function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| visa/visa-vulnerability-agentic-harness VVAH is Visa's open-source agentic harness for autonomous vulnerability discovery, remediation, and validation using frontier AI models. It… | 67 | 2601 | active |
| kboghdady/youTube_ads_4_pi-hole A shell script and maintained DNS blocklist for blocking YouTube ads via Pi-hole. It provides a regularly updated blacklist file to add to … | 32 | 2597 | active |
| mas-bandwidth/netcode A C library implementing a secure, connection-oriented client/server protocol on top of UDP for real-time multiplayer games. It handles enc… | 99 | 2595 | active |
| MeowDump/Integrity-Box Integrity Box is a Magisk module toolkit for rooted Android devices that manages Play Integrity attestation and system environment signals.… | 87 | 2591 | active |
| botswin/BotBrowser BotBrowser is a privacy-focused browser core (Chromium-based) that unifies and controls browser fingerprint signals across platforms, integ… | 85 | 2589 | active |
| shaka-project/shaka-packager Shaka Packager is a media packaging tool and SDK for preparing video content for online streaming via DASH and HLS. It supports VOD and liv… | 97 | 2588 | active |
| kubearmor/KubeArmor KubeArmor is a cloud-native runtime security enforcement system that restricts process execution, file access, and networking behavior of p… | 97 | 2588 | active |
| runkids/skillshare skillshare is a Go-based CLI tool that keeps AI CLI skills, agents, rules, and commands in sync across 60+ AI coding assistants (Claude Cod… | 77 | 2586 | active |
| mewebstudio/captcha A Laravel service provider package that generates CAPTCHA images for form protection, supporting Laravel 5 through 12. It offers session-ba… | 85 | 2583 | active |
| proot-me/proot PRoot is a user-space implementation of chroot, mount --bind, and binfmt_misc for Linux that requires no privileges or setup, built on ptra… | 66 | 2583 | active |
| apify/fingerprint-suite A modular TypeScript toolkit by Apify for generating realistic browser fingerprints and HTTP headers and injecting them into Playwright or … | 98 | 2581 | active |
| honmashironeko/ProxyCat ProxyCat is a self-hosted tunnel proxy pool middleware that turns short-lived proxy IPs into a stable fixed tunnel endpoint over HTTP/SOCKS… | 66 | 2581 | active |
| snake-4/Zygisk-Assistant A Zygisk module written in C++ that hides the existence of root and Zygisk from apps on Android 5.0 and above. It works with KernelSU, Magi… | 52 | 2581 | active |
| gaasedelen/lighthouse Lighthouse is a code coverage explorer plugin for IDA Pro and Binary Ninja that lets reverse engineers interactively visualize execution co… | 53 | 2577 | stable |
| nelenkov/android-backup-extractor A Java command-line utility that extracts and repacks Android backup archives created with adb backup, based on AOSP's BackupManagerService… | 86 | 2576 | active |
| sarperavci/CloudflareBypassForScraping A Python library that bypasses Cloudflare's anti-bot verification for web scraping, supporting cookie generation and request mirroring for … | 72 | 2576 | active |
| bytedance/bhook ByteHook is a production-grade Android PLT hook library written in C, supporting armeabi-v7a, arm64-v8a, x86, and x86_64. It lets native co… | 79 | 2570 | active |
| ajinabraham/nodejsscan nodejsscan is a static application security testing (SAST) scanner for Node.js applications, built on libsast and semgrep. It provides a we… | 44 | 2570 | active |
| pythops/oryx Oryx is a terminal user interface (TUI) application for sniffing and inspecting network traffic in real time using eBPF on Linux. It also p… | 76 | 2568 | active |
