function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| brandonlw/Psychson A toolkit for creating custom firmware and firmware patches for Phison 2251-03 (2303) USB controller chips, enabling BadUSB attacks via HID… | 23 | 4181 | maintenance |
| internetwache/GitTools GitTools is a collection of three shell/Python scripts for finding and exploiting websites that publicly expose their .git directory. It in… | 64 | 4178 | maintenance |
| fankes/TSBattery TSBattery is an open-source Xposed module written in Kotlin that reduces battery drain from QQ, TIM, and WeChat on rooted Android devices. … | 67 | 1196 | active |
| vanhauser-thc/thc-ipv6 A comprehensive IPv6 attack toolkit written in C, providing dozens of tools for spoofing, man-in-the-middle, denial-of-service, scanning, a… | 58 | 1196 | active |
| symfony/security The Symfony Security Component provides a complete authentication and authorization system for PHP web applications. It supports HTTP basic… | 10 | 1196 | stable |
| isec-tugraz/meltdown A collection of proof-of-concept applications demonstrating the Meltdown CPU vulnerability, built on the libkdump library. It includes demo… | 10 | 4172 | maintenance |
| DataDog/guarddog GuardDog is a CLI tool from Datadog that identifies malicious packages on PyPI, npm, Go modules, Rust crates, RubyGems, GitHub Actions, and… | 99 | 1194 | active |
| cloudflare/flan Flan Scan is a lightweight network vulnerability scanner from Cloudflare that wraps Nmap and the vulners script to detect open ports, servi… | 10 | 4166 | maintenance |
| deepfence/FlowMeter FlowMeter is a Go utility that analyzes network packet headers, groups packets into flows, and uses machine learning to classify flows as b… | 10 | 1193 | active |
| RikkaApps/Sui Sui is a modern superuser (root) interface implementation for Android, installed as a Magisk/Riru module. It provides Java APIs (Shizuku AP… | 23 | 4164 | maintenance |
| openfheorg/openfhe-development OpenFHE is an open-source C++ library for fully homomorphic encryption (FHE), implementing all major schemes (BFV, BGV, CKKS, FHEW/TFHE, LM… | 88 | 1192 | active |
| P3GLEG/Whaler Whaler is a Go CLI tool that reverse engineers Docker images back into the Dockerfiles that created them. It also extracts files added via … | 57 | 1192 | active |
| huntergregal/mimipenguin MimiPenguin is a post-exploitation tool that dumps the current Linux desktop user's cleartext login password from process memory, inspired … | 41 | 4157 | maintenance |
| samyk/magspoof MagSpoof is a portable Arduino-based device that spoofs and emulates magnetic stripe cards (credit cards, hotel keys, etc.) wirelessly by g… | 32 | 4146 | maintenance |
| suzuki-shunsuke/pinact pinact is a Go CLI that pins GitHub Actions and Reusable Workflows to full commit SHAs in workflow and composite action files, adding versi… | 96 | 1188 | active |
| meziantou/Meziantou.Analyzer Meziantou.Analyzer is a C# Roslyn analyzer distributed as a NuGet package that performs static analysis to detect bugs, security issues, an… | 96 | 1187 | active |
| FiloSottile/passage passage is a fork of the password-store (pass) CLI password manager that uses age encryption instead of GnuPG. It stores secrets as age-enc… | 23 | 1187 | active |
| goretk/redress Redress is a command-line tool for analyzing stripped Go binaries, reconstructing symbols and extracting information such as compiler versi… | 94 | 1186 | active |
| rpardini/docker-registry-proxy An HTTPS caching proxy for Docker registries that provides centralized configuration and caching of image pulls from any registry (DockerHu… | 81 | 1186 | active |
| RobThree/TwoFactorAuth A PHP library for implementing two-factor (multi-factor) authentication using TOTP time-based one-time passwords and QR codes. It supports … | 58 | 1186 | stable |
| chaitin/xpoc xpoc is a fast emergency-response vulnerability scanner from Chaitin's xray community, designed for supply chain vulnerability scanning. It… | 20 | 1186 | active |
| LainsNL/OutlookRegister A Python automation tool that mass-registers Outlook/Hotmail email accounts using browser automation (Playwright or Patchright) with simula… | 62 | 1184 | active |
| dirkjanm/adidnsdump A Python CLI tool that enumerates and exports all DNS records in Active Directory Integrated DNS zones using any authenticated domain user'… | 29 | 1184 | active |
| google/end-to-end A JavaScript crypto library implementing OpenPGP (RFC 4880) and OTR for encrypting, decrypting, digitally signing, and verifying messages. … | 10 | 4125 | maintenance |
| trustedsec/CS-Remote-OPs-BOF A collection of Beacon Object Files (BOFs) by TrustedSec implementing remote operations commands for Cobalt Strike, covering tasks like use… | 94 | 1183 | active |
