function: security
4909 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| OISF/suricata Suricata is a high-performance network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring… | 93 | 6571 | stable |
| BruceDevices/firmware Bruce is an open-source (AGPL-3.0) ESP32 firmware packed with offensive-security and Red Team tools such as WiFi attacks, Evil Portal, ward… | 90 | 6570 | active |
| rust-lang/miri Miri is an interpreter for Rust's mid-level intermediate representation (MIR) that detects undefined behavior in Rust programs. It runs bin… | 77 | 6535 | active |
| aistra0528/Hail Hail is a free, open-source Android app for freezing, disabling, hiding, or suspending other apps without root, using Shizuku or root privi… | 88 | 6532 | active |
| bmrf/tron Tron is an automated Windows PC cleanup and disinfection script, implemented as a collection of batch files that orchestrate many community… | 65 | 6530 | active |
| EnableSecurity/wafw00f WAFW00F is a Python command-line tool that identifies and fingerprints Web Application Firewall (WAF) products protecting a website. It sen… | 79 | 6528 | stable |
| Mebus/cupp CUPP is a Python CLI tool that generates targeted password wordlists by profiling personal information about a user, such as birthdays, nic… | 74 | 6507 | active |
| romanvht/ByeByeDPI An Android application that runs ByeDPI locally and routes all device traffic through it via Android's VPN mode to bypass DPI-based blockin… | 88 | 6506 | active |
| cowrie/cowrie Cowrie is a medium-to-high interaction SSH and Telnet honeypot that logs brute-force attacks and full attacker shell sessions, capturing up… | 99 | 6504 | active |
| MISP/MISP MISP is an open source threat intelligence platform for collecting, storing, correlating, and sharing cyber security indicators, malware an… | 99 | 6490 | stable |
| palera1n/palera1n palera1n is an open-source jailbreak tool for Apple devices using the checkm8 bootrom exploit, supporting A8 through A11 chips and T2 secur… | 88 | 6475 | active |
| opa334/Dopamine Dopamine is a rootless semi-untethered jailbreak tool for iOS 15 through 26.0.1, supporting arm64e and A12/A13 devices. It is written prima… | 98 | 6449 | active |
| tock/tock Tock is an embedded operating system for low-power, low-memory microcontrollers that runs multiple concurrent, mutually distrustful applica… | 67 | 6423 | active |
| zizmorcore/zizmor zizmor is a static analysis tool for CI/CD configurations, primarily GitHub Actions workflows, as well as Dependabot and pre-commit configs… | 84 | 6394 | active |
| lexiforest/curl_cffi curl_cffi is a Python binding for a curl-impersonate fork via cffi, providing an HTTP client that can impersonate browser TLS/JA3, HTTP/2, … | 99 | 6390 | active |
| s0md3v/Arjun Arjun is a Python command-line tool that discovers hidden HTTP query parameters for URL endpoints using a large dictionary of over 25,000 p… | 26 | 6385 | active |
| zmap/zmap ZMap is a fast, stateless single-packet network scanner written in C, designed for Internet-wide network surveys such as scanning the entir… | 90 | 6366 | active |
| microsoft/Detours Microsoft Detours is a C++ library for intercepting, monitoring, and instrumenting Win32 API calls on Windows via function hooking and bina… | 67 | 6364 | stable |
| Mygod/VPNHotspot An Android app that shares your device's VPN connection over a Wi-Fi hotspot, repeater, or USB/Bluetooth tethering. It requires root access… | 94 | 6353 | active |
| crytic/slither Slither is a Python-based static analysis framework for Solidity and Vyper smart contracts. It runs vulnerability detectors, prints contrac… | 94 | 6352 | active |
| derailed/popeye Popeye is a read-only CLI tool that scans live Kubernetes clusters and reports potential issues with deployed resources and configurations.… | 59 | 6346 | active |
| dnSpy/dnSpy dnSpy is a Windows GUI application for debugging and editing .NET and Unity assemblies without needing source code. It combines a debugger,… | 10 | 29689 | maintenance |
| wxxsfxyzm/InstallerX-Revived InstallerX Revived is a modern Android package installer app supporting APK, APKS, APKM, XAPK, and ZIP formats with batch installation. It … | 84 | 6333 | active |
| 5ec1cff/TrickyStore Tricky Store is a Magisk module for Android 10+ that modifies the certificate chain generated during Android key attestation to spoof devic… | 46 | 6315 | active |
| DanTheMan827/ios-app-signer A macOS GUI application that re-signs iOS/tvOS apps and bundles them into installable ipa files. It accepts ipa, deb, app, and xcarchive in… | 40 | 6314 | active |
