function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| SychicBoy/NETReactorSlayer NETReactorSlayer is an open-source (GPLv3) deobfuscator and unpacker targeting assemblies protected with Eziriz .NET Reactor. It is availab… | 23 | 1255 | active |
| CodeIntelligenceTesting/jazzer Jazzer is a coverage-guided, in-process fuzz testing engine for the JVM, based on libFuzzer. It integrates with JUnit 5 and build tools lik… | 86 | 1254 | active |
| utkusen/promptmap promptmap2 is an automated prompt injection scanner for custom LLM applications, supporting white-box testing of system prompts and black-b… | 53 | 1254 | active |
| pry0cc/axiom Axiom is a dynamic infrastructure framework for spinning up disposable multi-cloud instances pre-loaded with security scanning tools like n… | 23 | 4415 | maintenance |
| genodelabs/genode Genode is an open-source C++ framework for building highly secure, component-based operating systems using capability-based security and a … | 10 | 1253 | active |
| relative/synchrony Synchrony is a JavaScript deobfuscator and cleaner focused on undoing obfuscation from javascript-obfuscator/obfuscator.io. It works as a C… | 82 | 1250 | active |
| facebook/mariana-trench Mariana Trench is a security-focused static analysis platform for Android and Java applications, built by Meta on the SPARTA and Redex infr… | 77 | 1250 | active |
| markets/invisible_captcha A Ruby gem providing unobtrusive spam protection for Rails applications using honeypot techniques. It adds hidden form fields that bots fil… | 74 | 1250 | active |
| obfuscator-llvm/obfuscator Obfuscator-LLVM is a fork of the LLVM compiler infrastructure that adds code obfuscation passes for software protection. It transforms comp… | 32 | 4389 | maintenance |
| wh1t3p1g/ysomap Ysomap is a Java deserialization exploit framework that lets users dynamically configure gadget chain payloads with different execution eff… | 26 | 1247 | active |
| f4rih/websploit Websploit is a high-level man-in-the-middle (MITM) security framework written in Python with a modular console interface similar to Metaspl… | 23 | 1247 | stable |
| JiGuroLGC/BetterVia BetterVia is an Xposed module (for LSPosed/LSPatch) that enhances the Via browser on Android by removing built-in whitelist restrictions on… | 81 | 1246 | active |
| latchset/clevis Clevis is a pluggable framework for automated encryption and decryption, producing JWE ciphertexts that can be decrypted without user inter… | 80 | 1246 | active |
| lemono0/FastJsonParty FastJsonParty is a collection of Dockerized vulnerable environments covering multiple FastJson versions (1.2.47, 1.2.68, 1.2.80) for practi… | 28 | 1246 | active |
| antonioCoco/ConPtyShell ConPtyShell is a fully interactive reverse shell for Windows that leverages the Windows Pseudo Console (ConPTY) API to turn a remote PowerS… | 23 | 1246 | stable |
| RoganDawes/P4wnP1 P4wnP1 is a highly customizable USB attack platform built on a Raspberry Pi Zero or Zero W, providing features like a Windows LockPicker an… | 23 | 4383 | maintenance |
| input-output-hk/daedalus Daedalus is the open-source desktop wallet for ada, the cryptocurrency of the Cardano blockchain. Built with Electron and TypeScript, it is… | 94 | 1244 | active |
| SeedSigner/seedsigner SeedSigner is a FOSS application that turns a Raspberry Pi Zero with a camera and screen into an air-gapped, stateless Bitcoin signing devi… | 86 | 1244 | active |
| Simple-Tracker/qBittorrent-ClientBlocker A cross-platform client blocker for qBittorrent, Transmission (beta), and BitComet (partial) that bans leeching BitTorrent peers such as Xu… | 83 | 1244 | active |
| delight-im/PHP-Auth A lightweight, secure authentication library for PHP that handles registration, login, email verification, password resets, and session man… | 44 | 1244 | stable |
