03 Aug 2026
C
★ 436
ICE9 Bluetooth Sniffer is a Wireshark-compatible tool designed for comprehensive Bluetooth traffic analysis through wideband sniffing capabilities, utilizing software-defined radios like HackRF and bladeRF. It features multi-channel support (4-60 MHz) and offers command-line operation for capturing Bluetooth Low Energy (BLE) packets or all channels, with the ability to log data into PCAP files for further analysis. Additionally, it supports GPU-accelerated FFT processing and can be integrated directly into Wireshark for user-friendly interface access.
03 Aug 2026
HTML
★ 54
Email-Security-Auditor is a robust tool designed to enhance email authentication verification by conducting in-depth behavioral analysis across security protocols such as SPF, DKIM, and DMARC. Its notable features include policy fuzzing for automated edge-case discovery, machine-learning-based reputation scoring, and comprehensive compliance reporting capabilities, making it essential for organizations facing contemporary email threats and regulatory pressures. The architecture supports horizontal scaling and microservices isolation, ensuring reliability and effectiveness in enterprise environments.
03 Aug 2026
Rust
★ 239
Hacking Rust is a comprehensive online tutorial designed to teach reverse engineering techniques for Rust programming, specifically targeting x64, ARM64, and ARM32 architectures. It includes step-by-step lessons covering various concepts such as debugging, scalar and compound data types, and functions, with an emphasis on hands-on hacking exercises. Notable features include a free downloadable book and a structured approach that guides users from basic Rust programming to more complex reverse engineering tasks.
03 Aug 2026
C#
★ 15
The Discord Token Password Stealer is a malicious tool designed to extract sensitive user information from Discord accounts, including passwords, tokens, and credit card details. Its primary use case involves the stealthy capture of credentials from victims, facilitated by a user-friendly interface for compiling and deploying the software. Notable features include extensive logging of user data, the ability to change passwords and emails, and bypassing certain protections within Discord clients.
03 Aug 2026
★ 18
Awesome-Hacking is a comprehensive resource hub designed for hacking, pentesting, and security research, providing a curated collection of tools and materials beneficial for System and Network Administrators, DevOps professionals, and security researchers. Notable features include its repository of daily use tools, practical navigation through a simple Table of Contents, and an open-source nature that encourages contributions from users. The repository serves as a valuable reference point for anyone interested in cybersecurity.
03 Aug 2026
Go
★ 15
The cisco-snmp-pwner tool facilitates the exploitation of Cisco devices with read-write SNMP access by enabling users to dump the running configuration or add new users. It operates a local TFTP server to manage these configurations and supports SNMP versions 1, 2c, and 3, with customizable community strings and user roles. Notable features include the ability to merge configurations and streamline user management, while requiring root access to function properly.
03 Aug 2026
★ 13
The MottaSec White Papers repository is a centralized collection of technical and cybersecurity white papers published by MottaSec, providing insights into various topics such as military drone security and IoT device boot integrity. Notable features include a clear organizational structure for easy navigation, self-contained papers with supporting materials, and multiple access formats including GitHub markdown and professionally formatted PDFs. This repository serves as a vital knowledge base reflecting the expertise and research of MottaSec in the cybersecurity domain.
03 Aug 2026
Python
★ 48
w4af is an open-source web application security scanner designed for developers and penetration testers to identify and exploit over 200 vulnerabilities, such as Cross-Site Scripting and SQL Injection. Built on Python 3.11 and currently in an alpha development phase, it features integrations for unit and integration testing alongside comprehensive documentation for user guidance.
03 Aug 2026
TypeScript
★ 63
Vigilo is an autonomous smart contract security auditing tool designed to identify vulnerabilities within Web3 applications. Utilizing specialized agents within a structured pipeline, it facilitates an automated auditing process by handling tasks such as reconnaissance, deep analysis, and report generation across multiple programming languages including Solidity and Rust. Notably, Vigilo features a modular architecture with dedicated auditors for various vulnerability types and integrates seamlessly with existing development workflows like Foundry.
03 Aug 2026
Ruby
★ 693
URLCrazy is an OSINT tool designed for generating and testing domain typos and variations to identify instances of typo squatting, URL hijacking, phishing, and corporate espionage. Notable features include support for 17 types of domain variants, over 8000 common misspellings, compatibility with 1500+ Top Level Domains, and options for popularity estimation and keyboard layout configurations. The tool automates the detection of potential threats against domains by checking the validity and usage of generated typo variants.
03 Aug 2026
★ 33
The TryHackMe-Beginner-Roadmap is a structured learning resource designed for novices in cybersecurity, providing a step-by-step guide to essential concepts and skills via the TryHackMe platform. It covers foundational topics such as operating system fundamentals, basic security principles, reconnaissance techniques, scripting for automation, and web security vulnerabilities, while incorporating hands-on exercises to reinforce learning through practical application. Notable features include a comprehensive overview of key cybersecurity tools and methodologies, facilitating knowledge development in both theoretical and practical dimensions.
03 Aug 2026
C#
★ 14
Torpedo is a modern enhancement of PsExec, designed for remote execution and token impersonation, featuring advanced capabilities for red teams and security researchers. Notable functionalities include fileless DLL payload delivery, polymorphic runtime encryption for evading detection, and robust artifact cleanup post-execution, all while maintaining a familiar operational structure for users of PsExec. The tool's stealth improvements and enhanced flexibility make it suitable for authorized penetration testing and security assessments.
