> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

niimbluelib

NiimBlueLib is an open-source library designed for communicating with NIIMBOT printers, providing an accurate implementation of the associated protocol. Primarily used within the NiimBlue project, it is currently in an Alpha state, meaning the API is subject to change and should be used in exact versions. Noteworthy features include seamless integration via NPM and CDN, as well as support for CLI use cases through related packages.

GM2Godot

GM2Godot is a conversion tool designed to facilitate the migration of GameMaker LTS 2026 source projects to Godot 4.7.1, utilizing both a graphical user interface and a headless command line interface. Key features include GML transpilation into GDScript, comprehensive diagnostics and compatibility reporting, and support for multiple platform settings, along with a robust asset conversion process for various GameMaker resources. The tool also incorporates customizable conversion options and detailed validation processes, ensuring a reliable transition while preserving project integrity.

dotscope

dotscope is a high-performance, cross-platform framework designed for the analysis, reverse engineering, and modification of .NET PE executables, implemented in pure Rust. It offers features such as efficient memory access, comprehensive metadata analysis, assembly modification capabilities, and a full bytecode interpreter, allowing users to manipulate CIL bytecode and structure without dependence on Windows or the .NET runtime. Additionally, it incorporates advanced functionalities like deobfuscation and static analysis, making it a versatile tool for .NET developers and security researchers.

Auto-Android-App-Modding-Tool

UAMT (Ultimate Auto Android App Modding Toolkit) is a Termux-based toolkit for modifying Android APKs without requiring root access. Its primary use case includes injecting Frida Gadget and custom native libraries, alongside features such as a full APK rebuild pipeline, smart detection of injection methods, and an interactive TUI for user-friendly operation. Notable functionalities include automatic dependency management, safe modding practices, and optimized performance for Android security research and reverse engineering tasks.

anya

Anya is a fast, offline static malware analysis platform that processes a wide variety of file formats, including PE, ELF, PDF, and Office documents, without executing them. Key features include high-speed analysis of over 250 files per minute, detailed output such as hashes, entropy, and risk scores, while offering integration with MITRE ATT&CK mappings and support for both GUI and CLI interfaces across multiple operating systems. It should be noted that Anya is transitioning its development to the MalChela project for future enhancements.

Academia-Tehnica-Militara

Acest repository oferă un curs amplu despre analiza malware-ului, combinând concepte teoretice și metode practice pentru investigarea și contracararea amenințărilor informatice. Structurat în module, cursul acoperă subiecte precum tipologiile malware-ului, ingineria inversă, tehnici de detecție și analize comportamentale, dotând participanții cu abilitățile necesare pentru a înțelege și a combate atacurile cibernetice. Notabilele sale caracteristici includ discuții despre criptografie, tehnici avansate de analiză, utilizarea instrumentelor specializate și o privire detaliată asupra strategiilor de infecție și persistență.

cors

cors is a CORS misconfiguration scanner designed to identify vulnerabilities in web applications related to Cross-Origin Resource Sharing. Its primary use case includes scanning single URLs or multiple URLs from a file, with capabilities for specifying output files and concurrent scanning threads to enhance efficiency. Notable features include detailed vulnerability reporting, flexible usage options for various scanning scenarios, and easy installation on Linux systems.

go-dependency-scanner

Educational dependency scanner built in pure Go—parse go.mod and go.sum, inspect direct and indirect modules, query OSV for vulnerabilities, and summarize licenses.

surveillance-capabilities-map

The Surveillance Capabilities Map is an interactive visualization tool that maps police surveillance capabilities across the United States, aggregating data from various authoritative sources, including the EFF Atlas of Surveillance and federal contracts. Key features include technology filtering across 19 surveillance categories, a search function by location or agency, and the ability to export raw data in CSV format. Additionally, users can visualize FBI and DHS aircraft flight paths, enhancing the understanding of surveillance operations at specific locales.

SeeYou

SeeYou is a comprehensive real-time global intelligence platform that visualizes live data from over 25 public APIs on a dynamic 3D globe built with CesiumJS. Its primary use case includes tracking and analyzing diverse phenomena such as aircraft, satellites, earthquakes, wildfires, and cyber threats, with advanced features like military-grade shaders, predictive modeling for aircraft trajectories, and a wide array of intelligence layers. The platform operates entirely locally, requires no paid services, and offers multiple live data overlays to provide an integrated view of various global events and activities.

ai-smart-contract-auditor

AuditSentry is an AI-powered smart contract auditor designed for analyzing Solidity and Vyper contracts across EVM chains. It leverages 23 specialized AI agents to conduct in-depth security assessments, providing detection of critical vulnerabilities, working exploit proof-of-concepts, and gas profiling, all formatted into professional audit reports within minutes. Notable features include mainnet-fork simulations and on-chain certificates, enhancing both accuracy and trust in the audit process.

Rein-Ai

Rein is a Python library designed to serve as a runtime governor for autonomous AI agents, ensuring their actions are monitored and controlled based on real-time performance rather than just adhering to content guidelines. It features capabilities such as regime classification, Bayesian scoring of actions, a tamper-evident audit log, and a natural-language policy compiler, making it suitable for scenarios where costly or harmful actions could occur without adequate oversight. Rein is framework-agnostic, compatible with various AI platforms, and is particularly valuable in environments requiring dynamic decision-making under uncertainty.

