> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

XingDumper

XingDumper is a Python 3 script designed to extract employee data from the XING social networking platform via its unofficial API. The tool facilitates the retrieval of essential employee information such as name, position, and location using just two API calls, and it includes a feature for auto-generating email addresses based on specified formats. Users must provide a valid XING login cookie and the company URL to initiate the data dump.

osintgpt

`osintgpt` is a Python package that utilizes large language models (LLMs) to perform text analysis tasks relevant to open-source intelligence (OSINT), such as calculating text embeddings and searching for similar documents. Key features include an interactive mode for dynamic user interaction with the GPT model, SQLite database integration for efficient data management, and connectivity to the Qdrant vector similarity search engine for high-performance embedding storage and retrieval.

meta_scan

Meta Scan is an OSINT tool designed to extract comprehensive public profile data from Facebook pages, leveraging the RapidAPI Facebook Pages Scraper. Key features include the ability to retrieve detailed information such as profile and business details, transparency data, and generate JSON reports, all while ensuring secure API key handling and a user-friendly CLI interface. The tool is intended for educational purposes and supports batch processing of usernames, enhancing its usability for researchers.

hostagram

Hostagram is an OSINT tool designed to extract and monitor extensive information from public Instagram accounts. Its primary use case is for research and analysis in the realm of social media intelligence, offering features such as user verification, email and phone number checks, and insights into follower activity. Currently in version 1.4, the tool is under active development with plans for future enhancements.

CyberSeek

Cyberseek is a comprehensive, local threat intelligence and defensive analysis tool designed for security teams, integrating asset visibility, reconnaissance, and indicator enrichment into a unified workspace. Key features include continuous monitoring of domains and IPs, email exposure checks, and robust reporting capabilities, while it also enables the mapping of observed behaviors to the MITRE ATT&CK framework and utilizes AI for evidence-bound summaries. The tool aims to facilitate investigation workflows by preserving local task history and analyst context, enhancing operational efficiency in cybersecurity tasks.

Web-Security-Analizer-Pro

Web Security Analyzer Pro is an advanced web security analysis tool designed for system administrators, developers, and security professionals, providing detailed examination of HTTP headers, cookies, common vulnerabilities, and SSL/TLS configuration. It operates without external queries, generating comprehensive security reports using only HTTP responses, and includes features such as CVE detection from a vast offline database, automated security scoring, and an interactive visual interface. Notable capabilities include in-depth analysis of security headers, cookie security flags, and the identification of technologies used in web applications.

Offensive-Linux-Privilege-Escalation

The Offensive Linux Privilege Escalation tool serves as a comprehensive guide to help users escalate from low-privileged Linux access to root, covering various techniques such as sudo and SUID abuse, kernel exploits, and credential mining. Its primary use case is educational, providing detailed methodology, enumeration scripts, and a structured approach to experience in privilege escalation while emphasizing lawful and authorized testing. Notable features include over 50 documented techniques, automated enumeration scripts, a methodology checklist, and practical lab setups for hands-on learning.

Offensive-Windows-Privilege-Escalation

Offensive Windows Privilege Escalation is a comprehensive guide designed for escalating privileges from a low-privileged Windows environment to Administrator or SYSTEM level, utilizing various techniques such as service misconfigurations, registry exploits, UAC bypass, and token-privilege abuse. The tool emphasizes an offensive security methodology, offering over 75 structured notes complete with hands-on exploitation and detection guidance, alongside ready-to-use commands and methodology checklists. It serves as an educational resource exclusively for authorized testing scenarios, ensuring ethical use in cybersecurity practices.

Offensive-File-Transfer-Techniques

Offensive File Transfer Techniques is an extensive guide designed for transferring files to and from target systems during security engagements, emphasizing staging payloads and exfiltrating data. It covers a diverse range of transport mechanisms, including HTTP, SMB, FTP, TFTP, and more obscure methods like base64 encoding, while also providing detection and defense mappings for each technique. The tool features organized notes with ready-to-use commands for both client and server setups, ensuring comprehensive coverage of file transfer methods in offensive security contexts.

wifi-deauther

The wifi-deauther tool is a Python-based application that automates deauthentication attacks to help users understand 802.11 management frame injection. Primarily intended for testing on networks with proper authorization, it allows users to select a wireless interface and target access points for deauthentication. Notable features include support for Linux systems, the necessity for a wireless card with monitor mode, and the recommendation to use two wireless cards for optimal performance.

SearchToolkit

SearchToolkit is an advanced collection of resources designed for penetration testers, red teamers, blue teamers, and forensic analysts. It includes tools, hardware, cheatsheets, and references across various cybersecurity domains such as geolocation tracking, OSINT, malware analysis, and bug bounties. Notable features include a comprehensive navigation system for quick access to specific areas of cyber defense and offense, highlighting its utility in diverse cybersecurity tasks.

Ethical-Hacking

The Ethical-Hacking repository provides a comprehensive step-by-step guide for learning cybersecurity and ethical hacking using Kali Linux. It covers foundational knowledge in networking and Linux commands, introduces tools like Nmap and Metasploit, and offers practice platforms for hands-on experience. Notable features include recommended resources, structured learning paths, and additional guidance on specialized areas like web application security and certifications.

