function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| feder-cr/invisible_playwright A Python library that provides an antidetect, stealth-patched Firefox build for Playwright, with fingerprints set at the C++ engine level a… | 81 | 1938 | active |
| eth-infinitism/account-abstraction The reference implementation of ERC-4337 account abstraction for Ethereum, providing the singleton EntryPoint contract, base classes for sm… | 58 | 1938 | active |
| vxunderground/VX-API VX-API is a C++ collection of functions implementing malicious functionality to aid in malware development, maintained by vx-underground. I… | 32 | 1938 | active |
| anthropics/defending-code-reference-harness A reference implementation from Anthropic for autonomous vulnerability discovery and remediation using Claude, including Claude Code skills… | 57 | 7368 | maintenance |
| evilsocket/legba Legba is a fast, multiprotocol credentials bruteforcer, password sprayer, and enumerator written in Rust on top of the Tokio async runtime.… | 84 | 1934 | active |
| Azure/Microsoft-Defender-for-Cloud The official Microsoft Defender for Cloud community repository containing PowerShell scripts, Azure Policy definitions, Logic App templates… | 73 | 1930 | active |
| deepfence/PacketStreamer PacketStreamer is a distributed, high-performance remote packet capture tool that runs lightweight sensors on target hosts to stream filter… | 10 | 1929 | active |
| OP-TEE/optee_os OP-TEE Trusted OS is the secure-world operating system implementation of the OP-TEE project, running on ARM TrustZone-enabled hardware. It … | 77 | 1927 | active |
| 1Password/for-open-source 1Password for Open Source is a program that grants eligible open source projects a free 1Password Teams account for securely storing and sh… | 67 | 1927 | active |
| bee-san/pyWhat pyWhat is a Python CLI tool that identifies what arbitrary text, files, or pcap network captures contain - emails, IP addresses, API keys, … | 23 | 7313 | maintenance |
| jdx/aube aube is a fast Node.js package manager written in Rust that auto-installs dependencies when you run scripts, with secure defaults like a li… | 77 | 1925 | active |
| nelmio/NelmioCorsBundle A Symfony bundle that adds Cross-Origin Resource Sharing (CORS) headers to responses with ACL-style per-URL configuration. It handles CORS … | 67 | 1925 | stable |
| SleepingBag945/dddd dddd is a Go-based batch information gathering and supply-chain vulnerability detection CLI tool designed to streamline red team workflows.… | 19 | 1924 | active |
| fideloper/TrustedProxy A Laravel package that configures trusted proxies so applications behind load balancers or reverse proxies correctly interpret X-Forwarded … | 23 | 7307 | maintenance |
| xrpcommunity/XRP-community-wallet A non-custodial, open-source web wallet for XRP Ledger and EVM networks, built by the community. Keys and seed phrases are encrypted and st… | 75 | 1920 | active |
| JustasMasiulis/lazy_importer A header-only C++ library for resolving Windows DLL exports at runtime in a way that hides imports from static analysis tools. It uses comp… | 32 | 1920 | stable |
| libimobiledevice/idevicerestore A cross-platform command-line application that restores or upgrades firmware (IPSW files) on iOS devices, reimplementing all granular resto… | 67 | 1918 | active |
| hackerschoice/gsocket Global Socket (gsocket) is a C-based toolkit that lets two machines behind NAT or firewalls establish secure, end-to-end encrypted TCP conn… | 67 | 1918 | active |
| atmoz/sftp A Docker image providing an easy-to-use SFTP server based on OpenSSH. Users can be defined via command arguments, environment variables, or… | 60 | 1907 | active |
| zs1083339604/FaceWinUnlock-Tauri A Windows face-recognition unlock application built with Tauri, Vue 3, and OpenCV that injects a custom Credential Provider DLL into the Wi… | 76 | 1906 | active |
