03 Aug 2026
Python
★ 30
CloverSec-CTF-Build-Dockerizer is a specialized tool designed for generating Docker containers tailored for Capture The Flag (CTF) competitions and vulnerability assessment environments. Its primary use case focuses on automating the conversion of challenge attachments, source codes, and specific directories into Docker images that comply with validated competition platforms, utilizing a structured workflow that significantly reduces manual intervention and uncertainty in the build process. Notable features include stage-specific document handling, improved token efficiency, and automated validation checks, which collectively enhance the operational flow and maintain the quality of deliverables.
03 Aug 2026
Python
★ 45
cheb3 is a web3 Capture the Flag (CTF) tool built on the web3.py library, designed to simplify interactions with Ethereum smart contracts. Its primary use case is to facilitate the development of exploits and solutions for blockchain-based challenges, featuring streamlined transaction operations and the ability to load compiled smart contract ABIs efficiently. Notable features include a user-friendly connection interface and utility functions for managing account and contract interactions, making it suitable for both novice and experienced CTF participants.
03 Aug 2026
Lua
★ 50
The Cheat Engine MCP Bridge — TCP Enhanced Edition is a tool that facilitates remote control of Cheat Engine via a native C TCP bridge, eliminating the need for Python's pywin32 dependency and supporting multiple instances. Key features include built-in remote access via environment variables, improved stability with auto-reconnect capabilities, and a dedicated diagnostic console, making it a more versatile and reliable option compared to the original fork.
03 Aug 2026
Python
★ 14
Axion is a versatile toolkit designed for Capture The Flag (CTF) competitions that allows users to control various input/output operations of its integrated tools, streamlining the CTF experience. It is compatible with several popular Linux distributions and requires Python 2.7, enhancing accessibility for cybersecurity practitioners. Notable features include easy installation via a script and a user-friendly command-line interface for launching functionalities.
03 Aug 2026
Python
★ 126
Ataka is a command-line tool designed for running exploits in competitive Capture The Flag (CTF) hacking environments, allowing players to create, manage, and test their exploits efficiently. Notable features include the ability to set up exploits with specified target IPs, hot-reload configurations, and a templating system for easy exploit creation. The tool operates within a Docker container, providing a flexible and isolated environment for users to conduct their attacks and tests.
03 Aug 2026
Perl
★ 25
ASN.1 Template is a Perl-based tool designed to convert DER or PEM encoded ASN.1 structures into a human-readable textual format suitable for modifications and subsequent encoding via OpenSSL's ASN1_generate_nconf(3) function. Key features include support for processing multiple concatenated ASN.1 structures and options for simplified labeling and unwrapping of top-level sequences, enabling streamlined ASN.1 structure manipulation without the need for compilation.
03 Aug 2026
Go
★ 120
`xsubfind3r` is a command-line utility that efficiently discovers subdomains for a specified domain using information from various passive data sources. It is particularly useful for security researchers and IT professionals, offering features such as support for multiple output formats (including JSONL and stdout), the ability to integrate seamlessly into automated workflows via `stdin` and `stdout`, and cross-platform compatibility across Windows, Linux, and macOS.
03 Aug 2026
Go
★ 111
`xcrawl3r` is a command-line tool that recursively spiders websites to discover URLs by actively traversing webpages and parsing files such as sitemaps and `robots.txt`. This active spidering approach distinguishes it from similar tools by revealing hidden or unindexed links, making it particularly useful for security researchers and IT professionals. Notable features include support for multiple output formats, cross-platform compatibility, and integration with automated workflows through standard input and output options.
03 Aug 2026
Python
★ 149
Writeup-Miner is a versatile tool that scrapes new RSS feeds and stores them in a MongoDB database or a text file while providing real-time notifications through Telegram or Discord. Its notable features include keyword filtering, an easy command-line interface, and support for multiple storage methods, making it ideal for security researchers and technology enthusiasts looking to stay current with Medium content.
03 Aug 2026
Python
★ 14
This program aims to check active targets by saving screenshots in a project.
03 Aug 2026
Python
★ 35
Web Scraper is a Python-based tool designed for web hacking and assessment, featuring a suite of 20 widely-used functionalities for executing various attacks and reconnaissance tasks with a single command. Its notable features include ASN lookups, HTTP header analysis, subdomain discovery, vulnerability scanning, and more, providing users with a comprehensive toolkit for bug bounty and data extraction efforts. It operates on Python 3.7 or higher and is optimized for Linux environments.
03 Aug 2026
TypeScript
★ 69
Warlusts is a repository that provides a collection of curated and custom wordlists for use in various security testing scenarios, particularly for password cracking and penetration testing. Its primary use case is to enhance the efficiency and effectiveness of brute force attacks by supplying tailored wordlists. Notable features include the extensive curation of words and phrases, which are designed to cater to different attack vectors.
03 Aug 2026
Shell
★ 20
Vasuki is an automation tool designed for security professionals that streamlines the process of subdomain enumeration and vulnerability scanning. It aggregates multiple reconnaissance tools to identify subdomains, check for subdomain takeover potential, and detect various injection parameters including XSS and SSRF. Notable features include integration with tools like Nuclei for vulnerability scanning, notification capabilities for scan results, and an organized output of findings in text files.
