Unlock the full potential of your penetration testing engagements with our curated collection of essential commands and tools. This resource is designed for security professionals seeking to streamline their workflows, discover new techniques, and enhance their testing capabilities. Whether you are identifying vulnerabilities, exploiting misconfigurations, or automating tasks, these tools will equip you to tackle real-world challenges efficiently and effectively.
| Name | Description | Category | Attributes |
|---|---|---|---|
| Tool for automating customized attacks against web applications. | Bug bounty | ||
| Automate customized attacks against web applications | Web Application Exploitation | ||
| zero-configuration DNS utilities for assisting in detection and exploitation of SSRF-related vulnerabilities | Web Application Exploitation | ||
| Bake a windows payload from the C2 of your choice to bypass AV | Red Teaming | ||
| FTP server for OOB XXE attacks | Web Application Exploitation | ||
| Enumerate s3 buckets for a specific target. | Cloud & services | ||
| 403/401 Bypass Methods. | Auth & perms | ||
| A Burp Suite extension made to automate the process of bypassing 403 pages. | Auth & perms | ||
| HTTP 403 bypass tool. | Auth & perms | ||
| Advanced discovery of Privileged Accounts, includes Shadow Admins. | Auth & perms | ||
| Active Directory assessment and privilege escalation script. | Auth & perms | ||
| Wrapper around adb to ease certain tasks | Mobile | ||
| ADCS exploitation automation by weaponizing Certipy and Coercer | Networking | ||
| Read information from Active Directory and ADFS Configuration Database; fed information into ADFSpoof to generate security tokens | System Exploitation | ||
| Using ADFSDump information, produce a usable key/cert pair for token signing, produce a signed security token that can be used to access a federated application | System Exploitation | ||
| Active Directory audit tool that extract data from Bloodhound to uncover security weaknesses and generate an HTML report | Networking | ||
| Active Directory Report Tool. | Informations gathering | ||
| Enumerate an Active Directory environment with LDAP queries. | Auth & perms | ||
| Gather information about the Active Directory and generates a report. | Auth & perms | ||
| Gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment | Networking | ||
| Active Directory delegation management tool allowing to make a detailed inventory of delegations set up so far in a forest | Reconnaissance | ||
| Find misconfiguration through the LDAP protocol and exploit some weaknesses with kerberos | Networking | ||
| Find misconfiguration through LDAP to exploit weaknesses with Kerberos. | Auth & perms | ||
| Online virtual machine for malware hunting, sandbox with interactive access, real-time data-flow | Reverse Engineering | ||
| All in one recon tool for bug bounty. | Informations gathering | ||
| Fuzz request attributes using common pentesting techniques and lists vulnerabilities. | Development | ||
| Library to fuzz request attributes using common pentesting techniques and lists vulnerabilities | Web Application Exploitation | ||
| Passive enumeration utility For Android applications. | Operating systems | ||
| Static code analysis for Android apps that is based on the OWASP MASVS framework | Code Analysis | ||
| Scanning APK file for URIs, endpoints & secrets. | Informations gathering | ||
| Scanning APK file for URIs, endpoints and secrets | Code Analysis | ||
| Android application identifier for packers, protectors, obfuscators and oddities. | Operating systems | ||
| APTRS (Automated Penetration Testing Reporting System) is an automated reporting tool in Python and Django. The tool allows Penetration testers to create a report directly without using the Traditional Docx file. It also provides an approach to keeping track of the projects and vulnerabilities. | Collaboration and Report | ||
| Automated penetration testing reporting system. | Bug bounty | ||
| Tool for ASLR bypass with stack-spraying | Binary Exploitation | ||
| Leverage ASN to look up IP addresses owned by a specific organization. | Informations gathering | ||
| CLI and Library for quickly mapping organization network ranges using ASN information | Networking | ||
| Quickly maps organization network ranges using ASN information. | Informations gathering | ||
| Authentication Token Obtain and Replace Extender. | Auth & perms | ||
| AntiVirus Evasion Tool; targeting windows machines with executable files | Red Teaming | ||
| Identify and test S3 buckets, Google Storage buckets and Azure Storage containers for common misconfiguration | Plugins | ||
| Command-line script to test cloud storage for common misconfiguration issues. | Cloud & services | ||
| Test S3 buckets as well as Google Storage buckets and Azure Storage containers for common misconfiguration issues | Cloud | ||
| This script enumerates the permissions of all the AWS principals of an account. | Auth & perms | ||
| This Burp Suite provides additional Scanner checks for AWS security issues. | Cloud & services | ||
| Security Tool to Look For Interesting Files in S3 Buckets. | Cloud & services | ||
| A damn vulnerable AWS infrastructure. | Cloud & services | ||
| Pull secrets from an AWS environment. | Cloud & services | ||
| Database protection suite with field level encryption and intrusion detection. | Cryptanalysis | ||
| Enumerate AD through LDAP with a collection of helpfull scripts being bundled: ASREPRoasting, Kerberoasting, dump AD as BloodHound JSON files, searching GPOs in SYSVOL for cpassword and decrypting, run without creds | Networking | ||
| Extends Burp Suite's active and passive scanning capabilities. | Well known products | ||
| Quickly find and fix the vulnerabilities that put your web applications at risk of attack. | Bug bounty | ||
| Web application security scanner | Web Application Exploitation | ||
| Active Directory ACL visualizer and explorer; similar to BloodHound | Networking | ||
| Android APK reversing and analysis suite | Code Analysis | ||
| API key/token exploitation made easy. | Informations gathering | ||
| A library of adversary emulation plans to allow organizations to evaluate their defensive capabilities against the real-world threats they face | Adversary Simulation | ||
| Web directory and file scanner (wordlist bruteforce) | Web Application Exploitation | ||
| Burp Suite extension for dynamic payload generation to detect injection flaws. | Vulnerabilities | ||
| Android remote administration tool. | Operating systems | ||
| Suite of tools to assess WiFi network security (cracking WEP and WPA PSK) | Wireless | ||
| Bug Bounty notes gathered from various sources. | Auth & perms | ||
| Generates permutations, alterations and mutations of subdomains and then resolves them. | Informations gathering | ||
| DNS enumeration and network mapping tool suite: scraping, recursive brute forcing, crawling web archives, reverse DNS sweeping | OSINT and Reconnaissance | ||
| In-depth Attack Surface Mapping and Asset Discovery. | Informations gathering | ||
| Post-exploitation framework designed to assist with lateral movement within Active Directory. | Auth & perms | ||
| Software utility with a collection of forensic tools for smartphones; performs read-only, non-destructive acquisition | Digital Forensics | ||
| Android APK vulnerability analyzer | Code Analysis | ||
| Manage Burp Suite certificate in Android to redirect all traffic to Burp Suite. | Operating systems | ||
| Grants root privileges on the fly to shells running on Android virtual machines that use google-provided emulator images called Google API Playstore | System Exploitation | ||
| Fast and simple-to-use open-source/cross-platform network scanner. | Informations gathering | ||
| Statistical learning algorithm to create a model on the command lines of the Process Creation events on Windows, in order to detect anomalies in future events | Defensive | ||
| 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0 | AI Skills | ||
| Multi-AV checker that doesn't distribute the check results, based on Dyncheck.com | Red Teaming | ||
| Steganalysis web platform with layer, zsteg, steghide and exiftool analysis | Steganography | ||
| Tool for automating the search for IDOR vulnerabilities in web applications and APIs. | Vulnerabilities | ||
| Android decompiler (wrapper for apktool, dex2jar, and jd-gui) | Reverse Engineering | ||
| Android disassembler and rebuilder | Reverse Engineering | ||
| A tool for reverse engineering Android APK files. | Operating systems | ||
| eLearning management system for information security | Learning | ||
| A Tool for Domain Flyovers. | Auth & perms | ||
| Domain flyover tool; visual inspection of websites across a large amount of hosts and is convenient for quickly gaining an overview of HTTP-based attack surface | Web Application Exploitation | ||
| Web application security scanner framework | Web Application Exploitation | ||
| Web Application Security Scanner Framework. | Auth & perms | ||
| OSINT tool used for web crawling or examining JavaScript files for likely useful data. | Informations gathering | ||
| Vulnerability Assessment and Management tool, run scan and manage vulnerabilities | Collaboration and Report | ||
| Endpoint for Out-of-Band Exfiltration (DNS & HTTP) | Networking | ||
| Static analysis framework built in house to do security vetting for Android applications. | Operating systems | ||
| HTTP parameter discovery suite. | Informations gathering | ||
| HTTP parameter discovery suite | Web Application Exploitation | ||
| Just a quick inventory, reminder and launcher for pentest commands. | Auth & perms | ||
| Another Subdomain ENumeration Tool. | Cloud & services | ||
| Leverage ASN to look up IP addresses (IPv4 & IPv6) owned by a specific organization for reconnaissance purposes, then run port scanning on it | OSINT and Reconnaissance | ||
| Web pentest framework for information gathering and vulnerability scanning | Web Application Exploitation | ||
| Automated Security Testing For REST API's. | Vulnerabilities | ||
| REST API penetration testing tool | Web Application Exploitation | ||
| DNS asynchronous brute force utility. | Informations gathering | ||
| Arch Linux-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool! | Resources | ||
| Coverage-guided Python fuzzing engine | Fuzzing | ||
| Tool that suggests sqlmap tampers to bypass WAF/IDS/IPS based on status codes | Web Application Exploitation | ||
| Small and highly portable detection tests based on MITRE's ATT&CK. | Auth & perms | ||
| A library of tests mapped to the MITRE ATT&CK® framework used to quickly, portably, and reproducibly test their environments | Adversary Simulation | ||
| A platform built for productivity, collaboration and visibility. | Bug bounty | ||
| AttackForge helps you manage your penetration testing programs, and deliver large-scale pentesting services. Pentest Management and Reporting Made Easy, A Platform Built for Productivity, Collaboration and Visibility. | Collaboration and Report | ||
| AttackSurfaceMapper is a tool that aims to automate the reconnaissance process. | Informations gathering | ||
| Subdomain enumerator | OSINT and Reconnaissance | ||
| Distribution for pentesting IoT devices. | Operating systems | ||
| Tool to edit and analyze audio tracks | Steganography | ||
| The Burp extension helps you to find authorization bugs. | Vulnerabilities | ||
| Provides a simple way to test authorization in web applications and web services. | Auth & perms | ||
| Multi-threaded network reconnaissance tool which performs automated enumeration of services | OSINT and Reconnaissance | ||
| Multi-threaded network reconnaissance tool which performs automated enumeration of services. | Informations gathering | ||
| Automated HTTP request repeating with Burp Suite. | Well known products | ||
| Automated Mass Exploiter. | Cloud & services | ||
| Automatic authorization enforcement detection extension for Burp Suite. | Auth & perms | ||
| A one-stop pentesting checklist and logger tool. | Resources | ||
| Service to check if an account has been compromised in a data breach, send an email with the breaches not the password | OSINT and Reconnaissance | ||
| A comprehensive curated list of available Bug Bounty & disclosure programs and writeups. | Bug bounty | ||
| A curated list of bugbounty writeups (Bug type wise). | Bug bounty | ||
| List of awesome CobaltStrike resources. | Resources | ||
| 🔥🔒 Awesome MCP (Model Context Protocol) Security 🖥️ | AI MCP Servers | ||
| Dynamic infrastructure framework to distribute the workload of many different scanning tools with ease | Cloud | ||
| Lateral movement graph for Azure Active Directory. | Auth & perms | ||
| Gathers information about the Azure Active Directory and generates a report which can provide a holistic picture of the current state of the target environment | Cloud | ||
| A damn vulnerable Azure infrastructure. | Cloud & services | ||
| Toolkit to detect and keep track on Blind XSS, XXE & SSRF. | Vulnerabilities | ||
| Displays stats and graphs about your Bug Bounty activity. | Bug bounty | ||
| Aggregate reports/bounties from different platforms in order to create combined stats and graphs | Bug bounty | ||
| Bull's Eye Wordlist Generator, password wordlist generator based on target information | Cracking | ||
| Backup File Artifacts Checker; automated backup artifacts checker | Web Application Exploitation | ||
| Check for backup artifacts that may disclose the web-application's source code. | Informations gathering | ||
| Extract information from BloodHound and Neo4J | Other | ||
| A .NET Runtime for Cobalt Strike's Beacon Object Files | Red Teaming | ||
| Bloodhound Query Merger; deduplicate custom BloudHound queries from different datasets and merge them in one customqueries.json file | Other | ||
| Enumerating and attacking Java Remote Method Invocation services. | Development | ||
| Java RMI enumeration and attack tool | Web Application Exploitation | ||
| Generate wordlist based on the URLs to check for backup, installation, etc files. | Informations gathering | ||
| Bandit is a tool designed to find common security issues in Python code. | Code Analysis | ||
| Binary Analysis and Reverse engineering Framework | Reverse Engineering | ||
| The Browser Exploitation Framework is a penetration testing tool that focuses on the web browser. | Vulnerabilities | ||
| Multiplaform privilege escalation project. | Auth & perms | ||
| Static application security testing tool that helps discover, filter, and prioritize security risks and vulnerabilities | Code Analysis | ||
| HTTP request collector and inspector | Web Application Exploitation | ||
| OSINT tool, collect data and document actively or passively | OSINT and Reconnaissance | ||
| A backdoor with a multitude of features. | Auth & perms | ||
| Code Scanning/SAST/static analysis/linting using many tools/scanners with one report. | Informations gathering | ||
| Quickly find differences and similarities in disassembled code. | Auth & perms | ||
| Crossplatform binary analysis framework | Reverse Engineering | ||
| Injects custom XSS payloads on every form/request submitted to detect blind XSS. | Vulnerabilities | ||
| Reconnaissance Apparatus; Information gathering, conglomerate of tools including custom algorithms, API wrappers | OSINT and Reconnaissance | ||
| Web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website. | Informations gathering | ||
| Identify usage of pre-shared Machine Keys in a application for encryption and decryption. | Development | ||
| Login page bruteforcer: CSRF, SQLi, Clickjacking, WAF detection | Web Application Exploitation | ||
| Tool to reveal the hidden and unintended relationships within an Active Directory environment | System Exploitation | ||
| Six Degrees of Domain Admin. | Auth & perms | ||
| Pinpoint the security issues that actually matter. | Auth & perms | ||
| Helps blue teams pinpoint the security issues that actually matter by combining information about user permissions, network access and unpatched vulnerabilities, to reveal the paths attackers would take if they were inside the network | Defensive | ||
| Client-side vulnerability playground, CTF style application, a bot program which simulates the real-world victim | Intentionally Vulnerable Applications | ||
| Client/Server HTTP pivoting tool | Networking | ||
| Before Outset PaSsword CRacKing, password wordlist generator with exclusive features like lyrics based mode | Cracking | ||
| Stealth redirector for your red team operation security. | Network | ||
| Aggregate reports/bounties from different platforms in order to create combined stats and graphs, report and template management system, invoice creation system | Bug bounty | ||
| Dashboard to combine rewards from all platforms, giving insights about progress and bug hunting patterns | Bug bounty | ||
| Combine your rewards from platforms giving you insights about your bug hunting progress. | Bug bounty | ||
| Static analysis security vulnerability scanner for Ruby on Rails applications | Code Analysis | ||
| Service to check if an account has been compromised in a data breach, display the breaches, partial password and hash | OSINT and Reconnaissance | ||
| A framework including all the tools that work on Windows. | Virtualization | ||
| Command & Control server; DNS over HTTPS, external channels, indirect syscalls | Red Teaming | ||
| Network forensic analysis tool that performs deep processing and inspection of network traffic. | Auth & perms | ||
| Takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa | Networking | ||
| Tool using nmap and hydra to automatically bruteforce network service accounts | Networking | ||
| Automatically brute force all services running on a target. | Informations gathering | ||
| Tool written in Python simply to find XSS vulnerabilities in web application. | Vulnerabilities | ||
| Bluetooth Low Energy Swiss-army knife | Wireless | ||
| Find interesting Amazon S3 Buckets by watching certificate transparency logs. | Cloud & services | ||
| An automated S3-compatible bucket inspector. | Cloud & services | ||
| Launchpad for bug bounty programs and bug bounty hunters. | Auth & perms | ||
| A list of Bug Bounty writeups that is categorized by the bug nature. | Bug bounty | ||
| Bug Bounty Reports Explained channel. | Resources | ||
| Adversarial AI bug hunter with auto-fix skill for Claude Code, Cursor, Codex CLI, GitHub Copilot CLI, Kiro CLI, Opencode, Pi Coding Agent, and more. Multi-agent pipeline finds security vulnerabilities, logic errors, and runtime bugs — then fixes them autonomously on a safe branch. | AI Skills | ||
| App that helps bug bounty hunters to manage their bounties and target list | Bug bounty | ||
| Helping you become a BugBountyHunter. | Resources | ||
| Search Bug Bounty writeups easily. | Bug bounty | ||
| A Bash script and Docker image for Bug Bounty reconnaissance, intended for headless use. | Virtualization | ||
| Automated firmware analysis tool for composition analysis and vulnerability scanning. | Operating systems | ||
| Autonomous AI-powered security scanner — multi-agent vulnerability detection, exploitation, and validation engine | Artificial Intelligence | ||
| Terminal dashboard for bug bounty hunters that use HackerOne and Bugcrowd | Bug bounty | ||
| Bugcrowd’s baseline priority ratings for common security vulnerabilities. | Bug bounty | ||
| Find out what websites are Built With. | Informations gathering | ||
| Collaborative penetration test, vulnerability database and reporting platform | Collaboration and Report | ||
| Burp Extender API. | Development | ||
| Burp extension to decode NTLM SSP headers and extract domain/host information. | Auth & perms | ||
| The class-leading vulnerability scanning, penetration testing, and web app security platform. | Network | ||
| Intercepting proxy to replay, inject, scan and fuzz HTTP requests (a limited free version exists) | Web Application Exploitation | ||
| Find known vulnerabilities in WordPress plugins and themes, WPScan like plugin for Burp. | CMS | ||
| Performs passive scan to identify buckets and test them for publicly accessible vulnerabilities. | Cloud & services | ||
| Burp Suite extension to encode an IP address focused to bypass application IP/domain blacklist. | Cryptanalysis | ||
| Generates wordlists from the Burp sitemap. | Resources | ||
| Performing SQLInjection test on Burp Suite Bulk Requests using SQLMap. | Well known products | ||
| Burpsuite extension for beautifying request/response body. | Development | ||
| Improve the active and passive Burp Suite scanner by means of custom rules through GUI. | Well known products | ||
| Scan Check Builder in BApp Store, improve the active and passive scanner by means of personalized rules through a graphical interface | Plugins | ||
| A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan. | Well known products | ||
| Burp Extension for a passive scanning JS files for endpoint links. | Development | ||
| GUI Burp Plugin to ease discovering of security holes in web applications. | Vulnerabilities | ||
| A Burp Suite content discovery plugin that add the smart into the Buster. | Informations gathering | ||
| A Burp Suite extension to bypass WAFs or test their effectiveness using a number of techniques. | Vulnerabilities | ||
| Intentionally-vulnerable Kubernetes cluster, intended to help people self-train on attacking and defending Kubernetes clusters | Intentionally Vulnerable Applications | ||
| Tool that tests MANY url bypasses to reach a 40X protected page. | Auth & perms | ||
| A simple script just made for self use for bypassing 403. | Auth & perms | ||
| Malware sandbox derived from Cuckoo with the goal of adding automated malware unpacking, config and payload extraction | Reverse Engineering | ||
| Make security testing of K8s, Docker, and Containerd easier. | Virtualization | ||
| Create a copy of a targeted website with CDN and WAF restrictions disabled. | Cloud & services | ||
| PE Editor | Reverse Engineering | ||
| Asses systems against CIS Benchmarks | Configuration Audit | ||
| Asses systems against CIS Benchmarks | Configuration Audit | ||
| A project for fuzzing HTTP/1.1 CL.0 Request Smuggling attack vectors. | Network | ||
| Scan Wordpress, Drupal, Joomla, vBulletin websites for security issues. | CMS | ||
| Wordpress, Drupal, Joomla, vBulletin CMS security scanner with dashboard | Web Application Exploitation | ||
| CMS Detection and Exploitation suite that supports over 180 other CMSs. | CMS | ||
| CMS detection and exploitation suite; capable of detecting more than 180 CMS | Web Application Exploitation | ||
| CMS scanner that automates the process of detecting security flaws of the most popular CMSs. | CMS | ||
| WordPress, Joomla, Drupal, Moodle CMS security scanner | Web Application Exploitation | ||
| A multi-threaded scanner that helps identify CORS flaws/misconfigurations. | Vulnerabilities | ||
| A simple CORS misconfiguration scanner. | Vulnerabilities | ||
| Command line tool for testing CRLF injection on a list of domains. | Vulnerabilities | ||
| CRLFMap is a tool to find HTTP Splitting vulnerabilities. | Vulnerabilities | ||
| The most powerful CRLF injection scanner. | Vulnerabilities | ||
| A fast tool to scan CRLF vulnerability written in Go. | Auth & perms | ||
| A fun, free platform for learning modern cryptography. | Resources | ||
| Large-scale firmware analysis of cryptographic misuse in IoT devices; supports ARM, MIPS, MIPSel architetures | Cryptography | ||
| Check CSP serves as a strong mitigation against cross-site scripting attacks. | Vulnerabilities | ||
| Check Content Security Policy (CSP) configuration and assists with the reviewing process | Web Application Exploitation | ||
| Test for CSP bypass payloads | Web Application Exploitation | ||
| A lightweight CSRF Toolkit for easy Proof of Concept. | Vulnerabilities | ||
| Cobalt Strike Shellcode Generator; script used to more easily generate and format beacon shellcode in Cobalt Strike | Red Teaming | ||
| Cyber Security Transformation Chef; chaining simple operations and formatting on each incoming or outgoing HTTP message | Plugins | ||
| Cross-Site WebSocket Hijacking Tester | Web Application Exploitation | ||
| Collaborative platform for CTF teams, event planning, credentials sharing, tasks management, notes taking | Collaboration and Report | ||
| Abusing Certificate Transparency logs for getting HTTPS websites subdomains. | Informations gathering | ||
| A Capture The Flag framework focusing on ease of use and customizability. | Resources | ||
| Common User Passwords Profiler, wordlist generator based on user profiling | Cracking | ||
| Common User Passwords Profiler. | Informations gathering | ||
| A hub for finding CVEs and exploits based on the official NIST, ExploitDB and Github databases. | Auth & perms | ||
| CLI tool designed to provide a structured interface to various vulnerability databases | Vulnerability Assessment | ||
| Navigate the CVE jungle with ease using CLI tool designed to provide a structured interface. | Auth & perms | ||
| Intercepting proxy to replay, inject, scan and fuzz HTTP requests (a limited free version exists) | Web Application Exploitation | ||
| Password recovery tool for Microsoft Operating Systems. | Network | ||
| Cutting-edge project designed to automate the continuous discovery of vulnerabilities in webapps. | Development | ||
| Cyber security platform designed to easily automate adversary emulation, assist manual red-teams, and automate incident response | Adversary Simulation | ||
| Automated adversary emulation platform. | Auth & perms | ||
| RTSP stream access; detect open hosts, device model, automated dictionary attacks on stream route and credentials | Reconnaissance | ||
| A list of DNS providers and how to claim (sub)domains via missing hosted zones. | Informations gathering | ||
| A list of services and how to claim (sub)domains with dangling DNS records. | Informations gathering | ||
| Quickly deployable honeypot with docker image, the online service allows to get alerted by email for URL token, DNS token, unique email address, custom image, MS word doc., Acrobat Reader PDF doc., and more | Honeypot and Decoy | ||
| Track activity and actions on your network. | Network | ||
| Penetration test platform: vulnerability database and reporting | Collaboration and Report | ||
| Web directory and file scanner (wordlist bruteforce) | Web Application Exploitation | ||
| Assessment tool that allows penetration testing and hostile attack simulations. | Auth & perms | ||
| PCAP analyzer | Networking | ||
| Create a spoofed certificate of any online website and signs an executable for AV Evasion; works for Windows and Linux | Red Teaming | ||
| Creates a spoofed certificate of any online website and signs an executable for AV evasion. | Informations gathering | ||
| Assessment of on-premises Microsoft servers such as ADFS, Skype, Exchange, and RDWeb | Networking | ||
| Custom Word List Generator. | Informations gathering | ||
| CeWL is a Custom Word List Generator | Cracking | ||
| Custom word list generator redefined, based on the Scrapy framework. | Resources | ||
| Extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys. | Informations gathering | ||
| Perform subdomain enumeration using the certificate transparency logs from Censys. | Informations gathering | ||
| File analyzer and inspector | Digital Forensics | ||
| Unstrip Rust and Go binaries (ELF and PE) for static analysis; based on hashing and scoring systems, it can retrieve lots of symbol names | Reverse Engineering | ||
| Network services credentials brute-forcer: SSH, FTP | Networking | ||
| Uses data from SSL Certificates to find potential host names. | Cloud & services | ||
| A .NET tool for exporting and importing certificates without touching disk. | Cryptanalysis | ||
| A CLI tool to extract server certificates. | Informations gathering | ||
| Get informations about SSL certificates. | Informations gathering | ||
| Active Directory certificate abuse. | Auth & perms | ||
| Active Directory Certificate Services enumeration and abuse. | Auth & perms | ||
| Active Directory Certificate Services enumeration and exploitation | Networking | ||
| Intelligence feed that gives real-time updates from the Certificate Transparency Log network | OSINT and Reconnaissance | ||
| Cervantes is an open-source, collaborative platform designed specifically for pentesters and red teams. It serves as a comprehensive management tool, streamlining the organization of projects, clients, vulnerabilities, and reports in a single, centralized location. | Collaboration and Report | ||
| Tool to bypass disable_functions and open_basedir in PHP by calling sendmail and setting LD_PRELOAD environment variable | Web Application Exploitation | ||
| Collect and maintain internet-wide assets data for public Bug Bounty programs. | Informations gathering | ||
| HTTP proxy / monitor / reverse proxy that allows to view all of the HTTP(S) traffic. | Network | ||
| Intercepting proxy to replay, inject, scan and fuzz HTTP requests | Web Application Exploitation | ||
| Obfuscation script designed to bypass AMSI and commercial antivirus solution. | Cryptanalysis | ||
| Toolchain for side-channel power analysis and glitching attacks | Hardware | ||
| Web application security scanner based on templates | Web Application Exploitation | ||
| Scan endpoints and identify exposition of sensitive services/files/folders. | Informations gathering | ||
| A searchable directory of TLS ciphersuites and related security details | Cryptography | ||
| Automates decryptions & decodings with encodings, classical ciphers, hashes, or more. | Cryptanalysis | ||
| Android and Java bytecode viewer. | Development | ||
| Uncover the true IP address of websites safeguarded by Cloudflare & others. | Cloud & services | ||
| Awesome cloud enumerator. | Cloud & services | ||
| Utilize misconfigured DNS and old database records to find hidden IPs behind CloudFlare network. | Cloud & services | ||
| Find origin servers of websites behind Cloudflare by using Internet-wide scan data from Censys. | Cloud & services | ||
| Scanner to identify misconfigured CloudFront domains | Web Application Exploitation | ||
| A tool for identifying misconfigured CloudFront domains. | Cloud & services | ||
| Vulnerability scanner for AWS customer managed policies using ChatGPT | Cloud | ||
| Vulnerable by design AWS deployment tool. | Cloud & services | ||
| Route53/CloudFront Vulnerability assessment utility. | Cloud & services | ||
| CloudMapper helps you analyze your Amazon Web Services environments. | Cloud & services | ||
| Analyze AWS environments auditing for security issues | Cloud | ||
| Finding assets and subdomains from certificates! Scan the web! | Informations gathering | ||
| Tool to enumerate targets in search of cloud resources. | Cloud & services | ||
| PCAP analyzer | Networking | ||
| Find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies | Cloud | ||
| Automating situational awareness for cloud penetration tests. | Cloud & services | ||
| Automatic code static analysis tool to detect bugs and vulnerabilities | Code Analysis | ||
| Semantic code analysis engine; discover vulnerabilities across a codebase, lets you query code as though it were data, write a query to find all variants of a vulnerability | Code Analysis | ||
| An application curated to crisis zones to facilitate the dissemination of accurate mission-critical information from sources on the ground to key partners with minimal lag time | Crisis Management | ||
| A Windows potato to privesc. | Auth & perms | ||
| Coerce a Windows server to authenticate on an arbitrary machine through 12 methods | Networking | ||
| Automatically coerce a Windows server to authenticate on an arbitrary machine. | Bug bounty | ||
| Supports Java developers in using Java Cryptographic APIs | Plugins | ||
| Burp Suite extension which injects non-invasive headers to reveal backend systems. | Development | ||
| Company Passwords Profiler helps making a bruteforce wordlist for a targeted company | Cracking | ||
| Fully customizable Windows-based pentesting virtual machine distribution. | Operating systems | ||
| Automated All-in-One OS Command Injection Exploitation Tool. | Vulnerabilities | ||
| OSINT tool to find usernames across 80+ social media and social networking sites. | Informations gathering | ||
| Password spraying in Active Directory checking the default domain password policy as well as PSO and the badpwdcount LDAP attribute to avoid account locking | Networking | ||
| An open-source, free protector for .NET applications. | Development | ||
| Protector for .NET applications | Red Teaming | ||
| Convert BloodHound output files into nmap XML that can be imported into reporting software like Dradis and Plextrac | Other | ||
| Read local Chrome cookies without root or decrypting and display then in JSON; Javascript implementation of cookie_crimes | System Exploitation | ||
| Copies the selected request(s) as FFUF skeleton | Plugins | ||
| Copies the selected request(s) as Go Request invocations | Plugins | ||
| Copies selected request(s) as Python-Requests invocations | Plugins | ||
| Copies selected request(s) as JavaScript XMLHttpRequest invocations | Plugins | ||
| Copies the selected request(s) as Node.JS Request invocations | Plugins | ||
| Copies the selected request(s) as PowerShell invocation(s) | Plugins | ||
| Designed to enable security teams to conduct advanced penetration tests with ease. | Bug bounty | ||
| CORS misconfiguration scanner tool with speed and precision in mind! | Vulnerabilities | ||
