> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

decompose

Decompose is a reverse-engineering tool designed for analyzing Docker environments by extracting and visualizing all network connections from containers. It supports multiple output formats including graphviz dot, structurizr DSL, and CSV, providing detailed insights into container interconnections, including ports and statistics. Notable features include high-speed scanning capabilities, deep inspection of process connections, and a single-binary deployment for cross-platform compatibility.

capa-rs

capa-rs is a file capability extractor designed to analyze executable files, including PE, ELF, Mach-O, and .NET binaries. It identifies specific capabilities and behaviors, such as potential backdoor functions or security attributes like ASLR and NX, while providing a command-line interface for ease of use. The tool is a Rust implementation of the original Python capa, offering high accuracy and customizable security checks, making it suitable for in-depth malware analysis and binary security assessments.

Bullseye

Bullseye is a reverse engineering tool specifically designed for the game Resident Evil: Dead Aim, facilitating the extraction of game assets such as audio files, model data, and textures, with ambitions of achieving full decompilation. It supports meticulous matching of the original executable by reconstructing the binary byte-for-byte, ensuring that every loadable portion is accurate, a characteristic vital for developers and modders aiming to analyze or modify the game's code. Key features include a structured build process utilizing an EE binutils toolchain and compatibility with original game dumps, allowing users to verify the integrity of their builds against the original release.

Awesome

Awesome is an open-source repository that aggregates a variety of tools and resources across multiple domains including communication, development, finance, and information security. Its primary use case is to provide users with a centralized catalog of high-quality software, libraries, and educational resources, aiding in quick access to knowledge and tools. Notable features include a structured table of contents for easy navigation and a focus on simplicity, readability, and collaboration best practices.

areclaw

areclaw is an automated command-line environment designed for Android application security analysis, enabling tasks such as decompilation, traffic interception, dynamic instrumentation, secret scanning, and API discovery. It leverages an AI-driven orchestrator, Claude Code, to streamline the analysis process, and includes an automated installer for essential tools, a structured workspace for outputs, and various utility scripts for enhanced interaction and reporting.

wow-optimize

wow_optimize is a performance optimization DLL specifically designed for World of Warcraft 3.3.5a, targeting enhancements at the engine and runtime level to address memory allocation, Lua VM efficiency, and various low-level bottlenecks. Its primary use case is to improve frametime stability and reduce Lua overhead during addon-heavy gameplay while maintaining safety from historically unsafe features. Notable features include memory address space reduction, CPU-intensive optimizations, and compatibility adjustments that allow for smoother long-session gameplay.

windiff

WinDiff is an open-source, web-based tool designed for browsing and comparing symbol, type, and syscall information of Microsoft Windows binaries across different OS versions. Its primary use case is to facilitate analysis for security researchers by providing a user-friendly interface to visualize changes in Windows binaries and automate version comparisons through an integrated AI assistant. Notable features include a dual structure comprising a CLI tool and a TypeScript frontend, automatic updates from the latest Windows versions, and the ability to analyze binary changes using the Claude Code skill.

ttd-capa

ttd-capa is a capability extractor that works with Time Travel Debugging (TTD) traces to identify the capabilities exercised by a binary during its runtime execution. Designed to enhance the analysis of packed or obfuscated malware, it generates CAPA-compatible reports that allow for the extraction of runtime capabilities, leveraging full execution context and timestamp data for detailed analysis. Notable features include automatic resolution of string arguments, reconstruction of execution order, and integration with existing CAPA rule sets for comprehensive malware triage.

TRR-SaveMaster

TRR-SaveMaster is an open source savegame editor designed for Tomb Raider I-VI Remastered, allowing users to modify various aspects of their savegames, including inventory, weapons, health, and player position. It supports cross-platform compatibility, enabling edits for PC, PS4, Android, and Nintendo Switch formats, and features tools for unlocking game content and deleting savegames. The editor also provides a position teleportation feature, facilitating seamless navigation within game levels.

SR-CoD4x

SR CoD4x is a modification of the Call of Duty 4: Modern Warfare server that addresses original game bugs and enhances server functionality through a plugin system. Notable features include automated client updates, robust anti-cheat measures, extended player movements, and a reliable player identification mechanism, providing a more optimized and feature-rich gaming experience for players.

spm-decomp

spm-decomp is a decompilation project focused on the Super Paper Mario game, primarily targeting the PAL versions along with some support for the NTSC-U version. It aims to extract specific parts of the game's code useful for modding or analysis, without intending to provide a complete decompilation or platform ports. Notable features include the ability to modify game behavior through a configurable setup and support for various disc image formats for building the project.

SonolusReverse

SonolusReverse is a modification for the Sonolus rhythm game that enables enhanced features through the Frida framework, specifically tailored for Android (with potential iOS compatibility). Its primary use case is to unlock VIP access and custom themes for the game, along with providing functionalities for version spoofing and a dedicated settings section for personalized configurations. Notable features include the ability to create custom themes in JSON format and a client-side unlock for all exclusive content, facilitating a tailored gaming experience.

sonicheroes

Sonic Heroes is a decompilation project aimed at preserving the Nintendo GameCube version of the game, specifically targeting the G9SE8P revision. This non-commercial initiative does not contain any game code or assets but allows users to build their own copy using a legally obtained game. Notable features include detailed tracking of progress through badges, cross-referencing with PS2 builds for metadata, and a strict adherence to legal guidelines concerning artifact distribution.

