function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Moham3dRiahi/XAttacker XAttacker is a Perl-based command-line tool that scans websites for vulnerabilities and automatically exploits them. It detects the target'… | 32 | 1758 | maintenance |
| java-deobfuscator/deobfuscator A Java-based CLI tool that deobfuscates Java JAR files produced by commercial obfuscators such as Zelix KlassMaster, Stringer, Allatori, Da… | 23 | 1757 | maintenance |
| chenjj/espoofer espoofer is a Python-based testing tool that crafts spoofed emails to bypass SPF, DKIM, and DMARC authentication, including forged DKIM sig… | 32 | 1749 | maintenance |
| queer/boxxy boxxy is a Rust-based Linux CLI tool that uses namespaces to sandbox misbehaving applications and redirect their file reads/writes to speci… | 49 | 1747 | maintenance |
| knownsec/shellcodeloader A Windows shellcode loader generator written in C++ that packages raw shellcode into encrypted executables with multiple loading techniques… | 23 | 1747 | maintenance |
| alienator88/Sentinel Sentinel is a native macOS SwiftUI application providing a GUI for managing Gatekeeper settings. It lets users unquarantine apps by drag-an… | 75 | 1741 | maintenance |
| samdenty/Wi-PWN Wi-PWN is ESP8266 firmware for performing WiFi deauthentication attacks with a fast, responsive Material Design web UI. It includes an inte… | 23 | 1741 | maintenance |
| liexusong/php-beast php-beast is a PHP extension written in C that encrypts PHP source code files so they can be distributed without exposing the original code… | 32 | 1739 | maintenance |
| AnonHackerr/toolss A Python script that automatically installs a collection of hacking and penetration-testing tools on Android devices running Termux. It act… | 32 | 1739 | maintenance |
| jtesta/ssh-mitm A penetration testing tool that intercepts SSH connections by running a patched OpenSSH v7.5p1 server as a proxy between a victim and their… | 10 | 1739 | maintenance |
| aahmad097/AlternativeShellcodeExec A collection of C++ examples demonstrating alternative Windows callback functions for executing position-independent shellcode, avoiding de… | 32 | 1737 | maintenance |
| mprimi/portable-secret Portable Secret is a tool that packs an encrypted payload and decryption JavaScript into a single self-contained HTML file, using the brows… | 32 | 1736 | maintenance |
| gamelinux/passivedns PassiveDNS is a network sniffer written in C that passively collects DNS server replies from a live interface or pcap files and logs them i… | 32 | 1735 | maintenance |
| citronneur/rdpy RDPY is a pure Python implementation of the Microsoft Remote Desktop Protocol (RDP) built on the Twisted event-driven network engine, suppo… | 32 | 1735 | maintenance |
| lijiejie/ds_store_exp A Python CLI exploit tool that parses exposed .DS_Store files on web servers to enumerate hidden files and directories, then recursively do… | 32 | 1734 | maintenance |
| m57/dnsteal dnsteal is a fake DNS server written in Python that enables stealthy exfiltration of files from a victim machine via DNS requests. It suppo… | 32 | 1730 | maintenance |
| EASY233/Finger Finger is a Python-based red team tool that performs liveness probing and web system fingerprint detection across large asset lists, identi… | 32 | 1723 | maintenance |
| Azure/Stormspotter Stormspotter is an Azure red team tool that builds an attack graph of Azure subscription and Azure Active Directory resources, storing them… | 23 | 1718 | maintenance |
| DotNetOpenAuth/DotNetOpenAuth DotNetOpenAuth is a C# library implementing the OpenID and OAuth protocols for .NET applications. It lets developers build both Identity Pr… | 10 | 1716 | maintenance |
| antirez/hping hping3 is a command-line network tool that sends custom TCP/IP packets and displays target replies, similar to ping but supporting arbitrar… | 32 | 1715 | maintenance |
