function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| DanOps-1/Gpt-Agreement-Payment A Python toolkit that reverse-engineers and replays the end-to-end ChatGPT Plus/Team/Pro subscription payment flow (Stripe Checkout, PayPal… | 53 | 2225 | active |
| grimdoomer/Xbox360BadUpdate A non-persistent, software-only hypervisor exploit for the Xbox 360 that runs unsigned code on the latest dashboard (17559) using a support… | 10 | 2221 | active |
| shwenzhang/AndResGuard AndResGuard is a tool from the WeChat team that obfuscates and shrinks Android APK resources, working like ProGuard but for resource files … | 23 | 8645 | maintenance |
| SysSec-KAIST/LTESniffer LTESniffer is an open-source LTE downlink/uplink eavesdropper built on FALCON and srsRAN that decodes PDCCH, PDSCH, and PUSCH channels to c… | 20 | 2219 | active |
| asdcorp/ohook ohook is a C-written hook library that masquerades as the Office sppc.dll to intercept the SLGetLicensingStatusInformation license check, e… | 19 | 2218 | active |
| nielsfaber/alarmo Alarmo is a Home Assistant custom integration that turns existing sensors into a full-featured home alarm system, configurable entirely thr… | 93 | 2216 | active |
| punk-security/dnsReaper DNS Reaper is a Python CLI tool that scans DNS records for subdomain takeover vulnerabilities using over 50 signatures, at roughly 50 subdo… | 58 | 2216 | active |
| AbsInt/CompCert CompCert is a formally verified C compiler whose correctness is machine-checked with the Coq proof assistant, guaranteeing generated assemb… | 78 | 2215 | active |
| eeeeeeeeee-code/e0e1-wx A Windows GUI tool (PySide6, Python 3.10+) for analyzing and penetration-testing WeChat mini-programs locally. It automates mini-program pa… | 80 | 2214 | active |
| kaaass/ZerotierFix An unofficial ZeroTier Android client patched from the official app, adding features like self-hosted Moon support, custom planet configura… | 23 | 2212 | active |
| Encryqed/Dumper-7 Dumper-7 is a C++ DLL that, when injected into an Unreal Engine game, generates a full C++ SDK (headers for engine classes, functions, and … | 96 | 2211 | active |
| fly8888/cursor_machine_id A cross-platform set of Python, shell, and batch scripts that reset the device/machine identifiers used by the Cursor editor to bypass devi… | 46 | 2211 | active |
| kismetwireless/kismet Kismet is a wireless network detector, sniffer, and intrusion detection system for Wi-Fi, Bluetooth, SDR, and other wireless protocols. It … | 77 | 2210 | active |
| login-securite/lsassy Lsassy is a Python CLI tool that remotely extracts credentials from the LSASS process memory of Windows hosts over the network. It uses imp… | 71 | 2210 | active |
| m13253/dns-over-https A high-performance DNS-over-HTTPS (DoH) client and server written in Go, supporting both the Google DoH JSON API and IETF RFC 8484 wire for… | 62 | 2204 | active |
| qwj/python-proxy pproxy is a lightweight asynchronous tunnel proxy implemented in pure Python 3 asyncio, supporting HTTP, HTTP2, HTTP3/QUIC, SOCKS4/5, Shado… | 32 | 2204 | active |
| yandex/gixy Gixy is a Python-based static analyzer for Nginx configuration files that detects security misconfigurations and flaws. It ships as a CLI t… | 23 | 8566 | maintenance |
| baresip/baresip Baresip is a portable and modular SIP User-Agent written in C with audio and video call support. It provides a rich feature set including m… | 95 | 2202 | active |
| AdventDevInc/kudu Kudu is a free, open-source (MIT) system maintenance suite for Windows, macOS, and Linux offering 15+ tools including a system cleaner, mal… | 77 | 2201 | active |
| lefayjey/linWinPwn linWinPwn is a bash script that wraps and streamlines a large set of Active Directory penetration testing tools such as impacket, bloodhoun… | 77 | 2200 | active |
