Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: security

4909 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
HiddenRamblings/TagMo
TagMo is an Android application for managing NTAG215, Power Tag, N2 Elite, and Bluetooth NFC tags used with Nintendo amiibo figures on 3DS,…
863209active
D3Ext/WEF
WEF is a Wi-Fi Exploitation Framework written in Bash that automates a wide range of wireless attacks against WPA/WPA2/WPA3, WPS, and WEP n…
523209active
tahowallet/extension
Taho is a community-owned Web3 cryptocurrency wallet implemented as a browser extension, positioned as an open-source alternative to MetaMa…
833204active
AChep/keyguard-app
Keyguard is a multiplatform password manager client for the Bitwarden platform and KeePass (KDBX) files, built with Kotlin and Jetpack Comp…
913203active
jaykali/maskphish
MaskPhish is a simple Bash script that masks phishing URLs under normal-looking URLs (e.g., google.com or facebook.com) as a proof of conce…
423191active
vmware/photon
Photon OS is an open-source, security-hardened minimal Linux distribution purpose-built as a container host for cloud-native applications, …
673178active
LaurieWired/Malimite
Malimite is a Java-based decompiler for iOS and macOS binaries, built on Ghidra, that analyzes IPA files and Application Bundles with direc…
383174active
obfuscar/obfuscar
Obfuscar is an open source MIT-licensed obfuscation tool for .NET assemblies that renames metadata to minimal names, making decompiled code…
933172active
crytic/echidna
Echidna is a Haskell-based fuzzer for Ethereum smart contracts that performs property-based testing by generating sequences of contract cal…
893170active
pingc0y/URLFinder
URLFinder is a fast, easy-to-use Go CLI tool that extracts JS files, URLs, and sensitive information from web pages, including hidden unaut…
803170active
pglombardo/PasswordPusher
Password Pusher is an open-source Ruby web application for securely sharing passwords, text, files, and URLs via encrypted, self-deleting l…
953169active
sa7mon/S3Scanner
A multi-threaded CLI tool written in Go that scans for misconfigured (open) S3 buckets across AWS and other S3-compatible providers like GC…
773165active
the-tcpdump-group/libpcap
libpcap is a system-independent C/C++ library providing a portable API for user-level network packet capture, with BPF-based filtering and …
763163stable
crossutility/Quantumult-X
Quantumult X is a network proxy and traffic manipulation tool for iOS, rebuilt from scratch with support for TUN-based traffic, HTTPS MitM …
723163active
NASA-SW-VnV/ikos
IKOS is a static analyzer for C and C++ programs based on the theory of Abstract Interpretation, built on LLVM. It provides reusable abstra…
643160active
google-agentic-commerce/AP2
Agent Payments Protocol (AP2) is an open protocol and Python SDK for secure, interoperable payments initiated by AI agents, addressing auth…
633160active
QiuChenly/CoreInject
CoreInject (successor to InjectLib) is a macOS application injection and binary-patching tool by QiuChenly, distributed alongside a communi…
843157active
BinDiff
BinDiff is an open-source comparison tool for binary files that finds differences and similarities in disassembled code using graph-theoret…
623155active
Devolutions/IronRDP
IronRDP is a modular Rust implementation of the Microsoft Remote Desktop Protocol (RDP), providing PDU codecs, connection/session state mac…
973137active
easychen/CookieCloud
CookieCloud is a browser extension plus self-hosted server that syncs browser cookies and localStorage across devices with end-to-end encry…
843133active
qltysh/qlty
Qlty CLI is a multi-language code quality tool written in Rust that unifies linting, auto-formatting, maintainability analysis, and securit…
953130active
Mic92/sops-nix
sops-nix is a NixOS module that provides atomic, declarative secret provisioning based on Mozilla's sops. It decrypts sops-encrypted files …
673130active
PartialVolume/shredos.x86_64
ShredOS is a small bootable Linux distribution for securely erasing disks using nwipe on x86 PCs, servers, and Intel-based Macs. It boots d…
903128active
pallets/itsdangerous
ItsDangerous is a Python library for cryptographically signing data so it can be safely passed to untrusted environments (like cookies or U…
343127stable
mozilla/multi-account-containers
A Firefox browser extension by Mozilla that separates browsing into color-coded containers with isolated cookie storage, letting users run …
