domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| prateek147/DVIA-v2 Damn Vulnerable iOS App (DVIA-v2) is a deliberately vulnerable iOS application written in Swift for practicing iOS penetration testing. It … | 23 | 1112 | maintenance |
| liggitt/audit2rbac audit2rbac is a Go CLI tool that takes a Kubernetes audit log and a username as input and generates RBAC Role and RoleBinding objects cover… | 23 | 1111 | maintenance |
| calebstewart/CVE-2021-1675 A pure PowerShell proof-of-concept exploit for CVE-2021-1675 (PrintNightmare), a Windows Print Spooler local privilege escalation vulnerabi… | 32 | 1109 | maintenance |
| tevora-threat/SharpView SharpView is a C#/.NET port of the PowerView PowerShell script for Active Directory domain enumeration and reconnaissance. It exposes Power… | 32 | 1109 | maintenance |
| mohuihui/antispy AntiSpy is a free Windows anti-rootkit and antivirus toolkit that detects, analyzes, and restores kernel modifications and hooks with the h… | 23 | 1109 | maintenance |
| chishaxie/BlindWaterMark A Python command-line tool that embeds invisible blind watermarks into images and extracts them later using frequency-domain techniques. De… | 41 | 1108 | maintenance |
| curi0usJack/luckystrike LuckyStrike is a PowerShell-based utility for generating malicious Microsoft Office macro documents, intended for penetration testing and e… | 10 | 1108 | maintenance |
| KathanP19/JSFScan.sh JSFScan.sh is a shell script that automates JavaScript reconnaissance for bug bounty hunting. Given a list of subdomains, it gathers JS fil… | 32 | 1107 | maintenance |
| DasSecurity-HatLab/AoiAWD AoiAWD is a lightweight, portable EDR (Endpoint Detection and Response) system designed for CTF Attack-Defense (AWD) competitions. It captu… | 32 | 1106 | maintenance |
| dark-lbp/isf ISF (Industrial Exploitation Framework) is a Python-based exploitation framework modeled after Metasploit, focused on industrial control sy… | 10 | 1105 | maintenance |
| Arrexel/phpbash phpbash is a standalone, semi-interactive web shell written in PHP and packaged as a single file. It is designed to assist penetration test… | 32 | 1102 | maintenance |
| utkusen/wholeaked wholeaked is a file-sharing tool written in Go that embeds a unique hidden signature for each recipient into a shared file. If the file lea… | 23 | 1101 | maintenance |
| jborg/attic Attic is a deduplicating backup program written in Python that stores only changed data chunks, with optional AES-256 encryption and SSH-ba… | 32 | 1099 | maintenance |
| endgameinc/RTA Red Team Automation (RTA) is a Python framework of scripts that emulate malicious tradecraft modeled after the MITRE ATT&CK matrix, letting… | 32 | 1097 | maintenance |
| G4lile0/ESP32-WiFi-Hash-Monster A firmware for M5Stack/ESP32 devices that captures WPA2 EAPOL handshake and PMKID packets over WiFi and stores them on an SD card for later… | 32 | 1095 | maintenance |
| M4sc3r4n0/Evil-Droid Evil-Droid is a shell-based framework that creates, generates, and embeds APK payloads for penetrating Android platforms, built on top of t… | 23 | 1095 | maintenance |
| sibears/IDAGolangHelper A set of IDA Pro Python scripts that parse Go type information embedded in compiled Go binaries and register the recovered types inside IDA… | 32 | 1093 | maintenance |
| aguinet/wannakey A C++ tool that recovers the RSA private key prime numbers generated by the WannaCry ransomware from the wcry.exe process memory. It exploi… | 32 | 1091 | maintenance |
| JackOfMostTrades/gadgetinspector A Java bytecode analyzer that automatically discovers deserialization gadget chains in Java libraries and application classpaths. It produc… | 32 | 1090 | maintenance |
| genuinetools/amicontained amicontained is a container introspection CLI tool that detects which container runtime (docker, lxc, rkt, systemd-nspawn, etc.) it is runn… | 23 | 1089 | maintenance |
