03 Aug 2026
★ 516
as-ip-blocks is a tool that provides daily-updated datasets of autonomous systems (AS) with active BGP prefix announcements, available for download in JSON and plaintext formats. Its primary use case includes network analysis, firewall rule creation, and tracking IP ranges associated with specific organizations, with notable features such as aggregated prefixes, historical change tracking via Git history, and bulk download options.
03 Aug 2026
Rust
★ 11
Advanced Secret Finder is a high-performance API key scanner developed in Rust, capable of detecting over 70 API key patterns while employing concurrent scanning of GitHub repositories. It features live validation of keys against major platforms, intelligent false positive filtering, and separation of public and private findings to enhance security during analysis. Additionally, it offers a user-friendly interactive mode and integration with GitHub Actions for seamless automation in continuous integration workflows.
03 Aug 2026
TypeScript
★ 25
AEGIS is a strategic recon and situational intelligence platform designed for live operator workflows, utilizing a Next.js-based web application. It features a comprehensive suite of tools including live global tracking layers, open-source intelligence workflows, browser-accessible recon tools, AI-generated analysis, and the capability to produce fusion dossiers, making it suitable for security, geopolitical, and crisis-monitoring applications. The platform emphasizes a user-friendly interface for fast situational assessments, integrating various data layers and alerts within a single operational workspace.
03 Aug 2026
★ 59
The wordlist-generator is a terminal-based tool designed for creating customizable password lists to facilitate brute force dictionary attacks on social media accounts. Notable features include the ability to incorporate predicted prefixes and suffixes, as well as an option to generate numeric sequences, enhancing the likelihood of successfully cracking passwords.
03 Aug 2026
C
★ 11
WiFi-Deauther is a tool designed for executing deauthentication attacks and monitoring Wi-Fi packets using an ESP8266 module. It features an OLED display for real-time status updates, button controls for navigation, and the ability to enhance signal strength with external antennas. The tool is primarily intended for educational and security testing, emphasizing responsible use with appropriate permissions.
03 Aug 2026
Python
★ 70
VulnScan is a vulnerability scanning tool designed to assist website owners in identifying and addressing security threats by leveraging the OpenAI ChatGPT AI model to analyze JavaScript code for vulnerabilities. Although no longer actively maintained, it offers features aimed at detecting and fixing security flaws, with potential future enhancements planned, including support for various vulnerability types and improved user interface options. The tool is intended for educational use, emphasizing the importance of compliance with legal standards.
03 Aug 2026
★ 40
The tool described in the repository focuses on utilizing blockchain analysis to uncover relationships between dark web services and trace cryptocurrency transactions, specifically Bitcoin. It leverages tools like Fresh Onions and Wallet Explorer to identify digital fingerprints of onion sites and analyze wallet connections, thereby enhancing the investigative capabilities of OSINT activities related to cryptocurrency crimes. Notable features include the ability to link onion sites, trace transactions to exchanges, and reveal ownership connections among dark web platforms.
03 Aug 2026
Shell
★ 23
Termux-AutoSetup is a modular toolkit designed for efficiently setting up a Termux environment on Android devices, enabling users to install essential command-line and security tools with a single command. Notable features include a categorized selection of tools for basic functionalities, hacking applications, and custom-built utilities, streamlining the installation process for users. The script is beginner-friendly, requiring minimal initial setup and offering a straightforward execution process.
03 Aug 2026
Go
★ 14
SubFors is a modular subdomain discovery tool designed for rapid enumeration of subdomains, integrating various techniques for comprehensive attack surface analysis. Notable features include multi-engine enumeration, API support for services like VirusTotal and GitHub, certificate transparency monitoring, and bulk domain processing with customizable wordlists. This tool is particularly beneficial for security professionals seeking to enhance their reconnaissance capabilities and automate the discovery process.
03 Aug 2026
C++
★ 138
SpyAI is an intelligent malware designed to capture screenshots of entire monitors and exfiltrate the data via a secure channel to a Command and Control (C2) server. Utilizing GPT-4 Vision, it analyzes the images frame by frame to construct daily activity reports. Key features include integration with Slack for secure communication and customizable operational parameters for timing and monitoring.
03 Aug 2026
PHP
★ 230
slopShell is a PHP webshell designed for educational exploitation purposes, primarily allowing unauthorized file uploads to potentially compromised servers. Notable features include mutual TLS support in future iterations, a more refined dropper to evade detection, and the ability to interface with a personal database of cloud entities. This tool is intended for use in controlled environments and is equipped with capabilities for randomized user agents to minimize detection risks.
03 Aug 2026
C++
★ 210
RunAs-Stealer is a credential harvesting tool designed to exploit Windows systems by implementing three techniques: hooking `CreateProcessWithLogonW`, smart keylogging, and remote debugging. Its primary use case is to stealthily capture user credentials and store them in an alternate data stream of a desktop.ini file for later retrieval. Notable features include continuous operation in the background and the ability to eliminate captured credentials directly via command-line instructions.
03 Aug 2026
Python
★ 22
RAR-NextgenerationAI-expliot is a robust toolkit designed for conducting scientific investigations into malware development and evasion techniques. It encompasses a variety of functionalities, including executable file creation, RAR file assembly with both documents and payloads, process injection, and advanced AI-driven methods to evade detection by security mechanisms. Additionally, it integrates polymorphic code and persistence techniques to enhance stealth and maintain access, culminating in a comprehensive resource for malware analysis and research.
