CATEGORY
Security 391 crates
Data as of 2026-07-25 (crates.io database dump, timestamp 2026-07-25T02:00:36Z). Source: crates.io · db-dump.tar.gz · methodology & corrections.
rite-sdkBackend traits and domain types for the Rite cryptographic key ceremony toolkit413Apache-2.0 OR MIT
toq-cliEncrypted agent-to-agent communication daemon and CLI362Apache-2.0
lockrail-protocolProtocol primitives, secret sealing, and LRAP verification for Lockrail362PolyForm-Noncommercial-1.0.0
sentinel-sdkRust SDK for Sentinel LLM Security Gateway360MIT
cedrus-cedarCore library for Cedar Policy serialization and type bindings.347Apache-2.0
pbt-testsProperty-based testing with `derive` macros, aware of mutual induction & instantiability.345MIT OR Apache-2.0
ckmsCommand Line Interface used to manage the Cosmian KMS server.
If any assistance is needed, please either visit the Cosmian…344BUSL-1.1
rite-modelDomain model and intermediate representation for the Rite key ceremony DSL344Apache-2.0 OR MIT
mewtMutation testing framework with multi-language support343AGPL-3.0
cargo-annealFormally verify that your safety comments are correct.335BSD-2-Clause OR Apache-2.0 OR MIT
pbt-macro2High-throughput property-based testing with `derive`, swarm-testing, precise sizing, and full graph-theoretic type analysis over…332MIT OR Apache-2.0
ThreatDeckTerminal-based threat intelligence monitoring and alerting platform330MIT
lazynmapA TUI for interactively generating nmap commands321MIT
cargo-reproduceA Cargo subcommand for reproducible Rust builds. Normalizes the build environment, strips nondeterministic metadata, and verifies…308MIT
shipper-encryptState file encryption for shipper using AES-256-GCM306MIT OR Apache-2.0
lockrail-vaultEncrypted local vault and agent-key storage for Lockrail284PolyForm-Noncommercial-1.0.0
lockrail-auditTamper-evident audit chain primitives for Lockrail281PolyForm-Noncommercial-1.0.0
il2cpp_rsA library for interacting with il2cpp on Windows280GPL-3.0
vks_clientClient implementation of the Verifying Keyserver (VKS) interface279LGPL-2.1-or-later
rsrp-policy-dslCompiled policy DSL for deterministic access-control and proof-oriented rule execution279EUPL-1.2
rsrp-security-coreSecurity primitives for deterministic proof systems (hashing, signatures, Merkle helpers)278EUPL-1.2
webinfoA tool to gather information about a list of websites.270Apache-2.0
cf-gears-credstore-sdkSDK for credstore gear: API traits, models, and error definitions267Apache-2.0
cosmian_kms_cli_actionsCommand Line Interface used to manage the KMS server
If any assistance is needed, please either visit the Cosmian technical…265BUSL-1.1
shamir-zeroFast zero-copy Shamir's Secret Sharing in Rust - derived from IBM / HashiCorp Vault's original Go implementation (MPL-2.0)253MIT OR Apache-2.0
rsrp-pqcryptoHybrid post-quantum cryptographic primitives for deterministic proof systems250EUPL-1.2
raxit-coreCore security scanning engine for AI agent applications247MIT OR Apache-2.0
lockrail-relayPolicy-enforcing relay with replay protection for Lockrail244PolyForm-Noncommercial-1.0.0
lockrail-proxyLocal HTTPS intercepting proxy for Lockrail — scans AI API traffic for secrets243PolyForm-Noncommercial-1.0.0
ancaptchaStateless human verification engine using interactive CSS instead of JavaScript.237Apache-2.0
magic_capMagic Cap is a user-friendly tool for encrypted files.234AGPL-3.0-or-later
libsignify-rsOpenBSD-compatible file signing & verification library234ISC
pfnatdEasy NAT mode for OpenBSD packet filter (pf)230MPL-2.0
attestation-validatorValidates attestation certificate chains and inspects attestation certificates230MIT OR Apache-2.0
wolfssl-wolfcryptRust wrapper for wolfssl C library cryptographic functionality229GPL-3.0
