Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: security

4909 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
OISF/suricata
Suricata is a high-performance network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring…
936571stable
BruceDevices/firmware
Bruce is an open-source (AGPL-3.0) ESP32 firmware packed with offensive-security and Red Team tools such as WiFi attacks, Evil Portal, ward…
906570active
rust-lang/miri
Miri is an interpreter for Rust's mid-level intermediate representation (MIR) that detects undefined behavior in Rust programs. It runs bin…
776535active
aistra0528/Hail
Hail is a free, open-source Android app for freezing, disabling, hiding, or suspending other apps without root, using Shizuku or root privi…
886532active
bmrf/tron
Tron is an automated Windows PC cleanup and disinfection script, implemented as a collection of batch files that orchestrate many community…
656530active
EnableSecurity/wafw00f
WAFW00F is a Python command-line tool that identifies and fingerprints Web Application Firewall (WAF) products protecting a website. It sen…
796528stable
Mebus/cupp
CUPP is a Python CLI tool that generates targeted password wordlists by profiling personal information about a user, such as birthdays, nic…
746507active
romanvht/ByeByeDPI
An Android application that runs ByeDPI locally and routes all device traffic through it via Android's VPN mode to bypass DPI-based blockin…
886506active
cowrie/cowrie
Cowrie is a medium-to-high interaction SSH and Telnet honeypot that logs brute-force attacks and full attacker shell sessions, capturing up…
996504active
MISP/MISP
MISP is an open source threat intelligence platform for collecting, storing, correlating, and sharing cyber security indicators, malware an…
996490stable
palera1n/palera1n
palera1n is an open-source jailbreak tool for Apple devices using the checkm8 bootrom exploit, supporting A8 through A11 chips and T2 secur…
886475active
opa334/Dopamine
Dopamine is a rootless semi-untethered jailbreak tool for iOS 15 through 26.0.1, supporting arm64e and A12/A13 devices. It is written prima…
986449active
tock/tock
Tock is an embedded operating system for low-power, low-memory microcontrollers that runs multiple concurrent, mutually distrustful applica…
676423active
zizmorcore/zizmor
zizmor is a static analysis tool for CI/CD configurations, primarily GitHub Actions workflows, as well as Dependabot and pre-commit configs…
846394active
lexiforest/curl_cffi
curl_cffi is a Python binding for a curl-impersonate fork via cffi, providing an HTTP client that can impersonate browser TLS/JA3, HTTP/2, …
996390active
s0md3v/Arjun
Arjun is a Python command-line tool that discovers hidden HTTP query parameters for URL endpoints using a large dictionary of over 25,000 p…
266385active
zmap/zmap
ZMap is a fast, stateless single-packet network scanner written in C, designed for Internet-wide network surveys such as scanning the entir…
906366active
microsoft/Detours
Microsoft Detours is a C++ library for intercepting, monitoring, and instrumenting Win32 API calls on Windows via function hooking and bina…
676364stable
Mygod/VPNHotspot
An Android app that shares your device's VPN connection over a Wi-Fi hotspot, repeater, or USB/Bluetooth tethering. It requires root access…
946353active
crytic/slither
Slither is a Python-based static analysis framework for Solidity and Vyper smart contracts. It runs vulnerability detectors, prints contrac…
946352active
derailed/popeye
Popeye is a read-only CLI tool that scans live Kubernetes clusters and reports potential issues with deployed resources and configurations.…
596346active
dnSpy/dnSpy
dnSpy is a Windows GUI application for debugging and editing .NET and Unity assemblies without needing source code. It combines a debugger,…
1029689maintenance
wxxsfxyzm/InstallerX-Revived
InstallerX Revived is a modern Android package installer app supporting APK, APKS, APKM, XAPK, and ZIP formats with batch installation. It …
846333active
5ec1cff/TrickyStore
Tricky Store is a Magisk module for Android 10+ that modifies the certificate chain generated during Android key attestation to spoof devic…
466315active
DanTheMan827/ios-app-signer
A macOS GUI application that re-signs iOS/tvOS apps and bundles them into installable ipa files. It accepts ipa, deb, app, and xcarchive in…
406314active
ikarus23/MifareClassicTool
