function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| nefarius/HidHide HidHide is a Windows kernel-mode filter driver that acts as an 'input device firewall', allowing users to block individual applications' ac… | 64 | 1511 | active |
| firedancer-io/firedancer Firedancer is Jump Crypto's from-scratch Solana validator client written in C, designed for extreme performance and security with a restric… | 95 | 1510 | active |
| hybridgroup/go-haystack A Go/TinyGo library and toolset for tracking personal Bluetooth devices through Apple's Find My network, using OpenHaystack and Macless-Hay… | 37 | 1509 | active |
| pallets-eco/flask-wtf Flask-WTF is a Python library that integrates WTForms with the Flask web framework, providing form rendering, validation, CSRF protection, … | 80 | 1508 | stable |
| jaraco/keyring A Python library providing a simple API to access the operating system's native keyring service for safe password storage and retrieval. It… | 70 | 1508 | stable |
| 0xsp-SRD/mortar Mortar Loader is a red team evasion tool that encrypts PE binaries and shellcode and executes them in memory using various injection techni… | 23 | 1508 | active |
| kenryu42/cc-safety-net CC Safety Net is a pre-execution hook for AI coding agent CLIs (Claude Code, Codex, Cursor, Gemini CLI, and many others) that blocks destru… | 83 | 1507 | active |
| Internet-Architecture-and-Security/PacketScope PacketScope is an open-source, eBPF-based protocol stack analysis and debugging tool for server-side network observability and defense. It … | 75 | 1507 | active |
| nikaiw/VMkatz VMkatz is a Rust CLI tool that extracts Windows credentials (NTLM hashes, DPAPI keys, Kerberos tickets, LSA secrets, BitLocker keys) direct… | 69 | 1507 | active |
| mike-engel/jwt-cli jwt-cli is a fast command-line tool written in Rust for decoding and encoding JSON Web Tokens (JWTs). It supports custom headers, arbitrary… | 67 | 1507 | active |
| DarthTon/Blackbone Blackbone is a C++ library for Windows memory hacking, providing APIs for process memory manipulation, DLL injection, manual PE image mappi… | 32 | 5479 | maintenance |
| nikitastupin/clairvoyance Clairvoyance is a Python CLI tool that recovers a GraphQL API's schema even when introspection is disabled, by probing field and type names… | 57 | 1506 | active |
| Gowtham-Darkseid/AutoPentestX AutoPentestX is a Python-based automated penetration testing toolkit that scans targets for vulnerabilities and generates security reports.… | 45 | 1504 | active |
| nohajc/anylinuxfs A Rust CLI utility for macOS that mounts any Linux-supported filesystem (ext4, btrfs, xfs, ZFS, NTFS, exFAT, etc.) with full read-write acc… | 85 | 1503 | active |
| tirrenotechnologies/tirreno tirreno is an open-source, self-hosted security framework written in PHP/PostgreSQL that provides event tracking, threat detection, and ris… | 83 | 1503 | active |
| ChendoChap/pOOBs4 A kernel exploit for PlayStation 4 firmware 9.00 that leverages a filesystem (exfat) bug triggered via a specially formatted USB drive, com… | 32 | 1503 | stable |
| assetnote/nowafpls nowafpls is a Jython-based Burp Suite plugin that bypasses web application firewalls (WAFs) by inserting junk data into HTTP request bodies… | 38 | 1502 | active |
| uber/ADR ADR (Agentic AI Detection and Response) is an open-source enterprise security framework for AI agents, providing endpoint discovery of AI t… | 68 | 1501 | active |
| kkapsner/CanvasBlocker A Firefox browser extension that protects users from browser fingerprinting by blocking or faking readouts of JavaScript APIs such as canva… | 64 | 1501 | active |
| ZimengXiong/tinyTouch tinyTouch is an open-source DIY hardware and software project that lets you authenticate, sudo, and log in to your computer with a fingerpr… | 69 | 1500 | active |
