function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| ReversecLabs/awspx awspx is a graph-based security tool that visualizes effective access and resource relationships in AWS environments. It resolves IAM polic… | 23 | 1018 | maintenance |
| maaaaz/impacket-examples-windows A repository of pre-compiled Windows binaries of the Impacket example scripts, a collection of network protocol tools for security testing.… | 23 | 1018 | maintenance |
| quentinhardy/msdat MSDAT is an open-source Python penetration testing tool for remotely testing the security of Microsoft SQL Server databases. It supports cr… | 32 | 1017 | maintenance |
| hackerxphantom/HACK-CAMERA A Bash-based penetration-testing tool that hosts a phishing page which requests camera access and captures webcam shots from targets who op… | 23 | 1017 | maintenance |
| secretsquirrel/BDFProxy BDFProxy is a man-in-the-middle proxy that patches downloaded binaries on the fly by embedding payloads, combining the Backdoor Factory wit… | 32 | 1016 | maintenance |
| rwfpl/rewolf-wow64ext A C++ helper library enabling 32-bit (x86) applications running under the WOW64 layer on 64-bit Windows to interact with native x64 process… | 23 | 1015 | maintenance |
| WithSecureLabs/python-exe-unpacker A Python CLI script that unpacks and decompiles Windows EXEs compiled from Python code, supporting executables built with py2exe and PyInst… | 32 | 1014 | maintenance |
| c0ny1/java-memshell-scanner A JSP-based scanner that detects and helps remove Java web memory shells (memshells) such as Filter, Servlet, and Listener types in middlew… | 32 | 1014 | maintenance |
| ajayrandhawa/Keylogger A Windows keylogger written in Visual C++ that invisibly captures keystrokes, mouse clicks, and periodic screenshots, uploading them to an … | 49 | 1012 | maintenance |
| everestpipkin/image-scrubber A browser-based tool for anonymizing photographs taken at protests by stripping Exif metadata and letting users paint over or blur faces an… | 32 | 1012 | maintenance |
| zhovner/OneFileLinux A minimal live Linux distribution packed into a single ~20MB EFI executable that boots directly from any UEFI computer's firmware without i… | 23 | 1012 | maintenance |
| felix-pb/kfd kfd is a C library that provides kernel memory read/write on Apple devices by exploiting physical use-after-free (PUAF) vulnerabilities to … | 28 | 1011 | maintenance |
| facebookexperimental/MIRAI MIRAI is an abstract interpreter for Rust's mid-level intermediate representation (MIR) that performs static analysis to detect potential b… | 10 | 1011 | maintenance |
| atc-project/atomic-threat-coverage Atomic Threat Coverage is a Python framework that automatically generates actionable security analytics from Detection, Response, Mitigatio… | 32 | 1010 | maintenance |
| ryancdotorg/brainflayer Brainflayer is a proof-of-concept command-line cracker for cryptocurrency brainwallets and other low-entropy key derivation schemes, using … | 32 | 1010 | maintenance |
| s7ckTeam/Glass Glass is a Python CLI tool for rapid fingerprint identification of asset lists, querying Fofa, ZoomEye, Shodan, and 360 Quake APIs to gathe… | 32 | 1010 | maintenance |
| TideSec/FuzzScanner FuzzScanner is a Ruby/Python-based reconnaissance toolset that batch-collects information about target websites, including subdomains, open… | 32 | 1008 | maintenance |
| feihong-cs/Java-Rce-Echo A collection of Java test code for achieving command output echo after remote code execution (RCE) across common application servers and pl… | 32 | 1008 | maintenance |
| mayankk2308/purge-wrangler A shell script that patches macOS to enable unsupported AMD and NVIDIA external GPU (eGPU) configurations on Thunderbolt Macs. It has been … | 23 | 1008 | maintenance |
| Snorby/snorby Snorby is a Ruby on Rails web application for network security monitoring that interfaces with intrusion detection systems such as Snort, S… | 23 | 1007 | maintenance |
