Network
2026-08-31
Python
★ 16
NetSentinel is a comprehensive network management tool designed for discovering devices, diagnosing connectivity issues, and monitoring network health. It features rogue device detection, detailed device inventory, bandwidth monitoring, a root cause correlator, and automated reporting capabilities, all while ensuring complete data privacy with a fully local, open-source architecture. With its extensive functionality, NetSentinel serves as a powerful aide for network administrators and users seeking to enhance both security and reliability in their network environments.
2026-08-31
C#
★ 17
Reecon is a lightweight network reconnaissance tool designed for early-stage network enumeration and information gathering. It features manual suggestions for various enumeration techniques, including HTTP/S and SMB, and operates as a standalone application with built-in components of the .NET Framework. Currently in development, it is not recommended for production use, and future enhancements are planned for broader functionality, such as improved DNS querying and service detection capabilities.
2026-08-30
Python
★ 104
Phantom is a multi-platform HTTP(S) reverse shell server and client implemented in Python 3, designed for securely establishing remote connections over HTTP or HTTPS. It features automatic certificate generation for HTTPS, bundled dependencies for seamless execution on Linux and Windows, and provides a user-friendly shell script for rapid certificate creation. The tool is tailored for penetration testing and remote administration scenarios, allowing quick setup and deployment for secure command execution.
2026-08-30
Python
★ 95
Simple-Async-Port-Scanner is a Python 3-based asynchronous TCP port scanner that utilizes the asyncio framework to efficiently connect to multiple ports on specified IP addresses within a user-defined timeout. It features a straightforward command-line interface for scanning specified ports, supports both IP addresses and domain names, and can filter results to display only open ports. This tool is particularly notable for its speed, capable of scanning the first 1000 TCP ports on a target in under two seconds, while maintaining minimal dependencies.
2026-08-30
HTML
★ 278
TorNet is a tool that automates IP address rotation through the Tor network, providing users with enhanced anonymity during internet browsing or application usage. It allows for configurable settings such as rotation intervals and the number of IP changes, and offers both command-line and Python API interfaces for integration and automation. Notable features include the ability to run indefinitely, check current IP addresses, and fix missing dependencies automatically.
2026-08-30
HTML
★ 55
AQW-Sequence Weaver is a bioinformatics-inspired toolkit designed to visualize and extract patterns from network telemetry specifically for AQW private server research. It enables users to map packet transactions, identify variable fields through heuristic analysis, and interactively explore session flows, while also supporting export to standard formats and multilingual interfaces. Notably, it offers a protocol diff engine for comparing captures across versions and a community research log for collaborative annotation of packet sequences.
2026-08-29
C++
★ 15
Spyglass is a packet capture tool designed to run within the Minecraft: Bedrock client, providing visibility into every packet sent and received by the client, along with details on decoding failures. It facilitates debugging for server software and proxies by presenting a structured overlay that displays packet details, error information, and hex data, allowing users to filter, search, and analyze communication with ease. Notable features include an interactive packet list, detailed breakdowns of failed packets, various data export options, and customizable filtering capabilities.
2026-08-27
Shell
★ 32
Claude Guard is a dual-channel architecture tool for managing Claude Code versions and startup strategies, ensuring strict auditing and version control for the official Claude channel while allowing independent updates via the CC Switch channel. Notable features include comprehensive lifecycle policies, detailed security checks before launching the client, and a dry-run guardian for ongoing monitoring without consuming user tokens or resources.
2026-08-27
★ 21
Network Analyzer is a comprehensive network scanning tool designed to help users monitor Wi-Fi connections, evaluate network security, and troubleshoot performance issues across home and office environments. It features detailed analysis of connected devices, real-time internet speed metrics, various network tools for performance and security assessments, and full IPv6 support. The tool also provides insights into Wi-Fi signal quality, channel usage, and the ability to discover local services on the network.
2026-08-27
Visual Basic .NET
★ 24
The PPS MH8A Transmitter is an Arduino-based tool designed to decode and transmit data packets from wireless air integration systems used in scuba diving. Its primary use case is to allow divers to monitor air pressure and related metrics by creating custom data packets that can be displayed on a computer or device. Notable features include a Windows standalone encoder for packet creation and forthcoming support for a receiver and additional encoding and decoding functionalities.
2026-08-27
C
★ 48
SLEEPWALKER is a passive backdoor tool designed for offensive security tasks, featuring a 64-bit Windows DLL that impersonates `dpapi.dll` and loads into ESET's Management Agent. It utilizes a proprietary command language interpreted through a 23-opcode bytecode system, allowing for various operations including data transmission and remote execution of shellcode upon receiving a specific trigger packet. Notably, the tool includes a Python controller for compiling and encrypting commands, alongside a configurable architecture enabling advanced covert command execution and behavior customization.
2026-08-27
JavaScript
★ 10
ObuscatedBOT is a multi-functional Telegram bot designed for performing instant network scans and providing security insights, aimed at ethical hackers and security enthusiasts. Key features include real-time alerts for suspicious activity, comprehensive vulnerability reports, and a user-friendly interface within the Telegram platform, facilitating easy navigation and interaction.
2026-08-26
★ 15
Acunetix Premium Web Scanner - Practical Windows release with complete modules and an easy first launch.
2026-08-26
Rust
★ 61
Fluere is a comprehensive network monitoring and analysis tool that captures network packets in pcap format and converts them into NetFlow data, enabling users to analyze traffic dynamics effectively. It supports both live and offline data capture across multiple platforms (Windows, macOS, Linux) and features a Terminal User Interface (TUI) for real-time feedback during live captures. Notable functionalities include integration with AWS Traffic Mirroring, active firewall implementation using plugins, and customizable command-line arguments for enhanced user experience.
2026-08-26
Python
★ 231
Project Eyes On is a multi-threaded reconnaissance tool designed for the global scanning and identification of open IP cameras by leveraging both web dorking and directory scraping techniques. Notable features include support for multiple search engines, anti-rate limiting, path probing to locate hidden streams, and interactive TUI for user-friendly operation. This tool aims to serve educational and security auditing purposes but highlights the importance of device security for camera owners.
2026-08-26
Python
★ 12
Ingram-Pro is an enhanced network camera vulnerability scanner that builds upon the original Ingram framework, providing extensive coverage of over 40 proof of concept (POC) exploits for CVEs from 2017 to 2024, alongside brand-specific weak-password detection for more than 15 camera brands. Key features include authenticated and unauthenticated remote code execution (RCE), high concurrency scanning using gevent, and the ability to capture live snapshots from vulnerable devices. The tool is designed for authorized security assessments and facilitates rapid vulnerability detection across large IP ranges.
2026-08-26
Python
★ 244
Deep Focus is a high-performance asynchronous network reconnaissance tool designed for security researchers and network administrators to discover and fingerprint services across IP ranges. It features intelligent probing of common network services, detailed authentication detection, and structured export of actionable intelligence, all while managing system resources to prevent overheating on passively-cooled devices. Its notable capabilities include comprehensive scanning for services like HTTP, FTP, SSH, and more, along with robust thermal management to ensure optimal performance.
2026-08-26
HTML
★ 13
PageZero is a JavaScript-based browser exploitation and command-and-control (C2) framework that integrates features from both Evilginx and BeEF. It allows security professionals to deploy phishing attacks without the need for complex configurations, enabling live sessions to execute over 40 modules including credential theft, keylogging, and LAN scanning from a web admin panel. The tool is designed for authorized penetration testing and operates using a simple hook that grants persistent control over the victim's browser context.
2026-08-26
C#
★ 53
Atlas is a cross-platform network execution and security assessment toolkit designed for authorized penetration testing, leveraging TrustedSec's Titanis protocol library. It features modular enumeration capabilities across multiple protocols such as SMB, Kerberos, WMI, and LDAP, allowing for credential checks, session enumeration, and remote command execution, along with a streamlined workflow similar to NetExec. Notable features include multi-host concurrency, comprehensive authentication methods, and detailed console output, facilitating efficient security assessments across diverse network environments.
2026-08-25
Python
★ 22
Network Scanner is an open-source security tool designed for vulnerability assessments and penetration testing, enhancing traditional methodologies with AI capabilities for intelligent analysis and detailed reporting. Tailored for a diverse user base including beginners and professionals, it offers functionalities such as automated reconnaissance, various scan types (subdomain, port, DNS), and an AI assistant for context-sensitive support. Notable features include report generation in PDF/HTML formats, an educational learning mode, and API readiness for seamless integration.
2026-08-25
C
★ 79
Blitzping is a high-speed, configurable packet-crafting utility designed for embedded devices, enabling the rapid generation of minimal TCP packets with optimized performance compared to existing tools like hping3 and nping. Its notable features include support for CIDR notations for source IPs, asynchronous raw socket configuration, multithreading, and efficient queuing to minimize system calls, making it particularly suitable for scenarios requiring high packet generation rates. Users can easily specify the number of threads and target IP/port combinations for efficient network testing and analysis.
2026-08-25
★ 139
Claude-AD is a plugin for Claude Code that streamlines the methodology for conducting Active Directory (AD) penetration tests. It organizes engagement phases such as setup, data collection, exploitation, and post-exploitation, while addressing environment-specific constraints and providing telemetry insights to enhance operational security. The tool integrates standard AD assessment techniques, orchestrating third-party tools like BloodHound CE and Impacket, ensuring effective execution of assessments aligned with compliance controls.
2026-08-24
Rust
★ 12
Ghidrust is a Rust-based reverse-engineering toolkit designed for analyzing PE and ELF binaries, offering multi-architecture support through Capstone-class listings and pseudo-C decompilation. Its key features include a headless CLI, a GUI interface, an experimental GPU decompilation capability for enhanced performance, and integrated network analysis via Ghidnet for process attribution and IDS records. Ghidrust aims to improve upon Ghidra's analysis speed and output quality while maintaining a small, auditable core.
2026-08-24
Python
★ 12
Hackwifi is a modular Python-based Wi-Fi penetration testing toolkit designed for automating tasks such as network scanning, packet capturing, deauthentication attacks, and Wi-Fi password cracking. It facilitates the identification of target networks and the extraction of handshake packets for offline password cracking, while requiring a Linux environment and necessary tools like Aircrack-ng. The tool emphasizes ethical use, necessitating proper authorization before any testing.
2026-08-24
Python
★ 87
PwnRM is an advanced WinRM post-exploitation tool designed for conducting authorized security assessments in Windows Active Directory environments. It features an interactive PowerShell runspace, support for various authentication methods, stealthy payload delivery, and a built-in Active Directory triage engine, enabling users to perform a wide range of assessment tasks through a command-line interface as well as via a Python library. Notable functionalities include file transfer capabilities, remote command execution, and comprehensive AD enumeration and session management features.
2026-08-23
C++
★ 75
VanBus is an Arduino library designed for reading and writing packets on the VAN bus of Peugeot and Citroën vehicles, which communicates using a protocol similar to CAN bus. It supports ESP8266 and ESP32 platforms, facilitating interactions with comfort-related equipment in vehicles manufactured by PSA up until around 2009. Notable features include compatibility with various hardware setups and comprehensive schematics for implementation, ensuring ease of use for developers working on automotive applications.
2026-08-23
★ 11
The Cyber Security 101 repository provides comprehensive technical documentation for beginners engaged in the TryHackMe Cyber Security learning path. It includes structured notes, commands, and walkthroughs across 14 modules covering vital topics such as networking, cryptography, operating systems, offensive and defensive security, and career guidance, along with over 56 hands-on labs and essential cybersecurity tools and methodologies. This resource serves as a detailed study notebook, supporting learners in building foundational knowledge and skills in cybersecurity.
2026-08-22
JavaScript
★ 145
AEGIS is an OS-level monitoring tool designed to observe the activities of AI coding agents, tracking their processes, file accesses, and network interactions without requiring any hooks. Its key features include the ability to attribute actions to specific agent instances, maintain an evidence graph for auditing, and support multiple operating systems while ensuring no telemetry is transmitted off the local machine. Built with a robust monitoring engine, AEGIS provides extensive detection rules and anomaly scoring for enhanced visibility into agent behavior.
2026-08-22
Rust
★ 43
HSR-OWNER is a comprehensive reverse-engineering and modding toolkit specifically designed for Honkai: Star Rail on Windows, stripped of any illicit cheat features to maintain legitimacy. It provides functionalities to analyze game data, modify client behavior, and aid in updating through minimal manual intervention, with full support for integration with AI tools for automation. Key features include a runtime layer that adapts to game updates, in-depth client analysis capabilities, and a straightforward build process using the MSVC toolchain.
2026-08-22
★ 16
The "Python for Security Professionals" course equips learners with practical skills in Python programming specifically tailored to security tasks, ranging from language fundamentals to the development of security tools. It features hands-on labs that culminate in building applications like port scanners and log analyzers, all while emphasizing clean coding practices and error handling. This lab-driven, self-paced curriculum is suitable for beginners and progresses through advanced concepts, ensuring students learn to write maintainable security software effectively.
2026-08-22
Python
★ 11
CRIMENET is an open-source knowledge graph that documents relationships among criminal organizations globally, leveraging multi-language Wikipedia data through a sophisticated LLM pipeline. It features a comprehensive dataset with over 4,500 organizations and nearly 11,000 relationships, all traceable to specific Wikipedia revisions, allowing for in-depth queries about criminal networks and history via a natural language interface called Ask CRIMENET AI. This tool offers the ability to explore organizational connections, historical contexts, and activity periods while ensuring information integrity through auditable sourcing.
2026-08-21
Go
★ 38
Boggart is a low-interaction experimental honeypot designed for mimicking specific host behaviors to attract and analyze potential threats in a home lab environment. Its notable features include a customizable configuration via `config.yaml`, support for multiple open ports (including a honeypot, dashboard, and API service), and deployment capabilities using Docker. This tool serves primarily for educational and experimental purposes, providing insights into attacker behaviors without being intended for professional or industrial use.
2026-08-21
Python
★ 11
NetWatch is a local-first visibility tool designed for IT admins and small security teams to monitor and assess changes within their authorized local networks. This tool provides a dashboard for asset discovery, TCP service exposure review, and maintaining context around significant changes, while emphasizing the importance of operating within authorized boundaries. Notable features include a repeatable workflow for local asset awareness, integration with Docker for easy deployment, and a focus on defensive visibility rather than exploitation.
2026-08-21
C#
★ 671
MikuSB is an open-source server emulator for a specific dungeon anime game, designed to enable local gameplay and testing by mimicking server functionalities. It features distinct components including `SdkServer` for HTTP API responses, `GameServer` for TCP connections, and an optional local proxy for domain redirection. Key capabilities include account management, player data handling, inventory, and weapon functionalities, while supporting research and educational purposes within a safe environment.
2026-08-21
Shell
★ 10
NEO-Radar is a lightweight network scanner designed for Linux and Termux, aimed at simplifying network scanning for users without extensive networking or cybersecurity knowledge. Its primary use case is to provide essential scanning functionalities akin to more complex tools like Nmap, while also including a command reference for learning purposes. Notable features include ease of installation via a single command, compatibility with mobile devices, and a focus on user-friendly operations, making it accessible for a wider audience.
2026-08-21
PHP
★ 49
The Ethical-Hacking repository provides a comprehensive step-by-step guide for learning cybersecurity and ethical hacking using Kali Linux. It covers foundational knowledge in networking and Linux commands, introduces tools like Nmap and Metasploit, and offers practice platforms for hands-on experience. Notable features include recommended resources, structured learning paths, and additional guidance on specialized areas like web application security and certifications.
2026-08-21
Python
★ 157
The wifi-deauther tool is a Python-based application that automates deauthentication attacks to help users understand 802.11 management frame injection. Primarily intended for testing on networks with proper authorization, it allows users to select a wireless interface and target access points for deauthentication. Notable features include support for Linux systems, the necessity for a wireless card with monitor mode, and the recommendation to use two wireless cards for optimal performance.
2026-08-20
Python
★ 89
Core Net Scanner is a cross-platform Python tool designed for network discovery and open port detection on local IPv4 subnets, applicable for both personal and organizational purposes. Notable features include LAN detection, custom scanning of specific IPs or ranges, HTTP service scanning, real-time traffic inspection, and a comprehensive logging system for detailed output. This tool is specifically intended for lawful use with explicit permission from network owners, ensuring ethical and responsible operation.
2026-08-20
HTML
★ 11
WireTapper is a tool designed for detecting and mapping nearby wireless signals, including Wi-Fi networks, Bluetooth devices, IoT devices, and CCTV cameras. Its notable features include Wi-Fi detection with detailed information, Bluetooth scanning, and signal visualization on a user-friendly map interface, enabling users to gather intelligence from their environment effectively. The tool is intended for responsible use in compliance with local privacy laws and regulations.
2026-08-20
HTML
★ 263
The Flipper Zero Evil Portal tool transforms a Wi-Fi development board into a phishing access point, serving a fake login screen to connected users. It captures user credentials and logs them onto the SD card, functioning as an educational demonstration for learning about Wi-Fi exploits and programming. Notable features include compatibility with both official and unleashed firmware, easy installation via pre-built app files, and customizable HTML login screens.
2026-08-19
Python
★ 10
GRID v2 is a comprehensive local intelligence dashboard that integrates multiple capabilities for OSINT, network reconnaissance, satellite tracking, IoT, and automation, all within a single conversational interface. Its notable features include a sophisticated layered memory engine that retains knowledge across sessions, enabling efficient recall and context management, alongside over 68 built-in tools for various operational tasks, making it a versatile solution for cybersecurity professionals. Unlike competing tools, GRID uniquely combines a wide range of functionalities while operating entirely offline, ensuring user autonomy and data security.
2026-08-19
Java
★ 11
Sonar Bypass is a Node.js script designed to circumvent the Sonar 2.1.x anti-bot verification mechanism for Minecraft servers by mimicking legitimate client behavior through raw socket communication. The tool operates without the need for captcha solving or manual interaction, handling various verification stages by copying the exact interactions of a real player, documented in its accompanying research files. Key features include automated packet responses and support for multiple server environments, making it effective for bypassing bot protections in targeted servers.
2026-08-18
Python
★ 50
SMBScan is a tool designed for enumerating file shares on internal networks, allowing users to scan either a single target or a range of targets. Notable features include the capability to identify potentially sensitive files, support for guest and domain user authentication, and tactics to minimize detection by security teams. Additionally, it generates log files for comprehensive output analysis following scans.
2026-08-18
★ 10
TikTok-SSL-Pinning-Bypass is a tool designed to intercept network traffic from the TikTok application on Android devices without the need for rooting. It supports Android versions 6.0 and above, and has been successfully tested using Mitmproxy in a non-root environment, specifically for the arm64-v8a architecture. Notable features include the ability to bypass SSL pinning, compatibility with real Android devices and AVD emulators, and the provision of a free patched APK that resolves specific login errors.
2026-08-18
Python
★ 1815
Getsploit is a tool designed for searching and downloading public exploits from the Vulners database, facilitating both online searches and fully offline operations via a local SQLite index. Its notable features include a comprehensive query capability across multiple exploit collections, local query support without internet connectivity, and robust JSON and tab-separated output formats, all while maintaining data privacy and integrity. The tool is compatible with Python 3.11 and above, ensuring reliable performance across various platforms.
2026-08-18
Lua
★ 3418
nmap-vulners is a set of Nmap scripts designed to enhance network vulnerability assessments by converting service scan results into a detailed list of known Common Vulnerabilities and Exposures (CVEs) along with their respective CVSS scores and exploits. Notable features include three independent scripts that can perform various vulnerability lookups—one leveraging the public Vulners database, another utilizing the Vulners API for advanced scoring, and a regex-based script that identifies web software through HTTP headers. This tool aims to streamline the process of gathering security-related information during Nmap scans, improving the effectiveness of vulnerability management.
2026-08-17
HTML
★ 181
BomberCat is an advanced security tool designed for auditing banking terminals and NFC technology, integrating both NFC and magnetic stripe functionalities for comprehensive access control and identification analysis. It supports features such as card emulation, read/write capabilities, and MagSpoof for magnetic stripe interactions, all while being compatible with popular programming frameworks like Arduino and CircuitPython. Additionally, it is equipped with WiFi connectivity for remote testing and supports a wide range of RF protocols, making it a versatile solution for security professionals.
2026-08-17
Kotlin
★ 33
ZeroDroid is a comprehensive Android hardware security toolkit designed to transform smartphones into portable RF labs, network analyzers, and security auditing tools, featuring 29 specialized utilities. Its primary use case includes analyzing various radio frequencies and sensors, as well as conducting detailed network assessments. Notable features include the ability to access WiFi, Bluetooth, NFC, GPS, and other device sensors, all presented through a terminal-hacker user interface.
2026-08-17
JavaScript
★ 87
The Apple Continuity Reverse Engineering Toolkit is designed for analyzing Apple’s wireless ecosystem services, including AirDrop and Handoff, primarily for security research and vulnerability assessment. It includes various tools for monitoring processes and accessing keychain items, requiring potential modifications to macOS' System Integrity Protection for full functionality. Notable features include `process_recon` for system log scanning and `keychain_access` for monitoring keychain interactions.
2026-08-17
Swift
★ 18
The "Apple Wi-Fi Password Sharing" tool provides a reverse-engineered implementation of Apple's Wi-Fi Password Sharing protocol for macOS, enabling cross-device sharing of Wi-Fi passwords via Bluetooth Low Energy (BLE). It includes functionalities for both grantor and requestor roles, allowing a device to share or request a Wi-Fi password, although it requires specific security settings and additional setups for the requestor role due to macOS restrictions. Notably, the project serves primarily educational purposes and remains experimental, with an emphasis on its untested nature and the need for additional configuration when operating on macOS.
2026-08-16
Python
★ 42
OSINT-Nexus is an open-source intelligence platform designed for security researchers, penetration testers, and intelligence analysts, integrating passive reconnaissance tools with AI-driven analysis. Notable features include advanced graph analytics, interactive visualizations, and AI-powered insights using Google Gemini, along with robust reporting capabilities in multiple formats. This cross-platform tool supports Windows and Linux, making it a versatile resource for gathering actionable intelligence from publicly available data.
2026-08-15
★ 114
SOCMIntelligence is a comprehensive Social Media Intelligence (SOCMINT) tool designed for monitoring and analyzing social networks to identify profiles, relationships, and organizations, enabling the construction of contextual diagrams relevant to various intelligence cycles. Key features include support for multiple social media platforms, advanced search capabilities, and a variety of analytics and monitoring tools. This tool facilitates the extraction of valuable information from social media exchanges, making it essential for intelligence gathering and network analysis.
2026-08-15
Python
★ 58
SYNINT: Agentic OSINT & Intelligence Framework – Modular, Stealthy, API-Free, Multi-Agent System for Automated Intelligence Collection & Analysis.
2026-08-15
HTML
★ 13
AryterLink is a self-hosted, browser-based remote control panel designed for Termux on Android devices, enabling users to manage their smartphones from any browser globally. It offers capabilities such as SMS management, call handling, access to contacts, device controls (like flashlight and screen brightness), real-time battery stats, audio recording, and secure terminal shell access, all while ensuring data protection through robust security measures. Notably, it operates without the need for root access or third-party servers, relying solely on Python and direct interactions with the device's hardware via the Termux:API.
2026-08-13
HTML
★ 60
Bjorn Manager is a desktop application designed to facilitate the discovery and management of Bjorn devices across various network interfaces, including LAN, USB, and Bluetooth. It allows users to install, update, and control these devices from a single user interface, featuring multilingual support, smart device naming, and real-time terminal logs for installations. Key functionalities include auto-discovery, SSH installation capabilities, and configurable settings, making it a comprehensive tool for managing Bjorn devices efficiently.
2026-08-13
Python
★ 264
PyPCAPKit is an open-source Python library designed for comprehensive network packet parsing and analysis, enabling users to extract, construct, and analyze PCAP files with detailed insights into packet structures. Its notable features include support for various extraction engines, a user-friendly interface, and a modular design that encompasses interface management, protocol handling, and utility functions, making it a robust tool for network analysis. While it operates with moderate extraction speed compared to some competitors, its comprehensiveness and extensibility position it as a powerful option for network specialists.