| FGRibreau/mailchecker MailChecker is a cross-language library for validating email format and detecting temporary/disposable email addresses, backed by a databas… | 77 | 1905 | active |
| joaoviictorti/RustRedOps RustRedOps is a collection of red team tools and technique implementations written in Rust, primarily targeting Windows. It provides workin… | 53 | 1900 | active |
| netero1010/EDRSilencer A C-based Windows command-line tool that uses Windows Filtering Platform (WFP) APIs to block outbound traffic of running EDR agents, preven… | 17 | 1899 | active |
| CHIZI-0618/box4magisk A Magisk/KernelSU/APatch module that deploys proxy cores such as sing-box, clash/mihomo, v2ray, xray, and hysteria on rooted Android device… | 57 | 1897 | active |
| ECTO-1A/AppleJuice AppleJuice is a Python proof-of-concept tool that spoofs Apple BLE proximity pairing messages to trigger pairing popups on nearby Apple dev… | 28 | 1897 | active |
| trycompai/comp Comp AI is an open-source, AI-native compliance platform that automates evidence collection, policy generation, and continuous monitoring f… | 81 | 1896 | active |
| liamg/traitor Traitor is a Go-based CLI tool that automatically exploits common Linux misconfigurations and known vulnerabilities (GTFOBins, pwnkit, dirt… | 23 | 7160 | maintenance |
| web-push-libs/web-push-php A PHP library implementing the Web Push protocol (RFC 8030) for sending push notifications to browsers via service workers. It handles subs… | 91 | 1890 | active |
| stevemk14ebr/PolyHook_2_0 PolyHook 2.0 is a C++20 library for hooking functions at runtime on x86 and x64 architectures. It supports multiple hooking techniques (inl… | 73 | 1890 | active |
| sleeyax/burp-awesome-tls A Burp Suite extension that hijacks Burp's HTTP and TLS stack to spoof any browser's TLS fingerprint (JA3). It helps evade WAF bot detectio… | 89 | 1889 | active |
| federicodotta/Brida Brida is a Burp Suite extension that bridges Burp Suite and Frida, letting testers invoke and manipulate an application's own methods while… | 49 | 1889 | active |
| evildevill/instahack Instahack is a Bash and Python-based brute-force tool for testing Instagram account password strength, routing traffic through Tor for anon… | 62 | 1888 | active |
| pentestfunctions/BlueDucky BlueDucky is a Python tool that exploits CVE-2023-45866, an unauthenticated Bluetooth peering vulnerability, to execute keystroke injection… | 56 | 1888 | active |
| tuya-cloudcutter/tuya-cloudcutter Tuya Cloudcutter is a Python-based toolchain that exploits a wireless vulnerability in Tuya smart devices using Beken BK7231 and Realtek ch… | 70 | 1887 | active |
| cisagov/cset CSET is a free desktop application from CISA and Idaho National Laboratory that guides organizations through step-by-step cybersecurity ass… | 69 | 1887 | active |
| RabbyHub/Rabby Rabby Wallet is an open-source browser extension wallet for Ethereum and all EVM-compatible chains, aimed at DeFi users. It injects a stand… | 95 | 1886 | active |
| nsonaniya2010/SubDomainizer SubDomainizer is a Python CLI tool that discovers hidden subdomains and secrets in webpages, external JavaScript files, GitHub, and local f… | 66 | 1886 | active |
| Sathvik-Rao/ClipCascade ClipCascade is a lightweight, open-source utility that automatically syncs the clipboard across multiple devices without any key press. It … | 75 | 1880 | active |
| essensoft/paylinks Paylinks is a modern .NET SDK for integrating third-party payment platforms, supporting Alipay and WeChat Pay with cross-platform and multi… | 64 | 1879 | active |
| jazzband/django-two-factor-auth A Django package providing complete two-factor authentication built on top of django-otp and Django's built-in auth framework. It supports … | 82 | 1878 | active |
