function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| 0xacb/recollapse REcollapse is a Python CLI helper tool that generates fuzzing payloads for black-box regex fuzzing against web applications. It helps bypas… | 46 | 1371 | active |
| simondankelmann/Bluetooth-LE-Spam An Android app that uses built-in Bluetooth Low Energy to send phantom device advertisements mimicking services like Apple popups, Microsof… | 61 | 4903 | maintenance |
| andresriancho/w3af w3af is an open source web application attack and audit framework that scans web applications for over 200 vulnerability types, including X… | 23 | 4900 | maintenance |
| emalderson/ThePhish ThePhish is an automated phishing email analysis web application built on TheHive, Cortex, and MISP. It extracts observables from email hea… | 32 | 1368 | stable |
| SpiderLabs/Responder Responder is a Python-based LLMNR, NBT-NS, and mDNS poisoner with built-in rogue authentication servers (SMB, HTTP/S, MSSQL, FTP, LDAP, POP… | 10 | 4890 | maintenance |
| aws/s2n-quic s2n-quic is a Rust implementation of the IETF QUIC transport protocol, offering a simple API with configurable providers for TLS (s2n-tls o… | 99 | 1366 | active |
| Yubico/yubioath-flutter Yubico Authenticator is a companion desktop and Android app for managing YubiKey hardware security keys and accessing OATH one-time passwor… | 93 | 1366 | stable |
| NotRequiem/VMAware VMAware is a cross-platform, header-only C++ library for detecting virtual machines, hypervisors, emulators, containers, and sandboxes usin… | 90 | 1364 | active |
| Cracked5pider/Stardust Stardust is a modern 32/64-bit position independent shellcode (implant) template written in C++20. It provides compile-time FNV-1a hashing … | 70 | 1364 | active |
| Morsmalleo/AhMyth AhMyth is a cross-platform Android Remote Administration Tool (RAT) used to build APK payloads and remotely control Android devices through… | 66 | 1364 | active |
| alphasoc/flightsim flightsim is a lightweight Go CLI utility that safely generates malicious network traffic patterns such as DNS tunneling, DGA domains, C2 c… | 23 | 1363 | active |
| 61106960/adPEAS adPEAS is a single-file PowerShell tool that automates Active Directory security assessment, enumerating misconfigurations, vulnerabilities… | 99 | 1361 | active |
| cmontage/mas-cn A Chinese-localized fork of Microsoft Activation Scripts (MAS), an open-source tool for activating Windows and Office via methods like HWID… | 80 | 1361 | active |
| LibVNC/libvncserver LibVNCServer/LibVNCClient are cross-platform C libraries for implementing VNC server and client functionality using the RFB protocol. LibVN… | 64 | 1361 | stable |
| boku7/Loki Loki is a stage-1 command and control (C2) framework written in Node.js that exploits script-jacking vulnerabilities in Electron applicatio… | 50 | 1360 | active |
| zalexdev/strykerapp StrykerOSS is a free, open-source mobile penetration testing suite for rooted Android devices that bundles network, wireless, and web secur… | 98 | 1359 | active |
| GrapheneOS/Camera GrapheneOS Camera is a modern Android camera app built on CameraX, focused on privacy and security. It includes QR and barcode scanning and… | 98 | 1359 | active |
| LSPosed/LSPlant LSPlant is a C++ library for hooking Java methods in the Android Runtime (ART), supporting hook/unhook and inline deoptimization. It is par… | 77 | 1359 | active |
| AEPKILL/devtools-detector A TypeScript browser library that detects whether browser DevTools is open. It lets developers trigger actions like crashing the page or lo… | 40 | 1358 | active |
| ossf/best-practices-badge The OpenSSF Best Practices Badge is a web application (BadgeApp) that lets Free/Libre and Open Source Software projects self-certify that t… | 95 | 1357 | active |
