function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| lasting-yang/frida_hook_libart A collection of Frida hook scripts for intercepting Android ART JNI functions, most notably RegisterNatives. It reveals native method regis… | 54 | 1713 | active |
| Rob--W/crxviewer A browser add-on and web app for viewing the source code of Chrome, Firefox, Opera, Edge, and Thunderbird extensions without installing the… | 72 | 1712 | active |
| cloudflare/circl CIRCL is Cloudflare's Go library of cryptographic primitives covering post-quantum algorithms (ML-KEM/Kyber, ML-DSA/Dilithium, SIKE/CSIDH),… | 94 | 1710 | active |
| cr0hn/dockerscan DockerScan is a comprehensive Docker security scanner written in Go that scans containers, images, and registries using multiple techniques… | 93 | 1710 | active |
| Septrum101/zteOnu A Go CLI tool that opens factory/telnet mode on ZTE ONU (fiber optic modem) devices via their webFac interface. It authenticates with facto… | 94 | 1708 | active |
| elasticdog/transcrypt A single Bash script that configures transparent encryption of sensitive files in a Git repository using Git's clean/smudge filters and Ope… | 80 | 1708 | stable |
| S3cur3Th1sSh1t/PowerSharpPack PowerSharpPack wraps many useful offensive C# security projects (Seatbelt, Rubeus, SharpUp, winPEAS, etc.) into PowerShell scripts for easy… | 39 | 1708 | active |
| mganss/HtmlSanitizer A .NET library for cleaning HTML fragments and documents of constructs that can lead to XSS attacks, built on the AngleSharp parser. It is … | 98 | 1707 | active |
| dolevf/Damn-Vulnerable-GraphQL-Application Damn Vulnerable GraphQL Application (DVGA) is an intentionally insecure GraphQL service built for learning and practicing GraphQL security … | 33 | 1705 | active |
| Safe3/uusec-waf UUSEC WAF is a free, high-performance web application firewall and API security gateway (WAAP) that combines AI/semantic detection engines … | 98 | 1703 | active |
| black-ant/Ant-Browser Ant Browser is a desktop anti-detect (fingerprint) browser for managing multiple isolated browser profiles, each with its own proxy binding… | 80 | 1701 | active |
| ErwinM/acts_as_tenant A Ruby gem that adds fail-safe row-level multi-tenancy to Ruby on Rails applications using a shared database. It scopes models to a current… | 30 | 1701 | active |
| project-copacetic/copacetic Copa (Project Copacetic) is a Go CLI tool built on BuildKit that directly patches OS package vulnerabilities in container images without re… | 91 | 1700 | active |
| jazzband/django-axes django-axes is a Django plugin that tracks failed login attempts and blocks brute-force attacks on Django-powered sites. It supports monito… | 84 | 1700 | stable |
| webprofusion/certify Certify The Web is an ACME v2 certificate management application with a Windows desktop UI and background renewal service, plus a cross-pla… | 77 | 1700 | stable |
| sudo-project/sudo Sudo is a Unix utility that allows a system administrator to delegate limited root or other-user privileges to users on a per-command basis… | 78 | 1699 | stable |
| roothide/Bootstrap A full-featured bootstrap (package manager environment) for jailbroken iOS 15.0-17.0 on A8-A17 Pro and M1/M2 devices using the roothide jai… | 84 | 1697 | active |
| bromite/bromite Bromite is a Chromium fork for Android with a built-in ad-blocking engine and privacy enhancements such as anti-fingerprinting flags, DNS-o… | 23 | 6299 | maintenance |
| SiriusScan/Sirius Sirius is an open-source vulnerability scanner that automates network discovery via Nmap and performs CVE-based detection with CVSS scoring… | 88 | 1695 | active |
| pgaudit/pgaudit pgAudit is a PostgreSQL extension written in C that provides detailed session and object audit logging through the standard PostgreSQL logg… | 80 | 1695 | stable |
| nix-community/nix-ld nix-ld is a shim dynamic linker that lets unpatched precompiled Linux binaries run on NixOS by installing itself at the conventional loader… | 78 | 1695 | active |
| duo-labs/cloudmapper CloudMapper is a tool for analyzing Amazon Web Services (AWS) environments, originally built to generate interactive network diagrams in th… | 23 | 6288 | maintenance |
| cedar-policy/cedar Cedar is a purpose-built policy language and Rust implementation for writing and enforcing fine-grained authorization policies in applicati… | 95 | 1693 | stable |
| AdguardTeam/AdguardForiOS AdGuard for iOS is an open-source ad-blocking and privacy app for iPhone and iPad that blocks ads in Safari via content blocking rules. It … | 95 | 1692 | active |
| hasherezade/tiny_tracer A Pin Tool built on Intel Pin for dynamic binary instrumentation that traces API calls, syscalls, selected instructions, and section transi… | 80 | 1692 | active |
