domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| genuinetools/binctr binctr is a Go library and tool for building fully static binaries that embed a container rootfs and run the container directly, without re… | 32 | 2518 | abandoned |
| activecm/rita-legacy RITA (Real Intelligence Threat Analytics) is an open-source framework for detecting command and control communication through network traff… | 59 | 2509 | abandoned |
| WiFi-Pumpkin WiFi-Pumpkin is a Python framework for auditing Wi-Fi security by creating rogue wireless access points and performing man-in-the-middle at… | 23 | 2497 | abandoned |
| SpiderLabs/owasp-modsecurity-crs The OWASP ModSecurity Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity or compatible web application… | 10 | 2490 | abandoned |
| evilsocket/bettercap bettercap is a network attack and reconnaissance framework, described as a Swiss Army knife for WiFi, BLE, HID hijacking, CAN-bus, and IPv4… | 10 | 2490 | abandoned |
| IvanGlinkin/CCTV CCTV (Close-Circuit Telegram Vision) is an open-source OSINT tool that abuses Telegram's 'People Nearby' feature to triangulate and track u… | 28 | 2480 | abandoned |
| pycrypto/pycrypto PyCrypto is the Python Cryptography Toolkit, providing secure hash functions (SHA256, RIPEMD160) and encryption algorithms (AES, DES, RSA, … | 10 | 2473 | abandoned |
| conorpp/u2f-zero U2F Zero is an open source hardware U2F security token for two-factor authentication, built on a small USB device with secure key storage. … | 23 | 2450 | abandoned |
| DuendeArchive/identity-model-oidc-client-js oidc-client is a JavaScript library providing OpenID Connect (OIDC) and OAuth2 protocol support for browser-based client applications, incl… | 10 | 2423 | abandoned |
| Marten4n6/EvilOSX EvilOSX is a Remote Administration Tool (RAT) for macOS/OS X written in pure Python, with a server providing both GUI and CLI interfaces an… | 32 | 2416 | abandoned |
| DrizzleRisk/drizzleDumper drizzleDumper is a memory-search-based Android unpacking tool that dumps DEX files from packed/protected Android apps. It runs as a command… | 32 | 2415 | abandoned |
| pedant/safe-java-js-webview-bridge An Android library providing a safe alternative to WebView's addJavascriptInterface for Java-JavaScript communication, using WebChromeClien… | 23 | 2415 | abandoned |
| witoldsz/angular-http-auth An AngularJS module that installs an $http interceptor to buffer requests failing with HTTP 401 and broadcast login-required events, plus a… | 23 | 2378 | abandoned |
| jaeles-project/jaeles Jaeles is a Go-based framework for building and running automated web application vulnerability scanners using customizable YAML signatures… | 62 | 2369 | abandoned |
| codebutler/firesheep Firesheep is a Firefox extension that demonstrates HTTP session hijacking attacks by sniffing unencrypted Wi-Fi traffic and capturing sessi… | 32 | 2353 | abandoned |
| aress31/burpgpt burpgpt is a Burp Suite extension that sends HTTP traffic to OpenAI GPT models for AI-driven passive vulnerability scanning and traffic ana… | 30 | 2352 | abandoned |
| lucadegasperi/oauth2-server-laravel An OAuth 2.0 authorization and resource server bridge for the Laravel and Lumen PHP frameworks, built on the League OAuth 2.0 server packag… | 23 | 2347 | abandoned |
| praetorian-inc/noseyparker Nosey Parker is a Rust-based command-line secrets scanner that finds credentials and sensitive information in files, directories, GitHub, a… | 10 | 2343 | abandoned |
| evilsocket/xray XRay is a Go-based CLI tool for network reconnaissance and OSINT that enumerates subdomains via DNS bruteforcing, gathers open-port intelli… | 10 | 2331 | abandoned |
| expressjs/csurf csurf is Node.js CSRF protection middleware for Express that creates and validates CSRF tokens via session or cookie-based storage. The rep… | 10 | 2307 | abandoned |
