> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

Moxy

Moxy is an open-source Dynamic Application Security Testing (DAST) tool designed for penetration testing, leveraging agentic AI capabilities for enhanced testing efficiency. Notable features include an intuitive user interface, support for both local and OpenAI's API integration for AI functionalities, and ease of deployment through Docker. Moxy is currently in beta, implying potential instability and incomplete features during active development.

miniss

miniss is a lightweight tool designed to display open listening sockets, serving as a minimal alternative to `ss` or `netstat`. Primarily aimed at penetration testers and CTF players, it offers a standalone static binary for environments where traditional socket tools might be absent, supporting both TCP and UDP protocols over IPv4 and IPv6. Notable features include customizable output options, socket type differentiation, and clear display of socket states along with associated user information.

Medium-Miner

Medium Miner is a tool designed for scraping articles from Medium, enabling users to read Medium blogs offline in their preferred Markdown reader. Its notable features include the ability to search for specific topics and download all articles from a specified author, making it a comprehensive solution for content consumption from Medium. The tool is free and easy to install and use, catering to users who wish to access Medium content without an internet connection.

Lucid-Engine

Lucid Engine is a tool designed for modifying game variables via the Chrome DevTools Protocol, establishing a websocket connection between the tool and the game, unlike traditional memory manipulation tools. Its primary use case is to provide a user-friendly interface for altering game elements, enabling customizations without direct memory edits. Notable features include its architecture overhaul and a straightforward interaction model for game manipulation.

longtongue

Longtongue is a tool designed to generate customized password and passphrase wordlists based on specific target information, such as individuals or companies. Notable features include the ability to incorporate various permutations like leet (1337) variations, numbers, and specified length limits, providing flexibility for different password complexity requirements. Users can easily configure the generation parameters through command-line options to tailor their wordlists for security assessments or penetration testing.

lit-bb-hack-tools

lit-bb-hack-tools is a command-line toolkit specifically designed for bug bounty hunters and penetration testers, focusing on web application security assessments. It includes a variety of tools that analyze URLs to extract critical information such as unique extensions, headers, status codes, and potential security vulnerabilities like DOM XSS sinks. Noteworthy features include processing input from standard input, producing comprehensive outputs, and supporting various common web testing scenarios.

LinuxDroid

LinuxDroid is a tool that provides a Linux Command Line Interface (CLI) and Graphical User Interface (GUI) for Android, enabling users to run various Linux distributions on their Android devices. It features a one-click installation script for easy setup, supports multiple distributions like Kali and Ubuntu, and includes essential security tools such as Nmap and Wireshark, making it suitable for tasks like penetration testing and server management. Additionally, it offers multiple desktop environments and window managers, enhancing the user experience across diverse use cases.

Link-x

Link-x is a malicious tool designed to extract sensitive data from victims' devices through various attack vectors, including accessing the camera, microphone, clipboard, and location. It primarily enables an attacker to gather extensive information with minimal effort, only requiring the victim to click on a specially crafted link. Notable features include real-time data capturing, remote access capability, and comprehensive device information retrieval.

K-OTP-X

K-OTP-X is an advanced one-time password (OTP) phishing tool designed for security testing and educational purposes. The tool primarily facilitates the creation of phishing pages that can capture OTPs, featuring tunnelling options such as Ngrok for remote access and requiring a PHP and Apache setup. It is compatible with various Linux distributions and Termux on Android, emphasizing ease of installation and use.

IntelTrace

IntelTrace is an automated OSINT intelligence collection tool designed for Linux environments, featuring a hacker-themed Flask web dashboard. It facilitates the collection of public intelligence data on IPs, emails, phone numbers, and usernames, offering advanced functionalities such as a reputation scoring engine, timeline builder, and robust reporting capabilities in both PDF and JSON formats. Notable features include a dark web scanning capability and a user-friendly interface with animated effects, catering to investigators seeking legal OSINT solutions.

instagrambruteforcer

InstagramBruteforcer is a Python-based tool designed for conducting brute force attacks on Instagram accounts using a configurable list of proxies. It features the ability to upload and manage proxy lists, monitor their performance through statistical insights, and prune underperforming proxies, all while attempting to find valid usernames and passwords from a specified list. The tool also provides real-time feedback on the progress of password attempts and highlights successful logins.

inject

Inject is a command line tool designed for crafting, injecting, and sniffing various network protocols, making it ideal for network troubleshooting, testing, or educational purposes. It supports multiple protocols such as Ethernet, ARP, IP, ICMP, TCP, and UDP, and includes features for creating custom network packets, integrating payload files, and capturing packets with customizable filtering options. Notable functionalities encompass detailed packet injection and robust network sniffing capabilities.

homodeus

Homo-Deus is a phishing toolkit designed for educational purposes, enabling users to simulate spear-phishing and conventional phishing attacks against over 40 popular websites to obtain authentication credentials. Notable features include website cloning capabilities and seamless integration with the evil-link tool for link masquerading. The tool emphasizes ethical usage and warns against illegal activities related to its functionality.

