domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| 0xERR0R/blocky Blocky is a fast, lightweight DNS proxy and ad-blocker for local networks, written in Go. It blocks ads and malware via external allow/deny… | 98 | 6895 | active |
| lwthiker/curl-impersonate A special build of curl (and libcurl) whose TLS and HTTP/2 handshakes are identical to real browsers like Chrome, Edge, Safari, and Firefox… | 23 | 6895 | active |
| MacPass/MacPass MacPass is a native macOS KeePass password manager client that opens and manages KDBX password databases. It is written in Objective-C and … | 32 | 6855 | active |
| jstedfast/MailKit MailKit is a cross-platform .NET mail client library built on top of MimeKit, providing IMAP, POP3, and SMTP support along with a high-perf… | 76 | 6844 | stable |
| external-secrets/external-secrets External Secrets Operator is a Kubernetes operator that synchronizes secrets from external secret management systems such as AWS Secrets Ma… | 94 | 6808 | stable |
| CTFd/CTFd CTFd is an open-source Capture The Flag (CTF) platform built on Flask for hosting cybersecurity competitions and workshops. It provides cha… | 94 | 6807 | active |
| travist/jsencrypt JSEncrypt is a tiny, zero-dependency JavaScript library for OpenSSL-compatible RSA encryption, decryption, signing, and key generation. It … | 66 | 6804 | active |
| V2Ray An official Bash installer script (plus community config examples) that installs and manages V2Ray, a network proxy platform, on systemd-ba… | 32 | 6802 | active |
| urbanadventurer/WhatWeb WhatWeb is a command-line web scanner that identifies the technologies powering websites, including CMSs, web servers, JavaScript libraries… | 76 | 6800 | stable |
| fleetdm/fleet Fleet is an open-source device management (MDM) and security platform for IT and security teams, built on osquery. It provides cross-OS dev… | 95 | 6780 | stable |
| ticarpi/jwt_tool A Python command-line toolkit for validating, forging, scanning, and tampering with JSON Web Tokens (JWTs). It automates checks for known J… | 31 | 6754 | active |
| chaifeng/ufw-docker A shell-based tool that fixes the well-known security flaw where Docker bypasses UFW firewall rules and exposes published ports to the publ… | 69 | 6749 | active |
| AFLplusplus/AFLplusplus AFL++ is a superior, actively maintained fork of American Fuzzy Lop, a coverage-guided fuzzer with many mutators, power schedules, and inst… | 92 | 6736 | active |
| cppcheck-opensource/cppcheck Cppcheck is an open-source static analysis tool for C and C++ code that detects bugs, undefined behavior, and dangerous coding constructs w… | 87 | 6733 | stable |
| superagent-ai/superagent Superagent is an open-source SDK and platform for securing AI applications and agents, offering runtime guardrails that block prompt inject… | 78 | 6719 | active |
| bleachbit/bleachbit BleachBit is an open-source system cleaner for Windows and Linux that frees disk space and protects privacy by deleting caches, cookies, lo… | 95 | 6713 | stable |
| infobyte/faraday Faraday is an open-source vulnerability management platform that aggregates, normalizes, and deduplicates findings from over 90 security to… | 98 | 6695 | active |
| thephpleague/oauth2-server A standards-compliant OAuth 2.0 authorization server library for PHP, supporting all major grants (authorization code, client credentials, … | 87 | 6662 | stable |
| markbates/goth Goth is a Go library providing a simple, idiomatic way to add multi-provider authentication to web applications via OAuth, OAuth2, and Open… | 57 | 6597 | active |
| The-Z-Labs/linux-exploit-suggester A shell-based auditing tool that assesses a Linux system's exposure to publicly known kernel privilege escalation exploits based on kernel … | 65 | 6593 | active |
| OISF/suricata Suricata is a high-performance network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring… | 93 | 6571 | stable |
| BruceDevices/firmware Bruce is an open-source (AGPL-3.0) ESP32 firmware packed with offensive-security and Red Team tools such as WiFi attacks, Evil Portal, ward… | 90 | 6570 | active |
| j3ssie/osmedeus Osmedeus is a security-focused declarative orchestration engine that lets users define reconnaissance and vulnerability-scanning pipelines … | 93 | 6538 | active |
| bmrf/tron Tron is an automated Windows PC cleanup and disinfection script, implemented as a collection of batch files that orchestrate many community… | 65 | 6530 | active |
| EnableSecurity/wafw00f WAFW00F is a Python command-line tool that identifies and fingerprints Web Application Firewall (WAF) products protecting a website. It sen… | 79 | 6528 | stable |
