{"slug": "black-hat-usa-2026-arsenal-all-101-tools-with-github-links", "title": "Black Hat USA 2026 Arsenal — all 101 tools with GitHub links", "summary": "Black Hat USA 2026 Arsenal will feature 101 open-source security tools, including new AI-focused offerings such as AgentsLeak, a runtime protection platform for AI coding agents, and ARAY, which generates benign binaries to validate YARA rules. Major updates include AD Miner, which applies graph theory to Active Directory security, and BadZure, which builds cloud attack labs from natural language descriptions.", "body_md": "| 1 |\n**AC Scanner - QubitAC Automated Post-Quantum Cryptography Discovery Tool** |\nCryptography |\nNew Tool |\nScans TLS endpoints and SSH services for post-quantum readiness against NIST PQC standards and emits a Cryptographic Bill of Materials (CBOM). |\n[qubitac/AC-Scanner](https://github.com/qubitac/AC-Scanner) |\n| 2 |\n**AD Miner – One step further applying graph theory for Active Directory security analysis** |\nRisks |\nMajor Update |\nApplies graph theory to BloodHound data to turn raw Active Directory graphs into prioritized, ranked findings and remediation paths. |\n[AD-Security/AD_Miner](https://github.com/AD-Security/AD_Miner) |\n| 3 |\n**AgentsLeak: Runtime Protection for AI Coding Agents** |\nAI, ML & Data Science |\nNew Tool |\nRuntime security platform hooking Claude Code and Cursor to enforce policy on file, network, process and command actions before they execute. |\n[IngaCherny/AgentsLeak](https://github.com/IngaCherny/AgentsLeak) |\n| 4 |\n**AI Attack & Defence Wargame: The Insurance Company Edition** |\nArsenal Lab, AI |\nMajor Update |\nLive adversarial wargame: each player hardens their own LLM insurance chatbot against prompt injection and exfiltration while attacking everyone else's. |\n— *live wargame on the SecDim platform* |\n| 5 |\n**AI Security Playground** |\nArsenal Lab, AI |\nNew Tool |\nHands-on workshop covering real-world attacks against LLMs, AI agents and MCP servers, beginner through advanced. |\n— *workshop; no repo* |\n| 6 |\n**Anthropic-Cybersecurity-Skills** |\nArsenal Lab, AI |\nMinor Update |\n734 open-source agent skills across 37 security subdomains, mapping 127+ MITRE ATT&CK techniques with 1,000+ runnable scripts. |\n[mukul975/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills) |\n| 7 |\n**APTL: Advanced Purple Team Labs** |\nArsenal Lab, Exploitation |\nNew Tool |\nDocker-based purple team lab with an open-source SOC stack, MCP servers and a scenario system for running red and blue AI agents against each other. |\n[Brad-Edwards/aptl](https://github.com/Brad-Edwards/aptl) |\n| 8 |\n**ARAY: Benign Binary Synthesis for Signature Validation Without the Malware** |\nMalware |\nNew Tool |\nGenerates benign ELF/PE binaries matching a given YARA rule via a nine-node LangGraph LLM pipeline, to validate detections without live malware. |\n— *no repo confirmed* |\n| 9 |\n**Azazel-Edge : Deterministic Edge Decision Support for Constrained SOC/NOC Operations** |\nNetwork |\nNew Tool |\nDeterministic edge decision appliance (Raspberry Pi) scoring NOC reliability and SOC threat context separately for small, constrained networks. |\n[01rabbit/Azazel-Edge](https://github.com/01rabbit/Azazel-Edge) |\n| 10 |\n**BadZure: Building Cloud Attack Labs with AI** |\nCloud Security |\nMajor Update |\nDescribe an attack scenario in natural language and BadZure provisions a matching misconfigured Entra ID / Azure tenant with traversable attack paths. |\n[mvelazc0/BadZure](https://github.com/mvelazc0/BadZure) |\n| 11 |\n**Bastet: An Infrastructure for Benchmarking LLM Smart Contract Auditing** |\nAI, ML & Data Science |\nMajor Update |\nBenchmark dataset of real-world DeFi smart contract vulnerabilities plus an AI detection pipeline for bugs static analyzers miss. |\n[OneSavieLabs/Bastet](https://github.com/OneSavieLabs/Bastet) |\n| 12 |\n**Bedrock Keys Security (BKS): Hunting Phantom IAM Users