| rednaga/APKiD APKiD is a command-line tool that identifies how an Android APK was built, detecting compilers, packers, obfuscators, and app-shielding/RAS… | 78 | 2565 | active |
| BishopFox/cloudfox CloudFox is an open-source command line tool by Bishop Fox that automates situational awareness and enumeration in cloud environments, prim… | 90 | 2563 | active |
| hmgle/graftcp graftcp is a Linux command-line tool that redirects TCP, UDP, and DNS traffic of arbitrary processes to SOCKS5 or HTTP proxies using ptrace… | 97 | 2561 | active |
| caido/caido Caido is a lightweight web security auditing toolkit and HTTP proxy for intercepting, viewing, and modifying traffic between browsers and w… | 99 | 2558 | active |
| s0lst1c3/eaphammer EAPHammer is a toolkit for performing targeted evil twin attacks against WPA2-Enterprise networks, including credential stealing and hostil… | 23 | 2552 | active |
| cgsecurity/testdisk TestDisk and PhotoRec are free, open-source data recovery utilities written in C. TestDisk recovers lost partitions and repairs boot sector… | 76 | 2550 | stable |
| YeQing17-2026/OmniAgent OmniAgent is an open-source Python agent framework that self-evolves across skills, context, memory, and its underlying model during intera… | 56 | 2549 | active |
| NVISOsecurity/AlwaysTrustUserCerts A Magisk/KernelSU module that automatically copies user-installed certificates into the Android system root CA store. It enables TLS traffi… | 47 | 2549 | active |
| lgandx/PCredz PCredz is a Python CLI tool that extracts credentials and authentication tokens (NTLM, Kerberos, HTTP Basic, FTP, SMTP, IMAP, POP3, LDAP, S… | 64 | 2548 | active |
| bkerler/edl A Python CLI tool for communicating with Qualcomm devices in EDL (Emergency Download) mode via the Sahara, Firehose, Streaming, and Diag pr… | 66 | 2547 | active |
| monoxgas/sRDI sRDI is a shellcode implementation of Reflective DLL Injection that converts DLL files into position-independent shellcode via a compiled P… | 32 | 2547 | stable |
| splunk/attack_range Splunk Attack Range is a tool that builds instrumented, vulnerable lab environments in the cloud (AWS, Azure, GCP) or locally using Terrafo… | 84 | 2545 | active |
| 7h30th3r0n3/Evil-M5Project Evil-M5Project is a C++ firmware/tool for M5Stack devices (Cardputer, AtomS3, Fire, Core2) that scans, monitors, and interacts with WiFi ne… | 70 | 2543 | active |
| madeye/proxydroid ProxyDroid is an Android app that routes all device traffic through an upstream SOCKS5 or HTTP proxy without root, using a VpnService-based… | 70 | 2542 | active |
| evi0s/WMPFDebugger A debugger tweak for WeChat's Mini-Program Framework (WMPF) that exploits the remote debug feature of WeChat devtools to enable full Chrome… | 65 | 2542 | active |
| refraction-networking/utls uTLS is a fork of Go's crypto/tls library that provides low-level access to the TLS ClientHello message, enabling fingerprint mimicry and r… | 81 | 2539 | active |
| rabbitstack/fibratus Fibratus is a Windows security sensor that performs realtime threat detection by analyzing kernel and system telemetry (including ETW event… | 90 | 2537 | active |
| Barre/privaxy Privaxy is a MITM HTTP(S) proxy written in Rust that blocks ads and trackers at the network level, supporting Adblock Plus and uBlock Origi… | 23 | 2530 | active |
| sidex15/susfs4ksu-module A KernelSU addon module that installs userspace helpers (ksu_susfs, sus_su) to communicate with a SUSFS-patched kernel for kernel-level roo… | 86 | 2527 | active |
| x90skysn3k/brutespray Brutespray is a fast, multi-protocol credential brute-forcing tool written in Go. It parses scan output from Nmap, Nessus, Nexpose, JSON, a… | 95 | 2525 | active |
| DidierStevens/DidierStevensSuite A bundled collection of Didier Stevens' security research tools, distributed as a ZIP and GitHub repository of Python scripts and utilities… | 75 | 2525 | active |
