function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| pwnlandia/mhn Modern Honey Network (MHN) is a centralized Flask-based server for managing honeypot sensors and collecting their attack data. It exposes a… | 32 | 2464 | maintenance |
| zerodytrash/Simple-YouTube-Age-Restriction-Bypass A browser extension and userscript that bypasses YouTube's age verification, letting users watch age-restricted videos without signing in. … | 30 | 2462 | maintenance |
| RootMyTV/RootMyTV.github.io RootMyTV is a user-friendly browser-based exploit for rooting/jailbreaking LG webOS smart TVs, leveraging CVE-2022-23727 and CVE-2020-9759.… | 23 | 2433 | maintenance |
| sans-blue-team/DeepBlueCLI DeepBlueCLI is a PowerShell module for threat hunting that analyzes Windows Event Logs (Security, System, Application, PowerShell, Sysmon) … | 32 | 2429 | maintenance |
| screetsec/Sudomy Sudomy is a Bash-based subdomain enumeration and reconnaissance framework that collects subdomains via active brute-forcing and passive thi… | 23 | 2429 | maintenance |
| Chora10/Cknife Cknife (China Chopper Knife) is a Java-based cross-platform webshell management tool, an open-source client compatible with the China Chopp… | 32 | 2422 | maintenance |
| secretsquirrel/SigThief SigThief is a Python CLI tool that rips the Authenticode signature off a signed PE file and appends it to another binary, patching the cert… | 32 | 2420 | maintenance |
| robotmedia/RMStore RMStore is a lightweight iOS library that wraps Apple's StoreKit framework for In-App Purchases. It adds block-based APIs, notifications, r… | 23 | 2411 | maintenance |
| knownsec/ksubdomain ksubdomain is a stateless subdomain enumeration tool written in Go that performs extremely fast DNS brute-forcing by separating packet send… | 23 | 2393 | maintenance |
| besimorhino/powercat powercat is a PowerShell reimplementation of netcat supporting TCP, UDP, and DNS (dnscat2) connections, file transfer, and shell serving. I… | 32 | 2389 | maintenance |
| solokeys/solo1 Solo 1 is the open-source C firmware for the Solo security key, implementing FIDO2 (CTAP2) and U2F (CTAP) over USB and NFC on an STM32L432 … | 23 | 2382 | maintenance |
| FiloSottile/Heartbleed A command-line tool and former web service for detecting the Heartbleed vulnerability (CVE-2014-0160) in TLS servers. Written in Go, it tes… | 32 | 2380 | maintenance |
| tr0uble-mAker/POC-bomber POC-bomber is a Python-based offensive security tool that bundles a large arsenal of high-impact POCs and EXPs (RCE, deserialization, file … | 23 | 2368 | maintenance |
| dana-at-cp/backdoor-apk A shell script that automates injecting a Metasploit backdoor payload into any Android APK by decompiling, hooking smali code, and re-signi… | 32 | 2366 | maintenance |
| Cocos-BCX/cocos-bcx-node-bin Binary executables for the Cocos-BCX blockchain, including a full node (witness_node) and a CLI wallet client. It ships prebuilt binaries p… | 32 | 2349 | maintenance |
| byt3bl33d3r/SILENTTRINITY SILENTTRINITY is an asynchronous, multiplayer and multiserver C2/post-exploitation framework built with Python 3 and .NET's DLR. It uses em… | 32 | 2341 | maintenance |
| flyzy2005/ss-fly A set of one-click shell scripts to install and configure Shadowsocks (SS/SSR) proxy servers on Ubuntu, CentOS, and Debian, with optional B… | 32 | 2341 | maintenance |
| bugcrowd/HUNT HUNT Suite is a collection of Burp Suite and OWASP ZAP proxy extensions that identify common parameters vulnerable to vulnerability classes… | 67 | 2333 | maintenance |
| noob-hackers/mrphish mrphish is a Bash-based Termux script that hosts fake social media login pages (60+ templates) with port forwarding via ngrok and OTP bypas… | 50 | 2328 | maintenance |
| Hax4us/TermuxBlack TermuXBlacK is an unofficial third-party APT repository for Termux on Android that packages hacking and penetration-testing tools not avail… | 32 | 2328 | maintenance |
