function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| mdsecactivebreach/SharpShooter SharpShooter is a payload creation framework for retrieving and executing arbitrary CSharp source code, generating payloads in formats like… | 32 | 1989 | maintenance |
| Lora-net/LoRaMac-node A reference implementation of a LoRaWAN end-device (node) stack written in C, with example projects for various MCU platforms. It implement… | 23 | 1989 | maintenance |
| nfc-tools/libnfc libnfc is a platform-independent C library that gives userspace applications access to NFC devices and readers, supporting multiple drivers… | 27 | 1987 | maintenance |
| samyk/slipstream NAT Slipstreaming is a security research tool by Samy Kamkar that demonstrates remotely opening arbitrary firewall pinholes through a victi… | 32 | 1984 | maintenance |
| h3xduck/TripleCross TripleCross is a Linux eBPF rootkit demonstrating offensive capabilities of eBPF technology, including library injection, execution hijacki… | 23 | 1978 | maintenance |
| jondonas/linux-exploit-suggester-2 A Perl script that suggests Linux kernel privilege escalation exploits based on the running kernel version. It matches the kernel release a… | 32 | 1973 | maintenance |
| tjfoc/gmsm A Go library implementing the Chinese national cryptography standards SM2 (elliptic curve), SM3 (hash), and SM4 (block cipher). It supports… | 23 | 1964 | maintenance |
| D35m0nd142/LFISuite LFISuite is a fully automatic Python tool that scans for and exploits Local File Inclusion (LFI) vulnerabilities using eight different atta… | 23 | 1963 | maintenance |
| r00t-3xp10it/venom VENOM is a shell-based framework that uses msfvenom to generate, obfuscate, and compile multi-format shellcode payloads (exe, dll, apk, elf… | 23 | 1961 | maintenance |
| cytopia/pwncat pwncat is a Python-based netcat replacement and reverse/bind shell handler with firewall and IDS/IPS evasion, self-injecting shells, and po… | 23 | 1955 | maintenance |
| duckduckgo/iOS The DuckDuckGo Privacy Browser for iOS, an open-source mobile web browser with built-in private search, third-party tracker blocking, ad bl… | 10 | 1953 | maintenance |
| psal/anonymouth Anonymouth is a Java-based desktop application that helps users anonymize documents by detecting and suggesting edits to stylometric patter… | 32 | 1950 | maintenance |
| w-digital-scanner/w13scan W13Scan is an open-source Python3 web vulnerability scanner supporting both passive (proxy-based) and active scanning modes. It ships with … | 32 | 1944 | maintenance |
| openshift/osin OSIN is a Go library for building your own OAuth2 authentication server, implementing the RFC 6749 specification including authorization an… | 76 | 1935 | maintenance |
| produck/svg-captcha A Node.js library that generates SVG-based CAPTCHA images without native C++ dependencies. It produces random text or math-expression captc… | 32 | 1935 | maintenance |
| Ranginang67/DarkFly-Tool DarkFly-Tool is a menu-driven installer for Termux that bundles 530 hacking and utility tools, letting users install them by number instead… | 32 | 1935 | maintenance |
| scipr-lab/libsnark libsnark is a C++ library implementing zkSNARK schemes, cryptographic constructions for proving and verifying computations in zero knowledg… | 44 | 1933 | maintenance |
| sense-of-security/ADRecon ADRecon is a PowerShell-based tool that extracts a wide range of artefacts from an Active Directory environment, including users, groups, t… | 32 | 1930 | maintenance |
| OpenDrop OpenDrop is an open-source command-line tool written in Python that implements the Apple AirDrop protocol for sharing files directly over W… | 67 | 9730 | experimental |
| Und3rf10w/kali-anonsurf A port of ParrotSec's anonsurf and pandora modules to Kali Linux, packaged as a deb installer. It routes all system traffic through TOR via… | 90 | 1919 | maintenance |
