15 Aug 2026
Python
★ 10
The VSphereRansomwareRecovery tool provides a recovery solution for virtual machines affected by Babuk-family ransomware on ESXi hosts. It facilitates the restoration of virtual disks ending in `.babyk` through partition table rebuilding and file system recovery, ensuring minimal data loss in the process. Notable features include the capability to leverage AI agents for automated recovery steps and the assurance of recovering readable data from the majority of affected disk space.
15 Aug 2026
★ 237
The Malware Analysis tool focuses on dissecting and evaluating the risk associated with PDF-based malware (maldoc). It provides an in-depth exploration of PDF structures, including headers and encoding techniques, making it a valuable resource for security researchers aiming to understand and analyze malicious code embedded within PDFs. Notable features include detailed explanations of malware behaviors, obfuscation techniques, and how to identify command and control (C&C) mechanisms within PDF binaries.
15 Aug 2026
Python
★ 66
Packing Box is a Docker container that offers a command-line interface (CLI) environment designed for the static detection of executable packing. It integrates various executable analyzers, packing detectors, and tools for generating datasets, specifically tailored for evaluating detection techniques and automating machine learning pipelines involving packed and unpacked executables across different formats such as PE, ELF, and Mach-O. The toolkit features a user-friendly YAML configuration system, enabling straightforward customization for research evaluations and model training.
15 Aug 2026
Go
★ 55
_rlapi_ is a Go SDK that provides access to Rocket League's internal APIs through a reverse-engineered framework, enabling functionalities like authentication, item shop access, player stats retrieval, and match history. It includes capabilities for traffic interception using Frida for dynamic instrumentation and features a MITM proxy to log API requests and responses while managing authentication tokens. The library allows developers to manipulate network traffic and reconstruct HTTP and WebSocket requests, although not all API endpoints are fully documented.
15 Aug 2026
JavaScript
★ 49
Fingerprint Pro Internals is a deobfuscated and documented version of the Fingerprint Pro v4 library, providing detailed insights into its 143 defined signal collectors, signal map, and wire format operations. The tool allows developers to analyze and run collectors independently without a network, enabling the examination of the library's inner workings in a browser environment. Notable features include a comprehensive signal map, individual collector source files, and the ability to explore the wire format from JSON to bytes in an organized manner.
15 Aug 2026
C++
★ 35
DeMuxUSB is a C++20 tool suite designed for capturing, demultiplexing, and analyzing USB sessions involving Apple iDevices, focusing particularly on reverse engineering recovery and restore protocols. It enables forensic analysis by allowing users to examine device restores against known baselines to identify deviations or unauthorized modifications, with features such as detailed USB transaction tracking, protocol demultiplexing, and support for various input capture formats like PCAPNG. Noteworthy capabilities also include reconstructing USB device states and extracting TCP streams and plist data, making it a valuable resource for cybersecurity analysis and digital forensics in the Apple ecosystem.
15 Aug 2026
JavaScript
★ 373
Frida Script Runner is a web-based toolkit designed for comprehensive Android and iOS penetration testing and mobile application security analysis. It streamlines interactions with Frida through a user-friendly Flask interface and supports advanced functionalities such as AI-powered script generation, real-time output, and automated analysis with integration for Ghidra and JADX. Notable features include APK/IPA dumping, SSL detection, multi-device monitoring, and an extensive set of tools for script management and execution.
15 Aug 2026
PowerShell
★ 94
dsh-reverse-skill is a comprehensive DeepSeek Harness (dsh) plugin that encapsulates 85 skills from the upstream reverse-skill repository, providing seamless integration into the dsh environment without manual maintenance of skill lists. The tool automatically registers a complete library of skills upon startup, includes both domain and CTF-oriented skills, and offers a straightforward installation process via GitHub or configuration files. It is specifically designed for authorized reverse engineering, penetration testing, and security research.
15 Aug 2026
C++
★ 156
Dll Proxy Generator is a tool designed to create a proxy DLL that intercepts calls between a game and its original DLL, allowing for the inspection and modification of DLL interactions. Its primary use case is for game developers and researchers seeking to debug or enhance game functionality through DLL manipulation. Notable features include the automatic generation of proxy DLL source code and the capability to handle specific public Windows DLLs effectively, although some limitations exist with game-specific DLLs that have mangled function names.
15 Aug 2026
CSS
★ 83
Awesome Touhou is a comprehensive resource hub for the Touhou Project, a bullet hell shoot 'em up game series by ZUN, facilitating access to official resources, game tools, and community-driven enhancements. It features categories for tools related to game launching, input configuration, patching, and modding, along with gameplay tools for scoring and replays, making it an essential platform for both newcomers and seasoned players in the Touhou gaming community. Notable offerings include compatibility tools for various operating systems and community patches that enhance the gameplay experience.
15 Aug 2026
Python
★ 19
WMN-Docker is a containerized API wrapper for the WhatsMyName (WMN) tool, designed to facilitate username discovery on websites within an OSINT framework. Notable features include JWT authentication for secure access, the ability to perform individual or batch username lookups, cached job results for performance, and built-in API documentation. This tool aims to enhance integration, modularity, and scalability for users involved in online investigative tasks.
15 Aug 2026
Python
★ 58
SYNINT: Agentic OSINT & Intelligence Framework – Modular, Stealthy, API-Free, Multi-Agent System for Automated Intelligence Collection & Analysis.
15 Aug 2026
★ 115
SOCMIntelligence is a comprehensive Social Media Intelligence (SOCMINT) tool designed for monitoring and analyzing social networks to identify profiles, relationships, and organizations, enabling the construction of contextual diagrams relevant to various intelligence cycles. Key features include support for multiple social media platforms, advanced search capabilities, and a variety of analytics and monitoring tools. This tool facilitates the extraction of valuable information from social media exchanges, making it essential for intelligence gathering and network analysis.