| sevagas/macro_pack macro_pack is a Python CLI tool that automates obfuscation and generation of MS Office documents, VBA/VBS scripts, shortcuts, and other for… | 10 | 2307 | abandoned |
| lamster2018/EasyProtector EasyProtector is an Android library that detects rooted devices, Xposed framework hooks, debuggers/tracers, virtual apps (multi-instance), … | 23 | 2289 | abandoned |
| dgiese/dustcloud A research project for reverse engineering and rooting Xiaomi Smart Home devices, including robot vacuums, providing methods to root device… | 23 | 2279 | abandoned |
| github/SoftU2F SoftU2F is a software U2F authenticator for macOS that emulates a hardware U2F HID device and performs cryptographic operations using the m… | 10 | 2244 | abandoned |
| DarkCoderSc/PowerRemoteDesktop PowerRemoteDesktop is a remote desktop application written entirely in PowerShell, with both client and server components implementing its … | 23 | 2243 | abandoned |
| Magisk-Modules-Repo/MagiskHidePropsConf A Magisk module providing a terminal-based UI for editing Android system prop values via resetprop, including a maintained list of certifie… | 10 | 2228 | abandoned |
| secgroundzero/warberry WarBerryPi is a tactical exploitation toolkit built to run on a Raspberry Pi, acting as a drop-box/implant for red-team engagements to scan… | 32 | 2221 | abandoned |
| PowerShellEmpire/PowerTools PowerTools is a collection of PowerShell projects focused on offensive security operations, including tools like PowerView, PowerUp, PowerP… | 23 | 2206 | abandoned |
| python-security/pyt PyT (Python Taint) is a static analysis tool that detects security vulnerabilities like injection flaws in Python web applications using ta… | 23 | 2199 | abandoned |
| ysrc/yulong-hids-archived Yulong HIDS is an open-source host intrusion detection system composed of an Agent, Daemon, Server, and Web console that collects host info… | 10 | 2184 | abandoned |
| mozilla/MozDef MozDef is Mozilla's Enterprise Defense Platform, an open-source SIEM-style application for automating security incident handling and enabli… | 10 | 2161 | abandoned |
| killgcd/chromego ChromeGo is a bundled censorship-circumvention toolkit providing one-click proxy/VPN packages for Chrome, Firefox, and Android to bypass th… | 32 | 2153 | abandoned |
| UnkL4b/GitMiner GitMiner is a Python CLI tool for advanced searching and mining of code and code snippets on GitHub, often used to find sensitive informati… | 45 | 2151 | abandoned |
| 8enet/Charles-Crack A repository that provided a crack/patch to bypass licensing of Charles Proxy, an HTTP debugging proxy tool. The repository content was rem… | 32 | 2150 | abandoned |
| jetstack/kube-lego kube-lego is a Kubernetes daemon that automatically requests and renews TLS certificates from Let's Encrypt for Ingress resources annotated… | 10 | 2149 | abandoned |
| ircmaxell/password_compat A PHP library providing forward compatibility with the password_* functions (password_hash, password_verify) that ship natively with PHP 5.… | 32 | 2128 | abandoned |
| Caiyeon/goldfish Goldfish is a web-based UI and workflow tool for HashiCorp Vault, built with VueJS on the frontend and a Go backend using Vault's native AP… | 10 | 2127 | abandoned |
| HikariObfuscator/Hikari Hikari is an LLVM-based code obfuscator that transforms compiled binaries with techniques like string encryption, indirect branching, funct… | 10 | 2106 | abandoned |
| M66B/XPrivacy XPrivacy is an Xposed-based privacy manager for Android that restricts which data categories (contacts, location, etc.) apps can access, fe… | 10 | 2099 | abandoned |
| AdrMXR/KitHack KitHack is a Python-based framework that automates downloading and installing a curated pack of penetration testing tools, organized into c… | 26 | 2086 | abandoned |
