function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| michenriksen/aquatone Aquatone is a Go CLI tool for visual inspection of websites across many hosts, taking screenshots via headless Chrome/Chromium and generati… | 10 | 5961 | maintenance |
| cathugger/mkp224o mkp224o is a C command-line tool that generates vanity ed25519 onion service (Tor hidden service v3) addresses by brute-forcing keypairs ma… | 23 | 1616 | active |
| DuendeSoftware/products Duende Products is a suite of identity and access management SDKs for ASP.NET Core, centered on Duende IdentityServer, a standards-complian… | 93 | 1614 | stable |
| ProtonMail/ios-mail Proton Mail's official iOS client for end-to-end encrypted email, written in Swift/SwiftUI with core business logic in a Rust-based SDK. Th… | 66 | 1613 | active |
| coffinxp/loxs Loxs is a Python-based multi-vulnerability scanner for web applications that detects SQL injection, XSS, LFI, open redirect, and CRLF injec… | 52 | 1612 | active |
| SecurityRiskAdvisors/VECTR VECTR is a self-hosted web application for tracking red and blue team testing activities to measure detection and prevention capabilities a… | 98 | 1611 | active |
| ankane/lockbox Lockbox is a Ruby gem providing modern encryption for database fields, files, and strings in Ruby and Rails applications. It integrates wit… | 66 | 1609 | stable |
| hashcat/hashcat-utils A collection of small standalone C utilities that assist with advanced password cracking tasks, complementing the hashcat tool. Each utilit… | 48 | 1609 | active |
| fofapro/fapro FaPro is a free, cross-platform, single-file mass network protocol server simulator written in Python. It can start or stop many fake netwo… | 23 | 1609 | active |
| Jelmerro/Vieb Vieb is a free, open-source web browser built on Electron/Chromium that provides Vim-style modal keyboard bindings for navigating the web. … | 93 | 1607 | active |
| AfterShip/email-verifier A Go library for verifying email addresses without sending any emails. It validates syntax, checks DNS MX records, performs SMTP verificati… | 67 | 1607 | active |
| liamg/gitjacker Gitjacker is a Go CLI tool that downloads and reconstructs git repositories from websites where the .git directory has been mistakenly expo… | 48 | 1607 | active |
| jakehildreth/Locksmith Locksmith is a PowerShell module and script that audits Active Directory Certificate Services (AD CS) for common misconfigurations. It can … | 75 | 1606 | active |
| FireHOL FireHOL is a Linux firewall management tool built on iptables/ipsets, paired with a repository of IP blocklists dynamically updated via the… | 56 | 1603 | active |
| repplus/rep-chrome rep+ is a Chrome DevTools extension inspired by Burp Suite's Repeater that captures and replays HTTP requests with modified methods, header… | 54 | 1603 | active |
| Jon-Becker/heimdall-rs Heimdall is a Rust-based EVM smart contract toolkit for bytecode analysis, decompilation, disassembly, control flow graph generation, stora… | 89 | 1602 | active |
| Orange-Cyberdefense/ocd-mindmaps A collection of interactive mindmaps from Orange Cyberdefense covering offensive security and penetration testing methodologies, published … | 37 | 1602 | active |
| miniupnp/miniupnp MiniUPnP is a lightweight ANSI C implementation of the UPnP Internet Gateway Device (IGD) specifications, comprising a client library (mini… | 98 | 1601 | stable |
| StamusNetworks/Clear-NDR-ISO Clear NDR Community (formerly SELKS) is a Debian-based Linux distribution for network detection and response built around Suricata, OpenSea… | 41 | 1591 | active |
| WireGuard/wireguard-android The official Android GUI application for WireGuard, a fast and modern VPN. It opportunistically uses the in-kernel WireGuard implementation… | 73 | 1589 | stable |
