> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

Vulnos-Chronos-Lab-Walkthrough

VulnOS: Chronos is a penetration testing lab designed to simulate a medium-difficulty hacking scenario, emphasizing skills in recon, web exploitation, pivoting, and privilege escalation. Noteworthy features include a step-by-step walkthrough that outlines methodologies such as utilizing tools like `nmap`, `gobuster`, and `hydra` for effective enumeration and exploitation, as well as creative techniques like exploiting a misconfigured upload filter for executing a PHP payload. Users can capture flags through various challenges, ultimately aiming to attain root access.

SUID3NUM

SUID3NUM is a standalone Python script designed to identify and exploit SUID binaries on Linux systems, distinguishing between default and custom binaries. Its primary use case is in penetration testing, particularly for scenarios like Capture The Flag (CTF) challenges, where it automates the exploitation of non-default SUID binaries while providing a clear overview of potentially exploitable binaries from the GTFO Bins repository. Notable features include the ability to auto-exploit custom binaries without impacting the system, as well as color-coded output for improved readability.

Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462

The tool addresses two high-severity privilege escalation vulnerabilities, CVE-2025-32463 and CVE-2025-32462, affecting the `sudo` utility in various Linux distributions, with a critical CVSS score of 9.3 for CVE-2025-32463. It emphasizes the risks associated with misconfigured `sudoers` rules, particularly those involving wildcard commands, and provides mitigation strategies such as immediate updates to the fixed version and careful audit of `sudoers` policies. Key features include vulnerability detection guidance and examples of secure configuration practices to prevent potential exploitation.

SecOps-CLI-Guides

SecOps-CLI Guides is a curated repository providing PDF command-line cheat sheets and how-to guides tailored for security professionals, facilitating offline reference for key cybersecurity tools and techniques. Notable topics include Metasploit, Nmap, SQLMap, and Active Directory attacks, making it a valuable resource for penetration testing and security operations. The repository invites contributions to expand its collection, enhancing its utility for the security community.

rootisnaked

Rootisnaked is an eBPF-based tool crafted for monitoring root privilege escalations on Linux systems by intercepting changes to user credentials, specifically monitoring when a process's UID changes to 0 (root). Primarily used for detecting potential privilege escalation attempts, it logs these events to a ring buffer, enabling subsequent analysis. The tool additionally supports centralized alerting via integration with Alertmanager and Telegram for real-time notifications.

rfxn-defense

rfxn-defense is a Linux defense tool that provides a responsive mitigation layer against local privilege escalation (LPE) vulnerabilities by deploying kernel-level protections as soon as new vulnerabilities are identified. It supports automatic updates every four hours and requires no system reboots to apply mitigations, currently covering seven LPE classes across two families, including various techniques such as `LD_PRELOAD` and `modprobe` interventions. This tool is designed for ease of installation and ongoing security management within environments running Enterprise Linux distributions.

PrivHunterAI-detects-access-vulnerabilities

PrivHunterAI is a tool designed to identify unauthorized access vulnerabilities through passive proxying, utilizing various mainstream AI engines such as Kimi, DeepSeek, and GPT. The tool's notable features include support for HTTPS traffic detection, customizable request headers, and the ability to view scan results via both terminal and a web interface. It requires configuration of AI models and API keys, allowing for flexible integration and usage in vulnerability assessments.

Pentesting-Methodology

The Pentesting-Methodology repository provides a structured approach to penetration testing, encompassing networking fundamentals, reconnaissance, and analysis techniques. It includes tools for identifying web servers and technologies, brute-forcing subdomains, and performing directory enumeration, making it useful for security professionals looking to streamline their penetration testing workflows. Notable features include detailed networking information and integration with various reconnaissance tools such as Sublist3r and Amass.

