function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| hanc00l/nemo_go Nemo is an automated information-gathering platform for penetration testing that integrates common recon tools (Masscan, Nmap, Subfinder, H… | 88 | 2086 | active |
| GrapheneOS/Vanadium Vanadium is a privacy and security hardened variant of Chromium that serves as the standard browser and WebView provider on GrapheneOS. It … | 95 | 2085 | active |
| 520coding/confuse A Mac application that performs source-to-source obfuscation of iOS projects, simulating human-style renaming with context awareness includ… | 88 | 2085 | active |
| rebootuser/LinEnum LinEnum is a shell script that performs scripted local Linux enumeration and privilege escalation checks. It gathers system, user, network,… | 32 | 8012 | maintenance |
| Trail of Bits Claude Code Config A Claude Code plugin marketplace from Trail of Bits offering skills for AI-assisted security analysis, code auditing, and vulnerability det… | 60 | 2079 | active |
| oss-review-toolkit/ort The OSS Review Toolkit (ORT) is a FOSS policy automation toolkit that analyzes project dependencies, scans licenses and copyrights, checks … | 95 | 2075 | active |
| someengineering/fixinventory Fix Inventory is an open-source cloud asset inventory and security tool that collects metadata from cloud providers (AWS, GCP, Azure, Digit… | 56 | 2074 | active |
| microsoft/sbom-tool Microsoft's SBOM Tool is a scalable, enterprise-ready CLI that generates SPDX 2.2 and SPDX 3.0 compatible Software Bill of Materials docume… | 81 | 2068 | active |
| redballoonsecurity/ofrak OFRAK is a binary analysis and modification platform that identifies, unpacks, analyzes, modifies, and repacks binaries, with first-class s… | 67 | 2067 | active |
| lasting-yang/frida_dump A collection of Frida scripts for dumping DEX files and native shared libraries (.so) from running Android processes. It includes SoFixer-b… | 49 | 2067 | active |
| CorentinTh/enclosed Enclosed is a minimalistic self-hostable web application for sharing end-to-end encrypted notes and file attachments. Notes are encrypted c… | 69 | 2066 | active |
| SamueleAmato/sosec sosec is a Python command-line toolkit with a terminal UI for automated credential testing and HTTP request orchestration against social me… | 63 | 2065 | active |
| haad/proxychains ProxyChains is a UNIX command-line tool that forces TCP connections and DNS lookups of any dynamically linked program through SOCKS4/5 or H… | 32 | 7938 | maintenance |
| erocarrera/pefile pefile is a multi-platform Python module for parsing and working with Portable Executable (PE) files such as EXE and DLL binaries. It expos… | 67 | 2064 | stable |
| lukechilds/reverse-shell A hosted service (reverse-shell.sh) that generates reverse shell payloads on demand; piping its URL output into sh on a target spawns a she… | 63 | 2055 | active |
| massgravel/TSforge TSforge is a C# command-line tool implementing a collection of activation and evaluation extension methods for Windows Vista through 11, in… | 46 | 2053 | active |
| CYB3RMX/Qu1cksc0pe Qu1cksc0pe is an all-in-one malware analysis tool that statically and dynamically analyzes many file types, including Windows/Linux/macOS e… | 77 | 2049 | active |
| openpubkey/opkssh opkssh is a Go CLI tool that enables SSH authentication via OpenID Connect identities instead of long-lived SSH keys. It generates SSH publ… | 85 | 2048 | active |
| berdav/CVE-2021-4034 A proof-of-concept exploit and vulnerability checker for CVE-2021-4034 (PwnKit), a polkit pkexec local privilege escalation vulnerability i… | 32 | 2048 | stable |
| garywill/linux-router A single-file bash script that turns a Linux machine into a router in one command, wrapping iptables, dnsmasq, and related tools. It suppor… | 82 | 2047 | active |
| w2016561536/android_virtual_cam An Xposed module for Android that replaces the camera feed of target apps with a custom video or image. It hooks camera APIs so apps receiv… | 23 | 2047 | active |
| canonical/snapd snapd is the background daemon and snap CLI tool that manages snap packages on Linux systems, handling installation, updates, confinement, … | 95 | 2046 | stable |
| mcu-tools/mcuboot MCUboot is a secure bootloader for 32-bit microcontrollers that defines common infrastructure for bootloaders and flash layout, enabling se… | 80 | 2045 | stable |
| sipt/shuttle Shuttle is a cross-platform network proxy tool written in Go supporting SOCKS5, SOCKS5 over TLS, and shadowsocks protocols. It offers rule-… | 48 | 2045 | active |
| ine-labs/AWSGoat AWSGoat is a deliberately vulnerable AWS infrastructure deployed via Terraform, featuring OWASP Top 10 web vulnerabilities and cloud miscon… | 42 | 2044 | active |
