domain: security
4787 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| smallstep/cli Step CLI is a Go-based command-line tool for building, operating, and automating PKI systems, working with X.509 certificates, JWTs, OAuth … | 95 | 4317 | active |
| cilium/hubble Hubble is a fully distributed network, service, and security observability platform for Kubernetes, built on top of Cilium and eBPF. It pro… | 91 | 4315 | active |
| ufrisk/MemProcFS MemProcFS is an memory forensic tool that exposes physical memory, memory dump files, and live memory acquisition sources as files in a vir… | 89 | 4300 | active |
| iancoleman/bip39 A web-based tool for converting BIP39 mnemonic seed phrases into addresses and private keys across many cryptocurrencies. It can be used on… | 23 | 4300 | stable |
| XTLS/RealiTLScanner A Go-based TLS server scanner built for the XTLS Reality protocol ecosystem. It scans IP ranges, CIDRs, domains, or target lists to find TL… | 86 | 4286 | active |
| jtesta/ssh-audit ssh-audit is a Python CLI tool that audits SSH server and client configurations, analyzing banners, key exchange, encryption, MAC, and comp… | 82 | 4280 | active |
| JonathanSalwan/Triton Triton is a dynamic binary analysis library providing dynamic symbolic execution, taint analysis, and ISA semantics for x86, x86-64, ARM32,… | 65 | 4274 | active |
| x64dbg/ScyllaHide ScyllaHide is an advanced usermode anti-anti-debug library that hooks Windows functions to hide the presence of a debugger from debugged pr… | 23 | 4271 | active |
| open-policy-agent/gatekeeper Gatekeeper is a CNCF policy controller for Kubernetes built on Open Policy Agent (OPA). It enforces admission policies via customizable con… | 97 | 4269 | stable |
| ConsenSysDiligence/mythril Mythril is a symbolic-execution-based security analysis tool for EVM bytecode that detects vulnerabilities in Ethereum and other EVM-compat… | 58 | 4265 | active |
| TideSec/TscanPlus TscanPlus is a comprehensive network security detection and operations tool for rapid asset discovery, identification, and vulnerability de… | 82 | 4257 | active |
| jonaslejon/malicious-pdf A Python CLI tool that generates 67 malicious PDF test files embedding callbacks for SSRF, XSS, XXE, NTLM credential theft, and data exfilt… | 86 | 4254 | active |
| megadose/toutatis Toutatis is a Python CLI tool that extracts public information from Instagram accounts, such as emails, phone numbers, follower counts, and… | 32 | 4240 | active |
| dmno-dev/varlock Varlock is a CLI tool and library for managing environment variables and secrets via a typed .env.schema file, serving as a drop-in dotenv … | 82 | 4220 | active |
| google/tamperchrome Tamper Dev is a browser extension that intercepts and edits HTTP/HTTPS requests and responses in real time without requiring a proxy or aux… | 54 | 4218 | active |
| JaveleyQAQ/WeChatOpenDevTools-Python A Python tool that force-enables the hidden developer tools (F12) in WeChat mini programs and WeChat's built-in browser. It is a Python rew… | 16 | 4211 | active |
| Velocidex/velociraptor Velociraptor is an open-source endpoint visibility, digital forensics, and incident response platform that collects host-based state inform… | 94 | 4208 | stable |
| irbis-sh/zen-desktop Zen is an open-source, system-wide ad-blocker and privacy guard for Windows, macOS, and Linux. It runs a local proxy that intercepts HTTP/H… | 96 | 4205 | active |
| marmotedu/iam IAM is an enterprise-grade identity and access management system written in Go, used to authenticate users and authorize access to resource… | 28 | 4205 | active |
| hellzerg/optimizer Optimizer is a Windows GUI configuration utility for enhancing privacy and security, applying system tweaks, disabling telemetry, cleaning … | 10 | 18307 | maintenance |
| aarondl/authboss Authboss is a modular authentication system for Go web applications, providing pluggable modules for common auth features like login, regis… | 70 | 4198 | active |
| baihengaead/wlan-sec-test-tool A Python-based GUI tool for wireless network security testing that checks WiFi networks for weak passwords by attempting connections with a… | 70 | 4183 | active |
| guelfoweb/knockpy KnockPy is a modular Python 3 CLI tool for enumerating subdomains of a target domain using passive reconnaissance sources and DNS bruteforc… | 64 | 4178 | active |
| PurpleI2P/i2pd i2pd (I2P Daemon) is a full-featured C++ implementation of an I2P client, providing a universal anonymous network layer with end-to-end enc… | 93 | 4176 | active |
| monasticacademy/httptap httptap is a static Go CLI binary that shows the HTTP and HTTPS requests made by any Linux program by running it inside an isolated network… | 63 | 4176 | active |
