> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

Android-DFU-Library

The Android DFU Library facilitates firmware updates for Nordic Semiconductor's nRF51 and nRF52 Series SoCs via Bluetooth Low Energy. Key features include support for firmware packaged in ZIP format, integration with deep links for easy access to downloadable firmware, and a mobile application that manages the update process seamlessly. The library is designed to work with versions of the nRF5 SDK Bootloader and provides comprehensive permissions management for various Android API levels.

android-classyshark

ClassyShark is a binary inspection tool designed for Android developers, enabling detailed exploration of Android executables and libraries. It supports various formats including .dex, .aar, .apk, and .jar, providing insights into class structures, dependencies, and XML resources. Notable features include an intuitive browsing interface, command-line functionality, and data export capabilities.

Android_boot_image_editor

Android_boot_image_editor is a tool designed for reverse engineering Android ROM images, enabling extraction and modification of boot images and their components. Its primary use case includes unpacking and repacking boot images, vendor boot images, and recovery images across various platforms, with support for device tree blobs and other formats. Notable features include a straightforward command-line interface for unpacking and repacking processes, and the ability to work with multiple ROM image types following the AOSP verified boot flow.

ai-prompt-fuzzer

AI Prompt Fuzzer is a Burp Suite extension designed to identify and mitigate vulnerabilities in AI-based applications, particularly focusing on prompt injection risks. It automates the testing process by sending preloaded payloads to AI prompt APIs, analyzing responses for specific indicators of harmful behavior, and includes advanced features like AI-assisted testing for enhanced efficiency. The tool provides a seamless interface for security professionals to review and refine payloads, enabling comprehensive vulnerability assessments of large language model interactions.

Z0FCourse_ReverseEngineering

The Z0F Course on Reverse Engineering is designed to elevate learners from beginner to intermediate in reverse engineering focusing on Windows 64-bit architecture, while also providing applicable knowledge for various operating systems. The curriculum includes practical exercises such as reverse engineering binaries, DLLs, and malware, emphasizing the use of tools to facilitate the learning process and enhance analytical abilities. Notable features include interactive components available via TryHackMe and supplementary advanced course offerings for deeper exploration of Windows internals and exploit development.

yggdrasil-decision-forests

Yggdrasil Decision Forests (YDF) is an advanced library designed for training, evaluating, interpreting, and serving various ensemble learning models such as Random Forests and Gradient Boosted Decision Trees. Its primary use case lies in the efficient handling of machine learning tasks, offering features like model evaluation, partial dependence analysis, and benchmarking capabilities while supporting both Python and C++ APIs. The framework emphasizes extensibility and speed, making it a valuable tool for data scientists and machine learning engineers.

xmlrpc-scan

xmlrpc-scan is a specialized tool designed for identifying and testing vulnerabilities in the XML-RPC interface of WordPress sites. Its primary use case involves scanning URLs to determine if the XML-RPC interface is open and to test for Server-Side Request Forgery (SSRF) vulnerabilities using various methods. Notable features include generating unique URLs for each SSRF attempt and the ability to work with a list of URLs or a single URL input for targeted assessments.

xenia

Xenia is an experimental open-source emulator for the Xbox 360, designed for research and educational purposes in emulation technology. Its primary use case is to run Xbox 360 games on Windows and Linux systems, with a focus on compatibility and performance, although not all games are supported. Notable features include a game compatibility list, community-driven development, and comprehensive build instructions.

x64dbg-MiniDumpPlugin

The MiniDumpPlugin for x64dbg allows users to save the current debugging state in a full minidump format, facilitating analysis and troubleshooting of applications. Developed originally for integration with the dumpulator project, this tool has since been incorporated into x64dbg's core functionality as the `minidump` command. Notable features include ease of installation and the ability to generate both 32-bit and 64-bit plugins using CMake.

WraithXOL

WraithXOL is a specialized asset extraction tool designed for Call of Duty: Online, focusing on the extraction of game assets. It employs custom extraction logic to facilitate the retrieval of in-game resources, making it an essential utility for modders and developers interested in game content analysis and modification. Notable features include its tailored extraction capabilities, which enable users to access complex game asset structures.

WraithXArchon

WraithXArchon is a specialized asset extraction tool designed for extracting game assets from Call of Duty using the WraithX Library. It includes specific extraction logic for Call of Duty titles and provides user interface resources for streamlined functionality, making it valuable for modders and developers involved in game asset manipulation. Notable features include its integration with the WraithX Library and targeted extraction capabilities tailored to the Call of Duty game series.

werckmeister

Werckmeister is an open-source tool designed to compile sheet music written in a readable text format into MIDI files, catering primarily to composers and musicians looking to prototype songs and experiment with musical ideas. Notable features include a fast MIDI compiler, a sheet file player, a Visual Studio Code extension, and an accompaniment template rendering engine, which facilitates experimentation with chord progressions in a straightforward manner. This tool addresses the limitations of traditional scorewriters by allowing users to work without the constraints of proprietary file formats, promoting a more versatile approach to music creation.

