26 Aug 2026
Python
★ 70
GMapsScraper is a Python-based tool designed for scraping business data from Google Maps without requiring an API key. It offers features such as multi-threaded querying, extraction of over 15 fields including contact details and GPS coordinates, and the ability to crawl business websites for additional information. Users can export data in formats like CSV, Excel, or JSON, making it a versatile solution for lead generation and data enrichment.
26 Aug 2026
Python
★ 20
Awesome OSINT Repositories is a comprehensive catalog that organizes open-source investigative tools into 12 distinct categories, each tailored to specific input types such as usernames, domains, and IP addresses. The repository features a diverse range of projects, with additional sections highlighting emerging tools and AI-agent integrations, providing users with a robust resource for enhancing their open-source intelligence capabilities. It emphasizes only publicly accessible source-code repositories, ensuring a focused selection of actionable tools for investigations.
26 Aug 2026
★ 117
Cyber Intelligence GPT is a specialized tool for operational security and cyber investigations, integrating OSINT, DFIR, threat intelligence, and AI security into a cohesive workflow. It enables users to collect, analyze, and report on information while providing capabilities for entity research, incident triage, and correlation of cyber threats across multiple public sources. Notable features include the ability to create collection plans, resolve contradictions, assess confidence in findings, and suggest strategic next actions based on intelligence gaps.
26 Aug 2026
Python
★ 12
Ingram-Pro is an enhanced network camera vulnerability scanner that builds upon the original Ingram framework, providing extensive coverage of over 40 proof of concept (POC) exploits for CVEs from 2017 to 2024, alongside brand-specific weak-password detection for more than 15 camera brands. Key features include authenticated and unauthenticated remote code execution (RCE), high concurrency scanning using gevent, and the ability to capture live snapshots from vulnerable devices. The tool is designed for authorized security assessments and facilitates rapid vulnerability detection across large IP ranges.
26 Aug 2026
PowerShell
★ 17
WinFlesher is an advanced attack surface security assessment tool designed for security professionals and auditors to automate the discovery of vulnerabilities and evaluate security postures in Active Directory and local infrastructures. Its notable features include real-time automated discovery of configurations and services, in-depth Active Directory analysis with a focus on trust and privilege relationships, a built-in attack paths engine for identifying potential escalation routes, and integrated remediation support with practical guides. The tool also provides a modern GUI for intuitive visualization of findings and security scores, enhancing the management of risk assessments.
26 Aug 2026
Python
★ 12
RedAgent is an offensive security tool designed for authorized security teams to conduct adversary-grade testing across various surfaces, including web, API, cloud, and identity. It operates within strict authorization boundaries, enabling controlled and precise engagements while leveraging supervised AI to enhance expert workflows. Notable features include comprehensive auditing of operations, policy-gated engagements, and a focus on ensuring all actions remain within authorized scopes.
26 Aug 2026
Python
★ 244
Deep Focus is a high-performance asynchronous network reconnaissance tool designed for security researchers and network administrators to discover and fingerprint services across IP ranges. It features intelligent probing of common network services, detailed authentication detection, and structured export of actionable intelligence, all while managing system resources to prevent overheating on passively-cooled devices. Its notable capabilities include comprehensive scanning for services like HTTP, FTP, SSH, and more, along with robust thermal management to ensure optimal performance.
26 Aug 2026
Python
★ 17
PI Recon is a lightweight AI red teaming harness designed for authorized agent security challenges, facilitating a streamlined workflow of task acquisition, reconnaissance, validation, and summarization. It features continuous scheduling, bounded execution, multi-stage reconnaissance, structured summaries, and secure builds that do not expose sensitive information. This tool emphasizes simplicity and efficiency, making it an ideal choice for users looking to optimize their red teaming processes without the overhead of a heavier framework.
26 Aug 2026
HTML
★ 13
PageZero is a JavaScript-based browser exploitation and command-and-control (C2) framework that integrates features from both Evilginx and BeEF. It allows security professionals to deploy phishing attacks without the need for complex configurations, enabling live sessions to execute over 40 modules including credential theft, keylogging, and LAN scanning from a web admin panel. The tool is designed for authorized penetration testing and operates using a simple hook that grants persistent control over the victim's browser context.
26 Aug 2026
Python
★ 17
ZeroBurst is an advanced command-line application security testing framework designed for ethical hacking and vulnerability assessment. With over 55 specialized modules, it enables users to conduct thorough reconnaissance, injection testing, and auditing of web applications, focusing on various attack vectors such as server-side request forgery and SQL injection. Notable features include automated vulnerability detection across multiple tiers, advanced auditing capabilities, and comprehensive mapping tools for application infrastructure.
26 Aug 2026
★ 15
The repository provides a comprehensive collection of cybersecurity bookmarks curated by a senior information security engineer, focusing on critical topics such as OSINT, exploitation, privilege escalation, and malware analysis. It features over 40 tools for reconnaissance, privacy, and attack methodologies, along with curated news sources, making it a valuable resource for cybersecurity professionals looking to enhance their operational security and situational awareness. Notable features include categorized tools for specific cybersecurity tasks and a visually engaging presentation of the content.
26 Aug 2026
C#
★ 53
Atlas is a cross-platform network execution and security assessment toolkit designed for authorized penetration testing, leveraging TrustedSec's Titanis protocol library. It features modular enumeration capabilities across multiple protocols such as SMB, Kerberos, WMI, and LDAP, allowing for credential checks, session enumeration, and remote command execution, along with a streamlined workflow similar to NetExec. Notable features include multi-host concurrency, comprehensive authentication methods, and detailed console output, facilitating efficient security assessments across diverse network environments.
