domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| commixproject/commix Commix (short for command injection exploiter) is an open-source penetration testing tool that automates the detection and exploitation of … | 75 | 5824 | active |
| mscdex/ssh2 SSH2 client and server modules written in pure JavaScript for Node.js. It supports exec, shell, SFTP, port forwarding, and custom HTTP(S) a… | 76 | 5816 | stable |
| jedisct1/dsvpn DSVPN is a dead-simple, single-binary VPN tool written in C that tunnels traffic over TCP with modern, formally verified cryptography. It r… | 68 | 5816 | stable |
| Pennyw0rth/NetExec NetExec (nxc) is a community-maintained, open-source network execution tool and successor to CrackMapExec, used for pentesting and red-team… | 74 | 5815 | active |
| 34306/vphone-aio A single shell script that downloads, assembles, and runs a pre-built virtualized iOS environment (vphone) on macOS, complete with a jailbr… | 46 | 5805 | active |
| win-acme/win-acme win-acme is an ACMEv2 client for Windows that automates obtaining and installing SSL/TLS certificates from Let's Encrypt, ZeroSSL, and othe… | 62 | 5787 | active |
| windtf/wireproxy wireproxy is a userspace WireGuard client written in Go that exposes a WireGuard connection as a SOCKS5/HTTP proxy or TCP tunnels, without … | 97 | 5771 | active |
| rack/rack-attack Rack::Attack is Rack middleware for protecting Ruby and Rails web applications from abusive clients. It lets you define rules to allow, blo… | 68 | 5763 | stable |
| smol-machines/smolvm smolvm is an open-source CLI and runtime for running lightweight, hardware-isolated Linux microVMs locally on macOS, Linux, and Windows, bu… | 79 | 5756 | active |
| laravel/socialite Laravel Socialite is a first-party Laravel package providing a fluent interface for OAuth 1 and OAuth 2 social authentication. It handles t… | 99 | 5745 | stable |
| letsencrypt/boulder Boulder is the Go implementation of an ACME-based certificate authority that powers Let's Encrypt. It automates domain validation and issua… | 95 | 5742 | active |
| dependabot/dependabot-core Dependabot-Core is the Ruby library powering GitHub's Dependabot automated dependency updates. It resolves and updates dependencies across … | 95 | 5738 | active |
| elceef/dnstwist dnstwist is a Python command-line tool that generates permutations of a domain name (typos, homoglyphs, IDN tricks) and checks which ones r… | 30 | 5730 | active |
| yonggekkk/argosbx ArgoSBX is a one-click, non-interactive shell script ('little cannon') that deploys proxy servers on VPS or Docker by combining Sing-box, X… | 52 | 5722 | active |
| pfsense/pfsense pfSense is a free, open-source network firewall and router distribution based on FreeBSD with a custom kernel, managed entirely through a w… | 66 | 5721 | stable |
| seL4/seL4 seL4 is a formally verified microkernel operating system kernel written in C, providing high-assurance isolation and capability-based secur… | 89 | 5717 | active |
| freedomofpress/dangerzone Dangerzone is a desktop application from Freedom of the Press Foundation that converts untrusted documents (PDFs, office files, images) int… | 88 | 5715 | active |
| dotenvx/dotenvx Dotenvx is a secure, cross-platform CLI and SDK for managing .env files, adding encryption so secrets can be safely committed to git and de… | 89 | 5707 | active |
| jpadilla/pyjwt PyJWT is a Python library implementing JSON Web Tokens (JWT) per RFC 7519, supporting encoding and decoding of signed tokens. It is the de … | 90 | 5694 | stable |
| EFForg/rayhunter Rayhunter is an EFF-developed Rust tool that detects IMSI catchers (cell-site simulators, also known as stingrays) used for cellular survei… | 93 | 5688 | active |
| CanCanCommunity/cancancan CanCanCan is an authorization library for Ruby and Ruby on Rails that restricts which resources a user can access. Permissions are defined … | 66 | 5686 | stable |
| elder-plinius/T3MP3ST T3MP3ST is a multi-agent offensive-security framework that turns existing AI coding agents (Claude Code, Codex, Ollama, etc.) into autonomo… | 58 | 5684 | active |
| gilbertchen/duplicacy Duplicacy is a cross-platform cloud backup tool built around lock-free deduplication, allowing multiple computers to back up to the same st… | 69 | 5670 | stable |
| openfga/openfga OpenFGA is a high-performance, open-source fine-grained authorization and permission engine inspired by Google's Zanzibar, owned by the CNC… | 99 | 5661 | stable |
| burrowers/garble Garble is a CLI tool that obfuscates Go binaries by wrapping the Go toolchain's compiler and linker. It replaces identifiers, package paths… | 89 | 5659 | active |