webify

`webify` is a lightweight CGI server that transforms functions or commands into web services by forwarding HTTP requests to a specified script. It operates with minimal configuration, invoking the script and relaying the standard input and output as HTTP request and response bodies, respectively. Notably, it supports Docker deployment and can be easily configured with environment variables for flexible use cases.

weaviate

Weaviate is an open-source, cloud-native vector database designed for semantic search at scale by storing both objects and their vector representations. It integrates capabilities such as vector similarity search, keyword filtering, retrieval-augmented generation, and reranking into a unified query interface, making it suitable for applications like RAG systems, chatbots, and recommendation engines. Notable features include automatic vectorization with various embedding models, support for pre-computed vectors, and built-in functionalities for multi-tenancy, replication, and role-based access control.

waveterm

Wave Terminal is an open-source terminal application designed for macOS, Linux, and Windows that integrates AI capabilities to enhance user interactions and workflows. Its primary use case is to facilitate more efficient terminal operations through features such as context-aware AI assistance, durable SSH sessions, and a built-in graphical file editor for remote files. Notable features include the automatic reconnection of SSH sessions, rich file previews, a customizable interface, and comprehensive support for multiple AI models without requiring user accounts.

wappalyzergo

Wappalyzergo is a high-performance Go implementation of the Wappalyzer Technology Detection Library, designed for identifying web technologies used on websites. It features a streamlined interface, utilizing normalized regex patterns and an auto-updating database of fingerprints, while optimizing HTML parsing for enhanced speed. This tool is particularly useful for developers and security professionals seeking to analyze web applications and their underlying technologies efficiently.

wails

Wails is a framework designed for creating desktop applications using Go and web technologies, allowing developers to bundle Go code with a web frontend into a single executable binary. It features a straightforward development process with capabilities like native dialogs, light/dark mode support, auto-generated TypeScript definitions, and a unified eventing system between Go and JavaScript, while ensuring performance through the use of native rendering engines without embedded browsers. The tool also includes powerful CLI utilities for project generation and building, enhancing productivity across multiple platforms.

vulnrepo-server

VULNRΞPO Server is a Go-based application that serves as a personal server integration point for the VULNRΞPO vulnerability repository. Its primary use case is simplifying access to vulnerability data via a customizable API, with notable features including certificate-based authentication and configurable storage limits for hosted vulnerability reports. Users can deploy the server locally or within a Docker container, making it flexible for various environments.

volana

Volana is a shell command obfuscation tool designed for penetration testing, allowing users to execute commands on compromised machines without being logged by SIEM or detection systems. It operates by providing a stealthy shell environment to run commands, with features like ring mode for command obfuscation and encryption for executing commands in non-interactive shells. While not foolproof, Volana significantly complicates detection and post-attack investigations.

vince

Vince is a self-hosted web analytics tool designed as an alternative to Google Analytics, offering key features like outbound link tracking, file download tracking, and 404 page tracking while prioritizing user privacy through cookie-less tracking compliant with GDPR and CCPA. Its notable aspects include zero dependencies packaged as a single binary, unlimited site and event management capabilities, and public dashboards with customizable access controls. Vince enables quick setup with minimal command line intervention, making it user-friendly for single-entity deployments.

vinaysomawat.github.io

The repository provides a zero-build, data-driven portfolio website utilizing vanilla JavaScript ES modules and lit-html for templating. Its primary use case is to serve as a customizable online portfolio that aggregates content from a single data file without requiring a framework or build step. Notable features include a visitor counter powered by Firebase, external data integration from various APIs, and a lightweight architecture with hand-crafted animations and styles.

veles

Veles is a binary analysis tool designed to facilitate the identification of patterns in large binary datasets through statistical visualizations, making it easier for users to extract meaningful insights from complex data. Its primary use case includes assisting security professionals and researchers in analyzing binary files by transforming raw data into intuitive visual representations. Notable features include its ability to leverage visual pattern recognition and the provision of compiled binaries for easy deployment.

veles

Veles is an advanced binary analysis tool designed for visual reverse engineering, utilizing n-gram principles to enhance the analysis process. It supports intuitive navigation through its 3D interface, allowing users to manipulate projections with mouse or keyboard controls. Key features include a user-friendly graphical interface and support for building with essential dependencies, making it suitable for developers and researchers in the cybersecurity field.

vaulted

`vaulted` is a tool designed for managing and utilizing secret vaults to create secure environments for executing commands. Its primary use case includes storing sensitive information such as AWS credentials and SSH keys, while offering features like insulating individual sessions through temporary credentials and SSH agents. Notably, it supports interactive vault management, session spawning, and integrates with existing shell utilities for enhanced usability.

vault

Vault is a secure tool designed for managing and accessing secrets, such as API keys and passwords, with a focus on tight access control and detailed audit logging. Its primary use case is providing dynamic and secure secret storage while enabling features like dynamic secret generation, data encryption, lease management, and revocation capabilities. Notable features include encrypted storage, on-demand secret generation for cloud services, and comprehensive auditing of access and operations for security compliance.