25 Aug 2026
XY is a high-performance, interactive Python charting library designed for creating a wide range of visualizations on the web, in notebooks, and for static exports. Notable features include the ability to handle vast datasets with ease, customizable visual elements via Python and CSS, and support for interactive functionalities such as pan, zoom, and selection, all while seamlessly integrating with existing matplotlib workflows. The library is particularly well-suited for users needing flexible visual solutions, making it capable of rendering large datasets like OpenStreetMap with high efficiency.
25 Aug 2026
Reflex is a Python library designed for building full-stack web applications entirely in Python, eliminating the need for JavaScript. It offers notable features such as an AI Builder for rapid app generation, a customizable framework for developing complex applications, and integrated app management for seamless deployment and maintenance. This tool is particularly suited for developers looking to create performant applications with minimal overhead in learning new languages or frameworks.
25 Aug 2026
NiceGUI is a Python-based framework that enables the creation of browser-accessible graphical user interfaces, ideal for micro web applications, dashboards, and robotics projects. Its notable features include built-in standard GUI elements, powerful high-level components for plotting graphics and 3D scenes, real-time updates, data binding, and customizable user interactions, making it particularly suited for developing interactive applications with minimal coding.
25 Aug 2026
Python
★ 93
search_vulns is a modular tool designed for searching known vulnerabilities, exploits, and other related information across various data sources. Its primary use case is to facilitate vulnerability assessments by allowing users to query a local database with inputs such as product titles or vulnerability IDs, while supporting integration of additional data sources through its modular architecture. Notable features include a command-line interface for automated workflows, a web server for enhanced functionality, and the ability to accommodate diverse input formats.
25 Aug 2026
Python
★ 116
Guardana is an open-source AI security verification tool designed to assess AI artifacts and deployed models for security vulnerabilities from the build stage to production. It features 51 configurable security checks, deterministic evidence collection, and graded verdicts for attack impact assessment, ensuring comprehensive reporting on model behavior and security weaknesses. Notably, it maintains user privacy by avoiding telemetry and streamlines grading through swappable components, offering detailed outcomes and confidence metrics for its findings.
25 Aug 2026
Rust
★ 13
Databoxer is a lightweight, cross-platform data encryption tool designed for efficiency, safety, and user-friendliness. It employs the ChaCha20 encryption algorithm combined with the Poly1305 hash function, allowing for secure, fast encryption of files, which are stored in a unique `.box` format encapsulating data integrity and metadata. Notable features include a profile management system for key storage and planned integration with native keyring tools for enhanced security.
25 Aug 2026
PHP
★ 61
PrestaScan Security is a PrestaShop module designed to scan PrestaShop websites for malware and known vulnerabilities in both the core and its modules. It features an intuitive installation process, regular vulnerability alerts, and is compatible with multiple PrestaShop versions, ensuring comprehensive security for e-commerce sites. This free and open-source tool is supported by a dedicated team of security experts who continually monitor and audit for potential threats.
25 Aug 2026
Python
★ 22
Network Scanner is an open-source security tool designed for vulnerability assessments and penetration testing, enhancing traditional methodologies with AI capabilities for intelligent analysis and detailed reporting. Tailored for a diverse user base including beginners and professionals, it offers functionalities such as automated reconnaissance, various scan types (subdomain, port, DNS), and an AI assistant for context-sensitive support. Notable features include report generation in PDF/HTML formats, an educational learning mode, and API readiness for seamless integration.
25 Aug 2026
Go
★ 234
GitAlerts is a tool designed to detect and monitor public repositories created under organization user accounts, which cannot be controlled by GitHub administrators. It provides features such as secrets detection using TruffleHog and Gitleaks, monitoring for new repository creation, and integration with Slack for notifications, all while offering both a command-line interface and a web platform with advanced search capabilities, filtering, and asynchronous scanning.
25 Aug 2026
Kotlin
★ 329
Certora Prover is a formal verification tool designed for analyzing and ensuring the correctness of smart contracts. Primarily used in blockchain development, it leverages advanced SMT solvers and integrates various programming languages to validate contract logic against specified properties. Notable features include support for multiple solvers, a cloud platform for ease of use, and detailed reporting capabilities for diagnostics.
25 Aug 2026
★ 310
Awesome Malware Persistence is a curated repository that compiles tools and resources related to malware persistence techniques across various platforms, including Windows, Linux, macOS, and cloud systems. Its primary use case is to provide cybersecurity professionals with insights into how adversaries maintain system access through various persistence methods, as well as strategies for detection, prevention, and removal of these threats. Notable features include a comprehensive categorization of persistence techniques and relevant forensic tools, linked to established frameworks such as MITRE ATT&CK.
25 Aug 2026
Python
★ 23
The Assemblyline Client Library is a Python library designed to simplify the process of issuing requests to the Assemblyline API. Its primary use case is to enable developers to efficiently interact with Assemblyline's services, facilitating integration and automation of cybersecurity-related tasks. The library is notable for its comprehensive documentation and ease of use, streamlining the interaction with the Assemblyline platform.
25 Aug 2026
Python
★ 11
The TikTok X-Mssdk-Info Reverse Engineering & Decrypter is a comprehensive Python tool designed to analyze and decrypt the X-Mssdk-Info telemetry header used by TikTok for device fingerprinting and security measures. It operates without external dependencies, enabling users to generate and decrypt the header payloads for API verification and device registration processes. Notable features include a complete implementation of the XXTEA encryption algorithm used by TikTok, alongside detailed instructions for payload generation and decryption.