03 Aug 2026
C
★ 68
TibaneC2 is a modular Command & Control (C2) framework designed for offensive security research and red teaming, featuring a C/C++ core server, a PHP-based web panel, and a CLI console. Its notable characteristics include cross-platform implants, multi-language stagers, and scripting tools for enhanced automation and emulation, facilitating extensive customization without altering core functionality. The framework is intended strictly for educational and authorized testing purposes.
03 Aug 2026
YARA
★ 166
The ThreatHunting-Keywords-yara-rules repository provides a collection of YARA rules tailored for threat hunting sessions, enabling users to identify potential threats based on specific keywords associated with offensive and greyware tools. It features two main ruleset folders: one prioritizing broader detection coverage at the cost of performance, and another optimized for higher fidelity and efficiency, along with a Python script for cross-platform scanning capabilities. The rules are systematically organized and include specialized sets for different tool types while allowing for the identification of potential threats in various file formats.
03 Aug 2026
PowerShell
★ 672
ThreatHunting-Keywords is a repository providing a comprehensive list of keywords to facilitate threat hunting activities in cybersecurity. It serves both blue teams and red teams, offering tools and methodologies for detecting and analyzing malicious activities that may evade automated security systems. Notable features include integration with SIEM tools like Splunk and ELK, DFIR optimized hunting strategies, and support for creating detections using YARA rules and SIGMA rules.
03 Aug 2026
★ 27
The Potato Garden repository compiles various Windows privilege escalation tools, referred to as "Potatoes," each sourced from different open-source projects. Its primary use case is to provide security professionals with readily accessible binaries for testing and exploiting vulnerabilities within Windows environments. Notable features include the aggregation of multiple tools into a single collection, enabling streamlined access and use for penetration testing and security assessments.
03 Aug 2026
C++
★ 10
SyscallInjector is a stealthy DLL injector designed to execute direct syscalls on Windows, effectively bypassing endpoint detection and antivirus hooks. Its notable features include dynamic resolution of System Service Numbers, manual PE mapping, and the use of RWX memory allocation to circumvent commonly hooked functions. Additionally, it incorporates a mechanism to wipe shellcode after execution to further evade detection.
03 Aug 2026
Python
★ 174
SuperLibrary is an educational repository designed to provide access to a collection of books and courses aimed at individuals who may face financial constraints in obtaining these learning resources. It emphasizes ethical usage, urging users to support authors and publishers whenever possible, while also featuring a disclaimer regarding copyright and legal responsibilities. Notable features include categorized content such as books and courses, fostering self-education in various subjects.
03 Aug 2026
C++
★ 57
Stealth Keylogger is a discreet Windows keylogger that utilizes low-level keyboard hooks to capture all keystrokes across the system, including special characters and unicode, while tracking the active window. Its notable features include a thread-safe buffer, immediate data flush upon right-click or enter, mechanisms for evading detection such as indirect syscalls and API hashing, and configurable logging to a file or transmission to a command and control server. The tool is designed for educational and authorized security research purposes.
03 Aug 2026
Jupyter Notebook
★ 225
SploitCraft is a repository designed for hacking and offensive security that provides a curated collection of exploits, penetration testing techniques, and vulnerability demonstrations. Its primary use case is to assist cybersecurity professionals and enthusiasts in understanding and showcasing the latest threats through organized guides and proof-of-concept demonstrations. Notable features include a structured layout by specific topics and comprehensive step-by-step instructions, enabling users to easily replicate the techniques in controlled environments.
03 Aug 2026
Python
★ 19
SpecterNet is an advanced network anonymization framework designed to route all system traffic through the Tor network, enhancing security and privacy. Its notable features include full traffic routing, built-in DNS and IPv6 leak protection, a kill switch to block traffic during Tor disconnections, and hardware identity spoofing. Additionally, it offers comprehensive leak testing, censorship bypassing capabilities, and a modern terminal interface for monitoring and management.
03 Aug 2026
Python
★ 18
Slacksploit is a forensic analysis framework designed to enumerate slack artifacts within various operating systems, including Windows, Mac, and Linux. It offers capabilities such as fetching cookies, retrieving user and Slack client logs, and extracting authentication tokens from levelDB files; additionally, it provides a GUI visualizer plugin for Slack user data and allows data export to CSV format. This tool is particularly useful for investigating and analyzing Slack-related data within a forensic context.
03 Aug 2026
HTML
★ 38
SecuSploitX is an advanced, modular, open-source penetration testing and cybersecurity toolkit designed for offensive security operations. It features a comprehensive suite of tools including web and network security modules, AI-driven automation for tasks like phishing simulations, and both GUI and CLI interfaces for user flexibility across multiple platforms. Notable capabilities include automated vulnerability scanning, advanced brute force tactics, and extensive documentation, making it suitable for both educational and professional use.
03 Aug 2026
Python
★ 18
Scrapy Scraper is a web crawling and scraping tool that utilizes Scrapy integrated with Playwright's headless browser to handle JavaScript-rendered content effectively. Its primary use case includes probing, crawling, and extracting data from websites, with features such as support for concurrent requests, customizable sleep intervals, and the ability to take screenshots. Additionally, it offers options for rate limiting and recursive crawling, enhancing its usability for various scraping scenarios.
03 Aug 2026
Python
★ 18
SLAP (Secret Locator and Package-Analyzer) is a tool designed to streamline the discovery of sensitive information in SCCM deployment points by searching for secrets within files and downloading entire packages for analysis. Key features include the ability to report on secrets found using customizable regex patterns, inventory files in CSV format, and bypass secured datalibs for comprehensive scanning. SLAP enhances the efficiency of threat detection in SCCM environments by automating the retrieval and examination of data stored across application packages.