| LeeeSe/MessAuto MessAuto is a free macOS menu bar application, built in Rust, that automatically extracts SMS and email verification codes from the built-i… | 69 | 1589 | active |
| PentestPad/subzy Subzy is a Go-based command-line tool that checks subdomains for takeover vulnerabilities by matching HTTP response fingerprints from the c… | 32 | 1589 | active |
| Autumn-27/ScopeSentry ScopeSentry is a self-hosted attack surface and asset mapping platform that combines subdomain enumeration, port scanning, fingerprinting, … | 88 | 1587 | active |
| KindleModding/WinterBreak WinterBreak is a jailbreak tool for Amazon Kindle e-readers, built on top of the Mesquito framework. It allows users to unlock their Kindle… | 86 | 1587 | active |
| s0md3v/uro uro is a Python CLI tool that declutters URL lists for crawling and security testing without making any HTTP requests. It removes duplicate… | 29 | 1587 | stable |
| xnl-h4ck3r/xnLinkFinder xnLinkFinder is a Python CLI tool that discovers endpoints, potential parameters, target-specific wordlists, and secrets for a given target… | 78 | 1585 | active |
| linuxboot/heads Heads is an open-source firmware and OS configuration that runs a minimal Linux as a coreboot or LinuxBoot ROM payload, moving the root of … | 67 | 1585 | active |
| DimensionDev/Maskbook Mask Network is a browser extension that bridges Web2 social media platforms (X, Facebook, Instagram, Minds, Mirror) with Web3 services. It… | 96 | 1584 | active |
| attify/firmware-analysis-toolkit Firmware Analysis Toolkit (FAT) is a Python-based automation wrapper around Firmadyne that emulates IoT and embedded device firmware images… | 23 | 1582 | active |
| ReaJason/MemShellParty MemShellParty is a self-hosted, visual tool for rapidly generating Java memory shells (fileless webshells) for mainstream web middleware an… | 89 | 1581 | active |
| dyne/tomb Tomb is a minimalist command-line tool for GNU/Linux that creates and manages encrypted storage folders ('tombs') using dm-crypt and LUKS v… | 58 | 1581 | stable |
| gurnec/btcrecover btcrecover is an open-source Python command-line tool for recovering Bitcoin (and altcoin) wallet passwords and seed phrases when most of t… | 32 | 1580 | active |
| nzymeorg/nzyme Nzyme is an open-source intrusion detection system that monitors WiFi, Bluetooth, and Ethernet networks for threats such as rogue access po… | 79 | 1579 | active |
| SimpleMobileTools/Simple-File-Manager Simple File Manager is an open-source, ad-free file and folder manager app for Android devices built in Kotlin. It offers file operations l… | 23 | 1579 | stable |
| nccgroup/PMapper Principal Mapper (PMapper) is a Python CLI tool and library that models AWS IAM users and roles as a directed graph to identify privilege e… | 23 | 1576 | active |
| spatie/laravel-honeypot A Laravel package that prevents spam form submissions using honeypot fields and submission-time checks. It provides a Blade component and m… | 91 | 1575 | stable |
| B16f00t/whapa Whapa is a Python-based forensic toolset for parsing and analyzing WhatsApp databases from Android and iOS devices. It includes tools for d… | 75 | 1575 | active |
| Waujito/youtubeUnblock A C-based tool that bypasses YouTube's SNI-based detection systems, originally created to work around YouTube throttling in Russia. It runs… | 68 | 1575 | active |
| pk-fr/yakpro-po YAK Pro - Php Obfuscator is a free, open-source CLI tool that obfuscates pure PHP source code using the PHP-Parser library. It removes comm… | 65 | 1574 | active |
| zama-ai/concrete Concrete is an open-source fully homomorphic encryption (FHE) compiler built on TFHE and LLVM that converts Python programs into their FHE … | 56 | 1574 | active |
