Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: security

4909 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
nefarius/HidHide
HidHide is a Windows kernel-mode filter driver that acts as an 'input device firewall', allowing users to block individual applications' ac…
641511active
firedancer-io/firedancer
Firedancer is Jump Crypto's from-scratch Solana validator client written in C, designed for extreme performance and security with a restric…
951510active
hybridgroup/go-haystack
A Go/TinyGo library and toolset for tracking personal Bluetooth devices through Apple's Find My network, using OpenHaystack and Macless-Hay…
371509active
pallets-eco/flask-wtf
Flask-WTF is a Python library that integrates WTForms with the Flask web framework, providing form rendering, validation, CSRF protection, …
801508stable
jaraco/keyring
A Python library providing a simple API to access the operating system's native keyring service for safe password storage and retrieval. It…
701508stable
0xsp-SRD/mortar
Mortar Loader is a red team evasion tool that encrypts PE binaries and shellcode and executes them in memory using various injection techni…
231508active
kenryu42/cc-safety-net
CC Safety Net is a pre-execution hook for AI coding agent CLIs (Claude Code, Codex, Cursor, Gemini CLI, and many others) that blocks destru…
831507active
Internet-Architecture-and-Security/PacketScope
PacketScope is an open-source, eBPF-based protocol stack analysis and debugging tool for server-side network observability and defense. It …
751507active
nikaiw/VMkatz
VMkatz is a Rust CLI tool that extracts Windows credentials (NTLM hashes, DPAPI keys, Kerberos tickets, LSA secrets, BitLocker keys) direct…
691507active
mike-engel/jwt-cli
jwt-cli is a fast command-line tool written in Rust for decoding and encoding JSON Web Tokens (JWTs). It supports custom headers, arbitrary…
671507active
DarthTon/Blackbone
Blackbone is a C++ library for Windows memory hacking, providing APIs for process memory manipulation, DLL injection, manual PE image mappi…
325479maintenance
nikitastupin/clairvoyance
Clairvoyance is a Python CLI tool that recovers a GraphQL API's schema even when introspection is disabled, by probing field and type names…
571506active
Gowtham-Darkseid/AutoPentestX
AutoPentestX is a Python-based automated penetration testing toolkit that scans targets for vulnerabilities and generates security reports.…
451504active
nohajc/anylinuxfs
A Rust CLI utility for macOS that mounts any Linux-supported filesystem (ext4, btrfs, xfs, ZFS, NTFS, exFAT, etc.) with full read-write acc…
851503active
tirrenotechnologies/tirreno
tirreno is an open-source, self-hosted security framework written in PHP/PostgreSQL that provides event tracking, threat detection, and ris…
831503active
ChendoChap/pOOBs4
A kernel exploit for PlayStation 4 firmware 9.00 that leverages a filesystem (exfat) bug triggered via a specially formatted USB drive, com…
321503stable
assetnote/nowafpls
nowafpls is a Jython-based Burp Suite plugin that bypasses web application firewalls (WAFs) by inserting junk data into HTTP request bodies…
381502active
uber/ADR
ADR (Agentic AI Detection and Response) is an open-source enterprise security framework for AI agents, providing endpoint discovery of AI t…
681501active
kkapsner/CanvasBlocker
A Firefox browser extension that protects users from browser fingerprinting by blocking or faking readouts of JavaScript APIs such as canva…
641501active
ZimengXiong/tinyTouch
tinyTouch is an open-source DIY hardware and software project that lets you authenticate, sudo, and log in to your computer with a fingerpr…
691500active
pyca/bcrypt
pyca/bcrypt is a Python library providing bcrypt password hashing and a bcrypt_pbkdf key derivation function. It offers salted hashing with…
771499active
skyjake/lagrange
Lagrange is a cross-platform desktop and mobile client for browsing Geminispace, written in C with SDL for graphics and OpenSSL for TLS. It…
991498active
twofas/2fas-android
The official open-source Android app for 2FAS, a two-factor authentication service that generates one-time passwords (TOTP and HOTP) for se…
861497active
ray-lothian/UserAgent-Switcher
A highly configurable browser extension that spoofs the User-Agent string across Chrome, Firefox, Edge, and Opera. It overrides HTTP reques…
771497active
T4y1oR/RingQ
RingQ is a post-exploitation antivirus evasion tool that obfuscates and loads arbitrary Windows executables or shellcode (e.g., Cobalt Stri…
