> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

Awesome-Bootkits-Rootkits-Development

The Awesome Bootkits & Rootkits Development repository provides a comprehensive collection of resources focused on the development of bootkits and rootkits, targeting both BIOS/UEFI specifications and Windows kernel intricacies. Notable features include analysis tools, tutorials, source code examples for various operating systems, and insights into kernel security mechanisms such as Driver Signature Enforcement and Kernel Patch Protection. This repository serves as a vital resource for security researchers and developers interested in low-level malware development and analysis.

attack-shark-x11-driver

The Attack Shark X11 Driver is a TypeScript library designed for configuring various settings of the Attack Shark X11 gaming mouse on cross-platform environments, with an emphasis on Linux. It allows users to adjust DPI, remap buttons, create macros, control lighting, and set polling rates while providing USB HID communication capabilities. Notable features include extensive customization options, support for multiple operating environments like Node.js and Bun, and an active open-source community for ongoing development and enhancements.

android-frida-hooks

Android Frida Hooks is a collection of Frida scripts designed for device spoofing, integrity bypass, and exploring application tampering detection on Android devices for educational and security research purposes. It includes two versions: "full stealth," which encompasses extensive Java and native hooks for deep coverage against aggressive app checks, and "clean and minimal," focusing on essential spoofing while maintaining a lower detection footprint. Notable features include device ID generation, process list filtering, Play Integrity token faking, and safety mechanisms against common detection methods, making it suitable for a range of security testing scenarios.

alkahest

Alkahest is a tool designed to facilitate the analysis and transformation of shader code, specifically targeting optimization and adaptability for game development. Its primary use case lies in improving visual fidelity and performance in rendering engines, particularly for projects inspired by the technological advancements in games like Destiny 2. Notable features include support for multiple shader languages and an extensive library of resources linked to graphics technology in the gaming industry.

ai-reverse-engineering

Rev·Deck is a localized static-analysis workstation that integrates Ghidra with an AI-driven web interface for reverse engineering binaries. It allows users to browse deterministic evidence from analyzed binaries without executing them, while an AI assistant provides fact-based responses citing specific evidence. This tool supports various LLM backends and enables secure, efficient analysis with a user-friendly interface.

yap

Yet Another Packer (YAP) is a tool designed for the obfuscation and protection of x86_64 Windows PE applications, such as executables and DLLs, specifically excluding C# files. Its primary use case focuses on enhancing application security through a packer that encapsulates the original application to hinder static and dynamic analysis, as well as a reassembler that mutates and reassembles code to further obscure its functionality. Notable features include anti-debugging and anti-dumping mechanisms, alongside an SDK for seamless integration within protected applications.

xiaomi-hyperos-bootloader-unlock

Xiaomi MTK Bootloader Unlock is a tool designed to bypass the Dual-Layer Lock Verification for Xiaomi MTK devices running HyperOS or MIUI14+. It enables the unlocking of the bootloader by erasing a specific magic string stored in the Replay Protected Memory Block (RPMB), thus allowing the device to revert to the seccfg unlock state. The tool requires specific hardware conditions and careful execution to prevent common pitfalls associated with USB connections during the unlocking process.

VanMooof-Module

The VanMooof-Module ES3 is a specialized tool designed for interfacing with and extracting information from the MX25L51245GMI-08G-TR SPI Flash Chip used in VanMoof electric bicycles. Its primary use case includes reading and writing BLE keys, managing firmware updates, and performing detailed analyses of logs and sound files, which can help in troubleshooting and enhancing system performance. Notable features include authentication key extraction, firmware encryption/decryption, BLE permission inspection, and support for uploading firmware via y-modem.

vanmoof-tools

vanmoof-tools facilitates the reverse engineering of VanMoof S3/X3 electric bike firmware, providing utilities for analyzing various firmware images from multiple microcontrollers used in the bike's components. Notable features include detailed specifications for firmware structure, including boot loader and image header formats, CRC calculation methods, and support for different firmware generation containers. The toolset is designed to operate on Linux, macOS, or Raspberry Pi, making it accessible for users across various platforms.

Unreal-Library

UELib is an API designed for parsing and deserializing Unreal Engine game package files, such as .UDK and .UPK formats. Its primary use case is to decompile UnrealScript byte-code and reconstruct the original source from various Unreal data classes. Notable features include support for deserializing multiple Unreal asset types like textures, sounds, and fonts, as well as the ability to manage and initialize package objects efficiently.

TombExtract

TombExtract is an open-source savegame manager specifically designed for remastered versions of Tomb Raider I-VI, enabling users to import, manage, and convert savegames across different platforms such as PC, PS4, Android, and Nintendo Switch. Notable features include savegame management (deletion, reordering), platform and patch conversion, and the ability to create new savegames via level selection. The tool ensures compatibility across various gaming platforms and incorporates automated patch detection to facilitate seamless savegame conversions.

slicer

Slicer is a modern Java reverse engineering tool designed to operate in a web environment, offering disassembly and decompilation of Java class files through various decompilers like CFR and Procyon. Its notable features include a multi-pane workspace for simultaneous file viewing, graph visualizations of code structures, bytecode-level search capabilities, and a JS scripting API for enhanced functionality. Ideal for quickly examining class files without local setup, Slicer caters to users seeking a straightforward and accessible reverse engineering experience.

skyrim_vr_address_library

The Skyrim VR Address Library is a specialized tool that facilitates the conversion of Skyrim Special Edition (SSE) mod addresses to their corresponding Virtual Reality (VR) addresses, enabling modders to adapt existing mods for use in Skyrim VR. It provides a collection of CSV files that serve as a community resource for identifying and mapping addresslib IDs, along with automated and manual verification of addresses to ensure compatibility. Notable features include a comprehensive database for address mapping, release CSV generation for plugin integration, and analysis CSVs to assist in tracking changes and maintaining accurate mappings across various Skyrim versions.