| PHPGangsta/GoogleAuthenticator A PHP library implementing TOTP (RFC 6238) for Google Authenticator two-factor authentication. It generates secrets and codes, verifies cod… | 23 | 2328 | maintenance |
| sensepost/ruler Ruler is a Go-based command-line tool for interacting with and abusing Microsoft Exchange servers via MAPI/HTTP or RPC/HTTP. It enables off… | 23 | 2313 | maintenance |
| xtr4nge/FruityWifi FruityWiFi is an open-source wireless network auditing tool with a web-based control panel for deploying advanced WiFi attacks. It is modul… | 23 | 2278 | maintenance |
| inconshreveable/go-update A Go library that lets programs update themselves by safely replacing their own executable file with a new version. It supports checksum ve… | 32 | 2273 | maintenance |
| topotam/PetitPotam PetitPotam is a proof-of-concept tool that coerces Windows hosts to authenticate to attacker-controlled machines via the MS-EFSRPC protocol… | 32 | 2270 | maintenance |
| itm4n/PrintSpoofer PrintSpoofer is a Windows privilege escalation tool that abuses SeImpersonatePrivilege via the Print Spooler 'Printer Bug' to escalate from… | 10 | 2268 | maintenance |
| davidprowe/BadBlood BadBlood is a PowerShell tool that populates a Microsoft Active Directory domain with thousands of randomized users, groups, computers, and… | 32 | 2267 | maintenance |
| rabbitmask/WeblogicScan A one-click Python vulnerability scanner for Oracle WebLogic servers, covering nearly all historical WebLogic CVEs (SSRF, Java deserializat… | 32 | 2260 | maintenance |
| worawit/MS17-010 A collection of Python exploit scripts and proof-of-concepts for the MS17-010 Windows SMB vulnerabilities, including Eternalblue, Eternalch… | 32 | 2260 | maintenance |
| outflanknl/EvilClippy Evil Clippy is a cross-platform C# command-line assistant for crafting malicious MS Office documents with hidden or stomped VBA macros. It … | 32 | 2257 | maintenance |
| ldpreload/BlackLotus An open-source UEFI bootkit targeting Windows that implements a Secure Boot bypass, kernel-level persistence, and an HTTP-based C2 loader w… | 29 | 2243 | maintenance |
| shmilylty/netspy netspy is a fast, cross-platform Go CLI tool for discovering reachable intranet network segments from a compromised host. It supports ICMP,… | 23 | 2238 | maintenance |
| Ascotbe/Medusa Medusa is a self-hosted red team arsenal platform written in Python that bundles tools such as an XSS platform, collaborative platform, CVE… | 23 | 2235 | maintenance |
| abba23/spotify-adblock A Spotify adblocker for Linux implemented as a shared library that wraps cef_urlrequest_create and blocks requests to denylisted URLs via L… | 93 | 2230 | maintenance |
| jackspirou/clientjs ClientJS is a pure JavaScript library for browser device fingerprinting and device information gathering. It generates a 32-bit integer fin… | 23 | 2229 | maintenance |
| asLody/SandHook SandHook is an Android ART runtime hooking library supporting Java method hooks and native inline hooks on Android 4.4 through 11.0 for bot… | 23 | 2229 | maintenance |
| evilcos/xssor2 XSS'OR is a self-hostable web application for penetration testers that provides XSS/CSRF payload generation, encoding/decoding utilities, a… | 32 | 2222 | maintenance |
| HatBoy/Struts2-Scan A Python CLI tool that scans and exploits known Apache Struts2 vulnerabilities (S2-001 through S2-057) using publicly disclosed exploits. I… | 32 | 2220 | maintenance |
| zendesk/cross-storage A JavaScript library enabling cross-domain local storage sharing with per-origin permissions. It uses a hub-and-client architecture with em… | 48 | 2219 | maintenance |
| diafygi/gethttpsforfree A browser-based web application (source for gethttpsforfree.com) that walks users through obtaining free TLS certificates from Let's Encryp… | 44 | 2215 | maintenance |