271497active
project-oak/oak
Oak is a Rust-based platform for building distributed systems whose components can produce externally verifiable claims about their behavio…
771496active
salvogiangri/KnoxPatch
An LSPosed/Xposed module written in Kotlin that restores Samsung apps and features (Samsung Health, Samsung Cloud, Samsung Flow, etc.) on r…
871495active
Meckazin/ChromeKatz
ChromeKatz is a set of offensive security tools (CookieKatz, ElevationKatz) written in C that dump cookies and decryption keys directly fro…
721495active
usbarmory/usbarmory
USB armory is an open source hardware design for a compact secure computer built into a USB stick form factor, based on ARM SoCs. This repo…
661495active
vinkla/hashids
A small PHP library that generates YouTube-like short, URL-safe IDs from numbers, so numeric database IDs are not exposed to users. It supp…
575429maintenance
google/go-safeweb
go-safeweb is a collection of Go libraries for building secure-by-default HTTP servers. It applies security mechanisms like XSS and CSRF pr…
101494active
facebook/fishhook
fishhook is a small C library from Facebook that dynamically rebinds symbols in Mach-O binaries running on iOS, similar to DYLD_INTERPOSE o…
325425maintenance
dekuNukem/bob_cassette_rewinder
An open-source hardware/firmware project that defeats the DRM on Bob dishwasher detergent cassettes, allowing users to reset and refill the…
321493active
duckduckgo/duckduckgo-privacy-extension
DuckDuckGo Privacy Essentials is a browser extension for Firefox, Chrome, Edge, and Opera that blocks third-party trackers and ads, manages…
991492active
spyboy-productions/r4ven
R4ven is a security awareness and penetration testing tool that hosts a web page which, when a user grants browser permissions, captures GP…
601492active
cossacklabs/acra
Acra is a database security suite that provides field-level encryption, searchable encryption, tokenization, data masking, SQL firewalling,…
581491active
rfxn/linux-malware-detect
Linux Malware Detect (LMD) is a bash-based malware scanner for Linux servers featuring a multi-stage detection pipeline (MD5/SHA-256 hashin…
861490active
stealthcopter/AndroidNetworkTools
A Java library for Android providing handy networking utilities such as port scanning, subnet device discovery, ping, and Wake-on-LAN. It f…
231490active
libressl/portable
LibreSSL Portable is the portable build of LibreSSL, a TLS and cryptography stack forked from OpenSSL 1.0.1g by the OpenBSD project. It pro…
941489stable
Spomky-Labs/otphp
A PHP library for generating one-time passwords according to RFC 4226 (HOTP) and RFC 6238 (TOTP). It is compatible with Google Authenticato…
931488stable
hellman/xortool
xortool is a Python command-line tool for cryptanalysis of multi-byte XOR ciphers. It guesses the key length based on character frequency s…
421488active
TheresAFewConors/Sooty
Sooty is a Python CLI tool that automates routine tasks for SOC (Security Operations Center) analysts, such as URL sanitization, DNS and Wh…
321488active
halo/LinkLiar
LinkLiar is a free, open-source macOS status menu application written in Swift for spoofing the MAC addresses of Wi-Fi and Ethernet interfa…
391486active
liuzq2002/Adguard-Home-For-Magisk-Mod
A Magisk module that runs AdGuard Home on rooted Android devices to block ads by redirecting and filtering DNS requests. It ships with buil…
851485active
kalessil/phpinspectionsea
Php Inspections (EA Extended) is an open-source static code analysis tool distributed as a PhpStorm/IntelliJ IDEA plugin. It detects archit…
731485active
pass-extension/pass-otp
pass-otp is an extension for the pass password manager that stores and manages one-time-password (OTP) tokens as otpauth:// URIs. It genera…
391485active
Schira4396/VcenterKiller
A Go-based all-in-one exploitation and verification tool targeting VMware vCenter, covering major CVEs such as CVE-2021-21972, CVE-2021-219…
231485active
securitybunker/databunker
Databunker is a self-hosted, Go-based secure vault for tokenizing and storing personal records such as PII, PHI, KYC, and PCI data. It expo…
751482active
Shopify/ejson
EJSON is a Go CLI utility for managing encrypted secrets in JSON files using asymmetric elliptic-curve (NaCl Box) encryption. It lets teams…
861480stable
Fuzion24/JustTrustMe
An Xposed module for rooted Android devices that disables SSL certificate pinning in apps, enabling traffic interception during security au…
