function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| ChrispyBacon-dev/DockFlare DockFlare is a self-hosted Python/Flask application that watches Docker container events and automatically manages Cloudflare Tunnel ingres… | 85 | 2407 | active |
| anticensority/runet-censorship-bypass A browser extension for Chromium and Firefox that bypasses internet censorship in Russia using PAC (Proxy Auto-Config) scripts. It keeps th… | 66 | 2405 | active |
| hasherezade/hollows_hunter Hollows Hunter is a Windows command-line tool built on the PE-sieve passive memory scanner that scans running processes for malicious impla… | 71 | 2401 | active |
| JayBizzle/Crawler-Detect CrawlerDetect is a zero-dependency PHP library that detects bots, crawlers, and spiders by matching User-Agent and HTTP_FROM headers agains… | 95 | 2400 | active |
| zfl9/ss-tproxy A shell script that sets up transparent proxying on Linux using iptables/nftables TPROXY and REDIRECT rules, working with clients like ss-l… | 51 | 2394 | active |
| kubeovn/kube-ovn Kube-OVN is a CNCF Sandbox CNI plugin that integrates OVN-based network virtualization with Kubernetes, providing an advanced container net… | 95 | 2393 | active |
| htrgouvea/nipe Nipe is a Perl-based command-line engine that routes all of a machine's network traffic through the Tor network by manipulating iptables/ip… | 72 | 2387 | active |
| XZB-1248/Spark Spark is a web-based, cross-platform Remote Administration Tool (RAT) written in Go that lets you monitor and control devices from a browse… | 55 | 2381 | active |
| DataDog/stratus-red-team Stratus Red Team is a self-contained Go CLI that emulates granular, actionable cloud attack techniques mapped to MITRE ATT&CK, against AWS,… | 99 | 2379 | active |
| bootleg/ret-sync ret-sync is a set of plugins that synchronize a debugging session (WinDbg, GDB, LLDB, OllyDbg, x64dbg) with disassemblers (IDA, Ghidra, Bin… | 53 | 2378 | active |
| dndx/phantun Phantun is a lightweight, high-performance UDP-to-TCP obfuscator written in safe Rust that disguises UDP packets as TCP streams to pass thr… | 72 | 2376 | active |
| hisxo/gitGraber gitGraber is a Python3 command-line tool that monitors GitHub search results in real time to find leaked sensitive data such as API keys an… | 66 | 2376 | active |
| OPCFoundation/UA-.NETStandard The official OPC Foundation reference implementation of the OPC Unified Architecture (OPC UA) protocol for .NET, providing client, server, … | 93 | 2375 | stable |
| lihenggui/blocker Blocker is an Android application that manages app components (activities, services, receivers, providers) using PackageManager and Intent … | 72 | 2374 | active |
| eslint-community/eslint-plugin-security An ESLint plugin providing security-focused linting rules for Node.js code. It flags potential security hotspots like eval usage, unsafe ch… | 86 | 2372 | active |
| bytedance/android-inline-hook Shadowhook is an Android inline hook library written in C, supporting armeabi-v7a (thumb/arm32) and arm64-v8a architectures on Android 4.1 … | 84 | 2372 | active |
| mkj/dropbear Dropbear is a small SSH server and client written in C, designed for low memory and disk footprints. It is widely used on embedded Linux sy… | 91 | 2371 | stable |
| slimm609/checksec A Go rewrite of the classic checksec tool that inspects security hardening properties (RELRO, stack canaries, NX, PIE, FORTIFY_SOURCE, CFI)… | 86 | 2371 | active |
| lijiejie/BBScan BBScan is a fast, lightweight, high-concurrency web vulnerability scanner written in Python. It helps penetration testers quickly identify … | 23 | 2371 | active |
| LSPosed/LSPatch LSPatch is a non-root implementation of the LSPosed Xposed framework that integrates the Xposed API into target Android APKs by inserting d… | 10 | 9336 | maintenance |
