> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

Rosint

Rosint.dev is a Reddit user intelligence tool that allows users to search the complete post and comment history of any Reddit account, including those with private profiles and deleted content. Its notable features include dual-source search functionality from Arctic Shift and PullPush, a user-friendly interface for viewing posts and comments, date range filtering, and pagination—all without requiring user login.

ransomposts

Ransomposts is a tool that aggregates and displays ransom notes published by ransomware groups, with updates occurring twice daily from the source at ransomware.live. Its primary use case is to provide cybersecurity professionals and researchers with timely information about ransomware activities and trends. Notable features include automated data fetching and a dedicated publication interface accessible via a web link.

phishing_kits

The phishing_kits repository provides an archive of phishing kits collected from suspicious domains identified by phishunt.io. Its primary use case is for research and OSINT purposes, offering a structured layout for easy access to these kits while maintaining the original capture format. Notable features include organization by date and hostname, facilitating efficient analysis and study of phishing techniques.

p2pblocklists

P2PBlocklists is an extensive repository designed for IPv4 address lookup, enabling users to map and filter IP addresses based on their associated countries or organizations. This tool is particularly useful for cybersecurity applications such as denying or allowing traffic from specific providers, OSINT investigations, and implementing firewall rules to enhance network security. Notable features include a comprehensive database of over 3 billion public IPv4 addresses, compatibility with popular firewall solutions, and customizable lists to suit organizational needs.

OpenTrace

OpenTrace is an offline desktop application designed for organizing and analyzing Open Source Intelligence (OSINT) investigations. It features a visual investigation board that allows for extensive customization, including editable relationship labels and a task management system, while ensuring complete user privacy without any online dependencies. Key functionalities include a global OSINT tool library, automatic saving, cross-platform compatibility, and the ability to export data in both PNG and JSON formats.

OpenOSINT

OpenOSINT is an OSINT agent designed for security researchers and analysts, featuring 19 investigation tools accessed through a natural-language interface. It can be utilized as a REPL, CLI, MCP server, or web UI, with notable capabilities including credible execution of tool calls, ensuring accurate data retrieval without hallucinations. The tool also integrates seamlessly with services like IP2Location for enhanced IP tracking and RapidProxy for efficient data collection.

opencti

OpenCTI is an open-source platform designed for managing cyber threat intelligence, enabling organizations to structure, store, and visualize both technical and non-technical information about cyber threats using a STIX2-based knowledge schema. Its notable features include a GraphQL API, integration capabilities with tools like MISP and TheHive, and functionality for data import and export in various formats, promoting comprehensive analysis and understanding of cyber threat data. The platform supports enhanced user experience through its modern web application and offers both Community and Enterprise editions with varying levels of features.

open-source-aviation

Open-source Aviation is a comprehensive catalog of aviation-related open-source projects and datasets, providing access to a wealth of information such as ADS-B data, airport details, weather data, and tools for various aviation applications. Key features include community-driven resources, statistical data, and tools for aeronautic calculations, making it a valuable repository for developers and aviation enthusiasts looking to leverage open-source data for analysis and development. The project encourages contributions and continuous expansion, fostering collaboration in the aviation software community.

nzz-maps

The nzz-maps tool facilitates the scraping and analysis of territorial control data related to the Ukraine war, utilizing resources from nzz.ch and liveuamap.com. It automates daily updates through GitHub actions and offers API endpoints for querying areas, battalions, and annotations. Notable features include an interactive Jupyter notebook for data analysis and visual representations of territorial changes over time.

kafSIEM

kafSIEM is an edge-ready operations intelligence tool that monitors Kafka agent traffic and OSINT feeds to build an evidence-linked entity graph stored in SQLite. It provides an analyst workflow through a web desk and a typed OpenAPI, facilitating the tracking of unmanned systems and SCADA infrastructures. Notable features include a configurable analyst desk, domain-specific ontology packs, and a streamlined deployment via Docker without the need for a cluster database.

IPscanner

OSINT NET Auditor is a desktop IP and port scanner application developed using Tauri, primarily for scientific and educational purposes. Key features include a user-friendly installation process, customizability through building from source using Node.js and Rust, and the capability to detect potential security vulnerabilities in network configurations. The app aims to provide an accessible tool for users interested in network auditing and security assessment.

ip-tracker

Ip-tracker (Chakravyuh) is a reconnaissance framework designed for red teaming and security research, offering a fusion of passive OSINT techniques with advanced social engineering features. Its notable capabilities include auto-tunneling, real-time alerts to Telegram, and comprehensive device fingerprinting, all without manual port forwarding. The tool facilitates IP intelligence, phone number validation, and multi-threaded port scanning, enhancing the efficiency of data collection and target analysis.

ip-fraud-database

The IP Fraud Database is an open-source tool that provides a continuously updated list of over 750,000 confirmed malicious IP addresses and networks, with refresh intervals of just 30 minutes. It features individually verified threat categories and infrastructure types, allowing easy integration into security systems such as firewalls and web application firewalls (WAFs) without restrictions. Additionally, the community-driven aspect enables users to report and contribute new malicious IPs, enhancing the database's effectiveness in combating cyber threats.