| CORS Misconfiguration Scanner. | Vulnerabilities | ||
| Parse the Database Lock Files of the Cortex XDR Agent by Palo Alto Networks and extract Agent Settings, the Hash and Salt of the Uninstall Password, as well as possible Exclusions | Red Teaming | ||
| Collaborative C2 framework for red teamers. | Cloud & services | ||
| Command & Control framework with multi-user collaboration | Red Teaming | ||
| Know the dangers of credential reuse attacks. | Informations gathering | ||
| A swiss army knife for pentesting networks. | Auth & perms | ||
| Post-exploitation tool to assess Active Directory networks | Networking | ||
| Hashcat cracking queue system, API and WebUI | Cracking | ||
| GraphQL password brute-force and fuzzing utility | Web Application Exploitation | ||
| Pre-computed lookup tables to crack password hashes | Cracking | ||
| Password wordlist generator, Smartlist creation and password hybrid-mask | Cracking | ||
| Hashcat WebUI; session management, mask generation, API, notifications, local and LDAP authentication | Cracking | ||
| Scalable, pluggable, and distributed system for hash cracking, supports Hashcat | Cracking | ||
| A powerful browser crawler for web vulnerability scanners | Auth & perms | ||
| Password spraying, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling | Red Teaming | ||
| CRLF bug scanner for WebPentesters and Bugbounty Hunters. | Vulnerabilities | ||
| PortSwigger XSS cheat sheet that contains many vectors that can help you bypass WAFs and filters. | Vulnerabilities | ||
| Generate CobaltStrike's cross-platform payload. | Auth & perms | ||
| LinkedIn enumeration tool to get employee names from an organization using scraping. | Cloud & services | ||
| Wordlist generator and Wi-Fi cracker | Wireless | ||
| Program analysis tool to find cryptographic misuse in Java and Android | Cryptography | ||
| Library consisting of explanation and implementation of all the existing attacks on various Encryption Systems, Digital Signatures, Hashing Algorithms along with example challenges from CTFs | Cryptography | ||
| Identify misuse of cryptographic libraries by collecting and analysing logs | Cryptography | ||
| The most advance set of Content Security Policy tools. | Vulnerabilities | ||
| Python 3 port of Cuckoo, automated malware analysis system | Reverse Engineering | ||
| An automated dynamic malware analysis system. | Informations gathering | ||
| Qt and C++ GUI for radare2 | Reverse Engineering | ||
| A web app for encryption, encoding, compression and data analysis. | Cryptanalysis | ||
| Data manipulation toolkit in web browser | Other | ||
| Test your knowledge on cyber security and practice for industry recognised certifications. | Resources | ||
| Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team. | Artificial Intelligence | ||
| Cygeniq is an end-to-end AI security, governance, and compliance platform designed to protect artificial intelligence systems from emerging threats, operational risks, and regulatory challenges. As AI becomes central to enterprise decision-making, organizations face new and evolving risks such as prompt injection, data poisoning, model theft, adversarial manipulation, and non-compliance with AI regulations. Cygeniq addresses these challenges by securing AI systems across their full lifecycle, from development and testing to deployment, monitoring, and governance. Cygeniq’s platform is powered by three integrated solutions: Hexashield AI – Advanced AI Security & Protection Hexashield AI protects AI models and applications against modern attack vectors including prompt injection, data poisoning, adversarial threats, and model exploitation. It provides continuous monitoring, vulnerability detection, and runtime protection to ensure AI systems remain resilient and trustworthy. GRCortex AI – AI Governance, Risk & Compliance (AI GRC) GRCortex AI enables organizations to manage AI risk, enforce governance frameworks, and maintain compliance with evolving global AI regulations. It provides visibility into AI usage, risk assessments, policy enforcement, audit readiness, and regulatory alignment, ensuring responsible and compliant AI adoption. CyberTiX AI – Intelligent Threat Intelligence & Risk Insights CyberTiX AI delivers actionable intelligence and risk insights tailored to AI ecosystems. It helps security teams proactively identify vulnerabilities, assess emerging AI-related threats, and strengthen defensive posture across AI-driven environments. Together, these solutions provide unified visibility, control, and protection across the AI lifecycle. Cygeniq integrates seamlessly with modern AI stacks, cloud environments, and enterprise systems, allowing organizations to deploy and scale AI securely without disrupting innovation. Built for enterprises, regulated industries, and AI-first organizations, Cygeniq ensures that AI systems remain secure, compliant, and resilient in an increasingly complex digital and regulatory landscape. | Red Teaming | ||
| PowerShell Cmdlets to interact with BloodHound Data via Neo4j HTTP API. | Auth & perms | ||
| Automate pentest reporting & project management, generate content with AI, improve client retention, and organize your pentest workload. | Collaboration and Report | ||
| An advanced tool for persistence in Linux. | Operating systems | ||
| Windows project to empower incident response, digital forensics, malware analysis, and network defense with HashiCorp Packer and Vagrant | Defensive | ||
| Documentation And Reporting Tool; Collaborative penetration test and vulnerability database platform | Collaboration and Report | ||
| Spot all domain controllers in a Microsoft Active Directory environment, find computer name, FQDN, and IP address(es) of all DCs | Networking | ||
| Script that is able to enumerate the possible vulnerable DCOM applications that might allow for lateral movement, code execution, data exfiltration, etc. | System Exploitation | ||
| The world’s most prominent and well-known computer security conferences. | Resources | ||
| Forensics artefact collection tool for systems running Microsoft Windows | Incident Response | ||
| Incident response tracking web application, focused on handling one major incident with a lot of affected systems | Incident Response | ||
| Dll injection tool | System Exploitation | ||
| Password filter DLL, triggered on password change to exfiltrate credentials | System Exploitation | ||
| Toolkit to test further DNS rebinding attacks | Networking | ||
| A DNS bruteforcing wordlist generator. | Informations gathering | ||
| Domain research tool that can discover hosts related to a domain | OSINT and Reconnaissance | ||
| Data exfiltration over DNS request covert channel. | Informations gathering | ||
| Domain name permutation engine written in Go. | Informations gathering | ||
| Allows you to perform multiple dns queries of your choice with a list of user supplied resolvers. | Informations gathering | ||
| DNS reconnaissance tool: AXFR, DNS records enumeration, TLD expansion, wildcard resolution, subdomain bruteforce, PTR record lookup, check for cached records | OSINT and Reconnaissance | ||
| DNS Enumeration Script. | Informations gathering | ||
| A fast tool to check missing hosted DNS zones that can lead to subdomain takeover. | Informations gathering | ||
| Trace the path of a DNS query. | Informations gathering | ||
| DNS traffic sniffer and analyzer. | Informations gathering | ||
| A tool to scan source code for DOM based XSS vulnerabilities. | Vulnerabilities | ||
| Chrome extension that finds DOM based XSS vulnerabilities. | Vulnerabilities | ||
| DOM XSS scanner for Single Page Applications. | Vulnerabilities | ||
| A DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. | Development | ||
| Automated black-box hypervisor-level malware analysis system | Reverse Engineering | ||
| DS_Store file parser/viewer. | Operating systems | ||
| List DTDs and generate XXE payloads using those local DTDs. | Vulnerabilities | ||
| Damn vulnerable cloud application. | Cloud & services | ||
| Dump web accessible (distributed) version control systems (DVCS/VCS): GIT, Mercurial/hg, Bazaar/bzr, … | Web Application Exploitation | ||
| Damn Vulnerable GraphQL Application, insecure webapp for GraphQL security trainings | Intentionally Vulnerable Applications | ||
| Damn Vulnerable iOS App, insecure webapp for mobile security trainings | Intentionally Vulnerable Applications | ||
| The Damn Vulnerable Router Firmware project. | Network | ||
| Damn Vulnerable Web Application, insecure webapp for security trainings | Intentionally Vulnerable Applications | ||
| Damn Vulnerable Web Application. | Vulnerabilities | ||
| Vulnerable application with a web service and an API. | Development | ||
| Helps to bypass antiviruses by providing an encryption wrapper and loader for your shellcode. | Cryptanalysis | ||
| Powerful open source XSS scanning tool and parameter analyzer. | Vulnerabilities | ||
| XSS scanner and utility focused on automation | Web Application Exploitation | ||
| A vulnerable Android application with an interface to test your mobile hacking skills. | Operating systems | ||
| An intentionally vulnerable web API game for learning and training purposes. | Resources | ||
| A Burp Suite extension for finding the use of potentially dangerous methods/functions. | Development | ||
| Lightshot scraper with multi-threaded OCR and auto categorizing screenshots | OSINT and Reconnaissance | ||
| Runs a scan using Dastardly by Burp Suite against a target site and generates a report. | Bug bounty | ||
| A Burp Suite extension to extract data from source code while browsing. | Informations gathering | ||
| Sstatic analysis security scanner for ruby written web applications; supports Sinatra, Padrino and Ruby on Rails frameworks | Code Analysis | ||
| Front-end for the Windows debugger engine | Reverse Engineering | ||
| Code and decode all kind of checksums, algorithms, codes or ciphers | Cryptography | ||
| toolkit for python reverse engineering. | Informations gathering | ||
| DeHashed provides free deep-web scans and protection against credential leaks. | Cryptanalysis | ||
| Service to check if an account has been compromised in a data breach | Other | ||
| Track down footprints of a phone number | OSINT and Reconnaissance | ||
| Multi-decompiler engine; supports angr, BinaryNinja, Boomerang, dewolf, Ghidra, Hex-Rays, RecStudio, Reko, Relyze, RetDec, Snowman | Reverse Engineering | ||
| C#, Python, Android and Java online decompiler | Reverse Engineering | ||
| Free, accessible, and platform-independent decompilation service. | Informations gathering | ||
| Secrets scanner that understands code. | Informations gathering | ||
| One place for all the default credentials to assist on finding devices with default password. | Informations gathering | ||
| Default passwords database sorted by manufacturers. | Informations gathering | ||
| Vulnerability management application built for DevOps and continuous security integration | Collaboration and Report | ||
| Online x86 (32/64 bits) assembler and disassembler | Reverse Engineering | ||
| Deception framework which can be used to deploy decoys across the infrastructure | Honeypot and Decoy | ||
| HTA encryption tool for Red Teams. | Cryptanalysis | ||
| Management tool for the information security management system (ISMS); manage, plan, track and report the effectiveness of security controls | Defensive | ||
| Utility that detects publicly disclosed vulnerabilities in application dependencies. | Bug bounty | ||
| Recovers passwords from pixelized screenshots. | Cryptanalysis | ||
| Android reverse engineering platform focus on instrumentation automation (decompile/disass intercepted bytecode at runtime, write hook code, search interesting pattern | Reverse Engineering | ||
| Multi threaded application to brute force directories and files names on web/application servers. | Informations gathering | ||
| A Go implementation of dirsearch. | Informations gathering | ||
| Web Fuzzer. | Informations gathering | ||
| Multi threaded application designed to brute force paths on web servers. | Informations gathering | ||
| Asset discovery and identification tool. | Informations gathering | ||
| All of the ad-hoc things you're doing to manage incidents today, done for you, and much more!. | Cloud & services | ||
| Evenly distributes scanner load across targets. | Well known products | ||
| Divide full port scan results and use it for targeted Nmap runs. | Informations gathering | ||
| Create DNS request collector and inspector | Networking | ||
| Link a domain with registered organisation names and emails, to other domains. | Informations gathering | ||
| Analyze the security of any domain by finding all the information possible. Made in python. | Informations gathering | ||
| Checks expired domains to determine good candidates for phishing and C2 domain names. | Informations gathering | ||
| Domain reconnaissance for organizational network scanning | OSINT and Reconnaissance | ||
| Script that makes active and/or passive scan to obtain subdomains and search for open ports. | Informations gathering | ||
| Dumping DPAPI credentials remotely; dumps relevant information on compromised targets without AV detection | System Exploitation | ||
| Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files. | Development | ||
| Generates x86_32, x86_64, or AMD64 position-independent shellcode that loads .NET Assemblies, PE files (EXE), VBScript, JScript, and DLL files from memory and runs them with parameters | Red Teaming | ||
| Advanced Google searches using dorks to locate specific files on the internet. | Cloud & services | ||
| Generate Google dorks with AI. | Cloud & services | ||
| Directory Traversal fuzzer | Web Application Exploitation | ||
| The Directory Traversal Fuzzer. | Vulnerabilities | ||
| An extension for checking if .git is exposed in visited websites. | Source code management | ||
| Web browser extension (Firefox and CHromium) checking if .git is exposed in visited websites | Web Application Exploitation | ||
| Headless browser in order to load pages and execute JavaScript that often generates things like dynamic nonces that validate the page was actually rendered by a human for password spraying | Other | ||
| Collaboration and reporting for infosec teams made simple. | Bug bounty | ||
| Dradis is an open-source reporting and collaboration tool trusted by 1,000s of InfoSec professionals around the world. | Collaboration and Report | ||
| Collaborative penetration test, vulnerability database and reporting platform; Pro edition | Collaboration and Report | ||
| Evasive shellcode loader for bypassing injection detection. | Operating systems | ||
| Different versions of the DroidGuard VM as well as different version of the bytecode running through this VM | Reverse Engineering | ||
| Android apps/malware analysis/reversing tool | Reverse Engineering | ||
| Drone pentesting framework console. | Operating systems | ||
| Drupal enumeration & exploitation tool. | CMS | ||
| A network forensic analysis framework. | Auth & perms | ||
| LSASS memory dumper using direct system calls and API unhooking. | Auth & perms | ||
| Tool to search secrets in various filetypes. | Cloud & services | ||
| Remove duplicates from massive wordlist, without sorting it (for dictionary-based password cracking) | Cracking | ||
| Targeted attacks against WPA2-Enterprise networks, wireless pivots using hostile portal attacks. | Network | ||
| Ultimate domain enumeration tool. | Informations gathering | ||
| Uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server | Red Teaming | ||
| The security analyzer for firmware of embedded devices. | Operating systems | ||
| Security analyzer for firmware of embedded devices | Reverse Engineering | ||
| Analyze EML files: headers, bodies, attachments; extract IOCs; identify suspicious attachments | Digital Forensics | ||
| Vulnerability scanner for mass detection of web-based applications vulnerabilities. | Auth & perms | ||
| Image recognition on instagram, facebook and twitter | OSINT and Reconnaissance | ||
| Stalk your friends on social media using image recognition and reverse image search. | Cloud & services | ||
| Sensitive data detection tool capable of scanning source code repositories. | Informations gathering | ||
| Collaborative penetration test platform; terminal sharing, target information extraction, command suggestion, exploit searching, chatting, graph visualization | Collaboration and Report | ||
| Post-exploitation and adversary emulation framework that is used to aid Red Teams and pentesters. | Auth & perms | ||
| PowerShell and Python post-exploitation agent | System Exploitation | ||
| GUI for Empire framework | System Exploitation | ||
| An extension that auto extracts URLs from the current webpage and JS files. | Well known products | ||
| Loots information from a Symfony target using profiler | Web Application Exploitation | ||
| Crisis management platform | Crisis Management | ||
| Your performance & security consultant, an artisan command away. | Development | ||
| The extension is based on the BurpSSO Extension, developed by the Chair of Network and Data Security, Ruhr University Bochum and the Hackmanit GmbH. The extension is part of a bachelor thesis by Tim Guenther at the Ruhr-University Bochum in cooperation with Context Information Security Ltd.. | Web Application Exploitation | ||
| Domain information gathering: whois, history, dns records, web technologies, records | OSINT and Reconnaissance | ||
| Free and open source network security tool for man-in-the-middle attacks on a LAN. | Network | ||
| Interactive .NET SQL console client with enhanced SQL Server discovery/access/exfiltration features. | Databases | ||
| Enhanced WinRM shell | Networking | ||
| Create malicious MS Office documents to hide VBA macros, stomp VBA code. | Informations gathering | ||
| Standalone MITM attack framework allowing for the bypass of 2-factor authentication. | Auth & perms | ||
| Library and CLI tool to read and write meta information (EXIF, GPS, IPTC, XMP, JFIF, …) in files (JPEG, PNG, SVG, MPEG, …) | Steganography | ||
| ExifTool meta information reader/writer. | Informations gathering | ||
| Library and CLI tool for reading, writing and editing metadata for a lot of file types | Digital Forensics | ||
| Library and CLI tool to read and write meta information (Exif, IPTC & XMP metadata and ICC Profile) in images (JPEG, TIFF, PNG, …) | Steganography | ||
| Exploits found on the INTERNET. | Auth & perms | ||
| Copies selected request(s) as cURL, wget, Python Request, Perl LWP, PHP HTTP_Request2, Go, NodeJS Request, jQuery AJAX, PowerShell, HTML Forms, Ruby Net::HTTP, JavaScript XHR invocations | Plugins | ||
| Smart SSRF scanner using different methods like parameter brute forcing in POST and GET. | Vulnerabilities | ||
| Scans for different types of XSS on a list of urls. | Vulnerabilities | ||
| Designed to enumerate and gain access to IP cameras via RTSP. | Operating systems | ||
| Take screenshots of websites, provide some server header info, and identify default credentials if possible | Web Application Exploitation | ||
| Take screenshots of websites, provide server header info and identify default credentials. | Informations gathering | ||
| Convolutional neural network for analyzing pentest screenshots. | Informations gathering | ||
| Convolutional neural network for analyzing pentest screenshots and automatically label them | Web Application Exploitation | ||
| Service to check if an account has been compromised in a data breach, send an email with the breaches not the password | Other | ||
| File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool. | Vulnerabilities | ||
| Freedom Fighting Mode (FFM), hacking harness, post-exploitation tool | System Exploitation | ||
| OSINT framework and metadata analyser | OSINT and Reconnaissance | ||
| Tool to find metadata and hidden information in the documents. | Informations gathering | ||
| Investigate electronic devices; full disk imaging capabilities: preview and image hard drives from Windows and Linux computers, CDs, DVDs, thumb drives, and other USB; forensic image mounting: mount an image for a read-only view that leverages file explorer; preview data; RAM capture | Digital Forensics | ||
| OSINT tool, facebook profile dumper, windows and chrome only | OSINT and Reconnaissance | ||
| Use a Fake image.jpg to exploit targets (hide known file extensions). | Auth & perms | ||
| Plug BloodHound with a SIEM or other log aggregation | Defensive | ||
| Collaborative penetration test and reporting platform | Collaboration and Report | ||
| Open source sulnerability management and orchestration platform. | Auth & perms | ||
| Site fast fuzzing with chorme extension. | Auth & perms | ||
| Favicon fingerprinting using Shodan | Web Application Exploitation | ||
| Favicon fingerprinting | Web Application Exploitation | ||
| Making favicon.ico based recon great again. | Informations gathering | ||
| Favicon fingerprinting | Web Application Exploitation | ||
| Cryptanalysis tool and library | Cryptography | ||
| Automated blind-xss search for Burp Suite. | Vulnerabilities | ||
| IOC scanner | Incident Response | ||
| A fast, simple, recursive content discovery tool written in Rust. | Informations gathering | ||
| The powered S3 bucket finder and content discover. | Cloud & services | ||
| Tool for exploration and tracing of the Windows kernel | Digital Forensics | ||
| Web debugging proxy for MacOS, Windows, and Linux. | Network | ||
| A DNS reconnaissance tool for locating non-contiguous IP space. | Informations gathering | ||
| Full-fledged phishing framework to manage all phishing engagements. | Informations gathering | ||
| An extremely fast and flexible web fuzzer. | Informations gathering | ||
| A fast DOM based XSS vulnerability scanner with simplicity. | Vulnerabilities | ||
| All In One Web Recon. | Informations gathering | ||
| Web reconnaissance script | OSINT and Reconnaissance | ||
| Quickly find uncommon shares in vast Windows domains. | Auth & perms | ||
| Fast subdomain enumerator | OSINT and Reconnaissance | ||
| The complete solution for domain recognition. | Informations gathering | ||
| Find exploits in local and online databases instantly. | Auth & perms | ||
| CMS version detection tool | Web Application Exploitation | ||
| CMS/LMS/Library etc Versions Fingerprinter. | CMS | ||
| The ultimate Vulnerability Disclosure Policy and Bug Bounty list! | Bug bounty | ||
| Realtime map that integrates Firebase, Google Maps and Shodan. | Informations gathering | ||
| A tool written in python for scraping firebase data. | Cloud & services | ||
| Black box fuzzer for web applications. | Resources | ||
| Web directory and file scanner (wordlist bruteforce); but also a web fuzzer | Web Application Exploitation | ||
| Service to check if an account has been compromised in a data breach, display the breaches not the password | Other | ||
| Hashcat-based distributed password cracking system with WebUI | Cracking | ||
| Processes SWF and extract scripts from it | Reverse Engineering | ||
| A script that let you encode and decode a Flask session cookie | Web Application Exploitation | ||
| Disassembler tool for SWF bytecode | Reverse Engineering | ||
| Automatically extract obfuscated strings from malware. | Cryptanalysis | ||
| Provides view with filtering capabilities for all requests from all Burp Suite tools. | Well known products | ||
| A Burp Suite extension that brings taint analysis to web applications, by tracking all parameters. | Informations gathering | ||
| Explore, analyze, and gain valuable data & insights from reverse engineered Flutter apps | Reverse Engineering | ||
| Fluxion is the future of MITM WPA attacks. | Network | ||
| MITM WPA attack tool | Wireless | ||
| Test Cache Poisoning | Web Application Exploitation | ||
| CLI tool to recover files based on their headers, footers, and internal data structures | Digital Forensics | ||
| DFIR automation for collecting and analyzing evidence | Digital Forensics | ||
| A Burp Suite extension to aid in detecting and exploiting serialisation libraries/APIs. | Development | ||
| A curated list of free courses & certifications. | Resources | ||
| Payload creation tool used for circumventing EDR security controls to execute shellcode in a stealthy manner | Red Teaming | ||
| Payload toolkit for bypassing EDRs using suspended processes, direct syscalls written. | Auth & perms | ||
| List of fresh DNS resolvers updated every 12h. | Informations gathering | ||
| Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers. | Informations gathering | ||
| Dynamic code instrumentation toolkit | Reverse Engineering | ||
| Android application tracer powered by Frida. | Operating systems | ||
| Wireless network auditing tool controlled by a web interface | Wireless | ||
| Wireless network auditing tool. | Network | ||
| Penetration testing platform, automate some scan & attack | Web Application Exploitation | ||
| Attack patterns and primitives for black-box application fault injection and resource discovery. | Resources | ||
| Web-UI for API-fuzzer | Web Application Exploitation | ||
| Used for REST API pentesting and provide UI solution for gem. | Development | ||
| A JavaScript Engine Fuzzer. | Development | ||
| A Burp Suite extension to find potential endpoints and parameters. | Informations gathering | ||
| Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, Common Crawl, and URLScan for any given domain | Cracking | ||
| Enumerate Google Storage buckets, check the access and if they can be privilege escalated. | Cloud & services | ||
| Exfiltrate files from a target's Google Drive that you have access to, via Google's API. | Cloud & services | ||
| GNU debugger | Reverse Engineering | ||
| GDB Enhanced Features, multi-architecture | Plugins | ||
| Gather all companies acquired by a given company domain name. | Informations gathering | ||
| DLL injection library supporting x86, WOW64 and x64 injections; 5 injection methods, 4 shellcode execution methods and various additional options; session separation can be bypassed with all methods | System Exploitation | ||
| Investigate Google accounts with emails and find name, usernames, Youtube Channel, probable location, Maps reviews, etc. | OSINT and Reconnaissance | ||
| Game Of Active Directory is a test environment lab that includes all the common vulnerabilities of an active directory | Other | ||
| Game of Active Directory. | Resources | ||
| A powerful network scanner, DNS recon, subdomain enumeration and IP Geolocator tool powered by GPT. | Informations gathering | ||
| Run a Google based passive recon against your scope. | Informations gathering | ||
| Extract subdomains from SSL certificates in HTTPS sites. | Informations gathering | ||
| GitHub Sensitive Information Leakage. | Informations gathering | ||
| Unix binaries that can be manipulated for argument injection. | Auth & perms | ||
| CLI for earching gtfobins and lolbas from the terminal; allows more advanced search than gtfo | Other | ||
| Unix binaries that can be used to bypass local security restrictions in misconfigured systems. | Auth & perms | ||
| Automatic privilege escalation for misconfigured capabilities, sudo and suid binaries using GTFOBins. | Auth & perms | ||
| The Greenbone Vulnerability Management (GVM) is a framework of several services: gvmd is the central service that consolidates plain vulnerability scanning into a full vulnerability management solution. The Greenbone Security Assistant (GSA) is the web interface of GVM. The main scanner (OpenVAS) is a full-featured scan engine that executes a continuously updated and extended feed of Network Vulnerability Tests (NVTs). Complementary to the web interface, GVM-Tools allows batch processing / scripting via the Greenbone Management Protocol (GMP). Additional scanners can be integrated via the Open Scanner Protocol (OSP) | Vulnerability Assessment | ||
| Probe endpoints consuming Java serialized objects for fingerprinting. | Informations gathering | ||
| LLM-powered web honeypot using the OpenAI API | Honeypot and Decoy | ||
| Attack framework for distributed systems | Networking | ||
| Policy controller for Kubernetes. | Virtualization | ||
| Burp Suite extension to pull employee names from Google and Bing LinkedIn search results. | Cloud & services | ||
| Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl. | Adversary Simulation | ||
| Helps to identify IoT related dashboards and scan them for default passwords. | Informations gathering | ||
| Generate wordlists of passwords containing cities at a defined distance around the client city. | Informations gathering | ||
| Generate wordlists of passwords containing cities at a defined distance around the client city | Cracking | ||
| Automatic GEOINT using deep learning | OSINT and Reconnaissance | ||
| Automates the process of detecting and exploiting SQL injection security flaws. | Vulnerabilities | ||
| Automatic SQL injection and database takeover; inspired by SQLmap | Web Application Exploitation | ||
| Software reverse engineering (SRE) suite of tools: disassembly, assembly, decompilation, graphing, scripting, etc. | Reverse Engineering | ||
| Useful tool to track location or mobile number. | Informations gathering | ||
| Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts. | Informations gathering | ||
| Project management and reporting engine | Collaboration and Report | ||
| Detect the OS and execute the correct commands to upgrade it to a full interactive reverse shell | Networking | ||
| Investigate GitHub profiles; features: username history, email address to GitHub account, finds potential secondary GitHub accounts, dumps SSH public keys, etc. | OSINT and Reconnaissance | ||
| An OSINT tool to investigate GitHub profiles. | Informations gathering | ||
| Rapidly search through troves of public data on GitHub for sensitive secrets. | Informations gathering | ||
| A Git source leak exploit tool that restores the entire Git repository, including data from stash. | Informations gathering | ||
| Tool used for harvesting information from GitHub. | Source code management | ||
| Find sensitive information in git repositories | OSINT and Reconnaissance | ||
| A tool for searching a Git repository for interesting content. | Informations gathering | ||
| Tool for advanced mining for content on Github. | Informations gathering | ||
| A repository with 3 tools for pwn'ing websites with .git repositories available. | Source code management | ||
| 3 tools: Finder (find websites with .git repository exposed), Dumper (dump exposed .git), Extractor (extract commits and their content from a broken repository) | Web Application Exploitation | ||
| Reconnaissance tool for GitHub organizations. | Informations gathering | ||
| Socks proxy router to handle multi-clients on the same port | Networking | ||
| Go365 performs user enumeration and password guessing attacks on organizations that use Office365. | Cloud & services | ||
| User enumeration and password guessing for Office 365 / Microsoft365 | Red Teaming | ||
| A permutation generation tool written in golang. | Informations gathering | ||
| Checks whether a domain is hosted on a cloud service. | Cloud & services | ||
| Management frontend for hash cracking tools, supporting hashcat | Cracking | ||
| A fast and minimal JS endpoint extractor. | Development | ||
| User enumeration and password bruteforce on Azure, ADFS, OWA, O365 and gather emails on Linkedin | Networking | ||
| Open-source phishing toolkit. | Informations gathering | ||
| Username lookup comparable to Maigret/Sherlock, IP Lookup, License Plate & VIN Lookup, Info Cull, and Fake Identity Generator | OSINT and Reconnaissance | ||
| Directory/File, DNS and VHost busting tool written in Go | Reconnaissance | ||
| Directory/File, DNS and VHost busting tool written in Go | Reconnaissance | ||
| Directory/File, DNS and VHost busting tool written in Go. | Informations gathering | ||
| Network security technology that achieves rapid security emergency. | Auth & perms | ||
| Privilege escalation tool for Windows. | Auth & perms | ||
| Uses the dehashed.com API to search for compromised assets | Other | ||
| Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket | Networking | ||
| Passive reconaissance enumerating directories, files, subdomains or parameters using google dorks | OSINT and Reconnaissance | ||
| Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation | System Exploitation | ||
| Codelab for white-box and black-box hacking | Intentionally Vulnerable Applications | ||
| Solve Google reCAPTCHA in less than 5 seconds! | Cloud & services | ||
| Generates gopher link for exploiting SSRF and gaining RCE access from unprotected services | Web Application Exploitation | ||
| Generates gopher link for exploiting SSRF and gaining RCE in various servers. | Vulnerabilities | ||
| Phishing toolkit providing the ability to setup and execute phishing engagements and security awareness training | Red Teaming | ||
| Reconnaissance toolkit | OSINT and Reconnaissance | ||
| Gives root access on remote docker containers that expose their APIs. | Virtualization | ||
| Whois command implemented by golang with awesome whois servers list. | Informations gathering | ||
| GraphQL automated security testing | Web Application Exploitation | ||
| Scaffold a postman collection for a GraphQL API; compatible with Postman and Insomnia | Web Application Exploitation | ||
| GraphQL security layer for Apollo and Yoga / Envelop servers | Defensive | ||
| Burp Suite extension to help make Graphql request more readable. | Databases | ||
