function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Ullaakut/nmap An idiomatic Go library that wraps the nmap network scanner by shelling out to the nmap binary and parsing its XML output. It lets Go devel… | 90 | 1047 | active |
| bountyyfi/lonkero Lonkero is a professional-grade web application security scanner written in Rust, built for real penetration testing with 125+ scan modules… | 73 | 1047 | active |
| Jacobtims/filament-breezy A Filament plugin for Laravel that adds enhanced security features to Filament admin panels, including a customizable profile page, two-fac… | 97 | 1046 | active |
| secureblue/secureblue secureblue is a security-focused desktop and server Linux operating system built as OCI bootable container images on top of Fedora Atomic D… | 91 | 1046 | active |
| xm1k3/cent Cent is a Go CLI tool that aggregates and organizes community-contributed Nuclei vulnerability scanning templates into a single local folde… | 81 | 1046 | active |
| wh201906/Proxmark3GUI A cross-platform Qt5 graphical interface for the Proxmark3 RFID research tool, wrapping the official and Iceman fork clients. It provides a… | 57 | 1046 | active |
| paradiseduo/appdecrypt A Swift CLI tool that decrypts FairPlay-encrypted Mach-O application binaries on macOS (SIP-enabled, macOS 11.3 or below, with newer suppor… | 56 | 1046 | active |
| ac3ss0r/obfusheader.h Obfusheader.h is a portable, header-only C++14 library providing compile-time obfuscation via metaprogramming, including string and constan… | 27 | 1046 | active |
| chris1111/Wireless-USB-Big-Sur-Adapter A macOS installer package providing drivers for Realtek 802.11n and 802.11ac USB Wi-Fi adapters, distributed as prebuilt binaries with no s… | 62 | 1045 | active |
| jonrau1/ElectricEye ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for asset management, security posture management, and attack surface monitoring. … | 62 | 1045 | active |
| apple/security-pcc Apple's source code for Private Cloud Compute (PCC), the infrastructure that runs Apple Intelligence requests in a privacy-preserving cloud… | 59 | 1043 | active |
| splx-ai/agentic-radar Agentic Radar is an open-source security scanner that analyzes LLM agentic workflows built with popular frameworks (e.g., CrewAI, LangGraph… | 53 | 1043 | active |
| smoochiee/Bluetooth-jammer-esp32 An ESP32 firmware project that uses NRF24L01 radio modules to generate 2.4GHz noise signals that jam Bluetooth and WiFi devices. It include… | 10 | 1043 | active |
| amlweems/xzbot A research toolkit for the xz backdoor (CVE-2024-3094) containing an OpenSSH honeypot patch to detect exploit attempts, a patch script to r… | 25 | 3554 | maintenance |
| kelvinBen/AppInfoScanner A Python-based static information-gathering scanner for mobile apps (Android APK/DEX, iOS IPA/Mach-O) and static web content (HTML, JS, H5)… | 23 | 3554 | maintenance |
| brichard19/BitCrack BitCrack is a C++ command-line tool for brute-forcing Bitcoin private keys using CUDA (NVIDIA) or OpenCL (AMD/Intel) GPU acceleration. It w… | 23 | 1042 | active |
| buffer/thug Thug is a Python low-interaction honeyclient that mimics the behavior of a web browser to detect and emulate malicious web content. It comp… | 87 | 1041 | active |
| PhonePe/mantis Mantis is a command-line security framework that automates asset discovery, reconnaissance, and vulnerability scanning for given top-level … | 67 | 1039 | active |
| topjohnwu/zygisk-module-sample An official template repository by the Magisk author for building Zygisk modules, which inject code into Android's Zygote process. It inclu… | 10 | 1039 | stable |
| Anorov/cloudflare-scrape A Python module (cfscrape) built on Requests that bypasses Cloudflare's JavaScript anti-bot challenge page ('I'm Under Attack Mode') so scr… | 23 | 3538 | maintenance |