| mojocn/base64Captcha A Go library that generates various types of captchas (digits, strings, math, Chinese, audio) and returns them as base64-encoded image or a… | 54 | 2367 | stable |
| Impostor/Impostor Impostor is an open-source reimplementation of the Among Us game server, written in C#. It fully replaces the official server, supports plu… | 87 | 2362 | active |
| FiloSottile/whoami.filippo.io A public SSH server (written in Go) that identifies visitors by enumerating the public keys their SSH client offers and matching them again… | 67 | 2361 | stable |
| jorhelp/Ingram Ingram is a Python-based vulnerability scanning framework targeting network cameras (IP/CCTV devices). It integrates known exploits for com… | 67 | 2356 | active |
| unrolled/secure Secure is an HTTP middleware library for Go that adds quick security wins to web applications. It works as a standard net/http Handler and … | 70 | 2354 | stable |
| jtpereyda/boofuzz boofuzz is a Python-based network protocol fuzzing framework and the successor to the Sulley Fuzzing Framework. It provides data generation… | 66 | 2354 | active |
| int128/kubelogin kubelogin is a kubectl plugin (kubectl oidc-login) for Kubernetes OpenID Connect authentication, running as a client-go credential plugin. … | 93 | 2351 | active |
| MikeMcQuaid/strap Strap is a bash script (with a small companion web app) that bootstraps a minimal macOS development system. It applies security settings, i… | 76 | 2348 | active |
| david942j/one_gadget A Ruby command-line tool that finds one-gadget RCE candidates (execve('/bin/sh',...) call sites) in libc binaries for CTF pwn challenges. I… | 67 | 2346 | active |
| MegaManSec/SSH-Snake SSH-Snake is a self-propagating, file-less bash script that automatically discovers SSH private keys on a system, attempts to connect to re… | 10 | 2342 | active |
| AabyssZG/SpringBoot-Scan SpringBoot-Scan is an open-source penetration testing framework targeting Spring Boot applications, written in Python. It scans for sensiti… | 53 | 2340 | active |
| dnakov/little-rat A small Chrome extension that monitors and optionally blocks network calls made by other browser extensions. It requires the extensions-on-… | 34 | 2340 | active |
| MatinSenPai/SenPaiScanner SenPai Scanner is a lightweight, cross-platform Cloudflare IP and endpoint scanner written in Go. It probes Cloudflare edge IPs, validates … | 78 | 2339 | active |
| hzqst/VmwareHardenedLoader A Windows kernel driver that mitigates VMware VM detection by filtering VMware-related firmware strings and blocking VMware PnP registry en… | 87 | 2334 | active |
| rabobank-cdc/DeTTECT DeTT&CT is a Python CLI tool and framework that helps blue teams score and map data source quality, visibility, detection coverage, and thr… | 75 | 2334 | active |
| googleprojectzero/fuzzilli Fuzzilli is a coverage-guided fuzzer for JavaScript engines, built in Swift by Google Project Zero. It generates test programs via a custom… | 67 | 2334 | active |
| BeichenDream/GodPotato GodPotato is a C# Windows privilege escalation tool that abuses a DCOM/RPCSS oxid resolution defect to elevate from a service account with … | 22 | 2334 | stable |
| nfcgate/nfcgate NFCGate is an Android application for capturing, analyzing, modifying, relaying, replaying, and cloning NFC traffic. It is a security resea… | 84 | 2333 | active |
| kubernetes-sigs/aws-iam-authenticator A tool that lets users authenticate to Kubernetes clusters using AWS IAM credentials instead of separate certificates or tokens. It runs as… | 99 | 2332 | active |
| Ch0pin/medusa MEDUSA is a modular automation framework and script repository for runtime testing and investigating Android and iOS apps, built on FRIDA. … | 84 | 2332 | active |
