function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Dr-TSNG/TwiFucker TwiFucker is an Xposed module for the Android Twitter/X app that removes ads, promoted content, and other unwanted elements. The project is… | 10 | 1297 | abandoned |
| elvanderb/TCP-32764 A collection of Python proof-of-concept code and research notes documenting a hidden backdoor listening on TCP port 32764 in Linksys, Netge… | 32 | 1291 | abandoned |
| hardware/mailserver A simple and full-featured mail server distributed as a set of Docker images, bundling Postfix, Dovecot, Rspamd, ClamAV, Sieve, Fetchmail, … | 10 | 1288 | abandoned |
| clymb3r/PowerShell A collection of useful PowerShell scripts, most notably security and penetration testing tools that were contributed to PowerSploit. The re… | 32 | 1284 | abandoned |
| cisagov/log4j-scanner A CISA-derived scanner for detecting web services vulnerable to the Log4Shell remote code execution vulnerabilities (CVE-2021-44228 and CVE… | 10 | 1278 | abandoned |
| lanx-x/VRouter VRouter is a desktop application that runs a lightweight OpenWRT virtual machine via VirtualBox to provide transparent TCP/UDP proxying on … | 10 | 1277 | abandoned |
| pengliangAndroid/VirtualLocation An Android app that spoofs GPS, Wi-Fi, and cell-tower locations for other apps without requiring root, by running them inside a hooked Virt… | 32 | 1275 | abandoned |
| lachesis/scallion Scallion is a GPU-accelerated (OpenCL) vanity key generator that creates custom .onion addresses for Tor hidden services and vanity GPG key… | 23 | 1275 | abandoned |
| YelpArchive/dockersh dockersh is a login shell written in Go that places each interactive user into their own individual Docker container when they log in. It c… | 10 | 1274 | abandoned |
| ClaudiuGeorgiu/Obfuscapk Obfuscapk is a modular Python tool that obfuscates Android APKs and App Bundles in a black-box fashion, without needing source code, by dec… | 10 | 1272 | abandoned |
| uknowsec/SharpDecryptPwd SharpDecryptPwd is a Windows command-line tool that decrypts passwords saved locally by popular applications such as Navicat, TeamViewer, F… | 32 | 1271 | abandoned |
| forseti-security/forseti-security Forseti Security is a collection of open-source tools for auditing and improving the security of Google Cloud Platform environments, includ… | 10 | 1269 | abandoned |
| crmulliner/adbi ADBI is a dynamic binary instrumentation toolkit for Android ARM and Thumb binaries, based on library injection and inline hooking of funct… | 32 | 1266 | abandoned |
| samyk/usbdriveby USBdriveby is an Arduino/Teensy microcontroller project that emulates a USB HID keyboard and mouse to covertly install a backdoor, evade fi… | 32 | 1265 | abandoned |
| KrauseFx/detect.location A proof-of-concept iOS library and demo app that extracts a user's location history from photo metadata in the image library, without requi… | 32 | 1256 | abandoned |
| LOoLzeC/ASU ASU is a Python-based Facebook hacking toolkit offering account checking and spamming features, distributed via a Termux/Linux install scri… | 32 | 1252 | abandoned |
| privacypass/challenge-bypass-extension A browser extension implementing the client side of the Privacy Pass protocol, which issues and redeems unlinkable cryptographic tokens (ba… | 26 | 1250 | abandoned |
| vaycore/OneScan OneScan is a BurpSuite extension written in Java for recursive directory scanning, helping discover hidden vulnerabilities in deeper direct… | 10 | 1250 | abandoned |
| ldandersen/scifihifi-iphone A collection of open-source iPhone/Objective-C code, best known for SFHFKeychainUtils, a simple wrapper for storing credentials in the iOS … | 32 | 1249 | abandoned |
| tomer8007/widevine-l3-decryptor A Chrome extension that demonstrated bypassing Widevine L3 DRM by hijacking Encrypted Media Extensions calls to extract content decryption … | 10 | 1247 | abandoned |
