function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| guardianproject/haven Haven is an open-source Android application that turns a spare phone into a physical security monitor using its on-device sensors (motion, … | 23 | 6814 | maintenance |
| cifertech/RF-Clown RF-Clown is an open-source BLE and Bluetooth jammer built on ESP32 and multiple nRF24L01 radio modules, with an OLED display, NeoPixel feed… | 66 | 1810 | active |
| tdragon6/Supershell Supershell is a web-accessible C2 remote control platform that establishes reverse SSH tunnels to targets, yielding fully interactive shell… | 54 | 1810 | active |
| wagiro/BurpBounty Burp Bounty (Scan Check Builder) is a Burp Suite extension that lets users improve Burp's active and passive web vulnerability scanners wit… | 23 | 1809 | active |
| enetx/surf Surf is an advanced HTTP client library for Go with fluent, chainable API design. It supports browser impersonation (Chrome/Firefox), JA3/J… | 83 | 1808 | active |
| mschwager/fierce Fierce is a Python 3 DNS reconnaissance tool that locates non-contiguous IP space and hostnames for specified domains. It enumerates subdom… | 32 | 1808 | active |
| antrea-io/antrea Antrea is a Kubernetes-native CNI plugin that provides pod networking and NetworkPolicy enforcement using Open vSwitch as the data plane. I… | 99 | 1807 | stable |
| any1/wayvnc wayvnc is a VNC server for wlroots-based Wayland compositors such as sway. It attaches to a running Wayland session, exposes the display vi… | 91 | 1807 | active |
| bogdanfinn/tls-client A Go HTTP client library with a net/http-like interface that lets you select specific browser TLS fingerprints (Chrome, Firefox, Safari, et… | 90 | 1807 | active |
| core-lib/xjar XJar is a Java library and Maven-integrated tool that encrypts Spring Boot and plain JAR files (e.g., with AES) and provides a custom class… | 23 | 1807 | active |
| OpenSCAP/openscap OpenSCAP is a NIST-certified open-source toolkit providing both a C library and the 'oscap' command-line tool for parsing, validating, edit… | 87 | 1806 | stable |
| Lojii/Knot Knot is a full-featured iOS app for capturing and analyzing HTTP/HTTPS network traffic using MITM (man-in-the-middle) techniques, built ent… | 74 | 1806 | active |
| dreadl0ck/netcap Netcap is a Go framework that converts network packets into structured, type-safe Protocol Buffer audit records for security monitoring, fo… | 92 | 1805 | active |
| Tai-e Tai-e is an easy-to-learn, developer-friendly static analysis framework for Java and Android programs, offering pointer analysis, taint ana… | 84 | 1804 | active |
| hashtopolis/server Hashtopolis is a multi-platform client-server application for distributing hashcat password cracking tasks across multiple computers. It pr… | 90 | 1802 | active |
| doyensec/inql InQL is an open-source Burp Suite extension for advanced GraphQL security testing. It provides schema introspection, vulnerability detectio… | 76 | 1801 | active |
| wallarm/gotestwaf GoTestWAF is a Go-based tool that simulates OWASP and API attacks (SQL injection, XSS, etc.) across REST, GraphQL, gRPC, SOAP, and XMLRPC p… | 41 | 1799 | active |
| netyouli/WHC_ConfuseSoftware A macOS (and Windows for some helpers) GUI application that obfuscates and 'renovates' mobile and game project source code across Objective… | 76 | 1797 | active |
| PortSwigger/turbo-intruder Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests at exceptional speed and analyzing the results. It uses… | 66 | 1796 | active |
| acidanthera/VirtualSMC VirtualSMC is an advanced Apple SMC (System Management Controller) emulator implemented as a macOS kernel extension, requiring the Lilu kex… | 64 | 1796 | active |
| SkyBlue997/enableMacosAI A shell-based installer plus a minimal macOS kernel extension (kext) that spoofs the device region code in IORegistry from CH/A to LL/A, un… | 53 | 1794 | active |
| OpenVPN/openvpn-gui OpenVPN GUI is a graphical frontend for OpenVPN on Windows 10 and 11, providing a notification-area icon to start and stop VPN tunnels, vie… | 77 | 1793 | active |
| 0vercl0k/wtf wtf (what the fuzz) is a distributed, code-coverage guided, snapshot-based fuzzer for attacking user- and kernel-mode targets on Windows an… | 74 | 1793 | active |
| betterleaks/betterleaks Betterleaks is a fast, configurable secrets scanner for finding leaked credentials in git repositories, filesystems, and platforms like Git… | 82 | 1792 | active |
| nccgroup/sobelow Sobelow is a security-focused static analysis tool for Elixir and the Phoenix framework, detecting common vulnerability classes like SQL in… | 23 | 1791 | active |