| pyca/bcrypt pyca/bcrypt is a Python library providing bcrypt password hashing and a bcrypt_pbkdf key derivation function. It offers salted hashing with… | 77 | 1499 | active |
| skyjake/lagrange Lagrange is a cross-platform desktop and mobile client for browsing Geminispace, written in C with SDL for graphics and OpenSSL for TLS. It… | 99 | 1498 | active |
| twofas/2fas-android The official open-source Android app for 2FAS, a two-factor authentication service that generates one-time passwords (TOTP and HOTP) for se… | 86 | 1497 | active |
| ray-lothian/UserAgent-Switcher A highly configurable browser extension that spoofs the User-Agent string across Chrome, Firefox, Edge, and Opera. It overrides HTTP reques… | 77 | 1497 | active |
| T4y1oR/RingQ RingQ is a post-exploitation antivirus evasion tool that obfuscates and loads arbitrary Windows executables or shellcode (e.g., Cobalt Stri… | 27 | 1497 | active |
| project-oak/oak Oak is a Rust-based platform for building distributed systems whose components can produce externally verifiable claims about their behavio… | 77 | 1496 | active |
| salvogiangri/KnoxPatch An LSPosed/Xposed module written in Kotlin that restores Samsung apps and features (Samsung Health, Samsung Cloud, Samsung Flow, etc.) on r… | 87 | 1495 | active |
| Meckazin/ChromeKatz ChromeKatz is a set of offensive security tools (CookieKatz, ElevationKatz) written in C that dump cookies and decryption keys directly fro… | 72 | 1495 | active |
| usbarmory/usbarmory USB armory is an open source hardware design for a compact secure computer built into a USB stick form factor, based on ARM SoCs. This repo… | 66 | 1495 | active |
| vinkla/hashids A small PHP library that generates YouTube-like short, URL-safe IDs from numbers, so numeric database IDs are not exposed to users. It supp… | 57 | 5429 | maintenance |
| google/go-safeweb go-safeweb is a collection of Go libraries for building secure-by-default HTTP servers. It applies security mechanisms like XSS and CSRF pr… | 10 | 1494 | active |
| facebook/fishhook fishhook is a small C library from Facebook that dynamically rebinds symbols in Mach-O binaries running on iOS, similar to DYLD_INTERPOSE o… | 32 | 5425 | maintenance |
| dekuNukem/bob_cassette_rewinder An open-source hardware/firmware project that defeats the DRM on Bob dishwasher detergent cassettes, allowing users to reset and refill the… | 32 | 1493 | active |
| duckduckgo/duckduckgo-privacy-extension DuckDuckGo Privacy Essentials is a browser extension for Firefox, Chrome, Edge, and Opera that blocks third-party trackers and ads, manages… | 99 | 1492 | active |
| spyboy-productions/r4ven R4ven is a security awareness and penetration testing tool that hosts a web page which, when a user grants browser permissions, captures GP… | 60 | 1492 | active |
| cossacklabs/acra Acra is a database security suite that provides field-level encryption, searchable encryption, tokenization, data masking, SQL firewalling,… | 58 | 1491 | active |
| rfxn/linux-malware-detect Linux Malware Detect (LMD) is a bash-based malware scanner for Linux servers featuring a multi-stage detection pipeline (MD5/SHA-256 hashin… | 86 | 1490 | active |
| stealthcopter/AndroidNetworkTools A Java library for Android providing handy networking utilities such as port scanning, subnet device discovery, ping, and Wake-on-LAN. It f… | 23 | 1490 | active |
| libressl/portable LibreSSL Portable is the portable build of LibreSSL, a TLS and cryptography stack forked from OpenSSL 1.0.1g by the OpenBSD project. It pro… | 94 | 1489 | stable |
| Spomky-Labs/otphp A PHP library for generating one-time passwords according to RFC 4226 (HOTP) and RFC 6238 (TOTP). It is compatible with Google Authenticato… | 93 | 1488 | stable |
