function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Tobi823/ffupdater FFUpdater is an open-source Android app that installs and keeps privacy-friendly browsers (Firefox variants, Brave, Cromite, Tor Browser, a… | 70 | 1083 | active |
| alcideio/rbac-tool A kubectl plugin and standalone CLI that simplifies Kubernetes RBAC by visualizing, analyzing, generating, and querying RBAC policies. It h… | 26 | 1083 | active |
| HZJQF/help_tool A PyQt5-based Windows GUI tool that uses inference models to identify the encryption or hashing algorithm behind a given ciphertext and att… | 24 | 1083 | active |
| immanuwell/dockerfile-roast droast is a Dockerfile linter written in Rust with 85 opinionated rules that report bad practices using snarky, humorous messages. It runs … | 80 | 1082 | active |
| bhattsameer/Bombers A curated collection of Python scripts that flood phone numbers and email addresses with repeated SMS, email, WhatsApp, Twitter, and Instag… | 10 | 3711 | maintenance |
| flutter-stripe/flutter_stripe The official Stripe Flutter SDK for building payment experiences in Flutter apps on Android, iOS, and web. It provides pre-built native UI … | 95 | 1081 | active |
| tophant-ai/ClawVault ClawVault is a security vault plugin for OpenClaw AI agents that provides fine-grained, composable 'atomic' controls over what agents can a… | 76 | 1081 | active |
| jazzband/django-defender A Django reusable app that blocks brute-force login attempts by rate limiting on username and IP address, using Redis as a fast cache backe… | 52 | 1081 | active |
| EternalPain/ZJL ZJL is a shell script for Android that integrates the tiny and clnc engines to enable 'mianliu' (carrier free-data traffic) with anti-leak … | 23 | 1081 | active |
| google/fully-homomorphic-encryption Google's repository of demos for fully homomorphic encryption (FHE), originally a C++ transpiler and now showcasing the HEIR MLIR-based FHE… | 86 | 3708 | maintenance |
| mbechler/marshalsec marshalsec is a Java tool and research project that generates exploitation payloads for insecure unmarshalling across many Java marshalling… | 32 | 3708 | maintenance |
| DroneBridge/ESP32 DroneBridge for ESP32 is open-source firmware for ESP32 modules that provides a secure, transparent, bidirectional telemetry link between a… | 95 | 1080 | active |
| maester365/maester Maester is a PowerShell-based test automation framework that monitors and validates the security configuration of Microsoft 365 and Entra I… | 88 | 1080 | active |
| mtrojnar/osslsigncode osslsigncode is a small C tool that implements Microsoft Authenticode signing and timestamping, based on OpenSSL and cURL. It signs, verifi… | 93 | 1079 | active |
| TimothyYe/skm SKM is a command-line SSH key manager written in Go that lets users create, list, alias, switch, back up, and audit multiple SSH keys. It a… | 92 | 1079 | active |
| muraenateam/muraena Muraena is an almost-transparent reverse proxy written in Go that automates phishing and post-phishing activities by dynamically proxying a… | 66 | 1079 | active |
| danielrobbins/keychain Keychain is a Python-based CLI manager for ssh-agent and gpg-agent that maintains a single long-running agent per user and host, so passphr… | 100 | 1077 | stable |
| Windscribe/Desktop-App The open-source (GPL-2.0) desktop VPN client for the Windscribe service, built in C++ for Windows, macOS, and Linux. It supports multiple V… | 96 | 1077 | active |
| ydkhatri/mac_apt mac_apt is a Python-based DFIR framework that parses macOS and iOS disk images or live systems to extract forensic artifacts like Safari hi… | 92 | 1077 | stable |
| semihalev/sdns SDNS is a high-performance recursive DNS resolver server written in Go, with DNSSEC validation and a privacy-first design supporting DNS-ov… | 100 | 1076 | active |
| AlephNullSK/dnsgen DNSGen is a Python CLI tool that generates intelligent permutations of domain names to aid subdomain discovery during security assessments.… | 32 | 1076 | active |
| hahwul/jwt-hack jwt-hack is a fast, single-binary Rust CLI toolkit for testing, analyzing, and attacking JSON Web Tokens (JWT) and JWE tokens. It supports … | 91 | 1075 | active |
| trailofbits/anamorpher Anamorpher is a tool for crafting and visualizing image scaling attacks that hide multi-modal prompt injections in images, revealed only wh… | 55 | 1075 | active |
| xiaogang000/XG_NTAI A Java-based GUI tool for generating obfuscated webshell payloads (ASP, PHP, JSP, JSPX) that evade WAF and antivirus detection, compatible … | 37 | 1075 | active |
| EchoHS/GeekezBrowser GeekEZ Browser is an anti-detect (fingerprint spoofing) browser built on Electron and Puppeteer with integrated Xray-core proxy support. It… | 83 | 1074 | active |
