function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| pass-with-high-score/universal-installer Universal Installer is an open-source Android package manager app built with Kotlin and Jetpack Compose that installs APK, APKS, XAPK, and … | 84 | 1309 | active |
| codingo/VHostScan VHostScan is a Python-based virtual host scanner that discovers hidden vhosts on a web server using wordlists, reverse lookups, and catch-a… | 39 | 1309 | active |
| AliyunContainerService/pouch PouchContainer is an open-source, OCI-compliant enterprise-class container engine created by Alibaba Group. It packs, delivers, and runs ap… | 23 | 4644 | maintenance |
| sulab999/AppMessenger AppMessenger is a free cross-platform (Windows/Mac/Linux, Java-based) GUI tool for analyzing mobile application packages including APK (And… | 86 | 1308 | active |
| devise-two-factor/devise-two-factor A minimalist Ruby gem extending Devise with two-factor authentication via TOTP. It integrates with authenticator apps like Google Authentic… | 72 | 1308 | active |
| PentesterFlow/agent PentesterFlow is a terminal-based agentic AI CLI assistant for penetration testers and bug bounty hunters. It orchestrates LLM-driven recon… | 71 | 1308 | active |
| ReSukiSU/ReSukiSU ReSukiSU is a KernelSU-based root solution for Android, forked from SukiSU Ultra with a focus on enhanced stability. It provides kernel-lev… | 69 | 1308 | active |
| davewasmer/devcert A Node.js library that generates trusted SSL/TLS certificates for local HTTPS development. It creates a local certificate authority, regist… | 57 | 1308 | active |
| AdguardTeam/AdGuardExtra AdGuard Extra is a userscript and browser extension that combats ad-blocking circumvention on sites where regular filter rules fail. It wor… | 37 | 1308 | active |
| mozilla/policy-templates A collection of policy templates for centrally deploying and managing Firefox in enterprise environments such as businesses, schools, and p… | 98 | 1307 | active |
| stackrox/stackrox StackRox is a Kubernetes security platform that performs risk analysis of container environments, delivers visibility and runtime alerts, a… | 95 | 1306 | active |
| hephaest0s/usbkill usbkill is a Python-based anti-forensic kill-switch daemon that monitors USB ports and immediately shuts down the computer when any USB cha… | 32 | 4631 | maintenance |
| Albert-Weasker/niubi_guard An open-source defense system that protects GitHub repositories from spam, harassment, and coordinated abuse via configurable detection sig… | 65 | 1305 | active |
| shenruisi/Stay Stay is an open-source local userscript manager implemented as a Safari extension for iOS and iPadOS, compatible with Tampermonkey/Greasemo… | 23 | 1305 | active |
| tg123/sshpiper sshpiper is a reverse proxy for SSH that routes incoming SSH/SCP connections to upstream servers, with pluggable authentication mapping and… | 94 | 1304 | active |
| demisto/content The official content repository for Cortex XSOAR (formerly Demisto), a security orchestration, automation and response (SOAR) platform. It … | 68 | 1304 | active |
| jamesmcm/vopono Vopono is a Rust CLI tool that runs individual applications through VPN tunnels using temporary network namespaces on Linux. It supports mu… | 95 | 1303 | active |
| JFreegman/toxic Toxic is a terminal-based (ncurses) instant messaging client for the Tox peer-to-peer network, offering end-to-end encrypted text chat, fil… | 86 | 1303 | active |
| google/longfellow-zk A C++ library from Google implementing zero-knowledge proof protocols for identity verification, supporting standards like ISO MDOC, JWT, a… | 75 | 1303 | active |
| 0xInfection/XSRFProbe XSRFProbe is a Python-based Cross Site Request Forgery (CSRF/XSRF) audit and exploitation toolkit. It crawls web applications, runs systema… | 82 | 1302 | stable |
| GFW4Fun/x-ui-pro XUI-PRO is a shell-based auto-installer that sets up a censorship-resistant web proxy server combining the x-ui panel (Xray/V2ray), v2rayA,… | 78 | 1302 | active |
| Corvus-Malus/XKeen XKeen is a community-maintained CLI installer and management tool for setting up Xray and Mihomo proxy cores on Keenetic routers running En… | 52 | 1302 | active |
| Marven11/Fenjing Fenjing is an automated Jinja2 SSTI (server-side template injection) exploitation tool designed for CTF competitions. It automatically anal… | 87 | 1301 | active |
| sighook/pixload pixload is a set of Perl CLI tools for creating and injecting payloads into image files (BMP, GIF, JPG, PNG, WebP). It is used in offensive… | 23 | 1300 | active |
| rootless-containers/rootlesskit RootlessKit is a Linux-native 'fake root' tool that uses user and mount namespaces to let unprivileged users run container engines like Doc… | 94 | 1299 | active |
