03 Aug 2026
HTML
★ 44
The Hacking-PenTesting-Utils repository serves as a comprehensive collection of tools, scripts, and configurations specifically designed for Internet of Things (IoT) penetration testing. It provides a variety of microcontroller options, RF modules, and essential hardware components to assist users in developing and deploying effective IoT security testing solutions. Notable features include a diverse range of compatible microcontrollers such as the ESP32, along with numerous supporting modules for enhanced functionality in various pen-testing scenarios.
03 Aug 2026
Shell
★ 59
Hackify is a bash script designed for Debian-based systems that facilitates the rapid installation of penetration testing wordlists and tools with a single command. Its primary use case is to streamline the setup process for cybersecurity professionals and enthusiasts, offering ease of deployment for various pentesting utilities. Notable features include comprehensive installation commands, support for Docker installations, and optional enhancements like Firefox themes and addons tailored for security tasks.
03 Aug 2026
★ 29
GrapheneUX is a modification tool for enhancing the functionality of GrapheneOS, focusing on reinstating various features typically found in Google Pixel devices. Its primary use case involves enabling options such as pattern unlock, on-device ADB, and advanced camera functionalities, as well as other user-requested tweaks like improved flashlight intensity and additional lockscreen widgets. Notable features include support for system privileges without root access and reverse-engineered functionalities that enhance user experience.
03 Aug 2026
JavaScript
★ 18
FexCam is a proof of concept tool designed for security research and education, demonstrating the exploitation of modern web APIs, including camera and geolocation functionalities, upon user consent. Its primary use case is to foster awareness of social engineering tactics and the importance of browser permission management, featuring capabilities such as media stream processing, system metadata extraction, and geolocation precision. Notable functionalities include integration with tunneling services like Ngrok and Cloudflare, enabling secure external access to local servers for demonstration purposes.
03 Aug 2026
Python
★ 97
Facemash is a Python-based tool designed for conducting brute force attacks on Facebook accounts, utilizing AI-driven strategies to enhance attack efficacy. It features various advanced password exploitation methods, real-time logging, and manual input capabilities, all aimed at identifying and testing vulnerabilities in social media security. Specifically developed for ethical hacking and cybersecurity research, Facemash is characterized by its precision and relentless attack mechanisms, but it is strictly intended for educational purposes only.
03 Aug 2026
Shell
★ 20
Evil-AP is an automation tool designed for conducting Evil Twin attacks, streamlining the process for both cybersecurity professionals and enthusiasts. Notable features include its open-source nature, allowing extensive customization, and the ability to personalize the web interface, making it adaptable for various use cases.
03 Aug 2026
Shell
★ 18
The Endpoints Extractor is a Bash script tool that efficiently retrieves and extracts URLs and API endpoints from HTML, JavaScript, and JSON content found on web pages. It allows users to scan either a single URL or a list of URLs, with the capability to save the extracted results for further analysis, and features a straightforward command-line interface. Key functionalities include the use of `curl` for fetching content, alongside utilities like `grep` and `sort` for refining output, ensuring unique entries in the results.
03 Aug 2026
Go
★ 1742
emp3r0r is an advanced, zero-trust post-exploitation framework and command & control (C2) system designed for secure operations on both Linux and Windows environments. Its notable features include autonomous gossip mesh networking, fileless memory execution of Starlark-scripted agents, and robust cryptographic identity pinning, ensuring high levels of stealth, operational control, and security against impersonation attacks. The framework facilitates seamless integration and execution without relying on host-based interpreters, making it highly suitable for high-security scenarios.
03 Aug 2026
Python
★ 14
d3m0n_c1 is an open-source hacking phone designed for performing a variety of wireless attacks, including radio and WiFi hacking, as well as physical attacks via BadUSB. It features a customizable operating system, various connectivity options, and a compact design, making it suitable for security researchers and penetration testers. Notable capabilities include sub-GHz radio communication, an LTE module for SMS and calls, and a user-friendly application system.
03 Aug 2026
HTML
★ 222
CyberTrace is an advanced OSINT (Open Source Intelligence) and cyber intelligence platform designed for security researchers, bug bounty hunters, and penetration testers. It consolidates various reconnaissance techniques such as IP geolocation, ISP lookup, and WHOIS information into a streamlined, cyberpunk-themed dashboard, facilitating faster and more efficient investigations. Key features include an interactive map for visualizing data and the ability to gather intelligence from public camera sources, enhancing situational awareness for security operations.
03 Aug 2026
Python
★ 1233
Buildware-Tools is a versatile cybersecurity multitool designed for tasks such as Discord automation, OSINT reconnaissance, network diagnostics, and cryptographic utilities, all accessible via a single terminal interface. It operates natively on both Windows and Linux, requires only Python for setup, and features an array of tools, including an IP port scanner, DNS lookup, and a website vulnerability scanner, with some functionalities accessible only after contributing to the project. Regular updates ensure continuous enhancements and the introduction of new features, while a plugin manager allows the integration of community-made plugins.
03 Aug 2026
Python
★ 139
Black-Hat-Python is a repository of Python scripts designed for educational and ethical hacking purposes, focusing primarily on security research. It features tools for various password and credential attacks, including capabilities for password hash cracking and LDAP brute force attacks, while emphasizing compliance with legal and ethical guidelines. Users are encouraged to utilize these tools strictly for authorized security assessments, as the repository supports responsible disclosure and proper usage protocols.
