> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

lowlevelprogramming-university

Low-Level Programming University is an educational resource designed to guide users in acquiring skills in low-level programming, particularly in languages like C and Assembly. It provides a roadmap for beginners aspiring to become low-level programmers or Linux kernel engineers, covering essential theories, languages, and applications, as well as recommending practical learning approaches. Notably, it emphasizes the importance of hands-on experience and self-directed projects while acknowledging the declining demand for low-level programming roles in the job market.

lisperati-1000-diy

The Lisperati 1000 is a DIY computer kit that guides users through the construction of a fully operational machine using 3D printed chassis and commercially available components, such as a Vortex Core keyboard and specific battery configurations. Notable features include detailed STL files for custom chassis parts, assembly instructions, and considerations for safe battery handling, making it suitable for hobbyists interested in computer building and customization. Users are advised to possess technical skills, particularly in electrical engineering, to safely complete the project.

learn-chrome-extensions

The "Learn Chrome Extensions" repository serves as a tutorial for developing Chrome extensions using standard web technologies such as HTML, CSS, and JavaScript. Its primary use case includes demonstrating how to enhance Chrome's functionality with tools such as browser actions, bookmarks management, and browsing data manipulation. Notable features include the ability to change icon states dynamically, access browsing history, implement keyboard shortcuts, and utilize desktop capture capabilities.

laravel-zero

Laravel Zero is a micro-framework designed for building command-line applications, leveraging the components of Laravel for a customized experience. It features support for interactive menus, desktop notifications across multiple operating systems, a built-in task scheduler, and a standalone compiler, making it ideal for developers looking to create elegant console applications efficiently. Notably, it also integrates with Collision for enhanced error reporting, ensuring a robust development experience.

KMlink

KMlink is a Stream Deck plugin that facilitates the execution of Keyboard Maestro macros directly from the Stream Deck interface. It fetches and displays a list of all available macros, allowing users to select and execute them seamlessly. Notable features include automatic refresh of the macro list and the ability to add execution parameters for enhanced functionality.

keyhacks

KeyHacks is a specialized tool designed to validate various API keys encountered during Bug Bounty Programs or penetration testing. It offers a comprehensive catalog of API keys and access tokens for numerous services, enhancing the efficiency of security assessments by automating the validation process for these credentials. Notable features include a detailed list of supported API keys from popular platforms, making it an essential resource for security professionals.

js-vuln-db

The js-vuln-db repository provides a comprehensive database of JavaScript engine vulnerabilities, specifically focusing on the V8 engine. It lists various Common Vulnerabilities and Exposures (CVEs) along with their associated features, keywords, and credit to researchers. The primary use case is to identify and analyze security issues in JavaScript environments, allowing developers to improve code safety and engine resilience against exploitation.

jailbreakprompt

The AI Jailbreak Research Project focus on exploring and analyzing AI "jailbreak" prompts to understand and enhance the limitations and ethical boundaries of AI systems in an academic context. The tool facilitates safe experimentation by enabling users to test various prompts with multiple AI models while adhering to strict ethical guidelines. Notable features include a commitment to scientific research only, acknowledgment of original AI contributions, and a collaborative approach to advance the field of AI safety.

IRNotes

IR Notes is a cybersecurity tool designed to analyze Windows Event IDs related to security events and lateral movements within a network. Its primary use case is aiding security professionals in identifying and investigating suspicious activities through a structured log of significant event IDs. Notable features include categorization of logon events, scheduled task management, and detection of unauthorized service behaviors.

iOSAppReverseEngineering

iOS App Reverse Engineering is a comprehensive resource designed to equip iOS enthusiasts, senior developers, architects, and reverse engineers with in-depth knowledge of iOS app reverse engineering techniques. The book is structured into four parts covering essential concepts, commonly used tools, theoretical frameworks, and practical exercises, alongside insights into the iOS file system and architecture. Notable features include a methodological approach to Objective-C and ARM assembly theories, alongside hands-on practices that solidify understanding of reverse engineering processes.

iocs

The Unit 42 IOC repository aggregates various indicators of compromise (IOCs) derived from Unit 42's public reports, primarily aimed at enhancing threat intelligence and network defense strategies. Its notable feature includes a structured collection of IOCs that security analysts and incident responders can leverage to detect and mitigate threats effectively.

InveighZero

Inveigh is a cross-platform .NET tool designed for penetration testing, specifically enabling IPv4/IPv6 man-in-the-middle attacks. Its primary use case involves intercepting and manipulating network traffic to assess vulnerabilities in target systems, making it a valuable asset for security assessments. Notable features include support for both IPv4 and IPv6 networks, enhancing its versatility in various environments.

