> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

skyroads-sdl

SkyRoads SDL is a cross-platform port of the classic DOS space racing game SkyRoads, rewritten in C using SDL2, enabling native execution on macOS and Linux without the need for emulation. Notable features include a self-contained app bundle with integrated game data, customizable controls, and advanced graphical options such as CRT effects. The tool allows users to build from source easily while providing comprehensive compatibility with various hardware architectures.

rvt-rs

rvt-rs is a Rust/Python toolkit designed for inspecting Autodesk Revit files without requiring a Revit installation. It allows users to open OLE/CFB containers, decode truncated-gzip streams, extract metadata, and classify schema field encodings, with notable features including a zero-upload browser viewer that enables real-time 3D rendering and element analysis. The toolkit offers a variety of command-line interfaces and Python bindings, enhancing accessibility for both technical and non-technical users.

n64-decomp-workbench

N64 Decomp Workbench is a diagnostic tool designed to identify and analyze discrepancies in late-stage MIPS decompilation, particularly for near-matched functions. Its primary use case is for developers working with MIPS assembly code, allowing them to efficiently isolate functions, understand the reasons behind mismatches, and generate hypotheses for resolution without requiring extensive setup or external tools. Notable features include a guided workflow, exhaustive documentation, and commands like `diagnose-dumps` and `compare-dumps` that enable users to comprehensively compare and troubleshoot decompiled outputs.

Multiline-Ultimate-Assembler

Multiline Ultimate Assembler is a plugin for x64dbg and OllyDbg that serves as a multiline assembler and disassembler. Its primary use case involves modifying and extending the functionality of compiled executables and creating code caves. Notable features include support for multiline assembly input, enhancing the reverse engineering process.

hcaptcha-hsj-reverse

The hcaptcha-hsj-reverse tool is designed to reverse engineer hCaptcha's hsj.js to extract encryption keys used in its operations. It provides functionality to hook into the AES key schedule of hsj.js and dump encryption keys from memory, utilizing various cryptographic algorithms such as AES-GCM. Notable features include a KeyFetcher class for retrieving these keys and a comprehensive set of helper classes for encryption, hashing, and encoding processes.

grate

Grate is an open source reverse-engineering toolset specifically designed for analyzing NVIDIA Tegra 2/34 2D and 3D graphics engines. Its primary use case is to facilitate understanding and documentation of the Tegra architecture through various resources, including command streams and shader instructions. Notable features include comprehensive wiki documentation that details MMIO registers, shader ISAs, and geometry submission methods.

FF-16-TUI

FF-16-TUI is an interactive static analysis tool designed to identify frequently occurring local 16-bit patterns within files, aiding in the analysis of file structures and layouts. It features a text user interface that allows users to navigate through patterns efficiently while providing customizable filtering options for detailed pattern analysis. Notable functionalities include command-line usage with support for dictionary files, along with keyboard shortcuts for seamless interaction throughout various analysis panels.

DelphiReSym

DelphiReSym is a reverse engineering tool that recovers fully qualified Delphi symbol names from the metadata in Delphi executables, facilitating the analysis of Delphi malware and legacy applications. Integrated with Ghidra, it not only restores human-readable context for functions and types but also automatically populates virtual table structures in Ghidra's Data Type Manager. This tool supports multiple Delphi versions, enabling detailed reconstruction of metadata for effective reverse engineering.

r3ngine

r3ngine v3.7.4 is an advanced web reconnaissance and vulnerability scanning tool that facilitates comprehensive security assessments through its Target Report Generation feature, allowing users to generate detailed multi-scan PDF reports with historical vulnerability tracking. Key features include an Attack Path Modeling Engine aligned with MITRE ATT&CK, integration with WPScan/WPTaint for static analysis, and enhanced infrastructure for scalability and reliability using Django and PostgreSQL. This enterprise-grade platform is designed for thorough and efficient security analysis while ensuring operational security and ease of use.

VeltCLI

VeltCLI is a terminal-based OSINT and defensive security research toolkit that consolidates multiple reconnaissance and analysis tasks into a single interface. Its primary use case includes vulnerability assessment, DNS checks, web security analysis, and various research workflows across social media, emails, IP intelligence, and more, all while supporting data export in formats such as JSON, CSV, and Markdown. Notable features include comprehensive vulnerability scanning, domain and cloud analysis, and detailed reporting capabilities, streamlining the security research process for users.

Huntable-CTI-Studio

Huntable CTI Studio is an advanced Cyber Threat Intelligence (CTI) tool designed to automate the collection, extraction, and generation of detection rules from over 38 OSINT sources. Its notable features include AI-driven relevance scoring, sigma rule generation, and a comprehensive workflow management system using LangGraph and Celery, which facilitates extensive threat intelligence aggregation while ensuring duplicate prevention through community rule comparisons. The tool also supports hardened deployments for secure operation in sensitive environments.

findme

FindME is a CLI-based tool designed for discovering social media and online platform profiles associated with a specified username, enabling rapid reconnaissance across over 400 platforms. Key features include multi-threaded concurrent searching for fast results, real-time progress tracking, and no data collection to ensure user privacy. It serves multiple use cases such as cybersecurity research, digital footprint verification, and username availability checks.

digital-footprint-cleaner

Digital Footprint Cleaner is an open-source web application designed for identifying and managing personal information exposure online by facilitating the generation of data-removal requests. It features a multi-pass search mechanism, match confidence scoring, and provides an exposure report categorized by source, alongside a comprehensive data-broker opt-out checklist for 30+ sites. Additional functionalities include a removal tracker, scan coverage reporting, and optional passcode protection to enhance user security.