03 Aug 2026
Python
★ 109
agent-smith is an innovative penetration testing framework designed to facilitate deeper and more intelligent security assessments while minimizing manual oversight. It utilizes advanced skills-based methodology combined with a customizable LLM to generate dynamic attack strategies and deliver comprehensive end-to-end findings, including proofs of concept and threat models. Key features include support for local LLMs, Docker-based isolation, and real-time collaboration through an interactive dashboard, enhancing the overall efficiency and effectiveness of the penetration testing process.
03 Aug 2026
Python
★ 414
Agartha is an advanced payload generation and access control assessment tool designed to identify injection vulnerabilities (such as SQLi, LFI, and RCE) and authentication issues in web applications. Key features include a dynamic wordlist generator for various injection vectors, a comprehensive access matrix for assessing authorization vulnerabilities, and the ability to convert HTTP requests to JavaScript for XSS exploitation. Additionally, it includes functionality for HTTP 403 bypass checks and generates Bambdas-compatible scripts for enhanced testing efficiency.
03 Aug 2026
Python
★ 96
WiFuX is a WPS security auditing tool designed for Android devices running Termux, enabling automated Pixie Dust and Bruteforce attacks against WPS-enabled routers. Notable features include a global command system, session management, and reporting capabilities, making it ideal for security researchers and network administrators wishing to evaluate their wireless infrastructure's security. The tool is fully optimized for mobile use and requires root access and a compatible Wi-Fi adapter.
03 Aug 2026
Python
★ 22
VivisectION is an emulation-driven toolset designed as a plugin for the Vivisect reverse engineering framework, enhancing GUI capabilities with functions for function emulation and reconnaissance. It enables users to emplace an emulator for specific functions easily, offering features such as an interactive console for dynamic analysis, and streamlined integration with other Vivisect tools. Noteworthy functionalities include function emulation via context menu operations and an interactive Python shell for advanced analyses, fostering a comprehensive environment for vulnerability research and reverse engineering.
03 Aug 2026
Python
★ 66
Vimana is a modular security framework designed for auditing Python APIs and web applications, leveraging a plugin-based architecture for thorough security assessments. Its primary use case encompasses vulnerability detection, static and dynamic analysis, and CI/CD integration, with notable features like application crawling, persistence analysis, and support for various continuous integration platforms. This tool enhances security professionals' capabilities through both automated and manual testing techniques.
03 Aug 2026
C#
★ 21
TerraAngel is a utility client designed for the game Terraria, offering advanced tools for enhanced gameplay and development. Notable features include an inspector for detailed character, NPC, projectile, and item information; a freecam mode for unrestricted camera movement; and a suite of visual utilities for analyzing game mechanics. The client supports real-time C# execution and net message debugging, making it particularly useful for developers working with Terraria's environment.
03 Aug 2026
Rust
★ 20
StegCloak is a tool designed to conceal secrets within plain text by compressing and encrypting the data, and then embedding it using invisible Unicode characters, enabling covert communication in various digital platforms. With features such as AES-256-CTR encryption, password protection, and high performance in both plaintext and encrypted modes, it allows users to watermark strings or engage in discreet messaging. The tool is also compatible with WebAssembly (Wasm) for integration in web applications.
03 Aug 2026
HTML
★ 23
Sqlite3 Page Explorer is an Electron-based application that enables users to open and explore SQLite databases, allowing for in-depth examination of their internal structures, including schemas, tables, and indices. Its notable features include hierarchical navigation of B-Tree pages, parsing of cell content, and the ability to view both current and deleted data pages, making it an essential tool for software development, ethical hacking, troubleshooting, and academic studies related to database formats.
03 Aug 2026
Python
★ 15
ShinobiShell is a specialized penetration testing tool designed for file exfiltration and exploit injection, facilitating remote shell interactions between the attacking and victim machines. Its notable features include encrypted tunnel creation, a command for seamless reverse shell connections, and capabilities for managing machine information and various payload delivery methods through a user-friendly shell interface. The tool is particularly geared toward enhancing operational efficiency during pentesting activities.
03 Aug 2026
JavaScript
★ 115
Pwnagotchi 64-Bit AI Edition is an advanced, high-performance adaptation of the Pwnagotchi project, optimized for 64-bit systems, leveraging PyTorch for enhanced AI inference and learning. Its primary use case involves automating Wi-Fi handshake capture through bettercap while intelligently adapting its behavior to varying environments based on reinforcement learning. Notable features include modernized AI engine support, a Kali Linux backbone for stable operation, and a Bluetooth Tethering Wizard for simplified connectivity setup.
03 Aug 2026
Python
★ 17
Logicytics is a forensic data collection tool designed for Windows systems, developed in Python to systematically retrieve and package extensive system data into a ZIP file for analysis. Its primary use case is to assist cybersecurity professionals in gathering sensitive information for forensic investigations. Notable features include its active development status and straightforward installation process, ensuring comprehensive data harvesting capabilities.
03 Aug 2026
Python
★ 24
The low cortisol shell handler
03 Aug 2026
HTML
★ 60
INtrack is a multi-threaded internet crawler and security scanner focused on network reconnaissance and vulnerability detection. It supports various scanning types, including the detection of web applications, IoT devices, and exposures, while offering flexible target selection, customizable settings, and real-time progress visualization. Notable features include support for multiple scanner types based on CVEs, the ability to scan either specific IPs or subnets, and a customizable thread count for efficient scanning.