function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| TakeScoop/SwiftyRSA SwiftyRSA is a Swift library for RSA public/private key encryption and decryption on Apple platforms. It supports loading keys from PEM, DE… | 23 | 1303 | maintenance |
| Viralmaniar/Passhunt Passhunt is a Python-based command-line tool for searching default credentials across 523 vendors and 2084 default passwords for network de… | 23 | 1303 | maintenance |
| nccgroup/SocksOverRDP A SOCKS4/4a/5 proxy implementation that tunnels traffic over RDP or Citrix (XenApp/XenDesktop) connections using Dynamic Virtual Channels. … | 23 | 1301 | maintenance |
| devanshbatham/FavFreak A Python CLI tool that fetches favicon.ico files from lists of URLs, computes their mmh3 hashes, and groups domains/subdomains/IPs by match… | 23 | 1300 | maintenance |
| wbenny/injdrv A proof-of-concept Windows kernel driver that injects DLLs into user-mode processes using Asynchronous Procedure Calls (APC). It hooks into… | 32 | 1297 | maintenance |
| aoh/radamsa Radamsa is a general-purpose fuzzer that mutates input data to test software robustness against malformed input. This GitHub repository is … | 23 | 1295 | maintenance |
| Vu1nT0tal/IoT-vulhub A collection of Docker-based environments for reproducing IoT firmware vulnerabilities, inspired by the Vulhub project. It uses binwalk for… | 23 | 1295 | maintenance |
| guyoung/CaptfEncoder CaptfEncoder is an open-source, cross-platform network security tool suite offering encoding/decoding conversions, classical and modern cry… | 23 | 1295 | maintenance |
| LangziFun/LangSrcCurise LangSrcCurise is a Django-based automated subdomain asset monitoring system for security researchers tracking SRC (Security Response Center… | 32 | 1294 | maintenance |
| med0x2e/SigFlip SigFlip is a red-team tool for patching Authenticode-signed PE files (exe, dll, sys) without invalidating their existing signatures, by emb… | 32 | 1293 | maintenance |
| MasterDevX/Termux-Kali A shell script that installs a Kali Linux rootfs on Android devices via Termux using proot, without requiring root access. It is a lightly … | 32 | 1291 | maintenance |
| kinghacker0/WishFish WishFish is a bash-based security testing tool that generates phishing-style links (wishing or custom pages) which, when opened by a target… | 32 | 1290 | maintenance |
| smxiazi/xia_sql A Burp Suite extension (written in Java) that appends single and double quotes to every request parameter to detect possible SQL injection,… | 23 | 1290 | maintenance |
| mandiant/gocrack GoCrack is a management frontend and API server for coordinating password cracking tasks, currently supporting hashcat 6.x+ as a cracking e… | 64 | 1289 | maintenance |
| hubert3/iSniff-GPS iSniff-GPS is a passive WiFi sniffing tool that captures SSID probes, ARPs, and MDNS packets from nearby iOS devices to infer their previou… | 32 | 1287 | maintenance |
| alexzielenski/optool A command line tool for modifying Mach-O binaries on macOS and iOS. It can insert or remove load commands, strip or repair code signatures,… | 23 | 1287 | maintenance |
| entropy1337/infernal-twin Infernal-Wireless is an automated wireless hacking framework written in Python that aids penetration testers in assessing Wi-Fi security. I… | 23 | 1285 | maintenance |
| hangetzzu/saycheese SayCheese is a shell-based social engineering tool that generates a malicious HTTPS page to capture webcam photos from a target who clicks … | 32 | 1284 | maintenance |
| hsiafan/apk-parser A Java library for parsing Android APK files, extracting metadata such as package name, version, icon, and label. It also decodes binary XM… | 10 | 1284 | maintenance |
| starjun/openstar OpenStar (WAF+) is a Web Application Firewall written in Lua that runs on nginx/OpenResty (LuaJIT), filtering HTTP traffic through JSON-con… | 32 | 1283 | maintenance |
