20 Aug 2026
Python
★ 89
Core Net Scanner is a cross-platform Python tool designed for network discovery and open port detection on local IPv4 subnets, applicable for both personal and organizational purposes. Notable features include LAN detection, custom scanning of specific IPs or ranges, HTTP service scanning, real-time traffic inspection, and a comprehensive logging system for detailed output. This tool is specifically intended for lawful use with explicit permission from network owners, ensuring ethical and responsible operation.
20 Aug 2026
JavaScript
★ 10
reCAPTCHA VM is a tool that emulates Google's reCAPTCHA validation mechanism by running its BotGuard engine in a jsdom sandbox environment, enabling the generation of legitimate reCAPTCHA tokens without a browser. It fully supports reCAPTCHA v3 token minting and provides a scoring mechanism to evaluate token legitimacy, while also offering a proof-of-concept for reCAPTCHA v2 that demonstrates the anchor flow and audio challenge URL capture. Key features include real network calls to Google's API and an in-depth implementation of the VM's bytecode interpretation.
20 Aug 2026
Rust
★ 204
Hacksguard is a high-performance, multi-threaded Terminal UI (TUI) static analysis tool designed for SOC analysts, threat hunters, and reverse engineers to analyze Portable Executable (PE) files. Key features include automatic risk scoring based on multiple heuristic axes, integrated YARA scanning capabilities for threat detection, deep inspection of PE format details, and an interactive dashboard for efficient analysis within the terminal. Additionally, it offers functionality for auto-decoding strings, built-in disassembly of opcodes, and can operate in CLI mode for automation in CI/CD environments.
20 Aug 2026
Java
★ 18
ECD++ is a fork of the Enhanced Class Decompiler (ECD) designed for decompiling Java class files into readable source code. Its primary use case is to assist developers in analyzing and understanding compiled Java applications by providing improved decompilation capabilities. Notable features include support for integration with Eclipse, multiple download sources (GitHub, Jitpack, SourceForge), and regular updates to enhance functionality and performance.
20 Aug 2026
Python
★ 19
Yuri is a decompiler and compiler specifically designed for the Yu-Ris engine, featuring support for parallel processing. Its primary use case is facilitating the decompilation and compilation of game files from various versions of the engine, including both public and commercial releases. Notable features include tools for text extraction and translation, such as `patch_text.py` for editing dialogue in .yuri files and `gbk.py` for modifying text encoding to support Chinese translations.
20 Aug 2026
TypeScript
★ 27
Listary Keygen is a Windows GUI tool designed for activating the Listary Pro license using a single-click process. It employs reverse engineering techniques to bypass the official license verification system, allowing users to generate and write a valid license key directly into the application's configuration file. Notable features include automatic key generation, backup of existing settings, and a straightforward user interface for seamless activation.
20 Aug 2026
TypeScript
★ 2619
JS Reverse MCP is an AI-native JavaScript reverse engineering server designed to enhance AI coding assistants with continuous debugging and analysis capabilities for web JavaScript behavior. It features advanced tools for breakpoint management, network and WebSocket analysis, and browser state replay, while also incorporating anti-detection mechanisms to navigate strongly protected sites seamlessly. The tool organizes script execution and data handling specifically for AI agents, enabling them to perform sophisticated tasks like locating scripts, saving sources, and reproducing complex web interactions.
20 Aug 2026
Rust
★ 34
fnprint is a binary analysis tool that uniquely identifies functions in stripped executables by analyzing their behavioral side effects rather than relying on byte signatures or control-flow graphs. It emulates function execution with fabricated inputs to generate behavior-based fingerprints, allowing for more resilient matches across different compiler optimizations and versions. Key features include indexing known binaries for function identification, differential analysis to detect behavioral changes between builds, and a triage capability to assess potential vulnerabilities based on function behavior comparison.
20 Aug 2026
TypeScript
★ 32
ReconGPT serves as a robust tool for passive reconnaissance, allowing security analysts to assess an authorized attack surface using corroborated public information while avoiding active scanning. Its interface is designed as a casefile that facilitates the entire investigative process, from target selection to evidence collection, with features like live telemetry for monitoring progress, an evidence explorer for detail inspection, and a report generation capability that preserves the context and limitations of findings. Notably, ReconGPT emphasizes evidential quality and offers insights into risk and data provenance, enabling analysts to effectively distinguish between validated evidence and inferences.
20 Aug 2026
Python
★ 37
Metawarc is an indexing tool that catalogs WARC collections into a versioned DuckDB database equipped with Parquet sidecars, enabling structured querying, metadata extraction, and payload export. Notable features include support for immutable source archives, atomic publication processes, typed queries accessible via CLI and REST API, and local replay capabilities similar to the Wayback Machine. The tool is designed for efficient analysis and manipulation of web archive datasets, facilitating incremental updates and recovery operations.
20 Aug 2026
★ 457
Cyberleek is a research tool focused on analyzing and verifying the authenticity of leaks related to the anticipated GTA VI gameplay. It consolidates evidence and critical research findings, emphasizing the distinction between genuine community research and false claims propagated by unverified sources. Notable features include detailed analysis of gameplay videos and an official Discord community for collaboration and discussion on leak verification.
20 Aug 2026
Python
★ 674
Cybermes is an advanced autonomous security research framework designed for offensive security tasks, including bug bounty hunting and red teaming. It features over 50 specialized modules for in-depth reconnaissance, attack surface analysis, and vulnerability validation, leveraging a unique integration of modern LLM reasoning and automated workflows. Notable capabilities include dynamic attack planning, multi-source knowledge retrieval, and programmatic validation of findings to ensure zero false positives.
