> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

bf_active_sub

bf_active_sub is a subdomain enumeration tool designed for active scanning through brute-force techniques. It efficiently verifies the existence of subdomains by attempting various combinations from a provided wordlist, ensuring zero false positives, and allowing results to be outputted directly in the terminal or saved to a file. Notable features include support for various wordlist sizes and compatibility with Debian-based systems, making it a valuable asset for penetration testing and bug bounty efforts.

beetle

Beetle is an offline-first Application Security Intelligence Platform designed for the analysis of Android APKs and iOS IPAs, including those built with Flutter and React Native. It integrates static analysis with a focus on creating explainable workflows that correlate isolated findings into realistic attack chains, facilitating better understanding of vulnerabilities with evidence-based insights. Key features include low false-positive rates, source navigation for precise findings, and optional AI assistance for reasoning about security issues, all while maintaining data security by performing analysis locally.

Awesome-Hacking-with-AI

The "Awesome Hacking with AI" repository is a comprehensive resource that explores the integration of Artificial Intelligence in offensive security practices, such as penetration testing and red teaming. It features a curated collection of AI-driven tools, methodologies, and case studies while emphasizing ethical considerations in their application. Notable features include a learning roadmap, prompt libraries for various tasks (e.g., payload generation and OSINT profiling), and advanced tactics like AI-powered malware development and botnet exploitation.

autoDeploy

autoDeploy is a Bash script designed for customizing Kali Linux by automating the installation of various plugins, applications, and utilities to enhance the user environment. It offers three installation modes: a complete setup, terminal and desktop customization, and installation of third-party applications, with automated error logging for troubleshooting. This tool streamlines the setup process, making it easier for users to tailor their Kali Linux experience.

arsenic

Arsenic is a tool designed to establish standard conventions for organizing penetration testing data, primarily focusing on directory structures and file naming conventions. Its notable features include the ability to create custom operation setups, a dedicated structure for storing host information and reconnaissance data, and integration capabilities with other tools like arsenic-hugo to enhance the offensive operations process. Arsenic aims to streamline and augment the workflow of penetration testers by making data management more systematic and enjoyable.

architect-to-product

A2P (Architect-to-Product) is an AI engineering framework that serves as a middleware component (MCP server) aimed at converting AI-generated code into production-ready software with rigorous verification processes. The tool enforces systems engineering principles through evidence-gated methodologies, ensuring that each development phase—requirements, tests, and deployment—includes substantiated evidence, thereby addressing common gaps in AI coding outputs. Notable features include a transition from v1 to v2, which integrates comprehensive systems engineering concerns, alongside a strict verification layer that transforms AI agents' self-reports into machine-checkable validations.

AndroidManifestExplorer

AndroidManifestExplorer is a high-performance static analysis tool designed to automate the identification of attack surfaces in Android applications by examining decompiled `AndroidManifest.xml` files. Its primary use case is to uncover security vulnerabilities, including exposed app components, dangerous permission usage, and configuration risks while generating actionable ADB payloads for dynamic verification. Notable features include implicit export detection, deep link analysis, MIME-type intent detection, and comprehensive JSON output for integration into security pipelines.

AIDA

AIDA is an AI-driven autonomous pentesting agent designed for comprehensive security assessments of web applications, APIs, and infrastructure. It utilizes large language models to reason and understand application logic, execute commands in an isolated environment, and systematically document findings. Notable features include a fully equipped Docker execution environment with essential pentesting tools, on-the-fly Python script generation for custom exploitations, sophisticated HTTP request manipulation, and persistent logging for detailed results.

AD-PathFinder

ADPathFinder is a specialized attack mapping tool designed for penetration testers and red teamers, enabling the analysis of SharpHound data in conjunction with OpenGraph plugins to identify potential attack pathways to critical targets within Active Directory (AD) environments. It supports a variety of data sources, including MSSQLHound and ConfigManBearPig, facilitating comprehensive audits across AD, Active Directory Certificate Services (ADCS), System Center Configuration Manager (SCCM), and SQL Server. Notable features include the ability to map escalation paths, detect weak passwords, and generate detailed reports on vulnerabilities within the network.

abspider-recon

ABSpider Recon is a web reconnaissance tool designed for authorized passive intelligence gathering and active vulnerability assessments, targeted primarily at bug bounty hunters, security engineers, and auditors. It features a unified dashboard and command-line interface (CLI) that simplifies key reconnaissance tasks, including DNS lookups, port scans, and payload checks into a streamlined workflow. Notably, it offers a live demo environment and can be run locally via npm, making it accessible for both professionals and educational purposes.

ziran

ZIRAN is a comprehensive security testing framework designed to identify vulnerabilities in AI agents, including those with complex capabilities such as tool usage and memory. By modeling agents as graphs of capabilities, it effectively discovers dangerous tool chains, detects execution-level side effects, and conducts adaptive multi-phase campaigns, surpassing the capabilities of single-prompt scanners. Notable features include graph-based analysis, tool-chain discovery, and thorough coverage of established security benchmarks like OWASP and MITRE.

Z3r0

Z3r0 is an open-source red team collaboration workbench designed for authorized penetration testing, vulnerability discovery, and security research. It integrates a React-based console with a FastAPI management layer, allowing users to coordinate multi-Agent sessions, track project-specific evidence, and manage sandbox environments and controlled egress efficiently. Notable features include comprehensive evidence management, detailed workflow tracking, and a session timeline that enhances operational transparency and collaboration among red team participants.

