> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

AutoShell

AutoShell is a web scanner tool designed to identify vulnerabilities and potential file upload points on websites. Its primary use case is to exploit such vulnerabilities by uploading files using various evasion techniques, including modifying file extensions, employing steganography, and using polyglot files to bypass security measures. Notable features include automated vulnerability detection, an array of file manipulation techniques to conceal uploaded scripts, and a user-friendly interface for initiating scans.

ZYRA

ZYRA is a Zig-based obfuscator, packer, and loader aimed at safeguarding executable files against static analysis and reverse engineering. Its notable features include performance optimization through Zig, the ability to generate complex control flow to hinder reversing efforts, and runtime decryption for secure execution of payloads. Currently, ZYRA supports Linux, with straightforward installation and usage options for packaging executables.

Xviews

Xviews is a traffic generation tool designed to increase the number of views on specified websites, particularly effective with Blogspot. It features a proxy support mechanism, allows simultaneous requests, and provides real-time monitoring through terminal color displays, enhancing user control over traffic parameters. The tool is intended strictly for educational purposes, with a clear warning against potential misuse.

xhackTool

xhackTool is a penetration testing framework designed for Android systems, enabling users to easily install and utilize multiple hacking tools. This tool streamlines the setup process by automating the downloading and installation of selected penetration testing utilities, making it ideal for educational purposes in cybersecurity. Notable features include a straightforward installation procedure and user-friendly selection interface for managing various tools.

Xbughunting

XbugHunting is a comprehensive suite designed for bug hunters and penetration testers, providing tools for information gathering, mapping, discovery, exploitation, and reporting. Notable features include a variety of integrated utilities such as DNS enumeration tools, port scanners (e.g., Masscan, Nmap), vulnerability scanners (e.g., Burp Suite, Acunetix), and exploitation frameworks for common web vulnerabilities. Its modular organization allows users to access and execute tools easily from a single Python interface, streamlining the bug hunting process.

X-tool

X-tool is a versatile hacking tool that provides a collection of utilities for various cyberattack methodologies, including phishing and DDoS attacks. It facilitates easy installation and management of these tools, enabling users to select and deploy their preferred options seamlessly. Notably, tools are automatically saved in the user's home directory for convenient access.

witchcraft

WITCHCRAFT is an advanced cybersecurity toolkit designed for professionals engaged in operational security (OPSEC), offering functionalities for hacking, OSINT, and forensic analysis. Key features include a modular command structure for tasks such as port scanning, data mapping, and searching for keywords across numerous platforms, bolstered by a comprehensive spellbook containing unique wordlists and databases for enhanced reconnaissance. This tool serves as an all-in-one cyberdeck system for efficient data-ghosting, network penetration, and threat analysis.

Windows-Post-Exploitation

The Windows Post-Exploitation repository provides a comprehensive resource for post-exploitation techniques specifically tailored for Windows systems. It includes an extensive catalog of commands, tools, and guides for executing post-exploitation tasks, especially in scenarios where traditional frameworks like Meterpreter are unavailable. Notable features include curated lists of PowerShell scripts, privilege escalation tools, and various post-exploitation techniques, making it an invaluable tool for penetration testers and security professionals.

wifite2-requirements

Wifite2 Requirements is a professional installation script designed to set up Wifite2 along with essential penetration testing tools such as hcxtools, hashcat, and aircrack-ng on Debian/Ubuntu-based systems. The script offers features like robust error handling, dependency management, optional update skipping, and detailed logging, making it user-friendly for authorized network testing and educational purposes while ensuring compliance with legal considerations.

WIFIHacker

WIFIHacker is a comprehensive WiFi penetration testing tool designed to automate various WiFi security audits and attacks, including phishing, SSID spamming, and denial of service attacks. Notable features include the ability to create fake access points for phishing, broadcast multiple fake SSIDs, and capture credentials. This tool requires a WiFi adapter that supports monitor mode to function effectively and aims to serve educational purposes while emphasizing responsible use.

WiFi-Pinapple

WiFi-Pinapple is a tool designed to create a Wi-Fi Pineapple device using Raspberry Pi hardware, enabling users to simulate attacks such as Evil Portal for testing purposes. It incorporates features like easy setup instructions, DHCP server configuration with dnsmasq, and iptables manipulation for traffic redirection to capture credentials on a spoofed access point. This tool is particularly useful for penetration testing and educational purposes in cybersecurity.

wifi-jammer

WiFi Jammer v1.3 is an advanced network testing tool designed for evaluating WiFi security with features such as an interactive user interface, automatic monitor mode setup, dual band support, and multiple attack methods including standard deauth and advanced MDK3 attacks. Its primary use case is for educational and authorized penetration testing of wireless networks, providing detailed security analysis and client detection functionalities while ensuring proper network restoration and error handling. The tool is developed for use on Kali Linux and requires essential wireless tools like the aircrack-ng suite for its operations.

Wifi-Brute

Wifi-Brute is a Python-based tool designed to crack Wi-Fi passwords using a user-provided wordlist. Its primary use case is testing the security of Wi-Fi networks by attempting to brute-force passwords, although effectiveness can vary depending on the wordlist size. Notable features include a simple command-line interface, the ability to specify custom wordlists, and the option to use a built-in default wordlist.