| stormshadow07/HackTheWorld A Python CLI script that generates Windows payloads designed to evade antivirus detection, integrating with Metasploit and mingw-w64 for co… | 32 | 1006 | maintenance |
| CRAnimation/CRBoxInputView CRBoxInputView is an iOS UI component library written in Objective-C that provides a boxed verification-code input view, commonly used for … | 32 | 1005 | maintenance |
| maaaaz/thc-hydra-windows A Windows-compiled distribution of THC-HYDRA, the popular network login brute-forcing tool, bundled with Cygwin DLLs and optional SSH, MySQ… | 23 | 1004 | maintenance |
| TheKingOfDuck/ApkAnalyser A Python-based command-line tool that extracts potentially sensitive information from Android APK files, including URLs, IPs, hashes, acces… | 23 | 1004 | maintenance |
| ddz/whatsapp-media-decrypt A Go command-line tool that decrypts WhatsApp encrypted media files (.enc) using the media key extracted from WhatsApp's local databases on… | 32 | 1003 | maintenance |
| Mattiwatti/PPLKiller PPLKiller is a Windows kernel-mode driver that removes Protected Process Light (PPL) protection from all running processes on Windows 8.1 a… | 32 | 1000 | maintenance |
| theseus-os/Theseus Theseus is a research operating system written from scratch in Rust that explores intralingual design, shifting OS responsibilities like re… | 32 | 3192 | experimental |
| snyk/agent-scan Snyk Agent Scan is a Python-based CLI security scanner that discovers installed AI agent components (agent harnesses, MCP servers, and agen… | 82 | 3003 | experimental |
| microsoft/litebox LiteBox is a security-focused library OS written in Rust that drastically reduces the interface exposed to the host, minimizing attack surf… | 66 | 2686 | experimental |
| Armur-Ai/Pentest-Swarm-AI An open-source autonomous penetration testing application that orchestrates a swarm of AI agents (recon, classification, exploitation, repo… | 75 | 2449 | experimental |
| nebulet/nebulet Nebulet is a proof-of-concept microkernel written in Rust that executes WebAssembly modules in Ring 0 within a single address space. It use… | 10 | 2356 | experimental |
| s0md3v/Striker Striker is a Python-based offensive reconnaissance and vulnerability scanning suite that discovers subdomains, scans common ports, detects … | 23 | 2341 | experimental |
| cryfs/cryfs CryFS is a cryptographic filesystem that encrypts files locally so they can be safely stored in cloud services like Dropbox, iCloud, or One… | 85 | 2304 | experimental |
| accrescent/accrescent Accrescent is a security- and privacy-focused Android app store client built in Kotlin with Jetpack Compose. It enforces signed repository … | 84 | 2230 | experimental |
| Jigsaw-Code/Intra Intra is an experimental Android app from Jigsaw (Google) that routes DNS lookups over DNS-over-HTTPS to encrypt them and prevent network-l… | 75 | 2187 | experimental |
| vgough/encfs EncFS is a userspace encrypted virtual filesystem built on FUSE, originally released in 2003 and recently rewritten in Rust. It transparent… | 84 | 2161 | experimental |
| earendil-works/gondolin Gondolin is a TypeScript library and CLI that runs untrusted AI-agent code inside fast local Linux micro-VMs (QEMU by default, optional lib… | 73 | 2097 | experimental |
| xoreaxeaxeax/skitter-creek-bath-salts A security research tool written in C that reprograms AMD Family 16h DRAM controller address translation registers to scramble physical mem… | 56 | 1982 | experimental |
| google/rune Rune is an experimental, Python-inspired systems programming language from Google that compiles to C and emphasizes memory safety and const… | 74 | 1929 | experimental |
| m4ll0k/BBTz A collection of bug bounty tools and example scripts written in Python by security researcher m4ll0k. It serves as a set of ideas and refer… | 32 | 1911 | experimental |