An Android NFC application for reading, writing, analyzing, and cloning MIFARE Classic RFID tags. It includes dictionary-based key manageme…
836312active
google/syzkaller
syzkaller is an unsupervised coverage-guided kernel fuzzer originally built for the Linux kernel and now supporting FreeBSD, Fuchsia, gViso…
776309active
mviereck/x11docker
x11docker is a shell-based CLI tool that runs graphical applications and entire desktop environments inside Docker, podman, or nerdctl cont…
846303stable
infinition/Bjorn
Bjorn is an autonomous network scanning and offensive security tool that runs on a Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers …
636252active
Outline
Outline is a pair of open-source applications from Jigsaw (Google) for creating and using your own VPN server: Outline Manager sets up and …
716249active
sigstore/cosign
Cosign is a CLI tool from the Sigstore project for signing and verifying OCI containers and other software artifacts, with support for keyl…
986247stable
dehydrated-io/dehydrated
Dehydrated is an ACME client for signing TLS certificates from CAs like Let's Encrypt and ZeroSSL, implemented as a single bash/zsh-compati…
596244active
express-validator/express-validator
express-validator is an Express.js middleware wrapping the validator.js library for request validation and sanitization. It lets you declar…
826236stable
auth0/java-jwt
A Java library for creating and verifying JSON Web Tokens (JWT) per RFC 7519, supporting HMAC, RSA, and ECDSA signing algorithms. It is mai…
926235active
PBH-BTN/PeerBanHelper
PeerBanHelper is a self-hosted Java application that automatically bans unwanted, leeching, and abnormal BitTorrent peers by connecting to …
886210active
androguard/androguard
Androguard is a full Python tool and library for reverse engineering and analyzing Android files, including DEX/ODEX bytecode disassembly a…
836209active
PhilippC/keepass2android
Keepass2android is an open-source password manager app for Android, compatible with the KeePass 2.x database format. It stores credentials …
976205active
projectdiscovery/naabu
Naabu is a fast, lightweight port scanner written in Go that performs SYN, CONNECT, and UDP scans to enumerate open ports on hosts. It is d…
896205active
Trusted-AI/adversarial-robustness-toolbox
Adversarial Robustness Toolbox (ART) is a Python library for machine learning security covering evasion, poisoning, extraction, and inferen…
556204stable
k8gege/K8tools
K8tools is a large curated collection of penetration testing and offensive security tools covering internal network penetration, privilege …
346203active
gitleaks/gitleaks
Gitleaks is an open-source CLI tool for detecting secrets like passwords, API keys, and tokens in git repositories, files, directories, and…
9128965maintenance
BrowserWorks/waterfox
Waterfox is a free, open-source web browser built on the Mozilla Firefox/Gecko platform with telemetry and data collection disabled at buil…
996198active
expressjs/cors
A Node.js middleware for Express and Connect that sets CORS response headers, telling browsers which origins may read responses from your s…
706191stable
GhostTroops/scan4all
scan4all is a Go-based automated vulnerability scanning and reconnaissance tool that integrates vscan, nuclei, ksubdomain, and subfinder. I…
236170active
SukiSU-Ultra/SukiSU-Ultra
SukiSU-Ultra is a kernel-based Android root solution providing kernel-level su and root access management, with support for KPM kernel modu…
826162active
mandiant/capa
capa is Mandiant FLARE's open-source tool that identifies capabilities in executable files (PE, ELF, .NET, shellcode) by matching expert-wr…
876156active
DominicBreuker/pspy
pspy is a command line tool that snoops on Linux processes without root permissions by combining procfs scans with inotify watchers to catc…
546155stable
cloud-hypervisor/cloud-hypervisor
Cloud Hypervisor is an open source Virtual Machine Monitor (VMM) written in Rust that runs on top of KVM or Microsoft's MSHV hypervisor. It…
936149active
guanzhi/GmSSL
GmSSL is an open-source cryptographic toolkit developed at Peking University implementing Chinese national commercial cryptography standard…
806147stable
AzeemIdrisi/PhoneSploit-Pro
PhoneSploit Pro is an all-in-one Python CLI tool for remotely exploiting and testing Android devices using ADB and the Metasploit Framework…
886128active