| Mebus/cupp CUPP is a Python CLI tool that generates targeted password wordlists by profiling personal information about a user, such as birthdays, nic… | 74 | 6507 | active |
| cowrie/cowrie Cowrie is a medium-to-high interaction SSH and Telnet honeypot that logs brute-force attacks and full attacker shell sessions, capturing up… | 99 | 6504 | active |
| cloudquery/cloudquery CloudQuery is an open-source CLI and plugin-based data pipeline tool that extracts cloud infrastructure configuration and security data fro… | 95 | 6496 | active |
| MISP/MISP MISP is an open source threat intelligence platform for collecting, storing, correlating, and sharing cyber security indicators, malware an… | 99 | 6490 | stable |
| palera1n/palera1n palera1n is an open-source jailbreak tool for Apple devices using the checkm8 bootrom exploit, supporting A8 through A11 chips and T2 secur… | 88 | 6475 | active |
| lldap/lldap lldap is a lightweight LDAP authentication server written in Rust, providing an opinionated, simplified LDAP interface for user management.… | 81 | 6464 | active |
| opa334/Dopamine Dopamine is a rootless semi-untethered jailbreak tool for iOS 15 through 26.0.1, supporting arm64e and A12/A13 devices. It is written prima… | 98 | 6449 | active |
| apurvsinghgautam/robin Robin is an AI-powered dark web OSINT investigation tool that uses LLMs to refine queries, filter results from dark web search engines, and… | 84 | 6438 | active |
| BLAKE3-team/BLAKE3 The official Rust and C implementations of the BLAKE3 cryptographic hash function, which is faster than MD5, SHA-2, and BLAKE2 while remain… | 98 | 6398 | stable |
| zizmorcore/zizmor zizmor is a static analysis tool for CI/CD configurations, primarily GitHub Actions workflows, as well as Dependabot and pre-commit configs… | 84 | 6394 | active |
| lexiforest/curl_cffi curl_cffi is a Python binding for a curl-impersonate fork via cffi, providing an HTTP client that can impersonate browser TLS/JA3, HTTP/2, … | 99 | 6390 | active |
| s0md3v/Arjun Arjun is a Python command-line tool that discovers hidden HTTP query parameters for URL endpoints using a large dictionary of over 25,000 p… | 26 | 6385 | active |
| zmap/zmap ZMap is a fast, stateless single-packet network scanner written in C, designed for Internet-wide network surveys such as scanning the entir… | 90 | 6366 | active |
| microsoft/Detours Microsoft Detours is a C++ library for intercepting, monitoring, and instrumenting Win32 API calls on Windows via function hooking and bina… | 67 | 6364 | stable |
| expressjs/session express-session is official session middleware for the Express web framework that manages user sessions via cookies holding only a session … | 75 | 6358 | stable |
| crytic/slither Slither is a Python-based static analysis framework for Solidity and Vyper smart contracts. It runs vulnerability detectors, prints contrac… | 94 | 6352 | active |
| derailed/popeye Popeye is a read-only CLI tool that scans live Kubernetes clusters and reports potential issues with deployed resources and configurations.… | 59 | 6346 | active |
| snare/voltron Voltron is an extensible debugger UI toolkit written in Python that adds utility views (registers, disassembly, stack, memory, breakpoints,… | 25 | 6345 | active |
| dnSpy/dnSpy dnSpy is a Windows GUI application for debugging and editing .NET and Unity assemblies without needing source code. It combines a debugger,… | 10 | 29689 | maintenance |
| LSPosed/LSPosed.github.io The official website for LSPosed, an Xposed framework implementation for rooted Android devices, providing downloads and changelogs. It als… | 77 | 6315 | active |
| 5ec1cff/TrickyStore Tricky Store is a Magisk module for Android 10+ that modifies the certificate chain generated during Android key attestation to spoof devic… | 46 | 6315 | active |
| ikarus23/MifareClassicTool An Android NFC application for reading, writing, analyzing, and cloning MIFARE Classic RFID tags. It includes dictionary-based key manageme… | 83 | 6312 | active |
| google/syzkaller syzkaller is an unsupervised coverage-guided kernel fuzzer originally built for the Linux kernel and now supporting FreeBSD, Fuchsia, gViso… | 77 | 6309 | active |
| mviereck/x11docker x11docker is a shell-based CLI tool that runs graphical applications and entire desktop environments inside Docker, podman, or nerdctl cont… | 84 | 6303 | stable |
| dwisiswant0/apkleaks APKLeaks is a Python CLI tool that decompiles Android APK files with jadx and scans them for URIs, endpoints, and hardcoded secrets using r… | 39 | 6275 | active |