| hellman/xortool xortool is a Python command-line tool for cryptanalysis of multi-byte XOR ciphers. It guesses the key length based on character frequency s… | 42 | 1488 | active |
| TheresAFewConors/Sooty Sooty is a Python CLI tool that automates routine tasks for SOC (Security Operations Center) analysts, such as URL sanitization, DNS and Wh… | 32 | 1488 | active |
| halo/LinkLiar LinkLiar is a free, open-source macOS status menu application written in Swift for spoofing the MAC addresses of Wi-Fi and Ethernet interfa… | 39 | 1486 | active |
| liuzq2002/Adguard-Home-For-Magisk-Mod A Magisk module that runs AdGuard Home on rooted Android devices to block ads by redirecting and filtering DNS requests. It ships with buil… | 85 | 1485 | active |
| kalessil/phpinspectionsea Php Inspections (EA Extended) is an open-source static code analysis tool distributed as a PhpStorm/IntelliJ IDEA plugin. It detects archit… | 73 | 1485 | active |
| pass-extension/pass-otp pass-otp is an extension for the pass password manager that stores and manages one-time-password (OTP) tokens as otpauth:// URIs. It genera… | 39 | 1485 | active |
| Schira4396/VcenterKiller A Go-based all-in-one exploitation and verification tool targeting VMware vCenter, covering major CVEs such as CVE-2021-21972, CVE-2021-219… | 23 | 1485 | active |
| securitybunker/databunker Databunker is a self-hosted, Go-based secure vault for tokenizing and storing personal records such as PII, PHI, KYC, and PCI data. It expo… | 75 | 1482 | active |
| Shopify/ejson EJSON is a Go CLI utility for managing encrypted secrets in JSON files using asymmetric elliptic-curve (NaCl Box) encryption. It lets teams… | 86 | 1480 | stable |
| Fuzion24/JustTrustMe An Xposed module for rooted Android devices that disables SSL certificate pinning in apps, enabling traffic interception during security au… | 23 | 5361 | maintenance |
| inguardians/peirates Peirates is a Go-based, interactive Kubernetes penetration testing tool that automates privilege escalation, lateral movement, and cluster … | 90 | 1477 | active |
| controlplaneio/kubesec Kubesec is a static analysis tool that performs security risk analysis on Kubernetes resource manifests, assigning a security score and det… | 64 | 1477 | active |
| LionSec/katoolin A Python CLI tool that lets users add or remove Kali Linux repositories on other Debian-based systems (like Ubuntu) and install Kali Linux … | 32 | 5348 | maintenance |
| vslavik/winsparkle WinSparkle is an app update framework for Windows desktop applications, inspired by Sparkle for macOS. It ships as a single dependency-free… | 88 | 1475 | stable |
| anytls/anytls-go anytls-go is the Go reference implementation of the AnyTLS protocol, a proxy protocol designed to mitigate TLS-in-TLS nested handshake fing… | 78 | 1475 | active |
| jvoisin/php-malware-finder PHP Malware Finder is a command-line tool that scans filesystems for potentially malicious PHP files using YARA rules. It detects obfuscate… | 10 | 1475 | active |
| ioi/isolate Isolate is a Linux sandbox for securely executing untrusted programs, originally built for programming contest judges. It uses kernel featu… | 77 | 1473 | stable |
| lengjibo/RedTeamTools A collection of red team tools written and modified by the author, primarily in C++ and Python. It includes utilities for AV bypass, privil… | 53 | 1472 | active |
| shuanx/BurpAPIFinder BurpAPIFinder is a Burp Suite extension written in Java that passively analyzes HTTP traffic (HTML and JS files) to discover hidden API end… | 15 | 1472 | active |
| JJTech0130/TrollRestore TrollRestore is a Python-based installer that installs TrollStore on iOS/iPadOS 15.2 through 16.7 RC and 17.0 by exploiting CVE-2024-44252 … | 13 | 1472 | active |
