> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

evil-winrm-py

`evil-winrm-py` is a Python tool designed for executing commands on remote Windows systems via the WinRM protocol, featuring an interactive shell with capabilities for file upload/download, command history, and colorized output. It supports various authentication methods, including NTLM and Kerberos, and offers advanced functionalities such as in-memory execution of local scripts and DLLs, making it highly versatile for authorized penetration testing and educational purposes. The tool prioritizes user experience with features like command auto-completion, comprehensive logging, and a lightweight design, enhancing usability for cybersecurity professionals.

ESP-HACK

ESP-HACK is a comprehensive firmware for the ESP32 designed for radio frequency research and penetration testing, encompassing protocols in RF, Bluetooth, infrared signals, and GPIO integrations. Targeted at enthusiasts and pentesters, the tool features a wide array of functionalities including WiFi deauthentication, Bluetooth spamming, Sub-GHz signal analysis and jamming (where legal), and infrared control capabilities, all while permitting extensive customization through GPIO and support for various modulations. Its versatility makes it an essential resource for exploring and testing a variety of wireless communication technologies.

dpulse

DPULSE is an advanced desktop application designed for domain OSINT and reconnaissance, streamlining the process to gather intelligence from open sources with minimal setup. Key features include automated WHOIS and subdomain enumeration, interactive network graph visualizations, real-time security analysis, and integrated API support, all presented in an easily navigable HTML report. This tool serves OSINT professionals looking to enhance their domain reconnaissance workflows while maintaining a user-friendly interface across Windows and Linux platforms.

daily-bugbounty-writeups

The 'Daily Bug Bounty Writeups' repository provides a collection of detailed writeups related to bug bounty exploits and vulnerabilities. It's primarily aimed at cybersecurity professionals and bug bounty hunters seeking insights on various security misconfigurations, pentesting techniques, and practical exploit scenarios. Notable features include links to external articles that cover cloud security misconfigurations, advanced web application security testing, and guides for utilizing GitHub as a reconnaissance tool.

cywise

Cywise is a cybersecurity solution designed for both on-premises and SaaS environments, enabling users to scan and secure their web-facing and internal infrastructures. It features a robust vulnerability scanner that monitors for over 50,000 vulnerabilities with automated remediation, alongside active data leak monitoring and intelligent honeypots to detect and analyze potential threats. This tool is particularly suitable for small to medium-sized enterprises looking to enforce comprehensive security measures while maintaining control over their data and infrastructure.

cyber-controller

Cyber Controller is a versatile application designed for flashing and controlling multiple ESP32 devices through a unified interface, facilitating both firmware installation and real-time management. It supports 50 firmware profiles and can operate over various interfaces, making it suitable for authorized security testing and educational purposes. Key features include simultaneous commands for multiple devices, anti-bricking safeguards, and compatibility with touchscreens or headless setups, enhancing user experience in cyberdeck operations.

cvemapping

The cvemapping tool aggregates CVE exploit data from GitHub, allowing users to clone repositories or export CVE information in JSON format for web use. It features options for pagination and year-specific searches, making it versatile for both developers and security researchers aiming to analyze or present CVE-related data efficiently. Notable features include the ability to authenticate using a GitHub token and the straightforward export functionality for integration with web applications.

cochise

Cochise is an autonomous penetration testing tool that leverages large language models (LLMs) to exploit vulnerabilities in Microsoft Active Directory environments. With a minimalistic design, Cochise allows users to easily customize and benchmark various LLMs, effectively orchestrating attack procedures including command execution and credential harvesting, all without requiring human intervention. Notable features include a dual-layer architecture comprising a strategic Planner and tactical Executor, along with built-in context management and analysis support for log file evaluation.

Claude-BugHunter

Claude-BugHunter is a comprehensive skill bundle for the Claude Code system, designed to enhance bug-hunting and red-team operations with 82 curated skills and 15 commands. It features a structured approach to vulnerability detection, engagement scaffolding, and automated reporting, drawing from a vast collection of 681 disclosed report patterns across 24 core vulnerability classes. Notably, it integrates with Burp MCP and provides enterprise identity and infrastructure attack matrices for sophisticated security assessments.

cheatengine-mcp-bridge

The Cheat Engine MCP Bridge is a tool that leverages AI capabilities to streamline the analysis of program memory, significantly reducing the time required for reverse engineering tasks such as locating pointers, tracing operations, and documenting structures. Notable features include support for automatic memory reading and structure analysis, the ability to follow pointer chains, and disassembly functionalities, all of which transform tedious manual processes into quick, conversational queries directed at the memory. This tool is particularly useful for creating game mods, trainers, and conducting security audits efficiently.

baboossh

BabooSSH is a specialized tool designed for red teams to facilitate SSH spreading from a compromised host, enabling quick reconnaissance and compromise of additional SSH endpoints. Its notable features include straightforward installation via pip, automated tests using pytest integrated into GitHub Actions, and an evolving documentation site.

adscan

ADscan is a comprehensive Active Directory pentesting tool designed for Linux environments that consolidates 103 attack techniques into a streamlined CLI interface. Its primary use case lies in automating the penetration testing process for red teamers and security professionals, providing capabilities such as enumeration, Kerberoasting, and attack-path analysis without the need for Windows. Notable features include fully automated scans through the 'adscan ci' command, which allows for both authenticated and unauthenticated assessments while leveraging Docker for its operational environment.

adhammer

ADhammer is an Active Directory security-assessment toolkit implemented in Rust that functions as an auditor similar to PingCastle, capable of mapping domain attack paths with scoring, graphing, and MITRE tagging. It performs low-privileged audits via LDAP, validates identified vulnerabilities using live offensive techniques, and supports execution on both Kali Linux and Windows as a single static binary. Notable features include its custom-built DCE/RPC and Kerberos stack, extensive checks across various security categories, and the ability to export findings to BloodHound.

