> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

tips-solidity-code-auditors

The "Tips for Solidity Code Auditors" repository provides a comprehensive collection of suggestions, tools, and resources specifically tailored for auditing Solidity smart contracts. It features general tips, links to various auditing tools and services, as well as curated resources to enhance the auditor's workflow and understanding of potential vulnerabilities. Notably, it encourages community input to continuously expand and refine the knowledge base for Solidity code analysis.

steam-osint

Steam OSINT is an open-source intelligence tool specifically designed for analyzing public Steam profile data. It facilitates the discovery of mutual friends, identifies hidden relationships, and retrieves historical account information like previous usernames and URLs, making it a valuable resource for OSINT researchers and cybersecurity professionals. Notable features include a command-line interface, cross-platform support, and capabilities for uncovering connections beyond the Steam platform.

SAMDump

SAMDump is a tool designed for extracting Windows Security Account Manager (SAM) and SYSTEM files utilizing the Volume Shadow Copy Service (VSS) with options for local saving or remote transfer, along with XOR obfuscation for enhanced security. It supports multiple programming languages including C++, C#, Crystal, Deno, and Python, and is capable of listing and creating shadow copies as needed, while automatically cleaning up after use. Noteworthy features include file operation via NT API calls, support for various exfiltration methods, and automatic XOR encoding to protect the extracted data.

Hacking-Cheatsheets

Hacking Cheatsheets is a comprehensive resource designed for penetration testing and ethical hacking, offering a collection of quick reference guides for various tools and methodologies. Notable features include clear explanations of tool functionalities, command syntax with practical examples, and a structured attack methodology following the MITRE ATT&CK framework. Additionally, it provides defensive security guides for SOC analysts, covering incident response and log analysis.

cc-tree

cc-tree is a Claude Code plugin designed to transform open-ended thinking tasks into structured phylogenetic trees for easier auditing and exploration. It features a universal radial-tree exploration engine with four distinct presets—divergent brainstorming, adversarial critique, design-space exploration, and code audit—utilizing a disciplined approach where every generated node includes detailed evidence for its derivation. The tool emphasizes substantive convergence over arbitrary thresholds, ensuring that only high-value findings are further explored and represented in the tree structure.

AutoPtT

AutoPtT is a cross-platform tool designed for enumerating Kerberos tickets and executing Pass-the-Ticket (PtT) attacks, offering a standalone alternative to popular tools like Rubeus and Mimikatz. It provides various functionalities such as automated ticket retrieval, session listing, ticket export, and explicit ticket import, enabling users to perform interactive or stepwise attacks efficiently. Notable features include a user-friendly command structure and support across multiple programming languages including C#, Python, and Rust.

AddUser-SAMR

AddUser-SAMR is a tool for creating local administrators via the SAMR API, providing a lower-level alternative to traditional commands like `net.exe` and PowerShell's `New-LocalUser`. It supports multiple programming languages including C#, Python, Rust, Crystal, and Deno, and offers features such as custom username and password input, group specification, and verbose output. The tool requires administrator privileges for operation and retains existing users in the group without updating passwords.

Kioskonomicon

Kioskonomicon is a comprehensive workshop resource designed for exploring and exploiting security vulnerabilities in public-facing kiosks, emphasizing the path from kiosk escape to Active Directory compromise. It features a structured "choose your adventure" format, allowing users to engage in DIY attacks, hard mode challenges, or follow guided exercises, all set within a specialized Active Directory lab environment. Notable elements include detailed scenarios for various kiosk types, a range of Active Directory attack methodologies, and supplementary resources for both hacking techniques and defensive measures.

brutecraber

BruteCraber is a high-performance hash cracking tool developed in Rust that utilizes GPU acceleration via OpenCL by default, with a seamless fallback to a multithreaded CPU backend when necessary. It supports a variety of hashing algorithms including MD5, SHA-1, SHA-256, and modern key derivation functions like Argon2 and Scrypt, along with automated hash type detection and a customizable rules engine for generating password variations. Its simplicity allows users to initiate cracking with a single command, eliminating the need for complex configurations.

Zombieland

Zombieland is a browser-based command and control (C2) dashboard frontend designed for educational and authorized penetration testing research. It features mock agent management with grid and list views, a global console for broadcasting commands, and a modular UI that supports customization and enhanced visual effects. The tool is currently in development for backend and agent components, aiming for cross-platform compatibility and improved user management in future releases.

WinGuard

WinGuard is a user-mode Windows threat detection tool designed to monitor and log suspicious activities on PCs, employing techniques inspired by Endpoint Detection and Response (EDR) frameworks. Its primary use case is for educational and experimental purposes, featuring advanced capabilities such as process and execution monitoring, file system analysis, persistence detection, and memory scans for malicious patterns, along with comprehensive logging functionalities. Notable features include the ability to analyze command line buffers for malicious intent, detect abnormal process behaviors, and whitelist benign applications to mitigate false positives.

urlvet

url.vet is an open-source phishing detection engine designed to analyze URLs and domains, providing users with a trust score, detailed verdicts, and comprehensive security reports in real time. Key features include instant live scanning using 18 concurrent analyzers and 33 individual signals, an explainable scoring system devoid of black-box machine learning, as well as integrations for a REST API, web UI, and a Chrome extension, making it a developer-friendly alternative to existing services like VirusTotal.

osv.net

OSV.NET is a .NET library designed to interact with the Open Source Vulnerabilities (OSV) API and schema, specifically supporting version 1.7.0. Its primary use case is to facilitate querying for vulnerabilities in open source packages, and it provides flexible integration options through manual instantiation or dependency injection, making it straightforward to incorporate into .NET applications. Notable features include asynchronous querying capabilities and customizable HTTP client settings for enhanced configurability.

