> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

loopback4-ratelimiter

loopback4-ratelimiter is a LoopBack 4 extension that enables rate limiting functionality for LoopBack applications by leveraging the express-rate-limit package. It supports various storage backends, including Redis, Memcache, and MongoDB, for managing rate limiting data, and allows for customizable configurations such as key generation and default options for enabling or disabling rate limits across APIs. Notable features include its easy integration into LoopBack applications and flexibility in configuring storage options based on application needs.

yaramail

Yaramail is a Python tool designed for scanning emails using YARA rules, primarily aimed at automating the triage process of phishing reports. It offers comprehensive functionality that allows users to analyze all components of an email, including headers, body content in various formats (Markdown conversion), and various attachment types, while also providing customizable password options for encrypted ZIP files. Notably, Yaramail categorizes emails systematically and parses authentication results for enhanced analysis.

ps-fuzz

Prompt Fuzzer is an interactive security assessment tool designed for GenAI applications, evaluating the robustness of system prompts against a variety of dynamic attacks, including jailbreak and prompt injection. It adapts its testing methodology to the specific characteristics of the application, allowing for iterative improvement through a Playground chat interface. Notable features include support for multiple LLM providers, a command-line interface, and multi-threaded testing capabilities.

agentmetry

Agentmetry is an open-source endpoint flight recorder specifically designed for AI coding agents, capturing detailed logs of tool calls, approvals, and denials to provide visibility into agent actions. Its primary use case is enhancing incident response by generating a comprehensive JSONL trail and correlating events with MITRE ATT&CK tactics, issuing critical alerts when a series of actions could signify an attack. The tool can function locally on Windows and Linux machines, with optional forwarding to SIEM solutions like Loki, Elastic, Splunk, or Google SecOps for centralized monitoring.

assemblyline-service-overpower

The Assemblyline Overpower service is designed to de-obfuscate and profile PowerShell files for analytical purposes. It utilizes modified open-source tools like PSDecode and PowerShellProfiler to statically analyze scripts and extract behavioral indicators. Key features include configurable submission parameters and integration within the Assemblyline framework for streamlined deployment and operation.

helm-d

helmd is a comprehensive security analysis plugin designed for the DeepSeek Harness, integrating capabilities across six domains: Android, Web, Native, Protocol, Malware, and AI-Security. This tool facilitates a streamlined installation with ten independently released bundles, enabling users to access all essential functionalities with minimal configuration while maintaining a modular architecture for on-demand knowledge and tool utilization. Notable features include first-round tool anchoring for user queries, specialized routing for domain-related tasks, and a focused referencing system that supports autonomous model decision-making.

open-web-bridge

Open Web Bridge is a tool designed to facilitate the interaction of AI agents with a user's personal web browser, leveraging authenticated sessions and user-specific data. The tool features a command-line interface that integrates seamlessly with AI agents, offering capabilities such as semantic snapshots for web elements, waiting primitives for improved asynchronous interactions, and options for both local and remote operation modes. Notably, it allows AI agents to perform tasks in real-time using the currently active browser session, enhancing their ability to access and manipulate content beyond publicly available information.

ReHitman

ReHitman is a reverse engineering project aimed at modifying the game "Hitman: Blood Money" to create a multiplayer experience similar to Mafia 2's multiplayer. The tool focuses on developing an open-source SDK for the Glacier 1 Engine, reversing its rendering and input APIs, and building an associated toolset for game enhancements. Notable features include the integration of an ImGUI backend and current work on the game's scene format and GUI API.

Grok-Api

Grok-Api is a deprecated Python API wrapper for Grok AI that enables users to interact with the conversational AI without needing official API credentials or accounts. This tool features a FastAPI server for RESTful access, supports HTTP proxies, and allows for high-performance, concurrent requests with streaming response capabilities. Notably, it provides both automatic and expert processing modes, though it is rendered obsolete due to changes in Grok's access policy.

ane-guide

The Apple Neural Engine (ANE) guide provides an in-depth examination of the architecture, programming, and performance characteristics of Apple's proprietary neural hardware present in its A11 and M1 silicon. It details the internal mechanisms, data pathways, and performance metrics of the ANE, with sections dedicated to model deployment and tuning as well as comprehensive documentation on the engine's programming interface, memory hierarchy, and private runtime features. This guide serves as a resource for research and development purposes, emphasizing that the methods described are not officially supported by Apple and are subject to change with operating system updates.

MBBSDASM

MBBSDASM is a C#-based disassembler designed for analyzing 16-bit segmented executable files, specifically targeting MajorBBS and Worldgroup modules, as well as any NE format DLLs and executables. It features a command-line interface to support varied disassembly modes, including minimal, normal, and enhanced analysis that provides extensive information on code segments, external references, and string resolutions. Additionally, MBBSDASM offers a cross-platform text-based user interface for ease of use.

lucasartsifier

The Sierra softlock analyzer is a static analysis tool designed for decompiling and enhancing Sierra SCI adventure games by identifying and mitigating softlocks—game states where players can input commands but cannot win. It effectively derives, verifies, and installs protective guards against these non-winnable scenarios without requiring any game-specific code, allowing for seamless integration and the preservation of original game content. Notable features include automated trap detection, comprehensive scripting alterations, and customizable guard behaviors, ensuring gameplay remains normal while safeguarding against progression-blocking states.

kx-trainer-free

KX Trainer Free is an open-source utility for Guild Wars 2 that injects itself as a DLL to provide an in-game overlay menu, enhancing gameplay functionality. Its primary use case is to assist players with various game tools while ensuring compatibility with updates through community contributions. Notable features include modular maintainability, user-configurable hotkeys, and a commitment to transparency and educational use.