Created by AWS Bedrock API Keys** |\nCloud Security |\nNew Tool |\nDecodes AWS Bedrock API keys (base64 bearer tokens) and hunts the phantom IAM users AWS provisions behind them and never cleans up. |\n[BeyondTrust/bedrock-keys-security](https://github.com/BeyondTrust/bedrock-keys-security) |\n| 13 |\n**Brutus: Modern Multi-Protocol Credential Testing in Go** |\nExploitation |\nNew Tool |\nZero-dependency Go replacement for THC Hydra: credential testing across SSH, MySQL, Postgres, Redis, MongoDB and SMB. |\n[praetorian-inc/brutus](https://github.com/praetorian-inc/brutus) |\n| 14 |\n**capa: Beyond Disassembly: Dynamic Matching for Static Blindspots** |\nMalware |\nMajor Update |\nFLARE's capability identification tool, now applying its rule engine to dynamic execution traces to cover packed, obfuscated, Rust and Go binaries. |\n[mandiant/capa](https://github.com/mandiant/capa) |\n| 15 |\n**Chameleon Forensics (Android): Assume Adversarial Logical Extraction Forensic Tool** |\nDigital Forensics |\nNew Tool |\nAndroid logical extraction built on the assumption the device is adversarial and actively disrupting forensic acquisition. |\n[Ins1ght32/Chameleon-Forensics-Android](https://github.com/Ins1ght32/Chameleon-Forensics-Android) |\n| 16 |\n**Chef Special: Updates to CSTC - CyberChef-inspired Message Transformator in BurpSuite** |\nArsenal Lab, Vuln Assessment |\nMajor Update |\nCyberChef-style recipe engine inside Burp Suite: transformation chains applied automatically to outgoing and incoming HTTP traffic. |\n[usdAG/cstc](https://github.com/usdAG/cstc) |\n| 17 |\n**Cleric: ETW Sandbox and Memory Scanner** |\nMalware |\nNew Tool |\nWindows malware analysis framework combining a C++ memory scanner (15 detection techniques), ETW sandboxing and runtime process inspection. |\n— *no repo confirmed* |\n| 18 |\n**CLOAK : Cloud Testing Agent Harness** |\nCloud Security |\nMajor Update |\nAI red team agent for cloud assessments using \"Dual Output Rendering\" so ARNs, account IDs and resource names never enter the model's context window. |\n— *no repo confirmed* |\n| 19 |\n**Command Line Threat Analyzer** |\nThreat Hunting & IR |\nNew Tool |\nCross-platform detector reconstructing whole attack sequences from command line activity rather than flagging isolated commands. |\n— *no repo confirmed* |\n| 20 |\n**ConfigManBearPig - Identify, Visualize, and Navigate SCCM Attack Paths in BloodHound** |\nExploitation |\nMajor Update |\nFrom a low-privileged AD context, collects SCCM/ConfigMgr data and maps every Misconfiguration Manager TAKEOVER, ELEVATE and CRED path into BloodHound. |\n[SpecterOps/ConfigManBearPig](https://github.com/SpecterOps/ConfigManBearPig) |\n| 21 |\n**Continuous Threat Modeling in Agentic AI era - tmdd** |\nCode Assessment |\nNew Tool |\nThreat Modeling Driven Development: an AI agent infers components and data flows from code and emits a version-controlled YAML threat model reviewed via PRs. |\n[attasec/tmdd](https://github.com/attasec/tmdd) |\n| 22 |\n**CrowdSentinel: AI-Orchestrated Threat Hunting Across Unified Security Data Sources** |\nThreat Hunting & IR |\nNew Tool |\nMCP-based threat hunting orchestrator unifying Elasticsearch, Wireshark, Chainsaw and 5,049 detection rules behind one natural-language endpoint. |\n[thomasxm/CrowdSentinels-AI-MCP](https://github.com/thomasxm/CrowdSentinels-AI-MCP) |\n| 23 |\n**CyberArkHound** |\nExploitation |\n— |\nGo tool exporting CyberArk PVWA data (users, safes, accounts, permissions) into BloodHound OpenGraph so PAM privilege paths sit alongside AD ones. |\n[jazofra/CyberArkHound](https://github.com/jazofra/CyberArkHound) |\n| 24 |\n**Dradis Framework: Intelligent Automation for collaboration and reporting** |\nOSINT |\nMajor Update |\nCollaboration and reporting portal ingesting 47+ scanners, with bring-your-own-LLM assistance (Dradis Echo) that stays on your own infrastructure. |\n[dradis/dradis-ce](https://github.com/dradis/dradis-ce) |\n| 25 |\n**EMBA – The product security analysis framework** |\nArsenal Lab, IoT |\nMajor Update |\nThe firmware security analyzer for IoT/ICS/OT: automated static and dynamic analysis of embedded Linux firmware images end to end. |\n[e-m-b-a/emba](https://github.com/e-m-b-a/emba) |\n| 26 |\n**EMBArk – Firmware Analysis for the Enterprise** |\nVulnerability Assessment |\nMajor Update |\nWeb-based enterprise front end for EMBA — orchestrate, compare and manage firmware analyses across a product portfolio and supply chain. |\n[e-m-b-a/embark](https://github.com/e-m-b-a/embark) |\n| 27 |\n**Emulate cloud-native attacks with Stratus Red Team** |\nCloud Security |\nMinor Update |\nGranular, self-contained adversary emulation for AWS, Azure, GCP, Entra ID and Kubernetes to validate that cloud threat detections fire. |\n[DataDog/stratus-red-team](https://github.com/DataDog/stratus-red-team) |\n| 28 |\n**FAInd my XPC: Automated Discovery of Privilege Escalation via macOS XPC Trust Boundaries - powered by LLM** |\nExploitation |\nNew Tool |\nAutomated macOS XPC attack-surface discovery: static binary analysis plus runtime enumeration and LLM semantic scoring to find privesc across installed apps. |\n— *no repo confirmed* |\n| 29 |\n**fetter** |\nVulnerability Assessment |\nMajor Update |\nSystem-wide Python package discovery, validation and allow-listing — what is actually installed, rather than what the manifest claims. |\n[fetter-io/fetter-rs](https://github.com/fetter-io/fetter-rs) |\n| 30 |\n**findmytakeover - find dangling domains in a multi cloud environment** |\nCloud Security |\nMajor Update |\nFinds dangling DNS records across multi-cloud, multi-account estates by comparing live DNS zones against actual infrastructure — no wordlists or brute force. |\n[anirudhbiyani/findmytakeover](https://github.com/anirudhbiyani/findmytakeover) |\n| 31 |\n**From Breakthrough to Completeness: arkdecompiler - The Decompiler for HarmonyOS NEXT** |\nReverse Engineering |\nMajor Update |\nDecompiler for Huawei HarmonyOS NEXT, targeting the Ark bytecode execution environment outside the Android/AOSP toolchain. |\n[jd-opensource/arkdecompiler](https://github.com/jd-opensource/arkdecompiler) |\n| 32 |\n**Ghost in the IDE** |\nExploitation |\nMajor Update |\nResearch into the IDE plugin ecosystem as an attack surface across JetBrains IntelliJ, VS Code and Eclipse. |\n— *no repo confirmed* |\n| 33 |\n**Ghostwriter** |\nExploitation |\nMajor Update |\nOffensive-ops platform for report writing, reusable findings libraries, client management and red team infrastructure tracking. |\n[GhostManager/Ghostwriter](https://github.com/GhostManager/Ghostwriter) |\n| 34 |\n**GolemHalt: A Deterministic Reference Monitor for AI Coding Agents** |\nAI, ML & Data Science |\nNew Tool |\nDeterministic boundaries for AI coding agents against prompt injection, exfiltration and destructive actions. |\n— *no repo confirmed* |\n| 35 |\n**Hecate: a trivial UART tool** |\nArsenal Lab |\nMinor Update |\nTurns any CircuitPython-compatible microcontroller into a customizable UART implant for sniffing and interposing on serial links. |\n[tigard-tools/hecate](https://github.com/tigard-tools/hecate) |\n| 36 |\n**HoneyMCP: A Deception Security Layer for MCP Servers** |\nAI, ML & Data Science |\nNew Tool |\nDeception layer for MCP servers: plants LLM-generated decoy tools that emit telemetry on exfiltration or indirect prompt injection attempts. |\n[barvhaim/HoneyMCP](https://github.com/barvhaim/HoneyMCP) |\n| 37 |\n**ICSForge™: OT/ICS Security Coverage Validation Platform** |\nSmart Grid/Industrial |\nNew Tool |\nGenerates realistic OT traffic and PCAPs across 500+ scenarios in 10 industrial protocols (Modbus/TCP, DNP3, S7comm, IEC-104, OPC UA). |\n[ICSForge/ICSForge](https://github.com/ICSForge/ICSForge) |\n| 38 |\n**INFLEX: Cross-Format Malware Analysis and Correlation Framework** |\nMalware |\nNew Tool |\nCorrelates PE, ELF, shellcode and malicious documents in one