function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| cuckoosandbox/cuckoo Cuckoo Sandbox is an open-source automated dynamic malware analysis system that executes suspicious files in an isolated environment and re… | 10 | 5966 | abandoned |
| tenable/terrascan Terrascan is a static code analyzer for Infrastructure as Code that detects compliance and security violations across Terraform, CloudForma… | 10 | 5210 | abandoned |
| RikkaApps/Riru Riru is a Magisk module that injects code into Android's zygote process, allowing other modules to run their code inside app processes or t… | 10 | 5143 | abandoned |
| aquasecurity/kube-hunter kube-hunter is a Python-based tool that hunts for security weaknesses and vulnerabilities in Kubernetes clusters, running remotely, on a ma… | 23 | 5084 | abandoned |
| unCaptcha unCaptcha2 is a Python-based security research tool that defeats Google's ReCaptcha v2 audio challenges by submitting the audio to free spe… | 32 | 4916 | abandoned |
| 10se1ucgo/DisableWinTracking A Windows 10 utility that applies known registry and service tweaks to minimize Microsoft telemetry and tracking. It ships as a GUI/CLI Pyt… | 10 | 4902 | abandoned |
| ARMmbed/mbed-os Arm Mbed OS is an open-source embedded operating system for IoT devices built on Arm Cortex-M microcontrollers, providing an RTOS, security… | 23 | 4871 | abandoned |
| nbs-system/naxsi NAXSI is a high-performance, low-maintenance web application firewall (WAF) implemented as a third-party NGINX module written in C. Instead… | 10 | 4811 | abandoned |
| Consensys/quorum GoQuorum is a permissioned implementation of Ethereum built as a fork of go-ethereum, adding transaction and contract privacy plus alternat… | 10 | 4763 | abandoned |
| spring-attic/spring-security-oauth A Spring Security library providing OAuth 1(a) and OAuth 2 support for both consumers and providers in Spring web applications. It was arch… | 10 | 4690 | abandoned |
| oblique/create_ap A shell script that turns a Linux machine's WiFi adapter into a NATed or bridged wireless access point using hostapd. It supports WPA/WPA2 … | 10 | 4510 | abandoned |
| google/santa Santa is a binary and file access authorization system for macOS, consisting of a system extension that monitors executions, a daemon that … | 10 | 4509 | abandoned |
| shadowsocksr-backup/shadowsocksr-csharp ShadowsocksR is a Windows proxy client written in C# that tunnels traffic through ShadowsocksR servers via a local SOCKS5/HTTP proxy with s… | 23 | 4494 | abandoned |
| shadowsocksr-backup/shadowsocks-rss ShadowsocksR (SSR) is a fork of Shadowsocks providing an encrypted SOCKS/HTTP proxy client and server with additional protocol obfuscation … | 32 | 4438 | abandoned |
| buttercup/buttercup-desktop Buttercup Desktop is a free, open-source, cross-platform password manager built with Electron and TypeScript that stores credentials in enc… | 10 | 4392 | abandoned |
| Netflix/security_monkey Security Monkey is a self-hosted service from Netflix that monitors AWS, GCP, OpenStack, and GitHub organizations for assets and policy cha… | 10 | 4371 | abandoned |
| zhzyker/exphub Exphub is a collection of standalone Python, Java, PHP, and shell exploit scripts for known CVE vulnerabilities in products like Weblogic, … | 32 | 4290 | abandoned |
| iMeiji/shadowsocks_install A shell script that automatically installs and configures a Shadowsocks proxy server on Linux VPS instances, forked from Teddysun's well-kn… | 23 | 4170 | abandoned |
| nucleuscloud/neosync Neosync is an open-source data security platform that detects PII, anonymizes production data, and generates synthetic data to sync across … | 10 | 4141 | abandoned |
| bytecodealliance/lucet Lucet is a native WebAssembly ahead-of-time compiler and runtime for safely executing untrusted Wasm programs inside applications, built on… | 10 | 4045 | abandoned |