ELFKit

ELFKit is a library designed for parsing ELF (Executable and Linkable Format) files, enabling users to extract detailed information about segments, sections, dynamics, and symbols. Its notable features include the ability to retrieve all C strings and rebase information, making it particularly useful for developers involved in reverse engineering and binary analysis. The tool is implemented in Swift and provides a straightforward interface for loading ELF files from the filesystem.

DeNuitkanizator

DeNuitkanizator is a utility designed for analyzing .exe files compiled with Nuitka and other packagers such as PyInstaller. Its primary use case is for reverse engineers and malware analysts, providing detailed extraction of metadata, strings, modules, and PE structure information, while also disassembling machine code and identifying potential suspicious patterns. Notably, it distinguishes between different packagers, retrieves network-related data, and analyzes the executable's PE structure, although it does not function as a decompiler.

cross-channel_chinese-localization_project

The CROSS†CHANNEL Chinese Localization Project is a collaborative effort aimed at translating the visual novel "CROSS†CHANNEL" and its remake into Chinese, utilizing a patch system for language integration. Notable features of this project include an extensive staff contributing to translation and quality assurance, as well as a suite of tools developed for packaging and deploying the localization, which eliminates dependencies on the Windows registry. The project is open-source under GPLv2, ensuring that any derivative works must remain open-source as well.

cordial

Cordial is a tool that enables the native execution of Roblox's Android x86-64 engine on Linux, employing a custom runtime that bypasses traditional emulation methods. It uniquely supports user-extensible functionality through plugins, allowing developers to write custom code that integrates directly into the client without modifying the core Roblox experience. Notable features include direct GPU access through Vulkan or GLES2 and a robust API designed for plugin development, emphasizing a commitment to maintainability and community contribution.

yentra

Yentra is a Burp Suite extension designed to streamline collaborative security testing by deduplicating proxy history into a real-time unique request feed and color-coding traffic based on listener ports. Its notable feature, Live Share, enables real-time peer-to-peer sharing of HTTP requests without prior registration, accompanied by robust tools like a Magic Cookie, Match & Replace, and an inline Repeater for enhanced testing efficiency. Additional capabilities include automatic sharing of unique requests, replay options through local proxies, and integration with AI services for exporting requests.

wprecon

WPRecon is a WordPress reconnaissance and vulnerability scanning tool that leverages a YAML-driven template architecture for efficient vulnerability detection and configuration assessment in WordPress installations. Notable features include parallel scanning with configurable worker pools, a library of over 150 templates for comprehensive coverage, and dynamic variable resolution, offering flexibility for security engineers to extend capabilities without recompilation. The tool supports both command-line and API interfaces, allowing for versatile integration into security workflows.

GridSetup

GRID v2 is a comprehensive local intelligence dashboard that integrates multiple capabilities for OSINT, network reconnaissance, satellite tracking, IoT, and automation, all within a single conversational interface. Its notable features include a sophisticated layered memory engine that retains knowledge across sessions, enabling efficient recall and context management, alongside over 68 built-in tools for various operational tasks, making it a versatile solution for cybersecurity professionals. Unlike competing tools, GRID uniquely combines a wide range of functionalities while operating entirely offline, ensuring user autonomy and data security.

phantomtide

Phantom Tide is a geospatial OSINT tool designed for maritime and airspace intelligence that enables analysts to efficiently identify and prioritize anomalies across various signals. Its notable features include a ranking system for cross-source hotspots, an analyst notebook for personalized tracking and evidence management, and rapid load times for world-scale maps. The tool facilitates swift context identification with features like mission cues and area intelligence reports, ensuring users can move from detection to actionable insights with minimal friction.

instagrapi

instagrapi is an unofficial Instagram API wrapper for Python that facilitates fast and effective automation of various Instagram functionalities, including user interactions, media management, direct messaging, and insights retrieval. It supports session persistence and challenge handling while allowing extensive integration with both public web and private mobile API flows, making it suitable for testing, research, and controlled automation. Notable features include optional TLS impersonation support, built-in video upload capabilities, and comprehensive documentation for effective usage.

OSINT-CSE

OSINT Custom Search Engines is a versatile collection of Google Custom Search Engines (CSEs) specifically designed for conducting open-source intelligence (OSINT) searches across various platforms and languages, with a focus on Central Asia and Russian-speaking communities. This tool allows users to perform targeted searches for social media profiles, public documents, and other data sources, with notable features including tailored CSEs for platforms like Facebook, Instagram, and Telegram, as well as the ability to search specific countries and demographics. Users can contribute to the repository by adding their own CSEs or reporting issues, encouraging community engagement and continuous improvement.

adsbtrack

adsbtrack is a Python tool designed to retrieve and structure historical ADS-B flight data for any aircraft using its ICAO hex code. It facilitates comprehensive analysis by extracting individual flights, correlating takeoff and landing coordinates with airports, and evaluating flight data quality over specified date ranges, making it particularly useful for OSINT and aviation enthusiasts seeking detailed insights into aircraft travel patterns. Notable features include multi-network data retrieval, flight quality classifications, and the ability to analyze signal gaps and generate routing fingerprints.

awinrm

AWINRM is an advanced WinRM post-exploitation framework designed specifically for red teams and offensive research, implemented in Ruby. Its primary use case revolves around facilitating efficient post-exploitation activities with features like built-in tool staging, automated AMSI/ETW bypasses, stealth file transfers, and automatic loot extraction, addressing common challenges encountered in traditional WinRM tools. The framework provides a streamlined operator-centric workflow that enhances operational security and supports automated reconnaissance and credential gathering.