> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

SUASS

SUASS is a comprehensive repository designed to provide cybersecurity professionals and learners with a wide array of study materials, covering essential topics such as penetration testing, cloud security, mobile application security, network security, and more. This resource serves as a centralized hub for enhancing knowledge and skills in cybersecurity, offering practical learning pathways through Capture the Flag (CTF) challenges and recommendations for certifications. Notable features include categorized content for various security domains and links to external learning platforms and communities.

rvbbit-arsenal

RVBBIT Arsenal is a dual-purpose cybersecurity tool designed for educational purposes in Linux rootkit warfare, encompassing both offensive and defensive capabilities. It includes Project RVBBIT, a kernel rootkit integrated with a miner and a network worm for attack simulations, and RvbbitSafe, a defensive framework that detects and eliminates RVBBIT threats. This repository serves as a comprehensive resource for understanding both the techniques of rootkit deployment and the corresponding countermeasures.

rustsploit

Rustsploit is a modular offensive security tool written in Rust, designed for targeting embedded systems such as routers and cameras. It features a unified interface that provides an interactive shell, command-line execution, and a post-quantum encrypted REST/WebSocket API, along with built-in fingerprinting using Recog and JARM/JA3 methods. Notable aspects include self-registering modules, a credential management system, and extensive support for various network protocols and services, making it a versatile tool for penetration testing and vulnerability assessment.

rs-shell

RS-Shell is a reverse shell tool developed in Rust, designed to facilitate secure command and control operations through both TLS over TCP and HTTPS communication modes. It features a semiautomatic reverse shell, file transfer capabilities, and advanced execution options for PE and shellcode, complete with a proxy-aware Windows implant and privilege escalation methods. The modular architecture allows for easy customization and integration of various functionalities, making it suitable for offensive cybersecurity operations and testing.

Red-Team-Rust

Red-Team-Rust is an educational repository that provides a comprehensive collection of notes and resources focused on using the Rust programming language for offensive security. It covers fundamental Rust concepts, programming patterns, and specific applications in red teaming and malware development, emphasizing the advantages of Rust's memory safety and evasion properties. Aimed at security researchers and developers, the project facilitates a thorough understanding of Rust for creating robust red team tools.

Red-Team-Playbooks

Red Team Playbooks is a comprehensive repository designed to assist cybersecurity professionals in Red Team engagements by providing a collection of open-source tools, techniques, and procedures. Its primary use case includes guiding users through various phases of penetration testing such as reconnaissance, exploitation, and post-exploitation activities. Notable features include detailed playbooks for each stage of an attack lifecycle, covering essential actions from initial access to data exfiltration and situational awareness.

recon-deck

recon-deck is a self-hosted reconnaissance tool that transforms nmap output into an actionable, port-aware checklist in under 30 seconds. It features an AI co-pilot to explain scan results and suggest next steps, supports cross-host attack planning, and provides detailed export options for penetration testers and OSCP students, all while maintaining offline functionality. Notable capabilities include usage analytics and integration with HackTricks for enhanced documentation.

Python-Obfuscation-Framework

The Python Obfuscation Framework (pof) is an advanced toolkit designed for generating complex, staged obfuscated payloads aimed at enhancing offensive security practices. Its primary use case revolves around evading static and dynamic analysis through customizable obfuscation techniques that can combine to produce highly obfuscated outputs, including methods to verify target environments to ensure payload execution only occurs in specified conditions. Notable features include automation capabilities for producing multiple payload variants, methods for safeguarding against static and dynamic analysis, and options to store payload stages within images or trusted locations.

pwnbase

UFSC OFFSEC PwnBase is an academic initiative aimed at enhancing practical knowledge in offensive security and ethical hacking through research and educational development. The project focuses on vulnerability studies, exploit development, and creating training materials while promoting participation in Capture The Flag (CTF) events, all adhering to ethical standards. Notable features include hands-on learning opportunities and a collaborative approach to cybersecurity education.

operant-mcp

Operant-MCP is a comprehensive security testing tool designed for penetration testing, network forensics, memory analysis, and vulnerability assessment, offering an extensive array of 51 specialized tools. Key features include SQL injection tests, XSS vulnerability assessment, command injection detection, PCAP analysis for network traffic, and cloud security audits. This tool is targeted at security professionals seeking to streamline their testing processes and enhance their incident response capabilities.

offsecnotes

offsecnotes is a comprehensive web platform that aggregates notes and resources focused on offensive security and penetration testing methodologies. It encompasses various topics including Android, web application security, networking, and operating systems like Linux and Windows, providing essential concepts, exploitation techniques, and practical tools for security practitioners. Notable features include organized sections for different domains of security, making it a valuable reference for both beginners and experienced professionals.

offsec-ai

`offsec-ai` is a sophisticated Python library and command-line interface designed for authorized red-team engagements, integrating classic network reconnaissance methodologies with advanced AI and LLM security testing. It features a suite of tools for probing AI/LLM endpoints against the OWASP LLM Top 10, scanning MCP servers for critical vulnerabilities, and conducting comprehensive infrastructure security assessments, with recent enhancements for A2A protocol security checks that include dangerous skill detection and secret scanning. This tool mandates explicit authorization for active attack features, ensuring ethical use while delivering powerful capabilities for security testing.

offensive-onos

Offensive ONOS is a cybersecurity research tool designed to weaponize ONOS applications, primarily for the detection of Cross App Poisoning Attacks in Software Defined Networks. Notable features include the ability to compile and activate ONOS applications, as well as the generation of ONOS archive files for testing, ultimately contributing to the discovery of vulnerabilities such as CVE-2023-24279 and CVE-2023-30093. This tool is a part of a broader research initiative within the context of a Cybersecurity M.Sc. thesis.