| M2TeamArchived/NSudo NSudo is a Windows system administration toolkit whose launcher lets users run programs with TrustedInstaller, SYSTEM, or elevated user tok… | 10 | 2208 | maintenance |
| wulabing/V2Ray_ws-tls_bash_onekey A one-click bash installation script that deploys a V2Ray proxy server with VMess/VLESS over WebSocket + TLS, fronted by Nginx with automat… | 32 | 2207 | maintenance |
| LionSec/xerosploit Xerosploit is a Ruby-based penetration testing toolkit that wraps bettercap and nmap to perform man-in-the-middle attacks, port scanning, a… | 23 | 2201 | maintenance |
| thehackingsage/hacktronian Hacktronian is a Python-based, menu-driven collection of penetration testing tools that bundles popular utilities for information gathering… | 32 | 2198 | maintenance |
| codingo/Reconnoitre Reconnoitre is a Python CLI tool for multithreaded information gathering and service enumeration of target hosts and ranges, built original… | 23 | 2195 | maintenance |
| SystemRage/py-kms py-kms is a Python-based KMS (Key Management Service) server emulator that responds to v4, v5, and v6 KMS requests to activate volume-licen… | 32 | 2191 | maintenance |
| iamj0ker/bypass-403 A shell script that attempts to bypass HTTP 403 Forbidden responses using 24 known bypass techniques via curl. It also compares responses u… | 32 | 2190 | maintenance |
| SimonBrazell/privacy-redirect A browser extension that redirects requests to Twitter, YouTube, Instagram, Google Maps, Reddit, Google Search, and Google Translate to pri… | 10 | 2190 | maintenance |
| peewpw/Invoke-PSImage Invoke-PSImage is a PowerShell tool that encodes a PowerShell script into the pixels of a PNG image using steganography, then generates a o… | 32 | 2188 | maintenance |
| Quip Network Quip Network SDK is a TypeScript SDK plus a set of EVM smart contracts (Deployer, WOTSPlus, QuipFactory) for interacting with the Quip Netw… | 63 | 11346 | experimental |
| IAmBlackHacker/Facebook-BruteForce A Python script that performs brute-force password attacks against Facebook accounts using wordlists, intended for educational purposes. It… | 23 | 2184 | maintenance |
| hexway/apple_bleee A collection of experimental Python PoC scripts for sniffing and injecting Apple Bluetooth Low Energy (BLE) and AWDL (AirDrop) traffic. It … | 23 | 2184 | maintenance |
| bats3c/shad0w SHAD0W is a modular post-exploitation C2 (command and control) framework written in Python and C, designed to operate covertly in heavily m… | 23 | 2176 | maintenance |
| emersion/hydroxide Hydroxide is a third-party, open-source ProtonMail bridge written in Go that translates standard protocols (IMAP, SMTP, CardDAV) into Proto… | 10 | 2175 | maintenance |
| CedArctic/DigiSpark-Scripts A collection of hand-written Arduino IDE sketches for the DigiSpark ATtiny85 board that turn it into a USB HID keyboard for executing autom… | 32 | 2172 | maintenance |
| Dliv3/Venom Venom is a multi-hop proxy tool written in Go for penetration testers, connecting multiple nodes to build chained proxies through internal … | 23 | 2165 | maintenance |
| praetorian-inc/gokart GoKart is a static analysis (SAST) tool for Go that detects vulnerabilities using SSA-form source-to-sink taint tracing. It reduces false p… | 10 | 2157 | maintenance |
| noob-hackers/ipdrone Ipdrone is a simple Python script for IP lookup that retrieves information about a target IP address, including live location with address … | 32 | 2149 | maintenance |
| FeeiCN/GSIL GSIL is a Python tool that monitors GitHub for sensitive information leaks, such as leaked credentials, internal domains, and proprietary c… | 10 | 2146 | maintenance |
| hmaverickadams/breach-parse Breach-Parse is a shell-based command-line tool for searching breached password compilations (like the BreachCompilation torrent) for crede… | 32 | 2143 | maintenance |
