in the Linux kernel, with no dependency on libbpf… | 92 | 7933 | stable |
| zeek/zeek Zeek (formerly Bro) is an open-source network security monitor and analysis framework that passively inspects network traffic and produces … | 99 | 7908 | stable |
| PCILeech PCILeech is DMA attack software that uses PCIe hardware devices (or software memory acquisition methods) to read and write target system me… | 65 | 7899 | active |
| tutao/tutanota Tuta Mail (formerly Tutanota) is an open-source, end-to-end encrypted email service with integrated encrypted calendar and contacts, availa… | 95 | 7874 | active |
| APatch APatch is a kernel-based root solution for Android devices that patches the Android kernel and system, relying on KernelPatch. It supports … | 86 | 7862 | active |
| p1ngul1n0/blackbird Blackbird is a Python CLI OSINT tool that searches for user accounts by username or email across 600+ social networks and platforms, levera… | 46 | 7861 | active |
| vercel-labs/deepsec Deepsec is an open-source, agent-powered vulnerability scanner that runs AI coding agents over your entire existing codebase to find hard-t… | 58 | 7828 | active |
| EmenstaNougat/ESP32-BlueJammer ESP32-BlueJammer is firmware for an ESP32 paired with nRF24 modules that disrupts 2.4GHz communications (Bluetooth, BLE, WiFi, RC) by flood… | 50 | 7822 | active |
| Scout Suite Scout Suite is an open source multi-cloud security auditing tool that assesses the security posture of cloud environments. It gathers confi… | 42 | 7801 | stable |
| kelektiv/node.bcrypt.js A Node.js library providing bcrypt password hashing implemented as a native C++ addon. It handles salting and hashing passwords for secure … | 57 | 7800 | stable |
| peazip/PeaZip PeaZip is a free, open-source, cross-platform file archiver and archive manager supporting 200+ formats including 7z, RAR, ZIP, TAR, and Zs… | 93 | 7793 | stable |
| mandiant/commando-vm Commando VM is a fully customizable Windows-based security distribution for penetration testing and red teaming, packaged as a PowerShell i… | 53 | 7791 | active |
| panva/jose A zero-dependency JavaScript/TypeScript library implementing JSON Object Signing and Encryption standards (JWA, JWS, JWE, JWT, JWK, JWKS). … | 99 | 7767 | stable |
| hfiref0x/UACME UACMe is a C-based command-line tool that demonstrates dozens of Windows User Account Control (UAC) bypass techniques abusing built-in Auto… | 87 | 7764 | active |
| reconurge/flowsint Flowsint is an open-source, self-hosted OSINT platform for visual, graph-based investigations, providing entity relationship visualization … | 87 | 7752 | active |
| r0ysue/r0capture A Frida-based universal Android application-layer packet capture script that hooks SSL/TLS regardless of certificate pinning, obfuscation, … | 64 | 7750 | active |
| boltgolt/howdy Howdy provides Windows Hello-style facial authentication for Linux using IR emitters and a camera with facial recognition. It integrates wi… | 38 | 7738 | active |
| warp-tech/warpgate Warpgate is an open-source, clientless bastion host and privileged access management (PAM) tool written in Rust that transparently proxies … | 99 | 7726 | active |
| pyca/cryptography pyca/cryptography is a Python package providing cryptographic recipes and primitives, aiming to be Python's 'cryptographic standard library… | 77 | 7725 | stable |
| yaklang/yakit Yakit is an all-in-one interactive application security testing platform built as a GUI client for the Yaklang security DSL engine over gRP… | 95 | 7700 | active |
| dependency-check/DependencyCheck OWASP Dependency-Check is a Software Composition Analysis (SCA) tool that identifies publicly disclosed vulnerabilities (CVEs) in a project… | 98 | 7671 | active |
| netblue30/firejail Firejail is a SUID security sandbox program for Linux that uses kernel namespaces, seccomp-bpf filters, and Linux capabilities to run appli… | 82 | 7611 | active |
| tiagozip/cap Cap is a lightweight, open-source, self-hosted CAPTCHA alternative to reCAPTCHA, hCaptcha, and Cloudflare Turnstile. It uses invisible proo… | 81 | 7610 | active |
| rustls/rustls Rustls is a modern TLS library written in Rust implementing TLS 1.2 and TLS 1.3 for both clients and servers. It provides secure defaults w… | 98 | 7585 | stable |
| aceberg/WatchYourLAN WatchYourLAN is a lightweight network IP scanner written in Go with a web GUI, designed to discover and track hosts on a local network via … | 51 | 7549 | active |
| aircrack-ng/aircrack-ng Aircrack-ng is a complete suite of command-line tools for assessing WiFi network security, covering packet capture, injection, monitor mode… | 62 | 7541 | active |
| mullvad/mullvadvpn-app The official Mullvad VPN client app for desktop and mobile, including a Rust system service/daemon, an Electron-based GUI, a CLI, and dedic… | 99 | 7507 | active |
| lcobucci/jwt A PHP library for creating, parsing, and validating JSON Web Tokens (JWT) and JSON Web Signatures (JWS) per RFC 7519. It is installed via C… | 83 | 7483 | stable |
| arkime/arkime Arkime is an open-source, large-scale network analysis, full packet capture, and session indexing system that stores traffic in standard PC… | 99 | 7459 | active |
| timvisee/ffsend ffsend is a fully featured command-line client for the Firefox Send file-sharing service, letting users upload and download files and direc… | 47 | 7394 | active |
| jonasstrehle/supercookie A demonstration web application that assigns persistent unique identifiers to website visitors via favicon-based browser fingerprinting. It… | 10 | 7387 | active |
