Penetration testing tools

Unlock the full potential of your penetration testing engagements with our curated collection of essential commands and tools. This resource is designed for security professionals seeking to streamline their workflows, discover new techniques, and enhance their testing capabilities. Whether you are identifying vulnerabilities, exploiting misconfigurations, or automating tasks, these tools will equip you to tackle real-world challenges efficiently and effectively.

Filters

Category

Open Source

Has Video Review

Used in Reports

(2757 tools)
NameDescriptionCategoryAttributes
Tool for automating customized attacks against web applications.Bug bounty
Automate customized attacks against web applicationsWeb Application Exploitation
zero-configuration DNS utilities for assisting in detection and exploitation of SSRF-related vulnerabilitiesWeb Application Exploitation
Bake a windows payload from the C2 of your choice to bypass AVRed Teaming
FTP server for OOB XXE attacksWeb Application Exploitation
Enumerate s3 buckets for a specific target.Cloud & services
403/401 Bypass Methods.Auth & perms
A Burp Suite extension made to automate the process of bypassing 403 pages.Auth & perms
HTTP 403 bypass tool.Auth & perms
Advanced discovery of Privileged Accounts, includes Shadow Admins.Auth & perms
Active Directory assessment and privilege escalation script.Auth & perms
Wrapper around adb to ease certain tasksMobile
ADCS exploitation automation by weaponizing Certipy and CoercerNetworking
Read information from Active Directory and ADFS Configuration Database; fed information into ADFSpoof to generate security tokensSystem Exploitation
Using ADFSDump information, produce a usable key/cert pair for token signing, produce a signed security token that can be used to access a federated applicationSystem Exploitation
Active Directory audit tool that extract data from Bloodhound to uncover security weaknesses and generate an HTML reportNetworking
Active Directory Report Tool.Informations gathering
Enumerate an Active Directory environment with LDAP queries.Auth & perms
Gather information about the Active Directory and generates a report.Auth & perms
Gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environmentNetworking
Active Directory delegation management tool allowing to make a detailed inventory of delegations set up so far in a forestReconnaissance
Find misconfiguration through the LDAP protocol and exploit some weaknesses with kerberosNetworking
Find misconfiguration through LDAP to exploit weaknesses with Kerberos.Auth & perms
Online virtual machine for malware hunting, sandbox with interactive access, real-time data-flowReverse Engineering
All in one recon tool for bug bounty.Informations gathering
Fuzz request attributes using common pentesting techniques and lists vulnerabilities.Development
Library to fuzz request attributes using common pentesting techniques and lists vulnerabilitiesWeb Application Exploitation
Passive enumeration utility For Android applications.Operating systems
Static code analysis for Android apps that is based on the OWASP MASVS frameworkCode Analysis
Scanning APK file for URIs, endpoints & secrets.Informations gathering
Scanning APK file for URIs, endpoints and secretsCode Analysis
Android application identifier for packers, protectors, obfuscators and oddities.Operating systems
APTRS (Automated Penetration Testing Reporting System) is an automated reporting tool in Python and Django. The tool allows Penetration testers to create a report directly without using the Traditional Docx file. It also provides an approach to keeping track of the projects and vulnerabilities.Collaboration and Report
Automated penetration testing reporting system.Bug bounty
Tool for ASLR bypass with stack-sprayingBinary Exploitation
Leverage ASN to look up IP addresses owned by a specific organization.Informations gathering
CLI and Library for quickly mapping organization network ranges using ASN informationNetworking
Quickly maps organization network ranges using ASN information.Informations gathering
Authentication Token Obtain and Replace Extender.Auth & perms
AntiVirus Evasion Tool; targeting windows machines with executable filesRed Teaming
Identify and test S3 buckets, Google Storage buckets and Azure Storage containers for common misconfigurationPlugins
Command-line script to test cloud storage for common misconfiguration issues.Cloud & services
Test S3 buckets as well as Google Storage buckets and Azure Storage containers for common misconfiguration issuesCloud
This script enumerates the permissions of all the AWS principals of an account.Auth & perms
This Burp Suite provides additional Scanner checks for AWS security issues.Cloud & services
Security Tool to Look For Interesting Files in S3 Buckets.Cloud & services
A damn vulnerable AWS infrastructure.Cloud & services
Pull secrets from an AWS environment.Cloud & services
Database protection suite with field level encryption and intrusion detection.Cryptanalysis
Enumerate AD through LDAP with a collection of helpfull scripts being bundled: ASREPRoasting, Kerberoasting, dump AD as BloodHound JSON files, searching GPOs in SYSVOL for cpassword and decrypting, run without credsNetworking
Extends Burp Suite's active and passive scanning capabilities.Well known products
Quickly find and fix the vulnerabilities that put your web applications at risk of attack.Bug bounty
Web application security scannerWeb Application Exploitation
Active Directory ACL visualizer and explorer; similar to BloodHoundNetworking
Android APK reversing and analysis suiteCode Analysis
API key/token exploitation made easy.Informations gathering
A library of adversary emulation plans to allow organizations to evaluate their defensive capabilities against the real-world threats they faceAdversary Simulation
Web directory and file scanner (wordlist bruteforce)Web Application Exploitation
Burp Suite extension for dynamic payload generation to detect injection flaws.Vulnerabilities
Android remote administration tool.Operating systems
Suite of tools to assess WiFi network security (cracking WEP and WPA PSK)Wireless
Bug Bounty notes gathered from various sources.Auth & perms
Generates permutations, alterations and mutations of subdomains and then resolves them.Informations gathering
DNS enumeration and network mapping tool suite: scraping, recursive brute forcing, crawling web archives, reverse DNS sweepingOSINT and Reconnaissance
In-depth Attack Surface Mapping and Asset Discovery.Informations gathering
Post-exploitation framework designed to assist with lateral movement within Active Directory.Auth & perms
Software utility with a collection of forensic tools for smartphones; performs read-only, non-destructive acquisitionDigital Forensics
Android APK vulnerability analyzerCode Analysis
Manage Burp Suite certificate in Android to redirect all traffic to Burp Suite.Operating systems
Grants root privileges on the fly to shells running on Android virtual machines that use google-provided emulator images called Google API PlaystoreSystem Exploitation
Fast and simple-to-use open-source/cross-platform network scanner.Informations gathering
Statistical learning algorithm to create a model on the command lines of the Process Creation events on Windows, in order to detect anomalies in future eventsDefensive
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0AI Skills
Multi-AV checker that doesn't distribute the check results, based on Dyncheck.comRed Teaming
Steganalysis web platform with layer, zsteg, steghide and exiftool analysisSteganography
Tool for automating the search for IDOR vulnerabilities in web applications and APIs.Vulnerabilities
Android decompiler (wrapper for apktool, dex2jar, and jd-gui)Reverse Engineering
Android disassembler and rebuilderReverse Engineering
A tool for reverse engineering Android APK files.Operating systems
eLearning management system for information securityLearning
A Tool for Domain Flyovers.Auth & perms
Domain flyover tool; visual inspection of websites across a large amount of hosts and is convenient for quickly gaining an overview of HTTP-based attack surfaceWeb Application Exploitation
Web application security scanner frameworkWeb Application Exploitation
Web Application Security Scanner Framework.Auth & perms
OSINT tool used for web crawling or examining JavaScript files for likely useful data.Informations gathering
Vulnerability Assessment and Management tool, run scan and manage vulnerabilitiesCollaboration and Report
Endpoint for Out-of-Band Exfiltration (DNS & HTTP)Networking
Static analysis framework built in house to do security vetting for Android applications.Operating systems
HTTP parameter discovery suite.Informations gathering
HTTP parameter discovery suiteWeb Application Exploitation
Just a quick inventory, reminder and launcher for pentest commands.Auth & perms
Another Subdomain ENumeration Tool.Cloud & services
Leverage ASN to look up IP addresses (IPv4 & IPv6) owned by a specific organization for reconnaissance purposes, then run port scanning on itOSINT and Reconnaissance
Web pentest framework for information gathering and vulnerability scanningWeb Application Exploitation
Automated Security Testing For REST API's.Vulnerabilities
REST API penetration testing toolWeb Application Exploitation
DNS asynchronous brute force utility.Informations gathering
Arch Linux-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool!Resources
Coverage-guided Python fuzzing engineFuzzing
Tool that suggests sqlmap tampers to bypass WAF/IDS/IPS based on status codesWeb Application Exploitation
Small and highly portable detection tests based on MITRE's ATT&CK.Auth & perms
A library of tests mapped to the MITRE ATT&CK® framework used to quickly, portably, and reproducibly test their environmentsAdversary Simulation
A platform built for productivity, collaboration and visibility.Bug bounty
AttackForge helps you manage your penetration testing programs, and deliver large-scale pentesting services. Pentest Management and Reporting Made Easy, A Platform Built for Productivity, Collaboration and Visibility.Collaboration and Report
AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.Informations gathering
Subdomain enumeratorOSINT and Reconnaissance
Distribution for pentesting IoT devices.Operating systems
Tool to edit and analyze audio tracksSteganography
The Burp extension helps you to find authorization bugs.Vulnerabilities
Provides a simple way to test authorization in web applications and web services.Auth & perms
Multi-threaded network reconnaissance tool which performs automated enumeration of servicesOSINT and Reconnaissance
Multi-threaded network reconnaissance tool which performs automated enumeration of services.Informations gathering
Automated HTTP request repeating with Burp Suite.Well known products
Automated Mass Exploiter.Cloud & services
Automatic authorization enforcement detection extension for Burp Suite.Auth & perms
A one-stop pentesting checklist and logger tool.Resources
Service to check if an account has been compromised in a data breach, send an email with the breaches not the passwordOSINT and Reconnaissance
A comprehensive curated list of available Bug Bounty & disclosure programs and writeups.Bug bounty
A curated list of bugbounty writeups (Bug type wise).Bug bounty
List of awesome CobaltStrike resources.Resources
🔥🔒 Awesome MCP (Model Context Protocol) Security 🖥️AI MCP Servers
Dynamic infrastructure framework to distribute the workload of many different scanning tools with easeCloud
Lateral movement graph for Azure Active Directory.Auth & perms
Gathers information about the Azure Active Directory and generates a report which can provide a holistic picture of the current state of the target environmentCloud
A damn vulnerable Azure infrastructure.Cloud & services
Toolkit to detect and keep track on Blind XSS, XXE & SSRF.Vulnerabilities
Displays stats and graphs about your Bug Bounty activity.Bug bounty
Aggregate reports/bounties from different platforms in order to create combined stats and graphsBug bounty
Bull's Eye Wordlist Generator, password wordlist generator based on target informationCracking
Backup File Artifacts Checker; automated backup artifacts checkerWeb Application Exploitation
Check for backup artifacts that may disclose the web-application's source code.Informations gathering
Extract information from BloodHound and Neo4JOther
A .NET Runtime for Cobalt Strike's Beacon Object FilesRed Teaming
Bloodhound Query Merger; deduplicate custom BloudHound queries from different datasets and merge them in one customqueries.json fileOther
Enumerating and attacking Java Remote Method Invocation services.Development
Java RMI enumeration and attack toolWeb Application Exploitation
Generate wordlist based on the URLs to check for backup, installation, etc files.Informations gathering
Bandit is a tool designed to find common security issues in Python code.Code Analysis
Binary Analysis and Reverse engineering FrameworkReverse Engineering
The Browser Exploitation Framework is a penetration testing tool that focuses on the web browser.Vulnerabilities
Multiplaform privilege escalation project.Auth & perms
Static application security testing tool that helps discover, filter, and prioritize security risks and vulnerabilitiesCode Analysis
HTTP request collector and inspectorWeb Application Exploitation
OSINT tool, collect data and document actively or passivelyOSINT and Reconnaissance
A backdoor with a multitude of features.Auth & perms
Code Scanning/SAST/static analysis/linting using many tools/scanners with one report.Informations gathering
Quickly find differences and similarities in disassembled code.Auth & perms
Crossplatform binary analysis frameworkReverse Engineering
Injects custom XSS payloads on every form/request submitted to detect blind XSS.Vulnerabilities
Reconnaissance Apparatus; Information gathering, conglomerate of tools including custom algorithms, API wrappersOSINT and Reconnaissance
Web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.Informations gathering
Identify usage of pre-shared Machine Keys in a application for encryption and decryption.Development
Login page bruteforcer: CSRF, SQLi, Clickjacking, WAF detectionWeb Application Exploitation
Tool to reveal the hidden and unintended relationships within an Active Directory environmentSystem Exploitation
Six Degrees of Domain Admin.Auth & perms
Pinpoint the security issues that actually matter.Auth & perms
Helps blue teams pinpoint the security issues that actually matter by combining information about user permissions, network access and unpatched vulnerabilities, to reveal the paths attackers would take if they were inside the networkDefensive
Client-side vulnerability playground, CTF style application, a bot program which simulates the real-world victimIntentionally Vulnerable Applications
Client/Server HTTP pivoting toolNetworking
Before Outset PaSsword CRacKing, password wordlist generator with exclusive features like lyrics based modeCracking
Stealth redirector for your red team operation security.Network
Aggregate reports/bounties from different platforms in order to create combined stats and graphs, report and template management system, invoice creation system Bug bounty
Dashboard to combine rewards from all platforms, giving insights about progress and bug hunting patternsBug bounty
Combine your rewards from platforms giving you insights about your bug hunting progress.Bug bounty
Static analysis security vulnerability scanner for Ruby on Rails applicationsCode Analysis
Service to check if an account has been compromised in a data breach, display the breaches, partial password and hashOSINT and Reconnaissance
A framework including all the tools that work on Windows.Virtualization
Command & Control server; DNS over HTTPS, external channels, indirect syscallsRed Teaming
Network forensic analysis tool that performs deep processing and inspection of network traffic.Auth & perms
Takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using MedusaNetworking
Tool using nmap and hydra to automatically bruteforce network service accountsNetworking
Automatically brute force all services running on a target.Informations gathering
Tool written in Python simply to find XSS vulnerabilities in web application.Vulnerabilities
Bluetooth Low Energy Swiss-army knifeWireless
Find interesting Amazon S3 Buckets by watching certificate transparency logs.Cloud & services
An automated S3-compatible bucket inspector.Cloud & services
Launchpad for bug bounty programs and bug bounty hunters.Auth & perms
A list of Bug Bounty writeups that is categorized by the bug nature.Bug bounty
Bug Bounty Reports Explained channel.Resources
Adversarial AI bug hunter with auto-fix skill for Claude Code, Cursor, Codex CLI, GitHub Copilot CLI, Kiro CLI, Opencode, Pi Coding Agent, and more. Multi-agent pipeline finds security vulnerabilities, logic errors, and runtime bugs — then fixes them autonomously on a safe branch.AI Skills
App that helps bug bounty hunters to manage their bounties and target listBug bounty
Helping you become a BugBountyHunter.Resources
Search Bug Bounty writeups easily.Bug bounty
A Bash script and Docker image for Bug Bounty reconnaissance, intended for headless use.Virtualization
Automated firmware analysis tool for composition analysis and vulnerability scanning.Operating systems
Autonomous AI-powered security scanner — multi-agent vulnerability detection, exploitation, and validation engineArtificial Intelligence
Terminal dashboard for bug bounty hunters that use HackerOne and BugcrowdBug bounty
Bugcrowd’s baseline priority ratings for common security vulnerabilities.Bug bounty
Find out what websites are Built With.Informations gathering
Collaborative penetration test, vulnerability database and reporting platformCollaboration and Report
Burp Extender API.Development
Burp extension to decode NTLM SSP headers and extract domain/host information.Auth & perms
The class-leading vulnerability scanning, penetration testing, and web app security platform.Network
Intercepting proxy to replay, inject, scan and fuzz HTTP requests (a limited free version exists)Web Application Exploitation
Find known vulnerabilities in WordPress plugins and themes, WPScan like plugin for Burp.CMS
Performs passive scan to identify buckets and test them for publicly accessible vulnerabilities.Cloud & services
Burp Suite extension to encode an IP address focused to bypass application IP/domain blacklist.Cryptanalysis
Generates wordlists from the Burp sitemap.Resources
Performing SQLInjection test on Burp Suite Bulk Requests using SQLMap.Well known products
Burpsuite extension for beautifying request/response body.Development
Improve the active and passive Burp Suite scanner by means of custom rules through GUI.Well known products
Scan Check Builder in BApp Store, improve the active and passive scanner by means of personalized rules through a graphical interfacePlugins
A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan.Well known products
Burp Extension for a passive scanning JS files for endpoint links.Development
GUI Burp Plugin to ease discovering of security holes in web applications.Vulnerabilities
A Burp Suite content discovery plugin that add the smart into the Buster.Informations gathering
A Burp Suite extension to bypass WAFs or test their effectiveness using a number of techniques.Vulnerabilities
Intentionally-vulnerable Kubernetes cluster, intended to help people self-train on attacking and defending Kubernetes clustersIntentionally Vulnerable Applications
Tool that tests MANY url bypasses to reach a 40X protected page.Auth & perms
A simple script just made for self use for bypassing 403.Auth & perms
Malware sandbox derived from Cuckoo with the goal of adding automated malware unpacking, config and payload extractionReverse Engineering
Make security testing of K8s, Docker, and Containerd easier.Virtualization
Create a copy of a targeted website with CDN and WAF restrictions disabled.Cloud & services
PE EditorReverse Engineering
Asses systems against CIS BenchmarksConfiguration Audit
Asses systems against CIS BenchmarksConfiguration Audit
A project for fuzzing HTTP/1.1 CL.0 Request Smuggling attack vectors.Network
Scan Wordpress, Drupal, Joomla, vBulletin websites for security issues.CMS
Wordpress, Drupal, Joomla, vBulletin CMS security scanner with dashboardWeb Application Exploitation
CMS Detection and Exploitation suite that supports over 180 other CMSs.CMS
CMS detection and exploitation suite; capable of detecting more than 180 CMSWeb Application Exploitation
CMS scanner that automates the process of detecting security flaws of the most popular CMSs.CMS
WordPress, Joomla, Drupal, Moodle CMS security scannerWeb Application Exploitation
A multi-threaded scanner that helps identify CORS flaws/misconfigurations.Vulnerabilities
A simple CORS misconfiguration scanner.Vulnerabilities
Command line tool for testing CRLF injection on a list of domains.Vulnerabilities
CRLFMap is a tool to find HTTP Splitting vulnerabilities.Vulnerabilities
The most powerful CRLF injection scanner.Vulnerabilities
A fast tool to scan CRLF vulnerability written in Go.Auth & perms
A fun, free platform for learning modern cryptography.Resources
Large-scale firmware analysis of cryptographic misuse in IoT devices; supports ARM, MIPS, MIPSel architeturesCryptography
Check CSP serves as a strong mitigation against cross-site scripting attacks.Vulnerabilities
Check Content Security Policy (CSP) configuration and assists with the reviewing processWeb Application Exploitation
Test for CSP bypass payloadsWeb Application Exploitation
A lightweight CSRF Toolkit for easy Proof of Concept.Vulnerabilities
Cobalt Strike Shellcode Generator; script used to more easily generate and format beacon shellcode in Cobalt StrikeRed Teaming
Cyber Security Transformation Chef; chaining simple operations and formatting on each incoming or outgoing HTTP messagePlugins
Cross-Site WebSocket Hijacking TesterWeb Application Exploitation
Collaborative platform for CTF teams, event planning, credentials sharing, tasks management, notes takingCollaboration and Report
Abusing Certificate Transparency logs for getting HTTPS websites subdomains.Informations gathering
A Capture The Flag framework focusing on ease of use and customizability.Resources
Common User Passwords Profiler, wordlist generator based on user profilingCracking
Common User Passwords Profiler.Informations gathering
A hub for finding CVEs and exploits based on the official NIST, ExploitDB and Github databases.Auth & perms
CLI tool designed to provide a structured interface to various vulnerability databasesVulnerability Assessment
Navigate the CVE jungle with ease using CLI tool designed to provide a structured interface.Auth & perms
Intercepting proxy to replay, inject, scan and fuzz HTTP requests (a limited free version exists)Web Application Exploitation
Password recovery tool for Microsoft Operating Systems.Network
Cutting-edge project designed to automate the continuous discovery of vulnerabilities in webapps.Development
Cyber security platform designed to easily automate adversary emulation, assist manual red-teams, and automate incident responseAdversary Simulation
Automated adversary emulation platform.Auth & perms
RTSP stream access; detect open hosts, device model, automated dictionary attacks on stream route and credentialsReconnaissance
A list of DNS providers and how to claim (sub)domains via missing hosted zones.Informations gathering
A list of services and how to claim (sub)domains with dangling DNS records.Informations gathering
Quickly deployable honeypot with docker image, the online service allows to get alerted by email for URL token, DNS token, unique email address, custom image, MS word doc., Acrobat Reader PDF doc., and moreHoneypot and Decoy
Track activity and actions on your network.Network
Penetration test platform: vulnerability database and reportingCollaboration and Report
Web directory and file scanner (wordlist bruteforce)Web Application Exploitation
Assessment tool that allows penetration testing and hostile attack simulations.Auth & perms
PCAP analyzerNetworking
Create a spoofed certificate of any online website and signs an executable for AV Evasion; works for Windows and LinuxRed Teaming
Creates a spoofed certificate of any online website and signs an executable for AV evasion.Informations gathering
Assessment of on-premises Microsoft servers such as ADFS, Skype, Exchange, and RDWebNetworking
Custom Word List Generator.Informations gathering
CeWL is a Custom Word List GeneratorCracking
Custom word list generator redefined, based on the Scrapy framework.Resources
Extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.Informations gathering