| samtap/fang-hacks A collection of shell-script-based modifications for the XiaoFang WiFi camera, delivered via a bootable SD card that runs scripts on the de… | 23 | 1712 | maintenance |
| genuinetools/reg A Docker Registry v2 command line client written in Go that can list repositories, fetch manifests and digests, download layers, and delete… | 23 | 1710 | maintenance |
| Err0r-ICA/TermuxCyberArmy TermuxCyberArmy is a shell/Python-based hacking toolkit script for the Termux terminal environment on Android. It bundles a collection of s… | 43 | 1709 | maintenance |
| Paisseon/SatellaJailed Satella Jailed is an in-app purchase cracker for non-jailbroken ('jailed') iOS devices running iOS 12–16, distributed as an injectable dyli… | 32 | 1708 | maintenance |
| sting8k/BurpSuite_403Bypasser A Burp Suite extension written in Python that automatically attempts to bypass 403 Forbidden responses on restricted directories. It hooks … | 32 | 1706 | maintenance |
| The404Hacking/AndroRAT AndroRAT is a Remote Administration Tool (RAT) for Android, consisting of a Java Android client that runs as a background service and a Jav… | 32 | 1702 | maintenance |
| dynup/kpatch kpatch is a Linux dynamic kernel patching infrastructure that lets sysadmins apply critical security patches to a running kernel without re… | 72 | 1696 | maintenance |
| irsdl/IIS-ShortName-Scanner A Java-based scanner that detects and exploits the Microsoft IIS short file name (8.3) disclosure vulnerability using tilde (~) character r… | 32 | 1694 | maintenance |
| dylanbai8/kmspro A one-click bash script for deploying a self-hosted KMS (Key Management Service) activation server on Linux, Windows, or Android, based on … | 32 | 1692 | maintenance |
| Cybereason/Logout4Shell A Java-based proof-of-concept tool by Cybereason that exploits the Log4Shell vulnerability (CVE-2021-44228) to 'vaccinate' a vulnerable ser… | 32 | 1692 | maintenance |
| swisskyrepo/GraphQLmap GraphQLmap is a Python scripting engine and interactive CLI for interacting with GraphQL endpoints during penetration testing. It supports … | 32 | 1688 | maintenance |
| eladshamir/Internal-Monologue A C# post-exploitation tool that retrieves NTLM hashes by inducing NetNTLM challenge-response computations in-process, without touching the… | 32 | 1685 | maintenance |
| natemcmaster/LettuceEncrypt LettuceEncrypt is a NuGet library for ASP.NET Core that integrates with certificate authorities like Let's Encrypt via the ACME protocol to… | 10 | 1685 | maintenance |
| zhengjim/camille Camille is a Frida-based auxiliary tool for detecting Android app privacy compliance. It hooks sensitive Android APIs to reveal whether the… | 32 | 1682 | maintenance |
| TryCatchHCF/Cloakify CloakifyFactory is a Python-based text-based steganography toolset that converts any file type into lists of innocuous everyday strings (e.… | 23 | 1682 | maintenance |
| Ghr07h/Heimdallr Heimdallr is a fully passive Chrome extension for security professionals that identifies high-risk vulnerability framework fingerprints in … | 23 | 1682 | maintenance |
| davglass/license-checker A Node.js CLI tool that inspects an npm project's dependency tree and reports the license of every installed package. It supports JSON/CSV … | 32 | 1681 | maintenance |
| threatexpress/domainhunter Domain Hunter is a Python CLI tool that finds expired or available domains with prior benign usage history via ExpiredDomains.net, then che… | 32 | 1680 | maintenance |
| rasta-mouse/Watson Watson is a .NET console tool that enumerates missing Windows KB patches and suggests exploits for known privilege escalation vulnerabiliti… | 10 | 1678 | maintenance |
| krisnova/boopkit boopkit is a Linux rootkit and backdoor written in C that uses eBPF to enable remote command execution over raw TCP. It requires prior priv… | 23 | 1677 | maintenance |