| firewalld/firewalld firewalld is a dynamically managed firewall daemon for Linux that provides zone-based trust levels for network connections and interfaces, … | 97 | 1037 | stable |
| bnb-chain/tss-lib A Go library implementing multi-party threshold signature schemes (TSS) for ECDSA and EdDSA, based on the Gennaro-Goldfeder CCS 2018 protoc… | 70 | 1037 | active |
| exein-io/pulsar Pulsar is a modular, eBPF-powered runtime security and observability tool for Linux devices, written in Rust and designed for IoT and edge … | 48 | 1037 | active |
| dyc3/steamguard-cli A Rust command-line utility for setting up and using Steam Mobile Authenticator (2FA). It generates Steam Guard codes and handles trade, ma… | 93 | 1036 | active |
| nickvourd/Supernova Supernova is an open-source command-line tool written in Go for encrypting and obfuscating raw shellcode. It supports multiple ciphers incl… | 87 | 1036 | active |
| bszapp/android-wifi-pojie An Android WiFi toolbox app written in Kotlin that brute-forces WiFi passwords using password dictionaries, supporting multiple run modes (… | 73 | 1036 | active |
| TheRook/subbrute SubBrute is a Python DNS meta-query spider that enumerates subdomains and arbitrary DNS record types by leveraging open resolvers to bypass… | 23 | 3526 | maintenance |
| vanhoefm/krackattacks-scripts Scripts by Mathy Vanhoef to test whether Wi-Fi clients or access points are vulnerable to the KRACK attack against WPA2. They include a mod… | 23 | 3524 | maintenance |
| cdklabs/cdk-nag cdk-nag is a library that checks AWS CDK applications and CloudFormation templates for best practices using pre-built rule packs such as AW… | 94 | 1035 | active |
| django-recaptcha/django-recaptcha A Django app providing form fields and widgets for integrating Google reCAPTCHA (v2 checkbox, v2 invisible, and v3) into Django forms. It h… | 67 | 1035 | active |
| DrJonaC/Pensieve Pensieve is a local-first dashboard for visualizing, interpreting, and governing the structured memory that LLMs keep about users. It expos… | 57 | 1035 | active |
| zhzyker/vulmap Vulmap is a Python 3 command-line tool that scans web applications for known CVE vulnerabilities and can immediately verify or exploit them… | 23 | 3521 | maintenance |
| Velocidex/WinPmem WinPmem is an open-source Windows physical memory acquisition tool with a signed kernel driver and standalone imager executables. It dumps … | 44 | 1034 | active |
| aaugustin/django-sesame django-sesame is a Python library that adds 'Magic Links' authentication to Django projects by generating URLs containing signed authentica… | 59 | 1033 | active |
| in-toto/in-toto in-toto is a Python framework and reference implementation of the in-toto specification for protecting software supply chain integrity. It … | 81 | 1032 | stable |
| carlospolop/legion Legion is a Python-based automatic enumeration tool that orchestrates well-known open-source pentesting tools (nmap, hydra, metasploit) to … | 74 | 1032 | active |
| mitmproxy/android-unpinner A Python CLI tool that removes certificate pinning from Android APKs so traffic can be intercepted with mitmproxy, without requiring a root… | 54 | 1032 | active |
| EdgeSecurityTeam/EHole EHole (棱洞) is a Go-based fingerprint identification tool for red team reconnaissance that pinpoints high-value, easily attackable systems (… | 23 | 3511 | maintenance |
| TurboVNC/turbovnc TurboVNC is a high-performance VNC (Virtual Network Computing) remote display system derived from TightVNC, with a tuned Tight encoding opt… | 90 | 1031 | stable |
| square/certigo Certigo is a Go command-line utility for examining, dumping, and validating TLS/SSL certificates in formats like X.509 (DER/PEM), PKCS7, PK… | 73 | 1031 | stable |
