function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| zidansec/CloudPeler CrimeFlare is a PHP command-line OSINT tool that attempts to reveal the real origin IP address behind websites protected by Cloudflare's WA… | 10 | 1576 | maintenance |
| unixpickle/gobfuscate A command-line tool that obfuscates Go binaries by compiling from obfuscated source code. It hashes package names, global identifiers, meth… | 32 | 1574 | maintenance |
| XiphosResearch/exploits A collection of miscellaneous proof-of-concept exploit scripts written by Xiphos Research for security testing purposes, covering CVEs acro… | 32 | 1573 | maintenance |
| BishopFox/GitGot GitGot is a semi-automated, feedback-driven CLI tool for searching public GitHub data (code and gists) for exposed sensitive secrets. Users… | 32 | 1572 | maintenance |
| DeEpinGh0st/Erebus Erebus is a post-exploitation plugin for Cobalt Strike written in PowerShell and Sleep (Aggressor Script). It bundles information gathering… | 23 | 1570 | maintenance |
| javiersantos/PiracyChecker An Android library that helps prevent app piracy by verifying Google Play Licensing (LVL), APK signatures, and other tampering checks. It t… | 61 | 1569 | maintenance |
| Viralmaniar/BigBountyRecon BigBountyRecon is a C# Windows GUI tool that automates initial reconnaissance on a target organisation using 58 techniques, including Googl… | 23 | 1567 | maintenance |
| koush/Superuser An open-source Superuser management app and su binary for rooted Android devices, written in C and Java. It grants and manages root permiss… | 32 | 1562 | maintenance |
| cinit/WSAPatch A C++ patch that enables Windows Subsystem for Android (WSA) to run on Windows 10 instead of requiring Windows 11. It works by patching icu… | 22 | 1562 | maintenance |
| google/log4jscanner A Go-based filesystem scanner and library that detects JAR files containing the vulnerable Log4j classes behind the Log4Shell vulnerability… | 10 | 1562 | maintenance |
| Mr-Un1k0d3r/PowerLessShell PowerLessShell is a Python CLI tool that generates MSBuild project files capable of executing PowerShell scripts or raw shellcode without s… | 66 | 1559 | maintenance |
| csujedihy/proximac Proximac is an open-source command-line alternative to Proxifier that forces any application's traffic through a SOCKS5 proxy on macOS. It … | 23 | 1559 | maintenance |
| ben-z/free-sidecar A macOS GUI application that unlocks Apple's Sidecar feature on unsupported iPads and Macs by patching the SidecarCore framework blacklist.… | 23 | 1559 | maintenance |
| Picocrypt/Picocrypt Picocrypt is a small, simple, and secure file encryption tool built in Go, using XChaCha20 and Argon2id. It offers a portable GUI applicati… | 10 | 1554 | maintenance |
| liftoff/pyminifier Pyminifier is a command-line tool that minifies, obfuscates, and compresses Python source code. It can produce self-executing compressed sc… | 32 | 1553 | maintenance |
| Cn33liz/p0wnedShell p0wnedShell is a C# offensive PowerShell host application that runs PowerShell commands and modules within a runspace environment without r… | 32 | 1550 | maintenance |
| orta/cocoapods-keys A CocoaPods plugin that stores per-developer environment and application keys securely in the macOS keychain instead of source code. On pod… | 32 | 1548 | maintenance |
| w5teams/w5 W5 is an open-source, low-code Security Orchestration, Automation and Response (SOAR) platform built in Python with a visual playbook edito… | 23 | 1548 | maintenance |
| SharadKumar97/OSINT-SPY OSINT-SPY is a Python command-line tool that performs open-source intelligence scans on emails, domains, IP addresses, organizations, Bitco… | 23 | 1544 | maintenance |
| mandiant/SharPersist SharPersist is a Windows persistence toolkit written in C# that can add, remove, check, and list various persistence techniques such as reg… | 10 | 1541 | maintenance |