| veracode-research/rogue-jndi Rogue JNDI is a malicious LDAP and HTTP server written in Java for exploiting insecure JNDI API usage in Java applications. It serves vario… | 32 | 1085 | maintenance |
| google/mundane Mundane is a Rust cryptography library backed by BoringSSL, designed to be difficult to misuse, ergonomic, and performant. It vendors its o… | 32 | 1085 | maintenance |
| Accenture/Spartacus Spartacus is a Windows toolkit that automates discovery and exploitation of DLL and COM hijacking vulnerabilities by parsing Process Monito… | 10 | 1085 | maintenance |
| dmpayton/django-admin-honeypot A Django app that serves a fake admin login screen at the standard /admin/ URL to trap unauthorized access attempts. It logs and notifies s… | 32 | 1084 | maintenance |
| mmozeiko/aes-finder A small C++ command-line utility that scans the memory of running processes to locate AES encryption and decryption keys (128, 192, and 256… | 32 | 1083 | maintenance |
| pentestmonkey/unix-privesc-check A single shell script that audits Unix systems for misconfigurations allowing local privilege escalation. It can be uploaded and run direct… | 32 | 1082 | maintenance |
| sysdream/chashell Chashell is a Go-based reverse shell that tunnels communication over DNS, paired with a multi-client control server called chaserv. All tra… | 32 | 1082 | maintenance |
| Leeon123/CC-attack A Python3 command-line tool that performs Layer 7 HTTP/HTTPS flood (CC) attacks through SOCKS4/5 or HTTP proxies, with multithreading, rand… | 23 | 1082 | maintenance |
| asterinas/asterinas Asterinas is a memory-safe, production-oriented OS kernel written in Rust that implements the Linux ABI, aiming to be a drop-in Linux alter… | 95 | 4833 | experimental |
| vmt/udis86 Udis86 is a C library (libudis86) for disassembling x86 and x86-64 machine code, decoding raw binary streams into structured instructions w… | 32 | 1081 | maintenance |
| ajinabraham/CMSScan CMSScan is a self-hosted security dashboard that scans WordPress, Drupal, Joomla, and vBulletin websites for vulnerabilities by wrapping wp… | 32 | 1080 | maintenance |
| Apache Guacamole Apache Guacamole is a clientless remote desktop gateway that lets users access RDP, VNC, and SSH sessions through a standard web browser us… | 10 | 1080 | maintenance |
| xdmjun/mp-unpack A tool for unpacking WeChat mini-program packages (wxapkg files) to recover readable source code. It appears to be a reverse-engineering ut… | 32 | 1079 | maintenance |
| NickstaDB/SerializationDumper A Java-based command-line tool that dumps Java serialization streams and RMI packet contents into a human-readable form without deserializi… | 23 | 1079 | maintenance |
| FriendsOfSymfony/FOSOAuthServerBundle FOSOAuthServerBundle is a Symfony bundle that provides server-side OAuth2 capabilities, letting Symfony applications act as OAuth2 authoriz… | 23 | 1078 | maintenance |
| admintony/Prepare-for-AWD A collection of Python and PHP scripts for AWD (Attack with Defense) CTF competitions, including batch attack scripts for planting and trig… | 32 | 1077 | maintenance |
| dirkjanm/PrivExchange PrivExchange is a set of Python proof-of-concept tools that abuse Exchange Web Services push notifications to relay authentication and esca… | 32 | 1077 | maintenance |
| wireghoul/htshells A collection of self-contained .htaccess files that turn Apache servers into web shells or launch various attacks when uploaded. It include… | 32 | 1077 | maintenance |
| cyb3rfox/Aurora-Incident-Response A cross-platform Electron desktop application for documenting incident response investigations. It digitizes the SANS FOR508 'Spreadsheet o… | 23 | 1077 | maintenance |
| daviddesberg/PHPoAuthLib PHPoAuthLib is a PHP client library providing OAuth 1.x and OAuth 2.0 support with prebuilt service implementations for dozens of providers… | 23 | 1077 | maintenance |