2026-08-13
★ 154
Awesome AI in Cybersecurity is a curated repository that provides an extensive collection of resources focused on the application of artificial intelligence in various cybersecurity domains. It categorizes AI uses within cybersecurity into prediction, prevention, detection, response, and monitoring, while also detailing tools for penetration testing, malware analysis, and security for AI SaaS environments. Notable features include automated penetration testing frameworks, and support for network protocol verification, enhancing traditional security measures with AI-driven insights and efficiencies.
2026-08-12
Python
★ 123
findcdn is a Python-based tool designed to scan domains to identify the Content Distribution Network (CDN) they utilize. Its primary use case includes providing actionable insights regarding CDN usage for security assessments or operational purposes, with features that allow output to files, invocation as a module, and customizable processing options such as threading and user-agent specification. The tool supports multiple domains and offers verbose output for enhanced monitoring and analysis.
2026-08-12
C
★ 921
GhostESP is an open-source wireless research platform that transforms an affordable ESP32 board into a multifunctional wireless tool with a user-friendly touchscreen interface. Its primary use case includes advanced wireless monitoring, firmware updates, and network analysis, featuring capabilities such as on-device firmware management, a cloud app store, and robust scripting support via GhostScript. Notable enhancements in version 2.x include expanded NFC functionalities, efficient Wi-Fi attack and monitoring tools, and improved user interface performance with a focus on accessibility and multitasking.
2026-08-11
★ 30
SagarBiswas-MultiHAT is a GitHub repository showcasing a range of cybersecurity and web development projects by Sagar Biswas, a Computer Science and Engineering student. The repository includes open-source tools focused on web application security and ethical hacking, featuring a system called "PromptVault" that enables users to securely manage AI prompts with features like PIN protection, organizational categories, and optional cloud synchronization.
2026-08-11
Go
★ 33
Reconner is a self-hosted reconnaissance tool designed for bug bounty hunters and security researchers, facilitating comprehensive web and network scanning from a single dashboard. It offers a full pipeline of discovery, vulnerability assessment, and continuous monitoring without relying on third-party services, ensuring that all data remains on the user's system. Notable features include real-time logging, native context-aware DAST for multiple vulnerabilities, and seamless integration with Nuclei for enhanced scanning capabilities.
2026-08-11
Python
★ 28
The Nmap Scanning Tool is an interactive wrapper for Nmap that simplifies the execution of common scans and enhances readability of results. It supports multiple scan profiles, including SYN, aggressive, and vulnerability scans, along with an optional output filter to highlight open ports. The tool requires Python and Nmap to be installed on the user's system and aids in providing helpful error messages regarding user permissions and installation checks.
2026-08-11
Java
★ 13
OpenLPX is an anti-packet exploit tool designed for Minecraft servers, focusing on protecting against crash packet exploits, specifically NettyCrasher attacks, without requiring any external dependencies. Key features include a smooth packet limiter with a configurable violation system, advanced packet logging capabilities for analyzing potential exploits, and compatibility with Minecraft mods like Printer and Schematica, ensuring minimal disruption to player experiences. The tool provides detailed configuration options to tailor protection measures while allowing for real-time alerts and server management commands.
2026-08-11
★ 42
This repository offers a curated collection of over 70 free cybersecurity books organized by domain and difficulty, facilitating self-paced learning in various cybersecurity disciplines. Notable features include a structured learning roadmap progressing from beginner to advanced levels, an emphasis on community maintenance for up-to-date resources, and a direct link to an extensive Google Drive library containing the materials.
2026-08-11
C
★ 14
Slave I is an offensive-security firmware specifically designed for the M5Stack Tab5, facilitating wireless research through an integrated toolkit for Wi-Fi, BLE, and 802.15.4 recon and attack capabilities. Notable features include a touch UI, a physical-keyboard workflow, extensive scanning and capturing functions, and a desktop emulator for development. It allows users to implement advanced wireless attacks while emphasizing ethical usage and compliance with legal standards.
2026-08-11
Shell
★ 127
CamSniff is an automated reconnaissance toolkit designed for discovering and profiling IP cameras and network video streams within local networks. It employs both active and passive scanning methods to generate structured and auditable datasets, while enabling users to acquire snapshots and streams from various protocols, including RTSP and ONVIF. Notable features include its mode-aware scanning capabilities, multi-protocol support, and the ability to produce comprehensive output formats such as structured JSON files and logs.
2026-08-10
DART is a test documentation and reporting tool designed for penetration testing in isolated environments, facilitating quick setup and minimal configuration. It enables teams to document tests and capture artifacts efficiently, generating comprehensive reports in Microsoft Word format while applying NISPOM-friendly markings. The tool is intended for use on trusted networks and is versatile across various operating systems, including Windows, Linux, and Docker.
2026-08-10
Rust
★ 63
Sherlock-rs is a Rust-based tool designed to hunt down social media accounts by a specified username across over 400 social networks. It provides features such as outputting results to text, CSV, or Excel files, supports proxy usage, customizable site analysis, and extensive debugging options, making it ideal for users needing comprehensive username availability checks across multiple platforms.
2026-08-09
Go
★ 40
Nixis is an AI agent firewall designed to enforce real-time governance for AI coding agents like Claude Code, by intercepting and evaluating tool calls against security policies before execution. Its notable features include blocking unauthorized actions such as sensitive file access and destructive commands, along with a user-friendly installation process and an embedded real-time governance dashboard for monitoring and policy testing. This ensures external enforcement of security policies without relying on the AI model's inherent trustworthiness.
2026-08-09
JavaScript
★ 58
SafeIP is a lightweight web application designed for network security validation, which checks the user's current IP location against a manually selected country to identify potential security risks before accessing sensitive services online. Notable features include real-time IP detection, safety status indicators, a quick link manager with client-side validation, and persistent settings using LocalStorage, ensuring a user-friendly experience while maintaining a focus on security.
2026-08-09
Go
★ 15
inform-inspect is a tool designed for inspecting and debugging Ubiquiti Unifi Inform packets, which is essential for analyzing communication with Unifi SDN Controllers. Its notable features include support for both AES-128-CBC and AES-128-GCM encryption methods, a two-step decoding process for raw byte streams, and the ability to output decoded data in JSON format or as a hexdump. The tool requires access to incoming inform packets and the respective encryption keys stored in the controller’s MongoDB for effective analysis.
2026-08-09
Python
★ 14
The Ubisoft Game Service (GS) is a software development kit that facilitated online features such as user authentication, matchmaking, in-game chat, and CD key validation for Ubisoft games released between 2000 and 2005. It integrates with a dedicated network protocol for game server communication and includes components for both web service operations and specific game server implementations, exemplified by its integration with 'Heroes of Might and Magic V'. Notably, the project comes with a structured directory for common services, game-specific implementations, and testing scripts, requiring Python 3.11 or higher for execution.
2026-08-08
C#
★ 19
McProtoNet is a high-performance .NET library designed for interfacing with the Minecraft Java Edition protocol, currently under active development. Its primary use case includes creating custom clients and tools for Minecraft, featuring an asynchronous API, support for multiple Minecraft versions (1.12.2 to 1.21.4), and capabilities for parsing Named Binary Tag (NBT) data. Additionally, it allows connections to cracked servers, enhancing its versatility for developers working with Minecraft protocol interactions.
2026-08-08
C
★ 162
Radmin VPN for Linux allows users to run the Radmin VPN client via Wine on Linux systems, enabling VPN network access without the overhead of a Windows virtual machine. The tool employs a custom driver that bridges Wine to a Linux TAP device, overcoming compatibility issues and ensuring a fully functional VPN experience. Notable features include AI-assisted reverse engineering for protocol implementation, AppImage distribution for simplicity, and command-line options for flexible usage scenarios.
2026-08-08
Python
★ 18
WiFi Jammer is an advanced educational penetration testing tool designed for WiFi security assessments, utilizing Python for 802.11 frame injection. It facilitates multiple attack types, including deauthentication, disassociation, and various flooding attacks, while offering rich interfaces through CLI, TUI, and GUI across multiple platforms. Notable features include channel hopping automation, PMKID and WPA handshake capture, and an architectural design grounded in SOLID principles.
2026-08-07
Go
★ 46
`knockr` is a port-knocking utility written in Go that simplifies the access control mechanism of opening blocked ports through predefined sequences. It supports multiple protocols and offers features such as delay configuration, timeout settings, and the ability to verify port status after knocking, all while allowing users to save frequently used sequences as profiles in a secure configuration file. This tool is cross-platform and can be easily integrated into scripts for automated processes.
2026-08-07
Shell
★ 17
The Sthenos Embedded Toolkit is a comprehensive solution for building static debugging and analysis tools tailored for embedded systems across over 50 architectures. Notable features include support for both musl and glibc toolchains, a range of available tools such as strace and tcpdump, and the capability to compile specific tools for designated architectures using a Docker-based build environment. This toolkit enables streamlined development and troubleshooting for embedded systems, ensuring reliable performance in diverse operating environments.
2026-08-06
Go
★ 199
gonids is a Go library designed to parse and create Intrusion Detection System (IDS) rules for engines like Snort and Suricata. Its primary use case involves assisting security professionals in managing and optimizing IDS rules, featuring capabilities to parse rules, create DNS rules, and optimize HTTP rules for cross-platform compatibility. Notable features include error handling during rule parsing, support for flexible rule creation, and an optimization function for adapting rules between IDS engines.
2026-08-06
★ 56
ATLAS is a comprehensive open dataset that maps all known data center locations globally, encompassing 18,110 facilities across 116 countries and 4,181 operators. Primarily designed for research and publication purposes, the tool allows users to explore data centers with GPS coordinates and provides access to a live map interface. Notable features include extensive categorization of data centers by country and operator, making it a valuable resource for understanding the infrastructure of the internet.
2026-08-06
★ 58
ODINT (Observatory for Digital Infrastructure & Network Transparency) is an independent, decentralized platform focused on auditing publicly accessible government digital infrastructure through open-source intelligence (OSINT) methodologies. It facilitates collaborative research, encouraging contributions of domain data, investigative leads, and methodologies to enhance accountability and expose vulnerabilities in governmental digital systems. Notable features include an organized repository structure for cyber reconnaissance and a dedicated Recon Suite powering its operations with various OSINT tools.
2026-08-05
Python
★ 63
Secuditor Lite is a Python-based diagnostic security tool designed for Windows environments, facilitating endpoint security assessments through a user-friendly graphical interface. Its primary use case involves identifying vulnerabilities, suspicious activities, and misconfigurations across systems and networks, while providing features like SSL/TLS interception analysis, operational security evaluations, and the generation of structured audit reports. The tool supports comprehensive security checks covering system hardware, network configurations, shared folder permissions, and a variety of security controls.
2026-08-05
Python
★ 19
The Noimosiny Python SDK is a client library designed to interact with the Noimosiny API, which specializes in OSINT and reverse-lookups. Its primary use case includes performing reverse email lookups to retrieve associated social media profiles and online records while managing account credit balances for API usage. Notable features include session management via a context manager, simplified method calls for API interactions, and built-in rate limiting for request handling.
2026-08-05
JavaScript
★ 61
The Cybersecurity Handbook is an interactive, open-source knowledge base tailored for cybersecurity professionals, students, and enthusiasts. It offers over 400 comprehensive notes on diverse topics, enhanced by an interactive knowledge graph, full-text search capabilities, and a user-friendly interface that supports dark/light modes and is mobile-friendly. This community-driven resource keeps pace with the rapidly evolving cybersecurity landscape, providing practical insights into real-world threats and defense strategies without any paywalls.
2026-08-04
Python
★ 48
Hermes Katana is a defense-in-depth security tool designed for AI agents, providing mechanisms for tracking input provenance, scanning content for prompt injections, and enforcing YAML policies before tool execution. Notable features include configurable human-in-the-loop escalation, purpose-trained injection classifiers, and a tamper-evident audit trail for decision-making, all aimed at enhancing the security posture of AI applications. This tool is particularly useful for developers looking to safeguard AI systems from potential vulnerabilities and malicious inputs.
2026-08-04
Rust
★ 211
Huginn Net is a passive traffic fingerprinting tool that analyzes TCP, HTTP, and TLS protocols without active probing, providing insights into operating systems, applications, network infrastructure, and client capabilities. Built in pure Rust, it utilizes open-source specifications such as p0f for TCP and JA4 for TLS, allowing for community-driven signature databases. Notable features include support for HTTP/1 and HTTP/2 fingerprinting, OS type and version identification, and detailed analysis of TLS handshakes and TCP signatures.
2026-08-04
TypeScript
★ 3596
Anything Analyzer is a comprehensive traffic capturing and analysis tool designed for various sources, including web applications, desktop apps, and command-line interfaces. Its primary use case revolves around automatic protocol reverse engineering and security auditing, leveraging AI to streamline the analysis process. Notable features include support for multiple capture environments, unified session management, two-phase intelligent analysis, and the ability to generate detailed reports on encryption and API interactions.
2026-08-03
apk-mitm is a command-line tool designed to automate the process of modifying Android APK files for HTTPS traffic inspection. It disassembles the APK, adjusts its Network Security Configuration to accept user-added certificates, disables certificate pinning, and reassembles and signs the modified APK, all without requiring a rooted device. Key features include support for Android App Bundles, streamlined installation via npm, and compatibility with various proxy tools for traffic analysis.
2026-08-03
EGRESSION is a cybersecurity tool designed to evaluate the effectiveness of egress and Data Loss Prevention (DLP) controls by testing the upload of sensitive data from a network. It systematically attempts to connect and transmit sensitive files using various methods, categorized into four testing levels, which provide insights on potential vulnerabilities. Noteworthy features include its self-contained nature, multiple testing techniques ranging from FTP to DNS, and plans for future enhancements such as additional egress methods.
2026-08-03
Good-MITM is a rule-based Man-in-the-Middle (MITM) attack engine designed for rewriting, redirecting, and rejecting HTTP(S) requests and responses. It features a YAML-based rule description language for flexible matching and content manipulation, including domain-specific interception, JavaScript support for dynamic interventions, and the ability to install user-generated root certificates for secure communication. The tool is capable of functionally acting as a transparent proxy while supporting both HTTP and HTTPS multiplexing on a single port.
2026-08-03
mitmrouter is a Bash script designed to facilitate the setup of a Linux router specifically tailored for IoT device traffic analysis and SSL man-in-the-middle (MITM) attacks. It automates the configuration of network interfaces and services such as hostapd, dnsmasq, and nftables, allowing users to effectively manage both wired and wireless connections for traffic interception. Notable features include the ability to toggle LAN and Wi-Fi interfaces, refresh configurations without complete teardown, and custom configuration through a structured setup file.
2026-08-03
Sandcat is a Docker and dev container framework designed to securely run AI agents in a controlled environment, offering features such as network traffic regulation through mitmproxy and secret management via transparent substitution. Its primary use case is for developers who require a secure development shell with minimal configuration overhead, facilitated by a bash CLI for project initialization and customizable proxy settings. Notable features include a comprehensive traffic routing system, controlled access lists, and reusable configuration templates that streamline the setup of development environments in IDEs like VS Code.
2026-08-03
SpeedTestDashboard is a network monitoring tool that integrates with pfSense and the SpeedTest.net CLI to provide a visual representation of network performance metrics through a Dockerized Grafana dashboard. It simplifies deployment with Docker Compose and requires no additional configuration, allowing users to quickly set up and access performance data via a web interface. Notable features include out-of-the-box functionality and customizable Grafana credentials.
2026-08-03
aws_public_ips is a Ruby tool designed to retrieve all public IP addresses (both IPv4 and IPv6) associated with various AWS services within an account. It functions as both a library and command-line interface (CLI), supporting services such as EC2, RDS, and ELB, while offering flexible output formatting options and configuration via AWS SDK. Notable features include support for both Classic and VPC structures, integration with Docker for environment variable-based execution, and an easy installation process via RubyGems.
2026-08-03
COD-MW-2019-DNN provides deep neural network models specifically designed for detecting enemies and heads in the game Call of Duty: Modern Warfare 2019. The tool utilizes image segmentation techniques on 200x200 pixel blocks from the player's screen, enabling functions such as real-time enemy detection and precise localization of enemy heads in a 10x10 grid, significantly enhancing gameplay awareness. Notable features include self-training capabilities that refine model accuracy through continuous image data collection from streams, customizable training datasets, and GPU acceleration for improved performance.
2026-08-03
Fuzzowski is a sophisticated network protocol fuzzer designed to facilitate the fuzzing process for various communication protocols. It enables users to define packet structures, identify potential vulnerabilities, and automate testing with features such as session management, response validation, and an interactive console for monitoring suspect cases. Noteworthy attributes include its reliance on Python 3, a variety of integrated protocols like LPD and IPP, and advanced data generation capabilities allowing for refined and targeted fuzzing strategies.
2026-08-03
Kerbrute is a Python script designed for performing brute-force attacks on Kerberos authentication using the Impacket library. It accepts user and password lists to enumerate valid username/password pairs, valid usernames, and those that do not require pre-authentication, while generating a list of valid credentials and retrieved TGTs. Notable features include multithreading support, customizable output options, and the ability to handle input files for users and passwords.
2026-08-03
Modern Honey Network (MHN) is a centralized server solution designed for the management and data collection of honeypots, enabling rapid deployment of sensors and immediate data collection for analysis via a web interface. It supports various honeypot technologies, including Snort, Cowrie, Dionaea, and Glastopf, while providing features such as an HTTP API for honeypots to register and send intrusion detection logs, alongside tools for administrators to monitor attacks and manage detection rules. The tool is in the process of being updated to support Python 3 on Ubuntu 20.04, with stability maintained for earlier versions.
2026-08-03
DALL-E 2 - Pytorch is an implementation of OpenAI's advanced text-to-image synthesis model, DALL-E 2, built using the PyTorch framework. Its primary use case is generating images from natural language descriptions using a diffusion prior network, enhancing the variety and quality of generated images by adding an autoregressive component. Notable features include support for unconditional image generation, verified decoder functionality, and collaborative community contributions to enable scaling and optimization.
2026-08-03
IoT Inspector is a client tool designed for monitoring and analyzing Internet of Things (IoT) traffic across various operating systems. It features an internal SQLite database to collect network statistics and provides scripts for data anonymization. Key functionalities include real-time packet analysis, device inspection, and user-friendly installation scripts for different platforms.
2026-08-03
NetWorm is a Python-based network worm designed to spread across local networks and provide attackers control over compromised machines. It serves as a template for developing similar malware, featuring capabilities like SSH brute-forcing and propagation via USB devices. This tool is not fully functional but offers a starting point for educational use, emphasizing the need for conversion into executables for deployment on target machines.
2026-08-03
The Python portpicker module facilitates the discovery of unused network ports on a host, primarily for testing and development purposes. Its key feature is the `pick_unused_port()` function, which can be utilized directly from Python code or the command line, and supports an optional port server for coordinated port assignment across multiple processes, minimizing the risk of port conflicts. Users are advised to implement a port server for robust scenarios, especially in automated testing environments.
2026-08-03
Database of known signatures identified using the mechanism in "Passive Taxonomy of Wifi Clients using MLME Frame Contents" from research.google.com/pubs/pub45429.html
2026-08-03
The Audio Super Resolution tool implements a neural network model aimed at enhancing the resolution of audio signals by converting low-resolution audio patches into high-resolution counterparts. Utilizing TensorFlow and Keras, it features a preparation pipeline for dataset generation, including functionalities for patch extraction and pre-processing parameters such as scaling and audio sampling rates, essential for training and validating the model effectively.
2026-08-03
DeepVariant is a deep learning-based variant caller that processes aligned genomic reads to produce pileup image tensors, which are then classified using a convolutional neural network and output as VCF or gVCF files. Its primary use case is germline variant calling in diploid organisms, capable of handling diverse input data sources such as Illumina, PacBio, and Oxford Nanopore technologies. Notable features include support for hybrid datasets, pangenome-aware calling, and the extension to trio variant calling through the DeepTrio module, facilitating nuanced analysis of genomic variants in family-based studies.
2026-08-03
Impacket is a Python library that provides programmatic access to low-level networking protocols, facilitating packet construction and parsing for protocols like SMB1-3 and MSRPC. Its primary use case is within security and penetration testing, enabling users to interact with complex protocol hierarchies and implement authentication methods, including NTLM and Kerberos. Noteworthy features include support for various networking protocols (Ethernet, IP, TCP, etc.), complete MSRPC functionality, and example tools demonstrating its capabilities.
2026-08-03
Ludwig is a declarative deep learning framework designed for training, fine-tuning, and deploying AI models across various applications, including large language models (LLMs), multimodal models, and tabular data processing. Its notable features include a YAML configuration syntax for streamlined model definitions, advanced PEFT adapters for fine-tuning, and capabilities for distributed deployment, allowing for efficient model training with minimal boilerplate code.
2026-08-03
NetProbe is a network scanning tool designed to identify devices on a specified IP address or subnet by sending ARP requests. It effectively displays detailed information about each discovered device, including IP addresses, MAC addresses, manufacturers, and models, and offers features such as live tracking, saving scan results, and filtering options for manufacturers and IP ranges.
2026-08-03
Nogotofail is a network security testing tool that enables developers and security researchers to identify and remediate vulnerabilities in TLS/SSL connections and sensitive cleartext traffic within applications and devices. It features a man-in-the-middle (MiTM) approach for testing various SSL-related issues, including certificate verification flaws and stripping vulnerabilities. This tool is designed to operate on Linux systems and requires Python 2.7 and specific dependencies for its execution.
2026-08-03
Tunna is a proactive tool designed to tunnel TCP connections over HTTP, particularly effective in bypassing network restrictions in fully firewalled environments. Its primary use case includes establishing a local proxy to facilitate access to remote services, with the ability to manipulate data exchange transparently over standard web ports (80/443). Notable features include customizable local and remote port configurations, verbose logging options, and upstream proxy support with authentication capabilities.
2026-08-03
Ultimate Vocal Remover GUI (UVR) is an advanced application designed for vocal isolation and removal from audio files, utilizing state-of-the-art source separation models. Its primary use case caters to musicians and audio engineers seeking clean instrumental tracks for remixing or sampling, while notable features include ease of installation with all required dependencies bundled and support for multiple audio processing backends.
2026-08-03
The Universal Radio Hacker (URH) is a comprehensive tool designed for investigating wireless protocols, particularly those utilizing Software Defined Radios (SDRs). It features automated modulation detection, customizable decoding for complex encodings, and both manual and automatic protocol field assignment capabilities, making it ideal for reverse-engineering and analyzing wireless communications. Additionally, URH includes fuzzing components for stateless protocols and a simulation environment to facilitate stateful attacks.
2026-08-03
ODIN is a Python-based tool designed for automating intelligence gathering, asset discovery, and reporting within network environments. Its primary use case is for red teams to conduct reconnaissance by collecting and managing data on network assets, including domains and IP addresses, while offering notable features such as the ability to generate HTML reports and create Neo4j graph databases for visualizing discovered relationships among assets.
2026-08-03
PyTorch is a Python library that facilitates tensor computation with robust GPU acceleration and enables the development of deep neural networks through a tape-based automatic differentiation system. It serves as both a powerful alternative to NumPy for performance on GPUs and as a flexible platform for deep learning research, featuring a range of utilities such as automatic differentiation, model optimization via TorchScript, and enhanced data handling with multiprocessing capabilities. Notable features include seamless integration with Python packages and a focus on imperative programming for dynamic neural network construction.
2026-08-03
Websploit is a high-level Man-In-The-Middle (MITM) framework designed for performing various network attacks and exploits. It features a modular architecture that allows users to select and configure different modules, such as ARP spoofing, through an intuitive command-line interface. Notable features include easy installation methods, a comprehensive menu for module navigation, and configurable options for each attack module.
2026-08-03
WebSploit is a versatile penetration testing framework designed for exploiting vulnerabilities in web applications and network services. It features a comprehensive suite of attacks including Autopwn integration with Metasploit, browser exploitation, various Denial of Service techniques, and utilities for scanning and identifying weaknesses in web servers and applications. Notable capabilities include USB infection attacks and multiple Wi-Fi targeted attacks, making it a powerful tool for security professionals.