| tornadocash/tornado-core Tornado Cash is a non-custodial privacy protocol for Ethereum and ERC20 tokens built on zkSNARKs, implemented as smart contracts with JavaS… | 10 | 1677 | maintenance |
| noob-hackers/kalimux Kalimux is a bash script that automatically installs Kali Linux with a GUI inside Termux on Android, without requiring root. It uses proot … | 32 | 1674 | maintenance |
| noob-hackers/grabcam Grabcam is a bash-based Termux script that generates a fake offer page and an ngrok link to trick a victim into granting camera access, cap… | 32 | 1674 | maintenance |
| Chainfire/libsuperuser A Java library for Android that simplifies executing shell commands and root (su) operations from apps, with interactive shells, threading … | 32 | 1673 | maintenance |
| PAGalaxyLab/YAHFA YAHFA is a hook framework for Android ART that enables efficient Java method hooking and replacement. It is distributed as an Android libra… | 23 | 1672 | maintenance |
| Google Authenticator The open-source implementations of Google Authenticator, generating one-time passcodes using the OATH HOTP (RFC 4226) and TOTP (RFC 6238) s… | 10 | 1672 | maintenance |
| Dheerajmadhukar/4-ZERO-3 4-ZERO-3 is a Bash-based security testing script that automates a wide range of techniques for bypassing HTTP 403/401 access restrictions o… | 32 | 1669 | maintenance |
| TheKingOfDuck/burpFakeIP A Burp Suite extension written in Java that forges IP addresses in HTTP request headers (X-Forwarded-For and similar) to test servers with … | 23 | 1669 | maintenance |
| securesocketfunneling/ssf Secure Socket Funneling (SSF) is a cross-platform network tool and toolkit that multiplexes TCP and UDP traffic through a single TLS-encryp… | 23 | 1669 | maintenance |
| taviso/ctftool An interactive command-line tool for exploring the CTF (Clipboard/Text Services Framework) protocol used by Windows Text Services. It suppo… | 23 | 1667 | maintenance |
| kitsuned/PotatoNV PotatoNV is a Windows desktop application (with a separate cross-platform build) that unlocks the bootloader on Huawei/Honor devices powere… | 54 | 1666 | maintenance |
| asLody/whale Whale is a cross-platform hook framework written in C++ that runs on Android, iOS, Linux, and macOS, supporting ARM/THUMB, ARM64, X86, and … | 32 | 1665 | maintenance |
| opensec-cn/kunpeng Kunpeng is an open-source vulnerability POC (proof-of-concept) detection framework written in Go, bundling POCs for databases, middleware, … | 23 | 1665 | maintenance |
| pydantic/monty Monty is a minimal, secure Python interpreter written in Rust designed for safely executing LLM-generated code without container-based sand… | 95 | 8158 | experimental |
| Mr-Un1k0d3r/SCShell SCShell is a fileless lateral movement tool that executes commands on remote Windows systems by modifying a service's binary path via Chang… | 32 | 1661 | maintenance |
| davehull/Kansa Kansa is a modular incident response framework written in PowerShell that uses PowerShell Remoting to run data-collection modules across ma… | 23 | 1661 | maintenance |
| ius/rsatool A Python command-line tool that computes RSA and RSA-CRT parameters (p, q, n, d, e, dP, dQ, qInv) from either two primes or a modulus and p… | 74 | 1659 | maintenance |
| Dec0ne/KrbRelayUp KrbRelayUp is a C# command-line tool that wraps Rubeus and KrbRelay to automate a Kerberos relay-based local privilege escalation in Window… | 32 | 1657 | maintenance |
| mdp/rotp A Ruby library for generating and validating one-time passwords (HOTP and TOTP) according to RFC 4226 and RFC 6238. It is compatible with G… | 47 | 1656 | maintenance |
| Adminisme/ServerScan ServerScan is a high-concurrency network scanning and service detection tool written in Go, designed for intranet lateral information gathe… | 23 | 1655 | maintenance |