| SAP/macOS-enterprise-privileges Privileges is a free macOS application from SAP that lets enterprise users temporarily elevate their accounts to administrator rights for a… | 89 | 2043 | active |
| stacklok/toolhive ToolHive is an open-source platform for running, securing, and managing Model Context Protocol (MCP) servers. It wraps MCP servers in isola… | 83 | 2043 | active |
| kaikramer/keystore-explorer KeyStore Explorer is a free, open-source Java desktop application that provides a graphical interface replacing the keytool and jarsigner c… | 88 | 2042 | active |
| ipxe/ipxe iPXE is the leading open source network boot firmware, providing a full PXE implementation enhanced with features like booting from HTTP/HT… | 79 | 2040 | active |
| eugene1g/agent-safehouse Agent Safehouse is a macOS-native sandboxing tool that runs local LLM coding agents (Claude Code, Codex, Gemini CLI, Aider, etc.) inside a … | 80 | 2037 | active |
| mandiant/speakeasy Speakeasy is a Windows user-mode and kernel-mode emulation framework that runs binaries, drivers, and shellcode inside a modeled Windows ru… | 91 | 2036 | active |
| lirantal/is-website-vulnerable A Node.js CLI tool that scans a website's frontend JavaScript libraries for publicly known security vulnerabilities using the Snyk database… | 97 | 2035 | active |
| ainfosec/FISSURE FISSURE is an open-source RF and reverse engineering framework built around software-defined radios, supporting signal detection, classific… | 76 | 2033 | active |
| brightio/penelope Penelope is a modern reverse shell handler for penetration testers and CTF players, serving as a more capable alternative to basic netcat l… | 92 | 2031 | active |
| jtsylve/LiME LiME (Linux Memory Extractor) is a loadable kernel module that acquires volatile memory from Linux and Android devices, writing captures to… | 81 | 2028 | active |
| meetrevision/playbook ReviOS Playbook is a collection of Windows system modifications applied via AME Wizard to create a lightweight, privacy-focused, performanc… | 75 | 2028 | active |
| TrianguloY/URLCheck URLCheck is an open-source Android app that acts as an intermediary when opening URLs, letting users inspect, clean, and modify links befor… | 87 | 2027 | active |
| lowRISC/ibex Ibex is a production-quality, open-source 32-bit RISC-V CPU core written in SystemVerilog, originally developed as 'Zero-riscy' in the PULP… | 76 | 2026 | active |
| tensorflow/privacy TensorFlow Privacy is a Python library providing TensorFlow optimizers for training machine learning models with differential privacy. It i… | 67 | 2026 | active |
| jkroepke/helm-secrets helm-secrets is a Helm plugin that transparently encrypts and decrypts Helm value files using sops, allowing secrets to be safely stored in… | 95 | 2025 | active |
| Tencent/soter TENCENT SOTER is a biometric authentication standard and platform for Android, developed by Tencent and used in WeChat fingerprint payment.… | 53 | 2025 | active |
| GhostPack/Certify Certify is a C# command-line tool for enumerating and abusing misconfigurations in Active Directory Certificate Services (AD CS). It was re… | 76 | 2023 | active |
| OpenSteam001/OpenSteamTool OpenSteamTool is an open-source Windows-only Steam unlocker written in C++ that unlocks unowned games and DLCs via Lua configuration, manif… | 74 | 2021 | active |
| sc0tfree/mentalist Mentalist is a graphical Python tool for generating custom password wordlists based on common human password-construction patterns. It can … | 63 | 2021 | active |
| wyzxxz/jndi_tool A Java-based JNDI exploitation tool that runs malicious RMI/LDAP reference servers to test and exploit JNDI injection vulnerabilities, incl… | 32 | 2021 | active |
| daymade/Twitter-Block-Porn A Tampermonkey/Greasemonkey userscript that batch-blocks Twitter/X accounts from shared blocklists of porn-spam scammers. It simulates Twit… | 73 | 2019 | active |
| attr-encrypted/attr_encrypted A Ruby gem that generates attr_accessors which transparently encrypt and decrypt attributes on any Ruby class. It integrates with ActiveRec… | 46 | 2018 | active |
| Cookie-AutoDelete/Cookie-AutoDelete A Firefox, Chrome, and Edge WebExtension that automatically deletes cookies and other browsing site data when a tab closes, the domain chan… | 49 | 2014 | active |
| Kritt-ai/open-kritt open·kritt is an open-source, self-hosted AI vulnerability research platform that decomposes a codebase into focused security tasks, runs A… | 79 | 2011 | active |
| authgear/authgear-server Authgear is an open-source customer identity and access management (CIAM) platform serving as a self-hostable alternative to Auth0, Clerk, … | 95 | 2010 | active |
