> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

Raphtory

Raphtory is a high-performance, in-memory vectorised graph database implemented in Rust, providing Python APIs for integration. It excels in handling large-scale graphs with features such as time traveling, full-text search, multilayer modelling, and advanced analytics for automatic risk detection and dynamic scoring. The tool can be embedded in existing pipelines or run as a server instance using GraphQL, supporting both in-memory and on-disk scaling without performance degradation.

rainfrog

rainfrog is a terminal-based database interaction tool designed for efficient navigation and query management across various databases. Notable features include vim-like keybindings, a powerful query editor with keyword highlighting, session history, and support for multiple database types categorized by support tiers. While still in beta, it emphasizes cross-platform compatibility and provides shortcuts for quick data access and schema switching, making it a versatile option for developers managing databases directly from the command line.

r-web-scraping-cheat-sheet

The "r-web-scraping-cheat-sheet" tool serves as a comprehensive reference for web scraping using R, particularly with the rvest and httr packages, along with support for Rselenium for more complex tasks. Its primary use case is to facilitate the extraction of web data through a variety of methods, including handling javascript-heavy sites and managing sessions and cookies. Notable features include guidance on advanced scraping techniques, data storage options, and practical interactions with web drivers, making it a valuable resource for R users looking to implement web scraping effectively.

quick

Quick is a tool designed to effortlessly convert a GitHub repository's `README.md` file into a fully functional GitHub Pages website. Key features include customizable themes, multi-page support via `index.md`, and various configuration options for language, background color, and site title, making it an ideal solution for creating project landing pages quickly and with minimal setup.

qiling

Qiling is an advanced binary emulation framework designed for analyzing and debugging software across multiple platforms (Windows, macOS, Linux, Android, and more) and architectures (such as ARM, x86, and MIPS). Its notable features include a fully configurable sandbox environment, support for various file formats and drivers, fine-grain instrumentation for detailed analysis, cross architecture debugging, and a built-in debugger with reverse debugging capabilities, making it suitable for developing customized security analysis tools.

qdrant

Qdrant is a high-performance vector similarity search engine and database designed for AI applications, enabling efficient storage, management, and searching of vector data. It features extended filtering support and is optimized for use cases like semantic matching, recommender systems, and faceted searches. Written in Rust for speed and reliability, Qdrant offers both a self-hosted option and a managed cloud solution, complete with APIs and client libraries for seamless integration.

pywhisker

pyWhisker is a Python tool designed to manipulate the `msDS-KeyCredentialLink` attribute of user or computer accounts in a Windows domain, facilitating exploitation of "Shadow Credentials." It allows users to list, add, remove, and export KeyCredentials, and supports multiple authentication methods including NTLM and Kerberos variations. Noteworthy features include its integration with Impacket and PyDSInternals, and the capability to perform actions based on specific domain functional prerequisites.

public-apis

APILayer is a unified API suite that enables developers to integrate a variety of REST APIs through a single account and dashboard, using one API key. Its primary use case spans numerous functionalities, such as geocoding, email validation, and stock market data retrieval, making it a versatile tool for application development. Notable features include a curated list of APIs across different domains, easy setup with a Postman collection, and community support for continuous enhancement.

polyrhythmix

Polyrhythmix is a command-line tool that generates MIDI files for complex polyrhythmic drum patterns based on user-defined descriptions using a domain-specific language (DSL). Its primary use case is for musicians and composers in genres like progressive rock, metal, and fusion, facilitating the creation of intricate drum and bass patterns that synchronize rhythmically. Notable features include the intelligent calculation of rhythmic convergence, MIDI file generation for further editing, and the ability to create a bass track that follows the kick drum, enhancing the cohesiveness of the rhythm section.

pixi

Pixi is a cross-platform, multi-language package manager designed to streamline package management and workflow for developers across various programming languages such as Python, C++, and R. Notable features include a Cargo-like command-line interface, support for per-project or system-wide installations, and compatibility with all major operating systems, enhancing the overall developer experience. Built in Rust and based on the conda ecosystem, Pixi also ensures an up-to-date lock file and aims to support additional features like building and publishing Conda packages in future updates.

pipx

Install and Run Python Applications in Isolated Environments

perseus

Perseus is a high-performance frontend web development framework built in Rust that facilitates the creation of dynamic and static web applications. It supports various rendering strategies such as static generation, server-side rendering, and incremental regeneration while enabling reactive UI development through Sycamore. Notable features include hot state reloading, full internationalization support, and exceptional performance, achieving high Lighthouse scores for both desktop and mobile.

oxfeed

OxFeed is a feed reader tool designed for efficiently managing and interacting with web feeds. It features a PostgreSQL backend for data storage, supports read and favorite functionalities, and offers a systemd service configuration for easy deployment. Notably, it provides a demo environment to showcase its capabilities while allowing users to manage their feeds seamlessly.