workflow through static analysis, emulation, sandboxing and threat intel enrichment. |\n— *no repo confirmed* |\n| 39 |\n**Intercept.js: Context-Aware YARA for Runtime Detection In JavaScript Environments** |\nMalware |\nNew Tool |\nContext-aware YARA matching inside JavaScript runtimes — browsers, email clients, Office add-ins — where payloads exist only as in-memory buffers. |\n[rishi-sekantsec/sekant-intercept-js](https://github.com/rishi-sekantsec/sekant-intercept-js) |\n| 40 |\n**JS-Tap v3: JavaScript Post-Exploitation Moves to the Endpoint** |\nExploitation |\nMajor Update |\nJavaScript C2 extended past the web app to the endpoint, with implants for browser extensions, Electron desktop apps and Node.js CLI tools. |\n[hoodoer/JS-Tap](https://github.com/hoodoer/JS-Tap) |\n| 41 |\n**KEIP: Kernel-Enforced Install-Time Policies** |\nMalware |\nNew Tool |\neBPF/LSM kernel hooks intercepting and blocking malicious network activity during `pip install` — supply-chain defense at package install time. |\n[Otsmane-Ahmed/KEIP](https://github.com/Otsmane-Ahmed/KEIP) |\n| 42 |\n**Keychecker : SSH Key based attack tool for DVCS Systems** |\nVulnerability Assessment |\nMinor Update |\nFingerprints a found SSH private key and determines which Git hosting accounts it unlocks, via safe handshakes and read-only `git ls-remote` probes. |\n[cyfinoid/keychecker](https://github.com/cyfinoid/keychecker) |\n| 43 |\n**LLM Hacking 101** |\nArsenal Lab, AI |\nNew Tool |\nTwo-hour hands-on lab progressing from jailbreak development to guardrail bypass and direct/indirect prompt injection against agentic systems. |\n[RootInj3c/LLM-Playground](https://github.com/RootInj3c/LLM-Playground) |\n| 44 |\n**LogonTracer v2: Faster Malicious Windows Logon Investigations with AI Agent** |\nThreat Hunting & IR |\nMajor Update |\nVisualizes Windows authentication events as a user/host graph, now with an AI agent to speed triage of malicious logons in noisy event data. |\n[JPCERTCC/LogonTracer](https://github.com/JPCERTCC/LogonTracer) |\n| 45 |\n**LoRaCraft – Crafting Attacks for LoRaWAN Networks** |\nInternet of Things |\nNew Tool |\nLoRaWAN security assessment framework covering the full protocol stack — join request replay, RF-layer testing and target fingerprinting. |\n[pinarsadioglu/loracraft](https://github.com/pinarsadioglu/loracraft) |\n| 46 |\n**MachStealer: One Pipeline Behind Every macOS Infostealer** |\nMalware |\nNew Tool |\nReproduces the shared macOS infostealer pipeline (Keychain extraction, PBKDF2 derivation, SQLite copy, AES decrypt) behind AMOS, Poseidon, Banshee and Cuckoo. |\n[ultra-supara/MachStealer](https://github.com/ultra-supara/MachStealer) |\n| 47 |\n**MCParasite: Universal MCP Worm Security Testing Framework** |\nAI, ML & Data Science |\nNew Tool |\nChains prompt injection and tool poisoning into a self-propagating worm inside MCP — poisoning lands at connection time, before user interaction. |\n[MCParasite/mcparasite](https://github.com/MCParasite/mcparasite) |\n| 48 |\n**Mecha Hayabusa by Yamato Security** |\nDigital Forensics |\nNew Tool |\nMCP server loading Hayabusa timelines into DuckDB and exposing them to an LLM for natural-language Windows event log DFIR. |\n[Yamato-Security/mecha-hayabusa](https://github.com/Yamato-Security/mecha-hayabusa) |\n| 49 |\n**Medaudit, an AI assisted Tool for Auditing Hospital Networks and Pentesting Medical Devices** |\nSmart Grid/Industrial |\nMajor Update |\nAudits medical device network traffic (HL7 focus) for unencrypted transmissions and PHI/PII exposure, with fuzzing and AI-assisted triage. |\n[anirudhduggal/medaudit](https://github.com/anirudhduggal/medaudit) |\n| 50 |\n**MEM-SBOM: Runtime SBOM Generation from Python Process Memory** |\nDigital Forensics |\nNew Tool |\nGenerates SBOMs from live Python process memory rather than build manifests, catching dynamically loaded modules static tooling misses. |\n[HalaAli198/MEM-SBOM](https://github.com/HalaAli198/MEM-SBOM) |\n| 