> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

nuclei

Nuclei is a high-performance vulnerability scanner that utilizes YAML-based templates for customizable vulnerability detection, aiming to reduce false positives by mimicking real-world attack scenarios. Its notable features include ultra-fast parallel scan processing, support for multiple protocols such as HTTP and DNS, and seamless integration into CI/CD pipelines as well as various issue tracking and logging systems. The tool is designed for security professionals to stay ahead of trending vulnerabilities while conducting thorough regression testing.

nsauditor-ai

NSAuditor AI is a modular, AI-assisted network security audit platform designed to assess and prioritize vulnerabilities without data exposure, operating entirely within your infrastructure. It utilizes 27 specialized scanning plugins to generate AI-powered vulnerability reports while ensuring zero data exfiltration, as all processes including analysis and monitoring are conducted offline and any external API calls are opt-in. This tool emphasizes privacy and security by ensuring that sensitive scan data never leaves the user's environment.

medusa

MEDUSA is an AI-first security scanner designed to detect vulnerabilities in AI/ML applications, offering over 40,000 detection patterns and built-in rules for identifying threats such as API key leaks and AI supply chain attacks. Notable features include no setup required for usage, the ability to scan GitHub repositories for potential repo poisoning, and interactive tools for purging leaked information. The tool supports parallel processing for speed, integrates with various IDEs, and provides multiple reporting formats for versatility in usage.

L0p4Map

L0p4Map is a robust network monitoring and visualization tool that enhances the capabilities of Nmap, providing security researchers and network administrators with detailed insights into their network infrastructure through an intuitive interface. Key features include continuous monitoring of network traffic, real-time alerting for unauthorized devices, extensive device fingerprinting, and the ability to generate a real-time graphical representation of network topology. The tool supports multiple platforms (Linux, Windows, macOS) and integrates seamlessly with existing Nmap functionalities to deliver a comprehensive view of network security.

it-depends

It-Depends is a tool designed for automatically generating dependency graphs and Software Bill of Materials (SBOM) for various programming packages and source code repositories, supporting languages such as Go, JavaScript, Rust, Python, and C/C++. Key features include complete dependency version resolution, C/C++ support without the need to build projects, automated mapping of native library dependencies through dynamic analysis, and integration with vulnerability scanning from the OSV database.

isitsecure

isitsecure is an AI-powered security scanner designed for modern web applications, integrating Static Analysis (SAST), Dynamic Analysis (DAST), and AI-driven code review into a single scanning process. Its notable features include automatic generation of DAST tests based on SAST findings, AI-generated code patches for vulnerabilities, and support for multiple programming languages and frameworks. This tool targets developers aiming to improve code security without requiring deep security expertise, offering a comprehensive report along with actionable fixes for identified issues.

honey

honey is an automated supply-chain security tool that orchestrates multiple security scanners to assess vulnerabilities across a developer's machine. It integrates the findings from various scanners, such as bumblebee for compromised packages and osv-scanner for known CVEs, providing a unified verdict and optional daily reports through a messaging system. Key features include scheduling scans, customizable reporting policies, and the ability to suppress previously acknowledged findings.

harbor-scanner-adapter

The Harbor Scanner Adapter for Anchore Engine/Enterprise facilitates the integration of Harbor's scanning capabilities with the Anchore API, enabling vulnerability assessments on Docker images stored within Harbor. It offers TLS/HTTPS protection for API communications, supports authentication through Bearer tokens and Basic authentication, and can be configured via environment variables or configuration files. This tool is essential for users seeking to leverage Anchore's scanning features directly from Harbor, enhancing their image security posture.

grummage

Grummage is an interactive terminal frontend for the Grype vulnerability scanner, designed to simplify the analysis of Software Bill of Materials (SBOMs) by providing a user-friendly interface for navigating and viewing vulnerability details. Its notable features include real-time utilization of the Grype vulnerability database, customizable views by package name, vulnerability ID, package type, and severity, along with intuitive navigation controls. Grummage aims to streamline the process of vulnerability management for developers without the need to delve into complex query syntax.

getobserver

Observer is a command-line tool designed to analyze codebases and generate a comprehensive production health report, all from a single, offline binary with no dependencies or account requirements. It combines various analysis methods—such as static analysis, dependency checks, and runtime error detection—into a unified report that includes a security rating and suggested fixes for identified issues. The tool is aimed at developers seeking to efficiently identify and remediate production problems without navigating complex code and server logs.

foxguard

Foxguard is a comprehensive security scanning tool designed for local environments, offering fast analysis of code, secrets, dependencies, and post-quantum cryptographic risks. It boasts over 200 built-in rules across 12 programming languages, supports taint tracking, provides efficient CI integrations, and features output formats compatible with various tools such as SARIF and Semgrep. Key capabilities include secrets scanning, OSV-backed dependency checks, and the ability to pinpoint changes in code branches through diff mode scanning.

fleet-cve-scanner

The fleet-cve-scanner is an open-source, PowerShell 7-based CVE scanner designed for managing vulnerabilities in software across RMM-managed fleets, without the need for agents or appliances. It cross-references the software inventory of managed endpoints against multiple authoritative security feeds to determine if installed software versions are vulnerable and assess their urgency. Key features include the ability to generate per-device CSV reports, a SQLite history database for change tracking, and an HTML dashboard, making vulnerability assessment and management streamlined and efficient.

eraser

Eraser is a tool designed for Kubernetes administrators that facilitates the removal of non-running images from all nodes within a cluster. Its primary use case is to help optimize storage and resources by cleaning up unused images, thereby improving cluster efficiency. Notable features include easy integration with Kubernetes environments and a user-friendly quick start guide for rapid deployment.

drogonsec

Drogonsec is an open-source security scanner designed to perform comprehensive security assessments through Static Application Security Testing (SAST), Software Composition Analysis (SCA), and secret detection, aligning with the OWASP Top 10:2025 framework. It supports over 20 programming languages and various deployment strategies, including local or cloud-based AI remediation for findings. Key features include the ability to scan for vulnerabilities, identify misconfigurations in Infrastructure as Code (IaC), and integrate with CI/CD pipelines for automated security reporting.