2026-08-03
hcpy is a beta Python interface designed for interacting with Bosch-Siemens Home Connect appliances over a local network. Its primary use case is to enable secure local control and communication via MQTT for these devices, leveraging established cryptographic protocols like TLS PSK. Notable features include a streamlined OAuth authentication process for accessing device data and real-time message transformation from the Home Connect API into MQTT JSON messages for easier integration into smart home ecosystems.
2026-08-03
Neurite is a neural networks toolbox designed specifically for medical image analysis using PyTorch, offering tools for tensor operations, stateful layers, and prebuilt architectures for various spatial dimensions. Its primary use case includes enhancing medical imaging workflows through functionalities such as smoothing, resampling, and plotting tensor data. Notable features include reusable modules and flexible model architectures that accommodate 1D, 2D, and 3D data representations.
2026-08-03
WiresharkMCP is an integration toolkit that facilitates natural language interactions with network analysis by bridging Wireshark and the Machine Control Protocol (MCP) through Claude Desktop. It features a Python MCP server for communication and command-line packet analysis, along with a Lua extension for real-time packet dissection, custom protocol definitions, and automated interface management. This combination allows for efficient network monitoring and enhanced usability in packet analysis tasks.
2026-08-03
Canarytokens is a network activity tracking tool designed to alert users of unauthorized actions within their environments. It provides customizable token deployment options, supports various configurations for alerting mechanisms, and enhances security monitoring by leveraging email and webhook notifications. Key features include alert throttling, detailed configuration settings, and the ability to integrate with AWS and other external services for improved management and responsiveness.
2026-08-03
FFW (Fuzzing For Worms) is an advanced network fuzzer that intercepts and modifies valid network communication to identify vulnerabilities in network servers and services across various protocols. It supports both open-source applications with feedback-driven fuzzing capabilities via honggfuzz, and operates without the need for source code modifications or protocol reversing, ensuring a rapid setup and reasonable performance. Notably, FFW can also fuzz network clients and offers a streamlined Docker image for easy deployment.
2026-08-03
FakeNet-NG 3.5 is a dynamic network analysis tool tailored for malware analysts and penetration testers, enabling them to intercept and redirect network traffic while simulating legitimate services. It features a configurable interception engine and a modular framework that facilitates testing specific application functionalities and capturing malware signatures. Built on the foundation of the original Fakenet tool, it is designed for modern Windows and Linux environments, making it suitable for secure malware analysis setups.
2026-08-03
NetworkX is a Python package designed for the creation, manipulation, and analysis of complex networks. Its primary use case is in graphical representations of networks, facilitating operations such as finding the shortest path between nodes. Notable features include support for weighted edges and a comprehensive suite of algorithms and data structures for network analysis, as well as extensive documentation and community support.
2026-08-03
The WiFi Pineapple Pager Payload Library is a community-driven repository containing DuckyScript™ and Bash payloads specifically designed for the Hak5 WiFi Pineapple Pager. Its primary use case is to enable users to develop and share payloads for security testing and penetration testing, while notable features include a collaborative environment for submission and modification of payloads, along with a leaderboard for highlighting popular contributions.
2026-08-03
Bane is a cybersecurity tool designed for advanced malware analysis and dynamic analysis of malicious executables. Its primary use case lies in analyzing the behavior of malware samples in a controlled environment, enabling security experts to dissect and understand threat mechanisms. Notable features include extensive logging capabilities, customizable analysis settings, and support for various file types, facilitating comprehensive incident response and threat intelligence.
2026-08-03
PowerShell
★ 300
The PowerShell Reverse TCP tool facilitates bidirectional communication between a client and a remote host, enabling the remote host to execute commands on the client system. Designed primarily for educational purposes, it features multiple shell implementations using Invoke-Expression and process pipes, and includes a methodology for script obfuscation to evade detection by security systems. Users can customize IP addresses and port numbers, while future updates aim to enhance shell optimization further.
2026-08-03
RaspyJack is a portable offensive toolkit designed for use with Raspberry Pi devices and primarily aimed at authorized security testing and research. It features an LCD-driven handheld interface, dual-display support, and includes 231 payloads across multiple categories, along with a WebUI for remote control, various WiFi attack utilities, and exfiltration methods, making it versatile for penetration testing and educational purposes. Additionally, it supports a range of hardware configurations and offers an integrated Payload IDE for custom development.
2026-08-03
Amateur-SIGINT is a tool designed for blind reverse engineering of digital wireless protocols, enabling users to analyze and reconstruct signals without prior knowledge of the transmitter. Its primary use case is for enthusiasts engaged in signals intelligence, and it includes detailed documentation of both successful methods and challenges encountered during the process. Notable features include a comprehensive tutorial format and a focus on transparent experimentation, capturing errors alongside successes.
2026-08-03
★ 3527
The Awesome Connected Things Security Resources repository provides a comprehensive collection of security knowledge pertinent to IoT, embedded systems, industrial control systems, and automotive technologies. Its primary use case is to serve as a centralized reference for security practices and tools, featuring over 900 resources that cover various aspects of security, including hardware hacking, firmware analysis, and wireless protocols. Notable features include detailed sections on specific attack methodologies, categorized resources for easy navigation, and community engagement via platforms like Telegram and Discord.
2026-08-03
The "Awesome Computer Networking Resources" repository offers a curated list of invaluable resources for designing, implementing, and operating computer networks, catering to various aspects such as routing, switching, VPNs, and network management. Notable features include sections on network design guides, implementation tools, and operational best practices, as well as insights into network automation and monitoring tools. This repository serves as a comprehensive reference for networking professionals seeking to enhance their knowledge and skills in the field.
2026-08-03
Awesome-Selfhosted is a comprehensive catalog of free and open-source software solutions designed for self-hosting, enabling users to manage and run applications on their own servers rather than relying on third-party SaaS providers. The repository encompasses a wide variety of software categories, including analytics, content management systems, and communication tools, providing a structured and easily navigable resource for developers and system administrators seeking to implement self-hosting solutions. Notable features include an organized table of contents, contributions from the community, and ongoing checks for project maintenance and link validity.
2026-08-03
ESP32-BlueJammer is a tool designed to disrupt 2.4GHz wireless communications using an ESP32 and nRF24 modules, effectively functioning as a Bluetooth, WiFi, and RC jammer. It is primarily used for controlled disruption and security testing, featuring a range of over 30 meters and customizable hardware setups for optimal performance. The project also provides schematics for creating your own PCB that integrates the ESP32 and RF module capabilities.
2026-08-03
The Google Wifi API repository provides a collection of discovered API endpoints designed for interacting with Google Wifi Routers and OnHub devices. Its primary use case is to enable developers to retrieve status information, manage connected devices, and configure network settings programmatically. Notable features include endpoints for WAN configuration, device status retrieval, and the generation of diagnostic reports, facilitating advanced network management capabilities.
2026-08-03
The MITM-cheatsheet repository provides a comprehensive guide for penetration testers and security professionals on various Man In The Middle (MITM) attacks and associated protective measures. It catalogs a range of attack methods such as ARP spoofing, DHCP spoofing, and SSL stripping, along with the tools used to execute these attacks and strategies for defense. Notable features include detailed descriptions of each attack, their complexity and relevance, as well as tips and techniques for both offensive and defensive cybersecurity practices.
2026-08-03
The WiFi Pineapple Pager library provides a centralized resource for managing payloads, themes, and ringtones for the WiFi Pineapple Pager, a tool designed for mobile penetration testing and WiFi network manipulation. Its notable features include support for DuckyScript™ for dynamic attacks, customizable themes, and ringtones to enhance user interaction, as well as a robust payload management system. This repository facilitates direct contributions and engagement within the cybersecurity community by linking to specialized subrepositories for additional functionalities.
2026-08-03
Flax is a flexible, high-performance neural network library designed for use with the JAX framework, enabling researchers to create, inspect, debug, and analyze neural networks with ease. The recent Flax NNX API introduces Python reference semantics for better model expression and mutability, helping to foster innovation in neural network training methodologies. Key features include a comprehensive neural network API that supports various layers and operations, underscoring its ability to adapt to diverse research needs.
2026-08-03
This repository provides an Ansible playbook designed for deploying a self-hosted Matrix server using Docker, enabling secure and decentralized communication. Its primary use case is to facilitate users in running their own Matrix homeserver, allowing for personalized user IDs and the ability to host multiple services in containers for consistent and maintainable setups. Notable features include automated installation and maintenance tasks, extensive documentation, and support for various distros and architectures.
2026-08-03
react-native-google-nearby-messages is an asynchronous wrapper for the Google Nearby Messages API specifically designed for React Native applications on both Android and iOS platforms. Its primary use case involves facilitating the discovery and communication of nearby devices using various mediums such as Bluetooth and audio, while supporting features like custom discovery modes, awaitable native invocations, and React hooks for enhanced usability. Additionally, it serves as a practical example of integrating Swift within a React Native native module.
2026-08-03
SpeedTest by OpenSpeedTest™ is a lightweight, open-source HTML5 network performance estimation tool designed to measure bandwidth directly from web browsers without the need for client-side plugins or third-party libraries. It operates using only standard Web APIs, delivering high performance through a simple, secure architecture that consists of static files. Notably, it supports a wide range of devices and browsers from IE10 onwards, and enhances network analysis capabilities with its OpenPacketLoss tool for packet loss detection.
2026-08-03
The default-gateway tool is a Node.js package designed to retrieve the default gateway IP address of a machine for both IPv4 and IPv6, utilizing system commands specific to the operating system. Notable features include both asynchronous and synchronous methods to access gateway details, including the interface name and the IP version of the gateway, while ensuring error handling for unexpected conditions. This utility is essential for applications that require network configuration information for precise routing decisions.
2026-08-03
cfn-diagram is a command-line interface (CLI) tool designed to visualize CloudFormation, SAM, and CDK templates by generating diagrams in both Draw.io and HTML formats. Notable features include the ability to filter resource types, support for JSON and YAML templates, and options to customize output file names, making it suitable for effectively visualizing and managing cloud infrastructure architecture.
2026-08-03
cfn-diagram is a CLI tool designed to visualize AWS CloudFormation, SAM, and CDK templates as diagrams in various formats, including draw.io and HTML. It offers features like resource type filtering, CI mode for non-interactive execution, and supports both JSON and YAML templates, allowing users to customize their visualizations according to specific stacks or resource types.
2026-08-03
Nebula is a scalable, secure overlay networking tool designed for seamless connectivity among computers globally, operating on multiple platforms including Linux, Windows, and mobile devices. Its notable features include mutually authenticated peer-to-peer communication, user-defined security groups for traffic filtering, and the ability to function behind NATs through UDP hole punching. Built on the Noise Protocol Framework, it employs advanced encryption using ECDH key exchange and AES-256-GCM, making it suitable for creating secure, flexible network environments across diverse infrastructures.
2026-08-03
SimpleX Chat is a privacy-centric messaging platform designed to operate without user identifiers, ensuring complete anonymity and data protection. It utilizes double ratchet end-to-end encryption to secure messages and metadata while offering mobile applications for both Android and iOS, along with a command-line interface for desktop OS. Notable features include a TestFlight preview for iOS users, allowing early access to new functionalities, and extensive support for community contributions and translations.
2026-08-03
Tsunami is a versatile network security scanner designed to identify high severity vulnerabilities with high accuracy through its extensible plugin architecture. Its primary use case involves leveraging a wide array of plugins to enhance scanning capabilities, with all available plugins hosted separately. This tool provides a robust solution for organizations seeking to bolster their security posture by detecting vulnerabilities in their network infrastructure.
2026-08-03
WireMCP is a Model Context Protocol (MCP) server that enhances Large Language Models (LLMs) with real-time network traffic analysis through the capture and processing of live data using Wireshark's `tshark`. Its primary use cases include threat hunting, network diagnostics, and anomaly detection, with notable features such as live packet capture, conversation tracking, and threat intelligence checks against blacklist databases, all providing structured JSON outputs suitable for LLM analysis. Additionally, WireMCP enables detailed examination of PCAP files and the extraction of potential credentials, facilitating comprehensive security audits and forensic investigations.
2026-08-03
Blocky is a DNS proxy and ad-blocker for local networks, designed to enhance privacy, security, and performance. Key features include flexible blocking of DNS queries based on customizable allow/deny lists, advanced DNS resolution configurations for different client groups, and support for modern DNS protocols such as DoH and DoH3. Additionally, Blocky offers integration with monitoring tools like Prometheus and Grafana, along with a simple YAML-based configuration for easy management and backups.
2026-08-03
EADINLite is a master/slave network protocol designed for efficient, real-time communication in distributed control systems, particularly for aerospace applications like engine control. It features a command/response structure with a maximum payload size of 8 bytes, optimized for half-duplex serial communication over RS-485 networks, providing round-trip times as low as 943 microseconds at 4,000,000 baud. The protocol supports multiple node configurations without requiring time synchronization and is tailored for microcontrollers, with future implementations expected in FPGA or ASIC environments.
2026-08-03
ESP32Marauder is a comprehensive suite of WiFi and Bluetooth offensive and defensive tools tailored for the ESP32 platform. Its primary use case includes network security assessments and penetration testing, featuring a range of functionalities such as packet injection, sniffing, and network scanning. Notably, it offers an accessible setup for users and is designed for both beginners and experienced security professionals.
2026-08-03
The Unofficial OnHub Desktop Client is a tool designed for interfacing with Google Nest Wi-Fi routers, primarily enabling users to monitor real-time network traffic quantities. It is built using Qt and is currently undergoing a complete rewrite to improve maintainability and performance, with its functionality derived from reverse-engineering Google's private API. Notable features include a user-friendly interface and reliance on the Qt framework for cross-platform compatibility.
2026-08-03
High-rate Delay Tolerant Networking (HDTN) is a modular implementation of Delay Tolerant Networking that leverages modern hardware to significantly enhance data transfer rates and reduce latency in space networks. It maintains compatibility with existing DTN standards while introducing a newly defined data format and a parallel pipelined architecture capable of adapting to various processing elements, including specialized hardware accelerators. Notable features include its web-based telemetry command interface and support for multiple operating systems, facilitating efficient and scalable network operations in constrained environments.
2026-08-03
Hyperfox is a security auditing tool that functions as a transparent HTTP proxy to intercept and record HTTP and HTTPS traffic between clients and servers. Its notable features include the ability to store traffic data in an SQLite database, a user interface that can be accessed remotely, and SSL/TLS decryption capabilities through custom CA certificates. Hyperfox is ideal for security professionals conducting traffic analysis and debugging web applications.
2026-08-03
Hyprspace is a lightweight VPN solution built on IPFS and Libp2p, designed for creating truly distributed networks without the need for prior knowledge of node IP addresses. Its primary use case includes enabling seamless connections between devices behind NATs and firewalls, making it ideal for nomadic users and privacy advocates who require constant virtual IP addresses without manual port forwarding. Notable features include direct encrypted tunneling between nodes, allowing for resilient and efficient networking even in dynamic environments.
2026-08-03
The Mesh Network Communication System facilitates peer-to-peer communication among diverse network nodes, primarily designed for use with small satellites like cubesats and unmanned aerial systems (sUAS). Notable features include low latency data throughput, validated performance in dynamic environments, and a flexible architecture suitable for various data exchange applications.
2026-08-03
Netmaker is a tool designed for the automation of WireGuard VPN deployments, catering to both homelab and enterprise environments. Its primary use case includes the creation and management of WireGuard networks, remote access gateways, and mesh VPNs, while offering features such as an admin UI, OAuth integration, and private DNS. Notably, it supports cross-platform installations on Linux, Docker, Mac, and Windows, facilitating diverse deployment scenarios.
2026-08-03
OpenBTS is an open-source software toolkit that allows users to implement a GSM mobile network using software-defined radio components. Its primary use case is to provide a flexible platform for building and testing GSM networks, featuring support for SMS transmission, voice calls, and SIP protocols. Notable features include a comprehensive GSM stack, an integrated SMS server (smqueue), and modular architecture for easy customization of components and configurations.
2026-08-03
UDPX is a lightweight, single-packet UDP scanner written in Go, capable of discovering over 45 protocols with options for custom services. It operates across multiple platforms (Linux, Mac OS, Windows) and can scan entire /16 networks in approximately 20 seconds. Key features include customizable probes, JSONL output for results, and a concurrent connection setting to balance speed and stability.
2026-08-03
BruteShark is a Network Forensic Analysis Tool (NFAT) designed for deep processing and inspection of network traffic, primarily targeting PCAP files and live capturing from network interfaces. Its key functionalities include extracting and encoding usernames and passwords from various protocols, reconstructing TCP and UDP sessions, generating visual network maps, and extracting authentication hashes for brute force cracking. Available in both a GUI version for Windows and a command-line interface for Windows and Linux, BruteShark serves as an effective resource for security researchers and network administrators in identifying potential network vulnerabilities.
2026-08-03
SharpSecDump is a .NET tool that mimics the remote SAM and LSA Secrets dumping capabilities of impacket's secretsdump.py, enabling the extraction of credential data from registry hives on targeted machines, including local systems. Key features include support for using alternate credentials, concurrent enumeration of multiple hosts, and the ability to dump hashes from the local system while running under high-integrity contexts. It is designed for use strictly in authorized environments and does not currently support NTDS.dit parsing or dcsync functionality.
2026-08-03
Arkime is an open-source, large-scale network analysis and packet capture system designed to enhance security infrastructure by storing and indexing network traffic in standard PCAP format. Its primary use case is to provide fast, indexed access to captured packets via an intuitive web interface, while also supporting APIs for data consumption. Notable features include scalability to handle high traffic volumes, seamless integration with existing PCAP tools like Wireshark, and options for contextual intelligence and enhanced security measures.
2026-08-03
The ESP32 Wi-Fi Penetration Tool is a versatile framework designed for executing various Wi-Fi attacks on the ESP32 platform, facilitating functionalities such as PMKID and WPA/WPA2 handshake capturing, deauthentication, and denial-of-service attacks. It features a user-friendly web-based management interface for configuration, passive traffic sniffing, and the ability to format captured data into PCAP or HCCAPX formats, making it suitable for integration with tools like Hashcat. This tool's extensibility allows users to implement new attack methodologies easily, enhancing its utility in wireless security assessments.
2026-08-03
nDPI is an open-source library for deep packet inspection, enabling the identification and classification of network protocols through careful analysis of packet data. Its primary use case is to enhance network monitoring and security by providing detailed insights into traffic patterns, including the ability to add custom protocol dissectors. Notable features include support for multiple protocols, built-in testing capabilities, and extensive documentation to facilitate protocol additions.
2026-08-03
Nmap is a powerful network scanning tool primarily used for network discovery and security auditing. It provides features such as host discovery, port scanning, and service/version detection, making it essential for assessing the security posture of networked devices. Users can interact with it via command-line or utilize its graphical interface, Zenmap, for a more visual representation of scan results.
2026-08-03
revdgst is a collection of tools designed for analyzing and reverse engineering checksums specifically in short data packets, with a focus on software-defined radio (SDR) data transmission from sensor modules. Key features include the ability to reverse various checksum algorithms, such as 8-bit and 16-bit LFSR digests and simple checksum methods, while supporting multiple operating systems like Linux, MacOS, and Windows. The tools are implemented in portable C and require input files containing hexadecimal messages to perform analysis.
2026-08-03
RoomRelay is an open-source Windows application designed to stream live system audio or audio from specific applications to Sonos speakers over a local network. Its primary use case is to fill the gap in Sonos's capabilities by allowing users to stream audio from any Windows source, including browsers, games, and other media applications, while offering features like per-application audio selection, customizable settings for latency and quality, and built-in audio controls. Notable features include low-latency streaming modes, speaker discovery, and seamless integration with the Windows environment without reliance on external audio dependencies.
2026-08-03
SSH MITM is a penetration testing tool that enables security auditors to intercept and log SSH connections by modifying OpenSSH to function as a proxy. It captures plaintext passwords and session data while exploiting common user complacency regarding SSH key changes. Notable features include Docker support for easy deployment, full SFTP capabilities, and a specialized script for identifying potential SSH targets on a LAN through ARP spoofing.
2026-08-03
The AFL (American Fuzzy Lop) tool is a powerful open-source fuzzer designed for security testing by automatically generating a vast array of test cases to identify vulnerabilities in software. Its primary use case lies in discovering bugs in binaries by utilizing genetic algorithms to evolve test cases based on code coverage analysis. Notable features include the ability to perform instrumented fuzzing, support for various file formats, and real-time feedback on code paths, enhancing the effectiveness of vulnerability discovery.
2026-08-03
The HC-11 wireless modem emulator for the Flipper Zero serves to facilitate data transmission between a Flipper Zero device and a remote HC-11 RF UART module. It enables users to wirelessly send and receive serial data while supporting multiple radio channels, module addresses, and adjustable transmission power levels. Notable features include USB passthrough functionality, reliable operation in specific transmission modes, and real-time monitoring of serial traffic.
2026-08-03
Open Wireless Link (OWL) is an open-source implementation of the Apple Wireless Direct Link (AWDL) protocol designed for Linux and macOS, facilitating Apple AirDrop functionality on these platforms. It operates in user space, leveraging Linux's Netlink API to integrate with the networking stack and provide a virtual network interface for IPv6-capable applications. Notable features include support for wireless channel switching, required specifications for compatible Wi-Fi cards, and usability via command-line options for operation and logging.
2026-08-03
Rage Fuzzer is a protocol-unaware packet fuzzer and replayer designed for simplicity and speed, focusing on IP-based TCP and UDP traffic. Its key features include ease of use with minimal setup, deterministic fuzzing runs that can be reproduced using a seed, and a pre-defined collection of packets for common protocols, making it suitable for quick vulnerability assessments and network testing. The tool operates in a client-side context and supports basic command-line options for configuration during fuzzing sessions.
2026-08-03
SSHFS is a tool that enables users to mount remote filesystems over SFTP, facilitating seamless access to remote directories as if they were local. It supports various SSH options, offers the ability to bypass SSH for performance, and is widely integrated into major Linux distributions, making it highly accessible. While it has been in consistent production use, the project currently lacks active contributors and is maintained primarily to address critical issues.
2026-08-03
★ 14
Cybersec Notes is a comprehensive, expandable checklist aimed at individuals seeking to enhance their knowledge in various cybersecurity domains, including application, mobile, API, and network security. The tool features a structured outline of key topics and vulnerabilities, supplemented with resource links, while encouraging community contributions for continuous improvement and accuracy. Notable aspects include coverage of OWASP Top 10 vulnerabilities across multiple platforms and concepts related to DevSecOps.
2026-08-03
★ 11
The Jr Penetration Tester repository provides solutions and an answer key for the Penetration Tester learning path on TryHackMe, aimed at equipping users with essential skills for a career in penetration testing. It covers various critical topics, including web hacking, Burp Suite, network security, vulnerability research, and exploitation techniques using Metasploit. Notable features include comprehensive sections that guide learners through foundational concepts and practical applications in cybersecurity.
2026-08-03
★ 75
Road To Hacking is a comprehensive guide designed for enthusiasts of Ethical Hacking, providing an extensive overview of widely used tools for penetration testing and auditing. Notable features include detailed instructions on tools such as Nmap for vulnerability detection, Metasploit for exploitation, and Aircrack-ng for cracking WPA/WPA2-PSK, among many others. This resource emphasizes practical usage, ensuring users have foundational knowledge in Linux and terminal commands to effectively utilize the tools presented.
2026-08-03
★ 25
The Pentesting-Methodology repository provides a structured approach to penetration testing, encompassing networking fundamentals, reconnaissance, and analysis techniques. It includes tools for identifying web servers and technologies, brute-forcing subdomains, and performing directory enumeration, making it useful for security professionals looking to streamline their penetration testing workflows. Notable features include detailed networking information and integration with various reconnaissance tools such as Sublist3r and Amass.