51 |\n**MLOKit: MLOps Attack Toolkit** |\nExploitation |\nMajor Update |\nC# toolkit attacking MLOps platforms (Azure ML, SageMaker, Vertex AI, MLflow, BigML, Palantir AIP) via their REST APIs. |\n[h4wkst3r/MLOKit](https://github.com/h4wkst3r/MLOKit) |\n| 52 |\n**MORF - Mobile Reconnaissance Framework** |\nOSINT |\nMajor Update |\nAutomatically discovers secrets and sensitive information inside Android and iOS application packages. |\n[amrudesh1/morf](https://github.com/amrudesh1/morf) |\n| 53 |\n**MSCodePhish - Dynamic Device Code Phishing Framework** |\nExploitation |\nNew Tool |\nTurns Microsoft Device Code OAuth into an embeddable phishing primitive — codes minted on click via an API, defeating the 15-minute timeout race. |\n[TROUBLE-1/MSCodePhish](https://github.com/TROUBLE-1/MSCodePhish) |\n| 54 |\n**MSSQLHound - Identify, Visualize, and Navigate MSSQL Attack Paths in BloodHound** |\nExploitation |\nMajor Update |\nEnumerates MSSQL principals and permissions at domain, server and database level and maps abusable paths into the BloodHound graph. |\n[SpecterOps/MSSQLHound](https://github.com/SpecterOps/MSSQLHound) |\n| 55 |\n**Nemesis 2.2** |\nAI, ML & Data Science |\nMajor Update |\nCentralized enrichment pipeline for files collected on offensive engagements; 2.2 adds ingestion of full disk images and large forensic containers. |\n[SpecterOps/Nemesis](https://github.com/SpecterOps/Nemesis) |\n| 56 |\n**Nogitsune: eBPF-Based Anti-VM Detection for Linux Malware Analysis** |\nMalware |\nNew Tool |\nFirst eBPF-based anti-VM detection toolkit for Linux — hides the analysis VM from malware without patching QEMU or rebuilding SeaBIOS. |\n[sumukhchitloor/nogitsune](https://github.com/sumukhchitloor/nogitsune) |\n| 57 |\n**notyet: Automated IAM Persistence Analysis Through AWS Eventual Consistency Abuse** |\nCloud Security |\nNew Tool |\nAbuses the propagation delay in AWS IAM's eventual consistency to keep using credentials responders believe they revoked. |\n[OFFENSAI/notyet](https://github.com/OFFENSAI/notyet) |\n| 58 |\n**Obscurize: Malware for Defense and Counter Offense** |\nMalware |\nNew Tool |\nRepurposes rootkit environment-enumeration techniques (BIOS strings, MAC OUI, RAM size, process lists) into a defensive and offensive tool. |\n— *no repo confirmed* |\n| 59 |\n**OWASP EKS Goat: Hands-On AWS EKS Security** |\nCloud Security |\nMajor Update |\nIntentionally vulnerable AWS EKS cluster for hands-on learning: supply chain compromise, ECR/EKS abuse and RBAC misconfiguration scenarios. |\n— *no repo confirmed* |\n| 60 |\n**OWASP Faction 2.0** |\nVulnerability Assessment |\nMajor Update |\nGround-up rebuild of the pentest assessment and reporting platform, adding AI-assisted report writing, a CLI integration framework and app inventory. |\n[factionsecurity/faction](https://github.com/factionsecurity/faction) |\n| 61 |\n**Pathrunner: An AWS Privilege Escalation Framework** |\nCloud Security |\nMajor Update |\nModular AWS IAM privilege escalation framework automating the paths documented at pathfinding.cloud. |\n[DataDog/pathrunner](https://github.com/DataDog/pathrunner) |\n| 62 |\n**Pentest Copilot V2: The Agentic Pentesting Workspace** |\nExploitation |\nMajor Update |\nAI-native browser-based workspace unifying recon, exploitation support, scripting and web testing. |\n— *no repo confirmed* |\n| 63 |\n**Pentesting made easy - Keeping sessions alive with session-chains** |\nWebAppSec |\nNew Tool |\nKeeps multiple authenticated web sessions alive across users, roles and tenants so scanners and exploitation tools stop breaking on short-lived sessions and MFA. |\n— *no repo confirmed* |\n| 64 |\n**PETriage: Cross-Platform PE Surface Analysis for Malware Triage** |\nMalware |\nNew Tool |\nSymbol-unified PE reader bringing PEStudio/CFF Explorer-style triage to Linux and macOS hosts. |\n[uky007/PETriage](https://github.com/uky007/PETriage) |\n| 65 |\n**Practical Ransomware Detection on macOS (via Math, not