> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

AqaraCameraHubfw

The AqaraCameraHubfw repository provides firmware files, including bootloader and operating system components, for various Aqara camera and hub devices. Its primary use case is to facilitate firmware updates and customization for devices such as the Aqara Camera G3, Gateway M1S, and others. Notable features include the availability of raw firmware components, OTA binaries, and version mappings between Mi Home and Aqara Home applications.

apk2gold

apk2gold is an Android decompiler designed to streamline the decompilation process by combining multiple tools into a single, efficient workflow. Its notable features include the regeneration of R.* references, which improves code readability and resource identification, as well as the organization of decompiled outputs to closely resemble the original app structure. The tool is aimed at facilitating Android app introspection, making it easier for users to analyze and understand APK files.

api-docs

The nasa/api-docs repository provides the front-end for NASA's API portal, facilitating access to public APIs related to NASA's data. Its primary use case is to serve as a centralized resource for obtaining API keys, browsing available APIs, and understanding their usage capabilities, while dynamically generating content from a JSON storage system. Notable features include an API key generation form and a user-friendly interface that integrates with GSA's api.data.gov system.

alvm

alvm is a low-level Linux emulator for macOS that enables the execution of Linux binaries without the overhead of full Linux virtual machines. Utilized primarily for running ELF binaries, it leverages Apple's Hypervisor.framework to handle system calls within user land Rust code, facilitating seamless compatibility with Linux applications on macOS. Notable features include direct execution of ELF binaries and trap handling for syscall instructions.

alacritty

Alacritty is a high-performance, cross-platform terminal emulator that leverages OpenGL for rendering, delivering fast operations across BSD, Linux, macOS, and Windows environments. It emphasizes extensibility and user configuration while avoiding unnecessary reimplementation of existing application functionalities. Notable features include GPU acceleration, a flexible configuration system, and a focus on performance benchmarking that consistently positions it as one of the fastest terminal emulators available.

aichat

AIChat is a comprehensive command-line interface tool designed for seamless interaction with various large language model (LLM) providers, including OpenAI and Google AI Studio. Its notable features include a Shell Assistant for natural language command generation, interactive REPL and CMD modes for versatile input handling, customizable roles, and session management to maintain context in conversations. With support for diverse input forms and the ability to streamline repetitive tasks using macros, AIChat enhances command-line efficiency and productivity for users across multiple platforms.

agency-agents

The Agency is a comprehensive toolkit featuring specialized AI agents designed to optimize workflows across various domains. It includes a native application for easy browsing and installation of agents into AI tools like Claude Code and Codex, ensuring seamless updates and delivery of personalized, production-ready solutions. Each agent possesses unique expertise, personalities, and quantifiable deliverables, allowing users to effectively leverage the capabilities of AI specialists.

zola

Zola is a fast static site generator designed to create websites from a single binary, incorporating features such as syntax highlighting, Sass compilation, and multilingual support. Its primary use case is to streamline the process of building and deploying static websites with built-in capabilities for image processing, theme support, and internal linking. Notable features include a comprehensive templating engine, automatic generation of tables of contents, and a robust search functionality requiring no server-side processing.

zeroclaw

ZeroClaw is a minimalistic runtime operating system designed for agentic workflows, optimizing infrastructure for executing AI agents across various environments. With its trait-driven architecture, it features secure-by-default execution, pluggable components, and enables seamless swapping of providers, channels, and tools, making it ideal for lightweight deployments on low-resource hardware. This solution allows for high versatility while maintaining low overhead, supporting the development of robust AI applications.

zeptoclaw

ZeptoClaw is a lightweight personal AI assistant infrastructure designed for local deployment, offering robust performance with a 6MB binary footprint and rapid startup time of approximately 50ms. It integrates features like container isolation, prompt injection detection, and a circuit breaker provider stack, while supporting 18 different providers and a memory-based long-term retention system for findings. The tool is particularly suited for security analysis and API auditing, enabling efficient and streamlined integration tests and data storage.

yew

Yew is a Rust framework designed for building multi-threaded front-end web applications using WebAssembly, offering features that cater to developers familiar with JSX-like syntax. It emphasizes performance by reducing DOM API calls and enables background processing through web workers, while also providing JavaScript interoperability to integrate with existing applications and leverage NPM packages.

yek

`yek` is a Rust-based tool designed to serialize text-based files from a repository or directory for large language model (LLM) consumption, utilizing `.gitignore` rules to exclude unwanted files and leveraging Git history to prioritize important files in the output. This tool supports processing multiple directories and files simultaneously, allows for configurable input/output options via a YAML file, and can output results to the console or specified files, making it highly adaptable for different use cases. Notable features include automatic detection of output contexts, glob pattern support, and the ability to cap output size based on token or byte limits.

yazi

Yazi is an asynchronous terminal file manager written in Rust, designed for efficient and user-friendly file management. Key features include full asynchronous I/O support, powerful task management, built-in image decoding and code highlighting, a plugin system, and robust file processing capabilities including multi-tab support and a virtual filesystem. Its architecture allows for extensive customization and integration with existing tools like ripgrep and fzf, making it suitable for advanced users seeking a fast and versatile terminal solution.

yara-rules

The InQuest yara-rules repository provides a comprehensive collection of YARA rules aimed primarily at research and threat hunting in cybersecurity. Notable features include detection rules for various malware behaviors such as Base64 encoded Powershell, embedded PE files, and vulnerabilities related to Adobe Flash, along with references for further technical reading and related malware samples. These rules are intended for educational use rather than production environments.