| infinition/Bjorn Bjorn is an autonomous network scanning and offensive security tool that runs on a Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers … | 63 | 6252 | active |
| Outline Outline is a pair of open-source applications from Jigsaw (Google) for creating and using your own VPN server: Outline Manager sets up and … | 71 | 6249 | active |
| sigstore/cosign Cosign is a CLI tool from the Sigstore project for signing and verifying OCI containers and other software artifacts, with support for keyl… | 98 | 6247 | stable |
| dehydrated-io/dehydrated Dehydrated is an ACME client for signing TLS certificates from CAs like Let's Encrypt and ZeroSSL, implemented as a single bash/zsh-compati… | 59 | 6244 | active |
| repowise-dev/repowise Repowise is a Python-based codebase intelligence tool that indexes code structure, call graphs, git history, tests, and architectural decis… | 77 | 6240 | active |
| gnuradio/gnuradio GNU Radio is a free and open-source signal processing runtime and development toolkit for building software-defined radios and simulating w… | 67 | 6236 | stable |
| auth0/java-jwt A Java library for creating and verifying JSON Web Tokens (JWT) per RFC 7519, supporting HMAC, RSA, and ECDSA signing algorithms. It is mai… | 92 | 6235 | active |
| PBH-BTN/PeerBanHelper PeerBanHelper is a self-hosted Java application that automatically bans unwanted, leeching, and abnormal BitTorrent peers by connecting to … | 88 | 6210 | active |
| androguard/androguard Androguard is a full Python tool and library for reverse engineering and analyzing Android files, including DEX/ODEX bytecode disassembly a… | 83 | 6209 | active |
| PhilippC/keepass2android Keepass2android is an open-source password manager app for Android, compatible with the KeePass 2.x database format. It stores credentials … | 97 | 6205 | active |
| projectdiscovery/naabu Naabu is a fast, lightweight port scanner written in Go that performs SYN, CONNECT, and UDP scans to enumerate open ports on hosts. It is d… | 89 | 6205 | active |
| Trusted-AI/adversarial-robustness-toolbox Adversarial Robustness Toolbox (ART) is a Python library for machine learning security covering evasion, poisoning, extraction, and inferen… | 55 | 6204 | stable |
| k8gege/K8tools K8tools is a large curated collection of penetration testing and offensive security tools covering internal network penetration, privilege … | 34 | 6203 | active |
| gitleaks/gitleaks Gitleaks is an open-source CLI tool for detecting secrets like passwords, API keys, and tokens in git repositories, files, directories, and… | 91 | 28965 | maintenance |
| GhostTroops/scan4all scan4all is a Go-based automated vulnerability scanning and reconnaissance tool that integrates vscan, nuclei, ksubdomain, and subfinder. I… | 23 | 6170 | active |
| SukiSU-Ultra/SukiSU-Ultra SukiSU-Ultra is a kernel-based Android root solution providing kernel-level su and root access management, with support for KPM kernel modu… | 82 | 6162 | active |
| mandiant/capa capa is Mandiant FLARE's open-source tool that identifies capabilities in executable files (PE, ELF, .NET, shellcode) by matching expert-wr… | 87 | 6156 | active |
| DominicBreuker/pspy pspy is a command line tool that snoops on Linux processes without root permissions by combining procfs scans with inotify watchers to catc… | 54 | 6155 | stable |
| cloud-hypervisor/cloud-hypervisor Cloud Hypervisor is an open source Virtual Machine Monitor (VMM) written in Rust that runs on top of KVM or Microsoft's MSHV hypervisor. It… | 93 | 6149 | active |
| guanzhi/GmSSL GmSSL is an open-source cryptographic toolkit developed at Peking University implementing Chinese national commercial cryptography standard… | 80 | 6147 | stable |
| azukaar/Cosmos-Server Cosmos-Server is a self-hosted home server platform that acts as a secure gateway and server manager for your applications. It bundles auth… | 93 | 6131 | active |
| AzeemIdrisi/PhoneSploit-Pro PhoneSploit Pro is an all-in-one Python CLI tool for remotely exploiting and testing Android devices using ADB and the Metasploit Framework… | 88 | 6128 | active |
| InterceptSuite/ProxyBridge ProxyBridge is a free, open-source universal proxy client (Proxifier alternative) that transparently redirects TCP and UDP traffic from any… | 80 | 6128 | active |
| Passbolt Passbolt Community Edition API is the JSON backend for the open source, security-first password manager for teams, built in PHP on CakePHP.… | 98 | 6095 | stable |
| AutoRecon/AutoRecon AutoRecon is a multi-threaded Python CLI tool that automates network reconnaissance by performing port and service detection scans, then la… | 61 | 6093 | active |
