> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

pentest-harness

Pentest Harness is an open-source AI-driven security testing workspace designed for authorized penetration testing, bug bounty research, and CTF engagements. Its notable features include a multi-provider LLM engine for seamless integration with various AI model APIs, durable session management for persistence and replay, and a fully customizable plugin architecture allowing for extensive configuration and adaptability. The tool prioritizes security with private credential storage and offers a dark theme interface for extended use during testing sessions.

default-creds

Default-Creds is a community-driven database that provides a collection of factory-set credentials in plain YAML format, aimed at penetration testers and security researchers. Its primary use case is to assist in identifying weak access points during security audits or tests, thereby helping secure systems from potential exploitation due to unchanged default passwords. Notable features include a flat-file database structure, community contribution capabilities, and an associated tool for searching credentials via a terminal user interface (TUI).

awesome-security-agent-harnesses

Awesome Security Agent Harnesses provides a collection of AI-driven tools designed for penetration testing, code auditing, fuzzing, vulnerability discovery, and reverse engineering. The primary use case is to enhance security assessments through a variety of harnesses, sandboxes, and evaluation frameworks that streamline the detection and validation of vulnerabilities while minimizing false positives. Notable features include multi-agent collaboration, independent validation of findings, and integration with various coding agent methodologies to automate and enhance security processes.

Reverse-Shell-Whatsapp

Reverse Shell WhatsApp is a tool that exploits the WhatsApp Desktop application on Windows to enable remote code execution via a crafted `.pyz` file. When the victim opens the file, it is executed directly by the Python interpreter without any security prompts, allowing the attacker to gain full control of the victim's machine through privilege escalation. Notable features include bypassing multiple layers of security, such as Windows Defender and UAC, and operating discreetly within a trusted application context.

Acunetix-Premium-Web-Scanner

Acunetix Premium Web Scanner - Practical Windows release with complete modules and an easy first launch.

Project-Eyes-On

Project Eyes On is a multi-threaded reconnaissance tool designed for the global scanning and identification of open IP cameras by leveraging both web dorking and directory scraping techniques. Notable features include support for multiple search engines, anti-rate limiting, path probing to locate hidden streams, and interactive TUI for user-friendly operation. This tool aims to serve educational and security auditing purposes but highlights the importance of device security for camera owners.

fluere

Fluere is a comprehensive network monitoring and analysis tool that captures network packets in pcap format and converts them into NetFlow data, enabling users to analyze traffic dynamics effectively. It supports both live and offline data capture across multiple platforms (Windows, macOS, Linux) and features a Terminal User Interface (TUI) for real-time feedback during live captures. Notable functionalities include integration with AWS Traffic Mirroring, active firewall implementation using plugins, and customizable command-line arguments for enhanced user experience.

defango

Defango is a Golang tool designed for defanging URLs, IP addresses, and emails to neutralize Indicators of Compromise (IoCs) for safer analysis and sharing. Its primary use case is to convert potentially harmful IoCs into harmless formats for security practitioners. Notable features include easy integration and usage through its package methods, enabling users to sanitize malicious content seamlessly.

skyroads-mac

SkyRoads for macOS is a native port of the classic 1993 DOS space-racing game, allowing it to run seamlessly on both Apple Silicon and Intel Macs without the need for emulation. It features a self-contained application that incorporates game data, customizable controls, and visual enhancements such as CRT effects, while supporting easy installation and building from source. Notable features include a fully rewritten engine in portable C with SDL2, support for AdLib music synthesis, and plans for future enhancements like online leaderboards and improved visual effects.

sdocx

sdocx is a reverse-engineered tool and SDK designed for parsing and converting Samsung Notes (.sdocx) files, primarily used to extract and manipulate handwritten notes stored in these formats. Key features include a command-line interface for easy access, library support for Rust and JavaScript environments, and a best-effort parsing approach that provides insights into document structure, stroke data, and metadata while acknowledging potential limitations and fidelity concerns.

IFDA

IFDA is a tool designed for automated reverse engineering and vulnerability discovery in IoT firmware binaries, supporting the analysis of ELF files and extracted firmware trees. It features a bilingual web UI, integrates with existing tools like Capstone and PyELFTools for disassembly and ELF parsing, and offers a structured output for findings, including severity and vulnerability classifications. The architecture includes a Python analysis core and a Go service layer for orchestration, ensuring efficient task management and live progress tracking.

gtirb-pprinter

The GTIRB Pretty Printer is a tool designed to convert the GTIRB intermediate representation of binary files into gas-syntax assembly code, primarily for the purposes of binary analysis and reverse engineering. Notable features include the ability to generate reassembleable assembly files, create new binaries directly, and generate dummy shared object files to facilitate linking without actual libraries. The tool requires a C++17 compliant compiler and dependencies such as GTIRB and Capstone for its functionality.

ghidra-emotionengine-reloaded

Ghidra Emotion Engine: Reloaded is an extension for the Ghidra reverse engineering framework specifically designed to support the PlayStation 2 architecture. It enables users to disassemble and decompile Emotion Engine-specific instruction sets, recover data types and functions from ELF files, and import PCSX2 save states. Notable features include the STABS Analyzer for enhanced debugging capabilities and the MIPS-R5900 Constant Reference Analyzer for improved variable reference handling.