Perform subdomain enumeration using the certificate transparency logs from Censys.Informations gathering
File analyzer and inspectorDigital Forensics
Unstrip Rust and Go binaries (ELF and PE) for static analysis; based on hashing and scoring systems, it can retrieve lots of symbol namesReverse Engineering
Network services credentials brute-forcer: SSH, FTPNetworking
Uses data from SSL Certificates to find potential host names.Cloud & services
A .NET tool for exporting and importing certificates without touching disk.Cryptanalysis
A CLI tool to extract server certificates.Informations gathering
Get informations about SSL certificates.Informations gathering
Active Directory certificate abuse.Auth & perms
Active Directory Certificate Services enumeration and abuse.Auth & perms
Active Directory Certificate Services enumeration and exploitationNetworking
Intelligence feed that gives real-time updates from the Certificate Transparency Log networkOSINT and Reconnaissance
Cervantes is an open-source, collaborative platform designed specifically for pentesters and red teams. It serves as a comprehensive management tool, streamlining the organization of projects, clients, vulnerabilities, and reports in a single, centralized location.Collaboration and Report
Tool to bypass disable_functions and open_basedir in PHP by calling sendmail and setting LD_PRELOAD environment variableWeb Application Exploitation
Collect and maintain internet-wide assets data for public Bug Bounty programs.Informations gathering
HTTP proxy / monitor / reverse proxy that allows to view all of the HTTP(S) traffic.Network
Intercepting proxy to replay, inject, scan and fuzz HTTP requestsWeb Application Exploitation
Obfuscation script designed to bypass AMSI and commercial antivirus solution.Cryptanalysis
Toolchain for side-channel power analysis and glitching attacksHardware
Web application security scanner based on templatesWeb Application Exploitation
Scan endpoints and identify exposition of sensitive services/files/folders.Informations gathering
A searchable directory of TLS ciphersuites and related security detailsCryptography
Automates decryptions & decodings with encodings, classical ciphers, hashes, or more.Cryptanalysis
Android and Java bytecode viewer.Development
Uncover the true IP address of websites safeguarded by Cloudflare & others.Cloud & services
Awesome cloud enumerator.Cloud & services
Utilize misconfigured DNS and old database records to find hidden IPs behind CloudFlare network.Cloud & services
Find origin servers of websites behind Cloudflare by using Internet-wide scan data from Censys.Cloud & services
Scanner to identify misconfigured CloudFront domainsWeb Application Exploitation
A tool for identifying misconfigured CloudFront domains.Cloud & services
Vulnerability scanner for AWS customer managed policies using ChatGPTCloud
Vulnerable by design AWS deployment tool.Cloud & services
Route53/CloudFront Vulnerability assessment utility.Cloud & services
CloudMapper helps you analyze your Amazon Web Services environments.Cloud & services
Analyze AWS environments auditing for security issuesCloud
Finding assets and subdomains from certificates! Scan the web!Informations gathering
Tool to enumerate targets in search of cloud resources.Cloud & services
PCAP analyzerNetworking
Find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policiesCloud
Automating situational awareness for cloud penetration tests.Cloud & services
Automatic code static analysis tool to detect bugs and vulnerabilitiesCode Analysis
Semantic code analysis engine; discover vulnerabilities across a codebase, lets you query code as though it were data, write a query to find all variants of a vulnerabilityCode Analysis
An application curated to crisis zones to facilitate the dissemination of accurate mission-critical information from sources on the ground to key partners with minimal lag timeCrisis Management
A Windows potato to privesc.Auth & perms
Coerce a Windows server to authenticate on an arbitrary machine through 12 methodsNetworking
Automatically coerce a Windows server to authenticate on an arbitrary machine.Bug bounty
Supports Java developers in using Java Cryptographic APIsPlugins
Burp Suite extension which injects non-invasive headers to reveal backend systems.Development
Company Passwords Profiler helps making a bruteforce wordlist for a targeted companyCracking
Fully customizable Windows-based pentesting virtual machine distribution.Operating systems
Automated All-in-One OS Command Injection Exploitation Tool.Vulnerabilities
OSINT tool to find usernames across 80+ social media and social networking sites.Informations gathering
Password spraying in Active Directory checking the default domain password policy as well as PSO and the badpwdcount LDAP attribute to avoid account lockingNetworking
An open-source, free protector for .NET applications.Development
Protector for .NET applicationsRed Teaming
Convert BloodHound output files into nmap XML that can be imported into reporting software like Dradis and PlextracOther
Read local Chrome cookies without root or decrypting and display then in JSON; Javascript implementation of cookie_crimesSystem Exploitation
Copies the selected request(s) as FFUF skeletonPlugins
Copies the selected request(s) as Go Request invocationsPlugins
Copies selected request(s) as Python-Requests invocationsPlugins
Copies selected request(s) as JavaScript XMLHttpRequest invocationsPlugins
Copies the selected request(s) as Node.JS Request invocationsPlugins
Copies the selected request(s) as PowerShell invocation(s)Plugins
Designed to enable security teams to conduct advanced penetration tests with ease.Bug bounty
CORS misconfiguration scanner tool with speed and precision in mind!Vulnerabilities
CORS Misconfiguration Scanner.Vulnerabilities
Parse the Database Lock Files of the Cortex XDR Agent by Palo Alto Networks and extract Agent Settings, the Hash and Salt of the Uninstall Password, as well as possible ExclusionsRed Teaming
Collaborative C2 framework for red teamers.Cloud & services
Command & Control framework with multi-user collaborationRed Teaming
Know the dangers of credential reuse attacks.Informations gathering
A swiss army knife for pentesting networks.Auth & perms
Post-exploitation tool to assess Active Directory networksNetworking
Hashcat cracking queue system, API and WebUICracking
GraphQL password brute-force and fuzzing utilityWeb Application Exploitation
Pre-computed lookup tables to crack password hashesCracking
Password wordlist generator, Smartlist creation and password hybrid-maskCracking
Hashcat WebUI; session management, mask generation, API, notifications, local and LDAP authenticationCracking
Scalable, pluggable, and distributed system for hash cracking, supports HashcatCracking
A powerful browser crawler for web vulnerability scannersAuth & perms
Password spraying, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttlingRed Teaming
CRLF bug scanner for WebPentesters and Bugbounty Hunters.Vulnerabilities
PortSwigger XSS cheat sheet that contains many vectors that can help you bypass WAFs and filters.Vulnerabilities
Generate CobaltStrike's cross-platform payload.Auth & perms
LinkedIn enumeration tool to get employee names from an organization using scraping.Cloud & services
Wordlist generator and Wi-Fi crackerWireless
Program analysis tool to find cryptographic misuse in Java and AndroidCryptography
Library consisting of explanation and implementation of all the existing attacks on various Encryption Systems, Digital Signatures, Hashing Algorithms along with example challenges from CTFsCryptography
Identify misuse of cryptographic libraries by collecting and analysing logsCryptography
The most advance set of Content Security Policy tools.Vulnerabilities
Python 3 port of Cuckoo, automated malware analysis systemReverse Engineering
An automated dynamic malware analysis system.Informations gathering
Qt and C++ GUI for radare2Reverse Engineering
A web app for encryption, encoding, compression and data analysis.Cryptanalysis
Data manipulation toolkit in web browserOther
Test your knowledge on cyber security and practice for industry recognised certifications.Resources
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.Artificial Intelligence
Cygeniq is an end-to-end AI security, governance, and compliance platform designed to protect artificial intelligence systems from emerging threats, operational risks, and regulatory challenges. As AI becomes central to enterprise decision-making, organizations face new and evolving risks such as prompt injection, data poisoning, model theft, adversarial manipulation, and non-compliance with AI regulations. Cygeniq addresses these challenges by securing AI systems across their full lifecycle, from development and testing to deployment, monitoring, and governance. Cygeniq’s platform is powered by three integrated solutions: Hexashield AI – Advanced AI Security & Protection Hexashield AI protects AI models and applications against modern attack vectors including prompt injection, data poisoning, adversarial threats, and model exploitation. It provides continuous monitoring, vulnerability detection, and runtime protection to ensure AI systems remain resilient and trustworthy. GRCortex AI – AI Governance, Risk & Compliance (AI GRC) GRCortex AI enables organizations to manage AI risk, enforce governance frameworks, and maintain compliance with evolving global AI regulations. It provides visibility into AI usage, risk assessments, policy enforcement, audit readiness, and regulatory alignment, ensuring responsible and compliant AI adoption. CyberTiX AI – Intelligent Threat Intelligence & Risk Insights CyberTiX AI delivers actionable intelligence and risk insights tailored to AI ecosystems. It helps security teams proactively identify vulnerabilities, assess emerging AI-related threats, and strengthen defensive posture across AI-driven environments. Together, these solutions provide unified visibility, control, and protection across the AI lifecycle. Cygeniq integrates seamlessly with modern AI stacks, cloud environments, and enterprise systems, allowing organizations to deploy and scale AI securely without disrupting innovation. Built for enterprises, regulated industries, and AI-first organizations, Cygeniq ensures that AI systems remain secure, compliant, and resilient in an increasingly complex digital and regulatory landscape.Red Teaming
PowerShell Cmdlets to interact with BloodHound Data via Neo4j HTTP API.Auth & perms
Automate pentest reporting & project management, generate content with AI, improve client retention, and organize your pentest workload.Collaboration and Report
An advanced tool for persistence in Linux.Operating systems
Windows project to empower incident response, digital forensics, malware analysis, and network defense with HashiCorp Packer and VagrantDefensive
Documentation And Reporting Tool; Collaborative penetration test and vulnerability database platformCollaboration and Report
Spot all domain controllers in a Microsoft Active Directory environment, find computer name, FQDN, and IP address(es) of all DCsNetworking
Script that is able to enumerate the possible vulnerable DCOM applications that might allow for lateral movement, code execution, data exfiltration, etc.System Exploitation
The world’s most prominent and well-known computer security conferences.Resources
Forensics artefact collection tool for systems running Microsoft WindowsIncident Response
Incident response tracking web application, focused on handling one major incident with a lot of affected systemsIncident Response
Dll injection toolSystem Exploitation
Password filter DLL, triggered on password change to exfiltrate credentialsSystem Exploitation
Toolkit to test further DNS rebinding attacks Networking
A DNS bruteforcing wordlist generator.Informations gathering
Domain research tool that can discover hosts related to a domainOSINT and Reconnaissance
Data exfiltration over DNS request covert channel.Informations gathering
Domain name permutation engine written in Go.Informations gathering
Allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.Informations gathering
DNS reconnaissance tool: AXFR, DNS records enumeration, TLD expansion, wildcard resolution, subdomain bruteforce, PTR record lookup, check for cached recordsOSINT and Reconnaissance
DNS Enumeration Script.Informations gathering
A fast tool to check missing hosted DNS zones that can lead to subdomain takeover.Informations gathering
Trace the path of a DNS query.Informations gathering
DNS traffic sniffer and analyzer.Informations gathering
A tool to scan source code for DOM based XSS vulnerabilities.Vulnerabilities
Chrome extension that finds DOM based XSS vulnerabilities.Vulnerabilities
DOM XSS scanner for Single Page Applications.Vulnerabilities
A DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG.Development
Automated black-box hypervisor-level malware analysis systemReverse Engineering
DS_Store file parser/viewer.Operating systems
List DTDs and generate XXE payloads using those local DTDs.Vulnerabilities
Damn vulnerable cloud application.Cloud & services
Dump web accessible (distributed) version control systems (DVCS/VCS): GIT, Mercurial/hg, Bazaar/bzr, …Web Application Exploitation
Damn Vulnerable GraphQL Application, insecure webapp for GraphQL security trainingsIntentionally Vulnerable Applications
Damn Vulnerable iOS App, insecure webapp for mobile security trainingsIntentionally Vulnerable Applications
The Damn Vulnerable Router Firmware project.Network
Damn Vulnerable Web Application, insecure webapp for security trainingsIntentionally Vulnerable Applications
Damn Vulnerable Web Application.Vulnerabilities
Vulnerable application with a web service and an API.Development
Helps to bypass antiviruses by providing an encryption wrapper and loader for your shellcode.Cryptanalysis
Powerful open source XSS scanning tool and parameter analyzer.Vulnerabilities
XSS scanner and utility focused on automationWeb Application Exploitation
A vulnerable Android application with an interface to test your mobile hacking skills.Operating systems
An intentionally vulnerable web API game for learning and training purposes.Resources
A Burp Suite extension for finding the use of potentially dangerous methods/functions.Development
Lightshot scraper with multi-threaded OCR and auto categorizing screenshotsOSINT and Reconnaissance
Runs a scan using Dastardly by Burp Suite against a target site and generates a report.Bug bounty
A Burp Suite extension to extract data from source code while browsing.Informations gathering
Sstatic analysis security scanner for ruby written web applications; supports Sinatra, Padrino and Ruby on Rails frameworksCode Analysis
Front-end for the Windows debugger engineReverse Engineering
Code and decode all kind of checksums, algorithms, codes or ciphersCryptography
toolkit for python reverse engineering.Informations gathering
DeHashed provides free deep-web scans and protection against credential leaks.Cryptanalysis
Service to check if an account has been compromised in a data breachOther
Track down footprints of a phone numberOSINT and Reconnaissance
Multi-decompiler engine; supports angr, BinaryNinja, Boomerang, dewolf, Ghidra, Hex-Rays, RecStudio, Reko, Relyze, RetDec, SnowmanReverse Engineering
C#, Python, Android and Java online decompilerReverse Engineering
Free, accessible, and platform-independent decompilation service.Informations gathering
Secrets scanner that understands code.Informations gathering
One place for all the default credentials to assist on finding devices with default password.Informations gathering
Default passwords database sorted by manufacturers.Informations gathering
Vulnerability management application built for DevOps and continuous security integrationCollaboration and Report
Online x86 (32/64 bits) assembler and disassemblerReverse Engineering
Deception framework which can be used to deploy decoys across the infrastructureHoneypot and Decoy
HTA encryption tool for Red Teams.Cryptanalysis
Management tool for the information security management system (ISMS); manage, plan, track and report the effectiveness of security controlsDefensive
Utility that detects publicly disclosed vulnerabilities in application dependencies.Bug bounty
Recovers passwords from pixelized screenshots.Cryptanalysis
Android reverse engineering platform focus on instrumentation automation (decompile/disass intercepted bytecode at runtime, write hook code, search interesting patternReverse Engineering
Multi threaded application to brute force directories and files names on web/application servers.Informations gathering
A Go implementation of dirsearch.Informations gathering
Web Fuzzer.Informations gathering
Multi threaded application designed to brute force paths on web servers.Informations gathering
Asset discovery and identification tool.Informations gathering
All of the ad-hoc things you're doing to manage incidents today, done for you, and much more!.Cloud & services
Evenly distributes scanner load across targets.Well known products
Divide full port scan results and use it for targeted Nmap runs.Informations gathering
Create DNS request collector and inspectorNetworking
Link a domain with registered organisation names and emails, to other domains.Informations gathering
Analyze the security of any domain by finding all the information possible. Made in python.Informations gathering
Checks expired domains to determine good candidates for phishing and C2 domain names.Informations gathering
Domain reconnaissance for organizational network scanningOSINT and Reconnaissance
Script that makes active and/or passive scan to obtain subdomains and search for open ports.Informations gathering
Dumping DPAPI credentials remotely; dumps relevant information on compromised targets without AV detectionSystem Exploitation
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files.Development
Generates x86_32, x86_64, or AMD64 position-independent shellcode that loads .NET Assemblies, PE files (EXE), VBScript, JScript, and DLL files from memory and runs them with parametersRed Teaming
Advanced Google searches using dorks to locate specific files on the internet.Cloud & services
Generate Google dorks with AI.Cloud & services
Directory Traversal fuzzerWeb Application Exploitation
The Directory Traversal Fuzzer.Vulnerabilities
An extension for checking if .git is exposed in visited websites.Source code management
Web browser extension (Firefox and CHromium) checking if .git is exposed in visited websitesWeb Application Exploitation
Headless browser in order to load pages and execute JavaScript that often generates things like dynamic nonces that validate the page was actually rendered by a human for password sprayingOther
Collaboration and reporting for infosec teams made simple.Bug bounty
Dradis is an open-source reporting and collaboration tool trusted by 1,000s of InfoSec professionals around the world.Collaboration and Report
Collaborative penetration test, vulnerability database and reporting platform; Pro editionCollaboration and Report
Evasive shellcode loader for bypassing injection detection.Operating systems
Different versions of the DroidGuard VM as well as different version of the bytecode running through this VMReverse Engineering
Android apps/malware analysis/reversing toolReverse Engineering
Drone pentesting framework console.Operating systems
Drupal enumeration & exploitation tool.CMS
A network forensic analysis framework.Auth & perms
LSASS memory dumper using direct system calls and API unhooking.Auth & perms
Tool to search secrets in various filetypes.Cloud & services
Remove duplicates from massive wordlist, without sorting it (for dictionary-based password cracking)Cracking
Targeted attacks against WPA2-Enterprise networks, wireless pivots using hostile portal attacks.Network
Ultimate domain enumeration tool.Informations gathering
Uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the serverRed Teaming
The security analyzer for firmware of embedded devices.Operating systems
Security analyzer for firmware of embedded devicesReverse Engineering
Analyze EML files: headers, bodies, attachments; extract IOCs; identify suspicious attachmentsDigital Forensics
Vulnerability scanner for mass detection of web-based applications vulnerabilities.Auth & perms
Image recognition on instagram, facebook and twitterOSINT and Reconnaissance
Stalk your friends on social media using image recognition and reverse image search.Cloud & services
Sensitive data detection tool capable of scanning source code repositories.Informations gathering
Collaborative penetration test platform; terminal sharing, target information extraction, command suggestion, exploit searching, chatting, graph visualizationCollaboration and Report
Post-exploitation and adversary emulation framework that is used to aid Red Teams and pentesters.Auth & perms
PowerShell and Python post-exploitation agentSystem Exploitation
GUI for Empire frameworkSystem Exploitation
An extension that auto extracts URLs from the current webpage and JS files.Well known products
Loots information from a Symfony target using profilerWeb Application Exploitation
Crisis management platformCrisis Management
Your performance & security consultant, an artisan command away.Development
The extension is based on the BurpSSO Extension, developed by the Chair of Network and Data Security, Ruhr University Bochum and the Hackmanit GmbH. The extension is part of a bachelor thesis by Tim Guenther at the Ruhr-University Bochum in cooperation with Context Information Security Ltd..Web Application Exploitation
Domain information gathering: whois, history, dns records, web technologies, recordsOSINT and Reconnaissance
Free and open source network security tool for man-in-the-middle attacks on a LAN.Network
Interactive .NET SQL console client with enhanced SQL Server discovery/access/exfiltration features.Databases
Enhanced WinRM shellNetworking
Create malicious MS Office documents to hide VBA macros, stomp VBA code.Informations gathering
Standalone MITM attack framework allowing for the bypass of 2-factor authentication.Auth & perms
Library and CLI tool to read and write meta information (EXIF, GPS, IPTC, XMP, JFIF, …) in files (JPEG, PNG, SVG, MPEG, …)Steganography
ExifTool meta information reader/writer.Informations gathering
Library and CLI tool for reading, writing and editing metadata for a lot of file typesDigital Forensics
Library and CLI tool to read and write meta information (Exif, IPTC & XMP metadata and ICC Profile) in images (JPEG, TIFF, PNG, …)Steganography
Exploits found on the INTERNET.Auth & perms
Copies selected request(s) as cURL, wget, Python Request, Perl LWP, PHP HTTP_Request2, Go, NodeJS Request, jQuery AJAX, PowerShell, HTML Forms, Ruby Net::HTTP, JavaScript XHR invocationsPlugins
Smart SSRF scanner using different methods like parameter brute forcing in POST and GET.Vulnerabilities
Scans for different types of XSS on a list of urls.Vulnerabilities
Designed to enumerate and gain access to IP cameras via RTSP.Operating systems
Take screenshots of websites, provide some server header info, and identify default credentials if possibleWeb Application Exploitation
Take screenshots of websites, provide server header info and identify default credentials.Informations gathering
Convolutional neural network for analyzing pentest screenshots.Informations gathering
Convolutional neural network for analyzing pentest screenshots and automatically label themWeb Application Exploitation
Service to check if an account has been compromised in a data breach, send an email with the breaches not the passwordOther
File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.Vulnerabilities
Freedom Fighting Mode (FFM), hacking harness, post-exploitation toolSystem Exploitation
OSINT framework and metadata analyserOSINT and Reconnaissance
Tool to find metadata and hidden information in the documents.Informations gathering
Investigate electronic devices; full disk imaging capabilities: preview and image hard drives from Windows and Linux computers, CDs, DVDs, thumb drives, and other USB; forensic image mounting: mount an image for a read-only view that leverages file explorer; preview data; RAM captureDigital Forensics
OSINT tool, facebook profile dumper, windows and chrome onlyOSINT and Reconnaissance
Use a Fake image.jpg to exploit targets (hide known file extensions).Auth & perms
Plug BloodHound with a SIEM or other log aggregationDefensive
Collaborative penetration test and reporting platformCollaboration and Report
Open source sulnerability management and orchestration platform.Auth & perms
Site fast fuzzing with chorme extension.Auth & perms
Favicon fingerprinting using ShodanWeb Application Exploitation
Favicon fingerprintingWeb Application Exploitation
