03 Aug 2026
HTML
★ 79
Red Team Wiki serves as a centralized public resource for information on Red Team tactics, techniques, and procedures (TTPs), with an emphasis on both the offensive and defensive elements of these methodologies. It allows users to access detailed documentation while providing options for community contributions through role assignments or pull requests. Notable features include a focus on reporting aspects of TTPs and a collaborative approach to content creation.
03 Aug 2026
Python
★ 48
rec0n is an automated toolkit designed for subdomain reconnaissance and sensitive data discovery, facilitating threat assessment and vulnerability identification. Key features include subdomain enumeration, live host detection, CORS vulnerability scanning, and sensitive file discovery with effective CLI output management. The tool integrates multiple utilities for enhanced functionality, allowing for organized output and historical data collection.
03 Aug 2026
Python
★ 11
The Raspberry Pi Pico WH is configured as a Human Interface Device (HID) for keystroke injection, functioning similarly to a rubber ducky. This tool allows remote payload management via a web interface, enabling users to upload and modify DuckyScript payloads effortlessly. It features an access point for direct connectivity to the Pico, streamlining the process of payload customization during target analysis.
03 Aug 2026
HTML
★ 76
R8HEX is a flexible Android Remote Access Tool (RAT) designed for cybersecurity professionals, students, and researchers to understand malware behaviors without the need for port forwarding. This tool offers extensive features such as SMS management, camera access, microphone recording, and device location tracking, with both free and paid versions providing varying levels of functionality. Its integration with Telegram allows for seamless remote management and control of Android devices during security assessments.
03 Aug 2026
Python
★ 13
Quze is an advanced penetration testing framework that employs quantum-inspired techniques, such as probabilistic optimization and adaptive payload mutation, to evade high-level security defenses without utilizing actual quantum computing. Its notable features include AI-driven payload mutation for dynamic attack vector generation, autonomous reconnaissance for vulnerability identification, and advanced obfuscation methods to disguise malicious traffic and execute commands stealthily. Designed for authorized penetration testing, it focuses on maximizing exploitation success while maintaining stealth against signature and behavior-based detection systems.
03 Aug 2026
Python
★ 330
The Python Scripts repository offers a diverse collection of open-source Python scripts designed for various practical applications. Key features include tools for air quality analysis, blog reading, user management on social media like Twitter and Facebook, expense tracking through a GUI, and basic encryption techniques. These scripts support user-friendly operations from terminal commands, allowing for enhanced productivity across multiple domains.
03 Aug 2026
Python
★ 82
Prem is a Python-based Instagram brute-forcing tool that facilitates unauthorized access attempts to Instagram accounts. It features enhanced login methods, a modern interface, and dual language support (English and Indonesian), making it accessible for users with varying technical skills. Additionally, it provides a comprehensive step-by-step installation guide for deployment on Termux.
03 Aug 2026
C++
★ 403
PhiSiFi is a dual-function cybersecurity tool designed to exploit WiFi networks using an ESP8266 microcontroller, implementing both Deauthentication and Evil-Twin access point (AP) attacks simultaneously. It allows users to disconnect devices from a target WiFi network while also setting up a fake AP to capture passwords from unsuspecting users, verifying them against the original access point. Notable features include a user-friendly interface for managing attacks and the ability to execute both methods without manual toggling.
03 Aug 2026
HTML
★ 620
Phishbait is a phishing tool designed to simulate phishing attacks by hosting replicas of 38 different websites, allowing users to generate luring links to target victims. Key features include easy setup through command-line instructions, the ability to create a local server using PHP, and the integration with Ngrok for tunneling, which conceals the server's presence. It is intended strictly for educational purposes, with a disclaimer against misuse.
03 Aug 2026
★ 148
PentBox is a comprehensive penetration testing toolkit designed to simplify various aspects of security assessments. Written in Ruby, it supports multiple operating systems and offers a wide range of functionalities, including command execution, honeypot capabilities, an expanded wordlist, HTTP directory brute forcing, and denial-of-service exploit modules. Notable features include improved interface options, enhanced logging, and new tools for MAC address geolocation and IP targeting from email sources.
03 Aug 2026
Python
★ 88
Net Strike is a load testing tool designed to simulate various types of network attacks, including TCP SYN flood, ICMP flood, UDP flood, and HTTP flood, to evaluate network performance and resilience under stress conditions. It provides capabilities to spoof IP addresses and includes functionality for crafting HTTP requests with custom headers to bypass basic filtering, making it versatile for testing different scenarios. The tool is intended for educational and demonstration purposes, with a strong warning against unauthorized usage.
03 Aug 2026
Python
★ 125
MacAttack is a graphical user interface (GUI) tool specifically developed for testing and brute-forcing IPTV stalker portals that users own or have permission to test. It allows users to identify accessible MAC addresses and assess portal vulnerabilities while providing features for proxy management, portal URL input, and playlist retrieval via a modified video player. The tool emphasizes responsible use, warning against unauthorized access to non-owned portals.
03 Aug 2026
Shell
★ 656
M-wiz is a bash-based tool designed for users of the Metasploit Framework on Termux, facilitating the installation, repair, updating, and backing up of the Metasploit environment. It is compatible with both rooted and non-rooted Android devices and offers a user-friendly interface for beginners, as well as features to address common issues such as Ruby errors. This tool significantly streamlines the Metasploit setup process, requiring minimal user input for efficient deployment.
