function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Safe3/openresty-manager OpenResty Manager is a modern, web-based server control panel for managing OpenResty/Nginx reverse proxies, free SSL certificates, security… | 85 | 1444 | active |
| ossf/allstar Allstar is a GitHub App from OpenSSF that continuously monitors GitHub organizations and repositories for adherence to security best practi… | 74 | 1444 | active |
| One-Fox-Security-Team/One-Fox-T00ls One-Fox-T00ls is a curated collection of penetration testing and security toolboxes from the One-Fox security team, covering information ga… | 56 | 1443 | active |
| denandz/sourcemapper Sourcemapper is a Go CLI tool that parses JavaScript sourcemap (.map) files, whether from URLs or local directories, and reconstructs the o… | 75 | 1442 | stable |
| EgeBalci/amber Amber is a reflective PE packer that converts Windows PE files (EXE, DLL, SYS) into position-independent shellcode payloads for in-memory e… | 23 | 1442 | active |
| secretlint/secretlint Secretlint is a pluggable linting tool that scans projects for committed credentials and secrets, reporting matches with explanations. It r… | 99 | 1441 | active |
| tuneinsight/lattigo Lattigo is a pure Go library implementing lattice-based (RLWE) homomorphic encryption schemes such as BFV/BGV and CKKS, along with their mu… | 72 | 1440 | active |
| t3l3machus/toxssin toxssin is an open-source penetration testing CLI tool that automates exploitation of Cross-Site Scripting (XSS) vulnerabilities. It pairs … | 33 | 1440 | active |
| asz798838958/aBaiFreeGPT A self-hosted account registration and lifecycle management platform that automates bulk account signup, email verification, TOTP 2FA bindi… | 58 | 1438 | active |
| tclahr/uac UAC (Unix-like Artifacts Collector) is a portable, dependency-free shell-based incident response tool that automates forensic artifact coll… | 84 | 1437 | active |
| tahoe-lafs/tahoe-lafs Tahoe-LAFS is a free and open-source decentralized storage system that distributes encrypted, erasure-coded file shares across multiple unt… | 62 | 1435 | active |
| nowsecure/r2frida r2frida is a radare2 plugin that integrates the Frida dynamic instrumentation toolkit, letting users inspect and manipulate local or remote… | 94 | 1434 | active |
| crazy-max/WindowsSpyBlocker WindowsSpyBlocker is a Go application delivered as a single Windows executable that blocks spying and tracking on Windows systems. It captu… | 67 | 5168 | maintenance |
| bacher09/pwgen-for-bios A collection of master password generators for various BIOS/UEFI firmware from vendors like Dell, HP, Asus, Samsung, and Sony. It powers th… | 62 | 1433 | active |
| jawj/IKEv2-setup A Bash script that configures a fresh Ubuntu Server LTS install as an IKEv2 VPN server using strongSwan, with Let's Encrypt certificates an… | 57 | 1433 | active |
| eljojo/rememory ReMemory is a tool that encrypts your files with age and splits the key using Shamir's Secret Sharing among trusted people, who each receiv… | 74 | 1432 | active |
| sw33tLie/bbscope bbscope is a Go CLI tool that fetches, stores, and manages bug bounty program scopes from HackerOne, Bugcrowd, Intigriti, YesWeHack, and Im… | 73 | 1432 | active |
| redacted/XKCD-password-generator xkcdpass is a Python CLI tool and library that generates secure multi-word passphrases inspired by XKCD 936. It supports customizable wordl… | 61 | 1432 | stable |
| GoogleCloudPlatform/cloud-sql-proxy The Cloud SQL Auth Proxy is a Go utility that provides secure, IAM-authorized, TLS 1.3-encrypted connections to Google Cloud SQL instances … | 98 | 1431 | active |
| xtclovver/RKNHardering An Android application that detects VPN and proxy configurations on a device, implementing the methodology used by Roskomnadzor (RKN) to id… | 78 | 1431 | active |