| Run common security tests against GraphQL | Web Application Exploitation | ||
| Threat framework to research security gaps in GraphQL implementations. | Databases | ||
| Represent any GraphQL API as an interactive graph | Web Application Exploitation | ||
| Context-aware GraphQL Fuzzer | Fuzzing | ||
| Scripting engine to interact with a graphql endpoint for pentesting purposes. | Databases | ||
| Scripting engine to interact with a graphql endpoint for pentesting purposes | Web Application Exploitation | ||
| GraphQL enumeration and extraction | Web Application Exploitation | ||
| Enumerate and extract GraphQL APIs. | Databases | ||
| GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce | Web Application Exploitation | ||
| Modular cross-platform Microsoft Graph API enumeration and exploitation toolkit. | Cloud & services | ||
| Search for buckets and URL shorteners. | Cloud & services | ||
| A tool for automated security scanning of web applications. | Auth & perms | ||
| A collection of scripts mainly for debugging SSRF, blind XSS, and XXE vulnerabilities. | Vulnerabilities | ||
| Enumerate relevant settings in AD Group Policy, identify exploitable misconfigurations | Networking | ||
| Web security scanner. | Informations gathering | ||
| GUI HTTP intercepting proxy based on Pappy Proxy | Web Application Exploitation | ||
| Growing penetration test tool using Machine Learning. | Cryptanalysis | ||
| A burpsuite extension to find security reports published on HackerOne based on the selected host. | Bug bounty | ||
| Hash type identifier. | Cryptanalysis | ||
| Designed to streamline the extraction and sanitization of HARTokens from HTTP archives. | Informations gathering | ||
| Network fingerprinting standard which can be used to identify specific client and server SSH implementations | Networking | ||
| Automated tool for testing header based blind SQL injection. | Network | ||
| Connects to LDAP directory to retrieve all computers and users informations. | Auth & perms | ||
| Retrieve all computers and users informations from AD LDAP; download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them | Networking | ||
| Self contained web shells and other attacks via .htaccess files. | Auth & perms | ||
| Extension for Burp Suite designed to help you launch HTTP Request Smuggling attacks. | Vulnerabilities | ||
| Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware. | Development | ||
| HTTP-traceroute in Go. | Network | ||
| Automatic DNS rebinding-based SSRF attacks | Networking | ||
| A Burp Suite extension that checks for the HTTPoxy vulnerability. | Well known products | ||
| HUNT Suite is a collection of Burp Suite Pro/Free and OWASP ZAP extensions | Web Application Exploitation | ||
| Massive hacking playground, and infosec community. | Resources | ||
| Decrypt passwords/cookies/history/bookmarks from the browser. | Informations gathering | ||
| Web browser extension (Chromium, Firefox, Safari) including common functions for web pentest | Other | ||
| The all-in-one browser extension for offensive security professionals. | Auth & perms | ||
| Find trick/technique/whatever learnt from CTFs, real life apps, reading researches, and news. | Resources | ||
| Probe a rendering engine for vulnerabilities and other features. | Informations gathering | ||
| Intentionally vulnerable web shopping application using modern technologies and containing configurable areas | Intentionally Vulnerable Applications | ||
| A free class for web security. | Resources | ||
| HackerSploit YouTube channel. | Resources | ||
| A limited client library for interacting with HackerOne | Bug bounty | ||
| Join the front line of the internet, learn applicable cyber security skills. | Resources | ||
| ALL IN ONE Hacking Tool For Hackers. | Informations gathering | ||
| Risk Based Vulnerablity Management platform | Collaboration and Report | ||
| Tag based conversion tool written in Java implemented as a Burp Suite extension. | Well known products | ||
| Shellcode loader that combines multiple evasion techniques with the aim of bypassing the defensive mechanisms commonly used by modern AV/EDRs | Red Teaming | ||
| Go shellcode loader that combines multiple evasion techniques. | Auth & perms | ||
| Basic Command and Control server | Red Teaming | ||
| Hash type identifier (CLI & lib) | Cryptography | ||
| Collect useful information from urls, directories, and files. | Informations gathering | ||
| A cross-platform, collaborative, Command & Control framework. | Auth & perms | ||
| Cross-platform, collaborative, Command & Control framework | Red Teaming | ||
| Checks and hardens your Windows configuration. | Bug bounty | ||
| CLI tool; collect data and document actively or passively | OSINT and Reconnaissance | ||
| Search across 20 million exposed secrets in public GitHub repositories, gists, issues and comments. | Informations gathering | ||
| Crack hashes in seconds. | Informations gathering | ||
| Grab NetNTLMv2 hashes using ETW with administrative rights on Windows. | Auth & perms | ||
| Web interface for Hashcat | Cracking | ||
| Hash cracking tool and World's fastest and most advanced password recovery utility | Cracking | ||
| Hashcat WebUI; queuing, local authentication, SMS and email notifications, map integration | Cracking | ||
| Hashcat wrapper for distributed hashcracking | Cracking | ||
| Web-UI for managing, organizing, automating Hashcat commands/tasks | Cracking | ||
| Generate all permutations of a domain which are enriched for typosquatting detection | Defensive | ||
| Service to check if an account has been compromised in a data breach, display the breaches not the password | Other | ||
| Check if your email or phone is in a data breach. | Informations gathering | ||
| Malleable post-exploitation command and control framework | Red Teaming | ||
| Modern and malleable post-exploitation command and control framework. | Auth & perms | ||
| Network, recon and offensive-security tool for Linux. | Network | ||
| Filesystem analysis tool/directory looking for interesting stuff. | Informations gathering | ||
| Do more with less effort Whether you do pentesting, vulnerabillity scanning or a custom mix of the two, don't waste your time on repetitive work | Collaboration and Report | ||
| Blazing-fast tool to grab screenshots of your domain list right from terminal. | Informations gathering | ||
| Provides a suite of extensions and a maven plugin to automate security tests using Burp Suite. | Well known products | ||
| Scan with nmap to correlate CPE's found with cve-search to enumerate vulnerabilities | Networking | ||
| HTTP toolkit for security research; alternative to BurpSuite | Web Application Exploitation | ||
| HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities. | AI MCP Servers | ||
| Linux kernel module generator for custom rules with netfilter | Other | ||
| x86_64 disassembler for multiple formats | Reverse Engineering | ||
| Collect, categorize and highlight requests and/or responses according to their content. | Network | ||
| Android GUI for Aircrack, Airodump, Aireplay, MDK3 and Reaver | Wireless | ||
| GUI for the penetration testing tools Aircrack-ng, Airodump-ng, MDK3 and Reaver. | Network | ||
| Extracting the contents of Microsoft Windows Registry (hive) and display it as a colorful tree but mainly focused on parsing BCD files to extract WIM files path for PXE attacks | Networking | ||
| Collaborative penetration test and reporting platform | Collaboration and Report | ||
| Scans processes to detect and dump potentially malicious implants. | Auth & perms | ||
| Security oriented software fuzzer; supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based) | Reverse Engineering | ||
| HTTP request collector and inspector | Web Application Exploitation | ||
| Adds autocompletion support and useful payloads in Burp Suite | Plugins | ||
| Disassembler, decompiler and debugger | Reverse Engineering | ||
| Bruteforce existing subdomains and provide informations about them. | Informations gathering | ||
| Graphical search engine for Exploit-DB | Other | ||
| A runtime mobile application analysis toolkit with a Web GUI. | Operating systems | ||
| Automatic domain recognition (via amass) and vulnerability scan (via nuclei) platform with a WebUI | OSINT and Reconnaissance | ||
| Very fast password cracking tool. | Informations gathering | ||
| Network login cracker | Networking | ||
| Improve the display when debugging with GDB, needs GEF, pwndbg or peda to be loaded in GDB as a backend | Plugins | ||
| Advanced AWS access credentials scanner. | Auth & perms | ||
| Disassembler and debugger | Reverse Engineering | ||
| Simple tool to scan large scope and provide SSL/TLS vulnerabilities. | Cryptanalysis | ||
| Check for the IIS tilde enumeration / IIS 8.3 short filename disclosure vulnerability and to exploit it by enumerating all the short names in an IIS web server | Plugins | ||
| .NET assembly browser and decompiler to C# | Reverse Engineering | ||
| NET Decompiler with support for PDB generation, ReadyToRun, Metadata (&more) - cross-platform!. | Development | ||
| A tool to automatically generate alternative IP representations. | Cryptanalysis | ||
| Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request. | Cloud & services | ||
| Collaborative platform aiming to help incident responders sharing technical details during investigations | Incident Response | ||
| Network recon framework. | Auth & perms | ||
| IVRE (Instrument de veille sur les réseaux extérieurs) or DRUNK (Dynamic Recon of UNKnown networks); network recon framework including tools ofr passive and active recon | OSINT and Reconnaissance | ||
| SOCKS proxy for Citrix | Networking | ||
| Service to check if an account has been compromised in a data breach, send the breaches by email | Other | ||
| Check if a phone number is used on different sites like snapchat, instagram | OSINT and Reconnaissance | ||
| Hexadecimal editor tailored for reverse engineers; byte patching, data import / export, data inspector, huge file support, file hashing, disassembler for many architectures, data analyzer | Reverse Engineering | ||
| Hex editor for reverse engineers, programmers and people who value their retinas when working at 3am. | Informations gathering | ||
| Software suite and library to create, edit, compose, or convert images | Steganography | ||
| Allows developers and security experts to check if an Imagemagick XML Security Policy is hardened against a wide set of malicious attacks | Defensive | ||
| Windows debugger with Python scripting support | Reverse Engineering | ||
| Identify the attack paths in BloodHound breaking AD tiering | Networking | ||
| GraphQL security audit | Web Application Exploitation | ||
| Burp Extension for GraphQL Security Testing. | Databases | ||
| Test a data center's resiliency to perimeter breaches and internal server infection. | Informations gathering | ||
| Adversary emulation platform; test a data center's resiliency to perimeter breaches and internal server infection | Adversary Simulation | ||
| Automated wireless hacking tool | Wireless | ||
| Email OSINT. | Informations gathering | ||
| php.ini scanner for security best practices | Configuration Audit | ||
| Perform advanced MiTM attacks on websites with ease. | Vulnerabilities | ||
| CRLF and open redirect fuzzer. | Vulnerabilities | ||
| InsiderPhD Youtube channel. | Resources | ||
| Android package inspector. | Operating systems | ||
| Solution for collecting and processing security feeds using a message queuing protocol | Incident Response | ||
| Manage your threat intelligence at scale. | Informations gathering | ||
| Perform automated network reconnaissance scans to gather network intelligence. | Informations gathering | ||
| HTTP request collector and inspector; OOB interaction gathering server and client library; DNS / HTTP / SMTP interaction support | Web Application Exploitation | ||
| Turn single threaded command line applications into a fast, multi-threaded application. | Auth & perms | ||
| Turn single threaded command line applications into a multi-threaded application with CIDR and glob support | Other | ||
| Framework for discovering attack surface | Web Application Exploitation | ||
| Payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists. | Resources | ||
| Web Application Security For Enterprise. | Bug bounty | ||
| Automates the discovery and pwnage of ACLs in Active Directory that are unsafe configure. | Auth & perms | ||
| Automate Active Directory Enumeration using PowerView. | Auth & perms | ||
| PowerShell-based toolkit consisting of a collection of techniques and tradecraft for use in red team, post-exploitation, adversary simulation, or other offensive security tasks | Adversary Simulation | ||
| For when you want a computer to be done - without admin!. | Operating systems | ||
| Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute. | Auth & perms | ||
| An Internet Explorer post exploitation library. | Informations gathering | ||
| Socks proxy, and reverse socks server using powershell. | Auth & perms | ||
| Memory Backed Powershell WebDav Server. | Operating systems | ||
| PowerShell script to dump Windows credentials from the Credential Manager. | Informations gathering | ||
| Web security/vulnerability scanner (native for Windows only) | Web Application Exploitation | ||
| Improve the test coverage during web application penetration tests on J2EE applications. | Development | ||
| Take screenshots of websites | Web Application Exploitation | ||
| Just Another Windows (Enum) Script; quickly identify potential privilege escalation vectors on Windows systems | System Exploitation | ||
| A standalone Java decompiler GUI. | Development | ||
| GUI tool decompiling JAVA | Reverse Engineering | ||
| Disassembler, decompiler and debugger | Reverse Engineering | ||
| Decompile and debug binary code and obfuscated apps, break down and analyze document files. | Development | ||
| Generates JNDI links can start several servers to exploit JNDI Injection vulnerabilities. | Development | ||
| JavaScript Object Signing and Encryption Pentesting Helper. | Auth & perms | ||
| Free Flash decompiler. | Informations gathering | ||
| A.k.a ffdec, flash SWF decompiler | Reverse Engineering | ||
| A .js scanner, built in PHP, designed to scrape urls and other info. | Informations gathering | ||
| JavaScript payload and supporting software to be used as XSS payload or post exploitation implant. | Development | ||
| Javascript deobfustcator | Reverse Engineering | ||
| JSON Beautifier for Burp written in Java. | Development | ||
| JSONP endpoints/payloads to help bypass content security policy of different websites | Web Application Exploitation | ||
| A ready to use JSONP endpoints/payloads to help bypass Content Security Policy. | Vulnerabilities | ||
| Python script to parse relative URLs from JavaScript files. | Informations gathering | ||
| An interactive multi-user web JS shell. | Development | ||
| Generate javascript code to be injected in case you find a Server Side Javascript Injection. | Development | ||
| Burp Suite extension to crawl JS files in passive mode and display the results on the issues. | Development | ||
| Simple python script to check against hypothetical JWT vulnerability. | Auth & perms | ||
| A toolkit for testing, tweaking and cracking JSON Web Tokens. | Auth & perms | ||
| JWT brute force cracker written in C. | Auth & perms | ||
| Multi-threaded JWT brute-force cracker | Web Application Exploitation | ||
| Recover the public key used to sign JWT tokens | Cryptography | ||
| JWT Support for Burp Suite. | Auth & perms | ||
| Detects JWT algorithm and provides options to generate a new JWT based on another algorithm. | Auth & perms | ||
| The Swiss Army knife for automated Web Application Testing | Auth & perms | ||
| Framework for building your own Web Application Scanner | Web Application Exploitation | ||
| Abstracts away the complex steps required to perform a DNS rebind and exposes a HTML5 Fetch interface which transparently triggers a DNS rebind | Networking | ||
| .JAR and .Class to Java decompiler | Reverse Engineering | ||
| All-in-one plugin for the detection and exploitation of Java deserialization vulnerabilities. | Development | ||
| JavaScript obfuscator; features: variables renaming, strings extraction and encryption, dead code injection, control flow flattening, various code transformations, etc. | Red Teaming | ||
| Fast and customizable vulnerability scanner for Jira. | Well known products | ||
| ### Jiraffe Jiraffe is a modern, modular security reconnaissance and vulnerability validation framework for Atlassian Jira deployments. Designed for security professionals, Jiraffe focuses on accuracy, signal quality, and safe validation rather than noisy scanning. It follows a recon-first, exploit-second model, allowing users to understand a target's exposure before performing controlled vulnerability validation. Jiraffe currently includes 14+ dedicated reconnaissance modules covering unauthenticated access checks, information disclosures, and common Jira misconfigurations, along with 16 custom CVE exploit implementations, with new modules added continuously. #### Features * Modular reconnaissance and exploit framework * Passive, unauthenticated recon modules for: * Information disclosure * Misconfigurations * Exposed or weakly protected endpoints * Safe CVE validation with severity filtering * Jira version and deployment awareness (Cloud vs Server/DC) to avoid misleading or invalid checks * SSRF helpers, including cloud metadata and custom targets * JSON output for automation, CI/CD, and scripting * No automatic shell execution or intrusive behavior by default #### Use cases * Bug bounty reconnaissance * Internal security assessments * Red team tooling * Responsible vulnerability validation Jiraffe is actively maintained, extensible, and built with clean architecture to support long-term evolution as Jira's attack surface changes. | Web Application Exploitation | ||
| Code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs | Code Analysis | ||
| John Hammond YouTube channel. | Resources | ||
| Password cracker tool. | Informations gathering | ||
| Hash cracking tool | Cracking | ||
| Hash cracking tool, community-enhanced version of John The Ripper | Cracking | ||
| OWASP Joomla Vulnerability Scanner Project. | CMS | ||
| Identify Joomla version, scan for vulnerabilities and sensitive files. | CMS | ||
| Simple HS256, HS384 & HS512 JWT token brute force cracker. | Cracking | ||
| Find vulnerabilities, compliance issues and infrastructure misconfigurations in your IAC. | Auth & perms | ||
| Online XSS tool with demonstration of vulnerability. | Vulnerabilities | ||
| DNS dynamic update abuse in ADIDNS via DSPROPERTY_ZONE_ALLOW_UPDATE set to ZONE_UPDATE_UNSECURE combined with MitM attack using Kerberos AP-REQ hijacking | Networking | ||
| LFI, RFI, RCE scanner | Web Application Exploitation | ||
| Check for and exploit LFI vulnerabilities with a focus on PHP systems. | Vulnerabilities | ||
| Lists of resources: cdn ranges, ips ranges, sni ip ranges... | Informations gathering | ||
| Graphical user interface for Metasploit Meterpreter and session handler | Red Teaming | ||
| Graphical user interface for Metasploit Meterpreter and session handler. | Well known products | ||
| Declarative language to generate binary data parsers in various languages | Reverse Engineering | ||
| The most advanced penetration testing distribution. | Network | ||
| Crawling and spidering framework, supporting headless mode, JavaScript, customizable automatic form filling and scope control | Web Application Exploitation | ||
| Automate KeePass discovery and secret extraction | Plugins | ||
| A python script to help red teamers discover KeePass instances and extract secrets. | Informations gathering | ||
| A little toolbox to play with Microsoft Kerberos in C. | Auth & perms | ||
| macOS kernel pre and post callback-based framework | Reverse Engineering | ||
| Beacon Object Files for Kerberos abuse. | Auth & perms | ||
| Bruteforce and enumerate valid Active Directory accounts through Kerberos Pre-Authentication | Networking | ||
| Extracts Key Values from .keytab files. | Auth & perms | ||
| Find and analyze private/public key files and Android APK files. | Operating systems | ||
| A tool for testing and promoting user awareness by simulating real world phishing attacks | Red Teaming | ||
| A free, open source wireless stumbling and security tool for Mac OS X. | Network | ||
| Sniffer, WIDS, and wardriving tool for Wi-Fi, Bluetooth, Zigbee, RF | Wireless | ||
| Remote capture for all capture types over TCP sockets or websockets. | Network | ||
| Highly configurable script for dictionary/spray attacks against online web applications. | Informations gathering | ||
| Knock Subdomain Scan. | Informations gathering | ||
| This is a python wrapper around the amazing KNOXSS. | Vulnerabilities | ||
| Tool to find firms domains by searching their trademark information | OSINT and Reconnaissance | ||
| Java decompiler, assembler, and disassembler. | Development | ||
| Java decompiler, assembler, and disassembler | Reverse Engineering | ||
| Hashcat-based distributed password cracking system with WebUI; has a desktop client in addition | Cracking | ||
| Modular multi-language webshell focused on web post-exploitation and defense evasion; supports PHP, JSP and ASPX | Web Application Exploitation | ||
| A modular multi-language webshell. | Vulnerabilities | ||
| Distributed password brute-force system, supports Hashcat | Cracking | ||
| Toolkit for abusing unconstrained delegation | Networking | ||
| Kscan is an all-round scanner developed purely in Go, with functions such as port scanning, protocol. | Informations gathering | ||
| Scanner for security weaknesses in Kubernetes clusters | Code Analysis | ||
| Kubernetes attack graph tool allowing automated calculation of attack paths between assets in a cluster | Networking | ||
| Vulnerable by design cluster environment to learn and practice Kubernetes security. | Resources | ||
| Post-exploitation HTTP/2 Command & Control server and agent focused on containerized environments | Red Teaming | ||
| Cross-platform command & control server and agent focused on containerized environments. | Virtualization | ||
| Exploit Kubernetes clusters misconfigurations and be the swiss army knife of your pentests. | Virtualization | ||
| Pentest data management tool | Collaboration and Report | ||
| Infect an existing Android application with a Meterpreter payload. | Operating systems | ||
| Generate reverse shell payloads on the fly. | Auth & perms | ||
| Password Hunter in active directory. | Auth & perms | ||
| Check for LDAP protections regarding the relay of NTLM authentication. | Auth & perms | ||
| Anonymously bruteforce Active Directory usernames by abusing LDAP Ping requests. | Auth & perms | ||
| Monitor creation, deletion and changes to LDAP objects live during pentest or system administration | Networking | ||
| Bash script which checks and validates for leaked credentials. | Development | ||
| LFI scan and exploit tool | Web Application Exploitation | ||
| Totally Automatic LFI Exploiter and Scanner. | Vulnerabilities | ||
| Automatic LFI scanner and exploiter | Web Application Exploitation | ||
| Scripts to execute enumeration via LFI | Vulnerabilities | ||
| Dump remote files through a local file read or Local File Inclusion web vulnerability. | Operating systems | ||
| Language Independent Crypto-Misuse Analysis; multi-language analysis tool to identify incorrect initialization of crypto functions | Code Analysis | ||
| Lord Of Active Directory is a test environment lab that includes all the common vulnerabilities of an active directory and deploys automatically on AWS; based on AWS-Redteam-Lab and GOAD | Other | ||
| Living Off The Land Binaries, Scripts and Libraries. | Auth & perms | ||
| Living Off the Orchard: macOS Binaries. | Auth & perms | ||
| Login Pages Database forms a knowledge base on login pages related to malicious activities (C2 panels, phishing kits...) | Red Teaming | ||
| Password retriever | System Exploitation | ||
| Credentials recovery project. | Informations gathering | ||
| Collaborative penetration test and vulnerability management framework | Collaboration and Report | ||
| Patch management, vulnerability scanning, and network auditing. | Bug bounty | ||
| A framework that provides a web UI to commonly used Bug Hunting/Pentesting tools. | Auth & perms | ||
| Service to check if an account has been compromised in a data breach, requires an account | Other | ||
| Normalize, deduplicate, index, sort, and search leaked data sets on the multi-terabyte-scale | OSINT and Reconnaissance | ||
| Search engine for devices and services exposed on the Internet | OSINT and Reconnaissance | ||
| Discover, browse and monitor database/source code leaks | OSINT and Reconnaissance | ||
| Discover, browse and monitor database/source code leaks. | Informations gathering | ||
| Multiprotocol credentials bruteforcer, password sprayer and enumerator | Networking | ||
| Aids in discovery, reconnaissance and exploitation of information systems. | Bug bounty | ||
| Detect misconfigurations and security risks across GitHub and GitLab assets. | Source code management | ||
| Automated attack simulation in the cloud, complete with detection use cases. | Cloud & services | ||
| Advanced fuzzing librar. Slot your fuzzers together and extend their features using Rust. | Auth & perms | ||
| Local file inclusion exploitation tool. | Vulnerabilities | ||
| LFI exploitation tool | Web Application Exploitation | ||
| Framework for auditing web application firewalls and filters | Web Application Exploitation | ||
| Generate an obfuscated DLL that will disable AMSI & ETW | Red Teaming | ||
| Pivot / reverse tunneling tool with SOCKS5 and TCP tunnel support | Networking | ||
| Pivoting via TCP/TLS reverse tunneling with TUN interface | Networking | ||
| An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface. | Auth & perms | ||
| Linux enumeration and privilege escalation script | System Exploitation | ||
| System script for local Linux enumeration and privilege escalation checks | OSINT and Reconnaissance | ||
| Scripted Local Linux Enumeration & Privilege Escalation Checks. | Auth & perms | ||
| Find URL endpoints and their parameters in JavaScript files | Web Application Exploitation | ||
| A python script that finds endpoints in JavaScript files. | Informations gathering | ||
| Dump company employees from LinkedIn API | OSINT and Reconnaissance | ||
| Script that dumps employee data from the LinkedIn social networking platform. | Cloud & services | ||
| The Linux memory acquisition tool. | Operating systems | ||
| Based on operating system release number. | Operating systems | ||
| Linux kernel exploit suggester | System Exploitation | ||
| Information gathering (OSINT) on a person (EU), checks social networks and Pages Jaunes | OSINT and Reconnaissance | ||
| Assist forensic investigators and incidence responders in carrying out a quick live forensic investigation | Digital Forensics | ||
| LiveOverflow YouTube channel. | Resources | ||
| Generates lists of live hosts and URLs. | Informations gathering | ||
| CLI tool that checks if your PHP application depends on PHP packages with known security vulnerabilities | Configuration Audit | ||
| Another local Windows privilege escalation using a new potato technique. | Auth & perms | ||
| Detect and fix common misconfigurations in Active Directory Certificate Services. | Auth & perms | ||
| Find and fix common misconfigurations in AD CS | Networking | ||
| Log activities of all the tools in Burp Suite. | Well known products | ||
| Investigate malicious Windows logon by visualizing and analyzing Windows event log. | Auth & perms | ||
| IOC scanner | Incident Response | ||
| Allows users to capture a website page and then display a tree of domains that call each other. | Informations gathering | ||
| A web interface that allows you to capture a website page and display a tree of domains | Other | ||
| Web directory and file scanner (wordlist bruteforce) | Web Application Exploitation | ||
| An Open Source Java Decompiler GUI for Procyon. | Development | ||
| Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional. | Configuration Audit | ||
| The single instruction C compiler. | Cryptanalysis | ||
| Crawl SMB shares for juicy information; supports file content searching and regex | Networking | ||
| Spider entire networks for juicy files sitting on SMB shares. | Informations gathering | ||
| PoC tool to exploit common IEEE 802.11 protocol weaknesses | Wireless | ||
| PoC tool to exploit common IEEE 802.11 protocol weaknesses | Wireless | ||
| Check if MFA is enabled on multiple Microsoft services | Red Teaming | ||
| Threat intelligence platform & open standards for threat information sharing (formerly known as Malware Information Sharing Platform) | Threat Intelligence | ||
| Malware Information Sharing Platform, an Open Source threat intelligence platform and open standards for threat information sharing | Collaboration and Report | ||
| Knowledge base of adversary tactics and techniques based on real-world observations. | Resources | ||
| ATT&CK training and certification program produced by MITRE’s own ATT&CK subject matter experts | Adversary Simulation | ||
| Microsoft SQL database attacking tool. | Databases | ||
| Identify DNS records, check for zone transfers and conduct subdomain enumeration. | Informations gathering | ||
| Google Dork File Finder. | Informations gathering | ||
| A password spraying tool for Microsoft Online accounts (Azure/O365). | Cloud & services | ||
| MSSQL relay audit and abuse | Networking | ||
| SQL injection script for Microsoft SQL Server. | Databases | ||
| Mobile Verification Toolkit; collection of utilities to simplify and automate the process of gathering forensic traces helpful to identify a potential compromise of Android and iOS devices | Digital Forensics | ||
| A powerful shell script to maximize the recon and data collection process. | Informations gathering | ||
| Collect a dossier on a person by username from thousands of sites. | Informations gathering | ||
| Collect a dossier on a person by username from a huge number of sites, and extract details from them | OSINT and Reconnaissance | ||
| SMTP credentials bruteforcer / checker | Networking | ||
| It's a handy tool to help you analyze malware. | Cryptanalysis | ||
| A web-based collection of tools and resources for OSINT; successor of OSINT Framework | OSINT and Reconnaissance | ||
| Interactive data mining tool that renders directed graphs for link analysis. The tool is used in online investigations for finding relationships between pieces of information from various sources located on the Internet (exists in Community Edition) | Threat Intelligence | ||
| Open source intelligence and forensics application. | Informations gathering | ||
| Malware sample database. | Auth & perms | ||
| Collection of malware source code for a variety of platforms in an array of different programming la. | Auth & perms | ||
| Web oriented deobfuscating tool | Web Application Exploitation | ||
| Manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs | Red Teaming | ||
| Adversary emulation command line tool is parsing complex scenarios from Manticore public-threats repository and run these scenarios | Adversary Simulation | ||
| An advanced source map extractor based on headless browser. | Informations gathering | ||
| Open-source Intelligence Framework. | Informations gathering | ||
| Library and CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory | System Exploitation | ||
| Enumerate through a pre-compiled list of AWS S3 buckets using DNS instead of HTTP. | Cloud & services | ||
| High-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration) | OSINT and Reconnaissance | ||
| A high-performance DNS stub resolver for bulk lookups and reconnaissance. | Informations gathering | ||
| TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes. | Informations gathering | ||
| Port scanner for massive networks | Networking | ||
| Audit Unix/*BSD/Linux system libraries to find public security vulnerabilities | Configuration Audit | ||
| Encode Havoc shellcode (.bin) in XOR, chacha20, AES; supports 2 loaders: Myph, 221b | Plugins | ||
| Network login cracker | Networking | ||
| Medusa is a speedy, parallel, and modular, login brute-forcer. | Informations gathering | ||
| Interactive multi-architecture and multi-formats disassembler running on Windows and Linux | Reverse Engineering | ||
| GUI for Medusa | Networking | ||
| Graphical tool for custom wordlist generation, can output rules compatible with Hashcat and John the Ripper | Cracking | ||
| Web application to manage the mapping of an information system as described in the Mapping The Information System Guide of the ANSSI | Defensive | ||
| Post-exploitation HTTP/2 Command & Control server and agent | Red Teaming | ||
| Unleash metadata intelligence, bridging the chasm in metadata extraction and analysis. | Informations gathering | ||
| Searching information about IP address, ASN and organization; doesn't require any API key | OSINT and Reconnaissance | ||
| Intelligence tool to do OSINT tasks and more but without any API key. | Informations gathering | ||
| This tools covers Cross-Site Scripting (XSS) security issues with media-files containing metadata. Such data is usually created by trusted devices like cameras. Therefore, there is the chance that providers handling this metadata, also trust them and that they thus use insufficient or no filter mechanisms. We have developed an open source penetration testing tool called Metadata-Attacker. It consists of a suite of self-developed tools that allow to create malicious proof-of-concept image (.jpg), audio (.mp3), and video (.mp4) files. | Web Application Exploitation | ||