| dnsviz/dnsviz DNSViz is a Python tool suite for analysis and visualization of DNS behavior, including DNSSEC security extensions. It provides command-lin… | 30 | 1244 | active |
| curbox-app/curbox-android Curbox is a free, open-source Android app that blocks distracting apps, websites, and short-video feeds like Instagram Reels and YouTube Sh… | 90 | 1242 | active |
| Jacalz/rymdport Rymdport is a cross-platform GUI application for securely sharing files, folders, and text between devices using end-to-end encryption. It … | 61 | 1240 | active |
| damienbod/angular-auth-oidc-client An npm library for securing Angular applications with OpenID Connect and OAuth2, supporting Code Flow with PKCE, refresh tokens, and the Im… | 95 | 1239 | active |
| ProtonMail/gopenpgp GopenPGP is a high-level OpenPGP wrapper library for Go, developed by Proton Mail and built on a fork of the golang crypto library. It prov… | 91 | 1239 | stable |
| horizontalsystems/unstoppable-wallet-android Unstoppable is an open-source, non-custodial multi-wallet Android app for Bitcoin, Ethereum, BNB Chain, Avalanche, Solana, Zcash, and other… | 99 | 1238 | active |
| brainfucksec/kalitorify kalitorify is a shell script for Kali Linux that uses iptables rules to create a transparent proxy through the Tor network, redirecting all… | 32 | 1238 | active |
| iqiyi/xHook xHook is a PLT (Procedure Linkage Table) hook library for Android native ELF binaries and shared libraries, written in C. It lets native co… | 45 | 4348 | maintenance |
| mrwadams/attackgen AttackGen is a Streamlit-based cybersecurity tool that uses large language models to generate tailored incident response testing scenarios … | 95 | 1237 | active |
| HotBoy-java/PotatoTool PotatoTool is a comprehensive Java-based network security GUI tool for security professionals, red/blue team members, and enthusiasts. It i… | 29 | 1237 | active |
| PortSwigger/http-request-smuggler A Burp Suite extension that automatically detects and exploits HTTP Request Smuggling vulnerabilities, including HTTP/1.1 CL.TE/TE.CL desyn… | 76 | 1236 | active |
| rdbo/libmem A cross-platform game hacking library for C, C++, Rust, and Python providing process and memory manipulation, function hooking/detouring, c… | 74 | 1236 | active |
| alexhude/uEmu uEmu is an IDA Pro plugin built on the Unicorn engine that lets you emulate code directly inside the IDA disassembler. It supports x86, x64… | 76 | 1235 | active |
| arismelachroinos/lscript A shell script for Kali Linux that automates common WiFi penetration testing and hacking procedures through an interactive menu. It bundles… | 10 | 4330 | maintenance |
| rauc/rauc RAUC (Robust Auto-Update Controller) is an open-source update client and host tool for embedded Linux systems that manages fail-safe, atomi… | 87 | 1232 | stable |
| uunicorn/python-validity A Python driver and DBus service for Validity fingerprint sensors on Linux, integrating with fprintd for biometric authentication. It suppo… | 44 | 1231 | active |
| danielbohannon/Invoke-Obfuscation Invoke-Obfuscation is a PowerShell command and script obfuscation framework compatible with PowerShell 2.0+. It generates obfuscated varian… | 32 | 4320 | maintenance |
| EliasKotlyar/Xiaomi-Dafang-Hacks Custom firmware (CFW) for the Xiaomi Dafang, Xiaofang 1S, Wyzecam V2/Pan, and other Ingenic T10/T20-based IP cameras. It replaces the stock… | 32 | 4316 | maintenance |
| HemmeligOrg/Hemmelig.app Hemmelig is a self-hostable web application for sharing sensitive information via encrypted, self-destructing secret links with client-side… | 82 | 1229 | active |
| apache/teaclave-sgx-sdk Apache Teaclave SGX SDK (Rust SGX SDK) is a Rust-based software development kit for building Intel SGX enclave applications with memory saf… | 62 | 1229 | active |
