> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

cyclonedx-core-java

CycloneDX Core (Java) is a library that provides a model representation of Software Bills of Materials (SBOMs) and utilities for creating, validating, and parsing them. It supports multiple output formats, including XML and JSON, and is designed for use in application security contexts and supply chain component analysis, adhering to the CycloneDX specification. Notable features include compatibility with various versions of the CycloneDX schema, offering users versatile options for handling SBOMs.

cyclonedx-core-java

CycloneDX Core (Java) provides a comprehensive model representation of Software Bill of Materials (SBOM) and includes utilities for creating, validating, and parsing SBOMs. Designed for enhancing supply chain security, this library supports multiple output formats (XML and JSON) and adheres to the CycloneDX schema, facilitating interoperability within the ecosystem. Notable features include compatibility with various schema versions and a straightforward integration process via Maven.

cloudmapper

CloudMapper is a tool designed for analyzing and auditing Amazon Web Services (AWS) environments, focusing on identifying potential security misconfigurations and generating detailed reports. It includes commands for metadata collection, identifying admin users, finding unused resources, and generating HTML reports summarizing IAM and account details. Notably, it features functionality for continuous auditing and can highlight public hosts and trusted CIDR information within Security Groups.

bug-hunter

Bug Hunter is an advanced AI-driven skill designed for code review and security auditing, providing a structured approach to identifying potential bugs through a triage system with Hunter, Skeptic, and Referee roles. Its primary use case lies in performing detailed scans of code repositories with an emphasis on maintaining control over modifications, as editing and automatic fixes require explicit authorization. Notable features include a scan-only default mode, seamless integration with various AI coding agents, and a natural language interface for ease of use.

Alpine

Alpine is a scaffolding library designed for Java projects that emphasizes an API-first architecture with secure defaults and minimal dependencies. It facilitates the development of thin server architectures, ideal for client-side rendered web applications and mobile back-ends, by leveraging REST and JSON Web Tokens (JWT) for authentication while providing a simplified event system and flexible persistence options. Notable features include robust authentication support, a secure API by default, and a focus on maintaining developer control over application architecture.

Alpine

Alpine is an opinionated scaffolding library designed to facilitate the rapid development of Java projects with an API-first architecture, targeting server-side applications that predominantly provide JSON for client-side rendered web apps and mobile back-ends. Key features include secure defaults with authentication support (using JWT, LDAP, and API keys), a simplified event system for asynchronous processing, and a minimal dependency footprint to reduce the potential attack surface of applications. Additionally, Alpine emphasizes developer control while offering streamlined standards-based APIs to enhance productivity.

vcr

The Vulnerability Compliance Report Tool converts Nessus scan files into formatted HTML reports, tailored for security professionals, auditors, and pentesters. It supports parsing Basic Network and CIS Benchmark scans for various Windows operating systems, enabling users to visually present vulnerability data in a structured and accessible manner. Notable features include a user-friendly dashboard, IP and vulnerability-focused navigation, and customizable templates for report generation.

pentest-reporting-resources

Cyver Core Pentest Reporting Resources provides a streamlined platform for penetration testers to create efficient and high-quality reports by offering various report templates, compliance norms, and checklists. The tool supports Markdown and Excel formats to facilitate easy uploading and customization, covering a wide range of compliance standards such as OWASP, PCI DSS, and ISO27001. Notably, it includes a comprehensive collection of resources that enhance the reporting process by integrating established frameworks and best practices.

kuberay

KubeRay is an open-source Kubernetes operator that facilitates the deployment and management of Ray applications within Kubernetes environments. It features core components such as RayCluster for lifecycle management, RayJob for job execution with automated cluster management, and RayService for high availability and zero-downtime upgrades. Additionally, it offers community-managed components like a Python client and a CLI for streamlined resource management.

grype

Grype is a vulnerability scanner designed for container images and filesystems, allowing users to detect known security issues across various OS package ecosystems and language-specific packages. Notable features include support for multiple image formats such as Docker and OCI, threat prioritization mechanisms like EPSS and KEV, and enhanced scanning capabilities through OpenVEX integration. It streamlines the vulnerability assessment process for developers and security teams by enabling quick scans of container images and SBOMs.

duckdb

DuckDB is a high-performance analytical database system optimized for speed and ease of use, offering a robust SQL dialect that extends beyond basic functionality with support for complex queries, window functions, and advanced data types. Its versatility is highlighted by compatibility with multiple programming environments including CLI, Python, R, and Java, and deep integrations with data manipulation libraries like pandas and dplyr. Notable features include efficient data import from formats such as CSV and Parquet and accessibility through comprehensive documentation and user support.

cyclonedx-cli

The CycloneDX CLI tool facilitates the management of Bill of Materials (BOM) by enabling users to analyze, modify, convert, sign, and verify BOM files across various formats including XML, JSON, CSV, and SPDX. It supports automation through options for input/output via stdin/stdout and includes commands for tasks such as diffing and merging BOMs. Notable features include extensive file handling capabilities and support for generating RSA key pairs for secure BOM signing.

teep

Teep is a local proxy tool designed to enhance privacy when interacting with AI providers by ensuring that user prompts remain unreadable to the service provider and any third parties. It achieves this by verifying the authenticity of the hardware running the AI model and encrypting the conversation, only allowing the secure environment to decrypt the messages. Notable features include support for multiple AI providers, robust attestation mechanisms, and seamless integration with any OpenAI-compatible application.