| square/Valet Valet is a Swift library that simplifies securely storing data in the iOS, tvOS, watchOS, and macOS Keychain. It wraps the Keychain's compl… | 75 | 4175 | stable |
| simov/grant Grant is an OAuth proxy middleware for Node.js supporting 200+ OAuth providers across OAuth 1.0a, OAuth 2.0, and OpenID Connect. It integra… | 34 | 4169 | stable |
| RetireJS/retire.js Retire.js is a scanner that detects the use of JavaScript libraries and Node.js modules with known vulnerabilities, available as a CLI scan… | 99 | 4161 | active |
| KernelSU-Next/KernelSU-Next KernelSU Next is a kernel-based root solution for Android devices, providing superuser access via kernel-level hooks with a companion manag… | 81 | 4161 | active |
| nextdns/nextdns NextDNS CLI is an open-source command-line client (written in Go) that connects to NextDNS's DNS-over-HTTPS service, acting as a local DoH … | 95 | 4146 | active |
| DependencyTrack/dependency-track OWASP Dependency-Track is an open-source component analysis platform that ingests CycloneDX SBOMs to continuously identify vulnerabilities,… | 99 | 4145 | active |
| mandiant/flare-floss FLOSS (FLARE Obfuscated String Solver) is a Python CLI tool from Mandiant that automatically extracts and deobfuscates strings from malware… | 67 | 4138 | active |
| vvo/iron-session iron-session is a secure, stateless, cookie-based session library for JavaScript, storing session data in signed and encrypted cookies deco… | 58 | 4138 | active |
| Bubka/2FAuth 2FAuth is a self-hosted web application for managing Two-Factor Authentication accounts and generating TOTP, HOTP, and Steam Guard security… | 94 | 4125 | active |
| ivre/ivre IVRE is an open-source network recon framework written in Python that collects, stores, and analyzes network intelligence from active scann… | 66 | 4119 | active |
| AzureAD/microsoft-authentication-library-for-js Microsoft Authentication Library (MSAL) for JavaScript enables client-side and server-side JS apps to authenticate users with Microsoft Ent… | 95 | 4115 | active |
| yusing/godoxy GoDoxy is a lightweight, high-performance reverse proxy with a built-in WebUI, designed for self-hosters running Docker or Podman. It autom… | 88 | 4115 | active |
| Lucksi/Mr.Holmes Mr.Holmes is a Python-based OSINT (open-source intelligence) CLI tool that gathers information about usernames, domains, phone numbers, and… | 53 | 4112 | active |
| jasonxtn/Argus Argus is a Python-based all-in-one information gathering and reconnaissance toolkit with an interactive console and modular architecture. I… | 47 | 4082 | active |
| alexandreborges/malwoverview Malwoverview is a Python command-line first-response tool for threat hunting that queries many threat intelligence sources such as VirusTot… | 97 | 4075 | active |
| google/nsjail NsJail is a lightweight Linux process isolation tool that uses namespaces, cgroups, rlimits, and seccomp-bpf syscall filters (via the Kafel… | 91 | 4074 | stable |
| sundowndev/phoneinfoga PhoneInfoga is an information gathering framework for scanning international phone numbers, built in Go. It collects basic data like countr… | 67 | 17648 | maintenance |
| r0oth3x49/ghauri Ghauri is a cross-platform Python CLI tool that automates detection and exploitation of SQL injection vulnerabilities in web applications. … | 54 | 4070 | active |
| oauthjs/node-oauth2-server A Node.js module for implementing a fully RFC 6749/6750 compliant OAuth2 server/provider, framework-agnostic with official wrappers for Exp… | 23 | 4066 | active |
| hashicorp/boundary HashiCorp Boundary is an identity-aware proxy that provides secure, least-privilege access to hosts and critical systems across clouds and … | 89 | 4056 | active |
| theori-io/copy-fail-CVE-2026-31431 A proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation bug in the authencesn cryptographic template that … | 50 | 4049 | active |
| 0dayCTF/reverse-shell-generator A web-based reverse shell generator that produces common reverse shell payloads, listeners, MSFVenom commands, and HoaxShell integrations w… | 68 | 4047 | active |
| dekuNukem/daytripper Daytripper is an open-source hardware laser tripwire consisting of a wireless transmitter and a USB receiver that hides windows, locks the … | 50 | 4040 | active |
| sobolevn/git-secret git-secret is a bash-based command-line tool that encrypts private files with GPG public keys and stores them safely inside a git repositor… | 67 | 4038 | active |
| Motion-Project/motion Motion is an open-source C++ program that monitors video camera signals and detects changes (motion) in the images. It is commonly used for… | 65 | 4038 | active |