| RedTeamPentesting/pretender Pretender is a Go-based penetration testing tool that gains machine-in-the-middle positions via spoofed local name resolution (mDNS, LLMNR,… | 92 | 1299 | active |
| httpsok/httpsok httpsok is a shell-based SSL/TLS certificate auto-renewal tool designed for Nginx, OpenResty, and Apache servers, paired with a hosted web … | 60 | 1298 | active |
| LSPosed/DisableFlagSecure An LSPosed/Xposed module that enables screenshots in apps that block them via FLAG_SECURE and disables screenshot and screen-record detecti… | 83 | 1297 | active |
| Rurik/Noriben Noriben is a Python script that wraps Sysinternals Procmon to automatically collect, analyze, and report runtime indicators of malware, pro… | 56 | 1297 | stable |
| mrsteele/dotenv-webpack A webpack plugin that wraps dotenv and DefinePlugin to inject environment variables into your bundle at build time. It only exposes variabl… | 67 | 1295 | active |
| XiaoliChan/wmiexec-Pro wmiexec-Pro is a Python CLI tool built on Impacket that provides an enhanced version of wmiexec.py for remote command execution on Windows … | 67 | 1295 | active |
| pillarjs/cookies A Node.js module for getting and setting HTTP(S) cookies, with optional signing to prevent tampering via Keygrip. It works with the built-i… | 61 | 1295 | stable |
| pahaz/sshtunnel A pure Python library for creating SSH tunnels and TCP port forwarding through remote servers, built on paramiko. It lets applications prog… | 40 | 1295 | stable |
| h4r5h1t/webcopilot WebCopilot is a Bash-based automation script for bug bounty reconnaissance that enumerates subdomains using multiple tools, filters paramet… | 23 | 1295 | active |
| n0xa/m5stick-nemo NEMO is a firmware for M5Stack ESP32 devices (M5StickC, Cardputer) that implements high-tech pranks and digital self-defense tools such as … | 89 | 1294 | active |
| qwqdanchun/Pillager Pillager is a C# post-exploitation information gathering tool that exports and decrypts sensitive data from target Windows machines, includ… | 20 | 1294 | active |
| hausec/PowerZure PowerZure is a PowerShell framework for assessing and exploiting resources in Microsoft Azure and Entra ID. It provides both reconnaissance… | 53 | 1293 | active |
| waiting-for-dev/devise-jwt A Ruby gem that extends Devise to authenticate Rails users with JWT tokens instead of cookies, built as a thin layer over warden-jwt_auth. … | 72 | 1292 | active |
| sebadob/rauthy Rauthy is a lightweight, Rust-based Identity Provider offering Single Sign-On via OpenID Connect, OAuth 2, and PAM, with strong emphasis on… | 95 | 1291 | active |
| passff/passff PassFF is a Mozilla Firefox extension that provides browser access to a zx2c4 pass password store. It can list, fill, and submit login form… | 60 | 1291 | active |
| nette/latte Latte is a secure, intuitive templating engine for PHP featuring context-sensitive escaping that automatically protects against XSS vulnera… | 96 | 1290 | stable |
| google/crosvm crosvm is a secure, lightweight Virtual Machine Monitor (VMM) written in Rust, originally built for ChromeOS to run Linux and Android guest… | 77 | 1290 | active |
| knavesec/CredMaster CredMaster is a Python CLI tool for password spraying and brute-force attacks that rotates the source IP address on every authentication at… | 38 | 1290 | active |
| HaveIBeenPwned/PwnedPasswordsDownloader A .NET global tool that downloads the complete Pwned Passwords SHA1 and NTLM hash ranges for offline use, removing the need to query the k-… | 76 | 1289 | active |
| a2o/snoopy Snoopy is a small C library that logs every program execution on Linux/BSD systems, typically via a shared library loaded through the dynam… | 55 | 1289 | stable |
| utkusen/sast-skills A collection of LLM agent skills that turn coding assistants like Claude Code, Codex, Opencode, and Cursor into a SAST (static application … | 49 | 1289 | active |
| royhills/arp-scan arp-scan is a command-line network scanning tool that uses ARP requests to discover and fingerprint IPv4 hosts on a local network. It is wr… | 27 | 1289 | active |
| blueimp/JavaScript-MD5 A zero-dependency JavaScript implementation of the MD5 hash algorithm, supporting hex-encoded and raw MD5 as well as HMAC-MD5. It works in … | 10 | 4559 | maintenance |
| P1-Team/AlliN AlliN is a flexible, dependency-free Python scanner designed to assist penetration testing projects, especially lateral movement and intran… | 40 | 1288 | active |
| RickdeJager/stegseek Stegseek is a lightning-fast command-line cracker for steghide steganography, built as a fork of the original steghide project that can tes… | 23 | 1288 | stable |