| Search Google and download specific file types. | Cloud & services | ||
| Assembler, disassembler, compiler and debugger | Reverse Engineering | ||
| The world’s most used penetration testing framework. | Auth & perms | ||
| Tool and framework for pentesting system, web and many more, contains a lot a ready to use exploit, 4 versions: Pro (paid), Express (paid), Community (free with GUI but on request), Framework (free, open source, CLI) | Vulnerabilities | ||
| VM that is built from the ground up with a large amount of security vulnerabilities | Intentionally Vulnerable Applications | ||
| A collection of scripts for assessing Microsoft Azure security. | Cloud & services | ||
| Quickly and easily create backdoor Office exploitation using module Metasploit packet. | Well known products | ||
| A dynamic deception tool that actively deceives an attacker. | Auth & perms | ||
| Android APK vulnerability analyzer | Code Analysis | ||
| All-in-one mobile application pentesting, malware analysis and security assessment framework. | Operating systems | ||
| HTTP request collector and inspector | Web Application Exploitation | ||
| HTTP reverse proxy designed for phishing | Red Teaming | ||
| A powerful and flexible HTTP reverse proxy. | Network | ||
| Cellular networks jamming PoC for mobile equipments | Wireless | ||
| Tool to retrieve information of cellular networks | Wireless | ||
| Set of commands for Immunity Debugger | Plugins | ||
| Designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential. | Auth & perms | ||
| Manual search tool to find bugs like a grep unix command. | Informations gathering | ||
| An automated e-mail OSINT tool. | Informations gathering | ||
| SIP-based audit and attack tool. | Network | ||
| Post-exploitation tool for dumping and extracting LSASS memory discreetly. | Auth & perms | ||
| Online hash checker for Virustotal and other services | Incident Response | ||
| A toolkit for signing, forging and cracking JWT tokens | Web Application Exploitation | ||
| A collaborative, multi-platform, red teaming framework. | Virtualization | ||
| Collaborative red teaming framework | Red Teaming | ||
| Allows to embed data into application layer protocol fields, with the goal of establishing a bi-directional channel for arbitrary communications; supports encapsulation into HTTP, HTTPS, DNS and ICMP protocols | Red Teaming | ||
| Finding profiles by username over 350 websites | OSINT and Reconnaissance | ||
| Advanced GUI for Nmap | Networking | ||
| Quickly and accurately create a visual representation of their Nmap output. | Auth & perms | ||
| Python utility to takeover domains vulnerable to AWS NS Takeover. | Cloud & services | ||
| Utility to detect AWS NS Takeover. | Cloud & services | ||
| NTLM hash lookup table, billions of passwords indexed | Cracking | ||
| Enumerate information from NTLM authentication enabled web endpoints. | Auth & perms | ||
| Crisis management web application / project for software systems analysis and design | Crisis Management | ||
| A fast port scanner written in go with a focus on reliability and simplicity. | Informations gathering | ||
| The industry standard in IT infrastructure monitoring. | Bug bounty | ||
| NahamSec Twitch channel. | Resources | ||
| Service to check if an account has been compromised in a data breach, display the breaches not the password | Other | ||
| Check usernames on more than 100 websites, forums and social networks. | Informations gathering | ||
| A flexible tool that creates a minidump of the LSASS process. | Auth & perms | ||
| Minimal LSASS dumper | System Exploitation | ||
| Modular personalized dictionary generator | Cracking | ||
| Reliable and adaptative network login cracker supporting a large number of protocols | Networking | ||
| Chrome extension for instant access to bug bounty submission dashboard of various platforms and publicly disclosed reports | Bug bounty | ||
| The global gold standard in vulnerability assessment built for the modern attack surface. | Bug bounty | ||
| Export Nessus results to a relational database for use in reports, analysis, or whatever else. | Bug bounty | ||
| Windows / Active Directory environments pentest; fork of CrackMapExec | Networking | ||
| Network service exploitation tool that helps automate assessing the security of large networks. | Auth & perms | ||
| A tool you can use to scan for devices on your network. | Auth & perms | ||
| Rapidly detect and respond to any threat, anywhere. See Everything. Fear Nothing. | Bug bounty | ||
| Scrape sensitive information from paste sites | OSINT and Reconnaissance | ||
| PCAP analyzer; needs registration | Networking | ||
| Maltego alternative | Threat Intelligence | ||
| Netlas.io is the network atlas of Internet. IP, DNS, Web, IoT devices, and etc. | Informations gathering | ||
| Web application security scanner | Web Application Exploitation | ||
| Network Chuck YouTube channel. | Resources | ||
| Network sniffer/packet capturing tool | Networking | ||
| Network forensic analysis tool for Windows. | Informations gathering | ||
| PCAP analyzer; using Suricata | Networking | ||
| Vulnerability scanner which aims to support the entire vulnerability management lifecycle. | Bug bounty | ||
| Simple tool to look for common Nginx misconfigurations and vulnerabilities. | Auth & perms | ||
| Modern real-time collaborative editing tool secured by end-to-end encryption | Collaboration and Report | ||
| Command & Control framework; multi-operator, API driven, malleable native implant | Red Teaming | ||
| Nikto web server scanner. | Informations gathering | ||
| Light-weight first-stage Command & Control implant | Red Teaming | ||
| A light-weight first-stage C2 implant written in Nim. | Cryptanalysis | ||
| Simple and lightweight Command & Control framework | Red Teaming | ||
| Yet another (simple and lightweight) C2 framework. | Auth & perms | ||
| Tool for fingerprinting and exploiting Amazon cloud infrastructures. | Cloud & services | ||
| Script to make TOR as default gateway | Networking | ||
| Simplify your life with leak detection in JavaScript, NipeJS streamlines the use of regex, making it. | Development | ||
| Tool that parse router, switch, firewall configuration to discover vulnerabilities | Configuration Audit | ||
| Tool that parse router, switch, firewall configuration to discover vulnerabilities | Configuration Audit | ||
| Framework, collection of scripts and payloads in PowerShell for offensive security, penetration testing and red teaming | System Exploitation | ||
| Offensive PowerShell for red team, penetration testing and offensive security. | Auth & perms | ||
| Tool for network discovery and security auditing | Networking | ||
| The network mapper. | Informations gathering | ||
| Create a Nmap API that can do scans with a good speed online and is easy to deploy. | Development | ||
| Cybersecurity tools offered as SaaS: nmap, subdomain finder (Sublist3r, DNScan, Anubis, Amass, Lepus, Findomain, Censys), theHarvester, etc. | OSINT and Reconnaissance | ||
| NoSql Injection CLI tool for finding vulnerable websites using MongoDB. | Databases | ||
| Automated NoSQL database enumeration and web application exploitation tool. | Vulnerabilities | ||
| Automated NoSQL database enumeration and web application exploitation tool | Web Application Exploitation | ||
| Learn how OWASP Top 10 security risks apply to web applications developed using Node.js. | Development | ||
| Static security code scanner for Node.js applications | Code Analysis | ||
| Command-line tool that finds secrets and sensitive information in textual data and Git history. | Informations gathering | ||
| NoSQL scanning and exploitation framework | Web Application Exploitation | ||
| A Python Framework For NoSQL Scanning and Exploitation. | Databases | ||
| HTTP fuzzer engine security oriented. | Development | ||
| Multithreaded and modular bruteforce framework with network templates | Networking | ||
| Now, the Host is Mine!; sub-domain takeover detection | Web Application Exploitation | ||
| Web application security scanner based on templates | Web Application Exploitation | ||
| Fast and customizable vulnerability scanner based on simple YAML based DSL. | Vulnerabilities | ||
| Community curated list of templates for the Nuclei engine to find security vulnerabilities. | Informations gathering | ||
| A reference implementation and toolkit for enabling standardized emergency information exchange using the OASIS Emergency Data Exchange Language (EDXL) | Crisis Management | ||
| Burp Suite Extension useful to verify OAUTHv2 and OpenID security. | Auth & perms | ||
| Advanced multi-architecture online disassembler supporting a lot of architectures and object file formats | Reverse Engineering | ||
| Observe, Detect, and Investigate Networks, Automated reconnaissance tool | OSINT and Reconnaissance | ||
| Autonomously assesses your API for prevalent vulnerabilities. | Development | ||
| Bind9 DNS server for pentesters to use for Out-of-Band vulnerabilities | Networking | ||
| Markdown templates for OSCP exam report | Collaboration and Report | ||
| A web-based collection of tools and resources for OSINT | OSINT and Reconnaissance | ||
| OSINT Framework. | Informations gathering | ||
| Perform OSINT scan on email/domain/ip address/organization. | Informations gathering | ||
| OSINT from your favorite services in a friendly terminal user interface. | Informations gathering | ||
| Continuous Fuzzing for Open Source Software. | Auth & perms | ||
| A distributed vulnerability database for Open Source. | Auth & perms | ||
| Dump users's .plist on a Mac OS system and to convert them into a crackable hash. | Informations gathering | ||
| Free Mac OS X computer forensics tool. | Operating systems | ||
| A nonprofit foundation that works to improve the security of software. | Resources | ||
| Joomla vulnerability scanner | Web Application Exploitation | ||
| Insecure web application with >85 challenges; supports CTFs, custom themes, tutorial mode etc. | Intentionally Vulnerable Applications | ||
| Probably the most modern and sophisticated insecure web application. | Resources | ||
| Intentionally vulnerable web-application containing some OWASP Top Ten vulnerabilities, with hints and switch for secure version of the code | Intentionally Vulnerable Applications | ||
| Collection of XML templates, XML schemas and XSLT code, to generate IT security documents including test reports, offers and invoices | Collaboration and Report | ||
| Deliberately insecure web application to teach web application security lessons | Intentionally Vulnerable Applications | ||
| OWASP Zed Attack Proxy, intercepting proxy to replay, inject, scan and fuzz HTTP requests | Web Application Exploitation | ||
| A framework which tries to unite great tools and make pentesting more efficient. | Auth & perms | ||
| Framework allowing to write, build and patch instrumentation modules for Bluetooth Low Energy (BLE) controllers | Wireless | ||
| Data leak checker and monitoring | OSINT and Reconnaissance | ||
| Pre-operation C2 server | Red Teaming | ||
| OSINT tool used to discover environments, directories, and subdomains of a particular domain. | Informations gathering | ||
| Offensive Security Youtube channel. | Resources | ||
| Collection of offensive tools targeting Microsoft Azure written in Python to be platform agnostic. | Cloud & services | ||
| O365 user enumeration and password spraying tool. | Informations gathering | ||
| Windows debugger | Reverse Engineering | ||
| Perform information gathering from Google for search results related to a user query. | Cloud & services | ||
| OSINT framework; collection of tools | OSINT and Reconnaissance | ||
| A powerful subdomain integration tool. | Informations gathering | ||
| Subdomain enumeration tool | OSINT and Reconnaissance | ||
| A self-hosted fuzzing-as-a-service platform. | Auth & perms | ||
| Hacking tools installer and package manager for hackers. | Operating systems | ||
| Script that scrapes urls on different .onion search engines | OSINT and Reconnaissance | ||
| Parse OpenAPI specifications into the BurpSuite for automating RESTful API testing. | Development | ||
| Online platform for finding open buckets in cloud storage systems effortlessly. | Cloud & services | ||
| Platform designed for managing and analyzing cyber threat intelligence knowledge, centralizing data using the STIX2 standard and offering visualization and integration capabilities | Threat Intelligence | ||
| Open Cyber Threat Intelligence Platform. | Bug bounty | ||
| Modular and decentralised honeypot. | Auth & perms | ||
| Platform allowing organizations to plan, schedule and conduct crisis exercises | Crisis Management | ||
| A Fuzzer for OpenRedirect issues. | Vulnerabilities | ||
| Open Vulnerability Assessment Scanner | Other | ||
| This repository contains the scanner component for Greenbone Community Edition. | Auth & perms | ||
| Windows password cracker based on rainbow tables. | Auth & perms | ||
| Windows hash cracker based on rainbow tables | Cracking | ||
| Open Redirection Analyzer. | Vulnerabilities | ||
| A simple multi-threaded distributed SSH brute-forcing tool. | Informations gathering | ||
| Interactive shell to perform analysis on Instagram account of any users by their nickname | OSINT and Reconnaissance | ||
| An interactive shell to perform analysis on Instagram account of any users by its nickname. | Informations gathering | ||
| Automated framework for reconnaissance and vulnerability scanning | OSINT and Reconnaissance | ||
| A Workflow Engine for Offensive Security | Auth & perms | ||
| Uses SQL queries to monitor and analyze operating systems, providing endpoint visibility for security | Incident Response | ||
| Tool to hide messages in files (website down since 2004) | Steganography | ||
| CLI used to build Red Teaming infrastructure in an automated way, supports AWS and Digital Ocean | Red Teaming | ||
| Turn a Rapsberry Pi Zero W into a flexible, low-cost platform for pentesting, red teaming or PE. | Auth & perms | ||
| A collection of utilities developed to aid in analysis of password lists in order to enhance password cracking through pattern detection of masks, rules, character-sets and other password characteristics | Cracking | ||
| Platform for architecture-neutral dynamic analysis | Reverse Engineering | ||
| Fuzzing framework aiming at combining various software testing techniques within the same workflow to perform collaborative fuzzing also called ensemble fuzzing; supported engines are Honggfuzz, AFL++, TritonDSE | Reverse Engineering | ||
| No-root network monitor, firewall and PCAP dumper for Android. | Operating systems | ||
| This tool extracts secrets from a pcap file or from a live interface. | Informations gathering | ||
| Windows disassembler | Reverse Engineering | ||
| PE viewer, closed source and windows only | Reverse Engineering | ||
| Privilege Escalation Awesome Scripts SUITE; winPEAS and linPEAS are local privilege escalation scripts for Windows and Linux | System Exploitation | ||
| Privilege Escalation Awesome Scripts SUITE. | Operating systems | ||
| Python Exploit Development Assistance, (only python2.7) | Plugins | ||
| Shellcode & PE Packer | Red Teaming | ||
| PHP unserialize() payloads along with a tool to generate them. | Development | ||
| PHP Generic Gadget Chains, library of unserialize() payloads along with a tool to generate them, supporting various PHP frameworks | Web Application Exploitation | ||
| Reverse engineering tool for linux games. | Informations gathering | ||
| Web browser loaded with links and extensions for doing OSINT | OSINT and Reconnaissance | ||
| Kerberos PKINIT and relaying to AD CS | Networking | ||
| Suite of tools to work with PNG images | Steganography | ||
| A port scanner written purely in PowerShell. | Informations gathering | ||
| Bypass for PowerShell Constrained Language Mode. | Development | ||
| AD CS auditing based on the PSPKI toolkit | Networking | ||
| PenTests, Audits, and Reporting Tool; Collaborative penetration test, vulnerability database and reporting platform; fork of Sh00t | Collaboration and Report | ||
| Service to check if an account has been compromised in a data breach, doesn't display breaches, partially display password | Other | ||
| Packet manipulation library; forge, send, decode, capture packets of a wide number of protocols | Networking | ||
| PCAP analyzer; using Bro, Suricata and Elasticsearch | Networking | ||
| Stealthy Data exfiltration via DNS, without the need for attacker-controlled Name Servers or domain | Networking | ||
| The exploitation framework designed for testing the security of AWS environments. | Cloud & services | ||
| AWS exploitation framework | Cloud | ||
| Analysis framework that discovers if a file is suspicious and conveniently show the results | Defensive | ||
| Detect and remove malware from USB disks (based on Pandora) | Defensive | ||
| Automatic LFI and Path Traversal exploitation tool | Web Application Exploitation | ||
| Proxy Attack Proxy ProxY, HTTP intercepting proxy | Web Application Exploitation | ||
| This tool for brute discover GET and POST parameters. | Informations gathering | ||
| Mining parameters from dark corners of Web Archives. | Informations gathering | ||
| Finds parameters from web archives of the entered domain | Web Application Exploitation | ||
| Intercepting proxy to replay, inject, scan and fuzz HTTP requests | Web Application Exploitation | ||
| HTTP(S) proxy for assessing web application vulnerability. | Bug bounty | ||
| The ultimate framework for your cyber security operations. | Network | ||
| Robots.txt audit tool. | Auth & perms | ||
| CLI & library to search for default credentials among thousands of Products / Vendors | Other | ||
| Multi-protocol bruteforce tool | Networking | ||
| Multi-purpose brute-forcer, with a modular design and a flexible usage. | Informations gathering | ||
| Security operations orchestration and continuous threat management platform | Collaboration and Report | ||
| Provides a unified source of vulnerability, exploit and threat Intelligence feeds; comprehensive and continuously updated vulnerability database scored and enriched with exploit and threat news information | Threat Intelligence | ||
| Tool to generate stable undetected payload. | Auth & perms | ||
| A list of useful payloads and bypass for Web Application Security. | Auth & perms | ||
| Visualize a packet capture offline as a network diagram including device identification. | Auth & perms | ||
| PE reverse tool: recognizes packers, fast disassembler, visualization of sections layout, selective comparing of two chosen PE files | Reverse Engineering | ||
| Pentest Collaboration and Reporting Tool! PeCoReT is designed to be a fully open-source collaboration platform tailored for pentest projects. | Collaboration and Report | ||
| Collaborative penetration test, vulnerability database and reporting platform | Collaboration and Report | ||
| Take screenshots of websites | Web Application Exploitation | ||
| Collaborative penetration test, vulnerability database and reporting platform | Collaboration and Report | ||
| Pentest Collaboration Framework - an opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing! | Collaboration and Report | ||
| Burp Suite extension for application pentest to write test cases and map flows and vulnerabilities. | Well known products | ||
| Pre-configured portable penetration testing environment for Windows, all-in-one box | Other | ||
| Collaborative penetration test between team members and end-clients, vulnerability database and reporting platform | Collaboration and Report | ||
| PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows. | Artificial Intelligence | ||
| Learn Web Penetration Testing: The Right Way. | Resources | ||
| Sharing knowledge that makes your life as bug hunters and pentesters easier. | Bug bounty | ||
| Hunt persistences implanted in Windows machines. | Auth & perms | ||
| An SSL enabled basic auth credential harvester with a Word document template URL injector. | Auth & perms | ||
| Phishing catcher using Certstream. | Informations gathering | ||
| Information gathering framework for phone numbers. | Informations gathering | ||
| Remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session | Mobile | ||
| Remotely exploit Android devices using ADB and Metasploit. | Operating systems | ||
| Incredibly fast crawler designed for OSINT. | Informations gathering | ||
| Fast crawler designed for OSINT | OSINT and Reconnaissance | ||
| OSINT tool allowing you to find various information via a phone number. | Informations gathering | ||
| Assess the Active Directory security level with a methodology based on risk assessment | Configuration Audit | ||
| Crawl JavaScript file to find secret | Web Application Exploitation | ||
| Analyze password dump and return statistics about passwords' strength | Other | ||
| Shows detailed information about named pipes in Windows and searching for insecure permissions | Red Teaming | ||
| A tool that shows detailed information about named pipes in Windows. | Operating systems | ||
| Tool for breaking PkZip encryption | Cryptography | ||
| x86/ARM/MIPS interactive disassembler | Reverse Engineering | ||
| Collaborative penetration test reporting and vulnerability database platform | Collaboration and Report | ||
| Creates reports for blue and purple teams by extracting data from BloodHound | System Exploitation | ||
| The Email OSINT tool. | Informations gathering | ||
| Collaborative penetration test and reporting platform (DB + clients, no WebUI) | Collaboration and Report | ||
| Real-time network packet manipulation framework | Networking | ||
| Send emails from your terminal. | Informations gathering | ||
| The most comprehensive Postman recon / OSINT client and framework. | Informations gathering | ||
| A TCP port redirection utility that allows inbound traffic redirection. | Network | ||
| All the XSS cheatsheet data to allow contributions from the community. | Vulnerabilities | ||
| Free, online web security training from the creators of Burp Suite. | Resources | ||
| Javascript expression evaluator and inspector | Web Application Exploitation | ||
| Proxy aware Command & Control framework | Red Teaming | ||
| A proxy aware C2 framework used to aid with post-exploitation and lateral movement. | Auth & perms | ||
| A PostMessage fuzzing extension for Chrome. | Vulnerabilities | ||
| Audit script to inventory, analyze, and report excessive privileges assigned to SMB shares on Active Directory domain joined computers | Networking | ||
| Powershell payload generator In Bash ! | Development | ||
| A small library of powershell scripts for post exploitation that you may need or use! | Auth & perms | ||
| Searches for publicly available files hosted on various websites for a particular domain. | Informations gathering | ||
| Run PowerShell with dlls only to bypass software restrictions; it can be run with rundll32.exe, installutil.exe, regsvcs.exe, regasm.exe, regsvr32.exe or as a standalone executable | Red Teaming | ||
| Run PowerShell with rundll32 in order to bypass software restrictions. | Development | ||
| Password spraying script and helper for creating password lists | Cracking | ||
| A PowerShell Post-Exploitation Framework. | Auth & perms | ||
| Powershell exploitation framework | System Exploitation | ||
| Toolkit for attacking MS SQL Server, discovery, configuration auditing, privilege escalation, post exploitation | Web Application Exploitation | ||
| A PowerShell toolkit for attacking SQL Server. | Auth & perms | ||
| A Windows privilege escalation enumeration BAT script designed for legacy Windows machines without Powershell | System Exploitation | ||
| PowerShell MachineAccountQuota and DNS exploit tools. | Auth & perms | ||
| The perils of the pre-Windows 2000 compatible access group in a Windows domain. | Auth & perms | ||
| Automate the process of generating various reverse shells. | Auth & perms | ||
| Report generation tool for pentester with provided OWASP data | Collaboration and Report | ||
| Allow users to route Internet traffic through Tor and hide their real IP address. | Informations gathering | ||
| Monitor, collect and continuously query the assets data via a simple webUI | OSINT and Reconnaissance | ||
| Multi-Packer wrapper allowing daisy-chaining various packers and obfuscators; featured with artifacts watermarking, IOCs collection & PE backdooring | Red Teaming | ||
| Open Source Security tool to perform Cloud Security best practices | Cloud & services | ||
| A PowerShell tool heavily inspired by the popular tool CrackMapExec/NetExec. | Auth & perms | ||
| Unprivileged Linux process snooping. | Auth & perms | ||
| CTI platform to search, scan, and enrich IPs, URLs, domains and other IOCs from OSINT feeds or submit your own | Threat Intelligence | ||
| Official CLI utility for Subdomain Center & Exploit Observer. | Auth & perms | ||
| Cross-platform, multi function Command & Control and post-exploitation framework; fileless/all-in-memory execution, low footprint, multi-transport | Red Teaming | ||
| An open-source self-hosted purple team management web application. | Collaboration and Report | ||
| Collaborative penetration test reporting platform | Collaboration and Report | ||
| Pentest report generator. | Bug bounty | ||
| Collaborative penetration test reporting platform; fork and improvement of PwnDoc | Collaboration and Report | ||
| A Firefox/Burp Suite extension that provide usefull tools for your security audit. | Well known products | ||
| Allow to have multiple identities in the same browser using firefox containers and hightlight the profile used with different colors | Plugins | ||
| Command execution exploiter with an auto connection handling. | Auth & perms | ||
| Enhance GDB, for exploit development and reverse engineering | Plugins | ||
| Bypass client-side encryption using custom logic for testing with Python and NodeJS. | Cryptanalysis | ||
| Set as many exfiltration, techniques that CAN be used to bypass various. | Network | ||
| Multiplatform Python webshell. | Vulnerabilities | ||
| WSUS server designed to send malicious responses to clients | Networking | ||
| Persistent and stealthy backdooring of user and computer Active Directory objects | Networking | ||
| Search the web for files on a domain to download and extract metadata. | Informations gathering | ||
| The famous WPA precomputed cracker. | Network | ||
| A dependency vulnerability scanner for your python projects, straight from the terminal. | Development | ||
| Python Code Audit - A modern Python source code analyzer based on distrust. Python Code Audit is a tool to find security weaknesses in Python code. This static application security testing (SAST) tool has great features to simplify the necessary security tasks and make it fun and easy. This tool is designed for anyone who uses or creates Python programs and wants to understand and mitigate potential security risks. This tool is created for: Python Users who want to assess the security risks in the Python code they use. Python Developers: Anyone, from professionals to hobbyists, who wants to deliver secure Python code. Security-Conscious Users: People seeking a simple, fast way to gain insight into potential security vulnerabilities within Python packages or files. Creating secure software can be challenging. This tool, with its comprehensive documentation, acts as your helpful security colleague, making it easier to identify and address vulnerabilities. | Code Analysis | ||
| Android APK vulnerability analyzer | Code Analysis | ||
| Experimental binary diffing tool addressing the diffing as a aetwork alignement quadratic problem. | Auth & perms | ||
| Communicate with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames | Wireless | ||
| Timeless debugger (QIRA = QEMU Interactive Runtime Analyser) | Reverse Engineering | ||
| A comprehensive approach to the vulnerability analysis of Android application. | Informations gathering | ||
| The revolutionary architecture that powers Qualys' IT, security, and compliance cloud apps. | Bug bounty | ||
| Remote Administration Tool (RAT) for Windows | Red Teaming | ||
| Remote administration tool for Windows. | Operating systems | ||
| Point-and-click tool for producing advanced clickjacking and frame-slicing attacks. | Vulnerabilities | ||
| Unauthenticated enumeration of cloud principals | Cloud | ||
| The first ever CLI based menu-driven web application B-Tier recon framework. | Auth & perms | ||
| ActionScript disassembler | Reverse Engineering | ||
| Identify technologies and services used by domains through their DNS footprints. | Informations gathering | ||
| Enumerates users based off RDP Screenshots. | Informations gathering | ||
| All in one tool for information gathering, vulnerability scanning and crawling. | Informations gathering | ||
| A stateful fuzzing tool for automatically testing cloud services through their REST APIs. | Development | ||
| Enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities through wordlist and bruteforce strategies | Networking | ||
| Framework for ROP exploitation | Binary Exploitation | ||
| Tool to calculate RSA parameters | Cryptography | ||
| RSA attack and key manipulation tool | Cryptography | ||
| CLI tool and library allowing to simply decode all kind of BigIP cookies | Web Application Exploitation | ||
| A high performance offensive security tool for reconnaissance and vulnerability scanning. | Informations gathering | ||
| Tests for race conditions in web applications. | Development | ||
| Race Condition framework. | Vulnerabilities | ||
| Scan nearby devices and execute command when the target device comes in between range. | Network | ||
| It crack hashes with rainbow tables. | Informations gathering | ||
| The multi tool web vulnerability scanner. | Vulnerabilities | ||
| Flutter reverse engineering framework: allow traffic monitoring and interception, print classes and functions, display absolute code offset for functions, etc. | Reverse Engineering | ||
| Implements a brute force attack against Wifi Protected Setup (WPS) registrar PINs. | Informations gathering | ||
| Implement the multiple A record DNS rebinding attack. | Informations gathering | ||
| Implements multiple A record DNS rebinding attack | Networking | ||
| Edit Java bytecode, insert single line Java statements into the bytecode, recompile decompiled code | Reverse Engineering | ||
| Web-based reconnaissance tool | OSINT and Reconnaissance | ||
| OSINT tool aimed at reducing the time spent harvesting information from open sources. | Informations gathering | ||
| Multi-purpose reconnaissance tool, CMS detection, reverse IP lookup, port scan, etc. | OSINT and Reconnaissance | ||
| Continuous recon and pipeline tools setup. | Auth & perms | ||
| Network reconnaissance and vulnerability assessment tools | OSINT and Reconnaissance | ||
| Reconmap is an open-source penetration testing and report generation tool for Infosec teams that uses templating, automation and machine learning to streamline the delivery of security projects. | Collaboration and Report | ||
| Tool made to automate information gathering and service enumeration while storing results | OSINT and Reconnaissance | ||
| Web reconnaissance and vulnerability scanner tool | OSINT and Reconnaissance | ||
| Rapid content discovery tool for recursively querying webservers. | Informations gathering | ||
| Automated reconnaissance scanner and security checks | OSINT and Reconnaissance | ||
| Red Team's SIEM; used by Red Teams for tracking and alarming about Blue Team activities as well as better usability in long term operations | Red Teaming | ||
| Tool for Red Teams used for tracking and alarming about Blue Team activities. | Auth & perms | ||
| Red team C2 log visualization | Red Teaming | ||
| RedEye is a visual analytic tool supporting Red & Blue Team operations. | Auth & perms | ||
| Virtual machine for adversary emulation and threat hunting. | Virtualization | ||
| Retrieves hashes and credentials from Windows workstations, servers and domain controllers using OpSec Safe Techniques | System Exploitation | ||
| Open source Django offensive webapp which is keeping the best tools used in the redteaming. | Bug bounty | ||
| Enhance the security and confidentiality of HTTP request handling within the Burp Suite. | Network | ||
| Automated Red Team Infrastructure deployment using Docker | Red Teaming | ||
| Track the HTTP redirect chains; 301 and 302, JavaScript and Meta fresh redirects | Threat Intelligence | ||
| Mix of a security operations orchestration, vulnerability management and reconnaissance platform | OSINT and Reconnaissance | ||
| Real time phishing tool | Red Teaming | ||
| RegStrike is a .reg payload generator. | Cryptanalysis | ||
| Execute full pentesting processes combining multiple hacking tools automatically. | Cloud & services | ||
| x86 and ARM graphical interactive disassembler with Ruby plugin framework | Reverse Engineering | ||
| Automated reconnaissance framework for webapps, highly configurable streamlined recon process. | Informations gathering | ||
| Burp Suite extension to help developers replicate findings from pentests. | Bug bounty | ||
| Collaborative penetration test reporting platform | Collaboration and Report | ||
| Burp Suite extension that automatically highlights different HTTP requests. | Network | ||