| nsarno/knock Knock is a Ruby gem providing seamless JWT-based authentication for Rails API-only applications. It integrates with Rails controllers via a… | 10 | 2053 | abandoned |
| yahoo/gryffin Gryffin is a large-scale web security scanning platform written in Go, built on a publisher-subscriber architecture for horizontal scaling.… | 10 | 2052 | abandoned |
| rasta-mouse/Sherlock Sherlock is a PowerShell script that identifies missing software patches for known Windows local privilege escalation vulnerabilities. It i… | 10 | 2020 | abandoned |
| ttlequals0/autovpn A command-line tool that creates disposable OpenVPN endpoints on AWS EC2 instances in any region with a single command, then lets you termi… | 56 | 2018 | abandoned |
| google/rekall Rekall is a Python-based memory forensic framework for extracting and analyzing digital artifacts from physical memory images of Windows, L… | 10 | 2008 | abandoned |
| auto-ssl/lua-resty-auto-ssl An OpenResty/nginx plugin that automatically issues and renews free SSL/TLS certificates from Let's Encrypt on the fly as HTTPS requests ar… | 51 | 1988 | abandoned |
| Fadi002/unshackle Unshackle is a bootable Linux-based ISO that resets or bypasses Windows and Linux user login passwords from a USB drive. It works offline b… | 10 | 1980 | abandoned |
| sensiolabs/security-checker A PHP command-line tool that checks Composer dependency lock files against the security.symfony.com web service for known vulnerabilities. … | 10 | 1972 | abandoned |
| TunnlTo/desktop-app TunnlTo was an open-source WireGuard client for Windows featuring advanced split tunneling and a user-friendly interface. The open-source p… | 57 | 1965 | abandoned |
| feihong-cs/ShiroExploit-Deprecated A Java-based one-click exploitation tool for Apache Shiro vulnerabilities Shiro550 (hardcoded key) and Shiro721 (Padding Oracle), supportin… | 23 | 1956 | abandoned |
| square/go-jose A Go library implementing the JOSE standards (JWE, JWS, JWT) for JSON-based signing and encryption. This Square repository is deprecated an… | 10 | 1956 | abandoned |
| aspnet/Identity ASP.NET Core Identity is the membership system for ASP.NET Core web applications, providing login, membership, and user data management. Th… | 10 | 1945 | abandoned |
| mozilla/hawk A JavaScript implementation of the HTTP Hawk Holder-Of-Key authentication scheme, providing message authentication for HTTP requests. The r… | 10 | 1941 | abandoned |
| Shopify/kubeaudit kubeaudit is a command line tool and Go package that audits Kubernetes clusters against common security controls like running as non-root, … | 10 | 1937 | abandoned |
| XcodeGhostSource/XcodeGhost The published source code of XcodeGhost, the infamous 2015 malware that spread through a compromised Xcode build configuration and infected… | 32 | 1925 | abandoned |
| twoyi/twoyi Twoyi is a lightweight Android-in-Android container that runs a nearly complete Android 8.1 system as a normal app on Android 8.1-12 device… | 10 | 1916 | abandoned |
| lyft/confidant Confidant is a secret management service from Lyft that stores secrets encrypted at rest in AWS DynamoDB, with a web UI and client tooling.… | 10 | 1856 | abandoned |
| mozilla/http-observatory Mozilla HTTP Observatory is a Python-based scanner and grader that analyzes websites' HTTP headers and security configurations, providing a… | 10 | 1850 | abandoned |
| Veil-Framework/Veil-Evasion Veil-Evasion is a Python tool that generates Metasploit payloads designed to bypass common antivirus solutions, optionally compiling them i… | 10 | 1840 | abandoned |
| mozilla/persona Mozilla Persona is a secure, distributed identification system based on the BrowserID protocol, providing login services including a fallba… | 10 | 1838 | abandoned |
