> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

atheris

Atheris is a coverage-guided fuzzer for Python and native CPython extensions, leveraging libFuzzer for efficient bug detection. It provides features such as bytecode instrumentation for enhanced coverage analysis, the ability to fuzz both Python code and native libraries, and integrates with sanitizers like Address Sanitizer for comprehensive bug identification. The tool is designed for Linux and macOS, supporting multiple Python versions and offering installation via pip or from source for advanced configurations.

Artemis

Artemis is a cybersecurity tool designed for analyzing Android APK files to extract infrastructure details, such as IP addresses and domains. Its primary use case involves identifying potential threats and vulnerabilities within APKs through features like manifest information extraction, infrastructure discovery, and WHOIS lookups. Notable functionalities include customizable output options and the ability to seamlessly integrate various analysis commands via the command line.

angr-utils

Angr-utils is a utility library designed for the angr binary analysis framework, primarily focused on providing functionalities such as control flow graph (CFG) visualization, pretty printers, and auxiliary functions. It enables users to produce detailed CFG visualizations while serving as a facade for selecting specific features from the bingraphvis library, although interactive visualizations are not its purpose. Notably, it offers stable API functions for CFG plotting, which can integrate seamlessly with various angr workflows.

angr

angr is a platform-agnostic binary analysis framework designed for dynamic and static analysis of executable binaries. Its primary use case includes tasks such as symbolic execution, control-flow analysis, and program instrumentation, enabling security researchers to dissect binaries for vulnerabilities or insights. Notable features include disassembly, intermediate-representation lifting, and decompilation capabilities, which facilitate in-depth analysis and manipulation of binary files.

airflow

Apache Airflow is an open-source platform designed for orchestrating complex workflows and data processing pipelines. Its primary use case is to programmatically author, schedule, and monitor data workflows, utilizing Directed Acyclic Graphs (DAGs) for dependency management. Notable features include a rich user interface for visualizing workflows, extensive integration with various data sources and tools, and a strong community support system.

adb_shell

adb_shell is a Python package that provides ADB shell and FileSync functionality, enabling remote command execution on Android devices over TCP or USB. It supports asynchronous operations and allows for secure key management to authenticate device connections. Notable features include robust device connectivity options and the ability to easily generate ADB key files.

yt-dlp

yt-dlp is a versatile command-line tool designed for downloading audio and video content from a wide range of websites, building upon the foundation of youtube-dl with additional enhancements. Its primary use case is to facilitate the retrieval of multimedia files, offering support for extensive site compatibility, advanced configuration options, and user-friendly features like video format filtering and post-processing capabilities. Noteworthy aspects include its ability to handle geo-restricted content, the option to modify metadata, and support for plugins, making it a comprehensive solution for media downloading needs.

xsscrapy

xsscrapy is a fast, thorough web spider designed to test URLs for cross-site scripting (XSS) and basic SQL injection vulnerabilities by crawling all linked pages. Notable features include customizable options for logging in with HTTP Basic Auth, handling cookies, and controlling the rate of requests, alongside generating reports of identified XSS vulnerabilities. The tool utilizes efficient techniques to detect vulnerabilities, combining the detection of XSS and SQL injection through the analysis of common attack patterns.

X-Recon

X-Recon is a reconnaissance tool designed to identify web page inputs and perform XSS vulnerability scanning by extracting forms and links from websites. Key features include subdomain discovery, comprehensive link extraction, and the generation of JSON outputs to facilitate XSS testing, though it is currently optimized for PHP-based applications rather than Single Page Applications. The tool also allows users to customize which file types to skip during exploration, enhancing its adaptability for various scanning needs.

unsloth

Unsloth Studio is a versatile tool designed for running and training various AI models locally, including text, audio, and vision models across multiple operating systems. Notable features include robust model management through downloading and exporting, integration of an API inference endpoint for local LLMs, and advanced functionalities like side-by-side model comparison and self-healing tool calling. This tool optimizes training efficiency and resource usage, allowing for faster processing with significantly reduced VRAM consumption.

ultimatevocalremovergui

Ultimate Vocal Remover GUI (UVR) is an advanced application designed for vocal isolation and removal from audio files, utilizing state-of-the-art source separation models. Its primary use case caters to musicians and audio engineers seeking clean instrumental tracks for remixing or sampling, while notable features include ease of installation with all required dependencies bundled and support for multiple audio processing backends.

