> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

sentinel-attack

Sentinel ATT&CK is a tool designed to facilitate the deployment of a threat hunting capability utilizing Sysmon logs within Azure Sentinel, aligned with the MITRE ATT&CK framework. It includes a Sysmon log parser that is mapped to the OSSEM data model and provides a modular XML configuration for effective log analysis. Users must perform tuning and trialing to optimize the tool's effectiveness for production environments.

self-hosted-ai-starter-kit

The Self-hosted AI Starter Kit is an open-source Docker Compose template that enables the rapid establishment of a local AI and low-code development environment. It integrates the n8n low-code platform with essential AI tools such as Ollama for LLMs and Qdrant for vector storage, allowing users to create AI workflows for tasks like appointment scheduling and document summarization with enhanced security. Notable features include support for various GPU configurations and a comprehensive setup guide to streamline deployment.

secret-regex-list

The Secret Regex List is a collection of regular expressions designed for detecting and extracting secret API keys and sensitive information from textual data. Its primary use case is to integrate these regex patterns into Python code to facilitate the identification of various types of credentials, such as API keys for popular platforms and private keys. Notable features include a comprehensive set of regex patterns for different providers, ensuring broad coverage for security audits and vulnerability assessments.

SecLists

SecLists is a comprehensive collection of security-related lists that serves as an essential resource for security testers during assessments. It includes a variety of list types, such as usernames, passwords, URLs, and fuzzing payloads, all organized for easy access in a single repository. Noteworthy features include installation compatibility with popular penetration testing distributions like Kali Linux and BlackArch, facilitating rapid deployment for testing environments.

scrapers

The Scrapers repository compiles a comprehensive list of web scraping tools, providing links, pros and cons, and facilitating community contributions for maintaining the index. Each tool is categorized by functionality, offering diverse options such as cloud-based scrapers, Python libraries, and AI-driven extractors. Notable features include a detailed Table of Contents for easy navigation and the encouragement of user contributions to enhance the resource.

samlists

Samlists provides a collection of high-quality wordlists optimized for security testing and enumeration tasks, such as locating hidden functionality or brute-forcing URLs. Notable features include recent data sourcing, a scientific approach to wordlist construction that mitigates biases, and sorted entries to enhance the likelihood of successful findings. With automated updates and language-agnostic terminology, these lists are designed for comprehensive and efficient use in cybersecurity assessments.

RunJS

RunJS is an interactive playground for JavaScript and TypeScript that automatically executes code and displays instant results. It is designed for experimentation, learning, and teaching, featuring code completion, type checking, inline documentation, and easy installation of NPM packages. The tool also provides access to Node.js and Browser APIs, making it a versatile environment for developers to create and manage code snippets.

robotframework-libs

The RobotFramework-libs repository provides libraries for testing Android applications using the Robot Framework. Key features include `units.py` for parsing numerical values with units and `adb.py` for interacting with Android devices, facilitating streamlined automation in mobile testing environments.

ReverseEngineeringAndroidMalware

The Reverse Engineering Android Malware tool provides a comprehensive guide for analyzing and deconstructing malicious Android applications, focusing specifically on the identification of Command and Control (C2) servers within these apps. Notable features include a detailed flow of malware analysis from discovery to reverse engineering, illustrated by a case study of SpyNote malware, which serves as a practical example for users. This repository serves as a resource for cybersecurity professionals looking to enhance their skills in Android malware investigation.

reverse-engineering

The "Reverse Engineering" repository provides a curated collection of resources for reverse engineering, primarily aimed at enhancing skills in malware analysis and binary exploitation. It includes links to books, courses, practice challenges, and various tools such as disassemblers and hex editors, making it a comprehensive guide for both beginners and advanced practitioners in the field. Notable features include a categorized compilation of educational materials and practical exercises for real-world application.

RemoveWindowsAI

Remove Windows AI is a PowerShell script designed to eliminate AI features and components from Windows 11 (starting with build 25H2) to enhance user privacy and security. Notable features include disabling various AI-related registry keys, removing AI appx packages, preventing the reinstallation of AI components, and providing options to replace modern applications with classic versions. The script can be run from a PowerShell console and includes a UI for easier interaction.

redhawk

REDHAWK is a software-defined radio (SDR) framework that facilitates the development, deployment, and management of real-time software radio applications. Its primary use case involves creating and composing modular software components into comprehensive waveform applications, supported by a robust integrated development environment (IDE) featuring graphical editors and drag-and-drop functionality. Notable features include multi-instance management, streamlined component testing, and cross-computer deployment capabilities.