| Arachni/arachni Arachni is a modular, high-performance Ruby framework for scanning web applications for security vulnerabilities, including XSS and SQL inj… | 10 | 4042 | abandoned |
| eth0izzle/shhgit shhgit is a secrets detection tool that scans GitHub, GitLab, Bitbucket repositories and local directories for accidentally committed crede… | 36 | 3978 | abandoned |
| bitpay/wallet BitPay Wallet (formerly Copay) is an open-source, self-custody cryptocurrency wallet for Bitcoin, Bitcoin Cash, Ethereum, and ERC20 tokens … | 52 | 3942 | abandoned |
| FoundZiGu/GuJumpgate A Chrome browser extension that automated registration of free accounts and PayPal-based Plus subscription activation flows, including emai… | 10 | 3921 | abandoned |
| trailofbits/manticore Manticore is a symbolic execution tool for analyzing Ethereum smart contracts, Linux ELF binaries, and WASM modules. It explores program st… | 10 | 3857 | abandoned |
| Jessecar96/SteamDesktopAuthenticator A Windows desktop application that implements Steam's mobile authenticator (Steam Guard), allowing users to generate two-factor authenticat… | 23 | 3814 | abandoned |
| offensive-security/kali-nethunter Kali NetHunter is an Android ROM overlay providing a mobile penetration testing platform, combining a custom kernel, a Kali Linux chroot, a… | 10 | 3809 | abandoned |
| FastForwardTeam/FastForward FastForward is a browser extension for Chromium, Edge, and Firefox that automatically skips link shorteners and wait-for-ad interstitial pa… | 66 | 3772 | abandoned |
| yck1509/ConfuserEx ConfuserEx is a free, open-source protector for .NET applications that provides obfuscation features such as symbol renaming, control flow … | 10 | 3765 | abandoned |
| andOTP/andOTP andOTP is an open-source two-factor authentication app for Android that generates TOTP and HOTP one-time passwords. It stores tokens in enc… | 10 | 3713 | abandoned |
| cSploit/android cSploit is an open-source Android network analysis and penetration testing suite for rooted devices, integrating Metasploit RPC, MITM attac… | 23 | 3649 | abandoned |
| byt3bl33d3r/MITMf MITMf is a Python framework for performing Man-In-The-Middle and network attacks, featuring built-in SMB, HTTP, and DNS servers, an SSLStri… | 10 | 3645 | abandoned |
| YTLitePlus/YTLitePlus YTLitePlus is a tweaked YouTube client for iOS bundling YouTube Plus (YTLite) with tweaks like iSponsorBlock, background playback, ad remov… | 64 | 3638 | abandoned |
| Proxmark/proxmark3 The official (now archived) client software, FPGA logic, and design documentation for the Proxmark3, a general-purpose RFID tool that can s… | 50 | 3539 | abandoned |
| paralleldrive/cuid A deprecated JavaScript library for generating collision-resistant unique IDs optimized for horizontal scaling. It is insecure because it l… | 67 | 3503 | abandoned |
| henryboldi/felony Felony is an open-source PGP keychain desktop app built with Electron, React, and Redux, designed to make PGP encryption approachable for n… | 23 | 3461 | abandoned |
| google/lmctfy lmctfy (Let Me Contain That For You) is the open-source version of Google's container stack, providing Linux application containers with re… | 10 | 3404 | abandoned |
| 31b4/Leetcode-Premium-Bypass A Chrome browser extension that unlocked LeetCode premium features such as company-tagged questions and frequency bars without a paid subsc… | 10 | 3388 | abandoned |
| kjur/jsrsasign jsrsasign is a pure JavaScript cryptography library supporting RSA/RSAPSS/ECDSA/DSA signing and validation, ASN.1, PKCS key formats, X.509 … | 94 | 3373 | abandoned |
| EFForg/https-everywhere HTTPS Everywhere was a Firefox, Chrome, and Opera browser extension by EFF that rewrote HTTP requests to HTTPS to encrypt browsing. It was … | 10 | 3353 | abandoned |