AI)** |\nMalware |\nMajor Update |\nMath-driven, explicitly not ML, generic macOS ransomware detection keyed on the rapid file-encryption behaviour common to nearly every variant. |\n— *no repo confirmed* |\n| 66 |\n**Praxis - Semantic Command & Control Framework** |\nAI, ML & Data Science |\nMinor Update |\nAdversarial C2 for discovering and driving AI computer-use agents (Claude, Codex, Cursor) already running on endpoints. |\n— *no repo confirmed* |\n| 67 |\n**Precogly: Open Source Threat Modeling for AI-Assisted Security** |\nWebAppSec |\nNew Tool |\nOpen-source threat modeling: DFD editor, community threat libraries, LINDDUN/CAPEC/ATT&CK taxonomies and PCI-DSS/NIST mappings, with AI hooks. |\n[precogly/precogly](https://github.com/precogly/precogly) |\n| 68 |\n**PrivacyTrollShield: An Open-Source Scanner for Privacy Compliance** |\nPrivacy |\nNew Tool |\nScans public sites for the tracking behaviours behind CIPA wiretapping suits — session replay before consent, Meta Pixel form capture, dead Decline buttons. |\n[atekippe/PrivacyTrollShield](https://github.com/atekippe/PrivacyTrollShield) |\n| 69 |\n**PwnSat 2.0: The Vulnerable Satellite Hacking Platform for Learning Through Research** |\nExploitation |\nMajor Update |\nVulnerable-by-design satellite platform for aerospace security research; 2.0 adds enterprise mission-control integration beyond 1.0's RF attack focus. |\n— *no repo confirmed* |\n| 70 |\n**pymsi - Interactive MSI Installer Analysis in Python and the Browser** |\nCode Assessment |\nMajor Update |\nPure Python MSI parser exposing installer database tables and embedded streams, plus a fully client-side lessmsi-style browser UI. |\n[nightlark/pymsi](https://github.com/nightlark/pymsi) |\n| 71 |\n**QuicDraw & QuicDraw-UI: Racing and Fuzzing HTTP/3** |\nWebAppSec |\nMajor Update |\nFuzzes and race-tests HTTP/3 servers over QUIC using \"Quic-Fin-Sync\" for high-speed single-packet race conditions. Apache-2.0. |\n[cyberark/QuicDrawH3](https://github.com/cyberark/QuicDrawH3) |\n| 72 |\n**ReARM: Release Governance Platform** |\nVulnerability Assessment |\nMajor Update |\nDevSecOps release governance: an SBOM/xBOM repository and evidence store tracking releases with their bills of materials and security findings. |\n[relizaio/rearm](https://github.com/relizaio/rearm) |\n| 73 |\n**RedTeamSimmer: A Web Based Adversary Emulation Platform and Atomic Red Team Test Orchestration** |\nAI, ML & Data Science |\n— |\nFlask-based web UI for orchestrating Atomic Red Team tests across enterprise Windows estates, handling prerequisites and centralizing results. |\n[BreachSimRange/RedTeamSimmer](https://github.com/BreachSimRange/RedTeamSimmer) |\n| 74 |\n**ROP ROCKET: New ASLR Bypass Mini-Tool & Automating Advanced ROP Attacks** |\nExploitation |\nMajor Update |\nWindows code-reuse framework; adds a mini-tool generating nine automated bypasses for 64-bit high-entropy ASLR with complete x64 ROP chains. |\n[Bw3ll/ROP_ROCKET](https://github.com/Bw3ll/ROP_ROCKET) |\n| 75 |\n**RPCExplorer** |\nReverse Engineering |\nNew Tool |\nResearch toolkit for mapping and probing the Windows RPC attack surface at scale — turning an interface UUID into what it does and how to test it. |\n— *no repo confirmed* |\n| 76 |\n**SafeScribe - Edge Device AI Meeting Notetaker** |\nHardware/Embedded |\nNew Tool |\nPrivacy-first desk device generating meeting notes entirely locally and delivering them as a PDF. |\n— *no repo confirmed* |\n| 77 |\n**Sage: Giving an AI the Keys to Your C2 Framework** |\nAI, ML & Data Science |\nNew Tool |\nVirtual Mythic agent running on the C2 server rather than the target — a multi-agent AI operator that enumerates callbacks and tasks real agents. |\n[MythicAgents/sage](https://github.com/MythicAgents/sage) |\n| 78 |\n**SBoMPlay : SBoM Exploration and Intelligence extraction platform** |\nCode Assessment |\nMajor Update |\nBrowser-based, privacy-preserving SBOM exploration — query dependency data