03 Aug 2026
Shell
★ 154
JAR is a cybersecurity tool designed for automated reconnaissance and vulnerability scanning of web applications. Its primary use case is to assist security professionals and penetration testers in identifying security flaws through features such as modular scanning capabilities and integration with popular development tools. The tool is built using modern technologies such as React and Docker, enhancing its usability and deployment flexibility.
03 Aug 2026
Python
★ 127
HARRYv6 is a Facebook brute-force tool developed for cracking public files and automating Facebook interactions such as liking and commenting. It offers multiple cracking methods, an optimized file creator, and is designed to be used on the Termux platform, making it accessible and regularly updated without cost.
03 Aug 2026
Python
★ 37
The "Hacking Tools" repository offers a collection of cybersecurity utilities designed for various network reconnaissance and penetration testing tasks. Key features include ARP cache poisoning, subdomain enumeration via HTTPS certificate history, Google dorking for file discovery, and multiple implementations of network scanning and port scanning. These tools serve as essential resources for security professionals conducting assessments and vulnerability analysis.
03 Aug 2026
TypeScript
★ 150
Google Hacking Assistant is a Chrome extension designed to enhance security research by automating the injection of predefined and customizable hacking syntax into search engine results from platforms such as Google, Baidu, and Bing. It features an intelligent sidebar that facilitates advanced searches with over 11 built-in query types, custom syntax management, and bulk URL extraction capabilities, while ensuring user privacy through local data storage and no tracking. This tool aims to streamline the process of conducting legitimate security assessments and penetration testing.
03 Aug 2026
PHP
★ 153
Gecko is a web backdoor tool designed to facilitate exploitation and control of compromised systems, primarily targeting web applications. It features functionality for bypassing various HTTP error responses, auto-rooting capabilities, and the ability to manage backdoors, admin accounts, and file handling operations. Notably, it includes a Backdoor Destroyer and supports both Linux Exploit Suggester functionality and user account modifications, making it a versatile tool for penetration testing and system administration.
03 Aug 2026
Python
★ 14
gditools3 is a Python library and command-line tool designed for managing GD-ROM image (GDI) files, facilitating the listing, extraction, and generation of various file formats including sorttxt and boot sector (IP.BIN). The tool supports both Python 2 and 3, offers a graphical user interface for ease of use, and maintains file timestamps during extraction, while also providing functionality suitable for integration into other Python applications. Notable features include support for different data track formats and media playback capabilities via an external player.
03 Aug 2026
Python
★ 31
The Fake-SMS tool is a Python script that enables users to send SMS messages via the Textbelt API, featuring an interactive command-line interface with color enhancements for ease of use. Its primary use case revolves around programmatically sending text messages, providing clear feedback on message delivery status, and ensuring compatibility across multiple operating systems including Windows, macOS, and Linux. Notable features include API integration, colorful prompts using libraries such as `pystyle` and `colorama`, and a straightforward setup process.
03 Aug 2026
★ 17
The Ethical Hacking Course Resources repository provides a comprehensive collection of tools, links, and resources specifically designed to facilitate the learning and practice of ethical hacking. Its notable features include links to productivity tools for note-taking, setup guides for virtual environments, and curated references for various hacking methodologies, including courses on C programming and Active Directory attacks. This organized catalog serves as an essential reference for students and practitioners in ethical hacking.
03 Aug 2026
C++
★ 31
The WiFi Handshake Capture Tool is designed for security researchers and penetration testers to passively capture WPA/WPA2 EAPOL 4-way handshakes using an ESP32 development board. Key features include compatibility with standard network analysis tools like Wireshark and Aircrack-ng, a web interface for data retrieval, and the ability to save captures in PCAP format, facilitating further analysis. Users must adhere to legal and ethical standards when utilizing this tool for authorized network testing.
03 Aug 2026
Python
★ 38
DRILL (Distributable Remote Integrated Lightweight Link) is an advanced Command and Control (C2) framework designed for covert operations across diverse environments. Key features include WebSocket communication for efficient data transfer, single-port operation to evade detection, cloud tunnel compatibility, and comprehensive file transfer options. Additionally, it supports cross-platform payload generation and offers a redesigned user interface for improved usability, alongside robust persistence mechanisms and post-exploitation modules for enhanced control over target systems.
03 Aug 2026
Hack
★ 110
DefGen is a tool designed for creating customized HTML defacement pages, integrating CSS and JavaScript to enhance aesthetics. Its primary use case is for users looking to generate mock defaced webpages for testing or demonstration purposes. Notable features include easy installation via package managers and compatibility with various Linux distributions and mobile platforms.
03 Aug 2026
Python
★ 184
The "ddos" repository is a Python-based DDoS attack script that offers over 36 attack methods across Layer 7 and Layer 4 protocols, targeting various web server vulnerabilities. It includes notable features such as bypass mechanisms for popular anti-DDoS services like CloudFlare and OVH, as well as various flooding techniques like GET and POST floods. This tool is primarily aimed at penetration testing scenarios but is explicitly discouraged from usage against government sites.