| longguikeji/arkid ArkID is an open-source enterprise IDaaS/IAM platform providing unified identity, authentication, and authorization management. It supports… | 23 | 1283 | maintenance |
| c0ny1/upload-fuzz-dic-builder A Python CLI script that generates fuzzing dictionaries for testing file upload vulnerabilities. It tailors wordlists based on target detai… | 32 | 1280 | maintenance |
| samr7/vanitygen A standalone command-line vanity Bitcoin address generator written in C that searches for addresses matching custom prefixes or regular exp… | 32 | 1279 | maintenance |
| rbsec/dnscan dnscan is a Python command-line tool that performs DNS subdomain enumeration using wordlists, attempting zone transfers first and falling b… | 32 | 1278 | maintenance |
| yzddmr6/webshell-venom A tool that generates unlimited polymorphic (AV-evading) webshells for penetration testing. It mutates webshell code to bypass antivirus an… | 10 | 1278 | maintenance |
| khast3x/Redcloud Redcloud is a Python-based toolbox that automates deployment of red team attack infrastructure using Docker, deployable locally or remotely… | 23 | 1277 | maintenance |
| netxfly/x-crack x-crack is a command-line weak password (credential brute-force) scanner written in Go that tests common username/password combinations aga… | 23 | 1277 | maintenance |
| XploitWizer-Community/XploitSPY XploitSPY is a self-hosted, cloud-based Android monitoring tool built on NodeJS that logs GPS, SMS, calls, notifications, microphone audio,… | 32 | 1276 | maintenance |
| SECFORCE/Tunna Tunna is a Python toolset that tunnels arbitrary TCP connections over HTTP using a remote webshell and a local SOCKS-capable proxy. It is d… | 32 | 1274 | maintenance |
| square/sudo_pair A sudo IO-plugin written in Rust that requires a second live human to approve and monitor privileged sudo sessions. It enforces dual-contro… | 32 | 1272 | maintenance |
| screetsec/Brutal Brutal is a Linux toolkit for generating HID attack payloads for Teensy boards, similar to a Rubber Ducky but with different syntax. It cre… | 32 | 1271 | maintenance |
| Song-Li/cross_browser A research project from Johns Hopkins implementing cross-browser fingerprinting that identifies users across different browsers on the same… | 32 | 1270 | maintenance |
| seccome/Ehoney Ehoney is an open-source, cloud-native deception defense system that deploys high-interaction honeypots, honeytokens, and baits to lure, de… | 23 | 1270 | maintenance |
| darkr4y/geacon Geacon is a Go implementation of CobaltStrike's Beacon implant, built to study the C2 protocol through reverse engineering. It supports com… | 32 | 1267 | maintenance |
| lintstar/LSTAR LSTAR is a comprehensive Cobalt Strike post-exploitation Aggressor plugin written in PowerShell and CNA. It consolidates host information g… | 23 | 1267 | maintenance |
| UzJu/Cloud-Bucket-Leak-Detection-Tools A Python CLI tool that detects misconfigured and leaked cloud storage buckets across six major cloud providers including Aliyun, Tencent Cl… | 29 | 1266 | maintenance |
| shack2/SuperSQLInjectionV1 SuperSQLInjection (SSQLInjection) is a C#-based GUI SQL injection tool that builds raw HTTP requests over TCP sessions, supporting injectio… | 23 | 1266 | maintenance |
| Cybellum/DoubleAgent DoubleAgent is a research tool and proof-of-concept demonstrating a zero-day code injection and persistence technique on Windows, exploitin… | 32 | 1262 | maintenance |
| rails/strong_parameters Strong Parameters is a Ruby gem that provides whitelisting (permit) and required-key checking for Action Controller parameters, preventing … | 10 | 1260 | maintenance |
| andresriancho/enumerate-iam A Python CLI tool that enumerates the IAM permissions associated with an AWS credential set by brute-forcing all non-destructive API calls … | 32 | 1256 | maintenance |