| v0id4real/Void-Tools Void-Tools is a Python terminal multitool with a Rich TUI dashboard bundling 150+ utilities for OSINT research, network diagnostics, and Di… | 54 | 2524 | active |
| Mattiwatti/EfiGuard EfiGuard is a portable x64 UEFI bootkit that patches the Windows boot manager, boot loader, and kernel at boot time to disable PatchGuard a… | 62 | 2523 | active |
| pac4j/pac4j pac4j is a Java security engine for authenticating users, managing profiles, and enforcing authorizations across web applications and servi… | 77 | 2521 | stable |
| jedisct1/piknik Piknik is a command-line tool that securely copies and pastes clipboard content between arbitrary hosts over the network, using end-to-end … | 57 | 2516 | stable |
| kpcyrd/sn0int sn0int is a semi-automatic OSINT framework and package manager written in Rust that enumerates attack surface by processing public informat… | 60 | 2515 | active |
| rspamd/rspamd Rspamd is an advanced spam filtering system and email processing framework written in C with an extensive Lua plugin API. It evaluates mess… | 99 | 2514 | active |
| tobiabocchi/flipperzero-bruteforce A Python script that generates .sub files for brute-forcing fixed OOK code subghz protocols using a Flipper Zero device. It supports multip… | 32 | 2512 | active |
| CTurt/FreeDVDBoot FreeDVDBoot is a PlayStation 2 DVD Player exploit written in C that lets users burn homebrew discs which boot on unmodified PS2 consoles. I… | 32 | 2511 | stable |
| epsylon/ufonet UFONet is a free, P2P and cryptographic 'disruptive toolkit' written in Python for performing DoS and DDoS attacks at Layer 7 (HTTP) via Op… | 76 | 2509 | active |
| taamarin/box_for_magisk Box for Root (BFR) is a Magisk/KernelSU/APatch module that bundles proxy cores such as clash, sing-box, v2ray, hysteria, and xray to set up… | 58 | 2507 | active |
| SPIFFE SPIFFE is a framework and set of standards for issuing cryptographic identities to workloads, and SPIRE (the SPIFFE Runtime Environment) is… | 99 | 2500 | stable |
| bug-bit/fckvip An Android module (likely Magisk/LSPosed-based) that unlocks paid VIP memberships and enhances extended features in certain apps. It requir… | 74 | 2500 | active |
| m4ll0k/SecretFinder SecretFinder is a Python CLI script based on LinkFinder that discovers sensitive data like API keys, access tokens, and JWTs in JavaScript … | 32 | 2500 | active |
| mullvad/mullvad-browser Mullvad Browser is a privacy-focused desktop web browser developed jointly by Mullvad VPN and the Tor Project, essentially a Tor Browser de… | 98 | 2497 | active |
| quasar/Quasar Quasar is a free, open-source remote administration tool (RAT) for Windows written in C#, offering remote desktop, shell, file management, … | 10 | 9908 | maintenance |
| nil0x42/phpsploit PhpSploit is a full-featured command-and-control (C2) framework that persists on a webserver via a stealthy single-line PHP backdoor. It is… | 23 | 2491 | active |
| symfony/security-bundle SecurityBundle is the official Symfony bundle that integrates the Security component into the Symfony full-stack framework. It provides con… | 97 | 2489 | stable |
| ungoogled-software/ungoogled-chromium-windows Windows packaging and build scripts for ungoogled-chromium, a Chromium variant with all Google services and tracking removed. It provides b… | 95 | 2488 | active |
| HACKERALERT/Picocrypt Picocrypt is a very small, simple, and secure file encryption tool written in Go, using modern cryptography like XChaCha20, Argon2, and SHA… | 10 | 2488 | active |
| abrahamjuliot/creepjs CreepJS is a web application that performs advanced device and browser fingerprinting to expose weaknesses in anti-fingerprinting browsers … | 71 | 2486 | active |
