domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| pomerium/pomerium Pomerium is an open-source, identity- and context-aware reverse proxy that provides clientless, zero-trust access to internal applications … | 99 | 4978 | active |
| certd/certd Certd is a free, open-source, fully automated SSL certificate management system that applies for, renews, and deploys certificates via conf… | 95 | 4978 | active |
| perplexityai/bumblebee Bumblebee is a read-only Go CLI that scans developer endpoints for on-disk package, extension, and developer-tool metadata (lockfiles, pack… | 76 | 4975 | active |
| cilium/tetragon Tetragon is an eBPF-based security observability and runtime enforcement tool from the Cilium project. It monitors process execution, sysca… | 95 | 4955 | active |
| domcyrus/rustnet RustNet is a cross-platform terminal-based network monitoring tool that maps live TCP, UDP, and QUIC connections to their owning processes … | 86 | 4946 | active |
| Nyr/wireguard-install A Bash installer script that sets up a WireGuard VPN server on Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS, and Fedora in about a minute… | 73 | 4926 | active |
| bitsadmin/wesng WES-NG is a Python command-line tool that parses Windows `systeminfo` output (or missing KB listings) and cross-references it against a reg… | 76 | 4923 | active |
| DefectDojo/django-DefectDojo DefectDojo is an open-source vulnerability management, DevSecOps, and ASPM platform built on Django. It aggregates findings from hundreds o… | 95 | 4909 | active |
| internet-court/internet-court-skill An open Agent Skill / Claude Code plugin that acts as a trust layer for agent-to-agent commerce, combining natural-language mandates, ERC-7… | 57 | 4900 | active |
| nicocha30/ligolo-ng Ligolo-ng is a tunneling and pivoting tool written in Go that establishes tunnels over reverse TCP/TLS connections using a TUN interface in… | 98 | 4893 | active |
| UndeadSec/SocialFish SocialFish is a Python-based phishing toolkit that clones modern login pages using Playwright browser automation and captures credentials, … | 76 | 4851 | active |
| Security Onion Security Onion is a free and open Linux distribution and platform for threat hunting, enterprise security monitoring, and log management. I… | 94 | 4846 | stable |
| google/wuffs Wuffs is a memory-safe programming language plus a standard library for safely parsing, decoding and encoding untrusted file formats such a… | 75 | 4820 | active |
| NLnetLabs/unbound Unbound is a validating, recursive, and caching DNS resolver written in C, designed to be fast and lean while implementing modern open stan… | 94 | 4818 | stable |
| charles2gan/GDA-android-reversing-Tool GDA (GJoy Dex Analyzer) is a fast, native C++ Dalvik bytecode decompiler and reverse analysis platform for Android binaries such as APK, DE… | 70 | 4818 | active |
| aloshdenny/reverse-SynthID A research tool that reverse-engineers Google's SynthID watermark embedded in Gemini-generated images using spectral analysis and signal pr… | 66 | 4815 | active |
| jmpews/Dobby Dobby is a lightweight, modular function hooking framework supporting multiple platforms (Windows, macOS, iOS, Android, Linux) and architec… | 24 | 4813 | active |
| duckduckgo/Android The official DuckDuckGo Android app, a privacy-focused mobile browser and search client written in Kotlin. It blocks trackers, enforces enc… | 95 | 4802 | active |
| greenbone/openvas-scanner OpenVAS Scanner is the scan engine of the Greenbone Community Edition, executing a continuously updated feed of vulnerability tests against… | 95 | 4796 | active |
| immunant/c2rust C2Rust is a transpiler that converts C99-compliant C code into semantically equivalent but unsafe, unidiomatic Rust code, preserving functi… | 81 | 4794 | active |
| aya-rs/aya Aya is a Rust library for building and loading eBPF programs on Linux, implemented entirely in Rust without libbpf or BCC. It provides BTF-… | 96 | 4784 | active |
| mitchellkrogza/nginx-ultimate-bad-bot-blocker A drop-in Nginx configuration package that blocks bad bots, spam referrers, vulnerability scanners, malware, adware, and fake Googlebots, w… | 77 | 4781 | active |
| open-sdr/openwifi Open-source full-stack IEEE 802.11/Wi-Fi design based on Software Defined Radio, including a Linux mac80211-compatible driver and software,… | 68 | 4772 | active |
| microsoft/msquic MsQuic is Microsoft's cross-platform C implementation of the IETF QUIC transport protocol (RFC 9000), with API wrappers for C++, C#, and Ru… | 98 | 4771 | stable |
| diafygi/acme-tiny A tiny, auditable Python script (under 200 lines) that issues and renews TLS certificates from Let's Encrypt using the ACME protocol. It re… | 68 | 4770 | stable |