rite-resolverParser, validator, and resolver for the Rite key ceremony DSL228Apache-2.0 OR MIT
jwtypeTypes for jwtiny226MIT
llm-securityComprehensive LLM security layer to prevent prompt injection and manipulation attacks225MIT
rustenium-identityA versatile stealth overlay for rustenium219GPL-3.0-or-later
otlsp-coreCore library of shared structures for OTLSP216MIT OR Apache-2.0
cose_minicborno_std-friendly Rust crate for decoding and verifying COSE (CBOR Object Signing and Encryption) messages with optional…216MIT
coraza-sysRaw FFI bindings to OWASP Coraza WAF215Apache-2.0
ReXORCross-platform library with CLI app for encoding and decoding files using XOR encryption212MIT
modseclogIntrospection of ModSecurity log files211Apache-2.0
phishnanoLightweight offline phishing URL detection library with embedded Random Forest model, microsecond local inference, and zero…208MIT OR Apache-2.0
rustnmap-evasionFirewall and IDS evasion techniques for RustNmap network scanner206GPL-3.0-or-later
threat-intelComprehensive threat intelligence framework with multi-source aggregation, CVE integration, and risk assessment201MIT
cf-gears-credstorecredstore gateway module198Apache-2.0
hana-vaultA library used by the Hana SSH client for storing user data securely in encrypted SQLite.198MIT
rustcryptMacro-first encryption and obfuscation library for Rust197MIT
corazaSafe Rust bindings to OWASP Coraza WAF197Apache-2.0
cargo-hermesFormally verify that your safety comments are correct.193BSD-2-Clause OR Apache-2.0 OR MIT
malware-modelerTrain logisitic regression models for benign vs. malicious files based on byte n-grams and publish research, plus related tools.191Apache-2.0
cedrus-coreBusiness logic and authorization engine for Cedrus.188Apache-2.0
openvet-policyRequirement language and Kleene evaluator for OpenVet audit policies.187MIT OR Apache-2.0
lockrailLocal-first secret firewall for AI coding tools185PolyForm-Noncommercial-1.0.0
sealwdSecure password and token management library for Rust, featuring hashing, encryption, and random generation.178Apache-2.0
rsrp-proof-engineDeterministic proof engine for high-integrity Rust applications178EUPL-1.2
ghidra-version-managerGhidra Version Manager177GPL-3.0-only
rsrp-immutable-ledgerAppend-only immutable audit ledger with hash chaining, Merkle roots, and publication support172EUPL-1.2
passcorePasscore is a lightweight Rust library that scores password strength.163MIT
keynestSimple, offline, cross-platform secrets manager written in Rust163MIT OR Apache-2.0
cargo-dddA cargo subcommand for inspecting what changes brings dependency version update into your project152MIT OR Apache-2.0
polarstegoRust implementation of binary Steganographic Polar Codes150MIT
signify-rsOpenBSD-compatible file signing & verification tool149ISC
ingredientsCheck ingredients of published Rust crates145MIT
luct-testTest functionality used throughout the luct proces142MIT OR Apache-2.0
winauditAdvanced Windows auditing and security assessment Crate in Rust141MIT
otlsp-clientOblivious TLS proxy client133MIT OR Apache-2.0
get-mitreTools for CVE managing, exploring and collect some data about their weaknesses and classifications132MIT
openvet-serverReference HTTP server for hosting OpenVet logs.132MIT OR Apache-2.0
ureldUreld is a simple & fast URLs de-cluttering tool written in Rust.130GPL-3.0-only
nyx-agent-typesImplementation-detail serde and TypeScript wire types shared by nyx-agent crates.127AGPL-3.0-or-later
nargo-auditNargo audit tool127MIT
rustnmap-vulnVulnerability intelligence for RustNmap (CVE/CPE, EPSS, CISA KEV)124GPL-3.0-or-later
openvet-auditValidation and check logic for OpenVet audits.124MIT OR Apache-2.0
openvet-clientConsumer-side primitives for OpenVet: log client, on-disk cache, project/user config, audit workspace, publish staging, subject…120MIT OR Apache-2.0
