> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

PulsepointScraperV2

PulsepointScraperV2 is a web-based tool designed to scrape emergency incident data from pulsepoint.org and provide notifications based on user-defined conditions. Its primary use case involves monitoring specific locations for various incident types, with customizable filters and push notification support through services like Pushover. Notable features include a web interface for real-time monitoring and configuration, the ability to manage API keys, and a PulsePoint DB subproject for comprehensive data collection and analysis across multiple agencies.

protofuzz

ProtoFuzz is a versatile fuzzer designed for testing Google’s Protocol Buffers formats by automatically generating fuzzing cases from the format definitions. Its primary use case involves creating and manipulating binary objects based on user-defined Protocol Buffers messages, while supporting dependencies between fields to ensure valid data relationships. Notable features include the capability to generate diverse input variations and integrate custom dependency logic, enhancing testing scenarios for software relying on Protocol Buffers serialization.

PowerUpSQL

PowerUpSQL is a tool designed for SQL Server discovery and auditing, enabling users to perform privilege escalation and execute post-exploitation actions such as OS command execution during internal penetration tests and red team exercises. Its notable features include auditing weak configurations, facilitating SQL Server inventory for administrators, and offering a suite of functions for common threat hunting tasks related to SQL Server environments.

Powershellery

Powershellery is a collection of PowerShell scripts designed for various hacking tasks. Its primary use case is to facilitate penetration testing and security assessments through automated script execution. Notable features include streamlined functions for common hacking techniques and customizable scripts to enhance user efficiency in security evaluations.

powershell-reverse-tcp

The PowerShell Reverse TCP tool facilitates bidirectional communication between a client and a remote host, enabling the remote host to execute commands on the client system. Designed primarily for educational purposes, it features multiple shell implementations using Invoke-Expression and process pipes, and includes a methodology for script obfuscation to evade detection by security systems. Users can customize IP addresses and port numbers, while future updates aim to enhance shell optimization further.

PowerShell

NetSPI PowerShell is a collection of PowerShell scripts designed for penetration testing and security assessments. Its primary use case lies in automating tasks related to vulnerability scanning and exploitation within security engagements. Notable features include utility scripts for reconnaissance, enumeration, and reporting, facilitating efficient security analysis for practitioners.

petals

Petals is a distributed framework that facilitates running and fine-tuning large language models like Llama 3.1 and BLOOM from personal computers or Google Colab environments. The tool supports BitTorrent-style model layer sharing, enabling users to achieve inference and fine-tuning speeds up to 10 times faster than traditional offloading methods. Notable features include support for various cutting-edge models, a community-driven GPU sharing system, and the ability to configure private swarms for enhanced privacy.

PenTesting-Scripts

PenTesting-Scripts is a collection of utilities designed for penetration testing, primarily facilitating the encoding of PowerShell commands for execution in a Linux environment. A notable feature includes the ability to convert PowerShell one-liners to Base64 format, enabling stealthy execution of scripts that can be particularly useful for bypassing security measures.

PDMX

PDMX is a large-scale, open-source dataset containing over 250,000 public domain MusicXML scores designed to support symbolic music processing while mitigating copyright issues. It includes the `MusicRender` extension of the MusPy library, which facilitates the handling of MusicXML files and captures additional musical details not available in MIDI format. Notable features include the availability of various file formats (MXL, PDF, MIDI) and a subset directing users to songs with confirmed valid licenses.

patent_mcp_server

The USPTO Patent & Trademark MCP Server provides a comprehensive backend for accessing various United States Patent and Trademark Office data through multiple APIs, including full-text patent and trademark searches. Key features include access to prosecution history, bulk datasets, and real-time trademark status, supporting complex queries for patent clearance, research, and documentation retrieval. Additionally, the server can operate locally or over HTTP, facilitating flexible integration with applications like Claude Desktop and Claude Code.

pager-sec

pager-sec is a research project aimed at highlighting and addressing security vulnerabilities in medical pager systems, which often transmit sensitive health information without encryption. It demonstrates the ease of intercepting and decoding pager messages using affordable hardware like SDRs, and provides a proof of concept for enhancing pager security through practical solutions. Notable features include the use of software-defined radio for message interception and an Arduino-based implementation to illustrate security improvements.

OWASP-Xenotix-XSS-Exploit-Framework

OWASP Xenotix XSS Exploit Framework is a sophisticated tool designed for detecting and exploiting Cross Site Scripting (XSS) vulnerabilities. It boasts zero false positive scanning through its Triple Browser Engine and features over 1500 distinct XSS payloads, facilitating both vulnerability detection and WAF bypass. Additionally, it includes a comprehensive information gathering module and offensive XSS exploitation capabilities aimed at penetration testing and proof of concept development.

OpenViking

OpenViking is an open-source context database designed for AI agents, enabling them to manage memories, resources, and skills through a virtual filesystem accessed via the `viking://` protocol. Its notable features include tiered content processing that optimizes data loading based on task requirements, deterministic context manipulation akin to traditional file systems, and observable retrieval paths that enhance debugging capabilities. This tool aims to streamline interaction with context data, making it intuitive for AI-driven applications.

