> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

mdBook

mdBook is a command-line utility designed to create modern online books from Markdown files, facilitating the easy generation of static HTML sites. Its primary use case includes the structured organization and presentation of documentation or books via features like automatic rebuilding on file changes and local serving of the content. Notable features include commands for initializing new projects, building content, watching for changes, and serving the output over a local server.

mavs

MAVS (Mobile Application Vulnerability Scanner) is a shell script designed for static analysis of Android APK files, focusing on identifying and demonstrating vulnerabilities. Its primary use case is to not only highlight potential security flaws but also provide actionable exploitation techniques, thereby enabling users to understand and mitigate risks effectively. Notable features include verbose output for detailed analysis and direct commands for exploiting vulnerabilities, enhancing the practical applicability of its findings.

magisk-frida

MagiskFrida is a tool that enables the automatic execution of the Frida server on device boot across multiple root solutions, including Magisk, KernelSU, and APatch. It supports various architectures such as arm64, arm, x86, and x86_64, and provides instant updates by integrating with the official Frida build process. This tool is particularly beneficial for developers, reverse-engineers, and security researchers looking to leverage dynamic instrumentation in rooted Android environments.

magicRecon

MagicRecon is a comprehensive reconnaissance tool designed to enhance the data collection process for cybersecurity assessments. It facilitates both passive and active reconnaissance, enabling users to enumerate subdomains, analyze vulnerabilities, gather DNS and WHOIS information, and perform scans for common security flaws. Notable features include organized result storage, integration with tools for extensive vulnerability analysis, and robust scanning capabilities for various entry points and technologies used in target domains.

linux_malware_analysis_container

The Linux Malware Analysis Container is a Docker solution designed for dynamic analysis of Linux malware, providing a robust environment to isolate malware samples from the host system. It includes pre-installed reverse engineering tools such as strace, gdb, and objdump, allowing analysts to efficiently analyze malicious binaries. Notably, the container can be easily reset for multiple analyses, enhancing operational efficiency in malware research.

LinEnum

LinEnum is a Linux enumeration script designed to gather extensive system information, user details, and assess potential security weaknesses within a Linux environment. It provides various checks, including user permissions, network configuration, service status, and system vulnerabilities. Notably, it allows the user to export reports, perform thorough or quick scans, and search for specific keywords within files, making it an invaluable tool for security assessments and post-exploitation analysis.

lila

Lila is a free online chess game server designed for real-time gameplay, offering a comprehensive suite of features including game search, computer analysis, tournaments, and various training tools. Built using Scala 3 and relying on asynchronous server architecture, it supports a wide array of user interactions through a rich UI available in over 140 languages, while maintaining a robust database of more than 12 billion games. Notable integrations include Stockfish AI analysis and a dedicated mobile application, making it a versatile platform for chess enthusiasts.

lemmeknow

lemmeknow is a powerful tool designed for the rapid identification and analysis of text, particularly useful for examining hard-coded strings within network packets, malware, and other contexts. It features a user-friendly command-line interface, supports JSON output for structured data presentation, and can be integrated into projects as a Rust crate, with additional functionality in a web environment through WebAssembly. This tool is optimized for speed and provides a straightforward installation process, enhancing its appeal for cybersecurity professionals.

kosmonaut

Kosmonaut is a rudimentary web browser engine designed for educational purposes in browser development. It currently supports basic HTML parsing and a limited subset of CSS, allowing for the rendering of simple web pages, with features like layout and paint processing for block-level elements and support for high-DPI displays. The project aims to expand its capabilities while providing foundational knowledge on browser engine mechanics, using Rust as its core development language.

komorebi

komorebi is a tiling window manager designed for Windows 10 and above, extending the capabilities of the Desktop Window Manager. It provides users with the ability to control application windows, virtual workspaces, and monitors through a command-line interface, while supporting user-defined keyboard shortcuts via integration with third-party tools like whkd and AutoHotKey. Notably, it emphasizes minimal modifications to the operating system, allowing for user customization while maintaining default settings.

keyscope

Keyscope is a Rust-based tool designed for automating the validation workflows of API keys and secrets across over 40 different providers. It supports both validation and invalidation checks, exporting results in JSON format or auditing through CSV, enabling users to ensure the correctness and security of their embedded credentials. With a user-friendly command structure and the ability to list provider-specific requirements, Keyscope streamlines the process of managing sensitive keys effectively.