| yazgx97/frida-ios-hook A Python/JavaScript CLI tool that wraps Frida to make it easy to trace classes and functions, hook methods, and modify return values on iOS… | 69 | 1183 | active |
| J2TEAM/idm-trial-reset A small AutoIt-based Windows utility that resets the trial period of Internet Download Manager (IDM), allowing continued use without cracki… | 23 | 4120 | maintenance |
| runZeroInc/sshamble SSHamble is a Go-based research and scanning tool for probing SSH server implementations. It enumerates SSH capabilities and tests for auth… | 68 | 1180 | active |
| AdguardTeam/AdGuardMiniForMac AdGuard Mini for Mac is a free, open-source Safari extension that blocks ads, trackers, and annoyances like cookie notices and popups in th… | 94 | 1179 | active |
| austin-weeks/miasma Miasma is a lightweight Rust web server that traps AI web scrapers in an endless pit of poisoned training data and self-referential links. … | 82 | 1179 | active |
| briansmith/ring ring is a Rust library providing safe, fast cryptographic primitives (hashing, AEAD, signatures, key agreement) built largely on BoringSSL'… | 75 | 4104 | maintenance |
| Yubico/yubikey-manager A Python library and command line tool (ykman) for configuring YubiKey hardware security keys over all USB interfaces. It supports managing… | 92 | 1178 | active |
| data61/MP-SPDZ MP-SPDZ is a versatile C++ framework for secure multi-party computation (MPC) supporting many protocols across various security models, inc… | 85 | 1178 | active |
| steelbrain/ffmpeg-over-ip A client/server tool that lets applications use GPU-accelerated ffmpeg on a remote machine over a single TCP connection, without GPU passth… | 83 | 1176 | active |
| JoelGMSec/EvilnoVNC EvilnoVNC is a ready-to-run phishing platform that gives victims a real Chromium browser session over a noVNC connection inside Docker, whi… | 41 | 1176 | active |
| denisbrodbeck/machineid A Go library and small CLI that reads the operating system's native machine ID (machine UUID/GUID) on Windows, Linux, macOS, and BSD withou… | 32 | 1176 | stable |
| patriksimek/vm2 vm2 is a Node.js library that provides an in-process sandbox for running untrusted JavaScript code with whitelisted access to built-in modu… | 99 | 4093 | maintenance |
| canix1/ADACLScanner A PowerShell script (ADACLScan.ps1) with both CLI and GUI interfaces for reporting on discretionary and system access control lists (DACLs/… | 89 | 1175 | active |
| google/capslock Capslock is a capability analysis CLI for Go packages that classifies which privileged operations a package can access via transitive calls… | 73 | 1175 | active |
| google/certificate-transparency-go Google's Go implementation of Certificate Transparency (RFC 6962), providing libraries for parsing and auditing TLS certificates, client li… | 82 | 1174 | active |
| PKRoma/ProcessHacker System Informer (formerly Process Hacker) is a free, open-source, multi-purpose Windows tool for monitoring system resources, debugging sof… | 77 | 1174 | active |
| S3cur3Th1sSh1t/Creds A collection of PowerShell scripts and executables useful for penetration testing and forensics, mostly Windows and Active Directory domain… | 76 | 1174 | active |
| BiliUniverse/Universe BiliUniverse is a collection of enhancement modules for the Bilibili streaming platform, built as rewrite/script/MitM modules for proxy app… | 70 | 1173 | active |
| akitaonrails/ai-jail ai-jail is a Rust CLI that runs AI coding agents inside an OS-level sandbox using bubblewrap with Landlock, seccomp, and resource limits on… | 83 | 1172 | active |
| OpenVPN/openvpn3 OpenVPN 3 is a C++20 class library implementing an OpenVPN client that is protocol-compatible with OpenVPN 2.x, with a minimal command-line… | 77 | 1172 | active |
| jenish-sojitra/JSAnalyzer A Burp Suite extension written in Python (Jython) that performs static analysis on JavaScript files proxied through Burp. It extracts API e… | 44 | 1171 | active |
| NH-RED-TEAM/RustHound RustHound is a cross-platform Active Directory data collector for BloodHound Legacy 4.x, written in Rust. It enumerates users, groups, comp… | 23 | 1171 | active |
| SSLMate/certspotter Cert Spotter is an open-source Certificate Transparency log monitor written in Go that alerts you when SSL/TLS certificates are issued for … | 75 | 1169 | active |
| Quitten/Autorize Autorize is a Burp Suite extension, written in Jython, that automatically detects authorization and authentication enforcement flaws in web… | 56 | 1169 | active |
| jasonxtn/Kraken Kraken is a Python-based menu-driven toolkit that centralizes brute-force attacks across network protocols (SSH, FTP, LDAP, Telnet, WiFi), … | 23 | 1169 | active |
