> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

jaeles-signatures

The Jaeles Signatures repository provides a collection of default signatures for the Jaeles project, a framework designed for security scanning and vulnerability detection. Its primary use case is to enhance the scanning capabilities of Jaeles by allowing users to implement custom and predefined signatures targeting specific vulnerabilities, misconfigurations, and sensitive information. Notable features include easy integration with Jaeles, the ability to configure and reload signatures, as well as support for active and passive detection methodologies.

htk-lite

htk-lite is a streamlined version of the hackers-tool-kit, maintaining essential hacking capabilities while being lightweight. Its primary use case is to facilitate various penetration testing tasks. Notable features include easy installation with a simple Git clone, user-friendly command execution, and an update script for keeping the tool current.

HexraysToolbox

HexRays Toolbox (hxtb) is a versatile set of IDAPython scripts designed for identifying and analyzing code patterns in binaries across various processor architectures. Its primary use cases include vulnerability scanning, malware analysis, and proving code similarities, thus making it valuable for security analysts and reverse engineers. Notable features include a user-friendly GUI via hxtb_shell for query formulation, custom scripting capabilities, and batch processing scripts for enhanced automation.

Gopo

Gopo is a proof-of-concept (PoC) framework designed for generating and executing multiple exploitation scripts compatible with XRAY V2's PoC functionality. It facilitates vulnerability scanning by allowing users to load and execute predefined or custom PoCs against specified targets, with options for proxy settings, threat management, and debugging features. Notable capabilities include the ability to handle rules with logical expressions, multi-threaded scanning, and customizable execution parameters to optimize performance and accuracy.

Frey-Ruck-Attack

The Frey-Rück Attack implementation allows for the extraction of the ECDSA secret key ("K") from vulnerable Bitcoin transactions. This tool is particularly useful for cryptocurrency analysts and researchers studying signature vulnerabilities in blockchain protocols, enabling them to restore Bitcoin wallets by solving the discrete logarithm problem through compromised signatures. Notable features include practical examples of vulnerable Bitcoin addresses and methodologies for conducting cryptanalysis efficiently.

FireStorePwn

FireStorePwn (fsp) is a vulnerability scanner designed to analyze APK files for weaknesses in Firestore database security configurations, assessing both authenticated and unauthenticated access. Its primary use case is to identify insecure rules that could allow unauthorized data manipulation or access, potentially resulting in data theft and increased billing. Notable features include the ability to scan APKs with or without authentication using both user credentials and tokens.

FazScan

FazScan is a versatile vulnerability scanning and penetration testing tool implemented in Perl, designed to assess various web vulnerabilities, including SQL injection and CMS-specific weaknesses. With 18 distinct options, it enables users to perform automated scans for common vulnerabilities, detect content management systems, bypass WAF protection, and even conduct denial of service attacks. Its cross-platform compatibility allows for deployment on Linux, Windows, and Android systems.

erebus

Erebus is a configurable parameter-based vulnerability scanner that utilizes YAML templates to identify vulnerabilities across multiple targets efficiently, ensuring zero false positives. Its notable features include an intercepting proxy that allows users to dynamically test parameters as they browse web applications, along with built-in support for updating and downloading community-contributed vulnerability templates. This tool is designed for rapid scanning of large networks, making it ideal for penetration testers and cybersecurity researchers.

dorkScanner

DorkScanner is a search engine dorking tool that allows users to scrape search engines for vulnerable URLs based on user-defined queries. It is primarily used by security auditors and researchers to uncover hidden information on public websites. Notable features include support for multiple search engines (Google and Bing), customizable query parameters, and the ability to specify the number of pages and processes for enhanced searching efficiency.

cybersecurity-dynamic-analysis

The "cybersecurity-dynamic-analysis" repository is a curated collection of dynamic application security testing (DAST) tools, libraries, and frameworks aimed at enhancing vulnerability scanning processes. It primarily assists developers and security professionals in identifying and debugging vulnerabilities that static analysis may overlook, by evaluating applications during runtime. Notable features include support for multiple programming languages and links to various tools like Microsoft IntelliTest, KLEE, and Valgrind for dynamic analysis tasks.

CORS-Scanner

CORS-Scanner is a Go-based tool designed to identify CORS misconfiguration vulnerabilities in web applications. It allows users to specify origin headers and cookies for testing and processes line-delimited domains to check for vulnerabilities such as reflected origins with credentials and wildcard configurations. Notable features include customizable options for origin headers and cookie handling, as well as the capability to input multiple domains efficiently for scanning.

container-auto-scan

Lacework Auto Scanner is a tool designed to automate vulnerability assessments for active containers in a Lacework account, streamlining the scanning process via its API or inline scanner capabilities. It efficiently utilizes a local cache to skip rescans of recently assessed containers, with flexible configuration options for scan frequency and targeted registries. Notably, it supports Inline Scanning for containers lacking registry integration, enhancing its versatility and effectiveness in diverse environments.

collector

Collector is an automated tool designed for identifying XSS vulnerable parameters across entire domains by leveraging the Wayback Machine. Key features include comprehensive crawling of websites and JavaScript files, advanced error handling, and the capability to collect GET parameters. This tool facilitates a systematic approach to vulnerability assessment in web applications.