5ghost-wifi-lab

5Ghost WiFi Lab is a dual-band Wi-Fi research and security testing tool designed for the Flipper Zero, utilizing the Realtek RTL8720DN chipset to enable comprehensive 2.4 and 5 GHz scanning. It features capabilities such as WPA/WPA2 handshake capture, clientless PMKID capture, and BLE reconnaissance, making it suitable for advanced security testing and educational purposes. The tool operates through a user-friendly app with multiple firmware support and connects seamlessly to the Flipper Zero without the need for additional wiring or flashing.

wordpress-plugins

The wordpress-plugins repository is an automated monitoring tool that continuously aggregates and updates data from the official WordPress Plugin Directory, providing actionable insights for developers and security researchers. It utilizes GitHub Actions to refresh the metadata every six hours, allowing easy access to essential plugin information such as installation statistics, updates, and compatibility details in structured JSON format. Notable features include a custom data mining tool, JSON processing capabilities, and comprehensive analytics for tracking the overall health of the WordPress plugin ecosystem.

wordlists

The "wordlists" repository provides curated French wordlists aimed at enhancing password cracking efforts targeting French-speaking individuals. It features pre-compiled lists free from complex characters for easier input, supporting integration with popular cracking tools like Hashcat and John the Ripper, while also referencing various online resources for comprehensive coverage. This tool is particularly useful for penetration testing and security assessments within the French context.

subscan

Subscan is a Rust-based tool designed for monitoring and analyzing blockchain data, primarily focusing on Polkadot and its ecosystem. Its notable features include automated testing workflows, extensive documentation, and container support via Docker, enabling seamless integration into development pipelines. Subscan aims to enhance visibility and insight into blockchain activity, providing developers with essential tools for data analysis and monitoring.

shodan-dorks

Shodan Dorks is a specialized query catalog for Shodan that enhances the search experience by providing categorized and frequently updated dork lists, specifically for discovering various internet-connected devices such as cameras, industrial control systems, and network infrastructure. It features real-time updates every six hours to reflect current results and automatically purges queries that return zero results, making it a valuable tool for security professionals and researchers. The repository includes a wide array of search filters and exploitation details, enabling users to efficiently locate and assess vulnerable devices.

scope

scope is a CLI tool that provides a curated dataset for querying bug bounty program scopes across various platforms, including Bugcrowd and HackerOne. It enables security researchers to efficiently identify in-scope domains and assets through regular automated updates and a command-line interface for targeted searches. Notable features include categorized files for wildcards, domains, and GitHub repositories, along with a comprehensive list of in-scope and out-of-scope targets for enhanced usability in bug bounty activities.

resolvers

The "resolvers" tool provides a regularly updated list of DNS resolvers, with updates executed every hour. Its primary use case is to supply reliable and fresh DNS resolver information, categorized into three distinct files based on the recency of updates: resolvers updated within the last hour, stable resolvers from the past 24 hours, and all available resolvers. Notable features include automated saving of fresh resolvers using `dnsvalidator` and systematic organization for user accessibility.

rcekit

RCEKit is a Python-based toolkit designed for the detection and confirmation of remote code execution (RCE) vulnerabilities, specifically for authorized penetration testing and security research. It provides a robust CLI interface to assess targets by employing multiple verification methods against real-world CVEs, generating definitive "confirmed" verdicts that can be utilized in security reports. Noteworthy features include support for various RCE classes, an easy-to-use setup without third-party dependencies, and the ability to produce evidence-based results, ensuring accurate detection rather than mere conjecture.

promptfoo

Promptfoo is a command-line interface (CLI) and library designed for evaluating and red-teaming large language model (LLM) applications. Its primary use case involves automated testing of prompts, vulnerability scanning, and model comparison, enabling developers to enhance security and reliability in their AI applications while running evaluations locally without exposing data. Notable features include integration with CI/CD workflows, comprehensive security reporting, and support for multiple LLM providers, allowing for a developer-centric, flexible, and data-driven approach to AI application development.

OpenEASD

OpenEASD is an open-source external attack surface discovery (EASD) tool designed for red teamers and defenders, enabling users to rapidly map and assess external surfaces of authorized targets without the expense of commercial solutions. It integrates multiple recon tools—such as `subfinder`, `amass`, and `nmap`—into a single web interface, offering features like scheduling, alerts, and findings tracking, while ensuring results remain local to the user's infrastructure. This self-hosted platform emphasizes transparency and security through careful sourcing of its components and is aimed at small security teams, consultancies, and individual security learners.

medium-writeups

The rix4uni/medium-writeups repository aggregates recent articles and write-ups focused on cybersecurity, penetration testing, and security awareness from Medium. Its primary use case is to provide users with timely content related to various security topics, including the OWASP Top 10 vulnerabilities and advanced pentesting techniques. Notable features include categorization by tags such as "security," "hacking," and "infosec," allowing for easy navigation and discovery of relevant materials.