22 Aug 2026
Python
★ 11
CRIMENET is an open-source knowledge graph that documents relationships among criminal organizations globally, leveraging multi-language Wikipedia data through a sophisticated LLM pipeline. It features a comprehensive dataset with over 4,500 organizations and nearly 11,000 relationships, all traceable to specific Wikipedia revisions, allowing for in-depth queries about criminal networks and history via a natural language interface called Ask CRIMENET AI. This tool offers the ability to explore organizational connections, historical contexts, and activity periods while ensuring information integrity through auditable sourcing.
22 Aug 2026
TypeScript
★ 19
Ahtapot is an IOC (Indicators of Compromise) analysis extension that enables users to perform rapid and secure threat assessments directly from their browser. Its primary use case is to analyze various security indicators, such as IP addresses, domains, and hashes, leveraging multiple threat intelligence sources with AI-powered analysis capabilities. Notable features include integration with three AI providers, smart caching for analysis results, customizable provider ordering, and a fully responsive user interface.
22 Aug 2026
Rust
★ 13
OXIDE is a precision-forged vulnerability scanner developed in Rust, designed primarily for authorized penetration testing and security research. It features a unique combination of traditional scanning methods and machine learning-based anomaly detection, along with integrations for tools like Burp Suite, and offers a modular architecture for extensibility. Notable features include a headless DOM, WAF evasion capabilities, and enhanced security with an embedded TLS certificate, making it suitable for use in both lab environments and real-world assessments.
22 Aug 2026
Python
★ 31
BirdShot is an offline-first CLI and local web UI tool designed to streamline and standardize hardware research workflows for lab-owned Flock devices. It enables users to organize device states, work orders, logs, and evidence collection across various research phases, ensuring repeatable and authorized testing in controlled environments. Notable features include integration with local service checks, media validation, and seamless management of related evidence within a structured framework tailored for comprehensive device and deployment research.
22 Aug 2026
Python
★ 10
IndustrialXPL-Forge (IXF) is an extensive Python-based security assessment and exploitation framework designed specifically for Operational Technology (OT), Industrial Control Systems (ICS), and related environments. It encompasses the entire attack lifecycle from reconnaissance to reporting, and it features over 1,190 modular tools, support for more than 50 protocols, and extensive integration with the MITRE ATT&CK for ICS framework, along with a significant library of vulnerabilities, offering a comprehensive resource for cybersecurity professionals in the industrial sector.
22 Aug 2026
Python
★ 21
The lldp tool is a Mythic C2 profile designed for peer-to-peer communication utilizing IEEE 802.1AB (LLDP), allowing covert data transmission within Organizationally Specific TLVs. It operates at Layer 2, requiring agents to be within the same broadcast domain, and features customizable OUI settings for blending with vendor-specific LLDP traffic. Key functionalities include HTTP/HTTPX agent egress for bridging to the Mythic server and enhanced security through configurable encryption modes and key exchange mechanisms.
22 Aug 2026
PHP
★ 12
KrazePlanetCTF is an open-source web security training platform that features over 260 interactive challenges within isolated per-user sandboxes, enabling hands-on learning for cybersecurity professionals. Its primary use case is to facilitate practical training in web security through real-world scenarios, while notable features include Docker-based deployment and easy management via command-line tools for viewing logs and controlling the platform's state.
22 Aug 2026
Python
★ 405
Bountyforge is a comprehensive pentesting tool designed to facilitate automated vulnerability assessments across various platforms, including web APIs, smart contracts, and infrastructure. It employs eight parallelized security agents that systematically evaluate different attack vectors, generating deduplicated and CVSS-scored findings formatted into submission-ready reports for popular bug bounty platforms. Notable features include local tooling orchestration, multi-chain smart contract auditing, and isolated cloud pentesting environments, providing flexibility and efficiency for security professionals.