luct-otlspLuct client implementation using oblivious TLS client117MIT OR Apache-2.0
env_encryption_toolRust-based .env (dotenv) file encryption & decryption tool - store & retrieve your app environment variables safely 😎 now…117AGPL-3.0-only
wolfcrypt-wrapperRust wrapper for wolfssl C library cryptographic functionality115GPL-3.0-only OR LicenseRef-wolfSSL-commercial
rbatA terminal-native binary analysis tool for security researchers and reverse engineers.112MIT
askryptPassword manager without master password111Apache-2.0
nyx-agent-coreImplementation-detail config, state, persistence, and scan orchestration for nyx-agent.109AGPL-3.0-or-later
swage-blacksmithBlacksmith hammerer module for Swage.107MIT
openvetCommand-line tool for checking project conformance against auditing requirements, and authoring, signing and publishing software…107MIT OR Apache-2.0
swage-cocoCoCo allocator module for Swage.106MIT
swage-dummyDummy hammerer module for Swage.106MIT
swage-spoilerSPOILER allocator module for Swage.106MIT
swage-dev-memDevMem hammerer module for Swage.105MIT
swage-hugepageHugepage allocator module for Swage.105MIT
swage-pfnPFN allocator module for Swage.104MIT
swage-thpTHP allocator module for Swage.104MIT
swage-victim-dev-memcheckDevMemCheck victim module for Swage.104MIT
gensenseGenSense: High-performance semantic diagnostic engine for Rust, TypeScript, and Solidity.103MIT
safe-telnet-parserMemory-safe Telnet protocol parser for defensive security and CVE mitigation103MIT
touched-deriveDerive macro `Touchable` for `touched` crate.101MIT OR Apache-2.0
rama-net-apple-networkextensionApple Network Extension support for rama98MIT OR Apache-2.0
seccompySeccomp library with unotify support and without libseccomp dependency95Apache-2.0
spotspoof-cliDomain spoofing & IDN/Punycode detection for security automation workflows.95MIT
password_Simple and secure password hashing library based on Argon2 / 基于 Argon2 的简单安全密码哈希库91MulanPSL-2.0
token-privilegeSafe Rust wrapper around Windows process token privilege and elevation detection APIs91MIT OR Apache-2.0
secure-cryptUltra secure encryption/decryption tool using Rust + libsodium with zero secret leakage.89MIT
rbacrabRust 🦀RBAC🦀 library with some crabby🦀🧙 macro magic! Blazingly 🚀🚀🚀 fast.89MIT
boo-rsEncrypt primitives types at compile time88MIT
rustnmap-scan-managementScan management for RustNmap (persistence, diff, YAML profiles)88GPL-3.0-or-later
riteAuthor, execute, and verify cryptographic key ceremonies (the `rite` CLI)88GPL-3.0-only
hydra-syncLight-weight zero-copy E2E Single Producer Multiple Consumer network cluster library.83MIT
palisade-correlationSecurity-conscious correlation engine for Palisade honeypot and deception deployments79Apache-2.0
otlsp-serverOblivious TLS proxy server79MIT OR Apache-2.0
zed-highlight-lspAn LSP implemented for Zed that allows to highlight all occurrences of selected words.79MIT
rite-lsLanguage server for the Rite ceremony DSL79GPL-3.0-only
openinternetcryptographykeysA Simple Standard Cryptography-Suite For Web 3.20, offering cryptographic abstraction (Generic Signing/Verifying, Generic…77Apache-2.0 OR MIT
symbitSymbolic bitvector library with bitwise and integer arithmetic support76MPL-2.0
harbor-coreCore library for the Harbor tool.75MIT
skp-ratelimitAdvanced, modular, extensible rate limiting library with GCRA, per-route quotas, and composite keys74MIT
magic_cap_cliMagic Cap is a user-friendly tool for encrypted files.73AGPL-3.0-or-later
suit_validatorno_std-friendly Rust crate for decoding and verifying SUIT Manifest.72MIT
secret-managerA distributed secret rotation and management library68MIT OR Apache-2.0
luct-nodeAll-in-one server component for the luct project67MIT OR Apache-2.0
