domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| technoweenie/restful-authentication A widely-used Ruby on Rails plugin/generator that provides a foundation for user authentication, including login/logout, secure password ha… | 10 | 1564 | abandoned |
| viper-framework/viper Viper is a Python-based binary analysis and management framework for organizing collections of malware and exploit samples along with analy… | 10 | 1562 | abandoned |
| SpiderOak/Encryptr Encryptr is a zero-knowledge, cloud-based password manager and e-wallet built on the Crypton framework by SpiderOak. It stores passwords, c… | 23 | 1559 | abandoned |
| SofianeHamlaoui/Lockdoor-Framework Lockdoor Framework is a Python-based penetration testing framework that bundles a curated selection of security tools (information gatherin… | 34 | 1549 | abandoned |
| nucypher/zerodb ZeroDB is an end-to-end encrypted database built on ZODB, allowing data to be stored and queried on untrusted servers without exposing encr… | 10 | 1546 | abandoned |
| sailro/Reflexil Reflexil is a .NET assembly editor that runs as a plugin for Reflector, ILSpy, and JustDecompile. Built on Mono.Cecil, it can manipulate IL… | 10 | 1529 | abandoned |
| naoufal/react-native-touch-id A React Native library for authenticating users via biometric authentication, showing the native Touch ID / Face ID popup on iOS and experi… | 23 | 1527 | abandoned |
| cartalyst/sentry Sentry is a deprecated, framework-agnostic PHP authentication and authorization library providing user groups, permissions, activation, thr… | 32 | 1525 | abandoned |
| scottyab/secure-preferences An Android library that wraps SharedPreferences to encrypt stored values with AES-128/CBC and hash keys with SHA-256. It is deprecated in f… | 10 | 1518 | abandoned |
| ravenac95/sudolikeaboss sudolikeaboss is a macOS command-line tool that lets users retrieve passwords from the 1Password desktop app directly in iTerm2, e.g. to fi… | 10 | 1504 | abandoned |
| szhu/3030 A novelty browser game built around the 2015 Chrome %%30%30 URL-canonicalization crash bug, where hovering over tree links crashes vulnerab… | 32 | 1503 | abandoned |
| mitchellh/gon gon is a macOS CLI tool and Go library for code signing, notarizing, and packaging (dmg/zip) binaries and applications written in any langu… | 10 | 1497 | abandoned |
| fossasia/KikiAuth KikiAuth is a LuCI-based OpenWrt application that acts as an alternative auth server for WifiDog, enabling captive-portal authentication vi… | 32 | 1493 | abandoned |
| mesalock-linux/mesalink MesaLink is a memory-safe TLS library written in Rust that provides an OpenSSL-compatible C API, implemented on top of rustls, webpki, and … | 23 | 1483 | abandoned |
| ring04h/wydomain wydomain is a Python command-line tool for discovering subdomains of a target domain. It combines dictionary-based DNS bruteforcing with qu… | 32 | 1479 | abandoned |
| D4Vinci/Dr0p1t-Framework Dr0p1t-Framework is a Python-based penetration testing framework that generates stealthy Windows dropper executables designed to bypass ant… | 10 | 1473 | abandoned |
| IBM/fhe-toolkit-linux IBM's Fully Homomorphic Encryption Toolkit for Linux, a Docker-based toolkit demonstrating computation on encrypted data without decryption… | 10 | 1472 | abandoned |
| AeonLucid/SnapHide SnapHide is an iOS jailbreak tweak written in Logos that hides jailbreak evidence and hook traces from the Snapchat app. It was developed t… | 32 | 1470 | abandoned |
| ilektrojohn/creepy Creepy is a geolocation OSINT application that gathers location-related information about targets from social networking platforms. It pres… | 23 | 1470 | abandoned |
| jseidl/GoldenEye GoldenEye is a Python 3 command-line tool for testing HTTP servers against Layer 7 denial-of-service attacks using the HTTP KeepAlive + NoC… | 10 | 1469 | abandoned |