| digitalbazaar/forge Forge is a pure-JavaScript implementation of the TLS protocol plus a broad set of cryptographic utilities including AES, RSA, X.509 certifi… | 66 | 5330 | maintenance |
| hectorm/otpauth A JavaScript One-Time Password library implementing HOTP (RFC 4226) and TOTP (RFC 6238) for generating and validating 2FA tokens. It runs i… | 86 | 1471 | stable |
| Greenwolf/ntlm_theft ntlm_theft is a Python3 CLI tool that generates 21 different types of NTLMv2 hash theft files (e.g., .url, .scf, .docx, .pdf, .jnlp) that t… | 52 | 1470 | active |
| rooootdev/lara LARA is an iOS customization toolbox application that leverages the DarkSword kernel exploit to modify system behavior on supported devices… | 73 | 1467 | active |
| MonwF/customiuizer Pengeek (CustoMIUIzer fork) is an LSPosed/Xposed module that deeply customizes Xiaomi HyperOS and MIUI system behavior. It offers tweaks fo… | 66 | 1467 | active |
| infrahq/infra Infra is an open-source authentication and access management service for servers, Kubernetes clusters, and databases. It provides identity-… | 66 | 1467 | active |
| t3l3machus/psudohash psudohash is a Python CLI tool that generates millions of keyword-based password mutations for brute-force attacks and hash cracking. It mi… | 34 | 1467 | active |
| DualCoder/vgpu_unlock A Linux tool that patches the NVIDIA GRID vGPU driver to unlock vGPU functionality on consumer-grade GeForce and Quadro GPUs. It works by h… | 32 | 5300 | maintenance |
| Sorcery/sorcery Sorcery is a stripped-down authentication library for Ruby on Rails supporting ActiveRecord, Mongoid, and other ORMs. It provides core auth… | 71 | 1464 | active |
| ssh-mitm/ssh-mitm SSH-MITM is an open-source man-in-the-middle SSH server for authorized security audits and malware analysis. It proxies SSH client-server c… | 66 | 1464 | active |
| iliyami/MacSai Mac Sai is a free, open-source macOS application that cleans junk files, scans for malware, uninstalls apps completely, and visualizes disk… | 79 | 1463 | active |
| c0ny1/passive-scan-client A Burp Suite extension written in Java that forwards passive scanning traffic to external passive vulnerability scanners (like xray, w13sca… | 23 | 1462 | stable |
| epsylon/xsser XSSer is an automatic penetration testing framework for detecting, exploiting, and reporting cross-site scripting (XSS) vulnerabilities in … | 82 | 1461 | active |
| terraform-compliance/cli terraform-compliance is a lightweight, security-focused BDD test framework for Terraform that enables negative testing of infrastructure-as… | 81 | 1461 | active |
| fkie-cad/FACT_core FACT (Firmware Analysis and Comparison Tool) is a self-hosted Python application that automates firmware security analysis for devices like… | 92 | 1460 | active |
| PortSwigger/param-miner Param Miner is a Burp Suite extension that identifies hidden, unlinked HTTP parameters, headers, and cookies using diffing logic and binary… | 78 | 1460 | active |
| batfish/batfish Batfish is an open-source network configuration analysis tool that builds complete models of network behavior from device configurations to… | 67 | 1460 | active |
| coder/wush wush is a command-line tool for transferring files and opening remote shells between computers over peer-to-peer WireGuard connections. It … | 41 | 1460 | active |
| openclarity/openclarity OpenClarity is an open-source platform for agentless detection and management of Virtual Machine SBOMs and security threats such as vulnera… | 10 | 1460 | active |
| OWASP/wrongsecrets OWASP WrongSecrets is a deliberately vulnerable Java application containing 50+ challenges that demonstrate how secrets are commonly miscon… | 94 | 1459 | active |