| dafthack/MFASweep MFASweep is a PowerShell script that attempts to log in to multiple Microsoft services with provided credentials to detect whether MFA is e… | 67 | 1692 | active |
| openappsec/openappsec open-appsec is an open-source machine learning security engine that provides preemptive web application and API threat protection against O… | 99 | 1689 | active |
| wireghoul/graudit graudit is a shell-based source code auditing tool that uses GNU grep with signature databases of extended regular expressions to find pote… | 59 | 1688 | active |
| raodv/captcha AjPlus Captcha is an open-source behavioral CAPTCHA library providing sliding puzzle and click-word verification challenges with frontend U… | 39 | 1685 | active |
| BC-SECURITY/Starkiller Starkiller is a web-based graphical frontend for PowerShell Empire, a post-exploitation C2 framework. It is written in VueJS and ships prep… | 93 | 1684 | active |
| trailofbits/buttercup Buttercup is a Cyber Reasoning System (CRS) developed by Trail of Bits for the DARPA AI Cyber Challenge that automatically finds and patche… | 56 | 1683 | active |
| Gerenios/AADInternals AADInternals is a PowerShell module for administering and hacking Entra ID (Azure AD), Office 365, and related endpoints. It includes tools… | 52 | 1683 | active |
| fruitcake/laravel-cors A Laravel package that adds Cross-Origin Resource Sharing (CORS) headers support via middleware, handling pre-flight OPTIONS requests and c… | 10 | 6235 | maintenance |
| ImMALWARE/bash-warp-generator A shell script that generates Cloudflare WARP VPN configuration files for AmneziaWG (WireGuard-based) and Clash (MASQUE-based) clients. It … | 66 | 1681 | active |
| whwlsfb/JDumpSpider JDumpSpider is a Java CLI tool that extracts sensitive information (datasource credentials, config properties, Redis configs, Shiro keys, u… | 70 | 1680 | active |
| inverse-inc/packetfence PacketFence is a free and open source network access control (NAC) solution with a captive portal for registration and remediation, 802.1X … | 88 | 1678 | stable |
| MorDavid/BruteForceAI BruteForceAI is a Python-based penetration testing tool that uses LLMs (via Ollama or Groq) to automatically analyze login page HTML and id… | 60 | 1677 | active |
| sickcodes/osx-serial-generator A shell-based tool that generates valid macOS serial numbers, UUIDs, and board serials for use with OpenCore, OSX-KVM, and Docker-OSX. It i… | 39 | 1677 | stable |
| reek/anti-adblock-killer Anti-Adblock Killer is a userscript (AakScript) plus an AdBlock-style filter list (AakList) that together prevent websites from detecting a… | 23 | 6212 | maintenance |
| fire-keeper/BlindWatermark A Python library and CLI/GUI tool that embeds invisible blind watermarks into images using discrete wavelet transforms, protecting creators… | 23 | 1675 | active |
| keepassium/KeePassium KeePassium is a KeePass-compatible password manager app for iOS and macOS, written in Swift. It supports all KeePass database formats (kdb,… | 67 | 1674 | active |
| mikespook/gorbac goRBAC is a lightweight role-based access control (RBAC) library for Go, supporting many-to-many role/permission mappings and hierarchical … | 65 | 1674 | active |
| michenriksen/gitrob Gitrob is a Go-based reconnaissance tool that scans GitHub users' and organizations' public repositories for potentially sensitive files by… | 10 | 6198 | maintenance |
| KeenSecurityLab/BinAbsInspector BinAbsInspector is a static analyzer for automated reverse engineering and vulnerability scanning in binaries, built on abstract interpreta… | 23 | 1672 | active |
| rebeyond/Behinder Behinder ('冰蝎') is a cross-platform Java client for managing encrypted webshells on compromised web servers running PHP, Java, or .NET. It … | 23 | 6191 | maintenance |
| Lozy/danted A shell script that automates installing and configuring the Dante SOCKS5 proxy server on Linux systems, with Docker support. It auto-detec… | 32 | 1670 | active |
| GVCoder09/NoDPI NoDPI is a Python utility that bypasses Deep Packet Inspection (DPI) censorship by running a local proxy server that fragments TLS ClientHe… | 83 | 1666 | active |
| freeotp/freeotp-android FreeOTP is an open-source two-factor authentication app for Android that generates one-time passwords using the HOTP and TOTP standards. To… | 78 | 1666 | active |
| Asuswrt-Merlin Asuswrt-Merlin is an enhanced third-party firmware for Asus routers, based on Asus's stock Asuswrt firmware, focusing on bug fixes, tweaks,… | 77 | 6166 | maintenance |