| OWASP/threat-dragon OWASP Threat Dragon is a free, open-source, cross-platform threat modeling application for drawing data flow diagrams and listing threats f… | 89 | 1572 | active |
| libssh2/libssh2 libssh2 is a client-side C library implementing the SSH2 protocol, licensed under the revised BSD license. It provides session establishmen… | 67 | 1572 | stable |
| ultrasecurity/Storm-Breaker Storm-Breaker is a social engineering tool that generates phishing-style web pages to capture device information, location, webcam, and mic… | 32 | 5754 | maintenance |
| aleskxyz/reality-ezpz A single-command bash installer that deploys sing-box or xray proxy servers (vless, TUIC, hysteria2, shadowtls) with reality or TLS encrypt… | 57 | 1570 | active |
| cyberark/FuzzyAI FuzzyAI is an automated LLM fuzzing tool from CyberArk that tests LLM APIs for jailbreak vulnerabilities. It ships as a Python CLI with a w… | 51 | 1568 | active |
| stealthcopter/deepce DEEPCE is a single-file pure-shell script for enumerating Docker environments and attempting privilege escalation and container escapes. It… | 58 | 1567 | active |
| wikiZ/RedGuard RedGuard is a C2 front flow control tool written in Go that acts as a filtering reverse proxy in front of command-and-control servers. It h… | 23 | 1567 | active |
| OWASP/crAPI crAPI (completely ridiculous API) is an intentionally vulnerable web application built by OWASP to demonstrate the OWASP API Security Top 1… | 63 | 1566 | active |
| drduh/pwd.sh pwd.sh is a single Bash script that manages text secrets such as passwords using GnuPG symmetric encryption. Secrets are stored in randomly… | 88 | 1564 | active |
| meskarune/i3lock-fancy A bash script wrapper around i3lock that takes a screenshot of the desktop, blurs or pixelates it, and overlays a lock icon and text to cre… | 23 | 1564 | stable |
| Tsojan/TsojanScan TsojanScan is an integrated BurpSuite plugin for vulnerability detection that bundles multiple common vulnerability POCs into a single exte… | 85 | 1563 | active |
| AD-Security/AD_Miner AD Miner is an Active Directory (on-premise and Entra ID) auditing tool that runs Cypher queries against a BloodHound Neo4j graph database … | 70 | 1562 | active |
| moom825/xeno-rat Xeno-RAT is an open-source remote access tool (RAT) written in C# for remotely controlling Windows 10/11 machines. It includes features suc… | 18 | 1562 | active |
| Leon406/SubCrawler A Kotlin-based tool that automatically crawls and health-checks (via Google ping) free public proxy nodes for protocols like V2Ray, Shadows… | 77 | 1561 | active |
| dwisiswant0/crlfuzz CRLFuzz is a fast command-line tool written in Go that scans websites for CRLF (carriage return/line feed) injection vulnerabilities. It su… | 66 | 1560 | active |
| lqqyt2423/go-mitmproxy A Golang implementation of mitmproxy that intercepts, parses, monitors, and tampers with HTTP/HTTPS traffic via a man-in-the-middle proxy. … | 88 | 1559 | active |
| OWASP/QRLJacking QRLJacking is an OWASP project documenting and exploiting the Quick Response Code Login Jacking attack vector, which hijacks user sessions … | 48 | 1559 | active |
| kubernetes-sigs/secrets-store-csi-driver A Kubernetes CSI driver that mounts secrets, keys, and certificates from external secrets stores (Vault, Azure Key Vault, AWS Secrets Manag… | 86 | 1557 | stable |
| newaetech/chipwhisperer ChipWhisperer is an open-source toolchain for hardware security research, providing capture hardware designs, FPGA/USB firmware, and a Pyth… | 79 | 1557 | active |
| AndyFul/ConfigureDefender ConfigureDefender is a small portable Windows GUI utility for viewing and configuring Windows Defender antivirus settings on Windows 10/11 … | 74 | 1555 | active |