Tunna

Tunna is a proactive tool designed to tunnel TCP connections over HTTP, particularly effective in bypassing network restrictions in fully firewalled environments. Its primary use case includes establishing a local proxy to facilitate access to remote services, with the ability to manipulate data exchange transparently over standard web ports (80/443). Notable features include customizable local and remote port configurations, verbose logging options, and upstream proxy support with authentication capabilities.

test-lists

The test-lists repository provides URL testing lists designed to facilitate the examination of website censorship across various countries. It includes both local lists tailored by regional experts and a global list featuring popular sites with potentially sensitive content. Notable features consist of categorized content based on political, social, conflict/security, and internet tools themes, available in both CSV and JSON formats for accessibility.

swift

OpenStack Swift is a highly scalable distributed object storage system optimized for multi-tenancy and high concurrency, making it suitable for applications such as backups, web, and mobile content. It features a REST-based API, extensive documentation, and a modular architecture that supports various storage and server components, ensuring high availability and redundancy. Swift's testing framework includes unit, functional, and probe tests to maintain robustness and reliability in large-scale deployments.

spleeter

Spleeter is a source separation library developed by Deezer, leveraging TensorFlow to provide solutions for isolating audio sources. It offers pre-trained models for various separation tasks, including vocals/accompaniment (2 stems), vocals/drums/bass/other (4 stems), and a more complex 5-stem configuration, achieving real-time performance with GPU acceleration. The tool can be utilized through a command-line interface or as a Python library, making it suitable for integration into diverse audio processing workflows.

sigint

SIGINT is a distributed signal intelligence system that utilizes wideband Software Defined Radios (SDRs) to detect and triangulate short-burst signals, while also managing longer transmissions through remote sensor nodes in a meshed network. Its notable features include continuous band scanning, a live web dashboard for real-time situational awareness, and integration with the ATAK system for mapping detections. The tool is particularly useful for monitoring and analyzing various signal types in a coordinated manner.

Scrapegraph-ai

ScrapeGraphAI is a Python library designed for web scraping that leverages large language models and graph-based logic to automate the creation of scraping pipelines for various document types, including XML, HTML, JSON, and Markdown. Its notable features include easy integrations with popular frameworks, quick setup through minimal code, and the ability to extract specific information based on user input. The tool is particularly suited for developers seeking to streamline data extraction from websites and local documents at scale.

sarpy

SarPy 2.0 is a specialized Python library designed for reading, writing, and processing Synthetic Aperture Radar (SAR) data, primarily utilizing the National Geospatial-Intelligence Agency (NGA) SICD format. It features fast readers for various NGA file formats, including SICD, SIDD, CPHD, and CRSD, allowing efficient data manipulation and support for projections and remaps in SAR data. This updated version supersedes legacy functionalities, promoting standardization within the international SAR community.

RedzSIGINT

RedzSIGINT is a software framework designed to facilitate the development of customized SIGINT (Signals Intelligence) platforms, with a particular focus on creating a SIGINT vehicle. It provides configuration files and integration elements for tools such as OpenBTS and GNURadio, enabling users to capture, analyze, and jam signals effectively. Notable features include various configuration templates for IMSI catching, signal analysis, and frequency jamming, along with planned updates and community engagement for continued development.

QNXSecurity

The QNX Security Tools repository provides a suite of scripts designed for security research and analysis specifically within the QNX operating system environment. Its primary use cases include static analysis of firmware, multiple fuzzing tools targeting IPC and system calls, and device review, enabling researchers to identify vulnerabilities effectively. Notable features include specialized tools such as FWAnalysis, IPCFuzz, and blackberry_monitor.py, which facilitate comprehensive security assessments of QNX components.

py2mojo

py2mojo is a tool designed to facilitate the automated translation of Python code into the Mojo programming language. Its primary use case is for developers looking to leverage Mojo's features while maintaining existing Python codebases, providing options for in-place rewriting and file type specification. Notably, it employs an AST parser for code analysis, but users should be cautious of potential syntax discrepancies due to the experimental nature of Mojo.

PraisonAI

PraisonAI is a tool for deploying autonomous AI agents that can research, plan, and execute tasks across various applications with minimal setup. It offers capabilities such as code generation, content creation, data pipeline management, and customer support automation, all designed to improve productivity through a 24/7 AI workforce. Notable features include lightweight installation, multi-agent collaboration, and seamless integration into existing workflows.

PokemonGo-Bot

PokemonGo-Bot is a Python-based automation tool designed for playing Pokémon Go on various operating systems, enabling users to simulate gameplay through functions such as searching, spinning PokéStops, and managing Pokémon. Notable features include support for multi-bot configurations, customizable GPS location settings, and advanced behavioral options that mimic realistic human player actions. The bot allows extensive customization through pre-configured rules for catching, evolving, and transferring Pokémon, making it a flexible solution for automating gameplay.

Pokemon-Terminal

Pokemon-Terminal is a terminal-based application that allows users to interact with 719 unique Pokemon through a command-line interface. Its primary use case is to provide an immersive experience where users can select Pokemon by name or index, customize their terminal backgrounds, and search for Pokemon using an internal system. Notable features include support for various terminal emulators and desktop environments, making it versatile across different operating systems such as Windows, macOS, and Linux.

peda

PEDA (Python Exploit Development Assistance for GDB) is a GDB extension that enhances the debugging experience by colorizing disassembly and providing advanced commands to assist in exploit development. Notable features include utilities for checking binary security options, displaying function arguments, dumping ROP gadgets, and generating shellcode, all streamlined to facilitate the analysis and exploitation of binaries.