| alangrainger/immich-public-proxy A stateless proxy that sits in front of a self-hosted Immich instance and serves only explicitly shared photos, videos, and albums to the p… | 84 | 2198 | active |
| TheMythologist/GenP GenP is an open-source AutoIt patcher that applies binary hex patches to Adobe Creative Cloud applications on Windows to modify their licen… | 78 | 2196 | active |
| lkarlslund/Adalanche Adalanche is an open-source Active Directory attack graph visualizer and explorer written in Go. It collects data via LDAP and SYSVOL, anal… | 67 | 2195 | active |
| jwt-dotnet/jwt Jwt.Net is a C# library for generating, encoding, decoding, and validating JSON Web Tokens (JWT) per RFC 7519. It includes fluent builder A… | 92 | 2194 | stable |
| ghostunnel/ghostunnel Ghostunnel is a simple TLS proxy written in Go that adds mutual TLS authentication in front of (or behind) non-TLS backend services, in cli… | 99 | 2192 | active |
| MatthewKuKanich/FindMyFlipper A FlipperZero application that turns the device into a BLE tracker beacon emulating Apple AirTags, Samsung SmartTags, or Tile trackers. It … | 22 | 2192 | active |
| bytecode77/r77-rootkit r77 is a fileless ring 3 (userland) rootkit for Windows that hides files, processes, registry keys, services, and network connections using… | 75 | 2191 | active |
| tdurieux/anonymous_github Anonymous GitHub is a proxy server that anonymizes GitHub repositories (owner, org, repo name, file names, and file contents) so researcher… | 77 | 2190 | active |
| NeilFraser/JS-Interpreter A sandboxed JavaScript interpreter written in JavaScript that executes arbitrary ES5 code in isolation and safety. It supports line-by-line… | 72 | 2185 | active |
| jqssun/android-titanium-browser Titanium Browser is a secure, fully open-source Chromium-based Android browser forked from GrapheneOS's Vanadium, with support for Chrome a… | 84 | 2184 | active |
| ZerBea/hcxdumptool hcxdumptool is a C-based command-line tool that captures packets from WLAN devices and runs layer 2 attacks against the WPA protocol to fin… | 79 | 2184 | active |
| mandiant/flare-fakenet-ng FakeNet-NG is a dynamic network analysis tool that intercepts and redirects network traffic while simulating legitimate network services. I… | 63 | 2183 | active |
| ranisalt/node-argon2 Node.js bindings to the reference Argon2 password-hashing implementation, supporting Argon2i, Argon2d, and Argon2id. It provides a simple a… | 93 | 2182 | stable |
| DigitalRuby/IPBan IPBan is a free, open-source security service that monitors failed login attempts from event logs and log files on Windows and Linux server… | 84 | 2180 | active |
| 0vercl0k/rp rp++ is a fast C++ command-line tool that finds ROP (Return-Oriented Programming) gadgets in PE, ELF, and Mach-O binaries for x86, x64, ARM… | 44 | 2180 | active |
| ovh/the-bastion The Bastion is a self-hosted SSH bastion/gateway that acts as the single entry point for operational teams to access infrastructure devices… | 90 | 2177 | stable |
| Harry24k/adversarial-attacks-pytorch Torchattacks is a PyTorch library providing implementations of adversarial attacks to generate adversarial examples against deep learning m… | 23 | 2177 | active |
| kimci86/bkcrack bkcrack is a command-line tool that cracks legacy ZIP encryption (ZipCrypto/PKWARE) using Biham and Kocher's known plaintext attack. Given … | 73 | 2176 | active |
| Ylarod/Florida Florida is an automatically patched, anti-detection build of frida-server for Android, tracking the upstream FRIDA project. It rebuilds fri… | 89 | 2175 | active |
| assafdori/bypass-mdm A shell script that bypasses Mobile Device Management (MDM) enrollment during macOS setup, supporting versions up to macOS Tahoe 26.3. It r… | 55 | 2175 | active |