Claude-Pentest-Skills

Claude Pentest Skills is a specialized tool designed for structuring and automating penetration testing workflows within the Claude Code LLM environment. It features modular skill packs that provide comprehensive Active Directory reconnaissance, exploitation, and post-exploitation processes, along with robust functionalities such as checkpointing, parallel execution, and cross-platform support. Notable functionalities include automated evidence capture, JSON reporting, and seamless integration with multiple external tools for enhanced penetration testing efficacy.

sherlock-rs

Sherlock-rs is a Rust-based tool designed to hunt down social media accounts by a specified username across over 400 social networks. It provides features such as outputting results to text, CSV, or Excel files, supports proxy usage, customizable site analysis, and extensive debugging options, making it ideal for users needing comprehensive username availability checks across multiple platforms.

mflux

MFLUX is a machine learning tool designed to run advanced generative image models locally on Mac systems using the MLX framework. Its primary use case is to facilitate the creation of high-quality images from textual prompts through a command-line interface, featuring multiple state-of-the-art models implemented specifically for MLX. Notable features include the ability to customize image generation parameters, a minimalistic design for ease of use, and integration with the Hugging Face ecosystem for model acquisition and management.

ableton-mcp

AbletonMCP is a tool that facilitates a connection between Ableton Live and Claude AI using the Model Context Protocol (MCP). Its primary use case is to enable users to control and manipulate music production processes in Ableton Live through natural language prompts, allowing for actions such as track manipulation, clip creation, and composition of full arrangements. Notable features include real-time two-way communication, session control, and full integration with devices and instruments in Ableton, streamlining music creation and arrangement workflows.

PaCMAP

PaCMAP (Pairwise Controlled Manifold Approximation) is a dimensionality reduction tool designed to enhance data visualization by simultaneously preserving both local and global structures. It utilizes a unique approach that incorporates three types of point pairs during the embedding optimization process, allowing for effective handling of various dataset characteristics while providing improved speed and scalability through GPU support with PyTorch. Notable features include its dynamic handling of mid-near pairs to refine the representation of data clusters, setting it apart from traditional DR methods.

assistant-axis

The Assistant Axis is a tool designed to monitor, steer, and mitigate persona drift in large language models, particularly when they deviate from a default "helpful Assistant" persona during interactions. By projecting model activations onto the Assistant Axis, it enables real-time assessment of a model's adherence to desired behaviors and offers mechanisms to cap activations, thereby preventing harmful outputs. Notable features include interactive analysis notebooks, pre-computed persona vectors for popular models, and capabilities for detailed visualization of persona trajectories.

C1ZX

C1ZX is a professional dual-table Unicode substitution cipher tool that uses two independent substitution tables to encrypt printable ASCII characters, enhancing security by reducing simple repetition patterns. It features fully reversible encryption, extensive validation, automated self-testing, and supports terminal Unicode compatibility detection, making it robust for various platforms including Windows, Linux, and macOS.

U92

U92 is a specialized steganography tool that facilitates the embedding of files and directories into PNG images utilizing a Least Significant Bit (LSB) embedding method. It features continuous bitstream processing, integrated archive management for ZIP file creation, and robust integrity validation processes, ensuring accurate data recovery and minimal visual distortion during extraction. The utility supports command-line interaction for easy file embedding and extraction, making it a versatile solution for secure data concealment.

zombie

Zombie is a lightweight service password brute-forcing tool that integrates command-line design inspired by Hydra and dictionary generation capabilities like Hashcat, tailored for red team operations. Its notable features include support for various protocols (e.g., SSH, MySQL, MSSQL), customizable password generation, and the ability to perform targeted brute-forcing based on user-specified input files. This makes it a versatile solution for security assessments and penetration testing involving credential brute-forcing.

Ubuntu-Security-Hardening-Script

The Ubuntu Security Hardening Script automates the hardening of Ubuntu servers across various subsystems, including SSH, kernel settings, and firewall configurations, ensuring compliance with CIS benchmarks. It features comprehensive safety checks, automatic backups, and detailed reporting, while supporting the latest Ubuntu versions and incorporating advanced security mechanisms such as post-quantum SSH. The tool is designed for repeatability, preserving custom configurations on re-runs, making it suitable for production environments.

trivy-operator-dashboard

The Trivy Operator Dashboard is a security management tool designed for Kubernetes environments, offering comprehensive insights into security posture through detailed reporting on vulnerabilities, policy validation, and compliance assessments. Notable features include user-friendly dashboards for various security reports, including vulnerability and cluster assessments, with capabilities for data export and inspection. The tool aims to streamline security monitoring and response, prioritizing simplicity in its core functionality while considering future enhancements based on community demand.

templates

The chainreactors/templates repository provides a unified set of templates for various cybersecurity tools including gogo, spray, zombie, and found, facilitating consistent configurations and rules. Notable features include a template generator for packaging YAML and rules into embedded binary data, multiple fingerprinting and vulnerability detection rules, and configurable extraction rules for sensitive data retrieval. This tool is designed to streamline the setup and integration of various security artifacts across the chainreactors ecosystem.

SafeIP

SafeIP is a lightweight web application designed for network security validation, which checks the user's current IP location against a manually selected country to identify potential security risks before accessing sensitive services online. Notable features include real-time IP detection, safety status indicators, a quick link manager with client-side validation, and persistent settings using LocalStorage, ensuring a user-friendly experience while maintaining a focus on security.