ocsf-typesStrongly typed Rust structs for the OCSF (Open Cybersecurity Schema Framework)65MIT
swh-vulns-grpc-serverMine data from vulnerability databases in the OSV format63GPL-3.0-or-later
idalib-macrosIdiomatic bindings to IDA SDK63MIT OR Apache-2.0
nyx-agent-nyxImplementation-detail subprocess driver for the upstream nyx static scanner.62AGPL-3.0-or-later
tartarus-apiStructured API for sandboxing system (currently utilizing `bubblewrap`)62Apache-2.0
hash-hunterFind files with specified hashes61MIT OR Apache-2.0
nyx-agent-sandboxImplementation-detail sandbox runners used by nyx-agent verification and replay tasks.60AGPL-3.0-or-later
iptr-edge-analyzerExtract edges and branches in Intel PT traces, and construct AFL++-compatible fuzzing bitmaps59MIT OR Apache-2.0
security-mcpMCP (Model Context Protocol) server providing security screening, injection detection, and threat analysis57MIT
periodic-auditA tool to run cargo-audit periodically and send email reports.57MIT OR Apache-2.0
axum-securityA security toolbox for the Axum library56MIT
oxitokenFastest and most secure JWT encoding/validation library for Rust. Fully supports custom header/claims structs, an extendable…53Apache-2.0 WITH LLVM-exception
cirandaA deterministic password generator52Apache-2.0 OR MIT
radiotap-rsno_std compatible radiotap header encoder and decoder.49MIT OR Apache-2.0
mintrtSecurity-featured runtime for lua.47non-standard
cosmian_pkcs11_verifyDiagnostic binary to verify that libcosmian_pkcs11.so is loadable and communicates with the KMS server45BUSL-1.1
nyx-agent-uiImplementation-detail embedded single-page dashboard assets for nyx-agent.44AGPL-3.0-or-later
nyx-agent-aiImplementation-detail AI runtime adapters, prompts, and automation helpers for nyx-agent.44AGPL-3.0-or-later
lockb-xrayCLI tool to audit Bun bun.lockb for supply chain risks44MIT
tiny-vsockTiny vsock library for secure communication with enclaves44MIT
nyx-agent-apiImplementation-detail loopback HTTP API and WebSocket server for nyx-agent.43AGPL-3.0-or-later
sil-semanticSemantic analysis engine for the Semantic Integrity Layer — Jaccard similarity and intent clustering43MIT
sil-confusableConfusable detection engine for the Semantic Integrity Layer — homoglyph detection and cross-script mixing analysis43MIT
nyx-agentLocal-first application security agent for live pentesting, verified findings, and an embedded dashboard.42AGPL-3.0-or-later
busbiA CLI tool to create Bad-USB scripts from shell scripts for quick use.42MIT
sil-normalizerUnicode normalization engine for the Semantic Integrity Layer — NFKC normalization and zero-width character filtering41MIT
sil-policyPolicy evaluation engine for the Semantic Integrity Layer — risk scoring and Allow/Warn/Block/Rewrite decisions41MIT
tartarusCLI tool wrapping bubblewrap to run proccesses sandboxed to not be able to write to external directories40Apache-2.0
synapse-wafHigh-performance WAF and reverse proxy with embedded intelligence — built on Cloudflare Pingora39AGPL-3.0-only
cedrusCedrus REST API server for Cedar Policy37Apache-2.0
cosmian_cngWindows CNG Key Storage Provider (KSP) for Cosmian KMS37BUSL-1.1
nbpc-rsRust implementation of non-binary polar codes for ternary steganographic embedding35MIT
rkh-chkCommand line companion tool to Rootkit Hunter35GPL-3.0-or-later
ttyinject-rsLinux LPE via TIOCSTI tty injection.33MIT
pscanSYN Port Scanner written in Rust, with range and decoy scanning support.31MIT OR Apache-2.0
abir_guardAbir-Guard: Quantum-Resilient Agentic Vault for AI Agent Memory with NIST-standard Post-Quantum Cryptography31MIT
zorph-cryptoCryptographic primitives for the Zorph platform30MIT
harbor-cliThe Harbor CLI, which is a web security tool.30MIT
rustshellAn educational project to aid in security operations and testing27non-standard
