function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| AdrMXR/KitHack KitHack is a Python-based framework that automates downloading and installing a curated pack of penetration testing tools, organized into c… | 26 | 2086 | abandoned |
| ylechelle/OpenUDID OpenUDID is an open-source Objective-C library that provides a persistent, privacy-friendly replacement for Apple's deprecated UDID (unique… | 32 | 2079 | abandoned |
| yahoo/gryffin Gryffin is a large-scale web security scanning platform written in Go, built on a publisher-subscriber architecture for horizontal scaling.… | 10 | 2052 | abandoned |
| iotaledger-archive/legacy-wallet-use-trinity-wallet-instead The legacy desktop wallet for the IOTA cryptocurrency, built with Electron and JavaScript. It is deprecated and users are directed to the T… | 10 | 2043 | abandoned |
| rasta-mouse/Sherlock Sherlock is a PowerShell script that identifies missing software patches for known Windows local privilege escalation vulnerabilities. It i… | 10 | 2020 | abandoned |
| google/rekall Rekall is a Python-based memory forensic framework for extracting and analyzing digital artifacts from physical memory images of Windows, L… | 10 | 2008 | abandoned |
| auto-ssl/lua-resty-auto-ssl An OpenResty/nginx plugin that automatically issues and renews free SSL/TLS certificates from Let's Encrypt on the fly as HTTPS requests ar… | 51 | 1988 | abandoned |
| Fadi002/unshackle Unshackle is a bootable Linux-based ISO that resets or bypasses Windows and Linux user login passwords from a USB drive. It works offline b… | 10 | 1980 | abandoned |
| sensiolabs/security-checker A PHP command-line tool that checks Composer dependency lock files against the security.symfony.com web service for known vulnerabilities. … | 10 | 1972 | abandoned |
| TunnlTo/desktop-app TunnlTo was an open-source WireGuard client for Windows featuring advanced split tunneling and a user-friendly interface. The open-source p… | 57 | 1965 | abandoned |
| feihong-cs/ShiroExploit-Deprecated A Java-based one-click exploitation tool for Apache Shiro vulnerabilities Shiro550 (hardcoded key) and Shiro721 (Padding Oracle), supportin… | 23 | 1956 | abandoned |
| Shopify/kubeaudit kubeaudit is a command line tool and Go package that audits Kubernetes clusters against common security controls like running as non-root, … | 10 | 1937 | abandoned |
| XcodeGhostSource/XcodeGhost The published source code of XcodeGhost, the infamous 2015 malware that spread through a compromised Xcode build configuration and infected… | 32 | 1925 | abandoned |
| twoyi/twoyi Twoyi is a lightweight Android-in-Android container that runs a nearly complete Android 8.1 system as a normal app on Android 8.1-12 device… | 10 | 1916 | abandoned |
| JuncoJet/unlimited-landeng-for-win A Windows patcher/injector for the Lantern proxy client that modifies its PE structure or loads it via an injector to unlock paid/pro limit… | 32 | 1912 | abandoned |
| Gh0u1L5/WechatMagician WechatMagician is an open-source Xposed module written in Kotlin that hooks into the WeChat app to give users full control over chat messag… | 23 | 1893 | abandoned |
| lyft/confidant Confidant is a secret management service from Lyft that stores secrets encrypted at rest in AWS DynamoDB, with a web UI and client tooling.… | 10 | 1856 | abandoned |
| mozilla/http-observatory Mozilla HTTP Observatory is a Python-based scanner and grader that analyzes websites' HTTP headers and security configurations, providing a… | 10 | 1850 | abandoned |
| Xeroday/Spotify-Ad-Blocker EZBlocker is a Windows desktop application written in C# that blocks and mutes advertisements in the Spotify client. It detects ads via win… | 23 | 1845 | abandoned |
| Veil-Framework/Veil-Evasion Veil-Evasion is a Python tool that generates Metasploit payloads designed to bypass common antivirus solutions, optionally compiling them i… | 10 | 1840 | abandoned |