| Xposed-Modules-Repo/com.luckyzyx.luckytool LuckyTool is a free Xposed module that extends and optimizes ColorOS-based Android systems (OPPO, OnePlus, Realme). It provides hundreds of… | 80 | 1878 | active |
| symfony/security-core The core library of the Symfony Security component, providing infrastructure for authentication tokens, user providers, role hierarchies, a… | 95 | 1877 | stable |
| microsoft/openvmm OpenVMM is a modular, cross-platform Virtual Machine Monitor (VMM) written in Rust, developed by Microsoft. It also hosts OpenHCL, a paravi… | 88 | 1877 | active |
| younesaassila/ttv-lol-pro TTV LOL PRO is a browser extension that removes most livestream ads from Twitch by routing streams through standard HTTP proxies. It is a f… | 80 | 1876 | active |
| srixivas/PcapXray PcapXray is a Python-based network forensics tool that visualizes PCAP files or live traffic as an annotated network diagram. It identifies… | 84 | 1874 | active |
| lazaronixon/authentication-zero A Rails generator that scaffolds a complete, pre-built authentication system directly into a Rails application (web or API-only), following… | 34 | 1873 | active |
| airbus-seclab/bincat BinCAT is a static binary code analysis toolkit that performs value analysis, taint analysis, type reconstruction, and use-after-free/doubl… | 29 | 1872 | active |
| cake-tech/cake_wallet Cake Wallet is an open-source, noncustodial multi-currency cryptocurrency wallet supporting Monero, Bitcoin, Ethereum, Litecoin, Solana, an… | 98 | 1871 | active |
| tanrax/maza-ad-blocking Maza is a local ad blocker written as a single Bash script that blocks ads at the DNS level by editing the operating system's hosts file, w… | 76 | 1870 | active |
| niklasb/libc-database A shell-based tool that builds a searchable database of libc symbol offsets from Ubuntu, Debian, and other distributions to simplify binary… | 75 | 1869 | active |
| emsec/ChameleonMini ChameleonMini is a freely programmable, portable NFC device that can emulate and clone contactless smartcards, read RFID tags, and sniff/lo… | 23 | 1869 | active |
| trustedsec/CS-Situational-Awareness-BOF A collection of situational awareness commands implemented as Cobalt Strike Beacon Object Files (BOFs) in C, letting operators run low-foot… | 97 | 1868 | active |
| Yurii0307/yurikey YuriKey is a systemless root module (for Magisk, APatch, KernelSU and forks) that helps rooted Android devices pass Google Play Integrity's… | 79 | 1864 | active |
| 0xKayala/NucleiFuzzer NucleiFuzzer is a Python-based automation tool that combines URL discovery tools (ParamSpider, Waybackurls, Gauplus, Hakrawler, Katana) wit… | 66 | 1862 | active |
| sbabic/swupdate SWUpdate is a Linux update agent for safely updating embedded Linux devices in the field, supporting local and OTA updates with multiple st… | 87 | 1860 | stable |
| abc123info/BlueTeamTools BlueTeamTools is a Java-based GUI toolbox that aggregates utilities for blue-team security analysts, covering memory-shell decompilation, w… | 91 | 1859 | active |
| sourcery-ai/sourcery Sourcery is an AI-powered automated code review service that reviews pull requests on GitHub and GitLab, posting summaries, inline comments… | 97 | 1858 | active |
| AdguardTeam/AdguardForAndroid AdGuard for Android is a system-wide content blocker for Android that blocks ads, trackers, and malvertising across browsers and apps. This… | 95 | 1857 | active |
| complexorganizations/wireguard-manager A shell-based tool that automates the installation, configuration, and management of WireGuard VPN servers. It provides a user-friendly way… | 48 | 1856 | active |