Making favicon.ico based recon great again.Informations gathering
Favicon fingerprintingWeb Application Exploitation
Cryptanalysis tool and libraryCryptography
Automated blind-xss search for Burp Suite.Vulnerabilities
IOC scannerIncident Response
A fast, simple, recursive content discovery tool written in Rust.Informations gathering
The powered S3 bucket finder and content discover.Cloud & services
Tool for exploration and tracing of the Windows kernelDigital Forensics
Web debugging proxy for MacOS, Windows, and Linux.Network
A DNS reconnaissance tool for locating non-contiguous IP space.Informations gathering
Full-fledged phishing framework to manage all phishing engagements.Informations gathering
An extremely fast and flexible web fuzzer.Informations gathering
A fast DOM based XSS vulnerability scanner with simplicity.Vulnerabilities
All In One Web Recon.Informations gathering
Web reconnaissance scriptOSINT and Reconnaissance
Quickly find uncommon shares in vast Windows domains.Auth & perms
Fast subdomain enumeratorOSINT and Reconnaissance
The complete solution for domain recognition.Informations gathering
Find exploits in local and online databases instantly.Auth & perms
CMS version detection toolWeb Application Exploitation
CMS/LMS/Library etc Versions Fingerprinter.CMS
The ultimate Vulnerability Disclosure Policy and Bug Bounty list!Bug bounty
Realtime map that integrates Firebase, Google Maps and Shodan.Informations gathering
A tool written in python for scraping firebase data.Cloud & services
Black box fuzzer for web applications.Resources
Web directory and file scanner (wordlist bruteforce); but also a web fuzzerWeb Application Exploitation
Service to check if an account has been compromised in a data breach, display the breaches not the passwordOther
Hashcat-based distributed password cracking system with WebUICracking
Processes SWF and extract scripts from itReverse Engineering
A script that let you encode and decode a Flask session cookieWeb Application Exploitation
Disassembler tool for SWF bytecodeReverse Engineering
Automatically extract obfuscated strings from malware.Cryptanalysis
Provides view with filtering capabilities for all requests from all Burp Suite tools.Well known products
A Burp Suite extension that brings taint analysis to web applications, by tracking all parameters.Informations gathering
Explore, analyze, and gain valuable data & insights from reverse engineered Flutter appsReverse Engineering
Fluxion is the future of MITM WPA attacks.Network
MITM WPA attack toolWireless
Test Cache PoisoningWeb Application Exploitation
CLI tool to recover files based on their headers, footers, and internal data structuresDigital Forensics
DFIR automation for collecting and analyzing evidenceDigital Forensics
A Burp Suite extension to aid in detecting and exploiting serialisation libraries/APIs.Development
A curated list of free courses & certifications.Resources
Payload creation tool used for circumventing EDR security controls to execute shellcode in a stealthy mannerRed Teaming
Payload toolkit for bypassing EDRs using suspended processes, direct syscalls written.Auth & perms
List of fresh DNS resolvers updated every 12h.Informations gathering
Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.Informations gathering
Dynamic code instrumentation toolkitReverse Engineering
Android application tracer powered by Frida.Operating systems
Wireless network auditing tool controlled by a web interfaceWireless
Wireless network auditing tool.Network
Penetration testing platform, automate some scan & attackWeb Application Exploitation
Attack patterns and primitives for black-box application fault injection and resource discovery.Resources
Web-UI for API-fuzzerWeb Application Exploitation
Used for REST API pentesting and provide UI solution for gem.Development
A JavaScript Engine Fuzzer.Development
A Burp Suite extension to find potential endpoints and parameters.Informations gathering
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, Common Crawl, and URLScan for any given domainCracking
Enumerate Google Storage buckets, check the access and if they can be privilege escalated.Cloud & services
Exfiltrate files from a target's Google Drive that you have access to, via Google's API.Cloud & services
GNU debuggerReverse Engineering
GDB Enhanced Features, multi-architecturePlugins
Gather all companies acquired by a given company domain name.Informations gathering
DLL injection library supporting x86, WOW64 and x64 injections; 5 injection methods, 4 shellcode execution methods and various additional options; session separation can be bypassed with all methodsSystem Exploitation
Investigate Google accounts with emails and find name, usernames, Youtube Channel, probable location, Maps reviews, etc.OSINT and Reconnaissance
Game Of Active Directory is a test environment lab that includes all the common vulnerabilities of an active directoryOther
Game of Active Directory.Resources
A powerful network scanner, DNS recon, subdomain enumeration and IP Geolocator tool powered by GPT.Informations gathering
Run a Google based passive recon against your scope.Informations gathering
Extract subdomains from SSL certificates in HTTPS sites.Informations gathering
GitHub Sensitive Information Leakage.Informations gathering
Unix binaries that can be manipulated for argument injection.Auth & perms
CLI for earching gtfobins and lolbas from the terminal; allows more advanced search than gtfoOther
Unix binaries that can be used to bypass local security restrictions in misconfigured systems.Auth & perms
Automatic privilege escalation for misconfigured capabilities, sudo and suid binaries using GTFOBins.Auth & perms
The Greenbone Vulnerability Management (GVM) is a framework of several services: gvmd is the central service that consolidates plain vulnerability scanning into a full vulnerability management solution. The Greenbone Security Assistant (GSA) is the web interface of GVM. The main scanner (OpenVAS) is a full-featured scan engine that executes a continuously updated and extended feed of Network Vulnerability Tests (NVTs). Complementary to the web interface, GVM-Tools allows batch processing / scripting via the Greenbone Management Protocol (GMP). Additional scanners can be integrated via the Open Scanner Protocol (OSP)Vulnerability Assessment
Probe endpoints consuming Java serialized objects for fingerprinting.Informations gathering
LLM-powered web honeypot using the OpenAI APIHoneypot and Decoy
Attack framework for distributed systemsNetworking
Policy controller for Kubernetes.Virtualization
Burp Suite extension to pull employee names from Google and Bing LinkedIn search results.Cloud & services
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.Adversary Simulation
Helps to identify IoT related dashboards and scan them for default passwords.Informations gathering
Generate wordlists of passwords containing cities at a defined distance around the client city.Informations gathering
Generate wordlists of passwords containing cities at a defined distance around the client cityCracking
Automatic GEOINT using deep learningOSINT and Reconnaissance
Automates the process of detecting and exploiting SQL injection security flaws.Vulnerabilities
Automatic SQL injection and database takeover; inspired by SQLmapWeb Application Exploitation
Software reverse engineering (SRE) suite of tools: disassembly, assembly, decompilation, graphing, scripting, etc.Reverse Engineering
Useful tool to track location or mobile number.Informations gathering
Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.Informations gathering
Project management and reporting engineCollaboration and Report
Detect the OS and execute the correct commands to upgrade it to a full interactive reverse shellNetworking
Investigate GitHub profiles; features: username history, email address to GitHub account, finds potential secondary GitHub accounts, dumps SSH public keys, etc.OSINT and Reconnaissance
An OSINT tool to investigate GitHub profiles.Informations gathering
Rapidly search through troves of public data on GitHub for sensitive secrets.Informations gathering
A Git source leak exploit tool that restores the entire Git repository, including data from stash.Informations gathering
Tool used for harvesting information from GitHub.Source code management
Find sensitive information in git repositoriesOSINT and Reconnaissance
A tool for searching a Git repository for interesting content.Informations gathering
Tool for advanced mining for content on Github.Informations gathering
A repository with 3 tools for pwn'ing websites with .git repositories available.Source code management
3 tools: Finder (find websites with .git repository exposed), Dumper (dump exposed .git), Extractor (extract commits and their content from a broken repository)Web Application Exploitation
Reconnaissance tool for GitHub organizations.Informations gathering
Socks proxy router to handle multi-clients on the same portNetworking
Go365 performs user enumeration and password guessing attacks on organizations that use Office365.Cloud & services
User enumeration and password guessing for Office 365 / Microsoft365Red Teaming
A permutation generation tool written in golang.Informations gathering
Checks whether a domain is hosted on a cloud service.Cloud & services
Management frontend for hash cracking tools, supporting hashcatCracking
A fast and minimal JS endpoint extractor.Development
User enumeration and password bruteforce on Azure, ADFS, OWA, O365 and gather emails on LinkedinNetworking
Open-source phishing toolkit.Informations gathering
Username lookup comparable to Maigret/Sherlock, IP Lookup, License Plate & VIN Lookup, Info Cull, and Fake Identity GeneratorOSINT and Reconnaissance
Directory/File, DNS and VHost busting tool written in GoReconnaissance
Directory/File, DNS and VHost busting tool written in GoReconnaissance
Directory/File, DNS and VHost busting tool written in Go.Informations gathering
Network security technology that achieves rapid security emergency.Auth & perms
Privilege escalation tool for Windows.Auth & perms
Uses the dehashed.com API to search for compromised assetsOther
Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticketNetworking
Passive reconaissance enumerating directories, files, subdomains or parameters using google dorksOSINT and Reconnaissance
Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediationSystem Exploitation
Codelab for white-box and black-box hackingIntentionally Vulnerable Applications
Solve Google reCAPTCHA in less than 5 seconds!Cloud & services
Generates gopher link for exploiting SSRF and gaining RCE access from unprotected servicesWeb Application Exploitation
Generates gopher link for exploiting SSRF and gaining RCE in various servers.Vulnerabilities
Phishing toolkit providing the ability to setup and execute phishing engagements and security awareness trainingRed Teaming
Reconnaissance toolkitOSINT and Reconnaissance
Gives root access on remote docker containers that expose their APIs.Virtualization
Whois command implemented by golang with awesome whois servers list.Informations gathering
GraphQL automated security testingWeb Application Exploitation
Scaffold a postman collection for a GraphQL API; compatible with Postman and InsomniaWeb Application Exploitation
GraphQL security layer for Apollo and Yoga / Envelop serversDefensive
Burp Suite extension to help make Graphql request more readable.Databases
Run common security tests against GraphQLWeb Application Exploitation
Threat framework to research security gaps in GraphQL implementations.Databases
Represent any GraphQL API as an interactive graphWeb Application Exploitation
Context-aware GraphQL FuzzerFuzzing
Scripting engine to interact with a graphql endpoint for pentesting purposes.Databases
Scripting engine to interact with a graphql endpoint for pentesting purposesWeb Application Exploitation
GraphQL enumeration and extractionWeb Application Exploitation
Enumerate and extract GraphQL APIs.Databases
GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforceWeb Application Exploitation
Modular cross-platform Microsoft Graph API enumeration and exploitation toolkit.Cloud & services
Search for buckets and URL shorteners.Cloud & services
A tool for automated security scanning of web applications.Auth & perms
A collection of scripts mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.Vulnerabilities
Enumerate relevant settings in AD Group Policy, identify exploitable misconfigurationsNetworking
Web security scanner.Informations gathering
GUI HTTP intercepting proxy based on Pappy ProxyWeb Application Exploitation
Growing penetration test tool using Machine Learning.Cryptanalysis
A burpsuite extension to find security reports published on HackerOne based on the selected host.Bug bounty
Hash type identifier.Cryptanalysis
Designed to streamline the extraction and sanitization of HARTokens from HTTP archives.Informations gathering
Network fingerprinting standard which can be used to identify specific client and server SSH implementationsNetworking
Automated tool for testing header based blind SQL injection.Network
Connects to LDAP directory to retrieve all computers and users informations.Auth & perms
Retrieve all computers and users informations from AD LDAP; download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt themNetworking
Self contained web shells and other attacks via .htaccess files.Auth & perms
Extension for Burp Suite designed to help you launch HTTP Request Smuggling attacks.Vulnerabilities
Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware.Development
HTTP-traceroute in Go.Network
Automatic DNS rebinding-based SSRF attacksNetworking
A Burp Suite extension that checks for the HTTPoxy vulnerability.Well known products
HUNT Suite is a collection of Burp Suite Pro/Free and OWASP ZAP extensionsWeb Application Exploitation
Massive hacking playground, and infosec community.Resources
Decrypt passwords/cookies/history/bookmarks from the browser.Informations gathering
Web browser extension (Chromium, Firefox, Safari) including common functions for web pentestOther
The all-in-one browser extension for offensive security professionals.Auth & perms
Find trick/technique/whatever learnt from CTFs, real life apps, reading researches, and news.Resources
Probe a rendering engine for vulnerabilities and other features.Informations gathering
Intentionally vulnerable web shopping application using modern technologies and containing configurable areasIntentionally Vulnerable Applications
A free class for web security.Resources
HackerSploit YouTube channel.Resources
A limited client library for interacting with HackerOneBug bounty
Join the front line of the internet, learn applicable cyber security skills.Resources
ALL IN ONE Hacking Tool For Hackers.Informations gathering
Risk Based Vulnerablity Management platformCollaboration and Report
Tag based conversion tool written in Java implemented as a Burp Suite extension.Well known products
Shellcode loader that combines multiple evasion techniques with the aim of bypassing the defensive mechanisms commonly used by modern AV/EDRsRed Teaming
Go shellcode loader that combines multiple evasion techniques.Auth & perms
Basic Command and Control serverRed Teaming
Hash type identifier (CLI & lib)Cryptography
Collect useful information from urls, directories, and files.Informations gathering
A cross-platform, collaborative, Command & Control framework.Auth & perms
Cross-platform, collaborative, Command & Control frameworkRed Teaming
Checks and hardens your Windows configuration.Bug bounty
CLI tool; collect data and document actively or passivelyOSINT and Reconnaissance
Search across 20 million exposed secrets in public GitHub repositories, gists, issues and comments.Informations gathering
Crack hashes in seconds.Informations gathering
Grab NetNTLMv2 hashes using ETW with administrative rights on Windows.Auth & perms
Web interface for HashcatCracking
Hash cracking tool and World's fastest and most advanced password recovery utilityCracking
Hashcat WebUI; queuing, local authentication, SMS and email notifications, map integrationCracking
Hashcat wrapper for distributed hashcrackingCracking
Web-UI for managing, organizing, automating Hashcat commands/tasksCracking
Generate all permutations of a domain which are enriched for typosquatting detectionDefensive
Service to check if an account has been compromised in a data breach, display the breaches not the passwordOther
Check if your email or phone is in a data breach.Informations gathering
Malleable post-exploitation command and control frameworkRed Teaming
Modern and malleable post-exploitation command and control framework.Auth & perms
Network, recon and offensive-security tool for Linux.Network
Filesystem analysis tool/directory looking for interesting stuff.Informations gathering
Do more with less effort Whether you do pentesting, vulnerabillity scanning or a custom mix of the two, don't waste your time on repetitive workCollaboration and Report
Blazing-fast tool to grab screenshots of your domain list right from terminal.Informations gathering
Provides a suite of extensions and a maven plugin to automate security tests using Burp Suite.Well known products
Scan with nmap to correlate CPE's found with cve-search to enumerate vulnerabilitiesNetworking
HTTP toolkit for security research; alternative to BurpSuiteWeb Application Exploitation
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.AI MCP Servers
Linux kernel module generator for custom rules with netfilterOther
x86_64 disassembler for multiple formatsReverse Engineering
Collect, categorize and highlight requests and/or responses according to their content.Network
Android GUI for Aircrack, Airodump, Aireplay, MDK3 and ReaverWireless
GUI for the penetration testing tools Aircrack-ng, Airodump-ng, MDK3 and Reaver.Network
Extracting the contents of Microsoft Windows Registry (hive) and display it as a colorful tree but mainly focused on parsing BCD files to extract WIM files path for PXE attacksNetworking
Collaborative penetration test and reporting platformCollaboration and Report
Scans processes to detect and dump potentially malicious implants.Auth & perms
Security oriented software fuzzer; supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)Reverse Engineering
HTTP request collector and inspectorWeb Application Exploitation
Adds autocompletion support and useful payloads in Burp SuitePlugins
Disassembler, decompiler and debuggerReverse Engineering
Bruteforce existing subdomains and provide informations about them.Informations gathering
Graphical search engine for Exploit-DBOther
A runtime mobile application analysis toolkit with a Web GUI.Operating systems
Automatic domain recognition (via amass) and vulnerability scan (via nuclei) platform with a WebUIOSINT and Reconnaissance
Very fast password cracking tool.Informations gathering
Network login crackerNetworking
Improve the display when debugging with GDB, needs GEF, pwndbg or peda to be loaded in GDB as a backendPlugins
Advanced AWS access credentials scanner.Auth & perms
Disassembler and debuggerReverse Engineering
Simple tool to scan large scope and provide SSL/TLS vulnerabilities.Cryptanalysis
Check for the IIS tilde enumeration / IIS 8.3 short filename disclosure vulnerability and to exploit it by enumerating all the short names in an IIS web serverPlugins
.NET assembly browser and decompiler to C#Reverse Engineering
NET Decompiler with support for PDB generation, ReadyToRun, Metadata (&more) - cross-platform!.Development
A tool to automatically generate alternative IP representations.Cryptanalysis
Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.Cloud & services
Collaborative platform aiming to help incident responders sharing technical details during investigationsIncident Response
Network recon framework.Auth & perms
IVRE (Instrument de veille sur les réseaux extérieurs) or DRUNK (Dynamic Recon of UNKnown networks); network recon framework including tools ofr passive and active reconOSINT and Reconnaissance
SOCKS proxy for CitrixNetworking
Service to check if an account has been compromised in a data breach, send the breaches by emailOther
Check if a phone number is used on different sites like snapchat, instagramOSINT and Reconnaissance
Hexadecimal editor tailored for reverse engineers; byte patching, data import / export, data inspector, huge file support, file hashing, disassembler for many architectures, data analyzerReverse Engineering
Hex editor for reverse engineers, programmers and people who value their retinas when working at 3am.Informations gathering
Software suite and library to create, edit, compose, or convert imagesSteganography
Allows developers and security experts to check if an Imagemagick XML Security Policy is hardened against a wide set of malicious attacksDefensive
Windows debugger with Python scripting supportReverse Engineering
Identify the attack paths in BloodHound breaking AD tieringNetworking
GraphQL security auditWeb Application Exploitation
Burp Extension for GraphQL Security Testing.Databases
Test a data center's resiliency to perimeter breaches and internal server infection.Informations gathering
Adversary emulation platform; test a data center's resiliency to perimeter breaches and internal server infectionAdversary Simulation
Automated wireless hacking tool Wireless
Email OSINT.Informations gathering
php.ini scanner for security best practicesConfiguration Audit
Perform advanced MiTM attacks on websites with ease.Vulnerabilities
CRLF and open redirect fuzzer.Vulnerabilities
InsiderPhD Youtube channel.Resources
Android package inspector.Operating systems
Solution for collecting and processing security feeds using a message queuing protocolIncident Response
Manage your threat intelligence at scale.Informations gathering
Perform automated network reconnaissance scans to gather network intelligence.Informations gathering
HTTP request collector and inspector; OOB interaction gathering server and client library; DNS / HTTP / SMTP interaction supportWeb Application Exploitation
Turn single threaded command line applications into a fast, multi-threaded application.Auth & perms
Turn single threaded command line applications into a multi-threaded application with CIDR and glob supportOther
Framework for discovering attack surfaceWeb Application Exploitation
Payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.Resources
Web Application Security For Enterprise.Bug bounty
Automates the discovery and pwnage of ACLs in Active Directory that are unsafe configure.Auth & perms
Automate Active Directory Enumeration using PowerView.Auth & perms
PowerShell-based toolkit consisting of a collection of techniques and tradecraft for use in red team, post-exploitation, adversary simulation, or other offensive security tasksAdversary Simulation
For when you want a computer to be done - without admin!.Operating systems
Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute.Auth & perms
An Internet Explorer post exploitation library.Informations gathering
Socks proxy, and reverse socks server using powershell.Auth & perms
Memory Backed Powershell WebDav Server.Operating systems
PowerShell script to dump Windows credentials from the Credential Manager.Informations gathering
Web security/vulnerability scanner (native for Windows only)Web Application Exploitation
Improve the test coverage during web application penetration tests on J2EE applications.Development
Take screenshots of websitesWeb Application Exploitation
Just Another Windows (Enum) Script; quickly identify potential privilege escalation vectors on Windows systemsSystem Exploitation
A standalone Java decompiler GUI.Development
GUI tool decompiling JAVAReverse Engineering
Disassembler, decompiler and debuggerReverse Engineering
Decompile and debug binary code and obfuscated apps, break down and analyze document files.Development
Generates JNDI links can start several servers to exploit JNDI Injection vulnerabilities.Development
JavaScript Object Signing and Encryption Pentesting Helper.Auth & perms
Free Flash decompiler.Informations gathering
A.k.a ffdec, flash SWF decompilerReverse Engineering
A .js scanner, built in PHP, designed to scrape urls and other info.Informations gathering
JavaScript payload and supporting software to be used as XSS payload or post exploitation implant.Development
Javascript deobfustcatorReverse Engineering
JSON Beautifier for Burp written in Java.Development
JSONP endpoints/payloads to help bypass content security policy of different websitesWeb Application Exploitation
A ready to use JSONP endpoints/payloads to help bypass Content Security Policy.Vulnerabilities
Python script to parse relative URLs from JavaScript files.Informations gathering
An interactive multi-user web JS shell.Development