| remittor/zapret-openwrt OpenWrt packages (ipk/apk) of Zapret, an anti-DPI utility that bypasses deep packet inspection on routers, with a LuCI web interface. It is… | 79 | 1357 | active |
| mysensors/MySensors MySensors is an open-source C++ library and example collection for building DIY wireless sensor and actuator networks on Arduino, ESP8266/E… | 58 | 1356 | active |
| partout-io/passepartout Passepartout is an OpenVPN and WireGuard VPN client app for iPhone, iPad, Mac, and Apple TV, built on the Partout tunnel framework. It offe… | 95 | 1354 | active |
| xihan123/SignHook SignHook is an Xposed/LSPosed module for Android that spoofs app signature checks by returning a user-configured fake signature when a host… | 83 | 1354 | active |
| pypa/pip-audit pip-audit is a command-line tool that scans Python environments, requirements files, and dependency trees for packages with known security … | 83 | 1354 | active |
| google/nftables A pure Go library for programmatically interacting with Linux nftables, the iptables successor, without wrapping libnftnl. It provides data… | 73 | 1354 | active |
| openconnect/openconnect-gui A graphical VPN client built on the OpenConnect library, supporting Cisco AnyConnect-compatible VPNs. It is a Qt5-based desktop application… | 10 | 1354 | active |
| BullsEye0/shodan-eye Shodan Eye is a Python command-line tool that queries the Shodan search engine to collect information about all devices directly connected … | 75 | 1352 | active |
| voyagermesh/voyager Voyager is a secure L7 and L4 ingress controller for Kubernetes built on top of HAProxy, developed by AppsCode. It provides load balancing,… | 60 | 1351 | active |
| LegacyUpdate/LegacyUpdate Legacy Update is a Windows application and companion web service that restores Windows Update functionality, online activation, and Interne… | 86 | 1350 | active |
| MhmRdd/NoHello NoHello is a Zygisk module written in C++ that hides root and Zygisk from Android apps. It supports Magisk, KernelSU, KernelSU Next, and AP… | 33 | 1350 | active |
| roottusk/vapi vAPI is a self-hostable deliberately vulnerable API that mimics the OWASP API Security Top 10 scenarios through hands-on exercises. It ship… | 23 | 1349 | active |
| moyuwa/ApkCheckPack A Go-based CLI tool that detects APK hardening/packing features from 40+ vendors, plus third-party SDKs, anti-environment checks (ROOT, emu… | 82 | 1347 | active |
| yuanyuanxiang/SimpleRemoter SimpleRemoter (YAMA) is a C++ remote control suite derived from the Gh0st RAT codebase, providing remote desktop, file transfer, terminal, … | 60 | 1347 | active |
| webosbrew/webos-homebrew-channel An unofficial homebrew app store and root tooling for webOS TVs, providing package discovery, installation, and updates from independent re… | 74 | 1346 | active |
| yourduskquibbles/webannoyances Web Annoyances Ultralist is a filter list for uBlock Origin and AdGuard that removes annoying web elements like sticky headers, floating vi… | 32 | 1346 | active |
| cecio/USBvalve USBvalve is a firmware application for cheap RP2040-based hardware (Raspberry Pi Pico) that emulates a fake USB mass-storage filesystem and… | 93 | 1345 | active |
| fgkeepalive/AndroidKeepAlive An Android process keep-alive (daemon) library implemented with Linux-level techniques via C/JNI, claiming to keep apps alive even against … | 68 | 1345 | active |
| appneta/tcpreplay Tcpreplay is a suite of GPLv3 command-line utilities for editing and replaying captured network traffic (pcap files) back onto the network … | 98 | 1344 | active |
| BinTianqi/OwnDroid OwnDroid is an Android app that uses the DevicePolicyManager API with Device owner privileges to manage your own device. It provides system… | 89 | 1344 | active |