| samyk/skyjack SkyJack is a drone hacking tool that autonomously seeks out, disconnects the owner of, and takes wireless control of nearby Parrot AR.Drone… | 32 | 1831 | abandoned |
| Neo23x0/yarGen yarGen is a Python CLI tool that generates YARA rules from strings found in malware samples, filtering out strings that appear in a large i… | 50 | 1811 | abandoned |
| ycccccccy/wx_key A tool that extracted the local database and image encryption keys from WeChat 4.0+ desktop clients, enabling users to decrypt and back up … | 52 | 1810 | abandoned |
| eth0izzle/bucket-stream A Python CLI tool that monitors certificate transparency logs via certstream and discovers public Amazon S3 buckets by generating permutati… | 36 | 1809 | abandoned |
| EEliberto/IPA-Download Pastel is a native macOS (Apple Silicon, macOS 26+) SwiftUI application for downloading historical versions of iOS apps as IPA files from t… | 81 | 1782 | abandoned |
| Netflix/lemur Lemur is a TLS certificate management and orchestration service that acts as a broker between certificate authorities and environments, pro… | 10 | 1772 | abandoned |
| Xposed-Modules-Repo/com.bug.hookvip An Xposed module for Android that hooks into apps to unlock certain VIP/membership features and extend functionality. The repository has be… | 10 | 1763 | abandoned |
| kpwn/yalu102 Yalu102 is an incomplete, work-in-progress jailbreak for 64-bit iOS devices running iOS 10.0 through 10.2, created by qwertyoruiopz and mar… | 32 | 1762 | abandoned |
| govolution/avet AVET (AntiVirus Evasion Tool) is a shell-based toolbox for pentesters to build Windows executables that evade antivirus detection, using te… | 40 | 1755 | abandoned |
| mattt/CargoBay CargoBay is an Objective-C library that wraps Apple's StoreKit framework to simplify In-App Purchases on iOS. It provides block-based produ… | 10 | 1754 | abandoned |
| brutella/hc hc is a lightweight Go framework that implements Apple's HomeKit Accessory Protocol (HAP), letting developers build HomeKit accessories wit… | 23 | 1738 | abandoned |
| okTurtles/dnschain DNSChain is a blockchain-based DNS and HTTPS server that provides a decentralized, MITM-proof alternative to the traditional DNS and X.509 … | 23 | 1732 | abandoned |
| ProtonMail/proton-mail-android The official Proton Mail Android email client, an open-source app providing encrypted email access on Android. This repository has been arc… | 10 | 1731 | abandoned |
| desaster/kippo Kippo is a medium-interaction SSH honeypot written in Python that logs brute-force attacks and records the full shell interaction of attack… | 23 | 1715 | abandoned |
| xdavidhu/mitmAP A Python program that creates a fake wireless access point and performs man-in-the-middle data sniffing using tools like SSLstrip2, mitmpro… | 10 | 1694 | abandoned |
| Cisco-Talos/pyrebox PyREBox is a Python-scriptable reverse engineering sandbox built on QEMU that provides whole-system dynamic analysis and debugging of runni… | 10 | 1683 | abandoned |
| google/novm novm is an experimental, legacy-free type 2 hypervisor (VMM) written in Go that leverages the Linux KVM interface to run guest instances. I… | 10 | 1676 | abandoned |
| chaitin/passionfruit Passionfruit is a web-based GUI tool for blackbox assessment of iOS apps, built on the Frida instrumentation framework and Vue.js. It lets … | 10 | 1668 | abandoned |
| nodesecurity/nsp nsp is the Node Security Platform command-line tool that checks Node.js projects for known vulnerabilities in their dependencies, with CVSS… | 10 | 1653 | abandoned |
| leminlimez/Cowabunga Cowabunga is a jailed iOS toolbox app that exploits CVE-2022-46689 (MacDirtyCow) to customize iOS 14.0-15.7.1 and 16.0-16.1.2 devices witho… | 10 | 1647 | abandoned |