03 Aug 2026
Python
★ 18
Pinkcord is a Python-based remote administration tool that uses Discord bots for command and control (C2) communication, allowing users to manage remote systems in a manner analogous to traditional RATs. Notable features include executing remote shell commands, file transfers, screen capture, and system interaction capabilities, while leveraging Discord's infrastructure for seamless communication. It is important to note that Pinkcord is designed strictly for educational purposes and its misuse can lead to legal repercussions.
03 Aug 2026
Python
★ 13
php-in-jpg is a tool for generating JPEG images that embed PHP payloads leveraging two methods: inline embedding and EXIF metadata injection. It facilitates remote code execution (RCE) through a GET-based execution mode or fixed command specifications, making it particularly useful in webshell demos and upload exploitation scenarios. Notable features include customizable templates for output, an optional preview mode, and support for both embedding techniques.
03 Aug 2026
Shell
★ 16
Parrot is a lightweight shell-based tool designed specifically for Termux, enabling users to maximize the potential of Linux on their Android devices. Key features include its 100% shell script implementation for compatibility, seamless integration with Termux for mobile development, and a focus on fast performance with minimal dependencies.
03 Aug 2026
★ 76
The "osint-notes" repository is a comprehensive catalog of Open Source Intelligence (OSINT) tools organized by various categories such as data extraction, email investigation, and social media intelligence. It serves as a valuable resource for cybersecurity professionals and researchers seeking to enhance their investigative capabilities with tools tailored for specific OSINT tasks. Notable features include detailed sections on each tool with descriptions, links, and tags to facilitate easy navigation and discovery of appropriate utilities for gathering and analyzing public information.
03 Aug 2026
Python
★ 124
Kizagan is a Remote Access Trojan (RAT) and Command and Control (C2) tool developed in Python, designed to create executable files for controlling compromised machines. Key features include advanced functionalities such as file management, real-time screen streaming, capturing screenshots and video from the victim's camera, and an integrated keylogger. The tool is intended for educational use in security research and red teaming, with ongoing development for enhanced capabilities.
03 Aug 2026
Python
★ 21
Ghost Shell is a user-friendly Python-based backdoor generator that simplifies the process of creating payloads for Windows, Linux, and Android using msfvenom. It automates the payload creation and Metasploit listener setup for ease of use, featuring one-click operations and a visually appealing interface tailored for beginners in cybersecurity. Notable features include compatibility with services like Ngrok, customization options for IP and port, and a lightweight design aimed at educational purposes only.
03 Aug 2026
Python
★ 81
Email-Bomber is an open-source tool designed for sending bulk emails using Python's SMTP library, with an easy setup process including Docker support and a GUI version. Its primary use case is for testing email systems through simulated bulk sending, and it features secure app password integration for Gmail accounts, ensuring minimal interference with standard authentication processes. The tool provides comprehensive installation guidance for various platforms, including Termux and Linux distributions.
03 Aug 2026
★ 105
DogeRat is a premium Android RAT (Remote Access Trojan) designed for comprehensive control over target devices, specifically within an educational context. Key features include real-time screen capture, advanced keylogging, and the ability to manage files and applications remotely, alongside a powerful admin dashboard that supports simultaneous control of multiple devices. The tool also offers undetectability by antivirus software and persistent functionality, ensuring uninterrupted access even after device restarts.
03 Aug 2026
Shell
★ 329
Carpunk is an advanced CAN Injection Toolkit designed for testing and exploiting vulnerabilities within vehicle CAN (Controller Area Network) systems. Notable features include compatibility with both simulated and real vehicles, the introduction of two new types of CAN injection attacks, and operational functionality tested on Ubuntu and Parrot OS. The tool also facilitates basic sniffing capabilities and requires manual loading of CAN bus drivers for usage.
03 Aug 2026
★ 19
The Advanced Bug Bounty Arsenal is a comprehensive repository designed for bug hunters seeking to enhance their skills through curated methodologies, tools, and techniques. It covers all phases of the bug bounty process, including reconnaissance, vulnerability discovery, exploitation, and reporting, with specific scripts and tools provided for various tasks such as subdomain enumeration, API endpoint discovery, and cloud assets scanning. This resource serves both beginners and experienced researchers, promoting ethical hacking while fostering community growth and knowledge sharing.
03 Aug 2026
Python
★ 11
BruteForceIG is a brute force tool designed for educational purposes to test the security of Instagram accounts. Its primary use case is to help users understand authentication mechanisms and security defenses, featuring multi-threading for optimal speed, random user-agent support, and capabilities such as SSL pinning bypass. The tool emphasizes responsible use, stressing that unauthorized access may lead to account blocking or legal action.
03 Aug 2026
★ 140
The "Awesome Capture the Flag Cheatsheet" is a comprehensive resource designed to assist cybersecurity professionals and enthusiasts in tackling online Capture the Flag (CTF) challenges and Hackthebox machines. It features curated tips and strategies across various domains, including system hacking, web hacking, cryptography, and forensics, with a strong emphasis on practical tools like Nmap for reconnaissance and scanning tasks. Notable features include specific command examples, categorized hacking techniques, and best practices aimed at enhancing performance in competitive environments.