Severed-Chains

Severed Chains is a tool designed to reverse engineer the classic game Legend of Dragoon into a high-level language, specifically Java, while offering a modding API for customization. The project features a fully functional game engine with no known crashes, comprehensive controller support, and an automatic update mechanism that preserves user data. Users can enhance their gameplay experience through a variety of controller options and GPU preference settings, making the tool suitable for both players and mod developers.

sa2

Sonic Advance Trilogy (SAT-R/sa2) is an ongoing decompilation project focused on the Sonic Advance series, specifically Sonic Advance 1 and 2, with plans for Sonic Advance 3. The tool provides a fully cross-platform and matching C codebase transcribed from the original ROMs, enables compilation for multiple platforms including Windows and PlayStation, and features comprehensive extraction of audio and graphic assets alongside detailed documentation of game mechanics. Notably, it is still under active development, with a significant portion of the original functionality and metadata already extracted and converted.

OpenTestDriveUnlimited

Open Test Drive Unlimited (OpenTDU) is a source port for the PC version of Test Drive Unlimited, aimed at enhancing compatibility with modern systems by addressing issues related to AI, rendering, and security while providing cross-platform support. This tool allows users to run the game on Windows, Linux, and macOS, necessitating a legal copy of the original game assets. Notable features include a debug menu, command line options for various game modes, and a structured approach to ongoing project development status.

open-claude-in-chrome

Open Claude in Chrome is an open-source reimplementation of the official Claude in Chrome extension, providing complete web navigation without the restrictions of an allowlist. It supports any Chromium-based browser and maintains identical performance and feature parity, offering all 18 MCP tools while eliminating any blocked domains. This tool primarily enhances browser automation capabilities by allowing users to access a wider range of websites that the original extension restricts.

MikuTrace

traceMiku is an instruction-level dynamic tracing and runtime analysis tool designed for ARM64 Android devices. It captures real execution paths and provides various analysis features, including control flow graphs (CFG), call trees, taint tracking, and memory queries. Notably, it integrates with Frida for data collection and supports structured JSON output for automated analysis, complementing static tools like IDA and Ghidra.

mgbdis

mgbdis is a Game Boy ROM disassembler that converts ROM files into assembly code compatible with the RGBDS assembler. It supports multi-bank ROMs and utilizes symbol files to define regions of code, data, and other elements, enhancing disassembly accuracy. Additional features include outputting makefiles for ROM rebuilding and generating image files from graphical data blocks.

llm4free

LLM4Free is a versatile Python toolkit that provides access to over 40 AI models, web search capabilities, and image and voice generation, all through a unified interface that mimics the OpenAI SDK. Its notable features include a built-in free tier for various models, multi-provider support with automatic failover, and an OpenAI-compatible server, allowing for seamless integration and development. The tool is fully typed and documented, making it user-friendly for developers.

kUML

Architecture that compiles. Kotlin DSL for UML 2.x, SysML 2 and C4 diagrams-as-code — CLI, Compose Desktop, IntelliJ & Obsidian plugins, Asciidoctor extension on Maven Central, ELK layout, reverse engineering (Java/Kotlin), XMI import/export, plugin SPI. Apache-2.0.

khdays-decomp

khdays-decomp is a matching decompilation project for Nintendo DS's *Kingdom Hearts 358/2 Days*, aiming to produce C source code that can be compiled into an identical binary as the original game. Currently in early development, it reports progress by tracking the count of fully decompiled C functions and distinguishing between real C implementations and temporary ASM placeholders. Notable features include detailed progress metrics and separate handling for SDK/library byte-match identifications.

HBC-Tool

HBC-Tool is a Hermes bytecode disassembler and assembler specifically designed for React Native bundles, facilitating reverse engineering, inspection, and patching of applications that utilize the Hermes engine. Key features include the ability to disassemble bytecode into a human-readable format (HASM), modify the contents, and reassemble valid Hermes bundles, with options for enhanced performance through native C++ acceleration and fast JSON processing. The tool supports multiple Hermes bytecode versions and offers a command-line interface for various operations such as disassembly and assembly.

gitreverse

GitReverse transforms public GitHub repositories into concise synthetic user prompts suitable for various language models, enabling users to generate code from the project context. Key features include the extraction of repository metadata and file structure, as well as support for multiple LLM providers, allowing for flexible integration and enhanced user experience in coding projects.

GD

The Geometry Dash (1.710) decompilation project aims to recreate the core functionality of the game using an older version of the cocos2d-x framework to address limitations present in later versions, such as broken screen orientations and lack of slope features. Currently in a work-in-progress state, it supports multiple platforms, including iOS, Android, macOS, Windows, and Linux, while facilitating community contributions and providing SHA-1 file hashes for various builds.