| getqujing/qtunnel qTunnel is a lightweight Go-based network tunneling tool that acts as an encryption wrapper between clients and servers, serving as a simpl… | 32 | 1643 | abandoned |
| ZFC-Digital/puppeteer-real-browser A Node.js library that wraps Puppeteer with a real-browser profile to bypass bot detection systems like Cloudflare and Turnstile captchas. … | 34 | 1641 | abandoned |
| DesignativeDave/androrat Androrat is a client/server Remote Administration Tool for Android devices, with the client written in Java Android and the server in Java/… | 32 | 1636 | abandoned |
| Tlaster/YourAV YourAV is a lightweight, open-source Windows application that registers itself as an antivirus in the Windows Security Center, which causes… | 23 | 1633 | abandoned |
| BaltiApps/Pixelify-Google-Photos An LSPosed/EdXposed module that spoofs Pixel device features and build properties to unlock Pixel-exclusive Google Photos features on any A… | 23 | 1632 | abandoned |
| pallets-eco/flask-security-3.0 Flask-Security 3.0 is a Flask extension providing quick and simple authentication and security features such as login, registration, and ro… | 10 | 1624 | abandoned |
| asLody/legend Legend is a Java method hooking framework for Android that works without root access, supporting both Dalvik and ART runtimes. It lets deve… | 32 | 1605 | abandoned |
| carmaa/inception Inception is a Python-based physical memory manipulation tool that exploits PCI-based DMA (over FireWire, Thunderbolt, ExpressCard, PC Card… | 34 | 1602 | abandoned |
| chinoogawa/fbht A Python 2 command-line tool for interacting with and scraping Facebook accounts, including graph-based analysis of social connections. It … | 23 | 1597 | abandoned |
| jrendel/SwiftKeychainWrapper A Swift wrapper around the iOS/tvOS Keychain that lets developers store and retrieve secure items with a User Defaults-like API. It provide… | 10 | 1590 | abandoned |
| anchore/anchore-engine Anchore Engine is an open-source service that inspects, analyzes, and certifies container images, scanning them against a vulnerability dat… | 10 | 1589 | abandoned |
| blockchainsllc/DAO The Standard DAO Framework is a set of Solidity smart contracts for creating Decentralized Autonomous Organizations on the Ethereum blockch… | 23 | 1588 | abandoned |
| keraf/NoCoin No Coin is a small browser extension for Chrome, Firefox, and Opera that blocks browser-based coin miners such as Coinhive by blacklisting … | 10 | 1577 | abandoned |
| byt3bl33d3r/SprayingToolkit A set of Python 3 scripts for performing fast password spraying attacks against Lync/Skype for Business, OWA, IMAP, and Office 365, built o… | 10 | 1577 | abandoned |
| zeustrojancode/Zeus A GitHub mirror of the leaked source code (version 2.0.8.9) of the Zeus trojan, a notorious Windows banking malware from 2007-2011 that sto… | 10 | 1568 | abandoned |
| technoweenie/restful-authentication A widely-used Ruby on Rails plugin/generator that provides a foundation for user authentication, including login/logout, secure password ha… | 10 | 1564 | abandoned |
| viper-framework/viper Viper is a Python-based binary analysis and management framework for organizing collections of malware and exploit samples along with analy… | 10 | 1562 | abandoned |
| SpiderOak/Encryptr Encryptr is a zero-knowledge, cloud-based password manager and e-wallet built on the Crypton framework by SpiderOak. It stores passwords, c… | 23 | 1559 | abandoned |
| saturngod/IAPHelper An Objective-C helper library for Apple in-app purchases built on StoreKit, using ARC and blocks for requesting products, purchasing, and r… | 32 | 1552 | abandoned |
| SofianeHamlaoui/Lockdoor-Framework Lockdoor Framework is a Python-based penetration testing framework that bundles a curated selection of security tools (information gatherin… | 34 | 1549 | abandoned |