Pentest-Service-Enumeration

Pentest-Service-Enumeration (PSE) is a terminal-based tool designed for penetration testers, providing a quick-reference library of commands organized by service and enabling interaction with AI/LLM endpoints. Its primary use case is to facilitate service enumeration during penetration testing, while also incorporating fingerprinting and chat functionalities for AI services, aiding both practical application and certification preparation. Notable features include customizable command tracking, multi-technique extraction capabilities, and session isolation for enhanced security during testing operations.

PayloadsAllTheThings

Payloads All The Things is a comprehensive repository that provides a collection of useful payloads and techniques for web application security testing. It offers structured documentation on various vulnerabilities, including exploitation methods and payload examples, and is designed to assist penetration testers in identifying and utilizing attack vectors effectively. Notable features include templates for adding new vulnerabilities, integration with Burp Suite Intruder, and a community-driven approach to enhancing its content.

Offensive-Security-Forensics-Portfolio

The Offensive Security Forensics Portfolio is an educational repository showcasing practical skills in cybersecurity, particularly in forensic analysis, penetration testing, and vulnerability assessments. It features detailed documentation of various security techniques, including the implementation of Multi-Factor Authentication for SSH and memory forensics using the Volatility Framework, as well as threat hunting exercises with Splunk. This portfolio serves as a comprehensive example of applied offensive security methodologies within controlled environments.

kosty

Kosty is a comprehensive CLI tool designed for AWS cost optimization and security auditing, capable of scanning over 30 AWS services. Its key features include external attack surface mapping, IAM privilege escalation detection, and specific audits for GenAI workloads like Bedrock and SageMaker, alongside actionable insights on cost savings and security gaps. The tool facilitates organization-wide scanning with parallel processing and offers an interactive visual dashboard for in-depth report analysis.

Invoke-SeRestoreAbuse

Invoke-SeRestoreAbuse is a privilege escalation tool that exploits the SeRestorePrivilege via Seclogon service hijacking to execute arbitrary commands with SYSTEM privileges. It achieves this by modifying the Seclogon service's ImagePath using SeRestorePrivilege and REG_OPTION_BACKUP_RESTORE techniques. This tool is designed for authorized system penetration testing and is accompanied by usage demonstrations.

Hacking-Study-Guide

The Hacking Study Guide serves as a comprehensive resource for individuals preparing for cybersecurity certifications such as eJPT, PNTP, and OSCP. It encompasses essential topics including Windows and Linux privilege escalation, bug bounty techniques, and operational security intelligence (OSINT), providing checklists and detailed notes for practical learning. The tool is designed to enhance users' understanding of ethical hacking methodologies, enabling them to detect, prevent, and remediate security vulnerabilities effectively.

GoldenDMSA

Golden dMSA is a cybersecurity tool that facilitates the exploitation of delegated Managed Service Accounts (dMSAs) through the "Golden DMSA" attack, allowing unauthorized password generation for dMSAs offline. Key features include the ability to extract KDS Root keys, enumerate dMSA accounts, guess ManagedPasswordIDs, and generate valid passwords, making it a potent tool for penetration testing and security assessments of systems with vulnerabilities in dMSA authentication. The tool is built for .NET Framework 4.7.2 and includes functionalities for password conversion, information gathering on dMSAs and KDS keys, as well as brute force password attacks.

Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201

Glass Cage is a zero-click exploit chain targeting iOS 18.2.1, leveraging vulnerabilities in image processing and WebKit to achieve remote code execution, privilege escalation, and persistent control over compromised devices. The attack is initiated through a malicious PNG transmitted via iMessage, triggering an automatic parsing process that exploits multiple CVEs, ultimately allowing root access and the ability to manipulate device state without user interaction. Notable features include its stealthy operation, the capacity for device bricking, and comprehensive access to sensitive data through keychain exfiltration.

Fuck-Windows-Security

The repository titled "Fuck-Windows-Security" appears to be a tongue-in-cheek commentary rather than a functional cybersecurity tool. It does not provide a specific use case or notable features for any security-related applications.

elewrap

Elewrap is a minimalistic setuid wrapper program designed for secure privilege elevation, operating similarly to sudo but with a focus on simplicity and reduced attack surface. It statically compiles auth rules, allowing the definition of which users and commands can utilize elevated permissions, and provides a NixOS module for seamless integration and deployment. Notable features include the ability to authenticate target commands via SHA512 hash and fine-grained control over allowed users, groups, and environment variables.