| FairwindsOps/rbac-manager RBAC Manager is a Kubernetes operator that simplifies authorization management by allowing declarative configuration of Role Bindings and S… | 94 | 1665 | active |
| projectdiscovery/shuffledns shuffleDNS is a Go wrapper around massDNS for fast active subdomain enumeration via bruteforce and DNS resolution with smart wildcard filte… | 86 | 1664 | active |
| slackhq/go-audit go-audit is a Go-based replacement for the auditd daemon that consumes Linux kernel audit events via netlink and outputs them as JSON. It s… | 84 | 1664 | active |
| WangYihang/GitHacker GitHacker is a multi-threaded Python CLI tool that exploits exposed `.git` directories on web servers to reconstruct the entire Git reposit… | 77 | 1664 | active |
| bee-san/Name-That-Hash Name That Hash is a Python CLI tool and web app that identifies the type of an unknown hash string, supporting 300+ hash types like MD5 and… | 48 | 1664 | active |
| Moustachauve/cookie-editor Cookie-Editor is an open-source browser extension for creating, editing, deleting, importing and exporting cookies on the current tab. It w… | 66 | 1663 | active |
| summitt/Nope-Proxy NoPE Proxy is a Burp Suite extension that adds TCP and UDP traffic interception, a configurable DNS server, and a non-HTTP man-in-the-middl… | 23 | 1663 | active |
| Forward Email Forward Email is a 100% open-source, privacy-focused email service providing free email forwarding for custom domains, plus outbound SMTP, … | 94 | 1662 | active |
| secluso/core Secluso is an open-source, privacy-preserving home security camera system built for Raspberry Pi, featuring end-to-end encrypted remote acc… | 72 | 1661 | active |
| longld/peda PEDA is a Python plugin for GDB that enhances the debugger's display and adds exploit development commands. It provides colorized disassemb… | 23 | 6147 | maintenance |
| tabby-sec/tabby Tabby is a Java static code analysis tool built on the Soot framework that converts JAR/WAR/CLASS files into a code property graph stored i… | 51 | 1659 | active |
| dirkjanm/krbrelayx A Python toolkit for abusing Kerberos in Active Directory environments, including Kerberos relaying and unconstrained delegation attacks. I… | 64 | 1657 | active |
| kooritea/fcmfix An Xposed/LSPosed module written in Java that lets Firebase Cloud Messaging (FCM/GCM) wake fully stopped Android apps so push notifications… | 86 | 1656 | active |
| WangYihang/Platypus Platypus is a cross-platform reverse-shell and host management hub written in Go. Agents on managed machines dial back to a central server … | 67 | 1656 | active |
| ellermister/mtproxy A one-click shell script and Docker image for installing MTProxy (MTProto proxy) with Fake TLS disguise for Telegram clients. It fronts MTP… | 65 | 1656 | active |
| coral-xyz/backpack Backpack is an open-source crypto wallet browser extension built in TypeScript, serving as a home for xNFTs and supporting Solana, Ethereum… | 23 | 1656 | active |
| BigBoiCJ/SteamAutoCracker An open-source Python tool with a GUI that automatically removes Steam DRM from games by configuring Steam emulators and applying Steamless… | 23 | 1654 | active |
| 0xdea/frida-scripts A collection of Frida instrumentation scripts for reverse engineering mobile apps and native binaries, including tracers and enumerators fo… | 80 | 1653 | active |
| klezVirus/SysWhispers3 SysWhispers3 is a Python command-line tool that generates header and assembly (ASM) file pairs for direct system calls to the Windows kerne… | 32 | 1653 | active |
| chaitin/veinmind-tools veinmind-tools is a container security toolkit by Chaitin Tech built on the veinmind-sdk, providing scanners for malicious files, weak pass… | 23 | 1652 | active |
| Air14/HyperHide HyperHide is a hypervisor-based anti-anti-debug plugin for x64dbg/x32dbg that hides debuggers from detection. It uses Intel EPT to hook sys… | 23 | 1652 | active |
| zardus/preeny Preeny is a collection of LD_PRELOAD libraries written in C that help with binary exploitation and CTF-style challenges. It disables functi… | 54 | 1650 | active |
| x-falcon/Virtual-Hosts An Android app that lets users customize the hosts file on their device without root access by implementing a local VPN service. It support… | 50 | 1649 | active |
| whwlsfb/BurpCrypto BurpCrypto is a Burp Suite extension that encrypts Intruder payloads with algorithms like AES, RSA, and DES, or by executing arbitrary Java… | 23 | 1648 | active |
| scito/extract_otp_secrets A Python CLI tool that extracts one-time password (TOTP/HOTP) secrets from QR codes exported by two-factor authentication apps like Google … | 93 | 1647 | active |
| hanmaoye/IDM-Activation-Script An open-source batch/PowerShell script that activates Internet Download Manager (IDM) or freezes its 30-day trial indefinitely using a regi… | 22 | 1647 | active |