| rverton/webanalyze webanalyze is a Go port of Wappalyzer that detects the technologies used on websites, built for performant mass scanning of large host list… | 71 | 1168 | active |
| reversenseorg/dexcalibur Reversense (Dexcalibur 2) is a binary intelligence platform that automates reverse engineering of mobile and embedded applications. It comb… | 68 | 1168 | active |
| daboynb/Safetycore-placeholder A placeholder Android APK that occupies the com.google.android.safetycore package name so Google cannot install or update the real SafetyCo… | 66 | 1168 | active |
| dark-kingA/cloudTools A cross-platform desktop tool for cloud asset management and cloud security assessment, built with Electron, Vue, Node.js, and Go. It manag… | 59 | 1168 | active |
| Wixel/GUMP GUMP is a standalone, zero-dependency PHP data validation and filtering library with 76 built-in validators, XSS sanitization, and support … | 78 | 1167 | stable |
| CodePlato3721/shiro-redis A Java library that provides a Redis-based cache and session manager implementation for Apache Shiro, which otherwise only supports ehcache… | 60 | 1166 | active |
| mukul975/cve-mcp-server A Python-based Model Context Protocol (MCP) server that gives Claude ~28 security intelligence tools across 20+ APIs, including CVE lookup,… | 72 | 1164 | active |
| 64characters/Telephone Telephone is a free open-source SIP softphone for macOS that lets users make and receive phone calls over the Internet or a company network… | 64 | 1164 | active |
| nccgroup/Sniffle Sniffle is an open-source sniffer for Bluetooth 5 and 4.x LE that runs on TI CC1352/CC26x2 hardware with a Python host-side tool. It captur… | 42 | 1164 | active |
| citronneur/pamspy pamspy is a Linux credentials dumper that uses eBPF to hook the pam_get_authtok function in libpam.so, capturing passwords from processes l… | 23 | 1164 | active |
| 0xthirteen/SharpRDP SharpRDP is a C# console application that executes authenticated commands on remote Windows hosts via the Remote Desktop Protocol, using th… | 75 | 1162 | active |
| formal-land/rocq-of-rust rocq-of-rust is a formal verification tool that translates Rust programs (from the compiler's THIR representation) into the Rocq proof assi… | 76 | 1161 | active |
| arthepsy/CVE-2021-4034 A proof-of-concept exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec utility. It is a small… | 32 | 1160 | stable |
| JuneAndGreen/sm-crypto A pure JavaScript implementation of the Chinese national cryptography (Guomi) algorithms SM2 (elliptic curve encryption/signatures), SM3 (h… | 77 | 1159 | active |
| loveshell/ngx_lua_waf A lightweight, high-performance web application firewall (WAF) built on lua-nginx-module (OpenResty) for Nginx. It filters requests using r… | 23 | 4024 | maintenance |
| kairi003/Get-cookies.txt-LOCALLY A browser extension for Chrome and Firefox that exports cookies in Netscape cookies.txt or JSON format entirely locally, without transmitti… | 48 | 1158 | active |
| 0x727/ShuiZe_0x727 ShuiZe_0x727 is a Python-based automated information gathering (reconnaissance) tool for red team operators. Given a root domain, C-segment… | 23 | 4019 | maintenance |
| paragonie/halite Halite is a high-level, misuse-resistant cryptography library for PHP built on top of libsodium. It simplifies encryption, decryption, digi… | 55 | 1157 | active |
| polymind-inc/acmebot Acmebot is an Azure-native application that automates ACME SSL/TLS certificate issuance and renewal using DNS-01 validation, storing privat… | 100 | 1156 | active |
| OWASP/pytm pytm is a Pythonic framework from OWASP for threat modeling systems as code. Developers define their architecture in Python and it automati… | 85 | 1156 | active |
| WhiteNightShadow/hello_js_reverse_skill An AI-powered 'Skill' package for JavaScript reverse engineering that plugs into AI coding tools like Claude Code, Cursor, and Codex. It pr… | 78 | 1156 | active |
| soupslurpr/AppVerifier AppVerifier is an Android app that views and verifies app signing certificate hashes to confirm apps are genuine. Users can compare package… | 37 | 1156 | active |
| URenko/Accesser Accesser is a Python-based local HTTP proxy tool that circumvents SNI-based connection resets (SNI RST) used by the Great Firewall, restori… | 62 | 1154 | active |
| milesj/interweave A React library for safely rendering HTML strings without dangerouslySetInnerHTML, with XSS protection, attribute filtering, and text match… | 35 | 1154 | active |
| Unicorn369/HookEuicc An Xposed/LSPosed module that spoofs eSIM support on Android devices and extracts eSIM activation codes from apps that hide them. It also i… | 10 | 1154 | active |