InterceptSuite/ProxyBridge
ProxyBridge is a free, open-source universal proxy client (Proxifier alternative) that transparently redirects TCP and UDP traffic from any…
806128active
agentcodee/cursor-free-everyday
A desktop application written in Rust that automates resetting free trial quotas for AI code editors like Cursor, Windsurf, Kiro, and Codex…
596115active
Passbolt
Passbolt Community Edition API is the JSON backend for the open source, security-first password manager for teams, built in PHP on CakePHP.…
986095stable
AutoRecon/AutoRecon
AutoRecon is a multi-threaded Python CLI tool that automates network reconnaissance by performing port and service detection scans, then la…
616093active
anthropics/claude-code-security-review
A GitHub Action that uses Anthropic's Claude to perform AI-powered security reviews of pull requests, analyzing code diffs for vulnerabilit…
486093active
FederatedAI/FATE
FATE (Federated AI Technology Enabler) is an industrial-grade open-source federated learning framework hosted by the Linux Foundation. It e…
236089active
mishakorzik/AllHackingTools
AllHackingTools is an all-in-one installer and menu system for Termux that automates downloading and installing a large collection of penet…
566083active
foxcpp/maddy
Maddy is a composable all-in-one mail server written in Go that combines an SMTP MTA/MX, IMAP storage, and email security protocols (DKIM, …
926077active
Azure/Azure-Sentinel
The official community repository for Microsoft Sentinel, a cloud-native SIEM, containing out-of-the-box detections, hunting queries, workb…
776076active
qilingframework/qiling
Qiling is a Python-based binary emulation framework built on Unicorn Engine that emulates executables across multiple platforms (Windows, m…
796075active
langren1353/GM_script
A collection of Tampermonkey/Greasemonkey userscripts, most notably AC-baidu, which removes redirects and ads from Baidu, Sogou, Google, Bi…
726055active
cloud-custodian/cloud-custodian
Cloud Custodian (c7n) is a Python-based stateless rules engine for managing public cloud accounts and resources via YAML policy DSLs with f…
906053stable
lesspass/lesspass
LessPass is a stateless, open-source password manager that deterministically generates site-specific passwords from a single master passwor…
766053active
gerardog/gsudo
gsudo is a sudo equivalent for Windows that lets users run commands or relaunch shells with elevated permissions from the current console. …
706034active
alpkeskin/mosint
Mosint is an automated email OSINT tool written in Go that investigates target email addresses by consolidating multiple services. It check…
236008active
RfidResearchGroup/proxmark3
The Iceman fork of Proxmark3, the client software for the Proxmark3 RFID analysis device, supporting reading, cloning, simulating, and snif…
885986active
Tencent/AI-Infra-Guard
Tencent's full-stack AI red teaming platform that scans AI infrastructure, agents, MCP servers, and skills for vulnerabilities and evaluate…
885984active
undergroundwires/privacy.sexy
privacy.sexy is an open-source desktop application that enforces privacy and security best practices on Windows, macOS, and Linux. It provi…
605983active
openpgpjs/openpgpjs
OpenPGP.js is a pure JavaScript implementation of the OpenPGP protocol (RFC 9580), maintained by Proton Mail. It lets applications encrypt,…
905969stable
Ackites/KillWxapkg
A Go-based CLI tool that automatically decrypts, unpacks, and decompiles WeChat mini-program .wxapkg packages, restoring the original proje…
145957active
TsudaKageyu/minhook
MinHook is a minimalistic, lightweight C library for intercepting (hooking) x86 and x64 function calls on Windows, using a trampoline/detou…
625955stable
FluxionNetwork/fluxion
Fluxion is a security auditing and social-engineering research tool that retrieves WPA/WPA2 keys via phishing attacks using rogue access po…
915907active
shiaho777/web-to-app
WebToApp is an Android application that lets users build signed, installable APKs from web projects entirely on their phone, without a PC o…
835894active
vimeo/psalm
Psalm is an open-source static analysis tool for PHP that finds type-related bugs and security vulnerabilities through type inference and t…
885884active
lanmaster53/recon-ng
Recon-ng is a full-featured, modular reconnaissance framework for conducting web-based open source intelligence (OSINT) gathering. It offer…