| 9p4/jellyfin-plugin-sso A Jellyfin server plugin that enables single sign-on (SSO) login through external identity providers such as Google, Microsoft, Keycloak, A… | 10 | 1460 | abandoned |
| hteso/iaito Iaitō is a Qt and C++ graphical user interface for the radare2 reverse engineering framework, aimed at users who find radare2's CLI too dif… | 32 | 1457 | abandoned |
| OpenRCE/sulley Sulley is a pure-Python fuzzing engine and framework for automated, unattended fuzz testing of network protocols and targets. It handles da… | 23 | 1450 | abandoned |
| das-labor/panopticon Panopticon is a libre, cross-platform disassembler written in Rust for reverse engineering binaries. It supports AMD64, x86, AVR, and MOS 6… | 10 | 1445 | abandoned |
| Lucifer1993/AngelSword AngelSword is a simple CMS vulnerability detection framework written in Python3, designed to help security engineers quickly discover known… | 32 | 1441 | abandoned |
| SpenserCai/GoWxDump GoWxDump was a Windows CLI tool for extracting WeChat account information such as decryption keys and user data from local installations. T… | 58 | 1439 | abandoned |
| dark-kingA/superSearchPlus superSearchPlus is a Chrome browser extension that aggregates information gathering for white-hat hackers, integrating common asset mapping… | 32 | 1435 | abandoned |
| cisagov/Sparrow Sparrow.ps1 is a PowerShell script from CISA's Cloud Forensics team that helps incident responders detect possibly compromised accounts and… | 10 | 1430 | abandoned |
| bumptech/stud Stud is a scalable TLS/SSL termination proxy that unwraps encrypted connections and forwards plaintext traffic to a backend like HAProxy or… | 10 | 1422 | abandoned |
| cloudflare/redoctober Red October is a Go-based TLS server implementing two-man rule style encryption and decryption, where no single individual can decrypt data… | 10 | 1418 | abandoned |
| Tygs/0bin 0bin is a self-hostable pastebin that encrypts paste content client-side in the browser with AES256, so the server never sees plaintext or … | 39 | 1404 | abandoned |
| ReversecLabs/needle Needle is an open-source, modular Python framework for streamlining security assessments of iOS applications, covering areas like data stor… | 10 | 1401 | abandoned |
| ValdikSS/blockcheck BlockCheck is a Python utility that detects the type of website blocking used by Russian ISPs, including DNS tampering, DPI filtering, SSL … | 10 | 1391 | abandoned |
| jvns/dnspeep dnspeep is a Rust command-line tool that captures DNS packets on port 53 using libpcap and displays DNS queries and responses together in r… | 23 | 1383 | abandoned |
| aquasecurity/starboard Starboard is a Kubernetes-native security toolkit that integrates heterogeneous security scanners and exposes their results as Kubernetes C… | 85 | 1380 | abandoned |
| sslab-gatech/Rudra Rudra is a static analyzer that detects common undefined behaviors and memory safety issues in Rust programs, capable of analyzing single p… | 10 | 1367 | abandoned |
| danilop/LambdAuth LambdAuth is a sample serverless authentication service built on AWS Lambda with Amazon DynamoDB for user storage. It handles user signup w… | 23 | 1364 | abandoned |
| hahwul/XSpear XSpear is a Ruby-based XSS (cross-site scripting) scanner and parameter analysis tool distributed as a gem, usable both as a CLI and as a R… | 10 | 1364 | abandoned |
| zyq8709/DexHunter DexHunter is an automatic unpacking tool for Android Dex files protected by app-hardening services. It works by replacing the ART and DVM r… | 32 | 1358 | abandoned |
| byt3bl33d3r/gcat Gcat is a proof-of-concept Python backdoor that uses a Gmail account as its command-and-control channel, with an implant deployed on target… | 10 | 1351 | abandoned |