| HTTP request collector and inspector | Web Application Exploitation | ||
| HTTP request collector and inspector | Web Application Exploitation | ||
| HTTP request collector and inspector | Web Application Exploitation | ||
| Exploit race conditions in web apps with Requests. | Vulnerabilities | ||
| Scans dll/ocx/exe files and extract all resources found, Windows only | Digital Forensics | ||
| Responder is a LLMNR, NBT-NS and MDNS poisoner. | Informations gathering | ||
| LLMNR, NBT-NS and MDNS poisoner to intercept authentication requests/answers | Networking | ||
| Multi file formats and architectures machine-code decompiler | Reverse Engineering | ||
| Detects the use of JavaScript libraries with known vulnerabilities. | Development | ||
| Scanner detecting the use of JavaScript libraries with known vulnerabilities | Web Application Exploitation | ||
| Hosted Reverse Shell generator with a ton of functionality. | Vulnerabilities | ||
| Web-based reverse shell generator, includes features such as listener generation, raw mode, bind shell generation, msfvenom generation, payload encoding, many different languages, tools and shells supported | Other | ||
| A tool to generate various ways to do a reverse shell. | Vulnerabilities | ||
| A dynamic reverse engineering toolkit. | Informations gathering | ||
| Enumerate usernames on a domain where you have no creds by using SMB relay. | Auth & perms | ||
| All in one recon tool that just get a single domain name and do all of the work alone. | Informations gathering | ||
| A malicious LDAP server for JNDI injection attacks | Web Application Exploitation | ||
| A free and open source Ruby toolkit for security research and development. | Informations gathering | ||
| Toolkit for security research and development allowing for the rapid development and distribution of code, exploits, payloads, etc, via 3rd party git repositories | Other | ||
| Scans for rootkits, backdoors and possible local exploits. | Operating systems | ||
| Exploitation framework for embedded devices. | Informations gathering | ||
| Exploitation framework for embedded devices: exploits, default credentials, scanners, payloads | Networking | ||
| Tool to conduct manual or automated attack on RSA | Cryptography | ||
| RSA multi-attacks tool: uncypher data from a weak public key and try to recover a private key. | Cryptanalysis | ||
| Kerberos interaction and abuses | Networking | ||
| Rubeus is a toolkit for Kerberos interaction and abuses. | Auth & perms | ||
| Command line wrapper, library, and REST API for oclHashcat | Cracking | ||
| Interact with Exchange servers remotely, through either the MAPI/HTTP or RPC/HTTP to abuse the client-side Outlook features and gain a shell | Red Teaming | ||
| A powerful web interface that helps you to manipulate Android and iOS Apps at Runtime. | Operating systems | ||
| Active Directory data collector for BloodHound written in Rust. | Auth & perms | ||
| Active Directory data collector for BloodHound | Networking | ||
| The Modern Port Scanner. Fast, smart, effective. | Informations gathering | ||
| Port and reverse shell listener; less features than ncat, pwncat, pwncat-caleb but has command history | Networking | ||
| A suite of secret scanners built in Rust for performance. | Cloud & services | ||
| Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files. | Cloud & services | ||
| Firefox plugin that lists Amazon S3 Buckets found in requests. | Cloud & services | ||
| All-in-one AWS S3 bucket tool. | Cloud & services | ||
| Scan for open S3 buckets and dump the contents. | Cloud & services | ||
| Publicly open storage viewer. | Cloud & services | ||
| SBOM parser that performs cursory vulnerability assessment. | Auth & perms | ||
| Streamline identifying, profiling, and attacking SCCM related assets in an Active Directory domain | Networking | ||
| Sandia Cyber Omni Tracker; cyber security incident response management system and knowledge base | Incident Response | ||
| Fileless lateral movement that relies on ChangeServiceConfigA to run commands | System Exploitation | ||
| Smart DNS Brute Forcer. | Informations gathering | ||
| Web-based platform for the automation of infosec watching and vulnerability management | Vulnerability Assessment | ||
| Modular C2 framework designed to successfully operate covertly on heavily monitored environments | Red Teaming | ||
| Stego Helper Identification Tool, multi-purpose image steganography tool | Steganography | ||
| Asynchronous, multiplayer and multiserver Command & Control framework | Red Teaming | ||
| Find secrets in file and secret files among the SMB target shares. | Auth & perms | ||
| Fileshare auditing tool. | Network | ||
| Attack clients through file content swapping and compromise any data passed in cleartext. | Vulnerabilities | ||
| Offensive tool to scan & exploit vulnerabilities in Windows over SMB using Metasploit. | Well known products | ||
| SNMP brute force, enumeration, CISCO config downloader and password cracking script | Networking | ||
| Enumerate Active Directory environments via the Active Directory Web Services (ADWS) protocol. | Auth & perms | ||
| Searches for automated subdomain enumeration and runs SQLi tests. | Informations gathering | ||
| A C# MS-SQL toolkit designed for offensive reconnaissance and post-exploitation. | Cloud & services | ||
| Messy BurpSuite plugin for SQL Truncation vulnerabilities. | Vulnerabilities | ||
| Simple HTTP(S) proxy server and a SQLMAP API wrapper that makes digging SQLi easy. | Development | ||
| Helps you to detect SQL injection "Error based" by sending multiple requests. | Vulnerabilities | ||
| Automatic SQL injection with Charles and sqlmap API. | Vulnerabilities | ||
| SQL injection scanner, find vulnerable entry points | Web Application Exploitation | ||
| Massive SQL injection vulnerability scanner. | Vulnerabilities | ||
| Exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server. | Vulnerabilities | ||
| A wrapper script which uses PuTTY to perform SSH login bruteforce attacks. | Informations gathering | ||
| Fast and powerful SSL/TLS scanning library. | Cryptanalysis | ||
| SSL analysis library and a CLI tools | Web Application Exploitation | ||
| Server-side request forgery detector. | Vulnerabilities | ||
| Facilitates tunneling HTTP communications through servers vulnerable to SSRF | Web Application Exploitation | ||
| Genereate custom endpoint to test SSRF; support any HTTP method, content-specific responses, configurable secret token | Web Application Exploitation | ||
| A simple SSRF-testing sheriff written in Go. | Vulnerabilities | ||
| Checks for SSRF using custom payloads after fetching URLs from sources & applying complex patterns. | Vulnerabilities | ||
| SSRF testing tool. | Vulnerabilities | ||
| An automated SSRF finder. Just give the domain name and your server and chill! | Vulnerabilities | ||
| Automatic SSRF fuzzer and exploitation tool | Web Application Exploitation | ||
| Automatic SSRF fuzzer and exploitation tool. | Vulnerabilities | ||
| Automatic SSTI detection tool with interactive interface. | Vulnerabilities | ||
| Security Testing and Enumeration of WebSockets; tool suite for security testing WebSockets: discover endpoints, fingerprint server, detect vulnerabilities | Web Application Exploitation | ||
| A tool to identify and exploit sudo rules misconfigurations and vulnerabilities. | Auth & perms | ||
| Standalone script to enumerate SUID binaries, separate default binaries from customs. | Auth & perms | ||
| Android APK vulnerability analyzer | Code Analysis | ||
| Be notified when your favorite tool may be at risk. | Cloud & services | ||
| A self-hosted WAF to protect web applications from cyber attacks. | Auth & perms | ||
| The best security training environment for developers and AppSec professionals. | Resources | ||
| A Python script for AWS S3 bucket enumeration. | Cloud & services | ||
| Binary authorization system for macOS | Defensive | ||
| Grab target's webcam shots by link. | Informations gathering | ||
| Improved version of SayCheese, designed to capture images via social engineering. | Informations gathering | ||
| Combines the speed of masscan with the reliability and detailed enumeration of nmap. | Informations gathering | ||
| Packet manipulation library; forge, send, decode, capture packets of a wide number of protocols | Networking | ||
| Powerful and interactive packet manipulation program and library. | Network | ||
| Payload creation framework designed around EDR bypass | Red Teaming | ||
| Payload creation framework designed around EDR bypass. | Auth & perms | ||
| Create target specific and tailored wordlist from burp history | Plugins | ||
| Burp Suite extension to create target specific and tailored wordlist from burp history. | Resources | ||
| Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration. | Informations gathering | ||
| Command-line tool for finding in-scope targets for bug bounty programs. | Bug bounty | ||
| A Go tool for scope management. | Bug bounty | ||
| Netify.ai reconnaissance tool. | Cloud & services | ||
| Discover a web server's undisclosed files, directories and VHOSTs. | Informations gathering | ||
| Web directory and file scanner (wordlist bruteforce) | Web Application Exploitation | ||
| Multi-cloud security auditing tool. | Cloud & services | ||
| Harvest employee email addresses from a specific company through LinkedIn. | Informations gathering | ||
| Scrape LinkedIn without API restrictions for data reconnaissance. | Cloud & services | ||
| Convert your masscan/subdomain-scan results into screenshots for better analysis. | Informations gathering | ||
| Makes web screenshots and mobile emulations from the command line. | Informations gathering | ||
| ScriptSentry finds misconfigured and dangerous logon scripts. | Auth & perms | ||
| Mobile application testing toolkit, the mobile metasploit-like framework | Mobile | ||
| Collects RDP, web and VNC screenshots all in one place. | Informations gathering | ||
| Perform periodic syncs of data sources and performing analysis on the identified results. | Informations gathering | ||
| Netcraft tool; Search and find information for domains and subdomains | OSINT and Reconnaissance | ||
| Cli tool for Exploit-DB that also allows you to take a copy of Exploit Database with you. | Auth & perms | ||
| CLI tool to search among Exploit-DB exploits | System Exploitation | ||
| Performs security oriented safety checks relevant from offensive/defensive security perspectives. | Auth & perms | ||
| Create randomly insecure VMs. | Resources | ||
| Collection of multiple types of lists used during security assessments, collected in one place. | Informations gathering | ||
| Vulnerability scanning, reporting and analysis | Vulnerabilities | ||
| Second-order subdomain takeover scanner. | Informations gathering | ||
| SecretFinder is a script based on LinkFinder, written to find sensitive data in JavaScript files. | Development | ||
| Secret Detection Tool. | Source code management | ||
| Find secrets and passwords in container images and file systems. | Virtualization | ||
| Monitor AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time. | Cloud & services | ||
| Security Headers is a part of Snyk, a leading cybersecurity company, and was originally created by Scott Helme! It is a free and easy to use tool designed to help you better deploy and understand modern security features that are available for your website. Snyk is a comprehensive developer security platform that enables developers to secure their code, open source dependencies, container images, cloud infrastructures, as well as web apps and APIs, all from a single unified platform. There are services out there that will analyse the HTTP response headers of other sites, but we also have a grading system for results. The HTTP response headers that we analyse provide huge levels of protection, and it's important that sites deploy them. Hopefully, by providing an easy mechanism to assess them, and further information on how to deploy missing headers, we can drive up the usage of security based headers across the Web. | Web Application Exploitation | ||
| Open-source security skills for AI coding agents. Grounded in OWASP, NIST, MITRE ATT&CK, CIS. Works with Claude Code, Gemini CLI, Cursor, Codex CLI, OpenClaw, Kiro. | AI Skills | ||
| Data for Security companies, researchers and teams. | Informations gathering | ||
| Detect Vulnerable SSRF parameters. | Informations gathering | ||
| SSRF scanner to find entry points | Web Application Exploitation | ||
| Boost the cybersecurity skills of your teams with the cyber knowledge library. | Resources | ||
| Lightweight static analysis for many languages. Find bug variants with patterns that look like source code. | Code Analysis | ||
| SimplE RePort wrIting and CollaboratiOn tool, penetration testing report generation and collaboration tool | Collaboration and Report | ||
| SimplE RePort wrIting and CollaboratiOn tool NEXT-GENERATION, penetration testing report generation and collaboration tool, fork of Serpico | Collaboration and Report | ||
| Hijack user sessions by injecting malicious JavaScript code | Web Application Exploitation | ||
| Evaluate user privileges in web applications across a list of URLs. | Auth & perms | ||
| RDP MitM tool | Networking | ||
| The analyst console for network security monitoring. | Auth & perms | ||
| Pentesting platform with dynamic task manager, checklists, bug template & bug report | Collaboration and Report | ||
| C2 and proxy designed to help in the exploitation of XSS and malicious Service Workers. | Vulnerabilities | ||
| Spray shadow credentials across an entire domain. | Informations gathering | ||
| GraphQL schema extraction to JSON file with introspection | Web Application Exploitation | ||
| GraphQL security testing tool. | Databases | ||
| Windows persistence toolkit written in C#. | Operating systems | ||
| Command & Control framework | Red Teaming | ||
| Command and Control Framework written in C#. | Development | ||
| Extracts cookies from Chrome. | Development | ||
| Detect and identify the presence of known defensive products such as AV's, EDR's and logging tools | Red Teaming | ||
| Asynchronous password spraying tool for Windows environments. | Auth & perms | ||
| A User Impersonation tool - via Token or Shellcode injection. | Operating systems | ||
| A post-exploitation tool designed to leverage Microsoft Endpoint Configuration Manager. | Auth & perms | ||
| Payload Generation Framework for C# source code | System Exploitation | ||
| Automatically create cheat sheets from all relevant vectors on the system. | Vulnerabilities | ||
| Tool to craft bind and reverse shells in several languages | System Exploitation | ||
| Pop shells like a master. | Auth & perms | ||
| A QoL tool to obfuscate shellcode. | Cryptanalysis | ||
| Obfuscate shellcode using encoding, encryption, compression | Red Teaming | ||
| A comprehensive OS command injection payload generator. | Vulnerabilities | ||
| A script for generating common revshells fast and easily. | Vulnerabilities | ||
| A technique to hide malicious shellcode based on low-entropy via Shannon encoding | Red Teaming | ||
| Hunt down social media accounts by username across social networks. | Informations gathering | ||
| Hunt down social media accounts by username across social networks | OSINT and Reconnaissance | ||
| Search engine for Internet-connected devices. | Informations gathering | ||
| Search devices connected to the internet; helps find information about desktops, servers, IoT devices; including metadata such as the software running | OSINT and Reconnaissance | ||
| Find sensitive data inside the screenshots uploaded to prnt.sc. | Informations gathering | ||
| Dowgrade, convert, dissect and shuck authentication token based on Data Encryption Standard. | Auth & perms | ||
| Advanced exploit search tool designed to identify and gather information about exploits. | Auth & perms | ||
| System for Internet-Level Knowledge; collection of traffic analysis tools developed to facilitate security analysis of large networks | Networking | ||
| Generic signature format for SIEM systems | Incident Response | ||
| Quietly enumerates an Active Directory Domain via LDAP parsing users, admins, groups | Networking | ||
| Simple Malware Scanner based on file hash scan. | Auth & perms | ||
| LFI exploit tool | Web Application Exploitation | ||
| Email recon made fast and easy, with a framework to build on. | Informations gathering | ||
| DNS rebinding attack framework | Networking | ||
| Truly open-source general purpose vulnerability scanner. | Auth & perms | ||
| Web application security scanner, rewrite and newer version of WAScan | Web Application Exploitation | ||
| Tool for information gathering and penetration test automation | OSINT and Reconnaissance | ||
| Utility for information gathering and penetration testing automation. | Cloud & services | ||
| Dangerously fast DNS/network/port scanner. | Informations gathering | ||
| A security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. Combines pattern-based detection (YAML + YARA), LLM-as-a-judge, and behavioral dataflow analysis for comprehensive threat detection. Supports OpenAI Codex Skills and Cursor Agent Skills formats following the Agent Skills specification. | AI Skills | ||
| Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks. | AI Skills | ||
| Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows | AI Skills | ||
| Monitoring your Slack workspaces for sensitive informations. | Informations gathering | ||
| Sleepy Puppy XSS Payload Management Framework. | Vulnerabilities | ||
| Tool that parses Burp history to discover potential SQL injection points and prepare SQLmap request files | Web Application Exploitation | ||
| Burp History parsing tool to discover potential SQL injection points. | Vulnerabilities | ||
| Cross-platform adversary emulation/red team framework used by organizations of all sizes to perform security testing | Adversary Simulation | ||
| Cross-platform implant framework that supports C2 over Mutual-TLS, HTTP(S), and DNS; remote access tool (RAT) | Red Teaming | ||
| A blazing fast & feature rich Amazon S3 bucket enumerator. | Cloud & services | ||
| To to restore defocused and blurred images (update binary only for Windows, Mac OS binary out of date) | Steganography | ||
| Pentest oriented collaborative tool used to track the progress of your company's engagements and generate reports | Collaboration and Report | ||
| System Management Mode (SMM) backdoor for UEFI based platforms | Hardware | ||
| Find cloud assets that no one wants exposed. | Cloud & services | ||
| Identify AWS cloud assets | Cloud | ||
| A rapid HTTP downgrade smuggling scanner written in Go. | Vulnerabilities | ||
| An HTTP Request Smuggling / Desync testing tool. | Vulnerabilities | ||
| HTTP request smuggling, desync testing | Web Application Exploitation | ||
| Automated reconnaissance scanner | OSINT and Reconnaissance | ||
| Attack Surface Management Platform. | Auth & perms | ||
| A tool to help at finding delicious candy needles in a bunch of horrible boring haystacks. | Auth & perms | ||
| Find credentials and valuable information from windows active directory environments (shares, files) | Networking | ||
| Pastebin OSINT harvester. | Informations gathering | ||
| A framework for wireless pentesting. | Network | ||
| Intrusion detection system that monitors network traffic for suspicious activities and threats | Networking | ||
| Native code to C/C++ decompiler, supporting x86, AMD64, and ARM architectures, exists as standalone app or as a plug-in | Reverse Engineering | ||
| A social media enumeration & correlation tool. | Informations gathering | ||
| Phishing targeting social media logins; supports Ngrok tunneling and a mobile controller | Red Teaming | ||
| Allows to get the emails from a target published in social networks to find possible credentials. | Cloud & services | ||
| Automatic code review tool to detect bugs, vulnerabilities; continuous code inspection automated with static code analysis rules | Code Analysis | ||
| A rapid API for the project Sonar dataset. | Informations gathering | ||
| Tool to edit and analyze audio tracks | Steganography | ||
| The next generation Snort Intrusion Prevention System. | Informations gathering | ||
| Search millions of open source repositories. | Informations gathering | ||
| Automates OSINT for threat intelligence and mapping your attack surface. | Informations gathering | ||
| Advanced web spider/crawler for cyber security professionals. | Auth & perms | ||
| Maltego penetration testing Transforms | Plugins | ||
| Exploits & tools search engine. | Auth & perms | ||
| The unified security and observability platform. | Cloud & services | ||
| Checks if a list of domains can be spoofed based on SPF and DMARC records. | Informations gathering | ||
| Collection of Windows print spooler exploits and other utilities for practical exploitation. | Auth & perms | ||
| Fast multithreaded password spraying tool with backend database. | Informations gathering | ||
| Password spraying in Active Directory checking the default domain password policy and the badpwdcount LDAP attribute to avoid account locking, set pwned users as owned in Bloodhound and detect path to Domain Admins | Networking | ||
| Permutation-based password list generator | Cracking | ||
| Password spraying scripts for Lync/S4B and OWA | Other | ||
| This Chrome extension will read literally everything it can. | Development | ||
| Time-based blind SQL injection fuzzer for HTTP headers | Web Application Exploitation | ||
| Lets you use Burp Collaborator as a DNS server for exfiltrating data via Sqlmap. | Well known products | ||
| Builds a static reverse SSH server for pivoting; supports HTTP and SOCKS5 proxies, DNS and ICMP tunnelling, HTTP encapsulation | Networking | ||
| Reverse shell based on sshd supporting DNS and ICMP tunnelling as well as HTTP and Socks proxies. | Network | ||
| Crossplatform tool which help to perform static code analysis on mobile applications. | Informations gathering | ||
| Mobile applications static code analysis tool | Code Analysis | ||
| Automated scanning of social networks and other websites, using a single nickname | OSINT and Reconnaissance | ||
| WebUI for Empire | Red Teaming | ||
| Starkiller is a frontend for Empire. | Auth & perms | ||
| Stego image toolsuite in the browser | Steganography | ||
| Desktop application used to analyze images in different planes by taking off bits of the image. | Steganography | ||
| Steganography analysis tool | Steganography | ||
| Tool to hide messages in images | Steganography | ||
| Automatic tool to bruteforce LSB, transform image, extract metadata or trailing data | Steganography | ||
| Evolution of Burp Suite's Repeater tool, providing the ability to create sequences of steps and define regular expressions to extract values from responses | Plugins | ||
| A natural evolution of Burp Suite's Repeater tool. | Well known products | ||
| Social engineering tool, access eebcam & microphone & location finder. | Informations gathering | ||
| Granular, actionable adversary emulation for the cloud. | Cloud & services | ||
| Stratus Red Team is 'Atomic Red Team' for the cloud, allowing to emulate offensive attack techniques in a granular and self-contained manner | Adversary Simulation | ||
| Offensive information and vulnerability scanner. | Informations gathering | ||
| A very (very) FAST and simple subdomain finder based on online & free services. | Informations gathering | ||
| A free, open source, cross platform Intelligence gathering tool. | Informations gathering | ||
| A DNS meta-query spider that enumerates DNS records, and subdomains. | Informations gathering | ||
| Find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github | OSINT and Reconnaissance | ||
| A tool to find subdomains and interesting things hidden inside. | Cloud & services | ||
| Find subdomains with GPT, for free. | Informations gathering | ||
| A Powerful Subdomain Takeover Tool. | Informations gathering | ||
| Perform subdomain enumeration through various techniques and retrieve detailed output. | Informations gathering | ||
| Find subdomains by searching public certificate records. | Informations gathering | ||
| Discovery tool that discovers valid subdomains for websites. | Informations gathering | ||
| Subdomain Takeover tool written in Go. | Vulnerabilities | ||
| Monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate. | Informations gathering | ||
| Fast subdomains enumeration tool for penetration testers. | Informations gathering | ||
| Subdomains enumeration tool | OSINT and Reconnaissance | ||
| A Web-UI for subdomain enumeration. | Informations gathering | ||
| Passive reconnaissance/enumeration of interesting targets by watching for SSL certificates. | Informations gathering | ||
| Collects subdomains and analyzes domains performing automated reconnaissance. | Informations gathering | ||
| Subdomain enumeration tool | OSINT and Reconnaissance | ||
| Real fucking shellcode encryptor & obfuscator tool. | Cryptanalysis | ||
| Escalate SSRF vulnerabilities on modern cloud environments, enumerate reachable hosts | Web Application Exploitation | ||
| Implementation of the Language Server Protocol for Suricata signatures; real-time rule syntax checking and auto-completion | Networking | ||
| Designed to assist with auditing of exposed Swagger/OpenAPI) definition files. | Informations gathering | ||
| A collection of various Windows privilege escalation techniques from service accounts to SYSTEM. | Auth & perms | ||
| Collection of utilities to work with SWF files | Reverse Engineering | ||
| Cross-platform note-taking and target-tracking app for penetration testers | Collaboration and Report | ||
| Consulting different intelligence services, search engines and datasets for OSINT. | Informations gathering | ||
| HTTP(S) server designed to assist in red teaming activities such as receiving intercepted data via POST requests and serving content dynamically | Red Teaming | ||
| Http(s) server designed to host resources dynamically or act as a receiver for POST data intercepts. | Network | ||
| Collaborative penetration test, vulnerability database and reporting platform; supports findings in markdown, customized reports in HTML and VueJS, rendering to PDF, MFA, note-taking, data encryption, SSO | Collaboration and Report | ||
| SysWhispers on Steroid, AV/EDR evasion via direct system calls | Red Teaming | ||
| AV/EDR evasion via direct system calls. | Operating systems | ||
| The all in one multi honeypot platform. | Virtualization | ||
| Telegram Explorer created to help researchers, investigators and law enforcement agent. | Bug bounty | ||
| The offensive manual web application penetration testing framework. | Informations gathering | ||
| Comprehensive web-app audit framework | Web Application Exploitation | ||
| TInjA is a CLI tool for testing web pages for template injection vulnerabilities. It supports 44 of the most relevant template engines (as of September 2023) for eight different programming languages. TInjA was developed by Hackmanit and Maximilian Hildebrand. | Web Application Exploitation | ||
| Scan all possible TLD's for a given domain name. | Informations gathering | ||
| Domain availability checker. | Informations gathering | ||
| CLI & library for mapping TLS cipher algorithm names: IANA, OpenSSL, GnUTLS, NSS | Web Application Exploitation | ||
| TLS-Attacker is a Java-based framework for analyzing TLS libraries. It is able to send arbitrary protocol messages in an arbitrary order to the TLS peer, and define their modifications using a provided interface. This gives the developer an opportunity to easily define a custom TLS protocol flow and test it against his TLS library. Please note: TLS-Attacker is a research tool intended for TLS developers and pentesters. There is no GUI and no green/red lights. | Cryptography | ||
| TLS-Scanner is a tool to assist pentesters and security researchers in the evaluation of TLS server and client configurations. | Cryptography | ||
| Help to exploit weak implementation of library or program that used TPM | System Exploitation | ||
| Bindings for Microsoft WinDBG Time Travel Debugging (TTD) | Reverse Engineering | ||
| Flexible and scriptable password dictionary/wordlist generator | Cracking | ||
| Twitter Intelligence Tool; Twitter scraping & OSINT tool that doesn't use Twitter's API, allowing one to scrape a user's followers, following, Tweets and more while evading most API limitations | OSINT and Reconnaissance | ||
| View and modify HTTP requests before they are sent. | Network | ||
| Allows you to intercept and edit HTTP/HTTPS requests and responses. | Network | ||
| MS Teams implant persistent backdoor | Red Teaming | ||
| Security tool to discover S3 buckets on Amazon's AWS platform. | Cloud & services | ||
| Leverage paste sites as a medium for discovery of objectionable/infringing materials | OSINT and Reconnaissance | ||
| CLI tool for testing web pages for template injection vulnerabilities. | Vulnerabilities | ||
| With the Template Injection Playground a large number of the most relevant template engines (as of September 2023) can be tested for template injection possibilities. For this purpose, simple web pages are provided, each of which uses one of the template engines. Furthermore, various optional security measures such as sandboxes, encodings, and denylists can be activated. The Template Injection Playground was developed by Hackmanit and Maximilian Hildebrand. | Intentionally Vulnerable Applications | ||
| The Template Injection Table is intended to help during the testing of an application for template injection vulnerabilities. It was developed by Hackmanit and Maximilian Hildebrand. The table consists of so-called "polyglots" that can be used to detect template injection possibilities and identify which template engine is used by an application. | Web Application Exploitation | ||
| Scan for top potential vulnerabilities with known CVEs in your web applications. | Vulnerabilities | ||
| Misconfiguration scanner for terraform code | Code Analysis | ||
| Multi-purpose information gathering tool | OSINT and Reconnaissance | ||
| All in one tool for Information Gathering. | Informations gathering | ||
| Archive of public exploits and corresponding vulnerable software. | Auth & perms | ||
| Differential testing and fuzzing of HTTP servers and proxies. | Network | ||
| The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools. | Virtualization | ||
| Open-source penetration testing framework designed for social engineering. | Informations gathering | ||
| Weaponizing WaybackUrls for recon, bug bounties, OSINT, sensitive endpoints and what not. | Informations gathering | ||
| A collection of wordlists for many different usages. | Resources | ||
| The XSS rat YouTube channel. | Resources | ||
| Master the command line, in one page. | Operating systems | ||
| Fuzz Cross-Origin Resource Sharing implementations for common misconfigurations. | Vulnerabilities | ||
| Post-exploitation tools to gather credentials from various password managers and Windows utilities. | Auth & perms | ||
| Windows event log file viewer and analyser | Incident Response | ||
| Extract and aggregate threat intelligence (IOCs from threat feeds) | Threat Intelligence | ||
| Knowledge base workflow management for YARA rules and C2 artifacts | Threat Intelligence | ||
| Identify vulnerabilities in running containers, images, hosts and repositories | Vulnerability Assessment | ||
| Open source cloud native security observability platform. Linux, K8s, AWS Fargate and more. | Bug bounty | ||
| Azure JWT token manipulation toolset. | Auth & perms | ||
| Escalate a Cross-Site Scripting vulnerability to Remote Code Execution in WordPress. | Vulnerabilities | ||
| Kali linux hacking tool installer | Other | ||
| Retrieve information about ads of a facebook page, retrieve the number of people targeted, how much the ad cost and a lot of other information | OSINT and Reconnaissance | ||
| Assists with finding all sinks and sources of a webapp and display the results in a nice way. | Well known products | ||
| Tool that help to manually find XSS | Web Application Exploitation | ||
| A packet sniffer tool, allows you to monitor and analyze network traffic from PCAP files. | Network | ||
| Understand how input is transformed on a system, which can help to craft payloads. | Cryptanalysis | ||
| Remove URLs with duplicate funcionality based on script resources included | Web Application Exploitation | ||
| Command and control framework masking the activity by emulating legitimate website | Red Teaming | ||
| A legitimate website that tunnels client/server communications for covert command execution. | Auth & perms | ||
| Burp Suite Extension to hunt for common vulnerabilities found in websites. | Well known products | ||
| A dynamic binary analysis library. | Informations gathering | ||
| Dynamic binary analysis framework, automate reverse engineering | Reverse Engineering | ||
| Triton-based DSE library with loading and exploration capabilities | Reverse Engineering | ||
| Vulnerability and misconfiguration scanner for containers (OS and language-specific packages) | Code Analysis | ||
| Find secret information in git repositories | OSINT and Reconnaissance | ||
| Hands-on cyber security training through real-world scenarios. | Resources | ||
| Network security scanner with an extensible plugin system | Networking | ||
| Subdomains enumeration tool for penetration testers. | Informations gathering | ||