| n0tr00t/Sreg Sreg is a Python CLI OSINT tool that checks whether an email, phone number, or username has been used to register accounts across many Chin… | 32 | 1245 | abandoned |
| optiv/Mangle Mangle is a Go-based CLI tool that manipulates compiled Windows executables (.exe and DLL) to evade EDR detection. It strips known indicato… | 10 | 1235 | abandoned |
| Ha3MrX/Gemail-Hack A Python command-line script that performs brute-force password attacks against Gmail accounts. It is a simple educational/offensive-securi… | 66 | 1234 | abandoned |
| user1121114685/koolproxyR KoolProxyR is a Shell-based ad-blocking plugin for KoolShare LEDE router firmware, bundling filter rules like EasyList China, Fanboy, and y… | 32 | 1234 | abandoned |
| gekitz/UIDevice-with-UniqueIdentifier-for-iOS-5 An Objective-C category on UIDevice that restores unique device identifier support on iOS 5 by hashing the device MAC address (optionally c… | 32 | 1230 | abandoned |
| genuinetools/bane bane is a Go command-line tool that generates custom AppArmor security profiles for Docker containers from a declarative TOML config file. … | 23 | 1229 | abandoned |
| hfiref0x/TDL TDL is a Windows x64 driver loader that bypasses Driver Signature Enforcement by exploiting a VirtualBox kernel vulnerability to map specia… | 10 | 1227 | abandoned |
| littleRich/VirtualLocation An Android app that fakes the device's GPS location using ADB mock location or Xposed hooking of location APIs. It can spoof location in ap… | 32 | 1223 | abandoned |
| wibus-wee/InjectGUI InjectGUI is a macOS graphical application that wraps the QiuChenly InjectLib framework for injecting dylibs into macOS applications, handl… | 10 | 1221 | abandoned |
| jacopotediosi/GAppsMod GAppsMod is a root-required Android application that tweaks Google apps (like Phone and Messages) by modifying the Phenotype DB flags manag… | 10 | 1217 | abandoned |
| sakurity/securelogin SecureLogin is a decentralized passwordless authentication protocol that derives a cryptographic key pair from a user's email and master pa… | 32 | 1209 | abandoned |
| mozilla/mig MIG (Mozilla InvestiGator) is a distributed platform for real-time digital forensics and endpoint investigation, using agents installed acr… | 10 | 1202 | abandoned |
| FeezyHendrix/Insta-mass-account-creator A Python CLI tool that automatically mass-creates Instagram accounts, generating disposable email addresses, fetching OTPs, and populating … | 10 | 1200 | abandoned |
| nathanl/authority Authority is a Ruby gem that helps you authorize actions in Rails apps by grouping models under Authorizer classes with plain Ruby methods.… | 10 | 1197 | abandoned |
| fabpot/local-php-security-checker A command-line tool that checks PHP applications using Composer for dependencies with known security vulnerabilities, backed by the Friends… | 10 | 1182 | abandoned |
| creditease-sec/insight Insight is a self-hosted security management platform from CreditEase that combines application system asset management, full vulnerability… | 10 | 1182 | abandoned |
| 4x99/code6 Code6 (码小六) is a self-hosted web application that monitors GitHub for leaked code and secrets, scanning periodically and alerting via email… | 23 | 1177 | abandoned |
| diafygi/acme-nosudo A Python script that obtains free HTTPS certificates from the Let's Encrypt CA via the ACME protocol without requiring root or sudo access.… | 32 | 1172 | abandoned |
| DylanPiercey/auto-sni A NodeJS library that automatically obtains and renews free SSL/TLS certificates from Let's Encrypt using SNI, with near-zero configuration… | 32 | 1172 | abandoned |
| SecurityFTW/cs-suite Cloud Security Suite (cs-suite) is a command-line audit tool that checks the security posture of AWS, GCP, Azure, and DigitalOcean accounts… | 32 | 1171 | abandoned |