| ikarus23/MifareClassicTool An Android NFC application for reading, writing, analyzing, and cloning MIFARE Classic RFID tags. It includes dictionary-based key manageme… | 83 | 6312 | active |
| google/syzkaller syzkaller is an unsupervised coverage-guided kernel fuzzer originally built for the Linux kernel and now supporting FreeBSD, Fuchsia, gViso… | 77 | 6309 | active |
| mviereck/x11docker x11docker is a shell-based CLI tool that runs graphical applications and entire desktop environments inside Docker, podman, or nerdctl cont… | 84 | 6303 | stable |
| infinition/Bjorn Bjorn is an autonomous network scanning and offensive security tool that runs on a Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers … | 63 | 6252 | active |
| Outline Outline is a pair of open-source applications from Jigsaw (Google) for creating and using your own VPN server: Outline Manager sets up and … | 71 | 6249 | active |
| sigstore/cosign Cosign is a CLI tool from the Sigstore project for signing and verifying OCI containers and other software artifacts, with support for keyl… | 98 | 6247 | stable |
| dehydrated-io/dehydrated Dehydrated is an ACME client for signing TLS certificates from CAs like Let's Encrypt and ZeroSSL, implemented as a single bash/zsh-compati… | 59 | 6244 | active |
| express-validator/express-validator express-validator is an Express.js middleware wrapping the validator.js library for request validation and sanitization. It lets you declar… | 82 | 6236 | stable |
| auth0/java-jwt A Java library for creating and verifying JSON Web Tokens (JWT) per RFC 7519, supporting HMAC, RSA, and ECDSA signing algorithms. It is mai… | 92 | 6235 | active |
| PBH-BTN/PeerBanHelper PeerBanHelper is a self-hosted Java application that automatically bans unwanted, leeching, and abnormal BitTorrent peers by connecting to … | 88 | 6210 | active |
| androguard/androguard Androguard is a full Python tool and library for reverse engineering and analyzing Android files, including DEX/ODEX bytecode disassembly a… | 83 | 6209 | active |
| PhilippC/keepass2android Keepass2android is an open-source password manager app for Android, compatible with the KeePass 2.x database format. It stores credentials … | 97 | 6205 | active |
| projectdiscovery/naabu Naabu is a fast, lightweight port scanner written in Go that performs SYN, CONNECT, and UDP scans to enumerate open ports on hosts. It is d… | 89 | 6205 | active |
| Trusted-AI/adversarial-robustness-toolbox Adversarial Robustness Toolbox (ART) is a Python library for machine learning security covering evasion, poisoning, extraction, and inferen… | 55 | 6204 | stable |
| k8gege/K8tools K8tools is a large curated collection of penetration testing and offensive security tools covering internal network penetration, privilege … | 34 | 6203 | active |
| gitleaks/gitleaks Gitleaks is an open-source CLI tool for detecting secrets like passwords, API keys, and tokens in git repositories, files, directories, and… | 91 | 28965 | maintenance |
| BrowserWorks/waterfox Waterfox is a free, open-source web browser built on the Mozilla Firefox/Gecko platform with telemetry and data collection disabled at buil… | 99 | 6198 | active |
| expressjs/cors A Node.js middleware for Express and Connect that sets CORS response headers, telling browsers which origins may read responses from your s… | 70 | 6191 | stable |
| GhostTroops/scan4all scan4all is a Go-based automated vulnerability scanning and reconnaissance tool that integrates vscan, nuclei, ksubdomain, and subfinder. I… | 23 | 6170 | active |
| SukiSU-Ultra/SukiSU-Ultra SukiSU-Ultra is a kernel-based Android root solution providing kernel-level su and root access management, with support for KPM kernel modu… | 82 | 6162 | active |
| mandiant/capa capa is Mandiant FLARE's open-source tool that identifies capabilities in executable files (PE, ELF, .NET, shellcode) by matching expert-wr… | 87 | 6156 | active |
| DominicBreuker/pspy pspy is a command line tool that snoops on Linux processes without root permissions by combining procfs scans with inotify watchers to catc… | 54 | 6155 | stable |
| cloud-hypervisor/cloud-hypervisor Cloud Hypervisor is an open source Virtual Machine Monitor (VMM) written in Rust that runs on top of KVM or Microsoft's MSHV hypervisor. It… | 93 | 6149 | active |
| guanzhi/GmSSL GmSSL is an open-source cryptographic toolkit developed at Peking University implementing Chinese national commercial cryptography standard… | 80 | 6147 | stable |
| AzeemIdrisi/PhoneSploit-Pro PhoneSploit Pro is an all-in-one Python CLI tool for remotely exploiting and testing Android devices using ADB and the Metasploit Framework… | 88 | 6128 | active |