| Burp Suite extension for sending large numbers of HTTP requests and analyzing the results. | Network | ||
| Subdomain enumeration tool with analysis features for discovered domains. | Informations gathering | ||
| Tunnels HTTP over a permissive/open TURN server; supports HTTP and SOCKS5 proxy | Networking | ||
| Identifying function names in stripped binaries and un-named functions | Reverse Engineering | ||
| Enumerate Typo3 version and extensions | Web Application Exploitation | ||
| HTTP botnet PoC | Red Teaming | ||
| Fast and lightweight UDP scanner that supports the discovery of many services. | Network | ||
| A JavaScript parser, minifier, compressor and beautifier toolkit. | Cryptanalysis | ||
| JavaScript obfuscator or beautifier toolkit | Reverse Engineering | ||
| Salesforce lightning recon and exploitation tool. | Cloud & services | ||
| An asynchronous TCP and UDP port scanner. | Informations gathering | ||
| RFI, LFi and RCE scanner | Web Application Exploitation | ||
| Never ever ever use pixelation as a redaction technique. | Cryptanalysis | ||
| Bypass Windows and Linux user passwords from a bootable USB based on Linux. | Operating systems | ||
| Simple HTTP listener for security testing. | Network | ||
| HTTP file upload scanner for Burp Proxy. | Vulnerabilities | ||
| Domain user enumeration tool. | Informations gathering | ||
| Web dork and vulnerability scanner | Web Application Exploitation | ||
| Vulnerable REST API with OWASP top 10 vulnerabilities for security testing | Intentionally Vulnerable Applications | ||
| VBScript minifier | Other | ||
| VBA obfuscation tools combined with an MS Office document generator . | Cryptanalysis | ||
| Virtual host scanner that performs reverse lookups. | Auth & perms | ||
| Windows only web application and REST API vulnerability scanner | Web Application Exploitation | ||
| Wrapper for the Vulnerability Rating Taxonomy | Vulnerability Assessment | ||
| SWF vulnerability and information scanner | Reverse Engineering | ||
| UI-based tool with multiple techniques for attacking and enumerating Azure and AWS environment. | Cloud & services | ||
| Tool designed for fetching, validating, and storing working proxies. | Network | ||
| Vulnerable REST API with OWASP top 10 vulnerabilities for security testing. | Resources | ||
| Multi-platform web scanner and intercepting proxy | Web Application Exploitation | ||
| Post exploitation tool to maintain some level of acces. | Auth & perms | ||
| Endpoint visibility and collection tool | Digital Forensics | ||
| Endpoint visibility and collection tool. | Informations gathering | ||
| Popular Pentesting scanner for SQLi/XSS/LFI/RFI and other Vulns. | Vulnerabilities | ||
| vRx by Vicarius offers real-time and automated patching, patchless protection, and script-based remediation across apps, OS, and third-party software. | Collaboration and Report | ||
| Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision Native Scan (vigolium scan): Fast, powerful, and flexible. Deterministic, multi-phase scanning with 251 modules across content discovery, browser/SPA spidering, and active/passive audit, covering injection, access control, file/path, API/protocol, framework-specific, cloud/infra, and out-of-band (OAST) vulnerability classes. Agentic Scan (vigolium agent): Thoroughly audits your codebase. AI-driven scanning that autonomously plans attacks, selects modules, generates custom extensions, and triages results, combining deep source-code audit with autonomous and targeted vulnerability scanning. | Adversary Simulation | ||
| Distributed command and control framework | Red Teaming | ||
| Backdoor generator and multi-session handler for sessions sharing among connected sibling servers. | Auth & perms | ||
| A script to enumerate virtual hosts on a server. | Informations gathering | ||
| Online local vulnerability scanners project. | Auth & perms | ||
| Provide materials that allows anyone to gain practical 'hands-on' experience in security. | Resources | ||
| A place to learn and improve penetration testing/ethical hacking skills for FREE. | Vulnerabilities | ||
| Create and edit CVE information in CVE JSON format | Vulnerability Assessment | ||
| Pentesting management and automation platform | Collaboration and Report | ||
| Agent-less vulnerability scanner. | Auth & perms | ||
| Agentless system vulnerability scanner for Linux/FreeBSD with a dashboard (VulsRepo) for analyzing the scan results | Vulnerability Assessment | ||
| Interactive cheat sheet with a curated list of offensive security tools and their commands. | Operating systems | ||
| WAF bypassing tool | Web Application Exploitation | ||
| Web application security scanner | Web Application Exploitation | ||
| Windows Exploit Suggester - Next Generation. | Operating systems | ||
| Windows Exploit Suggester - Next Generation; analyses Windows targets patch levels to find exploits and Metasploit modules; works well with newer system (eg Windows 10) thanks to MSRC support | System Exploitation | ||
| EDR for Windows | Defensive | ||
| Powershell-based Windows security auditing toolbox. | Operating systems | ||
| Post exploitation tool that uses WMI event filter and MSBuild execution for lateral movement. | Auth & perms | ||
| Weakpass rule-based online generator; generates a wordlist based on a set of words entered by the user | Cracking | ||
| Tool for the recognition of vulnerabilities and blackbox information for Wordpress. | CMS | ||
| WordPress CMS vulnerability scanner | Web Application Exploitation | ||
| WPScan WordPress Security Scanner | CMS | ||
| A centralized dashboard for running and scheduling WordPress scans powered by WPScan utility. | CMS | ||
| WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University Bochum (https://nds.rub.de/) and the Hackmanit GmbH (https://hackmanit.de/). The basic idea behind WS-Attacker is to provide a functionality to load WSDL files and send SOAP messages to the Web Service endpoints (which is executed using the underlying SoapUI framework). This functionality can be extended using various plugins and libraries to build specific Web Services attacks. You can find more information on the WS-Attacker architecture and its extensibility in our paper: Penetration Testing Tool for Web Services Security (https://www.nds.rub.de/research/publications/ws-attacker-paper/) | Web Application Exploitation | ||
| WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University Bochum (https://nds.rub.de/) and the Hackmanit GmbH (https://hackmanit.de/). The basic idea behind WS-Attacker is to provide a functionality to load WSDL files and send SOAP messages to the Web Service endpoints (which is executed using the underlying SoapUI framework). This functionality can be extended using various plugins and libraries to build specific Web Services attacks. You can find more information on the WS-Attacker architecture and its extensibility in our paper: Penetration Testing Tool for Web Services Security (https://www.nds.rub.de/research/publications/ws-attacker-paper/) | Adversary Simulation | ||
| Modular framework for SOAP web services penetration testing | Web Application Exploitation | ||
| Burp Suite plugin to detect current and discover new WSDL files. | Development | ||
| Fuzzing penetration testing tool for testing HTTP SOAP based web services | Web Application Exploitation | ||
| Web Service Security Assessment Tool; WS, REST API, SOAP API dynamic scanner | Web Application Exploitation | ||
| The web-application vulnerability scanner. | Auth & perms | ||
| Web technologies detection; assemble different features from HTTPX, Naabu, GoWitness and Wappalyzer | Web Application Exploitation | ||
| Identify technologies on websites. | Informations gathering | ||
| Ansible playbook to deploy infrastructure in the cloud for conducting Red Team assessments | Red Teaming | ||
| Automated platform for discovering new potentially cybersecurity threats targeting your assets (detects typosquatting domain names, monitor malicious domain names, detects data leaks...) | Threat Intelligence | ||
| Enumerate missing KBs and suggest exploits for useful privilege escalation vulnerabilities. | Auth & perms | ||
| Hashcat WebUI; asynchronous task, chain tasks, statistics, export, segregation, local and LDAP authentication | Cracking | ||
| Explore more than 778 billion web pages saved over time. | Cloud & services | ||
| Find way more from the Wayback Machine! | Informations gathering | ||
| Security monitoring solution for threat detection, integrity monitoring, incident response and compliance; unified XDR and SIEM protection for endpoints and cloud workloads | Defensive | ||
| Browser extension that extracts users from LinkedIn company pages. | Informations gathering | ||
| XSS payloads designed to turn alert(1) into P1. | Auth & perms | ||
| Web Cache Vulnerability Scanner (WCVS) is a fast and versatile CLI scanner for web cache poisoning and web cache deception developed by Hackmanit and Maximilian Hildebrand. The scanner supports many different web cache poisoning and web cache deception techniques, includes a crawler to identify further URLs to test, and can adapt to a specific web cache for more efficient testing. It is highly customizable and can be easily integrated into existing CI/CD pipelines. | Web Application Exploitation | ||
| All-in-one OSINT tool for analysing any website. | Informations gathering | ||
| A web crawler oriented to infosec. | Informations gathering | ||
| Automation tool designed to enumerate subdomains and detect bugs using different open-source tools. | Vulnerabilities | ||
| Deliberately insecure application. | Resources | ||
| Hashcat WebUI with distributed cracking sessions and analytics | Cracking | ||
| An automated dynamic testing solution that provides comprehensive vulnerability detection. | Bug bounty | ||
| A web dashboard for nmap XML report | Networking | ||
| A web dashboard for nmap XML report | Networking | ||
| Framework for analysing applications that communicate using the HTTP and HTTPS protocols. | Network | ||
| A web scraper to scrape email's and phone numbers from websites. | Informations gathering | ||
| HTTP request collector and inspector | Web Application Exploitation | ||
| Web shell for post-exploitation working with a PHP agent | Web Application Exploitation | ||
| AWS Attack Library. | Cloud & services | ||
| Web application fuzzer. | Informations gathering | ||
| Web directory and file scanner (wordlist bruteforce); but also a web fuzzer | Web Application Exploitation | ||
| Service able to detect more than 430 CMS, find version used for some CMS, has an API for batch detection | Web Application Exploitation | ||
| Detect which CMS a site is using. | CMS | ||
| OSINT tool to find breached emails, databases, pastes, and relevant information. | Informations gathering | ||
| Discover what runs a website. | Well known products | ||
| Detect and bypass web application firewalls and protection systems. | Informations gathering | ||
| Next generation web scanner. | Auth & perms | ||
| Web scanner, recognises web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices, also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more; more than 1800 plugins | Web Application Exploitation | ||
| Enumerate usernames across many websites. | Informations gathering | ||
| Take over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding Shadow Credentials to the target account | Networking | ||
| Identify hardcoded secrets in static structured text. | Informations gathering | ||
| Domain & IP data intelligence for greater enterprise security. | Informations gathering | ||
| DNS Server for executing DNS Rebinding attacks | Networking | ||
| WiFi exploitation framework. | Network | ||
| Framework for rogue Wi-Fi access point attack. | Network | ||
| Dictionary generator used to generate dictionaries/wordlist for Wireless Router Passwords | Wireless | ||
| A simple wireless networks penetration testing toolkit. | Network | ||
| Windows debugger | Reverse Engineering | ||
| Windows WiFi brute forcing utility without the requirement of external dependencies. | Network | ||
| The Windows memory acquisition tool. | Operating systems | ||
| Automation for internal Windows pentest / AD-Security. | Auth & perms | ||
| UAC bypass, Elevate, Persistence methods. | Auth & perms | ||
| Compares target patch levels against the Microsoft vulnerability DB to detect missing patches. | Operating systems | ||
| Analyses Windows targets patch levels to find exploits and Metasploit modules, works only for older systems (eg Windows XP, Vista, etc.) because it relies on MS Security KBs | System Exploitation | ||
| WireGuard socks proxy for pentest pivoting | Networking | ||
| Network protocol analyzer | Networking | ||
| Network sniffer that captures and analyzes packets off the wire. | Vulnerabilities | ||
| Web Inventory tool, takes screenshots and provides some extra bells&whistles to make life easier. | Informations gathering | ||
| Take screenshots of websites, provide some server header info, and identify default credentials if possible | Web Application Exploitation | ||
| Selenium based web scraper to generate passwords list. | Informations gathering | ||
| Assist with creating tailored wordlists, mostly based on geolocation. | Resources | ||
| Collaborative penetration test reporting platform | Collaboration and Report | ||
| Hidden parameters discovery suite. | Informations gathering | ||
| Automate XPath injection/XXE attacks to retrieve documents | Web Application Exploitation | ||
| X-Forwarded-For [403 forbidden] enumeration. | Cloud & services | ||
| Tunnelling framework; supports TCP, UDP, ICMP, SOCKS, HTTP, SCTP, WebSocket, RDP | Networking | ||
| Tool to analyze multi-byte xor cipher | Cryptography | ||
| The Prime Cross Site Request Forgery Audit and Exploitation Toolkit. | Vulnerabilities | ||
| Advanced Cross Site Request Forgery (CSRF/XSRF) audit and exploitation toolkit | Web Application Exploitation | ||
| The fastest way to set up XSS Hunter to test and find blind cross-site scripting vulnerabilities. | Vulnerabilities | ||
| XSS probes host for finding blind XSS | Web Application Exploitation | ||
| The fastest way to set up XSS Hunter to test and find blind XSS vulnerabilities. | Vulnerabilities | ||
| A Chrome extension for fast and easy XSS fuzzing. | Vulnerabilities | ||
| XSS probes host for finding blind XSS | Web Application Exploitation | ||
| Hack with JavaScript. | Vulnerabilities | ||
| Multi-purpose tool for XSS or JavaScript analysis | Web Application Exploitation | ||
| Multi-purpose tool for XSS or JavaScript analysis | Web Application Exploitation | ||
| XSS automatic scanner | Web Application Exploitation | ||
| Simple XSS Scanner tool. | Vulnerabilities | ||
| Detect XSS vulnerability in Web Applications. | Vulnerabilities | ||
| Written by Black Hat Ethical Hacking and #ChatGPT for offensive security and XSS attacks. | Vulnerabilities | ||
| Automatic framework to detect, exploit and report XSS vulnerabilities in web-based applications. | Vulnerabilities | ||
| XSS automatic scanner and exploiter | Web Application Exploitation | ||
| semi-automatic reflected and persistent XSS scanner | Plugins | ||
| Most advanced XSS scanner. | Vulnerabilities | ||
| XSS detection tool, parser, payload generator, fuzzing engine, crawler | Web Application Exploitation | ||
| A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks. | Informations gathering | ||
| XS-Leak browser test suite | Web Application Exploitation | ||
| Powerfull XSS Scanning and Parameter analysis tool&gem. | Informations gathering | ||
| XSS Scanner | Web Application Exploitation | ||
| Extreme Vulnerable Node Application, insecure webapp for security trainings | Intentionally Vulnerable Applications | ||
| A badly coded web application that helps security enthusiasts to learn application security. | Resources | ||
| A mini webserver with FTP support for XXE payloads. | Network | ||
| Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods | Web Application Exploitation | ||
| Exploitation of XXE vulnerability using direct and different out of band methods. | Vulnerabilities | ||
| This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files. | Vulnerabilities | ||
| Generates XML payloads, and automatically starts a server to serve the needed DTD's or to do data exfiltration for XXE attacks | Web Application Exploitation | ||
| Tool to help exploit XXE vulnerabilities. | Vulnerabilities | ||
| Processes memory scanner | Reverse Engineering | ||
| XSS detection and exploit framework (Windows only) | Web Application Exploitation | ||
| An advanced Cross Site Scripting vulnerability detection and exploitation framework. | Vulnerabilities | ||
| A Chrome browser extension to show alerts for several hidden elements. | Vulnerabilities | ||
| Disassembly and static analysis library that provides triage analysis data | Reverse Engineering | ||
| Remote active operating system fingerprinting | Networking | ||
| Web security scanner (XSS, SQLi, SSRF, XXE, etc.) | Web Application Exploitation | ||
| Burp Suite plugin for XSS and SQLi which add our payload to all parameters with one click. | Vulnerabilities | ||
| Pattern matching helping malware researchers to identify and classify malware samples | Incident Response | ||
| TYet Another Stupid Audit Tool; check general Linux system and common softwares configuration | Configuration Audit | ||
| Scans for vulnerable & exploitable 3rd-party web applications | Web Application Exploitation | ||
| Yet Another Yara Automaton; automatically curate open source yara rules and run scans | Incident Response | ||
| The pattern matching swiss knife for malware researchers. | Informations gathering | ||
| Yara rules editor, generator, scanner | Incident Response | ||
| Access to all bug bounty programs directly inside Burp | Plugins | ||
| Yar is a tool for plunderin' organizations, users and/or repositories... | Informations gathering | ||
| A network analyzer that make easy to extract informations about network traffic. | Informations gathering | ||
| Organize observables, indicators of compromise, TTPs, and knowledge on threats in a single, unified repository | Threat Intelligence | ||
| Your OSINT Graphical Analyzer. | Informations gathering | ||
| Your OSINT Graphical Analyzer; project to help people understand different courses of action to take based upon the data | Web Application Exploitation | ||
| The world's most widely used web app scanner. | Network | ||
| GUI for Nmap | Networking | ||
| ZRT; project management, vulnerability management and pentest report creation application | Collaboration and Report | ||
| Collection of tools to scan and study massive networks | Networking | ||
| Automated phishing tool with multiple tunneling options; fork of Shellphish | Red Teaming | ||
| Auto Scanning to SSL Vulnerability. | Cryptanalysis | ||
| Automatically list vulnerable Windows ACEs/ACLs using DC's LDAP to list users/groups/computers/OU/certificate templates and their nTSecurityDescriptor to check for vulnerable rights | System Exploitation | ||
| Interacts with BloodHound to identify and exploit ACL based privilege escalation paths | System Exploitation | ||
| LDAP based Active Directory user and group enumeration tool | Networking | ||
| Powershell tool to automate Active Directory enumeration. | Auth & perms | ||
| Collection of scanner checks missing in Burp. | Well known products | ||
| Test credentials against Active Directory Federation Services (ADFS), allowing password spraying or bruteforce attacks | Networking | ||
| Enumeration and exporting of all DNS records in ADIDNS domain or forest DNS zones | Networking | ||
| Discover Adobe Experience Manager (AEM) Content Management System (CMS) websites. | CMS | ||
| A vulnerability scanning tools for penetration testing. | Informations gathering | ||
| Fully automated WPA PSK PMKID and handshake capture script. | Network | ||
| Complete suite of tools to assess WiFi network security. | Informations gathering | ||
| Wireless network audit script | Wireless | ||
| This is a multi-use bash script for Linux systems to audit wireless networks. | Network | ||
| Public malware techniques used in the wild: virtual machine, emulation, debuggers. | Virtualization | ||
| Modular web vulnerability scanner | Web Application Exploitation | ||
| Fast and customizable subdomain wordlist generator using DSL. | Informations gathering | ||
| Customizable subdomain wordlist generator using DSL | OSINT and Reconnaissance | ||
| Identify applications even if they are running on a different port than normal. | Informations gathering | ||
| Blind SQL Injection Tool with Golang. | Vulnerabilities | ||
| Tool for reverse engineering and malware analysis of Android applications | Reverse Engineering | ||
| Reverse engineering and pentesting for Android applications. | Operating systems | ||
| A powerful and user-friendly binary analysis platform. | Informations gathering | ||
| Platform-agnostic binary analysis framework | Reverse Engineering | ||
| Automated client-side template injection detection for AngularJS. | Development | ||
| A CLI application that automatically prepares Android APK files for HTTPS inspection. | Informations gathering | ||
| Extract endpoints from APK files. | Operating systems | ||
| Framework for monitoring and tampering system API calls of native macOS, iOS and android apps. | Operating systems | ||
| Scans the history of GitHub repositories to find sensitive things. | Informations gathering | ||
| Automate your application security orchestration and correlation (ASOC). | Bug bounty | ||
| Script for Arch Linux which use iptables settings to create a transparent proxy through Tor Network | Networking | ||
| Tool that allows instant setup of virtual machines on various architectures for reverse, exploit, fuzzing and programming purpose | Reverse Engineering | ||
| Discover hosts on your network using ARP requests | Networking | ||
| Find domains and subdomains related to a given domain. | Informations gathering | ||
| Create vulnerable instrumented local or cloud environments to simulate attacks. | Virtualization | ||
| Burp Suite plugin to test for authorization flaws. | Auth & perms | ||
| Smart context-based SSRF vulnerability scanner. | Vulnerabilities | ||
| A tool used to check if a CNAME resolves to the scope address. | Informations gathering | ||
| A shiny new copy of Chromium that will bring colors in your hunt. | Well known products | ||
| Specify targets and run sets of tools against them. | Auth & perms | ||
| An automated tool that automatically scanning a list of multiple websites with wordpress at once. | CMS | ||
| AntiVirus Evasion Tool. | Cryptanalysis | ||
| A collection about Proof of Concepts of Common Vulnerabilities and Exposures. | Auth & perms | ||
| Collection of AWS penetration testing scripts | Cloud | ||
| Distribute the workload of many different scanning tools with ease. | Cloud & services | ||
| PHP Webshell with handy features. | Development | ||
| Webshell with many features: file manager, search, command execution, DB connection, SQL explorer, process list | Web Application Exploitation | ||
| Buggy Web Application, insecure webapp for security trainings | Intentionally Vulnerable Applications | ||
| An extremely buggy web application!. | Resources | ||
| bXSS is a utility which can be used identify Blind Cross-Site Scripting. | Vulnerabilities | ||
| Finds unknown classes of injection vulnerabilities. | Well known products | ||
| Advanced network reconnaissance tool | OSINT and Reconnaissance | ||
| A library for detecting known or weak cryptographic secrets across many web frameworks | Web Application Exploitation | ||
| A library for detecting known secrets across many web frameworks. | Development | ||
| The AWS Cloud Post Exploitation framework! | Cloud & services | ||
| OSINT automation for hackers. | Informations gathering | ||
| Generation of bug bounty reports based on user provided templates | Bug bounty | ||
| Fetches latest bug bounty programs from many platforms and consolidates them in one place. | Auth & perms | ||
| Service enumerating all targets on Internet covered by a bug bounty program | Bug bounty | ||
| Help you coordinate your reconnaissance workflows across multiple devices. | Auth & perms | ||
| Scope gathering tool for multiple Bug Bounty platforms. | Bug bounty | ||
| JMX enumeration and attacking; helps to identify common vulnerabilities on JMX endpoints | Networking | ||
| Scan your source code against top security and privacy risks. | Development | ||
| PE parsing library (from PE-bear) | Reverse Engineering | ||
| The Swiss Army knife for WiFi, BLE, IPv4 and IPv6 networks reconnaissance and MITM attacks. | Network | ||
| MITM framework | Networking | ||
| Web UI for bettercap | Networking | ||
| A list of strings which have a high probability of causing issues when used as user-input data. | Vulnerabilities | ||
| Raw binary firmware analysis software; tries to determine the firmware loading address | Reverse Engineering | ||
| GNU collection of binary tools | Reverse Engineering | ||
| Fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images. | Auth & perms | ||
| Analyze, reverse engineer and extract firmware images (and other files, also usefull for Digital Forensics) | Reverse Engineering | ||
| Crack legacy zip encryption with Biham and Kocher's known plaintext attack | Cracking | ||
| Dump the syskey bootkey from a Windows NT/2K/XP system hive, often used with samdump2, part of the ophcrack project | System Exploitation | ||
| Active Directory privilege escalation framework | Networking | ||
| Network protocol fuzzing framework | Networking | ||
| Network protocol fuzzing for humans. | Network | ||
| x86 binaries to C decompiler | Reverse Engineering | ||
| Creates a TCP tunnel; exposing local ports to a remote server, bypassing standard NAT connection firewalls | Networking | ||
| A simple CLI tool for making tunnels to localhost. | Network | ||
| Crawls bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) hourly and dumps them into another git repo | Bug bounty | ||
| Crawls bug bounty platform scopes. | Bug bounty | ||
| Hourly-updated data dumps of bug bounty platform scopes that are eligible for reports. | Bug bounty | ||
| Automated security reporting from markdown templates. | Bug bounty | ||
| Automated bug bounty reporting/submission, supports HackerOne and Bugcrowd | Bug bounty | ||
| Static analysis security vulnerability scanner for Ruby on Rails applications. | Development | ||
| Find broken links, missing images, etc within your HTML. | Vulnerabilities | ||
| Broken Link Hijacking Burp Suite extension. | Vulnerabilities | ||
| Honeypot | Honeypot and Decoy | ||
| Wordlists handcrafted and automated with <3 | Resources | ||
| A customized command and control center for red team and adversary simulation. | Informations gathering | ||
| Automatically attempts default creds on found services based on Nmap output. | Informations gathering | ||
| Automation framework for running multiple open sourced subdomain bruteforcing tools in parallel. | Informations gathering | ||
| DigiNinja's bucket_finder utility. | Cloud & services | ||
| Patch-level verification for Bundler. | Development | ||
| Copy a Burp Suite request to a file or the clipboard as multiple programming languages functions. | Network | ||
| Vulnerability scanner based on vulners.com search API. | Well known products | ||
| Web service that allows for detection Blind XSS vulnerabilities within web applications. | Development | ||
| Add headers to all Burp requests to bypass some WAF products. | Network | ||
| Cisco password type-7 encryptor and decryptor | Cryptography | ||
| Regexp static code analysis | Code Analysis | ||
| Command-line WebDAV client. | Well known products | ||
| A lightweight web security auditing toolkit. | Network | ||
| Hacks its way into RTSP videosurveillance cameras. | Operating systems | ||
| The FLARE team's open-source tool to identify capabilities in executable files. | Informations gathering | ||
| Takes a list of domains, crawls urls and scans for endpoints, secrets, api keys, file extensions, tokens | OSINT and Reconnaissance | ||
| Crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more. | Informations gathering | ||
| Generate similar-looking domains for phishing attacks. | Informations gathering | ||
| Extracting URLs of a specific target based on the results of commoncrawl.org. | Cloud & services | ||
| Code Credential Scanner; scan a large, diverse codebase for hard-coded credentials, or credentials present in configuration files | Source code management | ||
| An asynchronous enumeration & vulnerability scanner. | Informations gathering | ||
| Network brute force tool, faster than other existing solutions. | Network | ||
| Scrape domain names from SSL certificates of arbitrary hosts. | Cryptanalysis | ||
| A certificate transparency log keyword sniffer written in Python. | Informations gathering | ||
| A tool for testing for certificate validation vulnerabilities of TLS connections. | Cryptanalysis | ||
| A simple certificate expiration monitor script. | Informations gathering | ||
| Search the entire internet by data in TLS certificates. | Informations gathering | ||
| Dump NTDS with golden certificates and UnPAC the hash | Networking | ||
| Rapidly search and hunt through windows forensic artefacts. | Auth & perms | ||
| Self-hosted website change detection tracking, monitoring and notification service | Other | ||
| Page change monitoring with alerts a breezem, the best way to monitor website changes. | Auth & perms | ||
| A default credential scanner. | Informations gathering | ||
| The only cheat sheet you need. | Resources | ||
| Prevent cloud misconfigurations and find vulnerabilities during build-time. | Cloud & services | ||
| Platform security assessment framework. | Auth & perms | ||
| Fast TCP tunneling over HTTP secured by SSH | Networking | ||
| Locally checks for signs of a rootkit. | Operating systems | ||
| eBPF-based networking, security, and observability. | Virtualization | ||
| Vulnerability static analysis for containers. | Virtualization | ||
| Obtain GraphQL API Schema even if the introspection is not enabled. | Databases | ||
| Obtain GraphQL API schema even if the introspection is disabled by abusing the "did you mean" feature | Web Application Exploitation | ||
| Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud. | Cloud & services | ||
| Try to find the origin IP of a webapp protected by Cloudflare. | Informations gathering | ||
| Cloudlist is a tool for listing Assets from multiple Cloud Providers. | Cloud & services | ||
| Cloud Security Posture Management (CSPM). | Cloud & services | ||
| Take a list of resolved subdomains and output any corresponding CNAMES en masse. | Informations gathering | ||
| A collection of enhancements for Portswigger's popular Burp Suite web penetration testing tool. | Well known products | ||
| Power security researchers around the world as well as code scanning. | Development | ||
| OSINT tool for finding Github repositories by extracting commit logs in real time. | Informations gathering | ||
| Web-based command injection tester | Web Application Exploitation | ||
| Overpower wordlist generator, words permutation and combinations, encoding/decoding... | Informations gathering | ||
| Wordlist generator: create permutations and combinations of words with predefined sets of extensions, words and patterns/function to create complex endpoints, wordlists and passwords | Cracking | ||
| Read local Chrome cookies without root or decrypting. | Development | ||
| Read local Chrome cookies without root or decrypting and display then in JSON | System Exploitation | ||
| Hashcat Web Interface. | Informations gathering | ||
| Multithreaded program to crack PKCS#12 files (p12 and pfx extensions) | Cracking | ||
| The unix-way web crawler. | Informations gathering | ||
| Dump windows credentials | System Exploitation | ||
| Crawl a site and extract useful informations for recon. | Informations gathering | ||
| Takes a single wordlist item and tests it one by one over a large collection of websites. | Informations gathering | ||
| Brute forcing tool that support several uncommon protocols. | Auth & perms | ||
| Offers crowdsourced protection against malicious IPs and access to the most advanced real-world CTI. | Informations gathering | ||
| Yet another subdomain finder. | Informations gathering | ||
| Wordlist generator | Cracking | ||
| Wordlist generator where you can specify a character set or any set of characters to be used. | Informations gathering | ||
| Tool that try to identify what cipher is used and uncipher the data | Cryptography | ||
| Analyze Content-Security-Policy header of a given URL. | Vulnerabilities | ||
| Discover new target domains using Content Security Policy. | Informations gathering | ||
| CSRF Scanner Extension for Burp Suite Pro. | Vulnerabilities | ||
| Burp Suite extension that allows request/response modification using a GUI. | Cryptanalysis | ||
| Library to enhance and speed up script/exploit writing for CTF players | Other | ||
| Some setup scripts for security research tools. | Auth & perms | ||
| Library to run basic functions from stripped binaries | Reverse Engineering | ||
| Interactive CTF exploration tool. | Auth & perms | ||
| A tool for fetching archived URLs. | Cloud & services | ||
| Gather and update all available and newest CVEs with their PoC. | Auth & perms | ||
| Simple latest CVE collector written in Python. | Auth & perms | ||
| Tool to import CVE and CPE into a MongoDB to facilitate search and processing of CVEs | Vulnerability Assessment | ||