| googleprojectzero/sandbox-attacksurface-analysis-tools A suite of PowerShell tools and .NET libraries from Google Project Zero for analyzing Windows sandbox attack surfaces. It includes NtCoreLi… | 56 | 2332 | active |
| bigbrodude6119/flipper-zero-evil-portal A Flipper Zero application that turns the Wi-Fi dev board (ESP32) into an open access point serving a fake captive portal login page. Captu… | 19 | 2332 | active |
| crev-dev/cargo-crev cargo-crev is a cryptographically verifiable, distributed code review system for the Rust cargo package manager. It lets developers review … | 85 | 2330 | active |
| ssl/ezXSS ezXSS is a self-hosted PHP application that helps penetration testers and bug bounty hunters detect and exploit (blind) cross-site scriptin… | 64 | 2330 | active |
| gjtorikian/html-pipeline A Ruby library providing a small framework of chainable filters for processing user-supplied content into HTML. It supports text filters, c… | 70 | 2329 | active |
| vpnhood/VpnHood VpnHood is an open-source, cross-platform VPN client and server built entirely from scratch in C#/.NET, designed to be undetectable by deep… | 98 | 2327 | active |
| onury/accesscontrol A Node.js library implementing Role-Based Access Control (RBAC) merged with Attribute-Based Access Control (ABAC), including role inheritan… | 96 | 2327 | active |
| rancher/rke2 RKE2 (RKE Government) is Rancher's fully conformant, next-generation Kubernetes distribution focused on security and compliance, particular… | 94 | 2325 | active |
| hwdsl2/wireguard-install A Bash script that automates setting up a WireGuard VPN server on various Linux distributions, with interactive and fully automatic install… | 77 | 2325 | active |
| safebuffer/vulnerable-AD A PowerShell script that configures a Windows Server domain controller into a deliberately vulnerable Active Directory environment for prac… | 32 | 2325 | active |
| quenhus/uBlock-Origin-dev-filter A set of uBlock Origin filter lists that hide copycat and SEO-spam websites from search results on Google, DuckDuckGo, and other engines. I… | 40 | 2322 | active |
| LifeArchiveProject/WeChatDataAnalysis A desktop application that decrypts WeChat 4.x's encrypted local databases (SQLCipher/WCDB) by scanning memory for the key, then lets users… | 85 | 2321 | active |
| keepassxreboot/keepassxc-browser KeePassXC-Browser is a WebExtension that integrates the KeePassXC password manager with Firefox, Chrome/Chromium, and Edge via native messa… | 95 | 2320 | active |
| V2Ray for OpenWrt OpenWrt/LEDE package definitions (Makefiles) for building and installing V2Ray core on OpenWrt routers, distributed via opkg feeds or prebu… | 99 | 2318 | active |
| UMSKT/UMSKT UMSKT (Universal MS Key Toolkit) is an open-source C++ CLI toolkit for researching and experimenting with Microsoft's pre-Vista (pre-2012) … | 78 | 2318 | active |
| kylemanna/docker-openvpn A Docker image and shell tooling that runs an OpenVPN server in a container, bundled with an EasyRSA PKI certificate authority. It automate… | 33 | 9089 | maintenance |
| MasterKale/SimpleWebAuthn SimpleWebAuthn is a collection of TypeScript-first libraries (@simplewebauthn/server and @simplewebauthn/browser) that simplify adding WebA… | 95 | 2316 | active |
| ps5-linux/ps5-linux-loader A Linux payload that uses hypervisor (HV) exploits to boot a custom Linux bootloader on PS5 Phat and Slim consoles running firmware 3.00-7.… | 78 | 2315 | active |
| p0dalirius/Coercer Coercer is a Python CLI tool that automatically coerces Windows servers to authenticate to an arbitrary machine via multiple RPC methods ov… | 58 | 2310 | active |
| h9zdev/WireTapper WireTapper is a wireless OSINT tool that passively detects and maps nearby radio-emitting devices such as Wi-Fi access points, Bluetooth de… | 51 | 2310 | active |