Generate javascript code to be injected in case you find a Server Side Javascript Injection.Development
Burp Suite extension to crawl JS files in passive mode and display the results on the issues.Development
Simple python script to check against hypothetical JWT vulnerability.Auth & perms
A toolkit for testing, tweaking and cracking JSON Web Tokens.Auth & perms
JWT brute force cracker written in C.Auth & perms
Multi-threaded JWT brute-force crackerWeb Application Exploitation
Recover the public key used to sign JWT tokensCryptography
JWT Support for Burp Suite.Auth & perms
Detects JWT algorithm and provides options to generate a new JWT based on another algorithm.Auth & perms
The Swiss Army knife for automated Web Application TestingAuth & perms
Framework for building your own Web Application ScannerWeb Application Exploitation
Abstracts away the complex steps required to perform a DNS rebind and exposes a HTML5 Fetch interface which transparently triggers a DNS rebindNetworking
.JAR and .Class to Java decompilerReverse Engineering
All-in-one plugin for the detection and exploitation of Java deserialization vulnerabilities.Development
JavaScript obfuscator; features: variables renaming, strings extraction and encryption, dead code injection, control flow flattening, various code transformations, etc.Red Teaming
Fast and customizable vulnerability scanner for Jira.Well known products
### Jiraffe Jiraffe is a modern, modular security reconnaissance and vulnerability validation framework for Atlassian Jira deployments. Designed for security professionals, Jiraffe focuses on accuracy, signal quality, and safe validation rather than noisy scanning. It follows a recon-first, exploit-second model, allowing users to understand a target's exposure before performing controlled vulnerability validation. Jiraffe currently includes 14+ dedicated reconnaissance modules covering unauthenticated access checks, information disclosures, and common Jira misconfigurations, along with 16 custom CVE exploit implementations, with new modules added continuously. #### Features * Modular reconnaissance and exploit framework * Passive, unauthenticated recon modules for: * Information disclosure * Misconfigurations * Exposed or weakly protected endpoints * Safe CVE validation with severity filtering * Jira version and deployment awareness (Cloud vs Server/DC) to avoid misleading or invalid checks * SSRF helpers, including cloud metadata and custom targets * JSON output for automation, CI/CD, and scripting * No automatic shell execution or intrusive behavior by default #### Use cases * Bug bounty reconnaissance * Internal security assessments * Red team tooling * Responsible vulnerability validation Jiraffe is actively maintained, extensible, and built with clean architecture to support long-term evolution as Jira's attack surface changes.Web Application Exploitation
Code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphsCode Analysis
John Hammond YouTube channel.Resources
Password cracker tool.Informations gathering
Hash cracking toolCracking
Hash cracking tool, community-enhanced version of John The RipperCracking
OWASP Joomla Vulnerability Scanner Project.CMS
Identify Joomla version, scan for vulnerabilities and sensitive files.CMS
Simple HS256, HS384 & HS512 JWT token brute force cracker.Cracking
Find vulnerabilities, compliance issues and infrastructure misconfigurations in your IAC.Auth & perms
Online XSS tool with demonstration of vulnerability.Vulnerabilities
DNS dynamic update abuse in ADIDNS via DSPROPERTY_ZONE_ALLOW_UPDATE set to ZONE_UPDATE_UNSECURE combined with MitM attack using Kerberos AP-REQ hijackingNetworking
LFI, RFI, RCE scannerWeb Application Exploitation
Check for and exploit LFI vulnerabilities with a focus on PHP systems.Vulnerabilities
Lists of resources: cdn ranges, ips ranges, sni ip ranges...Informations gathering
Graphical user interface for Metasploit Meterpreter and session handlerRed Teaming
Graphical user interface for Metasploit Meterpreter and session handler.Well known products
Declarative language to generate binary data parsers in various languagesReverse Engineering
The most advanced penetration testing distribution.Network
Crawling and spidering framework, supporting headless mode, JavaScript, customizable automatic form filling and scope controlWeb Application Exploitation
Automate KeePass discovery and secret extractionPlugins
A python script to help red teamers discover KeePass instances and extract secrets.Informations gathering
A little toolbox to play with Microsoft Kerberos in C.Auth & perms
macOS kernel pre and post callback-based frameworkReverse Engineering
Beacon Object Files for Kerberos abuse.Auth & perms
Bruteforce and enumerate valid Active Directory accounts through Kerberos Pre-AuthenticationNetworking
Extracts Key Values from .keytab files.Auth & perms
Find and analyze private/public key files and Android APK files.Operating systems
A tool for testing and promoting user awareness by simulating real world phishing attacksRed Teaming
A free, open source wireless stumbling and security tool for Mac OS X.Network
Sniffer, WIDS, and wardriving tool for Wi-Fi, Bluetooth, Zigbee, RFWireless
Remote capture for all capture types over TCP sockets or websockets.Network
Highly configurable script for dictionary/spray attacks against online web applications.Informations gathering
Knock Subdomain Scan.Informations gathering
This is a python wrapper around the amazing KNOXSS.Vulnerabilities
Tool to find firms domains by searching their trademark informationOSINT and Reconnaissance
Java decompiler, assembler, and disassembler.Development
Java decompiler, assembler, and disassemblerReverse Engineering
Hashcat-based distributed password cracking system with WebUI; has a desktop client in additionCracking
Modular multi-language webshell focused on web post-exploitation and defense evasion; supports PHP, JSP and ASPXWeb Application Exploitation
A modular multi-language webshell.Vulnerabilities
Distributed password brute-force system, supports HashcatCracking
Toolkit for abusing unconstrained delegationNetworking
Kscan is an all-round scanner developed purely in Go, with functions such as port scanning, protocol.Informations gathering
Scanner for security weaknesses in Kubernetes clustersCode Analysis
Kubernetes attack graph tool allowing automated calculation of attack paths between assets in a clusterNetworking
Vulnerable by design cluster environment to learn and practice Kubernetes security.Resources
Post-exploitation HTTP/2 Command & Control server and agent focused on containerized environmentsRed Teaming
Cross-platform command & control server and agent focused on containerized environments.Virtualization
Exploit Kubernetes clusters misconfigurations and be the swiss army knife of your pentests.Virtualization
Pentest data management toolCollaboration and Report
Infect an existing Android application with a Meterpreter payload.Operating systems
Generate reverse shell payloads on the fly.Auth & perms
Password Hunter in active directory.Auth & perms
Check for LDAP protections regarding the relay of NTLM authentication.Auth & perms
Anonymously bruteforce Active Directory usernames by abusing LDAP Ping requests.Auth & perms
Monitor creation, deletion and changes to LDAP objects live during pentest or system administrationNetworking
Bash script which checks and validates for leaked credentials.Development
LFI scan and exploit toolWeb Application Exploitation
Totally Automatic LFI Exploiter and Scanner.Vulnerabilities
Automatic LFI scanner and exploiterWeb Application Exploitation
Scripts to execute enumeration via LFIVulnerabilities
Dump remote files through a local file read or Local File Inclusion web vulnerability.Operating systems
Language Independent Crypto-Misuse Analysis; multi-language analysis tool to identify incorrect initialization of crypto functionsCode Analysis
Lord Of Active Directory is a test environment lab that includes all the common vulnerabilities of an active directory and deploys automatically on AWS; based on AWS-Redteam-Lab and GOADOther
Living Off The Land Binaries, Scripts and Libraries.Auth & perms
Living Off the Orchard: macOS Binaries.Auth & perms
Login Pages Database forms a knowledge base on login pages related to malicious activities (C2 panels, phishing kits...)Red Teaming
Password retrieverSystem Exploitation
Credentials recovery project.Informations gathering
Collaborative penetration test and vulnerability management frameworkCollaboration and Report
Patch management, vulnerability scanning, and network auditing.Bug bounty
A framework that provides a web UI to commonly used Bug Hunting/Pentesting tools.Auth & perms
Service to check if an account has been compromised in a data breach, requires an accountOther
Normalize, deduplicate, index, sort, and search leaked data sets on the multi-terabyte-scaleOSINT and Reconnaissance
Search engine for devices and services exposed on the InternetOSINT and Reconnaissance
Discover, browse and monitor database/source code leaksOSINT and Reconnaissance
Discover, browse and monitor database/source code leaks.Informations gathering
Multiprotocol credentials bruteforcer, password sprayer and enumeratorNetworking
Aids in discovery, reconnaissance and exploitation of information systems.Bug bounty
Detect misconfigurations and security risks across GitHub and GitLab assets.Source code management
Automated attack simulation in the cloud, complete with detection use cases.Cloud & services
Advanced fuzzing librar. Slot your fuzzers together and extend their features using Rust.Auth & perms
Local file inclusion exploitation tool.Vulnerabilities
LFI exploitation toolWeb Application Exploitation
Framework for auditing web application firewalls and filtersWeb Application Exploitation
Generate an obfuscated DLL that will disable AMSI & ETWRed Teaming
Pivot / reverse tunneling tool with SOCKS5 and TCP tunnel supportNetworking
Pivoting via TCP/TLS reverse tunneling with TUN interfaceNetworking
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.Auth & perms
Linux enumeration and privilege escalation scriptSystem Exploitation
System script for local Linux enumeration and privilege escalation checksOSINT and Reconnaissance
Scripted Local Linux Enumeration & Privilege Escalation Checks.Auth & perms
Find URL endpoints and their parameters in JavaScript filesWeb Application Exploitation
A python script that finds endpoints in JavaScript files.Informations gathering
Dump company employees from LinkedIn APIOSINT and Reconnaissance
Script that dumps employee data from the LinkedIn social networking platform.Cloud & services
The Linux memory acquisition tool.Operating systems
Based on operating system release number.Operating systems
Linux kernel exploit suggesterSystem Exploitation
Information gathering (OSINT) on a person (EU), checks social networks and Pages JaunesOSINT and Reconnaissance
Assist forensic investigators and incidence responders in carrying out a quick live forensic investigationDigital Forensics
LiveOverflow YouTube channel.Resources
Generates lists of live hosts and URLs.Informations gathering
CLI tool that checks if your PHP application depends on PHP packages with known security vulnerabilitiesConfiguration Audit
Another local Windows privilege escalation using a new potato technique.Auth & perms
Detect and fix common misconfigurations in Active Directory Certificate Services.Auth & perms
Find and fix common misconfigurations in AD CSNetworking
Log activities of all the tools in Burp Suite.Well known products
Investigate malicious Windows logon by visualizing and analyzing Windows event log.Auth & perms
IOC scannerIncident Response
Allows users to capture a website page and then display a tree of domains that call each other.Informations gathering
A web interface that allows you to capture a website page and display a tree of domainsOther
Web directory and file scanner (wordlist bruteforce)Web Application Exploitation
An Open Source Java Decompiler GUI for Procyon.Development
Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.Configuration Audit
The single instruction C compiler.Cryptanalysis
Crawl SMB shares for juicy information; supports file content searching and regexNetworking
Spider entire networks for juicy files sitting on SMB shares.Informations gathering
PoC tool to exploit common IEEE 802.11 protocol weaknessesWireless
PoC tool to exploit common IEEE 802.11 protocol weaknessesWireless
Check if MFA is enabled on multiple Microsoft servicesRed Teaming
Threat intelligence platform & open standards for threat information sharing (formerly known as Malware Information Sharing Platform)Threat Intelligence
Malware Information Sharing Platform, an Open Source threat intelligence platform and open standards for threat information sharingCollaboration and Report
Knowledge base of adversary tactics and techniques based on real-world observations.Resources
ATT&CK training and certification program produced by MITRE’s own ATT&CK subject matter expertsAdversary Simulation
Microsoft SQL database attacking tool.Databases
Identify DNS records, check for zone transfers and conduct subdomain enumeration.Informations gathering
Google Dork File Finder.Informations gathering
A password spraying tool for Microsoft Online accounts (Azure/O365).Cloud & services
MSSQL relay audit and abuseNetworking
SQL injection script for Microsoft SQL Server.Databases
Mobile Verification Toolkit; collection of utilities to simplify and automate the process of gathering forensic traces helpful to identify a potential compromise of Android and iOS devicesDigital Forensics
A powerful shell script to maximize the recon and data collection process.Informations gathering
Collect a dossier on a person by username from thousands of sites.Informations gathering
Collect a dossier on a person by username from a huge number of sites, and extract details from themOSINT and Reconnaissance
SMTP credentials bruteforcer / checkerNetworking
It's a handy tool to help you analyze malware.Cryptanalysis
A web-based collection of tools and resources for OSINT; successor of OSINT FrameworkOSINT and Reconnaissance
Interactive data mining tool that renders directed graphs for link analysis. The tool is used in online investigations for finding relationships between pieces of information from various sources located on the Internet (exists in Community Edition)Threat Intelligence
Open source intelligence and forensics application.Informations gathering
Malware sample database.Auth & perms
Collection of malware source code for a variety of platforms in an array of different programming la.Auth & perms
Web oriented deobfuscating toolWeb Application Exploitation
Manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRsRed Teaming
Adversary emulation command line tool is parsing complex scenarios from Manticore public-threats repository and run these scenariosAdversary Simulation
An advanced source map extractor based on headless browser.Informations gathering
Open-source Intelligence Framework.Informations gathering
Library and CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memorySystem Exploitation
Enumerate through a pre-compiled list of AWS S3 buckets using DNS instead of HTTP.Cloud & services
High-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)OSINT and Reconnaissance
A high-performance DNS stub resolver for bulk lookups and reconnaissance.Informations gathering
TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.Informations gathering
Port scanner for massive networksNetworking
Audit Unix/*BSD/Linux system libraries to find public security vulnerabilitiesConfiguration Audit
Encode Havoc shellcode (.bin) in XOR, chacha20, AES; supports 2 loaders: Myph, 221bPlugins
Network login crackerNetworking
Medusa is a speedy, parallel, and modular, login brute-forcer.Informations gathering
Interactive multi-architecture and multi-formats disassembler running on Windows and LinuxReverse Engineering
GUI for MedusaNetworking
Graphical tool for custom wordlist generation, can output rules compatible with Hashcat and John the RipperCracking
Web application to manage the mapping of an information system as described in the Mapping The Information System Guide of the ANSSIDefensive
Post-exploitation HTTP/2 Command & Control server and agentRed Teaming
Unleash metadata intelligence, bridging the chasm in metadata extraction and analysis.Informations gathering
Searching information about IP address, ASN and organization; doesn't require any API keyOSINT and Reconnaissance
Intelligence tool to do OSINT tasks and more but without any API key.Informations gathering
This tools covers Cross-Site Scripting (XSS) security issues with media-files containing metadata. Such data is usually created by trusted devices like cameras. Therefore, there is the chance that providers handling this metadata, also trust them and that they thus use insufficient or no filter mechanisms. We have developed an open source penetration testing tool called Metadata-Attacker. It consists of a suite of self-developed tools that allow to create malicious proof-of-concept image (.jpg), audio (.mp3), and video (.mp4) files.Web Application Exploitation
Search Google and download specific file types.Cloud & services
Assembler, disassembler, compiler and debuggerReverse Engineering
The world’s most used penetration testing framework.Auth & perms
Tool and framework for pentesting system, web and many more, contains a lot a ready to use exploit, 4 versions: Pro (paid), Express (paid), Community (free with GUI but on request), Framework (free, open source, CLI)Vulnerabilities
VM that is built from the ground up with a large amount of security vulnerabilitiesIntentionally Vulnerable Applications
A collection of scripts for assessing Microsoft Azure security.Cloud & services
Quickly and easily create backdoor Office exploitation using module Metasploit packet.Well known products
A dynamic deception tool that actively deceives an attacker.Auth & perms
Android APK vulnerability analyzerCode Analysis
All-in-one mobile application pentesting, malware analysis and security assessment framework.Operating systems
HTTP request collector and inspectorWeb Application Exploitation
HTTP reverse proxy designed for phishingRed Teaming
A powerful and flexible HTTP reverse proxy.Network
Cellular networks jamming PoC for mobile equipmentsWireless
Tool to retrieve information of cellular networksWireless
Set of commands for Immunity DebuggerPlugins
Designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential.Auth & perms
Manual search tool to find bugs like a grep unix command.Informations gathering
An automated e-mail OSINT tool.Informations gathering
SIP-based audit and attack tool.Network
Post-exploitation tool for dumping and extracting LSASS memory discreetly.Auth & perms
Online hash checker for Virustotal and other servicesIncident Response
A toolkit for signing, forging and cracking JWT tokensWeb Application Exploitation
A collaborative, multi-platform, red teaming framework.Virtualization
Collaborative red teaming frameworkRed Teaming
Allows to embed data into application layer protocol fields, with the goal of establishing a bi-directional channel for arbitrary communications; supports encapsulation into HTTP, HTTPS, DNS and ICMP protocolsRed Teaming
Finding profiles by username over 350 websitesOSINT and Reconnaissance
Advanced GUI for NmapNetworking
Quickly and accurately create a visual representation of their Nmap output.Auth & perms
Python utility to takeover domains vulnerable to AWS NS Takeover.Cloud & services
Utility to detect AWS NS Takeover.Cloud & services
NTLM hash lookup table, billions of passwords indexedCracking
Enumerate information from NTLM authentication enabled web endpoints.Auth & perms
Crisis management web application / project for software systems analysis and designCrisis Management
A fast port scanner written in go with a focus on reliability and simplicity.Informations gathering
The industry standard in IT infrastructure monitoring.Bug bounty
NahamSec Twitch channel.Resources
Service to check if an account has been compromised in a data breach, display the breaches not the passwordOther
Check usernames on more than 100 websites, forums and social networks.Informations gathering
A flexible tool that creates a minidump of the LSASS process.Auth & perms
Minimal LSASS dumperSystem Exploitation
Modular personalized dictionary generatorCracking
Reliable and adaptative network login cracker supporting a large number of protocolsNetworking
Chrome extension for instant access to bug bounty submission dashboard of various platforms and publicly disclosed reportsBug bounty
The global gold standard in vulnerability assessment built for the modern attack surface.Bug bounty
Export Nessus results to a relational database for use in reports, analysis, or whatever else.Bug bounty
Windows / Active Directory environments pentest; fork of CrackMapExecNetworking
Network service exploitation tool that helps automate assessing the security of large networks.Auth & perms
A tool you can use to scan for devices on your network.Auth & perms
Rapidly detect and respond to any threat, anywhere. See Everything. Fear Nothing.Bug bounty
Scrape sensitive information from paste sitesOSINT and Reconnaissance
PCAP analyzer; needs registrationNetworking
Maltego alternativeThreat Intelligence
Netlas.io is the network atlas of Internet. IP, DNS, Web, IoT devices, and etc.Informations gathering
Web application security scannerWeb Application Exploitation
Network Chuck YouTube channel.Resources
Network sniffer/packet capturing toolNetworking
Network forensic analysis tool for Windows.Informations gathering
PCAP analyzer; using SuricataNetworking
Vulnerability scanner which aims to support the entire vulnerability management lifecycle.Bug bounty
Simple tool to look for common Nginx misconfigurations and vulnerabilities.Auth & perms
Modern real-time collaborative editing tool secured by end-to-end encryptionCollaboration and Report
Command & Control framework; multi-operator, API driven, malleable native implantRed Teaming
Nikto web server scanner.Informations gathering
Light-weight first-stage Command & Control implantRed Teaming
A light-weight first-stage C2 implant written in Nim.Cryptanalysis
Simple and lightweight Command & Control frameworkRed Teaming
Yet another (simple and lightweight) C2 framework.Auth & perms
Tool for fingerprinting and exploiting Amazon cloud infrastructures.Cloud & services
Script to make TOR as default gatewayNetworking
Simplify your life with leak detection in JavaScript, NipeJS streamlines the use of regex, making it.Development
Tool that parse router, switch, firewall configuration to discover vulnerabilitiesConfiguration Audit
Tool that parse router, switch, firewall configuration to discover vulnerabilitiesConfiguration Audit
Framework, collection of scripts and payloads in PowerShell for offensive security, penetration testing and red teamingSystem Exploitation
Offensive PowerShell for red team, penetration testing and offensive security.Auth & perms
Tool for network discovery and security auditingNetworking
The network mapper.Informations gathering
Create a Nmap API that can do scans with a good speed online and is easy to deploy.Development
Cybersecurity tools offered as SaaS: nmap, subdomain finder (Sublist3r, DNScan, Anubis, Amass, Lepus, Findomain, Censys), theHarvester, etc.OSINT and Reconnaissance
NoSql Injection CLI tool for finding vulnerable websites using MongoDB.Databases
Automated NoSQL database enumeration and web application exploitation tool.Vulnerabilities
Automated NoSQL database enumeration and web application exploitation toolWeb Application Exploitation
Learn how OWASP Top 10 security risks apply to web applications developed using Node.js.Development
Static security code scanner for Node.js applicationsCode Analysis
Command-line tool that finds secrets and sensitive information in textual data and Git history.Informations gathering
NoSQL scanning and exploitation frameworkWeb Application Exploitation
A Python Framework For NoSQL Scanning and Exploitation.Databases
HTTP fuzzer engine security oriented.Development
Multithreaded and modular bruteforce framework with network templatesNetworking
Now, the Host is Mine!; sub-domain takeover detectionWeb Application Exploitation
Web application security scanner based on templatesWeb Application Exploitation
Fast and customizable vulnerability scanner based on simple YAML based DSL.Vulnerabilities
Community curated list of templates for the Nuclei engine to find security vulnerabilities.Informations gathering
A reference implementation and toolkit for enabling standardized emergency information exchange using the OASIS Emergency Data Exchange Language (EDXL)Crisis Management