| RUB-NDS/PRET PRET is a Python command-line toolkit for printer security testing that connects to devices via network (port 9100) or USB and exploits pri… | 32 | 4301 | maintenance |
| passportxyz/passport Passport is an identity verification application that lets users build collections of verifiable credentials to prove unique humanity in a … | 98 | 1226 | active |
| EvotecIT/GPOZaurr GPOZaurr is a PowerShell module for gathering, analyzing, and fixing issues in Active Directory Group Policies. A single command (Invoke-GP… | 94 | 1226 | active |
| cloudflare/cloudflare-blog A collection of code samples accompanying posts on the Cloudflare Blog, covering topics like networking, security, performance, and edge co… | 67 | 1226 | active |
| RubberDuck-com/rubberduck-use-case-playground A hands-on training playground for RubberDuck MCP, consisting of a local hub dashboard and a deliberately vulnerable restaurant demo app (R… | 54 | 1224 | active |
| DanMcInerney/wifijammer A Python script that continuously jams Wi-Fi clients and access points within range by sending deauthentication packets. It hops channels, … | 32 | 4291 | maintenance |
| mendersoftware/mender Mender is an open-source over-the-air (OTA) software update client for IoT and embedded Linux devices, part of a client-server platform for… | 83 | 1223 | stable |
| cherriesandmochi/gdmaim GDMaim is a Godot Engine plugin that obfuscates all GDScript source code when exporting a project, renaming identifiers, hardcoding constan… | 79 | 1223 | active |
| xchwarze/wifi-pineapple-cloner A set of shell scripts that port the WiFi Pineapple NANO/TETRA penetration-testing firmware onto generic routers and other hardware. It inc… | 64 | 1223 | active |
| lcvvvv/kscan Kscan is an all-in-one reconnaissance scanner written in pure Go that combines port scanning, protocol detection, service/application finge… | 23 | 4287 | maintenance |
| BehiSecc/VibeSec-Skill VibeSec-Skill is an AI skill (prompt/instruction pack) that teaches LLM coding assistants like Claude Code, Cursor, Codex, Copilot, and Ant… | 46 | 1220 | active |
| Tylous/SourcePoint SourcePoint is a Go-based polymorphic C2 profile generator for Cobalt Strike command and control servers. It generates unique malleable C2 … | 30 | 1220 | active |
| nmap/ncrack Ncrack is a high-speed network authentication cracking tool from the Nmap project, designed to audit hosts and network devices for weak pas… | 23 | 1220 | active |
| jx-sec/jxwaf JXWAF is an open-source web application firewall powered by an AI large language model, combining an AI security model, a semantic analysis… | 67 | 1219 | active |
| RamboRogers/rfhunter RFHunter is a DIY hardware device built on an ESP32 and AD8317 RF power detector that scans for RF signals to help locate hidden cameras, w… | 22 | 1219 | active |
| LavaMoat/LavaMoat LavaMoat is a suite of tools for securing JavaScript projects against software supply chain attacks by sandboxing the dependency graph. It … | 92 | 1218 | active |
| coreos/go-iptables A Go library that wraps the iptables command-line utility, providing functions to append and delete rules and to create, clear, and delete … | 23 | 1218 | stable |
| swaywm/swaylock swaylock is a screen locking utility for Wayland compositors, compatible with any compositor implementing the ext-session-lock-v1 protocol.… | 85 | 1215 | active |
| bitquark/shortscan Shortscan is a Go CLI tool that enumerates files with short (8.3) filenames on IIS web servers and attempts to recover their full filenames… | 29 | 1215 | active |
| mongodb/kingfisher Kingfisher is an open-source, Rust-based secret scanner that detects leaked credentials in code, Git history, cloud storage, and developer … | 82 | 1214 | active |