| wux1an/wxapkg A cross-platform desktop GUI tool built with Wails for scanning, decrypting, and unpacking WeChat mini-program .wxapkg files. It restores t… | 69 | 4037 | active |
| cartography-cncf/cartography Cartography is a Python CLI tool that ingests infrastructure assets and their relationships from 30+ platforms (AWS, GCP, Azure, Kubernetes… | 98 | 4028 | active |
| microsoft/SEAL Microsoft SEAL is an open-source homomorphic encryption library written in modern C++, with a .NET wrapper, supporting BFV/BGV and CKKS sch… | 97 | 4016 | active |
| HyperDbg/HyperDbg HyperDbg is an open-source, hypervisor-assisted debugger for Windows (with Linux support in development) that uses Intel VT-x and EPT to de… | 94 | 4012 | active |
| snooppr/snoop Snoop is a Python-based OSINT CLI tool that searches for a given username/nickname across ~5400+ websites, with a focus on the CIS region. … | 75 | 4009 | active |
| openssh/openssh-portable Portable OpenSSH is a complete implementation of the SSH protocol version 2 for secure remote login, command execution, and file transfer. … | 76 | 3970 | stable |
| schwabe/ics-openvpn An open-source OpenVPN client for Android that uses the Android VPNService API to provide VPN connectivity without root access. It is a sta… | 85 | 3967 | active |
| diego-treitos/linux-smart-enumeration A POSIX-compliant shell script that enumerates a local Linux system's security posture to help escalate privileges during pentesting and CT… | 59 | 3962 | active |
| APKLab/APKLab APKLab is a VS Code extension that turns the editor into an Android reverse-engineering workbench by integrating Apktool, Jadx, uber-apk-si… | 74 | 3952 | active |
| speed47/spectre-meltdown-checker A self-contained shell script that checks Linux and BSD systems for vulnerability to transient execution CPU vulnerabilities such as Spectr… | 94 | 3947 | active |
| a0rtega/pafish Pafish is a Windows testing tool that applies the same VM and sandbox detection techniques used by malware families to check whether an ana… | 10 | 3946 | active |
| cea-sec/miasm Miasm is a free and open source (GPLv2) reverse engineering framework written in Python for analyzing, modifying, and generating binary pro… | 67 | 3944 | active |
| trustedsec/unicorn Magic Unicorn is a Python CLI tool that generates PowerShell downgrade-attack commands to inject shellcode directly into memory. It support… | 70 | 3938 | active |
| itm4n/PrivescCheck A PowerShell enumeration script that identifies common Windows privilege escalation vulnerabilities and misconfigurations. It also collects… | 98 | 3928 | active |
| leebaird/discover A collection of custom Bash and Python scripts that automate penetration testing tasks including reconnaissance, scanning, enumeration, and… | 77 | 3928 | active |
| spotbugs/spotbugs SpotBugs is a static analysis tool that finds bugs in Java bytecode, serving as the community-maintained successor to the abandoned FindBug… | 99 | 3925 | active |
| lanjelot/patator Patator is a multi-purpose, multi-threaded brute-forcing tool written in Python with a modular design supporting dozens of protocols (SSH, … | 42 | 3923 | active |
| django-guardian/django-guardian django-guardian is a Python library that implements per-object (row-level) permissions on top of Django's built-in authorization backend. I… | 97 | 3910 | stable |
| BrowserBox/BrowserBox BrowserBox is a commercial Remote Browser Isolation (RBI) platform that streams a full modern browser to any client at 60 FPS, keeping web … | 99 | 3901 | active |
| abcz316/SKRoot-linuxKernelRoot SKRoot is a kernel-level hidden root solution for Android that patches stock kernel images without source code, granting root privileges wh… | 85 | 3897 | active |
| cifertech/ESP32-DIV ESP32-DIV is open-source firmware (with open schematics and PCB files) for a custom ESP32-S3 handheld device that bundles Wi-Fi, BLE, 2.4GH… | 89 | 3890 | active |
| oasisfeng/island Island is an Android app that leverages the Android device-owner/profile-owner (DPC) APIs to create isolated 'islands' for cloning or freez… | 42 | 3884 | active |
| freedomofpress/securedrop SecureDrop is an open-source whistleblower submission system that lets media organizations and NGOs securely accept documents from and comm… | 97 | 3878 | stable |
| ambionics/phpggc PHPGGC is a library of PHP unserialize() payloads (gadget chains) with a command-line tool to generate them, covering frameworks like Larav… | 52 | 3876 | active |
| Pocsuite pocsuite3 is an open-source remote vulnerability testing and proof-of-concept development framework by Knownsec's 404 Team. It provides a P… | 27 | 3872 | active |