| samyk/skyjack SkyJack is a drone hacking tool that autonomously seeks out, disconnects the owner of, and takes wireless control of nearby Parrot AR.Drone… | 32 | 1831 | abandoned |
| anthonyjgrove/react-google-login A React component and hooks library for adding Google OAuth sign-in and logout to web applications. It wraps the Google Identity API with a… | 10 | 1831 | abandoned |
| Neo23x0/yarGen yarGen is a Python CLI tool that generates YARA rules from strings found in malware samples, filtering out strings that appear in a large i… | 50 | 1811 | abandoned |
| ycccccccy/wx_key A tool that extracted the local database and image encryption keys from WeChat 4.0+ desktop clients, enabling users to decrypt and back up … | 52 | 1810 | abandoned |
| eth0izzle/bucket-stream A Python CLI tool that monitors certificate transparency logs via certstream and discovers public Amazon S3 buckets by generating permutati… | 36 | 1809 | abandoned |
| jaredrummler/AndroidProcesses A legacy Android library that enumerated running processes by parsing the /proc filesystem without special permissions. It worked only up t… | 42 | 1805 | abandoned |
| namshi/jose A lightweight PHP library implementing the JWS (JSON Web Signature) specification for signing and verifying JSON tokens, commonly used for … | 32 | 1804 | abandoned |
| KEV0143/Direct-memory-access-CS2-DMA A C++ framework demonstrating Direct Memory Access (DMA) interaction with Counter-Strike 2, covering memory reading, entity-state parsing, … | 62 | 1787 | abandoned |
| dephell/dephell DepHell is an all-in-one Python project management CLI that converts between dependency formats (setup.py, requirements.txt, Pipfile, poetr… | 10 | 1786 | abandoned |
| Netflix/lemur Lemur is a TLS certificate management and orchestration service that acts as a broker between certificate authorities and environments, pro… | 10 | 1772 | abandoned |
| kpwn/yalu102 Yalu102 is an incomplete, work-in-progress jailbreak for 64-bit iOS devices running iOS 10.0 through 10.2, created by qwertyoruiopz and mar… | 32 | 1762 | abandoned |
| govolution/avet AVET (AntiVirus Evasion Tool) is a shell-based toolbox for pentesters to build Windows executables that evade antivirus detection, using te… | 40 | 1755 | abandoned |
| okTurtles/dnschain DNSChain is a blockchain-based DNS and HTTPS server that provides a decentralized, MITM-proof alternative to the traditional DNS and X.509 … | 23 | 1732 | abandoned |
| pilcrowonpaper/arctic Arctic is a TypeScript library providing OAuth 2.0 client implementations for popular providers like Google and GitHub, handling authorizat… | 72 | 1717 | abandoned |
| desaster/kippo Kippo is a medium-interaction SSH honeypot written in Python that logs brute-force attacks and records the full shell interaction of attack… | 23 | 1715 | abandoned |
| xdavidhu/mitmAP A Python program that creates a fake wireless access point and performs man-in-the-middle data sniffing using tools like SSLstrip2, mitmpro… | 10 | 1694 | abandoned |
| Cisco-Talos/pyrebox PyREBox is a Python-scriptable reverse engineering sandbox built on QEMU that provides whole-system dynamic analysis and debugging of runni… | 10 | 1683 | abandoned |
| google/novm novm is an experimental, legacy-free type 2 hypervisor (VMM) written in Go that leverages the Linux KVM interface to run guest instances. I… | 10 | 1676 | abandoned |
| chaitin/passionfruit Passionfruit is a web-based GUI tool for blackbox assessment of iOS apps, built on the Frida instrumentation framework and Vue.js. It lets … | 10 | 1668 | abandoned |
| sc1341/InstagramOSINT A Python CLI tool and importable module that scrapes publicly available profile information from Instagram accounts, such as follower count… | 10 | 1656 | abandoned |
