> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

GTFONow

GTFONow is a Python-based tool designed for automatic privilege escalation on Unix systems by exploiting misconfigured setuid/setgid binaries, capabilities, and sudo permissions. With a focus on usability for both CTF challenges and real-world pentesting scenarios, it offers various automated exploitation techniques, including file read/write primitives and SSH key theft. The tool is lightweight, compatible with multiple Unix variants, and requires no third-party dependencies, making it easy to deploy via a single script.

GPOHound

GPOHound is a cybersecurity tool designed to dump and analyze Group Policy Objects (GPOs) from the SYSVOL share, highlighting misconfigurations, insecure settings, and potential privilege escalation paths within Active Directory environments. Key features include structured output in JSON or tree formats, multi-domain support, and the ability to enrich BloodHound data with additional relationships and properties derived from GPO analysis. The tool supports advanced filtering, regex searches, and the detection of insecure configurations, facilitating comprehensive assessments of Active Directory security posture.

ghostbadger

Ghostbadger is a PDF rendering engine that automates the generation of secure, password-protected PDF reports by leveraging Ghostwriter's GraphQL API for content and integrating with Vaultwarden for secure client delivery. Notable features include the ability to customize templates, utilize a streamlined Docker setup for deployment, and manage sessions through client-side cookies, ensuring flexibility for internal workflows. This tool is designed to be adapted for specific needs, requiring customization for production use.

getaltname

GSAN (Get Subject Alternative Names) is a tool designed to extract Subject Alternative Names (SAN) from SSL certificates of HTTPS servers, enabling the identification of DNS names and virtual hosts, particularly in environments involving internal or self-signed certificates. Its primary use case involves directly connecting to servers to retrieve SAN data without relying on Certificate Transparency logs, and it supports batch processing via file input and integration with other tools like Shodan or Nmap for enhanced functionality and output options. Notable features include flexible output capabilities and support for Docker installation, allowing seamless deployment and usage in various environments.

ffuf

ffuf is a high-performance web fuzzer developed in Go, designed for conducting security testing by discovering hidden resources on web applications. Its primary use cases include directory and virtual host discovery, as well as fuzzing GET and POST parameters, allowing users to efficiently identify vulnerabilities and misconfigurations. Notable features include customizable wordlists, support for interactive mode, and the ability to filter responses based on their size, enhancing both speed and effectiveness in identifying potential security flaws.

faraday_plugins

Faraday Plugins is a command-line tool designed to work seamlessly with Faraday, enabling users to manage and process security-related plugins. Its primary use case includes detecting and processing commands or reports generated by various security tools like Nmap and ping, offering features such as custom plugin support, JSON output formatting, and detailed command tracking. Notably, it allows for easy integration of custom plugins and includes logging capabilities for debugging purposes.

faction

FACTION is an OWASP project designed to streamline and automate the entire penetration testing and security assessment workflow. It offers features such as real-time collaboration among assessors, customizable report templates, a peer review system for tracking changes, and robust integration capabilities with tools like Burp Suite and various authentication systems. Additionally, it includes a REST API for seamless integration with other platforms, enhancing vulnerability management and team coordination.

ExaAiAgent

ExaAiAgent is an advanced AI-powered cybersecurity tool designed for comprehensive penetration testing, providing enhanced functionalities for various security assessments. Key features include a K8s scanner tool registration, smart fuzzing capabilities, response analysis for SQL errors, and automated installation processes, all aimed at integrating seamlessly into agent-driven workflows. The tool focuses on improving runtime reliability, error handling, and multi-tool coordination to facilitate efficient cybersecurity operations.

ethibench

EthiBench is an adaptable evaluation framework designed for assessing the efficacy of AI-driven pentesting agents against complex, real-world security targets and vulnerabilities. It shifts the evaluation focus from simple task completion to validated vulnerability discovery, incorporating advanced features such as LLM-based semantic matching, continuous ground-truth maintenance, and scoring under ambiguity. Users can customize evaluations with their own targets and findings, while also accessing a set of pre-defined expert-annotated entries for standardized assessment.

EmberHeart_OnePlus11

EmberHeart_OnePlus11 is a custom kernel designed for OnePlus 11 devices, primarily enabling advanced Android functionalities such as root access through KernelSU, along with enhanced security features via SUSFS for root hiding. The kernel is also optimized for use with the Nethunter penetration testing platform, allowing penetration testers to leverage their device for security assessments. Notable features include seamless installation instructions, compatibility with various kernel modules, and community contributions enhancing its capabilities.

EmbedXPL-Forge

EmbedXPL-Forge is an open-source exploitation and scanning framework designed for security assessments of embedded and perimeter devices including routers, switches, IoT devices, and printers. It features over 2800 modules encompassing various attack vectors such as credential testing, vulnerability exploitation, and firmware manipulation, alongside an extensive library of 700+ mapped CVEs across 114+ vendors, along with an APT Group Attack Engine for simulating real-world cyber attack scenarios.

dradis-burp

The Dradis Burp plugin facilitates the integration of Burp Scanner XML export files into the Dradis framework, enhancing reporting and collaboration capabilities for security assessments. It requires either Dradis Community Edition version 3.0 or higher, or Dradis Pro, enabling users to efficiently manage and visualize the results from their Burp Suite scans. Notable features include compatibility with both Dradis versions and streamlined file uploads, allowing for better organization of findings.

deepbug

DeepBug is an automated reconnaissance and bug bounty hunting platform that integrates various open-source tools to facilitate subdomain enumeration, port scanning, JavaScript analysis, and vulnerability scanning within an intuitive user interface. Its primary use case is to streamline bug bounty workflows, allowing users to manage projects, perform discovery scans, and generate comprehensive reports on findings. Notable features include customizable project management, a robust dashboard for tracking scan progress, and integration with popular vulnerability scanning tools like Nuclei.

