> cat /dev/github | grep security-tools

Rust

ida-headless-mcp

2026-08-31 Rust ★ 10
ida-headless-mcp is a Rust-based, multi-session headless server implementation for IDA Pro, designed to facilitate concurrent analysis of multiple databases while ensuring session isolation. Notable features include an explicit supervisor/worker architecture for process management, session lifecycle control, and a comprehensive suite of analysis tools categorized into 12 groups. This tool operates without GUI support, making it ideal for automated and headless environments requiring IDA Pro integration.

rsleigh

2026-08-31 Rust ★ 10
rsleigh is a pure-Rust reverse-engineering workbench designed to convert various binary formats, including PE, ELF, and Mach-O, into C-like pseudocode and other structured outputs like disassembly and call graphs. This tool excels in static analysis workflows by enabling users to navigate binaries efficiently, uncover function calls, analyze packed code, and integrate findings with LLMs for automated analysis, without dependence on JVM or C++ bindings. Notably, it supports a multi-architecture API, allowing for flexible integration and insights into binary behavior.

asimov-cli

2026-08-31 Rust ★ 26
ASIMOV CLI is a command-line interface designed for efficient data fetching and importation from various URLs, leveraging installed modules for enhanced functionality. Key features include the ability to automate data retrieval processes, execute external commands, and support multiple installation methods through popular package managers. This tool aims to streamline the data handling tasks in a public domain software environment.

asimov-sdk

2026-08-31 Rust ★ 32
The ASIMOV Software Development Kit (SDK) provides a polyglot framework for building trustworthy neurosymbolic artificial intelligence systems. It includes a command-line tool and a library that enables developers to create dataflow applications using reusable components called blocks, while supporting multiple programming languages such as Dart, Python, Ruby, Rust, and TypeScript. Notable features include a module system for ecosystem integration, flow-based program patterns for knowledge refinement, and its public domain licensing.

Warden

2026-08-31 Rust ★ 10
Warden is an autonomous endpoint detection and response (EDR) solution designed for Linux workstations, implemented in Rust to function without external servers or cloud dependencies. This tool monitors critical threat vectors such as ransomware, persistence mechanisms, privilege escalation, and malicious network activity, operating in either a monitoring or enforcement mode that allows for real-time response. Key features include robust detection modules tested rigorously through adversarial audits, local operation as a hardened systemd service, and optional eBPF capabilities for enhanced visibility into process execution and network connections.

dfang

2026-08-30 Rust ★ 10
Dfang is a tool designed for defanging and refanging indicators of compromise (IOCs) such as email addresses, URLs, and IP addresses to ensure safe transmission in potentially malicious environments. It features a command-line interface as well as a Rust library that allows developers to integrate the defanging functionality directly into their applications without external dependencies. Notable capabilities include transforming IOCs into unclickable formats and restoring them to their original state for analysis.

HexPatch

2026-08-30 Rust ★ 333
HexPatch: a binary patcher and editor written in Rust with terminal user interface (TUI).

patternsleuth

2026-08-28 Rust ★ 89
Patternsleuth is a testing suite designed to identify robust patterns for locating common functions and global variables within Unreal Engine games, specifically tailored for use with the UE4SS framework. Users can easily integrate game executables into the designated directory and run tests to analyze function recognition and isolation. Notable features include support for multiple game titles and a collection of established patterns that enhance the accuracy of symbol resolution.

rvt-rs

2026-08-28 Rust ★ 13
rvt-rs is a Rust/Python toolkit designed for inspecting Autodesk Revit files without requiring a Revit installation. It allows users to open OLE/CFB containers, decode truncated-gzip streams, extract metadata, and classify schema field encodings, with notable features including a zero-upload browser viewer that enables real-time 3D rendering and element analysis. The toolkit offers a variety of command-line interfaces and Python bindings, enhancing accessibility for both technical and non-technical users.

red-clippy

2026-08-28 Rust ★ 19
Red Clippy is an open-source penetration testing management tool designed to integrate with AI agents for streamlined test engagements. It retains detailed records of assets, observations, and findings, ensuring that testing sessions can progress smoothly without loss of information, while enforcing protocols for data verification and reporting. Notable features include a web-based interface for managing test data, customizable engagement rules, and the ability to connect to AI agents for enhanced testing efficiency.

stratum-c2

2026-08-28 Rust ★ 39
Stratum C2 is a cloud persistence framework designed to maintain command-and-control (C2) communication through trusted cloud storage providers like Dropbox and OneDrive, thus avoiding detection by traditional security defenses. Its notable features include end-to-end encryption with RSA and AES, the ability to switch between multiple cloud providers seamlessly, and a structurally unblockable channel that makes it difficult for security operations centers to intercept. The framework supports multiple agent formats for both Windows and Linux without requiring additional dependencies.

amv_decoder

2026-08-27 Rust ★ 10
`amv_decoder` is a Rust-based tool designed for parsing and partially decoding the AJPM (Alpha Movie) video format, predominantly utilized in KiriKiri engine titles. Its notable features include stability for reverse engineering tasks, the ability to read file headers, load quantization tables, and decode frame packets into RGBA frames, while also supporting the export of raw packet data and quick inspection PPM images.

datadome-rs

2026-08-27 Rust ★ 73
High-end Rust DataDome deobfuscator & solver with VM disassembly — all 3 challenge types (tags, interstitial, slider).

fluere

2026-08-26 Rust ★ 61
Fluere is a comprehensive network monitoring and analysis tool that captures network packets in pcap format and converts them into NetFlow data, enabling users to analyze traffic dynamics effectively. It supports both live and offline data capture across multiple platforms (Windows, macOS, Linux) and features a Terminal User Interface (TUI) for real-time feedback during live captures. Notable functionalities include integration with AWS Traffic Mirroring, active firewall implementation using plugins, and customizable command-line arguments for enhanced user experience.

sdocx

2026-08-26 Rust ★ 19
sdocx is a reverse-engineered tool and SDK designed for parsing and converting Samsung Notes (.sdocx) files, primarily used to extract and manipulate handwritten notes stored in these formats. Key features include a command-line interface for easy access, library support for Rust and JavaScript environments, and a best-effort parsing approach that provides insights into document structure, stroke data, and metadata while acknowledging potential limitations and fidelity concerns.

databoxer

2026-08-25 Rust ★ 13
Databoxer is a lightweight, cross-platform data encryption tool designed for efficiency, safety, and user-friendliness. It employs the ChaCha20 encryption algorithm combined with the Poly1305 hash function, allowing for secure, fast encryption of files, which are stored in a unique `.box` format encapsulating data integrity and metadata. Notable features include a profile management system for key storage and planned integration with native keyring tools for enhanced security.

BTG-packer

2026-08-24 Rust ★ 27
BTG Packer is a Rust-based research framework for the analysis, transformation, and virtualization of Windows x86-64 PE32+ executables. It features comprehensive functionality including PE reconstruction, control-flow transformation, RISC lifting, and runtime protection, making it suitable for security research and code modification tasks. Notable capabilities include its ability to generate polymorphic virtual machines, conduct advanced code analysis, and ensure build determinism and structural validation.

Ghidrust

2026-08-24 Rust ★ 12
Ghidrust is a Rust-based reverse-engineering toolkit designed for analyzing PE and ELF binaries, offering multi-architecture support through Capstone-class listings and pseudo-C decompilation. Its key features include a headless CLI, a GUI interface, an experimental GPU decompilation capability for enhanced performance, and integrated network analysis via Ghidnet for process attribution and IDS records. Ghidrust aims to improve upon Ghidra's analysis speed and output quality while maintaining a small, auditable core.

rilua

2026-08-24 Rust ★ 42
rilua is a Rust-based implementation of Lua 5.1.1 designed primarily for the World of Warcraft emulation ecosystem, enabling addon development, server-side scripting, and client Lua environment emulation without external dependencies. Notable features include a safe memory model with no unsafe blocks, structured error handling that preserves the call stack, and native WASM support, making it suitable for embedding in Rust applications while facilitating accurate behavioral equivalence with the reference Lua interpreter.

secutils

2026-08-23 Rust ★ 101
Secutils.dev is an open-source security toolbox designed for engineers and researchers, bridging the gap between complex enterprise solutions and scattered simple tools. It offers a guided experience for managing diverse security tasks, including webhooks for rapid API mocking, templates for cryptographic testing, and tools for Content Security Policy management. Notable features include user-friendly access to single-page tools, which do not require sign-up and provide stable URLs for easy sharing and AI-agent skills for enhanced automation.

HSR-OWNER

2026-08-22 Rust ★ 43
HSR-OWNER is a comprehensive reverse-engineering and modding toolkit specifically designed for Honkai: Star Rail on Windows, stripped of any illicit cheat features to maintain legitimacy. It provides functionalities to analyze game data, modify client behavior, and aid in updating through minimal manual intervention, with full support for integration with AI tools for automation. Key features include a runtime layer that adapts to game updates, in-depth client analysis capabilities, and a straightforward build process using the MSVC toolchain.

Oxide-communityedition-v8.7.2

2026-08-22 Rust ★ 13
OXIDE is a precision-forged vulnerability scanner developed in Rust, designed primarily for authorized penetration testing and security research. It features a unique combination of traditional scanning methods and machine learning-based anomaly detection, along with integrations for tools like Burp Suite, and offers a modular architecture for extensibility. Notable features include a headless DOM, WAF evasion capabilities, and enhanced security with an embedded TLS certificate, making it suitable for use in both lab environments and real-world assessments.

hacksguard

2026-08-20 Rust ★ 204
Hacksguard is a high-performance, multi-threaded Terminal UI (TUI) static analysis tool designed for SOC analysts, threat hunters, and reverse engineers to analyze Portable Executable (PE) files. Key features include automatic risk scoring based on multiple heuristic axes, integrated YARA scanning capabilities for threat detection, deep inspection of PE format details, and an interactive dashboard for efficient analysis within the terminal. Additionally, it offers functionality for auto-decoding strings, built-in disassembly of opcodes, and can operate in CLI mode for automation in CI/CD environments.

fnprint

2026-08-20 Rust ★ 34
fnprint is a binary analysis tool that uniquely identifies functions in stripped executables by analyzing their behavioral side effects rather than relying on byte signatures or control-flow graphs. It emulates function execution with fabricated inputs to generate behavior-based fingerprints, allowing for more resilient matches across different compiler optimizations and versions. Key features include indexing known binaries for function identification, differential analysis to detect behavioral changes between builds, and a triage capability to assess potential vulnerabilities based on function behavior comparison.

cordial

2026-08-19 Rust ★ 22
Cordial is a tool that enables the native execution of Roblox's Android x86-64 engine on Linux, employing a custom runtime that bypasses traditional emulation methods. It uniquely supports user-extensible functionality through plugins, allowing developers to write custom code that integrates directly into the client without modifying the core Roblox experience. Notable features include direct GPU access through Vulkan or GLES2 and a robust API designed for plugin development, emphasizing a commitment to maintainability and community contribution.

