> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

Kiva-SDK

The Kiva SDK is a multi-agent orchestration framework designed for constructing intelligent workflows with support for various workflow patterns, including Router, Supervisor, and Parliament. It features automatic complexity analysis for workflow selection, parallel execution of agent instances, and rich console output for enhanced terminal visualization. Additionally, Kiva allows real-time event streaming for custom handling, enabling the creation of modular applications through its AgentRouter component.

KitPloit_Arsenal

KitPloit_Arsenal is an advanced security search engine that aggregates exploits and security vulnerability news to assist cybersecurity professionals and researchers. Its primary use case is to enhance penetration testing and threat assessment activities by providing a centralized resource for security tools and information. Notable features include a stable release built with Python 2.7 and a user-friendly interface that supports the open-source community.

Kiln

Kiln is an open-source AI development platform designed to streamline the entire AI product lifecycle, enabling team collaboration in areas such as evaluations, prompt optimization, and fine-tuning. Notable features include an intuitive desktop app for multi-user input without coding, automatic generation of evaluation datasets, and integration of document-based retrieval-augmented generation (RAG) capabilities. Kiln emphasizes user-friendly functionality, allowing teams to optimize AI tasks while maintaining Git-native collaboration.

Kansa

Kansa is a modular PowerShell-based incident response framework designed to facilitate data collection across multiple hosts in an enterprise environment for incident response, breach hunting, and establishing environmental baselines. Leveraging PowerShell Remoting, Kansa allows for the execution of user-contributed modules to gather insights efficiently, with support for standalone module execution that enhances data formatting and analysis capabilities. Notable features include its compatibility with PowerShell v2 and later, the ability to run across numerous systems seamlessly, and versatile output formatting options for analysis.

json-lines

The json-lines library is a lightweight tool designed for reading JSON lines (.jl) files, including support for gzipped and corrupted files. Its notable features include the ability to handle broken files by skipping invalid entries while continuing to read, and the option to utilize ujson to enhance decoding performance. This makes it an essential tool for processing and managing JSON line data efficiently in various scenarios.

jefferson

Jefferson is a JFFS2 filesystem extraction tool designed to extract files, directories, symlinks, and device nodes from JFFS2 images. It supports both big-endian and little-endian formats with automatic detection, offers multiple compression methods (zlib, rtime, LZMA, LZO), and incorporates CRC checks to ensure data integrity, making it effective for recovering filesystem data. Notably, it intelligently handles duplicate inode numbers when multiple JFFS2 filesystems are present within a single image.

jacobian-lens

Jacobian Lens (jlens) is a tool designed to visualize and interpret internal activations of language models by mapping residual-stream vectors from any layer to their impact on final-layer predictions. This process involves calculating the average input-output Jacobian over a text corpus, allowing users to analyze how different internal activations contribute to the model's vocabulary outputs. Key features include the ability to fit the lens on custom models and render interactive visualizations that aid in understanding model behavior at various layers and positions.

iothackbot

IoTHackBot is an open-source IoT security testing toolkit designed for automated vulnerability discovery in IoT devices, IP cameras, and embedded systems. It integrates various command-line tools and AI-assisted workflows for network discovery, device-specific testing, firmware analysis, and hardware interaction, featuring capabilities such as ONVIF device scanning, network traffic analysis, and support for debugging interfaces like JTAG. Notable functionalities include automated credential brute-forcing, APK decompilation, and extensive file extraction for comprehensive security assessments.

Invoke-TheHash

Invoke-TheHash is a PowerShell module designed for conducting pass-the-hash attacks using WMI and SMB protocols, leveraging NTLM hash-based authentication without requiring local administrator privileges. Notable features include the functions Invoke-WMIExec for remote command execution over WMI, Invoke-SMBExec for SMB-based execution with configurable SMB versions, and Invoke-SMBEnum for enumeration tasks across shares, groups, users, and active sessions. The tool is compatible with PowerShell versions starting from 2.0 and provides options to customize execution behavior and delays.

intercept

iNTERCEPT is a versatile Signal Intelligence Platform designed for software-defined radio tools, facilitating real-time signal monitoring and decoding across various frequencies. It supports features such as aircraft and vessel tracking, weather satellite image decoding, and Bluetooth scanning, making it valuable for both hobbyist and professional applications in the fields of surveillance and data collection. The platform includes a user-friendly web interface, remote sensor node integration for distributed SIGINT, and offline capabilities for field use, enhancing its utility in diverse signal intelligence scenarios.

insect

Insect is a high-precision scientific calculator designed for evaluating mathematical expressions, manipulating physical units, and performing complex calculations with maximum accuracy. It features support for 30 significant digits, allows unit conversions, provides a variety of mathematical functions, and enables user-defined functions, making it suitable for scientific and engineering applications. The tool also includes helpful error messages and implicit conversions to enhance user experience and streamline calculations.

hunt-scanner

HUNT Suite is a collection of extensions for Burp Suite and OWASP ZAP that assists security testers in identifying common parameters susceptible to various vulnerability classes such as SQL Injection and OS Command Injection. Its primary functionality includes alerting users to these parameters for manual testing and providing a testing methodology organization tool within Burp Suite. Notable features include support for multiple vulnerability classes, a dedicated methodology organization tab, and curated resources for further manual analysis.