| v-byte-cpu/sx sx is a fast, UNIX-philosophy command-line network scanner written in Go that supports ARP/NDP host discovery, ICMP, TCP SYN/FIN/NULL/Xmas,… | 83 | 1553 | active |
| EdXposed EdXposed is a Riru-based Magisk module providing an ART hooking framework for Android 8.0-11, exposing the classic Xposed API so modules ca… | 23 | 5666 | maintenance |
| AeonLucid/AndroidNativeEmu A Python library that partially emulates Android native (.so) libraries on a host machine using the Unicorn CPU emulator. It emulates the J… | 26 | 1549 | active |
| samwafgo/SamWaf SamWaf is a lightweight, open-source web application firewall (WAF) written in Go, designed for small companies, studios, and personal webs… | 89 | 1547 | active |
| homeassistant-apps/app-cloudflared A Home Assistant add-on that runs Cloudflared to create a secure Cloudflare Tunnel to your Home Assistant instance. It enables remote acces… | 99 | 1543 | active |
| lucavallin/barco barco is a minimal Linux container runtime written in C, built from scratch using kernel features like namespaces, cgroups, seccomp, and ca… | 32 | 1543 | active |
| ServenScorpion/VirtualApp A fork of VirtualApp, an Android virtualization framework that runs apps inside a virtual container supporting app cloning (multi-instance)… | 74 | 1540 | active |
| Alex313031/Mercury Mercury is a Firefox fork with compiler optimizations (AVX, AES, LTO, PGO) and privacy/security patches drawn from LibreWolf, Waterfox, Gho… | 66 | 1539 | active |
| system-linux/FazJammer FazJammer is an ESP8266-based firmware project that turns a NodeMCU plus an NRF24L01+ radio module into a device that jams Wi-Fi, BLE, and … | 42 | 1539 | active |
| WildKernels/GKI_KernelSU_SUSFS Prebuilt Android GKI (Generic Kernel Image) kernels for Android 5.10+ devices with KernelSU root support and SUSFS root-hiding patches inte… | 85 | 1537 | active |
| BLE-Research-Group/MetaRadar MetaRadar (BLE Radar) is an Android application for monitoring Bluetooth Low Energy environments. It scans for nearby BLE devices, analyzes… | 71 | 1537 | active |
| ProtonMail/proton-bridge Proton Mail Bridge is a desktop application that runs local IMAP and SMTP servers, allowing standard email clients to send and receive encr… | 94 | 1536 | active |
| profanity-im/profanity Profanity is a console-based XMPP chat client written in C using ncurses and libstrophe, inspired by Irssi. It supports MUC chat rooms, OTR… | 91 | 1536 | active |
| guacsec/guac GUAC (Graph for Understanding Artifact Composition) is an OpenSSF incubating project that ingests software security metadata such as SBOMs,… | 90 | 1534 | active |
| occlum/occlum Occlum is a memory-safe, multi-process library OS (LibOS) written in Rust for Intel SGX enclaves. It lets legacy applications run inside se… | 52 | 1532 | active |
| xnl-h4ck3r/GAP-Burp-Extension GAP is a Burp Suite extension written in Python (Jython) that extracts potential endpoints, parameters, and links from Burp's site map, pro… | 66 | 1530 | active |
| canyie/pine Pine is a dynamic Java method hooking framework for the Android ART runtime, allowing interception and modification of almost any Java meth… | 55 | 1528 | active |
| MikeWang000000/FakeHTTP FakeHTTP is a Linux command-line tool that obfuscates TCP connections by disguising them as HTTP traffic using Netfilter Queue (NFQUEUE). I… | 34 | 1527 | active |
| ThisSeanZhang/landscape Landscape is a Linux router application built in Rust with eBPF that routes traffic by domain rather than just IP. It uses a userspace DNS … | 88 | 1526 | active |
| BlackSnufkin/LitterBox LitterBox is a self-hosted payload-analysis sandbox for red teams that runs static, dynamic, and EDR-based analysis on samples and produces… | 62 | 1526 | active |