| evyatarmeged/Raccoon Raccoon is a Python-based offensive security CLI tool for reconnaissance and information gathering. It performs DNS lookups, WHOIS, TLS ana… | 67 | 4001 | maintenance |
| Fanju6/NetProxy-Magisk NetProxy is a system-level transparent proxy module for rooted Android devices built on the sing-box core, distributed as a Magisk/KernelSU… | 86 | 1153 | active |
| Daninet/hash-wasm hash-wasm is a fast hash function library for browsers and Node.js implemented with hand-tuned WebAssembly binaries. It supports a wide ran… | 23 | 1152 | stable |
| orhanobut/hawk Hawk is a secure, simple key-value storage library for Android that encrypts data before persisting it. It supports storing any object type… | 23 | 3996 | maintenance |
| EmilStenstrom/justhtml JustHTML is a pure Python HTML5 parser with browser-style error recovery, safe-by-default sanitization, CSS selector querying, and serializ… | 83 | 1151 | active |
| WeBankBlockchain/WeIdentity WeIdentity is a blockchain-based distributed identity solution implementing W3C DID and Verifiable Credential specifications, developed by … | 30 | 1150 | active |
| CookiePLMonster/SilentPatch SilentPatch is a community-made patch plugin for the 3D-era Grand Theft Auto games (GTA III, Vice City, San Andreas) that fixes crashes, bu… | 95 | 1149 | active |
| mmalmi/nostr-vpn nostr-vpn is a Tailscale-style private mesh VPN written in Rust, built around a FIPS-backed data plane with a `nvpn` CLI/daemon, a shared n… | 77 | 1149 | active |
| Enginex0/tricky-addon-enhanced A native Rust daemon distributed as a root module (Magisk/KernelSU/APatch) that automatically manages TrickyStore and TEESimulator on roote… | 68 | 1149 | active |
| ichason/CPosed CPosed is an Android hooking framework forked from LSPosed that enables Xposed-style module injection on rooted devices running Android 8.1… | 47 | 1148 | active |
| yunginnanet/HellPot HellPot is a cross-platform HTTP honeypot that punishes bots ignoring robots.txt by streaming an infinite Markov-chain-generated page of ps… | 49 | 1147 | active |
| IJHack/QtPass QtPass is a multi-platform GUI front-end for pass, the standard Unix password manager, built with Qt. It manages GPG-encrypted password sto… | 93 | 1146 | active |
| Netflix/repokid Repokid is a Python tool from Netflix that enforces least privilege on AWS IAM roles by removing permissions for unused services from inlin… | 47 | 1146 | active |
| JusticeRage/Manalyze Manalyze is a static analyzer for PE (Windows executable) files written in C++. It performs primary malware assessment by parsing PE struct… | 87 | 1145 | active |
| 0xsha/CloudBrute CloudBrute is a Go CLI tool that enumerates a company's infrastructure, files, and applications across major cloud providers (Amazon, Googl… | 27 | 1145 | active |
| pureqh/Hyacinth Hyacinth is a Java-based GUI tool that bundles detection and exploitation modules for common Java vulnerabilities such as Struts2, Fast, We… | 55 | 1144 | active |
| GuhDoy/TiebaTS TiebaTS is an Xposed module written in Kotlin that customizes the Baidu Tieba Android app, offering features like custom bottom navigation,… | 10 | 1143 | active |
| iagox86/dnscat2 dnscat2 is an encrypted DNS tunneling tool designed to create a command-and-control (C&C) channel over the DNS protocol. It consists of a C… | 23 | 3958 | maintenance |
| ExeinfoASL/ASL Exeinfo Pe is a free Windows GUI tool that detects packers, protectors, compilers, .NET obfuscators, and packed binary data formats in PE e… | 93 | 1142 | active |
| gujjwal00/avnc AVNC is an open-source VNC client for Android with a Material Design interface. It supports features like SSH tunneling, TLS, Zeroconf serv… | 94 | 1140 | active |
| TheHive-Project/TheHive TheHive is a collaborative security incident response and case management platform for SOC teams, supporting alert triage, case investigati… | 10 | 3947 | maintenance |
| hackademix/noscript NoScript Security Suite is a free open-source browser extension that lets users decide which websites are trusted to run JavaScript and oth… | 98 | 1139 | active |
| FreneticLLC/KeyboardChatterBlocker A Windows GUI tool that blocks mechanical keyboard chatter by filtering rapidly repeated keystrokes. It supports per-key chatter thresholds… | 85 | 1138 | active |
| AvenCores/open-antigravity-patcher An open-source Python patcher that removes regional restrictions from Google's Antigravity IDE, CLI, and VS Code extension, allowing use in… | 82 | 1138 | active |
| laluka/bypass-url-parser A Python CLI tool (usable as a library) that generates and tests many URL bypass payloads to access 40X-protected pages, using curl as its … | 74 | 1138 | active |