> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

Erebos-Zero

Erebos-Zero is a personal arsenal for malware development featuring sophisticated techniques for evasion and injection. It includes a variety of exploitation methods such as shellcode injection, DLL injection, and process manipulation, along with advanced anti-forensics and evasion techniques tailored for bypassing endpoint detection and response systems. This tool is primarily intended for research and educational purposes, focusing on the creation and deployment of stealthy malicious payloads.

EACBypass-CR3ReadyDrv

The EAC Bypass + CR3 Ready IOCTL tool is a specialized driver designed to facilitate undetected communication and callback handling through IOCTL, primarily aimed at circumventing anti-cheat mechanisms. It serves as a foundational framework, allowing users to control CR3 and IOCTL communication between driver and user mode, while leaving advanced functionalities, such as handle randomization and user mode hiding, to the user's discretion. Notable features include a basis for EPROCESS bypass and miscellaneous system manipulations, emphasizing the need for user customization to complete the implementation.

Duolingo-Unlimited-Hearts

Duolingo Max is a browser extension designed to modify the Duolingo website to provide unlimited hearts for users, thereby enhancing the learning experience without the limitations imposed by the platform. It supports both Chrome and Firefox, offering a straightforward installation process alongside a userscript option for mobile Safari, allowing for broad accessibility. Key features include access to specific domains for patching the Duolingo site, storage for user settings, and version synchronization capabilities for updates.

DEFCON-33

The DEFCON-33 repository provides insights and resources on exploiting vulnerabilities found in Tuoshi and Kuwfi 5G & LTE routers, detailing CVE discoveries and offering practical exploitation demonstrations. Its primary use case is to educate security professionals and researchers on the security weaknesses of these devices, while notable features include comprehensive vendor analysis and connections to related works in the field of cybersecurity.

darknet-mcp-server

Darknet-mcp-server is a comprehensive tool designed for aggregating dark web and threat intelligence specifically for AI agents. It consolidates data from multiple sources, including HIBP, ThreatFox, ransomware tracking, and blockchain intelligence, into a unified server that allows for on-demand access to a wide array of threat data. Notable features include support for .onion access, malware analysis capabilities, and an array of tools and data sources to streamline dark web intelligence gathering and analysis.

cyber_threat_intelligence

The Cyber Threat Intelligence tool provides comprehensive analysis of ongoing activities and research by advanced persistent threat (APT) actors, leveraging broad monitoring of exploit markets, social media, and vulnerability discussions. Its key features include geopolitical analysis, a wide array of indicators such as IOCs and TTPs, and predictive capabilities powered by an AI-based system to forecast potential attacks. This enables organizations to proactively prepare for and mitigate cybersecurity threats.

CVEs

The CVEs repository catalogs vulnerabilities reported by the author, each assigned a CVE identifier. It provides detailed write-ups and proof-of-concept (PoC) exploits for various software vulnerabilities, facilitating research and reproduction. Noteworthy features include the inclusion of vulnerable software copies in certain folders for in-depth analysis.

CVE-Intel

CVE-Intel is a vulnerability intelligence platform that aggregates and correlates data from GitHub CVE-tagged repositories, the National Vulnerability Database (NVD), and cybersecurity news feeds. It is aimed at security researchers, blue teams, and integrators, providing a public API and frontend to access and analyze enriched CVE information. Notable features include a robust data ingestion pipeline, real-time news updates, and an interface for querying vulnerability details with pagination and filtering capabilities.

CVE-2026-PoCs

CVE-2026-PoCs is a curated repository providing a centralized collection of verified proof-of-concept exploits for vulnerabilities disclosed in the year 2026. Its primary use case is to serve security researchers and practitioners by offering a well-organized index of CVEs, complete with consistent metadata and a clear contribution process. Notable features include detailed listings of specific CVEs, affected products, and statuses of exploits, addressing the common issue of fragmented information across various platforms.

CVE-2026-57827

CVE-2026-57827 is a high-severity vulnerability within the RSFiles! component for Joomla, allowing unauthenticated arbitrary file uploads due to a split-controller design flaw. The vulnerability permits attackers to bypass critical security checks and directly write malicious files to the server, resulting in remote code execution without any authentication or CSRF protections. Notably, the exploit allows attackers to upload any file type and store it in a default web-accessible directory, significantly compromising the security of affected Joomla installations.

CVE-2026-48909

The CVE-2026-48909 tool identifies and exploits a critical Remote Code Execution vulnerability via PHP Object Injection in the JoomShaper SP LMS extension for Joomla versions ≤ 4.1.3. Notable features include a proof of concept script for detecting the vulnerability and an exploit script that allows an attacker to write PHP code to the server, requiring no authentication. The tool also details the underlying mechanics of the vulnerability and provides mitigation advice for affected systems.

CVE-2026-24061

CVE-2026-24061-PoC is a proof-of-concept tool designed to demonstrate the exploitation of a critical vulnerability in telnetd from GNU Inetutils, enabling remote attackers to bypass authentication and achieve root access. This tool requires Python 3.4+ and can target hosts by specifying an address through a text file or command line interface. It exploits improper handling of the USER environment variable, injecting command-line options to gain unauthorized access.

