> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

oxide-communityedition-v8.6.9

OXIDE is a precision-forged Rust-based vulnerability scanner designed for offensive security applications, particularly penetration testing and security research. Key features include an async concurrent architecture, a WAF evasion suite, an AI/ML-driven zero-day detection engine, and a modular framework with 14 detection modules. This tool is optimized for Kali Linux and emphasizes responsible use, strictly prohibiting unauthorized access or malicious applications.

opentaint

OpenTaint is an open-source taint analysis engine designed for application security, effectively identifying vulnerabilities that abstract syntax tree (AST) pattern matchers may overlook. Its primary use case involves enhancing security measures for applications, particularly those built with technologies like Java, Kotlin, and Spring, by allowing large language model (LLM) agents to execute vulnerability rules while offering scalable performance. Notable features include formal taint analysis capabilities and extensive integration support for various programming languages and platforms.

Offsec-Practice-Labs

The Offsec-Practice-Labs repository provides a comprehensive collection of virtual machines, notes, and resources specifically designed for individuals preparing for the eCPPT, OSCP, and CPTS cybersecurity certifications. It includes various platforms like VulnHub and HackTheBox, featuring machines categorized by skill sets essential for penetration testing, with an emphasis on vulnerability exploitation and practical learning through self-hosted labs. Key features include categorization of labs by difficulty and focus areas, making it a valuable resource for targeted skill development in offensive security.

nagooglesearch

Nagooglesearch is a Python library designed to facilitate web searches without relying on Google's direct API, making it suitable for educational and testing purposes. It allows users to customize search parameters, manage user agents, and configure cookies while ensuring the return of unique, relevant URLs that do not contain the keyword "google." Notable features include adjustable sleep intervals between requests to prevent rate limiting, the ability to specify custom user agents, and support for proxy connections.

mantishack

Mantishack is an autonomous vulnerability-discovery agent designed for ethically hacking and identifying software vulnerabilities through a comprehensive, AI-driven pipeline. It integrates multiple scanning capabilities, including static analysis and attacker-simulation validation, to ensure precise identification of exploitable flaws while explicitly tracking the status of findings. Notably, it operates with a focus on real validation over traditional detection, utilizing a modular architecture that can integrate various security tools as needed.

local-vuln-research-pipeline

LVRP (Local Vuln Research Pipeline) is an exhaustive LLM-driven vulnerability research tool designed to identify vulnerabilities across various source code files in up to 16 programming languages. It constructs a complete call graph of the codebase, enumerates all source-to-sink paths, and validates these paths for exploitability using a hybrid approach that combines static analysis and LLM insights. The tool is capable of analyzing extensive projects such as the Linux Kernel and VSCode, while ensuring deterministic path enumeration and comprehensive coverage, including blind spot reviews.

knary

knary is a canary token server designed to alert users via messaging platforms like Slack, Discord, and Teams when specific HTTP(S) or DNS requests are made to designated domains. Its primary use case is to enhance offensive security by notifying teams of interactions with their controlled servers, thereby revealing potential vulnerabilities and providing insights into unauthorized access attempts. Notable features include subdomain allow/denylisting, integration with Burp Collaborator, and automatic TLS certificate management through Let's Encrypt.

khaos-c2

KHAØS C2 is a sophisticated post-exploitation command and control framework designed for stealth and evasion against endpoint detection systems. It features five covert communication channels, including Microsoft Teams and GitHub Gist, ensuring that the traffic blends with normal operations. The framework includes extensive post-exploitation capabilities, such as token theft, process injection, and lateral movement, along with a user-friendly React-based UI for real-time monitoring and payload management.

kentra

Kentra is a Kubernetes-based offensive security framework designed for orchestrating penetration testing, red teaming operations, and large-scale security scans, both within and outside Kubernetes clusters. It allows users to define security tests as declarative YAML manifests, automating orchestration, scheduling, and logging through its native Kubernetes resources. Notable features include integration with Helm for deployment, a customizable dashboard for command output aggregation, and the use of a ConfigMap to manage tool specifications.

i-Detector

i-Detector is an educational tool designed for simulating Instagram login and two-factor authentication (2FA) mechanisms, aimed at ethical hacking and cybersecurity training. It includes a simple fake login page that collects user credentials via a data management script, which runs on various platforms including Windows, Linux, and Android. The tool is intended for practical learning experiences in social engineering techniques and is continuously updated with features in its main project repository.

