> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

vheap

vHeap is an extendable visualization and exploitation tool designed for glibc heap memory analysis during debugging sessions, primarily targeting security researchers and CTF players. It allows users to visualize heap memory in real-time within a web browser leveraging GDB's pwndbg integration, with features like automatic heap state updates and customizable extensions for other debuggers. Notably, vHeap facilitates easier exploitation of heap memory by transforming complex memory structures into interactive visual representations.

TryHackMe

TryHackMe is a free cybersecurity learning path designed to advance users from novice to expert through a range of practical exercises, introductory Capture The Flag (CTF) challenges, and educational modules covering topics like OpenVPN, Linux fundamentals, web scanning, and Metasploit. This resource is suitable for both newcomers to the field and those looking to enhance their skills, and it culminates in a comprehensive foundation in cybersecurity, preparing users to address more complex challenges. Notable features include diverse content formats, hands-on labs, and accessible learning materials to foster practical experience in cybersecurity practices.

TryHackMe

TryHackMe is a cybersecurity training tool that provides structured learning paths for users to develop their skills in various domains such as penetration testing and cyber defense. It features hands-on modules and challenges that allow learners to practice offensive and defensive security techniques, offering certifications upon completion of specific tracks. Notable capabilities include the ability to quickly download and execute training scripts, facilitating an interactive learning experience.

stegsolve

Stegsolve v1.3 is a steganography analysis tool designed for extracting and manipulating hidden data within images. Its primary use case includes visualizing different bit planes, extracting data, analyzing file formats, and solving stereograms, alongside features such as a frame browser for animated images and image combination capabilities. Notably, it also offers basic file recovery analysis for corrupted images while providing comprehensive functionality for steganographic challenges.

stegbrute

stegbrute is a rapid steganography brute-force tool developed in Rust, designed for extracting hidden data from media files that use the steghide utility. It offers multiple installation methods, including Cargo, Debian packages, and Docker, catering to various operating systems and user preferences. Notable features include customizable options for brute-forcing password protection and the ability to save results efficiently in a designated volume when used with Docker.

S4DFarm

S4DFarm is a modified version of the DestructiveFarm tool designed for automated server management and orchestration in a competitive environment. Its primary use case involves facilitating multiplayer game server deployments, leveraging Docker for containerization, with notable features including customizable configurations for server settings and secure password management.

reversingBits

The Reversing Bits Cheatsheets repository serves as a comprehensive resource for assembly programming, reverse engineering, and binary analysis tools. It includes in-depth guides on installation, usage examples, and advanced tips for a variety of tools, such as assemblers, debuggers, disassemblers, and binary analysis frameworks, catering to different operating systems and user needs in the field of cybersecurity. Notably, it features prominent tools like Ghidra, IDA Pro, and GDB, making it a valuable reference for professionals involved in security and malware analysis.

reversing-utils

My Reversing Utils is a collection of open-source tools designed for reversing, debugging, and software analysis, offering utilities for process management as well as web and binary analysis. Key features include the ProcSuspender, which enables users to launch processes in a suspended state for detailed debugging. This repository serves as a practical resource for security researchers and developers looking to facilitate their software analysis tasks.

mkctf

mkCTF is a framework designed to facilitate the creation and management of jeopardy-style Capture The Flag (CTF) challenges, employing a configurable structure for streamlined integration and deployment on CTF infrastructure. Its notable features include the mkctf-cli tool for repository manipulation and challenge management, as well as the mkctf-monitor for regular health checks and reporting, enhancing automation in the challenge deployment process. The framework is tailored for Python environments and emphasizes security protocols for handling challenge data.

liveexploit

Live Exploit is a comprehensive Python-based tool tailored for Capture The Flag (CTF) challenges, exploit development, and vulnerability research. It offers a rich feature set including buffer overflow payload generation, ROP chain creation, fuzzing, and interactive command execution, all presented through an intuitive command-line interface. This all-in-one toolkit is designed for both novice and advanced users, streamlining numerous exploit-related tasks while being cross-platform compatible.

LibcSearcher3

LibcSearcher3 is a Python tool designed for Capture The Flag (CTF) competitions, facilitating the search for function offsets in the C standard library (libc) when a function address is leaked. Its notable features include the ability to initialize a libc database, add constraints for more accurate results, and query multiple libc versions through a command-line interface or programmatically. This tool leverages the libc-database for efficient lookups and is aimed at reducing the time spent manually verifying common libc versions.

Karkinos

Karkinos is a lightweight penetration testing tool designed for ethical hacking and CTF competitions, offering functionalities such as encoding/decoding, encryption/decryption, and hash cracking/generating. It features three distinct modules and includes a new port scanning demo, allowing users to test applications and networks they have authorization to assess. Built primarily using PHP and Python, Karkinos is compatible with any server capable of hosting PHP and is designed to be Raspberry Pi Zero friendly.