| InterceptSuite/ProxyBridge ProxyBridge is a free, open-source universal proxy client (Proxifier alternative) that transparently redirects TCP and UDP traffic from any… | 80 | 6128 | active |
| agentcodee/cursor-free-everyday A desktop application written in Rust that automates resetting free trial quotas for AI code editors like Cursor, Windsurf, Kiro, and Codex… | 59 | 6115 | active |
| Passbolt Passbolt Community Edition API is the JSON backend for the open source, security-first password manager for teams, built in PHP on CakePHP.… | 98 | 6095 | stable |
| AutoRecon/AutoRecon AutoRecon is a multi-threaded Python CLI tool that automates network reconnaissance by performing port and service detection scans, then la… | 61 | 6093 | active |
| anthropics/claude-code-security-review A GitHub Action that uses Anthropic's Claude to perform AI-powered security reviews of pull requests, analyzing code diffs for vulnerabilit… | 48 | 6093 | active |
| FederatedAI/FATE FATE (Federated AI Technology Enabler) is an industrial-grade open-source federated learning framework hosted by the Linux Foundation. It e… | 23 | 6089 | active |
| mishakorzik/AllHackingTools AllHackingTools is an all-in-one installer and menu system for Termux that automates downloading and installing a large collection of penet… | 56 | 6083 | active |
| foxcpp/maddy Maddy is a composable all-in-one mail server written in Go that combines an SMTP MTA/MX, IMAP storage, and email security protocols (DKIM, … | 92 | 6077 | active |
| Azure/Azure-Sentinel The official community repository for Microsoft Sentinel, a cloud-native SIEM, containing out-of-the-box detections, hunting queries, workb… | 77 | 6076 | active |
| qilingframework/qiling Qiling is a Python-based binary emulation framework built on Unicorn Engine that emulates executables across multiple platforms (Windows, m… | 79 | 6075 | active |
| langren1353/GM_script A collection of Tampermonkey/Greasemonkey userscripts, most notably AC-baidu, which removes redirects and ads from Baidu, Sogou, Google, Bi… | 72 | 6055 | active |
| cloud-custodian/cloud-custodian Cloud Custodian (c7n) is a Python-based stateless rules engine for managing public cloud accounts and resources via YAML policy DSLs with f… | 90 | 6053 | stable |
| lesspass/lesspass LessPass is a stateless, open-source password manager that deterministically generates site-specific passwords from a single master passwor… | 76 | 6053 | active |
| gerardog/gsudo gsudo is a sudo equivalent for Windows that lets users run commands or relaunch shells with elevated permissions from the current console. … | 70 | 6034 | active |
| alpkeskin/mosint Mosint is an automated email OSINT tool written in Go that investigates target email addresses by consolidating multiple services. It check… | 23 | 6008 | active |
| RfidResearchGroup/proxmark3 The Iceman fork of Proxmark3, the client software for the Proxmark3 RFID analysis device, supporting reading, cloning, simulating, and snif… | 88 | 5986 | active |
| Tencent/AI-Infra-Guard Tencent's full-stack AI red teaming platform that scans AI infrastructure, agents, MCP servers, and skills for vulnerabilities and evaluate… | 88 | 5984 | active |
| undergroundwires/privacy.sexy privacy.sexy is an open-source desktop application that enforces privacy and security best practices on Windows, macOS, and Linux. It provi… | 60 | 5983 | active |
| openpgpjs/openpgpjs OpenPGP.js is a pure JavaScript implementation of the OpenPGP protocol (RFC 9580), maintained by Proton Mail. It lets applications encrypt,… | 90 | 5969 | stable |
| Ackites/KillWxapkg A Go-based CLI tool that automatically decrypts, unpacks, and decompiles WeChat mini-program .wxapkg packages, restoring the original proje… | 14 | 5957 | active |
| TsudaKageyu/minhook MinHook is a minimalistic, lightweight C library for intercepting (hooking) x86 and x64 function calls on Windows, using a trampoline/detou… | 62 | 5955 | stable |
| FluxionNetwork/fluxion Fluxion is a security auditing and social-engineering research tool that retrieves WPA/WPA2 keys via phishing attacks using rogue access po… | 91 | 5907 | active |
| shiaho777/web-to-app WebToApp is an Android application that lets users build signed, installable APKs from web projects entirely on their phone, without a PC o… | 83 | 5894 | active |
| vimeo/psalm Psalm is an open-source static analysis tool for PHP that finds type-related bugs and security vulnerabilities through type inference and t… | 88 | 5884 | active |
| lanmaster53/recon-ng Recon-ng is a full-featured, modular reconnaissance framework for conducting web-based open source intelligence (OSINT) gathering. It offer… | 32 | 5871 | active |