| promptpirate-x/discord-id-bypass-tool A browser-based tool (HTML/Three.js) that renders an animated 3D avatar head with mouth movement to trick Discord's k-ID face-scan age veri… | 46 | 1525 | abandoned |
| scottyab/secure-preferences An Android library that wraps SharedPreferences to encrypt stored values with AES-128/CBC and hash keys with SHA-256. It is deprecated in f… | 10 | 1518 | abandoned |
| Nuzair46/BlockTheSpot-Mac A shell-based patcher that blocks ads, logging, and skip restrictions in the Spotify desktop client for macOS. It is installed and managed … | 10 | 1511 | abandoned |
| ravenac95/sudolikeaboss sudolikeaboss is a macOS command-line tool that lets users retrieve passwords from the 1Password desktop app directly in iTerm2, e.g. to fi… | 10 | 1504 | abandoned |
| SpriteOvO/Telegram-Anti-Revoke A C++ plugin for the Telegram Desktop client that prevents messages from being revoked (deleted) by the server, marking revoked messages as… | 10 | 1500 | abandoned |
| mitchellh/gon gon is a macOS CLI tool and Go library for code signing, notarizing, and packaging (dmg/zip) binaries and applications written in any langu… | 10 | 1497 | abandoned |
| mesalock-linux/mesalink MesaLink is a memory-safe TLS library written in Rust that provides an OpenSSL-compatible C API, implemented on top of rustls, webpki, and … | 23 | 1483 | abandoned |
| ring04h/wydomain wydomain is a Python command-line tool for discovering subdomains of a target domain. It combines dictionary-based DNS bruteforcing with qu… | 32 | 1479 | abandoned |
| D4Vinci/Dr0p1t-Framework Dr0p1t-Framework is a Python-based penetration testing framework that generates stealthy Windows dropper executables designed to bypass ant… | 10 | 1473 | abandoned |
| IBM/fhe-toolkit-linux IBM's Fully Homomorphic Encryption Toolkit for Linux, a Docker-based toolkit demonstrating computation on encrypted data without decryption… | 10 | 1472 | abandoned |
| AeonLucid/SnapHide SnapHide is an iOS jailbreak tweak written in Logos that hides jailbreak evidence and hook traces from the Snapchat app. It was developed t… | 32 | 1470 | abandoned |
| jseidl/GoldenEye GoldenEye is a Python 3 command-line tool for testing HTTP servers against Layer 7 denial-of-service attacks using the HTTP KeepAlive + NoC… | 10 | 1469 | abandoned |
| 9p4/jellyfin-plugin-sso A Jellyfin server plugin that enables single sign-on (SSO) login through external identity providers such as Google, Microsoft, Keycloak, A… | 10 | 1460 | abandoned |
| OpenRCE/sulley Sulley is a pure-Python fuzzing engine and framework for automated, unattended fuzz testing of network protocols and targets. It handles da… | 23 | 1450 | abandoned |
| noidontdig/gitdown Gitdown is a novelty git commit-msg hook written in Ruby that gates commits based on your blood alcohol content, measured via an Arduino Dr… | 32 | 1446 | abandoned |
| Lucifer1993/AngelSword AngelSword is a simple CMS vulnerability detection framework written in Python3, designed to help security engineers quickly discover known… | 32 | 1441 | abandoned |
| fritz-smh/yi-hack A collection of shell scripts and binaries that replace parts of the Xiaomi Yi Ants home camera firmware, disabling cloud connectivity and … | 32 | 1440 | abandoned |
| SpenserCai/GoWxDump GoWxDump was a Windows CLI tool for extracting WeChat account information such as decryption keys and user data from local installations. T… | 58 | 1439 | abandoned |
| dark-kingA/superSearchPlus superSearchPlus is a Chrome browser extension that aggregates information gathering for white-hat hackers, integrating common asset mapping… | 32 | 1435 | abandoned |
| cisagov/Sparrow Sparrow.ps1 is a PowerShell script from CISA's Cloud Forensics team that helps incident responders detect possibly compromised accounts and… | 10 | 1430 | abandoned |
