> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

StreamDeckToolkit

StreamDeckToolkit is a template tool designed to facilitate the development of plugins for the Elgato Stream Deck using the Stream Deck SDK with .NET Core. Its primary use case is to streamline the creation of custom actions for Stream Deck buttons, enabling integration testing and efficient communication with the Stream Deck software. Notable features include two base classes for plugin actions that allow developers to manage data exchange effectively and automation of settings management.

streamdeck-cpu

The `CPU` plugin for Stream Deck displays real-time CPU usage on a designated key, serving as a utility for users to monitor system performance. Notable features include cross-platform compatibility for macOS and Windows, localization support, and implementation in C++.

StarWarsIntroCreator

Star Wars Intro Creator is a web-based tool that allows users to generate personalized Star Wars movie openings by inputting custom text and playing the intro animation. Notably, it facilitates URL sharing, enabling others to view the created intros easily. The tool builds on existing technologies to replicate the iconic opening crawl effect from the original 1977 film.

sqlitebrowser

DB Browser for SQLite (DB4S) is an open-source graphical tool designed for creating, designing, and editing SQLite database files, catering to users and developers without the need to write complex SQL commands. It features a spreadsheet-like interface that allows users to create and modify tables, browse and edit records, issue SQL queries, and import/export data in various formats, all enhanced with convenience controls and wizards. Notable capabilities include compacting databases, plotting simple graphs, and logging SQL commands issued during usage, making it a versatile tool for SQLite database management.

smogcloud

Smogcloud is a tool designed for security engineers, penetration testers, and AWS administrators to discover and monitor exposed AWS cloud assets across one or multiple accounts. It facilitates the identification of internet-facing resources, misconfigurations, and unused assets, delivering insights on vulnerabilities and shadow IT. Notable features include support for a range of AWS services, comprehensive asset inventory management, and the ability to monitor changes in dynamic environments.

SMB-Session-Spoofing

SMB-Session-Spoofing is a utility tool designed to create a fake SMB session for the purpose of luring attackers into interacting with a monitored honeypot device. This tool allows users to customize parameters for their production environment and requires specific setup instructions, including service installation and monitoring recommendations to effectively detect potential malicious activity. Notable features include the ability to modify session credentials and detailed verification steps to confirm functionality after deployment.

sing-box

Sing-Box is a universal proxy platform designed to facilitate secure and efficient internet access through various proxy methods. Its primary use case includes bypassing network restrictions and enhancing user privacy while browsing. Notable features include extensive documentation, compatibility with multiple proxy protocols, and adherence to the GNU General Public License for open-source collaboration.

simplehttp

SimpleHTTP is a lightweight tool designed to serve files from a local directory over HTTP. Its primary use case is for quickly sharing or testing static files during development, allowing users to specify the directory and port through command-line arguments. Notable features include the ability to serve from the current directory or a specified one, and to customize the port for the HTTP server.

silicon

Silicon is a lightweight CSS stylesheet designed for modern responsive web design, featuring both light and dark modes. Its primary use case is to simplify website styling without requiring class usage, while still allowing customization through CSS variables. Notable features include a small file size of 13kb for fast loading and separate versions for light and dark themes.

signal

mautrix-signal is a Matrix-Signal puppeting bridge that enables interoperability between Matrix and Signal messaging platforms. Its primary use case is to facilitate communication between users on these two networks, allowing for seamless message exchange. Notable features include comprehensive setup instructions, support for Docker deployment, and a roadmap for future functionality enhancement.

SigDigger

SigDigger is a free digital signal analyzer for GNU/Linux and macOS, designed to extract and analyze unknown radio signals in real time using various software-defined radio (SDR) devices through SoapySDR. Its primary use case includes adjustable demodulation of FSK, PSK, and ASK signals, decoding analog video, and analyzing bursty signals. Notable features include a user-friendly GUI, support for multiple plugins for extended functionality, and real-time processing capabilities, making it ideal for radio signal research and experimentation.

Sideloader

Sideloader is an open-source tool designed for installing third-party applications on iOS devices, serving as an alternative to Cydia Impactor. It features a cross-platform command-line interface (CLI) with capabilities to manage app IDs, certificates, and devices, as well as install and sign applications. Additionally, the project includes a GTK-based frontend for Linux and plans for Qt-based frontends across various operating systems, making it versatile and maintainable for users in the iOS development community.

shortcut-signing-server

The Shortcut Signing Server is a streamlined tool designed for signing iOS and macOS shortcuts via an HTTP interface. Its primary use case involves enabling developers to manage shortcut signing processes efficiently, utilizing features such as configurable logging options, TLS support for secure communication, and customizable HTML templates for response formatting. Notably, it supports maximum concurrent signing jobs and provides detailed error response handling to enhance the user experience.