| facebookresearch/CrypTen CrypTen is a PyTorch-based library for privacy-preserving machine learning built on secure multiparty computation. It exposes a CrypTensor … | 10 | 1649 | maintenance |
| TheCrypt0/yi-hack-v4 Custom firmware for Xiaomi Yi cameras based on the Hi3518e chipset, adding an RTSP server, SSH, FTP, web server, and MQTT motion detection … | 23 | 1639 | maintenance |
| d3vilbug/HackBar A Burp Suite plugin that adds a HackBar panel for quickly injecting common payloads like SQLi and XSS during manual web application testing… | 23 | 1633 | maintenance |
| androidmalware/android_hid A set of shell scripts that turn a rooted Android device into a USB HID keyboard (Rubber Ducky style) to inject keystroke payloads into tar… | 32 | 1631 | maintenance |
| dpnishant/appmon AppMon is an automated framework for monitoring and tampering with system API calls of native macOS, iOS, and Android apps, built on Frida.… | 10 | 1631 | maintenance |
| JohnHammond/msdt-follina A Python CLI tool that generates malicious Microsoft Word documents exploiting the MS-MSDT 'Follina' vulnerability (CVE-2022-30190) and sta… | 32 | 1630 | maintenance |
| jivoi/pentest A collection of Python and shell scripts for offensive security and penetration testing tasks, including host discovery, port scanning, and… | 32 | 1630 | maintenance |
| veo/vscan vscan is an open-source, lightweight, fast, cross-platform website vulnerability scanner written in Go, built for red team reconnaissance. … | 23 | 1630 | maintenance |
| frainzy1477/luci-app-clash A LuCI web interface plugin for OpenWrt routers that manages the Clash rule-based proxy client. It provides subscription handling, config e… | 23 | 1629 | maintenance |
| huangyz0918/AndroidWM AndroidWM is a lightweight Java library for Android that adds visible or invisible (steganographic) watermarks to images. It supports text … | 32 | 1628 | maintenance |
| bdamele/icmpsh icmpsh is a simple reverse ICMP shell tool with a Windows slave (client) written in C and a portable master (server) implemented in C, Perl… | 32 | 1625 | maintenance |
| firesunCN/BlueLotus_XSSReceiver BlueLotus_XSSReceiver is a self-hosted XSS data receiving platform written in PHP and JavaScript, designed for CTF practice and security le… | 32 | 1624 | maintenance |
| zed-0xff/zsteg zsteg is a Ruby CLI tool that detects steganography-hidden data in PNG and BMP images, including LSB steganography, zlib-compressed payload… | 61 | 1621 | maintenance |
| sweetsoftware/Ares Ares is a Python-based remote access tool (RAT) consisting of a web-based command-and-control server and a lightweight agent that runs on t… | 32 | 1621 | maintenance |
| TheHive-Project/Cortex Cortex is an open-source observable analysis and active response engine for SOCs, CSIRTs, and security researchers. It lets analysts analyz… | 84 | 1619 | maintenance |
| byt3bl33d3r/DeathStar DeathStar is a Python CLI tool that automates gaining Domain and Enterprise Admin privileges in Active Directory environments by chaining c… | 32 | 1618 | maintenance |
| spolu/warp Warp is a Go-based CLI tool for securely sharing a live terminal session with others via a simple `warp open` command. Clients connect read… | 23 | 1618 | maintenance |
| martinmarinov/TempestSDR A software toolkit for remotely eavesdropping on video monitors by capturing compromising electromagnetic emanations from video cables usin… | 32 | 1617 | maintenance |
| nccgroup/Winpayloads Winpayloads is a Python 2.7 tool for generating undetectable Windows payloads with extras like UAC bypass, persistence, and PowerShell stag… | 32 | 1616 | maintenance |
| dstmath/frida-unpack A Frida-based unpacking tool for Android apps that hooks libart.so's OpenMemory (or OpenCommon on Android 10) to dump decrypted DEX files f… | 44 | 1613 | maintenance |
