> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

aider

Aider is a terminal-based AI pair programming tool that leverages large language models (LLMs) to assist developers in starting new projects or enhancing existing codebases. Notable features include robust support for over 100 programming languages, automated Git integration for seamless version control, and the ability to work with both cloud and local LLMs, making it suitable for a wide range of coding environments. Additionally, Aider offers a codebase mapping feature to improve its functionality in larger projects, enhancing the development experience.

AgentForge

AgentForge is a low-code framework designed for rapid development and iteration of AI-powered autonomous agents and cognitive architectures. It supports a variety of LLM models and includes features such as declarative Cogs for orchestrating workflows, integrated memory for context-aware interactions, and dynamic prompt editing. This tool is aimed at both newcomers and advanced developers looking to create model-agnostic agent systems efficiently.

agent-zero

Agent Zero is an open agent framework designed to provide a fully functional Linux desktop environment within a Docker container, supporting comprehensive tasks beyond simple chat interactions. It features a browser with DOM annotation capabilities, live collaborative document editing, and a plugin hub for community extensions, allowing multi-agent cooperation and project-specific memory management. This tool is well-suited for scenarios requiring real GUI software usage, terminal access, and integration with local repositories through a CLI bridge.

Transcrypt

Transcrypt is a Python to JavaScript compiler that allows developers to write web applications in Python, which is then precompiled into optimized JavaScript for efficient loading and execution. It supports advanced Python features such as multiple inheritance, async/await, and decorators while ensuring seamless integration with JavaScript libraries suitable for web development. Notably, it offers readable code output, integrated static type checking, and debugging capabilities directly from Python source code, making it a robust tool for building professional web applications.

snipai

SnipAI is a macOS application designed for capturing and managing screenshots, leveraging local AI models to automatically describe and tag images. Its standout features include fast and accurate image description generation, natural language search using binary vector embeddings, and an interactive graph view for exploring similar screenshots. The tool emphasizes data privacy by processing all operations locally without the need for cloud storage.

secrets-patterns-db

Secrets Patterns Database is an extensive open-source collection designed for detecting secrets such as API keys, passwords, and tokens using regular expressions. It features over 1600 curated and tested regex patterns that are format-agnostic, allowing integration with various secret detection tools like TruffleHog and Gitleaks. The database emphasizes security by validating regex patterns against ReDoS attacks and categorizing them based on confidence levels, while also welcoming community contributions for ongoing enhancement.

RF-Drone-Detection

RF-Drone-Detection is a passive drone detection system designed to monitor Radio Frequency communications and identify the presence of drones by analyzing local Wi-Fi activity and mac addresses associated with drone manufacturers. Its primary use case is enhancing security and surveillance, particularly for institutional environments like the Georgia Tech Police Department, leveraging tools such as HackRF One and GNU Radio for detection methodologies. Notable features include detailed documentation for hardware and software setup, as well as a Wi-Fi monitoring script to aid in detection efforts.

pyWhat

PyWhat is a versatile identification tool designed for cybersecurity tasks, enabling users to quickly analyze and identify the nature of various types of text, files, and data structures. Its primary use cases include analyzing malware for critical information, extracting sensitive data from packet capture (pcap) files, and supporting bug bounty hunters in locating API keys and credentials with efficiency. Notable features include recursive scanning capabilities, file handling, and integration with various data analysis workflows, making it a valuable asset for rapid data identification and extraction.

pytm

pytm is a Python framework designed for threat modeling, aimed at automating and streamlining the process for developers. The tool automatically generates Data Flow Diagrams (DFDs), Sequence Diagrams, and relevant threat assessments based on user-defined architectural inputs. Notable features include support for generating reports and visual diagrams in various formats, along with options for customization and integration using containers or isolated environments like Devbox.

python-patterns

The python-patterns repository is a comprehensive collection of design patterns and idioms implemented in Python, aiming to provide developers with structured solutions to common programming challenges. It is organized into three main categories: Creational, Structural, and Behavioral patterns, each showcasing various strategies for object creation, class composition, and inter-object communication. Notable features include detailed descriptions and example implementations for each pattern, facilitating easier adoption and adaptation in Python projects.

prefect

Prefect is a Python-based workflow orchestration framework designed for automating and managing data pipelines. It enables users to create resilient and dynamic workflows by incorporating features such as scheduling, retries, and event-based triggers, while offering monitoring capabilities through both a self-hosted server and Prefect Cloud. Notably, Prefect supports complex branching logic and dependencies, allowing data teams to efficiently manage and scale their data processes.

