> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

open-web-bridge

Open Web Bridge is a tool designed to facilitate the interaction of AI agents with a user's personal web browser, leveraging authenticated sessions and user-specific data. The tool features a command-line interface that integrates seamlessly with AI agents, offering capabilities such as semantic snapshots for web elements, waiting primitives for improved asynchronous interactions, and options for both local and remote operation modes. Notably, it allows AI agents to perform tasks in real-time using the currently active browser session, enhancing their ability to access and manipulate content beyond publicly available information.

ReHitman

ReHitman is a reverse engineering project aimed at modifying the game "Hitman: Blood Money" to create a multiplayer experience similar to Mafia 2's multiplayer. The tool focuses on developing an open-source SDK for the Glacier 1 Engine, reversing its rendering and input APIs, and building an associated toolset for game enhancements. Notable features include the integration of an ImGUI backend and current work on the game's scene format and GUI API.

Grok-Api

Grok-Api is a deprecated Python API wrapper for Grok AI that enables users to interact with the conversational AI without needing official API credentials or accounts. This tool features a FastAPI server for RESTful access, supports HTTP proxies, and allows for high-performance, concurrent requests with streaming response capabilities. Notably, it provides both automatic and expert processing modes, though it is rendered obsolete due to changes in Grok's access policy.

ane-guide

The Apple Neural Engine (ANE) guide provides an in-depth examination of the architecture, programming, and performance characteristics of Apple's proprietary neural hardware present in its A11 and M1 silicon. It details the internal mechanisms, data pathways, and performance metrics of the ANE, with sections dedicated to model deployment and tuning as well as comprehensive documentation on the engine's programming interface, memory hierarchy, and private runtime features. This guide serves as a resource for research and development purposes, emphasizing that the methods described are not officially supported by Apple and are subject to change with operating system updates.

MBBSDASM

MBBSDASM is a C#-based disassembler designed for analyzing 16-bit segmented executable files, specifically targeting MajorBBS and Worldgroup modules, as well as any NE format DLLs and executables. It features a command-line interface to support varied disassembly modes, including minimal, normal, and enhanced analysis that provides extensive information on code segments, external references, and string resolutions. Additionally, MBBSDASM offers a cross-platform text-based user interface for ease of use.

lucasartsifier

The Sierra softlock analyzer is a static analysis tool designed for decompiling and enhancing Sierra SCI adventure games by identifying and mitigating softlocks—game states where players can input commands but cannot win. It effectively derives, verifies, and installs protective guards against these non-winnable scenarios without requiring any game-specific code, allowing for seamless integration and the preservation of original game content. Notable features include automated trap detection, comprehensive scripting alterations, and customizable guard behaviors, ensuring gameplay remains normal while safeguarding against progression-blocking states.

kx-trainer-free

KX Trainer Free is an open-source utility for Guild Wars 2 that injects itself as a DLL to provide an in-game overlay menu, enhancing gameplay functionality. Its primary use case is to assist players with various game tools while ensuring compatibility with updates through community contributions. Notable features include modular maintainability, user-configurable hotkeys, and a commitment to transparency and educational use.

ELFKit

ELFKit is a library designed for parsing ELF (Executable and Linkable Format) files, enabling users to extract detailed information about segments, sections, dynamics, and symbols. Its notable features include the ability to retrieve all C strings and rebase information, making it particularly useful for developers involved in reverse engineering and binary analysis. The tool is implemented in Swift and provides a straightforward interface for loading ELF files from the filesystem.

DeNuitkanizator

DeNuitkanizator is a utility designed for analyzing .exe files compiled with Nuitka and other packagers such as PyInstaller. Its primary use case is for reverse engineers and malware analysts, providing detailed extraction of metadata, strings, modules, and PE structure information, while also disassembling machine code and identifying potential suspicious patterns. Notably, it distinguishes between different packagers, retrieves network-related data, and analyzes the executable's PE structure, although it does not function as a decompiler.

cross-channel_chinese-localization_project

The CROSS†CHANNEL Chinese Localization Project is a collaborative effort aimed at translating the visual novel "CROSS†CHANNEL" and its remake into Chinese, utilizing a patch system for language integration. Notable features of this project include an extensive staff contributing to translation and quality assurance, as well as a suite of tools developed for packaging and deploying the localization, which eliminates dependencies on the Windows registry. The project is open-source under GPLv2, ensuring that any derivative works must remain open-source as well.

cordial

Cordial is a tool that enables the native execution of Roblox's Android x86-64 engine on Linux, employing a custom runtime that bypasses traditional emulation methods. It uniquely supports user-extensible functionality through plugins, allowing developers to write custom code that integrates directly into the client without modifying the core Roblox experience. Notable features include direct GPU access through Vulkan or GLES2 and a robust API designed for plugin development, emphasizing a commitment to maintainability and community contribution.

yentra

Yentra is a Burp Suite extension designed to streamline collaborative security testing by deduplicating proxy history into a real-time unique request feed and color-coding traffic based on listener ports. Its notable feature, Live Share, enables real-time peer-to-peer sharing of HTTP requests without prior registration, accompanied by robust tools like a Magic Cookie, Match & Replace, and an inline Repeater for enhanced testing efficiency. Additional capabilities include automatic sharing of unique requests, replay options through local proxies, and integration with AI services for exporting requests.

wprecon

WPRecon is a WordPress reconnaissance and vulnerability scanning tool that leverages a YAML-driven template architecture for efficient vulnerability detection and configuration assessment in WordPress installations. Notable features include parallel scanning with configurable worker pools, a library of over 150 templates for comprehensive coverage, and dynamic variable resolution, offering flexibility for security engineers to extend capabilities without recompilation. The tool supports both command-line and API interfaces, allowing for versatile integration into security workflows.