| xiecat/goblin Goblin is a phishing simulation system for red team/blue team security exercises, built in Go. It works as a reverse proxy that transparent… | 23 | 1537 | maintenance |
| s0md3v/Corsy Corsy is a lightweight Python 3 CLI tool that scans websites for known CORS (Cross-Origin Resource Sharing) misconfigurations. It tests for… | 23 | 1537 | maintenance |
| mattrajca/sudo-touchid A fork of the Unix sudo utility that adds Touch ID biometric authentication support on macOS via the LocalAuthentication framework. It lets… | 32 | 1534 | maintenance |
| Ha3MrX/InstaBrute InstaBrute is a shell script that performs brute-force password attacks against Instagram accounts, exploiting password-guessing vectors co… | 71 | 1533 | maintenance |
| GhostPack/SharpUp SharpUp is a C# port of common Windows privilege escalation checks from the PowerUp PowerShell script. It audits a system for misconfigurat… | 32 | 1533 | maintenance |
| galkan/crowbar Crowbar is a Python-based brute forcing tool for penetration testing that supports protocols often missing from other brute force tools, su… | 23 | 1530 | maintenance |
| gtxaspec/wz_mini_hacks A firmware modification toolkit for Ingenic T20/T31 based Wyze IP cameras that provides root access and extra features via a micro-SD card,… | 71 | 1529 | maintenance |
| harleyQu1nn/AggressorScripts A curated collection of Aggressor scripts (.cna) for Cobalt Strike 3.0+, aggregated from multiple community sources. The scripts automate r… | 32 | 1528 | maintenance |
| Yaxser/Backstab Backstab is a Windows command-line tool that kills antimalware/EDR-protected processes by abusing the Microsoft-signed Sysinternals Process… | 23 | 1528 | maintenance |
| gentilkiwi/kekeo kekeo is a C-based command-line toolbox for manipulating Microsoft Kerberos, from the author of mimikatz. It supports operations like ticke… | 23 | 1522 | maintenance |
| ultrasev/cursor-reset A small Python script that regenerates the device identifiers (telemetry.machineId, macMachineId, etc.) stored in the Cursor editor's confi… | 25 | 1520 | maintenance |
| CTF-MissFeng/bayonet Bayonet is a self-hosted web-based IT asset management and attack-surface platform for penetration testers, integrating subdomain enumerati… | 23 | 1519 | maintenance |
| chaitin/rad Rad (Radium) is a browser-based web crawler built for security scanning, driving a real Chrome browser to discover URLs and requests across… | 23 | 1515 | maintenance |
| HummerRisk/HummerRisk HummerRisk is an open-source, agentless cloud-native security platform for hybrid cloud security governance and Kubernetes/container securi… | 23 | 1512 | maintenance |
| gwen001/github-search A collection of Python, PHP, and Bash scripts that perform targeted searches on GitHub via its search API to find secrets, keys, private re… | 23 | 1511 | maintenance |
| WooyunDota/DroidSSLUnpinning A collection of Frida hook scripts (ObjectionUnpinningPlus) that bypass Android certificate pinning so HTTPS traffic can be intercepted wit… | 32 | 1510 | maintenance |
| nidem/kerberoast A collection of Python and PowerShell tools for attacking Microsoft Kerberos implementations, including requesting service tickets, crackin… | 32 | 1510 | maintenance |
| ViRb3/TrustMeAlready An Xposed module for rooted Android devices that disables SSL certificate verification and pinning system-wide. It hooks Java trust-check m… | 10 | 1507 | maintenance |
| hatRiot/zarp Zarp is a Python-based network attack tool focused on exploiting local networks by abusing networking protocols rather than systems. It pro… | 23 | 1506 | maintenance |
| Kevin-Robertson/Powermad Powermad is a set of PowerShell functions for exploiting Active Directory's default MachineAccountQuota and Active Directory-Integrated DNS… | 32 | 1502 | maintenance |