oatmeal

Oatmeal is a terminal UI application designed for interacting with large language models (LLMs) through a chat interface, offering versatile backend integrations including ChatGPT and Ollama. It supports slash commands, customizable themes, and is optimized for use alongside modern editors like Neovim, enhancing the user experience by providing a sleek, interactive environment for LLM communications. The tool also includes features for session management and syntax highlighting based on user preferences, ensuring flexibility and personalization.

ntlmv1-multi

The NTLMv1 Multi Tool facilitates the conversion of NTLMv1 hashes into a format compatible with hashcat's mode 14000, optimizing the cracking process for NTLM and NTLMv1-ESS/MSCHAPv2 hashes. It offers features like automatic calculation of the final NTLM digits, support for various input formats including `$99$` blobs, and options to directly derive DES keys or use existing potfiles, thereby streamlining the workflow for security experts and pentesters. Additionally, the tool is designed to be easily integrated into other Python scripts or run directly from its repository.

mwcfg

The Malware Configuration Extractor (mwcfg) is a tool designed for extracting configurations from various malware samples efficiently. It supports modular extension through MalDuck, allows for multi-threaded processing, and can be utilized via command-line or through a server using Docker. Notable features include the ability to list modules, debug options, and pretty print configurations, making it versatile for cybersecurity professionals analyzing malware behavior.

musescore-mcp

The MuseScore MCP Server facilitates integration between MuseScore and large language model (LLM) clients, allowing users to compose music via natural language commands. Key features include the ability to manipulate scores, add or delete notes, create tuplets, and perform actions like undoing changes. While it enhances music composition capabilities, the server is limited in handling multiple voices within a staff.

motor-admin

Motor Admin is a no-code admin panel and business intelligence tool designed to facilitate data management and reporting through an intuitive user interface. Its primary use case includes creating, updating, and deleting data entries, along with advanced functionalities such as custom actions, SQL query support, data visualization, and customizable dashboards. Notable features include role-based access control, multi-database support, automated reporting via email and Slack alerts, and mobile optimization.

midimi

midimi is a native desktop application designed for playing and visualizing MIDI files, leveraging a Rust backend and a Svelte frontend. Its primary use case is to provide an immersive experience through real-time audio rendering and dynamic visualizations, specifically featuring a "Cosmic Aurora" effect that responds to musical notes. Notable features include transport controls for playback management, persistent recent file tracking, and a bundled General MIDI soundfont for high-quality audio output.

mhn

Modern Honey Network (MHN) is a centralized server solution designed for the management and data collection of honeypots, enabling rapid deployment of sensors and immediate data collection for analysis via a web interface. It supports various honeypot technologies, including Snort, Cowrie, Dionaea, and Glastopf, while providing features such as an HTTP API for honeypots to register and send intrusion detection logs, alongside tools for administrators to monitor attacks and manage detection rules. The tool is in the process of being updated to support Python 3 on Ubuntu 20.04, with stability maintained for earlier versions.

metasploit-framework

The Metasploit Framework is a powerful open-source penetration testing tool designed for security professionals to develop and execute exploit code against remote target machines. Its primary use case is the identification and validation of security vulnerabilities within systems, supported by a robust library of exploits, payloads, and auxiliary modules. Notable features include an intuitive console interface, comprehensive documentation, and community-driven development support through platforms like GitHub Discussions and Slack.

memex-gate

MemexGATE is a server-side application designed for large-scale General Architecture Text Engineering (GATE) tasks, enabling comprehensive analysis of document resources such as court documents, press releases, and social media streams. It incorporates robust features like text processing, named entity recognition, and classification, alongside integration capabilities with external tools like Apache Solr and Elasticsearch. The tool facilitates easy deployment via Docker, allowing users to effectively manage and interrogate complex datasets through Natural Language Processing methodologies.

meetily

Meetily is a privacy-first AI meeting assistant designed to capture, transcribe, and summarize meetings directly on users' infrastructure, ensuring data sovereignty and compliance. Its primary use case is for enterprises requiring advanced meeting intelligence without cloud reliance, offering features such as real-time transcription and customizable summaries. Notably, Meetily is open source, emphasizes privacy, and includes a PRO version for enhanced functionalities like advanced exports and speaker diarization.

mcp-musescore

The MuseScore MCP Server facilitates programmatic control over MuseScore through a WebSocket-based plugin, enabling AI applications like Claude to compose music, add lyrics, and navigate scores. Key features include advanced navigation controls, multi-voice polyphony support, and integration with LilyPond for accurate music rendering, along with the ability to create and manage notes, rests, and measures efficiently. This tool is primarily aimed at enhancing musical composition workflows through automation and AI assistance.

Max

Max is a suite of tools designed to enhance BloodHound's capabilities for auditing and assessing Active Directory environments. Its primary use cases include gathering intelligence from the Neo4j database, marking owned or high-value targets, exporting data, and executing custom queries, with features such as the BloodHound Domain Password Audit Tool (DPAT) and new attack primitives like creating SPN and SharesPasswordWith relationships. The tool is compatible with both Kali Linux and Windows 10, providing flexibility for various operational contexts.