| JingMatrix/TEESimulator TEESimulator is an Android module that defeats hardware-backed key attestation by running AOSP's reference KeyMint trusted application insi… | 83 | 2307 | active |
| owerdogan/whoami-project Whoami is a user-friendly privacy and anonymity CLI tool for Debian and Arch-based Linux distributions. It bundles 9+ modules such as IP ch… | 44 | 2303 | active |
| ggerganov/kbd-audio A collection of command-line and GUI tools that capture and analyze microphone audio to recover keyboard keystrokes acoustically. Its Keyta… | 23 | 9024 | maintenance |
| bjdgyc/anylink AnyLink is an enterprise-grade SSL VPN server written in Go that supports many concurrent remote-access users. It implements the OpenConnec… | 88 | 2301 | active |
| 1N3/BruteX BruteX is a shell-based CLI tool that automatically brute forces all services running on a target, enumerating open ports, usernames, and p… | 23 | 2299 | active |
| n1nj4sec/pupy Pupy is an open-source, cross-platform (Windows, Linux, macOS, Android) command-and-control and post-exploitation framework written in Pyth… | 10 | 8999 | maintenance |
| jofpin/trape Trape is an OSINT analysis and research tool for tracking people online and executing real-time social engineering attacks, built in Python… | 32 | 8978 | maintenance |
| sh-dv/hat.sh Hat.sh is a browser-based web application for secure local file encryption and decryption using XChaCha20-Poly1305 with chunked streaming v… | 23 | 2291 | active |
| gnuton/asuswrt-merlin.ng A fork of the Asuswrt-Merlin third-party firmware that extends support to additional ASUS routers, including DSL and WiFi 6/7 models. It pr… | 89 | 2290 | active |
| yeojz/otplib otplib is a TypeScript-first library for generating and verifying one-time passwords (HOTP and TOTP) for two-factor authentication, compati… | 99 | 2289 | active |
| acidicoala/SmokeAPI SmokeAPI is a C++ library that hooks the Steamworks SDK to emulate DLC and inventory item ownership in Steam games the user legitimately ow… | 83 | 2289 | active |
| lz520520/railgun Railgun is a GUI-based penetration testing tool that automates common tasks from manual pentesting experience. It integrates port scanning,… | 35 | 2289 | active |
| API-Security/APIKit APIKit is a BurpSuite extension (Java plugin) that discovers, scans, and audits leaked API documentation such as GraphQL, OpenAPI/Swagger, … | 23 | 2286 | active |
| gautamkrishnar/nothing-private Nothing Private is a proof-of-concept website demonstrating that browser fingerprinting can identify and track users even in private browsi… | 48 | 2285 | active |
| squat/kilo Kilo is a multi-cloud network overlay for Kubernetes built on WireGuard, providing an encrypted layer 3 network that connects nodes across … | 78 | 2284 | active |
| allenymt/PrivacySentry PrivacySentry is an Android privacy compliance toolkit combining a Gradle plugin with a runtime SDK, using annotations plus ASM bytecode in… | 49 | 2283 | active |
| boxlite-ai/boxlite BoxLite is an embeddable micro-VM runtime written in Rust that runs any OCI image inside hardware-isolated virtual machines (KVM on Linux, … | 80 | 2278 | active |
| CravateRouge/bloodyAD bloodyAD is a Python CLI tool for Active Directory privilege escalation that performs specific LDAP calls against domain controllers. It su… | 97 | 2275 | active |
| Zouuup/landrun Landrun is a lightweight CLI tool that sandboxes arbitrary Linux processes using the kernel's Landlock security module, with no root privil… | 83 | 2274 | active |
| bank-vaults/bank-vaults Bank-Vaults is a CNCF Sandbox umbrella project of tools for cloud-native secret management with Hashicorp Vault. This repository provides t… | 86 | 2267 | active |