| aws/s2n-tls s2n-tls is a C99 implementation of the TLS/SSL protocols designed to be simple, small, fast, and security-focused, maintained by AWS. It pr… | 99 | 4755 | stable |
| cdk-team/CDK CDK is a zero-dependency container penetration toolkit written in Go for security testing of Kubernetes, Docker, and Containerd environment… | 70 | 4740 | active |
| MlgmXyysd/Xiaomi-HyperOS-BootLoader-Bypass A proof-of-concept PHP tool that exploits a vulnerability to bypass Xiaomi HyperOS community account restrictions on BootLoader unlock bind… | 40 | 4738 | active |
| its-a-feature/Mythic Mythic is a collaborative, multi-platform post-exploitation red teaming framework built with Go, Docker, and a web browser UI. It provides … | 78 | 4725 | active |
| DedSecInside/TorBot TorBot is a Python CLI tool for OSINT on the dark web, crawling .onion sites over the Tor network and building link trees. It can save craw… | 97 | 4716 | active |
| AntSwordProject/antSword AntSword is a cross-platform, open-source website administration toolkit built with Electron, designed for penetration testers, security re… | 73 | 4693 | active |
| SteveLTN/https-portal HTTPS-PORTAL is a Dockerized reverse proxy that automatically obtains and renews Let's Encrypt TLS certificates and serves any web applicat… | 88 | 4692 | active |
| TheWover/donut Donut is a shellcode generator that converts VBScript, JScript, EXE, DLL files, and .NET assemblies into x86, x64, or AMD64+x86 position-in… | 36 | 4689 | stable |
| intelowlproject/IntelOwl IntelOwl is an open-source, self-hosted application for managing threat intelligence at scale, querying many online analyzers and malware a… | 92 | 4683 | active |
| GhostPack/Seatbelt Seatbelt is a C# command-line tool that performs security-oriented host-survey 'safety checks' on Windows systems. It enumerates system and… | 32 | 4683 | active |
| HotCakeX/Harden-Windows-Security A suite of tools (Harden System Security app and AppControl Manager) that hardens Windows using only official, supported Microsoft methods,… | 95 | 4668 | active |
| motioneye-project/motioneye motionEye is a web-based frontend for the motion video surveillance daemon, providing a browser interface for configuring and viewing camer… | 84 | 4664 | active |
| Heeexy/SpringBoot-Shiro-Vue A full-stack reference project demonstrating fine-grained RBAC permission management using Spring Boot on the backend and Vue with ElementU… | 69 | 4656 | active |
| OPNsense OPNsense is an open-source, FreeBSD-based firewall and routing platform with a web GUI, REST API, and extensible plugin system. It provides… | 77 | 4653 | active |
| openziti/zrok zrok is an open-source tool for securely sharing local web services, files, and TCP/UDP resources over the internet without firewall or NAT… | 89 | 4645 | active |
| Authenticator-Extension/Authenticator A browser extension that generates two-factor authentication (2FA) codes, acting as a software TOTP authenticator. It is available for Chro… | 52 | 4642 | active |
| hyperlight-dev/hyperlight Hyperlight is a lightweight Virtual Machine Manager (VMM) library, written in Rust, that embeds micro virtual machines into applications fo… | 85 | 4635 | active |
| build-trust/ockam Ockam is a Rust library and CLI toolkit for building secure-by-design distributed applications with end-to-end encryption, cryptographic id… | 61 | 4633 | active |
| vaibhavpandeyvpz/apkstudio APK Studio is an open-source, cross-platform Qt6 IDE for reverse-engineering Android application packages. It bundles decompiling, recompil… | 69 | 4630 | active |
| Yelp/detect-secrets detect-secrets is a Python CLI tool from Yelp that detects secrets (API keys, passwords, tokens) in codebases using regex and entropy heuri… | 57 | 4629 | active |
| emanuele-f/PCAPdroid PCAPdroid is a privacy-friendly open source Android app that monitors, analyzes, and blocks network connections made by other apps without … | 99 | 4602 | active |
| ReversecLabs/drozer drozer is an open-source security assessment framework for Android that lets testers assume the role of an app and interact with the Androi… | 57 | 4597 | active |
| zrax/pycdc Decompyle++ is a C++ tool that translates compiled Python bytecode (.pyc files) back into readable Python source code. It includes pycdas, … | 66 | 4594 | active |
| aquasecurity/tracee Tracee is a Linux runtime security and forensics tool that uses eBPF to trace system calls, network activity, and file operations in real t… | 79 | 4593 | active |
| sensity-ai/dot dot (Deepfake Offensive Toolkit) is a Python tool that generates real-time, controllable deepfakes from a webcam feed and injects them into… | 23 | 4586 | active |