| KuroLabs/stegcloak StegCloak is a pure JavaScript steganography module that hides secrets inside plain text using invisible zero-width unicode characters, enc… | 23 | 3871 | stable |
| hasherezade/pe-sieve PE-sieve is a lightweight Windows tool that scans a given process for malicious implants such as replaced or injected PE files, shellcodes,… | 71 | 3867 | active |
| openbsd/src A read-only Git mirror of OpenBSD's official CVS source repository containing the complete operating system source tree, including the kern… | 77 | 3864 | active |
| trimstray/htrace.sh htrace.sh is a shell-script CLI that combines HTTP/HTTPS request troubleshooting (redirect tracing, headers, body, SSL parameters, custom m… | 32 | 3860 | active |
| PerformanC/ReZygisk ReZygisk is an open-source, standalone implementation of Zygisk providing Zygisk API support for KernelSU, APatch, and Magisk on rooted And… | 85 | 3857 | active |
| M66B/NetGuard NetGuard is a free and open-source no-root firewall application for Android that blocks internet access per app using a local VPN. It allow… | 92 | 3849 | active |
| nestybox/sysbox Sysbox is an open-source container runtime (a specialized runc) that improves container isolation via Linux user-namespaces and procfs/sysf… | 89 | 3840 | active |
| unikraft/unikraft Unikraft is an open-source Unikernel Development Kit for building custom, specialized operating system kernels tailored to individual appli… | 86 | 3832 | active |
| nolabs-ai/nono nono is a Rust-based CLI and SDK that runs AI coding agents and their tool invocations in ephemeral, kernel-enforced micro sandboxes with c… | 78 | 3830 | active |
| EFForg/privacybadger Privacy Badger is a free browser extension by EFF that automatically learns to block hidden third-party trackers as you browse. It sends Gl… | 94 | 3822 | active |
| ax/apk.sh A Bash script that automates Android APK reverse engineering tasks such as pulling, decoding, rebuilding, and patching APKs. It wraps apkto… | 73 | 3822 | active |
| thephpleague/oauth2-client A PHP library providing a base client for integrating with OAuth 2.0 service providers per RFC 6749. It includes a GenericProvider for Bear… | 76 | 3817 | stable |
| Rizin Cutter is a free and open-source graphical reverse engineering platform built on top of the Rizin framework, a Unix-friendly command-line t… | 88 | 3806 | active |
| elementalsouls/Claude-BugHunter A Claude Code skill bundle that turns Claude into a bug-hunting and red-team assistant, with 83 skills, 15 slash commands, and 681 disclose… | 77 | 3801 | active |
| panva/node-oidc-provider A Node.js library implementing an OpenID Certified OAuth 2.0 Authorization Server with full OpenID Connect support. It is highly configurab… | 99 | 3800 | active |
| dcodeIO/bcrypt.js A zero-dependency, pure JavaScript implementation of the bcrypt password hashing algorithm with TypeScript support. It is API-compatible wi… | 81 | 3799 | stable |
| serverless-dns/serverless-dns A serverless, Pi-hole-style DNS-over-HTTPS and DNS-over-TLS resolver with configurable blocklists. It deploys to Cloudflare Workers, Deno D… | 75 | 3794 | active |
| Findomain/Findomain Findomain is a fast subdomain enumeration tool written in Rust that discovers subdomains via Certificate Transparency logs and APIs without… | 76 | 3786 | active |
| Orange-Cyberdefense/arsenal Arsenal is a Python-based terminal tool that provides a searchable inventory of hard-to-remember pentest commands, letting users pick one a… | 32 | 3784 | active |
| pwntester/ysoserial.net ysoserial.net is a proof-of-concept command-line tool that generates deserialization payloads exploiting unsafe .NET object deserialization… | 62 | 3782 | active |
| hasherezade/pe-bear PE-bear is a multiplatform GUI reversing tool for Windows PE (Portable Executable) files, built on bearparser and capstone. It gives malwar… | 78 | 3781 | active |
| TracecatHQ/tracecat Tracecat is an open-source, AI-native security automation (SOAR) platform that combines low-code workflows, tool-calling agents, case manag… | 87 | 3780 | active |
| scipag/vulscan Vulscan is an Nmap NSE script that turns Nmap into a vulnerability scanner by matching version-detected services against offline vulnerabil… | 52 | 3780 | active |
| nabla-c0d3/sslyze SSLyze is a fast SSL/TLS scanning tool and Python library that analyzes a server's TLS configuration, including certificates, cipher suites… | 83 | 3775 | stable |
| aquasecurity/cloudsploit CloudSploit by Aqua is an open-source Cloud Security Posture Management (CSPM) tool that scans cloud infrastructure accounts for misconfigu… | 72 | 3768 | active |