| lirantal/npq npq is a command-line tool that audits npm packages for security risks before installing them, checking CVE databases and applying syntacti… | 95 | 1789 | active |
| libtom/libtomcrypt LibTomCrypt is a comprehensive, modular and portable cryptographic toolkit written in C, providing block ciphers, hash functions, chaining … | 66 | 1788 | stable |
| R4gd0ll/I-Wanna-Get-All A comprehensive Java post-exploitation vulnerability exploitation tool integrating 470 exploit modules for detection and attack of known vu… | 59 | 1787 | active |
| fulldecent/system-bus-radio A C program that transmits AM radio signals from computers and phones that lack radio transmitting hardware by generating precisely timed e… | 55 | 6697 | maintenance |
| ReversecLabs/C3 C3 (Custom Command and Control) is a C++ framework for rapidly prototyping custom command and control (C2) channels for red team operations… | 67 | 1785 | active |
| kost/dvcs-ripper dvcs-ripper is a set of Perl command-line tools that download (rip) web-accessible version control repositories such as GIT, SVN, Mercurial… | 32 | 1784 | stable |
| D4Vinci/One-Lin3r One-Lin3r is a lightweight, modular Python framework that provides a searchable database of over 176 one-liner commands for penetration tes… | 57 | 1783 | active |
| metlo-labs/metlo Metlo is an open-source API security platform that inventories API endpoints, detects malicious traffic in real time, and can automatically… | 38 | 1783 | active |
| OpenAEV-Platform/openaev OpenAEV is an open-source platform for planning, scheduling, and running cyber adversary simulation campaigns and security exercises, from … | 95 | 1782 | active |
| bizz84/SwiftyStoreKit SwiftyStoreKit is a lightweight Swift framework wrapping Apple's StoreKit to simplify in-app purchases on iOS, tvOS, watchOS, and macOS. It… | 23 | 6671 | maintenance |
| GoSecure/pyrdp PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library. It intercepts RDP connections to capture cre… | 60 | 1780 | active |
| Dyneteq/reconya reconYa is a self-hosted network reconnaissance and asset discovery tool written in Go that scans local networks via ICMP, TCP, and ARP to … | 87 | 1777 | active |
| pass-with-high-score/blockads-android BlockAds is a free, open-source Android app that blocks ads, trackers, and malware system-wide using local VPN-based DNS filtering, with no… | 79 | 1777 | active |
| hjdhjd/homebridge-unifi-protect A Homebridge plugin that provides complete native HomeKit integration for the UniFi Protect ecosystem, including cameras, doorbells, sensor… | 94 | 1776 | active |
| ron190/jsql-injection jSQL Injection is a free, open-source Java application for automatic SQL database injection, used to find and extract database information … | 84 | 1776 | active |
| quentinhardy/odat ODAT (Oracle Database Attacking Tool) is an open-source Python penetration testing tool for assessing the security of remote Oracle Databas… | 57 | 1776 | active |
| simsong/tcpflow tcpflow is a C++ command-line tool that captures TCP connection data and demultiplexes it into per-flow files, one per direction, for proto… | 52 | 1774 | active |
| mozilla/fx-private-relay Firefox Relay is a Mozilla service that generates email aliases (masks) which forward messages to your real inbox, hiding your personal add… | 94 | 1773 | active |
| andrivet/ADVobfuscator ADVobfuscator is a C++20 header-only library that obfuscates and encrypts strings and data blocks at compile time using metaprogramming, wi… | 73 | 1772 | active |
| un1cum/Beast_Bomber A Python CLI script that floods targets with SMS, email, Discord, and Telegram messages, and performs basic DDoS attacks. It runs on deskto… | 26 | 1772 | active |
| pwn20wndstuff/Undecimus Undecimus is the open-source iOS app behind the unc0ver jailbreak, supporting iOS 11.0 through 12.4 on ARM64 devices. It applies kernel and… | 23 | 6621 | maintenance |
| etesync/server The Etebase (EteSync 2.0) server, a Django-based backend that lets you self-host end-to-end encrypted synchronization of contacts, calendar… | 32 | 1766 | stable |
| SpatiumPortae/portal Portal is a command-line file transfer utility for sending files and folders between any two computers. It uses PAKE2 end-to-end encryption… | 23 | 1766 | active |
| tchx84/Flatseal Flatseal is a graphical utility for reviewing and modifying permissions of Flatpak applications on Linux. It lets users select an installed… | 77 | 1765 | active |
| fwdcloudsec/granted Granted is a Go-based CLI application that simplifies finding and assuming AWS IAM roles across multiple accounts. It encrypts cached SSO c… | 90 | 1764 | active |