| M66B/FairEmail FairEmail is a fully featured, open source, privacy oriented email client for Android. It supports unlimited accounts via standard protocol… | 95 | 4582 | active |
| rfjakob/gocryptfs gocryptfs is an encrypted overlay filesystem written in Go, built on the go-fuse library, that stores each file as a corresponding encrypte… | 77 | 4582 | stable |
| ntop/nDPI nDPI is an open source LGPLv3 C library for deep packet inspection that detects 450+ layer-7 application protocols from network traffic. It… | 76 | 4566 | stable |
| aaPanel/BaoTa BaoTa (BT Panel) is a self-hosted web-based server operations panel for Linux (and Windows) that simplifies managing websites, LAMP/LNMP st… | 71 | 4563 | active |
| hluwa/frida-dexdump A Frida-based CLI tool that finds and dumps DEX files from an Android app's memory, enabling unpacking of packed or obfuscated APKs. It sup… | 10 | 4560 | stable |
| SWE-agent/SWE-agent SWE-agent is a Python framework that lets a language model autonomously use tools to fix GitHub issues, find cybersecurity vulnerabilities,… | 67 | 20147 | maintenance |
| stratumauth/app Stratum (formerly Authenticator Pro) is a free, open-source two-factor authentication app for Android with a Wear OS companion. It supports… | 94 | 4555 | active |
| cerbos/cerbos Cerbos is an open-core, language-agnostic policy decision point (PDP) that externalizes authorization from application code using context-a… | 94 | 4555 | stable |
| spipm/Depixelization_poc Depix is a proof-of-concept tool that recovers plaintext from pixelized screenshots by matching pixelated blocks against a rendered font se… | 10 | 4551 | active |
| hacklcx/HFish HFish is a free, enterprise-grade honeypot platform for deception-based defense, threat detection, and attacker tracing. It deploys decoy s… | 65 | 4532 | active |
| ProvableHQ/snarkOS snarkOS is a decentralized operating system for zero-knowledge applications, forming the backbone of the Aleo network. It implements node s… | 99 | 4525 | active |
| Oros42/IMSI-catcher A Python tool that decodes GSM radio traffic captured via software-defined radio receivers (RTL-SDR, HackRF, BladeRF, OsmocomBB) to display… | 71 | 4515 | active |
| auth0/express-jwt Express middleware that validates JSON Web Tokens (JWTs) using the webtoken library and attaches the decoded payload to the request object.… | 72 | 4513 | stable |
| projectdiscovery/interactsh Interactsh is an open-source tool for detecting out-of-band (OOB) interactions via DNS, HTTP(S), SMTP(S), and LDAP, useful for identifying … | 85 | 4512 | active |
| taviso/loadlibrary A library that lets native Linux programs load and call functions from Windows DLLs via a custom PE/COFF loader with a dlopen-like API. It … | 39 | 4501 | active |
| samsesh/SocialBox-Termux SocialBox-Termux is a shell-based brute-force attack framework targeting social media and email services like Facebook, Gmail, Instagram, a… | 72 | 4497 | active |
| sensepost/gowitness gowitness is a Go-based command-line utility that uses Chrome Headless to take screenshots of websites, supporting scans of URL lists, CIDR… | 75 | 4488 | active |
| OpenVPN/easy-rsa easy-rsa is a shell-based CLI utility for building and managing a PKI certificate authority. It creates root and intermediate CAs, signs ce… | 80 | 4475 | active |
| JonathanSalwan/ROPgadget ROPgadget is a Python command-line tool that searches binaries for ROP gadgets to facilitate return-oriented programming exploitation. It s… | 67 | 4470 | active |
| Awarexone/Agentic-Bug-Hunter An AI-powered bug bounty hunting toolkit that automates reconnaissance, vulnerability testing, finding validation, and report generation fo… | 77 | 4464 | active |
| PowerDNS/pdns PowerDNS is a suite of open-source DNS software written in C++, comprising the Authoritative Server, the Recursor, and dnsdist. It provides… | 77 | 4456 | stable |
| BeichenDream/Godzilla Godzilla is a Java-based webshell management tool supporting dynamic payloads for JSP, ASPX, and PHP targets with multiple AES/XOR encrypto… | 23 | 4455 | active |
| apache/shiro Apache Shiro is a comprehensive Java security framework providing authentication, authorization, cryptography, and enterprise session manag… | 95 | 4451 | active |
| amidaware/tacticalrmm Tactical RMM is a self-hosted remote monitoring and management tool built with Django, Vue, and a Go agent, integrating MeshCentral for rem… | 94 | 4447 | active |
| trifectatechfoundation/sudo-rs A memory-safe, safety-oriented reimplementation of the classic sudo and su utilities written in Rust. It is actively maintained, independen… | 91 | 4447 | active |