memory-forensic

2026-08-18 Rust ★ 11
memory-forensic is a cross-platform memory forensics toolkit designed for analyzing Windows kernel memory through an independent implementation that matches the output of Volatility 3. It reads various memory dump formats and allows users to retrieve detailed process and network connection information without needing Python or pre-staged symbol catalogs. Notably, it offers a self-profiling capability to locate kernel symbols and validate its results through rigorous comparison with reference implementations, ensuring high correctness in process recovery.

ida-headless-mcp

2026-08-18 Rust ★ 12
ida-headless-mcp is a Rust-native server designed for headless interactions with IDA Pro, allowing for multi-session handling of databases through a supervisor-worker model. It provides public tools for database management and analysis, supports both stdio and Streamable HTTP modes, and is optimized for a headless environment with no GUI components involved. Notable features include individual worker processes for each database session and a limit on the number of simultaneous worker processes for efficient resource management.

blastdns

2026-08-18 Rust ★ 10
BlastDNS is an ultra-fast DNS resolver implemented in Rust, optimized for mass DNS lookups with superior performance when multiple resolvers are provided. Its notable features include built-in caching, support for various record types, and configurable parameters for fine-tuning performance, such as timeout settings and error handling. The tool can be utilized through a command-line interface, Rust library, or Python library, making it versatile for integration into broader applications or for use as a standalone resolver.

web-re-toolkit

2026-08-17 Rust ★ 38
web-re-toolkit is a reverse engineering toolkit designed to solve Akamai Bot Manager and Kasada Bot Defence protections without using a browser, leveraging a V8 sandbox. It features the capability to handle V2 and V3 sensors, along with various interrogation processes, while maintaining compatibility with real device profiles and allowing for cross-language integration across Node, Python, Go, and Rust. Notably, it utilizes the vendor's original scripts for payload calculation, ensuring robust operation against evolving web security measures.

recurse

2026-08-17 Rust ★ 26
Recurse is a reverse engineering desktop application leveraging radare2 for binary analysis, disassembly, and optional decompilation through r2ghidra integration. Notable features include a Cursor-style workspace for efficient navigation, a live analysis session capability, and an LLM agent that enhances the reverse engineering process via interactive queries driven by an OpenAI-compatible backend. Accessible through a dark-first UI, it aims to streamline the reverse engineering experience for security professionals and researchers.

brutecraber

2026-08-17 Rust ★ 11
BruteCraber is a high-performance hash cracking tool developed in Rust that utilizes GPU acceleration via OpenCL by default, with a seamless fallback to a multithreaded CPU backend when necessary. It supports a variety of hashing algorithms including MD5, SHA-1, SHA-256, and modern key derivation functions like Argon2 and Scrypt, along with automated hash type detection and a customizable rules engine for generating password variations. Its simplicity allows users to initiate cracking with a single command, eliminating the need for complex configurations.

dearxan

2026-08-16 Rust ★ 55
`dearxan` is a library designed for static and runtime analysis/patching of the Arxan protection checks embedded in binaries, specifically targeting various FromSoftware games. Its primary use case is to fully neutralize Arxan's anti-debug and integrity checks, thereby allowing for unhindered gameplay and modding experiences. Notable features include a straightforward API for integration with Rust, C, and C++ applications, as well as best-effort support for DLL injectors that do not suspend processes upon creation.

altium-designer-mcp

2026-08-16 Rust ★ 36
The Altium Designer MCP is a server tool that enables AI assistants to efficiently create and manage Altium Designer component libraries, specifically `.PcbLib` and `.SchLib` files, by handling file input/output and primitive placement. This tool addresses the challenges of manually building libraries by allowing AIs to perform engineering tasks while it manages the complexities of the undocumented binary formats, supporting the creation of any component rather than just predefined packages. Notable features include compatibility with multiple AI assistants and the ability to automate footprint generation based on datasheet interpretation and design specifications.

delink

2026-08-16 Rust ★ 13
delink is a versatile tool designed for splitting binaries in decompilation projects, supporting multiple formats such as shared objects, Mach-O, and Windows PE with associated PDBs. It features an IDA import mechanism that allows users to leverage IDA's analysis for splitting binaries without needing direct debug information, thereby enabling detailed function and relocation management. The output is customizable, accommodating usage across various architectures with a focus on both ELF and PE outputs.

dirplayer-rs

2026-08-14 Rust ★ 398
DirPlayer is a Rust-based emulator for Shockwave Player that facilitates the playback of legacy browser games in modern web environments. Its primary functionalities include a Chrome extension that auto-replaces `<embed>` elements linked to Shockwave files, a standalone application for debugging Lingo scripts, and a JavaScript polyfill for easy integration into web pages. Key features comprise a complete debugging toolset and a self-contained polyfill that includes a WebAssembly (WASM) virtual machine.

hudhook

2026-08-14 Rust ★ 355
Hudhook is a Rust-based rendering hook library designed for creating overlays with Dear ImGui, supporting rendering through DirectX 9, 11, 12, and OpenGL 3 on Windows and Wine/Proton. Its notable features include seamless integration for various graphics APIs, extensive documentation, and easy implementation through customizable render loops. The tool is particularly useful for developers looking to add interactive graphical interfaces to existing applications.

hxy

2026-08-14 Rust ★ 26
hxy is a hex editor developed in Rust that operates on both desktop and web platforms, utilizing the egui framework for its user interface. Its main use case is to provide a comprehensive tool for editing and inspecting binary data, featuring a file-backed hex view, data inspector, and support for various archive formats with a VFS browser. Notable functionalities include an integrated 010 Editor Binary Template runtime, ImHex pattern support, and IPC capabilities for opening files through the command line.

pw

2026-08-13 Rust ★ 12
PW is a web-based tool designed for securely sharing confidential information, with all data encrypted in the browser. Its primary use case includes sharing secrets through supported media types such as text and files while maintaining low resource usage and offering dynamic configuration limits based on IP whitelisting. Notable features include a fast performance due to Svelte and Rust, multi-language localization support, and a user-friendly interface with dark theme options.

bulwark

2026-08-12 Rust ★ 10
Bulwark is a comprehensive security tool for Linux systems, providing configuration validation, antivirus scanning with ClamAV, and specialized monitoring for AI coding assistants to prevent sensitive data leaks. Its framework includes 65 rules across multiple categories, plain-language findings, and one-click reversible fixes, ensuring users can easily address security issues. Additionally, Bulwark features a CLI interface (`bulwarkctl`), provides continuous monitoring, and employs a log analysis pipeline to detect security events.

sighook

2026-08-12 Rust ★ 43
Sighook is a runtime patching library primarily designed for low-level software experimentation, reverse engineering, and custom instrumentation workflows. It enables instruction-level manipulation through features such as inline detours, byte patching, and callback mechanisms for capturing execution at specified instructions. Notable capabilities include support for multiple architectures (x86_64 and aarch64), and functions for instrumenting calls, restoring original bytes, and handling function-entry hooks, making it adaptable for diverse use cases across different platforms.

blackhat-tools

2026-08-12 Rust ★ 13
Black Hat Tools is a repository designed for developing asynchronous and concurrent software for security applications using languages such as TypeScript, Go, Rust, and Python. The primary use case involves executing network-based tests and exercises derived from well-known cybersecurity literature, with notable features including integration with specific testing domains for practical application. This tool is still a work in progress, reflecting ongoing development in its functionality.

phraze

2026-08-11 Rust ★ 42
Generate random passphrases

apk-info

2026-08-11 Rust ★ 136
apk-info is a comprehensive tool for parsing Android APK files, designed primarily for analyzing and extracting information regarding APK contents and signatures. Its notable features include support for multiple APK signature schemes, excellent extraction capabilities for Android Binary XML and resources, and user-friendly command-line and Python bindings for easy integration into workflows. The tool also enhances malware analysis with its specialized extraction functionalities and provides accurate identification of the main activity in Android applications.

anya

2026-08-10 Rust ★ 11
Anya is a fast, offline static malware analysis platform that processes a wide variety of file formats, including PE, ELF, PDF, and Office documents, without executing them. Key features include high-speed analysis of over 250 files per minute, detailed output such as hashes, entropy, and risk scores, while offering integration with MITRE ATT&CK mappings and support for both GUI and CLI interfaces across multiple operating systems. It should be noted that Anya is transitioning its development to the MalChela project for future enhancements.

dotscope

2026-08-10 Rust ★ 25
dotscope is a high-performance, cross-platform framework designed for the analysis, reverse engineering, and modification of .NET PE executables, implemented in pure Rust. It offers features such as efficient memory access, comprehensive metadata analysis, assembly modification capabilities, and a full bytecode interpreter, allowing users to manipulate CIL bytecode and structure without dependence on Windows or the .NET runtime. Additionally, it incorporates advanced functionalities like deobfuscation and static analysis, making it a versatile tool for .NET developers and security researchers.

rfvp

2026-08-10 Rust ★ 130
rfvp is a non-official Rust-based cross-platform implementation of the FVP engine and IDE, enabling users to run and debug games while also functioning as an operating system with UEFI support. Notable features include the ability to use custom fonts, support for different text encodings for translated games, and platform-specific installation guides across major operating systems. Additionally, rfvp offers a debug HUD and the potential to develop applications based on the engine, thus enhancing its versatility.

SeeYou

2026-08-10 Rust ★ 18
SeeYou is a comprehensive real-time global intelligence platform that visualizes live data from over 25 public APIs on a dynamic 3D globe built with CesiumJS. Its primary use case includes tracking and analyzing diverse phenomena such as aircraft, satellites, earthquakes, wildfires, and cyber threats, with advanced features like military-grade shaders, predictive modeling for aircraft trajectories, and a wide array of intelligence layers. The platform operates entirely locally, requires no paid services, and offers multiple live data overlays to provide an integrated view of various global events and activities.

sherlock-rs

2026-08-10 Rust ★ 63
Sherlock-rs is a Rust-based tool designed to hunt down social media accounts by a specified username across over 400 social networks. It provides features such as outputting results to text, CSV, or Excel files, supports proxy usage, customizable site analysis, and extensive debugging options, making it ideal for users needing comprehensive username availability checks across multiple platforms.

hexerator

2026-08-09 Rust ★ 369
Hexerator is a versatile GUI hex editor for Linux designed for binary file exploration and pattern recognition. It leverages the latest nightly Rust features for enhanced functionality while encouraging contributions that optimize code without compromising performance or maintainability. The tool is particularly suited for developers and researchers who require advanced capabilities in analyzing binary data.

knife

2026-08-09 Rust ★ 39
Knife is a comprehensive binary analysis tool designed for reverse engineers, enabling static examination of PE, ELF, and Mach-O file formats without execution. It consolidates multiple analysis functions—such as header parsing, IOCs extraction, and disassembly—into a single command, while providing detailed triage reports on exploit mitigations and dangerous API calls. Key features include a variety of commands for deep analysis, an interactive TUI mode, and extensive output options tailored for vulnerability research and malware analysis.