| ossf/scorecard OpenSSF Scorecard is an automated tool that scores open source projects on security best practices through a series of checks. It can be ru… | 88 | 5653 | active |
| snyk/cli The Snyk CLI is a command-line tool that scans projects for security vulnerabilities across open-source dependencies, application code, con… | 99 | 5649 | active |
| LongSoft/UEFITool UEFITool is a cross-platform C++/Qt application that parses UEFI-compatible firmware images into a tree structure, verifies their integrity… | 90 | 5642 | active |
| geo-tp/ESP32-Bit-Pirate ESP32 Bit Pirate is open-source C++ firmware that turns an ESP32-S3 board into a multi-protocol hardware debugging and analysis workbench, … | 84 | 5634 | active |
| next-terminal/next-terminal Next Terminal is an open-source bastion host (jump server) and interactive session auditing system supporting SSH, RDP, VNC, Telnet, HTTP, … | 99 | 5612 | active |
| google/clusterfuzz ClusterFuzz is Google's scalable fuzzing infrastructure that finds security and stability bugs in software, serving as the backend for OSS-… | 95 | 5597 | active |
| pk910/PoWFaucet A self-hostable, modularized faucet for EVM-compatible blockchain testnets that distributes test ETH with multiple bot-protection mechanism… | 94 | 5597 | active |
| caddyserver/certmagic CertMagic is a Go library that provides fully-managed automatic HTTPS, handling TLS certificate issuance, renewal, and OCSP stapling via AC… | 89 | 5588 | stable |
| phpseclib/phpseclib A MIT-licensed pure-PHP library providing implementations of SSH-2, SFTP, X.509/CSR/CRL/PFX/CMS, and a wide range of cryptographic primitiv… | 99 | 5585 | stable |
| trustedsec/ptf The PenTesters Framework (PTF) is a Python-based modular framework that installs, compiles, and keeps penetration testing tools up to date … | 32 | 5558 | active |
| lief-project/LIEF LIEF is a cross-platform C++ library (with Python and Rust bindings) for parsing, inspecting, modifying, and writing executable file format… | 97 | 5549 | stable |
| the1812/Malware-Patch A Windows utility that blocks administrator (UAC) authorization for specified software, such as known Chinese rogueware, using digital sign… | 77 | 5546 | active |
| Dr-TSNG/Hide-My-Applist An Xposed module for rooted Android devices that hides installed apps from other apps' package list queries. It intercepts app list detecti… | 88 | 5539 | active |
| OWASP/Nettacker OWASP Nettacker is a Python-based automated penetration testing and information-gathering framework for reconnaissance, vulnerability scann… | 88 | 5535 | active |
| tonarino/innernet innernet is a self-hosted private network (overlay VPN) system built on WireGuard, with a coordination server and client CLI written in Rus… | 86 | 5535 | active |
| doorkeeper-gem/doorkeeper Doorkeeper is a Ruby gem (Rails engine) that adds OAuth 2.0 provider functionality to Ruby on Rails or Grape applications. It implements th… | 94 | 5521 | stable |
| permitio/opal OPAL (Open Policy Administration Layer) is an administration layer for policy engines such as Open Policy Agent (OPA) and Cedar Agent. It d… | 94 | 5505 | active |
| USArmyResearchLab/Dshell Dshell is an extensible network forensic analysis framework written in Python for dissecting network packet captures (pcap/pcapng). It supp… | 23 | 5492 | active |
| binpash/try try is a command-line tool that lets you run a command and inspect its effects before committing changes to your live system. It uses Linux… | 81 | 5490 | active |
| intel/hyperscan Hyperscan is a high-performance C library (written in C++) for simultaneously matching large numbers of regular expressions, using hybrid a… | 67 | 5475 | stable |
| charmbracelet/wish Wish is a Go library for building custom SSH applications, built on gliderlabs/ssh with sensible defaults and a middleware system analogous… | 93 | 5470 | active |
| xjasonlyu/tun2socks A Go-based tool that transparently routes all network traffic from any application through a proxy (SOCKS4/5, HTTP, Shadowsocks, SSH, WireG… | 84 | 5461 | active |
| scribejava/scribejava ScribeJava is a simple, threadsafe OAuth client library for Java supporting OAuth 1.0a and OAuth 2.0 flows. It ships prebuilt API integrati… | 60 | 5455 | stable |
| dev-sec/ansible-collection-hardening An Ansible collection of battle-tested hardening roles for Linux operating systems, SSH, nginx, and MySQL/MariaDB. It automates secure conf… | 90 | 5450 | active |
| Hackplayers/evil-winrm Evil-WinRM is a Ruby-based command-line WinRM shell designed for hacking and penetration testing of Windows servers. It supports features l… | 79 | 5448 | active |