HackSynth

HackSynth is a sophisticated LLM-based agent designed for autonomous penetration testing using a dual-module architecture comprising a Planner and a Summarizer. Its primary use case is to conduct security assessments, and it is benchmarked against two extensive CTF-based datasets derived from PicoCTF and OverTheWire, featuring 200 diverse challenges. Notable features include its iterative command generation and feedback processing capabilities, enabling comprehensive evaluation of LLM penetration testing agents.

hackme

HackMe is a Capture The Flag (CTF) tool designed for Android devices using Termux, enabling users to participate in cybersecurity challenges. Notable features include a simple setup process through bash scripts and a straightforward interface for executing CTF tasks. Primarily aimed at individuals looking to enhance their penetration testing skills in a controlled environment.

HackGurat

HackGurat is a cybersecurity resource platform that offers a wide array of expertise in fields such as web security, cryptography, reverse engineering, and more. It features educational platforms and useful links for further learning, alongside a section for write-ups and PDF resources, facilitating both skill development and practical understanding in cybersecurity. The tool aims to be a comprehensive hub for cybersecurity professionals and enthusiasts to enhance their knowledge and skills through curated content and resources.

fubar

FUBAR is a terminal user interface (TUI) tool designed for offline payload generation, retrieval, and exfiltration, particularly in restrictive shell environments. It provides power users with access to thousands of payloads sourced from gtfobins, facilitating security research and privilege escalation operations. The tool features intuitive navigation through keybindings, payload copying capabilities, and is currently in prototype status with additional features planned for future implementation.

forthectf

The "forthectf" repository is a curated collection of cybersecurity tools specifically assembled for use in Capture The Flag (CTF) competitions. It encompasses a wide array of categories including cryptography, cracking, steganography, and general forensics, featuring notable tools such as John The Ripper and Hashcat for password cracking, and various tools for encryption and steganalysis. This resource is intended for educational purposes, with users encouraged to contribute updates and fixes to the list of tools.

Flask-Unsign

Flask Unsign is a command-line tool designed for extracting, decoding, and manipulating Flask session cookies by brute-forcing secret keys. Its primary use case revolves around security testing of Flask applications, enabling users to obtain and decode session data either through direct input or automatic server interactions. Notable features include session cookie decoding, secret key brute-forcing, and the ability to create custom signed session data if the secret key is known.

first-strike-alert

First Strike Alert is a CTFd integration tool designed to announce "first blood" achievements during capture-the-flag competitions with real-time audio-visual notifications. Its notable features include automatic sound playback, fullscreen announcements, a cyberpunk-themed interface, and live tracking of team statistics and first bloods. The tool polls the CTFd API for updates every five seconds, ensuring instantaneous notifications, while its responsive design allows for usability across various display sizes.

Dragoman--The-Decoder

Dragoman is a versatile decoding tool designed specifically for tackling cryptography challenges in Capture The Flag (CTF) competitions, providing a comprehensive suite of decoding scripts. It includes functionalities for a wide range of ciphers and encoding schemes, such as Base64, Caesar cipher, Morse code, and more, streamlining the process of flag extraction. This tool enhances efficiency by consolidating multiple decoding methods into a single framework, allowing users to quickly switch between different decoders.

DOM-Clobber3r

DOM-Clobber3r is a tool designed to generate DOM clobbering attack vectors, which are used to exploit vulnerabilities in web applications that mishandle the Document Object Model (DOM). Its primary use case is to aid security researchers and developers in identifying potential attack surfaces within web applications. Notable features include automated generation of various clobbering scenarios, facilitating the testing of DOM-based security defenses.

ctfify

ctfify is a command-line tool designed to streamline the downloading and management of Capture The Flag (CTF) challenges. It allows users to efficiently search for challenges based on name, category, or tags, facilitating quick downloads to local machines. Notable features include an easy-to-use interface and the capability of handling multiple challenges with minimal commands.

CTF-Resources

The CTF Resources repository is a comprehensive collection of cybersecurity tools and practice platforms specifically designed for Capture the Flag (CTF) competitions. It includes an extensive array of tools categorized into areas such as Open Source Intelligence (OSINT), steganography, and anonymous communication, offering functionalities from data gathering and analysis to secure and anonymous internet browsing. Notable features include links to various open-source tools, detailed descriptions, and categorization for ease of use, supporting users in enhancing their digital security skills.

CTF-Heaven

CTF-Heaven serves as a resource hub for CTF (Capture The Flag) participants, offering a collection of security lists, cheatsheets, and wordlists that aid in penetration testing and security assessments. Notable features include organized links to essential tools like SecLists and PayloadsAllTheThings, as well as a dedicated section for esoteric programming languages, which adds a unique element for enthusiasts exploring unconventional coding challenges.

CTF-Game

The Pixels Camp Security CTF Dashboard is a web-based tool designed to manage Capture The Flag (CTF) security competitions, facilitating both participant engagement and organizer oversight. Key features include a public dashboard to display real-time CTF progress, a private area for teams to submit answers and track their performance, as well as a backoffice for administrative tasks, including logging submissions and issuing announcements. The tool allows for seamless competition management through start/stop controls, pause functionality, and team token authentication.