| sarperavci/GoogleRecaptchaBypass A Python library that automatically solves Google reCAPTCHA v2 challenges in under five seconds using browser automation with DrissionPage … | 68 | 1855 | active |
| trustedsec/hate_crack hate_crack is a Python tool by TrustedSec that automates password cracking methodologies on top of Hashcat, orchestrating wordlists, masks,… | 95 | 1854 | active |
| superagent-ai/vibekit VibeKit is a CLI tool that wraps AI coding agents such as Claude Code, Gemini CLI, Grok CLI, and Codex in isolated Docker sandboxes with au… | 49 | 1851 | active |
| DroidPluginTeam/DroidPlugin DroidPlugin is an Android plugin framework that lets a host app run any third-party APK without installation, modification, or repackaging.… | 23 | 6975 | maintenance |
| Jrohy/multi-v2ray A Python-based management script for deploying and administering multi-user V2Ray/Xray proxy servers on Linux. It provides a wizard-driven … | 23 | 6974 | maintenance |
| anddea/revanced-patches ReVanced Extended (RVX) is a collection of patches for modifying Android apps, primarily YouTube, to add features like ad blocking, backgro… | 91 | 1849 | active |
| anhskohbo/no-captcha A Laravel package integrating Google's No CAPTCHA reCAPTCHA into forms. It provides Blade helpers for rendering the widget and a validation… | 70 | 1849 | active |
| selinuxG/Golin Golin is a Go-based security assessment tool combining asset discovery, port/service scanning, weak password brute-forcing for 40+ services… | 66 | 1847 | active |
| zhlynn/zsign zsign is a fast, cross-platform open-source alternative to Apple's codesign tool for re-signing iOS .ipa packages, Mach-O binaries, and .ap… | 98 | 1846 | active |
| ninoseki/mitaka Mitaka is a browser extension for Chrome and Firefox that simplifies OSINT (Open Source Intelligence) searches. It automatically detects an… | 94 | 1846 | active |
| sniptt-official/ots OTS is a Go CLI tool for sharing end-to-end encrypted secrets (API keys, passwords, signing secrets) via one-time URLs. Secrets are destroy… | 36 | 1845 | active |
| Tencent/CodeAnalysis Tencent Cloud Code Analysis (TCA, code-named CodeDog) is a self-hosted static code analysis platform consisting of server, web, and client … | 45 | 1843 | active |
| devploit/nomore403 NoMore403 is a Go command-line tool that automates testing of HTTP 401/403 access-control bypasses via request path, method, header, and wi… | 87 | 1842 | active |
| Eugeny/russh Russh is a low-level, Tokio-based SSH2 client and server library for Rust, forked from Thrussh. It supports a wide range of ciphers, key ex… | 99 | 1840 | active |
| iredmail/iRedMail iRedMail is an open source, full-featured mail server solution that installs and configures SMTP, IMAP/POP3, webmail (Roundcube/SOGo), and … | 76 | 1840 | active |
| Automattic/jetpack Jetpack is a suite of WordPress plugins and packages providing security, performance, marketing, and site-management tools for WordPress si… | 67 | 1840 | active |
| mailvelope/mailvelope Mailvelope is a browser extension for Chrome and Firefox that adds OpenPGP end-to-end email encryption to arbitrary webmail providers. It u… | 85 | 1838 | active |
| hacl-star/hacl-star HACL* is a formally verified cryptographic library written in F* (Low*) and compiled to efficient standalone C code, covering algorithms li… | 62 | 1837 | active |
| DosX-dev/obfus.h A macro-only C header library that obfuscates code at compile time, designed for the Tiny C Compiler on Windows x86/x64. It provides contro… | 68 | 1836 | active |
| pandasec888/taowu-cobalt_strike Taowu is a red team automation plugin (Aggressor script) for the Cobalt Strike platform, bundling a large collection of post-exploitation m… | 56 | 1835 | active |
| HMBSbige/ShadowsocksR-Android A ShadowsocksR proxy client for Android written in Kotlin, forked from the shadowsocks-android codebase. It lets Android users route traffi… | 10 | 1835 | active |
