> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

ashirt-deployments

ashirt-deployments is a Terraform configuration repository designed to facilitate serverless deployments of the ASHIRT application on AWS (ECS Fargate) and GCP (Cloud Run). It provides opinionated templates for affordable, semi-fault tolerant environments tailored for small teams, with features including managed SQL servers, encrypted storage, and the absence of blue/green deployments. The repository is currently under construction, with the GCP version ready for testing and the AWS configuration forthcoming.

android-penetration-testing-cheat-sheet

The Android Penetration Testing Cheat Sheet is a comprehensive reference guide aimed at security professionals conducting penetration tests on Android applications. It provides a structured checklist of tools, techniques, and methodologies optimized for use in a Kali Linux environment, highlighting critical tasks such as APK inspection, vulnerability exploitation, and various Android security configurations. Notable features include integration of resources from OWASP, practical tips for creating proof-of-concept apps, and a focus on common vulnerabilities and mitigation strategies for Android apps.

AIRTBench-Code

AIRTBench is an autonomous AI red teaming agent designed to evaluate the adversarial capabilities of large language models (LLMs) through AI/ML Capture The Flag (CTF) challenges. It systematically targets LLM-based systems to exploit vulnerabilities, providing a standardized benchmark for measuring their performance in red teaming scenarios. Notable features include a modular architecture for extensibility, integration with the Dreadnode Strikes platform, and comprehensive documentation for setup and usage.

AIHound

AIHound is an AI credential and secrets scanner designed to identify exposed API keys, OAuth tokens, and other sensitive credentials across 29 AI tools on multiple platforms, including Windows, macOS, and Linux. It features a robust watch mode for continuous monitoring and real-time alerts on credential changes, alongside integration capabilities with BloodHound for visualizing attack paths and conducting security analysis. The tool promotes safe reporting by redacting credentials by default, making it a crucial asset for security assessments in environments utilizing AI technologies.

zerdecalistops

Zerdecalistops is an optimized wordlist collection designed for cybersecurity researchers and penetration testers, tailored by Zencefil Efendi and enhanced with a dashboard interface. Its primary use case is to provide comprehensive and up-to-date datasets—including usernames, passwords, and fuzzing payloads—essential for cybersecurity operations. Notable features include its extensive compilation of resources and user-friendly dashboard for easy access.

yublueflower

yublueflower is a security workflow designed to identify real-world threats by integrating multiple open-source tools, such as urlfinder, katana, and nuclei, to analyze web assets and vulnerabilities. It supports functionalities like session management, web archiving, and extended workflows for optimizing bug bounty results, while mapping findings to known vulnerabilities (CWE/CVE). This tool specifically operates within a Kali Linux environment and is ideal for penetration testers and security professionals looking to enhance their threat discovery processes.

XMT

XMT (eXtensible Malware Toolkit) is a versatile command and control (C2) framework written in Golang, designed for malware analysis and control functions, including data exfiltration. It features advanced process control for Windows, efficient networking resources, and compatibility with older Windows systems, while maintaining a minimal file size of approximately 5MB. Additionally, XMT supports various utility functionalities and aims for continuous enhancements, making it suitable for researchers and security professionals exploring cybersecurity threats.

x64dbg

x64dbg is an open-source binary debugger designed specifically for Windows, facilitating malware analysis and reverse engineering of executables without source code access. Key features include a comprehensive plugin system for extensibility, support for both 32-bit and 64-bit debugging, and a user-friendly interface that offers various tools such as memory mapping and graph visualization to enhance the debugging process.

WindowsShell-Injector-Shellcode-Loader

WindowsShell-Injector is a shellcode execution framework designed for security research and penetration testing on Windows systems. It features encrypted payloads, anti-debugging mechanisms, and an intuitive Qt-based GUI, allowing for seamless loading and execution of shellcode. Notable capabilities include asynchronous execution via separate threads, dynamic memory protection, and runtime API resolution to enhance evasion of static analysis tools.

wafrift

WafRift is a programmable WAF-evasion engine designed to test and bypass web application firewalls by generating and exploiting payload mutations through various encoding and grammar strategies. Its primary use case is for security researchers and penetration testers seeking to identify WAF vulnerabilities, featuring automated scanning, detailed response classification, and an integrated discovery tool for API endpoints. Notable features include customizable evasion strategies, session management, multi-signal response analysis, and comprehensive WAF fingerprinting capabilities.

vulnify

Vulnify is a CVE ingestion and enrichment pipeline that consolidates vulnerability data from various sources into a normalized SQLite database, facilitating easier access and exploration of this information. Its notable features include a comprehensive CVE repository, integration with various vulnerability databases, and a Streamlit-based explorer that provides approximately 70 pre-built views for data analysis. The tool also supports resume-safe pipeline states, enabling seamless data ingestion even after interruptions.

venom

Venom is a comprehensive collection of tools, resources, and documentation focused on information security, penetration testing, and offensive cybersecurity. Its primary use case is to serve as a centralized repository for cybersecurity professionals seeking various utilities, from analysis and network reconnaissance to incident response and exploit development. Notable features include organized sections for different types of tools, such as anti-virus evasion, cloud security, and forensics, facilitating easy access to resources tailored for various cybersecurity needs.

vbsmin

VBSmin is a VBScript minifier designed to optimize script files by removing unnecessary whitespace and comments, thus reducing overall file size. Its primary use case includes enhancing efficiency in scenarios like SQL injection and cross-site scripting, where compact scripts are essential for stealth and execution speed. Notable features include the ability to condense multi-line scripts into a single line and eliminate various types of whitespace and comments, making it a valuable tool for developers working with VBScript in the context of security exploitation.

unk9vvn.github.io

The Tools Installer facilitates the streamlined installation of various cybersecurity tools on Kali Linux and Ubuntu operating systems. Key features include automatic script updates, the capability to install individual tool sections, and a user-friendly menu and icon design for enhanced accessibility. This tool is ideal for cybersecurity professionals seeking quick and efficient setup of essential tools in their environments.