| cyberark/KubiScan KubiScan is a Python CLI tool that scans Kubernetes clusters for risky permissions in the RBAC authorization model. It identifies risky rol… | 33 | 1431 | active |
| boku7/BokuLoader BokuLoader is a proof-of-concept User-Defined Reflective Loader (UDRL) for Cobalt Strike written in C and assembly. It recreates, integrate… | 32 | 1431 | active |
| dockovpn/dockovpn DockOvpn is a stateless, out-of-the-box OpenVPN server packaged as a Docker image that starts in under two seconds and requires no persiste… | 23 | 1428 | active |
| six2dez/burp-ai-agent Custom AI Agent (formerly Burp AI Agent) is a Burp Suite extension written in Kotlin that integrates LLMs into web security workflows via l… | 82 | 1427 | stable |
| cinit/TMoe TMoe is an open-source Xposed module that hooks into Telegram Android clients to add extra features and tweaks. It works with official and … | 74 | 1427 | active |
| sleep3r/mtproto.zig A tiny, dependency-free MTProto proxy written in Zig that disguises Telegram traffic as standard TLS 1.3 HTTPS traffic. It is designed for … | 77 | 1426 | active |
| ultravnc/UltraVNC UltraVNC is a free, open-source VNC (Virtual Network Computing) suite for Windows comprising a VNC Server, Viewer, Repeater proxy, and Sing… | 77 | 1426 | active |
| creazyboyone/FastGithub FastGithub is a local proxy tool that accelerates access to GitHub by resolving clean IPs, speed-testing them, and proxying HTTPS traffic t… | 32 | 1426 | active |
| enarx/enarx Enarx is an open-source command-line tool and runtime for running applications inside hardware Trusted Execution Environments (TEEs) such a… | 52 | 1425 | active |
| dirkjanm/ldapdomaindump A Python CLI tool that dumps Active Directory information (users, groups, computers, policies, trusts) via LDAP and renders it as human-rea… | 30 | 1425 | stable |
| f0ng/autoDecoder A Burp Suite extension (written in Java) that lets users plug in custom encryption/decryption logic so intercepted HTTP traffic can be view… | 78 | 1424 | active |
| BiZken/PhishMailer A Python CLI tool that generates professional-looking phishing email templates for popular services like Instagram, PayPal, and Discord, ou… | 41 | 1424 | active |
| rebrowser/rebrowser-patches A collection of source-code patches for Puppeteer and Playwright that fix automation leaks and help avoid bot detection systems like Cloudf… | 34 | 1424 | active |
| antonioCoco/RunasCs RunasCs is an open-source C# utility for running processes with explicit credentials on Windows, serving as an improved alternative to the … | 23 | 1424 | stable |
| Isaacdelly/Plutus Plutus is a Python CLI tool that brute-forces Bitcoin private keys by generating sequential keys via elliptic curve point addition and chec… | 59 | 1423 | active |
| SamuelTulach/VirusTotalUploader An open-source C# WinForms desktop application for uploading files to VirusTotal for malware scanning. It serves as a maintained replacemen… | 23 | 1422 | active |
| mbi/django-simple-captcha A Django application that adds customizable captcha image challenges to any Django form. It supports custom challenge generators, image sty… | 85 | 1421 | stable |
| netsniff-ng/netsniff-ng netsniff-ng is a free, high-performance Linux networking toolkit written in C, often described as a Swiss army knife for network packets. I… | 34 | 1421 | stable |
| openwpm/OpenWPM OpenWPM is a web privacy measurement framework built on Firefox with Selenium automation, designed to collect data from thousands to millio… | 95 | 1417 | active |
| login-securite/DonPAPI DonPAPI is a Python CLI tool that remotely dumps DPAPI-protected secrets (browser credentials, certificates, WiFi passwords, and more) from… | 29 | 1417 | active |