Burp Suite Extension useful to verify OAUTHv2 and OpenID security.Auth & perms
Advanced multi-architecture online disassembler supporting a lot of architectures and object file formatsReverse Engineering
Observe, Detect, and Investigate Networks, Automated reconnaissance toolOSINT and Reconnaissance
Autonomously assesses your API for prevalent vulnerabilities.Development
Bind9 DNS server for pentesters to use for Out-of-Band vulnerabilitiesNetworking
Markdown templates for OSCP exam reportCollaboration and Report
A web-based collection of tools and resources for OSINTOSINT and Reconnaissance
OSINT Framework.Informations gathering
Perform OSINT scan on email/domain/ip address/organization.Informations gathering
OSINT from your favorite services in a friendly terminal user interface.Informations gathering
Continuous Fuzzing for Open Source Software.Auth & perms
A distributed vulnerability database for Open Source.Auth & perms
Dump users's .plist on a Mac OS system and to convert them into a crackable hash.Informations gathering
Free Mac OS X computer forensics tool.Operating systems
A nonprofit foundation that works to improve the security of software.Resources
Joomla vulnerability scannerWeb Application Exploitation
Insecure web application with >85 challenges; supports CTFs, custom themes, tutorial mode etc.Intentionally Vulnerable Applications
Probably the most modern and sophisticated insecure web application.Resources
Intentionally vulnerable web-application containing some OWASP Top Ten vulnerabilities, with hints and switch for secure version of the codeIntentionally Vulnerable Applications
Collection of XML templates, XML schemas and XSLT code, to generate IT security documents including test reports, offers and invoicesCollaboration and Report
Deliberately insecure web application to teach web application security lessonsIntentionally Vulnerable Applications
OWASP Zed Attack Proxy, intercepting proxy to replay, inject, scan and fuzz HTTP requestsWeb Application Exploitation
A framework which tries to unite great tools and make pentesting more efficient.Auth & perms
Framework allowing to write, build and patch instrumentation modules for Bluetooth Low Energy (BLE) controllersWireless
Data leak checker and monitoringOSINT and Reconnaissance
Pre-operation C2 serverRed Teaming
OSINT tool used to discover environments, directories, and subdomains of a particular domain.Informations gathering
Offensive Security Youtube channel.Resources
Collection of offensive tools targeting Microsoft Azure written in Python to be platform agnostic.Cloud & services
O365 user enumeration and password spraying tool.Informations gathering
Windows debuggerReverse Engineering
Perform information gathering from Google for search results related to a user query.Cloud & services
OSINT framework; collection of toolsOSINT and Reconnaissance
A powerful subdomain integration tool.Informations gathering
Subdomain enumeration toolOSINT and Reconnaissance
A self-hosted fuzzing-as-a-service platform.Auth & perms
Hacking tools installer and package manager for hackers.Operating systems
Script that scrapes urls on different .onion search enginesOSINT and Reconnaissance
Parse OpenAPI specifications into the BurpSuite for automating RESTful API testing.Development
Online platform for finding open buckets in cloud storage systems effortlessly.Cloud & services
Platform designed for managing and analyzing cyber threat intelligence knowledge, centralizing data using the STIX2 standard and offering visualization and integration capabilitiesThreat Intelligence
Open Cyber Threat Intelligence Platform.Bug bounty
Modular and decentralised honeypot.Auth & perms
Platform allowing organizations to plan, schedule and conduct crisis exercisesCrisis Management
A Fuzzer for OpenRedirect issues.Vulnerabilities
Open Vulnerability Assessment ScannerOther
This repository contains the scanner component for Greenbone Community Edition.Auth & perms
Windows password cracker based on rainbow tables.Auth & perms
Windows hash cracker based on rainbow tablesCracking
Open Redirection Analyzer.Vulnerabilities
A simple multi-threaded distributed SSH brute-forcing tool.Informations gathering
Interactive shell to perform analysis on Instagram account of any users by their nicknameOSINT and Reconnaissance
An interactive shell to perform analysis on Instagram account of any users by its nickname.Informations gathering
Automated framework for reconnaissance and vulnerability scanningOSINT and Reconnaissance
A Workflow Engine for Offensive SecurityAuth & perms
Uses SQL queries to monitor and analyze operating systems, providing endpoint visibility for securityIncident Response
Tool to hide messages in files (website down since 2004)Steganography
CLI used to build Red Teaming infrastructure in an automated way, supports AWS and Digital OceanRed Teaming
Turn a Rapsberry Pi Zero W into a flexible, low-cost platform for pentesting, red teaming or PE.Auth & perms
A collection of utilities developed to aid in analysis of password lists in order to enhance password cracking through pattern detection of masks, rules, character-sets and other password characteristicsCracking
Platform for architecture-neutral dynamic analysisReverse Engineering
Fuzzing framework aiming at combining various software testing techniques within the same workflow to perform collaborative fuzzing also called ensemble fuzzing; supported engines are Honggfuzz, AFL++, TritonDSEReverse Engineering
No-root network monitor, firewall and PCAP dumper for Android.Operating systems
This tool extracts secrets from a pcap file or from a live interface.Informations gathering
Windows disassemblerReverse Engineering
PE viewer, closed source and windows onlyReverse Engineering
Privilege Escalation Awesome Scripts SUITE; winPEAS and linPEAS are local privilege escalation scripts for Windows and LinuxSystem Exploitation
Privilege Escalation Awesome Scripts SUITE.Operating systems
Python Exploit Development Assistance, (only python2.7)Plugins
Shellcode & PE PackerRed Teaming
PHP unserialize() payloads along with a tool to generate them.Development
PHP Generic Gadget Chains, library of unserialize() payloads along with a tool to generate them, supporting various PHP frameworksWeb Application Exploitation
Reverse engineering tool for linux games.Informations gathering
Web browser loaded with links and extensions for doing OSINTOSINT and Reconnaissance
Kerberos PKINIT and relaying to AD CSNetworking
Suite of tools to work with PNG imagesSteganography
A port scanner written purely in PowerShell.Informations gathering
Bypass for PowerShell Constrained Language Mode.Development
AD CS auditing based on the PSPKI toolkitNetworking
PenTests, Audits, and Reporting Tool; Collaborative penetration test, vulnerability database and reporting platform; fork of Sh00tCollaboration and Report
Service to check if an account has been compromised in a data breach, doesn't display breaches, partially display passwordOther
Packet manipulation library; forge, send, decode, capture packets of a wide number of protocolsNetworking
PCAP analyzer; using Bro, Suricata and ElasticsearchNetworking
Stealthy Data exfiltration via DNS, without the need for attacker-controlled Name Servers or domainNetworking
The exploitation framework designed for testing the security of AWS environments.Cloud & services
AWS exploitation frameworkCloud
Analysis framework that discovers if a file is suspicious and conveniently show the resultsDefensive
Detect and remove malware from USB disks (based on Pandora)Defensive
Automatic LFI and Path Traversal exploitation toolWeb Application Exploitation
Proxy Attack Proxy ProxY, HTTP intercepting proxyWeb Application Exploitation
This tool for brute discover GET and POST parameters.Informations gathering
Mining parameters from dark corners of Web Archives.Informations gathering
Finds parameters from web archives of the entered domainWeb Application Exploitation
Intercepting proxy to replay, inject, scan and fuzz HTTP requestsWeb Application Exploitation
HTTP(S) proxy for assessing web application vulnerability.Bug bounty
The ultimate framework for your cyber security operations.Network
Robots.txt audit tool.Auth & perms
CLI & library to search for default credentials among thousands of Products / VendorsOther
Multi-protocol bruteforce toolNetworking
Multi-purpose brute-forcer, with a modular design and a flexible usage.Informations gathering
Security operations orchestration and continuous threat management platformCollaboration and Report
Provides a unified source of vulnerability, exploit and threat Intelligence feeds; comprehensive and continuously updated vulnerability database scored and enriched with exploit and threat news informationThreat Intelligence
Tool to generate stable undetected payload.Auth & perms
A list of useful payloads and bypass for Web Application Security.Auth & perms
Visualize a packet capture offline as a network diagram including device identification.Auth & perms
PE reverse tool: recognizes packers, fast disassembler, visualization of sections layout, selective comparing of two chosen PE filesReverse Engineering
Pentest Collaboration and Reporting Tool! PeCoReT is designed to be a fully open-source collaboration platform tailored for pentest projects.Collaboration and Report
Collaborative penetration test, vulnerability database and reporting platformCollaboration and Report
Take screenshots of websitesWeb Application Exploitation
Collaborative penetration test, vulnerability database and reporting platformCollaboration and Report
Pentest Collaboration Framework - an opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!Collaboration and Report
Burp Suite extension for application pentest to write test cases and map flows and vulnerabilities.Well known products
Pre-configured portable penetration testing environment for Windows, all-in-one boxOther
Collaborative penetration test between team members and end-clients, vulnerability database and reporting platformCollaboration and Report
PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.Artificial Intelligence
Learn Web Penetration Testing: The Right Way.Resources
Sharing knowledge that makes your life as bug hunters and pentesters easier.Bug bounty
Hunt persistences implanted in Windows machines.Auth & perms
An SSL enabled basic auth credential harvester with a Word document template URL injector.Auth & perms
Phishing catcher using Certstream.Informations gathering
Information gathering framework for phone numbers.Informations gathering
Remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter sessionMobile
Remotely exploit Android devices using ADB and Metasploit.Operating systems
Incredibly fast crawler designed for OSINT.Informations gathering
Fast crawler designed for OSINTOSINT and Reconnaissance
OSINT tool allowing you to find various information via a phone number.Informations gathering
Assess the Active Directory security level with a methodology based on risk assessmentConfiguration Audit
Crawl JavaScript file to find secretWeb Application Exploitation
Analyze password dump and return statistics about passwords' strengthOther
Shows detailed information about named pipes in Windows and searching for insecure permissionsRed Teaming
A tool that shows detailed information about named pipes in Windows.Operating systems
Tool for breaking PkZip encryptionCryptography
x86/ARM/MIPS interactive disassemblerReverse Engineering
Collaborative penetration test reporting and vulnerability database platformCollaboration and Report
Creates reports for blue and purple teams by extracting data from BloodHoundSystem Exploitation
The Email OSINT tool.Informations gathering
Collaborative penetration test and reporting platform (DB + clients, no WebUI)Collaboration and Report
Real-time network packet manipulation frameworkNetworking
Send emails from your terminal.Informations gathering
The most comprehensive Postman recon / OSINT client and framework.Informations gathering
A TCP port redirection utility that allows inbound traffic redirection.Network
All the XSS cheatsheet data to allow contributions from the community.Vulnerabilities
Free, online web security training from the creators of Burp Suite.Resources
Javascript expression evaluator and inspectorWeb Application Exploitation
Proxy aware Command & Control frameworkRed Teaming
A proxy aware C2 framework used to aid with post-exploitation and lateral movement.Auth & perms
A PostMessage fuzzing extension for Chrome.Vulnerabilities
Audit script to inventory, analyze, and report excessive privileges assigned to SMB shares on Active Directory domain joined computersNetworking
Powershell payload generator In Bash !Development
A small library of powershell scripts for post exploitation that you may need or use!Auth & perms
Searches for publicly available files hosted on various websites for a particular domain.Informations gathering
Run PowerShell with dlls only to bypass software restrictions; it can be run with rundll32.exe, installutil.exe, regsvcs.exe, regasm.exe, regsvr32.exe or as a standalone executableRed Teaming
Run PowerShell with rundll32 in order to bypass software restrictions.Development
Password spraying script and helper for creating password listsCracking
A PowerShell Post-Exploitation Framework.Auth & perms
Powershell exploitation frameworkSystem Exploitation
Toolkit for attacking MS SQL Server, discovery, configuration auditing, privilege escalation, post exploitationWeb Application Exploitation
A PowerShell toolkit for attacking SQL Server.Auth & perms
A Windows privilege escalation enumeration BAT script designed for legacy Windows machines without PowershellSystem Exploitation
PowerShell MachineAccountQuota and DNS exploit tools.Auth & perms
The perils of the pre-Windows 2000 compatible access group in a Windows domain.Auth & perms
Automate the process of generating various reverse shells.Auth & perms
Report generation tool for pentester with provided OWASP dataCollaboration and Report
Allow users to route Internet traffic through Tor and hide their real IP address.Informations gathering
Monitor, collect and continuously query the assets data via a simple webUIOSINT and Reconnaissance
Multi-Packer wrapper allowing daisy-chaining various packers and obfuscators; featured with artifacts watermarking, IOCs collection & PE backdooringRed Teaming
Open Source Security tool to perform Cloud Security best practicesCloud & services
A PowerShell tool heavily inspired by the popular tool CrackMapExec/NetExec.Auth & perms
Unprivileged Linux process snooping.Auth & perms
CTI platform to search, scan, and enrich IPs, URLs, domains and other IOCs from OSINT feeds or submit your ownThreat Intelligence
Official CLI utility for Subdomain Center & Exploit Observer.Auth & perms
Cross-platform, multi function Command & Control and post-exploitation framework; fileless/all-in-memory execution, low footprint, multi-transportRed Teaming
An open-source self-hosted purple team management web application.Collaboration and Report
Collaborative penetration test reporting platformCollaboration and Report
Pentest report generator.Bug bounty
Collaborative penetration test reporting platform; fork and improvement of PwnDocCollaboration and Report
A Firefox/Burp Suite extension that provide usefull tools for your security audit.Well known products
Allow to have multiple identities in the same browser using firefox containers and hightlight the profile used with different colorsPlugins
Command execution exploiter with an auto connection handling.Auth & perms
Enhance GDB, for exploit development and reverse engineeringPlugins
Bypass client-side encryption using custom logic for testing with Python and NodeJS.Cryptanalysis
Set as many exfiltration, techniques that CAN be used to bypass various.Network
Multiplatform Python webshell.Vulnerabilities
WSUS server designed to send malicious responses to clientsNetworking
Persistent and stealthy backdooring of user and computer Active Directory objectsNetworking
Search the web for files on a domain to download and extract metadata.Informations gathering
The famous WPA precomputed cracker.Network
A dependency vulnerability scanner for your python projects, straight from the terminal.Development
Python Code Audit - A modern Python source code analyzer based on distrust. Python Code Audit is a tool to find security weaknesses in Python code. This static application security testing (SAST) tool has great features to simplify the necessary security tasks and make it fun and easy. This tool is designed for anyone who uses or creates Python programs and wants to understand and mitigate potential security risks. This tool is created for: Python Users who want to assess the security risks in the Python code they use. Python Developers: Anyone, from professionals to hobbyists, who wants to deliver secure Python code. Security-Conscious Users: People seeking a simple, fast way to gain insight into potential security vulnerabilities within Python packages or files. Creating secure software can be challenging. This tool, with its comprehensive documentation, acts as your helpful security colleague, making it easier to identify and address vulnerabilities.Code Analysis
Android APK vulnerability analyzerCode Analysis
Experimental binary diffing tool addressing the diffing as a aetwork alignement quadratic problem.Auth & perms
Communicate with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio framesWireless
Timeless debugger (QIRA = QEMU Interactive Runtime Analyser)Reverse Engineering
A comprehensive approach to the vulnerability analysis of Android application.Informations gathering
The revolutionary architecture that powers Qualys' IT, security, and compliance cloud apps.Bug bounty
Remote Administration Tool (RAT) for WindowsRed Teaming
Remote administration tool for Windows.Operating systems
Point-and-click tool for producing advanced clickjacking and frame-slicing attacks.Vulnerabilities
Unauthenticated enumeration of cloud principalsCloud
The first ever CLI based menu-driven web application B-Tier recon framework.Auth & perms
ActionScript disassemblerReverse Engineering
Identify technologies and services used by domains through their DNS footprints.Informations gathering
Enumerates users based off RDP Screenshots.Informations gathering
All in one tool for information gathering, vulnerability scanning and crawling.Informations gathering
A stateful fuzzing tool for automatically testing cloud services through their REST APIs.Development
Enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities through wordlist and bruteforce strategiesNetworking
Framework for ROP exploitationBinary Exploitation
Tool to calculate RSA parametersCryptography
RSA attack and key manipulation toolCryptography
CLI tool and library allowing to simply decode all kind of BigIP cookiesWeb Application Exploitation
A high performance offensive security tool for reconnaissance and vulnerability scanning.Informations gathering
Tests for race conditions in web applications.Development
Race Condition framework.Vulnerabilities
Scan nearby devices and execute command when the target device comes in between range.Network
It crack hashes with rainbow tables.Informations gathering
The multi tool web vulnerability scanner.Vulnerabilities
Flutter reverse engineering framework: allow traffic monitoring and interception, print classes and functions, display absolute code offset for functions, etc.Reverse Engineering
Implements a brute force attack against Wifi Protected Setup (WPS) registrar PINs.Informations gathering
Implement the multiple A record DNS rebinding attack.Informations gathering
Implements multiple A record DNS rebinding attackNetworking
Edit Java bytecode, insert single line Java statements into the bytecode, recompile decompiled codeReverse Engineering
Web-based reconnaissance toolOSINT and Reconnaissance
OSINT tool aimed at reducing the time spent harvesting information from open sources.Informations gathering
Multi-purpose reconnaissance tool, CMS detection, reverse IP lookup, port scan, etc.OSINT and Reconnaissance
Continuous recon and pipeline tools setup.Auth & perms
Network reconnaissance and vulnerability assessment toolsOSINT and Reconnaissance
Tool made to automate information gathering and service enumeration while storing resultsOSINT and Reconnaissance
Web reconnaissance and vulnerability scanner toolOSINT and Reconnaissance
Rapid content discovery tool for recursively querying webservers.Informations gathering
Automated reconnaissance scanner and security checksOSINT and Reconnaissance
Red Team's SIEM; used by Red Teams for tracking and alarming about Blue Team activities as well as better usability in long term operationsRed Teaming
Tool for Red Teams used for tracking and alarming about Blue Team activities.Auth & perms
Red team C2 log visualizationRed Teaming
RedEye is a visual analytic tool supporting Red & Blue Team operations.Auth & perms
Virtual machine for adversary emulation and threat hunting.Virtualization
Retrieves hashes and credentials from Windows workstations, servers and domain controllers using OpSec Safe TechniquesSystem Exploitation
Open source Django offensive webapp which is keeping the best tools used in the redteaming.Bug bounty
Enhance the security and confidentiality of HTTP request handling within the Burp Suite.Network
Automated Red Team Infrastructure deployment using DockerRed Teaming
Track the HTTP redirect chains; 301 and 302, JavaScript and Meta fresh redirectsThreat Intelligence
Mix of a security operations orchestration, vulnerability management and reconnaissance platformOSINT and Reconnaissance
Real time phishing toolRed Teaming
RegStrike is a .reg payload generator.Cryptanalysis
Execute full pentesting processes combining multiple hacking tools automatically.Cloud & services
x86 and ARM graphical interactive disassembler with Ruby plugin frameworkReverse Engineering
Automated reconnaissance framework for webapps, highly configurable streamlined recon process.Informations gathering
Burp Suite extension to help developers replicate findings from pentests.Bug bounty
Collaborative penetration test reporting platformCollaboration and Report
Burp Suite extension that automatically highlights different HTTP requests.Network
HTTP request collector and inspectorWeb Application Exploitation
HTTP request collector and inspectorWeb Application Exploitation
HTTP request collector and inspectorWeb Application Exploitation
Exploit race conditions in web apps with Requests.Vulnerabilities
Scans dll/ocx/exe files and extract all resources found, Windows onlyDigital Forensics
Responder is a LLMNR, NBT-NS and MDNS poisoner.Informations gathering
LLMNR, NBT-NS and MDNS poisoner to intercept authentication requests/answersNetworking
Multi file formats and architectures machine-code decompilerReverse Engineering
Detects the use of JavaScript libraries with known vulnerabilities.Development
Scanner detecting the use of JavaScript libraries with known vulnerabilitiesWeb Application Exploitation
Hosted Reverse Shell generator with a ton of functionality.Vulnerabilities
Web-based reverse shell generator, includes features such as listener generation, raw mode, bind shell generation, msfvenom generation, payload encoding, many different languages, tools and shells supportedOther
A tool to generate various ways to do a reverse shell.Vulnerabilities
A dynamic reverse engineering toolkit.Informations gathering
Enumerate usernames on a domain where you have no creds by using SMB relay.Auth & perms
All in one recon tool that just get a single domain name and do all of the work alone.Informations gathering
A malicious LDAP server for JNDI injection attacksWeb Application Exploitation
A free and open source Ruby toolkit for security research and development.Informations gathering
Toolkit for security research and development allowing for the rapid development and distribution of code, exploits, payloads, etc, via 3rd party git repositoriesOther
Scans for rootkits, backdoors and possible local exploits.Operating systems
Exploitation framework for embedded devices.Informations gathering
Exploitation framework for embedded devices: exploits, default credentials, scanners, payloadsNetworking
Tool to conduct manual or automated attack on RSACryptography
RSA multi-attacks tool: uncypher data from a weak public key and try to recover a private key.Cryptanalysis
Kerberos interaction and abusesNetworking
Rubeus is a toolkit for Kerberos interaction and abuses.Auth & perms
Command line wrapper, library, and REST API for oclHashcatCracking
Interact with Exchange servers remotely, through either the MAPI/HTTP or RPC/HTTP to abuse the client-side Outlook features and gain a shellRed Teaming