| devxprite/infoooze Infoooze is a Node.js-based OSINT (Open-Source Intelligence) CLI tool for quickly gathering information about websites, IP addresses, usern… | 23 | 1077 | maintenance |
| SuprHackerSteve/Crescendo Crescendo is a Swift-based real-time event viewer for macOS built on Apple's Endpoint Security Framework. It consists of a system extension… | 23 | 1076 | maintenance |
| scrt/avcleaner avcleaner is a C/C++ source-to-source obfuscator built on LLVM, designed to evade antivirus detection by transforming source code (e.g., hi… | 32 | 1075 | maintenance |
| lingthio/Flask-User Flask-User is a Flask extension providing customizable user authentication and account management, including registration, email confirmati… | 23 | 1075 | maintenance |
| antonioCoco/SharPyShell SharPyShell is a Python tool that generates a tiny, obfuscated ASP.NET webshell for C# web applications on .NET Framework and provides an i… | 23 | 1072 | maintenance |
| tower1229/Vue-Access-Control Vue-Access-Control is a frontend access control framework built on Vue, Vue Router, and axios. It controls user permissions at three levels… | 32 | 1071 | maintenance |
| iphelix/dnschef DNSChef is a highly configurable DNS proxy (fake DNS) tool written in Python for penetration testers and malware analysts. It can forge DNS… | 32 | 1071 | maintenance |
| silverf0x/RpcView RpcView is a free, open-source Windows GUI tool for exploring and decompiling Microsoft RPC (Remote Procedure Call) interfaces present on a… | 23 | 1070 | maintenance |
| YahooArchive/xss-filters A JavaScript library providing context-dependent output filters to prevent cross-site scripting (XSS) attacks. It applies 'just sufficient'… | 10 | 1070 | maintenance |
| c0ny1/jsEncrypter A Burp Suite extension that uses PhantomJS to invoke front-end JavaScript encryption functions on payloads, enabling fuzzing and brute-forc… | 23 | 1069 | maintenance |
| FeeiCN/ESD ESD is a Python-based subdomain enumeration tool that brute-forces and collects subdomains for a given domain. It uses AsyncIO/aioDNS for f… | 10 | 1068 | maintenance |
| ohyicong/decrypt-chrome-passwords A Python script that decrypts Chrome passwords saved locally on a Windows machine, exporting them to a CSV file. It is intended to raise aw… | 57 | 1067 | maintenance |
| safebuffer/sam-the-admin A Python CLI exploit tool that chains CVE-2021-42278 and CVE-2021-42287 to impersonate a Domain Admin from a standard Active Directory doma… | 32 | 1067 | maintenance |
| 0xbadjuju/Tokenvator Tokenvator is a C# command-line tool for manipulating Windows tokens to elevate privileges, such as stealing a SYSTEM token from a running … | 23 | 1067 | maintenance |
| ZHacker13/ReverseTCPShell A PowerShell-based ReverseTCP shell framework that provides a command-and-control (C2) server with modules for remote host information gath… | 32 | 1066 | maintenance |
| raddyfiy/caidao-official-version An archive of the official versions of 'China Chopper' (中国菜刀), a well-known webshell management client, with archived download snapshots an… | 23 | 1064 | maintenance |
| momosecurity/rhizobia_J A Java security SDK from MOMO Security that provides utilities for SQL injection sanitisation, CSRF token handling, safe deserialization, S… | 32 | 1063 | maintenance |
| sickcodes/Docker-eyeOS A Docker container that boots the iPhone's iOS xnu kernel (arm64) under QEMU with KVM acceleration, exposing SSH and GDB ports for kernel d… | 32 | 1063 | maintenance |
| DavidBuchanan314/ambiguous-png-packer A Python tool that crafts PNG files rendering differently in Apple software versus other viewers, exploiting a parsing ambiguity in Apple's… | 32 | 1059 | maintenance |
| nsacyber/GRASSMARLIN GRASSMARLIN is a Java-based desktop application from NSA that provides IP network situational awareness for Industrial Control Systems (ICS… | 10 | 1059 | maintenance |