| docker-easyconnect/docker-easyconnect A Docker/Podman image that runs Sangfor's proprietary EasyConnect and aTrust VPN clients inside containers, exposing socks5 and HTTP proxie… | 64 | 5429 | active |
| 3proxy/3proxy 3proxy is a tiny, free proxy server written in C supporting SOCKS, HTTP, HTTPS, FTP, and TLS proxying with traffic shaping, port mapping, a… | 99 | 5421 | stable |
| Speykious/cve-rs cve-rs is a joke/educational Rust crate that reproduces classic memory vulnerabilities (use-after-free, buffer overflow, segfault) using on… | 36 | 5420 | active |
| drk1wi/Modlishka Modlishka is an open-source penetration testing tool written in Go that acts as a transparent man-in-the-middle reverse proxy. It can proxy… | 66 | 5407 | active |
| authlib/authlib Authlib is a Python library for building OAuth 1.0/2.0 and OpenID Connect clients, authorization servers, and protected resource servers, w… | 93 | 5406 | stable |
| cjdelisle/cjdns Cjdns is an encrypted IPv6 networking implementation that uses public-key cryptography for address allocation and a distributed hash table … | 73 | 5406 | active |
| ory/keto Ory Keto is an open-source authorization server implementing Google's Zanzibar model for scalable, low-latency permission checks. It suppor… | 80 | 5390 | active |
| hickory-dns/hickory-dns Hickory DNS (formerly Trust-DNS) is a Rust-based DNS client, server, and resolver library suite built for safety and security. It supports … | 93 | 5381 | active |
| portapack-mayhem/mayhem-firmware Mayhem is open-source firmware for the HackRF One combined with the PortaPack H1/H2/H4/H4M add-on, turning the SDR into a standalone touchs… | 83 | 5361 | active |
| P-H-C/phc-winner-argon2 The reference C implementation of Argon2, the winner of the Password Hashing Competition, providing memory-hard password hashing with Argon… | 23 | 5358 | stable |
| celzero/rethink-app Rethink DNS + Firewall is an open-source Android app combining an encrypted DNS client (DoH, Oblivious DoH, DoT, DNSCrypt) with blocklists,… | 98 | 5338 | active |
| PurpleAILAB/Decepticon Decepticon is an autonomous AI red-team hacking agent that uses LLMs (built on LangChain/LangGraph) to plan and execute context-aware offen… | 80 | 5335 | active |
| microsoft/azurelinux Azure Linux is an open-source, general-purpose Linux distribution built and optimized for Microsoft Azure, with sources derived from Fedora… | 98 | 5330 | active |
| Nasiko-Labs/nasiko Nasiko is a developer control plane for AI agents, built in Rust, that lets teams deploy, route, secure, and observe A2A-speaking agents wi… | 61 | 5330 | active |
| Ladon Ladon is a large-scale internal network penetration scanner written in C#, offering port scanning, service identification, network asset di… | 29 | 5320 | active |
| ThreatMapper Deepfence ThreatMapper is an open-source Cloud Native Application Protection Platform (CNAPP) that hunts threats in production cloud, Kuber… | 84 | 5318 | active |
| oomol-lab/open-connector OpenConnector is an open-source connector gateway that lets users authorize SaaS app accounts once and exposes 1,000+ providers and 10,000+… | 80 | 5316 | active |
| leizongmin/js-xss A JavaScript library for sanitizing untrusted HTML to prevent XSS attacks using a configurable whitelist of allowed tags and attributes. It… | 69 | 5313 | stable |
| RhinoSecurityLabs/pacu Pacu is an open-source AWS exploitation framework for offensive security testing of Amazon Web Services environments. It provides a modular… | 73 | 5312 | active |
| kanidm/kanidm Kanidm is a simple, secure, and fast identity management platform written in Rust that acts as a complete identity provider for other appli… | 99 | 5291 | active |
| CreditTone/hooker hooker is a Frida-based reverse engineering toolkit for Android that provides a comfortable command-line interface with universal hooking s… | 70 | 5285 | active |
| FunnyWolf/Viper VIPER is a self-hosted red teaming and adversary simulation platform with a web UI, 100+ post-exploitation modules covering MITRE ATT&CK, a… | 85 | 5279 | active |
| mentebinaria/retoolkit An Inno Setup-based installer that bundles a curated collection of reverse engineering and malware analysis tools for x86/x64 Windows syste… | 82 | 5278 | active |
| Naituw/IPAPatch IPAPatch is an Xcode project template that lets you patch decrypted iOS app IPA files by injecting your own dynamic libraries, without requ… | 54 | 5275 | active |
| hahwul/dalfox Dalfox is an open-source XSS vulnerability scanner written in Rust that automates discovery, injection, and DOM/AST-level verification of r… | 98 | 5256 | active |