| maxchehab/CSS-Keylogging A proof-of-concept Chrome extension and Express server demonstrating a CSS-based keylogging attack using attribute selectors and background… | 32 | 3240 | abandoned |
| protectai/llm-guard LLM Guard is a Python library providing input and output scanners to secure LLM interactions, including sanitization, harmful language dete… | 10 | 3204 | abandoned |
| Netflix/consoleme ConsoleMe is a web service from Netflix that centralizes AWS IAM permission management, offering console login, self-service permission req… | 10 | 3197 | abandoned |
| FeeiCN/Cobra Cobra is a source code security audit (SAST) tool that scans PHP, Java, and other languages for common vulnerabilities like SQL injection, … | 10 | 3186 | abandoned |
| jipegit/OSXAuditor OS X Auditor is a free Mac OS X computer forensics tool that parses and hashes system artifacts such as kernel extensions, daemons, startup… | 32 | 3133 | abandoned |
| stefanesser/dumpdecrypted A dylib that, when injected via DYLD_INSERT_LIBRARIES into an encrypted iPhone application on a jailbroken device, dumps the decrypted Mach… | 32 | 3036 | abandoned |
| NewEraCracker/LOIC LOIC (Low Orbit Ion Cannon) is an open-source network stress testing tool written in C#, based on Praetox's original LOIC. It supports TCP/… | 10 | 2967 | abandoned |
| microsoft/Git-Credential-Manager-for-Windows A secure Git credential helper for Windows that stores credentials and supports multi-factor authentication with GitHub, Bitbucket, and Vis… | 10 | 2939 | abandoned |
| facebookarchive/conceal Conceal is a Facebook library providing Java APIs for fast, memory-efficient encryption and authentication of data on Android, especially l… | 10 | 2930 | abandoned |
| zhuhaow/SpechtLite SpechtLite is a rule-based proxy application for macOS written in Swift. It has been archived because its underlying library, NEKit, is dep… | 10 | 2912 | abandoned |
| optiv/ScareCrow ScareCrow is a Go-based payload creation framework designed to bypass EDR (Endpoint Detection and Response) and application whitelisting co… | 10 | 2890 | abandoned |
| da2x/EdgeDeflector EdgeDeflector is a tiny Windows helper application that intercepts URIs forced to open in Microsoft Edge (such as links from Cortana and bu… | 10 | 2859 | abandoned |
| mozilla/bleach Bleach is a Python library for sanitizing HTML from untrusted sources using an allowlist-based approach, escaping or stripping markup and a… | 10 | 2766 | abandoned |
| Netflix/bless BLESS is an SSH Certificate Authority that runs as an AWS Lambda function and signs short-lived SSH certificates for user authentication. I… | 23 | 2759 | abandoned |
| speakeasyjs/speakeasy Speakeasy is a Node.js one-time passcode generator implementing HOTP (RFC 4226) and TOTP (RFC 6238) for two-factor authentication, compatib… | 23 | 2757 | abandoned |
| android-password-store/Android-Password-Store An Android password manager application compatible with ZX2C4's Pass command-line password store, using OpenPGP for encryption. It lets use… | 10 | 2655 | abandoned |
| Netflix-Skunkworks/Scumblr Scumblr is a Ruby on Rails web application from Netflix for performing periodic syncs of data sources (GitHub repos, URLs, DNS) and running… | 23 | 2641 | abandoned |
| DanMcInerney/LANs.py A Python-based penetration testing tool that scans WiFi networks for active clients, performs targeted ARP spoofing, and intercepts or inje… | 32 | 2632 | abandoned |
| square/keywhiz Keywhiz is a Java-based system for centrally storing, managing, and distributing secrets such as TLS keys, API tokens, and database credent… | 10 | 2623 | abandoned |
| CrimsonForge-io/king-phisher King Phisher is a phishing campaign toolkit for testing and promoting user awareness by simulating real-world phishing attacks, with contro… | 66 | 2581 | abandoned |