| stypr/clubhouse-py A Python implementation of the Clubhouse social audio API, including a standalone desktop client. It was created for security research and … | 10 | 1655 | abandoned |
| nodesecurity/nsp nsp is the Node Security Platform command-line tool that checks Node.js projects for known vulnerabilities in their dependencies, with CVSS… | 10 | 1653 | abandoned |
| getqujing/qtunnel qTunnel is a lightweight Go-based network tunneling tool that acts as an encryption wrapper between clients and servers, serving as a simpl… | 32 | 1643 | abandoned |
| ZFC-Digital/puppeteer-real-browser A Node.js library that wraps Puppeteer with a real-browser profile to bypass bot detection systems like Cloudflare and Turnstile captchas. … | 34 | 1641 | abandoned |
| DesignativeDave/androrat Androrat is a client/server Remote Administration Tool for Android devices, with the client written in Java Android and the server in Java/… | 32 | 1636 | abandoned |
| Tlaster/YourAV YourAV is a lightweight, open-source Windows application that registers itself as an antivirus in the Windows Security Center, which causes… | 23 | 1633 | abandoned |
| pallets-eco/flask-security-3.0 Flask-Security 3.0 is a Flask extension providing quick and simple authentication and security features such as login, registration, and ro… | 10 | 1624 | abandoned |
| ldapjs/node-ldapjs An LDAP client and server API library for Node.js, enabling directory authentication and LDAP protocol operations in JavaScript. The projec… | 10 | 1623 | abandoned |
| base/pessimism Pessimism is a self-hosted monitoring service that continuously assesses OP Stack and EVM-compatible blockchains for real-time threats usin… | 10 | 1614 | abandoned |
| jokermonn/permissions4m permissions4m is an Android runtime permission handling library built with compile-time annotations (APT), forked from MPermissions. It spe… | 10 | 1607 | abandoned |
| asLody/legend Legend is a Java method hooking framework for Android that works without root access, supporting both Dalvik and ART runtimes. It lets deve… | 32 | 1605 | abandoned |
| carmaa/inception Inception is a Python-based physical memory manipulation tool that exploits PCI-based DMA (over FireWire, Thunderbolt, ExpressCard, PC Card… | 34 | 1602 | abandoned |
| chinoogawa/fbht A Python 2 command-line tool for interacting with and scraping Facebook accounts, including graph-based analysis of social connections. It … | 23 | 1597 | abandoned |
| jrendel/SwiftKeychainWrapper A Swift wrapper around the iOS/tvOS Keychain that lets developers store and retrieve secure items with a User Defaults-like API. It provide… | 10 | 1590 | abandoned |
| anchore/anchore-engine Anchore Engine is an open-source service that inspects, analyzes, and certifies container images, scanning them against a vulnerability dat… | 10 | 1589 | abandoned |
| keraf/NoCoin No Coin is a small browser extension for Chrome, Firefox, and Opera that blocks browser-based coin miners such as Coinhive by blacklisting … | 10 | 1577 | abandoned |
| byt3bl33d3r/SprayingToolkit A set of Python 3 scripts for performing fast password spraying attacks against Lync/Skype for Business, OWA, IMAP, and Office 365, built o… | 10 | 1577 | abandoned |
| kryptco/kr A deprecated Go CLI tool that runs an SSH agent (krd) routing private key operations to a paired Krypton mobile app, so SSH authentication … | 10 | 1570 | abandoned |
| thiagoralves/OpenPLC_v3 OpenPLC Runtime version 3 is an open-source Programmable Logic Controller (PLC) runtime that executes ladder logic and other IEC 61131-3 pr… | 10 | 1570 | abandoned |
| zeustrojancode/Zeus A GitHub mirror of the leaked source code (version 2.0.8.9) of the Zeus trojan, a notorious Windows banking malware from 2007-2011 that sto… | 10 | 1568 | abandoned |