UnityResolve-V3

UnityResolve-V3 is a development tool designed to enhance Unity game development through assembly manipulation and runtime field access. Its primary use case includes modifying player attributes and handling method calls dynamically in the Unity engine, notably with functionality for accessing and manipulating class properties and methods. Key features include inline static fields and methods for streamlined access to Unity's runtime classes, providing developers with powerful capabilities for gameplay dynamics.

fibratus

Fibratus is a real-time security sensor designed for threat detection and protection, leveraging a behavior-driven rule engine and YARA memory scanning to analyze a wide range of system events. Its notable features include the ability to route events to various output sinks for further analysis, support for custom tool integration via filaments, and forensic capabilities to assist in understanding and responding to security incidents. The tool emphasizes real-time behavior detection, memory scanning, and comprehensive forensic analysis to combat advanced malware and attacker tactics.

tomcter

Tomcter is a Python-based tool designed for brute-forcing Apache Tomcat manager logins using default credentials. It supports targeting single or multiple instances, integrates with ProxyChains for enhanced anonymity, and is optimized for minimal resource usage. The tool is open-source and easily deployable via Docker, making it suitable for penetration testing scenarios.

YetAnotherPentestParser

YAPP (Yet Another Pentest Parser) is a robust Python library and CLI tool designed to parse and process outputs from multiple penetration testing tools, including Nessus, Nmap, and BloodHound, into actionable results. Notable features include comprehensive multi-tool support, an extensible framework for adding new parsers, dual interface options (CLI and TUI), in-memory processing, and advanced Active Directory analysis capabilities without the need for a Neo4j server. This allows for efficient vulnerability management and streamlined workflows, aiding penetration testers in reducing processing time and improving overall productivity.

stratum-c2

Stratum C2 is a cloud persistence framework designed to maintain command-and-control (C2) communication through trusted cloud storage providers like Dropbox and OneDrive, thus avoiding detection by traditional security defenses. Its notable features include end-to-end encryption with RSA and AES, the ability to switch between multiple cloud providers seamlessly, and a structurally unblockable channel that makes it difficult for security operations centers to intercept. The framework supports multiple agent formats for both Windows and Linux without requiring additional dependencies.

red-clippy

Red Clippy is an open-source penetration testing management tool designed to integrate with AI agents for streamlined test engagements. It retains detailed records of assets, observations, and findings, ensuring that testing sessions can progress smoothly without loss of information, while enforcing protocols for data verification and reporting. Notable features include a web-based interface for managing test data, customizable engagement rules, and the ability to connect to AI agents for enhanced testing efficiency.

R3d-Buck3T

R3d-Buck3T is a comprehensive repository designed for penetration testing and red teaming activities, featuring an extensive collection of tools and commands across multiple security domains, including web application, cloud, network, and wireless security. Notable characteristics include detailed sections on Active Directory and vulnerability research, alongside a dedicated wiki for easy navigation and resource access. This tool serves as a vital asset for security professionals aiming to enhance their offensive security skills and methodologies.

csp_toolkit

csp-toolkit is a Python library and command-line interface designed for parsing, analyzing, generating, and identifying bypasses in Content Security Policy (CSP) headers. Primarily aimed at security researchers and bug bounty hunters, it features automated CSP generation through website crawling, policy analysis with 21 vulnerability checks, and the ability to find potential bypasses against a database of known exploit vectors. Notable functionalities include the ability to score CSPs, detect nonce reuse, batch scan URLs, and generate output in various formats such as JSON and SARIF for integration with CI/CD workflows.

Google-Dorks-Simplified

Google Dorks Simplified is a resource aimed at educating users about the technique of Google dorking, enabling them to efficiently discover valuable information across the web. It offers a comprehensive collection of effective Google dorks tailored for various contexts, including cybersecurity, competitive analysis, and research, while also providing guidance on responsible usage and safeguarding information. Notable features include specialized collections for cybersecurity learners and bug bounty hunters, as well as practical tips on optimizing search results using Google dorks.

Vulnogram

Vulnogram is a comprehensive tool designed for reserving, managing, and publishing Common Vulnerabilities and Exposures (CVE) information, facilitating collaboration between vendors and security researchers. It offers both solo and team modes, allowing users to edit JSON documents that conform to specified schemas, with enhanced features such as real-time collaboration, version control, and a customizable plugin architecture for various tracking needs. Notable features include a web-based frontend, integration with MongoDB for persistent storage, and security-focused configurations to ensure the integrity of vulnerability data.

spicedb-operator

The SpiceDB Operator is a Kubernetes operator designed for managing SpiceDB clusters, enabling the creation, management, and scalability of these clusters through a single Custom Resource. Notable features include automated datastore migrations during version upgrades, as well as simple integration with Kubernetes tools using YAML configurations. This tool streamlines the deployment and configuration of SpiceDB, leveraging Kubernetes' orchestration capabilities.

cluster-image-scanner

ClusterImageScanner is a Kubernetes-native tool designed to identify vulnerabilities and misconfigurations in container images within production environments. It automates the analysis process by utilizing an image collector and orchestrator to periodically scan images with multiple security scanners, consolidating findings through a vulnerability management system like OWASP DefectDojo while providing real-time feedback to developers through communication channels. Notable features include its integration with Argo Workflows, flexible deployment options, and support for various scanning methods, ensuring comprehensive security monitoring for containerized applications.