03 Aug 2026
Python
★ 50
Status Checker is a Python-based tool designed to evaluate the HTTP status of multiple URLs or domains, categorizing them according to their response codes. It features asynchronous processing for enhanced speed, automatic redirection following, and capabilities to log results, which can be visually represented with color-coded output. The tool operates via a command-line interface, facilitating easy access and output management.
03 Aug 2026
Python
★ 47
The Ultimate Bug Hunting Tools repository provides a comprehensive script that automates the installation of 50 popular tools utilized in bug bounty programs for vulnerability assessment. It features a diverse range of functionalities, including reconnaissance, exploitation, and information gathering, through tools like Amass, EyeWitness, and WPScan. This facilitates a streamlined approach for security researchers to efficiently set up their bug hunting environment with essential tools.
03 Aug 2026
Go
★ 16
Subscan is a high-performance CLI tool designed for subdomain enumeration tailored for bug bounty hunters and security professionals. It offers both passive reconnaissance by leveraging public sources and active DNS resolution capabilities through customizable wordlists, alongside features for subdomain scoring, misconfiguration detection, and diverse output formats. Additionally, it supports concurrency for increased scanning speed and plans to introduce extensibility for plugins in the future.
03 Aug 2026
C#
★ 312
The Internets #1 Subdomain Takeover Tool
03 Aug 2026
Shell
★ 117
Sub-Drill is a straightforward script designed for penetration testers and bug bounty hunters to discover subdomains for a given domain using free online services, eliminating the need for API keys. It provides a pipe-able solution that aggregates subdomain data from multiple sources such as ThreatCrowd, CRT.sh, and URLscan.io, and enables optional output to a specified file. This tool is particularly useful for enhancing reconnaissance efforts in security assessments.
03 Aug 2026
TypeScript
★ 91
Red Kite is an Attack Surface Management (ASM) tool designed for security professionals to automate and streamline reconnaissance operations while providing extensive customization options. Its Kubernetes-based architecture supports horizontal scaling, ensuring robust performance, and it features an API for integration with third-party tools to facilitate automated data consumption and sharing.
03 Aug 2026
TypeScript
★ 98
SecTracker is a comprehensive management platform tailored for bug bounty hunting and security research, enabling users to efficiently track findings, manage reports, and organize their workflow. Key features include detailed bug report management with status tracking, customizable dashboards for activity overview, and integrated research tools such as an RSS feed reader and security checklists. Built with modern technologies like React and TypeScript, it enhances the user experience through real-time updates and a robust backend powered by Supabase and PostgreSQL.
03 Aug 2026
Makefile
★ 52
Scary Strings is a tool designed to identify potential security vulnerabilities in source code by flagging lines that contain "scary strings," which typically refer to sensitive API calls or operations. It provides a collection of technology-specific wordlists, enabling developers to audit their code for unsafe practices and helping hackers find exploitable code segments. Notable features include wordlists for various programming languages, specific categories such as comments and cryptography, and a focus on improving application security through proactive scanning.
03 Aug 2026
Python
★ 16
SCADA Scanner and Fingerprinter is a high-performance tool designed for asynchronous scanning and fingerprinting of industrial control systems (ICS) across networks. Its primary use case focuses on detecting vulnerabilities, identifying vendor and product information, and generating detailed risk reports, supporting a variety of protocols such as Modbus and DNP3. Notable features include fast scanning capabilities, protocol detection, vulnerability correlation with CVEs, and detailed logging, ensuring comprehensive risk assessments for authorized security assessments.
03 Aug 2026
Python
★ 40
SaaS Enum is a command line tool designed for identifying the Software as a Service (SaaS) platforms utilized by a company by analyzing DNS entries against known provider patterns and performing lightweight web checks for validation. It supports single and batch processing of company names, allows output in various formats (CSV, JSON, etc.), and provides features for listing providers and validating DNS patterns. Notably, it facilitates concurrent processing through configurable worker threads, enhancing efficiency in scanning multiple domains.
03 Aug 2026
Ruby
★ 42
ronin-recon is a micro-framework designed for efficient reconnaissance operations, utilizing multiple asynchronous workers to process various value types like IPs, hosts, and URLs. It features built-in recon capabilities such as DNS lookup, web spidering, and service scanning, and allows for the integration of additional third-party modules. Its unique queue architecture enhances performance, while support for multiple output formats and automatic result saving to a database makes it a versatile tool for cybersecurity practitioners.
03 Aug 2026
Python
★ 16
RedTiger is an automated XSS (Cross-Site Scripting) vulnerability testing tool that streamlines security assessments by performing subdomain enumeration, link filtering, endpoint extraction, and XSS scanning. Notable features include intelligent filtering of endpoints, a rich terminal UI with detailed reporting, and dependency checking to ensure all required tools are available. The tool is designed to enhance testing efficiency by focusing on parameters in URLs, improving the accuracy of vulnerability assessments.