IntelOwl

IntelOwl is an open-source Threat Intelligence management tool designed to provide comprehensive threat data regarding malware, IP addresses, and domains through a single API request. It features a fully-fledged REST API, a built-in graphical user interface for data visualization, and a modular plugin framework that allows for integration with various analyzers and connectors, facilitating automation for security analysts. Its scalability and speed in retrieving intelligence data make it suitable for enhancing the efficiency of security operations centers (SOCs).

GhostIntel

GhostIntel v2.5 is an advanced OSINT (Open Source Intelligence) framework designed for cybersecurity professionals and digital investigators to gather and analyze public information without the need for API keys. Notable features include support for 8 countries, batch processing capabilities, breach detection, and risk scoring, along with a user-friendly web interface that allows for intuitive multi-target scans across 129+ platforms. This tool is optimized for uncovering online footprints, enhancing threat intelligence, and conducting comprehensive digital reconnaissance.

European-Parliament-MCP-Server

The European Parliament MCP Server is a TypeScript implementation designed to facilitate structured access to European Parliament Open Data for AI clients, including handling various data regarding Members of the European Parliament (MEPs), legislative sessions, and parliamentary activities. Its notable features include advanced analytical tools for MEP influence scoring, coalition analysis, legislative scoring, and attendance trends, all while ensuring compliance with ISMS and GDPR standards, making it suitable for intelligence applications in OSINT contexts.

euparliamentmonitor

The EU Parliament Monitor is a Political Intelligence Platform designed to enhance transparency and accountability in the European Parliament. Its primary use case involves providing AI-generated news and detailed insights related to legislative activities affecting Europe’s 450 million citizens, available in 14 languages. Notable features include a comprehensive Political Intelligence Hub, an API for developers, and a site map that ensures accessibility to content across various languages.

Epstein

The Epstein repository is a monitoring tool designed to track changes to the Department of Justice's released Epstein Files, which contain extensive documentation of a global child sex trafficking network. It automatically checks for new, removed, or altered files every six hours, maintaining a comprehensive changelog and offering interactive data visualizations, such as flight maps and passenger networks. Key features include a searchable database of individuals connected to the case and detailed analysis of flight routes associated with the trafficking.

deepstate-map-data

DeepState Map Data is a tool that provides daily updated GeoJSON files representing the Russian-occupied territories of Ukraine, facilitating geographic analysis. It includes a unified, compressed dataset that consolidates historical geometries with their respective update dates, enabling users to easily access the most current and comprehensive data. Notable features include automated daily updates via GitHub Actions and a structured data format that supports various access methods, including Python and terminal utilities.

cybersecurity

The Excalibra cybersecurity repository serves as a comprehensive educational resource designed to enhance skills in ethical hacking, penetration testing, and cybersecurity fundamentals. Key features include detailed sections on Open Source Intelligence (OSINT), the use of Nmap for network discovery and security auditing, insights into social engineering tactics, and guidance on employing Kali Linux, making it a valuable tool for individuals seeking a structured learning path in cybersecurity.

Crypto-Scam-and-Crypto-Phishing-Threat-Intel-Feed

Crypto-Scam and Crypto-Phishing Threat Intel Feed provides a continuously updated feed of active cryptocurrency phishing and scam websites, helping organizations block these threats effectively. The tool is designed to be compatible with various blocking solutions, including Pi-hole and firewall systems, and features a daily update cycle to ensure users have access to the latest malicious domains. Additionally, it offers insights into domain characteristics, such as the prevalence of certain TLDs among scams, and supports reconnaissance activities for identifying rogue infrastructure.

contrastapi

ContrastAPI is a comprehensive security intelligence tool designed for AI agents, providing grounded answers regarding vulnerabilities, threats, and attack surfaces by aggregating data from authoritative sources like the NVD and CISA KEV. It features a robust REST API with over 60 endpoints for CVE/KEV/CWE lookups, exploit probability scoring, domain and IP investigations, IOC enrichment, and code-security checks, while also facilitating seamless integration through SDKs for Python and Node.js. Notably, it is free to use without requiring API keys or signups, offering 55 tools and 7 resources for effective security analysis.

cloudcheck

CloudCheck is a Rust-based tool designed to determine if a given IP address or hostname is associated with a cloud service provider. It features a command-line interface (CLI), a Rust library, and Python bindings, with dynamic updates for cloud provider signatures and CIDR data from community sources. The tool also supports a REST API for programmatic access, allowing for integration in various applications.

cia

Citizen Intelligence Agency (CIA) is a Swedish political intelligence platform designed to enhance democratic transparency and accountability through evidence-based analysis and Open Source Intelligence (OSINT) methodologies. Primarily aimed at monitoring the activities of the Riksdag, Government, and public agencies in Sweden, it features robust data analysis capabilities, a commitment to independence and non-partisanship, and is aligned with Information Security Management Standards (ISMS). Noteworthy attributes include comprehensive documentation, annual reviews, and a strong focus on secure software development practices.

as-metadata

as-metadata is a comprehensive dataset tool that provides detailed metadata for autonomous system numbers (ASNs), including organization names and country codes sourced from regional internet registries. Its primary use case is for offline lookups, network analysis, and threat intelligence, offering features like automatic updates based on source data changes and formatted data in both JSON and CSV. Notable enhancements include fields for categorization, network roles, and connectivity statistics, permitting thorough organizational mapping and analysis without API constraints.