RE-Thing

RE-Thing is a comprehensive catalog of reverse engineering and binary analysis tools, primarily focused on Android and Java applications. Notable features include tools for decompiling Android APKs, analyzing bytecode, and binary analysis, such as Angr and Ghidra, enhancing the capabilities for both static and dynamic analysis. This repository facilitates developers and security researchers in their project work by providing curated resources and tool recommendations.

query-translator

Query Translator is a PHP library designed to transform user search strings into a format compatible with various search backends, such as Solr and Elasticsearch. It features a robust error-handling mechanism that generates a detailed syntax tree, allowing for enhanced customization of the query language, including customized term clauses and the ability to modify syntax outputs. This library serves as a foundation for implementing user-friendly query interfaces and is extensible to accommodate various use cases in search query processing.

qu1ckdr0p2

Qu1ckdr0p2 is a tool designed for rapid HTTP/HTTPS hosting of payloads and post-exploitation binaries, primarily for use in penetration testing scenarios such as OSCP and Capture The Flag (CTF) events. Notable features include an alias and search function for simplification of file serving, automatic generation of self-signed certificates for secure connections, and streamlined installation and usage through pip with dynamic alias mappings to facilitate efficient file access.

python-pentest-tools

The dloss/python-pentest-tools repository offers a curated collection of Python-based tools designed for penetration testing, vulnerability research, and reverse engineering. It includes a variety of utilities for network reconnaissance, packet manipulation, and Active Directory enumeration, with notable features such as integration with existing C libraries for enhanced functionality and a focus on tools that prioritize legal compliance. This repository facilitates the work of whitehat hackers by providing efficient tools tailored for ethical hacking scenarios.

python-pentest-tools

The python-pentest-tools repository provides a collection of Python-based utilities specifically designed for penetration testing, vulnerability research, and reverse engineering. Notable features include various tools for network packet manipulation and analysis, subdomain enumeration, and debugging frameworks, all aimed at facilitating the tasks of cybersecurity professionals while promoting legal compliance. The tools integrate with existing C libraries and offer flexible frameworks for testing and exploitation in a user-friendly Python environment.

public-domain-lists

The OpenDNS Public Domain Lists provide datasets comprising the top 10,000 domain names based on query popularity and a random sample of 10,000 domains, both filtered for potential malware use. These lists, updated weekly, serve as valuable resources for researchers and developers to train and test models related to DNS and domain behavior analysis, while clarifying that they do not replace existing public lists.

PScout

PScout is an Android permission mapping tool that enables researchers and developers to analyze the permissions of Android applications by providing essential datasets. Its primary use case is to facilitate the understanding of permission usage and implications in Android apps, making it a valuable resource for security analysis. Notable features include its original research backing, comprehensive datasets, and an open-source license that allows for community contributions.

prog_models

The prog_models package is a component of the progpy Python package, developed by NASA, which integrates various programming models and algorithms. Its primary use case is to facilitate the development and implementation of programming methodologies for advanced scientific computations. Notable features include a variety of modeling techniques and easy integration with other scientific Python packages.

Priv2Admin

Priv2Admin is a security analysis tool designed to interpret Windows OS privileges and their potential impacts on system security, specifically addressing threats to administrator access, integrity, confidentiality, and availability. It prioritizes using built-in commands, PowerShell scripts, and other methods to evaluate an environment's privilege landscape, allowing users to identify and mitigate risks associated with privilege escalation. The tool provides detailed descriptions of various Windows privileges, their implications, and potential exploitation methods via external tools.

Powershell-Tools-and-Toys

The Powershell-Tools-and-Toys repository contains a diverse collection of Powershell scripts designed for educational and research purposes, ranging from harmless pranks to advanced red team tools. Primarily aimed at providing security professionals with resources for authorized security assessments and lab testing, this toolkit features a variety of scripts that illustrate different cybersecurity techniques while emphasizing legal and ethical usage.

plugin-php

The Prettier PHP Plugin is an opinionated code formatter that extends Prettier's functionality to support PHP, allowing developers to enforce consistent coding styles in their PHP code. It utilizes PSR/PER guidelines to shape formatting decisions, though it does not guarantee full compliance, focusing instead on delivering a formatting experience similar to other languages supported by Prettier. This plugin is deemed stable for pure PHP files, with ongoing adjustments for mixed PHP and HTML content.

Playbooks

The Playbooks repository provides a comprehensive set of Incident Response (IR) playbooks and workflows tailored for a Security Operations Center (SOC), structured according to NIST guidelines. It includes detailed sections on preparation, detection and analysis, containment, eradication, recovery, and post-incident activities, along with customer-specific information and required commercial product details. Notable features include organized playbook templates, workflows, and an auto-generated PDF documentation option for audits and client access.

personal-management-system

The Personal Management System (PMS) Backend is a self-hosted web application designed for organizing and managing personal data, functioning similarly to CMS and CRM systems. It offers modules for tracking goals, notes, contacts, passwords, achievements, and schedules, allowing users to customize and extend functionality according to their needs. Notable features include secure password management, a user-friendly interface for personal organization, and the ability to run the application locally on a terminal or Raspberry Pi.