| kyleavery/AceLdr AceLdr is a position-independent reflective loader (UDRL) for Cobalt Strike written in C, designed to evade memory scanners like Moneta, PE… | 23 | 1031 | active |
| hoo-dles/morphe-patches A collection of patches for the Morphe patcher that modify Android apps, such as unlocking premium features, skipping ads, and disabling te… | 83 | 1030 | active |
| googlesamples/android-testdpc Test DPC is a sample Device Policy Controller app for Android Enterprise that lets developers test how their apps behave in managed context… | 52 | 1030 | active |
| Exodus-Privacy/exodus-android-app The εxodus Android app shows which trackers are embedded in the apps installed on your smartphone and lists the permissions each app requir… | 47 | 1030 | active |
| Vuemony/vue-after-free A PlayStation 4 userland code execution exploit delivered through the PlayStation Vue app, chained with kernel exploits (Lapse, Poopsploit/… | 67 | 1029 | active |
| google/fscrypt fscrypt is a Go command-line tool for managing Linux native filesystem encryption (fscrypt API) on filesystems like ext4 and f2fs. It handl… | 88 | 1028 | active |
| Trow-Registry/trow Trow is a lightweight OCI-compliant container image registry written in Rust that runs inside a Kubernetes cluster. It caches external imag… | 77 | 1028 | active |
| X1Plus/X1Plus X1Plus is custom open-source firmware for Bambu Lab X1 and X1 Carbon 3D printers, replacing the stock firmware with extended features and c… | 63 | 1028 | active |
| a16z/halmos Halmos is a symbolic testing tool for EVM smart contracts, primarily targeting Solidity projects via a Foundry frontend. It leverages exist… | 50 | 1028 | active |
| karasevm/PrivateDNSAndroid An Android app that adds a quick settings tile for switching the active private DNS (DNS-over-TLS) provider with a single tap. It supports … | 69 | 1027 | active |
| k3yomi/Wall-of-Flippers Wall of Flippers is a Python-based tool for discovering Flipper Zero devices and detecting Bluetooth Low Energy based attacks. It provides … | 57 | 1027 | active |
| osohq/oso Oso is an embedded authorization framework with a declarative policy language (Polar) for building RBAC, relationships, and collection filt… | 26 | 3491 | maintenance |
| carcabot/tiktok-signature A self-hosted Node.js service that generates valid X-Bogus and X-Gnarly signature tokens for TikTok API requests using a headless browser r… | 93 | 1025 | active |
| esig/dss DSS (Digital Signature Service) is an open-source Java library from the European Commission for creating, extending, and validating advance… | 85 | 1025 | stable |
| GrapheneOS/PdfViewer A minimal, permission-free Android PDF viewer built on pdf.js and content providers, developed by the GrapheneOS project. It renders PDFs i… | 98 | 1024 | active |
| krzyzanowskim/OpenSSL A multiplatform distribution of the OpenSSL C libraries packaged for Swift Package Manager, CocoaPods, and Carthage, targeting iOS, macOS (… | 92 | 1023 | active |
| dvsekhvalnov/jose-jwt A zero-dependency .NET library implementing the full JOSE suite: JWT generation/decoding, JWE encryption, JWS signatures, and JWK key handl… | 72 | 1023 | active |
| ncopa/su-exec su-exec is a tiny C utility that switches user and group id and directly execs a program, avoiding the TTY and signal issues of su/sudo chi… | 47 | 1023 | stable |
| openmls/openmls OpenMLS is a Rust implementation of the Messaging Layer Security (MLS) protocol as specified in RFC 9420. It is a library providing safe, e… | 95 | 1022 | active |
| net-ssh/net-ssh Net::SSH is a pure-Ruby implementation of the SSH2 client protocol, packaged as a Ruby gem. It lets Ruby programs open SSH connections to r… | 75 | 1022 | active |