| wwh1004/ExtremeDumper A Windows GUI tool for dumping .NET assemblies from running processes, including bypassing anti-dump protections. It can also inject .NET a… | 23 | 1058 | maintenance |
| asLody/SandVXposed SandVXposed combines VirtualApp's app virtualization with the SandHook hooking framework to run Xposed modules on Android without root acce… | 23 | 1057 | maintenance |
| AHXR/ghost Ghost is a lightweight Remote Access Trojan (RAT) written in C++ that gives an attacker silent remote command-line access to Windows machin… | 23 | 1057 | maintenance |
| Mob2003/rakshasa Rakshasa is a cross-platform multi-level proxy and intranet tunneling tool written in Go. It forms a network of nodes that forward TCP traf… | 21 | 1057 | maintenance |
| Abacus-Group-RTO/legion Legion is an open-source, semi-automated network penetration testing framework with a graphical interface, forked from Sparta. It orchestra… | 10 | 1057 | maintenance |
| twitchyliquid64/subnet Subnet is a simple, auditable VPN server and client written in Go, using TLS mutual authentication and TUN interfaces to route traffic. It … | 10 | 1057 | maintenance |
| DuendeArchive/IdentityModel IdentityModel is a .NET Standard helper library for claims-based identity, OAuth 2.0, and OpenID Connect. It provides request/response obje… | 10 | 1056 | maintenance |
| ptoomey3/evilarc evilarc is a Python CLI tool that creates tar and zip archives containing files with directory traversal characters in their embedded paths… | 32 | 1055 | maintenance |
| btbd/access A Windows kernel driver plus DLL wrapper that lets a usermode process perform privileged operations on protected processes without creating… | 32 | 1054 | maintenance |
| doyensec/electronegativity Electronegativity is a CLI-based SAST tool that scans Electron applications for misconfigurations and security anti-patterns using AST and … | 39 | 1053 | maintenance |
| a1phaboy/FastjsonScan FastjsonScan is a Go-based command-line scanner that detects Fastjson deserialization vulnerabilities in Java web services. It identifies t… | 23 | 1053 | maintenance |
| noob-hackers/lazybee Lazybee is a Python-based CLI tool for generating random wordlists for brute-force attacks, primarily targeting Termux on Android. It gener… | 32 | 1052 | maintenance |
| unosquare/passcore PassCore is a one-page web application built with ASP.NET Core and React that lets users change their own Active Directory or LDAP password… | 10 | 1051 | maintenance |
| HatBoy/Pcap-Analyzer A Python-based visual offline pcap packet analyzer with a web interface built on Flask. It parses pcap files to show protocol and traffic s… | 32 | 1048 | maintenance |
| momosecurity/momo-code-sec-inspector-java An IntelliJ IDEA plugin by Momo Security that performs static security analysis of Java code in real time using IDEA's native Inspection me… | 32 | 1048 | maintenance |
| thomasxm/BOAZ_beta BOAZ is a multilayered AV/EDR evasion framework written in C++/C with Python linking, designed to generate polymorphic payloads that bypass… | 57 | 1047 | maintenance |
| samratashok/ADModule A backup of the Microsoft-signed ActiveDirectory PowerShell module (DLL and module files) from Server 2016 with RSAT. It allows enumerating… | 32 | 1047 | maintenance |
| shimmeris/SCFProxy SCFProxy is a CLI tool that deploys HTTP, SOCKS, and reverse proxies on cloud functions and API gateways across Alibaba Cloud, Tencent Clou… | 23 | 1047 | maintenance |
| rastating/wordpress-exploit-framework A Ruby framework for penetration testing WordPress installations, providing a console with loadable exploit and payload modules. It is dist… | 10 | 1047 | maintenance |
| vivirenremoto/doomcaptcha DOOM Captcha is a novelty captcha widget that replaces traditional CAPTCHA challenges with a mini DOOM-style shooting game where users must… | 32 | 1045 | maintenance |