| JoySafety/JoySafety JoySafety is an open-source large language model safety framework from JD.com, written in Java, providing prompt injection detection, conte… | 47 | 1344 | active |
| projectdiscovery/nuclei-burp-plugin A Burp Suite plugin that helps generate Nuclei vulnerability scanner templates from HTTP requests and responses captured in Burp's Proxy, R… | 44 | 1344 | active |
| WKL-Sec/HiddenDesktop Hidden Desktop is a Cobalt Strike BOF implementation of HVNC (Hidden Virtual Network Computing), letting red team operators interact with a… | 20 | 1343 | active |
| zxcvos/Xray-script A pure Shell management script for installing and configuring Xray proxy servers with protocols like VLESS-Vision-REALITY, VLESS-XHTTP-REAL… | 63 | 1342 | active |
| urbanadventurer/Android-PIN-Bruteforce A shell script that turns a rooted Android device running Kali NetHunter into a USB HID keyboard that bruteforces the lockscreen PIN of a l… | 32 | 4782 | maintenance |
| wotschofsky/domain-digger Domain Digger is a web application for in-depth domain analysis, offering DNS lookups across global resolvers, WHOIS queries, IP geolocatio… | 75 | 1340 | active |
| fzlee/alipay An unofficial Python SDK for Alipay (支付宝) that supports SHA1 and SHA256 with RSA request signing and verification. It provides client and s… | 65 | 1339 | active |
| yeswehack/PwnFox PwnFox is a Firefox extension paired with a Burp Suite extension that provides tools for web security audits, such as one-click Burp proxy … | 23 | 1339 | active |
| llm-attacks/llm-attacks Official research code for 'Universal and Transferable Adversarial Attacks on Aligned Language Models', implementing the GCG algorithm for … | 28 | 4769 | maintenance |
| adamyaxley/Obfuscate A header-only C++14 library that obfuscates string literals at compile time using constexpr XOR encryption with a random 64-bit key, preven… | 63 | 1338 | stable |
| littleWhiteDuck/SimpleHook SimpleHook is an Xposed/LSPosed module for Android app debugging and research, offering configurable Java/Smali hooking of methods, fields,… | 93 | 1337 | active |
| truongduy2611/app-store-preflight-skills An AI agent skill that scans iOS/macOS Xcode projects, source code, and App Store metadata for patterns that commonly cause App Store rejec… | 52 | 1337 | active |
| x364e3ab6/DudeSuite DudeSuite is a lightweight, integrated web penetration testing toolkit distributed as a desktop application for Windows and macOS. It bundl… | 85 | 1336 | active |
| CERT-Polska/drakvuf-sandbox DRAKVUF Sandbox is an automated, agentless malware analysis system that runs suspicious files inside a hypervisor-level sandbox powered by … | 87 | 1334 | active |
| F6JO/RouteVulScan RouteVulScan is a Burp Suite extension written in Java that passively and recursively probes each path layer of web traffic for vulnerable … | 82 | 1334 | active |
| ION28/BLUESPAWN BLUESPAWN is an open-source active defense and endpoint detection and response (EDR) tool for Windows. It helps blue teams detect, identify… | 69 | 1334 | active |
| ZupIT/horusec Horusec is an open-source SAST (static application security testing) CLI that scans a project for vulnerabilities across many languages wit… | 67 | 1333 | active |
| dafthack/GraphRunner GraphRunner is a post-exploitation toolset for interacting with the Microsoft Graph API, written in PowerShell. It enables reconnaissance, … | 62 | 1333 | active |
| silverhack/monkey365 Monkey365 is an open-source PowerShell-based security assessment framework for Microsoft 365, Azure, and Microsoft Entra ID. It collects te… | 97 | 1332 | active |
| mpgirro/docker-pihole-unbound A Docker image that runs Pi-hole (network-wide ad blocker) with an integrated Unbound recursive DNS resolver in a single container. It is t… | 96 | 1332 | active |
