domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| leonboe1/GoogleFindMyTools A Python framework that reimplements parts of Google's Find My Device (Find Hub) network, allowing users to query trackers and Android devi… | 58 | 1163 | experimental |
| NytroRST/ShellcodeCompiler A C++ command-line compiler that converts a simplified C/C++-style source language into small, position-independent, NULL-free shellcode fo… | 32 | 1158 | experimental |
| tailscale/tailscale-rs A work-in-progress Rust implementation of Tailscale, providing a library for building tailnet-connected applications with bindings to C, El… | 81 | 1130 | experimental |
| JuliaPoo/Artfuscator Artfuscator is a novelty C compiler built on ELVM that compiles C programs into a binary whose entire control flow graph renders as a chose… | 32 | 1104 | experimental |
| berylliumsec/nebula Nebula is an AI-powered penetration testing desktop application that combines a terminal, browser, notes, findings, and reporting into one … | 92 | 1100 | experimental |
| moturus/motor-os Motor OS is a microkernel-based operating system written entirely in Rust, designed for virtualized cloud workloads such as web serving, se… | 71 | 1090 | experimental |
| koutto/jok3r Jok3r is a Python3 CLI framework that automates network and web black-box penetration testing by chaining 50+ open-source security tools. I… | 32 | 1088 | experimental |
| google-deepmind/synthid-text A reference Python implementation of Google DeepMind's SynthID Text watermarking and detection technology for identifying AI-generated text… | 69 | 1085 | experimental |
| dannymcc/bluehood Bluehood is a self-hosted Bluetooth scanner that passively detects nearby BLE and Classic Bluetooth devices, identifies them by vendor and … | 77 | 1063 | experimental |
| ZeroMemoryEx/Terminator Terminator is a C++ proof-of-concept tool that terminates EDR/XDR/antivirus processes on Windows by abusing the vulnerable, signed zam64.sy… | 20 | 1062 | experimental |
| hackerxphantom/Facebook_hack A Python command-line tool that performs brute-force password attacks against Facebook accounts using an email or profile ID as the target,… | 10 | 1039 | experimental |
| fikrado/fikrado.py A Python 2.7 command-line script that attempts to gain access to Facebook accounts via the Facebook API using brute-force techniques. It ta… | 23 | 1037 | experimental |
| cloud-gouv/securix SécurixOS is a NixOS-based hardened Linux distribution for secure workstations, developed by the French DINUM for sysadmin, office, and dev… | 87 | 1029 | experimental |
| DragoQCC/CrucibleC2 HardHat C2 (CrucibleC2) is a cross-platform, multi-user Command & Control framework written in C#/.NET for red team engagements and penetra… | 22 | 1024 | experimental |
| a16z/jolt Jolt is a zero-knowledge virtual machine (zkVM) for RISC-V (RV64IMAC) that generates cryptographic proofs of arbitrary program execution, b… | 79 | 1022 | experimental |
| brix/crypto-js CryptoJS is a JavaScript library implementing standard cryptographic algorithms such as AES, DES, MD5, SHA family hashes, HMAC, and PBKDF2,… | 32 | 16407 | abandoned |
| OpenEthan/SMSBoom SMSBoom was a Python CLI tool that flooded phone numbers with SMS verification messages by replaying requests against configurable SMS APIs… | 10 | 15147 | abandoned |
| PowerShellMafia/PowerSploit PowerSploit is a collection of PowerShell modules for post-exploitation tasks during penetration tests, covering code execution, persistenc… | 10 | 13085 | abandoned |
| google/sanitizers The Google sanitizers repository hosts documentation and helper code for AddressSanitizer, ThreadSanitizer, MemorySanitizer, LeakSanitizer,… | 69 | 12465 | abandoned |
| dgrijalva/jwt-go A Go library for creating, signing, parsing, and verifying JSON Web Tokens (JWTs), supporting HMAC, RSA, RSA-PSS, and ECDSA signing algorit… | 10 | 10732 | abandoned |