Hazard

Hazard is a Rust-based dictionary brute-force tool designed for testing the security of various network protocols including SSH, FTP, Samba, MySQL, and PostgreSQL. Its primary use case is to facilitate password cracking through a user-friendly interface, allowing operators to input target IPs and utilize predefined wordlists. Key features include multi-protocol support, customizable input options, and a straightforward installation process.

hackwifi

hackwifi is a Python-based toolkit designed for Wi-Fi penetration testing, facilitating tasks such as network scanning, packet capturing, deauthentication attacks, and password cracking. Key features include the ability to identify nearby networks, capture handshake packets for offline cracking, and perform deauthentication attacks to aid in the capture process. This tool is intended for educational purposes and requires proper authorization for use.

HacKingPro

HacKingPro is an ethical hacking toolkit designed for comprehensive security assessments, offering features for reconnaissance, exploitation, lateral movement, and reporting among other attack vectors. Its primary use case is to facilitate ethical hacking practices through a user-friendly graphical interface built with PyQt5, along with advanced functionalities including multi-language support, customizable reporting, and a plugin system for extended capabilities. The toolkit supports a variety of attacks such as web application exploitation, password attacks, and social engineering, making it a versatile resource for security professionals.

HackerProxyPro

Hacker Proxy Pro is an open-source proxy controller designed for Firefox and Chrome that enables users to seamlessly switch between Direct, Burp Suite, and Tor connection modes. It is tailored for Bug Bounty Hunters and Web Application Penetration Testers, featuring one-click mode switching, a smart badge and icon system, and a lightweight architecture optimized for efficiency and minimal resource consumption. The tool aims to enhance the speed and reliability of live traffic interception and debugging processes.

H4ck3R

H4ck3R is an open-source package designed for individuals interested in learning hacking and cybersecurity techniques. It provides a framework for educational purposes, facilitating the exploration and understanding of various cybersecurity concepts. Notable features include a comprehensive collection of tools and resources aimed at enhancing practical skills in ethical hacking.

H1Notifier

H1Notifier is an automated tool that monitors HackerOne for new bug bounty programs and sends email notifications to users upon detection. It utilizes Selenium for web scraping, operates entirely on GitHub Actions, and can run every three hours or be triggered manually, requiring minimal setup. Notable features include email notification support and seamless deployment via GitHub Actions.

FSOCIETY-RAT

FSOCIETY RAT V2 is a Discord-based Remote Administration Tool designed for system control and manipulation through a command line interface. Its primary use case includes executing system commands, accessing device features like screenshots and webcam capture, and credential dumping. Notable features encompass new keylogging capabilities, process management, and various trolling options, all while emphasizing ethical use in educational contexts.

fleex

Fleex is a tool designed for orchestrating distributed workload execution across cloud-based VPS fleets, enabling rapid scaling of various security tools like masscan and nuclei. Its notable features include multi-provider support, user-friendly fleet management commands, distributed scanning capabilities, and result aggregation functionalities. Additionally, Fleex encompasses a build system for provisioning tools with pre-configured recipes and provides cost estimation before running tasks.

exploit

Exploit is an offensive hacking tool designed to assist cybersecurity professionals and ethical hackers in executing exploits and conducting penetration testing. Its primary use case is to facilitate hacking activities, enabling users to automate various exploitation tasks. Notable features include ease of installation on any Linux distribution and comprehensive support for dependency management through a requirements file.

ethpwn

ethpwn is a command line tool designed for debugging and interacting with smart contracts on EVM-based blockchains, notably inspired by the pwntools and GEF frameworks. Its primary use case is to simulate and replay Ethereum transactions through the `ethdbg` utility, while also providing convenient wrappers for various `web3` functionalities. Key features include easy installation, configuration setup for Ethereum nodes, and support for mainnet and sepolia testnet.

ESP-GRABER

ESP-GRABER is a multiband RF signal tool designed for use with the ESP32 microcontroller and the CC1101 RF module, capable of operating across 315, 433, 868, and 915 MHz bands. Its primary use cases include reading, repeating, analyzing, and storing RF signals, with features that include signal storage for up to 20 keys and cautionary options for jamming RF signals. Notably, it serves educational and testing purposes but comes with a legal disclaimer regarding the use of jamming capabilities.

EnRaiJin

Enraijin is a robust web brute-force framework designed for automating credential testing against HTTP(S) web forms. Its primary use case is to facilitate long-term brute-force runs with a focus on readability and easy configuration via a YAML file, while also supporting reliable proxy management and token crawling to enhance its effectiveness. Notable features include customizable settings for form fields, the ability to handle multiple configurations, and integration with notification systems for real-time feedback during tests.