20 Aug 2026
Python
★ 328
Consortium is a modern, extensible command and control (C2) framework that supports both asynchronous multi-client interactions and language-agnostic listener-agent designs, enabling users to develop custom agents and listeners efficiently. Key features include a robust REST API for automation, role-based access control for user management, and modular architecture that allows for extensive customization and collaboration among users. Currently in the alpha phase, the framework emphasizes a high degree of flexibility while still under rapid development.
20 Aug 2026
★ 18
The Roblox Robux Hack Script 2026 is a tool designed to exploit the developer exchange API of Roblox, enabling users to transfer Robux from compromised developer accounts. Its primary use case is the automated scanning for vulnerable accounts and facilitating stealthy transfers of Robux in small increments to avoid detection. Notable features include the ability to export scanned account lists to CSV, support for accounts with at least 10,000 Robux, and an operational stealth mode to minimize the risk of detection by Roblox.
20 Aug 2026
★ 30
The Roblox Robux Generator 2026 is a tool designed to add Robux to any Roblox account through the exploitation of a group payout vulnerability, claiming to facilitate the addition of 400–10,000 Robux per day without requiring user passwords. It supports both Roblox Premium and free accounts, necessitating only the account username and a verification step to mitigate abuse. Notable features include compatibility with Windows 10/11, and the ability to function without needing root or jailbreak access.
20 Aug 2026
Objective-C
★ 11
darksword-kexploit is an Objective-C tool designed to facilitate the execution of the DarkSword kernel exploit on iOS devices running up to version 26.0.1 via a straightforward Windows setup process. Notable features include a clear, step-by-step interface suitable for non-technical users, easy integration of local release files, and basic logging to monitor progress. The tool simplifies the requirements for successfully running the exploit by guiding users through connection and configuration steps.
20 Aug 2026
HTML
★ 11
WireTapper is a tool designed for detecting and mapping nearby wireless signals, including Wi-Fi networks, Bluetooth devices, IoT devices, and CCTV cameras. Its notable features include Wi-Fi detection with detailed information, Bluetooth scanning, and signal visualization on a user-friendly map interface, enabling users to gather intelligence from their environment effectively. The tool is intended for responsible use in compliance with local privacy laws and regulations.
20 Aug 2026
Shell
★ 25
h3-cli is a command-line interface designed for seamless interaction with the Horizon3 API, enabling users to schedule and execute autonomous penetration tests via NodeZero, as well as monitor their status and access detailed reports. Notable features include comprehensive documentation for installation and usage, alongside capabilities to run and manage a locally hosted MCP Server that integrates NodeZero’s functionalities into development and security workflows.
20 Aug 2026
HTML
★ 263
The Flipper Zero Evil Portal tool transforms a Wi-Fi development board into a phishing access point, serving a fake login screen to connected users. It captures user credentials and logs them onto the SD card, functioning as an educational demonstration for learning about Wi-Fi exploits and programming. Notable features include compatibility with both official and unleashed firmware, easy installation via pre-built app files, and customizable HTML login screens.
19 Aug 2026
Python
★ 33
Safer Dependencies is a security tool designed to enhance the integrity of package installations in AI-assisted coding environments like Claude. It automatically intercepts package addition requests to perform checks for known vulnerabilities, maintainability, and risks such as typosquats, while ensuring that only safe versions are installed across multiple ecosystems including npm, PyPI, and Maven. Notable features include its proactive blocking of vulnerable installations, automatic correction of risky dependencies, and a streamlined integration that operates in the background without user intervention.
19 Aug 2026
★ 14
password manager for Windows — LastPass with install and config notes. Store credentials securely with autofill across browsers and desktop apps. Whole application surface is usable — integrations and exports included.
19 Aug 2026
★ 18
Hide.me · VPN client. Encrypt traffic, switch regions and protect sessions on public Wi-Fi. Total feature availability — professional edition behavior on desktop.
19 Aug 2026
Python
★ 51
Wazuh-MCP-Server is a defensive blue team framework designed to integrate with Claude Desktop or any MCP client, serving as a complement to offensive security tools. It provides access to over 100 SOC tools, including multi-provider threat intelligence, alert enrichment, and advanced threat correlation capabilities using the MITRE framework. Notable features include a modular architecture, a variety of transport options for communication, and extensive configuration options for integrating with Wazuh SIEM and various threat intelligence sources.
19 Aug 2026
Pascal
★ 669
Token Universe is a sophisticated tool designed for experimentation with Windows security mechanisms, allowing users to create, view, and modify access tokens, manage Local Security Authority, and spawn processes under varying privilege levels. Its notable features include comprehensive token functionality such as user logon attempts, token editing capabilities, and access checks, making it suitable for security researchers and developers focused on Windows environment security analysis. The tool supports functionality across a broad spectrum of Windows versions, from Windows 7 onwards.
19 Aug 2026
TypeScript
★ 26
The `@sourceloop/vault` is a LoopBack 4 extension that integrates with HashiCorp's Vault, providing a simplified interface for secret management in Node.js applications. It enables developers to easily connect to Vault by configuring endpoint and authentication credentials, and allows access to various Vault operations through the injected `vaultConnector`. Notable features include seamless configuration updates with a reconnect method and comprehensive support for the capabilities of the underlying `node-vault` client.