| agilebits/onepassword-app-extension An iOS action extension from AgileBits that let third-party iOS apps integrate 1Password for filling login credentials and other form data.… | 10 | 2569 | abandoned |
| rockbruno/swiftshield SwiftShield is a Swift obfuscator that renames types and methods in iOS projects using SourceKit to protect apps against reverse engineerin… | 23 | 2547 | abandoned |
| genuinetools/binctr binctr is a Go library and tool for building fully static binaries that embed a container rootfs and run the container directly, without re… | 32 | 2518 | abandoned |
| activecm/rita-legacy RITA (Real Intelligence Threat Analytics) is an open-source framework for detecting command and control communication through network traff… | 59 | 2509 | abandoned |
| bin456789/Unblock163MusicClient-Xposed An Xposed module for rooted Android devices that unblocks grayed-out or region-restricted songs in the NetEase Cloud Music (163 Music) Andr… | 10 | 2502 | abandoned |
| MatsuriDayo/Matsuri Matsuri is a universal proxy toolchain app for Android, forked from SagerNet, supporting protocols like Shadowsocks, VMess, Trojan, SOCKS, … | 10 | 2498 | abandoned |
| WiFi-Pumpkin WiFi-Pumpkin is a Python framework for auditing Wi-Fi security by creating rogue wireless access points and performing man-in-the-middle at… | 23 | 2497 | abandoned |
| SpiderLabs/owasp-modsecurity-crs The OWASP ModSecurity Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity or compatible web application… | 10 | 2490 | abandoned |
| pycrypto/pycrypto PyCrypto is the Python Cryptography Toolkit, providing secure hash functions (SHA256, RIPEMD160) and encryption algorithms (AES, DES, RSA, … | 10 | 2473 | abandoned |
| conorpp/u2f-zero U2F Zero is an open source hardware U2F security token for two-factor authentication, built on a small USB device with secure key storage. … | 23 | 2450 | abandoned |
| Marten4n6/EvilOSX EvilOSX is a Remote Administration Tool (RAT) for macOS/OS X written in pure Python, with a server providing both GUI and CLI interfaces an… | 32 | 2416 | abandoned |
| DrizzleRisk/drizzleDumper drizzleDumper is a memory-search-based Android unpacking tool that dumps DEX files from packed/protected Android apps. It runs as a command… | 32 | 2415 | abandoned |
| pedant/safe-java-js-webview-bridge An Android library providing a safe alternative to WebView's addJavascriptInterface for Java-JavaScript communication, using WebChromeClien… | 23 | 2415 | abandoned |
| Corona-Warn-App The official open-source COVID-19 exposure notification app for Germany, developed by SAP and Deutsche Telekom for iOS and Android using th… | 10 | 2394 | abandoned |
| shadowsocks/simple-obfs A simple obfuscation plugin for Shadowsocks that disguises proxy traffic as ordinary HTTP or TLS traffic. It is deprecated and succeeded by… | 23 | 2371 | abandoned |
| jaeles-project/jaeles Jaeles is a Go-based framework for building and running automated web application vulnerability scanners using customizable YAML signatures… | 62 | 2369 | abandoned |
| codebutler/firesheep Firesheep is a Firefox extension that demonstrates HTTP session hijacking attacks by sniffing unencrypted Wi-Fi traffic and capturing sessi… | 32 | 2353 | abandoned |
| aress31/burpgpt burpgpt is a Burp Suite extension that sends HTTP traffic to OpenAI GPT models for AI-driven passive vulnerability scanning and traffic ana… | 30 | 2352 | abandoned |
| rongzhiy/LiTiaotiao A repository distributing Li Tiaotiao (李跳跳), a discontinued Android app that automatically skips splash/opening ads in other apps using cus… | 18 | 2349 | abandoned |
| praetorian-inc/noseyparker Nosey Parker is a Rust-based command-line secrets scanner that finds credentials and sensitive information in files, directories, GitHub, a… | 10 | 2343 | abandoned |