| Stebalien/tempfile A secure, cross-platform Rust library for creating and managing temporary files and directories. It supports anonymous temporary files, nam… | 76 | 1459 | stable |
| momosecurity/FindSomething FindSomething is a passive browser extension for Chrome and Firefox that extracts potentially sensitive information (like emails, API keys,… | 32 | 1458 | active |
| urbanadventurer/username-anarchy Username Anarchy is a Ruby command-line tool that generates lists of likely usernames from people's first and last names for use in penetra… | 23 | 1458 | stable |
| AhMyth/AhMyth-Android-RAT AhMyth is an open-source Android Remote Administration Tool (RAT) consisting of an Electron-based desktop control panel and an Android back… | 10 | 5273 | maintenance |
| OWASP/SecurityShepherd OWASP Security Shepherd is a self-hosted web and mobile application security training platform built in Java. It presents lessons and chall… | 66 | 1456 | active |
| qpoint-io/qtap Qtap is an eBPF agent that hooks TLS/SSL functions in the Linux kernel to capture network traffic before and after encryption, with full pr… | 64 | 1456 | active |
| small (OpenWrt proxy plugin feed) A collection of commonly used OpenWrt package feeds (luci apps, themes, and proxy/DNS plugins) maintained for easy inclusion when compiling… | 96 | 1455 | active |
| NullArray/AutoSploit AutoSploit is a Python CLI tool that automates mass exploitation of remote hosts by combining target discovery from Shodan, Censys, and Zoo… | 23 | 5253 | maintenance |
| NHAS/reverse_ssh A Go-based SSH server and client that enables SSH-based reverse shells, letting operators manage and connect to remote targets with native … | 98 | 1453 | active |
| strongbox-password-safe/Strongbox Strongbox is a native password manager client for iOS and macOS that opens KeePass (KDB/KDBX) and Password Safe (v3) vault files. It encryp… | 74 | 1453 | active |
| ossf/criticality_score A Go CLI tool from the OpenSSF that computes a criticality score (0 to 1) for open source projects based on parameters like contributor cou… | 67 | 1452 | active |
| tillson/git-hound GitHound is a Go-based CLI tool that hunts for exposed API keys, secrets, and credentials across all of GitHub using GitHub dorks, pattern … | 70 | 1451 | active |
| ViRb3/magisk-frida A Magisk/KernelSU/APatch module that automatically installs and runs frida-server on boot on rooted Android devices. It stays up to date by… | 93 | 1450 | active |
| ergrelet/unlicense A Python 3 command-line tool that dynamically unpacks executables protected with Themida/WinLicense 2.x and 3.x. It automatically recovers … | 23 | 1450 | active |
| intel/confidential-computing.sgx Intel Software Guard Extensions (SGX) software stack for Linux, comprising the SGX driver, SDK, and Platform Software (PSW). It enables dev… | 93 | 1449 | active |
| GhostPack/SharpDPAPI SharpDPAPI is a C# port of Mimikatz's Windows DPAPI functionality, allowing triage of DPAPI masterkeys, credentials, vaults, certificates, … | 32 | 1449 | active |
| passwordless-lib/fido2-net-lib A battle-tested .NET library implementing a FIDO2 server / WebAuthn relying party for passkey registration (attestation) and authentication… | 71 | 1448 | active |
| SeeFlowerX/stackplz stackplz is an eBPF-based stack tracing tool for Android (arm64). It supports syscall tracing, uprobe hooking of 64-bit userspace libraries… | 64 | 1447 | active |
| polhenarejos/pico-fido Open-source firmware that turns a Raspberry Pi Pico (RP2040/RP2350) or ESP32-S3 microcontroller into a FIDO2 passkey authenticator, support… | 95 | 1446 | active |
| wiresock/proxifyre ProxiFyre is a Windows SOCKS5 proxifier that transparently routes TCP and UDP traffic of selected applications through SOCKS5 proxies using… | 94 | 1445 | active |