| akemin-dayo/AppSync AppSync Unified is a jailbreak tweak (dynamic library) for iOS 5 through 18 that lets users install ad-hoc signed, fakesigned, unsigned, or… | 24 | 1417 | active |
| ahmedkhlief/APT-Hunter APT-Hunter is a Python-based threat hunting tool that analyzes Windows event logs (EVTX) to detect APT activity using predefined detection … | 23 | 1417 | active |
| jesseduffield/horcrux A Go CLI tool that splits a file into encrypted fragments using Shamir's Secret Sharing, requiring only a threshold of fragments to reconst… | 23 | 5097 | maintenance |
| danny0838/content-farm-terminator Content Farm Terminator is a cross-platform browser extension that identifies content farms by marking hyperlinks pointing to them and bloc… | 77 | 1416 | active |
| Metarget/metarget Metarget is a Python-based framework that automatically builds vulnerable cloud-native infrastructures, installing vulnerable versions of D… | 65 | 1415 | active |
| wetox-team/flipperzero-goodies A collection of useful data and scripts for the Flipper Zero multi-tool device, including intercom keys and Python scripts. It is maintaine… | 44 | 1415 | active |
| outflanknl/C2-Tool-Collection A collection of C-based offensive security tools that integrate with Cobalt Strike and other C2 frameworks via Beacon Object Files (BOF) an… | 32 | 1415 | active |
| RythmStick/AMSITrigger AMSITrigger is a C# command-line tool that identifies the specific strings in PowerShell scripts that trigger Microsoft's Antimalware Scan … | 32 | 1415 | active |
| ReSo7200/InstaEclipse InstaEclipse is an LSPosed/Xposed module for Instagram that adds features like Ghost Mode, ad-free browsing, developer options, and distrac… | 83 | 1414 | active |
| anonvector/SlipNet SlipNet is an open-source anti-censorship VPN client for Android (Kotlin/Jetpack Compose) with a cross-platform Go CLI companion, supportin… | 77 | 1414 | active |
| cr-marcstevens/sha1collisiondetection A C library and command-line tool that computes SHA-1 hashes while detecting known cryptanalytic collision attacks against SHA-1 with proba… | 45 | 1414 | stable |
| omegaee/my-fingerprint A lightweight browser extension built on Manifest V3 that protects against browser fingerprinting across Chrome, Edge, and Firefox. It spoo… | 94 | 1413 | active |
| BlendLog/MinerSearch A free Windows utility that scans for and removes hidden cryptocurrency miners by checking processes, files, registry, WMI, services, and s… | 91 | 1413 | active |
| Jayy001/Search-That-Hash Search-That-Hash is a Python CLI tool that automatically submits hashes to popular online hash-cracking APIs to crack them in seconds. If n… | 27 | 1413 | active |
| Bitwise-01/Instagram- A Python CLI tool that performs brute-force password attacks against Instagram accounts using a supplied password list and rotating proxies… | 32 | 5081 | maintenance |
| Gezine/Y2JB Y2JB is a PS5 exploit that achieves userland code execution through the console's YouTube app. It supports firmware 4.03+ via a payload del… | 78 | 1412 | active |
| ct-Open-Source/tuya-convert A collection of Python scripts that flash Tuya-based smart home IoT devices (mostly ESP8266-based) with alternative open-source firmware ov… | 23 | 5073 | maintenance |
| nuvious/pam-duress A Linux Pluggable Authentication Module (PAM) that lets users configure alternate 'duress' passwords which, when used under coercion, authe… | 74 | 1410 | active |
| primihub/primihub PrimiHub is an open-source privacy-preserving computing platform built by a team of cryptography experts, supporting secure multi-party com… | 44 | 1408 | active |
| mufeedvh/pdfrip pdfrip is a multithreaded PDF password cracking utility written in Rust. It supports dictionary attacks, mask and pattern-based brute force… | 68 | 1406 | active |