| WWILLV/GodOfHacker GodOfHacker is a satirical C# 'hacker all-in-one tool' whose feature list is intentionally absurd (one-click 0day attacks, stealing QQ acco… | 23 | 1342 | abandoned |
| vbuterin/pybitcointools A simple, common-sense Python library for Bitcoin-themed elliptic curve cryptography (secp256k1), including key handling, signing, and tran… | 32 | 1331 | abandoned |
| gorhill/httpswitchboard HTTP Switchboard is a Chromium browser extension that lets users point-and-click whitelist or blacklist network requests per domain and req… | 10 | 1330 | abandoned |
| hackappcom/ibrute A Python proof-of-concept tool that brute-forces AppleID passwords via the Find My iPhone service API, which lacked bruteforce protection. … | 32 | 1322 | abandoned |
| djenriquez/vault-ui Vault-UI is a graphical web and desktop interface for managing HashiCorp Vault, written in React with a Material UI design. It can be deplo… | 10 | 1313 | abandoned |
| linisme/Cipher.so A Gradle plugin for Android that packages key-value secrets (like API keys and passwords) into an encrypted native .so library at compile t… | 32 | 1306 | abandoned |
| aspnet/Security The former home of security and authorization middleware for ASP.NET Core, including authentication handlers for cookies, OAuth, and social… | 10 | 1293 | abandoned |
| elvanderb/TCP-32764 A collection of Python proof-of-concept code and research notes documenting a hidden backdoor listening on TCP port 32764 in Linksys, Netge… | 32 | 1291 | abandoned |
| hardware/mailserver A simple and full-featured mail server distributed as a set of Docker images, bundling Postfix, Dovecot, Rspamd, ClamAV, Sieve, Fetchmail, … | 10 | 1288 | abandoned |
| clymb3r/PowerShell A collection of useful PowerShell scripts, most notably security and penetration testing tools that were contributed to PowerSploit. The re… | 32 | 1284 | abandoned |
| cisagov/log4j-scanner A CISA-derived scanner for detecting web services vulnerable to the Log4Shell remote code execution vulnerabilities (CVE-2021-44228 and CVE… | 10 | 1278 | abandoned |
| lanx-x/VRouter VRouter is a desktop application that runs a lightweight OpenWRT virtual machine via VirtualBox to provide transparent TCP/UDP proxying on … | 10 | 1277 | abandoned |
| lachesis/scallion Scallion is a GPU-accelerated (OpenCL) vanity key generator that creates custom .onion addresses for Tor hidden services and vanity GPG key… | 23 | 1275 | abandoned |
| YelpArchive/dockersh dockersh is a login shell written in Go that places each interactive user into their own individual Docker container when they log in. It c… | 10 | 1274 | abandoned |
| ClaudiuGeorgiu/Obfuscapk Obfuscapk is a modular Python tool that obfuscates Android APKs and App Bundles in a black-box fashion, without needing source code, by dec… | 10 | 1272 | abandoned |
| uknowsec/SharpDecryptPwd SharpDecryptPwd is a Windows command-line tool that decrypts passwords saved locally by popular applications such as Navicat, TeamViewer, F… | 32 | 1271 | abandoned |
| forseti-security/forseti-security Forseti Security is a collection of open-source tools for auditing and improving the security of Google Cloud Platform environments, includ… | 10 | 1269 | abandoned |
| woj-ciech/kamerka Kamerka is a Python CLI script that builds an interactive map of internet-exposed cameras, printers, tweets, and photos around given coordi… | 10 | 1267 | abandoned |
| crmulliner/adbi ADBI is a dynamic binary instrumentation toolkit for Android ARM and Thumb binaries, based on library injection and inline hooking of funct… | 32 | 1266 | abandoned |
| samyk/usbdriveby USBdriveby is an Arduino/Teensy microcontroller project that emulates a USB HID keyboard and mouse to covertly install a backdoor, evade fi… | 32 | 1265 | abandoned |
