> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

project-rvbbit

RVBBIT is an educational proof-of-concept tool for researching Linux kernel rootkits, focusing on how they obscure the actual kernel state from userspace observations. It implements various rootkit techniques, including process and module hiding, syscall interception, and manipulation of filesystem and network visibility, all aimed at understanding these evasion methods in a controlled environment. Notably, the tool is designed strictly for research and education, lacking functional capabilities for exploitation or propagation.

ShadowPDF

ShadowPDF is a lightweight, privacy-focused tool that enables users to extract text from PDF documents directly in their browser without any data leakage risks. Its notable features include 100% offline processing, multi-format export options (Plain Text, Markdown, HTML), and a user-friendly drag-and-drop interface, making it ideal for developers and security-conscious individuals seeking efficient document conversions.

xorcise

XORCISE is a cybersecurity tool designed to run AI agents against real-world missions in a controlled environment, monitoring and grading their actions through detailed evidence collection. It utilizes OpenTelemetry for real-time tracking of commands and actions while providing a scoring system based on pre-defined mission criteria. Notably, XORCISE supports various AI models and generates comprehensive reports, allowing users to evaluate and compare the performance of different agents in a secure, isolated network.

github-vps

GitHub-VPS enables developers and security professionals to utilize GitHub Codespaces as a portable virtual private server (VPS), facilitating remote coding environments tailored for penetration testing and CTF challenges. It features high-performance configurations with varying CPU and RAM options, and supports Docker integration for deploying Kali Linux in both headless and GUI modes, allowing flexibility in tool usage depending on the user's needs.

credential-detector

Credential-Detector is a command-line tool designed to scan project files for hard-coded credentials, including passwords, API keys, and private keys that may have been inadvertently embedded in source code. It supports multiple file types, such as Go, JSON, YAML, and various others, and offers highly configurable scanning options to identify suspicious patterns and variable names while excluding obvious test data. Additionally, it features a web application for enhanced usability and can be integrated as a library within other Go applications.

Auto-IDOR

IDOR-Auto is an advanced testing tool designed specifically to identify Broken Object-Level Authorization (BOLA) or Insecure Direct Object Reference (IDOR) vulnerabilities by employing differential access testing rather than relying on simple HTTP status codes. It distinguishes itself by utilizing multiple identity responses to determine if one user can access another user's data, while effectively minimizing false positives through robust response comparison, identifier analysis, and support for various input formats. Key features include canary detection, injection point flexibility, identification of encoded IDs, method tampering, and direct raw request importation, making it suitable for authorized security testing in penetration tests and bug bounties.

ableton-mcp

AbletonMCP enables integration between Ableton Live and Claude AI using the Model Context Protocol (MCP), facilitating direct, real-time control over music production tasks via natural language commands. Key features include two-way communication allowing track manipulation, instrument and effect loading, clip creation, and full arrangement composition, thereby streamlining the music composition process. The tool consists of an Ableton Remote Script and an MCP Server, which interact through a local TCP socket to execute user commands efficiently.

chatterbox

Chatterbox is an advanced open-source text-to-speech (TTS) suite developed by Resemble AI, featuring multilingual capabilities with its latest release, Chatterbox Multilingual V3. This model improves speaker similarity and reduces hallucinations, providing high-quality, natural speech across multiple languages, while additional variations like Chatterbox-Turbo and Chatterbox-Nano offer low-latency performance and resource-efficient options for on-device deployment. Notable features include dedicated single-language packs for specialized language performance and native support for paralinguistic tags, enhancing realism in speech generation.

DawDreamer

DawDreamer is a Python-based digital audio workstation (DAW) framework designed for audio processing, enabling the creation of multi-channel audio graphs with various processing options. It supports real-time audio playback, VST plugin integration, MIDI manipulation, and advanced audio manipulation features like time-stretching, looping, and pitch-warping, all wrapped in an accessible user interface built on the JUCE framework. Notable capabilities include parameter automation, multiprocessing support, and compatibility across major platforms, making it a versatile tool for audio engineers and developers alike.

curl

curl is a versatile command-line tool designed for transferring data to and from servers using a wide array of protocols, including HTTP, FTP, and SMTP, among others. Its primary use case is for developers and system administrators to facilitate data retrieval and transmission in scripting and automation environments. Notable features include support for numerous protocols, the ability to work with both secure and unsecure connections, and the integration of libcurl for embedding functionality within applications.

vulnapi

VulnAPI is an open-source dynamic application security testing (DAST) tool tailored for scanning APIs to identify common security vulnerabilities. It features a command-line interface (CLI) that allows users to discover API details and execute scans using either a curl-like syntax or OpenAPI contracts, delivering comprehensive reports on detected vulnerabilities. Notable functionalities include detailed output reports, integration with OpenAPI specifications for scanning, and the ability to leverage the discover command for gaining insights into target APIs.