ARES-Spoofer-Byfron

2026-08-08 Rust ★ 55
ARES-RS is a Rust-based Roblox spoofer designed to protect user accounts from Byfron's detection and Roblox's ban system by modifying hardware identifiers (HWIDs). It features extensive configurability, automatic updates, and enhanced error handling, allowing users to execute spoofing operations either manually or automatically upon closing the Roblox application. Notable capabilities include spoofing BIOS, motherboard, and various hardware components, with recommendations for optimal use alongside a VPN.

ghost

2026-08-08 Rust ★ 387
Ghost is a robust process injection detection tool developed in Rust, designed to monitor running processes for signs of code injection, memory manipulation, and other malicious activities on Windows, Linux, and macOS. Its notable features include detection of memory anomalies, shellcode patterns, API hooks, and thread hijacking, all while mapping behaviors to the MITRE ATT&CK framework to aid in threat documentation. The tool offers both a command-line interface and an interactive terminal UI, providing real-time scanning results and support for extensible features like YARA rule scanning and neural ML integration.

oak-keyring

2026-08-07 Rust ★ 231
oak-keyring is a privacy-centric, terminal-based password manager that provides an interactive TUI for browsing, managing, and securing credentials. Key features include a customizable password generator, efficient vault management with tagging and soft-delete options, cloud sync capabilities via Google Drive, and robust recovery options. The tool emphasizes a local-first approach, ensuring user data remains private while facilitating convenient keyboard-driven interactions.

scan

2026-08-07 Rust ★ 49
Atomdrift Scan is a machine learning-based malware scanner designed for detecting 0-day attacks in the software supply chain. Its primary use case revolves around scanning files, URLs, and processes with support for over 100 file formats and more than 100,000 detection rules, delivering an 82% detection rate. Notable features include advanced static analysis with reinforcement learning for frequent rule updates, automated binary reverse engineering, and flexible integration into existing workflows.

badpiggies-editor

2026-08-07 Rust ★ 10
Bad Piggies Editor is a cross-platform tool for editing levels and saves in the game "Bad Piggies," developed in Rust. It allows users to manipulate various file formats, including `.bytes` and `.yaml`, while offering features such as a six-pass wgpu renderer for enhanced graphical representation and a CLI for file conversion and encryption. The application employs a shared backend architecture for both native and web environments, utilizing Web Workers for optimized processing and rendering tasks.

vesper

2026-08-07 Rust ★ 328
Vesper is a high-performance OSINT username scanner designed to investigate user profiles across over 2000 social networks and websites. Built in Rust, it offers features such as asynchronous scanning, Tor proxy support for privacy, automated screenshots of found profiles, and comprehensive reporting options including JSON and CSV formats. Its professional CLI provides real-time progress tracking, allowing users to efficiently gather and analyze online presence information.

envy

2026-08-06 Rust ★ 10
Envy is a local-first secret management tool that encrypts sensitive data using AES-256-GCM, ensuring that secrets are never stored in plaintext, whether on disk or in version control. Its key features include zero-trust storage with master key protection in the OS Keychain, memory-safe secret injection with automatic zeroing of sensitive data, and GitOps-native workflows that allow teams to manage secrets securely without reliance on external services. Additionally, Envy provides a pre-encrypt audit trail for visibility before sealing changes, facilitating multi-team access control with separate passphrases.

heretek

2026-08-06 Rust ★ 389
Heretek is a GDB TUI dashboard that facilitates debugging by allowing seamless connections to remote targets without the need for a functioning `gdbserver`. It is designed to operate without Python dependencies, is architecture-agnostic, and can work with minimal requirements (just `gdb`, `nc`, `cat`, and `mkfifo`), making it an ideal tool for developers facing issues with standard `gdbserver` binaries. Notable features include static linking for ease of use and robust support for various GDB commands execution.

fretwire

2026-08-06 Rust ★ 20
fretwire is an independent Linux editor for the Line 6 HX Stomp and Helix Floor, developed in Rust. It interfaces with the pedal via the MI_00 USB control protocol, allowing users to import data from their own HX Edit installation to manage presets and settings. Notable features include a graphical user interface built with WebKitGTK and Svelte, a command-line interface for device operation, and the ability to run a mock device for UI demonstration without hardware.

objdiff

2026-08-06 Rust ★ 525
objdiff is a local diffing tool designed for analyzing changes between decompilation project object files, providing detailed comparisons of functions and data within these files. It features built-in C++ symbol demangling, automatic rebuild on source changes, project-specific configuration options, and support for multiple architectures including ARM, MIPS, and x86. Additionally, the tool integrates with a web interface and has a Visual Studio Code extension in development, enhancing user accessibility and functionality in object file analysis.

unixtract

2026-08-06 Rust ★ 29
unixtract is a Rust-based extraction tool designed to unpack various firmware package formats primarily used in TVs and AV devices, ensuring compatibility across multiple platforms including Windows, Linux, MacOS, and Android. Its notable features include support for various file formats such as Amlogic burning images and Android OTA payloads, along with the ability to specify options for format-specific behaviors, while maintaining simplicity as it does not involve re-packing of the extracted files.

rustinel

2026-08-05 Rust ★ 460
Rustinel is an open-source endpoint detection tool designed for Windows, Linux, and macOS systems, focusing on providing native telemetry and alerting capabilities. It supports detection formats like Sigma and YARA, enabling rule reuse without needing proprietary adaptations, and produces SIEM-ready alerts in the Elastic Common Schema format. Key features include hot reloading for rules and IOC management, active response options for Windows and Linux, and comprehensive logging of alerts.

rebuilderd

2026-08-05 Rust ★ 428
rebuilderd is an independent verification system designed to ensure the reproducibility of binary packages from their source code within Linux distributions. Its primary use case is to monitor package repositories, utilizing backends to verify that binaries have been successfully rebuilt, while generating reports of discrepancies for troubleshooting. Notable features include support for various distributions like Arch Linux and Debian, and the ability to run instances locally, enhancing confidence in package integrity against tampering.

huginn-net

2026-08-04 Rust ★ 211
Huginn Net is a passive traffic fingerprinting tool that analyzes TCP, HTTP, and TLS protocols without active probing, providing insights into operating systems, applications, network infrastructure, and client capabilities. Built in pure Rust, it utilizes open-source specifications such as p0f for TCP and JA4 for TLS, allowing for community-driven signature databases. Notable features include support for HTTP/1 and HTTP/2 fingerprinting, OS type and version identification, and detailed analysis of TLS handshakes and TCP signatures.

secret-scan

2026-08-04 Rust ★ 10
Secret-scan is a high-performance secret detection tool designed for scanning codebases to identify and remediate exposed credentials, API keys, and sensitive information, thereby helping to prevent security vulnerabilities. Key features include parallel scanning for enhanced speed, support for over 30 secret types through advanced entropy analysis and regex pattern matching, customization options for detection rules, and multiple output formats. The tool operates with zero configuration by default, respects `.gitignore` files, and ensures production readiness with 100% test coverage.

ps5rs

2026-08-04 Rust ★ 19
ps5rs is a Rust-based framework designed for analyzing PS5 binaries, facilitating virtual loading and host-side emulation. Its primary use case involves parsing various binary formats, resolving imports, and extracting clean ELFs, while notable features include an interactive dashboard for analysis reports and a host-side emulator that executes guest binaries using pure Rust high-level emulation (HLE) modules. The framework leverages Rust's memory safety benefits to manage untrusted binary data securely.

CollapseScanner

2026-08-04 Rust ★ 14
CollapseScanner is a static security analysis tool specializing in the inspection of Java JARs, class files, and nested archives without executing them. It detects high-risk elements such as hardcoded secrets, suspicious APIs, and obfuscation techniques, allowing for customizable scans through various detection modes and options for detailed reporting. Notable features include support for configuration via TOML files, multi-threading for enhanced performance, and output in machine-readable JSON format for easier integration into automated workflows.

rusty_box

2026-08-04 Rust ★ 30
Rusty Box is a Rust-based emulator for 32/64-bit x86 architecture that supports full system virtualization and various advanced features such as integration with the x87 FPU and AVX extensions. It is capable of booting multiple Linux distributions, including DLX and Alpine, both in headless and GUI modes, and can be executed in web browsers using WASM. The tool also supports UEFI applications and provides multiple build configurations, including no_std environments for embedded targets, making it versatile for a range of use cases in emulation and testing.

git2mail

2026-08-04 Rust ★ 10
git2mail is an OSINT tool designed to efficiently find developers' email addresses from GitHub repositories and profiles by scraping commit metadata via the GitHub API. It supports both single and multi-token authentication for rapid bulk reconnaissance, allowing for the analysis of large repositories in under a minute. Notable features include support for a variety of repository and profile URL formats, high-performance data retrieval, and customizable token management for extensive scraping capabilities.

Rust-Privesc

2026-08-03 Rust ★ 20
Rust-Privesc is a collection of proof-of-concept (POC) tools designed to demonstrate User Account Control (UAC) bypass techniques implemented in Rust. It includes methods such as exploiting fake trusted directories and manipulating environment variables to execute command shell processes. Notable features include straightforward implementations of UAC bypass methods and the execution of `cmd.exe` as a default behavior.

copyfail-rs

2026-08-03 Rust ★ 19
copyfail-rs is a cybersecurity tool that provides multi-vector proof-of-concept (PoC) exploitation and detection for CVE-2026-31431, specifically targeting vulnerabilities in PAM authentication systems. Its notable features include a unique PAM auth-bypass vector and a detection mechanism that identifies alterations in critical files that traditional file integrity monitoring solutions overlook, using a novel hashing approach that differentiates between actual disk state and memory cache mutations. This tool operates as a single static binary with no runtime dependencies, making it easily deployable across various Linux architectures.

copyfail-rs

2026-08-03 Rust ★ 14
copyfail-rs is a Rust implementation of the Copy Fail exploit (CVE-2026-31431), which demonstrates a local privilege escalation vulnerability on major Linux distributions by chaining the `AF_ALG` and `splice()` syscalls. This tool features a high-performance and memory-safe design, dynamic ELF payload construction, zero-copy exploitation for efficient interaction with the Linux kernel, and allows customization of commands to be executed with root privileges. It is intended strictly for educational and research purposes, focusing on understanding and mitigating similar vulnerabilities.