| tiann/epic Epic is a dynamic Java method AOP hooking library for Android, continuing Dexposed on the ART runtime and supporting Android 5.0 through 11… | 23 | 4554 | maintenance |
| shizunge/endlessh-go A Go implementation of endlessh, an SSH tarpit that traps brute-force attackers by sending an endless SSH banner, while exporting Prometheu… | 87 | 1286 | active |
| corkami/mitra Mitra is a Python CLI tool that generates weird files such as binary polyglots, near-polyglots, polymocks, parasites, and zippers across ma… | 32 | 1286 | active |
| ProbiusOfficial/CTF-OS CTF-OS is a preconfigured virtual machine image purpose-built for Capture The Flag (CTF) competitions, bundling a curated set of security a… | 32 | 1286 | active |
| apache/impala Apache Impala is a massively parallel, distributed SQL query engine written in C++ for analyzing petabyte-scale data stored in open data an… | 67 | 1285 | stable |
| jvdsn/crypto-attacks A collection of Python implementations of cryptographic attacks and utilities, built on SageMath and PyCryptodome. It covers attacks agains… | 60 | 1285 | active |
| microsoft/CSS-Exchange A collection of PowerShell scripts from Microsoft Customer Service and Support for diagnosing and fixing issues in Microsoft Exchange Serve… | 95 | 1284 | active |
| owenthereal/upterm Upterm is an open-source CLI tool for instantly sharing terminal sessions over secure SSH tunnels to the public internet. It supports remot… | 92 | 1284 | active |
| SafeBreach-Labs/PoolParty PoolParty is a C++ command-line tool implementing eight novel, fully-undetectable process injection techniques that abuse Windows Thread Po… | 20 | 1284 | active |
| juliansteenbakker/flutter_secure_storage A Flutter plugin for securely storing sensitive key-value data using platform-specific encrypted storage such as iOS/macOS Keychain, Androi… | 98 | 1282 | active |
| Leseratte10/acsm-calibre-plugin A Calibre FileType plugin that converts ACSM files into EPUB or PDF without needing Adobe Digital Editions, implemented as a full Python re… | 65 | 1282 | active |
| bit4woo/Fiora Fiora is a graphical interface for the Nuclei vulnerability PoC framework, enabling quick PoC search and one-click execution of Nuclei scan… | 57 | 1282 | active |
| google/secrets-gradle-plugin A Gradle plugin by Google that injects secrets from a properties file (like local.properties) not checked into version control into BuildCo… | 23 | 1282 | stable |
| owasp-dep-scan/dep-scan OWASP dep-scan is a security and risk audit CLI tool that scans project dependencies in local repositories and container images for known C… | 97 | 1281 | active |
| larlarua/AutoCVE AutoCVE is a self-hosted multi-agent platform that automates CVE discovery: it filters target projects, imports repositories, audits source… | 77 | 1280 | active |
| keepassx/keepassx KeePassX is a cross-platform desktop password manager that stores credentials and other sensitive data in an encrypted database compatible … | 10 | 4523 | maintenance |
| 520CCC/AIGenerateCode A Java-based tool suite for Android that generates junk code (Java, drawables, layouts, strings, manifests) and ProGuard obfuscation files … | 37 | 1279 | active |
| gaasedelen/patching An interactive binary patching plugin for IDA Pro that adds a robust in-disassembler workflow for editing assembly instructions. It support… | 23 | 1279 | active |
| rails/globalid A Ruby library from the Rails project that provides app-wide URIs (gid://app/Model/id) for uniquely identifying model instances across diff… | 86 | 1277 | stable |
| roro2239/Stellar Stellar is a deeply customized fork of Shizuku, an Android framework that lets apps use system-level APIs via ADB wireless debugging or Roo… | 82 | 1277 | active |
| sardanioss/httpcloak httpcloak is a Go HTTP client library that reproduces browser-identical TLS, HTTP/2, and HTTP/3 fingerprints (JA3/JA4, Akamai, header order… | 61 | 1276 | active |
| asm89/stack-cors A PHP library and Stack middleware that implements the W3C CORS recommendation for http-foundation/http-kernel based applications. It can b… | 61 | 1276 | stable |
| icyguider/Shhhloader Shhhloader is a Python-based builder that compiles C++ shellcode loader stubs designed to bypass AV/EDR on Windows. It supports multiple sh… | 32 | 1276 | active |
| zhuifengshaonianhanlu/pikachu Pikachu is a deliberately vulnerable PHP/MySQL web application designed as a practice range for learning web security and penetration testi… | 71 | 4504 | maintenance |
| freeipa/freeipa FreeIPA is an integrated security information management solution providing centralized identity, authentication, and access control for Li… | 77 | 1274 | stable |
