> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

chomper

Chomper is a lightweight emulation framework designed for security algorithm testing in iOS executables and libraries, with limited support for Android native libraries. It supports the emulation of ELF and Mach-O binaries and integrates with the Unicorn engine for dynamic analysis, allowing users to engage with Objective-C runtime and directly manipulate security algorithms. Notable features include automatic loading of iOS system libraries and comprehensive API support for invoking functions and managing memory.

cascade-protocol-dissector

Torii Gateway is a middleware solution designed to provide researchers with persistent, authenticated access to advanced inference pathways of large language models (LLMs) while bypassing tiered consumption limits imposed by commercial APIs. Its notable features include protocol reflection to mimic enterprise-tier traffic, token frame rebalancing to adjust apparent consumption rates, and session entropy injection for neutralizing identifiable session fingerprints, facilitating a seamless connection to multiple inference providers without altering client-side code. This tool serves as a crucial resource for overcoming restrictions that hinder research and experimentation with frontier LLM capabilities.

Brovan

Brovan is an interactive x86_64 binary emulator designed for the analysis and execution of untrusted software while providing advanced features for reverse engineering, API tracing, and network traffic interception. It supports multiple binary formats, leverages hardware acceleration through WHP and KVM backends, and includes a custom Vulkan graphics layer for rendering applications. Primarily aimed at cybersecurity professionals and researchers, Brovan facilitates safe program execution and detailed inspection of system calls and network activity.

BetrockPlusPlus

BetrockPlusPlus (BPP) is a comprehensive, from-scratch reimplementation of Minecraft Beta 1.7.3, designed to function both as a client and server while prioritizing compatibility and faithful reproduction of original features. The tool is cross-platform, being compatible with both Windows and Linux, and fully open-source, providing the community with opportunities to fork, contribute, and enhance the project. Notably, BPP emphasizes clean coding practices by avoiding the use of decompiled code, ensuring that any necessary references to such code are clearly documented.

asmtransformers

ASMTransformers is a machine learning tool designed for analyzing ARM64 assembly functions by comparing them to a database of known functions to facilitate reverse engineering tasks. Its architecture includes a training and inference module, a FastAPI backend for service management, and a Ghidra frontend for user interaction, with models available on Hugging Face. Notable features include dynamic similarity scoring and an integration framework for seamless use within Ghidra.

AIDA64-Network-Audit-2026

AIDA64 Network Audit scans local and remote computers to collect hardware, software and network configuration data, generating inventory reports. It supports scheduled scans, queries, export to CSV, HTML, XML, and integrates with Active Directory for asset tracking.

advanced-anti-sandbox-Virtual-Machine

The Advanced Anti-Sandbox Virtual Machine tool develops techniques to counteract sandbox detection in malware analysis environments. Its primary use case is to assist security researchers and malware developers in executing samples without triggering detection in virtualized analysis frameworks by employing various bypass strategies, including path verification and time-based checks. Notable features include static bypassing capabilities, integration with C++ programming, and the ability to adapt to various sandbox systems, enhancing the efficacy of evasion techniques.

defcon-2017-tools

The DEFCON CTF 2017 repository features a collection of tools developed for the DEFCON 25 Capture The Flag competition. It includes an assembler with custom macros, a binary patcher, flag encryption utilities, IDA plugins for disassembly viewing, and PCAP analysis tools. Notable features include enhanced disassembly capabilities and various utility scripts aimed at improving offensive security techniques.

YAPS

YAPS is a lightweight PHP reverse shell that operates as a single file, allowing users to execute commands on remote systems through a TCP listener. It features customizable password protection, enumeration capabilities for gathering system information, and the ability to manage concurrent connections and execute PHP code remotely. Notably, it can auto-download enumeration tools, exploit known vulnerabilities like CVE-2021-4034, and send shellcode to the target host while supporting operations on both Linux and Windows in future updates.

xeca

xeca is a tool designed for creating encrypted PowerShell payloads intended for offensive security applications. It enables users to develop position-independent shellcode from DLL files and integrates an AMSI bypass feature for enhanced stealth. Key functionalities include encryption of payloads, remote execution capabilities, and retrieval of decryption keys via a controlled web server.

wiz-search

Wiz-search is a Python-based offline search tool designed for the Mac version of Wiz Note, enabling full-text search capabilities even without internet access. It analyzes the application's data storage structure, which uses SQLite for metadata and ZIP compression for notes, and employs Whoosh and Jieba for indexing and searching. Key features include the ability to create and update an index, facilitating seamless offline access to notes during situations such as offline CTF competitions.

web-ctf-labs

The "web-ctf-labs" repository is a collection of web-based Capture the Flag (CTF) challenges designed for cybersecurity training and skill development. It features diverse challenges, including Host Header Injection, Server-Side Template Injection in Flask, and SQL Injection, among others, providing a practical environment for enhancing web security knowledge. Notable features include a variety of challenge types that cater to different aspects of web vulnerabilities and security testing.