RUSTVERSARY

2026-08-03 Rust ★ 29
RustVersary is a comprehensive toolkit designed for malware development and penetration testing using the Rust programming language. It includes a variety of tools and scripts that facilitate tasks such as enumeration, exploitation, and post-exploitation, each thoroughly documented to aid both personal use and community contributions. Notable features include advanced techniques for process injection, persistence mechanisms, and a structured catalog of utilities tailored for security assessment challenges.

ferrocrypt

2026-08-03 Rust ★ 19
FerroCrypt is a specialized Rust library, CLI, and desktop application designed for secure file and directory encryption and decryption using both password-based and key-pair encryption methods. It allows users to create encrypted `.fcr` files that can securely be accessed by designated recipients through specific passphrase or public-key decryption methods. Notable features include an interactive command-line interface, support for multiple encryption methods, and an easy-to-use desktop application for end-users.

honggfuzz-rs

2026-08-03 Rust ★ 500
honggfuzz-rs is a Rust binding for the Honggfuzz fuzzer, enabling feedback-driven and evolutionary fuzz testing for Rust code. It offers features like fuzzing with runtime instrumentation, crash replay in a debugging environment, and support for various sanitizers, making it suitable for security-oriented software testing across multiple operating systems and architectures. The tool can be easily integrated into Rust projects by adding it as a dependency and utilizing its provided macros for fuzzing functionality.

pysentry

2026-08-03 Rust ★ 249
PySentry is a robust vulnerability scanning tool for Python dependencies, designed to audit projects against known security issues by analyzing lock files or manifests and resolving the full dependency tree. Its notable features include support for various dependency formats, integration with multiple vulnerability databases for comprehensive reporting, and capabilities for continuous integration (CI) environments, allowing detailed output formats and customizable failure thresholds. The tool is optimized for speed, utilizing a Rust core for efficient processing and local caching.

aiward

2026-08-03 Rust ★ 12
Ward is a local-first secret firewall designed for development environments, ensuring that project environment variables are securely encrypted in a `.env.vault` file while allowing seamless terminal workflows and scoped access for AI agents. Notable features include a simple recovery flow that keeps plaintext secrets off servers, human mode for terminal session protection, and support for agent workflows through generated instructions, all while maintaining local metadata storage for added security.

hexora

2026-08-03 Rust ★ 168
Hexora is a static analysis tool for Python code that identifies malicious patterns and harmful constructs through a combination of rule-based analysis and machine learning scoring. Its primary use cases include auditing project dependencies for supply chain vulnerabilities, detecting malicious scripts on public platforms, and analyzing compromise indicators from previous security incidents. Notable features include high-confidence scoring for detected threats, customizable audit options (such as excluding specific rule codes), and the ability to audit entire directories or virtual environments.

randompass

2026-08-03 Rust ★ 10
randompass is a static password generator that produces 20-character passwords with a combination of lower and uppercase letters as well as special characters enabled by default, simplifying the process of creating complex passwords. The tool allows users to customize the password length and can be easily installed via Cargo or used with precompiled binaries and Docker images. Notable features include guaranteed complexity in generated passwords and the ability to disable specific character categories if desired.

twistrs

2026-08-03 Rust ★ 135
Twistr is a Rust-based domain name permutation library that serves as a direct port of the well-known dnstwist tool, enabling fast and flexible permutational analysis of domain names. Its primary use case involves generating variations of a given domain to aid in identifying potential squatting or phishing attempts. Notable features include granular control over permutation algorithms, an allocation-free API for high throughput, and a core library designed for easy extensibility for command-line interfaces and other integrations.

qos

2026-08-03 Rust ★ 118
QuorumOS (QOS) is a specialized operating system designed for deploying applications within a Trusted Execution Environment (TEE) at cloud scale. It ensures secure computation by facilitating coordinated provisioning of a secure environment among multiple actors, employing a unique Quorum Key for data encryption and authentication. Notable features include deterministic builds using the StageX distribution and support for minimal, immutable Linux unikernel operations tailored for high-security use cases.

dotscope

2026-08-03 Rust ★ 25
dotscope is a high-performance, cross-platform framework designed for analyzing, reverse engineering, and modifying .NET PE executables using Rust. Its key features include efficient memory access for parsing and modifying CIL bytecode, comprehensive metadata analysis, method injection capabilities, and a rich set of tools for static analysis and deobfuscation. The tool supports native PE operations and is built with robustness in mind, providing memory safety and extensive error handling.

ghidra-cli

2026-08-03 Rust ★ 198
Ghidra CLI is a Rust-based command-line tool designed for automating reverse engineering tasks within the Ghidra framework. It features a direct communication bridge to Ghidra's JVM, enabling fast, in-memory queries and program analysis without the overhead of separate JVM invocations for each command. Notable functionalities include batch operations, flexible output formats, type system manipulation, and the ability to execute scripts, all of which enhance the efficiency of reverse engineering workflows.

lancelot

2026-08-03 Rust ★ 113
Lancelot is an Intel x86(-64) code analysis library designed to reconstruct control flow, facilitating detailed program analysis. It supports WebAssembly, enabling execution in browser environments, and includes a Zydis-based disassembler for enhanced disassembly capabilities. Notable features include integration with Cranelift for advanced code generation and the ability to create JavaScript bindings for easy deployment in Node.js and browser contexts.

malwaredb-rs

2026-08-03 Rust ★ 60
Malware DB is a malware knowledge management system designed to catalog and manage the lifecycle of malware, benign, and unknown file samples, including their hashes, origins, and similarity metrics. Targeted at malware researchers and forensic investigators, it offers features such as sample categorization via custom taxonomies, group-based access permissions, file encryption, and advanced search capabilities based on file characteristics and Yara rules. This tool is currently in beta and emphasizes best practices for handling potentially harmful samples.

PETriage

2026-08-03 Rust ★ 13
PETriage is a cross-platform Portable Executable (PE) surface analysis tool designed for malware triage, implemented in Rust for efficiency on Linux, macOS, and Windows. It offers a static-only analysis approach, ensuring the PE files are not executed, making it suitable for safe malware examination. Key features include a command-line interface for batch processing, interactive and graphical interfaces for detailed analysis, and extensive detection capabilities that encompass anomaly detection, OPSEC analysis, and PE file manipulation functionalities.

alkahest

2026-08-03 Rust ★ 88
Alkahest is a tool designed to facilitate the analysis and transformation of shader code, specifically targeting optimization and adaptability for game development. Its primary use case lies in improving visual fidelity and performance in rendering engines, particularly for projects inspired by the technological advancements in games like Destiny 2. Notable features include support for multiple shader languages and an extensive library of resources linked to graphics technology in the gaming industry.

dexdec

2026-08-03 Rust ★ 78
DexDec is a native reverse-engineering tool designed for decompiling and analyzing complex Android applications, capable of handling large APK files and producing high-fidelity Java or Kotlin code. Its notable features include fast project opening and responsive exploration, symbol-aware navigation, and seamless integration with AI agents for enhanced code analysis. Additionally, it supports a professional workspace with customizable themes and reversible renaming capabilities, making it an efficient choice for developers and security analysts.

mtkview

2026-08-03 Rust ★ 15
mtkview is a tool designed for loading GFH preloader binaries and MTK Little Kernel partitions within the Binary Ninja environment. Its primary use case is to facilitate the analysis of MTK firmware binaries by providing support for preloader and LK formats. Notable features include integration with Binary Ninja, allowing users to select and analyze these specific binary types, and the ability to build and install the tool manually from the source.

capa-rs

2026-08-03 Rust ★ 19
capa-rs is a file capability extractor designed to analyze executable files, including PE, ELF, Mach-O, and .NET binaries. It identifies specific capabilities and behaviors, such as potential backdoor functions or security attributes like ASLR and NX, while providing a command-line interface for ease of use. The tool is a Rust implementation of the original Python capa, offering high accuracy and customizable security checks, making it suitable for in-depth malware analysis and binary security assessments.

MikuTrace

2026-08-03 Rust ★ 36
traceMiku is an instruction-level dynamic tracing and runtime analysis tool designed for ARM64 Android devices. It captures real execution paths and provides various analysis features, including control flow graphs (CFG), call trees, taint tracking, and memory queries. Notably, it integrates with Frida for data collection and supports structured JSON output for automated analysis, complementing static tools like IDA and Ghidra.

augur

2026-08-03 Rust ★ 120
Augur is an advanced IDA headless plugin designed for efficient analysis of binary files by extracting strings and associated pseudocode. Its primary use case is to streamline vulnerability research by organizing and storing the pseudocode of functions that reference specific strings in an intuitive directory structure, leveraging the Hex-Rays decompiler's capabilities. Notable features include rapid processing, support for various architectures, and a robust decompilation process using the `decompile_to_file` API from the Haruspex library.

disrobe

2026-08-03 Rust ★ 98
disrobe is a static Rust binary designed for decompiling, deobfuscating, and unpacking compiled software across more than 20 programming ecosystems, including Python, JVM, .NET, JavaScript, and native binaries. It operates without executing the sample code, ensuring byte-identical outputs across platforms, supported by rigorous testing and validation against known references. Key features include automated pipeline composition for various formats and robust reporting on coverage and limits, with an option to run in-browser for experimentation.

dz6

2026-08-03 Rust ★ 201
dz6 is a fast Vim-inspired hex editor designed for terminal environments, enabling efficient editing of large files in hex or ASCII formats. Notable features include Vim-like key bindings, customizable options, regex string filtering, and the ability to parse PE/ELF headers, making it suitable for tasks involving low-level file inspection and manipulation. The tool is cross-platform, open-source, and offers a variety of navigation and editing commands to enhance user experience.

fireman

2026-08-03 Rust ★ 15
Fireman is a versatile decompiler designed to allow users to interactively modify Intermediate Representation (IR) through a graphical user interface (GUI), command-line interface (CLI), or text-based user interface (TUI) while observing real-time updates to C-like code. It features a complete instruction parsing routine for x64, IR-based analysis routines including data flow analysis, control flow analysis, and variable analysis, along with support for IR pattern matching and basic simulation functionalities. The tool aims to simplify the decompilation process while providing multiple interfaces for varying user preferences.

flutterdec

2026-08-03 Rust ★ 77
`flutterdec` is a static analysis tool designed for decompiling Flutter applications packaged as APKs or `libapp.so` files, specifically targeting Android ARM64 binaries. Its primary use case is for reverse engineering Flutter apps, providing readable pseudo-Dart code along with additional artifacts such as intermediate representation (IR), assembly, and symbol reports to aid in validation against lower-level codes. Notable features include the ability to extract and compare builds, enhance symbol naming from matched binaries, and various output options for deeper analysis.

fromsoftware-rs

2026-08-03 Rust ★ 63
FromSoftware-rs provides Rust bindings for mod creation in From Software games, enabling developers to interact with and manipulate game structures programmatically. The tool includes bindings for popular titles such as Dark Souls 3, Sekiro, and Elden Ring, along with shared utilities, making it highly versatile for game modding. Notable features include a well-defined crate structure for each game, extensive documentation, and a derive macro for streamlined trait implementation.