| dollarshaveclub/postmate Postmate is a lightweight, promise-based JavaScript library built on window.postMessage() that enables secure two-way communication between… | 23 | 1919 | maintenance |
| tiann/Leoric Leoric is a proof-of-concept Android library that demonstrates a technique for keeping an app process alive against force-stop kills on And… | 32 | 1918 | maintenance |
| dirkjanm/mitm6 mitm6 is a Python pentesting tool that exploits Windows' default IPv6 configuration by answering DHCPv6 requests, assigning victims a link-… | 23 | 1918 | maintenance |
| omnigent-ai/omnigent Omnigent is an open-source meta-harness that provides a common orchestration layer over AI coding agents like Claude Code, Codex, Cursor, a… | 80 | 9660 | experimental |
| Codeux-Software/Textual Textual is a highly customizable IRC client for macOS, supporting IRCv3, OTR encryption, and styling via CSS/HTML/JavaScript. It can be ext… | 10 | 1908 | maintenance |
| SummerSec/SpringBootExploit A Java GUI tool for quickly exploiting Spring Boot actuator/env page vulnerabilities, built from the LandGrey SpringBootVulExploit checklis… | 10 | 1895 | maintenance |
| s0md3v/Hash-Buster Hash-Buster is a Python CLI tool that identifies hash types automatically and cracks them by looking them up via online APIs. It supports M… | 23 | 1894 | maintenance |
| YelpArchive/osxcollector OSXCollector is a forensic evidence collection and analysis toolkit for macOS/OS X. It is a single-file Python script that gathers system d… | 10 | 1894 | maintenance |
| lobuhi/byp4xx byp4xx is a command-line tool written in Go that attempts to bypass HTTP 40X (access denied) responses using techniques like verb tampering… | 32 | 1891 | maintenance |
| corelan/mona mona.py is a Python plugin for debuggers (Immunity Debugger, x64dbg) that assists with exploit development tasks such as finding ROP gadget… | 10 | 1888 | maintenance |
| inbug-team/InScan InScan is a Go-based automated intranet penetration testing tool designed for use after breaching a network boundary. It provides port scan… | 32 | 1887 | maintenance |
| positive-security/send-my Send My is a research tool that transmits arbitrary data through Apple's Find My network by encoding it in BLE public-key broadcasts from a… | 23 | 1884 | maintenance |
| atmos/camo Camo is an HTTP image proxy that routes insecure HTTP images through SSL to prevent mixed-content warnings on HTTPS pages. It authenticates… | 10 | 1883 | maintenance |
| cobbr/SharpSploit SharpSploit is a .NET post-exploitation library written in C# that highlights the .NET attack surface for red teamers. It ports and extends… | 32 | 1882 | maintenance |
| google/security-research-pocs A collection of proof-of-concept exploit code produced during security research by the Google Security Team. It serves as a reference repos… | 10 | 1881 | maintenance |
| droe/sslsplit SSLsplit is a transparent SSL/TLS interception proxy for man-in-the-middle attacks against encrypted network connections. It terminates TLS… | 54 | 1875 | maintenance |
| ptrpaws/Oculess Oculess is a sideloaded Android app for Oculus Quest headsets that removes account requirements, disables telemetry apps, and enables backg… | 42 | 1872 | maintenance |
| arkdb/inception Inception is a self-hosted MySQL/MariaDB automated operations tool written in C that combines SQL statement auditing, execution, backup, an… | 32 | 1872 | maintenance |
| SpoofMAC SpoofMAC is a Python command-line tool that changes (spoofs) your computer's MAC address in one command, handling the Wi-Fi disassociation … | 32 | 1868 | maintenance |
| orlyjamie/mimikittenz mimikittenz is a post-exploitation PowerShell tool that uses the Windows ReadProcessMemory() function to extract plain-text passwords and o… | 32 | 1867 | maintenance |