| maticnetwork/contracts Ethereum smart contracts implementing the business logic of the Matic Network (Polygon PoS), including main chain and side chain contracts.… | 10 | 1168 | abandoned |
| pepe2k/u-boot_mod A deep modification of U-Boot 1.1.4 bootloader sources for MIPS-based routers with Qualcomm/Atheros SoCs, adding features like a web fail-s… | 10 | 1162 | abandoned |
| DeimosC2/DeimosC2 DeimosC2 is a Golang-based command and control (C2) framework for post-exploitation, supporting TCP, HTTPS, DoH, and QUIC agent communicati… | 30 | 1160 | abandoned |
| openstack-archive/bandit Bandit is a Python AST-based static analysis tool from the OpenStack Security Group that finds common security issues in Python code. This … | 10 | 1158 | abandoned |
| anubhavanonymous/XLR8_BOMBER XLR8_BOMBER is a Python command-line script that floods an Indian phone number with repeated SMS messages, calls, and WhatsApp messages by … | 32 | 1156 | abandoned |
| firesunCN/WechatEnhancement An Xposed framework module written in Java that hooks the WeChat Android app to add features like automatic red packet and transfer accepta… | 23 | 1153 | abandoned |
| troglobit/inadyn In-a-Dyn is a small Dynamic DNS (DDNS) client written in C that keeps DNS hostnames in sync with a changing public IP address, with HTTPS s… | 10 | 1153 | abandoned |
| hyperledger-archives/fabric A read-only historic archive of Hyperledger Fabric, an enterprise-grade permissioned blockchain framework written in Go with a modular arch… | 10 | 1152 | abandoned |
| fit2cloud/riskscanner RiskScanner is an open-source multi-cloud security compliance scanning platform built on Cloud Custodian, Prowler, and Nuclei engines. It p… | 10 | 1152 | abandoned |
| xillwillx/skiptracer Skiptracer is a Python-based OSINT web scraping framework that aggregates paid and free lookup services to enumerate target information suc… | 23 | 1147 | abandoned |
| dowsnature/dowsDNS A small Python DNS server that resolves domains via custom hosts files and wildcard records to bypass DNS poisoning by the Great Firewall o… | 23 | 1146 | abandoned |
| cryptosphere/cryptosphere Cryptosphere is a global peer-to-peer cryptosystem for publishing and securely distributing content pseudonymously with no central point of… | 10 | 1144 | abandoned |
| fengjueming/unblock-NetEaseMusic A proxy service that lets users outside mainland China access NetEase Cloud Music (and related Tencent music services) by spoofing a Chines… | 10 | 1144 | abandoned |
| uswitch/kiam Kiam is a Kubernetes agent that lets pods assume AWS IAM roles by intercepting EC2 Metadata API requests and serving STS credentials per-po… | 10 | 1143 | abandoned |
| ring04h/weakfilescan A Python-based multi-threaded sensitive information leakage detection tool that crawls a target site, dynamically builds dictionary rules f… | 32 | 1140 | abandoned |
| agrinman/sift-ios Sift is an open-source iOS app that reveals real-time network traffic made by every app on your phone, using push notifications to surface … | 32 | 1135 | abandoned |
| NYAN-x-CAT/Lime-RAT LimeRAT is a remote administration tool (RAT) for Windows written in Visual Basic .NET, providing remote desktop, file management, keyloggi… | 10 | 1133 | abandoned |
| googlearchive/caja Caja is a Java-based tool for safely embedding third-party HTML, CSS, and JavaScript in a website using an object-capability security model… | 10 | 1132 | abandoned |
| Lyndir/MasterPassword Master Password is a stateless password manager that derives unique site passwords on demand from a single master secret using a cryptograp… | 32 | 1128 | abandoned |
| out0fmemory/GoAgent-Always-Available A maintained fork of the classic GoAgent proxy that periodically scans for usable Google GAE/GWS IP addresses and ships an automated IP-fet… | 10 | 1127 | abandoned |