ARSCLib

ARSCLib is a Java library designed for the manipulation of Android binary resources, enabling users to read, write, modify, and create resource tables and binary XML files. Its primary use case is to replace aapt/aapt2 with enhanced decoding capabilities, allowing conversion to/from JSON and XML formats for both obfuscated and un-obfuscated resources, making resource management more accessible to developers. Notable features include seamless integration across platforms and the ability to handle unvalidated XML input, which provides flexibility in resource encoding without strict checks.

WinSecRuntime

WinSecRuntime is a Windows runtime security library implemented in C++20, designed to enhance application integrity by providing defensive mechanisms against tampering, debugging, and injection attacks. It features a modular architecture that supports header-only usage, static libraries, and hardened DLLs, allowing developers to configure anti-debugging, anti-hooking, and memory safety checks tailored to their security needs. The library emphasizes redundancy and safe detection methods rather than deceptive techniques, making it suitable for production environments focused on security hardening.

RPC-Triage

RPC-Triage is a static analysis tool designed to assess the Windows RPC attack surface by analyzing compiled PE binaries to identify registered RPC servers and their corresponding method signatures, security flags, and transport bindings. It uniquely ranks interfaces based on a composite score of reachability and danger, providing detailed receipts for transparency in scoring. Notably, the tool operates without the need for symbol files, making it effective on stripped binaries found in production environments.

Free-RASP-Community

freeRASP is a mobile in-app threat detection and security monitoring SDK designed to protect applications from runtime threats such as reverse engineering, repackaging, and unsafe operating environments. It offers a suite of precise security checks, is lightweight with minimal performance impact, and integrates easily with various platforms including iOS, Android, Flutter, and Unity. Notable features include real-time threat response via API, weekly security reports, and adherence to OWASP MASVS standards for resilience against reverse engineering.

patchbot

Patchbot is a comprehensive vulnerability scanning tool that integrates with existing scanners and threat feeds to automate the patching process in software repositories. It specializes in inventorying packages, identifying vulnerabilities, and applying fixes—either through version bumps or more complex code changes—while ensuring that each change is verified and re-scanned prior to the creation of pull requests. Notable features include the ability to utilize custom threat feeds and scanners, as well as the capability to operate independently of CI environments, thereby providing flexibility in deployment and usage.

querytool

QueryTool is a standalone HTML application designed for constructing and executing OSINT queries while providing access to a curated source catalogue of 178 sources. Its primary use case is to facilitate the generation of complex queries using Google-style syntax, allowing users to filter sources by various criteria and open multiple links in new tabs. Notable features include offline functionality, the ability to import and export browser sessions as JSON, and a straightforward setup with no installation required.

theory

THEORY is an open-source tool designed to produce comprehensive threat actor intelligence dossiers by aggregating data from various cybersecurity sources, including MITRE ATT&CK and AlienVault OTX. It leverages a large language model to synthesize information into easily digestible executive summaries and detailed intelligence reports, which feature TTP tables, detection opportunities, and enriched IoCs. Key functionalities include the generation of IR playbooks and export options in multiple formats, making it suitable for threat intelligence analysts, detection engineers, and security researchers.

Ordo

Ordo is an OSINT investigation toolkit designed to trace scam operations from a single website or app to the underlying network of operators. Its primary features include two data collection methods (WebPivot and BinaryPivot) that extract identifying artifacts, followed by a robust analysis and visualization capability to correlate data points and create interactive network graphs and professional reports. Additionally, Ordo focuses on maintaining operational security by ensuring that investigation data remains local and secure within an ignored directory.

SteamReveal

SteamReveal is an OSINT tool tailored for the Steam community, enabling users to discover concealed profile information, including player location and Close Friends network. It utilizes advanced features such as geographic triangulation and AI-powered cheater probability analysis specific to Counter-Strike players, while also offering a responsive user interface and multilingual support. Developed with modern web technologies, it aggregates data from the Steam API and employs machine learning for enhanced analysis and insights.

spotlight

Spotlight is an OSINT investigation orchestrator designed to convert leads into structured case files, integrating methodologies, sourced findings, and independent fact-checking. It features a client-driven workflow with explicit approval gates, allows for multiple research cycles, and maintains a separate knowledge vault for proven materials, ensuring that only verified data is published. Notable capabilities include drafting investigation briefs, running bounded research, and generating detailed reports with provenance records, making it suitable for rigorous investigative journalism and research.

Notes-on-OSINT

The OSINT Notebook is a comprehensive collection of tools, techniques, and resources aimed at facilitating ethical investigations and research based on publicly available information. Key use cases include username and email investigations, image analysis using reverse searches, geolocation identification, and social media behavior mapping. Notable features include the emphasis on anonymity through fictitious identities, structured methodologies for data correlation, and a dynamic approach that adapts to the evolving landscape of open-source intelligence.