| apache/ranger Apache Ranger is a framework to enable, monitor, and manage comprehensive data security across the Hadoop platform and beyond. It provides … | 77 | 1074 | stable |
| lukaspieper/Gcam-Services-Provider A lightweight Android app that fakes only the minimal Google Play Services APIs required to run the Google Camera (Gcam) app on devices wit… | 70 | 1074 | active |
| knownsec/Kunyu Kunyu is a Python command-line tool for efficient corporate asset collection using cyberspace mapping engines like ZoomEye and Seebug. It h… | 25 | 1074 | active |
| qiwentaidi/Slack Slack is an integrated security services toolkit built with Go and the Wails desktop framework, bundling website fingerprinting and vulnera… | 78 | 1073 | active |
| Junyi-99/ChatGPT-API-Scanner A Python CLI tool that scans GitHub for publicly leaked OpenAI API keys using Selenium browser automation. It is intended for security rese… | 58 | 1073 | active |
| thehackingsage/hackdroid HackDroid is a curated collection of 364+ pentesting and security-related Android apps organized into categories like MITM, forensics, snif… | 32 | 1072 | active |
| tomnomnom/assetfinder A Go command-line tool that discovers domains and subdomains potentially related to a given domain by querying multiple passive sources lik… | 23 | 3666 | maintenance |
| borisbabic/browser_cookie3 A Python library (fork of browsercookie) that loads cookies from installed web browsers like Chrome, Firefox, Edge, Safari, and others into… | 23 | 1070 | active |
| mandiant/GoReSym GoReSym is a cross-platform CLI tool that extracts symbols, function metadata, types, and program metadata from Go binaries, including stri… | 91 | 1069 | active |
| rednblkx/HomeKey-ESP32 Firmware for ESP32 boards that implements Apple HomeKit lock functionality with support for Apple Home Key, enabling NFC-based door unlocki… | 79 | 1069 | active |
| nathanlopez/Stitch Stitch is a cross-platform Python Remote Administration Tool (RAT) framework for building custom payloads for Windows, macOS, and Linux. It… | 32 | 3660 | maintenance |
| immortalwrt/homeproxy HomeProxy is the modern proxy platform for ImmortalWrt (an OpenWrt fork), built on top of sing-box. It provides a LuCI web interface for ma… | 76 | 1068 | active |
| grapheneX/grapheneX grapheneX is an automated system hardening framework that secures Linux and Windows systems by running predefined hardening commands organi… | 27 | 1067 | active |
| LandGrey/pydictor pydictor is a Python-based wordlist (dictionary) builder for brute-force and dictionary attacks. It generates general, custom, and social-e… | 23 | 3650 | maintenance |
| broamski/aws-mfa aws-mfa is a Python CLI tool that automates obtaining temporary AWS credentials from the Security Token Service (STS) using MFA and writes … | 32 | 1066 | stable |
| mCodex/react-native-sensitive-info A React Native library for hardware-backed secure storage of sensitive data, using iOS Keychain and Android Keystore with AES-GCM encryptio… | 96 | 1065 | active |
| nonbili/Nora Nora is an open-source SNS browser for Android, iOS, and desktop that wraps social network websites (Facebook, Instagram, Reddit, Threads, … | 81 | 1065 | active |
| clr2of8/DPAT DPAT is a Python-based Domain Password Audit Tool for penetration testers that analyzes NTDS password dumps combined with cracking results … | 58 | 1065 | active |
| synacktiv/php_filter_chain_generator A Python CLI tool by Synacktiv that generates PHP filter chains (php://filter gadget chains) to achieve remote code execution when an attac… | 32 | 1065 | stable |
| salesforce/tough-cookie Tough Cookie is a Node.js library implementing RFC6265 (and RFC6265bis features like SameSite and cookie prefixes) for parsing, storing, an… | 87 | 1064 | active |
| espressif/esp-matter Espressif's official SDK for building Matter smart home products on ESP32 series SoCs. It wraps the open-source Matter SDK (connectedhomeip… | 77 | 1064 | active |
| QQBackup/qq-win-db-key A collection of Python and Frida scripts for extracting database encryption keys from QQ (Tencent's messenger) across Windows, Linux, macOS… | 72 | 1064 | active |
| un33k/django-ipware A Django application/library that retrieves the client's real IP address from request headers, handling proxies and load balancers with con… | 32 | 1064 | stable |
| margelo/react-native-quick-crypto A fast C/C++ JSI-based implementation of Node's crypto module for React Native, built on Nitro Modules. It serves as a drop-in replacement … | 98 | 1063 | active |
| rpgp/rpgp rPGP is a pure Rust implementation of OpenPGP (RFC9580, RFC4880, RFC6637) with a flexible low-level API, published as the `pgp` crate. It s… | 91 | 1063 | active |