| microsoft/sudo Sudo for Windows is a Windows-specific implementation of the sudo concept, letting users run elevated commands directly from unelevated ter… | 70 | 5856 | active |
| Dicklesworthstone/destructive_command_guard A high-performance Rust CLI hook that intercepts and blocks destructive git and shell commands before AI coding agents execute them. It int… | 83 | 5840 | active |
| RedSiege/EyeWitness EyeWitness is a Python CLI tool that takes screenshots of websites using headless Chromium, captures server header information, and identif… | 50 | 5829 | active |
| commixproject/commix Commix (short for command injection exploiter) is an open-source penetration testing tool that automates the detection and exploitation of … | 75 | 5824 | active |
| jedisct1/dsvpn DSVPN is a dead-simple, single-binary VPN tool written in C that tunnels traffic over TCP with modern, formally verified cryptography. It r… | 68 | 5816 | stable |
| Pennyw0rth/NetExec NetExec (nxc) is a community-maintained, open-source network execution tool and successor to CrackMapExec, used for pentesting and red-team… | 74 | 5815 | active |
| win-acme/win-acme win-acme is an ACMEv2 client for Windows that automates obtaining and installing SSL/TLS certificates from Let's Encrypt, ZeroSSL, and othe… | 62 | 5787 | active |
| RIOT-OS/RIOT RIOT is an open-source, vendor-independent operating system for Internet of Things and embedded devices, supporting 8/16/32-bit microcontro… | 95 | 5778 | active |
| rack/rack-attack Rack::Attack is Rack middleware for protecting Ruby and Rails web applications from abusive clients. It lets you define rules to allow, blo… | 68 | 5763 | stable |
| smol-machines/smolvm smolvm is an open-source CLI and runtime for running lightweight, hardware-isolated Linux microVMs locally on macOS, Linux, and Windows, bu… | 79 | 5756 | active |
| letsencrypt/boulder Boulder is the Go implementation of an ACME-based certificate authority that powers Let's Encrypt. It automates domain validation and issua… | 95 | 5742 | active |
| elceef/dnstwist dnstwist is a Python command-line tool that generates permutations of a domain name (typos, homoglyphs, IDN tricks) and checks which ones r… | 30 | 5730 | active |
| pfsense/pfsense pfSense is a free, open-source network firewall and router distribution based on FreeBSD with a custom kernel, managed entirely through a w… | 66 | 5721 | stable |
| cinit/QAuxiliary QAuxiliary is an open-source Xposed module based on QNotified that adds extra features and tweaks to the QQ and TIM Android messaging clien… | 92 | 5720 | active |
| seL4/seL4 seL4 is a formally verified microkernel operating system kernel written in C, providing high-assurance isolation and capability-based secur… | 89 | 5717 | active |
| freedomofpress/dangerzone Dangerzone is a desktop application from Freedom of the Press Foundation that converts untrusted documents (PDFs, office files, images) int… | 88 | 5715 | active |
| EFForg/rayhunter Rayhunter is an EFF-developed Rust tool that detects IMSI catchers (cell-site simulators, also known as stingrays) used for cellular survei… | 93 | 5688 | active |
| elder-plinius/T3MP3ST T3MP3ST is a multi-agent offensive-security framework that turns existing AI coding agents (Claude Code, Codex, Ollama, etc.) into autonomo… | 58 | 5684 | active |
| openfga/openfga OpenFGA is a high-performance, open-source fine-grained authorization and permission engine inspired by Google's Zanzibar, owned by the CNC… | 99 | 5661 | stable |
| burrowers/garble Garble is a CLI tool that obfuscates Go binaries by wrapping the Go toolchain's compiler and linker. It replaces identifiers, package paths… | 89 | 5659 | active |
| ossf/scorecard OpenSSF Scorecard is an automated tool that scores open source projects on security best practices through a series of checks. It can be ru… | 88 | 5653 | active |
| snyk/cli The Snyk CLI is a command-line tool that scans projects for security vulnerabilities across open-source dependencies, application code, con… | 99 | 5649 | active |
| orestbida/cookieconsent CookieConsent is a lightweight, GDPR and CCPA compliant cookie consent management plugin written in vanilla JavaScript with no dependencies… | 65 | 5642 | active |
| samolego/Canta Canta is an Android app that lets users uninstall any app without root access, powered by Shizuku. It includes community-powered recommenda… | 85 | 5640 | active |
| geo-tp/ESP32-Bit-Pirate ESP32 Bit Pirate is open-source C++ firmware that turns an ESP32-S3 board into a multi-protocol hardware debugging and analysis workbench, … | 84 | 5634 | active |