873124active
namazso/SecureUxTheme
SecureUxTheme is a Windows utility that removes signature verification of visual styles (themes) in memory, enabling third-party custom the…
363115active
21y4d/nmapAutomator
nmapAutomator is a POSIX-compatible shell script that automates nmap-based network reconnaissance and enumeration, running scans in the bac…
323109active
hardentools/hardentools
Hardentools is a Windows utility that reduces the attack surface by disabling risky features in Windows 10/11, Microsoft Office, LibreOffic…
403105active
zegl/kube-score
kube-score is a static code analysis tool for Kubernetes object definitions that scores manifests and Helm charts against reliability and s…
603102active
oasislinux/oasis
Oasis is a small, fully statically-linked Linux system built around musl, with reproducible builds driven by Lua-generated samurai manifest…
623101active
AMD-OSX/AMD_Vanilla
A collection of binary kernel patches that enable near-native AMD CPU support on macOS via the OpenCore bootloader. It supports AMD 15h, 16…
573098active
biggerstar/wedecode
Wedecode is a fully automated tool that decompiles WeChat mini-program and mini-game wxapkg packages back into readable source code (JS, WX…
603091active
ulisesbocchio/jasypt-spring-boot
A Spring Boot integration of the Jasypt library that enables transparent encryption and decryption of property sources in Spring Boot appli…
683088active
jhaals/yopass
Yopass is a self-hostable web application for securely sharing secrets, passwords, and files via one-time, auto-expiring links. Secrets are…
993087active
cel-expr/cel-go
cel-go is a Go implementation of the Common Expression Language (CEL), a fast, portable, non-Turing complete expression language with gradu…
993085stable
inspec/inspec
Chef InSpec is an open-source testing framework for infrastructure that expresses compliance, security, and policy requirements as human- a…
923085active
OpenSC/OpenSC
OpenSC is a set of open-source libraries and command-line tools for working with smart cards, focused on cards that perform cryptographic o…
803078active
krille-chan/fluffychat
FluffyChat is an open-source, nonprofit Matrix instant messaging client written in Flutter with a cute, easy-to-use Material You design. It…
953077active
Virtual-Browser/VirtualBrowser
VirtualBrowser is a free, open-source anti-fingerprint browser built on Chromium that lets users create and manage multiple isolated browse…
933077active
cloudflare/security-audit-skill
A coding-agent skill from Cloudflare that turns an LLM coding agent into a security auditor via a six-phase pipeline (recon, hunting, valid…
543077active
m0bilesecurity/RMS-Runtime-Mobile-Security
Runtime Mobile Security (RMS) is a NodeJS-powered web interface built on FRIDA for manipulating Android and iOS apps at runtime. It lets us…
833075active
ThePorgs/Exegol
Exegol is a container-based, community-driven hacking environment for offensive security professionals, managed through a Python CLI wrappe…
973072active
korcankaraokcu/PINCE
PINCE is a GDB front-end and reverse engineering tool for Linux, focused on game hacking but usable for general reverse engineering. It pro…
983069active
bpc-clone/bpc_firefox_support
Support and issue-tracking repository for Bypass Paywalls Clean, a Firefox browser extension that bypasses news site paywalls. Development …
343068active
darkoperator/dnsrecon
DNSRecon is a Python-based DNS enumeration tool for security assessments and network troubleshooting. It supports zone transfer checks, gen…
913061active
davesc63/GeoPort
GeoPort is a cross-platform desktop application that simulates GPS location on iOS devices running iOS 17 and 18, letting users spoof their…
613056active
claration/Impactor
Impactor is an open-source, cross-platform GUI application for signing and sideloading IPA apps onto iOS, iPadOS, and tvOS devices using an…
803053active
aliasvault/aliasvault
AliasVault is a privacy-first, end-to-end encrypted password manager with a built-in email alias server, letting users create unique identi…
863051active
OdysseusYuan/LKY_OfficeTools
A one-click Windows tool that automates downloading, installing, and activating the latest version of Microsoft Office, including optional …
2312567maintenance
open-quantum-safe/liboqs
liboqs is an open source C library providing implementations of quantum-resistant (post-quantum) key encapsulation mechanisms and digital s…