2026-08-03
Jupyter Notebook
★ 35
SecOps-CLI Guides is a curated repository providing PDF command-line cheat sheets and how-to guides tailored for security professionals, facilitating offline reference for key cybersecurity tools and techniques. Notable topics include Metasploit, Nmap, SQLMap, and Active Directory attacks, making it a valuable resource for penetration testing and security operations. The repository invites contributions to expand its collection, enhancing its utility for the security community.
2026-08-03
Python
★ 30
MacOS-WPA-PSK is a proof-of-concept script that demonstrates how macOS stores the wireless network key in plaintext within NVRAM, rendering it accessible without root privileges. This tool highlights the risks associated with the management of sensitive credentials in macOS, serving as a reminder that users should be aware of the non-secure treatment of such information. The script operates using Python and has been tested across specific versions of macOS.
2026-08-03
Python
★ 78
HackingComm is a user-friendly penetration testing tool designed for individuals with limited terminal command knowledge. It simplifies common pentesting tasks on Kali Linux through a straightforward interface, allowing users to easily input required parameters while executing commands. Notable features include an installation script, guided prompts for user inputs, and reliance on Python for functionality, making it accessible for beginners in cybersecurity.
2026-08-03
Ruby
★ 245
Leprechaun is a penetration testing tool that facilitates the identification of valuable targets within an internal network by aggregating netstat results from multiple hosts. Its primary use case involves analyzing network traffic connections to uncover potential vulnerabilities and traffic patterns, and it features command-line options to specify output files, ports of interest, and IP address types. Notable features include the ability to output detailed connection statistics organized by server and traffic destination ports, enhancing visibility for security assessments.
2026-08-03
Shell
★ 537
swap_digger is a Bash script designed for automating the analysis of Linux swap space for post-exploitation and forensic purposes. It extracts sensitive information such as user credentials, web form credentials, and WiFi keys from the swap area, and offers extensive options for customization, including extended searches and optional logging. The tool is especially useful in penetration testing scenarios and can operate on local or mounted swap devices.
2026-08-03
Python
★ 17
Ant is a post-exploitation tool designed to automate the deployment of tunnels and port forwarding over a specified network topology using configuration files. Key features include support for WMI, WinRM, and SMB protocols, along with four main commands—deploy, desinfect, redeploy, and probe—that facilitate topology management. The tool also includes validation for configuration file accuracy and allows comments for better user guidance.
2026-08-03
Python
★ 459
PivotSuite is a network pivoting toolkit designed for Red Teamers and penetration testers, enabling the movement within a compromised network using either forward or reverse connections. Notable features include support for TCP tunneling, SOCKS5 proxies, and various network enumeration functions, all without requiring administrative access on the compromised host. The tool operates independently of installation requirements, utilizing only Python's standard libraries, making it versatile across different platforms and environments.
2026-08-03
Python
★ 809
PyExfil is a Python-based tool designed for stress testing the detection capabilities of security systems against various exfiltration and communication techniques employed by threat actors. It allows users to deploy multiple experimental and stable exfiltration methods, such as DNS queries, HTTP cookies, and ICMP packets, enabling organizations to evaluate their defenses. Notable features include a wide array of techniques for data exfiltration and communication, with the ability to configure and run tests across different operating systems.
2026-08-03
Shell
★ 14
Rogue is a bash script that automates penetration testing workflows by integrating tools such as Nmap, Metasploit, and John the Ripper. It streamlines the scanning, exploiting, and reporting phases of pentesting, providing a modular and customizable experience for security professionals. Notable features include automated scans, exploitation configuration, credential harvesting, and structured report generation, all initiated with a simple input of a target IP address.
2026-08-03
Python
★ 13
FinalThreatFeed is a high-performance automated threat intelligence aggregation engine designed for continuous collection and fusion of global open-source intelligence. Its architecture supports asynchronous operations to enhance data throughput, while features such as intelligent cleaning, deduplication, and full lifecycle management ensure high-quality, relevant threat data. The tool also offers flexible extension configurations and advanced IOC identification, making it suitable for enterprise security defense systems.
2026-08-03
Python
★ 104
sigwood is a local-first command-line tool designed for threat hunting by analyzing existing log files from sources such as Zeek, DNS servers, and syslogs. Its primary use case is to detect anomalies, including beaconing, suspicious DNS queries, and unusual activity within a user’s network, without requiring any external deployment or configuration. Notable features include its simple installation process, a suite of detectors for various events, and the ability to run directly on logs without needing to send data to the cloud.
2026-08-03
JavaScript
★ 849
SPR (Secure Programmable Router) provides a secure networking solution that facilitates adaptive, micro-segmented network management for WiFi devices, remote VPN access, and wired systems. Key features include multi-PSK support with WPA3, policy-based routing for enhanced security, advanced DNS capabilities with per-device rules, and a user-friendly interface accessible via a React-based web app and iOS application. This tool is optimized for a wide range of Linux systems, leveraging Docker for interoperability and offering comprehensive observability features such as traffic insights and health monitoring.
2026-08-03
Python
★ 37
Yoda is a passive RF monitoring tool designed for home environments, capable of tracking Bluetooth (BLE) devices and WiFi access points and clients in real time. It features a terminal user interface (TUI) that displays live data, push notifications for device and connection events via ntfy.sh, and advanced jamming detection using an asymmetric exponentially weighted moving average (EWMA). Users benefit from the ability to customize alert topics and monitor device stability, making it an effective solution for managing home network security and device presence.
2026-08-03
Go
★ 564
DNS-collector is a lightweight tool designed for capturing and intelligently processing DNS queries and responses from various DNS servers, including BIND and PowerDNS. Its primary use case is to filter and enrich DNS data by removing noise such as health checks and spam before forwarding the refined data to monitoring systems or databases. Notable features include support for multiple input sources via the DNStap protocol or live network capture, flexible output formats to various logging and monitoring systems, and enhanced data processing capabilities for improved operational insights.
2026-08-03
Python
★ 23
Scapy UsbBluetooth is a Python library that integrates Bluetooth communication capabilities into Scapy, enabling it to interact with Bluetooth controllers through UsbBluetooth. Its primary use case is for network and device analysis, providing functionality to list devices, establish sockets, and send command packets, like HCI commands. Notable features include easy installation via pip and support for specific platform requirements, facilitating access on Windows and Linux systems.
2026-08-03
JavaScript
★ 43
The Malicious IP Address List repository provides a continuously updated list of IP addresses associated with malicious activities, such as DDoS attacks and misuse through VPNs or proxies. Its primary use case is for threat identification, allowing users to recognize potentially harmful sources without directly blocking them at the firewall level. Notable features include regular updates every two hours, availability in both TXT and CSV formats, and a focus on long-term reputation blacklisting.
2026-08-03
Python
★ 157
PCAP Hunter is an AI-enhanced threat hunting workbench designed for SOC analysts, enabling seamless integration of manual packet analysis with automated security monitoring. It features a user-centric interface for geographic flow aggregation, linked visual analysis, and a durable analysis workflow, while also providing optional Large Language Model assistance for enriched analysis. The tool supports visualization and investigation of packet captures through advanced filtering and responsive dashboard capabilities, ensuring comprehensive threat detection and evidence management.
2026-08-03
★ 26
The "Awesome Malware Analysis" repository is a curated collection of malware analysis tools and resources, aimed at facilitating comprehensive malware research and detection. It features a wide array of categories, including malware collections, detection tools, honeypots, and online scanners, providing users with diverse methodologies for malware investigation and analysis. Notable features include organization by specific use cases, such as memory forensics and deobfuscation, which enhance the accessibility of relevant resources for researchers and analysts in the cybersecurity domain.
2026-08-03
Python
★ 184
IOC Finder is a tool designed to extract indicators of compromise (IOCs) such as URLs and email addresses from textual data. Its primary use case is enhancing threat detection and analysis by parsing relevant observables from various text sources. Notable features include interactive documentation and a focus on community support for ongoing improvements.
2026-08-03
JavaScript
★ 42
PacketSnitch is a network analysis tool that processes packet capture (.pcap) files, providing searchable, protocol-aware insights for security professionals and researchers. Its key features include an Electron-based frontend for interactive browsing and filtering of network traffic, GeoIP integration for location visualization, payload analysis, and support for various protocols. Additionally, it offers AI-generated summaries and a plugin engine for extended functionalities.
2026-08-03
C
★ 35
procscope is an eBPF-based process tracer for Linux that enables real-time observation of process behavior, including lifecycle events, file activity, and network connections, with minimal overhead and configuration. It is primarily designed for security researchers and incident responders to trace malware behavior and audit container workloads without the complexities of traditional monitoring tools like EDR. Notable features include support for various process-related events, file operations, and privilege transitions, allowing users to effectively monitor and analyze runtime activity.
2026-08-03
★ 17
The 'suspicious_IPs' repository provides a compiled list of potentially malicious or harmful IP addresses. Its primary use case is for cybersecurity professionals to enhance threat detection and mitigation measures by identifying and blocking traffic from these suspicious IPs. Notable features include a straightforward format that allows for easy integration into firewall rules and intrusion detection systems.
2026-08-03
Assembly
★ 40
The dism-exe/bn6f tool is a disassembly of the MegaMan Battle Network 6: Cybeast Falzar game, designed for developers to analyze and modify the game’s code and assets. Its primary use case is for ROM hacking and community-driven modding projects. The repository includes the ROM build with a specific SHA1 hash, facilitating easy setup and contributions from other developers.
2026-08-03
TypeScript
★ 11
DarkRide is a self-hosted, AI-native workbench tailored for mobile reverse engineering, primarily focusing on Android devices. It provides comprehensive features such as live device control, APK analysis, HTTPS traffic capture, and Frida instrumentation, all accessible through a unified web interface with a TypeScript automation engine and plugin system for extensibility. Additionally, it includes advanced functionalities like an AI agent for tool interaction, session history management, and a robust proxy pool for enhanced pentesting capabilities.
2026-08-03
HTML
★ 19
The J5 EV Dashboard is a self-hosted telematics solution designed for Jaecoo J5 EV vehicles, providing users with comprehensive insights into vehicle performance metrics such as battery status, range, efficiency, and charging sessions. This mobile-first Progressive Web App (PWA) allows users to access real-time data from their own car while also offering features like a trip planner and an interactive EV charger map. Notably, it guarantees high accuracy in charge-cost reporting, closely matching users' receipts, and is designed to operate exclusively with the owner's vehicle data.
2026-08-03
TypeScript
★ 1965
@jshookmcp/jshook is an MCP server designed for AI agents, offering over 600 tools across 34 domains primarily for JavaScript analysis and security research. Its notable features include AI-driven deobfuscation and crypto detection, full-stack browser automation with anti-detection capabilities, network interception, and a dynamic reverse engineering toolchain. The tool allows for efficient session and resource management, enabling multiple clients to share a single daemon instance while maintaining isolated sessions.
2026-08-03
Python
★ 41
reverseloom is a tool designed to automate the extraction of data from websites protected by advanced bot detection systems, such as Akamai Bot Manager. It employs a unique approach by interacting directly with the browser using a headless environment to reverse engineer the site's protocol, enabling it to generate standalone crawlers that function without a browser. Notable features include complete exposure of the website's DOM, network traffic, and JavaScript debugger, along with the ability to create fully operational, browser-free crawlers that are capable of executing tasks autonomously.
2026-08-03
★ 541
The TryHackMeRoadmap repository provides a curated list of over 350 free TryHackMe rooms, categorized by skill level and topic, aimed at enhancing the learning experience for cybersecurity enthusiasts. Its notable features include a structured approach that covers various areas such as network security and web exploitation, alongside self-contained rooms with practical exercises to facilitate hands-on learning. Regular updates ensure relevance and accessibility to new resources in the evolving cybersecurity landscape.
2026-08-03
★ 26
AIDA64 Network Audit scans local and remote computers to collect hardware, software and network configuration data, generating inventory reports. It supports scheduled scans, queries, export to CSV, HTML, XML, and integrates with Active Directory for asset tracking.
2026-08-03
HTML
★ 151
Torii Gateway is a middleware solution designed to provide researchers with persistent, authenticated access to advanced inference pathways of large language models (LLMs) while bypassing tiered consumption limits imposed by commercial APIs. Its notable features include protocol reflection to mimic enterprise-tier traffic, token frame rebalancing to adjust apparent consumption rates, and session entropy injection for neutralizing identifiable session fingerprints, facilitating a seamless connection to multiple inference providers without altering client-side code. This tool serves as a crucial resource for overcoming restrictions that hinder research and experimentation with frontier LLM capabilities.
2026-08-03
Python
★ 17
TryHackMeWriteups is a comprehensive repository that curates free TryHackMe rooms, providing organized resources for cybersecurity enthusiasts to learn and practice various skills. Notable features include categorized rooms across diverse topics, detailed notes and summaries, step-by-step writeups for Capture The Flag challenges, and continuous updates, making it an ideal starting point for beginners in cybersecurity and ethical hacking.
2026-08-03
Python
★ 43
EtherBlob Explorer is a tool designed for the extraction and analysis of blob files from the Ethereum blockchain, leveraging the Etherscan API. It allows users to search for various human-generated data types across multiple Ethereum networks, using diverse methods such as embedded file detection, ASCII string extraction, and entropy-based searches. Notable features include support for five Ethereum test networks, user-defined search parameters, and the ability to log search results for further analysis.
2026-08-03
Python
★ 17
A tool for fuzzing for ports that allow outgoing connections
2026-08-03
JavaScript
★ 652
Caronte is a network flow analysis tool designed for Capture The Flag (CTF) events, specifically for attack/defence scenarios. It reassembles TCP packets from pcap files, allowing users to define custom patterns for analysis through regex or protocol-specific rules, with results visualizable via a web application and accessible through a REST API. Key features include quick deployment via Docker, an intuitive GUI for configuration and rule management, and advanced analytics capabilities such as timeline visualizations and detailed connection filtering.
2026-08-03
Go
★ 71
CTFProxy is a comprehensive Capture The Flag (CTF) infrastructure solution designed to facilitate the deployment and management of CTF challenges with a Zero-Trust Network model. It utilizes a single command for container orchestration, integrates CI for continuous deployment, and supports detailed access control policies through Starlark configuration. Notable features include multi-container management, centralized logging, secure SSO authentication, and the ability to run challenges in both Docker and Kubernetes environments.
2026-08-03
Python
★ 50
Hack-Tool is a comprehensive all-in-one hacking tool tailored for cybersecurity professionals, providing a suite of utilities for various hacking tasks, including information gathering, web attacks, and post-exploitation analysis. Notably, the tool enhances functionality with recent updates that incorporate new features such as reverse engineering tools, remote administration tools (RAT), and advanced web crawling capabilities. Operating on Linux-based systems like Kali Linux and Parrot OS, it supports a wide range of offensive security operations.
2026-08-03
Shell
★ 392
TryHackMe is a free cybersecurity learning path designed to advance users from novice to expert through a range of practical exercises, introductory Capture The Flag (CTF) challenges, and educational modules covering topics like OpenVPN, Linux fundamentals, web scanning, and Metasploit. This resource is suitable for both newcomers to the field and those looking to enhance their skills, and it culminates in a comprehensive foundation in cybersecurity, preparing users to address more complex challenges. Notable features include diverse content formats, hands-on labs, and accessible learning materials to foster practical experience in cybersecurity practices.
2026-08-03
Vue
★ 922
CTFever is a comprehensive toolkit designed for Capture The Flag (CTF) participants, offering a variety of tools to assist in solving challenges. Its notable features include a wide range of utilities such as encoding/decoding formats (Base64, ROT13), cryptography tools (Caesar cipher, Vigenère cipher), and data analysis options (CRC checks, IP geolocation). This suite aims to streamline the CTF experience by providing essential resources in a user-friendly manner.
2026-08-03
Python
★ 79226
HackingTool is an AI-guided, all-in-one security testing toolkit designed for authorized penetration testing, providing access to 215 curated tools across 21 categories such as reconnaissance, web security, and forensics. Its standout feature is the AI layer that translates user queries in plain English into the appropriate tool and command, catering to a diverse audience including penetration testers, researchers, and bug bounty hunters. The tool is built to ensure legal operation on systems for which users have authorization, promoting responsible security practices.
2026-08-03
Go
★ 148
Pkappa2 is a sophisticated packet stream analysis tool designed for Attack & Defense Capture The Flag (CTF) competitions, enabling users to upload and analyze pcap files for network traffic streams. The tool features a custom query language for structured searches, real-time updates through a responsive web interface, and the ability to save queries as services or tags, facilitating quick access to specific stream data. Notably, it supports both IPv4 and IPv6, offers scriptable data converters, and can ingest traffic through various methods including HTTP POST, making it a versatile choice for network analysis in CTF environments.
2026-08-03
Ruby
★ 28
ronin-support is a Ruby library that enhances core Ruby functionality with various extensions tailored for security research and development, integrating features akin to pwntools and ActiveSupport. It provides user-friendly APIs for handling binary data manipulation, encoding, cryptography, and networking protocols, along with utilities for text processing and archive management. Notably, it has a small memory footprint, high documentation coverage, and extensive test coverage, making it a robust tool for developing security-related applications.
2026-08-03
Python
★ 582
StegoForge is an advanced steganography toolkit designed for embedding and extracting hidden data within images, audio, and video files, while also providing a comprehensive suite for digital forensics analysis. Its features include AES-256-GCM encryption, a local web UI for interactions, support for batch processing, and the ability to simulate network behavior on payloads, making it suitable for security researchers and CTF (Capture The Flag) participants. The framework offers zero-dependency binaries for easy deployment across multiple operating systems.
2026-08-03
Shell
★ 10
IP-Vortex is an advanced IP rotation tool designed for security professionals, enabling anonymous security testing by frequently changing public IP addresses. Its primary use case is to facilitate fuzzing and vulnerability scanning while avoiding IP-based rate limiting, featuring automatic IP rotation, timed intervals, multi-interface support, and optional MAC address randomization. Notable features include comprehensive logging, network status monitoring, and seamless integration with security testing workflows.
2026-08-03
JavaScript
★ 12
NarrowX is a specialized browser extension designed for bug bounty hunters and security engineers that facilitates the extraction of endpoints, parameters, and sensitive indicators from JavaScript and network activity. Notable features include advanced inline and external JavaScript parsing, network request capturing, and automatic extraction capabilities using safe synthetic interactions, all while maintaining user privacy through local processing. Additionally, it supports scope filtering across multiple domains/subdomains to refine focus on specific targets.
2026-08-03
Ruby
★ 42
ronin-recon is a micro-framework designed for efficient reconnaissance operations, utilizing multiple asynchronous workers to process various value types like IPs, hosts, and URLs. It features built-in recon capabilities such as DNS lookup, web spidering, and service scanning, and allows for the integration of additional third-party modules. Its unique queue architecture enhances performance, while support for multiple output formats and automatic result saving to a database makes it a versatile tool for cybersecurity practitioners.
2026-08-03
★ 96
Security Books is a comprehensive repository offering over 160 curated cybersecurity-related books, guides, and resources, catering to various skill levels from beginners to advanced practitioners. This tool features a fully categorized structure with clickable links for instant access to each resource, ensuring that the cybersecurity community has free access to critical knowledge. With a commitment to regular updates, it serves as a valuable, continually expanding library for topics ranging from ethical hacking to network defense.
2026-08-03
Python
★ 16
AdwanceSNI is a command-line tool designed for subdomain discovery and vulnerability scanning on Termux and Linux platforms. Leveraging the capabilities of subfinder for subdomain enumeration and bughunter-go for vulnerability analysis, it features a user-friendly colorful terminal UI, progress indicators, and supports batch processing for multiple domains. This tool is primarily intended for educational and ethical hacking purposes, emphasizing user responsibility for permissions when scanning targets.
2026-08-03
C
★ 31
The iOS 26 Activation Lock repository documents 31 firmware-level vulnerabilities found in iOS 26.3, specifically targeting the activation lock subsystem. It serves primarily as a resource for the security research community, featuring self-contained writeups for each vulnerability, ranking from critical to less severe, along with proof-of-concept implementations and exploitation scripts. Notable features include detailed descriptions, reproduction steps, and evidence for each finding, aiding researchers in understanding and possibly mitigating the identified security issues.
2026-08-03
Shell
★ 19
Facebook SSL Pinning Bypass is a tool designed to circumvent SSL/TLS certificate pinning in the Facebook app on Android devices, enabling users to intercept and analyze HTTPS traffic. It supports both rooted and non-rooted devices and functions with various proxy tools such as Burp Suite and mitmproxy. The tool provides a patched APK for different architectures, facilitating ease of use for security testing and debugging activities.
2026-08-03
Shell
★ 16
Threads SSL Pinning Bypass allows users to bypass SSL certificate pinning in the Meta Threads app on Android, enabling the interception and analysis of HTTPS traffic through various proxy tools like Burp Suite and mitmproxy. This project provides a pre-patched APK compatible with both rooted and non-rooted devices, ensuring that security researchers and penetration testers can effectively capture network requests and API responses for version 440.0.0.47.86. Notable features include support for multiple architectures and detailed setup instructions for both physical devices and emulators.
2026-08-03
Shell
★ 106
TIKTOK-SSL-Pinning-Bypass is a tool designed for security researchers and developers to bypass SSL certificate pinning in the TikTok app on Android devices, facilitating the interception and analysis of HTTPS traffic. Its notable features include compatibility with both rooted and non-rooted devices, support for various proxy tools, and recent enhancements that allow full functionality on Android 11 and above, including the capture of login and registration traffic. The tool provides a pre-patched TikTok APK, enabling users to inspect API calls and the app's network interactions seamlessly.
2026-08-03
Python
★ 67
AVAIN is an automated vulnerability analysis framework designed for IP-based networks, leveraging a modular architecture to conduct comprehensive assessments of both networks and individual hosts. It features collaborative modules that facilitate reconnaissance, vulnerability correlation, and active detection of security issues, culminating in a vulnerability score to gauge overall security. Noteworthy capabilities include simple result sharing, extensive module configurability, and the ability to integrate various tools, making it a robust platform for penetration testing and security evaluation.
2026-08-03
Python
★ 28
vuln-scanner-flask is a web application designed for scanning vulnerabilities within websites and performing network exploitation and reconnaissance. Its notable features include an intuitive user interface, fast scanning capabilities, and functionalities for scheduling assessments and generating reports. The tool aims to facilitate security assessments while ensuring user-friendliness and security.
2026-08-03
Go
★ 10
The network-vulnerability-scanner is a tool designed to identify vulnerabilities within networked systems by analyzing hosts and services for known security flaws. Its primary use case is to enable network administrators and security professionals to assess the security posture of their network infrastructure. Notable features include support for various network protocols, customizable scanning options, and detailed reporting on discovered vulnerabilities and recommended mitigations.
2026-08-03
Python
★ 131
This repository provides a structured introduction to offensive techniques that exploit neural networks, focusing on areas such as bug hunting, malware injection, and information extraction. Each technique is accompanied by practical exercises to facilitate hands-on learning. Notable features include detailed instructions for setting up a Python environment and using various ML tools, as well as a diverse range of attack scenarios aimed at enhancing understanding of security vulnerabilities in neural networks.
2026-08-03
★ 69
Libellux: Up & Running is a comprehensive guide for installing open-source security software from source, focusing on implementing a Zero Trust Network to bolster existing application security. The tool provides detailed documentation for notable security solutions including WireGuard for VPN, OSSEC for intrusion detection, Greenbone for vulnerability management, and ClamAV for antivirus. This resource is geared towards enhancing threat detection and prevention capabilities within various IT environments.
2026-08-03
Python
★ 686
RedTiger-Tools is a versatile automation tool designed for penetration testing (pentesting) and open-source intelligence (OSINT) that aims to consolidate multiple operations into a single, configurable platform. It features a plugin system for extending functionality, centralized configurations using JSON files, and dual operation modes (CLI and interactive interface), ensuring compatibility with both Windows and Linux environments while adhering strictly to legal and ethical standards for usage.