| vesche/scanless A Python CLI utility and library that scrapes online port scanning websites to perform port scans on a target IP or domain on your behalf. … | 10 | 1121 | abandoned |
| aave/aave-v3-core The core Solidity smart contracts and market configuration for Aave Protocol V3, a decentralized non-custodial liquidity protocol for suppl… | 10 | 1117 | abandoned |
| cryptocat/cryptocat Cryptocat is a desktop application providing encrypted, secure chat built on Electron with JavaScript. It packages for Windows, Linux, and … | 32 | 1115 | abandoned |
| sensepost/mana MANA is a toolkit for rogue access point (evilAP) attacks, implementing improved KARMA attacks via a modified hostapd plus MitM configurati… | 23 | 1115 | abandoned |
| kelseyhightower/kube-cert-manager A Kubernetes controller that automatically manages Let's Encrypt TLS certificates, storing them as Kubernetes secrets via ACME dns-01 chall… | 32 | 1111 | abandoned |
| GhostFlying/LocationReportEnabler A rooted Android app that enables Google Location Report, Google Now, and related services in mainland China by spoofing SIM operator prope… | 23 | 1109 | abandoned |
| remoteinterview/compilebox CompileBox is a Docker-based sandbox service that compiles and runs user-submitted code in isolated containers and returns the output via a… | 32 | 1107 | abandoned |
| yulingtianxia/FishChat FishChat is an Objective-C hooking project that injects a dylib into a decrypted WeChat.app binary to modify its behavior on non-jailbroken… | 10 | 1103 | abandoned |
| gnosis/MultiSigWallet Gnosis MultiSigWallet is an Ethereum multisignature wallet consisting of smart contracts and a web dapp interface that requires multiple pa… | 10 | 1099 | abandoned |
| threathunterX/nebula Nebula 1.x is an open-source business risk-control (anti-fraud) platform that captures traffic out-of-band via OpenResty and analyzes it in… | 10 | 1099 | abandoned |
| kolide/fleet Kolide Fleet was an open-source osquery fleet manager written in Go, providing a control server for managing and querying osquery deploymen… | 10 | 1098 | abandoned |
| evilsocket/bleah A deprecated command-line tool for scanning and enumerating Bluetooth Low Energy (BLE) devices. It has been ported into bettercap's BLE mod… | 10 | 1093 | abandoned |
| google/keyczar Keyczar is an easy-to-use open-source cryptographic toolkit originally developed by Google, designed to simplify encryption, signing, and k… | 10 | 1093 | abandoned |
| bytebuff/JSpider JSpider is a collection of JavaScript decryption files for website-encrypted request parameters, shared weekly alongside Python snippets th… | 32 | 1092 | abandoned |
| ZenGo-X/multi-party-ecdsa A Rust library implementing {t,n}-threshold ECDSA digital signatures using multi-party computation protocols, supporting key generation and… | 23 | 1085 | abandoned |
| arnaucube/coffeeMiner CoffeeMiner is a Python tool that performs a man-in-the-middle attack on a WiFi/LAN network, injecting a JavaScript cryptocurrency miner in… | 32 | 1077 | abandoned |
| opengs/uashield UA Cyber SHIELD is a volunteer cybersecurity tool built during the Russian invasion of Ukraine that coordinates distributed denial-of-servi… | 10 | 1077 | abandoned |
| 1n7erface/PocList A Java-based collection of proof-of-concept (PoC) tools for verifying and exploiting known vulnerabilities in products like Nacos, WebLogic… | 32 | 1075 | abandoned |
| ekkoo-z/Z-Godzilla_ekp A modified (second-development) fork of the Godzilla webshell management tool, customized to evade network traffic detection devices and an… | 42 | 1073 | abandoned |
| guardianproject/ChatSecureAndroid ChatSecure for Android was a free and open-source secure messaging app built on XMPP/Jabber with OTR encryption, SQLCipher local storage, a… | 10 | 1071 | abandoned |