CVE-2026-41089-Netlogon-RCE

CVE-2026-41089 is a critical cybersecurity tool designed to assess Windows Active Directory Domain Controllers for a severe unauthenticated remote code execution vulnerability caused by a stack-based buffer overflow in the Netlogon service. It allows users to execute crafted requests to identify susceptible systems without prior authentication, making it a crucial tool for detecting and mitigating potential exploits in enterprise environments. The tool features a Python-based script that facilitates various testing techniques, including baseline checks and aggressive payload testing, all while ensuring system stability.

CVE-2024-32019-Netdata-ndsudo-PATH-Vulnerability-Privilege-Escalation

This tool provides a Python-based exploit for the CVE-2024-32019 vulnerability in the Netdata Agent, specifically targeting the misconfigured `ndsudo` SUID binary that incorrectly handles the `PATH` environment variable. Its primary use case is for users with authorized access to demonstrate local privilege escalation (LPE) by executing a malicious binary with root privileges. Notable features include both manual and automated exploitation methods, aimed for educational purposes to assess potential risks in affected versions of the software.

Credential-Hunting

CredsHunter is a read-only credential discovery tool designed for authorized post-exploitation activities, efficiently identifying and extracting reusable credentials such as passwords, keys, and hashes while filtering out irrelevant cloud tokens. It operates through a structured five-stage process, scanning various OS credential stores and confirming the presence of valuable file types, ultimately delivering findings in a tiered format that prioritizes critical information. This tool supports both Linux and Windows environments, providing versatile and targeted scanning options without altering the host system.

copyfail-rs

copyfail-rs is a Rust implementation of the Copy Fail exploit (CVE-2026-31431), which demonstrates a local privilege escalation vulnerability on major Linux distributions by chaining the `AF_ALG` and `splice()` syscalls. This tool features a high-performance and memory-safe design, dynamic ELF payload construction, zero-copy exploitation for efficient interaction with the Linux kernel, and allows customization of commands to be executed with root privileges. It is intended strictly for educational and research purposes, focusing on understanding and mitigating similar vulnerabilities.

copyfail-rs

copyfail-rs is a cybersecurity tool that provides multi-vector proof-of-concept (PoC) exploitation and detection for CVE-2026-31431, specifically targeting vulnerabilities in PAM authentication systems. Its notable features include a unique PAM auth-bypass vector and a detection mechanism that identifies alterations in critical files that traditional file integrity monitoring solutions overlook, using a novel hashing approach that differentiates between actual disk state and memory cache mutations. This tool operates as a single static binary with no runtime dependencies, making it easily deployable across various Linux architectures.

copy-fail-CVE-2026-31431-IOC

copyfail-detect is a detection toolkit designed to identify exploitation attempts of CVE-2026-31431, a local privilege escalation vulnerability in the Linux kernel that alters page-cache data without modifying the actual disk file. It features multiple detection layers, including real-time eBPF monitoring of suspicious activities, auditd rules for syscall tracking, and a page-cache comparison tool for post-exploitation analysis, enabling proactive defense and investigation against the vulnerability. The toolkit also provides mitigation scripts and documentation for responders to safely address incidents involving the Copy Fail exploit.

cloud-audit-mcp

Cloud-audit-mcp is a cloud security auditing tool designed for AI agents to directly interact with cloud APIs, allowing for real-time checks, correlation of findings, and automated remediation of vulnerabilities. Unlike traditional tools that produce static reports requiring human analysis, this tool enables the AI to prioritize issues and generate specific commands for fixes, streamlining the security auditing process across multi-cloud environments such as AWS, Azure, and GCP. Notable features include the ability for the AI to chain checks, assess context, and follow up on remediation efforts without needing to re-scan the whole environment.