| ucsd-progsys/liquidhaskell LiquidHaskell is a formal verification tool that brings refinement types to Haskell via a GHC plugin. It uses the Z3 SMT solver to statical… | 94 | 1332 | active |
| SAML-Toolkits/php-saml A PHP library that adds SAML 2.0 support to PHP applications, enabling them to act as a Service Provider for single sign-on with identity p… | 92 | 1331 | stable |
| stripe/smokescreen Smokescreen is an HTTP CONNECT egress proxy written in Go, developed by Stripe to proxy outbound traffic such as webhooks. It enforces host… | 77 | 1331 | active |
| neuvector/neuvector NeuVector is an open-source full lifecycle container security platform providing vulnerability management and automated runtime security wi… | 94 | 1330 | active |
| Shopify/remote-dom Remote DOM is a TypeScript library that synchronizes a tree of DOM elements created in a sandboxed JavaScript environment (like an iframe o… | 89 | 1330 | active |
| cobbr/Covenant Covenant is a collaborative .NET command and control (C2) framework for red teamers, built as an ASP.NET Core cross-platform application wi… | 32 | 4730 | maintenance |
| samyk/evercookie Evercookie is a JavaScript API that creates extremely persistent, respawning 'super' cookies by storing identifiers across a dozen-plus bro… | 39 | 4726 | maintenance |
| backslashxx/mountify Mountify is a shell-based module for rooted Android that mounts other root modules globally via OverlayFS instead of Magic Mount. It works … | 88 | 1328 | active |
| wafinfo/DecryptTools A comprehensive encryption/decryption tool for penetration testers, supporting 22+ decryption schemes for Chinese enterprise software (OA s… | 22 | 1327 | active |
| ly4k/PwnKit A self-contained exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec. It ships as a prebuilt … | 32 | 1326 | stable |
| beakthoven/TrickyStoreOSS A fully open-source Magisk module that spoofs Android hardware keystore attestation, serving as a FOSS rewrite of the proprietary TrickySto… | 85 | 1325 | active |
| cseroad/Webshell_Generate A JavaFX desktop tool that generates evasive (antivirus-bypassing) webshells in multiple languages, supporting cmd shells and clients like … | 59 | 1323 | active |
| cfig/Android_boot_image_editor A Gradle-based Java tool for unpacking, editing, and repacking Android boot images such as boot.img, vendor_boot.img, recovery.img, vbmeta.… | 66 | 1322 | active |
| zalando/go-keyring A cross-platform Go library for setting, getting, and deleting secrets in the operating system's native keyring (macOS Keychain, Windows Cr… | 78 | 1321 | active |
| DNSCrypt/encrypted-dns-server A high-performance Rust proxy that lets anyone run their own encrypted DNS server supporting DNSCrypt v2 (including post-quantum), Anonymiz… | 92 | 1320 | active |
| platomav/MEAnalyzer ME Analyzer is a Python command-line tool that parses and identifies Intel Engine (CSME, TXE, SPS, GSC) and Graphics firmware images, repor… | 79 | 1320 | active |
| maqp/tfc Tinfoil Chat (TFC) is a peer-to-peer, end-to-end encrypted messaging system built on Tor onion services and high-assurance hardware archite… | 74 | 1320 | active |
| MrTuxx/SocialPwned SocialPwned is a Python-based OSINT tool that harvests emails published on Instagram, LinkedIn, and Twitter to find credential leaks via Pw… | 10 | 1320 | active |
| msasanmh/DNSveil DNSveil is a Windows-only secure DNS client supporting DNSCrypt, Anonymized DNSCrypt, DoH, DoT, and plain DNS over UDP/TCP, with built-in D… | 60 | 1319 | active |
| gorhill/uMatrix uMatrix is a browser extension that lets users point-and-click filter network requests by source, destination, and type, acting as a firewa… | 10 | 4686 | maintenance |
