03 Aug 2026
Python
★ 24
NetWatch Advanced Breach Scanner v2.0 is a sophisticated penetration testing toolkit designed for authorized security assessments, enabling users to probe web applications, APIs, and network services for vulnerabilities. Notable features include extensive recon capabilities such as web crawling and subdomain enumeration, various injection modules for SQL and XSS attacks, and robust security assessments of authentication methods and API protocols. The tool also provides detailed reporting options and a command-line interface for streamlined operations.
03 Aug 2026
★ 11
Web-Security is a comprehensive resource designed to educate users on web security practices, particularly focusing on the OWASP Top 10 vulnerabilities including XSS, SQL injection, and CSRF. It provides a collection of materials, tools, and hands-on labs, aimed at enhancing secure coding practices for developers. Notable features include detailed explanations of various vulnerability classes, their exploitation techniques, and links to relevant communities and learning resources.
03 Aug 2026
HTML
★ 230
ToolHunt is an advanced search engine designed to facilitate the discovery of cybersecurity tools from a comprehensive database exceeding 3,000 entries. Its primary use case is to help security professionals, pentesters, and researchers quickly identify relevant tools through a semantic search powered by AI, which utilizes hybrid algorithms for optimal match relevance. Notable features include a cyberpunk-themed user interface, responsive design for various devices, and cloud deployment capabilities via Google Colab.
03 Aug 2026
Go
★ 24
The Dark Mark is a command and control (C2) framework designed for efficient management of cybersecurity operations, enabling real-time command execution and secure client communication. It supports scalability, facilitates monitoring of client activities, and is user-friendly for both small and large-scale deployments. Key features include an intuitive command set for module management and easy setup, making it a versatile tool for cybersecurity professionals and researchers.
03 Aug 2026
C
★ 15
symp is a Mach-O symbol-based tool designed for patching functions in binary files by leveraging symbol tables, export tables, and Obj-C metadata. Its primary use case is for developers and security researchers to manipulate binary files through various patching methods, including writing hex bytes, implementing predefined patches, or replacing functions with new binaries. Notable features include support for multiple symbol formats, architecture selection, and integration with the xsp tool for enhanced hex patching workflows.
03 Aug 2026
Python
★ 39
SimpleReconSubdomain is a passive and active subdomain enumeration tool designed for OSINT and reconnaissance workflows, leveraging async Python to query 50 sources in parallel without external shell dependencies. Key features include multi-probe wildcard detection, DNSSEC NSEC zone walking, TLS SAN extraction, and advanced scraping techniques, which facilitate comprehensive subdomain discovery and enumeration, along with subdomain takeover detection capabilities. The tool supports continuous monitoring and provides output in various formats, making it suitable for integration into automated security workflows.
03 Aug 2026
Shell
★ 72
setupkali.sh is a setup script designed to enhance the functionality and usability of Kali Linux, particularly for version 2026.2, by integrating features such as root login, Nemo file manager replacement, and Wayland optimization. Its primary use case is to streamline the setup process for cybersecurity professionals and students, ensuring compatibility with the latest tools and improving system management through advanced configuration and verification strategies. Notable features include a smart cleanup strategy, idempotent configuration handling, and enhanced support for various cybersecurity tools.
03 Aug 2026
Python
★ 117
scan4secrets is a comprehensive security scanning tool that integrates both Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST) to identify leaked credentials, code vulnerabilities, and configuration misconfigurations across source trees, live web applications, and CI logs. Its notable features include live verification of secrets against vendor APIs, source-map parsing for JavaScript, authenticated DAST capabilities, and support for generating reports in SARIF, JSONL, and multiple formats for client presentations, thereby providing a holistic approach to application security assessment.
03 Aug 2026
Python
★ 654
PyHTools is a comprehensive collection of Python-based hacking tools designed for network security assessments, including functionalities such as network scanning, ARP spoofing, DNS spoofing, and credential harvesting. It features a user interface for accessibility while allowing command-line usage for advanced users, with an emphasis on ethical use, as all malicious components are stored in a separate repository. The toolkit facilitates a wide range of cybersecurity practices, from reconnaissance to exploitation, but users are warned against any illegal applications.
03 Aug 2026
Python
★ 15
Proxy Reaper is a multifunctional proxy evaluation tool designed to assess the availability, speed, and anonymity of various proxy servers, including HTTP, HTTPS, SOCKS4, and SOCKS5 protocols. Notable features include concurrent proxy checking, response-time categorization, anonymity detection, GeoIP resolution, and the ability to export results in multiple formats such as JSON, CSV, and SQLite. The tool also supports automatic proxy list downloads and includes advanced filtering options for efficient results analysis.
03 Aug 2026
Python
★ 12
PROTECT-KIT appears to be an unmaintained cybersecurity tool with no functional capabilities, as indicated by the warning of being "USELESS Code." Due to its lack of maintenance and features, it is not suitable for any practical use case in the cybersecurity domain.
03 Aug 2026
Python
★ 27
DARKSTAR v2.1 is a command-line penetration testing framework designed for security professionals, featuring 57 modular tools across various categories. Its key features include a plug-and-play plugin system, automatic plugin discovery, a matrix-inspired color-coded terminal UI, and support for threading and async operations, making it highly customizable and efficient for diverse security assessments. The toolkit is compatible with multiple platforms, including Kali Linux, Termux, Windows (WSL), and macOS, and requires only standard Python dependencies.