| aurae-runtime/aurae Aurae is a memory-safe distributed systems runtime daemon written in Rust that acts as a process manager and PID-1 initialization system fo… | 67 | 1909 | experimental |
| codykociemba/NoLongerEvil-Thermostat No Longer Evil is a right-to-repair firmware and cloud replacement for bricked or sunset Nest Gen 1 and Gen 2 thermostats. It flashes modif… | 54 | 1836 | experimental |
| xyzeva/k-id-age-verifier A TypeScript tool that automatically completes K-ID age verification as an adult on platforms like Discord, Twitch, Kick, and Quora. It aut… | 45 | 1727 | experimental |
| GFW-knocker/gfw_resist_tls_proxy A set of Python proof-of-concept scripts (notably pyprox and randchunk) that fragment TLS Client Hello packets to evade SNI-based deep pack… | 30 | 1708 | experimental |
| PedroHBessa/backscan A Node.js web application that serves a fake 'Comprovante' (payment receipt) page and exfiltrates the visitor's geolocation to an attacker-… | 28 | 1690 | experimental |
| MSNightmare/RoguePlanet RoguePlanet is a proof-of-concept exploit for a Windows Defender vulnerability written in C++. It uses a race condition (triggered via ISO … | 52 | 1638 | experimental |
| TarlogicSecurity/BlueSpy BlueSpy is a Python proof-of-concept tool that records and replays audio from vulnerable Bluetooth devices by exploiting pairing without us… | 61 | 1614 | experimental |
| google/keytransparency A Google open-source key transparency service that provides a lookup service for public keys backed by a publicly auditable, tamper-proof l… | 10 | 1569 | experimental |
| protectai/rebuff Rebuff is a self-hardening prompt injection detector that protects LLM-powered applications through multi-layered defenses: heuristics, a d… | 10 | 1521 | experimental |
| JonathanSalwan/VMProtect-devirtualization An experimental research project demonstrating a dynamic approach to devirtualize pure functions protected by VMProtect 3.x using symbolic … | 32 | 1515 | experimental |
| opa334/darksword-kexploit A reimplementation of the DarkSword kernel exploit in Objective-C, targeting iOS 15.0 through 26.0.1. It is a security research artifact ba… | 48 | 1495 | experimental |
| whitequark/unfork unfork(2) is a proof-of-concept Linux technique and library that joins two process address spaces into one, the inverse of fork(2), by comb… | 32 | 1486 | experimental |
| faizann24/wifi-bruteforcer-fsecurify An Android application that attempts to brute force WiFi passwords without requiring a rooted device. It is written in Java and distributed… | 32 | 1484 | experimental |
| achuna33/MYExploit MYExploit is a Java-based one-click scanning and exploitation tool targeting OA (office automation) enterprise products, built as an extens… | 23 | 1484 | experimental |
| alephsecurity/xnu-qemu-arm64 A fork of QEMU that emulates an iPhone (iPhone 6s Plus) well enough to boot a fully functional iOS 12.1 system, including launchd, bash, SS… | 32 | 1460 | experimental |
| bulwarkid/virtual-fido Virtual FIDO is a software-emulated FIDO2/U2F USB security key (like a YubiKey) that attaches to the host via a USB/IP server over local TC… | 32 | 1396 | experimental |
| chompie1337/SMBGhost_RCE_PoC A Python proof-of-concept exploit for CVE-2020-0796 (SMBGhost), achieving pre-authentication remote code execution against vulnerable Windo… | 32 | 1395 | experimental |
| iPower/KasperskyHook A Windows research project that hooks system calls by loading Kaspersky's hypervisor driver (klhk.sys) and a custom kernel driver that subv… | 66 | 1316 | experimental |
| amimo/dcc DCC (Dex-to-C Compiler) is a method-based ahead-of-time compiler that translates Android DEX bytecode into C code compiled via the NDK. It … | 32 | 1312 | experimental |
| SPIRIT-org/SPIRIT SPIRIT is an open-source smartphone hardware project built around the Raspberry Pi Compute Module 5, with KiCad PCB designs and schematics … | 67 | 1290 | experimental |