| zama-ai/tfhe-rs TFHE-rs is a pure Rust implementation of the TFHE fully homomorphic encryption scheme, enabling boolean and integer arithmetic over encrypt… | 97 | 1646 | active |
| mssun/passforios Pass for iOS is an iOS password manager client compatible with ZX2C4's Pass command line application. It encrypts password entries with GPG… | 78 | 1645 | active |
| cddmp/enum4linux-ng enum4linux-ng is a Python rewrite of the enum4linux.pl Windows/Samba enumeration tool, wrapping Samba utilities like nmblookup, net, rpccli… | 75 | 1644 | active |
| shekyan/slowhttptest SlowHTTPTest is a highly configurable command-line tool that simulates Application Layer Denial of Service attacks by prolonging HTTP conne… | 67 | 1644 | active |
| fabiocaccamo/FCUUID An Objective-C iOS library providing universally unique identifiers with different persistence levels (session, installation, device, user)… | 58 | 1644 | stable |
| YanCchen/YCursor YCursor is a free desktop GUI tool for Windows and macOS that automates resetting Cursor IDE machine IDs and auto-registering new trial acc… | 36 | 1644 | active |
| tevador/RandomX RandomX is a proof-of-work algorithm optimized for general-purpose CPUs that uses random code execution and memory-hard techniques to resis… | 92 | 1643 | stable |
| hyprwm/hyprlock hyprlock is a GPU-accelerated, multi-threaded screen locking utility built for the Hyprland Wayland compositor. It uses the ext-session-loc… | 89 | 1643 | active |
| geiger-rs/cargo-geiger cargo-geiger is a cargo plugin that scans a Rust crate and its dependency tree to report statistics on unsafe Rust code usage. It provides … | 67 | 1643 | active |
| rust-openssl/rust-openssl Rust bindings to the OpenSSL cryptography and TLS library, exposing its APIs (certificates, keys, hashing, SSL/TLS connections) to Rust pro… | 95 | 1641 | stable |
| outtable/confuse-9live A macOS GUI application (distributed as a DMG, not source code) that obfuscates iOS app binaries and resources to bypass App Store review i… | 57 | 1636 | active |
| monkeyWie/proxyee Proxyee is a Java library built on Netty that implements an HTTP proxy server supporting HTTP, HTTPS, and WebSocket protocols. It provides … | 30 | 1634 | active |
| AltraMayor/gatekeeper Gatekeeper is the first open-source DDoS protection system, built on DPDK for high-performance packet processing. It uses a geographically … | 45 | 1633 | active |
| ADD-SP/ngx_waf ngx_waf is a high-performance Nginx firewall module written in C that provides web application firewall capabilities. It is compatible with… | 24 | 1631 | active |
| Greedeks/GTweak GTweak is a portable Windows utility written in C# for optimizing, debloating, and customizing Windows 10/11 setups. It provides tweaks suc… | 90 | 1630 | active |
| Pentest AI pentest-ai is an MIT-licensed local CLI and MCP server that turns Claude Code (or any LLM) into an offensive security assistant, pairing 50… | 80 | 1629 | active |
| C0nw0nk/Nginx-Lua-Anti-DDoS A Lua-based Anti-DDoS script for Nginx that presents a Cloudflare-style JavaScript authentication puzzle to filter out bots and mitigate La… | 98 | 1628 | active |
| zhaodice/qemu-anti-detection A collection of patches for various QEMU versions that modify emulator-reported data (device names, serial numbers, UEFI VM bit, BGRT) to p… | 58 | 1627 | active |
| illera88/Ponce Ponce is an IDA Pro plugin that adds one-click symbolic execution and taint analysis over binaries, built on the Triton engine and written … | 34 | 1627 | active |
| JesseCHale/HaleHound-CYD HaleHound-CYD is a multi-protocol offensive security toolkit firmware for the ESP32 Cheap Yellow Display, offering 40+ attack modules acros… | 80 | 1623 | active |
| alexazhou/VeryNginx VeryNginx is an enhanced Nginx distribution built on lua-nginx-module (OpenResty) that adds a web application firewall, request routing, ra… | 23 | 5979 | maintenance |
| vladko312/SSTImap SSTImap is a Python-based penetration testing tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code i… | 88 | 1621 | active |
| wiredoor/wiredoor Wiredoor is a self-hosted ingress-as-a-service platform that exposes services running in private or local networks to the internet via reve… | 84 | 1620 | active |
| SELinuxProject/selinux The upstream userspace repository for Security Enhanced Linux (SELinux), providing the libraries and tools that complement SELinux support … | 88 | 1619 | stable |
| kkHAIKE/fake115 A Tampermonkey userscript that disguises the browser as the official 115 client to bypass login and download restrictions on the 115 cloud … | 67 | 1619 | active |