| hijkpw/scripts A collection of one-click shell scripts for installing proxy servers (Shadowsocks, ShadowsocksR, V2Ray, trojan, trojan-go) on VPS instances… | 32 | 2317 | abandoned |
| expressjs/csurf csurf is Node.js CSRF protection middleware for Express that creates and validates CSRF tokens via session or cookie-based storage. The rep… | 10 | 2307 | abandoned |
| sevagas/macro_pack macro_pack is a Python CLI tool that automates obfuscation and generation of MS Office documents, VBA/VBS scripts, shortcuts, and other for… | 10 | 2307 | abandoned |
| lamster2018/EasyProtector EasyProtector is an Android library that detects rooted devices, Xposed framework hooks, debuggers/tracers, virtual apps (multi-instance), … | 23 | 2289 | abandoned |
| dgiese/dustcloud A research project for reverse engineering and rooting Xiaomi Smart Home devices, including robot vacuums, providing methods to root device… | 23 | 2279 | abandoned |
| github/SoftU2F SoftU2F is a software U2F authenticator for macOS that emulates a hardware U2F HID device and performs cryptographic operations using the m… | 10 | 2244 | abandoned |
| DarkCoderSc/PowerRemoteDesktop PowerRemoteDesktop is a remote desktop application written entirely in PowerShell, with both client and server components implementing its … | 23 | 2243 | abandoned |
| Magisk-Modules-Repo/MagiskHidePropsConf A Magisk module providing a terminal-based UI for editing Android system prop values via resetprop, including a maintained list of certifie… | 10 | 2228 | abandoned |
| secgroundzero/warberry WarBerryPi is a tactical exploitation toolkit built to run on a Raspberry Pi, acting as a drop-box/implant for red-team engagements to scan… | 32 | 2221 | abandoned |
| PowerShellEmpire/PowerTools PowerTools is a collection of PowerShell projects focused on offensive security operations, including tools like PowerView, PowerUp, PowerP… | 23 | 2206 | abandoned |
| python-security/pyt PyT (Python Taint) is a static analysis tool that detects security vulnerabilities like injection flaws in Python web applications using ta… | 23 | 2199 | abandoned |
| ysrc/yulong-hids-archived Yulong HIDS is an open-source host intrusion detection system composed of an Agent, Daemon, Server, and Web console that collects host info… | 10 | 2184 | abandoned |
| mozilla/MozDef MozDef is Mozilla's Enterprise Defense Platform, an open-source SIEM-style application for automating security incident handling and enabli… | 10 | 2161 | abandoned |
| 8enet/Charles-Crack A repository that provided a crack/patch to bypass licensing of Charles Proxy, an HTTP debugging proxy tool. The repository content was rem… | 32 | 2150 | abandoned |
| jetstack/kube-lego kube-lego is a Kubernetes daemon that automatically requests and renews TLS certificates from Let's Encrypt for Ingress resources annotated… | 10 | 2149 | abandoned |
| ircmaxell/password_compat A PHP library providing forward compatibility with the password_* functions (password_hash, password_verify) that ship natively with PHP 5.… | 32 | 2128 | abandoned |
| iam4x/pokemongo-webspoof A macOS desktop application that spoofs the GPS location of a USB-connected iOS device so the user can play Pokémon GO from their Mac, movi… | 23 | 2126 | abandoned |
| Consensys/Tokens A repository of minimalist, standards-compliant Solidity smart contracts for Ethereum tokens, primarily implementing the EIP20 (ERC-20) sta… | 10 | 2123 | abandoned |
| HikariObfuscator/Hikari Hikari is an LLVM-based code obfuscator that transforms compiled binaries with techniques like string encryption, indirect branching, funct… | 10 | 2106 | abandoned |
| M66B/XPrivacy XPrivacy is an Xposed-based privacy manager for Android that restricts which data categories (contacts, location, etc.) apps can access, fe… | 10 | 2099 | abandoned |