| Ansem-SoD/Picofly Picofly is firmware and documentation for a Nintendo Switch hardware modchip built on RP2040-based microcontrollers (RP2040-Zero, Pi Pico, … | 30 | 1252 | maintenance |
| pmiaowu/BurpFastJsonScan A passive BurpSuite extension written in Java that detects FastJson deserialization vulnerabilities in JSON-bearing HTTP requests. It autom… | 23 | 1252 | maintenance |
| libunwind/libunwind libunwind is a portable C library providing an API to determine and manipulate the call chain (stack frames) of program threads, supporting… | 72 | 1251 | maintenance |
| AbirHasan2005/ShellPhish A modified (modded) version of the ShellPhish phishing simulation tool that generates fake login pages for popular websites like Facebook, … | 32 | 1251 | maintenance |
| mozilla-mobile/focus-ios Firefox Focus for iOS is an open-source privacy-focused mobile web browser that automatically blocks online trackers and lets users erase h… | 10 | 1251 | maintenance |
| W01fh4cker/Serein Serein is a graphical Python tool for batch-collecting URLs via the FOFA search engine API and running batch detection/exploitation of know… | 10 | 1250 | maintenance |
| ReChronoRain/Cemiuiler Cemiuiler is an Xposed module that enhances and customizes MIUI (Xiaomi's Android skin) on Android 11-13 devices running MIUI 12.5-14. It h… | 10 | 1250 | maintenance |
| eliasgranderubio/dagda Dagda is a Python-based security tool that performs static analysis of known vulnerabilities, trojans, viruses, and malware in Docker image… | 23 | 1249 | maintenance |
| m4n3dw0lf/pythem pythem is a multi-purpose penetration testing framework written in Python 2.7, providing an interactive CLI for security researchers. It bu… | 32 | 1247 | maintenance |
| Yawning/obfs4 obfs4 is a look-like-nothing traffic obfuscation protocol (the obfourscator) implemented in Go, based on ScrambleSuit with ntor handshakes … | 32 | 1247 | maintenance |
| MinhasKamal/TrojanCockroach Trojan Cockroach is an educational C++ trojan spyware that logs keystrokes on Windows PCs, exfiltrates the stolen data via email, and sprea… | 54 | 1246 | maintenance |
| n4ru/1vyrain 1vyrain is a bootable LiveUSB exploit chain that unlocks hidden BIOS features on Ivy Bridge-based xx30 ThinkPad laptops via software flashi… | 32 | 1246 | maintenance |
| mgeeky/ThreadStackSpoofer A proof-of-concept C++ implementation of thread call stack spoofing, an in-memory evasion technique that hides shellcode references from a … | 23 | 1245 | maintenance |
| open-license-manager/licensecc Licensecc is an open-source C++ library for software licensing and copy protection that generates hardware signatures and validates license… | 67 | 1243 | maintenance |
| positive-security/find-you A modified version of OpenHaystack that demonstrates a stealth AirTag clone capable of bypassing Apple's Find My tracking protection featur… | 32 | 1242 | maintenance |
| kristovatlas/osx-config-check A Python command-line tool that audits macOS (OS X) machines against hardened security configuration baselines, such as drduh's OS X Securi… | 23 | 1241 | maintenance |
| Tylous/SniffAir SniffAir is an open-source wireless security framework for parsing passively collected wireless traffic and launching wireless attacks. It … | 23 | 1241 | maintenance |
| nahamsec/bbht A shell script that installs a curated set of popular bug bounty hunting and reconnaissance tools on an Ubuntu box. It automates setup of t… | 32 | 1240 | maintenance |
| gaffe23/linux-inject A command-line tool written in C that injects a shared object (.so) into a running Linux process using ptrace(), analogous to CreateRemoteT… | 32 | 1237 | maintenance |
| blst-security/cherrybomb Cherrybomb is a Rust-based CLI tool that audits OpenAPI specifications for best practices and OAS compliance, then runs security tests agai… | 23 | 1236 | maintenance |