235361maintenance
inguardians/peirates
Peirates is a Go-based, interactive Kubernetes penetration testing tool that automates privilege escalation, lateral movement, and cluster …
901477active
controlplaneio/kubesec
Kubesec is a static analysis tool that performs security risk analysis on Kubernetes resource manifests, assigning a security score and det…
641477active
LionSec/katoolin
A Python CLI tool that lets users add or remove Kali Linux repositories on other Debian-based systems (like Ubuntu) and install Kali Linux …
325348maintenance
vslavik/winsparkle
WinSparkle is an app update framework for Windows desktop applications, inspired by Sparkle for macOS. It ships as a single dependency-free…
881475stable
anytls/anytls-go
anytls-go is the Go reference implementation of the AnyTLS protocol, a proxy protocol designed to mitigate TLS-in-TLS nested handshake fing…
781475active
jvoisin/php-malware-finder
PHP Malware Finder is a command-line tool that scans filesystems for potentially malicious PHP files using YARA rules. It detects obfuscate…
101475active
ioi/isolate
Isolate is a Linux sandbox for securely executing untrusted programs, originally built for programming contest judges. It uses kernel featu…
771473stable
lengjibo/RedTeamTools
A collection of red team tools written and modified by the author, primarily in C++ and Python. It includes utilities for AV bypass, privil…
531472active
shuanx/BurpAPIFinder
BurpAPIFinder is a Burp Suite extension written in Java that passively analyzes HTTP traffic (HTML and JS files) to discover hidden API end…
151472active
JJTech0130/TrollRestore
TrollRestore is a Python-based installer that installs TrollStore on iOS/iPadOS 15.2 through 16.7 RC and 17.0 by exploiting CVE-2024-44252 …
131472active
digitalbazaar/forge
Forge is a pure-JavaScript implementation of the TLS protocol plus a broad set of cryptographic utilities including AES, RSA, X.509 certifi…
665330maintenance
hectorm/otpauth
A JavaScript One-Time Password library implementing HOTP (RFC 4226) and TOTP (RFC 6238) for generating and validating 2FA tokens. It runs i…
861471stable
Greenwolf/ntlm_theft
ntlm_theft is a Python3 CLI tool that generates 21 different types of NTLMv2 hash theft files (e.g., .url, .scf, .docx, .pdf, .jnlp) that t…
521470active
rooootdev/lara
LARA is an iOS customization toolbox application that leverages the DarkSword kernel exploit to modify system behavior on supported devices…
731467active
MonwF/customiuizer
Pengeek (CustoMIUIzer fork) is an LSPosed/Xposed module that deeply customizes Xiaomi HyperOS and MIUI system behavior. It offers tweaks fo…
661467active
infrahq/infra
Infra is an open-source authentication and access management service for servers, Kubernetes clusters, and databases. It provides identity-…
661467active
t3l3machus/psudohash
psudohash is a Python CLI tool that generates millions of keyword-based password mutations for brute-force attacks and hash cracking. It mi…
341467active
DualCoder/vgpu_unlock
A Linux tool that patches the NVIDIA GRID vGPU driver to unlock vGPU functionality on consumer-grade GeForce and Quadro GPUs. It works by h…
325300maintenance
Sorcery/sorcery
Sorcery is a stripped-down authentication library for Ruby on Rails supporting ActiveRecord, Mongoid, and other ORMs. It provides core auth…
711464active
ssh-mitm/ssh-mitm
SSH-MITM is an open-source man-in-the-middle SSH server for authorized security audits and malware analysis. It proxies SSH client-server c…
661464active
iliyami/MacSai
Mac Sai is a free, open-source macOS application that cleans junk files, scans for malware, uninstalls apps completely, and visualizes disk…
791463active
c0ny1/passive-scan-client
A Burp Suite extension written in Java that forwards passive scanning traffic to external passive vulnerability scanners (like xray, w13sca…
231462stable
epsylon/xsser
XSSer is an automatic penetration testing framework for detecting, exploiting, and reporting cross-site scripting (XSS) vulnerabilities in …
821461active
terraform-compliance/cli
terraform-compliance is a lightweight, security-focused BDD test framework for Terraform that enables negative testing of infrastructure-as…
811461active
fkie-cad/FACT_core
FACT (Firmware Analysis and Comparison Tool) is a self-hosted Python application that automates firmware security analysis for devices like…
921460active
PortSwigger/param-miner
