> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

javafuzz

Javafuzz is a coverage-guided fuzzer designed for testing Java packages, aimed at identifying errors like unhandled exceptions, logic bugs, and security vulnerabilities through iterative testing with random data. The tool emphasizes robustness by allowing developers to catch expected exceptions and focus on application-level checks while reporting unhandled exceptions and resource usage issues. Notably, it integrates seamlessly with Maven, offering a straightforward setup and execution process for fuzz testing within Java environments.

janusgraph

JanusGraph is a scalable graph database designed for the efficient storage and querying of extensive graph structures, accommodating billions of vertices and edges across distributed systems. It facilitates transactional operations with support for high concurrency, complex traversals, and analytical queries, making it suitable for large-scale data management scenarios. Notable features include integration with various third-party graph visualizers and optimization for multi-machine clusters, enhancing its usability in diverse applications.

JADXecute

JADXecute is a plugin for the JADX decompiler that enhances it with dynamic code execution capabilities, allowing users to run Java code to modify or display components of the jadx-gui output. This tool is tailored for Android reverse engineers, facilitating more efficient analysis of APK files by leveraging standard Java libraries alongside JADX's APIs. Notable features include script examples and a user-friendly interface, inspired by IDAPython, which streamline the reverse engineering process.

ipmi

The zenfish/ipmi toolset is designed for exploring and auditing IPMI (Intelligent Platform Management Interface) systems, facilitating operations such as data retrieval and security assessments. Key features include remote password cracking, ciphers retrieval without authentication, and various probes for gathering authentication and device information with minimal input. The tools are predominantly implemented in Python, emphasizing ease of use while supporting a wide range of security tests tailored for IPMI configurations.

iotdb

IoTDB (Internet of Things Database) is a specialized data management system designed for handling time series data, emphasizing high performance and integration with big data ecosystems like Hadoop and Spark. It offers features such as a flexible deployment strategy, efficient data storage with high compression ratios, and the capability to manage complex data structures with high-throughput read and write capabilities, making it well-suited for industrial IoT applications.

intellij-community

The IntelliJ Community repository serves as the open-source foundation for JetBrains IDEs, including IntelliJ IDEA and PyCharm. Its primary use case is to facilitate development on the IntelliJ Platform, offering source code access, build instructions, and guidelines for contributions. Notable features include support for building from source, a structured approach for obtaining additional Android modules, and ongoing migration to the Bazel build system.

Inspeckage

Inspeckage is a dynamic analysis tool for Android applications that allows users to monitor and modify app behavior during runtime through function hooking within the Android API. Its primary use case centers around security analysis, enabling users to gather detailed information on app permissions, activities, and services, as well as offering various real-time action capabilities like bypassing security measures and modifying app parameters. Notable features include support for a wide array of hooks, location manipulation, and the ability to download APKs and app files, making it a comprehensive solution for Android app security assessments.

insomnium

Insomnium is a fast local API testing tool that is privacy-focused and 100% local. For testing GraphQL, REST, WebSockets and gRPC. This is a fork of Kong/insomnia

indigo

Indigo is a minimalist Jekyll template designed for personal websites and blogs, featuring both light and dark themes. It emphasizes performance, boasting a PageSpeed score of 99 for desktop views, and is easily customizable through the _config.yml file. The template supports Sass and SVG, making it a flexible option for users who seek a simple yet effective online presence.

ImportJSON

ImportJSON is a Google Sheets add-on designed to facilitate the importation of JSON data from any specified URL into spreadsheets using the `=ImportJSON()` function. It supports various methods of data retrieval including standard JSON imports, POST requests, and imports with HTTP Basic Authentication, offering users flexibility and robust functionality to handle diverse data integration needs. Notable features include the ability to import JSON from both web URLs and other sheets, as well as advanced options for script developers to extend the tool's capabilities.

hugo-PaperMod

Hugo PaperMod is a fast and responsive theme designed for the Hugo static site generator, featuring a clean aesthetic and extensive customization options. Its primary use case is to enhance user experience on personal or organizational websites with versatile layout modes, SEO optimization, dark/light theme support, and a multilingual interface. Notable features include an asset pipeline for efficient resource management, client-side search, support for multiple authors, and automated content generation like tables of contents and related post suggestions.

hugo-book

Hugo Book is a lightweight documentation theme designed for the Hugo static site generator, offering a clean and mobile-friendly interface suitable for creating simple book-like documentation. Key features include multi-language support, customizable options with zero initial configuration, handy shortcodes, and native support for light and dark mode, all while operating with minimal reliance on JavaScript. It is particularly useful for users seeking a straightforward setup to compile and present documentation efficiently.