| httptoolkit/frida-interception-and-unpinning A collection of Frida scripts that rewrite mobile applications at runtime to bypass certificate pinning and route all HTTPS traffic through… | 76 | 2266 | active |
| 11notes/docker-kms A Dockerized KMS (Key Management Service) server that can activate Windows and volume-licensed Microsoft Office products indefinitely. It s… | 54 | 2264 | active |
| Caligatio/jsSHA jsSHA is a pure TypeScript/JavaScript library implementing the complete SHA hash family (SHA-1, SHA-2, SHA-3, SHAKE, cSHAKE, KMAC) plus HMA… | 85 | 2263 | stable |
| Wind4/vlmcsd vlmcsd is a KMS (Key Management Service) emulator written in C that can activate Windows and Microsoft Office products. It runs as a daemon… | 10 | 8844 | maintenance |
| google/boringssl BoringSSL is Google's fork of OpenSSL, serving as the TLS/SSL library in Chrome, Chromium, and Android. It is open source but explicitly no… | 99 | 2262 | active |
| RustCrypto/hashes A collection of cryptographic hash function implementations written in pure Rust, organized as separate crates built on the digest crate's … | 77 | 2258 | active |
| iText iText is a high-performance PDF library/SDK for Java and .NET that lets developers create, manipulate, inspect, sign, and secure PDF docume… | 93 | 2255 | stable |
| ProjectOpenSea/seaport Seaport is a Solidity-based marketplace protocol for safely and efficiently buying and selling NFTs, with listings composed of arbitrary of… | 67 | 2255 | active |
| ARM-software/arm-trusted-firmware Trusted Firmware-A (TF-A) is a reference implementation of secure world software (EL3 firmware, trusted boot, and a small trusted runtime) … | 77 | 2251 | active |
| spyboy-productions/CloakQuest3r CloakQuest3r is a Python-based open-source security research tool that identifies potential origin IP exposure of websites protected by Clo… | 54 | 2250 | active |
| julian-klode/dns66 DNS66 is an open-source Android app that blocks ads and malicious hosts by intercepting DNS queries through a local VPN service. It uses co… | 10 | 2248 | active |
| Foxboron/sbctl sbctl is a user-friendly Secure Boot key manager for Linux written in Go. It creates and enrolls UEFI Secure Boot keys, tracks files that n… | 72 | 2247 | active |
| neurobin/shc shc is a generic shell script compiler that converts shell scripts (bash, sh, zsh, ksh, etc.) into C source code, which is then compiled in… | 23 | 2246 | stable |
| salesforce/cloudsplaining Cloudsplaining is an AWS IAM security assessment tool that identifies violations of least privilege in IAM policies. It generates a risk-pr… | 86 | 2244 | active |
| Versent/saml2aws saml2aws is a Go CLI tool that authenticates against SAML-based identity providers such as ADFS and PingFederate and exchanges the SAML ass… | 49 | 2241 | active |
| gsliepen/tinc Tinc is a peer-to-peer VPN daemon that creates encrypted private networks over the Internet with automatic full-mesh routing and NAT traver… | 80 | 2239 | stable |
| ckcr4lyf/EvilAppleJuice-ESP32 An ESP32 firmware written in C++ that spams Apple Continuity BLE advertisements to flood nearby iPhones with pop-up notifications. It is ba… | 66 | 2236 | active |
| srvrco/getssl A Bash-based CLI tool for obtaining and automatically renewing free SSL/TLS certificates from the Let's Encrypt ACME server. It can deploy … | 95 | 2230 | active |
| pen4uin/java-memshell-generator A highly customizable Java in-memory webshell (memshell) generator supporting multiple middleware servers, frameworks, shell types, and out… | 37 | 2230 | active |
| JingMatrix/NeoZygisk NeoZygisk is a Zygote injection module implemented via ptrace that provides Zygisk API support for APatch and KernelSU, and can replace Mag… | 87 | 2227 | active |