HTTP-revshell

HTTP-revshell is a PowerShell-based tool designed for red team exercises and penetration testing, facilitating reverse connections through HTTP/S to exploit victim machines while evading detection from intrusion detection systems (IDS), intrusion prevention systems (IPS), and antivirus solutions (AV). Notable features include SSL support, file upload and download capabilities, Powershell script loading without disk writing, and a payload generator that creates deceptive executable files to aid in evasion tactics.

hermitclaw

HermitClaw is an AI-driven research assistant that autonomously generates content such as research reports, Python scripts, and notes within a designated folder on the user's computer. Its notable features include a personality genome based on keyboard entropy, a memory system that evolves with user interactions, and a continuous thinking loop that allows it to engage with its environment and refine its interests over time. Designed for exploration and observation, users can interact with HermitClaw while it develops a unique body of work reflective of its evolving understanding.

hermes-agent

Hermes Agent is a self-improving AI tool designed for advanced conversational interactions, effectively creating and enhancing skills through a built-in learning loop. Its notable features include a real terminal interface with multiline editing and command autocomplete, support for multiple communication platforms like Telegram and Discord, a closed learning loop that fosters autonomous skill creation, and the ability to run in various environments, including serverless infrastructure. The tool is highly versatile, enabling users to switch between different AI models without code changes, making it suitable for both personal and research-oriented applications.

hdpv_ble

HDPV BLE is a Home Assistant integration designed to support Hunter Douglas PowerView devices via Bluetooth, facilitating control and monitoring of smart window coverings. Notable features include zero configuration setup, compatibility with ESPHome Bluetooth proxy, and comprehensive battery status reporting, providing indicators such as charging state and percentage cover open. The repository is archived, and users are encouraged to refer to a maintained fork for ongoing improvements.

hass-shairport-sync

The Shairport Sync media player for Home Assistant enables seamless control and feedback from a Shairport Sync installation via MQTT integration. It allows users to manipulate audio playback settings, including metadata and album art display, while also supporting advanced features like remote control and power management through smart devices. Notably, it facilitates easy configuration through both GUI and YAML, making it accessible for various setups.

gr-uaslink

gr-uaslink is a GNU Radio out-of-tree (OOT) module that facilitates the integration of MAVLink-controlled Unmanned Aerial Systems (UAS) with GNU Radio. Its primary use case is to demonstrate communication between GNU Radio and external UAS systems, and it includes various example applications to illustrate this functionality. Notable features include its ease of installation and the variety of provided examples that showcase different interaction scenarios.

GOAD

GOAD (Game Of Active Directory) is a penetration testing lab project designed to provide a vulnerable Active Directory environment for cybersecurity professionals to practice various attack techniques. It includes multiple lab configurations, such as GOAD, GOAD-Light, MINILAB, SCCM, NHA, and DRACARYS, each featuring different VM setups and complexities, allowing users to simulate various scenarios safely. Notably, it emphasizes the risks of using the lab in production environments while offering extensive documentation and support for setup and usage.

gitrecon

gitrecon is an OSINT tool designed to extract information from GitHub and GitLab profiles, specifically targeting leaked email addresses in commits. Its notable features include the ability to retrieve GitHub and GitLab profile details, SSH keys, and visually download user avatars while facilitating the saving of results in organized directories. The tool emphasizes user privacy by providing configuration instructions to help mitigate email exposure during repository activities.

gitem

Gitem is a reconnaissance tool designed for gathering comprehensive information about GitHub organizations, repositories, and users, facilitating various use cases such as OSINT and competitive analysis. Notable features include detailed output on organizational and repository metrics, user contributions, and the ability to perform queries at varying levels of granularity, with options for verbosity and parallel processing capabilities. The tool can be easily installed via pip and offers command-line interface functionality for straightforward usage.

git-filter-repo

git filter-repo is an advanced tool for rewriting Git repository history, designed to overcome the limitations and performance issues of git filter-branch. It allows users to perform complex history manipulations using a single-file Python script, and supports the development of custom history rewriting tools through its underlying library. Recommended by the Git project, it emphasizes usability and scalability for a wide range of rewrites and data cleaning operations.

GiantMIDI-Piano

GiantMIDI-Piano is a comprehensive dataset consisting of 10,855 classical piano MIDI files from 2,786 composers, designed for music information retrieval tasks and machine learning applications in music analysis. Its primary use case is facilitating the training and evaluation of algorithms regarding music transcription and generation, with notable features including a curated subset of MIDI files, integration with a high-resolution piano transcription system, and tools for downloading and processing audio files into MIDI format.

frontera-crawler

Frontera-crawler is designed to facilitate the development and implementation of web crawlers by providing specialized logic tailored for the Frontera framework. Its primary use case is to enhance the efficiency and scalability of web crawling operations, allowing for structured data extraction across diverse websites. Notable features include dynamic request scheduling and customizable crawling strategies.