| lucia-auth/lucia Lucia is a TypeScript authentication library for managing user sessions and OAuth in web applications. It was deprecated in March 2025 and … | 75 | 10449 | abandoned |
| aliasrobotics/cai Cybersecurity AI (CAI) is an open-source Python framework of specialized AI agents for offensive security tasks such as penetration testing… | 10 | 9821 | abandoned |
| xaoyaoo/PyWxDump PyWxDump was a Python tool for extracting and decrypting WeChat local data such as messages, contacts, and account information from Windows… | 40 | 9678 | abandoned |
| byt3bl33d3r/CrackMapExec CrackMapExec is a Python-based command-line swiss army knife for pentesting Windows and Active Directory networks, supporting protocols lik… | 10 | 9162 | abandoned |
| 99designs/aws-vault AWS Vault is a CLI tool that securely stores AWS IAM credentials in the operating system's native keystore (macOS Keychain, Windows Credent… | 49 | 8986 | abandoned |
| apenwarr/sshuttle sshuttle is a Python command-line tool that creates a transparent proxy over SSH, acting like a lightweight VPN without admin rights on the… | 32 | 8856 | abandoned |
| rkt/rkt rkt is a pod-native container engine for Linux, designed to be secure, composable, and built on open standards like appc, CNI, and OCI. Dev… | 10 | 8766 | abandoned |
| EmpireProject/Empire Empire is a post-exploitation framework with a pure PowerShell Windows agent and a pure Python Linux/OS X agent, offering encrypted communi… | 10 | 7860 | abandoned |
| bitwiseshiftleft/sjcl The Stanford Javascript Crypto Library (SJCL) is a JavaScript library providing high-level cryptographic primitives such as AES encryption,… | 55 | 7199 | abandoned |
| facebook/pyre-check Pyre is a performant, PEP 484-compliant static type checker for Python that provides incremental checking of large codebases, and it ships … | 10 | 7171 | abandoned |
| StackExchange/blackbox BlackBox is a CLI tool that uses GPG to encrypt specific files in a Git, Mercurial, Subversion, or Perforce repository so secrets are encry… | 10 | 6769 | abandoned |
| Netflix/dispatch Dispatch is a self-hosted incident management platform from Netflix that orchestrates security incident response by integrating with existi… | 10 | 6493 | abandoned |
| datreeio/datree Datree is a CLI-based policy enforcement tool that scans Kubernetes YAML manifests against built-in and custom rules to block misconfigurat… | 10 | 6334 | abandoned |
| p-e-w/maybe maybe is a Python CLI tool that runs a command under ptrace and intercepts filesystem-modifying syscalls, turning them into no-ops so you c… | 10 | 6301 | abandoned |
| cuckoosandbox/cuckoo Cuckoo Sandbox is an open-source automated dynamic malware analysis system that executes suspicious files in an isolated environment and re… | 10 | 5966 | abandoned |
| TheSpeedX/TBomb TBomb is a Python CLI application that floods phone numbers with SMS messages and calls via a collection of public APIs, runnable on Linux … | 10 | 5585 | abandoned |
| zcash/zcash The original zcashd full node implementation for Zcash, a privacy-focused cryptocurrency derived from Bitcoin Core that uses zero-knowledge… | 10 | 5484 | abandoned |
| tenable/terrascan Terrascan is a static code analyzer for Infrastructure as Code that detects compliance and security violations across Terraform, CloudForma… | 10 | 5210 | abandoned |
| Karumi/Dexter Dexter is an Android library that simplifies requesting runtime permissions on Android Marshmallow and above, decoupling permission logic f… | 10 | 5193 | abandoned |
| RikkaApps/Riru Riru is a Magisk module that injects code into Android's zygote process, allowing other modules to run their code inside app processes or t… | 10 | 5143 | abandoned |