| martin-ger/esp_wifi_repeater Firmware for the ESP8266/ESP8285 that turns the chip into a full WiFi NAT router and, in a separate edition, a true L2-bridge WiFi repeater… | 71 | 5242 | active |
| openiddict/openiddict-core OpenIddict is a flexible OAuth 2.0/OpenID Connect framework for .NET, providing server, client, and token validation stacks. It supports st… | 97 | 5236 | stable |
| dashingsoft/pyarmor Pyarmor is a command-line tool for obfuscating Python scripts, making them hard to reverse-engineer. It also supports binding obfuscated sc… | 99 | 5179 | active |
| Ullaakut/cameradar Cameradar is a Go-based command-line tool that scans targets for open RTSP video surveillance endpoints and uses dictionary attacks to disc… | 94 | 5173 | active |
| zhkl0228/unidbg A Java-based framework that emulates Android (and experimentally iOS) native libraries on non-ARM hosts, including JNI, syscalls, and ARM32… | 79 | 5165 | active |
| GhostPack/Rubeus Rubeus is a C# command-line toolset for raw Kerberos interaction and abuse on Windows, adapted from Kekeo and MakeMeEnterpriseAdmin. It sup… | 60 | 5145 | active |
| ngoduykhanh/wireguard-ui A self-hosted web user interface for managing WireGuard VPN setups, written in Go. It provides authentication, client management with extra… | 23 | 5145 | active |
| jinwyp/one_click_script A collection of one-click shell scripts for Linux servers that install latest or LTS Linux kernels and enable BBR or BBR Plus congestion co… | 71 | 5139 | active |
| SpaceTimee/Sheas-Cealer Sheas Cealer is a WPF (.NET 8) Windows desktop tool that forges the SNI extension field in Chromium's launch parameters, allowing users to … | 68 | 5116 | active |
| hakluke/hakrawler Hakrawler is a fast command-line web crawler written in Go, built on the Gocolly library, that discovers URLs and JavaScript file locations… | 66 | 5116 | active |
| yrutschle/sslh sslh is a protocol multiplexer daemon written in C that accepts connections on a single port and forwards them to different backend service… | 76 | 5109 | stable |
| gommzystudio/device-activity-tracker A proof-of-concept application that tracks device activity of phone numbers on WhatsApp and Signal by measuring round-trip times of silent … | 43 | 5098 | active |
| mimblewimble/grin Grin is a minimal, open-source implementation of the Mimblewimble blockchain protocol, providing a privacy-preserving digital currency with… | 93 | 5093 | active |
| niklashigi/apk-mitm A Node.js CLI application that automatically patches Android APK files to allow HTTPS traffic inspection through a man-in-the-middle proxy.… | 23 | 5092 | stable |
| angryip/ipscan Angry IP Scanner is a fast, open-source IP address and port scanner with a friendly GUI built on Eclipse SWT. It scans networks for hosts, … | 75 | 5091 | active |
| google/grr GRR Rapid Response is an incident response framework focused on remote live forensics. It consists of a Python agent installed on target sy… | 70 | 5088 | active |
| lc/gau gau (getallurls) is a Go CLI tool that fetches known URLs for a given domain from AlienVault's Open Threat Exchange, the Wayback Machine, C… | 56 | 5076 | active |
| ossec/ossec-hids OSSEC is an open-source host-based intrusion detection system (HIDS) that combines log analysis, file integrity monitoring, rootkit detecti… | 91 | 5047 | stable |
| techchipnet/CamPhish CamPhish is a bash-based penetration-testing tool that hosts a fake webpage on a built-in PHP server and exposes it via ngrok or CloudFlare… | 40 | 5020 | active |
| ClearURLs/Addon ClearURLs is a browser extension built on WebExtensions technology that automatically removes tracking parameters (like utm_source) from UR… | 38 | 5018 | active |
| pritunl/pritunl Pritunl is a distributed enterprise VPN server built on the OpenVPN protocol (with WireGuard support), managed through a web interface and … | 97 | 5010 | active |
| torproject/tor Tor is the core implementation of the Tor anonymity network, routing internet traffic through onion circuits to hide a user's IP address an… | 32 | 5008 | active |
| kokke/tiny-AES-c A small, portable implementation of AES encryption (128/192/256-bit) in C99, supporting ECB, CBC, and CTR modes. It is designed for minimal… | 23 | 5000 | stable |
| V4bel/dirtyfrag Dirty Frag is a proof-of-concept Linux kernel local privilege escalation exploit written in C. It chains the xfrm-ESP (CVE-2026-43284) and … | 50 | 4990 | active |
| atom0s/Steamless Steamless is a C# tool that removes the SteamStub DRM protection layer applied to Steam game executables via the Steamworks SDK DRM tool. I… | 23 | 4990 | active |