> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

frieren

Frieren is a micro-framework designed for managing security tools on OpenWrt routers and Single Board Computers (SBCs). It features a web panel that facilitates WiFi management, network diagnostics, and an extensible module system, allowing users to install third-party modules while providing an integrated terminal and package management capabilities. The stack leverages a PHP backend and React frontend, ensuring both lightweight performance and flexibility for embedded devices.

entropia

Entropia is a high-level compiled language designed for generating Windows position-independent x86-64 shellcode and Beacon Object Files (BOFs) with a streamlined build process. Its primary use case is to simplify the development pipeline for red-team artifacts by combining multiple stages—from compilation to OPSEC enhancements—into a single step. Notable features include direct access to Windows SDK headers, enabling easy integration of native functions, and support for compiling complete BOFs in minimal code, while maintaining a compact and intuitive language syntax.

Donut-CustomHost

Donut-CustomHost is a sophisticated tool designed to generate and execute shellcode while maintaining stealth against modern endpoint detection and response (EDR) solutions. Key features include a custom CLR host that intercepts assembly loading directly from memory, advanced memory tracking evasion techniques, and architecture-aware event tracing for Windows (ETW) bypassing, all of which are aimed at minimizing detection during execution. Additionally, the tool has optimized the shellcode size, ensuring efficient memory use and a reduced footprint.

DLLHijackHunter

DLLHijackHunter is an automated detection tool designed for identifying, validating, and confirming DLL hijacking opportunities on Windows systems. It employs a multi-phase approach that includes discovery of exploitable binaries, filtration of false positives, and the deployment of a harmless canary DLL for verification, providing a comprehensive scoring and reporting mechanism. Notable features include extensive coverage of various hijack types, UAC bypass discovery, and a focus on corroborating potential attack paths with actionable intelligence.

dj-camphish

dj-camphish is a browser-based toolkit designed for ethical hacking, OSINT training, and privacy awareness demonstrations, allowing users to capture webcam snapshots with permission and redirect them to a custom URL. Key features include an intuitive admin panel for managing captures, secure CSRF protection, responsive design for mobile and desktop, and a straightforward setup process without the need for port forwarding.

Cyberlivre

Cyberlivre is an open-source platform aimed at democratizing cybersecurity education by providing a structured journey through 20 practical modules, covering topics from basic infrastructure to advanced defense and exploitation techniques. Notable features include no registration or paywalls, a community-driven approach to content updates, and opportunities for collaboration through curriculum enhancements, challenge creation, and code improvements.

CyberInject

CyberInject is a professional browser extension toolkit focused on authorized security testing and penetration testing activities. It offers quick access to a diverse range of security payloads categorized into vulnerabilities such as XSS, SQL Injection, SSRF, and LFI, alongside features like one-click copying and an organized, user-friendly interface. Designed for compliance with legal standards, it ensures that users can efficiently execute their testing tasks while promoting responsible usage.

cyber-agent

Cyber Agent is an AI-driven penetration testing tool utilizing Claude Code agents to automate the entire penetration testing process, making it particularly suitable for HackTheBox challenges and authorized security assessments. Notable features include automated attack execution which encompasses reconnaissance, exploitation, and privilege escalation, as well as professional report generation adhering to the Penetration Testing Execution Standard (PTES) and mapping to the MITRE ATT&CK framework.

CloudSec

The Cloud Security Toolkit is a comprehensive resource designed for offensive security practitioners focused on cloud environments, facilitating the exploitation of vulnerabilities and simulating advanced attacks specifically within platforms like Azure, AWS, and Microsoft 365. Notable features include a collection of weaponized exploits, deep-dive vulnerability research, threat intelligence insights, and evasion techniques targeted at cloud defense systems, all aimed at enhancing red team operations and improving cloud security assessments. This toolkit provides practical, battle-tested resources essential for sophisticated penetration testing and incident response in cloud ecosystems.

claude-security-skills

Claude Security Skills is a collection of tools designed to enhance the security analysis of software projects, specifically through the Claude Code platform. It enables users to perform various tasks such as scanning for leaked secrets, conducting static code analysis on Python, testing for prompt injection in language models, and auditing HTTP headers and security configurations. With no external dependencies and the ability to run analyses offline, the tool provides a secure and efficient approach to identifying vulnerabilities in various project components.

ckcsec-security-wiki

CKCsec Wiki is a bilingual cybersecurity knowledge base designed for security researchers, engineers, and enthusiasts, covering a variety of topics including web security, blockchain security, CTF, and red team practices. Built with VitePress, it features a fully mirrored structure in both English and Chinese, providing searchable and shareable practical security knowledge, while also supporting open collaboration and maintenance. The platform allows for easy deployment on static hosting services, ensuring accessibility and usability for diverse user needs.

ChromiumSpecter

ChromiumSpecter is a tactical auditing suite for security assessments of Chromium-based browsers (such as Chrome, Edge, and Brave) on Windows, focusing on credential extraction and data exfiltration. It features a highly discreet and resilient decryption engine that utilizes SYSTEM impersonation with legitimate Windows APIs, making it less detectable compared to traditional code injection methods. Key functionalities include a professional dashboard for real-time statistics, support for multiple encryption schemes, and seamless integration with the latest browser versions.

cheat-sheet

The Offensive Security & DevSecOps Cheat Sheet is an interactive command reference designed for penetration testing and DevSecOps practices, featuring over 5040 commands organized into 53 categories and available in both English and Turkish. Notable features include a fully local operation with no telemetry, a fuzzy command palette for efficient searching, and the ability to add and manage personalized commands and profiles. It also integrates with MITRE ATT&CK tags for over 1,160 offensive commands, providing contextual security mapping and enhancing the tool's functionality for security professionals.