| pentestmonkey/windows-privesc-check A standalone Windows executable (built from Python with PyInstaller) that audits systems for privilege escalation vectors such as weak serv… | 32 | 1500 | maintenance |
| ChiChou/bagbak bagbak is a Node.js CLI tool that uses Frida to decrypt iOS App Store binaries on a jailbroken device, dumping decrypted IPAs including app… | 90 | 1499 | maintenance |
| ricmoo/aes-js A pure JavaScript implementation of the AES block cipher supporting all common modes of operation (CBC, CFB, CTR, ECB, OFB) and all key siz… | 23 | 1496 | maintenance |
| ptrkrysik/gr-gsm A set of GNU Radio blocks and tools for receiving and decoding GSM transmissions using software-defined radios. It is based on the Airprobe… | 37 | 1494 | maintenance |
| happylishang/AntiFakerAndroidChecker An Android library that detects whether the app is running on an emulator and retrieves relatively authentic device identifiers (IMEI, Andr… | 23 | 1491 | maintenance |
| veo/wsMemShell A Java-based WebSocket memory webshell (memshell) tool that injects WebSocket endpoints into running application servers like Tomcat, Sprin… | 32 | 1489 | maintenance |
| anttiviljami/browser-autofill-phishing A simple JavaScript demo showing how hidden form fields can be silently filled by browser autofill to phish user data. It demonstrates the … | 32 | 1489 | maintenance |
| mufeedvh/moonwalk moonwalk is a single-binary Rust CLI tool that covers tracks during Linux penetration testing by saving and reverting system log state, she… | 23 | 1487 | maintenance |
| 0x00-0x00/ShellPop ShellPop is a Python CLI tool that generates ready-to-use reverse and bind shell commands for penetration testing, with obfuscation, encode… | 23 | 1484 | maintenance |
| CYRUS-STUDIO/ApkToolPlus ApkToolPlus is a visual, cross-platform desktop application for Android APK reverse analysis built in Java. It bundles APK decompilation/re… | 40 | 1476 | maintenance |
| Consensys/eth-lightwallet A lightweight JavaScript HD wallet for Ethereum that stores private keys encrypted in the browser or Node.js. It generates BIP32/BIP39 addr… | 32 | 1476 | maintenance |
| optiv/Freeze Freeze is a Go-based payload creation toolkit that generates Windows shellcode loaders designed to bypass EDR security controls. It uses su… | 10 | 1475 | maintenance |
| jordanpotti/AWSBucketDump AWSBucketDump is a Python CLI security tool that enumerates AWS S3 buckets using wordlists, similar to a subdomain bruteforcer but for S3. … | 32 | 1473 | maintenance |
| matterpreter/OffensiveCSharp A collection of standalone C# tools and proof-of-concept programs for offensive security operations, each compiled individually in Visual S… | 32 | 1472 | maintenance |
| antonioCoco/RemotePotato0 RemotePotato0 is a Windows privilege escalation exploit that abuses the DCOM activation service to trigger NTLM authentication from privile… | 23 | 1471 | maintenance |
| elementor/wp2static WP2Static is a WordPress plugin that generates a static copy of a WordPress site and deploys it to static hosting. It improves security, pe… | 23 | 1470 | maintenance |
| doy/rbw rbw is an unofficial command line client for Bitwarden written in Rust. It runs a background agent that holds decryption keys in memory (li… | 69 | 1469 | maintenance |
| 0x09AL/RdpThief RdpThief is a standalone DLL that, when injected into the mstsc.exe (Remote Desktop client) process, uses API hooking to extract clear-text… | 32 | 1469 | maintenance |
| lunasec-io/lunasec LunaSec is an open-source supply chain security suite whose main product, LunaTrace, scans project dependencies for vulnerabilities like Lo… | 23 | 1469 | maintenance |
| psecio/iniscan A command-line tool that scans a php.ini file against common security best practices and reports pass/fail results per setting. It is insta… | 32 | 1468 | maintenance |