clj-nvd

clj-nvd is a Clojure tool designed to check dependencies specified in `deps.edn` against known security vulnerabilities from the National Vulnerability Database. It offers commands such as `check`, `update`, and `purge`, and generates detailed reports on vulnerabilities, with configuration options available through a dedicated `clj-nvd.edn` file. This tool acts as a wrapper around the existing lein-nvd, utilizing its functionality while adapting it for the Clojure tools.deps ecosystem.

burp-bounty

Burp Bounty is an extension for Burp Suite designed to enhance the capabilities of its scanning features by providing additional profiles for both active and passive scanning. Its primary use case is to facilitate vulnerability assessment by identifying misconfigurations and sensitive information exposure in various environments, particularly in Linux configurations. Notable features include predefined profile sets for scanning multiple common configurations and vulnerabilities, such as Apache2, MySQL, and JWT tokens.

badmoodle

badmoodle is a community-driven vulnerability scanner designed specifically for Moodle platform instances, aimed at penetration testers and security researchers. It identifies both official and community-discovered vulnerabilities, allowing users to operate in check mode for detection or exploit mode to validate and leverage identified vulnerabilities. Notable features include its modular architecture for easy integration of community vulnerability modules, multiple testing levels, customizable output options, and capability to scrape the latest vulnerabilities from Moodle's security resources.

awesome-software-supply-chain-security

The "Awesome Software Supply Chain Security" repository provides a curated list of tools and resources aimed at enhancing security throughout the software supply chain lifecycle. It covers various aspects, including Software Bill of Materials (SBOM), Software Composition Analysis (SCA), Static Application Security Testing (SAST), and tools for secret detection and malware analysis. Notable features include extensive categorizations of tools for CI/CD practices, Kubernetes security, and risk management, offering a comprehensive landscape for professionals seeking to bolster supply chain integrity.

avain

AVAIN is an automated vulnerability analysis framework designed for IP-based networks, leveraging a modular architecture to conduct comprehensive assessments of both networks and individual hosts. It features collaborative modules that facilitate reconnaissance, vulnerability correlation, and active detection of security issues, culminating in a vulnerability score to gauge overall security. Noteworthy capabilities include simple result sharing, extensive module configurability, and the ability to integrate various tools, making it a robust platform for penetration testing and security evaluation.

aqua-microscanner-plugin

The Aqua Jenkins MicroScanner Plugin facilitates the scanning of Docker builds within Jenkins for OS package vulnerabilities, ensuring the security of containerized applications. It integrates seamlessly into both Freestyle and Pipeline jobs, allowing users to configure vulnerability scans as part of their build process. Notable features include customizable actions for handling high-severity vulnerabilities, detailed scanning output in both console and HTML formats, and ease of setup requiring only Docker installation and token configuration.

advisor

Alcide Kubernetes Advisor is an agentless tool designed for auditing and ensuring compliance of Kubernetes clusters, focusing on enhancing DevSecOps workflows by providing early security scans. Its notable features include vulnerability scanning of Kubernetes infrastructure, detection of misplaced secrets and excessive access permissions, workload hardening, and application of security best practices for Istio and Ingress Controllers. The tool seamlessly integrates into CI/CD pipelines and offers a baseline profiling capability to streamline issue detection pertinent to a specific cluster.

actions-all-in-one

SecureStack provides an all-in-one GitHub Action designed to enhance security across GitHub project workflows by integrating several security analyses into a single step. It performs sensitive data detection, software composition analysis for vulnerable dependencies, scans for cloud misconfigurations and web vulnerabilities, and generates a Software Bill of Materials (SBOM) for comprehensive security coverage. Notable features include customizable severity settings for different analyses and a user-friendly setup utilizing GitHub Secrets for API key management.

xray-automation

The Xray automation script is a Bash utility designed for scanning websites for vulnerabilities using the Xray tool. It provides functionalities to scan multiple URLs from a text file or a single URL, with the added capability to download and install Xray if it is not already present. Notable features include comprehensive help documentation and the ability to output scan results both to a file and the terminal.

wacat

wacat is an automated web application testing tool that simulates chaotic input by navigating through a web application's links and forms in a random manner, providing comprehensive testing coverage. It offers advanced features like AI-driven error detection and content generation, supports various configurations for authentication, and can run in headless mode suitable for Continuous Integration (CI) pipelines. Built on Playwright, wacat is designed for user-defined behaviors and can detect a range of issues, making it ideal for thorough application assessments in a controlled environment.

Vulnerability-Scanner

The Vulnerability Scanner is a user-friendly tool designed for beginners in cybersecurity, capable of scanning systems for vulnerabilities and gathering information on potential targets. It includes features like DNS enumeration, OS detection, service/version detection, and integration with the OWASP ZAP for comprehensive security assessments. The tool is specifically built for Kali and Parrot Linux environments and requires minimal prior knowledge, making it an ideal starting point for aspiring security professionals.

StealthNewSQL

StealthNewSQL is an advanced command-line tool designed for detecting, exploiting, and securing NewSQL database vulnerabilities. It features capabilities such as DNS-based data exfiltration, advanced WAF evasion techniques, automated exploitation, and seamless integration with CI/CD pipelines, making it suitable for penetration testers, security researchers, and developers focused on database security. Notable functionalities include real-time monitoring, comprehensive reporting, and a modular plugin system for extending its capabilities.