SiliconRE

SiliconRE is a reverse-engineering tool for analyzing custom chips primarily from the 80s and 90s, focused on video game hardware. It provides detailed traces, schematics, and a chip database, along with functionalities like access to cell lists to streamline reverse-engineering processes. Notable features include the tracking of project statuses and collaborative resources for sharing findings in the retro hardware community.

Silent-Hill

Silent Hill Hub is a comprehensive repository designed for reverse engineering, documentation of file formats, and modding tools for the Silent Hill video game series. It provides utilities for extracting and viewing game assets such as 3D models, textures, audio, as well as scripts for various popular tools like 010 Editor and Noesis, facilitating in-depth exploration and modification of game content. Additionally, the project aims to preserve community knowledge and resources related to the series, thereby supporting both developers and enthusiasts in the Silent Hill modding community.

SickoMenu

SickoMenu v4.5.2 is a utility tool for the game Among Us, designed to enhance gameplay through various custom features, including NoClip, Ghost Visibility, and SickoChat. It is intended strictly for educational and experimental purposes within private lobbies, and emphasizes ethical use to avoid violations of Innersloth's terms. Notable functionalities include gameplay modifiers and a comprehensive list of mischief-inducing options, promoting responsible use while exploring game mechanics.

ShadowStrike

ShadowStrike Phantom is an open-source endpoint protection platform for Windows 10/11 that aims to deliver advanced threat detection capabilities comparable to commercial EDR solutions. Notable features include a custom kernel driver with 20 detection subsystems, an on-device analysis engine utilizing neural networks, and a malware emulation engine—all designed to ensure transparency and audibility in its security processes.

sead

The sead repository offers a decompilation of the standard C++ library used in first-party Nintendo games, specifically targeting more recent versions of the library. Its primary use case is to enhance interoperability and facilitate the development of projects that interact with these games, by accurately recreating the library structure based on debugging symbols from selected titles. Notable features include modular organization for various functionalities such as audio, graphics, and threading, as well as support for multiple Nintendo platforms through configurable source directories.

rtl8196e-gateway

The RTL8196E Gateway project provides open Linux firmware for the Lidl Silvercrest Zigbee Gateway, transforming it into a fully local smart home hub capable of serving as a Zigbee coordinator, Thread Border Router, or Zigbee router. Notable features include support for modern Zigbee stacks, SSH access for secure management, and the ability for over-the-air firmware updates. The firmware is designed to be portable across various RTL8196E-based gateways, bolstering its versatility in IoT environments.

rizin

Rizin is a comprehensive reverse engineering framework designed for analyzing binaries, disassembling code, and debugging programs, offering enhanced usability and features compared to its predecessor, radare2. It supports a wide array of operating systems and architectures, includes multiple utilities for scripting and binary manipulation, and facilitates interaction with popular programming languages through rzpipe. Notable features include a command-line assembler, tools for binary comparison and pattern searching, as well as extensive file format compatibility.

rhabdomancer

Rhabdomancer is a high-performance headless plugin for IDA that identifies calls to potentially insecure API functions within binary files. It aids security auditors by backtracking from these functions to find vulnerabilities related to untrusted input, complete with a prioritization system that categorizes known bad API calls. Notable features include support for various C/C++ binary targets and the ability to customize the list of bad API functions according to user-defined criteria.

reverseloom

reverseloom is a tool designed to automate the extraction of data from websites protected by advanced bot detection systems, such as Akamai Bot Manager. It employs a unique approach by interacting directly with the browser using a headless environment to reverse engineer the site's protocol, enabling it to generate standalone crawlers that function without a browser. Notable features include complete exposure of the website's DOM, network traffic, and JavaScript debugger, along with the ability to create fully operational, browser-free crawlers that are capable of executing tasks autonomously.

revenge-bundle-next

Revenge is a lightweight client modification for Android's Discord that enables users to customize their experience with plugins, themes, and experimental features. Its framework allows developers to create and integrate custom add-ons seamlessly, enhancing overall functionality. Notable features include a user-friendly interface, support for extensive personalization, and streamlined installation methods for both rooted and non-rooted devices.

REPENTOGON

REPENTOGON is an advanced mod for *The Binding of Isaac: Repentance+* that enhances the Lua API with critical bug fixes, extended functionality, and performance optimizations. Unlike traditional mods, REPENTOGON operates as an "EXE mod," interfacing directly with the game's code through the LibZHL framework, allowing for sophisticated modifications that were previously unachievable. Notable features include a robust API documentation, extensive enhancements to game mechanics, and an emphasis on performance without the need for intensive hacks.

rea

REA (Reverse Engineer Anything) is a command-line interface (CLI) and multi-component platform (MCP) server designed to facilitate reverse engineering of software applications, enabling users to investigate features even without access to source code. Notable features include deep native analysis using Hopper or Ghidra, execution-free managed PE/CLI triage, evidence management, and structured workflows that simplify the reverse engineering process by automating tool interactions and data collection. The tool ultimately aims to assist users in understanding, documenting, and recreating features for custom applications seamlessly.