> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

RivalSearchMCP

RivalSearchMCP is a deterministic research server that provides a comprehensive toolset to search, fetch, score, and compare information autonomously across multiple domains, including web, social platforms, news, academic databases, and code repositories. It features nine specialized tools with capabilities like auto-quality scoring, conflict detection, and structured output for seamless integration with AI models. The server operates without the need for API keys, ensuring accessibility and ease of use while maintaining production-level hygiene through rate limiting and built-in observability.

public-dns-servers

The `public-dns-servers` repository provides an up-to-date list of verified public DNS servers, filtered for reliability and performance. Its primary use case is to facilitate automated tasks or Open Source Intelligence (OSINT) activities that require dependable DNS resolvers. Notable features include weekly updates via a CI/CD pipeline and strict criteria for server validation based on response time and accuracy.

project-absence

Project Absence is an OSINT tool tailored for system administrators and security engineers, facilitating domain and server reconnaissance through modules such as subdomain and file discovery, as well as DNS data extraction. Its architecture allows for enhanced functionality via Lua scripting, while it adheres to an OSINT-only methodology by contacting each discovered entity just once to gather pertinent information. Notable features include support for clipboard integration and the ability to run the tool via Docker, alongside standard Rust installation methods.

Picarta-API

The Picarta Image Geolocalization API provides users with the capability to determine the geographic location of an image by analyzing its content and metadata. Its primary use case involves localizing images from either local files or URLs, returning details such as city, province, country, GPS coordinates, and confidence scores based on the provided image. Notable features include support for various location filters, flexibility in specifying the number of predictions, and the ability to search within defined geographic bounds.

MailAccess

MailAccess is a self-hostable OSINT platform designed for investigating email addresses by aggregating data from breach databases, social networks, DNS records, and the open web. It features an identity graph for correlating user accounts, a name consensus engine for verifying identities, and a domain email harvesting tool that discovers organization addresses from multiple data sources. The tool provides structured findings in various export formats and is specifically tailored for security researchers and penetration testers.

helm-opencti

The OpenCTI Helm Chart facilitates the deployment of the OpenCTI platform on Kubernetes, enabling organizations to efficiently manage and visualize cyber threat intelligence. Its primary use case is to structure and organize threat data in a scalable manner. Notable features include compatibility with Helm for streamlined installation and updates, and availability in both chart repository and OCI format for flexible usage.

go-fasttld

go-fasttld is a high-performance module designed for the extraction of effective top-level domains (eTLD) and subcomponents from various URL formats, including hostnames and IP addresses (both IPv4 and IPv6). Utilizing the Mozilla Public Suffix List, it supports private domains and offers a command-line interface (CLI) for easy extraction, while also providing functionality to handle internationalized label separators. Notable features include the ability to pretty-print results and robust handling of different URL structures.

GlobalAntiScamOrg-blocklist

The Global Anti Scam Organization blocklist provides a machine-readable list of scam URLs and IP addresses, updated daily, to assist in identifying and blocking fraudulent online activities. Utilizing Python and frameworks such as Selenium, the tool offers diverse formats for downloading the blocklist, including versions compatible with popular ad blockers and network-wide filtering tools. Its primary use case is to enhance cybersecurity measures by mitigating risks associated with online scams.

funstat-api

Funstat API is a Python client designed for interfacing with the Funstat/Telelog API to retrieve and analyze Telegram user and group statistics. It supports both synchronous and asynchronous operations, offering a variety of methods such as retrieving user stats, group members, message counts, and nickname histories, making it suitable for developers looking to gather insights into Telegram data efficiently. Notable features include easy token management, customizable configurations, and the ability to handle user privacy settings gracefully.

cti-expert

CTI Expert is a cyber threat intelligence and open-source intelligence analysis toolkit that enables users to convert Claude into a trained intelligence analyst, utilizing over 74 commands across 49 techniques. This tool operates without requiring API keys for its core functionalities, facilitating structured intelligence collection and analysis. Notable features include the capability to integrate personal API keys for enhanced functionality and ease of use with automatic detection of the keys in the configuration.

claude-skills-journalism

The "claude-skills-journalism" tool provides a suite of modular agent skills tailored for journalists, researchers, and media professionals, facilitating the integration of AI into their workflows. It features interactive skill browsing, setup guides, and support for multi-agent workflows, enabling users to automate and enhance various journalism-related tasks, such as fact-checking, interview preparation, and editorial processes. Notably, it supports both Claude and Codex environments, allowing for customized commands and persistent session management to maintain continuous productivity.

BCHackTool

BCHackTool is an all-in-one launcher and installer designed for penetration testing and OSINT (Open Source Intelligence) on Kali Linux and Termux environments. It features a menu-driven interface for easy access to a curated set of tools, automates the installation process, and includes helpful flags for managing scripts and tools. This tool streamlines the setup and execution of security testing tools while ensuring users operate within ethical boundaries.

Akashic

Akashic is a self-hosted geospatial intelligence tool that consolidates diverse live public data, including aircraft, satellites, earthquakes, and weather, into a single interactive operational workspace, all without the need for API keys. It offers multi-layered mapping, concurrent reconnaissance capabilities, and a dynamic intelligence deck for real-time event monitoring and analysis. Notable features include extensive entity inspection, live public radio integration, and a variety of views such as flat and photorealistic maps.