HaleHound-CYD

HaleHound™-CYD is a multi-protocol offensive security toolkit designed for the ESP32 Cheap Yellow Display, featuring over 40 attack modules focused on WiFi, Bluetooth, SubGHz, 2.4GHz, and NFC communications. This toolkit is designed for ease of use, allowing users to flash configurations directly from their browser without installation, and it supports various display sizes while incorporating external modules for enhanced functionality. Notable features include touch-driven controls and the capability to transmit at maximum power, facilitating a range of offensive security activities.

goshs

goshs is a versatile, single-binary file server designed for file transfer and capture tasks during penetration testing engagements. It supports multiple protocols including HTTP/S, WebDAV, FTP/SFTP, SMB, and LDAP, and offers features such as hash capturing, basic authentication, self-destructing payloads, and a TUI for interactive operations. Notable functionalities include token-based link sharing, DNS and SMTP server capabilities, and advanced collaboration tools for CTF scenarios.

frameseven

frameseven is a CLI-oriented offensive web security scanner designed for authorized security testing, capable of mapping a target's attack surface while executing active checks for prevalent web vulnerabilities and misconfigurations. Key features include extensive reconnaissance capabilities, support for authenticated scans, and structured reporting options, along with a dedicated MCP server for AI agents to utilize the same framework tooling. The tool emphasizes a standard-library-centric Go codebase, enhancing readability and extendability.

cybersec-projects

The Cyber Security Projects repository encompasses a collection of hands-on projects tailored for learning and experimentation in cybersecurity. It includes offensive and defensive tools, automation scripts, and real-world simulations, designed to enhance ethical hacking skills and practical security research. Notable features include a diverse set of project categories ranging from reconnaissance and web application security to network attacks and malware analysis.

CyberChef-MCP

CyberChef MCP Server provides an interface for the Model Context Protocol (MCP) to utilize CyberChef's extensive library of 463 data manipulation operations, facilitating seamless integration with AI assistants for tasks such as encryption, encoding, and forensic analysis. Notable features include the ability to execute complex multi-step transformations with the `cyberchef_bake` tool, recipe management for saving and reusing workflows, and advanced enterprise capabilities like batch processing and telemetry analytics. This tool effectively bridges natural language AI intent with deterministic data processing capabilities.

csprecon

csprecon is a reconnaissance tool designed to discover new target domains by leveraging Content Security Policy (CSP) data. Its primary use case is for security professionals conducting reconnaissance in order to identify potential attack surfaces across multiple domains, with features such as concurrent requests, domain filtering, output options in JSON format, and the ability to handle CIDR input. The tool can also be configured for rate limiting and proxy usage, making it versatile for various operational environments.

bjorn-detector

Bjorn Detector is a Python tool designed for detecting the Bjorn device on a local network, displaying its IP address, and facilitating the initiation of an SSH session with a single click on the Bjorn icon. Key features include continuous network detection, an interactive SSH launcher, and seamless installation support for the Bjorn device. It requires Python 3.9+ and utilizes a PyQt6 interface to enhance user interaction.

AISecurity

The AISecurity tool, now archived, was part of the Syntrex project, which has since evolved into the Syntrex AI SOC platform. Its primary use case involved providing an open-source core through GoMCP with support for the MCP protocol. Notable features included modular architecture and compliance with the Apache 2.0 License.

XWormRCE

XWorm RCE is a proof of concept tool that demonstrates a zero-click vulnerability within the XWorm plugin for RDP connections. It exploits a flaw where the server fails to validate client responses, allowing an attacker to execute commands on the victim's machine without user interaction. Notable features include the ability to exploit the vulnerability without initiating a connection command, showcasing its potential for remote code execution.

WSUS-CVE-2025-59287-RCE

WSUS-CVE-2025-59287-RCE is a proof-of-concept exploitation tool for a critical remote code execution vulnerability (CVE-2025-59287) in Microsoft Windows Server Update Services. The tool automates the generation and transmission of a malicious payload that exploits insecure deserialization in the WSUS GetCookie() endpoint, enabling unauthorized execution of arbitrary code with system privileges. Key features include payload generation, AES encryption, and SOAP request construction, facilitating a straightforward reverse shell setup through user input for target and listener configurations.

wpctf2025

The WP CTF 2025 repository offers a collection of cybersecurity challenges created for the WP Capture the Flag event, aimed at enhancing skills among young cybersecurity enthusiasts. It features a diverse range of challenges across multiple categories such as Crypto, OSINT, PWN, and Reversing, with varying difficulty levels, and includes source code, solutions, and walkthroughs for each challenge. Notable features include the ability to exploit vulnerabilities, reverse engineer to understand systems, and perform forensic analysis, making it a comprehensive resource for hands-on learning in cybersecurity.

WaSonar

WaSonar is a command-line interface tool designed for educational research and security assessments focused on the WhatsApp protocol. It facilitates real-time device tracking, device discovery, and profile extraction from linked devices, while also offering a resource exhaustion feature that can stress test the target by sending oversized payloads. Notably, WaSonar employs silent probes to determine online status without alerting the user and allows users to initiate rapid, high-frequency message deliveries to gauge system resilience.

vulnerability

The 'vulnerability' tool catalogs known vulnerabilities for various software, with a current focus on Microsoft Internet Explorer and Apple OSX, listing specific Common Vulnerabilities and Exposures (CVEs) associated with each platform. The primary use case is to provide a reference for security professionals looking to understand and track reported vulnerabilities. Notable features include the organization of vulnerabilities by vendor and product, enabling easier identification of security concerns.

valthrun-cs2

Valthrun an open source external CS2 read only kernel gameplay enhancer.