03 Aug 2026
Python
★ 20
Phone Number Tracker is an advanced OSINT framework designed for comprehensive phone intelligence gathering, utilizing over 2650 lines of Python code. It provides features such as phone parsing and validation, live location tracking through multiple APIs, and extensive subscriber information. Notably, it includes capabilities for forensic reporting, case management, and deep OSINT checks across various platforms, making it a robust tool for authorized security research and educational purposes.
03 Aug 2026
★ 94
Pentest-Resources is a comprehensive repository that consolidates essential resources for penetration testing and red teaming, including cheatsheets, tools, techniques, and write-ups. It serves as a centralized hub for offensive security practitioners, offering categorized content that enhances knowledge sharing and skill development in various cybersecurity domains. Noteworthy features include a well-structured organization of resources across multiple categories such as API security, networking, and programming, making it a valuable tool for cybersecurity professionals.
03 Aug 2026
C++
★ 18
OpenDoorSim is an open-source tool designed to simulate Physical Access Control Systems (PACS) for hands-on experimentation and research. It supports integration with both Wiegand and OSDP readers, featuring a web UI, on-device menu, and various operating modes for enhanced functionality. The tool is highly portable, powered via USB-C, and optimized for creating engaging demos and workshops in the field of RFID security.
03 Aug 2026
HTML
★ 48
NullPhish is an automated phishing toolkit designed for security research, featuring over 30 customizable templates with integrations for Discord and Telegram. It offers a range of notable features including multiple tunneling options, URL masking, and Docker support, making it beginner-friendly while providing advanced capabilities for simulating phishing attacks. The tool serves educational purposes to demonstrate phishing mechanisms and comes pre-loaded with the latest login page designs.
03 Aug 2026
Shell
★ 264
Nucleimonst3r is a high-speed vulnerability scanner tailored for Red Teams and Bug Bounty Hunters, enabling rapid identification of potential attack targets by fetching and filtering URLs from a specified domain. It leverages the httpx tool for scanning and provides dynamic template generation, real-time scan statistics, and comprehensive report generation, allowing users to customize scans effectively and integrate with other security tools for enhanced testing capabilities.
03 Aug 2026
JavaScript
★ 109
NGL - Nefariously Generated Links is a phishing tool masquerading as a legitimate application for receiving anonymous messages on Instagram. Its primary use case is to exploit users' trust by tricking their followers into submitting Instagram login credentials through a deceptive interface that mimics the popular NGL.LINK service. Notable features include the ability to create cloaked phishing links that can be shared on Instagram, allowing users to clandestinely harvest sensitive information.
03 Aug 2026
HTML
★ 623
NETHERCAP is a comprehensive Wi-Fi penetration testing and social engineering tool designed for deployment on ESP8266, ESP-32, and BW16 (RTL8720dn) devices. Its primary use case involves executing attacks such as deauthentication and the Evil Twin attack, offering features like multi-language support and easy installation through its GitHub releases. The tool is particularly targeted towards users in Indonesia and includes community support via Telegram and WhatsApp for enhanced user engagement.
03 Aug 2026
★ 10
Malware-Analysis is a comprehensive toolkit designed for learning and practicing malware analysis techniques, including reverse engineering, dynamic/static analysis, and sandboxing. The repository offers scripts, tools, and sample malware that facilitate hands-on experience in malware detection, classification, and analysis workflows. Noteworthy features include a curated collection of resources for anonymization, honeypots, and open-source threat intelligence, making it a valuable asset for cybersecurity professionals and researchers.
03 Aug 2026
C
★ 141
Lulzbuster is a high-speed, multithreaded HTTP(S) directory and file brute-forcing tool designed for penetration testing and security assessments. It leverages concurrent HTTP requests to efficiently enumerate valid file paths and directories, while offering customizable options such as status code filtering, proxy support, and client certificate usage. Notable features include the ability to minimize false positives through smart mode options and support for extensive wordlists to ensure comprehensive scan results.
03 Aug 2026
Python
★ 45
Linux-Monster is a versatile password cracking tool designed for Linux, macOS, Windows, and Android platforms, primarily used for brute-force password attacks. Notable features include custom dictionary generation, progress tracking for resumed sessions, improved UI/UX, and dynamic settings that do not require restarts to apply changes. The tool has been optimized for resource consumption and error handling, enhancing its overall efficiency during brute-force operations.
03 Aug 2026
Shell
★ 11
Linemadpeas is a comprehensive Linux privilege escalation enumeration tool implemented in Bash, designed to thoroughly scan Linux systems for potential privilege escalation vulnerabilities. It offers a user-friendly interface, automatic detection of over 25 vulnerability categories, and detailed exploit methods with executable examples while generating two separate output files for enumeration reports and exploit strategies. This tool is particularly valuable for penetration testing, security auditing, and educational purposes in understanding escalation techniques.
03 Aug 2026
Kotlin
★ 12
Intentions is an Android tool designed for testing and manipulating Inter-Process Communication (IPC) via Intents, primarily intended for users with rooted devices running Android 10 and above. Key features include the ability to scan installed apps for their exported components, build and dispatch custom Intents, capture incoming Intents through a sink and logcat observer, and perform replay and fuzzing of Intents, all while offering various export formats for generated commands. The tool acts as an IPC workbench, combining intent discovery, custom intent creation, and comprehensive testing capabilities tailored for security researchers and developers.
03 Aug 2026
C#
★ 22
InstaMailChecker is an OSINT tool designed to verify if a specific email is registered on Instagram. Its primary use case includes bulk processing of email addresses with support for saving results, utilizing options such as reading from a text file and integrating with GNU Parallel for enhanced performance. The tool is built on .NET 10 and provides a straightforward command-line interface for quick checks.