| endrazine/wcc The Witchcraft Compiler Collection (WCC) is a set of compilation tools for performing binary manipulation on ELF executables across POSIX p… | 90 | 2010 | active |
| pixelspark/sushitrain Sushitrain is an open-source iOS and macOS app that brings Syncthing-based secure file synchronization to Apple devices, built with a Go co… | 85 | 2009 | active |
| Google2FA A PHP library implementing Google-compatible two-factor authentication via HMAC-based (HOTP, RFC 4226) and time-based (TOTP, RFC 6238) one-… | 69 | 2007 | stable |
| bitbrute/evillimiter A Python command-line tool that monitors, analyzes, and limits the bandwidth of devices on a local network using ARP spoofing and traffic s… | 56 | 2007 | active |
| Runnin4ik/dpi-detector A Python CLI tool that detects and classifies Deep Packet Inspection (DPI) based internet censorship, including TCP 16-20KB connection drop… | 82 | 2005 | active |
| etherized/GenP GenP is a community tool used to patch Adobe desktop applications, and this repository is an unofficial Chinese-localized fork of it. It is… | 81 | 2005 | active |
| ambethia/recaptcha A Ruby gem providing helper methods for Google's reCAPTCHA API, supporting v2 checkbox, invisible, and v3 score-based verification. It offe… | 72 | 2005 | stable |
| shivaya-dav/DogeRat DogeRat is a Telegram-controlled Android remote access tool (RAT) consisting of a Node.js/Express/Socket.IO server and a Kotlin Android APK… | 42 | 2005 | active |
| EgeBalci/sgn SGN is a polymorphic binary encoder that encodes shellcode using an additive feedback loop similar to an LFSR, producing statically undetec… | 91 | 2003 | active |
| chris2511/xca XCA is a cross-platform desktop GUI application for creating and managing X.509 certificates, certificate requests, RSA/DSA/EC private keys… | 68 | 2003 | active |
| gin-contrib/cors The official CORS (Cross-Origin Resource Sharing) middleware for the Gin web framework in Go. It provides configurable handling of allowed … | 87 | 1999 | stable |
| pyupio/safety Safety CLI is a Python dependency vulnerability scanner that detects packages with known vulnerabilities and malicious packages in local de… | 94 | 1995 | active |
| bcrypt-ruby/bcrypt-ruby bcrypt-ruby is a Ruby binding to the OpenBSD bcrypt() password hashing algorithm, provided as a gem with a native C extension. It lets deve… | 82 | 1994 | stable |
| GitGuardian/ggshield ggshield is a CLI application from GitGuardian that detects over 500 types of hardcoded secrets in files, git history, and CI environments … | 99 | 1992 | active |
| mashirozx/Pixiv-Nginx A fork of nginx preconfigured with reverse-proxy configs, TLS certificates, and hosts entries to restore access to Pixiv from networks wher… | 59 | 1992 | active |
| mfontanini/libtins libtins is a high-level, multiplatform C++ library for network packet sniffing, parsing, and crafting. It provides an efficient, endianness… | 86 | 1991 | stable |
| hectorm/hblock hBlock is a POSIX-compliant shell script that aggregates domains serving ads, trackers, and malware from multiple blocklist sources and gen… | 66 | 1981 | active |
| t6x/reaver-wps-fork-t6x Reaver is a C-based command-line tool that performs brute force attacks against Wi-Fi Protected Setup (WPS) registrar PINs to recover WPA/W… | 45 | 1981 | active |
| manfredsteyer/angular-oauth2-oidc A TypeScript library adding OAuth 2, OAuth 2.1, and OpenID Connect support to Angular applications. It handles token issuance, validation, … | 93 | 1979 | stable |
| mewebstudio/Purifier A Laravel service provider that wraps the HTMLPurifier library for sanitizing HTML input. It provides a simple clean() helper and Purifier … | 75 | 1979 | stable |
| pgkt04/defender-control An open-source Windows utility that permanently disables or re-enables Windows Defender by running as TrustedInstaller, setting disabling p… | 80 | 1978 | active |
| WireGuard WireGuard is a fast, modern, and secure VPN tunnel that uses state-of-the-art cryptography (Noise framework, Curve25519, ChaCha20) to creat… | 70 | 1978 | stable |
| dswd/vpncloud VpnCloud is a high-performance peer-to-peer mesh VPN written in Rust that runs over UDP with strong end-to-end encryption (Curve25519 and A… | 23 | 1978 | stable |
| msoedov/agentic_security Agentic Security is an open-source LLM vulnerability scanner and AI red-teaming toolkit that probes large language models and agent workflo… | 87 | 1977 | active |
| GrapheneOS/hardened_malloc hardened_malloc is a security-focused general purpose memory allocator implementing the malloc API with extensive hardening against heap co… | 77 | 1975 | active |