B1ackOS

B1ackOS is a privacy-focused operating system based on Debian, designed to simplify software package installation and enhance user security. It features a lightweight and versatile environment, allowing for both live usage and easy assembly tailored to individual needs, with a rolling release model that ensures access to the latest software versions. Key functionalities include improved package management, extensive application availability, and compatibility with a wide range of hardware.

pass-the-passkey

The Pass-the-Passkey repository offers a suite of tools designed to exploit and assess the vulnerabilities of WebAuthn and FIDO2 authentication methods in Windows. Key features include the Passkey Injector for intercepting and modifying authentication assertions, SharpPasskeys for executing payloads to retrieve user credentials, and the WebAuthn Hook for tampering with the assertion workflow through API interception. This toolkit is invaluable for security researchers and penetration testers aiming to understand and enhance the security of passkey-based authentication systems.

kontext

Kontext is a runtime governance tool designed for AI agents that enables local policy decisions, pre-action enforcement, and maintains an authorization ledger. It captures tool-use events, evaluates policies prior to action execution, and provides mechanisms for recording decisions, facilitating a balance between security and agent utility. Key features include local enforcement of policies, an observation mode for testing policy impacts, and compatibility with various execution environments, ensuring that security actions are seamlessly integrated into AI workflows without constant reliance on external services.

ggshield-action

GitGuardian Shield (ggshield-action) is a GitHub Action designed to detect exposed credentials and other security vulnerabilities across commits and pull requests. Utilizing GitGuardian's public API, it identifies over 400 types of secrets in your code, allowing for integration into CI/CD workflows to enhance security. Key features include seamless GitHub integration, a stateless scan mechanism, and customizable scanning options.

core_net_scanner

Core Net Scanner is a cross-platform Python tool designed for network discovery and open port detection on local IPv4 subnets, applicable for both personal and organizational purposes. Notable features include LAN detection, custom scanning of specific IPs or ranges, HTTP service scanning, real-time traffic inspection, and a comprehensive logging system for detailed output. This tool is specifically intended for lawful use with explicit permission from network owners, ensuring ethical and responsible operation.

Recaptcha-VM

reCAPTCHA VM is a tool that emulates Google's reCAPTCHA validation mechanism by running its BotGuard engine in a jsdom sandbox environment, enabling the generation of legitimate reCAPTCHA tokens without a browser. It fully supports reCAPTCHA v3 token minting and provides a scoring mechanism to evaluate token legitimacy, while also offering a proof-of-concept for reCAPTCHA v2 that demonstrates the anchor flow and audio challenge URL capture. Key features include real network calls to Google's API and an in-depth implementation of the VM's bytecode interpretation.

hacksguard

Hacksguard is a high-performance, multi-threaded Terminal UI (TUI) static analysis tool designed for SOC analysts, threat hunters, and reverse engineers to analyze Portable Executable (PE) files. Key features include automatic risk scoring based on multiple heuristic axes, integrated YARA scanning capabilities for threat detection, deep inspection of PE format details, and an interactive dashboard for efficient analysis within the terminal. Additionally, it offers functionality for auto-decoding strings, built-in disassembly of opcodes, and can operate in CLI mode for automation in CI/CD environments.

ecd

ECD++ is a fork of the Enhanced Class Decompiler (ECD) designed for decompiling Java class files into readable source code. Its primary use case is to assist developers in analyzing and understanding compiled Java applications by providing improved decompilation capabilities. Notable features include support for integration with Eclipse, multiple download sources (GitHub, Jitpack, SourceForge), and regular updates to enhance functionality and performance.

yuri

Yuri is a decompiler and compiler specifically designed for the Yu-Ris engine, featuring support for parallel processing. Its primary use case is facilitating the decompilation and compilation of game files from various versions of the engine, including both public and commercial releases. Notable features include tools for text extraction and translation, such as `patch_text.py` for editing dialogue in .yuri files and `gbk.py` for modifying text encoding to support Chinese translations.

listary-keygen

Listary Keygen is a Windows GUI tool designed for activating the Listary Pro license using a single-click process. It employs reverse engineering techniques to bypass the official license verification system, allowing users to generate and write a valid license key directly into the application's configuration file. Notable features include automatic key generation, backup of existing settings, and a straightforward user interface for seamless activation.

js-reverse-mcp

JS Reverse MCP is an AI-native JavaScript reverse engineering server designed to enhance AI coding assistants with continuous debugging and analysis capabilities for web JavaScript behavior. It features advanced tools for breakpoint management, network and WebSocket analysis, and browser state replay, while also incorporating anti-detection mechanisms to navigate strongly protected sites seamlessly. The tool organizes script execution and data handling specifically for AI agents, enabling them to perform sophisticated tasks like locating scripts, saving sources, and reproducing complex web interactions.

fnprint

fnprint is a binary analysis tool that uniquely identifies functions in stripped executables by analyzing their behavioral side effects rather than relying on byte signatures or control-flow graphs. It emulates function execution with fabricated inputs to generate behavior-based fingerprints, allowing for more resilient matches across different compiler optimizations and versions. Key features include indexing known binaries for function identification, differential analysis to detect behavioral changes between builds, and a triage capability to assess potential vulnerabilities based on function behavior comparison.

ReconGPT

ReconGPT serves as a robust tool for passive reconnaissance, allowing security analysts to assess an authorized attack surface using corroborated public information while avoiding active scanning. Its interface is designed as a casefile that facilitates the entire investigative process, from target selection to evidence collection, with features like live telemetry for monitoring progress, an evidence explorer for detail inspection, and a report generation capability that preserves the context and limitations of findings. Notably, ReconGPT emphasizes evidential quality and offers insights into risk and data provenance, enabling analysts to effectively distinguish between validated evidence and inferences.