web-ctf-help

Web-CTF-Help is a set of Python scripts designed for assisting participants in web Capture The Flag (CTF) competitions by scraping relevant information from target websites. Its primary use case involves extracting HTML comments, JavaScript sources, image sources, and interesting HTTP headers, with features allowing for selective output based on user-defined parameters, including cookie management for authenticated requests. Future enhancements may include functionality for downloading extracted resources.

vulnlab

vulnlab is a tool designed to manage an OSCP-like lab environment by providing a web control panel for resetting virtual machines. Utilizing Flask and the pyvmomi library, it allows users to easily reset configured VMs through a simple web interface, with output accessible via HTTP requests. Notable features include the ability to configure VM settings for non-persistent disk changes and web-based controls for VM lifecycle management.

TryHackMe_writeups

This repository houses a collection of writeups for various Capture The Flag (CTF) challenges on the TryHackMe platform. The writeups cover a diverse range of scenarios, including penetration testing, web vulnerabilities, and privilege escalation, utilizing tools such as `nmap`, `gobuster`, and `metasploit`. Users can gain insights and methodologies for tackling CTF challenges while also having access to a more visually appealing format via GitHub Pages.

tankigen

Tankigen is a command-line tool for generating a variety of reverse shell payloads, drawing from established cheat sheets by PayloadsAllTheThings and Pentestmonkey. It supports multiple scripting languages such as Bash, Python, and PowerShell, allowing users to easily create reverse shells for capture the flag (CTF) challenges and penetration testing scenarios. Notable features include the capability to list available shell types and generate all shells simultaneously, enhancing the tool's flexibility for security professionals.

stegreg

Stegreg is a C++ based steganography tool that enables users to encrypt and conceal data within image files, specifically supporting JPG and PNG formats. Its primary use case is to hide messages within images through byte manipulation, while also allowing for easy extraction of the hidden data. Notable features include command-line options for encoding and decoding messages, as well as a straightforward installation process.

Stegall

Stegall is an automation tool designed to facilitate the use of popular steganography tools, primarily targeted towards participants in Capture The Flag (CTF) challenges. It encompasses a suite of 12 key tools, including Steghide and Exiftool, and provides streamlined commands for tasks such as extracting hidden text, analyzing metadata, and detecting concealed data within various file formats. The tool requires Python 2.7 and simplifies the steganographic process by automating tool suggestions, installations, and executions based on user inputs.

SSH-BruteForce

SSH Brute-Force is a simple Python script designed for brute-forcing SSH credentials against an OpenSSH server. Its primary use case is for ethical hacking and penetration testing, specifically within environments like HackTheBox. Notable features include the ability to execute commands upon successful authentication and the requirement of the pwntools library, though it is advised that users enhance its functionality to mitigate potential defenses against brute-force attacks.

soma

Soma is a cross-platform CTF problem container management tool that facilitates the creation, distribution, and execution of capture-the-flag (CTF) problems for both problem authors and solvers. Notable features include simple command-line usage for downloading and running CTF challenges, as well as support for easy configuration through a `soma.toml` file, which allows problem setters to define the execution environment and file permissions. The tool requires Docker to function and aims to streamline the CTF experience by providing reproducible environments for problem-solving.

shellcat

ShellCat is a centralized management tool for handling reverse shells, allowing multiple shells to connect to a single listening port, simplifying the process of managing numerous connections. Its primary use case is to streamline the execution of commands across multiple reverse shells simultaneously, enhancing operational efficiency in security operations. Notable features include the ability to send commands to all connected shells at once.

Scuffed_Low_Level_Stash

Scuffed Low Level Stash is a curated resource repository focused on binary exploitation and reverse engineering, providing a wealth of educational materials including tutorials, courses, and reference links related to assembly language and low-level programming. Its notable features include a comprehensive list of recommended resources, practical tutorials, and useful references for both beginner and advanced practitioners in the field. The tool serves as a centralized platform for learners and professionals looking to enhance their skills in binary exploitation tactics.

SCUCTF-CMS

SCUCTF-CMS is a content management system designed specifically for the Sichuan University Capture The Flag (CTF) Association. Its primary use case is to facilitate the organization and management of CTF events and content. Notable features include customizable content handling tailored for CTF activities.

RSA-Common-Modulus-Attack

RSA-Common-Modulus-Attack is a Python 3 script designed to exploit the common modulus vulnerability in RSA encryption by recovering plaintext messages from two ciphertexts encrypted with the same modulus but different exponents. The tool requires the public keys of both ciphertexts and operates under the condition that the greatest common divisor of the two exponents is 1. Notable features include a simple command-line interface for inputting ciphertexts and public keys, as well as dependency management through a requirements file for easy installation.

revshfuzz

A tool for fuzzing for ports that allow outgoing connections