haruspex

2026-08-03 Rust ★ 134
Haruspex is an advanced headless plugin for IDA Pro that efficiently extracts pseudocode from binaries, formatted for integration with IDEs or further parsing by static analysis tools like Semgrep. Notable features include its high-speed performance, compatibility with various architectures supported by IDA's Hex-Rays decompiler, and structured output where each function's pseudocode is saved separately for easy analysis.

launchpad-core-firmware

2026-08-03 Rust ★ 42
CoreFW is a custom firmware solution designed for the Novation Launchpad series, providing a complete reimplementation with advanced features such as optimized MIDI processing and multiple customizable color palettes. It supports various Launchpad models, including RGB and non-RGB devices, and offers performance enhancements suitable for lightshows, along with a color palette editor and custom boot animations. Built through reverse engineering, CoreFW does not include official Novation firmware and is aimed at enhancing user control and LED performance across compatible devices.

mwemu

2026-08-03 Rust ★ 314
MWEmu is a Rust-based hardware emulator and OS process simulator primarily designed for dynamic malware analysis and testing, focusing on Windows processes with some Linux support. It features fast and reliable x86 32/64-bit emulation, extensive implementation of 339 CPU instructions, and 260 WinAPI calls, as well as tools for memory tracking, state exploration, and interaction with various shellcodes and malware payloads. Notable functionalities include command-line, Rust, and Python library interfaces, as well as advanced dynamic analysis capabilities like iteration detection and PE execution.

oneiromancer

2026-08-03 Rust ★ 145
Oneiromancer is a reverse engineering assistant designed to enhance code analysis by utilizing a locally running large language model (LLM) that has been fine-tuned for Hex-Rays pseudocode interpretation. Its primary use case is to analyze code snippets, providing high-level descriptions, suggested function names, and variable renaming recommendations, while also saving improved pseudocode for further inspection. Notable features include cross-platform compatibility, integration with the pseudocode extractor 'haruspex', and the ability to invoke analysis through external crates, facilitating a seamless development experience.

rhabdomancer

2026-08-03 Rust ★ 133
Rhabdomancer is a high-performance headless plugin for IDA that identifies calls to potentially insecure API functions within binary files. It aids security auditors by backtracking from these functions to find vulnerabilities related to untrusted input, complete with a prioritization system that categorizes known bad API calls. Notable features include support for various C/C++ binary targets and the ability to customize the list of bad API functions according to user-defined criteria.

windiff

2026-08-03 Rust ★ 392
WinDiff is an open-source, web-based tool designed for browsing and comparing symbol, type, and syscall information of Microsoft Windows binaries across different OS versions. Its primary use case is to facilitate analysis for security researchers by providing a user-friendly interface to visualize changes in Windows binaries and automate version comparisons through an integrated AI assistant. Notable features include a dual structure comprising a CLI tool and a TypeScript frontend, automatic updates from the latest Windows versions, and the ability to analyze binary changes using the Claude Code skill.

binsafe

2026-08-03 Rust ★ 17
Binsafe is an obfuscator designed for 64-bit portable executables that employs a multi-step process to transform the structure and execution of compiled binaries. Its notable features include disassembly, instruction virtualization, operational scrambling, and runtime protections against debugging and tampering. This tool primarily serves to enhance binary security by making reverse engineering significantly more challenging.

neohook

2026-08-03 Rust ★ 28
NeoHook is a Rust-based toolkit designed for precise and safe runtime function hooking within Win32 applications, allowing users to hook APIs, game engine functions, and third-party DLL exports with ease. Its notable features include atomic transactions for batch-hooking, full thread safety during hook application, and advanced techniques such as instruction pointer redirection and stack scanning to maintain stability. The tool provides a high level of memory safety combined with the efficiency of low-level binary patching, making it suitable for debugging, profiling, and security research while ensuring compliance with licensing and legal constraints.

wakaru

2026-08-03 Rust ★ 973
Wakaru is a tool designed to unpack and reverse the minification and transpilation of JavaScript bundles produced by tools like webpack and esbuild, transforming them into readable modern JavaScript code. Its primary use case is to enhance the understandability of compiled code for auditing and debugging purposes by restoring original syntax, removing bundler runtimes, and effectively splitting bundles back into their modular components. Notable features include support for multiple bundler formats, advanced transpiler recovery functions, and various transformation levels to balance between readability and fidelity to the original semantics.

glaurung

2026-08-03 Rust ★ 31
Glaurung is a modern reverse engineering framework that aims to provide an AI-native binary analysis experience, effectively serving as a contemporary alternative to Ghidra. Utilizing Rust for performance and Python for accessibility, it integrates AI throughout the analysis pipeline, offering capabilities like automated format detection and decompilation for x86/x64 and ARM architectures. Notable features include a persistent knowledge base, a Python API for scripting, and built-in AI tools, making Glaurung suitable for both automated analysis and advanced reverse engineering workflows.

jingle

2026-08-03 Rust ★ 38
`jingle` is a tool for modeling and analyzing Ghidra's `p-code` using SMT (Satisfiability Modulo Theories) logic, specifically within the context of formal verification and program analysis. It features a Configurable Program Analysis algorithm that allows for flexible custom analyses of `p-code` operations, leveraging a high-level Rust API and providing Python bindings for integration with existing tools. This alpha software is intended for research purposes, facilitating the generation of SMT models and supporting the disassembly and analysis of hex-encoded instructions.

rbuster

2026-08-03 Rust ★ 18
Rbuster is a directory brute-forcing tool designed for web application security testing, enabling users to discover hidden directories and files on a web server. Key features include customizable user agents, cookie handling for authentication simulation, support for various HTTP status codes to filter responses, and the ability to utilize wordlists for brute-forcing directory paths. The tool is implemented in Rust and can be easily installed via Cargo or on Kali Linux.

soma

2026-08-03 Rust ★ 23
Soma is a cross-platform CTF problem container management tool that facilitates the creation, distribution, and execution of capture-the-flag (CTF) problems for both problem authors and solvers. Notable features include simple command-line usage for downloading and running CTF challenges, as well as support for easy configuration through a `soma.toml` file, which allows problem setters to define the execution environment and file permissions. The tool requires Docker to function and aims to streamline the CTF experience by providing reproducible environments for problem-solving.

fubar

2026-08-03 Rust ★ 63
FUBAR is a terminal user interface (TUI) tool designed for offline payload generation, retrieval, and exfiltration, particularly in restrictive shell environments. It provides power users with access to thousands of payloads sourced from gtfobins, facilitating security research and privilege escalation operations. The tool features intuitive navigation through keybindings, payload copying capabilities, and is currently in prototype status with additional features planned for future implementation.

stegbrute

2026-08-03 Rust ★ 245
stegbrute is a rapid steganography brute-force tool developed in Rust, designed for extracting hidden data from media files that use the steghide utility. It offers multiple installation methods, including Cargo, Debian packages, and Docker, catering to various operating systems and user preferences. Notable features include customizable options for brute-forcing password protection and the ability to save results efficiently in a designated volume when used with Docker.

RsaCracker

2026-08-03 Rust ★ 154
RsaCracker is a robust tool designed for breaking RSA encryption, particularly beneficial in Capture The Flag (CTF) competitions. It supports a variety of formats including RSA, X509, and OPENSSH, enabling users to recover private keys and decipher messages through a comprehensive suite of targeted attacks and heuristics. Notable features include support for both PEM and DER formats, a flexible command-line interface, and advanced functionalities for multi-key attacks and various cryptographic operations.

seg

2026-08-03 Rust ★ 21
`seg` is a command-line utility designed for analyzing and exploiting ELF binaries, offering comprehensive binary intelligence with a single command. Its primary use case targets CTF players and penetration testers, providing features such as dangerous function detection, libc resolution, and automatic exploit strategy suggestions. Notably, `seg` supports dual output formats for both human readability and automation pipelines, streamlining the reconnaissance process by integrating multiple tool functionalities into a cohesive reporting system.

pathbuster

2026-08-03 Rust ★ 155
Pathbuster is a path-normalization penetration testing tool built with Rust, designed to aid ethical hackers in scanning for vulnerabilities in web applications. It features an array of options for configuring requests, including various HTTP methods, custom headers, response filtering, and even supports proxy configurations for integrated use with tools like Burp Suite. Notable enhancements include unified response filtering, customized brute-force control, ETA estimations, and traversal strategy selection, making it a versatile choice for web application assessments.

cache-commander

2026-08-03 Rust ★ 68
Cache Commander (ccmd) is a terminal UI tool designed for exploring, auditing, and managing developer cache directories on macOS and Linux. Its primary use case is to help developers identify and clean up accumulated cache data, scan for known CVEs, and manage outdated dependencies, all through an intuitive two-pane interface that supports multiple cache providers. Notable features include vulnerability scanning, reclaiming disk space from various cache types, and integration with AI for enhanced capabilities.

chaca-scanner

2026-08-03 Rust ★ 41
Chaca is a native desktop web security scanner designed specifically for developers, providing fast and opinionated security audits of web applications through a user-friendly interface without requiring terminal use. It features both passive and active scanning capabilities, support for numerous content management systems and APIs, and generates detailed reports with filtering and export options. Additional highlights include a real-time progress dashboard, persistent scan history, and customizable scan presets, all built on a tech stack utilizing Rust, React, and Tauri.

qryon

2026-08-03 Rust ★ 11
Qryon is a security vulnerability scanning tool designed to rapidly identify issues within codebases, boasting scan times significantly faster than competing tools, capable of analyzing up to 1 million lines of code in under a minute. It supports 28 programming languages with a rich set of over 647 security rules covering various vulnerabilities, including SQL injection and hardcoded secrets, while offering features like interactive TUI for browsing findings, AI-powered triage, and integration with CI/CD pipelines via SARIF output. The tool leverages native Rust matchers for optimal performance and provides flexible installation options across various platforms.