A powerful web interface that helps you to manipulate Android and iOS Apps at Runtime.Operating systems
Active Directory data collector for BloodHound written in Rust.Auth & perms
Active Directory data collector for BloodHoundNetworking
The Modern Port Scanner. Fast, smart, effective.Informations gathering
Port and reverse shell listener; less features than ncat, pwncat, pwncat-caleb but has command historyNetworking
A suite of secret scanners built in Rust for performance.Cloud & services
Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.Cloud & services
Firefox plugin that lists Amazon S3 Buckets found in requests.Cloud & services
All-in-one AWS S3 bucket tool.Cloud & services
Scan for open S3 buckets and dump the contents.Cloud & services
Publicly open storage viewer.Cloud & services
SBOM parser that performs cursory vulnerability assessment.Auth & perms
Streamline identifying, profiling, and attacking SCCM related assets in an Active Directory domainNetworking
Sandia Cyber Omni Tracker; cyber security incident response management system and knowledge baseIncident Response
Fileless lateral movement that relies on ChangeServiceConfigA to run commandsSystem Exploitation
Smart DNS Brute Forcer.Informations gathering
Web-based platform for the automation of infosec watching and vulnerability managementVulnerability Assessment
Modular C2 framework designed to successfully operate covertly on heavily monitored environmentsRed Teaming
Stego Helper Identification Tool, multi-purpose image steganography toolSteganography
Asynchronous, multiplayer and multiserver Command & Control frameworkRed Teaming
Find secrets in file and secret files among the SMB target shares.Auth & perms
Fileshare auditing tool.Network
Attack clients through file content swapping and compromise any data passed in cleartext.Vulnerabilities
Offensive tool to scan & exploit vulnerabilities in Windows over SMB using Metasploit.Well known products
SNMP brute force, enumeration, CISCO config downloader and password cracking scriptNetworking
Enumerate Active Directory environments via the Active Directory Web Services (ADWS) protocol.Auth & perms
Searches for automated subdomain enumeration and runs SQLi tests.Informations gathering
A C# MS-SQL toolkit designed for offensive reconnaissance and post-exploitation.Cloud & services
Messy BurpSuite plugin for SQL Truncation vulnerabilities.Vulnerabilities
Simple HTTP(S) proxy server and a SQLMAP API wrapper that makes digging SQLi easy.Development
Helps you to detect SQL injection "Error based" by sending multiple requests.Vulnerabilities
Automatic SQL injection with Charles and sqlmap API.Vulnerabilities
SQL injection scanner, find vulnerable entry pointsWeb Application Exploitation
Massive SQL injection vulnerability scanner.Vulnerabilities
Exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server.Vulnerabilities
A wrapper script which uses PuTTY to perform SSH login bruteforce attacks.Informations gathering
Fast and powerful SSL/TLS scanning library.Cryptanalysis
SSL analysis library and a CLI toolsWeb Application Exploitation
Server-side request forgery detector.Vulnerabilities
Facilitates tunneling HTTP communications through servers vulnerable to SSRFWeb Application Exploitation
Genereate custom endpoint to test SSRF; support any HTTP method, content-specific responses, configurable secret tokenWeb Application Exploitation
A simple SSRF-testing sheriff written in Go.Vulnerabilities
Checks for SSRF using custom payloads after fetching URLs from sources & applying complex patterns.Vulnerabilities
SSRF testing tool.Vulnerabilities
An automated SSRF finder. Just give the domain name and your server and chill!Vulnerabilities
Automatic SSRF fuzzer and exploitation toolWeb Application Exploitation
Automatic SSRF fuzzer and exploitation tool.Vulnerabilities
Automatic SSTI detection tool with interactive interface.Vulnerabilities
Security Testing and Enumeration of WebSockets; tool suite for security testing WebSockets: discover endpoints, fingerprint server, detect vulnerabilitiesWeb Application Exploitation
A tool to identify and exploit sudo rules misconfigurations and vulnerabilities.Auth & perms
Standalone script to enumerate SUID binaries, separate default binaries from customs.Auth & perms
Android APK vulnerability analyzerCode Analysis
Be notified when your favorite tool may be at risk.Cloud & services
A self-hosted WAF to protect web applications from cyber attacks.Auth & perms
The best security training environment for developers and AppSec professionals.Resources
A Python script for AWS S3 bucket enumeration.Cloud & services
Binary authorization system for macOSDefensive
Grab target's webcam shots by link.Informations gathering
Improved version of SayCheese, designed to capture images via social engineering.Informations gathering
Combines the speed of masscan with the reliability and detailed enumeration of nmap.Informations gathering
Packet manipulation library; forge, send, decode, capture packets of a wide number of protocolsNetworking
Powerful and interactive packet manipulation program and library.Network
Payload creation framework designed around EDR bypassRed Teaming
Payload creation framework designed around EDR bypass.Auth & perms
Create target specific and tailored wordlist from burp historyPlugins
Burp Suite extension to create target specific and tailored wordlist from burp history.Resources
Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration.Informations gathering
Command-line tool for finding in-scope targets for bug bounty programs.Bug bounty
A Go tool for scope management.Bug bounty
Netify.ai reconnaissance tool.Cloud & services
Discover a web server's undisclosed files, directories and VHOSTs.Informations gathering
Web directory and file scanner (wordlist bruteforce)Web Application Exploitation
Multi-cloud security auditing tool.Cloud & services
Harvest employee email addresses from a specific company through LinkedIn.Informations gathering
Scrape LinkedIn without API restrictions for data reconnaissance.Cloud & services
Convert your masscan/subdomain-scan results into screenshots for better analysis.Informations gathering
Makes web screenshots and mobile emulations from the command line.Informations gathering
ScriptSentry finds misconfigured and dangerous logon scripts.Auth & perms
Mobile application testing toolkit, the mobile metasploit-like frameworkMobile
Collects RDP, web and VNC screenshots all in one place.Informations gathering
Perform periodic syncs of data sources and performing analysis on the identified results.Informations gathering
Netcraft tool; Search and find information for domains and subdomainsOSINT and Reconnaissance
Cli tool for Exploit-DB that also allows you to take a copy of Exploit Database with you.Auth & perms
CLI tool to search among Exploit-DB exploitsSystem Exploitation
Performs security oriented safety checks relevant from offensive/defensive security perspectives.Auth & perms
Create randomly insecure VMs.Resources
Collection of multiple types of lists used during security assessments, collected in one place.Informations gathering
Vulnerability scanning, reporting and analysisVulnerabilities
Second-order subdomain takeover scanner.Informations gathering
SecretFinder is a script based on LinkFinder, written to find sensitive data in JavaScript files.Development
Secret Detection Tool.Source code management
Find secrets and passwords in container images and file systems.Virtualization
Monitor AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.Cloud & services
Security Headers is a part of Snyk, a leading cybersecurity company, and was originally created by Scott Helme! It is a free and easy to use tool designed to help you better deploy and understand modern security features that are available for your website. Snyk is a comprehensive developer security platform that enables developers to secure their code, open source dependencies, container images, cloud infrastructures, as well as web apps and APIs, all from a single unified platform. There are services out there that will analyse the HTTP response headers of other sites, but we also have a grading system for results. The HTTP response headers that we analyse provide huge levels of protection, and it's important that sites deploy them. Hopefully, by providing an easy mechanism to assess them, and further information on how to deploy missing headers, we can drive up the usage of security based headers across the Web.Web Application Exploitation
Open-source security skills for AI coding agents. Grounded in OWASP, NIST, MITRE ATT&CK, CIS. Works with Claude Code, Gemini CLI, Cursor, Codex CLI, OpenClaw, Kiro.AI Skills
Data for Security companies, researchers and teams.Informations gathering
Detect Vulnerable SSRF parameters.Informations gathering
SSRF scanner to find entry pointsWeb Application Exploitation
Boost the cybersecurity skills of your teams with the cyber knowledge library.Resources
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.Code Analysis
SimplE RePort wrIting and CollaboratiOn tool, penetration testing report generation and collaboration toolCollaboration and Report
SimplE RePort wrIting and CollaboratiOn tool NEXT-GENERATION, penetration testing report generation and collaboration tool, fork of SerpicoCollaboration and Report
Hijack user sessions by injecting malicious JavaScript codeWeb Application Exploitation
Evaluate user privileges in web applications across a list of URLs.Auth & perms
RDP MitM toolNetworking
The analyst console for network security monitoring.Auth & perms
Pentesting platform with dynamic task manager, checklists, bug template & bug reportCollaboration and Report
C2 and proxy designed to help in the exploitation of XSS and malicious Service Workers.Vulnerabilities
Spray shadow credentials across an entire domain.Informations gathering
GraphQL schema extraction to JSON file with introspectionWeb Application Exploitation
GraphQL security testing tool.Databases
Windows persistence toolkit written in C#.Operating systems
Command & Control frameworkRed Teaming
Command and Control Framework written in C#.Development
Extracts cookies from Chrome.Development
Detect and identify the presence of known defensive products such as AV's, EDR's and logging toolsRed Teaming
Asynchronous password spraying tool for Windows environments.Auth & perms
A User Impersonation tool - via Token or Shellcode injection.Operating systems
A post-exploitation tool designed to leverage Microsoft Endpoint Configuration Manager.Auth & perms
Payload Generation Framework for C# source codeSystem Exploitation
Automatically create cheat sheets from all relevant vectors on the system.Vulnerabilities
Tool to craft bind and reverse shells in several languagesSystem Exploitation
Pop shells like a master.Auth & perms
A QoL tool to obfuscate shellcode.Cryptanalysis
Obfuscate shellcode using encoding, encryption, compressionRed Teaming
A comprehensive OS command injection payload generator.Vulnerabilities
A script for generating common revshells fast and easily.Vulnerabilities
A technique to hide malicious shellcode based on low-entropy via Shannon encodingRed Teaming
Hunt down social media accounts by username across social networks.Informations gathering
Hunt down social media accounts by username across social networksOSINT and Reconnaissance
Search engine for Internet-connected devices.Informations gathering
Search devices connected to the internet; helps find information about desktops, servers, IoT devices; including metadata such as the software runningOSINT and Reconnaissance
Find sensitive data inside the screenshots uploaded to prnt.sc.Informations gathering
Dowgrade, convert, dissect and shuck authentication token based on Data Encryption Standard.Auth & perms
Advanced exploit search tool designed to identify and gather information about exploits.Auth & perms
System for Internet-Level Knowledge; collection of traffic analysis tools developed to facilitate security analysis of large networksNetworking
Generic signature format for SIEM systemsIncident Response
Quietly enumerates an Active Directory Domain via LDAP parsing users, admins, groupsNetworking
Simple Malware Scanner based on file hash scan.Auth & perms
LFI exploit toolWeb Application Exploitation
Email recon made fast and easy, with a framework to build on.Informations gathering
DNS rebinding attack frameworkNetworking
Truly open-source general purpose vulnerability scanner.Auth & perms
Web application security scanner, rewrite and newer version of WAScanWeb Application Exploitation
Tool for information gathering and penetration test automationOSINT and Reconnaissance
Utility for information gathering and penetration testing automation.Cloud & services
Dangerously fast DNS/network/port scanner.Informations gathering
A security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. Combines pattern-based detection (YAML + YARA), LLM-as-a-judge, and behavioral dataflow analysis for comprehensive threat detection. Supports OpenAI Codex Skills and Cursor Agent Skills formats following the Agent Skills specification.AI Skills
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.AI Skills
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflowsAI Skills
Monitoring your Slack workspaces for sensitive informations.Informations gathering
Sleepy Puppy XSS Payload Management Framework.Vulnerabilities
Tool that parses Burp history to discover potential SQL injection points and prepare SQLmap request filesWeb Application Exploitation
Burp History parsing tool to discover potential SQL injection points.Vulnerabilities
Cross-platform adversary emulation/red team framework used by organizations of all sizes to perform security testingAdversary Simulation
Cross-platform implant framework that supports C2 over Mutual-TLS, HTTP(S), and DNS; remote access tool (RAT)Red Teaming
A blazing fast & feature rich Amazon S3 bucket enumerator.Cloud & services
To to restore defocused and blurred images (update binary only for Windows, Mac OS binary out of date)Steganography
Pentest oriented collaborative tool used to track the progress of your company's engagements and generate reportsCollaboration and Report
System Management Mode (SMM) backdoor for UEFI based platformsHardware
Find cloud assets that no one wants exposed.Cloud & services
Identify AWS cloud assetsCloud
A rapid HTTP downgrade smuggling scanner written in Go.Vulnerabilities
An HTTP Request Smuggling / Desync testing tool.Vulnerabilities
HTTP request smuggling, desync testingWeb Application Exploitation
Automated reconnaissance scannerOSINT and Reconnaissance
Attack Surface Management Platform.Auth & perms
A tool to help at finding delicious candy needles in a bunch of horrible boring haystacks.Auth & perms
Find credentials and valuable information from windows active directory environments (shares, files)Networking
Pastebin OSINT harvester.Informations gathering
A framework for wireless pentesting.Network
Intrusion detection system that monitors network traffic for suspicious activities and threatsNetworking
Native code to C/C++ decompiler, supporting x86, AMD64, and ARM architectures, exists as standalone app or as a plug-inReverse Engineering
A social media enumeration & correlation tool.Informations gathering
Phishing targeting social media logins; supports Ngrok tunneling and a mobile controllerRed Teaming
Allows to get the emails from a target published in social networks to find possible credentials.Cloud & services
Automatic code review tool to detect bugs, vulnerabilities; continuous code inspection automated with static code analysis rulesCode Analysis
A rapid API for the project Sonar dataset.Informations gathering
Tool to edit and analyze audio tracksSteganography
The next generation Snort Intrusion Prevention System.Informations gathering
Search millions of open source repositories.Informations gathering
Automates OSINT for threat intelligence and mapping your attack surface.Informations gathering
Advanced web spider/crawler for cyber security professionals.Auth & perms
Maltego penetration testing TransformsPlugins
Exploits & tools search engine.Auth & perms
The unified security and observability platform.Cloud & services
Checks if a list of domains can be spoofed based on SPF and DMARC records.Informations gathering
Collection of Windows print spooler exploits and other utilities for practical exploitation.Auth & perms
Fast multithreaded password spraying tool with backend database.Informations gathering
Password spraying in Active Directory checking the default domain password policy and the badpwdcount LDAP attribute to avoid account locking, set pwned users as owned in Bloodhound and detect path to Domain AdminsNetworking
Permutation-based password list generatorCracking
Password spraying scripts for Lync/S4B and OWAOther
This Chrome extension will read literally everything it can.Development
Time-based blind SQL injection fuzzer for HTTP headersWeb Application Exploitation
Lets you use Burp Collaborator as a DNS server for exfiltrating data via Sqlmap.Well known products
Builds a static reverse SSH server for pivoting; supports HTTP and SOCKS5 proxies, DNS and ICMP tunnelling, HTTP encapsulationNetworking
Reverse shell based on sshd supporting DNS and ICMP tunnelling as well as HTTP and Socks proxies.Network
Crossplatform tool which help to perform static code analysis on mobile applications.Informations gathering
Mobile applications static code analysis toolCode Analysis
Automated scanning of social networks and other websites, using a single nicknameOSINT and Reconnaissance
WebUI for EmpireRed Teaming
Starkiller is a frontend for Empire.Auth & perms
Stego image toolsuite in the browserSteganography
Desktop application used to analyze images in different planes by taking off bits of the image.Steganography
Steganography analysis toolSteganography
Tool to hide messages in imagesSteganography
Automatic tool to bruteforce LSB, transform image, extract metadata or trailing dataSteganography
Evolution of Burp Suite's Repeater tool, providing the ability to create sequences of steps and define regular expressions to extract values from responsesPlugins
A natural evolution of Burp Suite's Repeater tool.Well known products
Social engineering tool, access eebcam & microphone & location finder.Informations gathering
Granular, actionable adversary emulation for the cloud.Cloud & services
Stratus Red Team is 'Atomic Red Team' for the cloud, allowing to emulate offensive attack techniques in a granular and self-contained mannerAdversary Simulation
Offensive information and vulnerability scanner.Informations gathering
A very (very) FAST and simple subdomain finder based on online & free services.Informations gathering
A free, open source, cross platform Intelligence gathering tool.Informations gathering
A DNS meta-query spider that enumerates DNS records, and subdomains.Informations gathering
Find subdomains and interesting things hidden inside, external Javascript files of page, folder, and GithubOSINT and Reconnaissance
A tool to find subdomains and interesting things hidden inside.Cloud & services
Find subdomains with GPT, for free.Informations gathering
A Powerful Subdomain Takeover Tool.Informations gathering
Perform subdomain enumeration through various techniques and retrieve detailed output.Informations gathering
Find subdomains by searching public certificate records.Informations gathering
Discovery tool that discovers valid subdomains for websites.Informations gathering
Subdomain Takeover tool written in Go.Vulnerabilities
Monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.Informations gathering
Fast subdomains enumeration tool for penetration testers.Informations gathering
Subdomains enumeration toolOSINT and Reconnaissance
A Web-UI for subdomain enumeration.Informations gathering
Passive reconnaissance/enumeration of interesting targets by watching for SSL certificates.Informations gathering
Collects subdomains and analyzes domains performing automated reconnaissance.Informations gathering
Subdomain enumeration tool OSINT and Reconnaissance
Real fucking shellcode encryptor & obfuscator tool.Cryptanalysis
Escalate SSRF vulnerabilities on modern cloud environments, enumerate reachable hostsWeb Application Exploitation
Implementation of the Language Server Protocol for Suricata signatures; real-time rule syntax checking and auto-completionNetworking
Designed to assist with auditing of exposed Swagger/OpenAPI) definition files.Informations gathering
A collection of various Windows privilege escalation techniques from service accounts to SYSTEM.Auth & perms
Collection of utilities to work with SWF filesReverse Engineering
Cross-platform note-taking and target-tracking app for penetration testersCollaboration and Report
Consulting different intelligence services, search engines and datasets for OSINT.Informations gathering
HTTP(S) server designed to assist in red teaming activities such as receiving intercepted data via POST requests and serving content dynamicallyRed Teaming
Http(s) server designed to host resources dynamically or act as a receiver for POST data intercepts.Network
Collaborative penetration test, vulnerability database and reporting platform; supports findings in markdown, customized reports in HTML and VueJS, rendering to PDF, MFA, note-taking, data encryption, SSOCollaboration and Report
SysWhispers on Steroid, AV/EDR evasion via direct system callsRed Teaming
AV/EDR evasion via direct system calls.Operating systems
The all in one multi honeypot platform.Virtualization
Telegram Explorer created to help researchers, investigators and law enforcement agent.Bug bounty
The offensive manual web application penetration testing framework.Informations gathering
Comprehensive web-app audit frameworkWeb Application Exploitation
TInjA is a CLI tool for testing web pages for template injection vulnerabilities. It supports 44 of the most relevant template engines (as of September 2023) for eight different programming languages. TInjA was developed by Hackmanit and Maximilian Hildebrand.Web Application Exploitation
Scan all possible TLD's for a given domain name.Informations gathering
Domain availability checker.Informations gathering
CLI & library for mapping TLS cipher algorithm names: IANA, OpenSSL, GnUTLS, NSSWeb Application Exploitation
TLS-Attacker is a Java-based framework for analyzing TLS libraries. It is able to send arbitrary protocol messages in an arbitrary order to the TLS peer, and define their modifications using a provided interface. This gives the developer an opportunity to easily define a custom TLS protocol flow and test it against his TLS library. Please note: TLS-Attacker is a research tool intended for TLS developers and pentesters. There is no GUI and no green/red lights.Cryptography
TLS-Scanner is a tool to assist pentesters and security researchers in the evaluation of TLS server and client configurations.Cryptography
Help to exploit weak implementation of library or program that used TPMSystem Exploitation
Bindings for Microsoft WinDBG Time Travel Debugging (TTD)Reverse Engineering
Flexible and scriptable password dictionary/wordlist generatorCracking
Twitter Intelligence Tool; Twitter scraping & OSINT tool that doesn't use Twitter's API, allowing one to scrape a user's followers, following, Tweets and more while evading most API limitationsOSINT and Reconnaissance
View and modify HTTP requests before they are sent.Network
Allows you to intercept and edit HTTP/HTTPS requests and responses.Network
MS Teams implant persistent backdoorRed Teaming
Security tool to discover S3 buckets on Amazon's AWS platform.Cloud & services
Leverage paste sites as a medium for discovery of objectionable/infringing materialsOSINT and Reconnaissance
CLI tool for testing web pages for template injection vulnerabilities.Vulnerabilities
With the Template Injection Playground a large number of the most relevant template engines (as of September 2023) can be tested for template injection possibilities. For this purpose, simple web pages are provided, each of which uses one of the template engines. Furthermore, various optional security measures such as sandboxes, encodings, and denylists can be activated. The Template Injection Playground was developed by Hackmanit and Maximilian Hildebrand.Intentionally Vulnerable Applications
The Template Injection Table is intended to help during the testing of an application for template injection vulnerabilities. It was developed by Hackmanit and Maximilian Hildebrand. The table consists of so-called "polyglots" that can be used to detect template injection possibilities and identify which template engine is used by an application.Web Application Exploitation
Scan for top potential vulnerabilities with known CVEs in your web applications.Vulnerabilities