| truemail-rb/truemail Truemail is a configurable, framework-agnostic plain Ruby gem for validating and verifying email addresses. It validates emails via regex, … | 23 | 1274 | stable |
| mategol/PySilon PySilon is an open-source remote access trojan (RAT) written in Python that is controlled through Discord as its command-and-control channe… | 61 | 1271 | active |
| W01fh4cker/VcenterKit A comprehensive penetration testing toolkit targeting VMware vCenter, bundling exploitation modules for known CVEs such as CVE-2021-21972, … | 42 | 1270 | active |
| macadmins/nudge Nudge is a Swift/SwiftUI macOS application that strongly encourages users to install macOS security updates through customizable, multiling… | 86 | 1269 | active |
| jiacai2050/gooreplacer Gooreplacer is a browser extension for Chrome, Firefox, and Edge that redirects or blocks URLs and modifies HTTP request/response headers b… | 10 | 1269 | active |
| tklengyel/drakvuf DRAKVUF is a virtualization-based, agentless black-box binary analysis system that traces execution of arbitrary binaries, kernels, and fir… | 66 | 1268 | active |
| pinterest/knox Knox is a self-hosted secret management service written in Go that stores, serves, and rotates secrets, keys, and credentials used by other… | 64 | 1268 | active |
| xploitstech/Xteam Xteam is an all-in-one, menu-driven hacking toolkit written in Python and launched via bash scripts, bundling Instagram information gatheri… | 42 | 1268 | active |
| DimitarPetrov/stegify stegify is a Go command line tool and library for LSB (Least Significant Bit) steganography that hides any file inside images such as PNG a… | 23 | 1267 | stable |
| UndeadSec/EvilURL EvilURL is a Python CLI tool that generates Unicode (IDN) domain permutations used in homograph attacks, where look-alike characters trick … | 10 | 1267 | active |
| Athena-OS/athena Athena OS is an Arch/Nix-based Linux distribution focused on cybersecurity and penetration testing, available as ISO, Docker images, and WS… | 83 | 1266 | active |
| kpcyrd/sniffglue A secure multithreaded network packet sniffer written in Rust that parses packets concurrently across all CPU cores. It is hardened with se… | 72 | 1265 | active |
| mozillazg/ptcpdump ptcpdump is a tcpdump-compatible packet analyzer built on eBPF that automatically annotates captured packets with process, container, and K… | 77 | 1264 | active |
| edoardottt/scilla Scilla is a Go-based command-line information gathering (recon) tool for penetration testers and bug bounty hunters. It enumerates DNS reco… | 80 | 1262 | active |
| starkscan/starkscan-verifier A command-line tool (npm package 'starkscan') that verifies Cairo smart contract ABIs on the Starkscan block explorer for Starknet. Verific… | 32 | 1261 | active |
| flatcar/Flatcar Flatcar Container Linux is a minimal, immutable, container-optimized Linux distribution and the community-driven successor to CoreOS Contai… | 76 | 1260 | active |
| jazzband/django-rest-knox django-rest-knox is a token-based authentication library for Django REST Framework that improves on DRF's built-in TokenAuthentication. It … | 86 | 1259 | active |
| selfxyz/self Self is an open-source monorepo for a privacy-preserving identity verification platform that lets users generate zero-knowledge proofs from… | 73 | 1259 | active |
| 3xpl01tc0d3r/ProcessInjection A C# command-line tool that demonstrates and performs multiple Windows process injection techniques, including DLL injection, process hollo… | 48 | 1259 | active |
| step-security/harden-runner Harden-Runner is a CI/CD security agent that acts like an EDR for GitHub Actions runners, monitoring network egress, file integrity, and pr… | 98 | 1258 | active |
| cybersecsi/houdini HOUDINI is a curated catalog of hundreds of Docker images for network security and intrusion testing tools, presented through a searchable … | 47 | 1258 | active |
| WICG/webpackage A collection of IETF/WICG specifications and Go tooling for packaging websites into portable bundles, including Signed HTTP Exchanges (SXG)… | 72 | 1257 | active |
| btcsuite/btcwallet btcwallet is a secure hierarchical deterministic (HD) bitcoin wallet daemon written in Go. It acts as an RPC client to a btcd full node and… | 67 | 1256 | active |
| RoganDawes/P4wnP1_aloa P4wnP1 A.L.O.A. is a framework that turns a Raspberry Pi Zero W into a low-cost offensive security appliance for pentesting, red teaming, a… | 23 | 4422 | maintenance |
| google/re2j RE2/J is a pure Java port of Google's RE2 regular expression engine that guarantees linear-time matching using a nondeterministic finite au… | 60 | 1255 | active |