| j3ers3/Hello-Java-Sec A deliberately vulnerable Java Spring Boot application demonstrating common web vulnerabilities (SQLi, XSS, RCE, deserialization, SSTI, SSR… | 27 | 1763 | active |
| xaitax/Chrome-App-Bound-Encryption-Decryption A Windows post-exploitation research tool that bypasses Chromium's App-Bound Encryption using direct syscall-based reflective process hollo… | 63 | 1762 | active |
| symfony/security-csrf The Symfony Security CSRF component provides a CsrfTokenManager class for generating and validating cross-site request forgery (CSRF) token… | 93 | 1761 | stable |
| qi4L/JYso JYso is a Java-based offensive security tool that combines the capabilities of ysoserial (Java deserialization gadget generation) and JNDIE… | 83 | 1761 | active |
| privacyidea/privacyidea privacyIDEA is an open-source, self-hosted multi-factor authentication (MFA) server that centrally manages authentication tokens—OTP (HOTP/… | 93 | 1759 | stable |
| LoseNine/ruyipage RuyiPage is a Python browser automation framework built on Firefox and the WebDriver BiDi protocol, shipping with an anti-detection Firefox… | 79 | 1759 | active |
| google/sandboxed-api Google's Sandboxed API (SAPI) automatically generates sandboxes for individual C/C++ libraries, isolating them from the host program using … | 67 | 1758 | active |
| mpdavis/python-jose python-jose is a Python implementation of the JOSE (JavaScript Object Signing and Encryption) standards, including JWS, JWE, JWK, and JWT. … | 60 | 1756 | stable |
| xmendez/wfuzz Wfuzz is a Python-based command-line web application fuzzer that replaces a FUZZ keyword in HTTP requests with values from configurable pay… | 60 | 6558 | maintenance |
| orhun/gpg-tui gpg-tui is a terminal user interface for GnuPG written in Rust, built on tui-rs and GPGME bindings. It simplifies key management operations… | 81 | 1753 | active |
| ronf/asyncssh AsyncSSH is a Python library providing asynchronous client and server implementations of the SSHv2 protocol, including SFTP and SCP, built … | 76 | 1753 | stable |
| ossf/cve-bin-tool A Python CLI tool that scans binaries and systems for known CVEs in over 350 common open-source components like openssl, libpng, and expat.… | 67 | 1753 | active |
| murphysecurity/murphysec MurphySec CLI is an open-source software composition analysis (SCA) tool that detects vulnerable dependencies in projects from the command … | 57 | 1753 | active |
| facebookarchive/fbctf FBCTF is a self-hosted platform for running Jeopardy and King of the Hill style Capture the Flag security competitions. It supports team re… | 10 | 6548 | maintenance |
| bytedance/appshark AppShark is a static taint analysis platform written in Kotlin that scans Android APKs for security vulnerabilities and compliance issues. … | 54 | 1752 | active |
| adsbypasser/adsbypasser AdsBypasser is a lightweight userscript that automatically skips countdown ads, continue/redirect pages, and prevents ad pop-up windows acr… | 99 | 1750 | active |
| GreenmaskIO/greenmask Greenmask is an open-source CLI utility for logical database dumping, anonymization, synthetic data generation, and restoration, production… | 93 | 1750 | active |
| justinas/nosurf nosurf is a Go HTTP package that provides CSRF protection via a CSRFHandler middleware wrapping any http.Handler. It validates tokens on un… | 32 | 1747 | stable |
| hanchuanchuan/goInception goInception is a MySQL maintenance tool that audits, executes, backs up, and generates rollback statements for SQL. It parses SQL syntax us… | 23 | 1743 | active |
| IvanGlinkin/Fast-Google-Dorks-Scan A shell-based OSINT tool that automates Google dork searches against a target website to uncover admin panels, exposed file types, and path… | 46 | 1742 | active |
| jm33-m0/emp3r0r emp3r0r is an open-source post-exploitation framework and command-and-control (C2) system written in Go, targeting Linux and Windows hosts.… | 95 | 1741 | active |
| elder-plinius/ST3GG ST3GG is an all-in-one steganography toolkit that hides secret data inside images, audio, documents, and network packets using 100+ encodin… | 63 | 1741 | active |
| jaksi/sshesame sshesame is an SSH honeypot written in Go that runs a fake SSH server accepting any connection and logging all activity without executing a… | 23 | 1741 | active |
| wiire-a/pixiewps Pixiewps is a C command-line utility that brute-forces Wi-Fi Protected Setup (WPS) PINs offline, exploiting low- or non-entropy software im… | 57 | 1740 | active |
| standard-webhooks/standard-webhooks Standard Webhooks is an open specification plus reference libraries and tools for sending and verifying webhooks securely and consistently.… | 85 | 1737 | active |