| extremecoders-re/pyinstxtractor A Python script that extracts the contents of PyInstaller-generated executables, including fixing pyc headers so bytecode decompilers can p… | 84 | 4447 | stable |
| mr-karan/doggo doggo is a modern command-line DNS client for humans, written in Go and inspired by the Rust tool 'dog'. It supports multiple DNS transport… | 98 | 4444 | active |
| t3l3machus/Villain Villain is a high-level stage 0/1 command-and-control (C2) framework written in Python that handles multiple reverse TCP and HoaxShell-base… | 40 | 4439 | active |
| GerbenJavado/LinkFinder LinkFinder is a Python CLI script that discovers endpoints and their parameters in JavaScript files using jsbeautifier and regular expressi… | 32 | 4439 | stable |
| garinasset/leak-check A self-hostable personal information leak detection service that checks whether your personal data (name, phone, email, address, QQ, etc.) … | 49 | 4435 | active |
| rivet-dev/agentos agentOS is a library that gives AI agents a lightweight operating system running inside your existing backend process, using WebAssembly an… | 91 | 4426 | active |
| orhun/binsider Binsider is a terminal user interface tool for analyzing ELF binaries, offering static and dynamic analysis, string inspection, linked libr… | 84 | 4404 | active |
| microsoft/ApplicationInspector Microsoft Application Inspector is a source code characterization tool that uses a JSON-based rules engine with 400+ regex patterns to iden… | 95 | 4396 | active |
| zoontek/react-native-permissions A React Native library providing a unified permissions API across iOS, Android, and Windows. It lets apps check, request, and manage device… | 95 | 4379 | active |
| intuitem/ciso-assistant-community CISO Assistant is an open-source, self-hostable GRC (Governance, Risk, and Compliance) platform covering risk management, compliance and au… | 90 | 4376 | active |
| joxeankoret/diaphora Diaphora is a free and open source program diffing (binary diffing) tool that works as an IDA Pro plugin, comparing binaries to find change… | 94 | 4373 | active |
| zan8in/afrog afrog is an open-source security tool written in Go for vulnerability scanning using PoC (Proof of Concept) rules. It is designed for bug b… | 96 | 4372 | active |
| sshnet/SSH.NET SSH.NET is a Secure Shell (SSH-2) client library for .NET, optimized for parallelism. It provides SSH command execution, SFTP and SCP file … | 87 | 4370 | stable |
| ts1/BLEUnlock BLEUnlock is a macOS menu bar utility that locks and unlocks your Mac based on the proximity of a Bluetooth Low Energy device such as an iP… | 23 | 4370 | active |
| WireGuard/wireguard-go A userspace implementation of the WireGuard VPN protocol written in Go. It creates WireGuard tunnel interfaces on Linux, macOS, Windows, Fr… | 70 | 4366 | stable |
| meta-llama/PurpleLlama Purple Llama is Meta's umbrella project of tools and benchmarks for assessing and improving the security of large language models. It inclu… | 71 | 4365 | active |
| overspace-labs/HaE HaE (Highlighter and Extractor) is a framework-style cybersecurity project for fine-grained tagging and extraction of sensitive information… | 98 | 4362 | active |
| microsoft/PyRIT PyRIT is Microsoft's open-source Python framework for identifying security and safety risks in generative AI systems. It provides automatio… | 88 | 4361 | active |
| openziti/ziti OpenZiti is an open-source zero-trust networking platform that provides programmable mesh overlay networks with cryptographic identity, pol… | 98 | 4359 | active |
| lazy-luo/smarGate smarGate is a cross-network remote port mapping and NAT traversal tool consisting of an Android client app and lightweight server binaries,… | 79 | 4358 | active |
| AdguardTeam/AdguardBrowserExtension AdGuard Browser Extension is a free, open-source ad blocker for Chrome, Firefox, Opera, Edge, and other Chromium-based browsers. It blocks … | 99 | 4357 | active |
| Volatility Volatility is an open-source memory forensics framework for extracting digital artifacts from RAM captures of Windows, Linux, and macOS sys… | 84 | 4357 | active |
| zyantific/zydis Zydis is a fast, lightweight x86/x86-64 disassembler and encoder library written in C with zero dependencies, not even libc. It supports al… | 65 | 4351 | active |
| binarylogic/authlogic Authlogic is an unobtrusive Ruby authentication library built on ActiveRecord, treating user sessions as models. It handles login, logout, … | 62 | 4344 | stable |
| jazzband/djangorestframework-simplejwt Simple JWT is a JSON Web Token authentication plugin for the Django REST Framework. It provides token-based authentication for Django REST … | 70 | 4334 | stable |