| bitly/oauth2_proxy A Go reverse proxy and static file server that adds OAuth2 authentication (Google, GitHub, Azure, GitLab, and others) in front of web appli… | 10 | 5087 | abandoned |
| aquasecurity/kube-hunter kube-hunter is a Python-based tool that hunts for security weaknesses and vulnerabilities in Kubernetes clusters, running remotely, on a ma… | 23 | 5084 | abandoned |
| qTox/qTox qTox is a cross-platform instant messaging desktop client supporting encrypted text chat, voice and video calls, and file transfer over the… | 10 | 4976 | abandoned |
| unCaptcha unCaptcha2 is a Python-based security research tool that defeats Google's ReCaptcha v2 audio challenges by submitting the audio to free spe… | 32 | 4916 | abandoned |
| 10se1ucgo/DisableWinTracking A Windows 10 utility that applies known registry and service tweaks to minimize Microsoft telemetry and tracking. It ships as a GUI/CLI Pyt… | 10 | 4902 | abandoned |
| nbs-system/naxsi NAXSI is a high-performance, low-maintenance web application firewall (WAF) implemented as a third-party NGINX module written in C. Instead… | 10 | 4811 | abandoned |
| spring-attic/spring-security-oauth A Spring Security library providing OAuth 1(a) and OAuth 2 support for both consumers and providers in Spring web applications. It was arch… | 10 | 4690 | abandoned |
| google/santa Santa is a binary and file access authorization system for macOS, consisting of a system extension that monitors executions, a daemon that … | 10 | 4509 | abandoned |
| qwerty472123/wxappUnpacker wxappUnpacker is a tool for unpacking and decompiling packaged WeChat mini-program (wxapkg) files back into readable source files such as w… | 10 | 4505 | abandoned |
| hanc00l/wooyun_public A crawler and search application for the archived Wooyun.org security vulnerability disclosure platform, containing ~40k-88k public vulnera… | 10 | 4396 | abandoned |
| buttercup/buttercup-desktop Buttercup Desktop is a free, open-source, cross-platform password manager built with Electron and TypeScript that stores credentials in enc… | 10 | 4392 | abandoned |
| Netflix/security_monkey Security Monkey is a self-hosted service from Netflix that monitors AWS, GCP, OpenStack, and GitHub organizations for assets and policy cha… | 10 | 4371 | abandoned |
| zhzyker/exphub Exphub is a collection of standalone Python, Java, PHP, and shell exploit scripts for known CVE vulnerabilities in products like Weblogic, … | 32 | 4290 | abandoned |
| iMeiji/shadowsocks_install A shell script that automatically installs and configures a Shadowsocks proxy server on Linux VPS instances, forked from Teddysun's well-kn… | 23 | 4170 | abandoned |
| Greenwolf/social_mapper Social Mapper is a Python 3 OSINT tool that enumerates and correlates social media profiles across sites like LinkedIn, Facebook, Twitter, … | 32 | 4074 | abandoned |
| bytecodealliance/lucet Lucet is a native WebAssembly ahead-of-time compiler and runtime for safely executing untrusted Wasm programs inside applications, built on… | 10 | 4045 | abandoned |
| Arachni/arachni Arachni is a modular, high-performance Ruby framework for scanning web applications for security vulnerabilities, including XSS and SQL inj… | 10 | 4042 | abandoned |
| eth0izzle/shhgit shhgit is a secrets detection tool that scans GitHub, GitLab, Bitbucket repositories and local directories for accidentally committed crede… | 36 | 3978 | abandoned |
| novatic14/MANPADS-System-Launcher-and-Rocket A proof-of-concept launcher and interceptor system built from consumer electronics and 3D-printed components. The project has been disconti… | 53 | 3909 | abandoned |
| trailofbits/manticore Manticore is a symbolic execution tool for analyzing Ethereum smart contracts, Linux ELF binaries, and WASM modules. It explores program st… | 10 | 3857 | abandoned |