| Mixiaoxiao/Arduino-HomeKit-ESP8266 An Arduino library implementing a native Apple HomeKit accessory server for the ESP8266 (with an ESP32 variant), allowing microcontroller p… | 23 | 1612 | maintenance |
| shuhongfan/NavicatCracker A keygen and patcher for activating Navicat 16 database client software without a paid license. It patches the installed Navicat binary and… | 32 | 1610 | maintenance |
| HACK3RY2J/Anon-SMS A shell-based tool for Linux and Termux that sends anonymous SMS messages via a third-party service, limited to one message per day. It is … | 32 | 1608 | maintenance |
| google/highwayhash A C++ library providing fast, strong (well-distributed and unpredictable) hash functions: a portable SipHash implementation and HighwayHash… | 10 | 1605 | maintenance |
| matoous/go-nanoid A Go implementation of the nanoid algorithm for generating compact, URL-safe unique identifiers using a cryptographically strong random gen… | 48 | 1601 | maintenance |
| den4uk/andriller Andriller CE is a Python-based forensic toolkit for Android smartphones that performs read-only, non-destructive data acquisition from devi… | 23 | 1601 | maintenance |
| tenta-browser/tenta-dns Tenta DNS is a Go-based DNS server suite combining an authoritative DNS server, a recursive resolver with DNSSEC and DNS-over-TLS support, … | 32 | 1600 | maintenance |
| stark0de/nginxpwner Nginxpwner is a Python command-line tool that scans Nginx servers for common misconfigurations and known vulnerabilities, such as CRLF inje… | 10 | 1599 | maintenance |
| tokyoneon/Chimera Chimera is a PowerShell obfuscation script that transforms malicious PS1 payloads using string substitution and variable concatenation to b… | 32 | 1598 | maintenance |
| zetzit/zz ZetZ is a C dialect and transpiler that emits plain ANSI C while formally verifying all code via symbolic execution with an SMT prover at c… | 10 | 1598 | maintenance |
| savio-code/fern-wifi-cracker Fern Wifi Cracker is a Python/Qt GUI application for wireless security auditing that can crack and recover WEP, WPA/WPA2, and WPS keys. It … | 70 | 1597 | maintenance |
| outflanknl/Dumpert Dumpert is a proof-of-concept LSASS memory dumper written in C and assembly that uses direct system calls and API unhooking to evade AV/EDR… | 32 | 1597 | maintenance |
| Squalr/Squalr-Sharp Squalr is a high-performance memory editor for Windows desktop games, written in C#, supporting memory scanning, pointer scanning, and x86/… | 23 | 1596 | maintenance |
| Lotus6/ThinkphpGUI A Java-based GUI vulnerability exploitation tool targeting the ThinkPHP framework, supporting detection of vulnerabilities across ThinkPHP … | 23 | 1595 | maintenance |
| wyzxxz/shiro_rce_tool A Java-based command-line tool that assists in detecting and exploiting Apache Shiro rememberMe deserialization vulnerabilities. It brute-f… | 32 | 1594 | maintenance |
| sairson/Yasso Yasso is a Go-based intranet penetration testing toolkit that combines service brute-forcing (RDP, SSH, Redis, PostgreSQL, MongoDB, MSSQL, … | 23 | 1593 | maintenance |
| omadahealth/LolliPin LolliPin is a Material design styled Android library that adds PIN code lock protection to apps, storing only a SHA-1 hash of the PIN. It a… | 10 | 1590 | maintenance |
| MyEtherWallet MyEtherWallet (MEW) is a free, open-source, client-side interface for creating and managing Ethereum wallets and interacting with the Ether… | 99 | 1585 | maintenance |
| lelinhtinh/de4js de4js is a web-based JavaScript deobfuscator and unpacker that transforms obfuscated code (Eval, Array, JSFuck, JJencode, AAencode, Packer,… | 10 | 1580 | maintenance |
| 0xHJK/dumpall dumpall is a Python command-line tool for exploiting information disclosure vulnerabilities on web servers. It reconstructs source code fro… | 23 | 1579 | maintenance |