15 Aug 2026
★ 118
OSINTInvestigation is a comprehensive tool aimed at monitoring global events through the integration of Financial Intelligence (FININT), Social Media Intelligence (SOCMINT), and Geospatial Intelligence (GEOINT). Notably, it utilizes a tri-phase feedback cycle for anomaly detection, context analysis, and localization, leveraging web-based tools like Glint for financial visualization, Monitor The Situation for news aggregation, and World Monitor for geospatial mapping. This facilitates real-time insight into geopolitical, financial, and social trends, enabling users to detect and analyze significant occurrences effectively.
15 Aug 2026
HTML
★ 14
AryterLink is a self-hosted, browser-based remote control panel designed for Termux on Android devices, enabling users to manage their smartphones from any browser globally. It offers capabilities such as SMS management, call handling, access to contacts, device controls (like flashlight and screen brightness), real-time battery stats, audio recording, and secure terminal shell access, all while ensuring data protection through robust security measures. Notably, it operates without the need for root access or third-party servers, relying solely on Python and direct interactions with the device's hardware via the Termux:API.
15 Aug 2026
Python
★ 67
The Vulnerability PoC Repository offers curated Proof-of-Concept code, test labs, and prevention rules targeting high-severity CVEs for authorized security testing, penetration testing, CTF challenges, and security research. Key features include detection-only PoC scripts, Docker test labs with both vulnerable and patched applications, and bilingual documentation in English and Korean, ensuring comprehensive resources for cybersecurity professionals.
15 Aug 2026
TypeScript
★ 16
KageTarget is a Chrome extension designed for local web reconnaissance, enabling users to analyze the currently active tab or manually entered HTTP(S) addresses. Notable features include technology detection with evidence, detailed inspections of HTTP and security headers, and historical URL discovery through the Internet Archive, along with options for focused analysis and customizable user interface in multiple languages.
15 Aug 2026
★ 177
Awesome Recon Tools is a curated list of reconnaissance and footprinting tools designed to assist cybersecurity professionals in gathering domain and network information. It features a diverse array of tools for personal information footprinting, as well as specialized resources for analyzing web technologies, OSINT data collection, and visual network mapping. Notable features include integrations with services like Shodan, Censys, and Maltego, alongside functionalities for automated OSINT and detailed scanning of attack surfaces.
15 Aug 2026
Python
★ 13
jb_ape is an automated red-team engine designed to perform security assessments by probing target defenses, generating and mutating attack payloads through browser or API interfaces. It features a unique three-tier judgment system that ensures machine-verified outcomes for every attempt, employs a controlled submission budget to enhance efficiency, and utilizes reinforcement learning techniques to optimize the attack strategy while avoiding guessing. This tool is intended strictly for authorized use in sanctioned environments such as penetration testing or capture-the-flag competitions.
15 Aug 2026
★ 317
The OSCP-Pentesting-Cheatsheet serves as a comprehensive notes repository and study guide tailored for candidates preparing for the Offensive Security Certified Professional (OSCP) certification. It includes detailed enumerations using tools like Nmap for network scanning, explaining various scan types, traffic considerations, and OS fingerprinting techniques, thus aiding in efficient penetration testing practices. The cheatsheet is updated to remain relevant with upcoming exam changes, ensuring continuity of its commands and information.
15 Aug 2026
Shell
★ 24
BloodHoundAnalyzer is a bash script that automates the deployment, data import, and analysis of BloodHound CE, an Active Directory security tool. It enables efficient setup of multi-domain BloodHound CE instances, custom container management, and integration of various analysis tools to enhance Active Directory security assessments. Notable features include automated password management, support for multiple data formats, and comprehensive project listing and status tracking.
14 Aug 2026
PowerShell
★ 192
M365 Assess is a read-only security assessment tool for Microsoft 365 tenants, designed for IT consultants and administrators to quickly analyze and report security posture. It performs 292 automated checks across 15 compliance frameworks, generating comprehensive output in the form of CSV data, a branded HTML report, and an XLSX compliance matrix. Key features include customizable assessment sections, compatibility with various compliance standards, and an interactive wizard for streamlined execution.
14 Aug 2026
Python
★ 12
NEXUS REDFOX is a local-first codebase intelligence and security analysis tool designed to assist developers and security teams in understanding software projects by inspecting source code and dependencies without cloud reliance. It features comprehensive deterministic security scanning, architecture graph generation, and detailed reporting capabilities, enabling users to identify vulnerabilities, map project structures, and generate software bills of materials effectively. Notable functionalities include a local web dashboard, deterministic analysis, and integration with an optional AI analysis component, all aimed at enhancing developer security and project integrity.
14 Aug 2026
PowerShell
★ 11
The Scan-broken-owner tool is a PowerShell script designed to audit Active Directory for vulnerabilities related to object ownership, specifically targeting "broken owners" which pose a security risk. Its primary use case is to help organizations identify and mitigate control-takeover vulnerabilities by ensuring that Active Directory objects are owned by appropriate, legitimate users, thereby preventing potential attacks such as Kerberos Resource-Based Constrained Delegation abuse. Notable features include the generation of a detailed HTML report, the ability to skip specific users or groups during scans, and operation without requiring administrative privileges.
14 Aug 2026
Go
★ 22
Gemtracker is an interactive terminal UI tool designed to analyze Ruby gem dependencies and detect security vulnerabilities within projects. Key features include a tab-based interface for visualizing dependency trees, real-time gem search, CVE reporting, and group-based analysis, along with JSON export capabilities for integration with automated systems and AI tools. This tool enhances the management of gem versions and prioritizes security fixes, making it ideal for developers aiming to maintain safe and up-to-date Ruby applications.