Argo-Trivy-Insights

Argo Trivy Insights is a security extension for Argo CD that consolidates vulnerability and compliance data from Trivy scans directly within the Argo CD interface, allowing users to assess application security through a dedicated "Trivy Insights" tab. It features both per-application views and a cluster-wide dashboard, providing comprehensive scan reports, including vulnerabilities, exposed secrets, and configuration audits. The tool maintains low overhead by leveraging Argo CD's built-in React framework, enabling easy sharing of findings through exports in standard file formats.

aegis-vault

Aegis Vault is an offline password, identity, and secret management tool that operates solely on the user's local machine without requiring any server or cloud connectivity. It allows users to securely store various account types, including logins, API keys, SSH keys, and database credentials, all encrypted under a master password. Notable features include a modern web-based interface, a password generator, easy installation commands for multiple platforms, and robust security measures with no third-party dependencies.

tiktok-signature

The TikTok Signature Generator is a Python tool designed to create valid signatures for TikTok Web API requests, specifically **X-Gnarly**, **X-Bogus**, and **X-Dynosaur** signatures. It features support for SDK version 5.1.2 and employs advanced encryption and hashing algorithms, including ChaCha20 and RC4, to ensure secure and dynamic signature generation. This lightweight and production-ready implementation is tailored for developers seeking to interact with the TikTok API effectively.

retrore

RetroRE 6502 is a comprehensive repository of reverse-engineered and original source code for vintage games developed for platforms utilizing the 6502 CPU, such as the Acorn Electron, Apple II, and various arcade systems. Its primary use case is to serve as a resource for retro game developers and enthusiasts interested in game design and programming on historical systems. Notable features include the organization of games by platform and year, along with links to source code for both original and reverse-engineered projects, highlighting the state of their completeness.

MikuCffHelper

MikuCffHelper is a Binary Ninja plugin designed to deobfuscate binaries that utilize OLLVM-style control flow flattening (CFF). It employs static analysis techniques to identify dispatcher subgraphs and simulates state variables, offering two primary deobfuscation paths: a recommendation for the 'synthesize_switch' approach that preserves the dispatcher as a switch-case structure and an alternative 'deflate_hard' method that bypasses the dispatcher entirely. The tool significantly reduces High-Level Intermediate Language (HLIL) line counts, with half of the tested functions showing a decrease of 20-59% without losing any side effects.

MassAcre

MassAcre is a tool designed to exploit a zero-day vulnerability in the masscan banner scanning utility, causing it to enter an infinite loop and consume 100% CPU by sending a specially crafted TLS handshake record. Its primary use case is to demonstrate a remote, unauthenticated Denial of Service (DoS) attack that stalls the banner processing of masscan, leading to lost scan results. Notably, the attack is executed with a minimal payload and targets a specific flaw in masscan's certificate handling logic.

fallguys-frida-modmenu

The Fall Guys Mod Menu is an Android tool that utilizes Frida and frida-il2cpp-bridge to provide a suite of modifications for the game Fall Guys, enhancing gameplay with features such as teleportation, speed adjustments, and visual aids in rounds. Notable functionalities include the ability to bypass character physics checks, anti-AFK measures, and various movement enhancements like air jumps and 360 dives. This tool is intended solely for educational and research purposes, carrying risks of bans or game instability.

dearxan

`dearxan` is a library designed for static and runtime analysis/patching of the Arxan protection checks embedded in binaries, specifically targeting various FromSoftware games. Its primary use case is to fully neutralize Arxan's anti-debug and integrity checks, thereby allowing for unhindered gameplay and modding experiences. Notable features include a straightforward API for integration with Rust, C, and C++ applications, as well as best-effort support for DLL injectors that do not suspend processes upon creation.

Blackbird

Blackbird is a comprehensive real-time malware analysis platform designed for software reverse engineering and intrusion detection. Its primary use case involves performing detailed local analysis of malware through advanced features such as kernel capture, in-process telemetry, and flexible target execution workflows. Notable functionalities include memory behavior tracking, offline capture analysis, and a user-friendly interface that facilitates malware detonation and threat triage within a controlled virtual environment.

Zygisk-Loader

Zygisk-Loader is an ultra-lightweight Zygisk module developed in Pure C that facilitates the dynamic injection of external shared libraries into Android application processes. Its primary use case is to enable seamless and immediate updates of payloads without the need for device reboots, thanks to its "Hot-Swap" capability and robust memfd-based RAM injection, which ensures a zero forensic footprint. Key features include support for multiple target apps via a JSON configuration, no runtime dependencies, and compliance with the latest Zygisk API for enhanced compatibility with tools like Magisk.

revula

Revula is a production-grade MCP server designed for universal reverse engineering automation, facilitating connections between various compatible IDEs and custom tooling to an extensive reverse engineering backend through the Model Context Protocol. Its primary use case focuses on both static and dynamic analysis, featuring a robust suite of over 70 tools including binary parsing, disassembly, decompilation, and exploit development, alongside comprehensive support for Android reverse engineering and traffic interception capabilities. Additionally, Revula offers integration with numerous clients, enhanced debugging support, and a versatile configuration model, making it suitable for advanced security analysis and vulnerability research.

medc17-checksum-tool

The MEDC17 Checksum Tool is a specialized software designed to analyze and correct checksums for Bosch MED17 and EDC17 ECU firmware binaries, supporting CRC32, ADD32, and ADD16 algorithms. Notable features include automatic block detection, instant CRC32 solving via GF(2) matrix algebra, RSA signature forging, and calibration verification number (CVN) correction, all while ensuring safe operation by preserving original files. The tool is implemented in Python and offers both command-line and web-based usage options for convenience.