| psypanda/hashID hashID is a Python CLI tool that identifies over 220 hash types using regular expressions, working on single hashes, files, or directories.… | 23 | 1468 | maintenance |
| iTXTech/Daedalus Daedalus is an Android app that modifies DNS resolution without root access by creating a local VPN tunnel to intercept DNS requests. It su… | 23 | 1467 | maintenance |
| rootclay/WMIHACKER WMIHACKER is a VBScript-based command-line tool for lateral movement on Windows hosts via WMI (port 135), avoiding the commonly detected 44… | 33 | 1465 | maintenance |
| woj-ciech/LeakLooker A Python CLI tool that uses the Binaryedge.io API to find publicly exposed databases and services such as MongoDB, Elasticsearch, CouchDB, … | 10 | 1465 | maintenance |
| nccgroup/house House is a runtime mobile application analysis toolkit with a web GUI, powered by Frida and written in Python. It simplifies dynamic functi… | 32 | 1464 | maintenance |
| woodpecker-framework/woodpecker-framework-release Woodpecker-framework is a Java-based vulnerability detection and deep exploitation framework focused on precisely targeting high-risk vulne… | 23 | 1463 | maintenance |
| ptswarm/reFlutter A Python-based framework that repacks Flutter Android and iOS apps with a patched Flutter engine library to enable dynamic analysis. It red… | 10 | 1463 | maintenance |
| fingerprintjs/BotD BotD is a free, MIT-licensed browser library that detects automation tools and frameworks such as Puppeteer, Selenium, Playwright, and head… | 72 | 1462 | maintenance |
| Synzvato/decentraleyes Decentraleyes is a browser extension that emulates content delivery networks by serving popular CDN-hosted libraries (like JavaScript frame… | 10 | 1462 | maintenance |
| jesparza/peepdf peepdf is a Python tool for analyzing PDF files to determine whether they are malicious, offering object inspection, filter/encoding decodi… | 32 | 1461 | maintenance |
| wyzxxz/heapdump_tool A Java-based CLI tool that parses JVM heapdump files (via jhat) to search for sensitive information such as plaintext passwords, cloud acce… | 32 | 1456 | maintenance |
| DaGenix/rust-crypto A mostly pure-Rust library implementing many common cryptographic algorithms such as AES, SHA-2, ChaCha20, and Ed25519. It aims for practic… | 23 | 1456 | maintenance |
| airbnb/binaryalert BinaryAlert is an open-source serverless AWS pipeline that scans every file uploaded to an S3 bucket against a configurable set of YARA rul… | 23 | 1455 | maintenance |
| SySS-Research/Seth Seth is a Python and Bash proof-of-concept tool that performs a man-in-the-middle attack on RDP connections via ARP spoofing, downgrading t… | 56 | 1454 | maintenance |
| programa-stic/barf-project BARF is an open-source Python framework for binary analysis and reverse engineering. It lifts instructions from x86 and ARM binaries into a… | 32 | 1452 | maintenance |
| QAX-A-Team/BrowserGhost BrowserGhost is a C# command-line tool for red team operators that extracts saved browser credentials, cookies, history, and bookmarks from… | 23 | 1452 | maintenance |
| unixhot/waf A lightweight Web Application Firewall (WAF) implemented with Nginx + Lua (OpenResty). It provides IP black/white lists, URL and User-Agent… | 23 | 1450 | maintenance |
| oddcod3/Phantom-Evasion Phantom-Evasion is a Python-based antivirus evasion tool that generates obfuscated executables and payloads designed to bypass antivirus de… | 10 | 1450 | maintenance |
| mrash/fwknop fwknop implements Single Packet Authorization (SPA), a next-generation port knocking scheme that conceals services behind a default-drop fi… | 61 | 1447 | maintenance |
| SamJoan/droopescan Droopescan is a plugin-based command-line scanner that helps security researchers identify the CMS, version, plugins, themes, and interesti… | 32 | 1446 | maintenance |