2026-08-03
Python
★ 608
L0p4Map is a robust network monitoring and visualization tool that enhances the capabilities of Nmap, providing security researchers and network administrators with detailed insights into their network infrastructure through an intuitive interface. Key features include continuous monitoring of network traffic, real-time alerting for unauthorized devices, extensive device fingerprinting, and the ability to generate a real-time graphical representation of network topology. The tool supports multiple platforms (Linux, Windows, macOS) and integrates seamlessly with existing Nmap functionalities to deliver a comprehensive view of network security.
2026-08-03
JavaScript
★ 20
NSAuditor AI is a modular, AI-assisted network security audit platform designed to assess and prioritize vulnerabilities without data exposure, operating entirely within your infrastructure. It utilizes 27 specialized scanning plugins to generate AI-powered vulnerability reports while ensuring zero data exfiltration, as all processes including analysis and monitoring are conducted offline and any external API calls are opt-in. This tool emphasizes privacy and security by ensuring that sensitive scan data never leaves the user's environment.
2026-08-03
Go
★ 30950
Nuclei is a high-performance vulnerability scanner that utilizes YAML-based templates for customizable vulnerability detection, aiming to reduce false positives by mimicking real-world attack scenarios. Its notable features include ultra-fast parallel scan processing, support for multiple protocols such as HTTP and DNS, and seamless integration into CI/CD pipelines as well as various issue tracking and logging systems. The tool is designed for security professionals to stay ahead of trending vulnerabilities while conducting thorough regression testing.
2026-08-03
HTML
★ 51
BitDefender Total Security Ultimate Protection is a comprehensive cybersecurity suite that functions as a modular framework for fortifying network defenses against a wide array of cyber threats. Its primary use case revolves around system hardening, employing features such as vulnerability scanning, real-time threat correlation, and sandbox-based execution to protect various environments from evolving threats. Notable capabilities include automated policy enforcement, advanced heuristic analysis, and deep kernel inspection for rootkit remediation, all integrated within a responsive interface supporting multilingual operations and continuous 24/7 support.
2026-08-03
Python
★ 11
ShieldEye Core is a desktop network security scanner designed for Linux, primarily aimed at security researchers, pentesters, and system administrators. It utilizes Nmap for comprehensive port and service discovery, identifies vulnerabilities in common CMS platforms by cross-referencing with the CIRCL CVE database, and evaluates HTTP security headers, all presented through a GTK 4 GUI with intuitive reporting features. Key functionalities include customizable scanning profiles, a detailed analysis of web security, and robust safety measures against unauthorized access and disruption.
2026-08-03
Go
★ 12248
Vuls is an agent-less vulnerability scanner designed for Linux, FreeBSD, and macOS systems, written in Go, that automates the detection of vulnerabilities by continuously monitoring installed software against a variety of vulnerability databases. It generates regular reports that inform users about affected systems and related vulnerabilities, mitigating the risks of human oversight in the management of software updates. Notable features include high-quality scanning capabilities across major operating systems and integration with multiple security advisories and vulnerability databases.
2026-08-03
Go
★ 14967
OWASP Amass is a comprehensive tool for network mapping and external asset discovery aimed at enhancing cybersecurity through the use of open source information gathering and active reconnaissance techniques. Its primary use case is to identify and map attack surfaces, enabling security professionals to assess the security posture of the networks they oversee. Notable features include its ability to aggregate data from various sources and integrate with existing tools, providing a robust framework for comprehensive threat assessment.
2026-08-03
★ 31
Awesome Hacking & Cybersecurity Learning Path is a comprehensive resource designed to guide individuals from beginner to advanced levels in ethical hacking, penetration testing, and cybersecurity. It features curated materials on bug bounty hunting, OSINT tools, CTF challenges, and practical exercises for real-world scenarios, alongside essential concepts in networking and web application security. Notable features include detailed roadmaps for penetration testing, hands-on labs from platforms like TryHackMe and HackTheBox, and extensive coverage of privilege escalation techniques across multiple operating systems.
2026-08-03
Shell
★ 2659
The Awesome OSINT Arsenal is a comprehensive open-source toolkit designed for open-source intelligence (OSINT) and cybersecurity, comprising over 753 tools organized into 50 categories. It facilitates quick installations on various Linux distributions and offers targeted scripts for specific tasks such as red teaming, blue teaming, and forensics, simplifying access to essential security resources. This toolkit supports multi-distro installers and includes a Termux subset for Android, enhancing its versatility for security researchers and practitioners.
2026-08-03
Python
★ 13
Ayesha OSINT Toolkit is an open-source tool designed for conducting various Open Source Intelligence tasks, including username availability checks, email validation, and IP address lookups. Built with Python, it leverages scripts that access publicly available data sources, enabling users to gather crucial information efficiently. Key features include individual script functionalities for username checking, email finding, and detailed IP information retrieval, all of which can be executed based on user requirements.
2026-08-03
Python
★ 76
BIRDY-EDWARDS is an AI-driven SOCMINT platform designed for local analysis of publicly available Facebook profile data, enabling authorized users to collect and analyze information without cloud dependencies. Key features include automated profile collection, interaction intelligence with sentiment analysis, country detection using LLM, interactive network graphs, and customizable PDF reporting. This tool is designed for legitimate intelligence, law enforcement, and academic research use, operating with a valid Facebook session and adhering to privacy regulations.
2026-08-03
Python
★ 26
Birdy-Edwards Lite is a local-first SOCMINT platform designed for gathering and analyzing publicly available Facebook profile data, including posts and interactions, without requiring AI models or cloud services. It features automated data collection, network visualization, interaction mapping, and various graphical outputs such as heatmaps and force-directed graphs, all optimized for modest hardware capabilities. This tool is specifically tailored for investigators seeking rapid, reproducible results while adhering to data access limitations.
2026-08-03
Python
★ 17
PyAhmia is a command-line tool that allows users to search for hidden services on the Tor network by querying the Ahmia.fi search engine without the explicit requirement of using Tor. Notable features include the ability to export search results to CSV, enable or disable routing through Tor, cache responses for faster searches, and filter results by time period and limit.
2026-08-03
HTML
★ 28
SINARC (Sistema Integrado de Análise de Redes Complexas) is an experimental open-source program designed for data analysis of public sources by generating graphs. Its primary use case is to empower citizens to exercise social control over public administration in line with constitutional rights and the Law on Access to Information. Notable features include integration with various databases, interactive tutorials, and a command alphabet, facilitating user engagement and comprehensive data analysis.
2026-08-03
Python
★ 10
Visualize-External-Addresses is a Python tool that enables real-time visualization of external IP address connections for Windows devices, integrating netstat output with Whois data and displaying it through Google Earth. The tool allows users to monitor and analyze network connections by generating KML files for external addresses, which can be updated every few seconds for continuous tracking. Notable features include easy setup via Anaconda, location-based monitoring with latitude and longitude inputs, and the requirement of Google Earth for graphical representation.
2026-08-03
Go
★ 11
BannerGrapV2 is an advanced network reconnaissance and vulnerability discovery tool designed for both offensive and defensive security operations, making it suitable for Red and Blue Teams, bug bounty hunters, and security auditors. Notable features include multi-threaded banner grabbing, extensive service fingerprinting, a robust vulnerability detection engine, and flexible reporting options in multiple formats, all powered by a performance-focused architecture enabling concurrent scans of up to 10,000 hosts.
2026-08-03
★ 12
Blue OSINT is an open-source intelligence tool designed for investigators and analysts to gather publicly accessible information from the internet. Notable features include username and email lookups, phone number searches, domain and IP WHOIS information retrieval, social media profile scraping, and dark web breach checks, all with the ability to export results in multiple formats. The tool aims to facilitate various OSINT activities while emphasizing lawful use.
2026-08-03
Python
★ 38
NERD (Network Entity Reputation Database) is a software tool and service designed to acquire, store, and aggregate data on malicious network entities, primarily focusing on IP addresses. It provides users with an accessible interface to analyze and retrieve information about these threats, facilitating enhanced network security decision-making. Notable features include its comprehensive data aggregation capabilities and a dedicated instance available at nerd.cesnet.cz for user access.
2026-08-03
Python
★ 233
OnionClaw is a multifunctional tool designed to provide AI agents with complete access to the Tor network and .onion services, facilitating OSINT, threat intelligence, and security research. Its notable features include automated dark-web crawling, continuous threat monitoring, and advanced credential surveillance with full identity rotation, all capable of operating in both an OpenClaw skill environment and as a standalone application. While intended for legitimate use, the tool's capabilities raise significant concerns regarding the potential for misuse in criminal activities and automated disinformation campaigns.
2026-08-03
C++
★ 17
OsintgramCXX is an advanced OSINT tool designed for collecting and analyzing publicly available information from Instagram with a focus on ethical use. Notable features include modding support for custom hooks and commands, device spoofing capabilities for network calls, manual interaction for user control, support for multiple proxies, and the ability to engage with multiple Instagram profiles simultaneously. Currently in active development, it aims to enhance user experience while adhering to legal and ethical standards.
2026-08-03
TypeScript
★ 10
AI Tor.v69 is a hybrid neural intelligence core designed for managing a DAO, analyzing financial flows, and integrating advanced theoretical concepts of physics within the Web 3-4-5 ecosystem. Key features include a secure access module for digital sovereignty, autonomous governance analysis, and a quantum ledger for simulating financial flows in high-pressure environments, underpinned by a robust technical architecture utilizing modern web technologies.
2026-08-03
★ 515
as-ip-blocks is a tool that provides daily-updated datasets of autonomous systems (AS) with active BGP prefix announcements, available for download in JSON and plaintext formats. Its primary use case includes network analysis, firewall rule creation, and tracking IP ranges associated with specific organizations, with notable features such as aggregated prefixes, historical change tracking via Git history, and bulk download options.
2026-08-03
JavaScript
★ 16
OSINT NET Auditor is a desktop IP and port scanner application developed using Tauri, primarily for scientific and educational purposes. Key features include a user-friendly installation process, customizability through building from source using Node.js and Rust, and the capability to detect potential security vulnerabilities in network configurations. The app aims to provide an accessible tool for users interested in network auditing and security assessment.
2026-08-03
TypeScript
★ 43
Social Monitor is a comprehensive tool designed for aggregating and summarizing posts from various social networks and news sources, aiming to filter out noise and highlight the most relevant content based on user interests. Its notable features include customizable digest summaries on a daily, weekly, or monthly basis, and a robust backend architecture that supports various data ingestion and monitoring workflows. This tool is ideal for creating dashboards, monitoring topics or brands, and developing internal analytics for teams.
2026-08-03
★ 74
The "osint-notes" repository is a comprehensive catalog of Open Source Intelligence (OSINT) tools organized by various categories such as data extraction, email investigation, and social media intelligence. It serves as a valuable resource for cybersecurity professionals and researchers seeking to enhance their investigative capabilities with tools tailored for specific OSINT tasks. Notable features include detailed sections on each tool with descriptions, links, and tags to facilitate easy navigation and discovery of appropriate utilities for gathering and analyzing public information.
2026-08-03
C
★ 11
WiFi-Deauther is a tool designed for executing deauthentication attacks and monitoring Wi-Fi packets using an ESP8266 module. It features an OLED display for real-time status updates, button controls for navigation, and the ability to enhance signal strength with external antennas. The tool is primarily intended for educational and security testing, emphasizing responsible use with appropriate permissions.
2026-08-03
C++
★ 31
The WiFi Handshake Capture Tool is designed for security researchers and penetration testers to passively capture WPA/WPA2 EAPOL 4-way handshakes using an ESP32 development board. Key features include compatibility with standard network analysis tools like Wireshark and Aircrack-ng, a web interface for data retrieval, and the ability to save captures in PCAP format, facilitating further analysis. Users must adhere to legal and ethical standards when utilizing this tool for authorized network testing.
2026-08-03
Python
★ 37
The "Hacking Tools" repository offers a collection of cybersecurity utilities designed for various network reconnaissance and penetration testing tasks. Key features include ARP cache poisoning, subdomain enumeration via HTTPS certificate history, Google dorking for file discovery, and multiple implementations of network scanning and port scanning. These tools serve as essential resources for security professionals conducting assessments and vulnerability analysis.
2026-08-03
Python
★ 88
Net Strike is a load testing tool designed to simulate various types of network attacks, including TCP SYN flood, ICMP flood, UDP flood, and HTTP flood, to evaluate network performance and resilience under stress conditions. It provides capabilities to spoof IP addresses and includes functionality for crafting HTTP requests with custom headers to bypass basic filtering, making it versatile for testing different scenarios. The tool is intended for educational and demonstration purposes, with a strong warning against unauthorized usage.
2026-08-03
C++
★ 403
PhiSiFi is a dual-function cybersecurity tool designed to exploit WiFi networks using an ESP8266 microcontroller, implementing both Deauthentication and Evil-Twin access point (AP) attacks simultaneously. It allows users to disconnect devices from a target WiFi network while also setting up a fake AP to capture passwords from unsuspecting users, verifying them against the original access point. Notable features include a user-friendly interface for managing attacks and the ability to execute both methods without manual toggling.
2026-08-03
Python
★ 21
The Unbekannt Framework is a specialized hacking and penetration testing tool designed for Windows environments, emphasizing ease of use with a modular command system. Notable features include support for various attack modules, options configuration for each module, and the ability to import custom Python modules. The framework facilitates the execution of penetration tests while encouraging community contributions through shared module development.
2026-08-03
Python
★ 750
Wifi-Brute is a Python-based tool designed to crack Wi-Fi passwords using a user-provided wordlist. Its primary use case is testing the security of Wi-Fi networks by attempting to brute-force passwords, although effectiveness can vary depending on the wordlist size. Notable features include a simple command-line interface, the ability to specify custom wordlists, and the option to use a built-in default wordlist.
2026-08-03
Shell
★ 38
WiFi Jammer v1.3 is an advanced network testing tool designed for evaluating WiFi security with features such as an interactive user interface, automatic monitor mode setup, dual band support, and multiple attack methods including standard deauth and advanced MDK3 attacks. Its primary use case is for educational and authorized penetration testing of wireless networks, providing detailed security analysis and client detection functionalities while ensuring proper network restoration and error handling. The tool is developed for use on Kali Linux and requires essential wireless tools like the aircrack-ng suite for its operations.
2026-08-03
HTML
★ 13
WiFi-Pinapple is a tool designed to create a Wi-Fi Pineapple device using Raspberry Pi hardware, enabling users to simulate attacks such as Evil Portal for testing purposes. It incorporates features like easy setup instructions, DHCP server configuration with dnsmasq, and iptables manipulation for traffic redirection to capture credentials on a spoofed access point. This tool is particularly useful for penetration testing and educational purposes in cybersecurity.
2026-08-03
HTML
★ 50
WIFIHacker is a comprehensive WiFi penetration testing tool designed to automate various WiFi security audits and attacks, including phishing, SSID spamming, and denial of service attacks. Notable features include the ability to create fake access points for phishing, broadcast multiple fake SSIDs, and capture credentials. This tool requires a WiFi adapter that supports monitor mode to function effectively and aims to serve educational purposes while emphasizing responsible use.
2026-08-03
Shell
★ 103
Wifite2 Requirements is a professional installation script designed to set up Wifite2 along with essential penetration testing tools such as hcxtools, hashcat, and aircrack-ng on Debian/Ubuntu-based systems. The script offers features like robust error handling, dependency management, optional update skipping, and detailed logging, making it user-friendly for authorized network testing and educational purposes while ensuring compliance with legal considerations.
2026-08-03
Rust
★ 52
WITCHCRAFT is an advanced cybersecurity toolkit designed for professionals engaged in operational security (OPSEC), offering functionalities for hacking, OSINT, and forensic analysis. Key features include a modular command structure for tasks such as port scanning, data mapping, and searching for keywords across numerous platforms, bolstered by a comprehensive spellbook containing unique wordlists and databases for enhanced reconnaissance. This tool serves as an all-in-one cyberdeck system for efficient data-ghosting, network penetration, and threat analysis.
2026-08-03
Python
★ 12
BrutalNET V2 is a network attack tool specifically designed for executing large-scale ARP spoofing attacks that result in a denial-of-service (DoS) condition across an entire network. Unlike traditional ARP spoofing methods that focus on single targets, BrutalNET inundates connected devices with forged ARP packets to poison their ARP caches, effectively redirecting all network traffic to the attacker's MAC address. Notable features include its ease of use through simple command-line instructions and its capability to disrupt entire networks by leveraging the ARP protocol vulnerabilities.
2026-08-03
Python
★ 12
hackwifi is a Python-based toolkit designed for Wi-Fi penetration testing, facilitating tasks such as network scanning, packet capturing, deauthentication attacks, and password cracking. Key features include the ability to identify nearby networks, capture handshake packets for offline cracking, and perform deauthentication attacks to aid in the capture process. This tool is intended for educational purposes and requires proper authorization for use.
2026-08-03
Rust
★ 12
Hazard is a Rust-based dictionary brute-force tool designed for testing the security of various network protocols including SSH, FTP, Samba, MySQL, and PostgreSQL. Its primary use case is to facilitate password cracking through a user-friendly interface, allowing operators to input target IPs and utilize predefined wordlists. Key features include multi-protocol support, customizable input options, and a straightforward installation process.
2026-08-03
C
★ 73
Inject is a command line tool designed for crafting, injecting, and sniffing various network protocols, making it ideal for network troubleshooting, testing, or educational purposes. It supports multiple protocols such as Ethernet, ARP, IP, ICMP, TCP, and UDP, and includes features for creating custom network packets, integrating payload files, and capturing packets with customizable filtering options. Notable functionalities encompass detailed packet injection and robust network sniffing capabilities.
2026-08-03
Crystal
★ 39
miniss is a lightweight tool designed to display open listening sockets, serving as a minimal alternative to `ss` or `netstat`. Primarily aimed at penetration testers and CTF players, it offers a standalone static binary for environments where traditional socket tools might be absent, supporting both TCP and UDP protocols over IPv4 and IPv6. Notable features include customizable output options, socket type differentiation, and clear display of socket states along with associated user information.
2026-08-03
Python
★ 307
PANDORA is a multifaceted cybersecurity tool designed primarily for offensive security tasks, including DDoS attacks, web scanning, and data extraction through various methods like SQL injection and doxing. Notable features encompass a range of hacking utilities such as a deface maker, database dump capabilities, network sniffing, and an auto exploitation tool, making it versatile for both penetration testing and malicious activities. The tool is presented with detailed installation instructions for multiple environments, including Linux and Termux.
2026-08-03
Python
★ 16
Wifi-Confusion is a cybersecurity tool designed to create multiple fake Wi-Fi access points to mislead potential victims, primarily for educational purposes. It features a simplified process for accessing monitor mode and allows for the bulk generation of deceptive networks using an external Wi-Fi card compatible with Kali Linux. Users must adhere to ethical guidelines, as the tool is intended solely for legal, educational use.
2026-08-03
Python
★ 39
WiFi Security & Router Diagnostics is a cross-platform Python script designed to extract and display details of saved WiFi profiles, including passwords, authentication types, and encryption methods across Windows, Linux, and macOS systems. Notable features include an interactive menu for filtering, searching, exporting results to various formats, and an auto-install mechanism for dependencies like `colorama`. The tool prioritizes user consent by implementing a Terms and Conditions agreement before data retrieval, ensuring compliance with ethical standards.
2026-08-03
Python
★ 42
WIFIjam is a cross-platform WiFi deauthenticator and information tool that enables users to scan for nearby networks and perform a deauthentication attack on compatible Linux systems with the appropriate WiFi adapter. The tool boasts robust error handling, detailed WiFi information retrieval on macOS and Windows, and the ability to jam both 2.4GHz and 5GHz networks. It requires Python 3.x and various system-specific utilities to operate effectively.
2026-08-03
Python
★ 64
AirJack is a macOS tool designed for scanning Wi-Fi networks and capturing WPA/WPA2/WPA3 handshakes using CoreWLAN. It orchestrates the use of external tools such as AirSnare and hcxpcapngtool for data capture and facilitates the conversion of captures into hashcat format, providing users with options for dictionary or brute-force cracking workflows. Notable features include detailed logging, command line configurability, and a user-friendly launcher for streamlined operation.
2026-08-03
Python
★ 165
netpwn is a Python 2.7-based framework designed for automating various penetration testing tasks. It includes modules for creating reverse shells, sending files, and generating backdoors, along with tools for hash analysis, SSL certification retrieval, and various data encoding/decoding functionalities. Notable features include an auto-complete command interface, resource links for further learning, and an accessible command structure for executing modules effortlessly.
2026-08-03
Rust
★ 11
NetRaze is an offensive network-execution toolkit developed in Rust, providing a memory-safe, single-binary alternative to traditional Python-based tools like NetExec and CrackMapExec. It maintains a similar workflow for network post-exploitation but enhances performance with async I/O and offers a desktop GUI for visual workflow composition. Currently in alpha, it focuses on core functionality with a goal of expanding its protocol coverage across various operating systems.
2026-08-03
Batchfile
★ 339
WiFi Passview is a Windows-based open-source batch script tool designed to recover stored WiFi passwords quickly and effortlessly. It features the ability to extract passwords from specific SSIDs, save the credentials, generate WLAN reports, and even upload them to the cloud, all without requiring administrative rights for basic operations. The program streamlines the password recovery process by automating the extraction and removing the need for manual key content reading.
2026-08-03
Python
★ 52
ZX-DDoS is a Python-based Distributed Denial of Service (DDoS) tool designed for educational and testing purposes, allowing users to learn about network stress testing and security evaluation. It features a straightforward setup process and an interactive prompt for configuring target IP, number of worker threads, and requests, making it suitable for security researchers and network administrators. The tool is compatible with various operating systems, including Linux, Windows, and MacOS.
2026-08-03
Python
★ 1226
Buildware-Tools is a versatile cybersecurity multitool designed for tasks such as Discord automation, OSINT reconnaissance, network diagnostics, and cryptographic utilities, all accessible via a single terminal interface. It operates natively on both Windows and Linux, requires only Python for setup, and features an array of tools, including an IP port scanner, DNS lookup, and a website vulnerability scanner, with some functionalities accessible only after contributing to the project. Regular updates ensure continuous enhancements and the introduction of new features, while a plugin manager allows the integration of community-made plugins.
2026-08-03
Shell
★ 20
Evil-AP is an automation tool designed for conducting Evil Twin attacks, streamlining the process for both cybersecurity professionals and enthusiasts. Notable features include its open-source nature, allowing extensive customization, and the ability to personalize the web interface, making it adaptable for various use cases.
2026-08-03
HTML
★ 44
The Hacking-PenTesting-Utils repository serves as a comprehensive collection of tools, scripts, and configurations specifically designed for Internet of Things (IoT) penetration testing. It provides a variety of microcontroller options, RF modules, and essential hardware components to assist users in developing and deploying effective IoT security testing solutions. Notable features include a diverse range of compatible microcontrollers such as the ESP32, along with numerous supporting modules for enhanced functionality in various pen-testing scenarios.
2026-08-03
C#
★ 22
InstaMailChecker is an OSINT tool designed to verify if a specific email is registered on Instagram. Its primary use case includes bulk processing of email addresses with support for saving results, utilizing options such as reading from a text file and integrating with GNU Parallel for enhanced performance. The tool is built on .NET 10 and provides a straightforward command-line interface for quick checks.
2026-08-03
HTML
★ 622
NETHERCAP is a comprehensive Wi-Fi penetration testing and social engineering tool designed for deployment on ESP8266, ESP-32, and BW16 (RTL8720dn) devices. Its primary use case involves executing attacks such as deauthentication and the Evil Twin attack, offering features like multi-language support and easy installation through its GitHub releases. The tool is particularly targeted towards users in Indonesia and includes community support via Telegram and WhatsApp for enhanced user engagement.
2026-08-03
Python
★ 653
PyHTools is a comprehensive collection of Python-based hacking tools designed for network security assessments, including functionalities such as network scanning, ARP spoofing, DNS spoofing, and credential harvesting. It features a user interface for accessibility while allowing command-line usage for advanced users, with an emphasis on ethical use, as all malicious components are stored in a separate repository. The toolkit facilitates a wide range of cybersecurity practices, from reconnaissance to exploitation, but users are warned against any illegal applications.