| mCaptcha/mCaptcha mCaptcha is a self-hosted, privacy-respecting CAPTCHA system that uses SHA-256 proof-of-work to rate-limit users instead of image puzzles. … | 43 | 2486 | active |
| TH3xACE/SUDO_KILLER SUDO_KILLER is a Shell-based security tool that audits Linux systems for sudo-related privilege escalation vectors, including misconfigurat… | 64 | 2481 | active |
| LSPosed/AndroidHiddenApiBypass A pure-Java Android library that bypasses restrictions on non-SDK (hidden) interfaces, offering two variants: HiddenApiBypass (Unsafe-based… | 71 | 2480 | active |
| voidauth/voidauth VoidAuth is an open-source single sign-on (SSO) and user management provider for self-hosted applications, acting as an OIDC provider, prox… | 85 | 2478 | active |
| Proton VPN Official open-source Proton VPN client apps for Android and Windows, built by Proton AG to route traffic through Proton's VPN servers. The … | 91 | 2476 | active |
| unode/firefox_decrypt Firefox Decrypt is a Python command-line tool that extracts saved passwords from Mozilla product profiles (Firefox, Waterfox, Thunderbird, … | 77 | 2474 | active |
| coreos/go-oidc go-oidc is a mature Go client library for OpenID Connect, built on top of golang.org/x/oauth2. It enables verifying ID tokens and identifyi… | 89 | 2473 | stable |
| Ysurac/openmptcprouter OpenMPTCProuter is an OpenWrt-based router distribution that aggregates multiple internet connections (fiber, ADSL, 4G/5G, etc.) using Mult… | 77 | 2473 | active |
| sabri-zaki/EasY_HaCk EasY_HaCk is a Termux-based penetration testing menu tool that bundles and installs tools like Metasploit, Nmap, SQLmap, and recon-ng for n… | 43 | 2471 | active |
| archerysec/archerysec ArcherySec is an open-source application security orchestration and correlation (ASOC) and vulnerability management platform that integrate… | 34 | 2471 | active |
| seemoo-lab/AirGuard AirGuard is an Android app that protects users from unwanted tracking via AirTags and other Apple Find My accessories. It periodically scan… | 92 | 2468 | active |
| legendsayantan/ShizuTools ShizuTools is an Android app that provides a suite of tools for controlling the Android system beyond normal user permissions, using the Sh… | 71 | 2467 | active |
| Idov31/Nidhogg Nidhogg is an open-source Windows x64 kernel rootkit written in C++ that demonstrates a wide range of rootkit techniques such as process, t… | 83 | 2463 | active |
| builtbybel/CrapFixer CrapFixer is a lightweight Windows utility that cleans up junk, removes ads and preinstalled bloatware, and tweaks privacy settings on Wind… | 86 | 2461 | active |
| cisco-ai-defense/skill-scanner A security scanner for AI agent skills that detects prompt injection, data exfiltration, and malicious code patterns using pattern-based de… | 80 | 2460 | active |
| assetnote/react2shell-scanner A Python command-line scanner that detects RCE vulnerabilities CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server… | 41 | 2459 | active |
| Notselwyn/CVE-2024-1086 A proof-of-concept local privilege escalation exploit for CVE-2024-1086, a double-free vulnerability in the Linux kernel's nf_tables subsys… | 16 | 2457 | stable |
| mandiant/flare-ida A collection of IDA Pro plugins and IDAPython scripts from Mandiant's FLARE team for reverse engineering and malware analysis. It includes … | 10 | 2453 | active |
| square/certstrap certstrap is a Go-based CLI tool for bootstrapping your own certificate authorities and managing a simple public key infrastructure. It ini… | 52 | 2452 | active |
| DNSCrypt/SimpleDnsCrypt Simple DNSCrypt is a Windows GUI management tool for configuring dnscrypt-proxy. It simplifies setting up encrypted DNS on Windows systems. | 56 | 2450 | active |