| SafeAI-Lab-X/ClawKeeper ClawKeeper is a host-agnostic safety middleware layer that sits between AI agents and their tools, blocking risky tool calls, redacting sen… | 59 | 1022 | active |
| ferredoxin/QNotified QNotified is an open-source Xposed module that enhances the QQ/TIM Android messaging apps with dozens of quality-of-life tweaks. It adds fe… | 10 | 3469 | maintenance |
| AsjadOooO/Zero-attacker Zero-attacker is a multipurpose Python-based hacking toolkit bundling 15+ tools for ethical hacking and Discord operations, including DDoS,… | 45 | 1021 | active |
| jpr5/ngrep ngrep is a PCAP-based command-line tool that applies GNU grep-style regular or hexadecimal expression matching to network packet payloads. … | 74 | 1020 | active |
| Dheerajmadhukar/karma_v2 karma_v2 is a Bash-based passive OSINT reconnaissance framework that automates Shodan queries to enumerate assets, exposed services, CVEs, … | 42 | 1020 | active |
| Olsro/ipodclickwheelgamespreservationproject A preservation project distributing authenticated iPod Clickwheel games for iPod Nano 3G-5G and iPod Classic 5G-7G via a preconfigured Wind… | 48 | 1018 | active |
| AKCodez/hackingtool-plugin A Claude Code plugin that wraps 183+ pentesting and OSINT tools from Z4nzu/hackingtool, letting Claude automatically select and run securit… | 50 | 1016 | active |
| techchipnet/hound Hound is a lightweight PHP-based information gathering tool that captures a target device's exact GPS coordinates along with system and ISP… | 30 | 1016 | active |
| mikehaertl/php-pdftk A PHP library wrapping the pdftk command-line tool to fill PDF forms, merge/split PDFs, and manage passwords and metadata. It converts betw… | 94 | 1015 | active |
| Spade-sec/First A WeChat mini-program security debugging tool (fork/extension of WMPFDebugger) that uses Frida injection and Chrome DevTools Protocol bridg… | 74 | 1015 | active |
| redcode-labs/neurax Neurax is a Go framework for constructing self-spreading binaries (worms) that propagate across LAN/WAN networks without external servers. … | 32 | 1015 | active |
| secretsquirrel/the-backdoor-factory The Backdoor Factory (BDF) is a Python command-line tool that patches Windows PE, Linux ELF, and macOS Mach-O executables with user-supplie… | 32 | 3439 | maintenance |
| Aizistral-Studios/No-Chat-Reports A Minecraft mod that strips cryptographic signatures from chat messages and disables the Player Chat Reporting system introduced in Minecra… | 67 | 1013 | active |
| CityOfZion/neon-wallet Neon Wallet is an Electron-based desktop light wallet for the NEO blockchain, supporting wallet creation, Ledger hardware login, NEP6 accou… | 35 | 1013 | active |
| google/go-licenses A Go CLI tool that analyzes a Go package's dependency tree and reports the licenses of all libraries used, with versioned URLs to each lice… | 77 | 1012 | active |
| Browserpass Browserpass is a browser extension for zx2c4's pass (the UNIX password store) that auto-fills or copies credentials for the current domain,… | 85 | 1011 | active |
| aflnet/aflnet AFLNet is a greybox fuzzer for network protocol server implementations, extending American Fuzzy Lop with state-feedback derived from serve… | 43 | 1011 | active |
| greatscottgadgets/facedancer A Python library for emulating USB devices using hardware peripherals like Cynthion or GreatFET. It also supports MITM proxying of USB conn… | 83 | 1010 | active |
| BruceWind/AESJniEncrypt An Android NDK library that implements ChaCha20-Poly1305 encryption via libsodium, with keys hidden in native code to resist reverse engine… | 23 | 1010 | active |
| fullhunt/log4j-scan A Python-based automated scanner for detecting the Log4j RCE vulnerability (CVE-2021-44228, Log4Shell) and related CVEs across lists of URL… | 23 | 3422 | maintenance |