| microsoft/mxc MXC (Microsoft eXecution Container) is a sandboxed code execution system for safely running untrusted code such as model output, plugins, a… | 69 | 1283 | experimental |
| openairymax/agentrt AgentRT is an OS-grade runtime platform for AI agent teams, providing primitives for orchestrating, scheduling, isolating, and observing ag… | 66 | 1265 | experimental |
| ariel-os/ariel-os Ariel OS is a library operating system for secure, memory-safe, low-power IoT devices, written in Rust and targeting 32-bit microcontroller… | 77 | 1218 | experimental |
| lem0nSec/ShellGhost ShellGhost is a proof-of-concept memory-based evasion technique written in C that keeps shellcode invisible in memory from process start to… | 29 | 1200 | experimental |
| blackhillsinfosec/WifiForge WifiForge is a Python-based training framework from Black Hills InfoSec that simulates Wi-Fi networks using mininet-wifi so pentesters can … | 70 | 1190 | experimental |
| leonboe1/GoogleFindMyTools A Python framework that reimplements parts of Google's Find My Device (Find Hub) network, allowing users to query trackers and Android devi… | 58 | 1163 | experimental |
| tailscale/tailscale-rs A work-in-progress Rust implementation of Tailscale, providing a library for building tailnet-connected applications with bindings to C, El… | 81 | 1130 | experimental |
| JuliaPoo/Artfuscator Artfuscator is a novelty C compiler built on ELVM that compiles C programs into a binary whose entire control flow graph renders as a chose… | 32 | 1104 | experimental |
| berylliumsec/nebula Nebula is an AI-powered penetration testing desktop application that combines a terminal, browser, notes, findings, and reporting into one … | 92 | 1100 | experimental |
| dennis-tra/pcp pcp is a command-line peer-to-peer file transfer tool built on libp2p that transfers data directly between peers without relying on central… | 10 | 1099 | experimental |
| moturus/motor-os Motor OS is a microkernel-based operating system written entirely in Rust, designed for virtualized cloud workloads such as web serving, se… | 71 | 1090 | experimental |
| koutto/jok3r Jok3r is a Python3 CLI framework that automates network and web black-box penetration testing by chaining 50+ open-source security tools. I… | 32 | 1088 | experimental |
| google-deepmind/synthid-text A reference Python implementation of Google DeepMind's SynthID Text watermarking and detection technology for identifying AI-generated text… | 65 | 1085 | experimental |
| MultiboxLabs/flow-browser Flow Browser is a modern, privacy-focused desktop web browser built on Electron with Chromium rendering. It offers tabbed browsing, Chrome … | 74 | 1070 | experimental |
| dannymcc/bluehood Bluehood is a self-hosted Bluetooth scanner that passively detects nearby BLE and Classic Bluetooth devices, identifies them by vendor and … | 77 | 1063 | experimental |
| ZeroMemoryEx/Terminator Terminator is a C++ proof-of-concept tool that terminates EDR/XDR/antivirus processes on Windows by abusing the vulnerable, signed zam64.sy… | 20 | 1062 | experimental |
| syphon-org/syphon Syphon is a privacy-centric, open-source Matrix chat client built with Flutter/Dart, featuring end-to-end encryption via Olm/Megolm and no … | 23 | 1058 | experimental |
| hackerxphantom/Facebook_hack A Python command-line tool that performs brute-force password attacks against Facebook accounts using an email or profile ID as the target,… | 10 | 1039 | experimental |
| fikrado/fikrado.py A Python 2.7 command-line script that attempts to gain access to Facebook accounts via the Facebook API using brute-force techniques. It ta… | 23 | 1037 | experimental |
| cloud-gouv/securix SécurixOS is a NixOS-based hardened Linux distribution for secure workstations, developed by the French DINUM for sysadmin, office, and dev… | 88 | 1029 | experimental |