| Zerx0r/Kage Kage is an Electron-based graphical user interface for the Metasploit Framework's RPC server, allowing users to manage meterpreter sessions… | 10 | 1236 | maintenance |
| morrownr/88x2bu-20210702 An out-of-tree Linux kernel driver for USB WiFi adapters based on Realtek RTL8812BU and RTL8822BU chipsets, based on Realtek's v5.13.1 sour… | 77 | 1233 | maintenance |
| dark-player/instabrute.github.io IG-HACK is a bash-based brute-force script that attempts to crack Instagram account passwords using wordlist attacks, designed to run in Te… | 38 | 1232 | maintenance |
| mrknow001/aliyun-accesskey-Tools A Python tool for exploiting leaked Alibaba Cloud (Aliyun) AccessKeys: it enumerates ECS hosts associated with a key and enables remote com… | 23 | 1232 | maintenance |
| cloudflare/bpftools A toolkit of Python scripts and Linux binaries for analyzing pcap traffic dumps and generating BPF bytecode. Its core purpose is crafting B… | 67 | 1230 | maintenance |
| decentralized-identity/ion ION is a public, permissionless Decentralized Identifier (DID) network implementing the Sidetree protocol as a Layer 2 overlay on Bitcoin. … | 23 | 1228 | maintenance |
| bryanpkc/corkscrew Corkscrew is a small C command-line tool that tunnels SSH connections through HTTP proxies by acting as an SSH ProxyCommand helper. It supp… | 32 | 1227 | maintenance |
| craigz28/firmwalker Firmwalker is a simple bash script that searches extracted or mounted firmware file systems for security-relevant files and content, such a… | 32 | 1225 | maintenance |
| dagrz/aws_pwn A collection of Python scripts for penetration testing AWS environments, covering reconnaissance, exploitation, stealth, exploration, and p… | 32 | 1224 | maintenance |
| AndroBugs/AndroBugs_Framework AndroBugs Framework is a command-line Android vulnerability scanner that analyzes APK files to find potential security vulnerabilities and … | 10 | 1224 | maintenance |
| am0nsec/HellsGate The original C implementation of the Hell's Gate technique, which resolves Windows system call numbers at runtime to invoke NT APIs directl… | 32 | 1221 | maintenance |
| eastmaple/easytrojan A one-line shell script that deploys a Trojan proxy server on Linux, automatically provisioning a free nip.io domain and Let's Encrypt/Zero… | 32 | 1220 | maintenance |
| hacktoolspack/hack-tools A curated collection of free hacking and cybersecurity tools covering DoS, information gathering, malware/ransomware generation, and remote… | 23 | 1219 | maintenance |
| nccgroup/redsnarf RedSnarf is a pen-testing/red-teaming tool for retrieving hashes and credentials from Windows workstations, servers, and domain controllers… | 32 | 1216 | maintenance |
| HirbodBehnam/MTProtoProxyInstaller A one-click bash installer script that sets up an MTProto proxy server for Telegram on CentOS, Ubuntu, and Debian. It generates secrets, co… | 32 | 1216 | maintenance |
| vysecurity/LinkedInt LinkedInt is a Python CLI tool for LinkedIn reconnaissance that scrapes employee profiles for a target company and generates an HTML report… | 10 | 1215 | maintenance |
| elkokc/reflector Reflector is a Burp Suite extension written in Java that detects reflected XSS vulnerabilities in real time while browsing a target web app… | 23 | 1214 | maintenance |
| tp4a/teleport Teleport is an open-source bastion host (jump server) system that proxies and audits RDP, SSH, SFTP, and Telnet remote connections. It bund… | 23 | 1214 | maintenance |
| iagox86/hash_extender A C command-line tool that automates hash length extension attacks against algorithms like MD4, MD5, SHA-1, SHA-256, SHA-512, RIPEMD-160, a… | 34 | 1212 | maintenance |
| ebekker/ACMESharp ACMESharp is an ACME protocol client library and PowerShell module for the .NET platform, primarily used to obtain and manage certificates … | 23 | 1210 | maintenance |