DockSec

DockSec is an AI-powered Docker security scanner designed to translate complex security vulnerabilities into actionable insights for developers. It leverages popular security scanners like Trivy and Hadolint to provide prioritized vulnerability assessments and plain English explanations, while also suggesting specific fixes for Dockerfiles and generating interactive security reports. The tool ensures privacy by conducting scans locally, with options for local AI processing, minimizing external data exposure.

DLL-Hijacking-Vulnerability-Scanner

DLL Hijacking Vulnerability Scanner is a specialized tool for identifying DLL hijacking vulnerabilities within signed Windows executable files. It features automated scanning, DLL dependency analysis, and comprehensive filtering options, enabling security professionals to test executables for hijacking susceptibility and analyze their DLL loading behaviors, as well as generating detailed vulnerability reports.

dianxing

DianXing (点星) is an AI-driven end-to-end code security auditing system that autonomously identifies and verifies vulnerabilities in source code without human intervention, offering a structured output of detected issues. Unlike traditional SAST tools, it employs semantic understanding to uncover deep vulnerabilities, such as authentication bypass and privilege escalation, which are often missed by conventional scanners. The system has demonstrated the ability to autonomously exploit zero-privilege remote code execution vulnerabilities, reinforcing the need for responsible disclosure of its capabilities.

DeepSec

DeepSec is an AI-driven security platform that integrates code security auditing and authorized penetration testing into a unified CLI and terminal workbench. It features a three-layer detection architecture for real-time vulnerability scanning, leveraging regex, AST analysis, and LLM semantic evaluation, along with IDE plugins for seamless development integration. The platform is designed to enhance security efficiency by augmenting traditional methods with advanced AI capabilities.

cyber-neo

Cyber Neo is an open-source cybersecurity analysis agent designed to run within Claude Code, enabling developers to conduct comprehensive security audits on their projects effortlessly. The tool scans for vulnerabilities across 11 categories, including code security, authentication, cryptography, and dependency vulnerabilities, providing prioritized reports with concise remediation guidance. Notable features include no installation requirements, real-time operation, and the ability to run five parallel subagents for rapid assessments.

cwe_checker

cwe_checker is a static analysis tool designed to identify common software vulnerabilities, specifically by detecting classes of bugs known as Common Weakness Enumerations (CWEs) in ELF binaries across multiple CPU architectures. It leverages Ghidra for disassembly and utilizes a plugin-based, extensible architecture that supports customizable analyses, making it a useful resource for firmware analysis on Linux and Unix systems. Notable features include easy setup via Docker, support for various architectures, and the ability to integrate with the FACT framework for enhanced analysis capabilities.

cve-lite-cli

CVE Lite CLI is a terminal-based vulnerability scanning tool designed to analyze project lockfiles and provide actionable remediation commands. It focuses on delivering validated fix commands alongside parent-aware guidance for transitive dependencies, emphasizing a remediation-first approach while ensuring that no sensitive data leaves the user's machine. As an officially recognized OWASP Lab Project, it integrates seamlessly into CI workflows, promoting secure coding practices.

cscan

CSCAN is an enterprise-level distributed network asset scanning platform designed for comprehensive asset management and vulnerability detection. Its notable features include a distributed architecture for flexible scalability, automated scanning pipelines, customizable password dictionaries, periodic task scheduling, and real-time notification subscriptions, supporting extensive data isolation across multiple workspaces. This tool is ideal for organizations seeking to efficiently monitor and secure their network infrastructure.

cloud-audit

cloud-audit is an open-source AWS security scanning tool designed to identify attack paths, IAM escalation routes, and prioritize necessary fixes based on their impact on security. It operates in a read-only mode, ensuring no modifications are made to the user's AWS infrastructure while providing detailed reports on correlations between vulnerabilities and suggested remediation steps, including AWS CLI and Terraform fixes per finding. Key features include the identification of attack chains using MITRE ATT&CK methodology, root-cause analysis for prioritized fixes, and a simulation function to evaluate the potential impact of proposed changes.

ChYing

ChYing is an open-source penetration testing tool designed to provide an interactive platform for security professionals, facilitating the capture, modification, and replay of HTTP/HTTPS traffic. Its notable features include a lightweight UI, built-in scanning capabilities from the Jie tool, automated attack testing with multiple payload types, and an intuitive workflow for JWT parsing, which makes it an alternative to heavier tools like Burp Suite. The tool aims to offer a modern and customizable solution for active and passive web vulnerability assessments.

cert-x-gen

CERT-X-GEN is a polyglot execution engine designed for vulnerability detection, allowing users to write security checks in multiple programming languages including Python, Go, Rust, C, and Shell. It provides a unified execution layer that enables complex detection logic, such as multi-step protocol conversations and performance-critical operations, and is tailored for integration in CI/CD environments. Notable features include language-agnostic templates, sandboxing capabilities, and the ability to mix various programming languages within a single scan.