DDoSlayer

DDoSlayer Ultimate Edition is an advanced DDoS testing framework designed for professional penetration testing and red team operations, capable of simulating complex Layer 4 and Layer 7 attacks. Notable features include an AI-powered auto-detect mode for intelligent reconnaissance and attack vector recommendations, a rich terminal UI for enhanced user experience, and support for multiple attack vectors with stealth capabilities. This tool is optimized for efficiently executing concurrent attacks while providing comprehensive analytics through detailed reporting.

DACLSearch

DACLSearch is a comprehensive tool for extracting Access Control Entries (ACEs) associated with principals in Active Directory environments. It supports extensive filtering and database generation, allowing users to perform detailed queries on ACEs and manage access control data efficiently through a command-line interface. Notable features include the use of the Phantom Root for broad queries across domain objects, multi-filter capabilities, and the ability to save and load custom filter configurations in YAML format.

CyberBox

CyberBox is a hardened Docker sandbox designed for bug bounty and offensive security research, providing a secure environment with a comprehensive assortment of over 160 security tools. It features keyless signing with cosign, a complete Software Bill of Materials (SBOM), and SLSA build provenance to ensure trust and integrity throughout the supply chain, while also integrating AI analysis and an autonomous workflow for security tasks. Moreover, it seamlessly supports the Caido framework, offering a plugin manager and various utilities to enhance the research process.

CVE2PoC

CVE2PoC is a tool designed for penetration testers and security researchers to efficiently locate public exploits, Proof-of-Concepts (PoCs), and advisories associated with a specific CVE ID. Its notable features include the aggregation of public exploits from various sources, the provision of isolated Docker environments for safe testing, automated report generation, and comprehensive CVE intelligence, including remediation steps and related bug bounty reports. This powerful tool streamlines the vulnerability discovery and assessment process, allowing users to quickly gather essential information for their security assessments.

CommiPiste

CommiPiste is a tool designed for precise identification of open-source web software versions and associated CVEs by analyzing public static files. Its primary use case is authorized security testing and inventory management, leveraging a signature database that allows users to match files against specific Git commits. Notable features include automatic database updates, support for various output formats, and the capability to autoindex unknown software repositories for future scans.

cloud

Cloud is a cybersecurity tool designed for monitoring and collecting SSL certificate data from major cloud service providers, specifically AWS EC2 and GCP. Its primary use case is to assist security researchers in enumerating subdomains, domains of target companies, and performing IP lookups, with daily updates to the dataset ensuring relevance and timeliness. Notable features include the ability to discover origin IP addresses behind security proxies and the organization of data into structured CSV files for easy access and analysis.

cariddi

Cariddi is a domain crawling and scanning tool designed to identify sensitive information such as endpoints, secrets, API keys, and various file extensions from a list of provided URLs. Notable features include intensive crawling of subdomains, options for hunting specific secrets and errors, and customizable scanning parameters, making it particularly useful for penetration testing and bug bounty hunting. The tool can be easily installed across various platforms, supporting both single-target and bulk scanning configurations.

Cairn

Cairn is a general-purpose problem-solving engine designed for AI-driven penetration testing and exploration of various state spaces. It utilizes a Blackboard Architecture with a fact-intent graph to dynamically search for paths from a defined origin to a goal, enabling versatile applications such as vulnerability research and CTF challenges. Key features include agent-based coordination through stigmergy, adaptable task generation, and real-time updates to the shared knowledge graph.

Bug_Bounty_Tools_and_Methodology

The Bug Bounty Methodology and Tools repository provides a structured approach for ethical hackers to enhance their bug bounty hunting skills. It emphasizes the importance of reconnaissance and OSINT, which constitutes the majority of the bug hunting process, while also listing essential tools used during red team operations. Key features include a comprehensive methodology guide and practical resources, with a focus on continuous learning and improving attack vectors.

blood-web

Blood-Web is a modular honeypot system designed for penetration testing training and network attack detection, implemented in Python 3.8+ with zero dependencies. It features multiple honeypot services, including SSH, FTP, HTTP, and others, each configurable via command line flags, along with a real-time web dashboard for monitoring attack statistics and trends. The tool is designed to run on non-privileged ports by default, enabling easy deployment without additional setup.

BladeRecon

BladeRecon is a modular reconnaissance framework tailored for bug bounty hunters and web penetration testing, focusing on attack-surface discovery and reporting. It offers a terminal-native workflow that generates clean output in various formats, including HTML and Markdown, while integrating features such as subdomain discovery, endpoint extraction, secret detection, and Nuclei scanning for improved intelligence gathering. Designed to be lightweight and beginner-friendly, BladeRecon prioritizes usability without sacrificing operational transparency, making it a valuable tool for small-scale pentesting efforts.

Bjorn

Bjorn is an autonomous network scanning and vulnerability assessment tool optimized for Raspberry Pi, featuring a unique e-Paper HAT display. Its modular architecture allows for flexible configuration and operations like network scanning, vulnerability detection using Nmap, brute-force attacks, and data extraction from compromised services. With a real-time interface for monitoring and interaction, Bjorn supports extensive customization for diverse security testing requirements.