| valqore/valqore Valqore is a deterministic infrastructure governance engine that scans Kubernetes manifests, Terraform, Helm, and cloud resources against 1… | 81 | 1831 | active |
| 78778443/QingScan QingScan is a self-hosted, open-source security operations platform that unifies vulnerability scanning, code auditing, asset inventory, an… | 66 | 1831 | active |
| bvcyber/CVE-2020-1472 A Python CLI script that tests domain controllers for the ZeroLogon vulnerability (CVE-2020-1472) using the Impacket library. It attempts t… | 45 | 1830 | stable |
| White-hua/Apt_t00ls A Java-based exploitation tool that aggregates proof-of-concept and weaponized exploits for high-severity vulnerabilities in Chinese enterp… | 26 | 1830 | active |
| pirxthepilot/wtfis wtfis is a Python command-line tool that performs passive lookups of hostnames, domains, and IP addresses using OSINT services like VirusTo… | 74 | 1827 | active |
| initstring/linkedin2username A Python OSINT tool that scrapes LinkedIn employee lists for a target company and generates multiple probable username formats (e.g., first… | 76 | 1825 | active |
| alfiecg24/TrollInstallerX TrollInstallerX is a universal TrollStore installer for iOS 14.0 through 16.6.1, supporting both arm64 and arm64e devices. It uses the kfd … | 16 | 1824 | active |
| nilsteampassnet/TeamPass TeamPass is a free, self-hosted collaborative password manager written in PHP/MySQL, offering folder-level access control, AES-256-GCM auth… | 95 | 1823 | active |
| Meituan-Dianping/walle Walle is a tool from Meituan-Dianping for generating Android channel (multi-market distribution) APK packages under the APK Signature Schem… | 23 | 6857 | maintenance |
| scipag/HardeningKitty HardeningKitty is a PowerShell module that audits and hardens Windows system configurations against a predefined finding list. It reads reg… | 84 | 1822 | active |
| HoShiMin/Kernel-Bridge Kernel-Bridge is a C++20 Windows kernel driver template, development framework, and kernel-mode API with wrappers, including a hypervisor s… | 23 | 1822 | active |
| giampaolo/pyftpdlib pyftpdlib is a pure-Python FTP server library providing a high-level, portable interface for writing fast, scalable, asynchronous FTP serve… | 67 | 1819 | stable |
| zarfadev/MobaXterm-Keygen A browser-based web tool that generates MobaXterm license key files (.mxtpro) and merges custom MobaXterm settings, running entirely client… | 60 | 1819 | active |
| nix-community/lanzaboote Lanzaboote is Rust tooling that brings UEFI Secure Boot and Measured Boot support to NixOS. Its lzbt tool signs boot components, builds Uni… | 84 | 1818 | active |
| aj3423/SpamBlocker SpamBlocker is an Android app that blocks spam calls and SMS messages without replacing your default call or messaging apps. It works as a … | 92 | 1816 | active |
| QBDI/QBDI QBDI (QuarkslaB Dynamic binary Instrumentation) is a modular, cross-platform, cross-architecture DBI framework built on LLVM, supporting x8… | 83 | 1815 | active |
| Chleba/netscanner netscanner is a terminal-based network scanner and diagnostic tool with a modern TUI, written in Rust. It supports WiFi network scanning, C… | 83 | 1815 | active |
| Gregwar/Captcha A PHP library for generating CAPTCHA images to protect web forms from bots and spam. It builds distorted text images, exposes the phrase fo… | 83 | 1814 | active |
| vulnersCom/getsploit A Python command-line tool that searches and downloads public exploits from the Vulners database, aggregating sources like Exploit-DB, Meta… | 90 | 1813 | active |
| trezor/trezor-firmware The official open-source firmware monorepo for Trezor hardware wallets, containing firmware for Trezor One and Trezor T/Safe devices, a sta… | 77 | 1813 | active |