WonderSuite-Ai-Bug-Bounty

WonderSuite is a desktop-native offensive security research engine designed for comprehensive web application security testing, network reconnaissance, and exploit development, harnessing AI capabilities via Model Context Protocol (MCP) integration. It features an extensive toolkit of 91 security tools, enhanced by a full MITM proxy with advanced fingerprinting for obfuscation, facilitating efficient vulnerability research and response automation. The platform aims to streamline the process of identifying and addressing security issues, making it a powerful asset for security professionals.

website-passive-reconnaissance

The website-passive-reconnaissance tool automates passive reconnaissance on websites to aid cybersecurity assessments without directly engaging with the target. Its primary use case is to streamline the reconnaissance phase by defining and executing necessary steps using various integrated API services. Notable features include customizable API key integration, configurable options for domain analysis, and a user-friendly command-line interface.

WEBFANG

WEBFANG v2.0 is a command-line reconnaissance toolkit specifically designed for ethical hacking, enabling users to perform both passive and active reconnaissance through features such as web spidering, subdomain scanning, WHOIS checks, DNS queries, and header fingerprinting. It supports integration with Shodan and URLScan, and is modular in design, allowing for extensions and enhanced output options. Intended for authorized penetration testing and OSINT research, the tool ensures that users maintain compliance with ethical guidelines during usage.

Weaponize-CobaltStrike

Weaponize-CobaltStrike is an automated toolkit designed to streamline the setup and configuration of Cobalt Strike, enhancing its capabilities with a wide array of Beacon Object Files (BOFs) and offensive security tools. Key features include the automation of dependency installation and compilation of various community-driven tools, such as the CS-Aggressor-Kit and situational awareness BOFs, making it easier for security professionals to extend their Cobalt Strike operations. This tool aims to facilitate authorized security testing and educational purposes while also providing a platform for contributions and improvements from the community.

VSAT

VSAT (Volumetric Socket Artillery) is an advanced multi-layer network traffic generation framework designed for comprehensive stress testing and benchmarking of network infrastructure. The tool integrates Layer 3, Layer 4, and Layer 7 traffic engines, enabling high-throughput traffic simulation across various protocols while offering features such as HTTP/2 multiplexing, TLS JA3 fingerprinting, and raw packet crafting. Its multiprocessing architecture facilitates concurrent traffic generation, making it suitable for defensive security research and protocol analysis.

userscripts

4ndr0tools is a collection of userscripts designed to enhance digital sovereignty by countering anti-user web practices and empowering users with control over their browsing experience. Notable features include modular design for customizable implementation, transparent and auditable code, and a focus on anti-platform functionalities that resist modern web manipulations. This suite caters to advanced users and red team engagements, promoting a minimalist and performance-oriented approach to web interactions.

unigeek

UniGeek is a versatile multi-tool firmware designed for a wide range of ESP32-based handheld devices, enabling functionalities such as Wi-Fi and Bluetooth attacks, RF signal manipulation, and various diagnostic utilities. It offers an extensive feature set including network attacks, sub-GHz communication, NFC capabilities, and a suite of utility tools and games, all integrated into a user-friendly interface. Notable aspects of UniGeek include its comprehensive documentation and support for approximately 18 different device models.

UE-based-5G-Pentesting-Framework

The 5G-Pentest-UE is a penetration testing framework designed to identify vulnerabilities within 5G systems from the perspective of a user equipment (UE), requiring no prior knowledge or access to the network. Its notable features include the ability to configure and run tests against the 5G protocol stack, alongside the integration of patched Open Air Interface implementations to facilitate comprehensive security testing. This framework is particularly useful for assessing security in closed-source and proprietary 5G networks.

trilane

TriLane is an autonomous gray-box security auditing tool designed for authorized penetration testing on local labs, internal codebases, and bug-bounty targets. It features a staged audit process that includes the construction of an attack-surface graph, a six-lane semantic audit covering various security aspects, and a deduplication mechanism for findings, allowing for a thorough and organized assessment of security vulnerabilities. Notable features include a desktop GUI for tracking the audit process, two operational modes (Safe and Lab), and efficient evidence management for generating comprehensive reports.

toboggan

Toboggan is a post-exploitation tool that facilitates a semi-interactive shell on both Linux and Windows targets via Remote Code Execution (RCE) methods. It operates by allowing users to define custom command execution logic through a simple Python interface, enabling interaction with command outputs even in restrictive network environments. Key features include support for Python-based execution modules, an interactive shell with command history, and the ability to establish communications using named pipes when reverse shells are not feasible.

TheBigBrother

The Big Brother V5.0 is an advanced Open Source Intelligence (OSINT) framework designed for comprehensive reconnaissance on individuals, organizations, or groups. It features a highly interactive holographic dashboard supported by 21 distinct intelligence modules that facilitate deep investigative analysis. The tool allows users to conduct detailed searches and surveillance, enhancing the capabilities for gathering critical data while also offering an exclusive service for more intensive intelligence requirements.

taser

TASER (Testing and Security Resource) is an abstraction library designed to facilitate the development of custom offensive security tools by providing various protocols and classes. Its primary use case is to streamline the creation of tailored security scripts during engagement scenarios, and it includes features for browser integration, screenshot capabilities, and packaged scripts for different probing tasks.

SQL-Injector

SQL-Injector is a specialized tool designed for performing SQL injection testing on web applications, facilitating the identification of vulnerabilities in various database systems such as MySQL, PostgreSQL, MSSQL, and Oracle. Notable features include automated vulnerability detection, custom payload generation for bypassing WAFs, multi-threaded scanning for efficiency, and the ability to operate anonymously via Tor integration. Advanced capabilities support complex testing scenarios, including boolean-based blind SQL injection and detailed schema enumeration.