| A tool to perform local searches for known vulnerabilities. | Auth & perms | ||
| Lists CVEs that are currently being discussed on the social network Mastodon. | Auth & perms | ||
| CVSS calculator library | Vulnerability Assessment | ||
| Service to check if an account has been compromised in a data breach, only tells if the account is compromised | Other | ||
| A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. | Resources | ||
| A multitool for tracking and locating nearby devices via their RF activities. | Network | ||
| Self-hosted data breach search engine | OSINT and Reconnaissance | ||
| OSINT framework, find, aggregate and export data | OSINT and Reconnaissance | ||
| .NET deobfuscator and unpacker | Reverse Engineering | ||
| A dead-simple way to recursively look for broken links on a web page. | Vulnerabilities | ||
| Login hunter of default credentials for administrative web interfaces. | Informations gathering | ||
| A work-in-progress deobfuscator for movfuscated binaries. | Cryptanalysis | ||
| Better understand the structure, construction, and security of open source software packages. | Development | ||
| CLI client for deps.dev API. | Development | ||
| NodeJS deserialization payload generator. | Development | ||
| An enterprise friendly way of detecting and preventing secrets in code. | Informations gathering | ||
| Find CVEs that don't have a Detectify modules. | Bug bounty | ||
| Tools to work with android .dex and java .class files. | Development | ||
| differer finds how URLs are parsed by different languages in order to help bug hunters break filters. | Informations gathering | ||
| The disclose.io security.txt scraper (diosts) takes a list of domains as the input, retrieves and validates the security.txt if available and outputs it in the disclose.io JSON format. | OSINT and Reconnaissance | ||
| Web directory and file scanner (wordlist bruteforce) | Web Application Exploitation | ||
| Web directory and file scanner (wordlist bruteforce) | Web Application Exploitation | ||
| Find web directories without bruteforce. | Informations gathering | ||
| Finds Directory Listings or open S3 buckets from a list of URLs. | Cloud & services | ||
| Web directory and file scanner (wordlist bruteforce) | Informations gathering | ||
| Scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with Metasploit | Other | ||
| Custom bash scripts used to automate various penetration testing tasks. | Informations gathering | ||
| A list of disposable and temporary email address domains. | Informations gathering | ||
| HS256 JWT token distributed brute force cracker | Web Application Exploitation | ||
| DevSecOps, ASPM, Vulnerability Management. | Bug bounty | ||
| Perform permutations, mutations and alteration of subdomains. | Informations gathering | ||
| .NET assembly debugger, decompiler and editor | Reverse Engineering | ||
| .NET assembly debugger, decompiler and editor; fork of dnSpy | Reverse Engineering | ||
| It comes with crash detection and crash replay. To use it, first create a file called "records" in the same directory as the fuzzer with the dns records for the target in the following format: <record type>,<record question>,<record class> | OSINT and Reconnaissance | ||
| Subdomain takeover tool for attackers, bug bounty hunters and the blue team! | Cloud & services | ||
| Fast and multi-purpose DNS toolkit designed for running DNS queries. | Informations gathering | ||
| Python wordlist-based DNS subdomain scanner. | Informations gathering | ||
| DNS tunnel meant for encrypted Command & Control channel, data exfiltration | Red Teaming | ||
| Create an encrypted command-and-control (C&C) channel over the DNS protocol. | Informations gathering | ||
| Enumerates DNS information of a domain and to discover non-contiguous ip blocks. | Informations gathering | ||
| DNS reconnaissance tool: AXFR, DNS records enumeration, subdomain bruteforce, range reverse lookup | OSINT and Reconnaissance | ||
| Continuation of dnsenum project | OSINT and Reconnaissance | ||
| Generates combination of domain names from the provided input. | Informations gathering | ||
| Domain name permutation engine for detecting several types of attacks. | Informations gathering | ||
| A tool to monitor for potential spear phishing domains and send to Slack. | Informations gathering | ||
| A DNS database debugger. | Informations gathering | ||
| Multi-purpose DNS toolkit allow to run multiple DNS queries | OSINT and Reconnaissance | ||
| Uility to embed XXE and XSS payloads in docx, odt, pptx, etc | Web Application Exploitation | ||
| Utility to embed XXE and XSS payloads in docx, odt, pptx... | Vulnerabilities | ||
| Check for dozens of common best-practices around deploying Docker containers in production. | Virtualization | ||
| Small script to check a list of domains against open redirect vulnerability. | Vulnerabilities | ||
| Try to find all subdomains, similar-domains and related-domains of an organization. | Informations gathering | ||
| Multi Tool Subdomain Enumeration. | Informations gathering | ||
| Find a domain from an IP address | OSINT and Reconnaissance | ||
| Tool to bypass 40X response codes. | Auth & perms | ||
| Quickly do keyword searches over GitLab and GitHub for OSINT & bug bounty recon. | Source code management | ||
| The Deepfake Offensive Toolkit. | Auth & perms | ||
| .NET decompiler and assembly browser | Reverse Engineering | ||
| Proxycannon and botnet, using docker, ovpn files, tor nodes, and dante socks5 proxies that may be used for password spraying | Other | ||
| A static-code-analysis tool for performing security-focused code reviews. | Bug bounty | ||
| Detect, track and alert on infrastructure drift. | Cloud & services | ||
| Measures infrastructure as code coverage, and tracks infrastructure drift | Defensive | ||
| CMS scanner supporting SilverStripe and Wordpress, having partial support for Joomla, Moodle, Drupal | Web Application Exploitation | ||
| A plugin-based scanner that aids security researchers in identifying issues with several CMSs. | CMS | ||
| The leading security assessment framework for Android. | Operating systems | ||
| Drupal CMS enumeration and exploitation tool | Web Application Exploitation | ||
| Extract files from .DS_Store recursively | Digital Forensics | ||
| Filter and enrich a list of subdomains by level. | Informations gathering | ||
| Collection of tools for network auditing and penetration testing. | Informations gathering | ||
| Identify DTDs on filesystem snapshot and build XXE payloads using those local DTDs | Web Application Exploitation | ||
| Search exposed EBS volumes for secrets. | Cloud & services | ||
| May be used to extract various credentials from running processes. | Auth & perms | ||
| Dump web accessible (distributed) version control systems (DVCS/VCS): SVN, GIT, Mercurial/hg, Bazaar/bzr, … | Web Application Exploitation | ||
| Rip web accessible version control systems: svn, git... | Source code management | ||
| A tool that helps users searching and filtering queries in Ldap environment. | Auth & perms | ||
| Metasearch engine, query 16 search engines in parallel | OSINT and Reconnaissance | ||
| Cross platform AArch32/x86/x86-64 debugger | Reverse Engineering | ||
| Check egress filtering and identify if ports are allowed to automatically spawn a shell. | Informations gathering | ||
| An Intelligent wordlist generator based on user profiling, permutations, and statistics. | Cracking | ||
| A tool for extracting all the possible endpoints from the JS files. | Development | ||
| SSH tarpit that slowly sends an endless banner | Honeypot and Decoy | ||
| Informative site with EoL dates of everything. | Auth & perms | ||
| Enumerate data from Windows and Samba hosts. | Operating systems | ||
| Windows Samba enumeration tool | System Exploitation | ||
| Windows Samba enumeration tool, next generation version of enum4linux | System Exploitation | ||
| A Windows/Samba enumeration tool with additional features like JSON/YAML export. | Operating systems | ||
| Vulnerability management and reporting platform | Collaboration and Report | ||
| Enemies Of Symfony - debug mode Symfony looter. | Auth & perms | ||
| Collects informations related to domains whois, history, dns records and more. | Informations gathering | ||
| Spoof SSDP replies to phish for credentials and NetNTLM challenge/response. | Auth & perms | ||
| The ultimate WinRM shell for hacking/pentesting. | Auth & perms | ||
| Man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication | Networking | ||
| Combination of evilginx3 and GoPhish. | Informations gathering | ||
| Data exfiltration utility for testing detection capabilities. | Auth & perms | ||
| Shows EXIF information for JPEG files only | Steganography | ||
| Image metadata library and tools. | Informations gathering | ||
| Extract endpoints from source files. | Informations gathering | ||
| Tool to recover deleted files from an ext3 or ext4 partition | Digital Forensics | ||
| An easy way for penetration testers and bug bounty hunters to test (blind) XSS. | Vulnerabilities | ||
| Pen Test Report Generation and Assessment Collaboration | Collaboration and Report | ||
| Cloud native runtime security. | Virtualization | ||
| A DNS bruteforcer with multi-threading, and handling of bad resolvers. | Informations gathering | ||
| Python script implementing the favicon hash trick to find subdomains. | Informations gathering | ||
| Use favicon.ico to improve your target recon phase. | Informations gathering | ||
| Zip password cracker. | Informations gathering | ||
| Web directory and file scanner (wordlist bruteforce) | Web Application Exploitation | ||
| Fast web fuzzer written in Go. | Informations gathering | ||
| Web directory and file scanner (wordlist bruteforce); but also a web fuzzer | Web Application Exploitation | ||
| Golang tool which helps dropping the irrelevant entries from your ffuf result file. | Informations gathering | ||
| Modern tool for Windows kernel exploration and tracing with a focus on security. | Operating systems | ||
| Scans the top 500 sites daily for their security.txt file or DNS records. | Informations gathering | ||
| Browser fingerprinting library. | Development | ||
| Standalone utility for service discovery on open ports! | Informations gathering | ||
| Fileless linux malware framework | Red Teaming | ||
| A pretty sweet vulnerability scanner. | Informations gathering | ||
| Know and see everything an attacker can extract and get from your published Flutter app | Adversary Simulation | ||
| Take a list of domains/subdomains and probe for working http/https server. | Informations gathering | ||
| Kscan is an asset mapping tool. | Informations gathering | ||
| File upload vulnerability scanner and exploitation tool. | Vulnerabilities | ||
| Automates the process of detecting and exploiting file upload forms flaws | Web Application Exploitation | ||
| A fuzzing tool written in Go. It helps your pentesting journey. | Informations gathering | ||
| Find critical backup files by creating a dynamic wordlist based on the domain. | Informations gathering | ||
| OSINT framework; find mails, dumps, retrieve Telegram history and info about hosts | OSINT and Reconnaissance | ||
| Identify routers on the local LAN and paths to the Internet. | Network | ||
| Identify routers on the local LAN and paths to the Internet. | Network | ||
| Fetch known URLs from several sources. | Informations gathering | ||
| Fetch known URLs from several sources and Filter Urls With OpenRedirection or SSRF Parameters. | Vulnerabilities | ||
| A comprehensive scanner for Google Cloud. | Cloud & services | ||
| A modern experience for GDB with advanced debugging capabilities. | Informations gathering | ||
| A tool to fastly get all javascript sources/files. | Development | ||
| Command line utility for searching and downloading exploits. | Auth & perms | ||
| CLI utility for searching and downloading exploits from Exploit-DB, Metasploit, Packetstorm and others | Other | ||
| A wrapper around grep to avoid typing common patterns. | Informations gathering | ||
| Find multiple types of hardcoded secrets & types of infrastructure-as-code misconfigurations. | Informations gathering | ||
| Capture all the git secrets by leveraging multiple open source git searching tools. | Informations gathering | ||
| Dump the contents of a remote git repository without directory listing enabled | Web Application Exploitation | ||
| A tool to dump a git repository from a website. | Source code management | ||
| Dump the contents of a remote git repository without directory listing enabled | Web Application Exploitation | ||
| Prevents you from committing secrets and credentials into git repositories. | Informations gathering | ||
| Find potential software vulnerabilities from git commit messages. | Source code management | ||
| A tool to hunt for credentials in GitHub wild AKA git*hunt. | Informations gathering | ||
| Monitor GitHub to search and find sensitive data in real time. | Informations gathering | ||
| Monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe, etc. | OSINT and Reconnaissance | ||
| Find endpoints on GitHub. | Informations gathering | ||
| Basically a regexp over a GitHub search. | Informations gathering | ||
| Find subdomains on GitHub. | Informations gathering | ||
| Leak git repositories from misconfigured websites. | Source code management | ||
| Find subdomains on GitLab. | Informations gathering | ||
| Protect and discover secrets using Gitleaks. | Informations gathering | ||
| Extract data from a .git directory. | Source code management | ||
| Scrapes public GitHub repositories for common naming conventions in variables, folders and files. | Informations gathering | ||
| Find sensitive information for a git repo. | Informations gathering | ||
| Find sensitive information (username, password, email) in git repositories | OSINT and Reconnaissance | ||
| Undetectable C2 server that communicates via Google SMTP to evade antivirus protections and network traffic restrictions | Red Teaming | ||
| Self-hosted CVE feed server | Vulnerability Assessment | ||
| The fastest dork scanner written in Go. | Cloud & services | ||
| Tool to remotely dump secrets from the Windows registry. | Informations gathering | ||
| Remotely dump secrets from the Windows registry (SAM hive, LSA secrets, SECURITY hive) | Networking | ||
| A fast & light web screenshot without headless browser but Chrome DevTools protocol. | Informations gathering | ||
| A complete TUI for LDAP. | Auth & perms | ||
| Active Directory domain information dumper | System Exploitation | ||
| Active Directory domain information dumper | Networking | ||
| Indentify web servers by checking their HTTP responses against a user defined list of fingerprints | Web Application Exploitation | ||
| Get the TOTP secrets exported by Google Authenticator. | Auth & perms | ||
| Dump the contents of a remote git repository without directory listing enabled; focus on as-complete-as-possible dumps and handling as many edge-cases as possible | Web Application Exploitation | ||
| Capture and replay live HTTP traffic in order to continuously test your system with real data. | Network | ||
| The vertasile multi-threaded password sprayer built on the shoulders of giants. | Informations gathering | ||
| Fast web spider written in Go. | Cloud & services | ||
| Generates DNS wordlists through permutations. | Informations gathering | ||
| Take screenshots of websites | Web Application Exploitation | ||
| A golang, web screenshot utility using Chrome Headless. | Informations gathering | ||
| Authenticated SSRF in Grafana. | Cloud & services | ||
| A flexible tool for redirecting a given program's TCP traffic to SOCKS5 or HTTP proxy. | Network | ||
| Generate graphs and charts based on password cracking results; supports hashcat and john the ripper potfile as well as ntds file | Cracking | ||
| The missing GraphQL security security layer. | Databases | ||
| Graphql introspection query analyzer. | Databases | ||
| Lists the different ways of reaching a given type in a GraphQL schema. | Databases | ||
| Lists the different ways of reaching a given type in a GraphQL schema | Web Application Exploitation | ||
| Represent any GraphQL API as an interactive graph. | Databases | ||
| Runs a dozen of security checks against a given GraphQL endpoint | Web Application Exploitation | ||
| GraphQL Server Engine Fingerprinting utility for software security professionals. | Databases | ||
| GraphQL server engine fingerprinting | Web Application Exploitation | ||
| Searches code from over a half million public repositories on GitHub. | Informations gathering | ||
| An incident response framework focused on remote live forensics. | Auth & perms | ||
| Genesis Scripting Engine; framework to rapidly implement custom droppers for all three major operating systems | Red Teaming | ||
| CLI for searching gtfobins and lolbas from the terminal | Other | ||
| Sub domain wild card filtering tool. | Informations gathering | ||
| Request the public disclosures on a specific HackerOne program. | Bug bounty | ||
| HTTP Request Smuggling over HTTP/2 Cleartext. | Vulnerabilities | ||
| Email OSINT & Password breach hunting tool; supports chasing down related email | OSINT and Reconnaissance | ||
| Powerful and user-friendly password hunting tool. | Informations gathering | ||
| Modular web based pentesting interface designed to run on Raspberry Pi | Collaboration and Report | ||
| Feed it a list of subdomains, it will resolve them and tell you which ones are internal. | Informations gathering | ||
| Takes a list of IP addresses then does a series of checks to return associated domain names. | Informations gathering | ||
| Turns any junk text into a usable wordlist for brute-forcing. | Resources | ||
| Discover the origin host behind a reverse proxy, useful for bypassing cloud WAFs!. | Informations gathering | ||
| Simple, fast web crawler designed for discovery of endpoints and assets within a web application. | Informations gathering | ||
| Small, fast tool for performing reverse DNS lookups en masse. | Informations gathering | ||
| Extract domains/subdomains from URLs en masse. | Informations gathering | ||
| Golang client for querying SecurityTrails API data. | Informations gathering | ||
| Discover the netblocks or ranges (in CIDR notation) owned by the target organization. | Informations gathering | ||
| CLI tool for open source and threat intelligence. | Informations gathering | ||
| Identify the different types of hashes | Cryptography | ||
| Hash cracking tool using rainbow tables | Cracking | ||
| Analyze the security headers returned by a web page and report dangerous configurations. | Network | ||
| Small tool to capture packets from wlan devices. | Network | ||
| Fuzzer for analyzing how servers respond to different HTTP headers | Web Application Exploitation | ||
| Customisable and automated HTTP header injection. | Network | ||
| Bounded model checking framework for Heap-implementations | Binary Exploitation | ||
| An HTTP toolkit for security research. | Network | ||
| CLI tool for ephemeral penetration testing, rapidly deploy and manage various cloud services | Other | ||
| Windows reverse shell payload generator and handler that abuses the http(s) protocol. | Operating systems | ||
| Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell | Networking | ||
| Check if the mail is used on different sites like twitter, instagram and will retrieve information on sites with the forgotten password function | OSINT and Reconnaissance | ||
| A security oriented software fuzzer. | Auth & perms | ||
| Identify the different types of hashes | Cryptography | ||
| Network tool able to send custom TCP/IP packets. | Informations gathering | ||
| A really fast HTTP prober. | Informations gathering | ||
| Differential testing and fuzzing of HTTP servers and proxies | Web Application Exploitation | ||
| HTTP Request Smuggling Detection Tool. | Vulnerabilities | ||
| Nmap NSE script that scans for http server, takes a screenshot of them, and organizes the results into an HTML report | Plugins | ||
| Automatic tool for DNS rebinding-based SSRF attacks. | Cloud & services | ||
| Take a list of domains and probe for working HTTP and HTTPS servers. | Informations gathering | ||
| Grabs screenshots and HTML of large numbers of websites. | Informations gathering | ||
| Take screenshots of websites | Web Application Exploitation | ||
| HTTP toolkit that allows running multiple probes using the retryablehttp library. | Informations gathering | ||
| Multi-purpose HTTP toolkit allows to run multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads | Web Application Exploitation | ||
| Internet search engines for security researchers. | Informations gathering | ||
| An ICMP reverse shell written in Python3 and scapy. | Auth & perms | ||
| Discover and fingerprint IKE hosts. | Informations gathering | ||
| Command line IPSEC VPN brute forcing tool for Linux. | Network | ||
| Collection of Python classes for working with network protocols. | Network | ||
| A static analyzer for Java, C, C++, and Objective-C. | Development | ||
| User-friendly OSINT tool that allows you to quickly and easily gather informations. | Informations gathering | ||
| Scan QR-code, 1D, DataMatrix, Postal, PDF417, and more | Other | ||
| Research tools developed for Intel Wi-Fi chips : decode firmware files, communicate with the chip through Linux's debug filesystem | Wireless | ||
| An OOB interaction gathering server and client library | Vulnerabilities | ||
| Bypass IP source restrictions using HTTP headers. | Auth & perms | ||
| Finds publicly known security vulnerabilities in a website's frontend JavaScript libraries. | Development | ||
| Is This Domain In Scope; a small tool that allows you to check if a list of domains you have been provided is in the scope of your pentest or not | Other | ||
| Java application for automatic SQL database injection. | Development | ||
| Create SSL client fingerprints in an easy to produce and shareable way. | Cryptanalysis | ||
| Gather gather gather. | Informations gathering | ||
| DEX to Java decompiler | Reverse Engineering | ||
| Dex to Java decompiler. | Operating systems | ||
| GUI frontend to John the Ripper | Cracking | ||
| Network and Web Pentest Automation Framework. | Informations gathering | ||
| Beautifier for JavaScript. | Development | ||
| Fetches JavaScript files quickly and comprehensively from a defined list of URLs or domains. | Development | ||
| Find secrets, paths or links in the source code. | Informations gathering | ||
| Extract URLs, paths, secrets, and other interesting bits from JavaScript. | Informations gathering | ||
| JSON Web Tokens Support for Burp Suite. | Development | ||
| Improve your web application aecurity testing with rich data from static analysis. | Development | ||
| Simple JWT token brute force cracker. | Auth & perms | ||
| JWT encoding/decoding, generates payloads for JWT attack and very fast cracking. | Auth & perms | ||
| A toolkit for JWT tokens security testing | Web Application Exploitation | ||
| Burp Suite extension to check JWT for using keys from known from public sources. | Auth & perms | ||
| A toolkit for validating, forging and cracking JWT tokens | Web Application Exploitation | ||
| JWT brute-force cracker | Web Application Exploitation | ||
| Modular command-line tool to parse, create and manipulate JWT tokens. | Auth & perms | ||
| Script for Kali Linux which use iptables settings to create a transparent proxy through Tor Network | Networking | ||
| Passive open source intelligence automated reconnaissance. | Informations gathering | ||
| A next-generation crawling and spidering framework. | Informations gathering | ||
| Get your favourite Kali Linux tools on Debian/Ubuntu/Linux Mint. | Virtualization | ||
| Series of tools for attacking MS Kerberos implementations. | Auth & perms | ||
| Bruteforce and enumerate Active Directory accounts through Kerberos pre-authentication. | Auth & perms | ||
| Linux kernel CVE exploit analysis report and relative debug environment. | Operating systems | ||
| Automation of tokens/api keys testing. | Development | ||
| Convert OpenSSH known_hosts file hashed with HashKnownHosts to hashes crackable by Hashcat | Cracking | ||
| S3 bucket finder from html,js and bucket misconfiguration testing tool. | Cloud & services | ||
| Phishing Campaign Toolkit. | Auth & perms | ||
| Contextual content discovery tool. | Development | ||
| Hunts for phishing kit source code by traversing URL folders and searching in open directories for zip files; supports list of URLs or PhishTank | OSINT and Reconnaissance | ||
| Cloud resources manager designed to analyze and manage cloud cost, usage, security, and more!. | Cloud & services | ||
| Checks whether Kubernetes is deployed according to security best practices. | Virtualization | ||
| Adaption of tomnomnom's kxss tool with a different output format. | Vulnerabilities | ||
| Crack Windows passwords from hashes. | Auth & perms | ||
| Terminal based phishing campaign tool | Red Teaming | ||
| Powerful tool for extracting various types of data from a target URL. | Informations gathering | ||
| Ruby script to bruteforce for AWS s3 buckets using different permutations. | Cloud & services | ||
| Tool that print shared library dependencies | Reverse Engineering | ||
| Active Directory LDAP enumeration utility | Networking | ||
| Set of tools to process and visualize huge text files containing credentials. | Informations gathering | ||
| Set of tools to process and visualize huge text files containing credentials | OSINT and Reconnaissance | ||
| Library to simplify format string exploitation | Binary Exploitation | ||
| Cross-platform sandboxing library | Defensive | ||
| Reverse tunneling made easy for pentesters. | Auth & perms | ||
| Automates a number of Active Directory enumeration and vulnerability. | Operating systems | ||
| Script that automates a number of Active Directory enumeration and vulnerability checks | Networking | ||
| Command and control framework; HTTPS communication, process injection, in-memory .NET assembly execution, SharpCollection tools, sRDI implementation for shellcode generation, Windows link reloads DLLs from disk into current process | Red Teaming | ||
| Linux privilege escalation auditing tool. | Operating systems | ||
| Linux kernel exploit suggester | System Exploitation | ||
| Linux enumeration tool for pentesting and CTFs with verbosity levels. | Auth & perms | ||
| A Linux privilege escalation check script. | Auth & perms | ||
| Linux privilege escalation check script | System Exploitation | ||
| Reveals invisible links within JavaScript files. | Development | ||
| A multi-platform fuzzer for poking at userland binaries and servers. | Auth & perms | ||
| A fully configurable LinkedIn scraper: scrape anything within LinkedIn. | Cloud & services | ||
| Malicious shortcut generator for collecting NTLM hashes from insecure file shares. | Informations gathering | ||
| String-based secret-searching tool, high entropy and regexes. | Informations gathering | ||
| Password wordlist generator based on target information | Cracking | ||
| Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load. | Vulnerabilities | ||
| Python tool to remotely extract credentials on a set of hosts. | Auth & perms | ||
| CLI tool and library to extract credentials from lsass remotely | Networking | ||
| Locate and attack Lync and Skype for Business. | Cloud & services | ||
| Security auditing tool for Linux, macOS, and UNIX-based systems. | Operating systems | ||
| Tool to generate wordlists based on lyrics | Cracking | ||
| Makes the maniputation of MAC addresses of network interfaces easier. | Auth & perms | ||
| Obfuscation and generation of retro formats such as MS Office documents or VBS like format | Red Teaming | ||
| A portable device that can spoof/emulate any magnetic stripe, credit card or hotel card wirelessly. | Auth & perms | ||
| Generates a bunch of malicious pdf files with phone-home functionality. | Informations gathering | ||
| Malicious traffic detection system. | Auth & perms | ||
| Wifi rogue AP attacks and MitM. | Network | ||
| Command-line framework designed to automate the workflow of asset discovery, reconnaissance, and scanning | OSINT and Reconnaissance | ||
| Small utility program to perform multiple operations for a given subnet/CIDR ranges. | Informations gathering | ||
| Tests a list of s3 buckets to see if they have dir listings enabled or if they are uploadable. | Cloud & services | ||
| MassExploitConsole; mass reconnaissance and exploitation framework | Other | ||
| Fetch many paths for many hosts, without killing the hosts. | Informations gathering | ||
| Graphical tool for custom wordlist generation. | Informations gathering | ||
| Cross-platform post-exploitation HTTP/2 Command & Control server and agent. | Network | ||
| Script that automates the scanning of a target network for HTTP resources through XXE. | Vulnerabilities | ||
| VM that is built from the ground up with a large amount of security vulnerabilities. | Resources | ||
| Mifare classic offline cracker. | Operating systems | ||
| Aggregates results from Shodan, Censys, VirusTotal, SecurityTrail, etc. and extracts artifacts (IP addresses, domains, URLs or hashes) | OSINT and Reconnaissance | ||
| A little tool to play with Windows security. | Auth & perms | ||
| Extract plaintext passwords, hash, PIN code and kerberos tickets from memory; perform pass-the-hash, pass-the-ticket or build Golden tickets | System Exploitation | ||
| A post-exploitation powershell tool for extracting juicy info from memory. | Informations gathering | ||
| Library and CLI to parse and read Microsoft minidump file format | System Exploitation | ||
| pwning IPv4 via IPv6. | Network | ||
| A python program to create a fake AP and sniff data. | Network | ||
| Interactive HTTPS proxy | Web Application Exploitation | ||
| An interactive TLS-capable intercepting HTTP proxy. | Cryptanalysis | ||
| Generate tens of thousands of subdomain combinations in a matter of seconds. | Informations gathering | ||
| Aid operators in modifying ADCS certificate templates so that a created vulnerable state can be leveraged for privilege escalation | Networking | ||
| Leverage crt.sh website to monitor domains of a target. | Informations gathering | ||
| MD5-monomorphic shellcode packer, all payloads have the same MD5 hash | Red Teaming | ||
| Web directory and file scanner (wordlist bruteforce) | Web Application Exploitation | ||
| Cover your tracks during Linux exploitation by leaving zero traces on the exploited system. | Operating systems | ||
| Morphing Cobalt Strike's evil.HTA. | Well known products | ||
| LDAP enumeration tool implemented in Python3. | Auth & perms | ||
| A quick way to generate various basic Meterpreter payloads via MSFvenom. | Well known products | ||
| LDAP library for auditing Microsoft Active Directory. | Auth & perms | ||
| Perform lateral movement in restricted environments through a compromised MSSQL Server. | Auth & perms | ||
| An open source tool focused on software supply chain security. | Informations gathering | ||
| Helps with conducting forensics of mobile devices in order to find signs of a potential compromise. | Operating systems | ||
| Focuses DNS MX records and detects misconfigured MX records. | Informations gathering | ||
| Security analysis tool for EVM bytecode that supports smart contracts builds. | Auth & perms | ||
| Port scanner with a focus on reliability and simplicity | Networking | ||
| A cross-platform x86 assembler with an Intel-like syntax. | Auth & perms | ||
| Scan networks searching for NetBIOS information. | Network | ||
| Improved reimplementation of Netcat by nmap team; Supports TCP and UDP, IPv4 and IPv6, SSL, proxy (HTTP and SOCKS4) | Networking | ||
| Open source tool for network authentication cracking. | Auth & perms | ||
| Packet manipulation CLI tool; craft and inject packets of several protocols | Networking | ||
| A framework for secure and scalable network traffic analysis. | Network | ||
| Network address discovering tool. | Auth & perms | ||
| Protocol reverse engineering, modeling and fuzzing | Reverse Engineering | ||
| OSINT tool for finding profiles by username. | Informations gathering | ||
| ngrok collaborator link | Networking | ||
| Very light web security scanner | Web Application Exploitation | ||
| Network infrastructure configuration parser. | Auth & perms | ||
| Converts / manipulates / extracts data from a nmap scan output | Networking | ||
| A simple program to query nmap XML files in the terminal. | Informations gathering | ||
| Automate the process of enumeration & recon that is run every time. | Informations gathering | ||
| A static security code scanner for Node.js applications. | Development | ||
| Distributed hash cracking platform meant to be deployed on AWS (Cognito, DynamoDB, S3) so you pay only when you have a task running | Cracking | ||
| Retrieve information on linkedin profiles, companies on linkedin and search on linkedin companies/persons | OSINT and Reconnaissance | ||
| Generate multiple types of NTLMv2 hash theft files | Networking | ||
| A Burp Suite plugin intended to help with Nuclei template generation. | Well known products | ||
| Collection of Nuclei templates dedicated to WordPress core, plugins and themes vulnerabilities. | CMS | ||
| A ruby API for NVD CVE feeds management, the library will help you to download and manage NVD Data Feeds, search for CVEs, build your vulerability assesment platform or vulnerability database | Vulnerability Assessment | ||