2026-08-03
C
★ 436
ICE9 Bluetooth Sniffer is a Wireshark-compatible tool designed for comprehensive Bluetooth traffic analysis through wideband sniffing capabilities, utilizing software-defined radios like HackRF and bladeRF. It features multi-channel support (4-60 MHz) and offers command-line operation for capturing Bluetooth Low Energy (BLE) packets or all channels, with the ability to log data into PCAP files for further analysis. Additionally, it supports GPU-accelerated FFT processing and can be integrated directly into Wireshark for user-friendly interface access.
2026-08-03
JavaScript
★ 115
Pwnagotchi 64-Bit AI Edition is an advanced, high-performance adaptation of the Pwnagotchi project, optimized for 64-bit systems, leveraging PyTorch for enhanced AI inference and learning. Its primary use case involves automating Wi-Fi handshake capture through bettercap while intelligently adapting its behavior to varying environments based on reinforcement learning. Notable features include modernized AI engine support, a Kali Linux backbone for stable operation, and a Bluetooth Tethering Wizard for simplified connectivity setup.
2026-08-03
C#
★ 21
TerraAngel is a utility client designed for the game Terraria, offering advanced tools for enhanced gameplay and development. Notable features include an inspector for detailed character, NPC, projectile, and item information; a freecam mode for unrestricted camera movement; and a suite of visual utilities for analyzing game mechanics. The client supports real-time C# execution and net message debugging, making it particularly useful for developers working with Terraria's environment.
2026-08-03
Python
★ 96
WiFuX is a WPS security auditing tool designed for Android devices running Termux, enabling automated Pixie Dust and Bruteforce attacks against WPS-enabled routers. Notable features include a global command system, session management, and reporting capabilities, making it ideal for security researchers and network administrators wishing to evaluate their wireless infrastructure's security. The tool is fully optimized for mobile use and requires root access and a compatible Wi-Fi adapter.
2026-08-03
Python
★ 32
BlackBerryC2 is an encrypted remote administration and command-and-control (C2) framework primarily designed for educational and security research purposes within controlled environments. It features a custom TCP-based server that employs application-layer cryptography, including AES-256-GCM encryption and HMAC-SHA256 authentication, facilitating secure client communication, remote command execution, and file transfers. Key capabilities include session management, support for multiple concurrent clients, interactive console operations, and robust flood detection mechanisms.
2026-08-03
★ 109
Command CheatSheet is a comprehensive reference tool designed for penetration testing, focusing primarily on the OSCP framework. It offers an extensive collection of over 130 cheatsheets and 70 port references, providing quick access to emergency commands, checklists, and tools for various stages of the pentesting process, including scanning, exploitation, and privilege escalation. The tool emphasizes usability with a structure that promotes quick copy-paste actions for efficient workflow during assessments.
2026-08-03
Java
★ 72
Java Reverse TCP is a versatile tool designed for establishing reverse shell communications with remote hosts using JAR, JSP, and Java files. It operates seamlessly across multiple operating systems, automatically detecting the environment and enabling compatible interactions with `ncat` or `multi/handler`. Notable features include the ability to handle various shell types and user-friendly setup instructions for deploying and utilizing the tool in educational contexts.
2026-08-03
Python
★ 17
NetExec Automator is a parallel credential testing tool designed to exploit all 10 NetExec (nxc) protocols, allowing users to perform extensive authentication attempts using either combination or linear modes for credential pairing. Its notable features include live feedback on valid credentials and timeouts, support for local authentication variants, parallel execution with configurable worker counts, and detailed output summaries to streamline the penetration testing workflow.
2026-08-03
Python
★ 29
Nightcrawler-mitm is a mitmproxy addon designed for security researchers, facilitating passive analysis, crawling, and active scanning of web applications. Its notable features include a comprehensive vulnerability confidence system that assigns risk levels to findings, advanced scanning capabilities for various vulnerabilities like SQL injection and XSS, automated proof-of-concept generation, and smart targeting to enhance scanning efficiency. Additionally, it supports extensive customization through command-line options for tailored assessments.
2026-08-03
Python
★ 37
Pentest Toolkit is an advanced penetration testing framework designed for rapid and efficient security assessments, integrating over 100 industry-standard tools into both a Python suite for automation and a Bash interface for hands-on operations. Its primary use case includes comprehensive testing phases, from reconnaissance and web security to SSL/TLS analysis and network assessment, all culminating in professional report generation. Notable features encompass automated reporting in multiple formats, robust web application vulnerability testing, and streamlined reconnaissance processes.
2026-08-03
PHP
★ 574
The PHP Reverse Shell is a versatile tool designed to create reverse shells using PHP scripts across different operating systems, including Linux, macOS, and Windows. It automatically detects the OS and works with both `ncat` and `multi/handler`, offering educational utilities for establishing reverse shells and executing file upload/download functionalities. Notably, it supports multiple PHP versions and includes specific scripts for different environments, enhancing its adaptability for penetration testing scenarios.
2026-08-03
Shell
★ 11
PiSquirrel is a compact, versatile tool designed for red team and offensive security operations, functioning as an inline wiretap for monitoring servers, workstations, and network equipment. Notable features include its ability to mimic Brother printer responses to enhance stealth during network scans, a simplified setup script for quick configuration, and pre-installed tools for various network and penetration testing tasks. The device leverages inexpensive ARM architecture and open-source software, making it a cost-effective solution for cybersecurity professionals.
2026-08-03
HTML
★ 38
SecuSploitX is an advanced, modular, open-source penetration testing and cybersecurity toolkit designed for offensive security operations. It features a comprehensive suite of tools including web and network security modules, AI-driven automation for tasks like phishing simulations, and both GUI and CLI interfaces for user flexibility across multiple platforms. Notable capabilities include automated vulnerability scanning, advanced brute force tactics, and extensive documentation, making it suitable for both educational and professional use.
2026-08-03
Python
★ 19
SpecterNet is an advanced network anonymization framework designed to route all system traffic through the Tor network, enhancing security and privacy. Its notable features include full traffic routing, built-in DNS and IPv6 leak protection, a kill switch to block traffic during Tor disconnections, and hardware identity spoofing. Additionally, it offers comprehensive leak testing, censorship bypassing capabilities, and a modern terminal interface for monitoring and management.
2026-08-03
Jupyter Notebook
★ 225
SploitCraft is a repository designed for hacking and offensive security that provides a curated collection of exploits, penetration testing techniques, and vulnerability demonstrations. Its primary use case is to assist cybersecurity professionals and enthusiasts in understanding and showcasing the latest threats through organized guides and proof-of-concept demonstrations. Notable features include a structured layout by specific topics and comprehensive step-by-step instructions, enabling users to easily replicate the techniques in controlled environments.
2026-08-03
Python
★ 173
SuperLibrary is an educational repository designed to provide access to a collection of books and courses aimed at individuals who may face financial constraints in obtaining these learning resources. It emphasizes ethical usage, urging users to support authors and publishers whenever possible, while also featuring a disclaimer regarding copyright and legal responsibilities. Notable features include categorized content such as books and courses, fostering self-education in various subjects.
2026-08-03
★ 33
The TryHackMe-Beginner-Roadmap is a structured learning resource designed for novices in cybersecurity, providing a step-by-step guide to essential concepts and skills via the TryHackMe platform. It covers foundational topics such as operating system fundamentals, basic security principles, reconnaissance techniques, scripting for automation, and web security vulnerabilities, while incorporating hands-on exercises to reinforce learning through practical application. Notable features include a comprehensive overview of key cybersecurity tools and methodologies, facilitating knowledge development in both theoretical and practical dimensions.
2026-08-03
Python
★ 175
The "Awesome Black Hat Arsenal" repository is a curated collection of advanced cybersecurity tools presented at Black Hat Arsenal events, aimed at practitioners in red teaming, blue teaming, application security, and OSINT. It organizes tools by geographical location, year, and category, providing detailed descriptions, authorship, and GitHub links for each tool, facilitating easy access to cutting-edge security utilities. This resource serves as an invaluable reference for security professionals seeking to enhance their toolkit with the latest innovations in the field.
2026-08-03
★ 330
Impacket-IoCs is a reference repository providing indicators of compromise (IoCs) for detecting activities driven by the Impacket toolkit, aimed at both blue and red team professionals. It features 73 detailed IoCs categorized by protocols such as Kerberos, SMB, NTLM, and LDAP, focusing on deeper, protocol-level signals rather than surface-level artifacts. The project serves to enhance the operational security of offensive tools and improve defensive strategies by offering practical detection methodologies for smaller teams without access to commercial solutions.
2026-08-03
Python
★ 10
The Microsoft SQL TDS Downgrade Attack tool performs a Man-in-the-Middle attack by intercepting Tabular Data Stream (TDS) packets between a client and MSSQL server, enabling the downgrading of encryption for TDS login packets. Its primary use case is to extract sensitive login credentials (username and password) by manipulating traffic through ARP spoofing and modifying intercepted packets. Notable features include automatic cleanup of the ARP spoofing and iptables rules upon stopping the script, and requirements for running include a Linux host with root privileges and necessary dependencies like arpspoof and iptables.
2026-08-03
Java
★ 22
Offensive ONOS is a cybersecurity research tool designed to weaponize ONOS applications, primarily for the detection of Cross App Poisoning Attacks in Software Defined Networks. Notable features include the ability to compile and activate ONOS applications, as well as the generation of ONOS archive files for testing, ultimately contributing to the discovery of vulnerabilities such as CVE-2023-24279 and CVE-2023-30093. This tool is a part of a broader research initiative within the context of a Cybersecurity M.Sc. thesis.
2026-08-03
Python
★ 31
`offsec-ai` is a sophisticated Python library and command-line interface designed for authorized red-team engagements, integrating classic network reconnaissance methodologies with advanced AI and LLM security testing. It features a suite of tools for probing AI/LLM endpoints against the OWASP LLM Top 10, scanning MCP servers for critical vulnerabilities, and conducting comprehensive infrastructure security assessments, with recent enhancements for A2A protocol security checks that include dangerous skill detection and secret scanning. This tool mandates explicit authorization for active attack features, ensuring ethical use while delivering powerful capabilities for security testing.
2026-08-03
Python
★ 153
Bjorn Detector is a Python tool designed for detecting the Bjorn device on a local network, displaying its IP address, and facilitating the initiation of an SSH session with a single click on the Bjorn icon. Key features include continuous network detection, an interactive SSH launcher, and seamless installation support for the Bjorn device. It requires Python 3.9+ and utilizes a PyQt6 interface to enhance user interaction.
2026-08-03
Python
★ 17
The Cyber Security Projects repository encompasses a collection of hands-on projects tailored for learning and experimentation in cybersecurity. It includes offensive and defensive tools, automation scripts, and real-world simulations, designed to enhance ethical hacking skills and practical security research. Notable features include a diverse set of project categories ranging from reconnaissance and web application security to network attacks and malware analysis.
2026-08-03
★ 1646
HaleHound™-CYD is a multi-protocol offensive security toolkit designed for the ESP32 Cheap Yellow Display, featuring over 40 attack modules focused on WiFi, Bluetooth, SubGHz, 2.4GHz, and NFC communications. This toolkit is designed for ease of use, allowing users to flash configurations directly from their browser without installation, and it supports various display sizes while incorporating external modules for enhanced functionality. Notable features include touch-driven controls and the capability to transmit at maximum power, facilitating a range of offensive security activities.
2026-08-03
C
★ 218
KHAØS C2 is a sophisticated post-exploitation command and control framework designed for stealth and evasion against endpoint detection systems. It features five covert communication channels, including Microsoft Teams and GitHub Gist, ensuring that the traffic blends with normal operations. The framework includes extensive post-exploitation capabilities, such as token theft, process injection, and lateral movement, along with a user-friendly React-based UI for real-time monitoring and payload management.
2026-08-03
Shell
★ 42
Venom is a comprehensive collection of tools, resources, and documentation focused on information security, penetration testing, and offensive cybersecurity. Its primary use case is to serve as a centralized repository for cybersecurity professionals seeking various utilities, from analysis and network reconnaissance to incident response and exploit development. Notable features include organized sections for different types of tools, such as anti-virus evasion, cloud security, and forensics, facilitating easy access to resources tailored for various cybersecurity needs.
2026-08-03
Python
★ 12
Bl0ck is a specialized attack tool designed to exploit vulnerabilities in Wi-Fi 5 (802.11ac) and Wi-Fi 6 (802.11ax) networks by utilizing Block Ack (BA) frame attacks. Its primary use case is to disrupt the transmission of Quality of Service (QoS) Data traffic, effectively cutting off internet access for connected devices without disconnecting them from the access point. Notable features include its capability to execute three distinct attack scenarios that can halt data transmission from the AP to the target device and facilitate further attacks, such as Deauthentication and Evil Twin assaults.
2026-08-03
Python
★ 12
Domaineer is a semi-automated bot designed to extract data from domains, facilitating domain analysis and intelligence gathering. It supports multiple platforms, including Linux, Windows, and Android, and can be easily installed via Python dependencies. The tool is currently under maintenance for enhancements, with plans to transition to a desktop application using PyQT and Golang.
2026-08-03
Python
★ 69
Litefuzz is a multi-platform fuzzer designed to identify security-related bugs in userland binaries, clients, and servers across Linux, Mac, and Windows operating systems. Notable features include easy setup, support for both CLI and GUI applications, and capabilities for handling network communication, making it suitable for a wide range of testing scenarios. It emphasizes simplicity in discovering vulnerabilities rather than high performance or academic accolades.
2026-08-03
Python
★ 20
The botnet-exploits repository is a collection of network vulnerability scanners designed to identify security weaknesses across various devices for educational and authorized testing purposes. It includes tools specifically for testing DVRs, ZHONE routers, Fiber routers, and performing telnet brute force attacks, featuring capabilities like multi-threaded scanning, real-time status updates, and automated credential testing. Users are required to configure payload URLs for legitimate testing environments, reinforcing the ethical use of these tools.
2026-08-03
Jupyter Notebook
★ 729
BlueToolkit is an extensible, black-box framework designed for testing Bluetooth vulnerabilities in both Bluetooth Classic (BR/EDR) and Bluetooth Low Energy (BLE) systems. Its primary use case includes semi-automated testing through its three main modules: Recon for capability gathering, Exploit for executing a range of 43 public exploits, and Report for generating comprehensive JSON reports. Additionally, the framework has been evaluated against multiple automotive brands, revealing significant security vulnerabilities in their Bluetooth implementations.
2026-08-03
Python
★ 22
The CVE-2026-0073 tool exploits a critical authentication bypass vulnerability in the Android ADB daemon (`adbd`), enabling an attacker on the same local network to gain unauthorized shell access to the target device. It leverages a type confusion issue in the TLS client certificate validation process, allowing for full control without user consent. Notable features include the capability to execute single commands, use different key types, and support for verbose output to trace the exploitation process.
2026-08-03
Shell
★ 39
Bash is a collection of Bash scripts designed primarily for use by Red Teamers to facilitate offensive security tasks and simplify common operations in a Linux environment. Key features include various exploit scripts targeting vulnerabilities such as CVE-2014-6271 (ShellShock) and CVE-2006-3392 for remote file disclosure, as well as utility scripts for obtaining system information and performing network reconnaissance. The toolset is easily installable via standard Linux practices, promoting accessibility and efficiency for cybersecurity professionals.
2026-08-03
Python
★ 100
MikrotikAPI-BF is a comprehensive RouterOS attack and exploitation framework designed for conducting automated security audits, brute-force credential attacks, and exploiting vulnerabilities in Mikrotik routers. Its notable features include a robust exploit engine with coverage for over 100 CVEs, multiple attack vectors such as REST API, SSH, and MAC-Telnet, as well as threading capabilities for multi-target scans. The tool also supports offline credential decoding and unique capabilities like MAC-Server Layer-2 discovery for devices without IP addresses.
2026-08-03
Lua
★ 12
Awesomenmap is a comprehensive knowledge base dedicated to Nmap, providing a centralized repository for essential Nmap NSE scripts, CVE search tools, and automated reconnaissance pipelines. It streamlines access for security analysts, pentesters, and blue teams, featuring organized references and integration of third-party scripts to ensure they are current. Notable features include post-scan reporting capabilities and visualizations for enhanced security assessments.
2026-08-03
Python
★ 13
DDoSSCAN is an advanced open-source network availability and stress testing framework developed in Python, designed specifically for security professionals, system administrators, and network engineers to conduct authorized tests on their infrastructure. Notable features include multi-vector attack simulations (TCP, HTTP, UDP, Slowloris), smart domain safety blocking, a real-time statistics dashboard, and automated session report generation in both TXT and JSON formats, all supported across multiple platforms including Linux, Windows, macOS, and Termux.
2026-08-03
C++
★ 18
Evil Goat is a Wi-Fi security education tool that simulates an Evil Twin attack by creating a fake access point with a captive portal to demonstrate phishing techniques and enhance user awareness. Key features include automatic DNS redirection, a simulated login portal, local data storage for educational labs, and a web-based configuration panel. The project is intended exclusively for educational and laboratory purposes, emphasizing responsible use and ethical practices in cybersecurity training.
2026-08-03
C
★ 17
Flipper RF Lab transforms the Flipper Zero device into a sophisticated RF analysis and research tool, featuring 15 advanced capabilities such as RF fingerprinting, adaptive signal modeling, and real-time spectrum monitoring. It enables users to perform detailed signal capture and analysis, protocol reverse engineering, and long-term logging within the 300-928 MHz frequency range. Notable functionalities include real-time activity mapping, threat modeling, and a robust modular research mode, making it suitable for professional RF forensics.
2026-08-03
Python
★ 130
MockSSH is a tool designed to emulate SSH server environments, enabling testing and automation of tasks without access to actual servers. It features a modern, type-safe architecture that supports threading for end-to-end unit tests, as well as integration with Python and HyLang for scripting commands. The tool includes comprehensive development utilities for linting, static type checking, and testing, alongside a DSL for simplified configuration and usage.
2026-08-03
Shell
★ 17
NAC Bypass is a Linux-based tool designed to create a transparent Layer-2 bridge with two Ethernet interfaces that facilitates bypassing Network Access Control (NAC) mechanisms by inheriting an active authentication session from a legitimate workstation. Its primary use case centers on network penetration testing and security assessments, allowing attackers to forward traffic while maintaining authorized access. Notable features include customizable network interface assignment, built-in options for passive monitoring, and integration with tools like Responder for enhanced functionality.
2026-08-03
Shell
★ 66
NullSec is an advanced penetration testing and red team operations framework that provides a custom ParrotSec-based distribution tailored for offensive security tasks. It features over 150 custom attack modules across multiple categories, full integration with the Metasploit Framework, an AI-powered security assistant, and a user-friendly TUI launcher for easy navigation and module management. The platform supports dual operation modes for safe demos and real attacks, and allows users to build custom ISOs for deployment.
2026-08-03
Shell
★ 82
NullSec Pineapple Suite is a comprehensive payload collection for the Hak5 WiFi Pineapple Pager, featuring 125 payloads organized into 14 categories for various aspects of WiFi security testing, including reconnaissance, interception, exfiltration, and stealth operations. Notable features include an extensive range of attack and reconnaissance payloads, a fast boot optimizer, a user-friendly one-click installation process, and the option for active development support. This suite significantly expands the capabilities of the WiFi Pineapple Pager compared to official and other third-party offerings.
2026-08-03
C
★ 67
RedTeam-Agent is an AI-powered autonomous framework designed for red team security assessments, enabling automated execution of commands across multiple tools through a skill-first terminal workflow. Its notable features include support for over 15 integrated security tools, advanced output filtering, and comprehensive Active Directory attack coverage, allowing users to streamline the red teaming process without manual tool management. The framework facilitates multi-client operations and includes functionalities for reconnaissance, data collection, analysis, and lateral movement.
2026-08-03
Python
★ 10
ShadowMap is a professional IP geolocation intelligence tool designed for tracking IP addresses with multi-source accuracy and Google Maps integration. Its notable features include querying multiple APIs for enhanced accuracy, precise coordinate outputs, proxy and VPN detection, and compatibility with mobile platforms like Termux. Intended for educational and authorized testing purposes, it provides users a clean, professional interface and the ability to save detailed geolocation reports.
2026-08-03
JavaScript
★ 216
Frieren is a micro-framework designed for managing security tools on OpenWrt routers and Single Board Computers (SBCs). It features a web panel that facilitates WiFi management, network diagnostics, and an extensible module system, allowing users to install third-party modules while providing an integrated terminal and package management capabilities. The stack leverages a PHP backend and React frontend, ensuring both lightweight performance and flexibility for embedded devices.
2026-08-03
Go
★ 12
GoFenrir is an Active Directory enumeration and attack framework developed in Go, leveraging the Manticore protocol backend for efficient operations without dependency complexities. It supports various protocols, including LDAP/LDAPS for full enumeration, Kerberos for advanced credential attacks, and has a plan to support SMB v2/v3, providing a robust suite of enumeration and exploitation features ideal for penetration testing. Notable functionalities include user and group enumeration, domain controller discovery, and advanced Kerberos attack capabilities like Kerberoasting and AS-REP roasting.
2026-08-03
JavaScript
★ 22
OverQuack is a customizable HID automation tool designed for scripted payload execution, featuring an open-source platform that runs on Raspberry Pi Pico boards. Its notable capabilities include full DuckyScript support, wireless payload management via built-in Wi-Fi, and a browser-based IDE that enhances the development experience with real-time error checking and auto-completion. The tool is geared towards transparency and extensibility, making it suitable for educational purposes and research while providing a modern setup workflow.
2026-08-03
PowerShell
★ 44
PrecompiledBinaries is a curated repository of precompiled binaries designed for use in authorized security testing, including penetration testing, red teaming, and exploit validation. It facilitates rapid access to essential tools across various scenarios such as privilege escalation, Active Directory assessments, and tunneling, eliminating the need for time-consuming compilation from source. Notable features include an organized layout of binaries by tool and platform, covering a wide range of use cases in security assessments.
2026-08-03
Go
★ 227
PromptZero is a natural-language operator designed for the Flipper Zero device, enabling users to generate, deploy, and execute various payloads through simple text commands. It primarily facilitates tasks related to RF, NFC, RFID, and HID payload creation while offering an intuitive interface for both offensive and defensive cybersecurity scenarios. Notable features include end-to-end integration with Claude AI for payload generation, a read-only operational mode for safe usage, and real-time querying of connected devices.
2026-08-03
Go
★ 47
Zscan is a fast and customizable service detection tool designed to identify services, APIs, and network configurations within infrastructure using a flexible fingerprint system. Key features include high-performance concurrent port scanning, intelligent service detection capabilities (such as MAC vendor identification and OS fingerprinting), precise proof of concept (POC) targeting, and versatile output formats including JSON and human-readable options. This tool enhances scanning accuracy and speed compared to traditional methods, making it valuable for network security assessments.
2026-08-03
Python
★ 127
Fluffy-Barnacle is a toolkit designed for creating disposable, ephemeral network infrastructure using GitHub Codespaces, enabling users to rapidly deploy services such as SOCKS5 proxies, HTTPS file hosting, and WireGuard tunnels. Notable features include an auto-reconnecting SOCKS5 proxy with circuit breaker support, instant public HTTPS file hosting capabilities, and a suite of CLI tools that integrate with common security testing utilities while managing fresh egress IPs upon each deployment. This tool serves primarily for educational, research, and authorized security testing purposes, adhering strictly to GitHub's usage policies.
2026-08-03
Shell
★ 478
ScanCannon is a high-speed Bash script designed for efficient credentials-based attack surface enumeration and reconnaissance of large external networks, leveraging tools like `masscan` for rapid port detection and `nmap` for detailed service analysis. It outputs consolidated reports in HTML and CSV formats while enabling project-driven scanning that tracks changes over time, facilitating continuous monitoring of attack surfaces. Notable features include full ASN-based discovery, API detection, CVE hinting, and resilience through checkpointing and parallel scanning.