| eveem-org/panoramix Panoramix is a Python-based decompiler that converts Ethereum smart contract bytecode into readable pseudocode, powering the Eveem.org serv… | 32 | 1045 | maintenance |
| 9176324/Shark Shark is a Windows kernel driver project written in C that disables Kernel Patch Protection (PatchGuard) in real time on Windows 7 (7600) a… | 23 | 1044 | maintenance |
| superturtlee/gbl_root_canoe An EDK2-based toolkit for patching EFI applications inside Qualcomm Android Bootloader (ABL) images, exploiting a GBL vulnerability to load… | 82 | 1043 | maintenance |
| OffensivePython/Saddam Saddam is a Python command-line tool that performs DDoS amplification attacks using DNS, NTP, SNMP, and SSDP reflection vectors. It can als… | 32 | 1043 | maintenance |
| KULeuven-COSIC/Starlink-FI A research project from KU Leuven COSIC providing the design of a custom modchip that performs voltage fault injection to bypass signature … | 32 | 1043 | maintenance |
| x0tools/WeChatOpenDevTools A Windows tool that patches WeChat to enable the built-in DevTools (F12) for debugging WeChat Official Accounts and Mini Programs. It suppo… | 27 | 1041 | maintenance |
| minio/sha256-simd A pure Go library that accelerates SHA256 hashing using hardware instructions: AVX512 and Intel SHA Extensions on x86, and ARM64 Cryptograp… | 23 | 1041 | maintenance |
| daprofiler/DaProfiler DaProfiler is a Python-based OSINT CLI tool that traces a person's digital identity from a first and last name, recovering email addresses,… | 10 | 1041 | maintenance |
| TryCatchHCF/DumpsterFire DumpsterFire is a modular, menu-driven, cross-platform Python toolset for building repeatable, time-delayed, distributed security events. I… | 23 | 1040 | maintenance |
| rapid7/hackazon Hackazon is a deliberately vulnerable online storefront web application built with PHP, AJAX, and RESTful APIs. It serves as a training and… | 10 | 1040 | maintenance |
| adi0x90/attifyos Attify OS is a Linux distribution based on Ubuntu 18.04 pre-configured with tools for security assessment and penetration testing of IoT de… | 32 | 1038 | maintenance |
| SaadAhla/FilelessPELoader A C++ tool that fetches an AES-encrypted Windows PE executable from a remote location, decrypts it in memory, and executes it without writi… | 31 | 1038 | maintenance |
| rfunix/Pompem Pompem is a Python command-line tool that automates searching for exploits and vulnerabilities across major databases like PacketStorm, CXS… | 23 | 1037 | maintenance |
| bytedance/godlp godlp is a Go library from ByteDance for sensitive data discovery and de-identification (data loss prevention). It detects sensitive inform… | 10 | 1037 | maintenance |
| anhkgg/SuperDllHijack SuperDllHijack is a C++ library implementing a general DLL hijacking technique for Windows that forwards calls to the original DLL without … | 32 | 1036 | maintenance |
| securing/DumpsterDiver DumpsterDiver is a Python command-line tool that scans large volumes of files for hardcoded secrets such as AWS, Azure, and SSH keys as wel… | 10 | 1036 | maintenance |
| adonespitogo/AdoBot AdoBot is an open-source Android spyware application written in Java that monitors SMS messages, call logs, contacts, and device location, … | 32 | 1035 | maintenance |
| marco-lancini/goscan GoScan is an interactive network scanner client written in Go that provides abstraction and automation over nmap, with auto-completion and … | 23 | 1035 | maintenance |
| yassineaboukir/sublert Sublert is a Python CLI security and reconnaissance tool that uses certificate transparency logs to monitor new subdomains issued TLS/SSL c… | 32 | 1034 | maintenance |
| averagesecurityguy/scripts A collection of Python scripts written for use during penetration testing engagements, organized into categories like brute forcing, enumer… | 32 | 1033 | maintenance |