Misconfiguration scanner for terraform codeCode Analysis
Multi-purpose information gathering toolOSINT and Reconnaissance
All in one tool for Information Gathering.Informations gathering
Archive of public exploits and corresponding vulnerable software.Auth & perms
Differential testing and fuzzing of HTTP servers and proxies.Network
The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.Virtualization
Open-source penetration testing framework designed for social engineering.Informations gathering
Weaponizing WaybackUrls for recon, bug bounties, OSINT, sensitive endpoints and what not.Informations gathering
A collection of wordlists for many different usages.Resources
The XSS rat YouTube channel.Resources
Master the command line, in one page.Operating systems
Fuzz Cross-Origin Resource Sharing implementations for common misconfigurations.Vulnerabilities
Post-exploitation tools to gather credentials from various password managers and Windows utilities.Auth & perms
Windows event log file viewer and analyserIncident Response
Extract and aggregate threat intelligence (IOCs from threat feeds)Threat Intelligence
Knowledge base workflow management for YARA rules and C2 artifactsThreat Intelligence
Identify vulnerabilities in running containers, images, hosts and repositoriesVulnerability Assessment
Open source cloud native security observability platform. Linux, K8s, AWS Fargate and more.Bug bounty
Azure JWT token manipulation toolset.Auth & perms
Escalate a Cross-Site Scripting vulnerability to Remote Code Execution in WordPress.Vulnerabilities
Kali linux hacking tool installerOther
Retrieve information about ads of a facebook page, retrieve the number of people targeted, how much the ad cost and a lot of other informationOSINT and Reconnaissance
Assists with finding all sinks and sources of a webapp and display the results in a nice way.Well known products
Tool that help to manually find XSSWeb Application Exploitation
A packet sniffer tool, allows you to monitor and analyze network traffic from PCAP files.Network
Understand how input is transformed on a system, which can help to craft payloads.Cryptanalysis
Remove URLs with duplicate funcionality based on script resources includedWeb Application Exploitation
Command and control framework masking the activity by emulating legitimate websiteRed Teaming
A legitimate website that tunnels client/server communications for covert command execution.Auth & perms
Burp Suite Extension to hunt for common vulnerabilities found in websites.Well known products
A dynamic binary analysis library.Informations gathering
Dynamic binary analysis framework, automate reverse engineeringReverse Engineering
Triton-based DSE library with loading and exploration capabilitiesReverse Engineering
Vulnerability and misconfiguration scanner for containers (OS and language-specific packages)Code Analysis
Find secret information in git repositoriesOSINT and Reconnaissance
Hands-on cyber security training through real-world scenarios.Resources
Network security scanner with an extensible plugin systemNetworking
Subdomains enumeration tool for penetration testers.Informations gathering
Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.Network
Subdomain enumeration tool with analysis features for discovered domains.Informations gathering
Tunnels HTTP over a permissive/open TURN server; supports HTTP and SOCKS5 proxyNetworking
Identifying function names in stripped binaries and un-named functionsReverse Engineering
Enumerate Typo3 version and extensionsWeb Application Exploitation
HTTP botnet PoCRed Teaming
Fast and lightweight UDP scanner that supports the discovery of many services.Network
A JavaScript parser, minifier, compressor and beautifier toolkit.Cryptanalysis
JavaScript obfuscator or beautifier toolkitReverse Engineering
Salesforce lightning recon and exploitation tool.Cloud & services
An asynchronous TCP and UDP port scanner.Informations gathering
RFI, LFi and RCE scannerWeb Application Exploitation
Never ever ever use pixelation as a redaction technique.Cryptanalysis
Bypass Windows and Linux user passwords from a bootable USB based on Linux.Operating systems
Simple HTTP listener for security testing.Network
HTTP file upload scanner for Burp Proxy.Vulnerabilities
Domain user enumeration tool.Informations gathering
Web dork and vulnerability scannerWeb Application Exploitation
Vulnerable REST API with OWASP top 10 vulnerabilities for security testing Intentionally Vulnerable Applications
VBScript minifierOther
VBA obfuscation tools combined with an MS Office document generator .Cryptanalysis
Virtual host scanner that performs reverse lookups.Auth & perms
Windows only web application and REST API vulnerability scannerWeb Application Exploitation
Wrapper for the Vulnerability Rating TaxonomyVulnerability Assessment
SWF vulnerability and information scannerReverse Engineering
UI-based tool with multiple techniques for attacking and enumerating Azure and AWS environment.Cloud & services
Tool designed for fetching, validating, and storing working proxies.Network
Vulnerable REST API with OWASP top 10 vulnerabilities for security testing.Resources
Multi-platform web scanner and intercepting proxyWeb Application Exploitation
Post exploitation tool to maintain some level of acces.Auth & perms
Endpoint visibility and collection toolDigital Forensics
Endpoint visibility and collection tool.Informations gathering
Popular Pentesting scanner for SQLi/XSS/LFI/RFI and other Vulns.Vulnerabilities
vRx by Vicarius offers real-time and automated patching, patchless protection, and script-based remediation across apps, OS, and third-party software.Collaboration and Report
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision Native Scan (vigolium scan): Fast, powerful, and flexible. Deterministic, multi-phase scanning with 251 modules across content discovery, browser/SPA spidering, and active/passive audit, covering injection, access control, file/path, API/protocol, framework-specific, cloud/infra, and out-of-band (OAST) vulnerability classes. Agentic Scan (vigolium agent): Thoroughly audits your codebase. AI-driven scanning that autonomously plans attacks, selects modules, generates custom extensions, and triages results, combining deep source-code audit with autonomous and targeted vulnerability scanning.Adversary Simulation
Distributed command and control frameworkRed Teaming
Backdoor generator and multi-session handler for sessions sharing among connected sibling servers.Auth & perms
A script to enumerate virtual hosts on a server.Informations gathering
Online local vulnerability scanners project.Auth & perms
Provide materials that allows anyone to gain practical 'hands-on' experience in security.Resources
A place to learn and improve penetration testing/ethical hacking skills for FREE.Vulnerabilities
Create and edit CVE information in CVE JSON formatVulnerability Assessment
Pentesting management and automation platformCollaboration and Report
Agent-less vulnerability scanner.Auth & perms
Agentless system vulnerability scanner for Linux/FreeBSD with a dashboard (VulsRepo) for analyzing the scan resultsVulnerability Assessment
Interactive cheat sheet with a curated list of offensive security tools and their commands.Operating systems
WAF bypassing toolWeb Application Exploitation
Web application security scannerWeb Application Exploitation
Windows Exploit Suggester - Next Generation.Operating systems
Windows Exploit Suggester - Next Generation; analyses Windows targets patch levels to find exploits and Metasploit modules; works well with newer system (eg Windows 10) thanks to MSRC supportSystem Exploitation
EDR for WindowsDefensive
Powershell-based Windows security auditing toolbox.Operating systems
Post exploitation tool that uses WMI event filter and MSBuild execution for lateral movement.Auth & perms
Weakpass rule-based online generator; generates a wordlist based on a set of words entered by the userCracking
Tool for the recognition of vulnerabilities and blackbox information for Wordpress.CMS
WordPress CMS vulnerability scannerWeb Application Exploitation
WPScan WordPress Security ScannerCMS
A centralized dashboard for running and scheduling WordPress scans powered by WPScan utility.CMS
WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University Bochum (https://nds.rub.de/) and the Hackmanit GmbH (https://hackmanit.de/). The basic idea behind WS-Attacker is to provide a functionality to load WSDL files and send SOAP messages to the Web Service endpoints (which is executed using the underlying SoapUI framework). This functionality can be extended using various plugins and libraries to build specific Web Services attacks. You can find more information on the WS-Attacker architecture and its extensibility in our paper: Penetration Testing Tool for Web Services Security (https://www.nds.rub.de/research/publications/ws-attacker-paper/)Web Application Exploitation
WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University Bochum (https://nds.rub.de/) and the Hackmanit GmbH (https://hackmanit.de/). The basic idea behind WS-Attacker is to provide a functionality to load WSDL files and send SOAP messages to the Web Service endpoints (which is executed using the underlying SoapUI framework). This functionality can be extended using various plugins and libraries to build specific Web Services attacks. You can find more information on the WS-Attacker architecture and its extensibility in our paper: Penetration Testing Tool for Web Services Security (https://www.nds.rub.de/research/publications/ws-attacker-paper/)Adversary Simulation
Modular framework for SOAP web services penetration testingWeb Application Exploitation
Burp Suite plugin to detect current and discover new WSDL files.Development
Fuzzing penetration testing tool for testing HTTP SOAP based web servicesWeb Application Exploitation
Web Service Security Assessment Tool; WS, REST API, SOAP API dynamic scannerWeb Application Exploitation
The web-application vulnerability scanner.Auth & perms
Web technologies detection; assemble different features from HTTPX, Naabu, GoWitness and WappalyzerWeb Application Exploitation
Identify technologies on websites.Informations gathering
Ansible playbook to deploy infrastructure in the cloud for conducting Red Team assessmentsRed Teaming
Automated platform for discovering new potentially cybersecurity threats targeting your assets (detects typosquatting domain names, monitor malicious domain names, detects data leaks...)Threat Intelligence
Enumerate missing KBs and suggest exploits for useful privilege escalation vulnerabilities.Auth & perms
Hashcat WebUI; asynchronous task, chain tasks, statistics, export, segregation, local and LDAP authenticationCracking
Explore more than 778 billion web pages saved over time.Cloud & services
Find way more from the Wayback Machine!Informations gathering
Security monitoring solution for threat detection, integrity monitoring, incident response and compliance; unified XDR and SIEM protection for endpoints and cloud workloadsDefensive
Browser extension that extracts users from LinkedIn company pages.Informations gathering
XSS payloads designed to turn alert(1) into P1.Auth & perms
Web Cache Vulnerability Scanner (WCVS) is a fast and versatile CLI scanner for web cache poisoning and web cache deception developed by Hackmanit and Maximilian Hildebrand. The scanner supports many different web cache poisoning and web cache deception techniques, includes a crawler to identify further URLs to test, and can adapt to a specific web cache for more efficient testing. It is highly customizable and can be easily integrated into existing CI/CD pipelines.Web Application Exploitation
All-in-one OSINT tool for analysing any website.Informations gathering
A web crawler oriented to infosec.Informations gathering
Automation tool designed to enumerate subdomains and detect bugs using different open-source tools.Vulnerabilities
Deliberately insecure application.Resources
Hashcat WebUI with distributed cracking sessions and analyticsCracking
An automated dynamic testing solution that provides comprehensive vulnerability detection.Bug bounty
A web dashboard for nmap XML reportNetworking
A web dashboard for nmap XML reportNetworking
Framework for analysing applications that communicate using the HTTP and HTTPS protocols.Network
A web scraper to scrape email's and phone numbers from websites.Informations gathering
HTTP request collector and inspectorWeb Application Exploitation
Web shell for post-exploitation working with a PHP agentWeb Application Exploitation
AWS Attack Library.Cloud & services
Web application fuzzer.Informations gathering
Web directory and file scanner (wordlist bruteforce); but also a web fuzzerWeb Application Exploitation
Service able to detect more than 430 CMS, find version used for some CMS, has an API for batch detectionWeb Application Exploitation
Detect which CMS a site is using.CMS
OSINT tool to find breached emails, databases, pastes, and relevant information.Informations gathering
Discover what runs a website.Well known products
Detect and bypass web application firewalls and protection systems.Informations gathering
Next generation web scanner.Auth & perms
Web scanner, recognises web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices, also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more; more than 1800 pluginsWeb Application Exploitation
Enumerate usernames across many websites.Informations gathering
Take over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding Shadow Credentials to the target accountNetworking
Identify hardcoded secrets in static structured text.Informations gathering
Domain & IP data intelligence for greater enterprise security.Informations gathering
DNS Server for executing DNS Rebinding attacksNetworking
WiFi exploitation framework.Network
Framework for rogue Wi-Fi access point attack.Network
Dictionary generator used to generate dictionaries/wordlist for Wireless Router PasswordsWireless
A simple wireless networks penetration testing toolkit.Network
Windows debuggerReverse Engineering
Windows WiFi brute forcing utility without the requirement of external dependencies.Network
The Windows memory acquisition tool.Operating systems
Automation for internal Windows pentest / AD-Security.Auth & perms
UAC bypass, Elevate, Persistence methods.Auth & perms
Compares target patch levels against the Microsoft vulnerability DB to detect missing patches.Operating systems
Analyses Windows targets patch levels to find exploits and Metasploit modules, works only for older systems (eg Windows XP, Vista, etc.) because it relies on MS Security KBsSystem Exploitation
WireGuard socks proxy for pentest pivotingNetworking
Network protocol analyzerNetworking
Network sniffer that captures and analyzes packets off the wire.Vulnerabilities
Web Inventory tool, takes screenshots and provides some extra bells&whistles to make life easier.Informations gathering
Take screenshots of websites, provide some server header info, and identify default credentials if possibleWeb Application Exploitation
Selenium based web scraper to generate passwords list.Informations gathering
Assist with creating tailored wordlists, mostly based on geolocation.Resources
Collaborative penetration test reporting platformCollaboration and Report
Hidden parameters discovery suite.Informations gathering
Automate XPath injection/XXE attacks to retrieve documentsWeb Application Exploitation
X-Forwarded-For [403 forbidden] enumeration.Cloud & services
Tunnelling framework; supports TCP, UDP, ICMP, SOCKS, HTTP, SCTP, WebSocket, RDPNetworking
Tool to analyze multi-byte xor cipherCryptography
The Prime Cross Site Request Forgery Audit and Exploitation Toolkit.Vulnerabilities
Advanced Cross Site Request Forgery (CSRF/XSRF) audit and exploitation toolkitWeb Application Exploitation
The fastest way to set up XSS Hunter to test and find blind cross-site scripting vulnerabilities.Vulnerabilities
XSS probes host for finding blind XSSWeb Application Exploitation
The fastest way to set up XSS Hunter to test and find blind XSS vulnerabilities.Vulnerabilities
A Chrome extension for fast and easy XSS fuzzing.Vulnerabilities
XSS probes host for finding blind XSSWeb Application Exploitation
Hack with JavaScript.Vulnerabilities
Multi-purpose tool for XSS or JavaScript analysisWeb Application Exploitation
Multi-purpose tool for XSS or JavaScript analysisWeb Application Exploitation
XSS automatic scannerWeb Application Exploitation
Simple XSS Scanner tool.Vulnerabilities
Detect XSS vulnerability in Web Applications.Vulnerabilities
Written by Black Hat Ethical Hacking and #ChatGPT for offensive security and XSS attacks.Vulnerabilities
Automatic framework to detect, exploit and report XSS vulnerabilities in web-based applications.Vulnerabilities
XSS automatic scanner and exploiterWeb Application Exploitation
semi-automatic reflected and persistent XSS scannerPlugins
Most advanced XSS scanner.Vulnerabilities
XSS detection tool, parser, payload generator, fuzzing engine, crawlerWeb Application Exploitation
A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks.Informations gathering
XS-Leak browser test suiteWeb Application Exploitation
Powerfull XSS Scanning and Parameter analysis tool&gem.Informations gathering
XSS ScannerWeb Application Exploitation
Extreme Vulnerable Node Application, insecure webapp for security trainingsIntentionally Vulnerable Applications
A badly coded web application that helps security enthusiasts to learn application security.Resources
A mini webserver with FTP support for XXE payloads.Network
Tool for automatic exploitation of XXE vulnerability using direct and different out of band methodsWeb Application Exploitation
Exploitation of XXE vulnerability using direct and different out of band methods.Vulnerabilities
This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.Vulnerabilities
Generates XML payloads, and automatically starts a server to serve the needed DTD's or to do data exfiltration for XXE attacksWeb Application Exploitation
Tool to help exploit XXE vulnerabilities.Vulnerabilities
Processes memory scannerReverse Engineering
XSS detection and exploit framework (Windows only)Web Application Exploitation
An advanced Cross Site Scripting vulnerability detection and exploitation framework.Vulnerabilities
A Chrome browser extension to show alerts for several hidden elements.Vulnerabilities
Disassembly and static analysis library that provides triage analysis dataReverse Engineering
Remote active operating system fingerprintingNetworking
Web security scanner (XSS, SQLi, SSRF, XXE, etc.)Web Application Exploitation
Burp Suite plugin for XSS and SQLi which add our payload to all parameters with one click.Vulnerabilities
Pattern matching helping malware researchers to identify and classify malware samplesIncident Response
TYet Another Stupid Audit Tool; check general Linux system and common softwares configurationConfiguration Audit
Scans for vulnerable & exploitable 3rd-party web applicationsWeb Application Exploitation
Yet Another Yara Automaton; automatically curate open source yara rules and run scansIncident Response
The pattern matching swiss knife for malware researchers.Informations gathering
Yara rules editor, generator, scannerIncident Response
Access to all bug bounty programs directly inside BurpPlugins
Yar is a tool for plunderin' organizations, users and/or repositories...Informations gathering
A network analyzer that make easy to extract informations about network traffic.Informations gathering
Organize observables, indicators of compromise, TTPs, and knowledge on threats in a single, unified repositoryThreat Intelligence
Your OSINT Graphical Analyzer.Informations gathering
Your OSINT Graphical Analyzer; project to help people understand different courses of action to take based upon the dataWeb Application Exploitation
The world's most widely used web app scanner.Network
GUI for NmapNetworking
ZRT; project management, vulnerability management and pentest report creation applicationCollaboration and Report
Collection of tools to scan and study massive networksNetworking
Automated phishing tool with multiple tunneling options; fork of ShellphishRed Teaming
Auto Scanning to SSL Vulnerability.Cryptanalysis
Automatically list vulnerable Windows ACEs/ACLs using DC's LDAP to list users/groups/computers/OU/certificate templates and their nTSecurityDescriptor to check for vulnerable rightsSystem Exploitation
Interacts with BloodHound to identify and exploit ACL based privilege escalation pathsSystem Exploitation
LDAP based Active Directory user and group enumeration toolNetworking
Powershell tool to automate Active Directory enumeration.Auth & perms
Collection of scanner checks missing in Burp.Well known products
Test credentials against Active Directory Federation Services (ADFS), allowing password spraying or bruteforce attacksNetworking
Enumeration and exporting of all DNS records in ADIDNS domain or forest DNS zonesNetworking
Discover Adobe Experience Manager (AEM) Content Management System (CMS) websites.CMS
A vulnerability scanning tools for penetration testing.Informations gathering
Fully automated WPA PSK PMKID and handshake capture script.Network
Complete suite of tools to assess WiFi network security.Informations gathering
Wireless network audit scriptWireless
This is a multi-use bash script for Linux systems to audit wireless networks.Network
Public malware techniques used in the wild: virtual machine, emulation, debuggers.Virtualization
Modular web vulnerability scannerWeb Application Exploitation
Fast and customizable subdomain wordlist generator using DSL.Informations gathering
Customizable subdomain wordlist generator using DSLOSINT and Reconnaissance
Identify applications even if they are running on a different port than normal.Informations gathering
Blind SQL Injection Tool with Golang.Vulnerabilities
Tool for reverse engineering and malware analysis of Android applicationsReverse Engineering
Reverse engineering and pentesting for Android applications.Operating systems
A powerful and user-friendly binary analysis platform.Informations gathering
Platform-agnostic binary analysis frameworkReverse Engineering
Automated client-side template injection detection for AngularJS.Development
A CLI application that automatically prepares Android APK files for HTTPS inspection.Informations gathering
Extract endpoints from APK files.Operating systems
Framework for monitoring and tampering system API calls of native macOS, iOS and android apps.Operating systems
Scans the history of GitHub repositories to find sensitive things.Informations gathering
Automate your application security orchestration and correlation (ASOC).Bug bounty
Script for Arch Linux which use iptables settings to create a transparent proxy through Tor NetworkNetworking
Tool that allows instant setup of virtual machines on various architectures for reverse, exploit, fuzzing and programming purposeReverse Engineering
Discover hosts on your network using ARP requestsNetworking
Find domains and subdomains related to a given domain.Informations gathering
Create vulnerable instrumented local or cloud environments to simulate attacks.Virtualization
Burp Suite plugin to test for authorization flaws.Auth & perms
Smart context-based SSRF vulnerability scanner.Vulnerabilities
A tool used to check if a CNAME resolves to the scope address.Informations gathering
A shiny new copy of Chromium that will bring colors in your hunt.Well known products
Specify targets and run sets of tools against them.Auth & perms
An automated tool that automatically scanning a list of multiple websites with wordpress at once.CMS
AntiVirus Evasion Tool.Cryptanalysis
A collection about Proof of Concepts of Common Vulnerabilities and Exposures.Auth & perms
Collection of AWS penetration testing scriptsCloud
Distribute the workload of many different scanning tools with ease.Cloud & services
PHP Webshell with handy features.Development
Webshell with many features: file manager, search, command execution, DB connection, SQL explorer, process listWeb Application Exploitation
Buggy Web Application, insecure webapp for security trainingsIntentionally Vulnerable Applications
An extremely buggy web application!.Resources
bXSS is a utility which can be used identify Blind Cross-Site Scripting.Vulnerabilities
Finds unknown classes of injection vulnerabilities.Well known products
Advanced network reconnaissance toolOSINT and Reconnaissance
A library for detecting known or weak cryptographic secrets across many web frameworksWeb Application Exploitation
A library for detecting known secrets across many web frameworks.Development
The AWS Cloud Post Exploitation framework!Cloud & services
OSINT automation for hackers.Informations gathering
Generation of bug bounty reports based on user provided templatesBug bounty