| tihanyin/PSSW100AVB A curated collection of PowerShell scripts demonstrating antivirus evasion techniques, most notably reverse shells that go undetected by AV… | 70 | 1405 | active |
| superhedgy/AttackSurfaceMapper AttackSurfaceMapper is a Python CLI reconnaissance tool that expands a target's attack surface using OSINT and active techniques like subdo… | 32 | 1405 | active |
| MiForge/MiUnlockTool A cross-platform Python CLI tool that retrieves the encryptData(token) needed to unlock the bootloader on Xiaomi, Redmi, and Poco devices. … | 87 | 1404 | active |
| fabriziosalmi/certmate CertMate is a self-hosted certificate lifecycle management platform that issues and renews TLS certificates via ACME/Let's Encrypt across 2… | 81 | 1404 | active |
| karma9874/AndroRAT AndroRAT is an Android remote administration tool (RAT) with a Java-based Android client APK and a Python server, communicating over socket… | 32 | 5037 | maintenance |
| rosenpass/rosenpass Rosenpass is a post-quantum-secure key exchange tool written in Rust that establishes symmetric keys and feeds them to WireGuard via its pr… | 85 | 1401 | active |
| corna/me_cleaner A Python script that modifies Intel ME/TXE firmware images to reduce the co-processor's ability to interact with the system, disabling it d… | 23 | 5030 | maintenance |
| Flangvik/TeamFiltration TeamFiltration is a cross-platform penetration testing framework for enumerating, password spraying, exfiltrating data from, and backdoorin… | 55 | 1399 | active |
| cisco/libsrtp libSRTP is Cisco's open-source C library implementing the Secure Real-time Transport Protocol (SRTP, RFC 3711) along with a supporting cryp… | 78 | 1397 | stable |
| PeculiarVentures/PKI.js PKI.js is a pure TypeScript library implementing the common formats and protocols used in PKI applications, including X.509 certificates, P… | 90 | 1396 | stable |
| X1a0He/X1a0HeWeChatPlugin A macOS WeChat client plugin providing features like message anti-revoke, multiple app instances, update disabling, and log reporting. It i… | 87 | 1396 | active |
| bindhosts/bindhosts A systemless hosts manager for rooted Android devices that works with APatch, KernelSU, and Magisk. It provides ad-blocking and hostname re… | 93 | 1391 | active |
| INotGreen/XiebroC2 XiebroC2 is an open-source command-and-control (C2) framework for penetration testing, written in Go with a .NET teamserver. It supports Lu… | 27 | 1391 | active |
| WireGuard/wireguard-apple The official WireGuard VPN client application for iOS and macOS, written in Swift, including the WireGuardKit Swift package for integrating… | 32 | 1390 | active |
| simeononsecurity/Windows-Optimize-Harden-Debloat A PowerShell script that automates optimization, hardening, and debloating of Windows 10 and Windows 11 systems. It applies security and pr… | 31 | 1387 | active |
| solosky/pixl.js Pixl.js is an open-source hardware emulator for Nintendo Amiibo figures, based on a replica of the Espruino Pixl.js board. It emulates NTAG… | 83 | 1386 | active |
| RedByte1337/GraphSpy GraphSpy is an initial access and post-exploitation tool for Microsoft Entra ID (Azure AD) and Microsoft 365, offering a browser-based GUI … | 70 | 1386 | active |
| aws-cloudformation/cloudformation-guard AWS CloudFormation Guard (cfn-guard) is a general-purpose policy-as-code evaluation tool with an expressive DSL for defining rules. It vali… | 88 | 1385 | active |
| hasherezade/libpeconv libPeConv is a C++ library for loading, manipulating, and dumping Windows PE (Portable Executable) files. It provides a 'swiss army knife' … | 67 | 1385 | active |
| owasp-noir/noir OWASP Noir is a static analysis (SAST) CLI tool that scans source code to extract every endpoint an application exposes, including shadow A… | 99 | 1383 | active |