Param Miner is a Burp Suite extension that identifies hidden, unlinked HTTP parameters, headers, and cookies using diffing logic and binary…
781460active
batfish/batfish
Batfish is an open-source network configuration analysis tool that builds complete models of network behavior from device configurations to…
671460active
coder/wush
wush is a command-line tool for transferring files and opening remote shells between computers over peer-to-peer WireGuard connections. It …
411460active
openclarity/openclarity
OpenClarity is an open-source platform for agentless detection and management of Virtual Machine SBOMs and security threats such as vulnera…
101460active
OWASP/wrongsecrets
OWASP WrongSecrets is a deliberately vulnerable Java application containing 50+ challenges that demonstrate how secrets are commonly miscon…
941459active
Stebalien/tempfile
A secure, cross-platform Rust library for creating and managing temporary files and directories. It supports anonymous temporary files, nam…
761459stable
momosecurity/FindSomething
FindSomething is a passive browser extension for Chrome and Firefox that extracts potentially sensitive information (like emails, API keys,…
321458active
urbanadventurer/username-anarchy
Username Anarchy is a Ruby command-line tool that generates lists of likely usernames from people's first and last names for use in penetra…
231458stable
AhMyth/AhMyth-Android-RAT
AhMyth is an open-source Android Remote Administration Tool (RAT) consisting of an Electron-based desktop control panel and an Android back…
105273maintenance
OWASP/SecurityShepherd
OWASP Security Shepherd is a self-hosted web and mobile application security training platform built in Java. It presents lessons and chall…
661456active
qpoint-io/qtap
Qtap is an eBPF agent that hooks TLS/SSL functions in the Linux kernel to capture network traffic before and after encryption, with full pr…
641456active
small (OpenWrt proxy plugin feed)
A collection of commonly used OpenWrt package feeds (luci apps, themes, and proxy/DNS plugins) maintained for easy inclusion when compiling…
961455active
NullArray/AutoSploit
AutoSploit is a Python CLI tool that automates mass exploitation of remote hosts by combining target discovery from Shodan, Censys, and Zoo…
235253maintenance
NHAS/reverse_ssh
A Go-based SSH server and client that enables SSH-based reverse shells, letting operators manage and connect to remote targets with native …
981453active
strongbox-password-safe/Strongbox
Strongbox is a native password manager client for iOS and macOS that opens KeePass (KDB/KDBX) and Password Safe (v3) vault files. It encryp…
741453active
ossf/criticality_score
A Go CLI tool from the OpenSSF that computes a criticality score (0 to 1) for open source projects based on parameters like contributor cou…
671452active
tillson/git-hound
GitHound is a Go-based CLI tool that hunts for exposed API keys, secrets, and credentials across all of GitHub using GitHub dorks, pattern …
701451active
ViRb3/magisk-frida
A Magisk/KernelSU/APatch module that automatically installs and runs frida-server on boot on rooted Android devices. It stays up to date by…
931450active
ergrelet/unlicense
A Python 3 command-line tool that dynamically unpacks executables protected with Themida/WinLicense 2.x and 3.x. It automatically recovers …
231450active
intel/confidential-computing.sgx
Intel Software Guard Extensions (SGX) software stack for Linux, comprising the SGX driver, SDK, and Platform Software (PSW). It enables dev…
931449active
GhostPack/SharpDPAPI
SharpDPAPI is a C# port of Mimikatz's Windows DPAPI functionality, allowing triage of DPAPI masterkeys, credentials, vaults, certificates, …
321449active
passwordless-lib/fido2-net-lib
A battle-tested .NET library implementing a FIDO2 server / WebAuthn relying party for passkey registration (attestation) and authentication…
711448active
SeeFlowerX/stackplz
stackplz is an eBPF-based stack tracing tool for Android (arm64). It supports syscall tracing, uprobe hooking of 64-bit userspace libraries…
641447active
polhenarejos/pico-fido
Open-source firmware that turns a Raspberry Pi Pico (RP2040/RP2350) or ESP32-S3 microcontroller into a FIDO2 passkey authenticator, support…
951446active
wiresock/proxifyre
ProxiFyre is a Windows SOCKS5 proxifier that transparently routes TCP and UDP traffic of selected applications through SOCKS5 proxies using…
941445active

← prev page 20 / 50 next →