joern

Joern is a code analysis platform designed for vulnerability discovery and static program analysis, capable of processing source code, bytecode, and binary executables. It constructs code property graphs (CPGs) for cross-language analysis and employs a Scala-based query language for efficient code mining. Notable features include integration with a custom graph database and the ability to run in both local and Docker environments.

iRET

iRET (iOS Reverse Engineering Toolkit) is an automated toolkit designed for iOS penetration testing, streamlining various common tasks such as binary analysis, keychain access, database content reading, and binary decryption. Notable features include integration with tools like otool, keychain_dumper, and dumpdecrypted, along with the ability to manage Theos tweaks directly on jailbroken iOS devices. This tool enhances the efficiency of security assessments on iOS applications by providing a user-friendly interface to complex reverse engineering processes.

iptv

`iptv` is a command-line interface (CLI) IPTV player designed for streaming M3U playlists directly within the terminal. Its primary use case is to provide a lightweight and efficient way to watch IPTV channels, featuring fuzzy finding for easy access, automatic daily playlist updates, and dependency integration with tools like curl, fzf, and mpv for enhanced functionality.

ipfs-chat

IPFS-Chat is a decentralized, peer-to-peer messaging tool that utilizes IPFS pubsub for real-time communication, enabling secure chat, file sharing, and private messaging across both internet and LAN environments. It features a minimal terminal-based interface, automatic NAT-traversal, end-to-end encryption for messages and shared files, and a fully serverless architecture that prevents censorship. Developed in Bash, it is efficient in resource usage and includes malware scanning for shared content, making it suitable for secure and private online communication.

ion

Ion is a modern system shell developed in Rust, designed for enhanced quality, security, and performance compared to traditional Unix shells like Dash. It supports a powerful and simple syntax, making it suitable for both RedoxOS and other Unix-like platforms. Notable features include a formal RFC process for language proposals, an online documentation manual, and support for plugins to extend functionality.

install

Homebrew (un)installer is a command-line tool designed for the seamless installation and uninstallation of Homebrew on macOS and Linux systems. It supports advanced features such as non-interactive execution for automation scripts, geolocalized Git mirrors for faster installations, and specific path uninstallation to facilitate migrations between architectures.

instainsane

InstaInsane is a multi-threaded Shell Script designed for conducting brute force attacks on Instagram accounts, capable of testing up to 1000 passwords per minute across 100 simultaneous attempts. Notable features include session saving and resuming, anonymous attacks via TOR, and the utility to check valid usernames, alongside a default comprehensive password list. Users are cautioned to use this tool responsibly and in compliance with applicable laws.

ImHex-Patterns

The ImHex Database repository provides a comprehensive collection of binary format definitions and resources specifically designed for use with the ImHex Hex Editor. Its primary use case is to facilitate easy file analysis through a variety of patterns, encoding definitions, custom magic files, and scripts that enhance code generation and task automation. Notable features include community contributions, a structured library of pattern libraries, and support for custom themes and Yara rules, all of which are directly integrated into ImHex’s Content Store for seamless user access.

iced

Iced is a high-performance x86 instruction decoder, disassembler, and assembler that supports Intel and AMD architectures across various platforms including .NET, Rust, Python, and JavaScript. Notable features include advanced decoding speeds exceeding 250 MB/s, comprehensive instruction support with extensive formatting options, and the ability to re-encode instructions while providing detailed metadata about instruction behavior. The tool is rigorously tested against other disassemblers for accuracy and reliability, making it a robust solution for developers working with low-level x86 code.

Hyprland-Dots

Hyprland-Dots provides automated installation scripts for setting up the Hyprland window manager with customized dotfiles for various Linux distributions, including Arch, OpenSUSE, and Fedora. It streamlines the configuration process by allowing users to easily clone and apply specific settings tailored to their preferred distro. Notable features include multilingual support, integration with installation commands, and accessible documentation that enhances user experience.

huly-selfhost

Huly Self-Hosted is a resource-intensive application designed for deployment on servers using Docker Compose or Kubernetes, ideal for individuals or organizations requiring a self-hosted solution for their services. Notable features include detailed migration instructions for version upgrades, a quick start script for local testing, and customizable workspace initialization settings. This tool is particularly well-suited for users seeking control over their infrastructure while ensuring robust, scalable deployments.

hmw-client

The HMW Client is a versatile tool designed for managing and interacting with the Horizon social platform. Its primary use case includes facilitating communication and integration within the Horizon ecosystem, offering features such as user management and API interaction. Notably, the tool provides comprehensive installation guidance and community support through Discord.