| anthropics/claude-code-security-review A GitHub Action that uses Anthropic's Claude to perform AI-powered security reviews of pull requests, analyzing code diffs for vulnerabilit… | 48 | 6093 | active |
| NextAuth.js Auth.js (formerly NextAuth.js) is an open-source, runtime-agnostic authentication library built on standard Web APIs, with deep integration… | 90 | 28345 | maintenance |
| mishakorzik/AllHackingTools AllHackingTools is an all-in-one installer and menu system for Termux that automates downloading and installing a large collection of penet… | 56 | 6083 | active |
| Azure/Azure-Sentinel The official community repository for Microsoft Sentinel, a cloud-native SIEM, containing out-of-the-box detections, hunting queries, workb… | 77 | 6076 | active |
| qilingframework/qiling Qiling is a Python-based binary emulation framework built on Unicorn Engine that emulates executables across multiple platforms (Windows, m… | 79 | 6075 | active |
| cloud-custodian/cloud-custodian Cloud Custodian (c7n) is a Python-based stateless rules engine for managing public cloud accounts and resources via YAML policy DSLs with f… | 90 | 6053 | stable |
| lesspass/lesspass LessPass is a stateless, open-source password manager that deterministically generates site-specific passwords from a single master passwor… | 76 | 6053 | active |
| gerardog/gsudo gsudo is a sudo equivalent for Windows that lets users run commands or relaunch shells with elevated permissions from the current console. … | 70 | 6034 | active |
| alpkeskin/mosint Mosint is an automated email OSINT tool written in Go that investigates target email addresses by consolidating multiple services. It check… | 23 | 6008 | active |
| Ed1s0nZ/CyberStrikeAI CyberStrikeAI is a Go-based AI-native cybersecurity platform that combines LLM-powered agents, MCP-native tools, RAG knowledge bases, and v… | 79 | 5991 | active |
| RfidResearchGroup/proxmark3 The Iceman fork of Proxmark3, the client software for the Proxmark3 RFID analysis device, supporting reading, cloning, simulating, and snif… | 88 | 5986 | active |
| Tencent/AI-Infra-Guard Tencent's full-stack AI red teaming platform that scans AI infrastructure, agents, MCP servers, and skills for vulnerabilities and evaluate… | 88 | 5984 | active |
| undergroundwires/privacy.sexy privacy.sexy is an open-source desktop application that enforces privacy and security best practices on Windows, macOS, and Linux. It provi… | 60 | 5983 | active |
| openpgpjs/openpgpjs OpenPGP.js is a pure JavaScript implementation of the OpenPGP protocol (RFC 9580), maintained by Proton Mail. It lets applications encrypt,… | 90 | 5969 | stable |
| Ackites/KillWxapkg A Go-based CLI tool that automatically decrypts, unpacks, and decompiles WeChat mini-program .wxapkg packages, restoring the original proje… | 14 | 5957 | active |
| TsudaKageyu/minhook MinHook is a minimalistic, lightweight C library for intercepting (hooking) x86 and x64 function calls on Windows, using a trampoline/detou… | 62 | 5955 | stable |
| ZoneMinder/zoneminder ZoneMinder is an open-source video surveillance (CCTV) application for Linux that captures, records, analyzes, and monitors security camera… | 94 | 5919 | stable |
| FluxionNetwork/fluxion Fluxion is a security auditing and social-engineering research tool that retrieves WPA/WPA2 keys via phishing attacks using rogue access po… | 91 | 5907 | active |
| golang/oauth2 The official Go client implementation of the OAuth 2.0 specification, maintained by the Go team. It provides token acquisition, refresh, an… | 77 | 5896 | stable |
| vimeo/psalm Psalm is an open-source static analysis tool for PHP that finds type-related bugs and security vulnerabilities through type inference and t… | 88 | 5884 | active |
| lanmaster53/recon-ng Recon-ng is a full-featured, modular reconnaissance framework for conducting web-based open source intelligence (OSINT) gathering. It offer… | 32 | 5871 | active |
| microsoft/sudo Sudo for Windows is a Windows-specific implementation of the sudo concept, letting users run elevated commands directly from unelevated ter… | 70 | 5856 | active |
| Dicklesworthstone/destructive_command_guard A high-performance Rust CLI hook that intercepts and blocks destructive git and shell commands before AI coding agents execute them. It int… | 83 | 5840 | active |
| sammwyy/MikuMikuBeam MikuMikuBeam is a network stress testing tool written in Go with a Hatsune Miku-themed web UI, supporting HTTP flood, HTTP bypass, Slowlori… | 63 | 5835 | active |
| RedSiege/EyeWitness EyeWitness is a Python CLI tool that takes screenshots of websites using headless Chromium, captures server header information, and identif… | 50 | 5829 | active |