| rzcoder/node-rsa A pure TypeScript RSA cryptography library for Node.js and browsers supporting key generation, encryption/decryption, and signing/verificat… | 81 | 1381 | active |
| Jackalope Jackalope is a customizable, coverage-guided fuzzer for black-box binaries built on the TinyInst instrumentation library by Google Project … | 77 | 1380 | active |
| ChiChou/grapefruit Grapefruit is an open-source mobile security testing suite for iOS and Android that provides a browser-based GUI over Frida for runtime ins… | 91 | 1379 | active |
| Brandon7CC/mac-monitor Mac Monitor is a stand-alone macOS application that uses Apple's Endpoint Security and System Extension APIs to collect and enrich system e… | 80 | 1379 | active |
| xaitax/SploitScan SploitScan is a Python CLI cybersecurity utility that aggregates detailed vulnerability information for CVEs from sources like EPSS, CISA K… | 77 | 1379 | active |
| blacklanternsecurity/TREVORspray TREVORspray is a modular password spraying tool with threading, SSH/subnet proxy rotation, and loot modules targeting identity providers li… | 70 | 1379 | active |
| WindRunnerMax/TKScript A collection of GreaseMonkey/TamperMonkey userscripts and browser extensions written in TypeScript, including tools like Force Copy, link r… | 63 | 1379 | active |
| reveny/Android-Native-Root-Detector An Android application that detects whether a device is rooted, using native code checks. It is written in Kotlin and distributed as a down… | 71 | 1378 | active |
| haveno-dex/haveno Haveno is an open-source, non-custodial, peer-to-peer exchange platform for trading Monero against fiat currencies and other cryptocurrenci… | 96 | 1377 | active |
| microsoft/fhir-server FHIR Server for Azure is an open-source .NET Core implementation of the HL7 Fast Healthcare Interoperability Resources (FHIR) specification… | 95 | 1377 | active |
| guidedhacking/GuidedHacking-Injector A C++ DLL injection library supporting x86, WOW64, and x64 injection with five injection methods and six shellcode execution techniques. It… | 32 | 1377 | active |
| unjs/destr destr is a TypeScript library providing a faster, safer alternative to JSON.parse for arbitrary inputs. It gracefully falls back to the ori… | 79 | 1376 | stable |
| jonluca/anubis Anubis is a Python CLI tool for subdomain enumeration and information gathering that aggregates results from sources like HackerTarget, Vir… | 66 | 1375 | active |
| ClownQq/YDArk YDArk is a free x64 Windows kernel inspection tool similar to PCHunter, providing GUI views of processes, threads, handles, drivers, kernel… | 32 | 1375 | active |
| zfl9/chinadns-ng ChinaDNS-NG is a rewritten and enhanced version of ChinaDNS that splits DNS queries between domestic (China) and trusted upstream DNS serve… | 47 | 1374 | active |
| facebook/ThreatExchange A collection of Trust & Safety tools from Meta for fighting digital harms, including perceptual hashing algorithms (PDQ for images, TMK and… | 95 | 1373 | active |
| USBGuard/usbguard USBGuard is a C++ software framework for implementing USB device authorization policies on Linux, protecting against rogue USB devices (Bad… | 52 | 1373 | active |
| twoone-3/AdGuardHomeForRoot A Magisk/KernelSU/APatch module that runs AdGuardHome on rooted Android devices, providing a local DNS server that blocks ads, malware, and… | 94 | 1371 | active |
| google-github-actions/auth A GitHub Action that authenticates GitHub Actions workflows to Google Cloud, supporting Workload Identity Federation and Service Account Ke… | 78 | 1371 | active |
| glitchedgitz/cook COOK is a Go-based wordlist framework that generates, splits, merges, and finds wordlists, with support for permutations, combinations, and… | 66 | 1371 | active |