12 Aug 2026
Python
★ 79
CanLab is a comprehensive reverse-engineering workstation for CAN bus data, designed to facilitate the analysis, diagnostics, and modification of automotive communication protocols. It features a user-friendly PyQt6 interface that supports loading and inspecting CAN frames, running offline analyses, and utilizing AI assistance for interpreting IDs. Notable capabilities include DBC building and export, diagnostic protocol support, signal injection and fuzzing, as well as built-in safety mechanisms to prevent accidental misuse in live vehicle environments.
12 Aug 2026
Python
★ 35
Revagent is a black-box program analysis agent that leverages natural language processing to automate reverse engineering tasks across various file formats, including APKs, firmware, and executable binaries. Users can query the agent directly for insights, bypassing manual command inputs, while it dynamically assembles the necessary tools for tasks like unpacking, disassembly, and reporting findings. Notable features include support for Android and automotive firmware analysis, as well as a unified interface for interacting with different artifact types through a single command.
12 Aug 2026
C++
★ 23
ALPC Enumerator is a Windows userland tool designed to enumerate and classify Advanced Local Procedure Call (ALPC) ports, including those associated with Protected Process Light (PPL) processes that evade standard enumeration techniques. It dynamically resolves ALPC Port types and employs `NtQueryInformationProcess` for classification, addressing blind spots in conventional tools, thereby benefiting threat hunters and vulnerability researchers by accurately mapping high-privilege targets and identifying potentially malicious activity. Notably, it has been validated against kernel debugger output for precision and reliability.
12 Aug 2026
Python
★ 10
AIDebug is a command-line interface and terminal UI tool designed for malware reverse engineering, emphasizing evidence collection and analysis. Its primary use case involves deterministic offline triage of PE and ELF files, whole-file hex inspection, and in-depth structure analysis with features such as Ghidra-backed reconstruction and local ELF debugging, while also offering optional integration with large language models for enhanced review capabilities. Notable functionalities include paged hex viewing, customizable output formats for analyst reviews, and a robust history tracking system for SHA-256 indexed analyses.
12 Aug 2026
Python
★ 11
The Spiderfoot-local-data-module enhances the Spiderfoot reconnaissance tool by enabling it to search through locally stored databases for leaked and breached data. It allows users to specify the full paths of datasets and automatically scans for relevant information during Spiderfoot operations, reporting any findings with file names and content. Notable features include support for multiple data files and the ability to configure what types of data to search for, with potential performance improvements suggested through integration with tools like ripgrep.
12 Aug 2026
Python
★ 11
GHOST is an AI-powered OSINT investigation platform designed for automated intelligence gathering using various data vectors such as names, emails, and images. It offers notable features like AI-driven correlation, extensive reporting capabilities in HTML/PDF formats, and a web dashboard with graphical representations of data, enabling users to conduct thorough investigations efficiently. GHOST supports multiple platforms and provides tools for dark web monitoring, social media analysis, and entity resolution, all while being open source and cost-free.
12 Aug 2026
Python
★ 27
The FLOSS Toolbox is a multi-language utility designed to assist developers in maintaining clean projects within GitHub organizations. It features a variety of scripts for automating tasks such as data scraping from Git logs, interfacing with GitHub and GitLab APIs, managing license inventories, and generating documentation. The primary use case is to enhance code quality and streamline project management through efficient file processing and automation using Shell, Ruby, Python, and PHP.
12 Aug 2026
Go
★ 45
deps.cloud is a dependency management tool designed to analyze and provide insights into the libraries and projects utilized within a software system by extracting data from common manifest files such as `pom.xml`, `package.json`, and `go.mod`. Its primary use case includes answering specific dependency-related queries, such as identifying library versions and tracking open-source library usage across projects. Notable features include comprehensive dependency detection, a supportive community for development, and various workflows for project maintenance, although the project is currently in maintenance mode due to low community engagement.
12 Aug 2026
Python
★ 123
findcdn is a Python-based tool designed to scan domains to identify the Content Distribution Network (CDN) they utilize. Its primary use case includes providing actionable insights regarding CDN usage for security assessments or operational purposes, with features that allow output to files, invocation as a module, and customizable processing options such as threading and user-agent specification. The tool supports multiple domains and offers verbose output for enhanced monitoring and analysis.
12 Aug 2026
TypeScript
★ 39
Omnichron is a TypeScript library that provides a unified interface for querying multiple web archive providers, including the Wayback Machine, Archive.today, and Common Crawl. Its key features include lazy loading of providers, built-in caching, support for parallel queries, and comprehensive TypeScript type definitions. This tool is particularly useful for developers needing consistent access to various web archive data with enhanced performance and configurability.
12 Aug 2026
TypeScript
★ 11
Pulse Intelligence is an open-source, self-hosted threat intelligence platform that facilitates analyst workflows by enabling the tracking of threat actors, indicators, vulnerabilities, and campaigns from a unified interface. Its notable features include integration with various public threat feeds, automated enrichment of indicators, and the ability to conduct and export threat hunts, along with the generation of scheduled reports and a scoped API for programmatic access. The platform is designed to support the operational needs of junior Cyber Threat Intelligence teams through a comprehensive workspace solution.
12 Aug 2026
TypeScript
★ 22
Arina-OSINT is a console-based OSINT tool designed for checking the availability of usernames across 56 popular online platforms and services. It enables users to uncover forgotten or old profiles, as well as trace the digital footprint of a nickname by sending direct requests to various services to ascertain account existence based on HTTP response statuses and content markers. Notably, it maintains a 1:1 behavior porting from its original C# (.NET Core) implementation to TypeScript/Node.js, ensuring consistent functionality.