| anouarbensaad/vulnx VulnX is a Python CLI tool that detects CMS types (WordPress, Joomla, Drupal, etc.), gathers target information like subdomains and DNS rec… | 23 | 2143 | maintenance |
| Kkevsterrr/geneva Geneva is a research tool from the University of Maryland that uses a genetic algorithm to automatically evolve packet-manipulation strateg… | 32 | 2142 | maintenance |
| noob-hackers/ighack A bash-based Termux script that attempts to brute-force Instagram account passwords using wordlists, routing traffic through Tor for anonym… | 50 | 2141 | maintenance |
| D4Vinci/Cr3dOv3r Cr3dOv3r is a Python command-line pentesting tool for investigating credential reuse attacks. Given an email, it searches public breach dat… | 57 | 2136 | maintenance |
| skavngr/rapidscan RapidScan is a Python CLI tool that automates web vulnerability scanning by orchestrating multiple security tools (nmap, nikto, wafw00f, ss… | 23 | 2130 | maintenance |
| greatscottgadgets/ubertooth Ubertooth is an open source wireless development platform for Bluetooth experimentation, providing host software, firmware, and hardware de… | 56 | 2127 | maintenance |
| UnaPibaGeek/ctfr CTFR is a Python command-line tool that enumerates HTTPS website subdomains by querying Certificate Transparency logs (via crt.sh) instead … | 32 | 2117 | maintenance |
| quericy/one-key-ikev2-vpn A one-click bash script that installs and configures an IKEv2/L2TP VPN server using strongSwan on Ubuntu, CentOS, or Debian. It handles cer… | 32 | 2106 | maintenance |
| firmadyne/firmadyne FIRMADYNE is an automated, scalable platform for emulating and dynamically analyzing Linux-based embedded firmware using QEMU with instrume… | 32 | 2105 | maintenance |
| s0md3v/ReconDog ReconDog is a Python-based reconnaissance 'Swiss Army Knife' that gathers information about targets (domains, IPs) using third-party APIs l… | 23 | 2104 | maintenance |
| TideSec/WDScanner WDScanner is a self-hosted distributed web vulnerability scanning platform written in PHP with Python backend workers. It combines customer… | 32 | 2099 | maintenance |
| hlandau/acmetool acmetool is a command-line tool for automatically acquiring and renewing TLS certificates from ACME servers such as Let's Encrypt. It works… | 23 | 2092 | maintenance |
| TideSec/TideFinger TideFinger is a Python web fingerprinting tool that merges rule sets from multiple open-source fingerprint databases (Wappalyzer, webanalyz… | 32 | 2087 | maintenance |
| dafthack/DomainPasswordSpray DomainPasswordSpray is a PowerShell tool that performs password spray attacks against domain user accounts, automatically generating a user… | 32 | 2086 | maintenance |
| gurnec/HashCheck HashCheck is a Windows Explorer shell extension that lets users verify and generate file checksums (MD5, SHA-1, SHA-2, SHA-3, and more) dir… | 23 | 2078 | maintenance |
| 0xn0ne/weblogicScanner A Python CLI vulnerability scanner for Oracle WebLogic servers that detects a wide range of known CVEs (2014-2020), including deserializati… | 32 | 2075 | maintenance |
| moxie0/sslstrip sslstrip is a Python command-line tool that implements Moxie Marlinspike's SSL stripping man-in-the-middle attack, downgrading HTTPS links … | 32 | 2074 | maintenance |
| Aabyss-Team/ARL ARL (Asset Reconnaissance Lighthouse) is a self-hosted asset reconnaissance system that quickly discovers internet-facing assets associated… | 29 | 2066 | maintenance |
| JKornev/hidden A Windows kernel driver with a usermode library and CLI that can hide processes, files, directories, and registry keys, and protect process… | 23 | 2053 | maintenance |
| yzddmr6/WebCrack WebCrack is a Python CLI tool for batch detection of weak passwords and universal-password (SQL injection bypass) vulnerabilities on web ad… | 32 | 2048 | maintenance |