stealth-scannerA Solidity security scanner that detects common vulnerabilities through static analysis with intelligent pattern recognition27MIT
touchedUtility for writing fuzzing harnesses of callback-style and trait-style Rust crates27MIT OR Apache-2.0
oint-keysA Simple Standard Cryptography-Suite For Web 3.20, offering cryptographic abstraction (Generic Signing/Verifying, Generic…27Apache-2.0 OR MIT
opaque-rsA Rust implementation of the OPAQUE protocol for secure password authentication.27MIT
dusk-auth-core-rustAn opinionated, framework-agnostic authentication core enforcing correct session-based auth practices26MIT
telnet-sanitizerTelnet TCP proxy that sanitizes protocol input to mitigate CVE-class vulnerabilities25MIT
prudent-macros-enforceprudent-rs internal. Don't use directly/on its own. Instead, see and use prudent.25BSD-2-Clause OR Apache-2.0 OR MIT
prudent-macros-lintprudent-rs internal. Don't use directly/on its own. Instead, see and use prudent.25BSD-2-Clause OR Apache-2.0 OR MIT
skp-validator-actixActix Web integration for skp-validator - high-performance validation for Actix services24MIT
threatThreat manipulation library.24MIT OR Apache-2.0
lazycertACME certificate management daemon for Vane.24MIT
jitterbugA true random number generator based on CPU execution jitter.23AGPL-3.0-or-later
reaction-pluginPlugin interface for reaction, a daemon that scans logs and takes action (alternative to fail2ban)23AGPL-3.0
shellforgea highly customizable crate for generating assembly noops and junk code22GPL-3.0-or-later
tripfuseA one-time use container for sensitive values21MIT OR Apache-2.0
rustnmap-stateless-scanStateless high-speed scanning for RustNmap (masscan-like)21GPL-3.0-or-later
ry-godIndustrial-grade security & efficiency framework for Ry-Dit. Sandboxed execution, audit logging, memory limits, and zero-crash…20MIT
onetimepasswordOne-Time Password implementations20MIT OR Apache-2.0
openvet-mirrorValidating mirror for OpenVet logs.20MIT OR Apache-2.0
malinaCreate replicable and unique malware analysis laboratories from configuration19GPL-3.0-or-later
daniyal-cryptexThe ULTIMATE cryptographic framework for 2026! Functional Encryption, PSI, Verifiable Computation, ORAM - all in one!18MIT OR Apache-2.0
dynstallerDynamically retrieve installation files and metadata in a virtualized environment.18MIT
forward-proxyAn HTTP forward proxy designed for egress-based ACL filtering (and opt-in per-connection TOR routing).17MIT OR Apache-2.0
sil-cliCLI for the Semantic Integrity Layer — scan input for Unicode spoofing, confusable attacks, and semantic drift17MIT
safyControlled/scoped invocation of unsafe functions in Rust17BSD-2-Clause OR Apache-2.0 OR MIT
rbat-serverDistributed static binary analysis server wrapping the rbat static analysis engine.16MIT
palisade-telemetryTelemetry and monitoring engine for the Palisade honeypot system15MIT OR Apache-2.0
palisade-deceptionDeception engine for the Palisade honeypot system - creates and manages honeytokens and decoy artifacts15MIT OR Apache-2.0
silUnified crate for the Semantic Integrity Layer — Unicode spoofing, confusable attacks, and semantic drift detection15MIT
localHelp you make Rust code safer. Macros to provide locally scoped safe alternatives to unsafe references or values.12BSD-2-Clause OR Apache-2.0 OR MIT
privateHelp you make Rust code more accident-proof. Macros to enable other crates to export macros (either declarative/by example/using…12BSD-2-Clause OR Apache-2.0 OR MIT
si-security-audit-roomPLATO Security Audit Room — automated security auditing as a Rust engine block12MIT
restrictedPrevent consumers of your Rust macros from accidents. Enable crates to export private-like types, traits and functions that are…12BSD-2-Clause OR Apache-2.0 OR MIT