883044active
chromium/badssl.com
badssl.com is a hosted collection of test subdomains, each deliberately configured with a broken or unusual TLS/SSL setup (expired certific…
703043active
Qianlitp/crawlergo
crawlergo is a Go-based browser crawler that uses headless Chrome to discover URLs for web vulnerability scanners. It renders pages, fills …
273034active
6Kmfi6HP/EDtunnel
EDtunnel is a proxy tool deployed on Cloudflare Workers and Pages that supports VLESS and Trojan protocols with configurable proxy IPs, SOC…
583029active
cilame/v_jstools
v_jstools is a Chrome extension (Manifest V3) for debugging and reverse-engineering JavaScript on web pages. It provides API hooking, code …
583015active
Kevin-Robertson/Inveigh
Inveigh is a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers, with a primary C# version and a legacy Power…
533014active
evgenyneu/keychain-swift
A Swift library providing simple helper functions for securely storing and retrieving text, boolean, and Data values in the Apple Keychain.…
323012stable
f-droid/fdroidclient
The official Android client for F-Droid, the free and open-source software repository system. It lets users browse, install, and update FOS…
673011active
thinkst/opencanary
OpenCanary is a modular, multi-protocol network honeypot daemon written in Python, designed to detect attackers after they breach internal …
863003active
RavenSystem/esp-homekit-devices
HAA (Home Accessory Architect) is firmware that adds native Apple HomeKit support and custom configurations to ESP32 and ESP8266 based devi…
963002active
mgeeky/Penetration-Testing-Tools
A curated collection of 170+ penetration testing tools, scripts, and cheatsheets developed by the author over years of red teaming and IT s…
323001active
aws-actions/configure-aws-credentials
A GitHub Action that configures AWS credential environment variables for use in subsequent workflow steps. It supports OIDC federation for …
972996active
opengrep/opengrep
Opengrep is an open-source static application security testing (SAST) engine forked from Semgrep under LGPL-2.1, supporting pattern-based c…
842995active
adryfish/fingerprint-chromium
A fingerprint browser built on Ungoogled Chromium that lets users spoof or control browser fingerprint characteristics to avoid detection. …
762991active
kyujin-cho/pixel-volte-patch
Pixel IMS is a rootless Android application that enables VoLTE (IMS) on Google Tensor-based Pixel phones by overriding carrier configuratio…
682991active
tegal1337/CiLocks
CiLocks is a menu-driven Linux CLI toolkit for Android and iOS security testing, bundling lockscreen brute-force/bypass, ADB data extractio…
232991active
Manisso/fsociety
Fsociety is a Python-based penetration testing framework that bundles a menu of hacking tools covering information gathering, password atta…
7412275maintenance
baidu/openrasp
OpenRASP is Baidu's open-source Runtime Application Self-Protection (RASP) solution that embeds a protection engine directly into the appli…
432987stable
appleboy/gin-jwt
A JWT authentication middleware for the Gin web framework in Go, built on golang-jwt/jwt. It provides login handling, token refresh, and ro…
912973active
bethgelab/foolbox
Foolbox is a Python library for generating adversarial examples that fool deep neural networks, with state-of-the-art gradient-based and de…
482972active
makoto56/penetration-suite-toolkit
A preconfigured Windows 11 penetration testing toolkit distributed as a VM image, bundling a large curated collection of security tools wit…
342970active
frknkrc44/HMA-OSS
HMA-OSS is a Zygisk module that hides your app list, settings, and package installers from other apps on rooted Android devices. It is a Ko…
832968active
xiv3r/Burpsuite-Professional
A shell-based installer that deploys Burp Suite Professional (a commercial web security testing toolkit) on Linux and NixOS, bundled with a…
662968active
bytenode/bytenode
Bytenode is a minimalist bytecode compiler that compiles JavaScript into V8 bytecode (.jsc files) to protect source code. It works with Nod…
722966active
TheOfficialFloW/PPPwn
PPPwn is a proof-of-concept kernel remote code execution exploit for PlayStation 4 consoles up to firmware 11.00, exploiting CVE-2006-4304 …
242960active
strongswan/strongswan
strongSwan is an open-source, modular IPsec-based VPN solution implementing the IKEv2 (and IKEv1) key exchange protocols for securing IP tr…
872954stable