| sogonov/anubis An Android app manager that freezes and unfreezes groups of apps based on VPN connection state using system-level `pm disable-user` via Shi… | 67 | 1214 | active |
| martijnvanbrummelen/nwipe nwipe is a secure disk eraser for Linux, a fork of DBAN's dwipe command, that wipes entire block devices using multiple erasure methods. It… | 89 | 1212 | active |
| cfal/shoes A high-performance multi-protocol proxy server written in Rust supporting HTTP, SOCKS5, VMess, VLESS, Shadowsocks, Trojan, Snell, Hysteria2… | 82 | 1210 | active |
| jxy-s/herpaderping A proof-of-concept tool and technical write-up demonstrating Process Herpaderping, a Windows technique that maps a process image from a fil… | 32 | 1210 | active |
| paralus/paralus Paralus is an open source, CNCF Sandbox zero-trust Kubernetes access manager that provides controlled, audited access to Kubernetes cluster… | 71 | 1209 | active |
| mgeeky/PackMyPayload PackMyPayload is a Python CLI proof-of-concept tool that packages files or directories into container formats (ZIP, 7zip, PDF, ISO, IMG, CA… | 32 | 1209 | active |
| gorilla/csrf gorilla/csrf is a Go HTTP middleware library that provides cross-site request forgery (CSRF) protection for web applications and services. … | 30 | 1209 | stable |
| strozfriedberg/Windows-Exploit-Suggester A Python CLI tool that compares a Windows host's patch level (from systeminfo output) against the Microsoft security bulletin database to d… | 10 | 4229 | maintenance |
| darktohka/clean-flash-builds A repository of clean, spyware-free builds of Adobe Flash Player, stripped of the bundled adware and telemetry found in the Chinese Flash v… | 80 | 1208 | active |
| NyaMisty/AltServer-Linux AltServer-Linux is a Linux port of AltServer that signs and sideloads IPA files onto iOS devices using an Apple ID, and can run as an AltSt… | 28 | 1208 | active |
| Veil-Framework/Veil Veil is a Python-based command-line tool that generates Metasploit payloads designed to bypass common antivirus solutions. It supports mult… | 10 | 4226 | maintenance |
| bivlked/amneziawg-installer A one-command Bash installer that turns a fresh Ubuntu or Debian VPS (x86_64, ARM64, Raspberry Pi) into a self-hosted AmneziaWG 2.0/3.x VPN… | 83 | 1207 | active |
| qi4L/qscan Qscan is an extremely fast internal network scanner written in Go, offering port scanning, protocol detection, service fingerprinting, brut… | 72 | 1206 | active |
| SciresM/boot9strap Boot9strap is a custom firmware bootloader for the Nintendo 3DS that achieves Boot9/Boot11 code execution via a bootrom exploit. It loads a… | 48 | 1205 | stable |
| zxcvbn-ts/zxcvbn A TypeScript rewrite of Dropbox's zxcvbn password strength estimator that scores passwords based on pattern matching against common passwor… | 76 | 1204 | active |
| CERT-Polska/Artemis Artemis is a modular, open-source vulnerability scanner developed by CERT Polska that checks website security at scale. It automatically ge… | 74 | 1204 | active |
| topiam/eiam TOPIAM is an open-source IAM/IDaaS identity and access management platform for centrally managing employee accounts, permissions, authentic… | 40 | 1204 | active |
| opengnb/opengnb OpenGNB is an open-source decentralized Software Defined Virtual Network (SDVN) that creates a layer-3 P2P VPN with strong NAT traversal, l… | 93 | 1203 | active |
| JonasAlfredsson/docker-nginx-certbot A Docker image wrapping the official Nginx images with automatic Let's Encrypt certificate creation and renewal via certbot. It supports RS… | 92 | 1203 | active |
| ramosbugs/oauth2-rs An extensible, strongly-typed Rust implementation of the OAuth2 protocol (RFC 6749). It provides a client library for OAuth2 authorization … | 53 | 1203 | stable |