CVE-2025-32463

CVE-2025-32463 is a Go-based exploit tool designed to exploit a critical local privilege escalation vulnerability in sudo versions 1.9.14 to 1.9.17. The tool manipulates the `--chroot` option to load a malicious shared library, allowing unauthorized users to gain root access. Notable features include the ability to run the exploit in both normal and silent modes, and it supports building from source or using a pre-built binary.

CVE-2023-32315-EXPLOIT

CVE-2023-32315-EXPLOIT is a proof-of-concept tool designed to exploit a severe authentication bypass vulnerability in the Openfire real-time collaboration server's administrative console. It demonstrates how an attacker can leverage a path traversal flaw coupled with improper URL encoding handling to gain unauthorized access to admin-only pages. Notably, the exploit addresses a critical security issue affecting Openfire versions released after April 2015, specifically exploiting weaknesses in URL wildcards and path traversal protections.

CVE-2022-26265

CVE-2022-26265 is a Python-based tool designed to exploit a Remote Code Execution vulnerability in Contao CMS version 1.5.0. Users can specify target servers from a list file and execute arbitrary commands, making it useful for security assessments and penetration testing of affected installations. Notable features include the ability to handle multiple targets and customizable command execution through a straightforward command-line interface.

CVE-2022-23093

CVE-2022-23093 is a cybersecurity tool designed to exploit a stack-based buffer overflow vulnerability in the FreeBSD ping utility, which results from improper handling of IP option headers during ICMP response processing. Its primary use case is to demonstrate the ability to execute arbitrary shellcode through crafted ICMP packets that trigger the overflow. Notable features include the ability to customize the shellcode as well as the detailed technical analysis of the vulnerability's mechanics and its impact on system integrity.

Cryptolocker

Cryptolocker is an open-source encryption tool developed in Visual C++ that employs a robust 256-bit AES encryption algorithm to secure files, rendering them unreadable without a password. Its primary use case involves encrypting files across system drives while providing features such as a multi-threaded encryption process for efficiency, lockdown functionality to restrict system access, and a web admin interface for management. This tool is intended solely for educational purposes and emphasizes user responsibility regarding legal usage.

CR4SH3R

CR4SH3R is a vulnerability scanner specifically engineered to identify Arbitrary File Download flaws in WordPress plugins by scanning for sensitive data exposure through common file paths. It features multi-threaded scanning for efficiency, smart data extraction capabilities, and provides organized reports in XLSX format, all presented through a user-friendly GUI. Notably, the tool allows users to extend its payloads for enhanced detection and supports customized scanning configurations.

copy-fail-c

Copy Fail is a cross-platform implementation in C of the Copy Fail Linux Local Privilege Escalation (LPE) exploit (CVE-2026-31431), designed to demonstrate the vulnerability on various architectures without relying on per-architecture hex blobs or inline assembly. The tool includes multiple variants for payload delivery, such as a binary-mutation dropper and a variant that modifies the `/etc/passwd` file, as well as a non-destructive vulnerability checker. It requires no additional libraries and supports extensive architecture compatibility through the included nolibc.

camera-hacks

This repository provides a suite of custom tools and research materials focused on vulnerability assessment of Wansview Wi-Fi cameras and the AJCloud IoT device management platform. The primary use case is to facilitate security research and exploit development for these devices. Notable features include collected data, research notes, and insights shared from presentations at DEF CON 32.

camera-hack

camera-hack is a tool designed for gaining control over Yoosee/Jortan IP cameras using a UART serial connection facilitated by an Arduino device. The primary use case involves leveraging the tool to access and manage camera features via Telnet after establishing a connection. Notable features include straightforward setup instructions, compatibility with multiple operating systems, and community support for troubleshooting and contributions.

bypass-url-parser

Bypass Url Parser is a specialized tool designed to test various URL bypass techniques against 40X protected pages, utilizing `curl` as its backend for raw request handling. It allows users to send unencoded URLs and includes features such as custom header support, proxy integration, and configurable output options, making it suitable for security assessments and web application testing. The tool can be used as a standalone application or integrated as a library, providing flexibility for different user needs.

BUSted

BUSted is a repository designed for conducting microarchitectural side-channel attacks on MCU bus interconnects, specifically targeting the Smart Lock application as a proof of concept. It consolidates tools and scripts for measuring covert-channel capacities, along with the firmware and hardware configurations necessary for replicating the attack on STM32 devices. Notable features include a script for automated measurement of channel capacity and tools for visualizing the channel matrix.

BrowserSnatch

BrowserSnatch is an offensive-security tool designed for authorized penetration testing that extracts and decrypts sensitive data from over 40 web browsers, including both Chromium and Gecko-based platforms. Notable features include the ability to retrieve stored passwords, cookies, bookmarks, and browsing history, as well as support for app-bound encrypted data, all optimized for high performance with minimal dependencies. The tool serves red teams in demonstrating the impact of endpoint compromise and aids blue teams in improving detection tactics against browser data theft.

bluesploit

BlueSploit is a comprehensive Bluetooth framework targeting both Classic BR/EDR and BLE communication, featuring 160 modules for various purposes including exploits, denial of service, and reconnaissance. Its notable capabilities include persistent state storage, advanced scanning for Bluetooth devices and key exchange mechanisms, as well as support for AES-128 cryptography and mesh networking protocols. The tool is designed for authorized testing and enables users to engage interactively through a REPL interface, managing attacks and reconnaissance tasks efficiently.