> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

Sh3ller

Sh3ller is a lightweight command-and-control (C2) framework designed for managing incoming reverse shells via PowerShell. Its primary use case is to maintain persistent access to compromised systems, allowing users to manage multiple shell sessions simultaneously with minimal dependencies. Notable features include an always-on listening mode, support for various reverse shell payloads, and intuitive session management commands.

SeaShell

The SeaShell Framework is a post-exploitation tool designed for iOS and macOS that facilitates remote access to devices, allowing for control and extraction of sensitive data. Its notable features include a powerful payload named Pwny which supports custom post-exploitation modules, encrypted communication via TLS 1.3, and a basic set of modules for exfiltrating user data such as SMS, voicemail, and browsing history. Actively updated, it supports a wide array of iOS versions susceptible to specific vulnerabilities, enhancing its utility in security assessments and penetration testing.

searchbins

Searchbins is an offline command-line tool designed to search for GTFOBins binaries that allow users to bypass local security restrictions in misconfigured systems. Its notable features include the ability to enumerate specific binary functions, display commands to exploit those functions, maintain an up-to-date GTFOBins database, and allow for file-based binary searches. This tool serves as a valuable resource for security professionals to identify and utilize potential vulnerabilities in binary applications.

RUSTVERSARY

RustVersary is a comprehensive toolkit designed for malware development and penetration testing using the Rust programming language. It includes a variety of tools and scripts that facilitate tasks such as enumeration, exploitation, and post-exploitation, each thoroughly documented to aid both personal use and community contributions. Notable features include advanced techniques for process injection, persistence mechanisms, and a structured catalog of utilities tailored for security assessment challenges.

rogue

Rogue is a bash script that automates penetration testing workflows by integrating tools such as Nmap, Metasploit, and John the Ripper. It streamlines the scanning, exploiting, and reporting phases of pentesting, providing a modular and customizable experience for security professionals. Notable features include automated scans, exploitation configuration, credential harvesting, and structured report generation, all initiated with a simple input of a target IP address.

ReHTTP

ReHTTP is a PowerShell-based HTTP shell that features a web user interface, designed primarily for remote management and control of clients on a Windows platform. Key functionalities include executing PowerShell commands, managing client connections, and creating custom modules and variables, along with sophisticated event handling capabilities for connection management. This tool also supports scheduled tasks and offers a history feature for command execution, enhancing its usability in system administration and penetration testing contexts.

RedVision

RedVision is a collection of custom-designed HTML user interfaces specifically intended for Command & Control (C2) systems. Its primary use case is to enhance the operational efficiency of security professionals by providing a visually appealing and functional interface for managing C2 capabilities. Notable features include an array of templates, each visually distinct, allowing for flexible customization to suit various C2 deployment scenarios.

redpill

Redpill is a post-exploitation tool designed to facilitate various tasks following initial access via reverse TCP shells, particularly for red team engagements. It comprises a collection of PowerShell scripts, with the main script, redpill.ps1, serving as a central hub to download, configure, and execute these scripts, offering functionalities similar to the meterpreter environment. Notable features include system enumeration, remote process management, web server deployment, and a keystroke logger, all intended to enhance the capabilities of shell access in compromised systems.

reave

Reave is a post-exploitation framework developed for hypervisor endpoints, designed to facilitate automated penetration testing in heavily virtualized environments. This Python-based tool operates on a listener/agent model, offering features such as real-time interactive terminal sessions, automatic hypervisor enumeration, and modular payloads for tasks including exfiltration and persistence. Notably, Reave supports versatile configurations for agents, enabling comprehensive control over operations and network interactions.

python-remote-session-lab-poc

PythonRAT is a Command and Control (C2) server that orchestrates multiple machines infected with a Remote Administration Trojan (RAT), enabling the formation of a botnet cluster. Its primary use case is for educational purposes in cybersecurity training, allowing users to remotely control, monitor, and manipulate target sessions. Notable features include an integrated keylogger, screenshot and webcam capture, file transfer capabilities, privilege checking, and the ability to issue commands to all active sessions simultaneously.

PyIris

PyIris is a modular remote access trojan (RAT) toolkit implemented in Python, designed for the dynamic creation, encoding, and encryption of RAT payloads to facilitate the remote control of compromised systems. Its notable features include cross-platform compatibility for both Windows and Linux, robust error handling, dynamic payload generation, and advanced functionalities such as keylogging, webcam access, and file manipulation, making it a versatile tool for malicious actors. The ongoing development aims to enhance its capabilities further with improved encryption methods and operational persistence techniques.

PyExfil

PyExfil is a Python-based tool designed for stress testing the detection capabilities of security systems against various exfiltration and communication techniques employed by threat actors. It allows users to deploy multiple experimental and stable exfiltration methods, such as DNS queries, HTTP cookies, and ICMP packets, enabling organizations to evaluate their defenses. Notable features include a wide array of techniques for data exfiltration and communication, with the ability to configure and run tests across different operating systems.