locally instead of uploading it to a heavyweight platform. |\n[cyfinoid/sbomplay](https://github.com/cyfinoid/sbomplay) |\n| 79 |\n**SEmuRAI: Software Emulation and Reversing AI Agent** |\nReverse Engineering |\nNew Tool |\nAgentic reverse engineering: LLM-driven emulation and analysis of obfuscated or large binaries where compilation stripped the context. |\n[DevNerdGR/SEmuRAI-mcp](https://github.com/DevNerdGR/SEmuRAI-mcp) |\n| 80 |\n**ShadowHunt 2.0: Uncovering Shadow IT and Hidden Secrets** |\nOSINT |\n— |\nMaps Shadow IT on public repos — company code pushed to employees' personal GitHub, Docker Hub and Helm accounts — and the secrets left in it. |\n[Research-Nautilus/ShadowHunt](https://github.com/Research-Nautilus/ShadowHunt) |\n| 81 |\n**SHAREM: Next-Generation Shellcode Analysis Tool** |\nReverse Engineering |\nMajor Update |\nNSA-funded shellcode analysis framework emulating 45,000+ WinAPIs and Windows syscalls to defeat dynamic API resolution and self-unpacking. |\n[Bw3ll/sharem](https://github.com/Bw3ll/sharem) |\n| 82 |\n**ShellWasp: Creating Shellcode with Windows Syscalls** |\nExploitation |\nMajor Update |\nBuilds shellcode using Windows syscalls directly, solving the SSN-drift and Wow64 portability problems that break syscall shellcode across OS builds. |\n[Bw3ll/ShellWasp](https://github.com/Bw3ll/ShellWasp) |\n| 83 |\n**Social Engineering with Reel** |\nExploitation |\nNew Tool |\nWorkflow-driven phishing framework with credential capture, optional real-time MFA relay, email sending and a plugin system. |\n[trustedsec/Reel](https://github.com/trustedsec/Reel) |\n| 84 |\n**Splunk MCP LLM SIEMulator: Open Source AI Security Monitoring Through MCP Integration** |\nAI, ML & Data Science |\nMajor Update |\nBridges local LLM deployments to Splunk over MCP, giving SIEM visibility into prompt injection, jailbreak attempts and shadow AI usage. |\n[rsfl/splunk-mcp-llm-siemulator](https://github.com/rsfl/splunk-mcp-llm-siemulator) |\n| 85 |\n**StegoScan** |\nDigital Forensics |\n— |\nAutomated steganography detection across file types. |\n[LCBOWER33/StegoScan](https://github.com/LCBOWER33/StegoScan) |\n| 86 |\n**Surfactant - Modular Framework for File Information Extraction and SBOM Generation** |\nCode Assessment |\nMajor Update |\nLLNL's modular framework extracting software metadata from filesystems to identify components, vendors and third-party libraries and build SBOMs. |\n[llnl/Surfactant](https://github.com/llnl/Surfactant) |\n| 87 |\n**Suricata 8: Discover the Difference in Network Detection** |\nThreat Hunting & IR |\nMajor Update |\nThe open-source IDS/IPS and network security monitor — this session covers what is new in the Suricata 8 release. |\n[OISF/suricata](https://github.com/OISF/suricata) |\n| 88 |\n**Suricata Turbo: Let Your NIC Drop the Flows Suricata Won't Miss** |\nNetwork |\nMajor Update |\nAdds hardware traffic-filtering offload so the NIC drops uninteresting flows, stopping random packet loss when Suricata cannot keep up. |\n[DynaNIC/suricata-turbo](https://github.com/DynaNIC/suricata-turbo) |\n| 89 |\n**Suzaku by Yamato Security** |\nDigital Forensics |\nMajor Update |\nRust, Sigma-based threat hunting and DFIR timeline generator for cloud logs — Hayabusa's approach applied to JSON/JSON.gz at scale. |\n[Yamato-Security/suzaku](https://github.com/Yamato-Security/suzaku) |\n| 90 |\n**Tengu Marauder Vanguard Version 2.0** |\nArsenal Lab, Hardware |\nMajor Update |\nRaspberry Pi 5 robotic platform for physical red teaming and wireless assessment, with multiple units managed from a single Flask interface. |\n[Lexicon121/Tengu-Marauder-Vanguard](https://github.com/Lexicon121/Tengu-Marauder-Vanguard) |\n| 91 |\n**The Metasploit Framework 6.5: Malleable C2 Payloads, New Relay Capability and Protocol Session Upgrades** |\nExploitation |\nMinor Update |\nMetasploit 6.5: Malleable C2 profiles for HTTP Meterpreter, HTTP-to-SMB and HTTP-to-LDAP relaying, and protocol session