| jtblin/kube2iam kube2iam is a Kubernetes daemonset that intercepts traffic to the EC2 metadata API and returns per-pod AWS IAM credentials based on pod ann… | 85 | 2042 | maintenance |
| Cyb0r9/SocialBox SocialBox is a shell-based brute-force attack framework targeting Facebook, Gmail, Instagram, and Twitter login forms. It is a penetration-… | 32 | 2042 | maintenance |
| alibaba/LVS Alibaba's distribution of Linux Virtual Server (LVS) adding advanced features to the kernel IPVS load balancer. It introduces the FULLNAT p… | 32 | 2042 | maintenance |
| wszf/androrat AndroRAT is a remote administration tool (RAT) for Android built as a client/server pair: an Android client that runs as a boot-started bac… | 32 | 2039 | maintenance |
| pfn/keepasshttp KeePassHttp is a plugin for KeePass 2.x that exposes password entries securely over HTTP using 256-bit AES/CBC encryption. It is designed t… | 32 | 2038 | maintenance |
| es3n1n/no-defender A Windows CLI tool that disables Windows Defender and the firewall by registering a fake antivirus through the undocumented Windows Securit… | 10 | 2038 | maintenance |
| compound-finance/compound-protocol The Compound Protocol is an Ethereum smart contract system for decentralized lending and borrowing of crypto assets. Accounts supply Ether … | 23 | 2036 | maintenance |
| 0xbug/Hawkeye Hawkeye is a self-hosted system that monitors GitHub for leaked sensitive information, such as employees pushing company code or credential… | 23 | 2034 | maintenance |
| c0ny1/chunked-coding-converter A Burp Suite extension written in Java that converts HTTP request bodies to chunked transfer encoding, including delayed (sleep) chunking, … | 23 | 2028 | maintenance |
| fin3ss3g0d/evilgophish evilgophish is a Go-based framework combining evilginx3 and GoPhish for running authorized phishing and smishing campaigns with real-time c… | 32 | 2027 | maintenance |
| MegatronKing/StringFog StringFog is a Gradle plugin for Android that automatically encrypts string literals in compiled bytecode (dex/aar/jar) at build time and d… | 32 | 2015 | maintenance |
| Nekmo/dirhunt Dirhunt is a Python CLI web crawler optimized for finding and analyzing web directories without brute-forcing paths. It detects 'index of' … | 23 | 2006 | maintenance |
| Netflix-Skunkworks/stethoscope Stethoscope is a web application that collects device data from sources like JAMF, LANDESK, and G Suite mobile management and presents empl… | 32 | 2005 | maintenance |
| ETCExtensions/Edit-This-Cookie EditThisCookie is a Google Chrome/Chromium browser extension for managing cookies. It lets users add, delete, edit, search, protect, and bl… | 23 | 2003 | maintenance |
| cube0x0/CVE-2021-1675 A proof-of-concept exploit tool implementing the PrintNightmare vulnerabilities (CVE-2021-1675/CVE-2021-34527) in both C# and Python (Impac… | 32 | 2001 | maintenance |
| ionescu007/SimpleVisor SimpleVisor is a minimal, portable Intel VT-x hypervisor written in about 500 lines of C and 10 lines of assembly, supporting dynamic hyper… | 32 | 1998 | maintenance |
| Bashfuscator/Bashfuscator Bashfuscator is a modular, configurable Bash obfuscation framework written in Python 3 that transforms Bash commands and scripts into convo… | 32 | 1997 | maintenance |
| 411Hall/JAWS JAWS is a PowerShell enumeration script that helps penetration testers and CTF players quickly identify potential Windows privilege escalat… | 32 | 1997 | maintenance |
| weak1337/Alcatraz Alcatraz is a GUI-based x64 binary obfuscator for Windows PE files (.exe, .dll, .sys) written in C++. It applies transformations like contr… | 31 | 1995 | maintenance |
| mozilla/cipherscan Cipherscan is a command-line tool that tests which SSL/TLS ciphersuites a target server supports and in what order, wrapping the openssl s_… | 44 | 1994 | maintenance |