Portfolio concentration
48%
Top three share
Shows whether the organization is driven by one breakout repo or several visible projects.
Breadth
27 repos
Visible snapshot
2 repositories updated in the last 90 days.
Leading language
Python
Portfolio mix
Python (9), Go (3), C# (3)
Average size
79
Stars per repository
Useful for distinguishing one flagship-heavy publisher from a repeatable portfolio.
48%
of the visible star count comes from this organization's top three repositories.
79
stars per repository in this same snapshot.
Python
is the most common language here, with 2 repositories updated in the last 90 days.
Why this rank
This organization stands out because its public portfolio is relatively balanced across 27 repositories.
Organization pages work best when you separate portfolio breadth from flagship concentration. In SensePost's case, the visible top three repositories account for about 48% of total stars in this snapshot, which helps explain whether the organization is known for one breakout project or for a broader repeatable portfolio.
The dominant language mix here is Python (9), Go (3), C# (3). That makes this page useful not just for popularity checks, but also for seeing what technical shape an organization's public ecosystem actually has.
| # | Repository | Language | Stars |
|---|---|---|---|
| 1 | sensepost/pipetap A Windows Named Pipe Multi-tool / Proxy | C++ | 375 |
| 2 | sensepost/impersonate A windows token impersonation tool | Python | 329 |
| 3 | sensepost/susinternals psexecsvc - a python implementation of PSExec's native service implementation | Python | 314 |
| 4 | sensepost/wiresocks A sock, with a wire, so you can tunnel all you desire. | Shell | 300 |
| 5 | sensepost/InvokeADCheck InvokeADCheck is a PowerShell module designed to evaluate the security of Active Directory environments. | PowerShell | 125 |
| 6 | sensepost/mydumbedr | C | 123 |
| 7 | sensepost/mail-in-the-middle | Python | 109 |
| 8 | sensepost/offensive-rpc Offensive RPC PoC | C++ | 91 |
| 9 | sensepost/goLAPS Retrieve LAPS passwords from a domain. The tools is inspired in pyLAPS. | Go | 89 |
| 10 | sensepost/shellnot Pseudo-shell for RCE scenarios: tunnels commands via /tmp sockets to a local daemon, keeps context, no bind or reverse shell needed. | C | 48 |
| 11 | sensepost/sockstlsproxy | C# | 41 |
| 12 | sensepost/CVE-2025-64446 A scanner for the FortiNet vulnerability CVE-2025-64446 | Python | 32 |
| 13 | sensepost/steampipe-plugin-projectdiscovery A steampipe plugin to query projectdiscovery.io tools. | Go | 28 |
| 14 | sensepost/depscanner Detect public repository dependencies in the GitHub repositories with an orphan required library. | Python | 24 |
| 15 | sensepost/cipherchecks visually see issues with supported cipher suites | Python | 19 |
| 16 | sensepost/dresscode Scan websites CSP policies and visualise their vunlnerabilities from a dashboard | Python | 13 |
| 17 | sensepost/DotNetHookerToolkit | C# | 11 |
| 18 | sensepost/capchan Solving CAPTCHA with Image Classification | Python | 10 |
| 19 | sensepost/berate_radius Alpine hostapd-mana based RADIUS server | Shell | 10 |
| 20 | sensepost/wpswag Create an OpenAPI/Swagger spec from a WordPress REST entry point. | Python | 8 |
| 21 | sensepost/gopostille A X509 certificate chain cloning tool. | Go | 7 |
| 22 | sensepost/file-read-experiments A few short scripts to look at the performance of various file read strategies. | Rust | 6 |
| 23 | sensepost/ctf-challenges A collection of CTF challenges | CSS | 4 |
| 24 | sensepost/sensecon-2021-discord-bot Discord Bot used for the SenseCon 2021 Challenges: https://sensepost.com/blog/2021/sensecon-2021-wargames-edition/ | TypeScript | 3 |
| 25 | sensepost/arbitrary-object-instantiation A PHP, Arbitrary Object Instantiation Lab | PHP | 2 |
| 26 | sensepost/memunpin memunpin | JavaScript | 1 |
| 27 | sensepost/beacon-pipe-frame-proxy A toy, C# Cobalt Strike Beacon TCP to Named Pipe Frame Proxy | C# | 1 |
Total stars are useful as a discovery signal, but they do not tell you whether a team maintains every repository equally. Pair this page with release cadence, maintainer activity, and the flagship concentration shown above before making adoption decisions.
For broader background on GitStar's ranking logic and editorial guidance, see Methodology & Editorial Standards.