| Jessecar96/SteamDesktopAuthenticator A Windows desktop application that implements Steam's mobile authenticator (Steam Guard), allowing users to generate two-factor authenticat… | 23 | 3814 | abandoned |
| offensive-security/kali-nethunter Kali NetHunter is an Android ROM overlay providing a mobile penetration testing platform, combining a custom kernel, a Kali Linux chroot, a… | 10 | 3809 | abandoned |
| yck1509/ConfuserEx ConfuserEx is a free, open-source protector for .NET applications that provides obfuscation features such as symbol renaming, control flow … | 10 | 3765 | abandoned |
| andOTP/andOTP andOTP is an open-source two-factor authentication app for Android that generates TOTP and HOTP one-time passwords. It stores tokens in enc… | 10 | 3713 | abandoned |
| cSploit/android cSploit is an open-source Android network analysis and penetration testing suite for rooted devices, integrating Metasploit RPC, MITM attac… | 23 | 3649 | abandoned |
| byt3bl33d3r/MITMf MITMf is a Python framework for performing Man-In-The-Middle and network attacks, featuring built-in SMB, HTTP, and DNS servers, an SSLStri… | 10 | 3645 | abandoned |
| skoruba/IdentityServer4.Admin A web-based administration UI for managing IdentityServer4 clients, resources, and ASP.NET Core Identity users, roles, and claims. It ships… | 10 | 3577 | abandoned |
| Proxmark/proxmark3 The official (now archived) client software, FPGA logic, and design documentation for the Proxmark3, a general-purpose RFID tool that can s… | 49 | 3539 | abandoned |
| paralleldrive/cuid A deprecated JavaScript library for generating collision-resistant unique IDs optimized for horizontal scaling. It is insecure because it l… | 68 | 3503 | abandoned |
| henryboldi/felony Felony is an open-source PGP keychain desktop app built with Electron, React, and Redux, designed to make PGP encryption approachable for n… | 23 | 3461 | abandoned |
| kjur/jsrsasign jsrsasign is a pure JavaScript cryptography library supporting RSA/RSAPSS/ECDSA/DSA signing and validation, ASN.1, PKCS key formats, X.509 … | 93 | 3373 | abandoned |
| EFForg/https-everywhere HTTPS Everywhere was a Firefox, Chrome, and Opera browser extension by EFF that rewrote HTTP requests to HTTPS to encrypt browsing. It was … | 10 | 3353 | abandoned |
| maxchehab/CSS-Keylogging A proof-of-concept Chrome extension and Express server demonstrating a CSS-based keylogging attack using attribute selectors and background… | 32 | 3240 | abandoned |
| protectai/llm-guard LLM Guard is a Python library providing input and output scanners to secure LLM interactions, including sanitization, harmful language dete… | 10 | 3204 | abandoned |
| Netflix/consoleme ConsoleMe is a web service from Netflix that centralizes AWS IAM permission management, offering console login, self-service permission req… | 10 | 3197 | abandoned |
| FeeiCN/Cobra Cobra is a source code security audit (SAST) tool that scans PHP, Java, and other languages for common vulnerabilities like SQL injection, … | 10 | 3186 | abandoned |
| jpadilla/django-rest-framework-jwt A Python package that adds JSON Web Token (JWT) authentication to Django REST Framework APIs. It provides token obtain, refresh, and verify… | 10 | 3165 | abandoned |
| jipegit/OSXAuditor OS X Auditor is a free Mac OS X computer forensics tool that parses and hashes system artifacts such as kernel extensions, daemons, startup… | 32 | 3133 | abandoned |
| buzzfeed/sso sso (S.S. Octopus) is a single sign-on solution built at BuzzFeed for securing internal services behind OAuth-based authentication. It acts… | 10 | 3123 | abandoned |
| djkaty/Il2CppInspector Il2CppInspector is an automated tool for reverse engineering Unity IL2CPP binaries, extracting type definitions, metadata and method pointe… | 23 | 3040 | abandoned |