rabid

RABID is a command-line interface tool and library designed for the rapid decoding of various BigIP cookie formats. It supports all four standard cookie formats, making it a versatile option for cybersecurity professionals dealing with BigIP environments, and is designed to be extendable for advanced use cases. Notable features include its hackable nature and comprehensive support for BigIP cookies.

crypt.fyi

crypt.fyi is a secure, zero-knowledge secret sharing platform that employs end-to-end encryption and ML-KEM post-quantum cryptography for the safe transmission of sensitive data. Its notable features include strict content security policies, rate limiting, automatic expiration of secrets, optional password protection, and drag-and-drop file sharing, along with webhook notifications and extensive internationalization support. The architecture ensures that the server never accesses unencrypted data, reinforcing user privacy and data integrity.

vps-audit

The VPS Security Audit Script is a Bash tool designed for thoroughly auditing the security and performance of Ubuntu/Debian-based Virtual Private Servers. It conducts a variety of security checks such as SSH configuration, firewall status, and intrusion prevention settings, while also monitoring system performance metrics like CPU and memory usage. Notably, it provides real-time feedback with color-coded outputs indicating pass, warn, or fail statuses, and generates a comprehensive report with recommendations for improving the server's security and performance.

vaulytica

Vaulytica is a deterministic contract checker that operates entirely within the user's browser, providing a linting solution for legal documents without the need for authentication or external servers. It applies over 1,100 deterministic rules and performs extensive cross-document checks, generating reproducible reports in multiple formats, including DOCX and JSON, while ensuring compliance with specific legal standards through well-defined sources. Notably, Vaulytica offers a transparent process where the output is byte-identical for the same input and environment, enabling users to easily cite results and maintain a verifiable auditing trail.

Malware2.0Database

Malware2.0Database is a repository designed to catalog and archive various malware samples for educational purposes. Its primary use case is to provide researchers and security professionals with access to an up-to-date collection of malware, facilitating the study of malware behavior and trends. Notable features include an organized system for uploading new malware strains while archiving older versions.

Malware-Sandbox-mcp

Malware-Sandbox-mcp is a cloud-based tool designed to detonate suspicious files and URLs within multiple third-party malware sandboxes, providing normalized reports with threat intelligence data such as verdicts, indicators of compromise (IOCs), and MITRE ATT&CK techniques. It offers a streamlined asynchronous submission and polling mechanism, allowing users to efficiently manage and analyze malware reports while integrating with nine backend services and twenty analytical tools. Key features include a uniform report schema, customizable API key management for backends, and safety mechanisms to prevent exposure of sensitive data.

opendw

OpenDW is an open-source reimplementation of the online game Deepworld, originally designed for MacOS and iOS. Its primary use case is to allow users to build and run the game on different platforms using the Axmol Engine, although it does not aim for 100% accuracy compared to the original due to engine and platform differences. Notable features include compatibility with a separate server, build instructions for Windows, and a customizable asset framework, requiring users to provide their own game assets.

octabam

Octabam is a tool designed for creating custom digital signal processing (DSP) effects for the Elektron Octatrack MKII, allowing users to replace stock effects with original assembly-coded algorithms. The primary use case revolves around enabling a shared mixing bus for effects, allowing multiple tracks to feed into a single reverb and delay, features that were previously unavailable in the stock firmware. Notable capabilities include the ChonVerb, a versatile reverb effect with multiple modes and modulated taps, as well as the potential for a delay that interfaces with the reverb, all while providing comprehensive build and testing tools to ensure reliability without risking hardware integrity.

sleigh

The Sleigh library is a specialized tool for defining the semantics of instruction sets of general-purpose microprocessors, primarily used in the reverse engineering of compiled software. It serves as a component of the Ghidra reverse engineering platform, facilitating disassembly and decompilation processes. Notable features include a CMake-based build system for standalone usage, support for multiple operating systems, and an included example tool (`sleigh-lift`) for disassembling bytecode or lifting it to p-code.

sba

SBA (Scalable Binary Analysis Framework) is a comprehensive binary analysis tool designed to perform high-fidelity static analysis on ELF, PE, and Mach-O executable formats through a robust, architecture-agnostic disassembler. Its notable features include a ControlFlowGraphAPI for diverse graph construction, an efficient AnalysisAPI incorporating forward and backward dataflow analysis, and a pre-disassembly method that processes raw binary data efficiently, allowing for scalable analysis without the limitations of traditional disassembly. The framework's applications encompass advanced jump table analysis and function property checks, enhancing the robustness and accuracy of binary analysis tasks.

rfvp

rfvp is a non-official Rust-based cross-platform implementation of the FVP engine and IDE, enabling users to run and debug games while also functioning as an operating system with UEFI support. Notable features include the ability to use custom fonts, support for different text encodings for translated games, and platform-specific installation guides across major operating systems. Additionally, rfvp offers a debug HUD and the potential to develop applications based on the engine, thus enhancing its versatility.

openswx

Openswx is a cross-platform toolkit designed to read SolidWorks files (.SLDPRT, .SLDASM, .SLDDRW) without requiring a SolidWorks installation or any Windows dependencies. It features a C++20 library for file parsing and BOM (Bill of Materials) generation, alongside an HTTP server and CLI tools for metadata browsing and JSON output, making it suitable for applications needing SolidWorks data access in non-Windows environments. Notable features include comprehensive document property extraction, component path resolution, and a user-friendly web interface for metadata interaction.