RollCall-FlipperZero

RollCall is a tool for assessing the security of key fobs and garage remote controls by distinguishing between rolling code and static code protocols. It captures and analyzes the signal from the remote to confirm if the code changes with each press, providing health grades to indicate the security status. Notable features include its ability to fingerprint each press without additional hardware and a "Find My Remote" function to identify the frequency of unresponsive remotes.

zed

Zed is a command-line client for managing SpiceDB, designed to streamline permission and relationship handling within applications. It offers robust features including secure context switching, a variety of commands for permissions and relationships, comprehensive schema management, and backup/restore capabilities, making it suitable for scalable access control solutions.

integrated-security-testing-environment

ISTE (Integrated Security Testing Environment) is a comprehensive Burp extension designed to streamline the security testing process for web applications. It offers features such as URL management, note-taking linked to raw logs, progress tracking, and advanced functionalities like repeat request customization and authentication flow handling. Notable capabilities include a request chain management system that automates the execution of multiple requests in sequence, enhancing efficiency in testing scenarios while reducing the complexity of maintaining parameter consistency.

deidentify

Deidentify is a Go library designed to detect and remove personally identifiable information (PII) from both text and structured data, employing deterministic algorithms that maintain referential integrity. Key features include support for multiple PII types (such as emails, phone numbers, and SSNs), format preservation for usability, context-aware processing, and thread safety for concurrent applications. This tool is particularly useful for organizations requiring data anonymization while retaining original data structure and format.

ARES-Spoofer-Byfron

ARES-RS is a Rust-based Roblox spoofer designed to protect user accounts from Byfron's detection and Roblox's ban system by modifying hardware identifiers (HWIDs). It features extensive configurability, automatic updates, and enhanced error handling, allowing users to execute spoofing operations either manually or automatically upon closing the Roblox application. Notable capabilities include spoofing BIOS, motherboard, and various hardware components, with recommendations for optimal use alongside a VPN.

Analyst-Tool

The Analyst-Tool is a Python-based scripting tool designed to automate digital investigation and intelligence gathering across various indicators such as domains, URLs, IP addresses, and hashes. Notable features include concurrent lookups from multiple security services, result caching for efficient API usage, multi-user tracking, and the ability to annotate and tag indicators for collaborative work. The tool emphasizes passive data retrieval, ensuring that no new data is added to the monitored services during investigations.

apotrope

Apotrope is a portable Windows security posture auditing tool that performs a comprehensive assessment of Windows systems against CIS Microsoft Windows Benchmarks, providing a score from 0 to 100 along with detailed remediation recommendations. It operates as a standalone executable or via pip installation, requiring no network connection or user account for operation, and it returns results in both terminal output and self-contained HTML reports. With over 50 audit controls across 14 categories, Apotrope distinguishes itself by being read-only, user-friendly, and capable of generating actionable PowerShell commands for each identified issue.

PE-pal

PE-pal is a web-based Portable Executable (PE) file analysis tool that translates the internal structure of Windows executables into a user-friendly format, making it accessible for beginners. It features entropy analysis to detect anomalies, classification of imported functions, and string flagging for suspicious elements, all while ensuring that file processing occurs locally in the user's browser for privacy. Notably, PE-pal does not function as a virus scanner but provides insights into the file's behavior and characteristics.

HydraDragonAV-Mobile

HydraDragonAV Mobile is an advanced Android antivirus solution designed to provide comprehensive threat protection through a multi-layered security architecture. It utilizes static and dynamic analysis techniques, including YARA-X and ClamAV signatures, alongside a lightweight machine learning classifier for real-time detection of malware, ransomware, and other threats. Key features include a high-speed scanning engine, native Rust implementation for efficiency, and a Zero-Trust approach to ensure that known-good applications are exempt from false positives.

pocket-libre

Pocket Libre is a tool designed to replace the vendor app for the Pocket AI voice recorder, allowing users to extract recordings locally via Bluetooth. It features local transcription using Whisper, speaker identification, and optional summarization through API calls, ensuring that user audio data remains on their personal devices. The tool operates without reliance on cloud services and offers a web interface for managing recordings and transcripts, enhancing control over audio processing and data privacy.

morphe-patches

hxreborn Patches provides a collection of modifications for Android applications built upon the Morphe framework. Its primary use case is to enhance user experience by implementing features such as hiding upgrade prompts, enabling custom themes, and unlocking premium functionalities across various apps like Proton Mail and Showly. Notable features include the ability to disable tracking and customize UI elements, catering to users who seek greater control over their app interactions.

McProtoNet

McProtoNet is a high-performance .NET library designed for interfacing with the Minecraft Java Edition protocol, currently under active development. Its primary use case includes creating custom clients and tools for Minecraft, featuring an asynchronous API, support for multiple Minecraft versions (1.12.2 to 1.21.4), and capabilities for parsing Named Binary Tag (NBT) data. Additionally, it allows connections to cracked servers, enhancing its versatility for developers working with Minecraft protocol interactions.

antigravity-patch-proxy

The Google Antigravity Custom Model Proxy serves as an advanced patch that enables integration of various LLM models, such as Claude, OpenAI, and others, directly within the Google Antigravity IDE. It facilitates compatibility by intercepting and translating internal API communications into suitable payloads for over 19 LLM providers while offering features like real-time bi-directional SSE streaming, tool calling, and robust AES-256-GCM encryption for enterprise-level security.

agents-reverse-engineer

AGENTS REVERSE ENGINEER (ARE) is a tool designed to facilitate the reverse engineering of codebases into AI-friendly documentation, specifically generating `.sum` files and `AGENTS.md` documentation. It is primarily utilized for enhancing communication between developers and AI assistants like Claude Code and OpenCode by providing structured insights into codebase architecture. Notable features include compatibility with multiple AI platforms and a user-friendly installation process.