> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

poseidon

POSEIDON is a keyboard-driven pentesting firmware designed for the M5Stack Cardputer-Advance, enabling users to perform 163 types of attacks across various wireless protocols including WiFi, BLE, and IR. This tool simplifies pentesting by allowing direct input for network navigation and management without the need for a PC or complicated coding. Notable features include the integration of an autonomous WiFi handshake hunter named Argus, customizable interface themes, and ongoing development towards FIDO2 hardware security key functionality.

PenTestMethodology

The Penetration Testing Methodology repository provides a comprehensive framework for conducting penetration tests across various environments, including Active Directory, infrastructure, web applications, mobile, and cloud services. Key features include detailed methodologies for reconnaissance, exploitation, and post-exploitation techniques, along with specialized sections on API and mobile pentesting, as well as AI LLM security audits. This tool is designed to facilitate the identification of vulnerabilities and improve defensive measures in security practices.

Pentestcheatsheet

RedConsole is an offline, single-file penetration testing tool designed for Red Team operators, OSCP/OSEP preparation, and CTF/HTB engagements. It provides an interactive attack plan generator that automatically fills commands based on target details and adapts as progress is made, while also offering features like recon autopilot, credential reuse matrix, and playbook builder for streamlined execution. Its core advantage lies in its ability to run in any browser without requiring installation or internet access, making it suitable for various environments, including locked-down VMs and air-gapped systems.

pentest

The Pentester Guide is a comprehensive resource aimed at penetration testers, providing a curated collection of tools, methodologies, educational materials, and practical labs. It includes sections on certifications, bug bounty platforms, and independent pentesting resources, making it an essential tool for both novice and experienced cybersecurity professionals. Notable features include a detailed roadmap for cybersecurity learning and multiple links to pentesting practice environments.

OpenRediWrecked

OpenRediWrecked is a sophisticated tool designed for security professionals to detect and exploit open redirect vulnerabilities by automating the injection of carefully crafted payloads using the sed utility. Its notable features include parameter cleaning, support for various encoding techniques to bypass filters, and an intuitive output format that highlights vulnerable URLs in a color-coded manner. This makes it an essential asset for Red Teams and Bug Bounty Hunters seeking to improve their testing methodologies.

OpenFirebase

OpenFirebase is an automated security scanning tool designed to extract Firebase configurations from Android APKs and iOS IPAs, enabling unauthenticated and authenticated scanning of Firebase services, such as Realtime Database, Firestore, and Storage. Notably, it detects accidentally embedded service account credentials and supports multiple input formats, providing comprehensive analysis for both mobile and web applications. The tool also includes built-in wordlists and example payloads for effective fuzz testing and vulnerability assessment.

okhi

okhi is an open-source keystroke logging implant designed for integration into USB and PS2 keyboards, allowing real-time monitoring of keystrokes via WiFi. It employs an RP2040 microcontroller for data capture and an ESP32-C2 chip for wireless transmission, making it a compact and efficient solution for educational and proof-of-concept purposes. Key features include support for both keyboard types, real-time data access, and a modular design that facilitates easy installation and operation.

Offensive-Pentesting-Scripts

The Offensive Pentesting Scripts repository offers a suite of automation scripts designed to enhance the efficiency of penetration testing and bug hunting. Key features include the simultaneous installation of over 40 essential Go tools, generation of a comprehensive wordlist for subdomain brute forcing with over 66 million entries, and automated identification of live hosts and open ports using Nmap. Additionally, the toolset provides capabilities for thorough subdomain discovery through multiple techniques, streamlining the reconnaissance process for cybersecurity professionals.

Octocrawl

Fast, parallel and easy to use web crawler for penetration testing and bug bounty

OctoC2

OctoC2 is a GitHub-native command-and-control framework designed for authorized cybersecurity research, featuring encrypted multi-channel transport and resilient failover capabilities. Its architecture includes a TypeScript beacon, a durable controller, a local operator dashboard, and a comprehensive CLI, enabling secure task execution and management via various transport methods. Notable features include the use of GitHub artifacts for task exchange, a signed task protocol, and a focus on least-privilege credentials for robust security during operations.

NullSec-RedTeam-AI

NullSec Red Team AI is a highly specialized offensive security toolkit designed for red team operations, integrating seamlessly with Claude Desktop through the Model Context Protocol (MCP). This hardened version features a robust Flask orchestration server managing over 150 offensive security tools, a sandbox for AI vulnerability testing, and a self-healing diagnostic utility for system integrity. Its architecture enables high-speed workflows for reconnaissance, vulnerability research, and advanced exploitation simulations, making it ideal for professional security assessments.

netwatch-sec

NetWatch is an all-in-one network security dashboard designed to convert any Linux machine into a comprehensive security sensor. It features real-time deployment of honeypots, traffic sniffing, OSINT tools, and threat management capabilities, all accessible via a single command and user interface. Key functionalities include automatic threat scoring, detailed traffic analysis, and the ability to block attackers, making it suitable for security professionals and home users alike.

MoMo

MoMo is a modular wireless security audit platform specifically designed for Red Teams, penetration testers, and security researchers, operating on Raspberry Pi 5. It integrates various advanced features such as multi-radio management, real-time data synchronization with a central hub, and comprehensive tools for WPA2/WPA3 attacks, credential harvesting, and automation in a single extensible solution. Notable functionalities include an auto-pwn engine, GPS wardriving capabilities, and support for social engineering techniques, making it a versatile tool for wireless security assessments.

mcpsec

mcpsec is a security scanner and protocol fuzzer specifically designed for MCP (Model Context Protocol) servers, allowing real-time connection and exploitation testing against live services. Its primary use case is to identify vulnerabilities in AI development tools that utilize MCP, enabling users to discover and report security issues effectively. Notable features include support for 800+ fuzzing cases, detailed vulnerability reporting, and dynamic testing capabilities that surpass traditional static analysis methods.