21 Aug 2026
The mcp-turso-cloud is a Model Context Protocol (MCP) server designed for seamless integration with Turso databases to enhance interactions with large language models (LLMs). It features a robust two-level authentication system for organization and database operations, allowing users to execute various database management tasks such as creating, listing, and querying databases and tables, while maintaining security through proper separation of read-only and destructive query executions. Notably, it supports vector searches and utilizes customizable database tokens for secure, efficient access management in a structured environment.
21 Aug 2026
DeepSeek Harness (`dsh`) is an open-source agent framework designed for spatiotemporal composability, leveraging a plugin architecture powered by Cordis. Primarily intended for developers, it enables easy web interface deployment and supports rapid iteration with potential compatibility-breaking changes. Key features include a customizable Web UI, community support through GitHub Discussions and Discord, and straightforward setup instructions for both npm and source installations.
21 Aug 2026
Python
★ 11
NetWatch is a local-first visibility tool designed for IT admins and small security teams to monitor and assess changes within their authorized local networks. This tool provides a dashboard for asset discovery, TCP service exposure review, and maintaining context around significant changes, while emphasizing the importance of operating within authorized boundaries. Notable features include a repeatable workflow for local asset awareness, integration with Docker for easy deployment, and a focus on defensive visibility rather than exploitation.
21 Aug 2026
Go
★ 38
Boggart is a low-interaction experimental honeypot designed for mimicking specific host behaviors to attract and analyze potential threats in a home lab environment. Its notable features include a customizable configuration via `config.yaml`, support for multiple open ports (including a honeypot, dashboard, and API service), and deployment capabilities using Docker. This tool serves primarily for educational and experimental purposes, providing insights into attacker behaviors without being intended for professional or industrial use.
21 Aug 2026
Vue
★ 15
DetectionForge is a specialized detection engineering environment that enables security engineers to create, validate, and test detection rules specifically for the LimaCharlie platform. Key features include syntax checking, historical testing with LimaCharlie’s replay capabilities, and an intuitive workflow for iterative rule development using a modern Progressive Web Application architecture built with Vue 3 and TypeScript. The tool emphasizes seamless integration with LimaCharlie, allowing for comprehensive impact analysis and configuration management.
21 Aug 2026
JavaScript
★ 29
The ExploitDB MCP Server is a Model Context Protocol server designed to provide AI assistants with access to security exploit and vulnerability data from ExploitDB. Its primary use case is to enhance cybersecurity research and threat intelligence through functionalities like searching for exploits by various criteria, retrieving detailed exploit information, and tracking newly added exploits, all while supporting automatic database updates to ensure up-to-date information. Notable features include comprehensive search and analysis tools, statistics on exploit distribution, and batch retrieval capabilities for efficient data access.
21 Aug 2026
Go
★ 74
The Converged Security Suite is a comprehensive toolkit designed to implement and validate security features for Intel platforms, including Intel Trusted Execution Technology and Intel Boot Guard. Its primary use case involves providing both testing and provisioning capabilities for various Intel security features, along with support for some AMD Secure Processor functionalities. Notable features include dedicated test suites for validation and the ability to provision multiple security technologies, ensuring enhanced platform integrity and security compliance.
21 Aug 2026
Python
★ 222
IDA Skill is an AI-powered tool that enables automated malware analysis using IDA Pro, mimicking the capabilities of human security analysts. It features automatic identification of malicious behavior, code functionality understanding, key information extraction, and threat indicator localization, enhancing malware investigation efficiency. Notable components include REAI for AI function analysis and FindCrypt for detecting encryption algorithms, facilitating comprehensive and advanced threat assessment.
21 Aug 2026
Python
★ 14
The ANY.RUN SDK is a Python client library designed to interact with the ANY.RUN REST API, facilitating automated malware analysis and threat intelligence workflows. It provides features for file and URL submissions to an interactive sandbox, real-time monitoring of analysis progress, and access to comprehensive threat intelligence, including IOC searches and feeds. Notable functionalities include support for both synchronous and asynchronous operations, along with built-in exception handling and detailed reporting capabilities.
