> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

SentinelDeck

SentinelDeck is a passive attack-surface assessment tool designed for small businesses, agencies, and security consultants, which evaluates the public-facing posture of a specified domain or IP without intrusive scanning. It generates a risk score, provides an A to F grade, and offers prioritized findings along with actionable remediation steps. Key features include easy installation via pip, command-line scanning, and an interactive web dashboard for visualizing results.

ODINT

ODINT (Observatory for Digital Infrastructure & Network Transparency) is an independent, decentralized platform focused on auditing publicly accessible government digital infrastructure through open-source intelligence (OSINT) methodologies. It facilitates collaborative research, encouraging contributions of domain data, investigative leads, and methodologies to enhance accountability and expose vulnerabilities in governmental digital systems. Notable features include an organized repository structure for cyber reconnaissance and a dedicated Recon Suite powering its operations with various OSINT tools.

Global-Data-Center-Map

ATLAS is a comprehensive open dataset that maps all known data center locations globally, encompassing 18,110 facilities across 116 countries and 4,181 operators. Primarily designed for research and publication purposes, the tool allows users to explore data centers with GPS coordinates and provides access to a live map interface. Notable features include extensive categorization of data centers by country and operator, making it a valuable resource for understanding the infrastructure of the internet.

D0x-K1t-v2

D0x-K1t-v2 is a portable web application designed for active reconnaissance, information gathering, and Open Source Intelligence (OSINT) tasks. Its notable features include a user-friendly Bootstrap-based admin dashboard, capabilities for saving data in a database, and tools for conducting WhoIs lookups, phone scans, port checks, and GeoIP lookups. The tool is designed for ease of installation and deployment on various platforms, including serverless environments.

BlueMagic-Multitool

BlueMagic-Multitool is a comprehensive suite designed for malicious activities on platforms by providing functionalities such as token nuking, webhook management, and server manipulation. It includes features like automated account spamming, server deletion, and token brute-forcing, as well as tools for generating various credentials and identity manipulation. This tool is strictly outlined for educational use but possesses significant capabilities for exploitation if employed with malicious intent.

cyberful

Cyberful is an AI-driven application-security workbench designed for authorized penetration testing, code auditing, and bug bounty research. It features robust workflows including pentest phases for evaluating live targets, supports isolated tooling for independent verification, and offers report-ready outputs while maintaining a local-first approach without emitting telemetry. Notably, Cyberful emphasizes trustworthiness in security findings by ensuring actions remain within defined authorization boundaries and by providing detailed evidence tied to each engagement.

CVE-2026-60004-POC

The CVE-2026-60004-POC tool provides a proof-of-concept for exploiting a pre-authentication remote code execution vulnerability in Gitea versions 1.17 through 1.27.0, with a CVSS score of 9.8. This exploitation occurs via the `diffpatch` API endpoint, allowing attackers to inject malicious Git hooks that execute arbitrary commands by manipulating Git's patch processing. Notable features include two operational modes for automation and the ability to retrieve command output directly from the target server after exploitation.

FlutterTap

FlutterTap is a Zygisk module designed for intercepting network traffic from Flutter applications by redirecting it to a configurable proxy, effectively bypassing BoringSSL's TLS certificate verification without the need for a certificate installation or app repackaging. Its primary use case focuses on persistent traffic interception during mobile application analysis, providing an easy-to-use manager app for selecting target applications and configuring proxy settings. Notable features include automatic operation on device boot, minimal impact on non-selected apps, and the ability to capture native traffic without the drawbacks associated with traditional methods such as Frida or LSPosed.

Xpsd

Xpsd is a vulnerability reachability analysis tool that leverages LLMs to determine if reported vulnerabilities are actually exploitable within a specified codebase. By ingesting CVE descriptions or vulnerability scan reports, it employs structural code navigation and other tools to generate structured verdicts and detailed markdown reports compatible with GitHub code scanning. Noteworthy features include GitHub CI integration, support for multiple vulnerability scanners, and flexible model switching for tailored analysis.

rustinel

Rustinel is an open-source endpoint detection tool designed for Windows, Linux, and macOS systems, focusing on providing native telemetry and alerting capabilities. It supports detection formats like Sigma and YARA, enabling rule reuse without needing proprietary adaptations, and produces SIEM-ready alerts in the Elastic Common Schema format. Key features include hot reloading for rules and IOC management, active response options for Windows and Linux, and comprehensive logging of alerts.

inkog

Inkog is a static analysis tool designed to perform pre-flight checks on AI agents, identifying vulnerabilities unique to agent code, such as token bombing, prompt injection, and compliance gaps. It generates detailed reports that align with standards like the EU AI Act and OWASP guidelines, offering insights into critical security flaws and oversight issues. Notable features include easy integration with CI/CD processes, a no-install command-line option, and compatibility with multiple platforms.

SentryPeer

SentryPeer is a fraud detection tool designed to protect SIP servers from malicious activity by tracking and logging attempts to make phone calls from bad actors. Its primary use case involves monitoring outbound calls from VoIP PBXs to notify users of potentially harmful interactions based on an extensive database of probing phone numbers. Notable features include a RESTful API for easy integration, real-time notifications to service providers, and support for Syslog and Fail2ban for enhanced security logging and management.

sbomqs

sbomqs is a comprehensive tool for assessing Software Bill of Materials (SBOM) quality and ensuring compliance with various regulatory standards. It provides features for quality scoring, compliance validation across multiple frameworks, vulnerability tracking, and integration into CI/CD workflows. With its user-friendly interface and multi-standard support, sbomqs enables organizations to manage their software supply chain security effectively and share compliance results easily.