| KrauseFx/detect.location A proof-of-concept iOS library and demo app that extracts a user's location history from photo metadata in the image library, without requi… | 32 | 1256 | abandoned |
| LOoLzeC/ASU ASU is a Python-based Facebook hacking toolkit offering account checking and spamming features, distributed via a Termux/Linux install scri… | 32 | 1252 | abandoned |
| privacypass/challenge-bypass-extension A browser extension implementing the client side of the Privacy Pass protocol, which issues and redeems unlinkable cryptographic tokens (ba… | 26 | 1250 | abandoned |
| vaycore/OneScan OneScan is a BurpSuite extension written in Java for recursive directory scanning, helping discover hidden vulnerabilities in deeper direct… | 10 | 1250 | abandoned |
| ldandersen/scifihifi-iphone A collection of open-source iPhone/Objective-C code, best known for SFHFKeychainUtils, a simple wrapper for storing credentials in the iOS … | 32 | 1249 | abandoned |
| tomer8007/widevine-l3-decryptor A Chrome extension that demonstrated bypassing Widevine L3 DRM by hijacking Encrypted Media Extensions calls to extract content decryption … | 10 | 1247 | abandoned |
| n0tr00t/Sreg Sreg is a Python CLI OSINT tool that checks whether an email, phone number, or username has been used to register accounts across many Chin… | 32 | 1245 | abandoned |
| pq-crystals/kyber The official reference implementation of the Kyber key encapsulation mechanism (ML-KEM), a NIST-standardized post-quantum KEM, written in C… | 75 | 1237 | abandoned |
| optiv/Mangle Mangle is a Go-based CLI tool that manipulates compiled Windows executables (.exe and DLL) to evade EDR detection. It strips known indicato… | 10 | 1235 | abandoned |
| Ha3MrX/Gemail-Hack A Python command-line script that performs brute-force password attacks against Gmail accounts. It is a simple educational/offensive-securi… | 66 | 1234 | abandoned |
| magus/react-native-facebook-login A React Native component that wraps the native Facebook SDK login button and login manager for iOS and Android. It provides callbacks for l… | 23 | 1233 | abandoned |
| genuinetools/bane bane is a Go command-line tool that generates custom AppArmor security profiles for Docker containers from a declarative TOML config file. … | 23 | 1229 | abandoned |
| the-robot/sqliv SQLiv is a Python command-line tool that scans websites for SQL injection vulnerabilities. It supports dork-based scanning via search engin… | 10 | 1229 | abandoned |
| hfiref0x/TDL TDL is a Windows x64 driver loader that bypasses Driver Signature Enforcement by exploiting a VirtualBox kernel vulnerability to map specia… | 10 | 1227 | abandoned |
| 0xlousie/OSIF OSIF is a Python command-line tool that gathers sensitive information from Facebook accounts, such as residence, date of birth, occupation,… | 32 | 1223 | abandoned |
| sakurity/securelogin SecureLogin is a decentralized passwordless authentication protocol that derives a cryptographic key pair from a user's email and master pa… | 32 | 1209 | abandoned |
| mozilla/mig MIG (Mozilla InvestiGator) is a distributed platform for real-time digital forensics and endpoint investigation, using agents installed acr… | 10 | 1202 | abandoned |
| FeezyHendrix/Insta-mass-account-creator A Python CLI tool that automatically mass-creates Instagram accounts, generating disposable email addresses, fetching OTPs, and populating … | 10 | 1200 | abandoned |
| nathanl/authority Authority is a Ruby gem that helps you authorize actions in Rails apps by grouping models under Authorizer classes with plain Ruby methods.… | 10 | 1197 | abandoned |
| fabpot/local-php-security-checker A command-line tool that checks PHP applications using Composer for dependencies with known security vulnerabilities, backed by the Friends… | 10 | 1182 | abandoned |