GridSetup

GRID v2 is a comprehensive local intelligence dashboard that integrates multiple capabilities for OSINT, network reconnaissance, satellite tracking, IoT, and automation, all within a single conversational interface. Its notable features include a sophisticated layered memory engine that retains knowledge across sessions, enabling efficient recall and context management, alongside over 68 built-in tools for various operational tasks, making it a versatile solution for cybersecurity professionals. Unlike competing tools, GRID uniquely combines a wide range of functionalities while operating entirely offline, ensuring user autonomy and data security.

phantomtide

Phantom Tide is a geospatial OSINT tool designed for maritime and airspace intelligence that enables analysts to efficiently identify and prioritize anomalies across various signals. Its notable features include a ranking system for cross-source hotspots, an analyst notebook for personalized tracking and evidence management, and rapid load times for world-scale maps. The tool facilitates swift context identification with features like mission cues and area intelligence reports, ensuring users can move from detection to actionable insights with minimal friction.

instagrapi

instagrapi is an unofficial Instagram API wrapper for Python that facilitates fast and effective automation of various Instagram functionalities, including user interactions, media management, direct messaging, and insights retrieval. It supports session persistence and challenge handling while allowing extensive integration with both public web and private mobile API flows, making it suitable for testing, research, and controlled automation. Notable features include optional TLS impersonation support, built-in video upload capabilities, and comprehensive documentation for effective usage.

OSINT-CSE

OSINT Custom Search Engines is a versatile collection of Google Custom Search Engines (CSEs) specifically designed for conducting open-source intelligence (OSINT) searches across various platforms and languages, with a focus on Central Asia and Russian-speaking communities. This tool allows users to perform targeted searches for social media profiles, public documents, and other data sources, with notable features including tailored CSEs for platforms like Facebook, Instagram, and Telegram, as well as the ability to search specific countries and demographics. Users can contribute to the repository by adding their own CSEs or reporting issues, encouraging community engagement and continuous improvement.

adsbtrack

adsbtrack is a Python tool designed to retrieve and structure historical ADS-B flight data for any aircraft using its ICAO hex code. It facilitates comprehensive analysis by extracting individual flights, correlating takeoff and landing coordinates with airports, and evaluating flight data quality over specified date ranges, making it particularly useful for OSINT and aviation enthusiasts seeking detailed insights into aircraft travel patterns. Notable features include multi-network data retrieval, flight quality classifications, and the ability to analyze signal gaps and generate routing fingerprints.

awinrm

AWINRM is an advanced WinRM post-exploitation framework designed specifically for red teams and offensive research, implemented in Ruby. Its primary use case revolves around facilitating efficient post-exploitation activities with features like built-in tool staging, automated AMSI/ETW bypasses, stealth file transfers, and automatic loot extraction, addressing common challenges encountered in traditional WinRM tools. The framework provides a streamlined operator-centric workflow that enhances operational security and supports automated reconnaissance and credential gathering.

sonar-bypass

Sonar Bypass is a Node.js script designed to circumvent the Sonar 2.1.x anti-bot verification mechanism for Minecraft servers by mimicking legitimate client behavior through raw socket communication. The tool operates without the need for captcha solving or manual interaction, handling various verification stages by copying the exact interactions of a real player, documented in its accompanying research files. Key features include automated packet responses and support for multiple server environments, making it effective for bypassing bot protections in targeted servers.

roblox-infinite-yield-gui

Roblox Infinite Yield Admin Script GUI is a powerful tool designed for managing and manipulating gameplay in Roblox, featuring over 300 admin commands accessible through a full graphical user interface. Key functionalities include player teleportation, speed and gravity adjustments, server information access, and ESP commands, all of which operate without requiring in-game administrative rights. Compatible with various high-level script executors, the tool enhances the gaming experience by offering extensive control and flexibility.

roblox-arceus-x-pc

Arceus X PC is a Roblox executor designed for Windows that allows users to run Lua scripts and access a built-in script hub, facilitating game modifications for popular titles such as Blox Fruits and Arsenal. It features over 500 pre-loaded scripts, including an auto-farm for Blox Fruits and aimbot and ESP scripts for Arsenal, with one-click execution and regular updates to ensure compatibility with Roblox patches. This tool is a port from the mobile version, maintaining the core functionalities while catering to PC users.

PhantomTap

PhantomTap is a machine learning-enhanced tool for the Flipper Zero, specifically designed for RFID/NFC fuzzing and access-control auditing. It utilizes active learning to intelligently generate test credentials, significantly reducing the number of reader queries required for effective security assessments, and produces an explainable audit report for identifying vulnerabilities in badge systems. Notably, it features efficient characterization, Bayesian population sizing, and integrates detection mechanisms to monitor real-time security threats.

bugbountyrules

bugbountyrules is an AI agent skill designed for authorized bug bounty and penetration testing, emphasizing disciplined and methodical hunting behavior. It features 42 active rules to minimize false positives, avoid severity inflation, and ensure thorough surface coverage while performing tests across web, API, mobile, cloud, and LLM environments. The tool operates on a structured approach to testing, maintaining an organized flow of reconnaissance and validation while integrating a robust knowledge base for on-demand information retrieval.

langconfig

LangConfig is an open-source visual platform designed for building, testing, and deploying LangChain agents and LangGraph workflows without the need for coding. Its notable features include a drag-and-drop interface for creating complex multi-agent workflows, real-time execution monitoring, adaptive thinking capabilities, and support for various AI models, making it ideal for researchers and developers to experiment with agentic AI. Users can easily customize workflows, leverage prebuilt templates for popular integrations, and export their configurations for collaboration or deployment.