offensive-claude

Offensive Claude is a spec-driven offensive security framework designed for Claude Code that implements structured engagement workflows following the Cyber Kill Chain methodology. It features a comprehensive set of 31 kill-chain skills, collaborative agents, and a shared vulnerability library, facilitating automated penetration testing, reconnaissance, exploit development, and reporting through a series of orchestrated commands. This tool is particularly useful for security researchers and practitioners to streamline their offensive security operations while maintaining high quality and traceability throughout the engagement process.

offensive-azure

Offensive Azure is a Python-based suite of tools designed for security assessments and penetration tests targeting Microsoft Azure environments. Key functionalities include token manipulation, user enumeration, and tenant reconnaissance, with features enabling users to extract and analyze data from Azure Active Directory, generate tokens for social engineering, and produce BloodHound-compatible outputs for further analysis. This versatile toolset is platform-agnostic and aims to simplify offensive security operations within Azure ecosystems.

nutcracker

Nutcracker is an Android application analysis tool designed for security researchers, enabling the download of apps directly from Google Play and facilitating static and dynamic analysis to detect and bypass anti-root protections. Notable features include extraction of hardcoded secrets, insecure manifest analysis, and comprehensive OSINT reconnaissance, all of which culminate in a detailed technical PDF report. The tool also integrates an LLM-powered false positive filter for enhanced accuracy in its findings.

Null-CLi

Null AI CLI is an open-source command-line interface designed for authorized penetration testing and compliance readiness assessments, providing a framework for safe reconnaissance, scanner orchestration, and evidence-backed findings. It offers efficient local assessments, supports OWASP Top 10 coverage, and produces Markdown/SARIF reports, allowing teams to quickly obtain valuable security feedback. Notable features include reusable model profiles, encrypted API key storage, and a guided home screen for streamlined user interactions.

NekoCLI

NekoCLI is a lightweight AI assistant for terminal environments that facilitates image and video generation, code creation, and command execution. It boasts features such as persistent chat history, a variety of operational modes including pentest capabilities, and visually formatted output. Designed for quick access and minimal dependency, NekoCLI allows users to handle media files and interact with an AI logic API for real-time assistance.

NAAMSE

NAAMSE is an automated security fuzzing framework designed to evaluate vulnerabilities in LLM-based agents using evolutionary algorithms. By generating adversarial prompts through intelligent mutations, it tests for security issues such as jailbreaks and prompt injections, employing a behavioral scoring engine and organizing attack vectors through a clustering engine. Key features include comprehensive reporting of vulnerabilities and metrics, making it an essential tool for red-teaming and enhancing the security posture of LLM agents before deployment.

Mythic-OSEP-CheatSheet

Mythic-OSEP-CheatSheet is a specialized resource designed to assist users in passing the Offensive Security Exploitation Expert (OSEP) exam using the Mythic Command and Control (C2) framework. The repository features a comprehensive collection of automated scripts and one-liner commands for various attack techniques and evasion strategies, enhancing the user’s ability to configure and utilize Mythic in a lab or exam environment. Notably, it includes automation for generating payloads tailored to dynamic VPN IPs, thereby streamlining the workflow for users facing constantly changing network configurations.

MSSprinkler

MSSprinkler is a PowerShell-based password spraying utility designed to test Microsoft Online accounts while minimizing the risk of account lockouts. It features a low-and-slow approach, configurable attempt thresholds, and the ability to gather verbose account and tenant information without triggering MFA prompts. Notably, it logs access and refresh tokens for successful sign-ins, enhances testing efficiency by detecting non-existent or locked-out accounts, and stores results in JSON and CSV formats.

Microsoft-SQL-TDS-Downgrade-Attack

The Microsoft SQL TDS Downgrade Attack tool performs a Man-in-the-Middle attack by intercepting Tabular Data Stream (TDS) packets between a client and MSSQL server, enabling the downgrading of encryption for TDS login packets. Its primary use case is to extract sensitive login credentials (username and password) by manipulating traffic through ARP spoofing and modifying intercepted packets. Notable features include automatic cleanup of the ARP spoofing and iptables rules upon stopping the script, and requirements for running include a Linux host with root privileges and necessary dependencies like arpspoof and iptables.

mcp-security-hub

MCP Security Hub provides a collection of production-ready, Dockerized Model Context Protocol (MCP) servers tailored for offensive security applications, enabling AI-assisted security assessments and vulnerability scanning. With 38 MCP servers covering various domains like reconnaissance, web security, and binary analysis, it integrates over 300 security tools accessible through natural language commands via AI clients like Claude. Noteworthy features include a CI/CD-ready setup with GitHub Actions, minimal Docker images, and orchestration capabilities with Docker Compose for streamlined multi-tool workflows.

MalwareAnalysis

The Malware Analysis repository serves as a comprehensive resource for the technical dissection of various malware strains, aimed at security professionals and researchers. It features in-depth analysis articles on notable malware such as AsyncRAT and SamSam Ransomware, as well as a collection of tools like Flare-VM, which is a pre-configured Windows-based virtual machine tailored for reverse engineering and malware analysis.

malware-apk

Malware APK is a testing and exploitation tool designed for security engineers and bug hunters to create malicious Proof of Concept (PoC) applications for vulnerability testing in Android environments. Notable features include a variety of testing modules for intent injection, task hijacking, and accessibility monitoring, without requiring device rooting. It also supports advanced options like caching intercepted intents and compiling native code for arbitrary code execution, making it a comprehensive utility for penetration testing.