2026-08-03
Shell
★ 64
365 is a comprehensive OSINT and threat hunting tool designed for network and web reconnaissance, discovery, enumeration, vulnerability mapping, exploitation, and reporting. Its notable features include a streamlined setup process for Kali Linux and a range of scripts for automating various security assessment tasks. This tool is primarily used for enhancing security assessments and facilitating vulnerability exploitation in targeted environments.
2026-08-03
Go
★ 318
Brutus is an advanced, multi-protocol authentication testing tool designed for penetration testers and red team operators, enabling efficient credential validation across a diverse range of network services such as SSH, RDP, and databases. Built in Go as a single binary with no external dependencies, it offers features like SOCKS5 proxy support, aggressive mode tuning, and seamless integration with tools like Nerva and naabu for automated workflows. Notably, it includes a library of known bad keys and supports account enumeration, making it a versatile asset for modern offensive security practices.
2026-08-03
Python
★ 15
CredWolf is a credential validation tool designed for Active Directory Domain Services that tests various username and secret combinations against a domain controller to identify valid credentials. Notable features include support for multiple secret types (passwords, NT hashes, Kerberos keys), username enumeration without triggering account lockouts, and extensive configuration options for safe and efficient testing. It is tailored for use in authorized penetration testing and security audits, ensuring robust and secure credential verification processes.
2026-08-03
JavaScript
★ 13
The Cybersecurity Interview Questions repository is a comprehensive collection of over 200 interview questions and answers, tailored for various roles in cybersecurity, including Red Team, Blue Team, and Incident Response. Its notable features include categorization by specific topics such as web security and internal network security, along with a user-friendly live site for browsing and searching content. The repository serves as a valuable resource for job seekers, students, and professionals looking to enhance their knowledge and prepare for cybersecurity interviews.
2026-08-03
Rust
★ 34
Echos is a modular network beacon emulator designed for validating detection systems in cybersecurity labs. It generates realistic command-and-control (C2) traffic across multiple protocols, enabling security teams to test their EDR, NDR, and SIEM solutions under controlled conditions without introducing risks associated with real malware. Key features include a variety of built-in profiles for significant APT groups, customizable configurations, and export capabilities for Sigma, Suricata, and Snort rules, making it a versatile tool for detection engineering.
2026-08-03
Python
★ 82
Miner In The Middle is a Python-based tool that facilitates the injection of JavaScript cryptocurrency miners into HTTP responses of targets on a local network via ARP spoofing. It features configurable options for injection scripts and IP constraints to ensure targeted use, along with an easy setup process that automates iptables configuration and packet forwarding. Users can also implement custom JavaScript for injection and execute various attack modes, including standard miner attacks and popunder techniques.
2026-08-03
Go
★ 687
Titus is a high-performance secrets scanner designed to detect credentials, API keys, and tokens within source code, files, and git history. Targeted at security engineers and DevSecOps teams, it features accelerated regex matching, live secret validation, broad coverage with 487 detection rules, and multiple scanning interfaces including CLI, Go library, and browser extensions. Notably, Titus also supports container image scanning and binary file extraction for enhanced security assessments.
2026-08-03
C
★ 10
Tung is a command-line tool designed for configuring and testing firewalls against various types of DoS attacks. Its primary use case is to assist security professionals in evaluating firewall resilience and understanding DoS attack vectors through a collection of common techniques across multiple network protocols, including implementations of attacks like Slowloris and BlueNurse. Notable features include support for ICMP, TCP, UDP, and IP, making it a versatile tool for both educational and practical security testing purposes.
2026-08-03
Python
★ 30
BeeScan is a modular IT infrastructure security auditing platform that facilitates comprehensive penetration testing and infrastructure assessments through the integration of external tools as plugins. Its notable features include automated result collection and multi-format report generation (TERMINAL, HTML, PDF), PostgreSQL database support for centralized result management, and Docker isolation for environment containerization, making it suitable for DevSecOps workflows and large-scale security audits.
2026-08-03
Python
★ 96
The "cybersecurity-penetration-testing" repository serves as a comprehensive collection of resources focused on penetration testing techniques, tools, and best practices in cybersecurity. It includes categorized links to software, libraries, frameworks, technical guidelines, and educational materials, aiming to assist security professionals in identifying and mitigating vulnerabilities in various environments. Notable features include extensive categories covering everything from anonymity tools to network vulnerability scanners, ensuring a broad spectrum of resources for ethical hacking endeavors.
2026-08-03
★ 31
The DIY ESP32 Marauder is a cost-effective PCB design for building an ESP32-based Marauder device, primarily used for wireless network analysis and security assessments. It supports a TFT LCD display for user interaction and encompasses the requisite components for easy DIY assembly, including detailed flashing instructions for firmware installation. Notable features of the Cheapskate version include a simplified assembly process, compatibility with widely available hardware, and optional battery support for portability.
2026-08-03
Shell
★ 382
Kaboom is an automated penetration testing tool focused on information gathering and vulnerability assessment. It integrates multiple utilities such as Nmap, Dirb, Nikto, and Hydra to conduct comprehensive scans and assessments, with results organized in an easily navigable directory. Notable features include support for both interactive and non-interactive modes, extensive customization options, multi-target scanning, and automatic identification of relevant Metasploit modules for vulnerabilities found.
2026-08-03
C
★ 16
Macgonuts is a versatile ARP/NDP tool designed for network address spoofing, supporting both IPv4 and IPv6 protocols. It aims to provide a lightweight, user-friendly interface for ethical hacking and pentesting while allowing developers to leverage its functionalities via C libraries or bindings in Go and Python. Compatible with Linux and FreeBSD, Macgonuts emphasizes responsible use and ethical practices in network security assessments.
2026-08-03
C#
★ 17
NetExec is an open-source network exploitation tool that evolved from the original CrackMapExec, aimed at providing a community-driven framework for post-exploitation activities in network environments. Its primary use case is to facilitate the automation of network attacks and assessments, integrating a suite of tools for a comprehensive assessment workflow. Notable features include ease of installation via pipx, community contributions for continuous improvement, and an active support channel through Discord.
2026-08-03
PowerShell
★ 201
PowerLadon is a modular penetration testing tool designed for network reconnaissance, vulnerability scanning, and exploitation, offering capabilities for batch processing across various IP segments. It features extensive support for different protocols, built-in modules for high-risk vulnerabilities, password auditing, and remote command execution, while allowing users to customize and develop their own plugins. Its ease of use and compatibility with PowerShell and Cobalt Strike enhance its versatility in both internal and external network penetration tasks.
2026-08-03
JavaScript
★ 122
rfparty-monitor is a wireless situational awareness and debugging tool that allows users to visualize and analyze Bluetooth Low Energy (BLE) data, along with GPS and Wi-Fi logs. It supports diverse platforms such as Android and Linux, and features capabilities like log retrieval and GPX conversion, making it suitable for both casual users and security professionals focusing on wireless monitoring and intrusion detection. Notable features include support for various GPS sources, a flexible installation process, and a roadmap for future enhancements like protocol improvements and real-time sharing alerts.
2026-08-03
JavaScript
★ 104
rfparty-xyz is a visualization tool designed to enhance the understanding of Bluetooth Low Energy (BLE) interactions. Its primary use case revolves around providing insights into BLE data through user-friendly displays, with complementary data collection capabilities available via rfparty-monitor. Notable features include cross-platform compatibility and support for mobile usage with an Android version.
2026-08-03
Python
★ 304
The Rogue Toolkit is a cybersecurity tool designed for advanced users to simulate malicious activity and test network defenses. Its primary use case is to aid in penetration testing and security assessments, allowing for customized execution of various attack scenarios. Notable features include extensive documentation for argument configurations and example use cases, enabling tailored deployments in various environments.
2026-08-03
Python
★ 89
Sexettintool is a multifaceted cybersecurity tool designed for educational and ethical hacking purposes, enabling users to execute various automated exploits and security assessments. Key features include exploit scanning with Searchsploit, firewall detection via wafw00f, brute force automation with ncrack, and vulnerability analysis using nikto and lynis, among others. The tool is structured to enhance cybersecurity awareness while retaining a focus on responsible usage, with comprehensive support for Linux users and potential Docker deployment.
2026-08-03
Python
★ 29
SYCP (Solyd Certified Pentester) is a resource repository designed to complement students pursuing the SYCP certification in penetration testing. It details the activities and topics covered in the course, providing a comprehensive study guide for users to enhance their cybersecurity skills. Notable features include thorough documentation of course modules and practical insights into penetration testing techniques.
2026-08-03
Python
★ 19
WiFi-Creds-Grabber is a Python tool designed to extract Wi-Fi credentials from a local Windows machine. Its primary use case is to retrieve stored Wi-Fi passwords, which are then saved in a text file named "passwords.txt" for easy access. The program is straightforward to use, requiring only Python to be installed and executing simple command-line instructions.
2026-08-03
Shell
★ 182
Air Script is an automated Wi-Fi network penetration testing tool that simplifies the process of network scanning, handshake capturing, and brute-force password cracking. It features automated attacks on nearby networks, email notifications for successful handshake captures, and compatibility with devices like Raspberry Pi for discreet operation. Users can enhance their workflows by selecting from a variety of additional tools provided within the script.
2026-08-03
Python
★ 44
CTFEnum is a Python-based network penetration testing tool specifically tailored for Capture The Flag (CTF) challenges. It conducts reconnaissance by scanning open TCP and UDP ports on a specified IP address, employing a modular design to probe various services and leveraging multiprocessing for efficiency. Notable features include automatic Nmap scanning, service-specific handlers for tasks like brute-forcing credentials, and detailed recommendations for exploiting identified vulnerabilities.
2026-08-03
Python
★ 213
Deluder is a dynamic instrumentation tool designed for intercepting traffic from proxy unaware applications by leveraging Frida. It supports a variety of networking libraries, including WinSock, OpenSSL, and GnuTLS, and allows users to customize interception scripts using JavaScript. Primarily intended for integration with the PETEP penetration testing proxy, Deluder can also function autonomously for broader traffic interception tasks.
2026-08-03
Python
★ 984
Habu is a versatile hacking toolkit aimed at educating users on Python and network hacking techniques. It features practical functionalities such as ARP poisoning, DHCP exploitation, subdomain identification, and certificate cloning, alongside various data extraction and analysis tools. This comprehensive suite serves as both an instructional resource and a powerful utility for network testing and research.
2026-08-03
Python
★ 15
NetRaptor is a GUI-based ARP poisoning tool designed for educational use and authorized network security testing, allowing users to scan networks, select targets, and perform Man-in-the-Middle (MITM) attacks. Key features include easy network scanning, ARP poisoning capabilities, packet analysis integration with Wireshark, and a user-friendly interface built with Tkinter. The tool is compatible with various Linux distributions and emphasizes ethical usage in controlled environments.
2026-08-03
C
★ 117
Packet Batch is a high-performance tool designed for generating and sending network packets, primarily used for penetration testing and network monitoring. Its notable features include the ability to send multiple packets with random source IPs and payloads, support for UDP, TCP, and ICMP, and optional checksum calculations to offload processing to the NIC. The tool also offers a version utilizing AF_XDP sockets for improved performance on recent Linux kernels.
2026-08-03
Rust
★ 17
Packet Batch is a high-performance toolset for generating network packets, designed primarily for penetration testing, benchmarking, and network monitoring. This Rust implementation offers enhanced safety and modern coding practices while maintaining fast performance through AF_XDP socket technology, highly configurable packet generation, real-time statistics display, and detailed logging capabilities. Users can execute multiple packet batches with various configurations via a command-line interface, although the project is still considered experimental and in early development stages.
2026-08-03
Python
★ 175
Preferred Network List Sniffer (PNLS) is a Red Team Wi-Fi auditing tool designed to capture SSIDs from a device's preferred network list by intercepting Probe Requests in the surrounding environment. The tool features a user-friendly web interface for visualizing the intercepted data and is focused on exploring the privacy implications associated with Wi-Fi communication. Noteworthy functionalities include compatibility with Raspberry Pi, the ability to filter SSIDs, and the provision for asynchronous server communication using WebSockets.
2026-08-03
Shell
★ 94
ScanPro is a menu-driven tool that enhances the functionality of Nmap for network scanning purposes. Its primary use case involves simplifying the scanning process by allowing users to select target IPs, ports, and scan types through an interactive menu, while also facilitating service detection and output formatting. Notable features include support for NSE scripting and HTTP information gathering, making it a versatile utility for penetration testing and network analysis.
2026-08-03
Python
★ 11
The Largo-m/security-tools-hacking is a modular Windows penetration testing framework designed for security professionals, facilitating various stages of red team operations such as reconnaissance, exploitation, and post-exploitation. Key features include system information collection, geolocation lookup, browser history extraction, and optional key logging, all presented in a user-friendly manner that allows for easy integration and extension of custom modules.
2026-08-03
Python
★ 16
Sniff-NG is a Python-based tool designed for network security assessment, specifically offering capabilities for local network scanning, ARP spoofing, and man-in-the-middle (MITM) attacks through an interactive text user interface (TUI). Key features include automatic gateway detection, a user-friendly menu for executing attacks, and one-click dependency installation for Linux and macOS systems. Its design emphasizes ease of use for ethical hacking and penetration testing, while ensuring the restoration of ARP tables post-attack.
2026-08-03
Go
★ 17
SocialFinder is an efficient username enumeration tool built in Go, designed to verify the availability of usernames across multiple social media platforms and websites. It offers real-time output, customizable URL lists, and smart matching for URL variations, allowing for rapid enumeration with clear, colored terminal results. The tool is optimized for performance using httpx, and it supports options like inclusion of NSFW sites and silent mode for discreet checks.
2026-08-03
Python
★ 14
whomrx-dosX is a DDOS tool designed to flood a target server with packets until it becomes unresponsive. It requires a simple installation process and allows users to specify target IP addresses and packet configurations through command-line parameters. Notable features include the ability to set the port and number of packets sent, making it an educational resource for understanding network stress testing.
2026-08-03
PowerShell
★ 601
WiFi Password Stealer is a cybersecurity tool designed to extract WiFi credentials from target computers using keystroke injection techniques via a USB device, specifically leveraging a Raspberry Pi Pico configured as a Rubber Ducky. The tool facilitates information exfiltration through customized payloads, allowing stolen data to be sent over email or stored on a USB drive. It demonstrates advanced attack vectors, including both Rubber Ducky and Bash Bunny methods, while emphasizing the importance of physical access to the target system.
2026-08-03
Rust
★ 21
wifikit is a WiFi pentesting toolkit designed for macOS, implemented in pure Rust without the need for kernel extensions or virtual machines. It enables comprehensive wireless network penetration testing through features like channel scanning, multiple attack engines (including PMKID extraction and WPS PIN cracking), and packet capturing, all accessible via an intuitive terminal user interface. The tool is specifically tailored for Apple Silicon and directly interacts with USB WiFi chipsets, providing a unique solution for native macOS penetration testing.
2026-08-03
Go
★ 10
Cokmap is a high-speed network scanner developed in Go that detects services and products on open ports using probes formatted according to the nmap-service-probes schema. Notable features include rapid product detection through a plugin architecture, support for flexible configuration, and the ability to generate detailed statistics. It is compatible with both Linux and macOS systems and offers a straightforward command-line interface for input and output handling.
2026-08-03
C++
★ 14
Dark Nexus is a modular and multi-threaded C++17 framework designed for comprehensive network reconnaissance and infrastructure analysis. It consolidates various tools into a single executable, offering powerful features including subdomain scanning, OSINT gathering, and advanced asset mapping through a user-friendly hybrid CLI. Its aggressive multi-threading capabilities and intuitive architecture ensure efficient operations across 12 distinct modules, catering to a wide range of reconnaissance needs without the burden of complex setups.
2026-08-03
Python
★ 21
The "Awesome Hacking with AI" repository is a comprehensive resource that explores the integration of Artificial Intelligence in offensive security practices, such as penetration testing and red teaming. It features a curated collection of AI-driven tools, methodologies, and case studies while emphasizing ethical considerations in their application. Notable features include a learning roadmap, prompt libraries for various tasks (e.g., payload generation and OSINT profiling), and advanced tactics like AI-powered malware development and botnet exploitation.
2026-08-03
Python
★ 6257
Bjorn is an autonomous network scanning and vulnerability assessment tool optimized for Raspberry Pi, featuring a unique e-Paper HAT display. Its modular architecture allows for flexible configuration and operations like network scanning, vulnerability detection using Nmap, brute-force attacks, and data extraction from compromised services. With a real-time interface for monitoring and interaction, Bjorn supports extensive customization for diverse security testing requirements.
2026-08-03
Python
★ 17
Blood-Web is a modular honeypot system designed for penetration testing training and network attack detection, implemented in Python 3.8+ with zero dependencies. It features multiple honeypot services, including SSH, FTP, HTTP, and others, each configurable via command line flags, along with a real-time web dashboard for monitoring attack statistics and trends. The tool is designed to run on non-privileged ports by default, enabling easy deployment without additional setup.
2026-08-03
Python
★ 14
CyberBox is a hardened Docker sandbox designed for bug bounty and offensive security research, providing a secure environment with a comprehensive assortment of over 160 security tools. It features keyless signing with cosign, a complete Software Bill of Materials (SBOM), and SLSA build provenance to ensure trust and integrity throughout the supply chain, while also integrating AI analysis and an autonomous workflow for security tasks. Moreover, it seamlessly supports the Caido framework, offering a plugin manager and various utilities to enhance the research process.
2026-08-03
Python
★ 32
EmbedXPL-Forge is an open-source exploitation and scanning framework designed for security assessments of embedded and perimeter devices including routers, switches, IoT devices, and printers. It features over 2800 modules encompassing various attack vectors such as credential testing, vulnerability exploitation, and firmware manipulation, alongside an extensive library of 700+ mapped CVEs across 114+ vendors, along with an APT Group Attack Engine for simulating real-world cyber attack scenarios.
2026-08-03
Go
★ 11997
Hetty is an open-source HTTP toolkit designed for security research and penetration testing, serving as an alternative to commercial tools like Burp Suite Pro. Its notable features include a machine-in-the-middle (MITM) HTTP proxy with logging capabilities, an HTTP client for crafting and replaying requests, request and response interception for manual review, organized project-based database storage, and a user-friendly web-based interface. Hetty is continually under development, aiming to meet the needs of the infosec and bug bounty communities effectively.
2026-08-03
Rust
★ 24
Ironbullet is a desktop automation toolkit designed for creating and executing complex data processing workflows using a visual drag-and-drop pipeline interface. It features over 50 block types, including HTTP requests, parsing, checks, and browser automation, allowing users to perform multi-threaded job executions with advanced debugging capabilities, TLS fingerprinting, and built-in traffic capture for analysis. Moreover, the tool supports plugin extensions and the importation of configurations from OpenBullet 2 and SilverBullet, enhancing its flexibility and application in various automation tasks.
2026-08-03
Python
★ 28
MoMo is a modular wireless security audit platform specifically designed for Red Teams, penetration testers, and security researchers, operating on Raspberry Pi 5. It integrates various advanced features such as multi-radio management, real-time data synchronization with a central hub, and comprehensive tools for WPA2/WPA3 attacks, credential harvesting, and automation in a single extensible solution. Notable functionalities include an auto-pwn engine, GPS wardriving capabilities, and support for social engineering techniques, making it a versatile tool for wireless security assessments.
2026-08-03
Python
★ 26
NetWatch is an all-in-one network security dashboard designed to convert any Linux machine into a comprehensive security sensor. It features real-time deployment of honeypots, traffic sniffing, OSINT tools, and threat management capabilities, all accessible via a single command and user interface. Key functionalities include automatic threat scoring, detailed traffic analysis, and the ability to block attackers, making it suitable for security professionals and home users alike.
2026-08-03
C++
★ 125
POSEIDON is a keyboard-driven pentesting firmware designed for the M5Stack Cardputer-Advance, enabling users to perform 163 types of attacks across various wireless protocols including WiFi, BLE, and IR. This tool simplifies pentesting by allowing direct input for network navigation and management without the need for a PC or complicated coding. Notable features include the integration of an autonomous WiFi handshake hunter named Argus, customizable interface themes, and ongoing development towards FIDO2 hardware security key functionality.
2026-08-03
Python
★ 164
`pwneye` is an offensive security tool designed for interacting with IP cameras that support ONVIF and RTSP protocols, streamlining various tasks such as discovery, authentication testing, metadata collection, and stream validation through a single command-line interface. Notable features include multithreaded bruteforce attacks for credential guessing, ONVIF device enumeration, RTSP stream handling, and a dedicated live preview client, all aimed at facilitating security assessments of surveillance systems.
2026-08-03
HTML
★ 30
RRW (Rick Roll WiFi) is a prank tool that sets up a rogue access point designed to capture captive portal probes and serve a fake Wi-Fi login page that redirects connected devices to a rickroll video. It utilizes standard network utilities like `hostapd`, `dnsmasq`, and `iptables` to manage the AP and traffic redirection without collecting credentials or intercepting user data, making it a non-malicious tool meant for entertainment. Users can customize the SSID, video, and HTML templates, allowing for tailored rickroll experiences.
2026-08-03
Python
★ 56
Touti Cracker is a cross-platform ethical hacking toolkit designed for educational purposes, featuring capabilities for password cracking, WiFi auditing, and reverse shell payload generation to illustrate system vulnerabilities. Notable features include an enhanced neon-styled user interface, automatic Hashcat setup, error handling enhancements, and compatibility with multiple operating systems, making it a comprehensive tool for security professionals and educators.
2026-08-03
Python
★ 34
TransparentTorProxy (TTP) is a Linux command-line tool designed to route all system traffic transparently through the Tor network using nftables, thereby enhancing user privacy without requiring per-application configuration. Key features include zero DNS leaks through kernel-level handling, a fail-closed design that secures network routing during failures, and the use of volatile memory to ensure no persistent data is left on the system. TTP offers a modern solution for users seeking to anonymize their internet traffic effortlessly.
2026-08-03
Shell
★ 422
WiFiChallengeLab-docker is a containerized environment designed for security practitioners to simulate and practice WiFi attacks on various types of networks, including OPN, WPA2, WPA3, and Enterprise setups. It features a range of updated challenges with new attack vectors, such as WPA3 brute-force and captive portal evasion, alongside enhanced stability by using Docker instead of nested virtual machines. The tool also incorporates nzyme for monitoring and detection, making it a comprehensive solution for hands-on learning in WiFi security.
2026-08-03
Python
★ 1170
WifiForge is a tool designed to provide a safe and legal environment for learning WiFi hacking, built on the Mininet-WiFi framework. It automates the setup of networks and necessary tools to conduct various WiFi exploitation labs, eliminating the need for extensive hardware and overhead. Key features include easy installation, detailed documentation, and a focus on educational use for cybersecurity professionals.
2026-08-03
★ 101
The Wireless Security & WiFi Penetration Testing course offers an advanced, lab-driven educational experience aimed at mastering wireless security testing and attack techniques against Wi-Fi networks. It covers a comprehensive range of topics including 802.11 standards, encryption methods, various cracking techniques, and wireless penetration testing methodologies, all delivered through practical, hands-on labs. Noteworthy features include configuration guidance for wireless adapters, ethical attack methodologies, and a focus on both offensive and defensive strategies, ensuring learners can apply knowledge directly to real-world scenarios.
2026-08-03
C
★ 29
AL-ANQA-FIRMWARE is an offensive security firmware designed for the LilyGo T-Deck, transforming it into a portable pentesting terminal equipped with over 60 integrated WiFi, Bluetooth, network, and radio tools. Key features include on-device WiFi attack capabilities, a comprehensive Bluetooth LE security audit suite, an interactive SSH client, and tools for wardriving and device monitoring—all operational without the need for additional PCs or GUIs, ensuring a self-contained and efficient testing environment.