ApiHunter

2026-08-03 Rust ★ 24
ApiHunter is an asynchronous, modular API security scanner designed for baseline testing and regression detection in APIs. It facilitates both offensive and defensive use cases, enabling red-team activities like pentesting and exploit validation, as well as providing CI/CD regression gating and early misconfiguration detection. Notable features include adaptive concurrency, support for a variety of API security checks (such as CORS, CSP, GraphQL), and the ability to scan large numbers of targets rapidly with integrated threat intelligence capabilities.

artifact-keeper

2026-08-03 Rust ★ 986
Artifact Keeper is an enterprise-grade open-source artifact registry designed to support over 45 package formats, including Maven, NPM, Docker, and more. It features a WASM plugin system for custom format handling, automated security scanning for vulnerabilities, and a robust architecture with multi-auth support, full-text search capabilities, and artifact signing functionalities. Built in Rust, it emphasizes security with hardened container images and advanced replication features for scalable deployment.

auditor-skill

2026-08-03 Rust ★ 51
auditor-skill is an open-source AI-driven security audit tool designed for auditing Solana programs and applications. It leverages AI agents to evaluate codebases against 1,346 verification items across 20 security domains and 131 known attack vectors, producing detailed reports that include executable proofs of vulnerabilities and suggested fixes. Notable features include a comprehensive audit lifecycle, token efficiency through pre-scanning, and deep coverage of Solana-specific methodologies.

cwe_checker

2026-08-03 Rust ★ 1353
cwe_checker is a static analysis tool designed to identify common software vulnerabilities, specifically by detecting classes of bugs known as Common Weakness Enumerations (CWEs) in ELF binaries across multiple CPU architectures. It leverages Ghidra for disassembly and utilizes a plugin-based, extensible architecture that supports customizable analyses, making it a useful resource for firmware analysis on Linux and Unix systems. Notable features include easy setup via Docker, support for various architectures, and the ability to integrate with the FACT framework for enhanced analysis capabilities.

foxguard

2026-08-03 Rust ★ 289
Foxguard is a comprehensive security scanning tool designed for local environments, offering fast analysis of code, secrets, dependencies, and post-quantum cryptographic risks. It boasts over 200 built-in rules across 12 programming languages, supports taint tracking, provides efficient CI integrations, and features output formats compatible with various tools such as SARIF and Semgrep. Key capabilities include secrets scanning, OSV-backed dependency checks, and the ability to pinpoint changes in code branches through diff mode scanning.

nyx

2026-08-03 Rust ★ 38
Nyx is a local-first security scanner designed for cross-language taint analysis of code repositories, providing a sandboxed dynamic verification environment. Its notable features include a user-friendly React-based UI for real-time results, a detailed flow visualizer for tracking data paths, and the ability to persist triage states alongside code commits, ensuring collaboration within teams. Additionally, Nyx can be seamlessly integrated into CI pipelines, generating SARIF reports for GitHub Code Scanning.

Sighthound

2026-08-03 Rust ★ 277
Sighthound is a Tree-sitter based static vulnerability scanner designed for identifying security vulnerabilities in source code through AST-aware rules and taint-flow analysis. It supports multiple programming languages, executes scans in parallel, and offers output in various formats including JSON, CSV, and SARIF for integration with GitHub Code Scanning. Notably, Sighthound allows for custom rule packs and provides both pattern and taint mode analysis, catering to complex multi-file projects.

xint-rs

2026-08-03 Rust ★ 27
xint-rs is a command-line interface (CLI) tool designed for efficient and comprehensive real-time monitoring, search, and analysis of X (formerly Twitter) data. Built in Rust, it offers notable features such as full-text search, user and follower tracking, AI analysis, and a terminal user interface (TUI), all while ensuring minimal runtime overhead with a compact binary size of 2.5MB and startup time under 5ms. This tool requires X API access and supports myriad functionalities ranging from profile analysis to trend monitoring and tweet management.

haylxon

2026-08-03 Rust ★ 441
Haylxon is a high-performance, minimalistic screenshot tool designed for capturing web pages using Chrome's headless mode. It supports both local and remote browsers, facilitating features such as tab pooling for efficiency and the ability to execute tasks in parallel. Users can generate flexible outputs, including various image formats and HTML reports containing detailed metadata about the screenshots taken.

urx

2026-08-03 Rust ★ 190
Urx is a command-line tool that efficiently extracts URLs from OSINT archives like the Wayback Machine and Common Crawl, utilizing asynchronous processing for rapid data collection. Key features include keyless access to multiple sources, result filtering by various criteria, URL normalization, and support for multiple output formats, making it ideal for security testing and analysis applications. Additionally, it supports caching and incremental scanning to enhance performance and efficiency in URL collection tasks.

project-absence

2026-08-03 Rust ★ 18
Project Absence is an OSINT tool tailored for system administrators and security engineers, facilitating domain and server reconnaissance through modules such as subdomain and file discovery, as well as DNS data extraction. Its architecture allows for enhanced functionality via Lua scripting, while it adheres to an OSINT-only methodology by contacting each discovered entity just once to gather pertinent information. Notable features include support for clipboard integration and the ability to run the tool via Docker, alongside standard Rust installation methods.

APIKeyScanner

2026-08-03 Rust ★ 11
Advanced Secret Finder is a high-performance API key scanner developed in Rust, capable of detecting over 70 API key patterns while employing concurrent scanning of GitHub repositories. It features live validation of keys against major platforms, intelligent false positive filtering, and separation of public and private findings to enhance security during analysis. Additionally, it offers a user-friendly interactive mode and integration with GitHub Actions for seamless automation in continuous integration workflows.

witchcraft

2026-08-03 Rust ★ 52
WITCHCRAFT is an advanced cybersecurity toolkit designed for professionals engaged in operational security (OPSEC), offering functionalities for hacking, OSINT, and forensic analysis. Key features include a modular command structure for tasks such as port scanning, data mapping, and searching for keywords across numerous platforms, bolstered by a comprehensive spellbook containing unique wordlists and databases for enhanced reconnaissance. This tool serves as an all-in-one cyberdeck system for efficient data-ghosting, network penetration, and threat analysis.

Hazard

2026-08-03 Rust ★ 12
Hazard is a Rust-based dictionary brute-force tool designed for testing the security of various network protocols including SSH, FTP, Samba, MySQL, and PostgreSQL. Its primary use case is to facilitate password cracking through a user-friendly interface, allowing operators to input target IPs and utilize predefined wordlists. Key features include multi-protocol support, customizable input options, and a straightforward installation process.

NetRaze

2026-08-03 Rust ★ 11
NetRaze is an offensive network-execution toolkit developed in Rust, providing a memory-safe, single-binary alternative to traditional Python-based tools like NetExec and CrackMapExec. It maintains a similar workflow for network post-exploitation but enhances performance with async I/O and offers a desktop GUI for visual workflow composition. Currently in alpha, it focuses on core functionality with a goal of expanding its protocol coverage across various operating systems.

Hacking-Rust

2026-08-03 Rust ★ 239
Hacking Rust is a comprehensive online tutorial designed to teach reverse engineering techniques for Rust programming, specifically targeting x64, ARM64, and ARM32 architectures. It includes step-by-step lessons covering various concepts such as debugging, scalar and compound data types, and functions, with an emphasis on hands-on hacking exercises. Notable features include a free downloadable book and a structured approach that guides users from basic Rust programming to more complex reverse engineering tasks.

stegcloak

2026-08-03 Rust ★ 20
StegCloak is a tool designed to conceal secrets within plain text by compressing and encrypting the data, and then embedding it using invisible Unicode characters, enabling covert communication in various digital platforms. With features such as AES-256-CTR encryption, password protection, and high performance in both plaintext and encrypted modes, it allows users to watermark strings or engage in discreet messaging. The tool is also compatible with WebAssembly (Wasm) for integration in web applications.

ferrox

2026-08-03 Rust ★ 35
Ferrox is a research-focused Windows stealer written in Rust, designed to harvest sensitive data including browser credentials, cryptocurrency wallet information, and messaging app sessions while employing various evasion techniques to bypass antivirus and endpoint detection systems. Its notable features include polymorphic builds, compile-time encryption of strings, direct syscall execution, anti-analysis measures, and the ability to exfiltrate stolen data via Discord or Telegram within a stealthy execution environment. The tool is intended strictly for educational purposes in understanding modern attack methodologies for enhancing cybersecurity defenses.

injectum

2026-08-03 Rust ★ 33
Injectum is a modern, type-safe Rust library designed for process injection tailored for Red Teams and Offensive Security operations. Its primary use case is to provide a structured framework for executing various injection strategies while managing memory safety and minimizing artifacts to evade detection by Endpoint Detection and Response (EDR) systems. Notable features include a modular architecture that allows dynamic swapping of injection techniques, a fluent Builder API for compile-time error detection, and robust payload management to enhance operational security.

RustiveDump

2026-08-03 Rust ★ 388
RustiveDump is a Rust-based tool specifically developed to perform memory dumps of the lsass.exe process using only NT system calls, creating minimalistic minidump files that include crucial data such as SystemInfo and ModuleList. Notable features include Position Independent Code (PIC) support, XOR encryption for enhanced security, and remote transmission capabilities, along with efficient memory handling and a lean build size of 18KB due to its no_std and CRT-independent design.

RustPotato

2026-08-03 Rust ★ 369
RustPotato is a Rust-based privilege escalation tool that exploits DCOM and RPC to gain NT AUTHORITY\SYSTEM privileges on Windows systems. It features a TCP-based reverse shell utilizing Winsock APIs for remote command execution and employs indirect NTAPI calls to handle security tokens effectively. Its key capabilities include identifying and hijacking RPC communications, impersonating clients, and executing commands with elevated privileges.

RustSoliloquy

2026-08-03 Rust ★ 193
RustSoliloquy is a Rust-based tool for capturing NetNTLM hashes by utilizing the SSPI without directly accessing LSASS, thus enhancing security during the process. Key features include the use of native APIs for indirect syscalls to manipulate registry settings and impersonate logged-on users, alongside streamlined NTLM negotiation to facilitate hash extraction. The tool is designed for educational purposes, showcasing a thorough understanding of NTLM authentication mechanisms.

rs-shell

2026-08-03 Rust ★ 186
RS-Shell is a reverse shell tool developed in Rust, designed to facilitate secure command and control operations through both TLS over TCP and HTTPS communication modes. It features a semiautomatic reverse shell, file transfer capabilities, and advanced execution options for PE and shellcode, complete with a proxy-aware Windows implant and privilege escalation methods. The modular architecture allows for easy customization and integration of various functionalities, making it suitable for offensive cybersecurity operations and testing.

rustsploit

2026-08-03 Rust ★ 59
Rustsploit is a modular offensive security tool written in Rust, designed for targeting embedded systems such as routers and cameras. It features a unified interface that provides an interactive shell, command-line execution, and a post-quantum encrypted REST/WebSocket API, along with built-in fingerprinting using Recog and JARM/JA3 methods. Notable aspects include self-registering modules, a credential management system, and extensive support for various network protocols and services, making it a versatile tool for penetration testing and vulnerability assessment.

mantishack

2026-08-03 Rust ★ 493
Mantishack is an autonomous vulnerability-discovery agent designed for ethically hacking and identifying software vulnerabilities through a comprehensive, AI-driven pipeline. It integrates multiple scanning capabilities, including static analysis and attacker-simulation validation, to ensure precise identification of exploitable flaws while explicitly tracking the status of findings. Notably, it operates with a focus on real validation over traditional detection, utilizing a modular architecture that can integrate various security tools as needed.