| bumptech/stud Stud is a scalable TLS/SSL termination proxy that unwraps encrypted connections and forwards plaintext traffic to a backend like HAProxy or… | 10 | 1422 | abandoned |
| cloudflare/redoctober Red October is a Go-based TLS server implementing two-man rule style encryption and decryption, where no single individual can decrypt data… | 10 | 1418 | abandoned |
| yonggekkk/Doprax-Xray A one-click shell script that deploys an Xray-core proxy server on the Doprax container platform, running five protocols (vless, vmess, tro… | 31 | 1407 | abandoned |
| Tygs/0bin 0bin is a self-hostable pastebin that encrypts paste content client-side in the browser with AES256, so the server never sees plaintext or … | 39 | 1404 | abandoned |
| ReversecLabs/needle Needle is an open-source, modular Python framework for streamlining security assessments of iOS applications, covering areas like data stor… | 10 | 1401 | abandoned |
| danielamitay/iHasApp An Objective-C iOS framework that detects installed apps on a user's device by probing URL schemes via canOpenURL: and enriching results wi… | 10 | 1397 | abandoned |
| nining377/UnblockMusicPro_Xposed An Xposed module for Android that unlocks greyed-out (region- or license-restricted) songs in the Netease Cloud Music client by hooking the… | 23 | 1392 | abandoned |
| ValdikSS/blockcheck BlockCheck is a Python utility that detects the type of website blocking used by Russian ISPs, including DNS tampering, DPI filtering, SSL … | 10 | 1391 | abandoned |
| aquasecurity/starboard Starboard is a Kubernetes-native security toolkit that integrates heterogeneous security scanners and exposes their results as Kubernetes C… | 85 | 1380 | abandoned |
| sslab-gatech/Rudra Rudra is a static analyzer that detects common undefined behaviors and memory safety issues in Rust programs, capable of analyzing single p… | 10 | 1367 | abandoned |
| hahwul/XSpear XSpear is a Ruby-based XSS (cross-site scripting) scanner and parameter analysis tool distributed as a gem, usable both as a CLI and as a R… | 10 | 1364 | abandoned |
| master131/BlockTheSpot BlockTheSpot is a Windows-only mod that patches the Spotify desktop client to block banner, video, and audio ads and unlock track skipping.… | 10 | 1362 | abandoned |
| zyq8709/DexHunter DexHunter is an automatic unpacking tool for Android Dex files protected by app-hardening services. It works by replacing the ART and DVM r… | 32 | 1358 | abandoned |
| byt3bl33d3r/gcat Gcat is a proof-of-concept Python backdoor that uses a Gmail account as its command-and-control channel, with an implant deployed on target… | 10 | 1351 | abandoned |
| WWILLV/GodOfHacker GodOfHacker is a satirical C# 'hacker all-in-one tool' whose feature list is intentionally absurd (one-click 0day attacks, stealing QQ acco… | 23 | 1342 | abandoned |
| vbuterin/pybitcointools A simple, common-sense Python library for Bitcoin-themed elliptic curve cryptography (secp256k1), including key handling, signing, and tran… | 32 | 1331 | abandoned |
| gorhill/httpswitchboard HTTP Switchboard is a Chromium browser extension that lets users point-and-click whitelist or blacklist network requests per domain and req… | 10 | 1330 | abandoned |
| hackappcom/ibrute A Python proof-of-concept tool that brute-forces AppleID passwords via the Find My iPhone service API, which lacked bruteforce protection. … | 32 | 1322 | abandoned |
| nang-dev/hover-paywalls-browser-extension Hover is an open-source Chrome browser extension that bypasses paywalls on news sites and blocks ads and tracking modules. It works via web… | 23 | 1310 | abandoned |
| linisme/Cipher.so A Gradle plugin for Android that packages key-value secrets (like API keys and passwords) into an encrypted native .so library at compile t… | 32 | 1306 | abandoned |