| safe-fndn/safe-smart-account Safe Smart Account is the set of audited Solidity smart contracts implementing Safe's multisig smart account (contract wallet) for Ethereum… | 69 | 2174 | active |
| wasmi-labs/wasmi Wasmi is an efficient, lightweight WebAssembly interpreter written in Rust, focused on constrained and embedded (no_std) environments. It o… | 94 | 2173 | active |
| AhmetCanArslan/ShizuWall ShizuWall is a lightweight Android firewall app that controls per-app network access without using a VPN tunnel. It works on Android 11+ by… | 83 | 2172 | active |
| loc567/loc567 loc567 is a fully open-source, free, purely web-based iOS mock location tool that works through Safari without a computer, jailbreak, or Tr… | 53 | 2170 | active |
| lenucksi/aur-malware-check A Python CLI tool that detects compromised AUR packages from the June 2026 atomic-lockfile supply-chain attack and other historical campaig… | 54 | 2168 | active |
| dchristl/macless-haystack Macless-Haystack is a self-hosted application that lets you build your own Apple FindMy network tracker using OpenHaystack-compatible hardw… | 77 | 2167 | active |
| zmap/zgrab2 ZGrab2 is a fast, modular application-layer network scanner written in Go, designed for large Internet-wide surveys in tandem with ZMap. It… | 75 | 2167 | active |
| salesforce/policy_sentry Policy Sentry is a Python CLI tool and library that generates least-privilege AWS IAM policies. It automates writing security-conscious IAM… | 88 | 2166 | stable |
| LukeSmithxyz/emailwiz A shell script that automates installing and configuring a full email server on Debian/Ubuntu using Postfix, Dovecot, Spamassassin, OpenDKI… | 41 | 2166 | active |
| beelzebub-labs/beelzebub Beelzebub is an open-source deception runtime framework written in Go that deploys adaptive, LLM-powered honeypot decoy services across SSH… | 98 | 2165 | active |
| p4gefau1t/trojan-go Trojan-Go is a full-featured Trojan proxy written in Go that disguises proxy traffic as normal TLS traffic to bypass censorship systems lik… | 23 | 8388 | maintenance |
| alexbers/mtprotoproxy A fast, async MTProto proxy server for Telegram written in Python, deployable via Docker or directly. It supports channel advertising via M… | 73 | 2163 | stable |
| zhzyker/dismap Dismap is a Go-based asset discovery and identification tool that fingerprints web, TCP, UDP, and TLS services using a rule base of 4500+ w… | 23 | 2163 | active |
| projectcapsule/capsule Capsule is a Kubernetes Operator that turns a single cluster into a shared multi-tenant platform by grouping namespaces into Tenant abstrac… | 99 | 2162 | active |
| BishopFox/unredacter Unredacter is an Electron-based desktop tool that demonstrates how pixelated redactions in images can be reversed by brute-force guessing t… | 32 | 8382 | maintenance |
| dronesploit/dronesploit DroneSploit is a Metasploit-style console framework for pentesting commercial drones, built on sploitkit. It gathers drone-focused hacking … | 23 | 2161 | active |
| jar-analyzer/jar-analyzer A free, open-source GUI tool for analyzing Java JAR files, offering method call relationship search, DFS call chain analysis, taint analysi… | 94 | 2158 | active |
| ffffffff0x/f8x f8x is a Bash-based automation deployment script that installs 100+ security and development tools for red team, blue team, CTF, and cloud-… | 65 | 2156 | active |
| microsoft/SysmonForLinux Sysmon for Linux is a Sysinternals tool that monitors and logs system activity such as process lifetime, network connections, and file syst… | 86 | 2153 | active |
| vulhub/java-chains Java Chains is a self-hosted web platform for generating Java exploitation payloads, aimed at security researchers. It supports common Java… | 89 | 2152 | active |