htmls-to-datasette

htmls-to-datasette is a tool designed to index HTML files into a SQLite database for efficient search and visualization, particularly useful for web archiving and clipping. It integrates seamlessly with Datasette, allowing users to serve and query indexed content while optionally storing the HTML data within the database or linking to the original files. Notable features include full-text search capabilities and support for automated indexing through user-defined workflows.

html-text

html-text is a Python library designed to extract and clean text from HTML documents while omitting non-visible elements like styles and scripts. Its primary use case is to provide a more user-friendly text output by normalizing whitespace and intelligently adding newlines, making the extracted text resemble the rendered output seen in web browsers. Notable features include support for both raw HTML and parsed lxml elements, as well as customizable newline handling options for better text formatting.

hidden-char-scanner

Hidden Char Scanner is a tool designed to detect and classify hidden characters in text, including zero-width and control characters, using `Intl.Segmenter` for grapheme segmentation. Its primary use case is to identify suspicious code points that could facilitate confusables, bidirectional spoofing, or obfuscation in code reviews. Notable features include a per-grapheme risk assessment, an annotated preview interface with tooltips, and the ability to export findings as structured JSON for further analysis.

heritrix3

Heritrix is an open-source, web-scale archival-quality web crawler developed by the Internet Archive, designed primarily for collecting and preserving digital artifacts for future research. It features respect for `robots.txt` directives and META nofollow tags, ensuring ethical crawling practices, and offers extensive documentation for configuration and operational guidance, as well as a REST API for integration. The tool is extensible and supports customization through various modules and a comprehensive developer manual.

HarmTrace-Base

HarmTrace Base is a Haskell library designed for the unambiguous representation and manipulation of musical chords. Its primary use case is to serve as a backend tool for applications that require the storage, display, and processing of musical chord data. Notable features include a structured set of types and classes that ensure accurate chord representation according to established musical notation standards.

hackrf-spectrum-analyzer

The HackRF Spectrum Analyzer is a GUI tool designed for utilizing the HackRF One as a dedicated spectrum analyzer. It features automatic restart of settings, easy retuning, peak and persistent displays, high-resolution waterfall plots, and a spur filter to enhance spectrum clarity. It integrates with hackrf_sweep as a shared library, making it optimized for both Windows and Linux environments tailored for RF analysis.

hackershare

Hackershare is an open-source social bookmarking platform designed for hackers and developers, serving as an alternative to popular services like Delicious and Pocket. Its notable features include seamless integration with PostgreSQL and Rails, a Chrome extension for enhanced functionality, and a Docker setup for easy deployment and management. The platform emphasizes community-driven bookmarking, allowing users to efficiently save and share valuable resources.

gvisor

gVisor is an application kernel designed to provide enhanced isolation for containers by creating a strong boundary between applications and the host operating system. It implements a Linux-like interface while running in user space with memory safety, and integrates seamlessly with Docker and Kubernetes through its OCI runtime, `runsc`. Notable features include its ability to limit host kernel surface access while offering familiar application functionalities, thus improving security without the overhead of traditional virtual machines.

grumpy

Grumpy is a transcompiler tool that converts Python source code into Go code, effectively acting as a replacement for CPython 2.7 by compiling to native code without using a virtual machine. Notable features include a runtime library that mimics certain aspects of the Python C API and the ability to execute Grumpy programs through a simple `make run` command or by using compilation with the `grumpc` tool. However, it lacks support for dynamic features like `exec` and `eval`, and is limited in its handling of C extension modules.

goose3

Goose3 is a Python-based article extraction tool designed to parse news articles from web pages, extracting the main body of text, meta data, primary images, and embedded media such as videos. Its notable features include handling various languages through optional dependency installations and providing clean and structured article output for further processing. This library is useful for developers looking to integrate web scraping capabilities focused on article content into their applications.

googleapis.github.io

Google APIs is a collection of tools and client libraries for interacting with Google's RPC and REST APIs, designed to facilitate API usage across various programming languages. It emphasizes a consistent API design philosophy and provides generated API clients and documentation to assist developers in leveraging Google services seamlessly. Notable features include the use of Protocol Buffers for defining APIs, support for gRPC, and open-source client libraries available for multiple programming languages.

google-patents-mcp

The Google Patents MCP Server (`google-patents-mcp`) is designed to facilitate searching for Google Patents information by leveraging the SerpApi Google Patents API. Its primary use case centers on providing an MCP-compatible interface for patent searches, notably featuring a `search_patents` tool that enables efficient querying. Additionally, it supports quick installation via `npx` and requires a valid SerpApi API key for functionality.

godot-mcp

Godot MCP is a server designed for integrating AI agents with the Godot game engine, facilitating the launching of the editor, running projects, capturing debugging output, and controlling project execution. Its primary use case is to enhance AI-assisted development workflows by providing a direct feedback loop for agents, which improves their ability to understand and generate code for Godot projects. Notable features include seamless project management and real-time debugging support.