| indetectables-net/toolkit A curated Windows toolkit bundling 101 applications for reverse engineering, malware analysis, and cracking, installed via an automated Inn… | 89 | 1009 | active |
| 0x6rss/matkap Matkap is a self-hosted web application for hunting malicious Telegram bots used as malware command-and-control infrastructure. It validate… | 65 | 1008 | active |
| Sustainsys/Saml2 Sustainsys.Saml2 is a C# library that adds SAML2P support to ASP.NET applications, letting a web site act as a SAML2 Service Provider for s… | 60 | 1008 | active |
| JackJuly/linkook Linkook is a Python-based OSINT command-line tool that discovers linked social media accounts and associated email addresses across multipl… | 53 | 1008 | active |
| tarunkant/Gopherus Gopherus is a Python CLI tool that generates Gopher protocol payloads for exploiting SSRF vulnerabilities to achieve remote code execution.… | 32 | 3411 | maintenance |
| AthenZ/athenz Athenz is an open source platform for X.509 certificate-based service authentication and fine-grained role-based access control (RBAC) in d… | 100 | 1006 | active |
| dedsec1121fk/DedSec DedSec Project is an educational cybersecurity and Termux toolkit for Android that bundles scripts, utilities, local web interfaces, and pr… | 88 | 1005 | active |
| cdimascio/express-openapi-validator An Express middleware library that automatically validates API requests, responses, and security against an OpenAPI 3.0.x or 3.1.x specific… | 88 | 1005 | active |
| akaunting/laravel-firewall A Web Application Firewall (WAF) package for Laravel that protects applications from attacks like XSS, SQLi, RFI, LFI, and malicious user a… | 75 | 1005 | active |
| RuoJi6/audit-skills A lightweight Claude/Codex skill package for AI-assisted source code security auditing, covering Java, .NET, and PHP. It provides vulnerabi… | 73 | 1005 | active |
| ki9mu/ARL-plus-docker A Docker-based fork of ARL (Asset Reconnaissance Lighthouse) v2.6.2 that performs automated asset discovery and vulnerability scanning for … | 35 | 1005 | active |
| libreswan/libreswan Libreswan is a free, GPLv2-licensed implementation of the Internet Key Exchange (IKE) protocol for setting up IPsec VPNs, supporting IKEv1 … | 99 | 1004 | active |
| microsoft/DevSkim DevSkim is a Microsoft security linting framework consisting of IDE extensions, a .NET CLI, and a rule engine that flags security issues in… | 98 | 1004 | active |
| Tencent/TencentKona-8 Tencent Kona 8 is a no-cost, production-ready distribution of OpenJDK 8 with long-term support and quarterly updates, serving as the defaul… | 92 | 1004 | stable |
| d78ui98/APKDeepLens APKDeepLens is a Python-based static analysis tool that decompiles Android APK files with JADX and scans them for security vulnerabilities … | 64 | 1004 | active |
| odedshimon/BruteShark BruteShark is an open-source Network Forensic Analysis Tool (NFAT) that deeply inspects network traffic from PCAP/PCAPng files or live capt… | 23 | 3395 | maintenance |
| controlplaneio/simulator A distributed systems and infrastructure security training platform that provisions a Kubernetes cluster in your AWS account and runs scena… | 23 | 1000 | active |
| linkedin/qark QARK (Quick Android Review Kit) is a Python command-line tool from LinkedIn that scans Android applications, either as Java source code or … | 23 | 3382 | maintenance |
| noraj/haiti Haiti is a CLI tool and Ruby library that identifies hash types, detecting 675+ hash formats including modern algorithms like SHA3, Keccak,… | 76 | 999 | active |
| ullmark/hashids.net A small .NET (C#) library that encodes integers into short, YouTube-like reversible string IDs (e.g. 347 -> yr8) and decodes them back, wit… | 32 | 3354 | maintenance |