| samyk/poisontap PoisonTap is a USB-based attack tool built on a Raspberry Pi Zero and Node.js that exploits locked, password-protected computers by emulati… | 32 | 6475 | maintenance |
| MatheuZSecurity/Singularity Singularity is a stealthy Linux kernel module (LKM) rootkit targeting modern 6.x kernels, using ftrace-based syscall hooking to hide proces… | 56 | 1736 | active |
| j3ssie/metabigor Metabigor is a Go-based command-line OSINT tool that maps a target's infrastructure—IP ranges, subdomains, related domains, open ports, and… | 86 | 1735 | active |
| awslabs/aws-config-rules A community repository of sample custom AWS Config rules written in Python, Node.js, and Java. These Lambda-based rules evaluate AWS resour… | 70 | 1735 | active |
| polymorf/findcrypt-yara An IDA Pro plugin that uses YARA rules to scan binaries for known cryptographic constants and other recognizable byte patterns. It helps re… | 32 | 1735 | active |
| i12bp8/TagTinker TagTinker is a Flipper Zero application for researching infrared electronic shelf label (ESL) protocols, letting users transmit custom imag… | 50 | 1734 | active |
| Fr4nkFletcher/ESP32-Marauder-Cheap-Yellow-Display A port of the ESP32-Marauder WiFi/Bluetooth testing firmware to the Cheap Yellow Display (CYD) family of ESP32 boards with ILI9341/ST7789/S… | 47 | 1734 | active |
| Consensys/gnark gnark is a fast zk-SNARK library in Go offering a high-level API to define circuits, compile them to constraint systems, and generate/verif… | 91 | 1731 | active |
| cleverhans-lab/cleverhans CleverHans is a Python library for benchmarking machine learning systems' vulnerability to adversarial examples, providing reference implem… | 23 | 6450 | maintenance |
| FossifyOrg/File-Manager Fossify File Manager is an open-source, ad-free Android file manager for browsing, organizing, compressing, and securing files on device st… | 89 | 1729 | stable |
| hwdsl2/openvpn-install A Bash script that automates setting up an OpenVPN server on a wide range of Linux distributions, including Ubuntu, Debian, CentOS, Fedora,… | 77 | 1728 | active |
| xbrowsersync/app xBrowserSync is a free, privacy-focused tool for syncing browser data (bookmarks, settings, etc.) between different browsers and devices. T… | 68 | 1728 | active |
| mandatoryprogrammer/CursedChrome CursedChrome is a Chrome extension implant that converts a victim's Chrome browser into a fully-functional HTTP proxy, letting an operator … | 32 | 1728 | active |
| CodingGay/BlackDex BlackDex is an Android app that unpacks DEX files from installed or uninstalled APKs on Android 5.0-12 without requiring root, Xposed, Frid… | 23 | 6439 | maintenance |
| ghostery/ghostery-extension Ghostery is a browser extension that blocks ads, trackers, and cookie pop-ups across Firefox, Chrome, Opera, Edge, Safari, and Yandex. It p… | 95 | 1726 | active |
| Tokeii0/LovelyMem Lovelymem V2 is a Windows desktop memory forensics workbench built with Rust, Tauri 2, and TypeScript. It integrates MemProcFS, Volatility … | 87 | 1725 | active |
| AikidoSec/safe-chain Aikido Safe Chain is a free, tokenless CLI tool that wraps package managers (npm, yarn, pnpm, npx, pip, uv, poetry, and more) to block mali… | 84 | 1725 | active |
| theupdateframework/python-tuf Python reference implementation of The Update Framework (TUF), a CNCF-graduated specification for securing software update systems against … | 83 | 1724 | stable |
| GrimAnticheat/Grim GrimAC is an open-source Minecraft anticheat plugin that detects cheats by simulating real client movement with fully asynchronous, multith… | 82 | 1724 | active |
| cmu-sei/pharos Pharos is a static binary analysis framework from Carnegie Mellon's Software Engineering Institute built on the ROSE compiler infrastructur… | 75 | 1723 | active |
| kdrag0n/safetynet-fix A Magisk module (Zygisk-based, with an older Riru version) that works around Google's SafetyNet and Play Integrity hardware attestation che… | 23 | 6412 | maintenance |
| upspin/upspin Upspin is an experimental framework of protocols and reference implementations providing a secure, global naming system for sharing files a… | 46 | 6399 | maintenance |
| apple/swift-crypto Swift Crypto is an open-source Swift library implementing a substantial portion of Apple CryptoKit's API for use on Linux, Windows, and oth… | 97 | 1718 | active |
| DanielLavrushin/b4 B4 (Bye Bye Big Bro) is a Linux service that bypasses Deep Packet Inspection (DPI) censorship by rewriting network packets via fragmentatio… | 80 | 1714 | active |
| ev-flow/quark-engine Quark Engine is an Android malware scoring and analysis system that inspects APKs using rule-based behavioral detection on Dalvik bytecode.… | 98 | 1713 | active |