| google/AFL American Fuzzy Lop (AFL) is a security-oriented, coverage-guided fuzzer that uses compile-time instrumentation and genetic algorithms to di… | 10 | 4205 | maintenance |
| maoabc/nmmp nmmp is an APK/AAB/AAR hardening tool that converts Dalvik bytecode from classes.dex into native C code executed by a custom dex virtual ma… | 40 | 1202 | active |
| floating/frame Frame is a system-wide Web3 wallet platform for macOS, Windows, and Linux that exposes local JSON-RPC endpoints so any browser, CLI, or nat… | 39 | 1202 | active |
| x64dbg/GleeBug GleeBug is a debugging framework for Windows written in C, designed to make building debuggers and debugging tools complete and easy to use… | 76 | 1201 | active |
| dromara/tianai-captcha TianaiCAPTCHA is a Java-based behavioral CAPTCHA library supporting slider, rotation, slide-restore, and text-click CAPTCHA types. It ships… | 65 | 1201 | active |
| mbrg/power-pwn Power Pwn is an offensive and defensive security toolset for Microsoft 365 Power Platform and AI services, including Copilot Studio, custom… | 63 | 1201 | active |
| zgjx6/SocialEngineeringDictionaryGenerator A browser-based social engineering password dictionary generator that builds candidate password lists from personal information such as nam… | 48 | 1201 | active |
| zetaloop/BetterWX A set of Python patch scripts for WeChat PC 4.0 on Windows x64 that enable anti-revoke (message recall prevention with notice), multi-insta… | 33 | 1201 | active |
| epinna/tplmap Tplmap is a Python command-line tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code injection vulne… | 23 | 4197 | maintenance |
| facebookincubator/fizz Fizz is a C++14 implementation of the TLS 1.3 protocol, supporting all major handshake modes including PSK resumption, early data, client a… | 96 | 1200 | active |
| Janusec/janusec Janusec Application Gateway is a Go-based application gateway providing secure access for web applications, including reverse proxy, WAF, C… | 83 | 1200 | active |
| DragonOS-Community/DragonOS DragonOS is a 64-bit operating system with a fully independent kernel written from scratch in Rust, offering Linux binary compatibility. It… | 82 | 1200 | active |
| Hackmanit/Web-Cache-Vulnerability-Scanner A fast, Go-based CLI scanner for detecting web cache poisoning and web cache deception vulnerabilities. It supports many attack techniques,… | 60 | 1200 | active |
| notmarek/LanguageBreak LanguageBreak is a software jailbreak for Amazon Kindle e-readers running firmware 5.16.2.1.1 or lower, exploiting a demo-mode vulnerabilit… | 19 | 1199 | active |
| helloyanis/age-verification-bypass A Firefox WebExtension that skips age verification screens on sites like AgeChecker.net, AgeVerif, Bluesky, Reddit, and AliExpress. It is a… | 80 | 1198 | active |
| 7h30th3r0n3/Raspyjack RaspyJack is a portable offensive security toolkit for Raspberry Pi (with Waveshare LCD HAT) and Cardputer Zero, offering 231 payloads acro… | 78 | 1198 | active |
| ycdxsb/PocOrExp_in_Github A Python CLI tool that automatically aggregates proof-of-concept (POC) and exploit (EXP) code from GitHub by CVE ID, using CVE information … | 77 | 1198 | active |
| ozguralp/gmapsapiscanner A Python CLI tool that tests whether a leaked or discovered Google Maps API key is vulnerable to unauthorized usage across many Google Maps… | 70 | 1198 | active |
| The-Viper-One/PsMapExec PsMapExec is a PowerShell-based post-exploitation framework inspired by CrackMapExec/NetExec for assessing Active Directory environments. I… | 61 | 1198 | active |
| petoolse/petools PE Tools is a Windows GUI toolkit for researching and manipulating Portable Executable (PE) files and running processes. It bundles a PE he… | 44 | 1197 | active |