ThunderStorm

ThunderStorm is a comprehensive Command and Control (C2) solution developed in Golang, designed to facilitate the management and deployment of software implants known as Bolts across various platforms. Key features include Cirrus, a ReST API for task management and real-time updates; JetStream, a Bolt builder that supports multiple formats and obfuscation; and Doppler, a user-friendly Python CLI for interacting with Cirrus and managing multiple implants efficiently. This tool aims to enhance operational capabilities while providing robust flexibility for cyber operations.

TeleStrike

TeleStrike is a red team utility for simulating penetration tests and conducting security audits on Telegram accounts, designed solely for authorized assessments and educational purposes. Its notable features include two-factor authentication enumeration, session hijacking simulations, automated social engineering flows, and customizable modules for various attack vectors. The toolkit serves to evaluate the resilience of Telegram's authentication mechanisms against real-world attack scenarios.

T3MP3ST

T3MP3ST is a multi-agent offensive security framework designed to leverage existing AI coding agents for automated zero-day hunting. It facilitates a complete kill chain from reconnaissance to exploitation and reporting, using powerful models that can operate offline without the need for API keys. Notable features include reproducibility of results through a verification command, a keyless operational model, and transparency regarding the tool's capabilities and current features.

strix

Strix is an open-source AI-powered penetration testing tool designed to autonomously identify and remediate vulnerabilities in applications. It provides a comprehensive pentesting toolkit including real exploit validation, multi-agent orchestration for scalability, and integration with CI/CD pipelines for continuous security checks. Key features include actionable findings with remediation guidance, auto-fixing capabilities, and the generation of compliance-ready reports, significantly accelerating the security testing process compared to traditional methods.

SpyIt

SpyIt is a real-time desktop surveillance tool designed for educational and research purposes, utilizing DXGI Desktop Duplication to capture and stream screen content over HTTP as MJPEG. It offers low-overhead operation, system audio streaming, and a user-friendly HTML viewer with multi-monitor support, making it suitable for red team operations and integration with AdaptixC2 for streamlined deployment and control. Key features include dynamic port assignment, background execution, and extensive audio device handling.

secfiles

Secfiles is a repository that provides a collection of useful files designed for penetration testing, security assessments, and bug bounty hunting. Its primary use case is to facilitate security-related tasks by offering easily accessible resources and scripts. Notable features include a straightforward cloning process and comprehensive release notes for version tracking.

rango

Rango is a basic C2 agent developed in Zig for GNU/Linux systems, primarily serving as a proof of concept for utilizing Zig in command and control applications. Notable features include basic command execution capabilities, a straightforward codebase without external dependencies, and recent support for Windows targets mirroring its Linux functionality. The tool is still in development, with additional features such as file upload/download and BOF support planned for the future.

project-scorpio

Project Scorpio is a sophisticated Windows process injection loader that utilizes techniques such as PPID spoofing, manual DLL mapping, and direct NT syscall execution to stealthily execute staged shellcode within a targeted remote process. Notable features include its ability to fetch payloads from a command and control server using HTTP, spawn a decoy process with a masqueraded parent process, and replace the text section of a mapped DLL without registering it in system tools, thereby minimizing detection risk.

probeagent

ProbeAgent is a command-line tool designed for offensive security testing of AI agents, performing automated red-team attacks such as prompt injection and credential exfiltration against any HTTP-accessible agent. Notable features include a detailed attack grading system that categorizes responses as Compromised, Resisted, or Blocked, allowing users to evaluate the effectiveness of their security controls, and advanced guardrail detection to distinguish between model defenses and actual security mechanisms.

pentestcode

PentestCode is an AI-driven penetration testing agent that operates directly in the terminal, enabling users to conduct comprehensive security assessments with minimal input. It features a multi-agent architecture that autonomously scans, enumerates, attacks, and exploits vulnerabilities within a defined target, while systematically tracking engagement state and allowing real-time querying of findings. Supporting over 20 large language model providers, PentestCode streamlines the offensive security process and facilitates detailed reporting with evidence of each engagement step.

Pentest-Swarm-AI

Pentest Swarm AI is an open-source penetration testing tool that leverages a swarm architecture for coordinated multi-agent operations, enabling efficient vulnerability assessment. Its primary use case is facilitating authorized security testing through live integration with popular offensive tools like nmap, sqlmap, and Metasploit, while incorporating AI models for advanced analysis. Notable features include a stigmergic blackboard for agent coordination, automated evidence capture, and the ability to generate submission-ready reports.