| HomeSpan/HomeSpan HomeSpan is an Arduino library for building custom Apple HomeKit accessories on ESP32 microcontrollers, implementing the HAP-R2 protocol di… | 89 | 2151 | active |
| 0Chencc/CTFCrackTools CTFCrackTools X is a cross-platform desktop CTF toolkit built with Rust and Tauri, featuring a visual node-based workflow for composing enc… | 80 | 2146 | active |
| bit4woo/domain_hunter_pro Domain Hunter Pro is a Burp Suite plugin (Java jar) for automated domain and subdomain collection, web title fetching, and target managemen… | 63 | 2145 | active |
| sashs/Ropper Ropper is a Python CLI tool that displays information about binary files (ELF, PE, Mach-O, RAW) and finds ROP/JOP gadgets to build exploit … | 77 | 2144 | active |
| 7723mod/NPatch NPatch is a rootless Xposed framework forked from LSPatch, based on LSPosed, that injects Xposed modules into target APKs by inserting dex … | 84 | 2143 | active |
| Infisical/agent-vault Agent Vault is an open-source HTTP credential proxy and vault by Infisical that sits between AI agents and the APIs they call. It stores cr… | 80 | 2141 | active |
| thinkst/canarytokens Canarytokens is a self-hostable service by Thinkst that generates tripwire tokens (URLs, DNS names, AWS keys, files, etc.) which alert you … | 76 | 2140 | active |
| last-byte/PersistenceSniper PersistenceSniper is a PowerShell module for hunting persistence mechanisms implanted in Windows machines. It is aimed at Blue Teams, Incid… | 34 | 2139 | active |
| datatheorem/TrustKit TrustKit is an open-source Objective-C framework that simplifies deploying SSL public key pinning and reporting in iOS, macOS, tvOS, and wa… | 78 | 2138 | active |
| fortra/nanodump NanoDump is a C-based tool that creates minidumps of the Windows LSASS process using a variety of stealthy handle-acquisition and dumping t… | 32 | 2137 | active |
| afaa1991/BetterWX-UI A Windows desktop utility that patches WeChat, WeCom, DingTalk, and Douyin chat clients to allow running multiple instances simultaneously,… | 55 | 2135 | active |
| PowerShell/Win32-OpenSSH A Win32 port of OpenSSH for Windows, now serving as a release and issue tracker plus wiki for the project. Active development has moved to … | 53 | 8252 | maintenance |
| teddysun/shadowsocks_install A collection of shell scripts that automatically install and configure Shadowsocks and ShadowsocksR proxy servers (Python, libev, and Go va… | 64 | 8250 | maintenance |
| uBlock-LLC/uBlock uBlock is a fast, lightweight browser extension that blocks ads, pop-ups, and trackers in Chrome, Firefox, Safari, Edge, and Opera. It emph… | 10 | 8246 | maintenance |
| nettitude/PoshC2 PoshC2 is a proxy-aware Command and Control (C2) framework written in Python3 that aids penetration testers with red teaming, post-exploita… | 47 | 2132 | active |
| phra/PEzor PEzor is an open-source shellcode and PE packer that wraps executables or raw shellcode into new binaries with evasion features like unhook… | 32 | 2129 | active |
| martin-ger/esp32_nat_router Open-source firmware that turns an ESP32 into a WiFi NAT router and firewall, routing between an AP interface and a STA or Ethernet uplink.… | 72 | 2126 | active |
| a13xp0p0v/kernel-hardening-checker A Python CLI tool that checks the security hardening options of the Linux kernel across Kconfig options, boot command line arguments, and s… | 76 | 2123 | active |
| 0xsdeo/AntiDebug_Breaker A Chrome browser extension built on the Hook_JS library that assists with JavaScript reverse engineering and penetration testing reconnaiss… | 76 | 2122 | active |
| znc/znc ZNC is an advanced IRC bouncer (BNC) that stays connected to IRC networks so clients can disconnect and reconnect without losing chat histo… | 76 | 2122 | stable |