WhatsApp-Viewer

Linuxndroid WhatsApp-Viewer is a Python GUI application designed for extracting and displaying WhatsApp chat conversations from the app's SQLite database. Its primary use case is to provide users a straightforward way to view chat histories in a familiar chat-bubble format, along with features such as light and dark modes, support for contact names, and the capability to compile into a standalone executable for Windows. The tool eliminates the need for command line interfaces and web servers, making it accessible for users seeking to analyze their chat data effortlessly.

WannaTool

WannaTool is a cybersecurity tool designed for performing assessments on systems, with a primary focus on analyzing and exploiting vulnerabilities. Notable features include its compatibility with various Linux distributions such as Kali, Ubuntu, and Parrot OS, and its straightforward installation process via bash scripts. The tool aims to facilitate penetration testing and vulnerability exploitation in environments where security assessments are required.

Viridae

Viridae is a malicious software repository designed for educational purposes, emphasizing malware research and analysis. The tool is implemented in Python 2 and is intended to work across various Linux distributions and Termux on Android, allowing users to study different forms of malware behavior. Notably, it requires a specific set of Python dependencies and offers installation instructions for easy setup.

unbekannt-framework

The Unbekannt Framework is a specialized hacking and penetration testing tool designed for Windows environments, emphasizing ease of use with a modular command system. Notable features include support for various attack modules, options configuration for each module, and the ability to import custom Python modules. The framework facilitates the execution of penetration tests while encouraging community contributions through shared module development.

uCVE

uCVE is a cybersecurity tool developed in Go that facilitates the extraction of Common Vulnerabilities and Exposures (CVE) associated with specific software and version numbers. It generates reports in HTML format and supports exporting data in various formats, including text, JSON, and CSV, offering customizable search parameters such as risk levels and vendor inclusion/exclusion. The tool is designed for penetration testing and vulnerability management, streamlining the process of identifying security risks in software dependencies.

stickyburp

StickyBurp is a Burp Suite extension designed to facilitate the management of global per-project environment variables, referred to as "stickies," which can be created from selected text across different Burp tabs. This tool allows users to easily store, replace, and utilize dynamic payload content such as authentication tokens, UUIDs, and server URLs, enhancing the efficiency of penetration testing workflows. Notable features include sticky management with color coding, persistence across projects, and the ability to copy values easily for use in various Burp functions like Repeater and Intruder.

sqlmap-command-builder

SQLMap Command Builder is a web-based tool designed to simplify the process of crafting SQLMap commands through an intuitive point-and-click interface, eliminating the need to memorize complex command-line switches. It features real-time command generation, a fully client-side architecture for enhanced security, and compatibility with the latest SQLMap versions, making it accessible and user-friendly for penetration testers of all skill levels. The tool requires no installation and can be used directly through any modern web browser.

sms-sender

sms-sender is a Python-based tool designed to facilitate the sending of SMS messages via a command-line interface, primarily aimed at educational and testing purposes. It is compatible with both Windows and Linux environments, offering easy installation through automated scripts and dependency management. Notable features include compatibility with platforms like Termux and Kali Linux, as well as user-friendly command execution options.

smbrelay

SMBRelay is an offensive automation tool designed to exploit SMB relay vulnerabilities by intercepting NTLM authentication requests and relaying them to compromised systems to gain remote access. Key features include complete automation of NTLM relay attacks, integration with payload delivery tools like Nishang and MSFVenom, and real-time monitoring of incoming SMB requests, making it ideal for penetration testing in Windows environments. It is specifically developed for use on Kali Linux and focuses on facilitating security assessments by simulating real-world attack scenarios.

SharpGmailC2

SharpGmailC2 is a Command and Control (C2) tool that utilizes Gmail for exfiltrating data and receiving commands via SMTP and IMAP protocols. It allows users to send commands through unread emails while leveraging Gmail's infrastructure for stealthy operation, though it is noted that the tool is currently flagged by Windows Defender. This tool is designed for educational and testing purposes, enabling operators to manage remote implants over email while maintaining a relatively low detection profile.

samba-de-amigo-2k_modding

The Samba de Amigo 2K Modding toolset provides resources and utilities for modding the Dreamcast version of the rhythm game "Samba de Amigo: Ver. 2000." Key features include a console script for analyzing and converting AMG files, the ability to import Wii songs into the Dreamcast GDI image, and detailed file descriptions for enabling English translations and custom content. Future enhancements aim to simplify GDI modding and expand song import options from various sources.

Rubber-Ducky-Bad-USB

The Rubber Ducky Bad USB is a script that mimics the behavior of a Rubber Ducky device, utilizing the WshShell.SendKeys method from Windows Script Host to execute various commands for information gathering. It primarily serves as an educational tool to collect system and network information, including Wi-Fi passwords, by running a PowerShell script from a USB drive that is treated as a trusted Human Interface Device. Notable features include the automatic creation of a Data directory on the USB, comprehensive system data collection capabilities, and the ability to bypass script execution policies for enhanced control.