Laitoxx-Multi-Tool

Laitoxx is an OSINT and cybersecurity toolkit featuring a user-friendly GUI, designed for educational purposes to facilitate security analysis, penetration testing, and digital footprint assessment. Key functionalities include an extensible plugin system (Lua), various OSINT tools for data collection, web and network scanning capabilities, and a suite of utilities for hash and text manipulation. Notable enhancements in version 2.3.2 include an advanced theme editor, auto-theme scheduling, and multiple bug fixes for enhanced stability and usability.

KUMO-Domain-Recon-Tool

Kumo is an OSINT and security reconnaissance framework that enables the analysis of a target domain via a single command, leveraging 26 parallel modules to deliver comprehensive results in real-time. Key features include extensive checks on DNS records, email security, open ports, leaked credentials, and malware associations, as well as a user-friendly web interface and fast scanning options. This tool is ideal for security professionals conducting thorough assessments of domain-related vulnerabilities and exposures without the need for API keys.

keyleak-detector

KeyLeak Detector is a runtime security tool designed to identify and validate exposed API keys and misconfigurations in Backend-as-a-Service (BaaS) implementations, specifically targeting frameworks like Supabase and Firebase. Its notable features include a Chrome extension for real-time detection of secrets in web applications, a full site scanning capability that reports on potential vulnerabilities across subdomains, and the ability to validate active status of found keys. Unlike traditional static scanners, KeyLeak assesses the exploitability of keys at runtime, offering a comprehensive audit for web applications.

keyFinder

KeyFinder is a browser extension designed for Chrome and Firefox that passively scans web pages for leaked API keys, tokens, and secrets. With over 80 detection patterns across multiple categories such as cloud services, payments, and databases, it operates silently in the background, leveraging techniques like entropy analysis and monitoring various attack surfaces to identify sensitive information. Notable features include zero dependencies, compatibility with modern web standards (Manifest V3), and the ability to alert users via tab badges when potential exposures are detected.

Kali-Booster

Kali-Booster is a script designed to enhance Kali Linux by installing additional pentesting tools, configuring system settings, and creating useful aliases for command line efficiency. Key features include the restoration of legacy tools, the addition of new wordlists, enhanced font support, and customized settings for a streamlined pentesting environment. The script also facilitates the setup of OpenVPN connections for various hacking platforms and includes automated customization of the user interface.

Ironbullet

Ironbullet is a desktop automation toolkit designed for creating and executing complex data processing workflows using a visual drag-and-drop pipeline interface. It features over 50 block types, including HTTP requests, parsing, checks, and browser automation, allowing users to perform multi-threaded job executions with advanced debugging capabilities, TLS fingerprinting, and built-in traffic capture for analysis. Moreover, the tool supports plugin extensions and the importation of configurations from OpenBullet 2 and SilverBullet, enhancing its flexibility and application in various automation tasks.

huntkit

HuntKit is a Dockerized collection of tools designed for penetration testing, bug bounty hunting, red teaming, and capture the flag challenges, enabling rapid deployment and usage without the overhead of a virtual machine. It offers notable features such as quick execution, easy updates, and disposable environments, allowing users to quickly run tools like nmap and commix with minimal setup. The containerization approach streamlines security assessments while providing a convenient method for maintaining the latest versions of essential penetration testing tools.

httpgrep

httpgrep is a high-performance asynchronous Python tool designed to scan HTTP(S) servers and search for specific strings or regex patterns within HTTP response bodies and headers. It supports a variety of input formats for target hosts, parallel scanning of multiple ports, and advanced features, including live match streaming, log file outputs in multiple formats, and the ability to resume interrupted scans, making it suitable for extensive network assessments. The tool is built for efficiency with an async core capable of handling thousands of concurrent connections while implementing intelligent timeout and port preflight mechanisms.

htb-thm-oscp-checklist

The HTB / THM / OSCP Master Penetration Testing Checklist is a comprehensive, modular framework designed to guide penetration testers through the phases of engaging with Hack The Box, TryHackMe, and OSCP-level machines. Key features include structured sections from setup and reconnaissance through exploitation and post-exploitation activities, as well as a quick reference for tools, commands, and troubleshooting. This checklist serves as a valuable resource for both beginners and intermediate practitioners in the penetration testing field.

hetty

Hetty is an open-source HTTP toolkit designed for security research and penetration testing, serving as an alternative to commercial tools like Burp Suite Pro. Its notable features include a machine-in-the-middle (MITM) HTTP proxy with logging capabilities, an HTTP client for crafting and replaying requests, request and response interception for manual review, organized project-based database storage, and a user-friendly web-based interface. Hetty is continually under development, aiming to meet the needs of the infosec and bug bounty communities effectively.

haiti

HAITI is a command-line interface (CLI) tool and library designed for identifying over 675 types of hash algorithms, including modern algorithms like SHA3, Keccak, and Blake2. Its primary use case is for cybersecurity professionals needing to determine hash types quickly, and it features references for integration with tools such as Hashcat and John the Ripper, along with a hackable architecture for customization.