| cartalyst/sentinel Sentinel is a PHP 8.3+ framework-agnostic authentication and authorization library by Cartalyst. It provides user authentication, roles, pe… | 61 | 1526 | active |
| janmojzis/tinyssh TinySSH (tinysshd) is a minimalistic SSHv2 server written in C with under 100,000 words of code, implementing only a secure subset of the p… | 89 | 1524 | active |
| raspberrypi/rpi-eeprom Official Raspberry Pi tooling of shell scripts and pre-compiled binaries for updating and configuring the bootloader EEPROM on Raspberry Pi… | 94 | 1522 | active |
| mysk-research/loupe Loupe is an open-source iOS and iPadOS app that demonstrates device fingerprinting by showing raw values from public iOS APIs that any thir… | 53 | 1522 | active |
| contiki-ng/contiki-ng Contiki-NG is an open-source, cross-platform operating system for next-generation IoT devices, forked from the original Contiki OS. It focu… | 88 | 1521 | active |
| Tongsuo-Project/Tongsuo Tongsuo (铜锁) is an open-source cryptographic library providing modern cryptographic primitives and secure communication protocols, includin… | 84 | 1521 | active |
| FossifyOrg/Messages Fossify Messages is an open-source Android SMS/MMS messenger app with no ads or tracking. It supports group messaging, spam blocking, messa… | 97 | 1520 | stable |
| nemesida-waf/waf-bypass WAF Bypass Tool is an open-source Python CLI tool that tests web application firewalls for false positives and false negatives using predef… | 83 | 1520 | active |
| nfephp-org/sped-nfe A PHP library for generating, signing, and transmitting Brazilian electronic fiscal documents (NF-e model 55 and NFC-e model 65) to SEFAZ a… | 66 | 1519 | active |
| mushorg/conpot Conpot is a low-interaction ICS/SCADA honeypot written in Python that emulates industrial control system protocols and devices. It collects… | 66 | 1519 | active |
| Danny-Dasilva/CycleTLS CycleTLS is a Go library with a JavaScript/TypeScript wrapper that lets clients spoof TLS/JA3 (and JA4) fingerprints when making HTTP reque… | 73 | 1518 | active |
| gobysec/Goby Goby is a network security assessment tool that maps an organization's attack surface and scans for known vulnerabilities and weak password… | 23 | 1517 | active |
| fossas/fossa-cli FOSSA CLI is a zero-configuration, language-agnostic dependency analysis tool that detects dependencies in any codebase across 20+ build sy… | 95 | 1516 | active |
| overspace-labs/CaA CaA is a BurpSuite extension (Montoya API) that analyzes HTTP traffic to extract parameters, paths, files, and parameter values with freque… | 83 | 1516 | active |
| shirokhorshid/shirokhorshid-android Shir o Khorshid is an independently maintained, community fork of the open-source Psiphon Android VPN/circumvention client, adding extra co… | 71 | 1516 | active |
| ztgrace/changeme changeme is a Python CLI tool that scans networks for devices and services using default or backdoor credentials. Credential definitions ar… | 36 | 1516 | active |
| globaleaks/globaleaks-whistleblowing-software GlobaLeaks is a free, open-source whistleblowing platform that lets any organization set up and maintain a secure, anonymous reporting syst… | 94 | 1514 | stable |
| awslabs/aws-support-tools A curated collection of diagnostic and troubleshooting scripts and sample code for AWS services, maintained by AWS Premium Support. Tools a… | 96 | 1513 | active |
| webpwnized/mutillidae OWASP Mutillidae II is a deliberately vulnerable PHP web application used as a target for web-security training and practice. It includes o… | 72 | 1513 | active |
| deathmemory/FridaContainer FridaContainer is a modular collection of popular and custom Frida scripts written in TypeScript to speed up reverse engineering work on An… | 56 | 1512 | active |