XSpear

XSpear is a Ruby-based XSS scanner that provides a comprehensive suite of tools for detecting cross-site scripting vulnerabilities within web applications. Its primary use case includes pattern matching XSS scans, dynamic and static analysis of security headers, and testing various parameters for XSS attacks, with additional functionality for blind XSS detection. Noteworthy features include support for custom payloads, detailed reporting in multiple output formats (CLI, JSON, HTML), and a versatile command-line interface with adjustable verbosity levels for enhanced scanning insights.

xonsh

Xonsh is a cross-platform shell built on Python, enabling users to run shell commands seamlessly alongside Python code. Its notable features include user extensibility through xontribs, integration with various environments like Jupyter and Docker, and a flexible prompt system that allows for enhanced user interaction. Xonsh offers a powerful meta-shell experience, making it ideal for users looking for extensive customization and the ability to leverage Python directly within their shell environment.

Wooey

Wooey is a web interface designed to simplify the execution of command line Python scripts, primarily targeting data analysts and users without command line experience. Its notable features include automatic documentation of workflows, enabling script sharing among colleagues, and the ability to wrap various programs in accessible Python code. This tool enhances routine data analysis and file processing through a user-friendly web platform.

WindowsExploits

WindowsExploits is a collection of precompiled exploits for Windows operating systems, primarily focused on privilege escalation vulnerabilities. The repository consists mostly of forked content from another project, providing users with ready-to-use exploit code for security testing and penetration assessments. Notable features include its emphasis on ease of use and accessibility for penetration testers.

windhawk

Windhawk is a customization tool for Windows programs, facilitating modifications through global injection and hooking techniques. Its primary use case is to allow users to install and manage modifications (mods) to enhance or alter the functionality of various applications. Notable features include a dedicated Visual Studio Code extension for installing and listing mods, as well as robust support for deep technical customization through its source code architecture.

Win7Blue

Win7Blue is a penetration testing tool designed to scan and exploit vulnerabilities related to the EternalBlue exploit (CVE-2017-0143) specifically for Windows 7 systems. It features a vulnerability scanner that utilizes Nmap to detect susceptible targets and includes an architecture identification module to ascertain system architecture. The tool requires several dependencies including Python and Msfvenom for effective exploitation and is primarily tested on the Kali Linux platform.

WhatWeb

WhatWeb is a robust web scanner designed to identify the technologies behind websites, including CMS, servers, programming languages, and frameworks, utilizing a vast library of over 1800 plugins. Its primary use case is for web technology reconnaissance, offering features such as adjustable aggression levels for balancing speed and thoroughness, multiple logging formats, and support for proxy connections. Notable functionalities include custom plugin creation, support for both HTTP and HTTPS scanning, and detailed output options tailored for various analysis needs.

WebHackersWeapons

WebHackersWeapons is a comprehensive collection of tools designed for web security professionals and ethical hackers, facilitating various stages of penetration testing and vulnerability assessment. It categorizes tools into diverse types such as recon, scanning, exploitation, and utilities, while also offering browser extensions and bookmarklets to enhance user experience. Notable features include a well-structured repository and tags for efficient navigation of resources tailored to specific cybersecurity tasks.

webapp.rs

webapp.rs is a complete web application framework built entirely in Rust, utilizing Leptos and Axum for frontend and backend development, respectively. It features user authentication via JWT, Argon2 password hashing, and PostgreSQL for database management, eliminating the need for a separate REST API through seamless communication between the server and client. Additional capabilities include server-side rendering, CSRF protection, and single binary deployment for streamlined operations.

warp

Warp is an agentic development environment that enhances the terminal experience by integrating built-in coding agents and allowing users to implement their own CLI agents such as Codex or Gemini CLI. It provides features like issue triage, PR review, and community management through a user-friendly interface and tracks contributions via a dedicated dashboard. Additionally, Warp supports open-source project maintainers with its Oz for OSS program to streamline development workflows effectively.

vulcan

Vulcan is a streamlined tool for producing STIG-ready security guidance documentation and InSpec automated validation profiles, facilitating the integration of high-level security requirements into actionable implementation guidance. It features STIG process modeling, InSpec code testing, collaborative authoring, and cross-referencing with published STIGs, enabling organizations to efficiently create tailored documentation for security control compliance. Additionally, Vulcan supports flexible authentication methods and incorporates notifications for workflow management.