| maliceio/malice Malice is an open-source malware analysis framework that acts as a self-hosted VirusTotal alternative, scanning files with Docker-based plu… | 10 | 1863 | maintenance |
| trimstray/sandmap sandmap is a shell-based CLI wrapper around the Nmap engine that simplifies network and system reconnaissance. It offers 31 modules with 45… | 32 | 1862 | maintenance |
| DanMcInerney/net-creds A Python command-line tool that sniffs passwords, hashes, and other sensitive data from a live network interface or a pcap file. It reassem… | 32 | 1862 | maintenance |
| eldraco/domain_analyzer Domain Analyzer is a Python-based security analysis tool that automatically discovers and reports information about a given domain, includi… | 32 | 1861 | maintenance |
| jaykali/hackerpro HackerPro is an all-in-one penetration testing tool collection for Linux and Android (Termux) that bundles popular security tools like Nmap… | 32 | 1858 | maintenance |
| winauth/winauth WinAuth is a portable, open-source Windows desktop application that acts as a software two-factor authenticator, supporting RFC 6238 TOTP a… | 10 | 1857 | maintenance |
| phpv8/v8js V8Js is a PHP extension that embeds Google's V8 JavaScript engine into PHP, allowing execution of JavaScript code from PHP scripts. It prov… | 58 | 1855 | maintenance |
| n0a/telegram-get-remote-ip A Python CLI script that reveals the IP address of a Telegram voice call interlocutor by capturing and analyzing traffic with tshark. It ex… | 32 | 1855 | maintenance |
| Defi-Cartel/salmonella Salmonella is a demonstration project that deploys a malicious ERC-20 token contract designed to detect and punish sandwich traders on Ethe… | 32 | 1853 | maintenance |
| glmcdona/Process-Dump Process Dump is a Windows command-line reverse-engineering tool that dumps unpacked malware PE files and loose code chunks from process mem… | 23 | 1853 | maintenance |
| awake1t/linglong Linglong is a self-hosted asset reconnaissance and scanning system written in Go that continuously discovers network assets using masscan+n… | 32 | 1848 | maintenance |
| kozmer/log4j-shell-poc A proof-of-concept exploit tool for the Log4Shell vulnerability (CVE-2021-44228) in the Java log4j logging library. It automates setting up… | 10 | 1848 | maintenance |
| 1N3/Findsploit Findsploit is a simple bash script that instantly searches local and online exploit databases, including Exploit-DB, Metasploit modules, an… | 23 | 1847 | maintenance |
| wavestone-cdt/EDRSandblast EDRSandBlast is a C-based offensive security tool that weaponizes vulnerable signed drivers to bypass EDR detections on Windows, including … | 32 | 1846 | maintenance |
| CCob/SweetPotato SweetPotato is a C# command-line tool that collects multiple native Windows privilege escalation techniques (RottenPotato, PrintSpoofer, Ef… | 32 | 1839 | maintenance |
| sleventyeleven/linuxprivchecker A single-file Python script that enumerates a local Linux system and searches for common privilege escalation vectors such as world-writabl… | 32 | 1839 | maintenance |
| Hackertrackersj/Instabruteforce A Python CLI tool that brute-forces Instagram account passwords using a wordlist and a rotating proxy list, with proxy scoring and pruning … | 32 | 1838 | maintenance |
| cyweb/hammer A Python 3 command-line script for performing DDoS (denial-of-service) flood attacks against target servers. It is a simple offensive secur… | 48 | 1836 | maintenance |
| raiden-network/raiden Raiden is a Python client implementing an off-chain state channel network for Ethereum, enabling near-instant, low-fee token transfers with… | 23 | 1832 | maintenance |
| neex/phuip-fpizdam A Go-based exploit tool for CVE-2019-11043, a remote code execution vulnerability in php-fpm when used behind certain nginx configurations.… | 32 | 1831 | maintenance |
