> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

cryptocat-gitbook

CryptoCat is a secure messaging tool designed for private communication via end-to-end encryption. Its primary use case is to enable users to chat in real-time while ensuring that messages remain confidential. Notable features include anonymous chat rooms and the ability to communicate securely without data logging.

coli

COLI (Command Orchestration & Logic Interface) is a command line tool designed to streamline workflow management by enabling users to visually create and connect tasks through a drag-and-drop interface. It offers features such as real-time scan monitoring, an interactive web terminal, and a built-in file explorer, making it ideal for those seeking a more efficient way to manage command line operations and enhance visualization. Additionally, COLI supports mobile access, allowing users to operate workflows from anywhere.

Bug-Bounty-Beginner-Roadmap

The Bug Bounty Beginner Roadmap serves as a comprehensive guide for newcomers interested in bug bounty hunting, providing essential knowledge on security vulnerabilities and effective learning paths. It emphasizes the importance of foundational skills in computer systems, networking, and operating systems, while also highlighting the potential rewards of participating in bug bounty programs. Notable features include curated resources and links to courses tailored for building the necessary expertise in this evolving field.

Bug-Bounty

The Bug Bounty repository serves as a comprehensive resource for security researchers engaged in vulnerability discovery and reporting, aggregating tools, checklists, and cheat sheets to streamline the bug hunting process. Key features include curated lists of bug bounty programs, essential tools, and educational resources, enhancing the usability and effectiveness of cybersecurity efforts. This tool is designed to aid both novice and experienced bug bounty hunters in their pursuits.

bountycatchremix

BountyCatch Remix is a Python-based domain management tool designed for security researchers and penetration testers involved in bug bounty programs. It enhances the original bountycatch.py script with features such as domain validation, automatic duplicate detection, project-based organization, and Redis-backed storage for optimal performance. Key capabilities include bulk domain import, multiple output formats, and advanced logging and error handling, making it a versatile resource for managing and analyzing domain lists efficiently.

AspGoat

AspGoat is an intentionally vulnerable ASP.NET Core web application designed for educational purposes, allowing Security Engineers and Developers to explore and practice web application security vulnerabilities. It encompasses a range of common security issues outlined by the OWASP Top 10, providing hands-on labs for vulnerabilities such as XSS, SQL Injection, and Cross-Site Request Forgery, along with features like Docker support for easy deployment and secure coding best practices.

Ai-Prompts

The Ai-Prompts tool serves as a comprehensive cheat sheet for crafting effective search queries aimed at enhancing information retrieval from AI models like GPT. Its primary use case lies in optimizing search accuracy and refining results based on specific parameters, such as keywords, sources, and recency. Notable features include customizable options for output formats, technical depth, and automated summarization, enabling users to tailor searches for precise and actionable information in various contexts.

0-click-RCE-Exploit-for-CVE-2024-10924

This repository provides a proof-of-concept exploit for CVE-2024-10924, allowing an attacker to bypass authentication and two-factor authentication in the Really Simple Security WordPress plugin to achieve remote command execution (RCE). The script automates the process of impersonating an administrator, uploading a malicious plugin, verifying interaction with the payload, and establishing an interactive remote shell. Notably, it operates pre-authentication, requiring only the target URL and a malicious plugin as input.

-Ultimate-Cybersecurity-Roadmap

The Ultimate Cybersecurity Roadmap is a comprehensive guide designed to facilitate the learning journey from novice to advanced cybersecurity professional. It encompasses structured learning paths, hands-on projects, and certification guidance, along with essential resources for skill development in various cybersecurity domains. Notable features include a focus on technical foundations, real-world interview preparation, and a curated list of tools and platforms relevant to the field.

xurlfind3r

`xurlfind3r` is a command-line utility that efficiently discovers URLs associated with a given domain by sourcing publicly available data through passive means. It is particularly useful for security researchers and IT professionals, offering features like multiple output formats (JSONL, file, stdout), support for automatic workflows via `stdin` and `stdout`, and cross-platform compatibility across Windows, Linux, and macOS.

web3-bug-bounty-hunting-ai-skills

The web3-bug-bounty-hunting-ai-skills tool equips security researchers with an extensive knowledge base for smart contract auditing, leveraging insights from thousands of real-world reports and reproductions. It integrates with AI models like Claude Code, streamlining the bug hunting process through predefined templates, target scoring systems, and detailed methodologies covering ten primary bug classes. Notably, the repository includes a comprehensive grep arsenal, proof of concept (PoC) templates, and case studies, allowing hunters to efficiently identify vulnerabilities in blockchain applications.

Security-Books

Security Books is a comprehensive repository offering over 160 curated cybersecurity-related books, guides, and resources, catering to various skill levels from beginners to advanced practitioners. This tool features a fully categorized structure with clickable links for instant access to each resource, ensuring that the cybersecurity community has free access to critical knowledge. With a commitment to regular updates, it serves as a valuable, continually expanding library for topics ranging from ethical hacking to network defense.

osint-mcp-server

The OSINT MCP Server is a unified platform that consolidates multiple open-source intelligence sources like Shodan, VirusTotal, and Censys into a single service, enabling AI agents to access comprehensive OSINT on demand. Its primary use case is to streamline the collection of reconnaissance data essential for penetration testing and threat assessments, eliminating the need for multiple tools and manual correlation. Notable features include support for numerous data sources, a simplified MCP protocol interface, an intuitive architecture, and a rich set of 37 integrated tools.

mergen-mcp

Mergen is an AI-powered penetration testing server that integrates with MCP-compatible agents, facilitating autonomous planning, adaptive execution, and professional reporting across over 44 security tools. With its multi-layer architecture featuring a FastAPI backend and an adaptive AI attack engine, Mergen enables sophisticated target profiling, dynamic attack execution, and unified risk scoring while supporting multiple output formats like HTML, JSON, and CSV for reporting. Notably, it offers a plugin system for seamless integration of security tools and automated operational capabilities, making it a comprehensive solution for red team engagements.