| cossacklabs/themis Themis is a cross-platform, high-level cryptographic library providing ready-made building blocks for secure data storage, encrypted messag… | 76 | 1973 | stable |
| cifertech/nRFBox nRFBox is an open-source ESP32-based handheld tool that scans, analyzes, jams, and spoofs BLE, Wi-Fi, and 2.4GHz signals using an nRF24L01 … | 73 | 1971 | active |
| hfiref0x/WinObjEx64 WinObjEx64 is a 64-bit Windows utility for exploring the Windows Object Manager namespace, viewing detailed object properties, structure du… | 88 | 1969 | active |
| MichaelGrafnetter/DSInternals DSInternals is a PowerShell module and .NET framework for working with Active Directory internals, including offline NTDS.DIT database pars… | 92 | 1967 | active |
| FouadRaheb/Watusi-for-WhatsApp Watusi is an all-in-one tweak for WhatsApp Messenger on iOS, distributed as a jailbreak package or pre-patched sideloadable IPA files. It a… | 77 | 1967 | active |
| hyperion-cs/dpi-checkers A collection of checkers (a comprehensive Go-based DPI-CH tool plus browser-based checkers) that detect whether an ISP or datacenter applie… | 85 | 1965 | active |
| bit4woo/knife Knife is a Burp Suite extension written in Java that adds useful right-click context menu functions to improve penetration testing workflow… | 63 | 1963 | active |
| rsc/2fa A command-line two-factor authentication agent written in Go that stores TOTP and HOTP keys and generates one-time authentication codes. Ke… | 32 | 1963 | stable |
| intruder-io/autoswagger Autoswagger is a Python command-line tool that discovers Swagger/OpenAPI specifications, parses their endpoints, and automatically tests th… | 34 | 1960 | active |
| guofei9987/text_blind_watermark A Python library that embeds invisible blind watermarks into plain text without changing its appearance or readability, using a password-pr… | 41 | 1956 | active |
| de4dot/de4dot de4dot is an open-source .NET deobfuscator and unpacker written in C# that restores packed and obfuscated .NET assemblies to near-original … | 10 | 7437 | maintenance |
| BasicProtein/AugmentCode-Free A Python-based maintenance toolkit that patches the AugmentCode extension across VS Code, Cursor, Windsurf, and JetBrains IDEs to enable un… | 39 | 1952 | active |
| siemens/jailhouse Jailhouse is a Linux-based partitioning hypervisor that splits hardware resources into isolated cells running bare-metal applications or ad… | 32 | 1952 | stable |
| Sergeydigl3/zapret-discord-youtube-linux A plug-and-play Linux shell script adapter that ports Flowseal's zapret-discord-youtube and bol-van's zapret for bypassing DPI-based thrott… | 78 | 1951 | active |
| editso/fuso Fuso is a lightweight, fast, cross-platform intranet penetration (NAT traversal) and port forwarding tool written in Rust. It supports mult… | 58 | 1950 | active |
| Apptainer Apptainer (formerly Singularity) is an open-source container platform designed for secure, portable, and reproducible containers on shared … | 93 | 1949 | active |
| owtf/owtf OWASP OWTF (Offensive Web Testing Framework) is a penetration testing framework that unites multiple security tools and aligns testing work… | 67 | 1949 | active |
| f0ng/captcha-killer-modified A modified version of the captcha-killer Burp Suite extension that intercepts captcha images from HTTP responses and recognizes them using … | 41 | 1948 | active |
| ys1231/MoveCertificate A Magisk/KernelSU/APatch root module that moves user-installed certificates into Android's system CA store, supporting Android 7 through 16… | 98 | 1947 | active |
| Ragnt/AngryOxide AngryOxide is an 802.11 WiFi attack tool written in Rust that provides a single-interface survey capability with automated attacks to captu… | 70 | 1945 | active |
| axi0mX/ipwndfu ipwndfu is an open-source Python tool that exploits iOS device bootroms, most notably via the checkm8 exploit, to put devices into pwned DF… | 32 | 7397 | maintenance |
| RustSec RustSec is the Rust ecosystem's security advisory database plus a workspace of tooling crates, including the rustsec client library, cargo-… | 97 | 1943 | stable |
| varnish/hitch Hitch is a scalable TLS/SSL termination proxy written in C by Varnish Software. It decrypts TLS connections and forwards unencrypted traffi… | 45 | 1943 | active |
| dromara/MaxKey MaxKey is an open-source IAM/IDaaS product providing Single Sign-On (SSO), identity management, and RBAC-based access control. It supports … | 92 | 1940 | active |
| moul/sshportal sshportal is a transparent SSH bastion (jump host) server written in Go that manages users, hosts, and access control without requiring a t… | 67 | 1940 | active |