AiTor

AI Tor.v69 is a hybrid neural intelligence core designed for managing a DAO, analyzing financial flows, and integrating advanced theoretical concepts of physics within the Web 3-4-5 ecosystem. Key features include a secure access module for digital sovereignty, autonomous governance analysis, and a quantum ledger for simulating financial flows in high-pressure environments, underpinned by a robust technical architecture utilizing modern web technologies.

XposedOrNot-API

XposedOrNot API provides real-time data breach monitoring by allowing users to check if an email or domain has been involved in known breaches. Its key features include easy access to breach lookups and analytics without requiring an API key for basic functionality, and comprehensive alerts for ongoing breach risks. This open-source API is designed for developers to integrate breach monitoring into their applications efficiently.

watchboard

Watchboard is a multi-topic intelligence dashboard platform designed to provide real-time tracking and updates on conflicts, scientific advancements, and political histories. It features over 60 active trackers, AI-driven updates, interactive 2D and 3D visualizations, a public JSON API for integration, and the capability for users to create custom trackers easily. Enhanced with push notifications and a comprehensive source tier classification system, it serves as a powerful tool for monitoring critical global events.

voidaccess

VoidAccess is a self-hostable OSINT tool designed for transforming dark-web research queries into structured threat intelligence, catering to security researchers and threat-intelligence teams. Its notable features include parallel collection of diverse data sources, entity extraction, multi-source enrichment, relationship mapping, and various export formats, all operable via a CLI or a web UI with a Docker Compose setup. The tool emphasizes content safety and pipeline efficiency to ensure reliable threat investigation and analysis.

USOM-Blocklists

The USOM Blocklists repository provides a daily updated collection of malicious URLs and IP addresses compiled by the Turkish Cyber Security Directorate. It serves as a resource for cybersecurity professionals to enhance their threat detection and prevention capabilities, offering various formats of blocklists suitable for different applications, such as ad blockers and network filtering tools. Notable features include multiple download options for blocklists and integration with GitHub Actions for automated updates.

urlinsane

URLInsane is a command-line tool designed for detecting domain typosquatting and facilitating OSINT (Open Source Intelligence) investigations across multilingual target domains. It generates and scans for potential typosquatting variants of a specified domain, allowing users to identify threats such as phishing and brandjacking, with features that include customizable variant generation, reporting options in various formats, and a focus on multiple target types beyond just domains.

TweetFeed

TweetFeed is a dynamic tool that aggregates and provides feeds of Indicators of Compromise (IOCs) shared by the community on Twitter/X, facilitating cybersecurity research and threat intelligence. Notable features include programmatic access with various output formats such as CSV, RSS, MISP, and STIX, along with real-time updates every 15 minutes to ensure the data is current and relevant. This enables users to easily integrate the IOCs into their security workflows and monitoring systems.

thumpersecure

THUMPERSECURE is a comprehensive collection of tools aimed at facilitating open-source intelligence (OSINT) and enhancing privacy by enabling effective digital footprint management and reconnaissance. It targets investigators, privacy-conscious users, developers, and operators, offering a streamlined, user-friendly experience with an emphasis on clarity and automation. Notable features include a live Code Cookbook providing access to utilities for recon and workflow processes.

ThreatFox-IOC-IPs

ThreatFox IOC IPs is a Python-based tool that generates a machine-readable IP blocklist sourced from ThreatFox, a project by Abuse.ch. It provides users with an updated blocklist of malicious IPs every hour, making it suitable for cybersecurity applications like threat intelligence and proactive network defense. Notable features include automatic updates and compatibility with the AIOHTTP library for efficient data handling.

spydithreatintel

Spydi's ThreatIntel Feed provides aggregated threat intelligence blocklists sourced from various OSINT databases, honeypots, and C2 trackers, offering tiers of confidence for IP and domain blocklists. It features multi-source validation to enhance accuracy, automatic whitelisting of CDN IPs to minimize false positives, and is constructed for compatibility with tools like Pi-hole and AdGuard. The service is designed for rapid global distribution via Cloudflare R2, ensuring low latency access to threat intelligence data.

social-monitor

Social Monitor is a comprehensive tool designed for aggregating and summarizing posts from various social networks and news sources, aiming to filter out noise and highlight the most relevant content based on user interests. Its notable features include customizable digest summaries on a daily, weekly, or monthly basis, and a robust backend architecture that supports various data ingestion and monitoring workflows. This tool is ideal for creating dashboards, monitoring topics or brands, and developing internal analytics for teams.

shortdot-evidence

ShortDot Evidence is a cybersecurity tool designed to catalog and analyze the domains registered under ShortDot SA's registry, focusing on domains that are primarily used for phishing activities. It provides a comprehensive enumeration of over 6.2 million domains, highlighting the high rate of brand impersonation and the absence of legitimate businesses among these registrations. Notable features include live statistics on phishing domain counts, daily auto-updated data retrieval, and detailed insights into the estimated revenue generated by ShortDot, making it a valuable resource for threat intelligence in the domain space.