InfoSec-Black-Friday

InfoSec Black Friday is a curated repository of legitimate discounts and deals for information security tools and software, specifically tailored for the Cybersecurity community during the Black Friday and Cyber Monday sales. The tool emphasizes quality by meticulously vetting each deal for authenticity and relevance, assuring that users have access to genuine offers that enhance their cybersecurity capabilities. Notable features include the removal of questionable deals and the provision of a comprehensive list categorized by infosec-related roles, complete with vendor details and expiry timestamps.

hyperawesome

Hyperawesome is a curated repository of resources for developers using Hyperapp, a lightweight front-end framework. It aggregates official documentation, tutorials, utilities, and example applications to streamline the development process in Hyperapp. Notable features include community links, starter projects, and integration utilities that enhance the framework's capabilities.

HRConvert2

HRConvert2 is a self-hosted drag-and-drop file conversion server that supports 445 file formats and offers advanced features such as Optical Character Recognition (OCR) and automated virus scanning with ClamAV. The tool allows for local file conversions without external dependencies, and it provides a customizable user interface with support for 17 languages and multiple color schemes. It operates securely on a home server, ensuring user privacy with no database or tracking capabilities.

GulfOfMexico

Gulf of Mexico is a novel programming language designed to enhance coding simplicity and readability through unique syntax elements, such as mandatory exclamation marks to terminate statements and an intuitive naming scheme allowing for Unicode characters in identifiers. Its standout features include innovative data declaration types (constants, variables, and their mutable counterparts), mutable data management, and a built-in garbage collector with customizable variable lifetimes. The tool aims to make coding more accessible, particularly for beginners, by incorporating unconventional elements for clarity and ease of use.

Grouper2

Grouper2 is a deprecated repository that serves as a warning about the dangers of long-term nuclear waste, rather than a functional cybersecurity tool. Users are directed to migrate to the Group3r repository for continued development and support. The content emphasizes the need for communication around hazardous materials and their management.

grep-search-for-secret-private-api-or-other-keys

The tool "grep-search-for-secret-private-api-or-other-keys" is designed to identify and extract sensitive keys, tokens, and passwords from codebases using regular expression patterns. Its primary use case is to enhance security by detecting hardcoded secrets that could be exploited by malicious actors. Notable features include a comprehensive list of common key patterns across various platforms and services, enabling automated scanning of repositories for potential security vulnerabilities.

graphql-apis

APIs-guru/graphql-apis is a comprehensive catalog of public GraphQL APIs, serving as a resource for developers seeking to integrate various functionalities such as payment processing, e-commerce solutions, and data analytics into their applications. Notable features of this repository include a structured listing of APIs with corresponding Graph*i*QL interfaces and documentation links, facilitating quick access and testing of each API's capabilities. The tool encourages community contributions through pull requests, fostering an expanding repository of resources.

google-wifi-api

The Google Wifi API repository provides a collection of discovered API endpoints designed for interacting with Google Wifi Routers and OnHub devices. Its primary use case is to enable developers to retrieve status information, manage connected devices, and configure network settings programmatically. Notable features include endpoints for WAN configuration, device status retrieval, and the generation of diagnostic reports, facilitating advanced network management capabilities.

Google-Dorks-Simplified

Google Dorks Simplified provides an educational resource for understanding and utilizing Google Dorks, a technique that leverages advanced search queries to retrieve sensitive or critical information from indexed web content. This tool is primarily aimed at cybersecurity experts, researchers, and enthusiasts who wish to efficiently gather data for various purposes, including vulnerability assessment and competitive analysis. Notable features include collections of useful queries tailored for cybersecurity professionals, bug bounty hunters, and individuals seeking to safeguard their information from unintentional exposure.

github-cheat-sheet

The GitHub Cheat Sheet is a comprehensive collection of both overlooked and well-known features of Git and GitHub, aiming to enhance user productivity and efficiency. It provides quick references for various functionalities, including advanced branch comparisons, issue management, and repository interactions, all while supporting multiple languages. Notable features include keyboard shortcuts, task lists in Markdown, and enhanced Markdown syntax capabilities, making it an essential resource for developers leveraging GitHub in their workflows.

generator

CTX is an AI-powered development toolkit designed to provide comprehensive access to a codebase, enabling enhanced coding support and automation. Its primary use case focuses on facilitating code generation and assistance by leveraging AI capabilities, thus improving developer productivity. Notable features include a robust documentation system, integration with various communication platforms for support, and tools for testing and schema validation, making it a versatile aid for software development.

fuzzdb

FuzzDB is a comprehensive dictionary designed for dynamic application security testing, focusing on identifying vulnerabilities through a vast collection of fault injection patterns and predictable resource locations. It features categorized attack payloads for various types of injection attacks, a discovery module for common resource locations, and regex patterns to analyze server responses, making it an essential tool for penetration testers and security researchers. Its extensive documentation and integration capabilities with tools like OWASP Zap and Burp Suite enhance its usability in crafting effective security test cases and improving overall testing strategies.