> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

GOD-OF-RAT

GOD-OF-RAT is an advanced Python Remote Access Trojan (RAT) framework designed for authorized penetration testing, offering extensive control over compromised systems. Its notable features include live screen controlling, credentials harvesting from various sources, an interactive agent builder with encryption capabilities, and advanced evasion techniques. The framework also supports remote shell access, file system management, and a suite of fun modules for additional functionalities.

ExtractBitlockerKeys

ExtractBitlockerKeys is a post-exploitation script designed for system administrators to automate the extraction of BitLocker recovery keys from a domain. It features multithreaded LDAP connections to retrieve data from domain controllers, supports pagination for large domains, and allows for exporting results in various formats, including JSON, XLSX, and SQLite3. This tool is essential for managing BitLocker recovery information in a secure and efficient manner.

DNS-Tunnel-Keylogger

DNS Tunnel Keylogger is a post-exploitation tool designed to covertly exfiltrate keystrokes via DNS tunneling, allowing for lightweight and persistent data exfiltration while minimizing detection risks. The tool features separate components for Linux and Windows, employing bash scripts and a compiled executable respectively, along with a server setup that listens on UDP port 53 by default. Notably, it can send keystrokes silently and can be configured for automatic startup in interactive shells to maintain persistence.

dfex

DFEX is a tool designed for DNS-based data exfiltration, leveraging the DNS protocol to transmit files across networks while circumventing traditional firewalls. Its primary use case is in post-exploitation scenarios, employing unique tactics to outsmart advanced firewalls, including techniques that disguise data transfers in plain sight. Notable features include a dual-client and server architecture, and compatibility with Python environments to facilitate easy installation and setup.

csharp_reverse_shell

The csharp_reverse_shell is a proof-of-concept tool for executing reverse shell operations in C# that supports SSL/TLS encryption and various evasion techniques. Its primary use case includes providing a stealthy command execution environment with features such as a no-visible-window mode, dual operation modes for interactive shell and shellcode execution, and advanced evasion strategies like AMSI and ETW bypassing. Notable functionalities include silent error handling and selective unhooking of system calls to avoid detection.

Clipboard-Hijacker

Clipboard-Hijacker is a post-exploitation payload designed for penetration testing that monitors and captures clipboard data on a target machine. It automatically sends captured clipboard contents, which may include sensitive information, to a specified web server or webhook every 10 seconds, while also optionally logging data locally. Notable features include the ability to modify clipboard contents and error handling mechanisms for reliable data transmission.

C2PE

C2PE is a tool designed for Red Team operations, focusing on Command and Control (C2) capabilities and post-exploitation activities. It features experimental code implementations suitable for hacking scenarios, allowing users to deploy C2 infrastructures and manage compromised systems effectively. The tool is developed in Python and Go, ensuring cross-platform compatibility and adherence to PEP8 code standards.

C2KepExec

C2KepExec is a Command and Control (C2) server designed to manage a BotNet of machines running a Remote Administration Trojan and is developed for educational purposes. Its notable features include remote keylogging, file management capabilities (uploading and downloading), integrated session control for multiple targets, and persistent infection techniques on Windows systems. The tool also allows for advanced monitoring functions such as screen captures and webcam access.

C-keystroke-monitoring-lab-poc

C_keylogger is a stealthy keylogging tool developed in C for Windows that utilizes a traditional approach to log keystrokes without relying on WinAPI hooks. It features persistence, remote activation, a stealth handler to hide the Command Prompt window, and efficient memory management through variable reuse. The tool is designed for educational purposes in a controlled lab environment, requiring specific amendments before compilation to ensure connectivity.

awesome-cyber

awesome-cyber is a curated repository that aggregates a diverse range of cybersecurity tools catering to red, blue, and purple team operations. This resource aims to provide an up-to-date collection of tools across various cybersecurity domains, including offensive and defensive techniques, forensics, and incident response. Notable features include organized categories for easy navigation and an open invitation for community contributions to keep the toolset relevant.

AntiForensic.NET

AntiForensic.NET is a lightweight library designed for Windows that facilitates the eradication of forensic trace logs from a computer system. Its primary use case involves implementing various anti-forensic techniques to ensure user privacy by removing artifacts such as application logs, event logs, and cached data. Notable features include the automatic deletion of numerous types of logs and cache files, including Recycle Bin contents, recent items, and compatibility logs, thereby aiding users in evading potential tracing.

Ant

Ant is a post-exploitation tool designed to automate the deployment of tunnels and port forwarding over a specified network topology using configuration files. Key features include support for WMI, WinRM, and SMB protocols, along with four main commands—deploy, desinfect, redeploy, and probe—that facilitate topology management. The tool also includes validation for configuration file accuracy and allows comments for better user guidance.

AlanFramework

Alan Framework is a post-exploitation framework designed for red-team activities, enabling advanced functionality such as in-memory tool execution and encrypted communication. It supports multiple agent types including Powershell, DLL, and executable formats across different architectures and operating systems, with a powerful command shell and real-time agent configuration updates. Notable features include a fully compliant SOCKS5 proxy, JavaScript execution capabilities, and a lack of external dependencies, making it suitable for stealthy operational tasks.