| EddieIvan01/iox iox is a Go-based command-line tool for TCP/UDP port forwarding and intranet SOCKS5 proxying, serving as a modern replacement for lcx/ew. I… | 23 | 1210 | maintenance |
| Viralmaniar/Powershell-RAT A Python-based remote access trojan (RAT) for red team engagements that backdoors Windows machines via scheduled tasks and exfiltrates scre… | 23 | 1207 | maintenance |
| sigstore/rekor Rekor is Sigstore's software supply chain transparency log, providing an immutable tamper-resistant ledger for signed build and provenance … | 95 | 1204 | maintenance |
| openenclave/openenclave Open Enclave SDK is a hardware-agnostic open source SDK for building C and C++ applications that use hardware-based Trusted Execution Envir… | 86 | 1204 | maintenance |
| Al-Azif/ps4-exploit-host A self-hosted exploit hosting tool for game consoles (PS4, PS5, Vita, Switch, Wii) that serves exploits over a LAN via DNS and HTTP. It can… | 23 | 1203 | maintenance |
| LiNuX-Mallu/CAM-DUMPER CAM-DUMPER is a shell-based security testing tool that generates a malicious HTTPS page served via Serveo or Ngrok port forwarding to captu… | 32 | 1202 | maintenance |
| softScheck/tplink-smartplug A Python command-line client for the proprietary TP-Link Smart Home protocol that controls HS100, HS110, and KP115 WiFi smart plugs over TC… | 32 | 1201 | maintenance |
| Viralmaniar/I-See-You ISeeYou is a Bash and JavaScript tool that captures a target's exact GPS coordinates (latitude/longitude) during social engineering or phis… | 32 | 1199 | maintenance |
| fofapro/Hosts_scan A small Python tool that brute-force matches IP addresses against domain names by binding Hosts headers, to discover weak or internal syste… | 32 | 1197 | maintenance |
| OWASP/joomscan OWASP JoomScan is an open-source Perl-based vulnerability scanner for Joomla CMS deployments. It enumerates versions, components, and known… | 23 | 1196 | maintenance |
| lucb1e/cookielesscookies A PHP demo showing how users can be tracked via HTTP ETag headers instead of cookies or localStorage. It serves as an educational proof-of-… | 37 | 1194 | maintenance |
| drcoms/drcom-generic An open-source Python reimplementation of the Dr.COM/DrCOM campus network authentication client, with d, p, and x protocol variants. It let… | 32 | 1193 | maintenance |
| l3m0n/Bypass_Disable_functions_Shell A PHP webshell that collects various techniques for bypassing PHP's disable_functions restriction to achieve command execution, including L… | 32 | 1193 | maintenance |
| the-xentropy/xencrypt Xencrypt is a single-file PowerShell crypter that encrypts, compresses, and obfuscates PowerShell scripts to bypass AMSI and antivirus dete… | 32 | 1192 | maintenance |
| alichtman/stronghold Stronghold is a Python command-line tool that securely configures macOS security settings such as the firewall, Gatekeeper, and metadata co… | 26 | 1191 | maintenance |
| AlexisAhmed/BugBountyToolkit A multi-platform bug bounty toolkit that bundles popular security and reconnaissance tools (Nmap, Amass, sqlmap, ffuf, etc.) into a pre-con… | 32 | 1190 | maintenance |
| bats3c/DarkLoadLibrary DarkLoadLibrary is a C library implementing an alternative to the Windows LoadLibrary API designed for offensive security operations. It lo… | 32 | 1190 | maintenance |
| shadow-1/yi-hack-v3 A collection of Makefiles, config files, and scripts that build alternative custom firmware for Xiaomi Yi cameras based on the HiSilicon Hi… | 23 | 1190 | maintenance |
| olafhartong/ThreatHunting A Splunk app with dashboards and over 130 pre-built search reports mapped to the MITRE ATT&CK framework to guide threat hunting. It require… | 32 | 1188 | maintenance |
| isboyjc/cursor-reset A cross-platform script and executable that resets the Cursor editor's trial period by resetting its machine fingerprint. It supports Curso… | 10 | 1188 | maintenance |