PyADRecon

PyADRecon is a Python-based tool designed for gathering comprehensive information from Microsoft Active Directory environments, catering to the needs of penetration testers and blue teams. It supports NTLM and Kerberos authentication methods, can generate XLSX reports, and offers an HTML dashboard for visualizing collected data, making it a versatile resource for Active Directory reconnaissance. Additionally, it provides options for standalone report generation from CSV files, enhancing its usability in various assessment scenarios.

powtel

Powtel is a remote system control tool designed for Windows environments, utilizing PowerShell and Telegram as its communication interface. Its primary use case is for authorized security testing and post-exploitation activities, providing features such as task scheduling, file upload/download capabilities, and screenshot functionality. The tool emphasizes ethical usage, aiming to aid cybersecurity professionals and researchers in controlled settings.

PivotSuite

PivotSuite is a network pivoting toolkit designed for Red Teamers and penetration testers, enabling the movement within a compromised network using either forward or reverse connections. Notable features include support for TCP tunneling, SOCKS5 proxies, and various network enumeration functions, all without requiring administrative access on the compromised host. The tool operates independently of installation requirements, utilizing only Python's standard libraries, making it versatile across different platforms and environments.

pE

pE is a comprehensive post-exploitation framework designed for offensive security operations, focusing on practical techniques and tool development across multiple programming languages including Bash, Python, C, and Go. It offers a structured roadmap for activities such as credential access, lateral movement, persistence techniques, and data exfiltration, alongside custom script creation and defense evasion strategies. Key features include detailed sections on host enumeration, Active Directory abuse, and environmental setup, aimed at enhancing the effectiveness and efficiency of post-exploitation efforts.

MsfMania

MsfMania is a Python-based payload obfuscation framework primarily aimed at evading endpoint detection and antivirus systems on Windows platforms. It boasts notable features such as dynamic code generation, multi-layer encryption using RC4, local memory injection, and extensive metadata spoofing, making it suitable for authorized security testing and research activities.

Metasploit-Tutorial

The Metasploit-Tutorial repository provides comprehensive guidance on utilizing the Metasploit framework, a robust open-source toolset designed for network enumeration, vulnerability identification, and exploit development. Users can learn key functionalities such as exploit execution, payload creation, and post-exploitation techniques through detailed sections covering various components and workflows of Metasploit. Notable features of the tutorial include practical exercises with modules, sessions, and Meterpreter commands, enabling hands-on experience with real-world cybersecurity tasks.

merlin

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

MagikIndex

MagikIndex is an advanced keylogger designed for stealthy data capture, boasting a low detection rate and various persistence mechanisms. It retrieves logged information via email, supports clipboard monitoring, and can capture screenshots with configurable modes while encrypting logs for security. Notable features include an auto-update capability, extensive system information logging, and a customizable architecture for tailored functionality.

LOLSpoof

LOLSpoof is an interactive shell program designed to spoof command line arguments of spawned processes, specifically targeting 64-bit LOLBins. Its primary use case is to obscure such processes from detection by telemetry solutions used by antivirus, endpoint detection and response (EDR) systems, and security analysts. Notable features include the ability to craft a spoofed command line, the manipulation of process creation telemetry, and the handling of suspended processes to override command line parameters.

KitsuneC2

KitsuneC2 is a pure-Go adversary emulation framework designed for security testing, providing both a web and CLI interface for user interaction with implants. Its notable features include dynamic implant generation, in-memory execution of shellcode, and malleable C2 traffic, making it a versatile tool for organizations aiming to evaluate their cybersecurity defenses. However, it is not intended for professional engagements as there are more mature frameworks available.

HVNC-windows-remote-toolkit

HVNC is a remote administration toolkit designed for red-team operators, enabling covert access to an invisible Windows desktop without user awareness. Its primary use case is to facilitate stealthy remote operations by creating a hidden session that processes actions off-screen and communicates with the operator via VNC-like commands, supporting functionalities such as file transfers, keylogging, and launching applications. Notable features include simultaneous session handling in separate console windows and a clean-up script for system hygiene post-usage.

Hacker-Road-Map

The Hacker Road Map repository provides a comprehensive overview of resources and tools necessary for learning penetration testing and practicing ethical hacking. It features a categorized collection of UNIX-compatible, free, and open-source tools, along with guidance on essential concepts, basic steps of penetration testing, and additional educational materials to support newcomers in the field of information security. Notably, the project has been archived, indicating that the content may be outdated as a new initiative is anticipated to replace it.

gtfobins-cli

GTFOBins CLI is a command-line tool designed for security professionals to quickly access and search for Unix binary exploitation techniques. It features capabilities such as fuzzy searching, filtering exploitation types, and an interactive mode for ease of navigation, all while providing an offline database for fast, local access. The tool supports cross-platform usage and enhances readability with syntax highlighting, allowing for efficient identification of security bypass methods.