oxide-communityedition-v8.6.9

2026-08-03 Rust ★ 12
OXIDE is a precision-forged Rust-based vulnerability scanner designed for offensive security applications, particularly penetration testing and security research. Key features include an async concurrent architecture, a WAF evasion suite, an AI/ML-driven zero-day detection engine, and a modular framework with 14 detection modules. This tool is optimized for Kali Linux and emphasizes responsible use, strictly prohibiting unauthorized access or malicious applications.

wafrift

2026-08-03 Rust ★ 21
WafRift is a programmable WAF-evasion engine designed to test and bypass web application firewalls by generating and exploiting payload mutations through various encoding and grammar strategies. Its primary use case is for security researchers and penetration testers seeking to identify WAF vulnerabilities, featuring automated scanning, detailed response classification, and an integrated discovery tool for API endpoints. Notable features include customizable evasion strategies, session management, multi-signal response analysis, and comprehensive WAF fingerprinting capabilities.

udbg

2026-08-03 Rust ★ 19
udbg is a cross-platform Rust library designed for binary debugging and memory manipulation, providing uniform interfaces across various operating systems. Its primary use case is to facilitate the inspection and control of multiple debug targets without invasive attachment, supporting comprehensive target information retrieval and debugging functionalities. Notable features include support for multiple architectures, non-invasive operation modes, and capabilities for breakpoint and watchpoint management.

valthrun-cs2

2026-08-03 Rust ★ 24
Valthrun an open source external CS2 read only kernel gameplay enhancer.

tx2hax

2026-08-03 Rust ★ 81
tx2hax is a repository that provides exploit implementations for vulnerabilities in the Tegra X2 and Magic Leap One devices, primarily focusing on achieving code execution in the BootROM of the Tegra X2 through USB Recovery Mode. Notable features include specific exploits such as `rcmhax`, `sparsehax`, and `dtbhax`, along with detailed writeups that document the exploitation techniques and methodologies employed.

Autorun-ng

2026-08-03 Rust ★ 52
Autorun-ng is a versatile tool designed for launching applications with a streamlined user interface, supporting both Linux and Windows environments. Its notable features include a sandboxed filesystem leveraging cap-std for enhanced security, ergonomic Lua API bindings for seamless integration, and a zero-dependency library for accessing source engine interfaces. This tool eliminates the need for menu plugins or manual injections, making application execution efficient and user-friendly.

CVE-2026-31431-Linux-Copy-Fail

2026-08-03 Rust ★ 56
The CVE-2026-31431-Linux-Copy-Fail tool is a Rust-based local privilege escalation exploit that leverages an arbitrary page cache write vulnerability in Linux systems. It facilitates the execution of customizable shellcode, including a Meterpreter payload, and offers functions for testing vulnerability and executing exploits. Notable features include support for direct payload substitution and detailed usage instructions for compiling and executing the tool on affected Linux distributions.

scap-rs

2026-08-03 Rust ★ 25
scap-rs is a Rust library designed for interacting with the National Vulnerability Database, encompassing various modules such as CVSS, CVE, CPE, and CWE, which facilitate vulnerability scoring, disclosure, platform enumeration, and weakness classification. Its primary use case provides developers with tools to access and manipulate vulnerability data, enabling better security posture management. Notable features include support for multiple vulnerability-related standards and well-documented APIs for ease of integration.

Hells-Hollow

2026-08-03 Rust ★ 290
Hell's Hollow is a rootkit technique specifically designed for Windows 11 that enables effective SSDT hooking by exploiting an undocumented Alternate Syscall handler mechanism. This tool allows users to manipulate system calls at the kernel level, enabling alteration of return values and system call arguments while bypassing existing defense mechanisms like HVCI. Notable features include its compatibility with Rust for driver development and the ability to hook and modify any specified system service number (SSN), making it a versatile tool for advanced kernel manipulation techniques.

ttyinject-rs

2026-08-03 Rust ★ 14
ttyinject-rs is a tool that exploits the `TIOCSTI` ioctl in the Linux kernel to inject keystrokes into a terminal, allowing a non-privileged user to gain root privileges when the root user executes `su - user`. Notable features include its easy integration with a user's `~/.bashrc`, its self-deleting behavior post-execution, and compatibility with specific Linux kernel configurations. It serves primarily as a demonstration of an exploit for educational purposes.

async-rust-rat

2026-08-03 Rust ★ 72
Async Rust RAT is an open-source Remote Administration Tool (RAT) designed for Windows, developed in Rust primarily for legitimate system administration, research, and educational purposes. Notable features include system information retrieval, remote desktop capabilities, webcam capture, file management, and various control functionalities such as shutdown and restart, along with a client builder for customization. The tool emphasizes responsible use, necessitating explicit permission for system management tasks.

Proteus

2026-08-03 Rust ★ 75
Proteus is a Rust-based command-and-control (C2) agent designed for integration with the Mythic framework, featuring capabilities such as raw shellcode production, COFF file analysis, and robust data-section obfuscation. Its key innovations include a shuffle pipeline that randomizes function order while repairing internal references, combined with ChaCha20-based encryption for added security. This tool serves as both a payload generator and a development aid, supporting advanced persistence and clandestine operations in targeted environments.

Solemn

2026-08-03 Rust ★ 25
Solemn is a command-line utility designed to facilitate the manual addition of drivers to the Hypervisor-Protected Code Integrity (HVCI) custom blocklist on Windows systems. Its primary use case is to enhance kernel security by allowing system administrators to block specific drivers, thereby preventing potentially malicious code from executing within the kernel. Key features include automatic creation of the registry entry for the blocklist, duplicate entry prevention, and user-friendly command-line output, all while ensuring necessary administrative privileges are checked before modifications are made.

stardust-rs

2026-08-03 Rust ★ 39
The Stardust-RS project provides a Rust template for creating position-independent shellcode (PIC) targeting both i686 and x86_64 architectures on Linux and Windows platforms. It allows for the compilation of shellcode that can be executed without specific memory locations, facilitating various exploit development scenarios. Notable features include cross-platform support, minimal payload sizes, and a customizable build environment with Docker compatibility.

ActiveBreach-Engine

2026-08-03 Rust ★ 51
ActiveBreach-Engine (ABE) is a Windows execution capability platform that enables secure and direct system call execution in heavily instrumented environments, mitigating risks from external attackers and process hooking. It offers a dynamic framework that avoids reliance on user-mode APIs or `ntdll.dll`, featuring built-in anti-debug and protection mechanisms to safeguard system calls. ABE is available in C, C++, and Rust adaptations, with the Rust version providing advanced features like build-time encrypted stubs and modular integration across various programming languages.

catchclaw

2026-08-03 Rust ★ 31
CatchClaw v5.3.0 is a multi-platform AI Agent security assessment tool that supports nine different AI platforms including OpenClaw and Dify. It features 78 DAG attack chains and exploit modules that cover a full range of attack vectors from reconnaissance to data leakage, utilizing an asynchronous Tokio engine for concurrent execution while offering visual attack graph exports and customizable reporting options. The tool is designed to facilitate automated vulnerability verification and threat modeling within complex multi-agent environments, restricted to non-commercial use only.

ghosthound

2026-08-03 Rust ★ 44
GhostHound is a specialized tool designed as an OpenGraph extension for BloodHound, targeting the enumeration of deleted objects (tombstones) in Active Directory environments. Its primary use case is to facilitate security assessments by revealing who can restore these deleted objects, thereby potentially allowing an attacker to reclaim identities. Notable features include the ability to generate a JSON payload compatible with BloodHound, detailed analysis of reanimation rights, and flexible LDAP connection options for various environments.

aterm

2026-08-03 Rust ★ 29
ASHIRT Terminal Recorder (aterm) is a tool designed for recording terminal sessions in a pseudo terminal, enabling users to upload these recordings to an ASHIRT server in asciicast v3 format. Its primary use case is to facilitate session logging for review and sharing, offering features such as easy navigation through menus, session management (including renaming and discarding recordings), and a configuration system that adheres to the XDG standard. Built as a single-binary Rust application, aterm supports multiple operating systems and can be easily run using standard Rust tooling without additional dependencies.

Echos

2026-08-03 Rust ★ 34
Echos is a modular network beacon emulator designed for validating detection systems in cybersecurity labs. It generates realistic command-and-control (C2) traffic across multiple protocols, enabling security teams to test their EDR, NDR, and SIEM solutions under controlled conditions without introducing risks associated with real malware. Key features include a variety of built-in profiles for significant APT groups, customizable configurations, and export capabilities for Sigma, Suricata, and Snort rules, making it a versatile tool for detection engineering.

SATAN2

2026-08-03 Rust ★ 11
SATAN2 is an advanced counter-forensics framework designed for security professionals, Red Teams, and privacy advocates, offering features for multi-pass data destruction, nested encryption, and forensic artifact forgery. Its primary use case is to effectively eliminate sensitive information and mislead forensic analysis, making it a formidable tool against incident-response efforts. Notable features include cross-platform support, modular architecture, and specialized modules for thorough deletion and deception on both Linux and Windows systems.

ETW-Bypass-Rust

2026-08-03 Rust ★ 40
The ETW-Bypass-Rust tool provides a method for bypassing the Event Tracing for Windows (ETW) framework, primarily aimed at evading Endpoint Detection and Response (EDR) systems. It modifies the `NtTraceEvent` function in `ntdll.dll` to prevent logging of actions that may trigger security alerts, utilizing dynamic function address resolution. This tool serves as an educational resource for cybersecurity professionals to understand and develop defensive strategies against potential detection mechanisms.

Rust-Hells-Gate

2026-08-03 Rust ★ 93
Rust-Hells-Gate is a proof-of-concept tool designed for evading Endpoint Detection and Response (EDR) systems through the use of direct syscalls in Rust. It specifically implements the Hell's Gate technique, allowing users to bypass EDR hooks by accessing the Process Environment Block (PEB) to resolve function pointers from ntdll.dll, thereby minimizing detection by common security measures. Notable features include its lightweight implementation approach and the potential for extension into a fully functional malware loader.

dirble

2026-08-03 Rust ★ 634
Dirble is a directory scanning tool designed for both Windows and Linux environments, enabling rapid enumeration of web directories and files. Its primary use case is for security assessments to identify accessible resources on web servers, with notable features including support for custom headers, HTTP authentication, multithreading, and options for saving output in various formats. It also effectively detects both listable directories and responds to various HTTP status codes, enhancing its utility in penetration testing scenarios.

pktbatch-rs

2026-08-03 Rust ★ 17
Packet Batch is a high-performance toolset for generating network packets, designed primarily for penetration testing, benchmarking, and network monitoring. This Rust implementation offers enhanced safety and modern coding practices while maintaining fast performance through AF_XDP socket technology, highly configurable packet generation, real-time statistics display, and detailed logging capabilities. Users can execute multiple packet batches with various configurations via a command-line interface, although the project is still considered experimental and in early development stages.

rusty_hack_browser_data

2026-08-03 Rust ★ 18
`rusty_hack_browser_data` is a Rust-based tool designed for extracting and analyzing browser data, including passwords, cookies, bookmarks, and history from various web browsers on Windows. Its primary use case is for cybersecurity research, providing support for popular browsers like Firefox, Microsoft Edge, and Google Chrome, with functionality to assist in data recovery and forensic investigations. Notably, the tool emphasizes a legal disclaimer, placing responsibility for usage on the user.

wifikit

2026-08-03 Rust ★ 21
wifikit is a WiFi pentesting toolkit designed for macOS, implemented in pure Rust without the need for kernel extensions or virtual machines. It enables comprehensive wireless network penetration testing through features like channel scanning, multiple attack engines (including PMKID extraction and WPS PIN cracking), and packet capturing, all accessible via an intuitive terminal user interface. The tool is specifically tailored for Apple Silicon and directly interacts with USB WiFi chipsets, providing a unique solution for native macOS penetration testing.

windfire

2026-08-03 Rust ★ 78
Windfire is a high-performance, Rust-based tool designed for URL liveness detection, enabling fast and lightweight asset availability checks for domains, IPs, and URLs. Its notable features include support for HTTP/SOCKS proxies, HTTP status code filtering, customizable paths, and the ability to choose between liveness-only and full fingerprinting scan modes, all while maintaining high concurrency and asynchronous execution. Additionally, users can control the scan rate and export results in CSV or JSON formats.