| chainreactors/gogo gogo is a high-performance, highly configurable automated scanning engine written in pure Go for red team operations. It combines port scan… | 91 | 2118 | active |
| j-hc/zygisk-detach A Zygisk module for rooted Android devices that detaches installed apps from the Play Store by hooking libbinder, preventing Play Store fro… | 85 | 2117 | active |
| smartwalle/alipay A Go SDK for integrating with the Alipay payment platform, supporting both public key certificate and plain public key signing/verification… | 75 | 2113 | active |
| paragonie/random_compat A PHP 5.x polyfill providing the random_bytes() and random_int() CSPRNG functions that were introduced in PHP 7. It fails with an exception… | 54 | 8154 | maintenance |
| bk138/droidVNC-NG droidVNC-NG is a VNC server app for Android that lets you view and remotely control an Android device from any VNC client or web browser, w… | 99 | 2110 | active |
| hannob/snallygaster Snallygaster is a Python command-line scanner that probes HTTP servers for files that should not be publicly accessible, such as exposed gi… | 54 | 2110 | active |
| haccer/subjack Subjack is a DNS takeover scanner written in Go that concurrently scans lists of subdomains to identify ones vulnerable to hijacking. It de… | 87 | 2109 | active |
| bulianglin/demo A collection of shell scripts and auxiliary files accompanying the 'bulianglin' (不良林) YouTube channel's tutorials on VPN and proxy tools, i… | 87 | 2107 | active |
| virtualabs/btlejack BtleJack is a Python CLI tool for sniffing, jamming, and hijacking Bluetooth Low Energy (BLE) connections. It relies on BBC Micro:Bit, Blue… | 23 | 2107 | active |
| sparrowwallet/sparrow Sparrow is a free, open-source desktop Bitcoin wallet application built in Java with a focus on security, privacy, and transparency. It sup… | 98 | 2106 | active |
| yjeanrenaud/yj_nearbyglasses Nearby Glasses is a mobile app that scans Bluetooth LE advertisements to detect smart glasses (like Ray-Ban Meta) nearby and warns the user… | 80 | 2099 | active |
| topjohnwu/libsu libsu is an Android library providing a complete solution for apps that need root (superuser) permissions. It wraps the Unix root shell pro… | 56 | 2099 | active |
| jdx/fnox fnox is a Rust CLI tool for managing secrets via encryption or cloud secret providers, storing them in a git-committed fnox.toml file. It s… | 84 | 2098 | active |
| Wifite Wifite is a Python command-line tool that automates wireless network security auditing by running existing tools like the Aircrack-ng suite… | 66 | 8084 | maintenance |
| thoughtworks/talisman Talisman is a Go-based CLI tool that installs a git pre-commit/pre-push hook to scan outgoing changesets for potential secrets such as toke… | 66 | 2096 | active |
| al0ne/LinuxCheck A shell-based Linux emergency response and information gathering tool that performs 70+ security checks across 13 categories, including roo… | 23 | 2096 | active |
| defparam/smuggler Smuggler is a Python 3 command-line tool that tests web servers and proxies for HTTP request smuggling and desync vulnerabilities. It fires… | 32 | 2093 | active |
| Sh1Yo/x8 x8 is a hidden parameter discovery suite written in Rust for security testing of web applications. It brute-forces parameter names against … | 23 | 2093 | active |
| vvb2060/KeyAttestation An Android app for generating, parsing, and verifying Android key and ID attestation data. It performs self-testing locally with no network… | 43 | 2088 | active |
| pivpn/pivpn PiVPN is a set of shell scripts that turn a Raspberry Pi or any Debian/Ubuntu server into a WireGuard or OpenVPN VPN server with a one-comm… | 81 | 8037 | maintenance |