JoySafeter

JoySafeter is an AI-native platform designed to automate and orchestrate security agents at scale, facilitating rapid security operation deployments from concepts to production in minutes. With capabilities such as autonomous APK vulnerability detection and dynamic penetration testing through adaptable DeepAgents, it eliminates the need for extensive manual coordination and integrates seamlessly with over 200 security tools via the MCP Protocol. Its focus on multi-agent collaboration and cognitive memory redefines traditional security methodologies, enabling efficient analysis and reporting with minimal human intervention.

dheater

D(HE)ater is a proof-of-concept tool that demonstrates the D(HE)at denial-of-service attack, which targets servers by saturating their CPU through enforced Diffie-Hellman ephemeral (DHE) or elliptic-curve Diffie-Hellman ephemeral (ECDHE) key exchanges over TLS and SSH. It allows users to specify protocols and various settings like key exchange type, socket timeout, and the number of threads for executing the attack, making it suitable for defensive security testing and research purposes. The tool is built on Python 3.9+ and relies on the CryptoLyzer library for traffic generation and DHE/ECDHE support validation.

slsa-provenance-action

The SLSA Provenance GitHub Action enables users to generate Level 1 SLSA provenance files for various artifact types, such as files and Docker images. Its primary use case is to facilitate automated analysis and auditing of software supply chains by providing provenance information in a standardized format, thereby improving traceability of software artifacts. Notable features include integration with GitHub Actions, compatibility with the SLSA framework, and support for multiple artifact types through a straightforward workflow configuration.

SkillSpector

SkillSpector is a security scanner designed for evaluating AI agent skills, identifying vulnerabilities and malicious patterns prior to their installation. It features multi-format input support, a two-stage analysis combining static and semantic evaluations, and live vulnerability lookups with real-time CVE data. The tool generates comprehensive reports and risk scores, making it integral to ensuring the safety of AI skill deployments.

secuditor-lite

Secuditor Lite is a Python-based diagnostic security tool designed for Windows environments, facilitating endpoint security assessments through a user-friendly graphical interface. Its primary use case involves identifying vulnerabilities, suspicious activities, and misconfigurations across systems and networks, while providing features like SSL/TLS interception analysis, operational security evaluations, and the generation of structured audit reports. The tool supports comprehensive security checks covering system hardware, network configurations, shared folder permissions, and a variety of security controls.

rebuilderd

rebuilderd is an independent verification system designed to ensure the reproducibility of binary packages from their source code within Linux distributions. Its primary use case is to monitor package repositories, utilizing backends to verify that binaries have been successfully rebuilt, while generating reports of discrepancies for troubleshooting. Notable features include support for various distributions like Arch Linux and Debian, and the ability to run instances locally, enhancing confidence in package integrity against tampering.

plecost

Plecost is a professional security scanner specifically designed for WordPress installations, capable of detecting vulnerabilities in the core, plugins, and themes while referencing a daily-updated local CVE database. It offers various scanning modes, such as deep and fast scanning, along with features like asynchronous scanning, extensive configuration options, and compatibility with task queues like Celery, making it suitable for automated security assessments without any external API dependencies or data sharing.

mailgoose

Mailgoose is a web application designed to verify the correct configuration of SPF, DMARC, and DKIM for email domains, thus enhancing email security and reducing the risk of spoofing. It underpins the service provided by CERT PL at bezpiecznapoczta.cert.pl, which assists Polish institutions in domain configuration. Notable features include integration with checkdmarc and dkimpy for comprehensive validation checks.

dnsmonster

Dnsmonster is a passive DNS monitoring framework developed in Golang that captures and indexes DNS traffic from various sources, including live network interfaces, pcap files, and dn stap sockets. It is designed for high performance, capable of indexing over 200,000 DNS queries per second while ensuring user privacy through IP masking. The tool provides flexibility with sampling and domain filtering options, making it suitable for security teams needing to analyze DNS traffic trends effectively.

atlas-trust-infrastructure

Atlas Trust Infrastructure is a metadata-centric framework designed to create and verify proof chains for operational integrity across various systems, such as GitHub, Nix, and SSH. Its primary use case is to enhance audit readiness and governance by recording and verifying actions' metadata, capabilities, policies, and approvals without replacing existing tools. Notable features include a proof-only recording mechanism that ensures metadata integrity and replayability, promoting transparency and reducing ambiguity in digital actions.

arcjet-docs

Arcjet offers runtime policy enforcement for applications and AI agents, enabling teams to implement budget constraints, bot protection, prompt-injection checks, sensitive-data controls, and action-level guardrails in real application contexts. This tool integrates seamlessly with code deployments, providing essential security measures tailored to application functionality. Notable features include real-time enforcement policies and application context awareness, enhancing the overall security posture of software solutions.

Java-Triage

Java Triage is a static analysis tool designed for examining suspicious Java codebases, decompiled JARs, and Minecraft mods. It features extensive capabilities including decompilation with CFR, advanced string recovery, and detection of malicious indicators and behaviors, all while producing comprehensive reports in various formats. Notable functionalities include runtime command and control resolution, detailed scoring for findings, and support for detecting obfuscation tactics commonly used in malware.