| creditease-sec/insight Insight is a self-hosted security management platform from CreditEase that combines application system asset management, full vulnerability… | 10 | 1182 | abandoned |
| Zizaco/confide Confide is an authentication package for Laravel 4 that reduces repetitive work in user account management. It provides account creation, l… | 23 | 1179 | abandoned |
| 4x99/code6 Code6 (码小六) is a self-hosted web application that monitors GitHub for leaked code and secrets, scanning periodically and alerting via email… | 23 | 1177 | abandoned |
| diafygi/acme-nosudo A Python script that obtains free HTTPS certificates from the Let's Encrypt CA via the ACME protocol without requiring root or sudo access.… | 32 | 1172 | abandoned |
| DylanPiercey/auto-sni A NodeJS library that automatically obtains and renews free SSL/TLS certificates from Let's Encrypt using SNI, with near-zero configuration… | 32 | 1172 | abandoned |
| SecurityFTW/cs-suite Cloud Security Suite (cs-suite) is a command-line audit tool that checks the security posture of AWS, GCP, Azure, and DigitalOcean accounts… | 32 | 1171 | abandoned |
| tomchop/malcom Malcom is a Python web application that analyzes network traffic (including pcaps) and visualizes malware communications as graphs, cross-r… | 23 | 1171 | abandoned |
| nhost/hasura-backend-plus Hasura Backend Plus is a self-hosted service providing authentication (JWT, OAuth providers, MFA) and S3-compatible file storage APIs desig… | 23 | 1170 | abandoned |
| remix-project-org/remix Remix is a suite of JavaScript modules for Ethereum smart contract development, covering compilation, static analysis, debugging, and unit … | 10 | 1167 | abandoned |
| DeimosC2/DeimosC2 DeimosC2 is a Golang-based command and control (C2) framework for post-exploitation, supporting TCP, HTTPS, DoH, and QUIC agent communicati… | 30 | 1160 | abandoned |
| openstack-archive/bandit Bandit is a Python AST-based static analysis tool from the OpenStack Security Group that finds common security issues in Python code. This … | 10 | 1158 | abandoned |
| anubhavanonymous/XLR8_BOMBER XLR8_BOMBER is a Python command-line script that floods an Indian phone number with repeated SMS messages, calls, and WhatsApp messages by … | 32 | 1156 | abandoned |
| cemerick/friend Friend is an extensible authentication and authorization library for Clojure Ring web applications and services. It provides authentication… | 10 | 1152 | abandoned |
| fit2cloud/riskscanner RiskScanner is an open-source multi-cloud security compliance scanning platform built on Cloud Custodian, Prowler, and Nuclei engines. It p… | 10 | 1152 | abandoned |
| pilcrowonpaper/oslo Oslo is a zero-dependency TypeScript collection of auth-related utilities covering JWTs, OAuth2, password hashing, OTP, WebAuthn, cookies, … | 10 | 1148 | abandoned |
| xillwillx/skiptracer Skiptracer is a Python-based OSINT web scraping framework that aggregates paid and free lookup services to enumerate target information suc… | 23 | 1147 | abandoned |
| zendesk/helm-secrets A deprecated Helm plugin that manages encrypted secrets files (YAML/JSON) within Git workflows, using SOPS as its backend for per-value enc… | 10 | 1146 | abandoned |
| cryptosphere/cryptosphere Cryptosphere is a global peer-to-peer cryptosystem for publishing and securely distributing content pseudonymously with no central point of… | 10 | 1144 | abandoned |
| uswitch/kiam Kiam is a Kubernetes agent that lets pods assume AWS IAM roles by intercepting EC2 Metadata API requests and serving STS credentials per-po… | 10 | 1143 | abandoned |
| ring04h/weakfilescan A Python-based multi-threaded sensitive information leakage detection tool that crawls a target site, dynamically builds dictionary rules f… | 32 | 1140 | abandoned |