| p3nt4/PowerShdll PowerShdll is a C# tool that runs PowerShell commands and scripts without invoking powershell.exe, by loading PowerShell automation DLLs vi… | 23 | 1830 | maintenance |
| SysWhispers SysWhispers is a Python CLI tool that generates header and assembly files for making direct system calls on Windows, bypassing user-mode AP… | 32 | 1829 | maintenance |
| cmuratori/meow_hash Meow Hash is an extremely fast non-cryptographic hash function taking a 128-byte seed and producing 128-bit output, implemented in C/C++ us… | 32 | 1829 | maintenance |
| mm0r1/exploits A collection of PHP 'pwn' exploits that bypass the disable_functions restriction in PHP using known interpreter bugs (e.g., bug #81705, #72… | 32 | 1824 | maintenance |
| x0rz/phishing_catcher A Python CLI tool that monitors TLS certificate issuances in near real time via the CertStream API and flags suspicious domains using a con… | 32 | 1823 | maintenance |
| klezVirus/inceptor Inceptor is a template-driven PE packer and AV/EDR evasion framework for Windows, aimed at penetration testers and red teamers. It automate… | 32 | 1821 | maintenance |
| Matrix07ksa/Brute_Force A Python CLI tool that performs brute-force password attacks against Gmail, Hotmail, Twitter, Facebook, and Netflix accounts, with optional… | 32 | 1820 | maintenance |
| newbit1/rootAVD A shell script that roots Android Studio Virtual Devices (AVDs) running on the QEMU emulator by installing Magisk, patching fstab, and opti… | 10 | 1820 | maintenance |
| whid-injector/WHID WHID Injector is an open-source WiFi HID injection tool that combines an ESP8266 with an ATmega32u4 to remotely deliver BadUSB keystroke at… | 32 | 1818 | maintenance |
| smarques84/MockLocationDetector An Android library written in Java that detects whether a device's location data comes from a mock (spoofed) provider. It offers static met… | 32 | 1817 | maintenance |
| InteliSecureLabs/Linux_Exploit_Suggester A Perl script that suggests possible Linux kernel exploits based on the operating system release number (uname -r). It matches the kernel v… | 32 | 1812 | maintenance |
| hlldz/Phant0m Phant0m is a Windows Event Log Killer that identifies the process hosting the Windows Event Log service and terminates only its threads, so… | 10 | 1812 | maintenance |
| lockedbyte/CVE-2021-40444 A proof-of-concept exploit generator for CVE-2021-40444, a Microsoft Office Word remote code execution vulnerability. It generates maliciou… | 32 | 1806 | maintenance |
| pmiaowu/BurpShiroPassiveScan A passive BurpSuite extension written in Java that automatically detects Apache Shiro framework usage and tests for known Shiro encryption … | 23 | 1806 | maintenance |
| gtank/cryptopasta A collection of copy-and-paste-friendly cryptography snippets for Go, wrapping the standard library's best practices for encryption (AES-GC… | 32 | 1805 | maintenance |
| Kevin-Robertson/Invoke-TheHash A collection of PowerShell functions for performing pass-the-hash attacks over WMI and SMB using NTLM hash authentication. It implements ra… | 32 | 1805 | maintenance |
| KimJun1010/WeblogicTool A GUI-based vulnerability exploitation toolkit targeting Oracle WebLogic servers, supporting detection and exploitation of numerous CVEs vi… | 20 | 1804 | maintenance |
| huolizhuminh/NetWorkPacketCapture An Android app that captures network packets using a local VPN service, showing live connections per app and parsing/saving HTTP (and parti… | 32 | 1802 | maintenance |
| enjoiz/XXEinjector XXEinjector is a Ruby command-line tool that automates exploitation of XML External Entity (XXE) vulnerabilities using direct and out-of-ba… | 32 | 1800 | maintenance |
| Ha3MrX/DDos-Attack A simple Python script for launching DDoS (denial of service) attacks against online targets. It is a command-line tool intended for learni… | 66 | 1797 | maintenance |