| Invoke-IR/PowerForensics PowerForensics is a PowerShell module built on a C# class library that provides an all-in-one framework for live disk forensic analysis. It… | 23 | 1444 | maintenance |
| L4ys/LazyIDA LazyIDA is an IDA Pro plugin written in Python (IDAPython) that adds convenience features like data format conversion with clipboard copy, … | 62 | 1441 | maintenance |
| syvaidya/openstego OpenStego is a Java-based steganography application that hides data inside image files and embeds invisible watermarks to detect unauthoriz… | 23 | 1441 | maintenance |
| PowerTunnel PowerTunnel is an extensible local proxy server built on LittleProxy that bypasses government censorship by evading Deep Packet Inspection,… | 23 | 1438 | maintenance |
| dxa4481/Pastejacking A proof-of-concept demo of pastejacking: using JavaScript to override a user's clipboard contents when they copy text from a webpage, trick… | 32 | 1437 | maintenance |
| Raikia/FiercePhish FiercePhish is a self-hosted PHP web application for managing full phishing engagements, including campaign tracking, scheduled email sendi… | 23 | 1437 | maintenance |
| spacehuhn/wifi_ducky WiFi Ducky is a Wi-Fi controlled BadUSB device built from an ESP8266 and ATmega32U4 that uploads, saves, and remotely executes Ducky Script… | 23 | 1437 | maintenance |
| aave/aave-protocol Open source implementation of Aave Protocol Version 1.0, a decentralized lending pool system built on Ethereum smart contracts. This is the… | 10 | 1437 | maintenance |
| jweny/pocassist Pocassist is an open-source vulnerability PoC testing framework written in Go that lets users edit, run, and batch-test PoCs through a web … | 10 | 1436 | maintenance |
| kmackay/micro-ecc A small, fast C library implementing ECDH key exchange and ECDSA signatures for 8-bit, 32-bit, and 64-bit processors, with optional inline … | 23 | 1435 | maintenance |
| nccgroup/demiguise Demiguise is a Python CLI tool from NCC Group that generates HTML files containing RC4-encrypted HTA payloads, which are decrypted dynamica… | 32 | 1429 | maintenance |
| bpellin/keepassdroid KeePassDroid is an Android port of the KeePass Password Safe, allowing users to open and manage KeePass password databases (.kdb and .kdbx,… | 42 | 1427 | maintenance |
| nfc-tools/mfoc MFOC is an open-source C implementation of the offline nested attack for recovering authentication keys from MIFARE Classic NFC cards. It r… | 32 | 1427 | maintenance |
| atom/node-keytar A native Node.js module (written in C++) for storing, retrieving, replacing, and deleting passwords in the operating system's credential st… | 10 | 1426 | maintenance |
| 7kbstorm/7kbscan-WebPathBrute 7kbscan-WebPathBrute is a Windows GUI tool for brute-forcing web paths and directories using dictionaries. It supports multithreaded scanni… | 23 | 1424 | maintenance |
| paranoidninja/CarbonCopy A Python CLI tool that downloads a website's TLS certificate, creates a spoofed version of it, and uses it to sign Windows executables for … | 32 | 1423 | maintenance |
| NtQuery/Scylla Scylla is a Windows x86/x64 tool for reconstructing import tables (IAT) of unpacked or dumped binaries. It supports dumping processes, fixi… | 23 | 1422 | maintenance |
| ptoomey3/Keychain-Dumper A command-line tool for jailbroken iOS devices that dumps Keychain items (passwords, certificates, identities) accessible to an attacker. I… | 23 | 1421 | maintenance |
| 易开发 (DeveloperHelper) DeveloperHelper (易开发) is an Android developer/analysis tool app with an Xposed module that dumps DEX files from packed (hardened) APKs, plu… | 39 | 1420 | maintenance |
| 0xnobody/vmpdump VMPDump is a dynamic dumper and import fixer for binaries protected with VMProtect 3.x (x64), built on the VTIL intermediate language. It s… | 23 | 1417 | maintenance |