| go-webauthn/webauthn A FIDO2-conformant WebAuthn and passkey backend library for Go applications. It implements the Web Authentication specification to enable m… | 94 | 1318 | active |
| test502git/awvs14-scan A Python batch-scanning script built on the Acunetix (AWVS) 14/15 API that automates bulk URL scanning with specialized templates for log4j… | 48 | 1318 | active |
| 0x727/BypassPro BypassPro is a Burp Suite extension written in Java that automates bypass attempts against authorization controls (401/403) and WAFs. It co… | 79 | 1317 | active |
| malaohu/MobaXterm-GenKey A small Python web application that generates license key files to activate MobaXterm, a commercial SSH/terminal client for Windows. It can… | 48 | 1317 | active |
| riverrun/comeonin Comeonin is a specification (behaviours) for password hashing libraries in Elixir, defining Comeonin and Comeonin.PasswordHash behaviours. … | 34 | 1317 | stable |
| iGio90/Dwarf Dwarf is a full-featured multi-architecture, multi-OS debugger built on PyQt5 and Frida, aimed at reverse engineers, security analysts, and… | 32 | 1317 | active |
| cseroad/Exp-Tools A Java-based integrated exploitation tool that bundles proof-of-concept exploits for high-risk vulnerabilities in Chinese enterprise softwa… | 21 | 1316 | active |
| getprobo/probo Probo is an open-source, self-hostable governance, risk, and compliance (GRC) platform for engineering and security teams, covering risk ma… | 84 | 1315 | active |
| nccgroup/singularity Singularity of Origin is a DNS rebinding attack framework that includes a DNS server, a web server, a management UI, and sample attack payl… | 74 | 1315 | active |
| microsoft/win32-app-isolation Microsoft's repository of tools and documentation for Win32 app isolation, a Windows security feature that contains damage from compromised… | 29 | 1315 | active |
| getdnsapi/stubby Stubby is a local DNS Privacy stub resolver daemon that encrypts DNS queries using DNS-over-TLS (RFC 7858), built on the getdns library. It… | 37 | 1314 | active |
| miscusi-peek/cheatengine-mcp-bridge A bridge that connects AI coding assistants (Claude, Cursor, Copilot) to Cheat Engine via the Model Context Protocol, letting agents read/w… | 60 | 1313 | active |
| apk-editor/APK-Explorer-Editor APK Explorer & Editor (AEE) is an open-source Android application for exploring the contents of installed APK files and APKs picked from st… | 85 | 1312 | active |
| colonelpanichacks/flock-you Flock-You is ESP32-S3 firmware that turns a Seeed XIAO ESP32-S3 into a passive 2.4 GHz promiscuous-mode WiFi sniffer for detecting Flock su… | 62 | 1312 | active |
| HXSecurity/DongTai DongTai IAST is an open-source Interactive Application Security Testing platform that detects vulnerabilities in Java (and some Python) app… | 33 | 1312 | active |
| CalebFenton/simplify Simplify is a generic Android deobfuscator that virtually executes Dalvik methods in a sandbox (smalivm) and applies optimizations like con… | 23 | 4657 | maintenance |
| erev0s/VAmPI VAmPI is a deliberately vulnerable REST API built with Flask that implements the OWASP Top 10 vulnerabilities for APIs. It is designed for … | 66 | 1311 | active |
| docker/docker-credential-helpers A suite of Go programs that store Docker login credentials in native platform keystores (e.g., macOS Keychain, Windows Credential Manager, … | 95 | 1310 | active |
| PlumHound/PlumHound PlumHound is a Python CLI reporting engine that wraps BloodHoundAD's Neo4j Cypher queries into consumable security reports for Blue and Pur… | 63 | 1310 | active |
| JailbrokenAI/wallbreaker Wallbreaker is a Claude-Code-style terminal harness for red-teaming LLMs, driving an autonomous agent loop that runs jailbreak attacks (PAI… | 57 | 1310 | active |