PPPwn

PPPwn is a kernel remote code execution exploit designed for the PlayStation 4, compatible with firmware versions up to 11.00. This proof-of-concept tool leverages the CVE-2006-4304 vulnerability, enabling users to execute arbitrary code on the console via a PPPoE connection. Notable features include the ability to adapt payloads for different firmware versions and the requirement of a simple setup process involving Ethernet connectivity and Python scripting.

phantom-licensecheck

Phantom-licensecheck is a tool designed to analyze the firmware of DJI Phantom 3 drones for open-source code compliance, particularly focusing on identifying components subject to the GNU General Public License (GPL). It examines the firmware's structure, extracts code modules, and searches for recognizable open-source license fingerprints, thus enabling potential legal inquiry into DJI's adherence to open-source obligations. Notable features include detailed firmware package analysis, the capability to unpack compressed modules, and the output of findings that highlight the presence of proprietary and open-source licensed code within the firmware.

osint-geo-extractor

The `osint-geo-extractor` library facilitates the extraction of geo-related information from various databases, making it particularly useful for OSINT (Open Source Intelligence) applications. It provides functions to retrieve data from sources like Bellingcat, GeoConfirmed, and Texty.org.ua, returning event information as structured `Event` objects, which can be exported to GeoJSON format for further analysis. Notable features include convenient access to multiple data sources and sample usage examples to streamline implementation.

music21

Music21 is a Python toolkit designed for computer-aided musical analysis and computational musicology. It supports a wide range of musicological tasks, enabling users to analyze, visualize, and manipulate musical scores and data. Notable features include compatibility with several Python versions, an extensive user guide, and community engagement guidelines promoting inclusivity and collaboration.

memoripy

Memoripy is a Python library that facilitates context-aware memory management for AI-driven applications, enabling both short-term and long-term memory interactions. Key features include contextual memory retrieval based on embeddings, memory decay and reinforcement strategies, hierarchical clustering for semantic grouping, and graph-based associations, allowing for more relevant and dynamic responses in conversational models. Its compatibility with major AI APIs such as OpenAI and Ollama enhances its utility in advanced memory management scenarios.

media-search-engine

The OSINT Geolocation Databases Search tool facilitates the identification of pre-existing social media posts that have been geolocated across multiple databases, such as Belllingcat's and GeoConfirmed. It features a web UI, API, and command-line client, allowing users to query URLs for geolocation data while providing visualization capabilities via Leaflet.js. Key functionalities include data extraction, URL searches, and output in various formats (JSON, CSV) for further analysis.

letta

Letta is an AI toolkit designed to create agents with advanced memory capabilities that can learn and self-improve over time. It primarily serves to facilitate the development of stateful agents through the Letta Agent and SDK, enabling functionality both locally and in the cloud, while supporting skills and subagents for enhanced performance. Notable features include local execution via a CLI tool, a model-agnostic approach, and integration with popular machine learning models for optimized outcomes.

khoj

Khoj is a personal AI application designed to enhance user capabilities by integrating various local and online large language models (LLMs) for efficient information retrieval and interaction. Key features include the ability to answer queries from diverse document formats, operate on multiple platforms such as browsers and mobile devices, create customized AI agents, and automate research-related tasks with personalized notifications. It supports both self-hosted and cloud solutions, ensuring flexibility in deployment.

Hidden-in-Plain-Hex

Hidden-in-Plain-Hex is a steganography tool designed to uncover concealed information encoded within invisible Unicode tag characters. Its primary use case is in CTF (Capture The Flag) challenges, where participants must interpret seemingly meaningless sequences to decode hidden URLs or data using knowledge of Unicode and encoding schemes. Notable features include the systematic analysis of Unicode patterns, the ability to strip prefixes for data extraction, and conversion from hexadecimal to ASCII for reveal purposes.

haystack

Haystack is an open-source AI framework designed for creating production-ready retrieval-augmented generation (RAG) systems and agents. Its primary use case is to facilitate the development of applications that can efficiently search, manage, and utilize documents and data pipelines. Notable features include support for various document stores, integrations with popular NLP models, and a modular architecture that allows for easy customization and scalability.

grab-site

grab-site is a preconfigured web crawler designed for backing up websites by recursively crawling and capturing content into WARC files. It features a user-friendly dashboard for monitoring crawl status, allows dynamic ignore pattern adjustments during runtime, and includes built-in duplicate page detection to enhance efficiency. The tool is capable of managing extensive web archives, making it suitable for large-scale website preservation efforts.

gmapsapiscanner

The Google Maps API Scanner is a tool designed to assess the vulnerability of Google Maps API keys against unauthorized access by external applications. It provides functionality to check multiple API endpoints for potential exploitation and can be run directly or within a Docker environment. Notable features include customizable scanning options, a semi-automated check for JavaScript APIs, and detailed output including specific vulnerabilities identified with proof-of-concept links.

gguf-tools

GGUF Tools provides a suite of utilities for manipulating and viewing the GGUF file format, primarily designed for assessing model integrity and merging components. Notable features include `gguf-checksum`, which generates SHA256 checksums unaffected by field order, `gguf-frankenstein`, enabling the assembly of metadata and tensor data into new GGUF files, and `gguf-tensor-to-image`, capable of visualizing tensor data, including support for both GGUF and Torch formats.

fuzzable

Fuzzable is a framework designed to automate the discovery of fuzzing targets through static analysis of C/C++ binaries and source code, aiding vulnerability researchers in identifying functions suitable for fuzzing. With capabilities for generating harness templates and integration as a plugin for Binary Ninja, it streamlines the process of analyzing complex codebases while applying various static heuristics to pinpoint risky software behaviors. Additionally, Fuzzable can operate as a standalone CLI tool, making it accessible for broader security assessments and continuous fuzzing integration.