12 Aug 2026
Go
★ 25
Siren is a desktop operator workbench designed for the Sliver C2 framework, enabling offensive security professionals to manage and execute operations within a native application environment. Notable features include comprehensive agent management with real-time session control, robust server management capabilities, and an integrated automation system for executing scripts and rules. The tool emphasizes user-friendly interaction through a customizable interface, command palettes, and extensive file manipulation functionalities for effective tactical operations.
12 Aug 2026
TypeScript
★ 17
SecTester is a developer-centric Dynamic Application Security Testing (DAST) scanner that integrates an enterprise-grade scanning engine directly into unit tests. Its primary use case is to allow developers to conduct security scans at the speed of unit tests, enabling the detection of vulnerabilities without false positives prior to finalizing pull requests. Notable features include seamless integration into continuous integration workflows and the capability to test individual functions and components.
12 Aug 2026
Go
★ 71
`blackstork-cli` is a source-available, headless execution engine designed for automating cybersecurity and compliance reporting through the use of BlackStork templates. It facilitates the extraction of structured data from various external tools, evaluates template logic, and renders formatted documents, enabling engineers to version control their reporting workflows and execute them locally or within CI/CD pipelines. Notable features include modular design for data querying and content drafting, extensive plugin support for integration with external APIs and services, and a library of production-ready templates for diverse cybersecurity applications.
12 Aug 2026
Rust
★ 13
Black Hat Tools is a repository designed for developing asynchronous and concurrent software for security applications using languages such as TypeScript, Go, Rust, and Python. The primary use case involves executing network-based tests and exercises derived from well-known cybersecurity literature, with notable features including integration with specific testing domains for practical application. This tool is still a work in progress, reflecting ongoing development in its functionality.
12 Aug 2026
Python
★ 18
Web of Flaws is a Markdown-based catalog that identifies vulnerable web patterns alongside safer alternatives, aimed at both developers and automated tools. Its primary use case is to educate users on exploitable vulnerabilities and provide concrete code examples for remediation, organized by security topics and vulnerability families. Notable features include detailed guides that explain risky patterns and their fix implementations.
12 Aug 2026
Shell
★ 14
mxhelp is a pentesting toolkit designed to streamline the use of various scripts by automatically populating IP and target addresses into pre-defined "cheatsheets." Its notable features include easy addition of new scripts, real-time updates using the 'sed' command to prevent errors, and a simple alias system for efficient command execution. By simplifying the process of managing pentesting scripts, mxhelp enhances the workflow for security professionals.
12 Aug 2026
C
★ 943
GhostESP is an open-source wireless research platform that transforms an affordable ESP32 board into a multifunctional wireless tool with a user-friendly touchscreen interface. Its primary use case includes advanced wireless monitoring, firmware updates, and network analysis, featuring capabilities such as on-device firmware management, a cloud app store, and robust scripting support via GhostScript. Notable enhancements in version 2.x include expanded NFC functionalities, efficient Wi-Fi attack and monitoring tools, and improved user interface performance with a focus on accessibility and multitasking.
11 Aug 2026
Perth is a robust Python library designed for audio watermarking and detection, capable of embedding imperceptible watermarks that can withstand various audio transformations. It features multiple watermarking techniques, including a neural network-based approach known as Perth-Net, and offers both a command-line interface and a comprehensive Python API for seamless integration and usability. The library also includes tools for evaluating the perceptual quality of watermarked audio, ensuring that watermarks remain resilient while maintaining high audio fidelity.
11 Aug 2026
MUDRammer is a modern MUD (Multi-User Dungeon) client designed for iPhone and iPad, prioritizing speed, accessibility, and flexibility. It allows users to connect to various online text-based multiplayer games, offering a `DefaultWorlds.plist` with pre-configured MUDs while enabling users to customize their experience. Notable features include easy installation via RubyGems and CocoaPods, comprehensive rake tasks for development, and a focus on user-friendly interactions within diverse fantasy, sci-fi, and horror game worlds.
11 Aug 2026
Awesome MUD is a curated repository that serves as a comprehensive resource for developers of text-based games, particularly Multi-User Dungeons (MUDs). It encompasses a variety of tools, clients, codebases, and tutorials, facilitating rapid development and engagement within the MUD community. Notable features include a categorized directory of MUD clients and engines, as well as guidelines for contributions to expand the resource base.
11 Aug 2026
Rune is a modern MUD client developed in Go and Lua, offering high performance and flexibility for scripting. Its primary use case is to enhance the user experience in multi-user dungeon games through features like command aliases, triggers, and robust scripting capabilities, while supporting structured data protocols such as GMCP and TLS for secure connections. Notable features include customizable key bindings, session logging, pane management, and rich scripting tools that enable users to automate and personalize their gameplay effectively.
11 Aug 2026
Python
★ 27
Precli is a command line interface designed for performing static code analysis on source code, primarily focusing on detecting vulnerabilities within the standard library of various programming languages. Its capabilities include predefined rules for analysis, and it offers an upgrade option to Precaution Professional for deeper inspection of third-party libraries. Notable features include easy installation via pip, and the ability to analyze specific code examples for potential security risks.
11 Aug 2026
Rust
★ 42
Generate random passphrases