Curated collection of security, development, and research tools refined through operational experience. From network reconnaissance to mobile forensics, these utilities power our daily workflows.
AI-Powered Security Orchestration
| Tool | Description | Link |
|---|
| HexStrike AI | Autonomously run 190+ cybersecurity tools for automated pentesting, vulnerability discovery, and bug bounty automation | GitHub |
| Villager AI | Autonomous penetration testing framework with HexStrike integration and GitHub discovery | GitHub |
| CodeNomad | Command center for AI-powered coding and automation workflows | GitHub |
| OpenChamber | Desktop and web interface for OpenCode AI agent with integrated tools | GitHub |
| AionUi | Free local AI coworking interface for Gemini, Claude, Qwen Code, and more | GitHub |
Reconnaissance & Discovery
| Tool | Description | Link |
|---|
| Nmap | Network discovery and port scanning with advanced host enumeration | nmap.org |
| ZoomEye AI MCP | Network asset intelligence and IoT discovery via Model Context Protocol | GitHub |
| Robin | AI-powered Dark Web OSINT for threat intelligence and vulnerability tracking | GitHub |
| CamXploit | Security reconnaissance tool for identifying exposed IP cameras and misconfigurations | GitHub |
Web Application Security
| Tool | Description | Link |
|---|
| Burp Suite | Web vulnerability scanning, manual testing, and API security | portswigger.net |
| Droopescan | Plugin-based CMS scanner for Drupal, Silverstripe, WordPress | GitHub |
| CMSScan | Unified scanner for WordPress, Drupal, Joomla, vBulletin | GitHub |
| wp-backdoor | WordPress persistence and surveillance techniques for advanced testing | GitHub |
Credentials & Exploitation
| Tool | Description | Link |
|---|
| Legba | Fast multiprotocol credentials bruteforcer and password sprayer (Rust) | GitHub |
Reverse Engineering & Binary Analysis
| Tool | Description | Link |
|---|
| Ghidra | NSA-developed reverse engineering and program analysis framework | ghidra-sre.org |
| Radare2 | Command-line reverse engineering and assembly analyzing toolkit | rada.re |
| Detect It Easy | Universal file type identifier for Windows, Linux, macOS | GitHub |
| pwntools | CTF framework and exploit development library (Python) | GitHub |
| pwn-toolkit | Extended pentesting utilities for exploit development | GitHub |
Endpoint Security & Monitoring
| Tool | Description | Link |
|---|
| OSQuery | SQL-driven endpoint visibility and system monitoring | osquery.io |
| YARA | Pattern matching engine for malware identification and classification | virustotal.github.io |
| MITRE ATT&CK | Adversarial tactics and techniques knowledge base for threat modeling | attack.mitre.org |
Command & Control Research
| Tool | Description | Link |
|---|
| Loki | Node.js C2 framework for Electron app research and testing | GitHub |
Android Security & Analysis
| Tool | Description | Link |
|---|
| scrcpy | Display and control Android devices over USB or TCP/IP from desktop | scrcpy.org |
| escrcpy | Web-based Android device control via WebRTC with browser interface | GitHub |
| oxproxion | Android chat application for LLM interactions with custom model support | GitHub |
| WallFlow | Modern Android wallpaper app built with Jetpack Compose | GitHub |
| Android-Skills | Community repository for AI agent skills targeting Android security | GitHub |
Audio & Voice Processing
| Tool | Description | Link |
|---|
| Whisper | Robust speech-to-text model supporting 99+ languages | GitHub |
| Audio-Guided-3D-Interaction | Offline real-time AI pipeline: Whisper STT + LLM + TTS with lip-synced avatars | GitHub |
CLI Essentials
Incident Response Kit
Development & Deployment
Self-Hosted Infrastructure
AI Agent Frameworks & Plugins
| Tool | Description | Link |
|---|
| Eliza OS | Core OS framework for autonomous agents | elizaos.ai |
| Eliza Web Search Plugin | Integration of powerful web search capabilities for agents | GitHub |
| Eliza Telegram Plugin | Direct Telegram chat interface for Eliza agents | GitHub |
Development Environment & Theme
| Tool | Purpose | Link |
|---|
| Hugo Terminal Theme | Simple retro terminal theme for Hugo | GitHub |
| GitHub-style CSS | CSS framework inspired by GitHub design | GitHub |
| Obsidian OpenCode Plugin | Embed OpenCode AI assistant in Obsidian sidebar | GitHub |
Resources & References
| Resource | Description | Link |
|---|
| Awesome Claude Skills | Curated collection of AI agent skills and workflows | GitHub |
| macOS on VMWare Guide | Comprehensive guide for virtualizing macOS | GitHub |
Tool recommendations evolve. We update this list as we discover new utilities, integrate cutting-edge AI frameworks, or when existing tools reach end-of-life.