21 Aug 2026
C++
★ 93
NotDec is a WebAssembly decompiler and static analysis framework that focuses on enhancing decompiler techniques through variable recovery and structural analysis. Its primary use case is to facilitate detailed type recovery experiments, allowing developers to gain insights into the inner workings of decompilation processes while improving their algorithms iteratively. Notable features include customizable environment variables for debugging type recovery and a robust setup for experimenting with LLVM and C code generation.
21 Aug 2026
Kotlin
★ 17
FitFace Studio is an Android application designed for customizing Fit3 (SM-R390) watch faces by allowing users to browse, edit, and install them directly to their watches via Bluetooth. The tool features a catalogue for searching and sorting watch faces, a layout editor for altering backgrounds and widgets, and does not redistribute watch face packages; instead, it edits the original binary directly. With functionalities such as widget movement, color adjustments, and real-time validation before installation, it facilitates a user-friendly interface for personalizing watch faces without the need for app re-signing or installation on the device.
21 Aug 2026
C++
★ 11
Onyx External ESP is a tool designed for emulation on Android x86_64 architecture, specifically for the MuMu Player, providing users with external ESP (Extra Sensory Perception) features such as skeletons, snaplines, bounding boxes, health indicators, and off-screen markers. Primarily aimed at educational purposes, it serves as a foundational codebase for understanding and modifying ESP implementations in games, though it currently lacks support for physical ARM devices and certain advanced features due to game obfuscation. The tool includes automated batch scripts for straightforward building and deployment, enhancing the user experience for developers and researchers.
21 Aug 2026
C++
★ 733
Metaforce is a reverse-engineered reimplementation of the video game Metroid Prime, currently in alpha state and focused on providing a native, cross-platform gaming experience on Windows, macOS, and Linux. Its notable features include support for multiple graphics APIs (D3D12, Vulkan, OpenGL, Metal), a console logging option, and developer functionalities such as world/area warping, enabling users to explore and debug the game more effectively. The project is supported by ongoing contributions from its decompilation counterpart, enhancing bug fixes and new implementations.
21 Aug 2026
Swift
★ 21
swift-dwarf is a Swift library designed for parsing binary files to extract DWARF debugging information from Mach-O and ELF binary formats. It utilizes MachOKit for Mach-O files and ELFKit for ELF files, supporting various DWARF sections such as `.debug_info`, `.debug_str`, and `.debug_line`. The tool provides interfaces to easily access string tables, abbreviation sets, and compilation units, facilitating a streamlined debugging process for developers working with low-level binaries.
21 Aug 2026
★ 85
The SOMtoday REST API provides comprehensive documentation for integrating with the SOMtoday educational management platform. Its primary use case is to facilitate access to various educational data endpoints, including student information, grades, schedules, and homework assignments via RESTful API calls. Notable features include authentication mechanisms, support for fetching specific student and school data, and options for accessing data in iCalendar format.
21 Aug 2026
Java
★ 117
smali/baksmali is an assembler and disassembler for the dex format utilized by Android's Dalvik Virtual Machine, enabling users to manipulate Android bytecode effectively. It supports comprehensive features of the dex format, including annotations and debugging information, while providing a command line interface for building and testing. The tool is a maintained fork of the original smali project, ensuring ongoing updates and support through Google Maven distribution.
21 Aug 2026
Shell
★ 13
The `rockchip-npu-notes` repository provides comprehensive reverse-engineering documentation for the Rockchip RK3588 Neural Processing Unit (NPU), focusing on the hardware's register-command interface and its integration with the mainline `rocket` DRM-accel driver. It includes subsystem-organized notes detailing machine parameters, register offset maps, precision encodings, and operational quirks, aiming to assist users constructing custom compute solutions using the RK3588. Notable features include empirical observations tagged with their verification methods, alongside in-depth explanations of NPU architecture and operational capabilities.