catchclaw

CatchClaw v5.3.0 is a multi-platform AI Agent security assessment tool that supports nine different AI platforms including OpenClaw and Dify. It features 78 DAG attack chains and exploit modules that cover a full range of attack vectors from reconnaissance to data leakage, utilizing an asynchronous Tokio engine for concurrent execution while offering visual attack graph exports and customizable reporting options. The tool is designed to facilitate automated vulnerability verification and threat modeling within complex multi-agent environments, restricted to non-commercial use only.

c2detect

c2detect is a tool designed to fingerprint command-and-control (C2) servers behind network beacons by analyzing telemetry data, specifically naming frameworks like Cobalt Strike and Sliver with a confidence score and matched indicators. Notable features include offline operation, the ability to generate Sigma and Suricata detection rules directly from detected signatures, and the fusion of indicators such as JA4, JARM, certificate, URI, and port for enhanced C2 identification. This tool serves as a passive defense mechanism for blue teams to detect known C2 infrastructure efficiently.

Beatrix-suite

Beatrix Suite is a command-line bug bounty hunting framework designed to streamline the entire pentesting workflow by integrating 32 scanner modules and 22 external tools. It features a 7-phase Kill Chain methodology, automated login and session management, and an AI-assisted pentester (GHOST) for advanced analysis, making it suitable for scanning domains, URLs, and IP addresses efficiently in headless environments. This tool aims to eliminate the fragmentation of traditional bug bounty tools by providing a single-command interface that orchestrates multiple tools throughout the assessment process.

ashirt

ASHIRT is a Qt-based tray application designed for capturing screenshots and codeblocks associated with a specific ASHIRT instance. Its primary use case involves enabling users to take screenshots through a user-defined key or tray menu selection, while managing submissions to a remote ASHIRT backend. Notably, it supports multiple Linux distributions and provides flexibility for configuration and usage within various desktop environments.

arsenal-ng

arsenal-ng is a modern pentest command launcher developed in Go, designed to enhance the efficiency of security assessments by providing instant access to a vast library of tools and commands. Notable features include a smart search with fuzzy matching, syntax highlighting for improved command readability, an intuitive terminal user interface for easy navigation, and support for global variables that streamline command usage. This tool prioritizes simplicity and speed, making it a valuable asset for cybersecurity professionals.

Arsenal

ARS3NAL is a comprehensive, offline-first pentesting and bug bounty tool designed to streamline the security testing process. It features clickable attack chains, payload generators, recon tools, and built-in report templates, all organized in a user-friendly interface that supports bilingual operation. Noteworthy functionalities include the interactive OAuth/SSO lab and advanced recon capabilities, enabling quick assembly of complex attack scenarios without cloud reliance or telemetry.

ArachneC2

Arachne C2 is a decentralized Command & Control framework leveraging libp2p for peer-to-peer communication, eliminating reliance on a central server or fixed IP addresses. Its notable features include self-contained binaries for cross-platform implant generation, encrypted messaging, interactive operator consoles, and built-in NAT traversal techniques, all designed to maintain operational continuity and enhance resilience against detection and takedown. This framework is particularly suited for secure, covert operations requiring dynamic connectivity amid adversarial environments.

akira

Akira is an AI-powered penetration testing tool designed to operate natively within various environments, including Claude Code and Gemini CLI. It specializes in identifying vulnerabilities that traditional scanners may overlook, such as logic flaws and cryptographic weaknesses, by integrating a structured reasoning system that demands reproducible evidence for each finding. Notable features include a robust technique library, a Bayesian hypothesis engine, and the ability to handle complex attack vectors through a systematic engagement and reporting workflow.

AI-PT-Lab

Vulnerable AI Lab is a modular AI security training environment designed to simulate and expose vulnerabilities in modern AI applications, specifically targeting the OWASP LLM Top 10 2025 threats. It facilitates practical learning by allowing users to engage in scenarios like RAG injection and tool invocation vulnerabilities, scoring runs automatically to provide insights into exploited vulnerabilities and the evidence collected. Notable features include customizable vulnerability modules, an accessible user interface hosted via Docker, and compatibility with capture-the-flag events and red team training exercises.

AI-Pentest-Playbook

The AI Pentest Playbook provides a comprehensive field manual for conducting penetration testing on AI chatbots and applications powered by large language models (LLMs). It offers curated attack payloads categorized by various threat classes, detailed guidance on identifying vulnerabilities, and remediation strategies, thereby equipping both offensive and defensive cybersecurity teams with essential insights for securing AI systems. The resource also aligns with the OWASP Top 10 for LLM Applications, ensuring coverage of critical attack vectors and emerging risks in the domain.

ai_osint

AI OSINT is a comprehensive toolkit designed for identifying exposed artificial intelligence infrastructure on the internet through curated OSINT resources, including Google dorks, Shodan, and GitHub queries. It serves Red Team operators, penetration testers, and OSINT researchers by providing specific detection methods for various AI entities, such as LLM endpoints, AI agent gateways, and leaked API keys, while addressing emerging threats such as systemic supply chain vulnerabilities and credential leaks. Notable features include a keyword substitution convention to tailor searches to specific needs, enhancing its utility in real-world cybersecurity assessments.

AgentPoison

AgentPoison provides a framework for red-teaming large language model (LLM) agents through the technique of memory or knowledge base backdoor poisoning. Its primary use case is to facilitate the identification of vulnerabilities in LLMs by allowing users to optimize triggers targeting specific agent behaviors. Notable features include support for various retriever-augmented generation (RAG) embedders, configuration customization via YAML files, and trigger optimization capabilities for multiple agent types.