| Retrieve information via O365 and AzureAD with valid credentials. | Cloud & services | ||
| Runtime mobile exploration toolkit, powered by Frida, built to help you assess the security posture of your mobile applications, without needing a jailbreak | Other | ||
| Runtime mobile exploration. | Operating systems | ||
| CLI tool which lets you query a plethora of databases and file formats. | Databases | ||
| An all-in-one GitHub open-source intelligence framework. | Informations gathering | ||
| Burp extension to detect alias traversal via NGINX misconfiguration at scale. | Well known products | ||
| Enumerate valid o365 users. | Cloud & services | ||
| SNMP scanner | Networking | ||
| Contains HackerOne disclosed reports and other bug bounty writeups. | Bug bounty | ||
| Bypass Kerberoast detections with modified KDC options and encryption types. | Auth & perms | ||
| Generate emails and usernames. | Informations gathering | ||
| On The Outside, Reaching In, exploitation toolbox for XXE attacks | Web Application Exploitation | ||
| Hydra wrapper for bruteforcing Microsoft Outlook Web Application | Networking | ||
| Comprehensive manual for mobile application security testing and reverse engineering. | Informations gathering | ||
| The industry standard for mobile application security. | Operating systems | ||
| Embeds XXE/XML exploits into different filetypes. | Vulnerabilities | ||
| Tool for embedding XXE/XML exploits into different filetypes (docx/xlsx, odt/ods, svg, xml, etc.) | Web Application Exploitation | ||
| An analysis tool for smart contracts. | Auth & perms | ||
| Identify the operating system of a target host simply by examining captured packets. | Network | ||
| PowerShell runspace post exploitation toolkit | System Exploitation | ||
| Execute padding oracle attacks with support for concurrent network requests and an elegant UI. | Informations gathering | ||
| Automate google hacking database scraping and searching. | Cloud & services | ||
| Identifies hidden, unlinked parameters, useful for finding web cache poisoning vulnerabilities. | Informations gathering | ||
| Brute discover GET and POST parameters. | Informations gathering | ||
| HTTP parameter discovery suite | Web Application Exploitation | ||
| CLI & library to search for default credentials among thousands of products/vendors. | Informations gathering | ||
| A network sniffer that logs all DNS server replies for use in a passive DNS setup. | Informations gathering | ||
| PHP Secure Configuration Checker; parse php.ini to find security misconfiguration | Configuration Audit | ||
| Converts PE into a shellcode | Red Teaming | ||
| Python Exploit Development Assistance for GDB. | Auth & perms | ||
| A compiled checklist of 300+ tips for protecting digital security and privacy. | Auth & perms | ||
| Command & Controll framework which silently persists on webserver via polymorphic PHP oneliner | Red Teaming | ||
| Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor. | Auth & perms | ||
| Get Active Directory security at 80% in 20% of the time. | Auth & perms | ||
| Collect HTTP or webhook requests and inspect them in a human-friendly way. | Network | ||
| A tool to make socks connections through HTTP agents. | Auth & perms | ||
| Interactive disassembler that generates indented pseudo-code with colored syntax. | Informations gathering | ||
| Prototype pollution scanner using headless chrome. | Informations gathering | ||
| An extensible multilanguage static code analyzer. | Development | ||
| Phone number wordlist generator | Cracking | ||
| Port scanner and banner grabber | Networking | ||
| A Chrome Extension to track postMessage usage (url, domain and stack). | Vulnerabilities | ||
| Search for sensitive data in Postman public library. | Informations gathering | ||
| Postman OSINT tool to extract creds, token, username, email & more from Postman Public Workspaces. | Informations gathering | ||
| Security testing and exploitation toolkit. | Informations gathering | ||
| Scan for client-side prototype pollution | Web Application Exploitation | ||
| A fast tool to scan client-side prototype pollution vulnerability written in Rust. | Auth & perms | ||
| Client-side prototype pollution scanner | Web Application Exploitation | ||
| The most advanced client-side prototype pollution scanner. | Auth & perms | ||
| Exploitation tool which leverages client-side Prototype Pollution to XSS. | Vulnerabilities | ||
| Prototype Pollution exploits collection. | Vulnerabilities | ||
| Swiss Army knife Proxy tool for HTTP(S) traffic capture, manipulation, and replay on the go. | Network | ||
| RFID tool designed to snoop, listen and emulate everything from Low to High Frequency tags. | Auth & perms | ||
| Force any TCP connection made by any given application to follow through proxy. | Network | ||
| Continuation of the unmaintained proxychains project. | Network | ||
| CLI tool designed to snoop on processes without need for root permissions; it allows to see commands run by other users, cron jobs, etc. as they execute | System Exploitation | ||
| Password list generator for orchestrating brute force attacks. | Informations gathering | ||
| Persistent multi reverse shell handler | Networking | ||
| Opensource, cross-platform C2 and post-exploitation framework written in python and C. | Operating systems | ||
| Puredns is a fast domain resolver & subdomain bruteforcing tool. | Informations gathering | ||
| Deep reinforcement learning instrumenting bettercap for WiFi pwning. | Network | ||
| Punch holes through firewalls/NATs where both clients and servers can be behind separate NATs. | Network | ||
| Sophisticated bind and reverse shell handler with many features as well as a drop-in replacement or compatible complement to netcat, ncat or socat | Networking | ||
| Netcat on steroids with many extra features. | Auth & perms | ||
| Fancy reverse and bind shell handler, can perform automated actions on the remote host including enumeration, implant installation and privilege escalation; attempt to spawn a pseudoterminal (pty) for a full interactive session | Networking | ||
| Self-deployable file hosting service allowing to easily upload and share payloads over HTTP and WebD. | Network | ||
| CTF framework and exploit development library. | Auth & perms | ||
| Framework and exploit development library | Binary Exploitation | ||
| Framework and exploit development library, ported onto ruby | Binary Exploitation | ||
| A multi-target URL bruteforcer. | Informations gathering | ||
| Partial python implementation of SharpGPOAbuse; modify an existing GPO by creating an immediate scheduled task as SYSTEM on the remote computer for computer GPO or logged in user for user GPO | Networking | ||
| A powerful and useful hacker dictionary builder for a brute-force attack. | Resources | ||
| Multi-method password wordlist generator | Cracking | ||
| Free web-application vulnerability and version scanner. | Informations gathering | ||
| Protocol demuxed honeypot and wordlists collected from it | Honeypot and Decoy | ||
| Platform idependent Mimikatz implementation | System Exploitation | ||
| Mimikatz implementation in pure Python. | Auth & perms | ||
| A (partial) Python rewriting of PowerSploit's PowerView. | Auth & perms | ||
| A partial Python rewriting of PowerSploit's PowerView | Networking | ||
| Look for several security related Android application vulnerabilities. | Operating systems | ||
| A generic and open source machine emulator and virtualizer. | Virtualization | ||
| QEMU Interactive Runtime Analyser. | Auth & perms | ||
| Quick network scanner library. | Informations gathering | ||
| qsfuzz is a tool that allows to write simple rules in YAML that define what value to inject | Auth & perms | ||
| Allows you to quickly substitute query string values with regex matches, one-at-a-time. | Informations gathering | ||
| Accept URLs on stdin, replace all query string values with a user-supplied value. | Auth & perms | ||
| UNIX-like reverse engineering framework and command-line toolset. | Auth & perms | ||
| Crossplatform binary analysis framework, disassembler, decompiler and debugger, support collaborative analysis | Reverse Engineering | ||
| Check whether the domain has a rate limit enabled. | Vulnerabilities | ||
| A semi-automated largely passive web application security audit tool. | Vulnerabilities | ||
| Rawsec Inventory search CLI to find security tools and resources | Other | ||
| Ruby BlackBag; a miscellaneous collection of command-line tools and ruby library helpers related to pen-testing and reversing | Reverse Engineering | ||
| Server for testing software against DNS rebinding vulnerabilities | Networking | ||
| Script to enumerate security settings of an RDP Service | Networking | ||
| Remote Desktop Protocol in twisted Python. | Network | ||
| Create a TCP circuit through validly formed HTTP requests. | Network | ||
| SOCKS proxies through the DMZ for pivoting | Networking | ||
| Pwn a bastion webserver and create SOCKS proxies through the DMZ. | Network | ||
| Automated recon framework for web applications; customizable scan engines & pipeline of reconnaissance | OSINT and Reconnaissance | ||
| OpenSource Poc && Vulnerable-Target Storage Box. | Auth & perms | ||
| Bruteforce WPS tool | Wireless | ||
| Bruteforce WPS tool | Wireless | ||
| Helper tool for black-box regex fuzzing to bypass validations. | Auth & perms | ||
| Perform automated recon on a target domain by running set of tools to perform scanning and finding out vulnerabilities | OSINT and Reconnaissance | ||
| Runs the best set of tools to perform scanning and finding out vulnerabilities on a target domain. | Auth & perms | ||
| Automated learning of regexes for DNS discovery. | Informations gathering | ||
| Rekall Memory Forensic Framework. | Auth & perms | ||
| Volatile memory extraction utility | Digital Forensics | ||
| Fork of rekall with support for Windows 10 memory compression | Digital Forensics | ||
| Find related domains of a given domain. | Informations gathering | ||
| Scan your code for security misconfiguration, search for passwords and secrets. | Informations gathering | ||
| The most exhaustive list of reliable DNS resolvers. | Informations gathering | ||
| Hosted Reverse Shell generator with a ton of functionality. | Auth & perms | ||
| Burp Suite plugin that extracts keywords from response using and test for reflected XSS. | Vulnerabilities | ||
| Rust-based high performance domain permutation generator. | Informations gathering | ||
| A micro-framework for writing and running exploits | Exploits | ||
| A micro-framework for writing and running exploit payloads | Exploits | ||
| Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects | Web Application Exploitation | ||
| Library for nmap, allows automating nmap and parsing nmap XML files | Networking | ||
| A tool to abuse Exchange services. | Network | ||
| Machine-learn password mangling rules; finds efficient password mangling rules (for John the Ripper or Hashcat) for a given dictionary and a list of passwords | Cracking | ||
| A cross-platform command-line tool for executing jobs in parallel. | Auth & perms | ||
| Web directory, file and DNS scanner (wordlist bruteforce); but also a web fuzzer | Web Application Exploitation | ||
| Find AWS S3 buckets and test their permissions. | Cloud & services | ||
| This extension will help you to detect GET/POST based XSS vulnerability in any website easily. | Vulnerabilities | ||
| Performs buckets checks from a given list of subdomains. | Cloud & services | ||
| Amazon S3 bucket finder and crawler. | Cloud & services | ||
| The format of various S3 buckets is convert in one format. | Cloud & services | ||
| A security toolkit for Amazon S3. | Cloud & services | ||
| JMX Exploitation Toolkit | Networking | ||
| Burp Extension for copying requests safely. | Network | ||
| Retrieves syskey and extract hashes from Windows 2k/NT/XP/Vista SAM, often used with bkhive, part of the ophcrack project | System Exploitation | ||
| Metasploit-like CLI interface for Nmap Script Engine (NSE) | Networking | ||
| The x86 processor fuzzer. | Auth & perms | ||
| x86 processor fuzzer | Reverse Engineering | ||
| Burp Suite extension which helps to improve the active and passive scanner by yourself. | Well known products | ||
| Online port scan scraper. | Informations gathering | ||
| multi-threaded post-exploitation scanning tool for scavenging systems, finding most frequently used files and folders as well as interesting files containing sensitive information | System Exploitation | ||
| The perfect butler for pentesters, bug-bounty hunters and security researchers. | Network | ||
| Monitors Github for leaked secrets. | Informations gathering | ||
| Continuous security scans based on kubernetes; orchestrate and automate a bunch of security-testing tools | Web Application Exploitation | ||
| Free and open platform for threat hunting, enterprise security monitoring, and log management. | Bug bounty | ||
| Searching for Sentry config on page or in Javascript files and check blind SSRF. | Vulnerabilities | ||
| Identifies server-side prototype pollution vulnerabilities. | Vulnerabilities | ||
| A post exploitation framework designed to operate covertly on heavily monitored environments. | Auth & perms | ||
| Shellbag parser (Windows Registry Keys) | Digital Forensics | ||
| Secrets detection for your GitHub, GitLab and Bitbucket repositories. | Source code management | ||
| Small tool to grab subdomains using Shodan API. | Cloud & services | ||
| Grab subdomains using Shodan api | OSINT and Reconnaissance | ||
| Enumerate valid subdomains using active bruteforce and DNS resolution. | Informations gathering | ||
| Wrapper around massdns that allows you to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard handling and easy input-output support | OSINT and Reconnaissance | ||
| Distributed systems and infrastructure simulator for attacking and debugging Kubernetes, creates a Kubernetes cluster in AWS and runs scenarios which misconfigure it or leave it vulnerable to compromise to train in mitigating against these vulnerabilities | Intentionally Vulnerable Applications | ||
| Swagger Jacker; audit API endpoints defined in exposed (Swagger/OpenAPI) definition files | Web Application Exploitation | ||
| Active web application security reconnaissance tool. | Informations gathering | ||
| Static analyzer for Solidity. | Auth & perms | ||
| Adversary emulation framework. | Auth & perms | ||
| A drop-in replacement for Nmap powered by shodan.io. | Auth & perms | ||
| Samba scanning tool. | Well known products | ||
| No-nonsense tool that takes credentials and a list of hosts and crawls through those shares. | Auth & perms | ||
| A handy SMB enumeration tool. | Informations gathering | ||
| Tool to scan for secret files on HTTP servers. | Informations gathering | ||
| Web scanner that looks for files accessible on web servers that shouldn't be public | Web Application Exploitation | ||
| Multithreaded script for bulk walking targeted host systems for SNMP data | Networking | ||
| IIS shortname scanner written in Go. | Well known products | ||
| Crawls the website and finds broken social media links that can be hijacked | Informations gathering | ||
| Continuous inspection. | Informations gathering | ||
| Simple and flexible tool for managing secrets. | Cryptanalysis | ||
| Extract JavaScript source trees from source map files. | Informations gathering | ||
| A tool to hunt for publicly accessible DigitalOcean Spaces. | Cloud & services | ||
| Node.js anti-spam, email filtering, and phishing prevention tool and service. | Informations gathering | ||
| OSINT framework, collect and manage data, scan target | OSINT and Reconnaissance | ||
| Web spidering library that can spider a site, multiple domains, certain links or infinitely | Web Application Exploitation | ||
| Fetch, install and search exploit archives from exploit sites like Packet Storm or Exploit-DB | Other | ||
| Simple script that checks a domain for email protection. | Informations gathering | ||
| Credentials gathering tool automating remote procdump and parse of lsass process. | Auth & perms | ||
| SQLI labs to test error based, blind boolean based, time based. | Resources | ||
| Python plugin for Burp Suite that integrates SQLMap using the SQLMap API. | Well known products | ||
| Automatic SQL injection and database takeover | Web Application Exploitation | ||
| Automatic SQL injection and database takeover tool. | Vulnerabilities | ||
| A friend of SQLmap which will do what you always expected from SQLmap. | Vulnerabilities | ||
| SSH server auditing: banner, key exchange, encryption, compatibility, security... | Cryptanalysis | ||
| SSH scanner that detects protocol, version, grab banner, recognize software and operating system, output algorithm information and recommendations | Networking | ||
| The best way to scan for weak ssh passwords on your network. | Informations gathering | ||
| Script to steal passwords from ssh. | Informations gathering | ||
| It's the C version of sshLooter. | Informations gathering | ||
| Brute force SSH public-key authentication interactively | Networking | ||
| CLI reference-implementation client for Qualys SSL Labs APIs, designed for automated and/or bulk testing | Web Application Exploitation | ||
| Tests SSL/TLS enabled services to discover supported cipher suites. | Cryptanalysis | ||
| Tests SSL/TLS enabled services to discover supported cipher suites | Web Application Exploitation | ||
| A tool for exploiting Moxie Marlinspike's SSL "stripping" attack. | Cryptanalysis | ||
| Steganography program that hides secrets in the least significant bits of a file. | Cryptanalysis | ||
| Debugger for Linux | Reverse Engineering | ||
| Esoteric sub-domain enumeration techniques - Bugcrowd LevelUp | Bug bounty | ||
| A fast tool to check subdomain takeover vulnerability. | Informations gathering | ||
| Hijacking forgotten & misconfigured subdomains. | Informations gathering | ||
| Discovers valid subdomains for websites, designed as a passive framework to be useful for bug bounties and safe for penetration testing | OSINT and Reconnaissance | ||
| Fetches javascript file from a list of URLS or subdomains. | Informations gathering | ||
| A fast passive subdomain enumeration tool that uses various sources to gather data. | Informations gathering | ||
| Extension of sublister tool to check for subdomain takeovers. | Informations gathering | ||
| DNS response-guided subdomain fuzzer | OSINT and Reconnaissance | ||
| A smart DNS response-guided subdomain fuzzer. | Informations gathering | ||
| Subdomain takeover vulnerability checker. | Informations gathering | ||
| A pure-python fully automated and unattended fuzzing framework. | Network | ||
| Simple script to extract all web resources by means of .SVN folder exposed over network. | Informations gathering | ||
| Extract and list API routes from Swagger files in YAML/JSON format. | Informations gathering | ||
| Automated brute-forcing attack tool. | Network | ||
| A tool for testing subdomain takeover possibilities at a mass scale. | Informations gathering | ||
| Validate the outgoing changeset for things that look suspicious such as tokens, passwords and keys. | Informations gathering | ||
| Enables you to safely and predictably create, change, and improve infrastructure. | Auth & perms | ||
| TLS/SSL scanner to find weak ciphers, protocols or flaws | Web Application Exploitation | ||
| Testing TLS/SSL encryption anywhere on any port. | Cryptanalysis | ||
| Security scanner for your Terraform code. | Informations gathering | ||
| E-mails, subdomains and names Harvester. | Informations gathering | ||
| Multi-purpose information gathering tool: emails, names, subdomains, IPs, URLs | OSINT and Reconnaissance | ||
| Repository of live malwares for malware analysis | Reverse Engineering | ||
| Open-source threat intelligence feeds; sharing malware URLs, IP reputation, bad IPs, etc. | Threat Intelligence | ||
| Collaborative forensic timeline analysis. | Auth & perms | ||
| Twitter intelligence analysis tool | OSINT and Reconnaissance | ||
| The most complete open-source tool for Twitter intelligence analysis. | Cloud & services | ||
| A tool that can help detect and takeover subdomains with dead DNS records. | Informations gathering | ||
| Fast and configurable TLS grabber focused on TLS based data collection. | Informations gathering | ||
| Open-source penetration testing tool that automates the process of exploiting XSS. | Vulnerabilities | ||
| XSS exploitation command-line interface and payload generator | Web Application Exploitation | ||
| Server-Side Template Injection and Code Injection Detection and Exploitation Tool. | Vulnerabilities | ||
| SSTI and code injection detection and exploitation tool | Web Application Exploitation | ||
| Like nmap for mapping wifi networks you're not connected to, plus device tracking. | Network | ||
| Tool for mapping and tacking wifi networks and devices through raw 802.11 monitoring | Wireless | ||
| Automatic Linux privilege escalation via exploitation of low-hanging fruit. | Auth & perms | ||
| Analysis and research tool, which allows people to track and execute intelligent social engineering attacks in real time | OSINT and Reconnaissance | ||
| People tracker on the Internet: OSINT analysis and research tool. | Informations gathering | ||
| Command line tool for URL parsing and manipulation. | Informations gathering | ||
| Network security scanner with an extensible plugin system. | Auth & perms | ||
| Time Travel Debugging IDA plugin | Plugins | ||
| Handle all network traffic of any internet programs sent by the device through a proxy. | Network | ||
| Twitter scraping & OSINT tool allowing you to scrape a user's followers, following, tweets and more. | Cloud & services | ||
| Denial of Service Toolkit. | Network | ||
| Translate sigma rules into various SIEM, EDR, and XDR formats | Incident Response | ||
| Python 2.7 binaries (.pyc) decompiler | Reverse Engineering | ||
| Python 1.5, 2.1 to 2.7, 3.1 to 3.6 binaries (.pyc) decompiler | Reverse Engineering | ||
| A cross-version Python bytecode decompiler. | Auth & perms | ||
| Quickly discover exposed hosts on the internet using multiple search engines. | Informations gathering | ||
| Discover exposed hosts on the internet using multiple search engines | OSINT and Reconnaissance | ||
| Optimized Selenium Chromedriver patch which does not trigger anti-bot services. | Auth & perms | ||
| An Entropy-Based Link Vulnerability Tool. | Informations gathering | ||
| Tool for using a PowerShell downgrade attack and inject shellcode into memory | System Exploitation | ||
| Simple tool for using a PowerShell downgrade attack and inject shellcode into memory. | Development | ||
| Toolkit for security research manipulating Unicode: confusables, homoglyphs, hexdump, code point, UTF-8, UTF-16, UTF-32, properties, regexp search, size, grapheme, surrogates, version, ICU, CLDR, UCD | Other | ||
| Shell script to check for simple privilege escalation vectors on Unix systems. | Auth & perms | ||
| File upload restrictions bypass by using different techniques! | Vulnerabilities | ||
| De-clutter a list of URLs. | Informations gathering | ||
| A golang utility to spider through a website searching for additional links. | Informations gathering | ||
| Allows searching on URLs that are exposed via shortener services. | Informations gathering | ||
| Declutters url lists for crawling/pentesting. | Informations gathering | ||
| Tool and framework for securely reading untrusted USB mass storage devices | Defensive | ||
| User-Agent, X-Forwarded-For and Referer SQLI Fuzzer. | Network | ||
| CTF toolkit / framework | Other | ||
| Web directory and file scanner (wordlist bruteforce); but also a web fuzzer | Web Application Exploitation | ||
| Cross-platform very advanced and fast web fuzzer written in nim. | Auth & perms | ||
| Hide any type of files inside a image of your choice using steganography. | Cryptanalysis | ||
| Detect, manage and exploit Blind Cross-site scripting (XSS) vulnerabilities. | Vulnerabilities | ||
| A black box vBulletin vulnerability scanner. | Auth & perms | ||
| Vulnerability Compliance Report; parse Nessus CIS benchmark scan files and generate HTML reports | Collaboration and Report | ||
| Plugin-based tool to scan public version control systems for sensitive information. | Source code management | ||
| Searching for virtual hosts among non-resolvable domains. | Informations gathering | ||
| The volatile memory extraction framework. | Auth & perms | ||
| Volatile memory extraction utility | Digital Forensics | ||
| Fork of volatility with support for Windows 10 memory compression | Digital Forensics | ||
| Volatility3 plugins that can retrieve partial and full gpg passphrases from gpg-agent's cache | Plugins | ||
| Vulnerability Dashboard; vulnerability database, project management and report generation | Collaboration and Report | ||
| Pre-built vulnerable environments based on docker-compose. | Resources | ||
| Create a vulnerable active directory to test most of the active directory attacks in a local lab. | Auth & perms | ||
| Vulnerability scanner based on vulners.com search API | Plugins | ||
| VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import Nmap/Nessus/Burp/OpenVAS/Bugcrowd/Trivy, Jira export, TXT/JSON/MARKDOWN/HTML/DOCX, attachments, automatic changelog, stats, vulnerability management, bugbounty, local ai/llm, super fast pentest reporting! | Collaboration and Report | ||
| Web application attack and audit framework, web-oriented security scanner | Web Application Exploitation | ||
| Web Application Attack and Audit Framework. | Auth & perms | ||
| A WPA3 dictionary cracker. | Network | ||
| Check your WAF before an attacker does. | Network | ||
| Identify and fingerprint Web Application Firewall products protecting a website. | Network | ||
| Web-oriented vulnerability scanner, can generates reports | Web Application Exploitation | ||
| Gather urls from wayback machine and test each GET parameter for SQL injection. | Cloud & services | ||
| Fetch all the URLs that the Wayback Machine knows about for a domain. | Cloud & services | ||
| Find links from Wayback Machine, Common Crawl, Alien Vault OTX and URLScan; download the archived responses for URLs on Wayback Machine | OSINT and Reconnaissance | ||
| The open source security platform. | Bug bounty | ||
| Database of wordlists for hash cracking and compilation of best wordlists. | Informations gathering | ||
| A web hacking toolkit. | Virtualization | ||
| Automate converting webshells into reverse shells. | Vulnerabilities | ||
| Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning | Web Application Exploitation | ||
| Uncovers technologies used on websites to automate mass scanning. | Auth & perms | ||
| A lightweight incoming webhook server to run shell commands. | Auth & perms | ||
| Easily test HTTP webhooks with this handy tool that displays requests instantly. | Network | ||
| A very simple webhook server launching shell scripts. | Auth & perms | ||
| A tool that traverses a website and generates a tree of all the webpages and their links. | Informations gathering | ||
| A simple script to screenshot a list of websites. | Informations gathering | ||
| Keep an eye on your targets to get quickly notified for any change they push on their server. | Informations gathering | ||
| Weaponized web shell. | Development | ||
| Semantic search tool for C and C++ designed to help security researchers identify interesting functionality in large codebases | Code Analysis | ||
| Generate rich wordlists for targeted attacks online. | Resources | ||
| A malicious DNS server for executing DNS Rebinding attacks on the fly. | Informations gathering | ||
| Local Area Network discovery tool with a modern Terminal User Interface (TUI) written in Go. Discover, explore, and understand your LAN in an intuitive way. Whosthere performs unprivileged, concurrent scans using mDNS and SSDP scanners. Additionally, it sweeps the local subnet by attempting TCP/UDP connections to trigger ARP resolution, then reads the ARP cache to identify devices on your Local Area Network. This technique populates the ARP cache without requiring elevated privileges. All discovered devices are enhanced with OUI lookups to display manufacturers when available. Whosthere provides a friendly, intuitive way to answer the question every network administrator asks: "Who's there on my network?" | Network | ||
| Android application to brute force WiFi passwords without requiring a rooted device. | Network | ||
| Script to jam wifi clients and access points | Wireless | ||
| Continuously jam all wifi clients/routers. | Network | ||
| The rogue access point framework. | Network | ||
| Powerful framework for rogue access point attack. | Network | ||
| Runs existing wireless-auditing tools for you. Stop memorizing command arguments & switches! | Informations gathering | ||
| Script for auditing wireless networks that runs existing wireless-auditing tools | Wireless | ||
| Nikto for Windows with some extra features. | Informations gathering | ||
| Nikto for Windows; web security scanner | Web Application Exploitation | ||
| Crawls URL to get a better image of what is tied to a website. | Informations gathering | ||
| Enumerate users, groups and computers from a Windows domain through LDAP queries. | Auth & perms | ||
| Script to enumerate users, groups and computers from a Windows domain through LDAP queries | Networking | ||
| A list of Windows kernel exploits. | Operating systems | ||
| Standalone executable to check for simple privilege escalation vectors. | Auth & perms | ||
| Automate building wordlists for AppSec directory/resource bruting. | Resources | ||
| Perform different ways of command execution via WMI protocol (port 135) for AV evasion | Networking | ||
| The new generation of wmiexec.py with all operations performed on port 135 for antivirus evasion. | Auth & perms | ||
| Modify version of impacket wmiexec.py, get output from registry. | Auth & perms | ||
| Library for reading, combining, manipulating, and building wordlists, efficiently | Cracking | ||
| Fetch, install and search wordlist archives from websites and torrent peers. | Resources | ||
| Fetch, install and search wordlist archives from websites and torrent peers | Cracking | ||
| Generate context-specific wordlists for content discovery from lists of URLs or paths | Cracking | ||
| Quickly generate context-specific wordlists for content discovery from lists of URLs or paths. | Informations gathering | ||
| Static code analysis for WordPress Plugins and Themes (and PHP) | Code Analysis | ||
| wpfinger is a red-team WordPress scanning tool. | CMS | ||
| Generates a php://filter chain that adds a prefix and a suffix to the contents of a file | Web Application Exploitation | ||
| Interactive websocket REPL designed specifically for penetration testing | Web Application Exploitation | ||
| Tunneling over websocket protocol - Static binary available. | Network | ||
| Passive hostname, domain and IP lookup tool for non-robots. | Informations gathering | ||
| Windows debugger | Reverse Engineering | ||
| An open-source user mode debugger for Windows for reverse engineering and malware analysis. | Informations gathering | ||
| HTTP parameter discovery suite | Web Application Exploitation | ||
| Discover endpoints and potential parameters for a given target | Web Application Exploitation | ||
| A python tool used to discover endpoints and potential parameters for a given target. | Informations gathering | ||
| Security assessment tool that supports common web security issue scanning and custom PoC. | Auth & perms | ||
| PNG IDAT chunks XSS payload generator. | Vulnerabilities | ||
| A Burp Intruder extender designed for automation and validation of XSS vulnerabilities. | Vulnerabilities | ||
| Fast, thorough, XSS/SQLi spider. | Vulnerabilities | ||
| Hack with JavaScript. | Vulnerabilities | ||
| A cli utility to find domain's known URLs from curated passive online sources. | Informations gathering | ||
| HTTP and FTP server for OOB XXE attacks | Web Application Exploitation | ||
| A mini webserver with FTP support for XXE payloads. | Network | ||
| XPath injection tool, designed for blind injection | Web Application Exploitation | ||
| XPath injection tool, fork of xxxpwn adding further optimizations and tweaks, uses predictive text based on a dictionary of words/phrases vs frequencies of occurrence | Web Application Exploitation | ||
| Small script for carving, scanning, compressing, decompressing and analyzing SWF files | Reverse Engineering | ||
| Find secret information (secrets, tokens, passwords) in git repositories | OSINT and Reconnaissance | ||
| Creates statistics on a yara rule set and files in a sample directory | Incident Response | ||
| YARA rules generator | Incident Response | ||
| Framework for layer 2 attacks | Networking | ||
| A framework for layer 2 attacks. | Network | ||
| Generates payloads that exploit unsafe Java object deserialization. | Development | ||
| Tool for generating payloads that exploit unsafe Java object deserialization | System Exploitation | ||
| Deserialization payload generator for a variety of .NET formatters. | Development | ||
| Network attack tool. | Network | ||
| Fast CLI DNS lookup tool. | Informations gathering | ||
| Fast Go application scanner. | Network | ||
| Fast single packet network scanner designed for Internet-wide network surveys. | Informations gathering | ||
| Detect stegano-hidden data in PNG & BMP. | Cryptanalysis | ||
| Tool to detect hidden data in PNG and BMP | Steganography |