OpenManus

OpenManus is a versatile framework designed to facilitate the development of AI agents without the need for an invite code. Its primary use case revolves around simplifying the implementation of agent-based solutions for various applications, enhanced by features such as seamless installation methods and ongoing support for reinforcement learning optimizations through the OpenManus-RL project. The tool's user-friendly design encourages contributions and feedback from its user community.

opendrop

OpenDrop is an open-source command-line tool that enables file sharing across devices using the Apple AirDrop protocol over Wi-Fi, primarily targeting compatibility with Apple devices on iOS and macOS. Notable features include the ability to send both files and web links, the use of extracted AirDrop credentials for contacts-only mode, and operational support on macOS and Linux systems with an appropriate Wireless Direct Link implementation. The tool is experimental and derives from reverse engineering efforts, thus may not support all AirDrop features or future updates.

openairplay

OpenAirplay is a Python-based implementation of the Apple Airplay client, designed to enable Linux users to stream multimedia content to Airplay receivers, such as Apple TV, from their desktop. Key features include the ability to stream desktop screens, send images, play videos, and stream music, all with a user-friendly system tray interface akin to that of OSX. However, the project is no longer under active development and is seeking contributors to enhance its functionality and compatibility across different operating systems.

openai-mcpkit

MCPKit is a framework for building authenticated Model Context Protocol (MCP) servers that facilitate the integration of proprietary data into ChatGPT, ensuring compliance with enterprise authentication protocols. It offers customizable blueprints with support for multiple programming languages, authorization patterns, and sample data, making it suitable for various industries such as finance, healthcare, and e-commerce. Notable features include scaffolded server implementations, integration with OIDC-compliant providers like Auth0, and a structured logging system for enhanced security and operational monitoring.

open-source-rover

The JPL Open Source Rover is a scaled-down, open-source robotic platform that emulates the six-wheel design of Mars rovers, ideal for mechanical engineering education and research in rugged terrains. It features a Rocker-Bogie suspension system, differential pivot for weight distribution, and 6-wheel Ackerman steering, all powered by a Raspberry Pi for customization and easy interfacing. Designed from consumer off-the-shelf components, it offers high customizability and performance, making it accessible for robotics enthusiasts without prior experience.

onyx

Onyx is an open-source AI platform designed as an application layer for large language models (LLMs), enabling advanced functionalities such as retrieval-augmented generation (RAG), web search, and code execution. It supports over 50 indexing-based connectors and allows users to create custom AI agents, generate documents, and interact with external applications, all of which can be easily deployed in various environments including Docker and Kubernetes. Notable features include deep research capabilities, voice interaction, and image generation, making it a versatile solution for AI-driven applications.

octotools

OctoTools is an agentic framework designed to facilitate complex reasoning through a range of extensible tools. Its primary use case involves enabling users to leverage different large language models (LLMs) with integrated support for various backends such as Azure OpenAI and model-specific architectures like Ollama and LiteLLM. Notable features include a comprehensive Python package, visualization capabilities, and extensive documentation, along with a strong community presence through Slack and GitHub support.

OBLITERATUS

OBLITERATUS is an advanced open-source toolkit designed for the mechanistic interpretability of large language models, specifically focusing on the identification and removal of refusal behaviors without the need for retraining. It employs a range of techniques for abliteration, allowing researchers to visualize and manipulate internal model representations while contributing to a crowd-sourced dataset that enhances future understanding of model alignment and behavior. The tool features a user-friendly Gradio interface and a comprehensive Python API, facilitating both casual use and in-depth analysis for researchers.

nanochat

nanochat is an experimental framework designed for training large language models (LLMs) on a single GPU node, emphasizing simplicity and customizability. It covers all major phases of LLM development—tokenization, pretraining, fine-tuning, evaluation, and inference—allowing users to efficiently train models like GPT-2 at significantly reduced costs. Key features include automatic hyperparameter optimization based on a single complexity setting, a leaderboard for tracking training performance, and streamlined CLI interaction for testing the trained models.

nanobot

nanobot is a self-hosted, open-source AI agent framework designed for personal use, implementing functionalities in a lightweight Python environment. It operates through a web UI, terminal, or various chat applications, allowing integration with multiple tools and platforms while providing features like long-term memory, scheduled automation, and model routing. Notably, nanobot supports an OpenAI-compatible API and can connect with messaging services such as Telegram and Discord, enhancing its usability across different communication channels.

multivac

MULTIVAC is a system developed under DARPA's ASKE program aimed at automating the extraction and integration of scientific knowledge into a semantic knowledge graph for enhanced modeling applications. It specifically focuses on the domain of epidemiological research, utilizing a Generative Adversarial Network (GAN) to train an expert query generator that facilitates accelerated scientific exploration through the interpretation of existing models and data. Notably, the system incorporates a "human-in-the-loop" approach to ensure responsiveness to researchers' needs during its operation and training.

mlflow

MLflow is an open-source AI engineering platform designed for managing and deploying production-quality applications involving agents, large language models (LLMs), and machine learning (ML) models. It offers a comprehensive suite of features, including observability, evaluation, prompt management, and optimization, all aimed at streamlining the workflow for AI production while optimizing costs and accessing models and data. With its straightforward setup and support for multiple programming languages, MLflow enables seamless integration and operational monitoring capabilities for AI developers and organizations.