| lico-n/ZygiskFrida A Zygisk (and Riru) module for rooted Android devices that injects the Frida gadget into application processes in a stealthy manner. It avo… | 52 | 1063 | active |
| N0rz3/Zehef Zehef is a Python command-line OSINT tool for investigating email addresses. It checks for pastes, data leaks, and linked social media acco… | 29 | 1062 | active |
| ZeroMemoryEx/Chaos-Rootkit Chaos-Rootkit is an x64 Ring 0 Windows kernel rootkit written in C++ as a research project to understand kernel internals and rootkit techn… | 58 | 1061 | active |
| cdxgen/cdxgen cdxgen is a CLI tool, library, and server that creates CycloneDX Bill of Materials (SBOM) documents from source code and container images, … | 95 | 1060 | active |
| ovh/debian-cis A set of modular shell scripts that audit and harden Debian 11/12/13 systems according to CIS security benchmarks, used in production at OV… | 78 | 1060 | active |
| itsreyi/BlockSuite Block-Suite is a modular JavaFX desktop application for authorized Minecraft server security assessments. It deploys a transparent MITM pro… | 67 | 1060 | active |
| bitsadmin/nopowershell NoPowerShell is a C# implementation of PowerShell-like commands that avoids using System.Management.Automation.dll, making execution invisi… | 59 | 1060 | active |
| ElevenPaths/FOCA FOCA is a Windows desktop application that finds metadata and hidden information in documents discovered via search engines (Google, Bing, … | 23 | 3622 | maintenance |
| lijiejie/subDomainsBrute A fast DNS subdomain brute-forcing tool for penetration testers, written in Python with multi-process and coroutine support. It enumerates … | 23 | 3621 | maintenance |
| proginosko/LeechBlockNG LeechBlock NG is a free browser extension for Firefox, Chrome, Edge, and other Chromium-based browsers that blocks time-wasting websites ac… | 93 | 1059 | active |
| duo-labs/py_webauthn A Python 3 library implementing the server-side of the WebAuthn API for verifying FIDO2 credential registration and authentication. It supp… | 88 | 1059 | active |
| lachlan2k/React2Shell-CVE-2025-55182-original-poc A collection of original proof-of-concept exploits for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server … | 41 | 1059 | active |
| darkk/redsocks redsocks is a transparent TCP-to-proxy redirector written in C that uses firewall rules (iptables, pf, ipfw) to redirect any TCP connection… | 32 | 3617 | maintenance |
| maciekish/iReSign iReSign is a macOS GUI application for signing or re-signing iOS .ipa app bundles with an Apple digital certificate, and for creating signe… | 32 | 3616 | maintenance |
| gopcua/opcua A native Go implementation of the OPC/UA Binary Protocol for industrial automation communication. It provides client and server functionali… | 97 | 1058 | active |
| chainreactors/spray Spray is a high-performance HTTP directory fuzzing and content discovery tool written in Go, positioned as a next-generation alternative to… | 93 | 1058 | active |
| DevLARLEY/WidevineProxy2 A browser extension (Chrome and Firefox, Manifest V3) that proxies Widevine and ClearKey EME challenges and license messages, modifying cha… | 86 | 1058 | active |
| hyugogirubato/KeyDive KeyDive is a Python CLI tool that extracts Widevine L3 DRM keys and device credentials from rooted Android devices using Frida instrumentat… | 80 | 1058 | active |
| YeeZTech/YeeZ-Privacy-Computing Fidelius is a privacy computing middleware built on Intel SGX trusted execution environments, enabling secure data collaboration where orig… | 69 | 1057 | active |
| Fahrj/reverse-ssh A statically-linked SSH server written in Go with reverse connection functionality, designed for remote access during CTFs, HackTheBox chal… | 65 | 1056 | active |
| shadowsocks/ChinaDNS ChinaDNS is a C-based local DNS server that prevents DNS poisoning by routing Chinese domain queries to local DNS servers and foreign domai… | 23 | 3606 | maintenance |
| madneal/gshark GShark is a self-hosted sensitive information detection and management platform that scans repositories exposed by providers like GitHub, G… | 100 | 1055 | active |
| farrokhi/dnsdiag A Python-based toolset for measuring, troubleshooting, and auditing DNS. It includes dnsping for latency measurement, dnstraceroute for tra… | 96 | 1055 | active |
| awa/go-iap go-iap is a Go library for verifying in-app purchase receipts across the Apple App Store, Google Play Store, Amazon AppStore, Huawei HMS, a… | 95 | 1055 | active |
| vigolium/vigolium Vigolium is a high-fidelity web vulnerability scanner written in Go that combines deterministic multi-phase scanning (317 modules for conte… | 82 | 1055 | active |