JWTLens

JWTLens is a comprehensive security scanner for JSON Web Tokens (JWTs) integrated with Burp Suite, designed to automatically detect and test for vulnerabilities across a wide array of JWT attack vectors. It incorporates 56 security checks, enabling both passive analysis and active exploitation tactics, including signature bypasses and algorithm confusion. Key features include a JWT Forge tab for live token editing, a built-in secret extractor to identify hardcoded secrets, and efficient request/response scanning capabilities for thorough JWT vulnerability assessments.

isXSS-Burp

isXSS-Burp is a Burp Suite extension designed to automate the detection of reflected XSS vulnerabilities by passively analyzing HTTP traffic and examining which special characters are reflected in HTML responses. It features comprehensive injection coverage for GET and POST requests, evaluating various parameter types, and includes advanced detection mechanisms for identifying dangerous DOM sinks. The tool also incorporates noise reduction techniques, a user-friendly interface for configuration, and provides detailed reporting on discovered vulnerabilities.

chomtesh

CHOMTE.SH is an advanced automation framework designed for reconnaissance tasks in penetration testing, primarily serving bug bounty hunters and security professionals. Its notable features include subdomain discovery, DNS brute-forcing, quick port scanning, HTTP probing, and detailed reporting capabilities, allowing users to identify vulnerabilities and misconfigurations effectively. The tool is customizable through a flags.conf file and supports deep internet reconnaissance and JavaScript analysis to enhance security assessments.

Burp-Pentest-Coverage-Tracker

Pentest Coverage Tracker is a Burp Suite extension that enhances penetration testing efforts by automatically logging discovered endpoints and parameters during assessments. Its primary use case is to provide real-time visibility into which parts of an application have been tested, helping security professionals systematically identify untested areas. Notable features include endpoint and parameter coverage tracking, a real-time dashboard, untested endpoint identification, and CSV export capabilities for reporting.

bucky

Bucky is a tool designed for S3 account ID enumeration and bucket discovery, enabling users to extract the 12-digit AWS account ID of an accessible S3 bucket and discover additional associated buckets through exhaustive fuzzing of bucket names against a wordlist. Key features include the use of inline STS session policies to systematically brute-force the account ID and the ability to report the discovered account ID, bucket regions, and all identified buckets, thus facilitating reconnaissance efforts on AWS S3 resources.

Anvil

Anvil is a runtime-first tool designed for privilege escalation and attack surface assessment specifically targeting Windows thick client applications. It effectively reduces false positives by combining Procmon capture with Windows AccessCheck to validate writable paths in real-time while enforcing multiple verification gates. Notable features include its comprehensive approach to assessing various attack classes, detailed filtered analysis of candidate paths, and the ability to produce actionable reporting outputs in multiple formats.

anti-debugger-bypass

Anti-Debugger Bypass is a Chrome extension designed to circumvent various client-side JavaScript anti-debugging mechanisms that can disrupt developer tools. It features capabilities such as intercepting `eval("debugger")` calls, preventing aggressive script redirects, and protecting console outputs while providing a smooth debugging experience for security researchers and penetration testers. The extension injects scripts to neutralize traps at the document start, ensuring that users can explore and inspect web elements without interference from anti-debugging practices.

Xposure

X-POSURE v4.0 is an autonomous credential intelligence platform designed for discovering, extracting, correlating, verifying, and reporting exposed secrets across an organization's entire attack surface. Its primary use case is to enhance security by identifying vulnerabilities related to exposed credentials, further augmented with features like recursive crawling, Shodan integration, AI-powered contextual analysis, and deep secrets scanning via TruffleHog. This tool is engineered for advanced users who recognize the significance of credential exposure as a substantial security threat.

Web-Recon-Automation

Web Recon Automation is an automated reconnaissance script designed for bug bounty hunters and penetration testers, enhancing the efficiency of subdomain enumeration, live host discovery, vulnerability scanning, and reporting. Key features include automated dependency checks, integration with tools like `subfinder`, `httprobe`, `nmap`, and `nuclei`, as well as comprehensive reporting that summarizes findings in a structured Markdown format. The tool simplifies the reconnaissance process by allowing users to conduct multiple security checks with a single command execution.

Subhunter

Subhunter is a subdomain takeover tool designed to identify vulnerabilities in specified subdomains, enabling users to detect potential security risks associated with unmonitored CNAME records. Notable features include automatic updates, the use of random user agents, and a built-in database of fingerprints sourced from reputable databases. It is implemented in Go and allows for customization in scanning parameters, such as threading and timeouts, enhancing its effectiveness in security assessments.

Subfind3r

Subfind3r is an advanced subdomain enumeration tool designed to enhance and address limitations found in the original Sublist3r project. It supports various features, including brute force enumeration, port scanning of discovered subdomains, and the ability to specify different passive DNS API sources, making it highly customizable for security researchers performing domain reconnaissance. The tool can be easily installed via pip, facilitating a user-friendly setup process.