| loft-sh/kiosk Kiosk is a multi-tenancy extension for Kubernetes that lets cluster admins securely share a single cluster among multiple tenants. It provi… | 10 | 1070 | abandoned |
| cisagov/CHIRP CHIRP is a DFIR (Digital Forensics and Incident Response) tool by CISA that dynamically queries hosts for Indicators of Compromise (IoCs) u… | 10 | 1058 | abandoned |
| EFForg/crocodilehunter Crocodile Hunter is an EFF tool that detects fake 4G/LTE cell towers (IMSI catchers/stingrays) using software-defined radios like LimeSDR, … | 10 | 1057 | abandoned |
| EquiFox/KsDumper KsDumper is a Windows tool that dumps process memory (including protected processes with stripped handles) using a kernel driver, rebuildin… | 23 | 1055 | abandoned |
| kallydev/privacy A personal data breach detection service that let users check whether their email, phone number, or identity information had been exposed i… | 10 | 1054 | abandoned |
| WyAtu/Perun Perun is a Python-based network asset vulnerability scanner and scanning framework designed for penetration testers and red teams, primaril… | 32 | 1051 | abandoned |
| xcicode/MifareOneTool MifareOneTool is a Windows GUI application for working with Mifare Classic NFC cards, including reading and cracking operations. It is writ… | 23 | 1050 | abandoned |
| Netflix-Skunkworks/sleepy-puppy Sleepy Puppy is a cross-site scripting (XSS) payload management framework from Netflix Skunkworks that captures, manages, and tracks XSS pa… | 32 | 1044 | abandoned |
| M4cs/BabySploit BabySploit is a beginner-friendly penetration testing toolkit and framework written in Python, designed to ease newcomers into using more c… | 23 | 1042 | abandoned |
| utkusen/leviathan Leviathan is a Python-based mass audit toolkit that combines masscan, ncrack, and DSSS to discover services, brute-force credentials, detec… | 10 | 1041 | abandoned |
| AndroidVTS/android-vts An on-device Android app that scans a device for known vulnerabilities such as kernel and framework bugs (e.g., Towelroot, Master Keys). It… | 23 | 1034 | abandoned |
| denandz/KeeFarce KeeFarce is a security tool that extracts passwords and other cleartext data from a running KeePass 2.x process by injecting a DLL into its… | 32 | 1030 | abandoned |
| duo-labs/webauthn A Go server library implementing the WebAuthn (FIDO2) specification for adding passwordless authentication to web applications. It handles … | 10 | 1030 | abandoned |
| Nightonke/BlurLockView An Android UI library providing a lock view with a blur effect for password entry, easily customizable. It is written in Java and distribut… | 32 | 1029 | abandoned |
| WereDev/Wu10Man Wu10Man is a Windows desktop application for enabling or disabling Windows 10 automatic updates by managing services and registry settings.… | 10 | 1025 | abandoned |
| halfkiss/ZjDroid ZjDroid is an Xposed framework module for dynamic reverse engineering of Android apps. It supports memory dumping of DEX files, BackSmali d… | 32 | 1021 | abandoned |
| hmailserver/hmailserver hMailServer is an open-source email server for Microsoft Windows providing SMTP, IMAP, and POP3 services. The project is no longer actively… | 86 | 1016 | abandoned |
| ba0gu0/520apkhook A Java-based tool that attaches an Android remote-access APK payload to a legitimate app, producing a trojanized APK where the original app… | 32 | 1015 | abandoned |
| qwqdanchun/DcRat DcRat is an open-source remote administration tool (RAT) written in C# for Windows, providing remote desktop, file management, and remote c… | 10 | 1011 | abandoned |
| timwr/CVE-2016-5195 A proof-of-concept exploit for CVE-2016-5195 (Dirty Cow) targeting Android devices, built with the Android NDK and deployed over ADB. It de… | 32 | 1010 | abandoned |