| SpotCompiled/SpotC-Plus-Plus SpotC++ is a repository of pre-compiled Spotify iOS IPA files that bundle tweaks like EeveeSpotify and Sposify to unlock premium features s… | 63 | 1055 | active |
| mwiede/jsch JSch (Java Secure Channel) is a pure Java implementation of the SSH2 protocol, maintained as an actively updated fork of the original JCraf… | 99 | 1054 | active |
| D0n9X1n/hexo-blog-encrypt A Hexo plugin that encrypts blog posts with passwords so only readers with the correct password can view the content. It works with the Hex… | 89 | 1054 | active |
| kort0881/telegram-proxy-collector A Python CLI tool that automatically collects, analyzes, and filters MTProto and SOCKS5 proxies for Telegram. It decodes proxy secrets to d… | 79 | 1054 | active |
| THU-BPM/MarkLLM MarkLLM is an open-source Python toolkit for watermarking large language model outputs, implementing multiple LLM watermarking algorithms w… | 65 | 1054 | active |
| ysrc/xunfeng Xunfeng is a self-hosted web application for rapid vulnerability emergency response and continuous scanning of enterprise internal networks… | 23 | 3597 | maintenance |
| endojs/endo Endo is a JavaScript framework for building secure plugin systems and resisting supply chain attacks, built on the SES (Secure ECMAScript) … | 95 | 1053 | stable |
| jjolano/shadow Shadow is a jailbreak detection bypass tweak for jailbroken iOS devices, hooking detection APIs so apps cannot detect the jailbreak. It sup… | 88 | 1053 | active |
| AmauriC/tarteaucitron.js tarteaucitron.js is an open-source, accessible GDPR consent management platform (CMP) that displays a cookie banner and per-service consent… | 92 | 1052 | stable |
| Cloxl/xhshow A pure-algorithm Python library that generates Xiaohongshu (XHS/RedNote) request signature headers such as x-s, x-s-common, x-t, and x-rap-… | 76 | 1052 | active |
| NetSPI/PowerHuntShares PowerHuntShares is a PowerShell audit tool that inventories, analyzes, and reports excessive privileges on SMB share ACLs across Active Dir… | 53 | 1052 | active |
| robotshell/magicRecon MagicRecon is a Bash shell script that automates reconnaissance and vulnerability scanning of target domains, including subdomain enumerati… | 23 | 1052 | active |
| cisco-ai-defense/mcp-scanner MCP Scanner is a Python tool and SDK from Cisco AI Defense that scans Model Context Protocol (MCP) servers, tools, prompts, and resources f… | 83 | 1051 | active |
| liujingxing/XmlClassGuard A Gradle plugin that obfuscates Android classes referenced in XML files, such as the four major components and custom Views, which ProGuard… | 23 | 1051 | active |
| projectdiscovery/cloudlist Cloudlist is a multi-cloud CLI tool written in Go that lists assets from multiple cloud providers such as AWS, GCP, and Azure. It is intend… | 89 | 1050 | active |
| apkunpacker/MagiskDetection A curated collection of publicly available proof-of-concept Android apps that detect root, Magisk, Zygisk, and hooking frameworks like Frid… | 68 | 1050 | active |
| 0xZDH/o365spray o365spray is a Python CLI tool for username enumeration and password spraying against Microsoft Office 365 domains. It implements multiple … | 32 | 1050 | active |
| smxiazi/NEW_xp_CAPTCHA xp_CAPTCHA is a Burp Suite extension (Java plugin) that automatically recognizes CAPTCHAs during brute-force attacks, using a companion Pyt… | 23 | 1050 | active |
| christiaangoossens/hass-oidc-auth A Home Assistant custom integration that adds OpenID Connect (OIDC) single sign-on authentication. It acts as a standards-compliant relying… | 99 | 1049 | active |
| TypeError/secure A lightweight, dependency-free Python library for defining and applying HTTP security headers across Python web frameworks via ASGI/WSGI mi… | 79 | 1049 | active |
| sunnisis/ixrail ixrail AgentPay is a VS Code extension that gives local AI agents a wallet, spending policy, authenticated broker, x402 payment flow, and s… | 67 | 1049 | active |
| lijiejie/GitHack GitHack is a Python CLI exploit tool that reconstructs a website's source code from an exposed .git folder. It parses the .git/index file, … | 32 | 3576 | maintenance |
| palantir/policy-bot policy-bot is a GitHub App that enforces configurable approval policies on pull requests by reporting a status check. It supports complex r… | 98 | 1048 | active |
| p0dalirius/smbclient-ng smbclient-ng is a Python command-line tool providing a fast, user-friendly interactive shell for interacting with SMB shares on remote Wind… | 82 | 1048 | active |
| PeterCxy/Shelter Shelter is a free and open-source Android app that uses the Work Profile feature to create an isolated space for installing or cloning apps… | 61 | 3575 | maintenance |