| go-gost/gost GOST (GO Simple Tunnel) is a Go-based multi-protocol tunnel and proxy tool supporting HTTP, HTTPS, SOCKS5, Shadowsocks, WebSocket, QUIC, KC… | 84 | 7355 | active |
| Col-E/Recaf Recaf is a modern Java bytecode editor with a JavaFX GUI that abstracts away low-level class file complexities like constant pools and stac… | 69 | 7355 | active |
| anomalyco/openauth OpenAuth is a universal, standards-based OAuth 2.0 auth provider that can be deployed as a standalone service or embedded into existing app… | 38 | 7355 | active |
| projectcalico/calico Calico is an open-source cloud-native networking and network security platform for Kubernetes, providing pod networking (CNI), network poli… | 99 | 7336 | stable |
| 648540858/wvp-GB28181-pro An open-source network video platform implementing China's GB28181-2016 and JT808/JT1078 standards, providing SIP signaling, device managem… | 76 | 7267 | active |
| presidentbeef/brakeman Brakeman is a free, open-source static analysis security scanner built specifically for Ruby on Rails applications. It analyzes Rails sourc… | 93 | 7262 | stable |
| SQLCipher SQLCipher is an open-source fork of SQLite that adds full-database 256-bit AES encryption, tamper detection, and strong key derivation. It … | 94 | 7254 | stable |
| apache/caldera Apache Caldera is a cybersecurity platform for automated adversary emulation built on the MITRE ATT&CK framework. It provides an asynchrono… | 79 | 7213 | active |
| cloudflare/boringtun BoringTun is a Rust implementation of the WireGuard VPN protocol, provided both as a reusable library and as a userspace CLI executable (bo… | 63 | 7185 | active |
| Kunzisoft/KeePassDX KeePassDX is a lightweight, open-source password manager and encrypted vault for Android, compatible with the KeePass format (.kdb/.kdbx). … | 96 | 7182 | active |
| openbao/openbao OpenBao is an open-source, identity-based secrets management system for storing, distributing, and rotating sensitive data such as secrets,… | 93 | 7177 | active |
| Cisco-Talos/clamav ClamAV is an open-source antivirus engine and toolkit for detecting trojans, viruses, malware, and other malicious threats. It includes a m… | 98 | 7176 | active |
| hwdsl2/docker-ipsec-vpn-server A Docker image that runs a self-hosted IPsec VPN server supporting IPsec/L2TP, Cisco IPsec, and IKEv2, built on Libreswan and xl2tpd. It au… | 77 | 7123 | active |
| Ylianst/MeshCentral MeshCentral is a self-hosted, web-based remote monitoring and management (RMM) platform built on Node.js. It lets administrators install ag… | 98 | 7110 | active |
| ayoubfaouzi/al-khaser Al-Khaser is a proof-of-concept Windows application that demonstrates a wide range of malware anti-analysis techniques, including anti-debu… | 73 | 7108 | active |
| gopasspw/gopass gopass is a command-line password manager for teams, serving as a drop-in replacement for the standard UNIX pass tool. It encrypts secrets … | 82 | 7107 | stable |
| RsaCtfTool/RsaCtfTool A Python CLI tool that attacks weak RSA public keys to recover private keys and decrypt ciphertext, combining many factorization and lattic… | 76 | 7097 | active |
| guardicore/monkey Infection Monkey is an open-source adversary emulation platform that simulates malware-like self-propagation across a network to test secur… | 31 | 7076 | active |
| onionshare/onionshare OnionShare is an open-source desktop and mobile application that lets users securely and anonymously share files, host websites, and chat o… | 86 | 7068 | active |
| sandstorm-io/sandstorm Sandstorm is a self-hostable web productivity suite implemented as a security-hardened web app package manager. It lets users install and r… | 71 | 7068 | active |
| stalniy/casl CASL is an isomorphic JavaScript authorization library that restricts what resources a user is allowed to access, using declarative rules t… | 98 | 7055 | stable |
| markqvist/Reticulum Reticulum is a cryptography-based networking stack written in Python that builds encrypted, resilient local and wide-area networks over LoR… | 99 | 7046 | active |
| NVIDIA-NeMo/Guardrails NVIDIA NeMo Guardrails is an open-source Python toolkit for adding programmable guardrails to LLM-based conversational applications. It sit… | 93 | 7017 | active |
| ntop/n2n n2n is a lightweight peer-to-peer VPN written in C that creates encrypted virtual networks capable of bypassing intermediate firewalls. It … | 66 | 7005 | active |
| LasCC/HackTools HackTools is an all-in-one browser extension for offensive security professionals that bundles penetration testing tools like XSS payloads,… | 23 | 7002 | active |
| erebe/wstunnel wstunnel is a Rust CLI tool that tunnels arbitrary TCP, UDP, Unix socket, or stdio traffic over WebSocket, HTTP2, or WebTransport to bypass… | 97 | 6996 | active |
| authzed/spicedb SpiceDB is an open-source, Google Zanzibar-inspired database for storing, computing, and validating fine-grained authorization data at scal… | 99 | 6990 | stable |
| albertan017/LLM4Decompile LLM4Decompile is an open-source series of large language models (1.3B to 33B) trained to decompile binary code back into readable, executab… | 55 | 6986 | active |
| netalertx/NetAlertX NetAlertX is a self-hosted network visibility and asset intelligence platform that performs continuous device discovery and monitoring acro… | 98 | 6954 | active |
| Mbed-TLS/mbedtls Mbed TLS is a portable C library implementing TLS, DTLS, and X.509 certificate handling, plus a reference implementation of the PSA Cryptog… | 92 | 6918 | stable |
| lintsinghua/DeepAudit DeepAudit is an open-source multi-agent AI system for automated code vulnerability discovery and security auditing, with a React frontend a… | 72 | 6905 | active |