2026-08-03
C
★ 15
Argos is a passive Wi-Fi tracking tool designed to capture probe request frames from Wi-Fi enabled devices, allowing users to extract SSID information and acquire geographic data through Wigle, subsequently visualizing this on a Google Maps interface. The tool features a web interface, dynamic data filtering options, and parameters for controlling the scanning environment, while emphasizing strict ethical usage guidelines to prevent privacy violations. Notable functionalities include the ability to limit signal strength, support for multiple network interfaces, and compatibility with various Wi-Fi adapters for optimal performance.
2026-08-03
★ 200
The R3LI4NT/articulos repository serves as a comprehensive resource for cybersecurity and hacking-related articles, focusing on topics such as vulnerability exploitation, security techniques, and network auditing. Notable features include detailed guides on various pentesting methodologies, firewall configurations for GNU/Linux, and resources on social engineering attacks, providing practical insights and tools for both novice and experienced security professionals. Users can access the content through an integrated blog link for easier navigation and learning.
2026-08-03
★ 119
Digital Forensics Tools is a comprehensive repository that curates essential utilities for digital investigations, including tools for disk forensics, memory analysis, malware detection, and network monitoring. Key features include disk imaging, file recovery, and memory acquisition tools, alongside advanced utilities like Volatility for memory analysis and Autopsy for user-friendly disk examination. This toolkit serves as a valuable resource for cybersecurity professionals conducting forensic investigations and data recovery tasks.
2026-08-03
★ 17
MasscanGUI provides a comprehensive graphical user interface for the Masscan port scanner, enabling users to easily configure and execute scans without requiring command line interaction. Notable features include support for all Masscan parameters, real-time output display, country-based scanning, multiple output formats, and advanced functionalities like intelligent rate adjustment and sharding for distributed scans. This tool is designed for ease of use on Windows with included executables, making it accessible for both novice and experienced users in network scanning tasks.
2026-08-03
Go
★ 306
Packémon is a terminal user interface (TUI) tool designed for packet generation and monitoring across any network interface, with compatibility for Windows, macOS, and Linux. It enables users to create arbitrary packets, including DNS queries, and observe real-time responses, whilst offering features like detailed packet inspection and filtering options. The tool is developed from scratch utilizing raw sockets, providing flexibility but also carries a warning for potential bugs.
2026-08-03
TypeScript
★ 2056
PentestingEverything is an open-source, comprehensive knowledge base for penetration testing, encompassing methodologies and resources across 23 security domains including web, API, mobile, and cloud. The tool offers a fully searchable interface with over 108 documentation pages, a filterable PDF library, and structured learning paths, enhancing the efficiency and effectiveness of security assessments. Its integration with an Agent Skill allows practitioners to apply this knowledge interactively during engagements, ensuring safe and authorized testing practices.
2026-08-03
Kotlin
★ 151
Spectre is an Android application designed for monitoring and interacting with various wireless signals, including Bluetooth, Wi-Fi, cellular, and GNSS. Its primary use case revolves around RF exposure measurement and pen-testing, featuring tools for detailed analysis of signal strength, local network discovery, and BLE device interaction. Notable features include comprehensive support for multiple network technologies, advanced filtering capabilities, and a GATT inspector for Bluetooth devices, all while adhering to Android's security restrictions.
2026-08-03
Python
★ 753
The Big Brother V5.0 is an advanced Open Source Intelligence (OSINT) framework designed for comprehensive reconnaissance on individuals, organizations, or groups. It features a highly interactive holographic dashboard supported by 21 distinct intelligence modules that facilitate deep investigative analysis. The tool allows users to conduct detailed searches and surveillance, enhancing the capabilities for gathering critical data while also offering an exclusive service for more intensive intelligence requirements.
2026-08-03
Shell
★ 10
The 5G-Pentest-UE is a penetration testing framework designed to identify vulnerabilities within 5G systems from the perspective of a user equipment (UE), requiring no prior knowledge or access to the network. Its notable features include the ability to configure and run tests against the 5G protocol stack, alongside the integration of patched Open Air Interface implementations to facilitate comprehensive security testing. This framework is particularly useful for assessing security in closed-source and proprietary 5G networks.
2026-08-03
Go
★ 13
VSAT (Volumetric Socket Artillery) is an advanced multi-layer network traffic generation framework designed for comprehensive stress testing and benchmarking of network infrastructure. The tool integrates Layer 3, Layer 4, and Layer 7 traffic engines, enabling high-throughput traffic simulation across various protocols while offering features such as HTTP/2 multiplexing, TLS JA3 fingerprinting, and raw packet crafting. Its multiprocessing architecture facilitates concurrent traffic generation, making it suitable for defensive security research and protocol analysis.
2026-08-03
Rust
★ 50
WonderSuite is a desktop-native offensive security research engine designed for comprehensive web application security testing, network reconnaissance, and exploit development, harnessing AI capabilities via Model Context Protocol (MCP) integration. It features an extensive toolkit of 91 security tools, enhanced by a full MITM proxy with advanced fingerprinting for obfuscation, facilitating efficient vulnerability research and response automation. The platform aims to streamline the process of identifying and addressing security issues, making it a powerful asset for security professionals.
2026-08-03
★ 32
5Ghost WiFi Lab is a dual-band Wi-Fi research and security testing tool designed for the Flipper Zero, utilizing the Realtek RTL8720DN chipset to enable comprehensive 2.4 and 5 GHz scanning. It features capabilities such as WPA/WPA2 handshake capture, clientless PMKID capture, and BLE reconnaissance, making it suitable for advanced security testing and educational purposes. The tool operates through a user-friendly app with multiple firmware support and connects seamlessly to the Flipper Zero without the need for additional wiring or flashing.
2026-08-03
Python
★ 133
Cochise is an autonomous penetration testing tool that leverages large language models (LLMs) to exploit vulnerabilities in Microsoft Active Directory environments. With a minimalistic design, Cochise allows users to easily customize and benchmark various LLMs, effectively orchestrating attack procedures including command execution and credential harvesting, all without requiring human intervention. Notable features include a dual-layer architecture comprising a strategic Planner and tactical Executor, along with built-in context management and analysis support for log file evaluation.
2026-08-03
Python
★ 143
Cyber Controller is a versatile application designed for flashing and controlling multiple ESP32 devices through a unified interface, facilitating both firmware installation and real-time management. It supports 50 firmware profiles and can operate over various interfaces, making it suitable for authorized security testing and educational purposes. Key features include simultaneous commands for multiple devices, anti-bricking safeguards, and compatibility with touchscreens or headless setups, enhancing user experience in cyberdeck operations.
2026-08-03
C++
★ 263
ESP-HACK is a comprehensive firmware for the ESP32 designed for radio frequency research and penetration testing, encompassing protocols in RF, Bluetooth, infrared signals, and GPIO integrations. Targeted at enthusiasts and pentesters, the tool features a wide array of functionalities including WiFi deauthentication, Bluetooth spamming, Sub-GHz signal analysis and jamming (where legal), and infrared control capabilities, all while permitting extensive customization through GPIO and support for various modulations. Its versatility makes it an essential resource for exploring and testing a variety of wireless communication technologies.
2026-08-03
Python
★ 13148
The OWASP Mobile Application Security Testing Guide (MASTG) serves as a comprehensive resource for mobile app security testing and reverse engineering, aligning with the OWASP Mobile Security Weakness Enumeration (MASWE) and the Mobile Application Verification Standard (MASVS). It features detailed methodologies for validating security weaknesses and offers tools like mobile app security checklists and interactive exercises, enhancing both understanding and practical application of mobile security principles.
2026-08-03
Go
★ 356
Nerva is a high-performance command-line interface (CLI) tool for fast service fingerprinting, capable of identifying over 170 network protocols across various transport layers including TCP, UDP, and SCTP. It is designed for use in network reconnaissance, providing features such as rich metadata extraction, security misconfiguration detection, and support for various output formats. Notably, Nerva integrates seamlessly with other security tools like Naabu, enabling automated workflows and robust scanning capabilities.
2026-08-03
Go
★ 374
RF Swift is a versatile tool designed to quickly set up a comprehensive hardware and RF security lab using containerized applications, allowing security professionals to utilize over 200 tools without altering their primary operating system. It supports multiple platforms, including Linux, Windows, and macOS, across various architectures while offering the ability to run specialized images for different engagement types. Notable features include rapid deployment, host OS preservation, and the ability to run on x86_64, ARM64, and RISC-V64 systems.
2026-08-03
Go
★ 12
Rosemary is a cross-platform tool for transparent network pivoting and tunneling over QUIC, enabling seamless traffic interception on remote hosts without the need for proxies or special configurations. Its key features include kernel-level interception of TCP, UDP, ICMP, and DNS traffic, a comprehensive web dashboard for real-time monitoring, and support for multi-hop connections through multiple agents. This tool is designed for scenarios where secure and efficient access to remote networks is required without altering client configurations.
2026-08-03
Python
★ 90696
Hunt down social media accounts by username across social networks
2026-08-03
Rust
★ 12
Sniper is an open-source web security proxy designed for macOS that allows penetration testers, bug bounty hunters, and developers to intercept, inspect, and modify HTTP/HTTPS traffic. Built in Rust, it offers a lightweight and efficient alternative to traditional proxy tools, featuring capabilities such as HTTP forwarding, passive vulnerability scanning, request replay, and an integrated command-line interface for automation. Notable for its rapid startup time and low memory usage, Sniper provides a user-friendly experience without the overhead of Java-based platforms.
2026-08-03
Go
★ 53
bgscan is a high-performance, modular multi-protocol network scanner implemented in Go, designed for host discovery and validation across various protocols including ICMP, TCP, HTTP, and DNS. Notable features include a fully keyboard-driven terminal user interface (TUI) for real-time monitoring, the ability to chain scan stages into pipelines for efficient scanning workflows, and robust data handling capabilities with options for output to CSV and integration with existing IP lists.
2026-08-03
★ 102
The "CIDR IP Ranges By Country" repository provides a comprehensive directory of CIDR IP ranges for both IPv4 and IPv6, organized by country. This tool is primarily used for network management and geolocation services, with the notable feature of being updated every hour to ensure accuracy and relevancy. Users can easily access IP range files for specific countries to facilitate their networking needs.
2026-08-03
Crystal
★ 87
gori is a versatile interception and analysis tool that acts as a capturing proxy for various protocols including HTTP/1.1, HTTP/2, WebSocket, gRPC, and SSE. Its primary use case is to capture, replay, fuzz, and scan HTTP flows, providing features like a searchable flow history, inline decoding of tokens, and integration with AI agents for automated engagement. Notable features include an intruder-style fuzzer, a command palette for efficient navigation, and a headless mode for scripting, making it suitable for both manual and automated testing scenarios.
2026-08-03
Shell
★ 116
Hacknetics is a comprehensive resource repository designed for OSCP students and Red Teaming professionals, offering a curated collection of code snippets, guides, and pentesting tools. Notable features include ready-to-use code in multiple programming languages, high-level strategies, step-by-step guides, and regular updates to ensure access to the latest techniques and tools essential for penetration testing.
2026-08-03
★ 23
The "resolvers" tool provides a regularly updated list of DNS resolvers, with updates executed every hour. Its primary use case is to supply reliable and fresh DNS resolver information, categorized into three distinct files based on the recency of updates: resolvers updated within the last hour, stable resolvers from the past 24 hours, and all available resolvers. Notable features include automated saving of fresh resolvers using `dnsvalidator` and systematic organization for user accessibility.
2026-03-30
Python
★ 750
DGFraud is a Graph Neural Network (GNN) toolbox designed for detecting fraud in various systems by integrating and comparing state-of-the-art GNN-based models. Its primary use case lies in enhancing the efficacy of fraud detection mechanisms through advanced graph-based methodologies. Notable features include a modular architecture for implementing new models, comprehensive documentation on existing algorithms, and support for TensorFlow 2.0, allowing seamless integration into existing projects.
2026-03-30
Python
★ 890
EvilWAF is a sophisticated transparent MITM Firewall bypass proxy and deep WAF vulnerability scanner designed for authorized security testing purposes. It operates at the transport layer, allowing seamless integration with various security tools while employing advanced techniques such as TCP and TLS fingerprint rotation, source port manipulation, and automated WAF detection to evade defensive mechanisms. Notable features include a comprehensive multi-layer WAF scanning capability, direct origin bypass, and a robust IP rotation strategy through Tor and proxy pools, ensuring effective assessment of firewall vulnerabilities.
2026-03-30
Python
★ 750
HaboMalHunter is an automated malware analysis tool specifically designed for Linux ELF files, facilitating both static and dynamic analysis to aid security analysts. It efficiently extracts crucial features such as process behavior, file I/O, and network interactions, generating comprehensive reports on malicious activities. Notable features include detailed static analysis of file dependencies and strings, as well as dynamic tracking of execution timestamps, API calls, and syscall sequences.
2026-03-30
Go
★ 726
NMAP-Formatter is a versatile tool designed to convert NMAP XML output into various formats such as HTML, CSV, JSON, Excel, and more, facilitating the analysis and reporting of network scan results. Notable features include support for output via stdin, the ability to generate diagrams using Graphviz, and options to skip down hosts, enhancing usability for security professionals and network administrators. This tool can also be utilized as a library in Golang for integration into other applications.
2026-03-30
Ruby
★ 756
Ronin is an open-source Ruby toolkit designed for security research and development, featuring a comprehensive suite of CLI commands and libraries tailored for various security tasks such as data encoding/decoding, vulnerability scanning, fuzzing, and reconnaissance. Notable features include a fully-loaded Ruby REPL, a lightweight web UI for database interaction, and the ability to install and run third-party exploits or payloads. This tool is primarily used by security researchers, bug bounty hunters, and developers for efficient data processing and rapid script prototyping.
2026-03-30
Shell
★ 716
The Shark Jack Payload Library provides a collection of community-driven payloads and extensions specifically designed for the Hak5 Shark Jack device, utilizing DuckyScript™ and Bash. Its primary use case is to enrich the functionality of the Shark Jack with customizable scripts for cybersecurity tasks, while also encouraging developer contributions for new payloads. Notable features include a platform for community collaboration and integration with Payload Studio for seamless payload creation.
2026-03-30
Python
★ 761
Spoilerwall is a network hardening tool that obscures open ports by serving movie spoilers whenever a scan is performed, effectively misleading potential attackers. Its primary use case is to create a deceptive environment that appears vulnerable but instead provides mundane content, deterring unwanted attention and scans. Notable features include customizable spoiler content, easy server setup, and the ability to redirect all TCP traffic to the Spoilerwall service, enhancing security through obfuscation.
2026-03-30
HTML
★ 771
THC-Archive is a repository that consolidates all releases from The Hacker’s Choice, a prominent security research group. This collection serves as a backup for their work, ensuring that projects are preserved despite the lack of a full web server. Notable active projects include THC-Hydra, THC-IPv6, and utilities aimed at various hacking and security tasks.
2026-03-22
Python
★ 843
Network Security Sniffer
2026-03-22
Shell
★ 7958
This is a multi-use bash script for Linux systems to audit wireless networks.
2026-03-22
Shell
★ 6114
All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.
2026-03-22
★ 2220
🔐🌐 Privacy-respecting web frontends for popular services
2026-03-22
Python
★ 923
Remove Certificate Pinning from APKs
2026-03-22
Rust
★ 1947
802.11 Attack Tool
2026-03-22
Python
★ 3514
一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
2026-03-22
Shell
★ 1926
ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web traceroute server
2026-03-22
Go
★ 1122
Go CLI and Library for quickly mapping organization network ranges using ASN information.
2026-03-22
C++
★ 1609
RubberDucky like payloads for DigiSpark Attiny85
2026-03-22
Shell
★ 11108
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
2026-03-22
★ 17364
A collection of hacking / penetration testing resources to make you better!
2026-03-22
★ 13541
Defund the Police.
2026-03-22
★ 7282
🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
2026-03-22
★ 4440
⚡️An awesome list of the best Termux hacking tools
2026-03-22
Python
★ 5873
An OSINT tool to search for accounts by username and email in social networks.
2026-03-22
Go
★ 2529
Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 28 protocols.
2026-03-22
Shell
★ 1275
Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters.
2026-03-22
Ruby
★ 966
Vagrant VirtualBox environment for conducting an internal network penetration test
2026-03-22
JavaScript
★ 1281
Captfencoder is opensource a rapid cross platform network security tool suite, providing network security related code conversion, classical cryptography, cryptography, asymmetric encryption, miscellaneous tools, and aggregating all kinds of online tools.
2026-03-22
Rust
★ 21587
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
2026-03-22
Python
★ 2529
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
2026-03-22
Vue
★ 918
Fantastic toolkit for CTFers and everyone.
2026-03-22
C++
★ 928
Detect deauthentication frames using an ESP8266
2026-03-22
Python
★ 1005
Unofficial DedSec Project GitHub Repository
2026-03-22
Python
★ 763
Deep Learning models for network traffic classification
2026-03-22
Go
★ 1709
DetectDee: Hunt down social media accounts by username, email or phone across social networks.
2026-03-22
Shell
★ 2037
Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
2026-03-22
Python
★ 2478
Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
2026-03-22
Python
★ 1031
A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.
2026-03-22
Python
★ 1035
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
2026-03-22
C++
★ 2671
ESP32DIV is a multi-purpose wireless testing toolkit powered by an ESP32
2026-03-22
Python
★ 2010
Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access.
2026-03-22
Python
★ 1279
Convolutional neural network for analyzing pentest screenshots
2026-03-22
Python
★ 2036
The RF and reverse engineering framework for everyone. Follow and ★ to show your support!
2026-03-22
Python
★ 12284
fsociety Hacking Tools Pack – A Penetration Testing Framework
2026-03-22
Python
★ 1215
Search WiFi geolocation data by BSSID and SSID on different public databases.
2026-03-22
★ 1500
Attack surface mapping
2026-03-22
Go
★ 1038
Interactive Network Scanner
2026-03-22
★ 1047
Security Apps for Android
2026-03-22
★ 2411
Hacking resources and cheat sheets. References, tools, scripts, tutorials, and other resources that help offensive and defensive security professionals.
2026-03-22
Python
★ 957
30 different honeypots in one package! (dhcp, dns, elastic, ftp, http proxy, https proxy, http, https, imap, ipp, irc, ldap, memcache, mssql, mysql, ntp, oracle, pjl, pop3, postgres, rdp, redis, sip, smb, smtp, snmp, socks5, ssh, telnet, vnc)
2026-03-22
Python
★ 1156
HostHunter a recon tool for discovering hostnames using OSINT techniques.
2026-03-22
TypeScript
★ 1249
Hundreds of Offensive and Useful Docker Images for Network Intrusion. The name says it all.
2026-03-22
Shell
★ 1171
🔨 List all IP ranges from: Google (Cloud & GoogleBot), Bing (Bingbot), Amazon (AWS), Microsoft, Oracle (Cloud), GitHub, Facebook (Meta), OpenAI (GPTBot) and other with daily updates.
2026-03-22
Python
★ 4118
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.
2026-03-22
HTML
★ 1077
Jok3r v3 BETA 2 - Network and Web Pentest Automation Framework
2026-03-22
Python
★ 836
JustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)
2026-03-22
Python
★ 8259
The most powerful Android RPA agent framework, next generation of mobile automation robots.
2026-03-22
Shell
★ 2201
linWinPwn is a bash script that streamlines the use of a number of Active Directory tools
2026-03-22
Shell
★ 1392
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations secure their infrastructure. LME Docs can be found at https://cisagov.github.io/lme-docs/docs/
2026-03-22
Python
★ 37179
🕵️♂️ Collect a dossier on a person by username from thousands of sites
2026-03-22
Python
★ 1165
Malcom - Malware Communications Analyzer
2026-03-22
HTML
★ 794
A tool to quickly identify relevant, publicly-available open source intelligence ("OSINT") tools and resources, saving valuable time during investigations, research, and analysis.
2026-03-22
★ 5174
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
2026-03-22
Go
★ 5396
Modlishka. Reverse Proxy.
2026-03-22
C++
★ 1837
Multi Theft Auto is a game engine that turns Grand Theft Auto: San Andreas into networked multiplayer.
2026-03-22
JavaScript
★ 11778
The best IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability, whois search and more! || 可能是最好用的IP工具箱。轻松检查你的 IP,IP 地理位置,检查DNS泄漏,检查 WebRTC 连接,速度测试,ping 测试,MTR测试,检查网站可用性,查询 Whois 信息等等。
2026-03-22
C
★ 885
NetCat for Windows
2026-03-22
Python
★ 5821
The Network Execution Tool
2026-03-22
Python
★ 5545
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
2026-03-22
Go
★ 1047
Idiomatic nmap library for go developers
2026-03-22
Go
★ 2087
A secure, efficient TCP/UDP tunneling solution that delivers fast, reliable access across network restrictions using pre-established TCP/QUIC/WebSocket or HTTP/2 connections.
2026-03-22
Java
★ 1656
TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.
2026-03-22
Go
★ 1104
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
2026-03-22
Swift
★ 13448
Build your own 'AirTags' 🏷 today! Framework for tracking personal Bluetooth devices via Apple's massive Find My network.
2026-03-22
Python
★ 835
An open source implementation of Apple's Wi-Fi Password Sharing protocol in Python.
2026-03-22
Python
★ 1297
Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.
2026-03-22
PowerShell
★ 2915
A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.
2026-03-22
Shell
★ 2098
Homemade Pwnbox :rocket: / Rogue AP :satellite: based on Raspberry Pi — WiFi Hacking Cheatsheets + MindMap :bulb:
2026-03-22
C
★ 1740
An offline Wi-Fi Protected Setup brute-force utility
2026-03-22
Go
★ 1273
Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.
2026-03-22
Python
★ 2892
(⌐■_■) - Raspberry Pi instrumenting Bettercap for Wi-Fi pwning.
2026-03-22
Python
★ 1482
A Python Library for Graph Outlier Detection (Anomaly Detection)
2026-03-22
Python
★ 1243
pentest framework
2026-03-22
Python
★ 1647
A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.
2026-03-22
★ 1047
The most exhaustive list of reliable DNS resolvers.
2026-03-22
Rust
★ 813
Rustcat(rcat) - The modern Port listener and Reverse shell
2026-03-22
Rust
★ 1134
Active Directory data ingestor for BloodHound Legacy written in Rust. 🦀
2026-03-22
Rust
★ 20345
🤖 The Modern Port Scanner 🤖
2026-03-22
C#
★ 817
Sandman is a NTP based backdoor for hardened networks.
2026-03-22
Shell
★ 1820
Nmap on steroids. Simple CLI with the ability to run pure Nmap engine, 31 modules with 459 scan profiles.
2026-03-22
★ 9023
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
2026-03-22
Python
★ 12505
Scapy: the Python-based interactive packet manipulation program & library.
2026-03-22
Go
★ 1264
Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration
2026-03-22
Shell
★ 4856
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
2026-03-22
Python
★ 1047
Mass scan IPs for vulnerable services
2026-03-22
Rust
★ 923
Dangerously fast DNS/network/port scanner
2026-03-22
★ 966
Social Media OSINT collection containing - tools, techniques & tradecraft.
2026-03-22
Python
★ 1464
SSH-MITM - ssh audits made simple
2026-03-22
C#
★ 3156
SteamKit2 is a .NET library designed to interoperate with Valve's Steam network. It aims to provide a simple, yet extensible, interface to perform various actions on the network.
2026-03-22
C
★ 12215
hydra
2026-03-22
C++
★ 1180
Skyrim mod to play online!
2026-03-22
Python
★ 4744
Dark Web OSINT Tool
2026-03-22
★ 1094
a list of 350+ Free TryHackMe rooms to start learning cybersecurity with THM
2026-03-22
Python
★ 806
A deauth attack that disconnects all devices from the target wifi network (2.4Ghz & 5Ghz), WPA3 also supported (PMF not tested)
2026-03-22
Python
★ 2674
Cyber Security Tool For Hacking Wireless Connections Using Built-In Kali Tools. Supports All Securities (WEP, WPS, WPA, WPA2/TKIP/IES)
2026-03-22
Shell
★ 848
CPlay2Air / Carlinkit Wireless Apple CarPlay Dongle reverse engineering
2026-03-22
Python
★ 1142
Xteam All in one Instagram,Android,phishing osint and wifi hacking tool available