| usnistgov/macos_security The macOS Security Compliance Project (mSCP) is an open-source tool from NIST that generates security baselines, configuration profiles, co… | 96 | 2449 | active |
| noob-hackers/hacklock Hacklock is a bash-based Termux tool that generates pattern phishing pages to capture an Android victim's unlock pattern via a shared link … | 53 | 2445 | active |
| Dewalt-arch/pimpmykali A shell script that applies a collection of fixes and configuration tweaks to freshly imported Kali Linux virtual machines. It offers an in… | 45 | 2444 | active |
| m0nad/Diamorphine Diamorphine is a loadable kernel module (LKM) rootkit for Linux kernels 2.6.x through 6.x on x86/x86_64 and ARM64. It demonstrates rootkit … | 68 | 2442 | active |
| XSS Hunter XSS Hunter Express is a self-hosted service for tracking and detecting blind cross-site scripting (XSS) vulnerabilities via injected payloa… | 32 | 2440 | active |
| find-sec-bugs/find-sec-bugs Find Security Bugs is a SpotBugs plugin that performs static security analysis of Java bytecode, detecting 144 vulnerability patterns inclu… | 56 | 2437 | active |
| dirkjanm/BloodHound.py BloodHound.py is a Python-based data ingestor for BloodHound that enumerates Active Directory domains, collecting users, groups, computers,… | 54 | 2437 | active |
| ramonvermeulen/whosthere Whosthere is a Local Area Network discovery tool with an interactive Terminal User Interface, written in Go. It discovers devices via mDNS,… | 83 | 2435 | active |
| brianshea2/addr.tools A collection of free DNS-based Internet utilities (dynamic DNS, public IP lookup, ACME dns-01 challenge helper, DNS resolver testing) plus … | 68 | 2432 | active |
| cloudflare/gokey gokey is a vaultless password manager written in Go that deterministically derives passwords and cryptographic keys on the fly from a maste… | 80 | 2431 | stable |
| ZerBea/hcxtools A set of C command-line tools that convert WiFi packet captures (pcap/pcapng) into hash formats compatible with Hashcat and John the Ripper… | 79 | 2431 | active |
| drk1wi/Portspoof Portspoof is a lightweight C++ tool that emulates open TCP ports and convincing service signatures across all 65535 ports, making port scan… | 85 | 2427 | active |
| NetSPI/MicroBurst MicroBurst is a PowerShell toolkit for assessing Microsoft Azure security, including service discovery, weak configuration auditing, and po… | 73 | 2426 | active |
| OneKeyHQ/app-monorepo OneKey is an open-source, multi-chain cryptocurrency wallet application supporting Bitcoin, Ethereum, Solana, Tron, and many other networks… | 99 | 2422 | active |
| GiacomoLaw/Keylogger A simple, bare-bones keylogger that records keystrokes and saves them to a local log file, with separate implementations for Windows, Linux… | 39 | 2421 | active |
| LoRexxar/Kunlun-M Kunlun-M is an open-source static code analysis (SAST) tool that detects security vulnerabilities in PHP, JavaScript/Node.js, Python, Golan… | 96 | 2413 | active |
| RevylAI/greenlight Greenlight is an offline CLI compliance scanner that checks mobile apps against Apple App Store Review Guidelines and Google Play Developer… | 71 | 2413 | active |
| wenlng/go-captcha GoCaptcha is a high-performance, modular behavioral CAPTCHA library for Go that generates interactive challenges including click, slide, dr… | 69 | 2411 | active |
| beenuar/AiSOC AiSOC is an open-source, self-hostable AI-powered Security Operations Center that fuses alerts, performs agent-assisted triage, purple-team… | 80 | 2408 | active |
| EmbarkStudios/cargo-deny cargo-deny is a Cargo plugin (cargo subcommand) for linting Rust dependency graphs. It checks crate licenses against allow/deny lists, bans… | 97 | 2407 | active |