325871active
microsoft/sudo
Sudo for Windows is a Windows-specific implementation of the sudo concept, letting users run elevated commands directly from unelevated ter…
705856active
Dicklesworthstone/destructive_command_guard
A high-performance Rust CLI hook that intercepts and blocks destructive git and shell commands before AI coding agents execute them. It int…
835840active
RedSiege/EyeWitness
EyeWitness is a Python CLI tool that takes screenshots of websites using headless Chromium, captures server header information, and identif…
505829active
commixproject/commix
Commix (short for command injection exploiter) is an open-source penetration testing tool that automates the detection and exploitation of …
755824active
jedisct1/dsvpn
DSVPN is a dead-simple, single-binary VPN tool written in C that tunnels traffic over TCP with modern, formally verified cryptography. It r…
685816stable
Pennyw0rth/NetExec
NetExec (nxc) is a community-maintained, open-source network execution tool and successor to CrackMapExec, used for pentesting and red-team…
745815active
win-acme/win-acme
win-acme is an ACMEv2 client for Windows that automates obtaining and installing SSL/TLS certificates from Let's Encrypt, ZeroSSL, and othe…
625787active
RIOT-OS/RIOT
RIOT is an open-source, vendor-independent operating system for Internet of Things and embedded devices, supporting 8/16/32-bit microcontro…
955778active
rack/rack-attack
Rack::Attack is Rack middleware for protecting Ruby and Rails web applications from abusive clients. It lets you define rules to allow, blo…
685763stable
smol-machines/smolvm
smolvm is an open-source CLI and runtime for running lightweight, hardware-isolated Linux microVMs locally on macOS, Linux, and Windows, bu…
795756active
letsencrypt/boulder
Boulder is the Go implementation of an ACME-based certificate authority that powers Let's Encrypt. It automates domain validation and issua…
955742active
elceef/dnstwist
dnstwist is a Python command-line tool that generates permutations of a domain name (typos, homoglyphs, IDN tricks) and checks which ones r…
305730active
pfsense/pfsense
pfSense is a free, open-source network firewall and router distribution based on FreeBSD with a custom kernel, managed entirely through a w…
665721stable
cinit/QAuxiliary
QAuxiliary is an open-source Xposed module based on QNotified that adds extra features and tweaks to the QQ and TIM Android messaging clien…
925720active
seL4/seL4
seL4 is a formally verified microkernel operating system kernel written in C, providing high-assurance isolation and capability-based secur…
895717active
freedomofpress/dangerzone
Dangerzone is a desktop application from Freedom of the Press Foundation that converts untrusted documents (PDFs, office files, images) int…
885715active
EFForg/rayhunter
Rayhunter is an EFF-developed Rust tool that detects IMSI catchers (cell-site simulators, also known as stingrays) used for cellular survei…
935688active
elder-plinius/T3MP3ST
T3MP3ST is a multi-agent offensive-security framework that turns existing AI coding agents (Claude Code, Codex, Ollama, etc.) into autonomo…
585684active
openfga/openfga
OpenFGA is a high-performance, open-source fine-grained authorization and permission engine inspired by Google's Zanzibar, owned by the CNC…
995661stable
burrowers/garble
Garble is a CLI tool that obfuscates Go binaries by wrapping the Go toolchain's compiler and linker. It replaces identifiers, package paths…
895659active
ossf/scorecard
OpenSSF Scorecard is an automated tool that scores open source projects on security best practices through a series of checks. It can be ru…
885653active
snyk/cli
The Snyk CLI is a command-line tool that scans projects for security vulnerabilities across open-source dependencies, application code, con…
995649active
orestbida/cookieconsent
CookieConsent is a lightweight, GDPR and CCPA compliant cookie consent management plugin written in vanilla JavaScript with no dependencies…
655642active
samolego/Canta
Canta is an Android app that lets users uninstall any app without root access, powered by Shizuku. It includes community-powered recommenda…
855640active
geo-tp/ESP32-Bit-Pirate
ESP32 Bit Pirate is open-source C++ firmware that turns an ESP32-S3 board into a multi-protocol hardware debugging and analysis workbench, …
845634active

← prev page 5 / 50 next →