thewhiteh4t/FinalRecon
FinalRecon is an all-in-one automatic web reconnaissance tool written in Python that provides a fast overview of a web target. It bundles h…
702953active
eteran/edb-debugger
edb is a cross-platform AArch32/x86/x86-64 debugger inspired by OllyDbg, built with Qt and Capstone. It provides a graphical interface for …
662952active
corbindavenport/just-the-browser
A collection of configuration files and installation scripts that disable AI features, telemetry, sponsored content, and other annoyances i…
812951active
microsoft/AttackSurfaceAnalyzer
Attack Surface Analyzer is a Microsoft open-source security tool that scans an operating system's security configuration before and after s…
822950active
RfidResearchGroup/ChameleonUltra
ChameleonUltra is the open-source firmware for an RFID/NFC card emulation device based on the NRF52840, capable of reading, writing, decryp…
842949active
pquerna/otp
A Go library implementing Time-based (TOTP, RFC 6238) and HMAC-based (HOTP, RFC 4228) one-time password algorithms for adding two-factor au…
392944stable
microsoft/restler-fuzzer
RESTler is the first stateful REST API fuzzing tool, automatically testing cloud services through their REST APIs to find security and reli…
712939active
netwrix/pingcastle
PingCastle is a C# tool that assesses the security posture of Active Directory and Entra ID environments, producing risk scores, health che…
982937active
scottyab/rootbeer
RootBeer is an Android library that detects whether a device has been rooted using multiple Java and native checks such as scanning for su …
672937active
Metabolix/HackBGRT
HackBGRT is a UEFI application that changes the Windows boot logo by overwriting the Boot Graphics Resource Table (BGRT) during boot. It sh…
702931active
padloc/padloc
Padloc is an open-source, end-to-end encrypted password manager for individuals and teams, built as a monorepo with a Node.js backend serve…
292923active
wolfSSL/wolfssl
wolfSSL is a lightweight, portable SSL/TLS library written in ANSI C, supporting TLS 1.3 and DTLS 1.3, powered by the wolfCrypt cryptograph…
922919stable
calebstewart/pwncat
pwncat is a post-exploitation platform and handler for reverse and bind shells, written in Python. It wraps raw shell communication with an…
102917active
SnaffCon/Snaffler
Snaffler is a C# command-line tool for pentesters and red teamers that enumerates Windows/AD environments to find sensitive files (mostly c…
762915active
Roave/SecurityAdvisories
A Composer package that acts as an exclusion list of known security vulnerabilities, preventing installation of dependency versions with do…
772914active
palahsu/DDoS-Ripper
DDoS-Ripper (DRipper) is a Python command-line tool that floods a target IP with traffic to simulate a distributed denial-of-service attack…
722914active
onetimesecret/onetimesecret
A self-hostable web service for sharing sensitive information like passwords via single-use, self-destructing links. Written in Ruby with R…
952912active
firecracker-microvm/firecracker-containerd
firecracker-containerd is a set of components that lets containerd manage containers running inside Firecracker microVMs, combining fast co…
762910active
NexAlloy/NexAlloy
NexAlloy is an LSPosed (Xposed) module for rooted Android devices that applies ReVanced/Morphe-style patches to apps like YouTube, YouTube …
882903active
FiloSottile/yubikey-agent
yubikey-agent is a seamless ssh-agent that stores SSH keys on YubiKey hardware via the PIV smartcard interface. It runs in the background, …
322903stable
rs/cors
rs/cors is a Go library providing a configurable net/http handler that implements the Cross Origin Resource Sharing (CORS) W3C specificatio…
702898stable
LukeZGD/Legacy-iOS-Kit
An all-in-one shell-based tool for restoring, downgrading, jailbreaking, and saving SHSH blobs on legacy iOS devices vulnerable to bootrom …
672895active
pyllyukko/user.js
A hardened user.js configuration template for Mozilla Firefox that enforces security and privacy settings. It limits tracking, fingerprinti…
662891active
jayofelony/pwnagotchi
Pwnagotchi is a Raspberry Pi-based Wi-Fi penetration-testing gadget that leverages Bettercap to passively sniff or actively attack nearby W…
932886active
pwndoc/pwndoc
PwnDoc is a self-hosted web application for writing penetration test findings and generating customizable Docx reports. It supports multi-u…
982882active

← prev page 10 / 50 next →