| google/stenographer Stenographer is a high-performance full-packet-capture utility that spools network packets to disk at up to ~10Gbps and manages disk usage … | 10 | 1796 | maintenance |
| pivotal/LicenseFinder LicenseFinder is a Ruby CLI tool that scans a project's dependencies via its package manager, detects each package's license, and compares … | 23 | 1795 | maintenance |
| acecilia/OpenWRTInvasion A Python/Docker-based exploit script that gains a root shell on several Xiaomi routers (4A Gigabit, 4A 100M, 4, 4C, 3Gv2, 4Q, miWifi 3C) vi… | 23 | 1795 | maintenance |
| sysdream/ligolo Ligolo is a lightweight Go tool for establishing SOCKS5 or TCP tunnels over reverse TLS connections, aimed at penetration testers pivoting … | 32 | 1788 | maintenance |
| iceyhexman/onlinetools A self-hosted web-based penetration testing toolbox written in Python that bundles common recon and scanning tasks behind a browser UI. It … | 10 | 1787 | maintenance |
| googleprojectzero/domato Domato is a grammar-based DOM fuzzer from Google Project Zero that generates HTML, CSS, and JavaScript test cases for finding browser DOM e… | 32 | 1784 | maintenance |
| mrh0wl/Cloudmare Cloudmare is a Python CLI tool that discovers the origin servers of websites protected by Cloudflare, Sucuri, or Incapsula when their DNS i… | 10 | 1783 | maintenance |
| intika/Librefox Librefox is a privacy- and security-hardened packaging of Firefox that applies 500+ settings, patches, and optional addons without forking … | 23 | 1777 | maintenance |
| Xposed-Modules-Repo/com.fkzhang.wechatxposed An Xposed module for WeChat (微X模块) that adds features like preventing message recalls, forwarding media to Moments, auto-claiming red packe… | 23 | 1776 | maintenance |
| Noovolari/leapp Leapp is a cross-platform Electron desktop app for managing and generating cloud credentials across multiple AWS and Azure accounts, with e… | 60 | 1775 | maintenance |
| krakenjs/lusca Lusca is web application security middleware for Express/Node.js apps. It provides configurable protections including CSRF tokens, Content … | 25 | 1775 | maintenance |
| ddvk/remarkable-hacks A collection of binary patches that add extra features to reMarkable 1 and 2 e-ink tablets, such as pinch-to-zoom, bookmarks, Zen mode, and… | 23 | 1775 | maintenance |
| lucasjacks0n/EggShell EggShell is a Python-based post-exploitation surveillance and remote administration tool that provides a command-line session with a target… | 32 | 1770 | maintenance |
| ssllabs/ssllabs-scan A command-line reference client for the SSL Labs APIs, written in Go, for automated and bulk SSL/TLS server assessment. It scans hosts agai… | 23 | 1768 | maintenance |
| YuHuanTin/IDM_Cracker An archived mirror of a crack/patch tool for Internet Download Manager (IDM), originally released by Ali.Dbg and re-hosted by YuHuanTin. It… | 76 | 1764 | maintenance |
| tanweai/wooyun-legacy A Claude Code plugin that injects real-world case citations, statistics, and data-driven prioritization into AI-generated security reports,… | 57 | 1764 | maintenance |
| indutny/elliptic A fast, pure-JavaScript implementation of elliptic curve cryptography supporting ECDSA signing/verification, ECDH key exchange, and EdDSA. … | 32 | 1764 | maintenance |
| s4n7h0/xvwa XVWA (Xtreme Vulnerable Web Application) is an intentionally insecure PHP/MySQL web application for learning application security. It conta… | 10 | 1763 | maintenance |
| tandasat/HyperPlatform HyperPlatform is an Intel VT-x based hypervisor for Windows that provides a thin VM-exit filtering platform for research. It lets researche… | 10 | 1760 | maintenance |
| al0ne/Vxscan Vxscan is a Python3-based comprehensive security scanning tool for authorized penetration testing. It combines host liveness checks, port s… | 32 | 1759 | maintenance |