| stefanesser/dumpdecrypted A dylib that, when injected via DYLD_INSERT_LIBRARIES into an encrypted iPhone application on a jailbroken device, dumps the decrypted Mach… | 32 | 3036 | abandoned |
| NewEraCracker/LOIC LOIC (Low Orbit Ion Cannon) is an open-source network stress testing tool written in C#, based on Praetox's original LOIC. It supports TCP/… | 10 | 2967 | abandoned |
| microsoft/Git-Credential-Manager-for-Windows A secure Git credential helper for Windows that stores credentials and supports multi-factor authentication with GitHub, Bitbucket, and Vis… | 10 | 2939 | abandoned |
| facebookarchive/conceal Conceal is a Facebook library providing Java APIs for fast, memory-efficient encryption and authentication of data on Android, especially l… | 10 | 2930 | abandoned |
| optiv/ScareCrow ScareCrow is a Go-based payload creation framework designed to bypass EDR (Endpoint Detection and Response) and application whitelisting co… | 10 | 2890 | abandoned |
| google/binnavi BinNavi is a binary analysis IDE for inspecting, navigating, editing, and annotating control-flow and call graphs of disassembled code, wit… | 10 | 2884 | abandoned |
| microsoft/onefuzz OneFuzz is a self-hosted Fuzzing-As-A-Service platform that lets developers launch continuous fuzzing jobs from a few VMs to thousands of c… | 10 | 2824 | abandoned |
| Python Social Auth Python Social Auth is a Python library providing easy-to-setup social authentication and registration with support for multiple frameworks … | 32 | 2801 | abandoned |
| mozilla/bleach Bleach is a Python library for sanitizing HTML from untrusted sources using an allowlist-based approach, escaping or stripping markup and a… | 10 | 2766 | abandoned |
| gravitational/teleconsole Teleconsole is a Go-based command line tool for sharing a UNIX terminal session with others and forwarding local TCP ports over SSH, aimed … | 10 | 2761 | abandoned |
| Netflix/bless BLESS is an SSH Certificate Authority that runs as an AWS Lambda function and signs short-lived SSH certificates for user authentication. I… | 23 | 2759 | abandoned |
| speakeasyjs/speakeasy Speakeasy is a Node.js one-time passcode generator implementing HOTP (RFC 4226) and TOTP (RFC 6238) for two-factor authentication, compatib… | 23 | 2757 | abandoned |
| android-password-store/Android-Password-Store An Android password manager application compatible with ZX2C4's Pass command-line password store, using OpenPGP for encryption. It lets use… | 10 | 2655 | abandoned |
| Netflix-Skunkworks/Scumblr Scumblr is a Ruby on Rails web application from Netflix for performing periodic syncs of data sources (GitHub repos, URLs, DNS) and running… | 23 | 2641 | abandoned |
| DanMcInerney/LANs.py A Python-based penetration testing tool that scans WiFi networks for active clients, performs targeted ARP spoofing, and intercepts or inje… | 32 | 2632 | abandoned |
| square/keywhiz Keywhiz is a Java-based system for centrally storing, managing, and distributing secrets such as TLS keys, API tokens, and database credent… | 10 | 2623 | abandoned |
| CrimsonForge-io/king-phisher King Phisher is a phishing campaign toolkit for testing and promoting user awareness by simulating real-world phishing attacks, with contro… | 66 | 2581 | abandoned |
| external-secrets/kubernetes-external-secrets A Kubernetes controller that syncs secrets from external secret management systems like AWS Secrets Manager and HashiCorp Vault into native… | 10 | 2579 | abandoned |
| agilebits/onepassword-app-extension An iOS action extension from AgileBits that let third-party iOS apps integrate 1Password for filling login credentials and other form data.… | 10 | 2569 | abandoned |
| rockbruno/swiftshield SwiftShield is a Swift obfuscator that renames types and methods in iOS projects using SourceKit to protect apps against reverse engineerin… | 23 | 2547 | abandoned |