| DragoQCC/CrucibleC2 HardHat C2 (CrucibleC2) is a cross-platform, multi-user Command & Control framework written in C#/.NET for red team engagements and penetra… | 22 | 1024 | experimental |
| brix/crypto-js CryptoJS is a JavaScript library implementing standard cryptographic algorithms such as AES, DES, MD5, SHA family hashes, HMAC, and PBKDF2,… | 32 | 16407 | abandoned |
| apprenticeharper/DeDRM_tools A collection of Python scripts packaged as calibre plugins (DeDRM and Obok) that remove DRM from ebooks, covering Amazon, Adobe Digital Edi… | 23 | 15322 | abandoned |
| PowerShellMafia/PowerSploit PowerSploit is a collection of PowerShell modules for post-exploitation tasks during penetration tests, covering code execution, persistenc… | 10 | 13085 | abandoned |
| google/sanitizers The Google sanitizers repository hosts documentation and helper code for AddressSanitizer, ThreadSanitizer, MemorySanitizer, LeakSanitizer,… | 70 | 12465 | abandoned |
| pixeltris/TwitchAdSolutions A collection of userscripts and uBlock Origin filters that block or bypass ads on Twitch streams using techniques like video swapping and a… | 10 | 11383 | abandoned |
| xaoyaoo/PyWxDump PyWxDump was a Python tool for extracting and decrypting WeChat local data such as messages, contacts, and account information from Windows… | 40 | 9678 | abandoned |
| byt3bl33d3r/CrackMapExec CrackMapExec is a Python-based command-line swiss army knife for pentesting Windows and Active Directory networks, supporting protocols lik… | 10 | 9162 | abandoned |
| 99designs/aws-vault AWS Vault is a CLI tool that securely stores AWS IAM credentials in the operating system's native keystore (macOS Keychain, Windows Credent… | 49 | 8986 | abandoned |
| CodeTips/BaiduNetdiskPlugin-macOS A macOS plugin that patches the Baidu Netdisk client binary via dylib injection to fake SVIP status and remove local download speed limits.… | 10 | 8876 | abandoned |
| rkt/rkt rkt is a pod-native container engine for Linux, designed to be secure, composable, and built on open standards like appc, CNI, and OCI. Dev… | 10 | 8766 | abandoned |
| EmpireProject/Empire Empire is a post-exploitation framework with a pure PowerShell Windows agent and a pure Python Linux/OS X agent, offering encrypted communi… | 10 | 7860 | abandoned |
| WindowsAddict/IDM-Activation-Script An open-source batch/PowerShell script that activates Internet Download Manager or freezes/resets its 30-day trial using a registry key loc… | 10 | 7692 | abandoned |
| bitwiseshiftleft/sjcl The Stanford Javascript Crypto Library (SJCL) is a JavaScript library providing high-level cryptographic primitives such as AES encryption,… | 55 | 7199 | abandoned |
| facebook/pyre-check Pyre is a performant, PEP 484-compliant static type checker for Python that provides incremental checking of large codebases, and it ships … | 10 | 7171 | abandoned |
| alibaba/AndFix AndFix is an Android library that provides online hot-fix capability, allowing developers to patch bugs in a shipped app by replacing metho… | 32 | 6965 | abandoned |
| LeDragoX/Win-Debloat-Tools A PowerShell-based tool with a GUI that debloats Windows 10/11, removing bloatware and applying system tweaks to make Windows feel like a m… | 10 | 6371 | abandoned |
| datreeio/datree Datree is a CLI-based policy enforcement tool that scans Kubernetes YAML manifests against built-in and custom rules to block misconfigurat… | 10 | 6334 | abandoned |
| p-e-w/maybe maybe is a Python CLI tool that runs a command under ptrace and intercepts filesystem-modifying syscalls, turning them into no-ops so you c… | 10 | 6301 | abandoned |
| TheRealJoelmatic/RemoveAdblockThing A Tampermonkey userscript that removes YouTube's 'Ad blocker is not allowed' popup and bypasses ad blocker detection. It also provides an u… | 10 | 5980 | abandoned |