shiori

Shiori is a lightweight bookmarks manager developed in Go, designed to serve as a straightforward alternative to Pocket. It offers essential bookmark management functions, including adding, editing, deleting, and searching, as well as support for importing and exporting bookmarks from various formats and databases. Notable features include a simple command-line interface, a web interface, the ability to create offline webpage archives, and beta support for browser extensions.

shell2http

shell2http is an HTTP server that executes shell commands in response to HTTP requests, facilitating rapid development, prototyping, and remote control of shell functionalities. It features easy setup with command-line arguments, support for environment variable parsing, CGI mode for enhanced script execution, and options for logging and error handling. The tool is particularly useful for testing shell scripts and integrating shell commands into web applications.

shell-plus-plus

Shell++ is a versatile programming language designed to simplify shell scripting by integrating features from modern programming paradigms, such as object-oriented and functional programming. It offers an advanced data manipulation capability akin to Python, along with native support for command execution, dynamic typing, and powerful constructs like lambdas and closures. Notable features include seamless integration of shell commands with native syntax, comprehensive file handling, and robust error management capabilities, making it an efficient tool for automating complex scripting tasks.

sftpgo

SFTPGo is a comprehensive, event-driven file transfer server that supports multiple protocols including SFTP, HTTP/S, FTP/S, and WebDAV, while accommodating various storage backends like local file systems and cloud services (S3, Google Cloud, Azure). It serves as a versatile solution for both standard and complex file transfer needs, offering two editions: an open-source Community edition with essential features and a commercial Enterprise edition that enhances capabilities for mission-critical applications and compliance-heavy industries. Notable features include automated data ingestion, extensive cloud storage integration, and advanced security options, including encryption and DLP.

server

Gotify/server is a self-hosted messaging server designed for real-time communication via WebSocket, enabling users to send and receive messages efficiently. Key features include a REST-API for message sending, user and client management, plugin support, and a user-friendly web interface, complemented by a command-line interface and an Android application for enhanced usability.

serenity

SerenityOS is a graphical Unix-like operating system designed for 64-bit x86, Arm, and RISC-V architectures, inspired by the aesthetics of late-1990s productivity software and the functionality of modern Unix systems. Its notable features include a modern kernel with multi-threading, a comprehensive POSIX compatibility layer, a custom web browser with support for JavaScript and WebAssembly, and a suite of system services and development tools, all built from scratch without external dependencies. Additionally, it supports a rich library of multimedia formats and comes with a variety of everyday applications and games, promoting both user accessibility and security.

serenity

SerenityOS is a graphical Unix-like operating system designed for x86 computers, emphasizing a nostalgic aesthetic reminiscent of 1990s user interfaces while integrating modern features. Notable functionalities include a custom kernel with preemptive multi-threading, robust security mechanisms, extensive POSIX compatibility, and a suite of applications ranging from web browsing to multimedia playback. This system combines user-friendly design with powerful development tools, making it suitable for both casual users and developers alike.

semaphore

Semaphore UI is a web-based interface designed to streamline the management of DevOps tools such as Ansible, Terraform/OpenTofu, and PowerShell. It enhances operational efficiency by allowing users to easily run tasks, automate execution schedules, control access, and manage configurations, making it an ideal solution for teams transitioning from terminal-based deployment to a more intuitive graphical interface. Notable features include reusable task templates, notifications for job failures, and variable group management for sensitive information.

seaweedfs

SeaweedFS is an open-source, distributed file system designed for efficient storage and retrieval of large amounts of data. Its primary use case is to serve as a scalable object store, with features including an efficient garbage collection mechanism, support for S3 API compatibility, and advanced data replication strategies. Notable functionalities include a simple command-line interface, high performance for both small and large files, and the ability to integrate seamlessly into cloud environments.

SDRPlusPlus

SDR++ is a lightweight, cross-platform software-defined radio (SDR) application designed for efficient and straightforward use, with broad hardware compatibility facilitated by SoapySDR and dedicated modules. Key features include multi VFO support, SIMD-accelerated digital signal processing, a modular architecture for custom plugins, and enhanced visualization with full waterfall updates for improved signal browsing. This tool is suitable for users seeking a responsive and customizable SDR solution across various operating systems.

ScyllaHide

ScyllaHide is an advanced open-source Anti-Anti-Debug library that operates in user mode (ring 3) to conceal debugging activities by hooking various functions. It supports multiple debuggers through plugins, including OllyDbg, x64dbg, and IDA, while also allowing standalone operation for process injection. This tool is particularly suited for reversing and security analysis tasks where maintaining stealth against debugging efforts is critical.

scour

Scour is a module-based exploitation framework designed for red team testing and blue team analysis specifically within the AWS Controlplane, enabling users to emulate various attack patterns. Its main features include command completion, dynamic resource listing, and blue team mode, which tags attacks with unique User Agents for easy detection and analysis. While currently a work in progress and not yet production-ready, Scour offers several modules for operations, enumeration, privilege escalation, and more, making it a versatile tool for security assessments in AWS environments.