upgrades. |\n[rapid7/metasploit-framework](https://github.com/rapid7/metasploit-framework) |\n| 92 |\n**ThreatShield - The Intelligent Way of Threat Modelling** |\nArsenal Lab, AI |\n— |\nTurns PRDs, architecture diagrams, Confluence pages, Slack threads and transcripts into STRIDE/PASTA threat models, attack trees, DREAD scores and ASVS tests. |\n— *no repo confirmed* |\n| 93 |\n**ThreatXtension: AI-Powered Browser Extension Security Analysis Framework** |\nVulnerability Assessment |\nNew Tool |\nChrome extension security analysis combining SAST with LLM threat intelligence to assess permission risk and detect obfuscated malicious patterns. |\n[barvhaim/ThreatXtension](https://github.com/barvhaim/ThreatXtension) |\n| 94 |\n**Trajan: Cross-Platform CI/CD Security Scanner** |\nExploitation |\nNew Tool |\nOne scanner across GitHub Actions, Azure DevOps, GitLab and Jenkins, replacing the per-platform tooling patchwork. |\n[praetorian-inc/trajan](https://github.com/praetorian-inc/trajan) |\n| 95 |\n**TSURUGI LINUX - the sharpest weapon in your DFIR arsenal** |\nDigital Forensics |\nNew Tool |\nDFIR-focused Linux distribution shipping a curated, ready-to-use forensics toolset. |\n— *not on GitHub; tsurugi-linux.org* |\n| 96 |\n**unrelabel: how to destroy an ML model** |\nAI, ML & Data Science |\nNew Tool |\nInteractive toolkit demonstrating label-poisoning attacks: import a dataset, pick an attack, and watch a classifier degrade from accurate to useless. |\n[oz9un/unrelabel](https://github.com/oz9un/unrelabel) |\n| 97 |\n**Vulnhalla 2.0: LLM-Guided Triage of CodeQL Findings** |\nCode Assessment |\nMajor Update |\nRuns CodeQL at scale and uses an LLM agent to triage findings true/false positive, with fast CSV-based context extraction and a reasoning engine. |\n[cyberark/Vulnhalla](https://github.com/cyberark/Vulnhalla) |\n| 98 |\n**VulnZoo: A Complete Vulnerable IoT Ecosystem for Security Research and Training** |\nInternet of Things |\nNew Tool |\nVulnerable IoT ecosystem modelling a whole product — firmware, mobile app and cloud services — so cross-component attack chains can be studied. |\n[DEKRA-Cybersecurity/VulnZoo](https://github.com/DEKRA-Cybersecurity/VulnZoo) |\n| 99 |\n**WaffleX: Adaptive Semantic Analysis for WAF Resilience Testing** |\nWebAppSec |\nNew Tool |\nGenerates semantically equivalent request variants to expose normalization gaps and parser inconsistencies between CDNs, proxies, WAFs and origin apps. |\n— *no repo confirmed* |\n| 100 |\n**WebAgentAudit: Security Auditing of Web-Based AI Agents Through Browser Automation** |\nVulnerability Assessment |\nNew Tool |\nAudits web-only AI agents (embedded chatbots and LLM widgets) through browser automation, requiring no API access to the model under test. |\n[atom41research/webagentaudit](https://github.com/atom41research/webagentaudit) |\n| 101 |\n**xEndity** |\nInternet of Things |\nNew Tool |\nEmulated digital twins of IoT devices, so teams can test hardware they cannot physically obtain or safely attack in production. |\n[kenleejl/xEndityv2](https://github.com/kenleejl/xEndityv2) |", "url": "https://wpnews.pro/news/black-hat-usa-2026-arsenal-all-101-tools-with-github-links", "canonical_source": "https://gist.github.com/chris-rock/6f32859d48a4742e28344d6c729ff51e", "published_at": "2026-08-05 16:06:59+00:00", "updated_at": "2026-08-13 20:52:50.875232+00:00", "lang": "en", "topics": ["ai-safety", "ai-tools", "developer-tools"], "entities": ["Black Hat USA", "AgentsLeak", "AD Miner", "BadZure", "ARAY", "Claude Code", "Cursor", "MITRE ATT&CK"], "alternates": {"html": "https://wpnews.pro/news/black-hat-usa-2026-arsenal-all-101-tools-with-github-links", "markdown": "https://wpnews.pro/news/black-hat-usa-2026-arsenal-all-101-tools-with-github-links.md", "text": "https://wpnews.pro/news/black-hat-usa-2026-arsenal-all-101-tools-with-github-links.txt", "jsonld": "https://wpnews.pro/news/black-hat-usa-2026-arsenal-all-101-tools-with-github-links.jsonld"}}