Ironbullet

2026-08-03 Rust ★ 24
Ironbullet is a desktop automation toolkit designed for creating and executing complex data processing workflows using a visual drag-and-drop pipeline interface. It features over 50 block types, including HTTP requests, parsing, checks, and browser automation, allowing users to perform multi-threaded job executions with advanced debugging capabilities, TLS fingerprinting, and built-in traffic capture for analysis. Moreover, the tool supports plugin extensions and the importation of configurations from OpenBullet 2 and SilverBullet, enhancing its flexibility and application in various automation tasks.

ghost

2026-08-03 Rust ★ 11
ghost is a private desktop application designed for Windows that facilitates local file searching, the execution of AI agents, and integration with over 10,000 tools. Its notable features include the ability to operate entirely offline, ensuring user data remains secure and private, alongside advanced protocol support for seamless communication between tools and AI functionalities. This makes ghost particularly suitable for users prioritizing data privacy and local processing capabilities.

RustPacker

2026-08-03 Rust ★ 341
RustPacker is a tool designed for authorized penetration testers and red team operators that transforms raw shellcode into secure and evasive Windows binaries. It encapsulates shellcode within a Rust-based executable or DLL, incorporating features such as encryption, multiple injection techniques, and evasion strategies to minimize detection by endpoint protection systems. Notably, it supports cross-platform builds and offers a variety of injection templates and encryption methods to enhance the stealth of the generated payloads.

scant3r

2026-08-03 Rust ★ 686
ScanT3r is a fast command-line interface (CLI) tool for dynamic application security testing (DAST), developed in Rust, designed to identify vulnerabilities such as Cross-Site Scripting (XSS) and Server-Side Template Injection (SSTI) through various testing modules. It supports concurrent scanning with customizable options, including target lists, module selection, and output formats like JSON reports. Notable features include context-aware payload delivery, the ability to integrate with Burp Suite, and an extensible module framework for developing additional testing capabilities.

skewrun

2026-08-03 Rust ★ 77
Skewrun is an Active Directory time discovery toolkit designed for red team operations, facilitating the resolution of time discrepancies when executing commands on target systems from a Linux environment. It utilizes various network protocols (CLDAP, SMB, NTP, Kerberos, NTLM) to dynamically fetch the Domain Controller's time, allowing users to circumvent the Kerberos `KRB_AP_ERR_SKEW` error without needing elevated privileges to adjust the system clock. The tool features a library-first architecture for seamless integration into other Rust applications and minimizes forensic traces during operation.

trilane

2026-08-03 Rust ★ 28
TriLane is an autonomous gray-box security auditing tool designed for authorized penetration testing on local labs, internal codebases, and bug-bounty targets. It features a staged audit process that includes the construction of an attack-surface graph, a six-lane semantic audit covering various security aspects, and a deduplication mechanism for findings, allowing for a thorough and organized assessment of security vulnerabilities. Notable features include a desktop GUI for tracking the audit process, two operational modes (Safe and Lab), and efficient evidence management for generating comprehensive reports.

WonderSuite-Ai-Bug-Bounty

2026-08-03 Rust ★ 50
WonderSuite is a desktop-native offensive security research engine designed for comprehensive web application security testing, network reconnaissance, and exploit development, harnessing AI capabilities via Model Context Protocol (MCP) integration. It features an extensive toolkit of 91 security tools, enhanced by a full MITM proxy with advanced fingerprinting for obfuscation, facilitating efficient vulnerability research and response automation. The platform aims to streamline the process of identifying and addressing security issues, making it a powerful asset for security professionals.

adhammer

2026-08-03 Rust ★ 89
ADhammer is an Active Directory security-assessment toolkit implemented in Rust that functions as an auditor similar to PingCastle, capable of mapping domain attack paths with scoring, graphing, and MITRE tagging. It performs low-privileged audits via LDAP, validates identified vulnerabilities using live offensive techniques, and supports execution on both Kali Linux and Windows as a single static binary. Notable features include its custom-built DCE/RPC and Kerberos stack, extensive checks across various security categories, and the ability to export findings to BloodHound.

Sniper

2026-08-03 Rust ★ 12
Sniper is an open-source web security proxy designed for macOS that allows penetration testers, bug bounty hunters, and developers to intercept, inspect, and modify HTTP/HTTPS traffic. Built in Rust, it offers a lightweight and efficient alternative to traditional proxy tools, featuring capabilities such as HTTP forwarding, passive vulnerability scanning, request replay, and an integrated command-line interface for automation. Notable for its rapid startup time and low memory usage, Sniper provides a user-friendly experience without the overhead of Java-based platforms.

subscan

2026-08-03 Rust ★ 54
Subscan is a Rust-based tool designed for monitoring and analyzing blockchain data, primarily focusing on Polkadot and its ecosystem. Its notable features include automated testing workflows, extensive documentation, and container support via Docker, enabling seamless integration into development pipelines. Subscan aims to enhance visibility and insight into blockchain activity, providing developers with essential tools for data analysis and monitoring.

Heroinn

2026-03-30 Rust ★ 712
Heroinn is a cross-platform command-and-control (C2) and post-exploitation framework developed in Rust, designed primarily for research and educational purposes. Notable features include a graphical user interface (GUI), an interactive PTY shell, system information collection, file management with support for large files and resuming broken transfers, and compatibility with multiple operating systems including Windows, Linux, BSD, and macOS, leveraging various communication protocols such as TCP, HTTP, and reliable UDP.

operative-framework

2026-03-30 Rust ★ 744
Operative Framework is a digital investigation tool designed for interacting with multiple targets, executing a variety of modules, and managing links with these targets. Its notable features include the ability to export reports in PDF format, support for crafting custom modules, and a RESTful API for integration, all underpinned by a redesigned architecture in Rust for enhanced performance and functionality.

VMkatz

2026-03-30 Rust ★ 1508
VMkatz is a cybersecurity tool designed to extract Windows credentials and secrets directly from virtual machine memory snapshots and disk images without the need for full exfiltration. It supports various input formats, including VMware snapshots and VirtualBox saved states, allowing efficient retrieval of sensitive data such as NTLM hashes, DPAPI master keys, and Kerberos tickets directly from the hypervisor or NAS. Notably, VMkatz operates as a single static binary, requiring minimal setup and enabling rapid credential access in red team engagements.

AngryOxide

2026-03-22 Rust ★ 1947
802.11 Attack Tool

binsider

2026-03-22 Rust ★ 4411
Analyze ELF binaries like a boss 😼🕵️‍♂️

biodiff

2026-03-22 Rust ★ 884
Hex diff viewer using alignment algorithms from biology

black-hat-rust

2026-03-22 Rust ★ 4394
Applied offensive security with Rust - https://kerkour.com/black-hat-rust

cargo-auditable

2026-03-22 Rust ★ 843
Make production Rust binaries auditable

chromepass

2026-03-22 Rust ★ 823
Chromepass - Hacking Chrome Saved Passwords

Ciphey

2026-03-22 Rust ★ 21587
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

CTFCrackTools

2026-03-22 Rust ★ 2148
The next-generation CTF Swiss Army Knife powered by Rust & Tauri. Features a visual node-based workflow and local AI intelligence for extreme performance and automation.China's first CTFTools framework.

DataSurgeon

2026-03-22 Rust ★ 904
Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text

Findomain

2026-03-22 Rust ★ 3787
The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.

goblin

2026-03-22 Rust ★ 1541
An impish, cross-platform binary parsing crate, written in Rust

imessage-exporter

2026-03-22 Rust ★ 5540
Export iMessage data + run iMessage Diagnostics

IPA

2026-03-22 Rust ★ 870
GUI analyzer for deep-diving into PDF files. Detect malicious payloads, understand object relationships, and extract key information for threat analysis.

lonkero

2026-03-22 Rust ★ 1049
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

lumen

2026-03-22 Rust ★ 1152
A private Lumina server for IDA Pro

matano

2026-03-22 Rust ★ 1663
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

moonwalk

2026-03-22 Rust ★ 1490
Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.

NeuroSploit

2026-03-22 Rust ★ 1360
NeuroSploit is an advanced, AI-powered penetration testing framework designed to automate and augment various aspects of offensive security operations. Leveraging the capabilities of large language models (LLMs).

noseyparker

2026-03-22 Rust ★ 2315
Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

obliteration

2026-03-22 Rust ★ 816
Experimental free and open-source PlayStation 4 kernel

panopticon

2026-03-22 Rust ★ 1441
A libre cross-platform disassembler.

pdfrip

2026-03-22 Rust ★ 1328
A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks.

pwninit

2026-03-22 Rust ★ 1117
pwninit - automate starting binary exploit challenges

rustcat

2026-03-22 Rust ★ 813
Rustcat(rcat) - The modern Port listener and Reverse shell

RustHound

2026-03-22 Rust ★ 1134
Active Directory data ingestor for BloodHound Legacy written in Rust. 🦀

RustRedOps

2026-03-22 Rust ★ 1901
RustRedOps is a repository for advanced Red Team techniques and offensive malware, focused on Rust

RustScan

2026-03-22 Rust ★ 20345
🤖 The Modern Port Scanner 🤖

skanuvaty

2026-03-22 Rust ★ 923
Dangerously fast DNS/network/port scanner

sn0int

2026-03-22 Rust ★ 2517
Semi-automatic OSINT framework and package manager

thorium

2026-03-22 Rust ★ 989
A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale.

zizmor

2026-03-22 Rust ★ 6420
Static analysis for GitHub Actions