Open-source Windows cybersecurity and IT diagnostics for authorized environments.
Overview · Features · Installation · Screenshots · Architecture · Roadmap · Security · Contributing · License
CyberTool is a local-first Windows desktop application built with WinUI 3 and .NET 8. It unifies network discovery, Windows system enumeration, security assessment helpers, optional AI-assisted analysis, and training-oriented simulations in one transparent toolkit.
Maintained as an independent open-source project by TahaAkgl27 and contributors.
Organizations and learners often juggle separate scripts, scanners, and ad-hoc PowerShell for basic Windows diagnostics. CyberTool reduces that fragmentation with a structured workflow—from port scan to device profile to exportable reports—while keeping data on the local machine.
Authorized use only. CyberTool includes security testing and simulation capabilities. Read DISCLAIMER.md before use.
| Problem | Fragmented Windows security diagnostics across multiple tools and scripts |
| Solution | Unified, inspectable, local-first diagnostics and training platform |
| Model | Open source (MIT), community-driven, safety-documented |
| Operations & Security | Education & Research |
|---|---|
| Windows Administrators | Cybersecurity Students |
| IT Engineers | Training Labs |
| Helpdesk Teams | Educational Institutions |
| SOC / Blue Teams | Authorized Red Team exercises |
CyberTool is not intended for unauthorized testing or use against systems without explicit permission.
| Capability | Description |
|---|---|
| Device profiling | Host metadata, OS context, and extended protocol hints |
| WMI enumeration | Remote Windows metadata via authenticated queries |
| Hardening insights | Registry and configuration checks for local posture |
| Executive summaries | Risk scoring and stakeholder-ready narratives |
| Capability | Description |
|---|---|
| Port scanning | Configurable TCP port range analysis |
| Service identification | Protocol and service mapping per open port |
| Exposure analysis | Internal vs. internet-facing scope classification |
| Attack surface summary | Aggregated external and risky service counts |
| Capability | Description |
|---|---|
| Risk scoring | Severity tiers with rationale per finding |
| Compliance hints | Framework-oriented violation mapping |
| Remediation suggestions | Template and AI-assisted fix scripts with rollback |
| Attack graph simulation | Chain-style path modeling for defense planning |
| Capability | Description |
|---|---|
| WMI deep scan | Authenticated enumeration of remote hosts |
| SMB context | Signing status and related protocol signals |
| System inventory | OS, CPU, RAM, domain/workgroup heuristics |
| Nmap XML import | Ingest external scan results |
| Capability | Description |
|---|---|
| Scan explanation | Optional OpenAI-powered attack scenario narratives |
| Remediation generation | Context-aware PowerShell packages (user-reviewed) |
| Fully optional | Core features work without any API key |
| Capability | Description |
|---|---|
| Session history | Local persistence of scan sessions |
| Technical / executive reports | Exportable summaries for stakeholders |
| Lab demo data | Generic sample hosts for classroom scenarios |
| Ransomware simulation | Subnet awareness training (authorized labs only) |
- Windows 10 (1809+) or Windows 11
- .NET SDK 8.0
- Windows App SDK (restored via NuGet)
- x64 recommended
git clone https://github.com/TahaAkgl27/CyberTool.git
cd CyberTool
dotnet restore CyberTool.csproj
dotnet build CyberTool.csproj -c Release -p:Platform=x64Run with Visual Studio (CyberTool (Unpackaged)) or:
.\bin\x64\Release\net8.0-windows10.0.19041.0\CyberTool.exe- Open Settings
- Enter your API key (
sk-...) - Click Save
The key is stored locally at %AppData%\CyberTool\config.json — never in source control.
Full guide: docs/usage.md
CyberTool v1.0.0 on Windows — premium dark UI with port scanning, attack chain visualization, security recommendations, and host analysis in a controlled demo environment.
CyberTool follows MVVM with a service-oriented backend:
Views (WinUI 3) → ViewModels → Services → Models / Local Storage
- Views: Dashboard, Scan, Device Profile, Attack, Ransomware, Reports, Settings
- Services: Scan orchestration, WMI, OpenAI, remediation, reporting, history
- Storage:
%AppData%\CyberTool\(config, history),%LocalAppData%\CyberTool\(logs)
Full diagrams: docs/architecture.md
| Version | Focus |
|---|---|
| v1.0 | Public release, safety docs, CI, premium UI |
| v1.1 | DPAPI / Credential Manager for API keys |
| v1.2 | Reporting export, Plugin SDK foundation |
| v1.5 | Localization, dark theme improvements |
| v2.0 | Enterprise Safe Mode, plugin marketplace, offline AI |
Details: docs/roadmap.md
| Document | Purpose |
|---|---|
| SECURITY.md | Vulnerability reporting and secure development |
| DISCLAIMER.md | Authorized-use legal notice |
| docs/safety.md | Operational safety guide |
Report vulnerabilities via GitHub Security Advisories only.
We welcome contributions that improve safety, documentation, and diagnostics quality.
- CONTRIBUTING.md — setup and PR checklist
- CODE_OF_CONDUCT.md — community standards
- docs/FIRST_ISSUES.md — starter issue ideas
dotnet build CyberTool.csproj -c Release -p:Platform=x64MIT License — Copyright (c) 2026 CyberTool Contributors.
Is CyberTool malware?
No. CyberTool is a legitimate diagnostics and training application. See DISCLAIMER.md.
Can I scan any IP address?
Only systems you own or have written authorization to assess.
Does CyberTool send data to the cloud?
Core scanning and history are local-only. Optional OpenAI features send scan summaries only when you configure an API key.
Do I need an OpenAI API key?
No. Scanning, enumeration, reporting, and simulation work without AI.
Built with WinUI 3 · .NET 8 · Windows App SDK
Copyright (c) 2026 CyberTool Contributors · MIT License