Agent-Loader

Agent Loader is a modular command-and-control (C2) tool designed to facilitate the deployment of in-memory payloads and covert operations through a DNS-over-HTTPS channel. Its notable features include dynamic function encryption, a reverse-shell module, and extensive file system management capabilities, alongside a customizable CLI builder for creating tailored implants via Python. The tool also offers a Node.js web panel for interactive management, showcasing a bot list and persistence mechanisms through OneDrive and Task Scheduler.

ShellOrd

ShellOrd is a cross-platform Command & Control (C2) framework designed for authorized penetration testing and educational purposes, implemented in Rust and Java. It supports Windows, MacOS, and Linux, and features a modular architecture with extensions, secure memory handling, and encrypted data transmission over TCP or UDP. The framework enables users to build and automate workflows, serving as an alternative to Trickest, while emphasizing speed and security.

ShellCode-Elevator-Uac-Bypass-Inject-Any-X64-fud

ShellCode Elevator is a sophisticated tool for bypassing User Account Control (UAC) and injecting shellcode into processes on x64 systems while maintaining stealth and undetectability. Its primary features include fully undetectable operation, privilege escalation, memory-only execution, and anti-debugging mechanisms to prevent detection by security tools. This makes it a potent option for executing malicious payloads without alerts on target systems.

linux-priv-esc-audit

linux-priv-esc-audit is a Linux system auditing script designed to identify privilege escalation vulnerabilities and enhance security. It offers dual-mode operation for both root and low-privilege users, generates comprehensive audit reports with vulnerability insights, and provides user-friendly guidance throughout the audit process. Regular updates ensure the tool remains effective against new security threats and techniques.

byob

BYOB is an open-source post-exploitation framework designed for educational purposes that facilitates command and control operations following a system compromise. It features a comprehensive web GUI for managing post-exploitation tasks, customizable payload generation for multiple platforms, and the ability to dynamically load third-party packages without leaving traces on the disk. The framework is optimized for ease of use, allowing students, researchers, and developers to extend its capabilities with minimal effort.

uzomuzo-oss

uzomuzo is a dependency management tool designed to identify unmaintained packages and facilitate the safe removal of vulnerabilities that traditional Software Composition Analysis (SCA) tools fail to detect. Its primary features include the `scan` command for detecting unmonitored packages lacking CVEs and the `diet` command to rank dependencies by their removability based on various risk factors. Thus, uzomuzo addresses the critical issue of hidden lifecycle risks in software dependencies, enhancing supply chain security.

TrivySummary

TrivySummary is a reporting tool designed to interpret and summarize JSON outputs from Trivy vulnerability scans, facilitating visual and comparative reports for package vulnerabilities. It consolidates vulnerabilities by CVE and provides functionality for generating PDF or JSON reports, comparing scan results over time, and integrating with CI/CD pipelines to enforce security thresholds. Notable features include customizable report generation, integration of EPSS scores for exploitability assessment, and whitelisting capabilities for specific CVEs.

stride-gpt

STRIDE GPT is an AI-driven threat modeling tool that utilizes Large Language Models to create detailed threat models and attack trees based on the STRIDE methodology. It offers features such as agentic codebase analysis, a user-friendly CLI and interactive REPL, integration with OWASP guidelines, and the capability to generate and edit architecture diagrams directly within the tool. Additionally, STRIDE GPT supports multi-modal input, allowing users to incorporate various diagram types into the threat modeling process.

setcap-static

`setcap-static` is a streamlined, statically linked tool designed to set file capabilities, particularly useful in containerized environments where non-root execution is required while maintaining specific privileges, such as binding to low-numbered ports. It addresses the limitations of Docker's `COPY` command, which does not preserve extended attributes, by allowing capabilities to be assigned directly in the target image, and it features self-deletion to minimize attack vectors by removing itself after execution. This tool is particularly advantageous in scratch images, enhancing security while facilitating necessary privilege assignments for applications.

security-risk-assessment-tool

The Security Risk Assessment Tool (ISRA) is an Electron-based application designed for evaluating security risks in engineering projects, specifically within Thales Digital Identity and Security Business Unit. It facilitates the identification of business and supporting assets, threat agents, vulnerabilities, and the assessment of associated risks, all while adhering to the ISO 27005 risk management standard. Notable features include detailed risk analysis workflows, integration of predetermined Targeted Level of Trust (TLoT), and a risk treatment strategy that allows for mitigation, acceptance, or avoidance of identified risks.

secure-repo

Secure-Repo is a GitHub repository tool designed to automate the implementation of security best practices within GitHub workflows. Its primary use case includes enhancing repository security by automatically setting minimum GITHUB_TOKEN permissions, integrating security actions like Harden-Runner, and facilitating dependency management through Dependabot and CodeQL. Notable features include a catalog of recommended fixes that can be applied to various security vulnerabilities in CI/CD processes, alongside an actionable knowledge base for GitHub Actions permissions.

pysentry

PySentry is a robust vulnerability scanning tool for Python dependencies, designed to audit projects against known security issues by analyzing lock files or manifests and resolving the full dependency tree. Its notable features include support for various dependency formats, integration with multiple vulnerability databases for comprehensive reporting, and capabilities for continuous integration (CI) environments, allowing detailed output formats and customizable failure thresholds. The tool is optimized for speed, utilizing a Rust core for efficient processing and local caching.