Fetches latest bug bounty programs from many platforms and consolidates them in one place.Auth & perms
Service enumerating all targets on Internet covered by a bug bounty programBug bounty
Help you coordinate your reconnaissance workflows across multiple devices.Auth & perms
Scope gathering tool for multiple Bug Bounty platforms.Bug bounty
JMX enumeration and attacking; helps to identify common vulnerabilities on JMX endpointsNetworking
Scan your source code against top security and privacy risks.Development
PE parsing library (from PE-bear)Reverse Engineering
The Swiss Army knife for WiFi, BLE, IPv4 and IPv6 networks reconnaissance and MITM attacks.Network
MITM frameworkNetworking
Web UI for bettercapNetworking
A list of strings which have a high probability of causing issues when used as user-input data.Vulnerabilities
Raw binary firmware analysis software; tries to determine the firmware loading addressReverse Engineering
GNU collection of binary toolsReverse Engineering
Fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images.Auth & perms
Analyze, reverse engineer and extract firmware images (and other files, also usefull for Digital Forensics)Reverse Engineering
Crack legacy zip encryption with Biham and Kocher's known plaintext attackCracking
Dump the syskey bootkey from a Windows NT/2K/XP system hive, often used with samdump2, part of the ophcrack projectSystem Exploitation
Active Directory privilege escalation frameworkNetworking
Network protocol fuzzing frameworkNetworking
Network protocol fuzzing for humans.Network
x86 binaries to C decompilerReverse Engineering
Creates a TCP tunnel; exposing local ports to a remote server, bypassing standard NAT connection firewallsNetworking
A simple CLI tool for making tunnels to localhost.Network
Crawls bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) hourly and dumps them into another git repoBug bounty
Crawls bug bounty platform scopes.Bug bounty
Hourly-updated data dumps of bug bounty platform scopes that are eligible for reports.Bug bounty
Automated security reporting from markdown templates.Bug bounty
Automated bug bounty reporting/submission, supports HackerOne and BugcrowdBug bounty
Static analysis security vulnerability scanner for Ruby on Rails applications.Development
Find broken links, missing images, etc within your HTML.Vulnerabilities
Broken Link Hijacking Burp Suite extension.Vulnerabilities
HoneypotHoneypot and Decoy
Wordlists handcrafted and automated with <3Resources
A customized command and control center for red team and adversary simulation.Informations gathering
Automatically attempts default creds on found services based on Nmap output.Informations gathering
Automation framework for running multiple open sourced subdomain bruteforcing tools in parallel.Informations gathering
DigiNinja's bucket_finder utility.Cloud & services
Patch-level verification for Bundler.Development
Copy a Burp Suite request to a file or the clipboard as multiple programming languages functions.Network
Vulnerability scanner based on vulners.com search API.Well known products
Web service that allows for detection Blind XSS vulnerabilities within web applications.Development
Add headers to all Burp requests to bypass some WAF products.Network
Cisco password type-7 encryptor and decryptorCryptography
Regexp static code analysisCode Analysis
Command-line WebDAV client.Well known products
A lightweight web security auditing toolkit.Network
Hacks its way into RTSP videosurveillance cameras.Operating systems
The FLARE team's open-source tool to identify capabilities in executable files.Informations gathering
Takes a list of domains, crawls urls and scans for endpoints, secrets, api keys, file extensions, tokensOSINT and Reconnaissance
Crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more.Informations gathering
Generate similar-looking domains for phishing attacks.Informations gathering
Extracting URLs of a specific target based on the results of commoncrawl.org.Cloud & services
Code Credential Scanner; scan a large, diverse codebase for hard-coded credentials, or credentials present in configuration filesSource code management
An asynchronous enumeration & vulnerability scanner.Informations gathering
Network brute force tool, faster than other existing solutions.Network
Scrape domain names from SSL certificates of arbitrary hosts.Cryptanalysis
A certificate transparency log keyword sniffer written in Python.Informations gathering
A tool for testing for certificate validation vulnerabilities of TLS connections.Cryptanalysis
A simple certificate expiration monitor script.Informations gathering
Search the entire internet by data in TLS certificates.Informations gathering
Dump NTDS with golden certificates and UnPAC the hashNetworking
Rapidly search and hunt through windows forensic artefacts.Auth & perms
Self-hosted website change detection tracking, monitoring and notification serviceOther
Page change monitoring with alerts a breezem, the best way to monitor website changes.Auth & perms
A default credential scanner.Informations gathering
The only cheat sheet you need.Resources
Prevent cloud misconfigurations and find vulnerabilities during build-time.Cloud & services
Platform security assessment framework.Auth & perms
Fast TCP tunneling over HTTP secured by SSHNetworking
Locally checks for signs of a rootkit.Operating systems
eBPF-based networking, security, and observability.Virtualization
Vulnerability static analysis for containers.Virtualization
Obtain GraphQL API Schema even if the introspection is not enabled.Databases
Obtain GraphQL API schema even if the introspection is disabled by abusing the "did you mean" featureWeb Application Exploitation
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.Cloud & services
Try to find the origin IP of a webapp protected by Cloudflare.Informations gathering
Cloudlist is a tool for listing Assets from multiple Cloud Providers.Cloud & services
Cloud Security Posture Management (CSPM).Cloud & services
Take a list of resolved subdomains and output any corresponding CNAMES en masse.Informations gathering
A collection of enhancements for Portswigger's popular Burp Suite web penetration testing tool.Well known products
Power security researchers around the world as well as code scanning.Development
OSINT tool for finding Github repositories by extracting commit logs in real time.Informations gathering
Web-based command injection testerWeb Application Exploitation
Overpower wordlist generator, words permutation and combinations, encoding/decoding...Informations gathering
Wordlist generator: create permutations and combinations of words with predefined sets of extensions, words and patterns/function to create complex endpoints, wordlists and passwordsCracking
Read local Chrome cookies without root or decrypting.Development
Read local Chrome cookies without root or decrypting and display then in JSONSystem Exploitation
Hashcat Web Interface.Informations gathering
Multithreaded program to crack PKCS#12 files (p12 and pfx extensions)Cracking
The unix-way web crawler.Informations gathering
Dump windows credentialsSystem Exploitation
Crawl a site and extract useful informations for recon.Informations gathering
Takes a single wordlist item and tests it one by one over a large collection of websites.Informations gathering
Brute forcing tool that support several uncommon protocols.Auth & perms
Offers crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.Informations gathering
Yet another subdomain finder.Informations gathering
Wordlist generatorCracking
Wordlist generator where you can specify a character set or any set of characters to be used.Informations gathering
Tool that try to identify what cipher is used and uncipher the dataCryptography
Analyze Content-Security-Policy header of a given URL.Vulnerabilities
Discover new target domains using Content Security Policy.Informations gathering
CSRF Scanner Extension for Burp Suite Pro.Vulnerabilities
Burp Suite extension that allows request/response modification using a GUI.Cryptanalysis
Library to enhance and speed up script/exploit writing for CTF playersOther
Some setup scripts for security research tools.Auth & perms
Library to run basic functions from stripped binariesReverse Engineering
Interactive CTF exploration tool.Auth & perms
A tool for fetching archived URLs.Cloud & services
Gather and update all available and newest CVEs with their PoC.Auth & perms
Simple latest CVE collector written in Python.Auth & perms
Tool to import CVE and CPE into a MongoDB to facilitate search and processing of CVEsVulnerability Assessment
A tool to perform local searches for known vulnerabilities.Auth & perms
Lists CVEs that are currently being discussed on the social network Mastodon.Auth & perms
CVSS calculator libraryVulnerability Assessment
Service to check if an account has been compromised in a data breach, only tells if the account is compromisedOther
A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities.Resources
A multitool for tracking and locating nearby devices via their RF activities.Network
Self-hosted data breach search engineOSINT and Reconnaissance
OSINT framework, find, aggregate and export dataOSINT and Reconnaissance
.NET deobfuscator and unpackerReverse Engineering
A dead-simple way to recursively look for broken links on a web page.Vulnerabilities
Login hunter of default credentials for administrative web interfaces.Informations gathering
A work-in-progress deobfuscator for movfuscated binaries.Cryptanalysis
Better understand the structure, construction, and security of open source software packages.Development
CLI client for deps.dev API.Development
NodeJS deserialization payload generator.Development
An enterprise friendly way of detecting and preventing secrets in code.Informations gathering
Find CVEs that don't have a Detectify modules.Bug bounty
Tools to work with android .dex and java .class files.Development
differer finds how URLs are parsed by different languages in order to help bug hunters break filters.Informations gathering
The disclose.io security.txt scraper (diosts) takes a list of domains as the input, retrieves and validates the security.txt if available and outputs it in the disclose.io JSON format.OSINT and Reconnaissance
Web directory and file scanner (wordlist bruteforce)Web Application Exploitation
Web directory and file scanner (wordlist bruteforce)Web Application Exploitation
Find web directories without bruteforce.Informations gathering
Finds Directory Listings or open S3 buckets from a list of URLs.Cloud & services
Web directory and file scanner (wordlist bruteforce)Informations gathering
Scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with MetasploitOther
Custom bash scripts used to automate various penetration testing tasks.Informations gathering
A list of disposable and temporary email address domains.Informations gathering
HS256 JWT token distributed brute force crackerWeb Application Exploitation
DevSecOps, ASPM, Vulnerability Management.Bug bounty
Perform permutations, mutations and alteration of subdomains.Informations gathering
.NET assembly debugger, decompiler and editorReverse Engineering
.NET assembly debugger, decompiler and editor; fork of dnSpyReverse Engineering
It comes with crash detection and crash replay. To use it, first create a file called "records" in the same directory as the fuzzer with the dns records for the target in the following format: <record type>,<record question>,<record class>OSINT and Reconnaissance
Subdomain takeover tool for attackers, bug bounty hunters and the blue team!Cloud & services
Fast and multi-purpose DNS toolkit designed for running DNS queries.Informations gathering
Python wordlist-based DNS subdomain scanner.Informations gathering
DNS tunnel meant for encrypted Command & Control channel, data exfiltrationRed Teaming
Create an encrypted command-and-control (C&C) channel over the DNS protocol.Informations gathering
Enumerates DNS information of a domain and to discover non-contiguous ip blocks.Informations gathering
DNS reconnaissance tool: AXFR, DNS records enumeration, subdomain bruteforce, range reverse lookupOSINT and Reconnaissance
Continuation of dnsenum projectOSINT and Reconnaissance
Generates combination of domain names from the provided input.Informations gathering
Domain name permutation engine for detecting several types of attacks.Informations gathering
A tool to monitor for potential spear phishing domains and send to Slack.Informations gathering
A DNS database debugger.Informations gathering
Multi-purpose DNS toolkit allow to run multiple DNS queriesOSINT and Reconnaissance
Uility to embed XXE and XSS payloads in docx, odt, pptx, etcWeb Application Exploitation
Utility to embed XXE and XSS payloads in docx, odt, pptx...Vulnerabilities
Check for dozens of common best-practices around deploying Docker containers in production.Virtualization
Small script to check a list of domains against open redirect vulnerability.Vulnerabilities
Try to find all subdomains, similar-domains and related-domains of an organization.Informations gathering
Multi Tool Subdomain Enumeration.Informations gathering
Find a domain from an IP addressOSINT and Reconnaissance
Tool to bypass 40X response codes.Auth & perms
Quickly do keyword searches over GitLab and GitHub for OSINT & bug bounty recon.Source code management
The Deepfake Offensive Toolkit.Auth & perms
.NET decompiler and assembly browserReverse Engineering
Proxycannon and botnet, using docker, ovpn files, tor nodes, and dante socks5 proxies that may be used for password sprayingOther
A static-code-analysis tool for performing security-focused code reviews.Bug bounty
Detect, track and alert on infrastructure drift.Cloud & services
Measures infrastructure as code coverage, and tracks infrastructure driftDefensive
CMS scanner supporting SilverStripe and Wordpress, having partial support for Joomla, Moodle, DrupalWeb Application Exploitation
A plugin-based scanner that aids security researchers in identifying issues with several CMSs.CMS
The leading security assessment framework for Android.Operating systems
Drupal CMS enumeration and exploitation toolWeb Application Exploitation
Extract files from .DS_Store recursivelyDigital Forensics
Filter and enrich a list of subdomains by level.Informations gathering
Collection of tools for network auditing and penetration testing.Informations gathering
Identify DTDs on filesystem snapshot and build XXE payloads using those local DTDsWeb Application Exploitation
Search exposed EBS volumes for secrets.Cloud & services
May be used to extract various credentials from running processes.Auth & perms
Dump web accessible (distributed) version control systems (DVCS/VCS): SVN, GIT, Mercurial/hg, Bazaar/bzr, …Web Application Exploitation
Rip web accessible version control systems: svn, git...Source code management
A tool that helps users searching and filtering queries in Ldap environment.Auth & perms
Metasearch engine, query 16 search engines in parallelOSINT and Reconnaissance
Cross platform AArch32/x86/x86-64 debuggerReverse Engineering
Check egress filtering and identify if ports are allowed to automatically spawn a shell.Informations gathering
An Intelligent wordlist generator based on user profiling, permutations, and statistics.Cracking
A tool for extracting all the possible endpoints from the JS files.Development
SSH tarpit that slowly sends an endless banner Honeypot and Decoy
Informative site with EoL dates of everything.Auth & perms
Enumerate data from Windows and Samba hosts.Operating systems
Windows Samba enumeration toolSystem Exploitation
Windows Samba enumeration tool, next generation version of enum4linuxSystem Exploitation
A Windows/Samba enumeration tool with additional features like JSON/YAML export.Operating systems
Vulnerability management and reporting platformCollaboration and Report
Enemies Of Symfony - debug mode Symfony looter.Auth & perms
Collects informations related to domains whois, history, dns records and more.Informations gathering
Spoof SSDP replies to phish for credentials and NetNTLM challenge/response.Auth & perms
The ultimate WinRM shell for hacking/pentesting.Auth & perms
Man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authenticationNetworking
Combination of evilginx3 and GoPhish.Informations gathering
Data exfiltration utility for testing detection capabilities.Auth & perms
Shows EXIF information for JPEG files onlySteganography
Image metadata library and tools.Informations gathering
Extract endpoints from source files.Informations gathering
Tool to recover deleted files from an ext3 or ext4 partitionDigital Forensics
An easy way for penetration testers and bug bounty hunters to test (blind) XSS.Vulnerabilities
Pen Test Report Generation and Assessment Collaboration Collaboration and Report
Cloud native runtime security.Virtualization
A DNS bruteforcer with multi-threading, and handling of bad resolvers.Informations gathering
Python script implementing the favicon hash trick to find subdomains.Informations gathering
Use favicon.ico to improve your target recon phase.Informations gathering
Zip password cracker.Informations gathering
Web directory and file scanner (wordlist bruteforce)Web Application Exploitation
Fast web fuzzer written in Go.Informations gathering
Web directory and file scanner (wordlist bruteforce); but also a web fuzzerWeb Application Exploitation
Golang tool which helps dropping the irrelevant entries from your ffuf result file.Informations gathering
Modern tool for Windows kernel exploration and tracing with a focus on security.Operating systems
Scans the top 500 sites daily for their security.txt file or DNS records.Informations gathering
Browser fingerprinting library.Development
Standalone utility for service discovery on open ports!Informations gathering
Fileless linux malware frameworkRed Teaming
A pretty sweet vulnerability scanner.Informations gathering
Know and see everything an attacker can extract and get from your published Flutter app Adversary Simulation
Take a list of domains/subdomains and probe for working http/https server.Informations gathering
Kscan is an asset mapping tool.Informations gathering
File upload vulnerability scanner and exploitation tool.Vulnerabilities
Automates the process of detecting and exploiting file upload forms flawsWeb Application Exploitation
A fuzzing tool written in Go. It helps your pentesting journey.Informations gathering
Find critical backup files by creating a dynamic wordlist based on the domain.Informations gathering
OSINT framework; find mails, dumps, retrieve Telegram history and info about hostsOSINT and Reconnaissance
Identify routers on the local LAN and paths to the Internet.Network
Identify routers on the local LAN and paths to the Internet.Network
Fetch known URLs from several sources.Informations gathering
Fetch known URLs from several sources and Filter Urls With OpenRedirection or SSRF Parameters.Vulnerabilities
A comprehensive scanner for Google Cloud.Cloud & services
A modern experience for GDB with advanced debugging capabilities.Informations gathering
A tool to fastly get all javascript sources/files.Development
Command line utility for searching and downloading exploits.Auth & perms
CLI utility for searching and downloading exploits from Exploit-DB, Metasploit, Packetstorm and othersOther
A wrapper around grep to avoid typing common patterns.Informations gathering
Find multiple types of hardcoded secrets & types of infrastructure-as-code misconfigurations.Informations gathering
Capture all the git secrets by leveraging multiple open source git searching tools.Informations gathering
Dump the contents of a remote git repository without directory listing enabledWeb Application Exploitation
A tool to dump a git repository from a website.Source code management
Dump the contents of a remote git repository without directory listing enabledWeb Application Exploitation
Prevents you from committing secrets and credentials into git repositories.Informations gathering
Find potential software vulnerabilities from git commit messages.Source code management
A tool to hunt for credentials in GitHub wild AKA git*hunt.Informations gathering
Monitor GitHub to search and find sensitive data in real time.Informations gathering
Monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe, etc.OSINT and Reconnaissance
Find endpoints on GitHub.Informations gathering
Basically a regexp over a GitHub search.Informations gathering
Find subdomains on GitHub.Informations gathering
Leak git repositories from misconfigured websites.Source code management
Find subdomains on GitLab.Informations gathering
Protect and discover secrets using Gitleaks.Informations gathering
Extract data from a .git directory.Source code management
Scrapes public GitHub repositories for common naming conventions in variables, folders and files.Informations gathering
Find sensitive information for a git repo.Informations gathering
Find sensitive information (username, password, email) in git repositoriesOSINT and Reconnaissance
Undetectable C2 server that communicates via Google SMTP to evade antivirus protections and network traffic restrictionsRed Teaming
Self-hosted CVE feed serverVulnerability Assessment
The fastest dork scanner written in Go.Cloud & services
Tool to remotely dump secrets from the Windows registry.Informations gathering
Remotely dump secrets from the Windows registry (SAM hive, LSA secrets, SECURITY hive)Networking
A fast & light web screenshot without headless browser but Chrome DevTools protocol.Informations gathering
A complete TUI for LDAP.Auth & perms
Active Directory domain information dumperSystem Exploitation
Active Directory domain information dumperNetworking
Indentify web servers by checking their HTTP responses against a user defined list of fingerprintsWeb Application Exploitation
Get the TOTP secrets exported by Google Authenticator.Auth & perms
Dump the contents of a remote git repository without directory listing enabled; focus on as-complete-as-possible dumps and handling as many edge-cases as possibleWeb Application Exploitation
Capture and replay live HTTP traffic in order to continuously test your system with real data.Network
The vertasile multi-threaded password sprayer built on the shoulders of giants.Informations gathering
Fast web spider written in Go.Cloud & services
Generates DNS wordlists through permutations.Informations gathering
Take screenshots of websitesWeb Application Exploitation
A golang, web screenshot utility using Chrome Headless.Informations gathering
Authenticated SSRF in Grafana.Cloud & services
A flexible tool for redirecting a given program's TCP traffic to SOCKS5 or HTTP proxy.Network
Generate graphs and charts based on password cracking results; supports hashcat and john the ripper potfile as well as ntds fileCracking
The missing GraphQL security security layer.Databases
Graphql introspection query analyzer.Databases
Lists the different ways of reaching a given type in a GraphQL schema.Databases
Lists the different ways of reaching a given type in a GraphQL schemaWeb Application Exploitation
Represent any GraphQL API as an interactive graph.Databases
Runs a dozen of security checks against a given GraphQL endpointWeb Application Exploitation
GraphQL Server Engine Fingerprinting utility for software security professionals.Databases
GraphQL server engine fingerprintingWeb Application Exploitation
Searches code from over a half million public repositories on GitHub.Informations gathering
An incident response framework focused on remote live forensics.Auth & perms
Genesis Scripting Engine; framework to rapidly implement custom droppers for all three major operating systemsRed Teaming
CLI for searching gtfobins and lolbas from the terminalOther
Sub domain wild card filtering tool.Informations gathering
Request the public disclosures on a specific HackerOne program.Bug bounty
HTTP Request Smuggling over HTTP/2 Cleartext.Vulnerabilities
Email OSINT & Password breach hunting tool; supports chasing down related emailOSINT and Reconnaissance
Powerful and user-friendly password hunting tool.Informations gathering
Modular web based pentesting interface designed to run on Raspberry PiCollaboration and Report
Feed it a list of subdomains, it will resolve them and tell you which ones are internal.Informations gathering
Takes a list of IP addresses then does a series of checks to return associated domain names.Informations gathering
Turns any junk text into a usable wordlist for brute-forcing.Resources
Discover the origin host behind a reverse proxy, useful for bypassing cloud WAFs!.Informations gathering
Simple, fast web crawler designed for discovery of endpoints and assets within a web application.Informations gathering
Small, fast tool for performing reverse DNS lookups en masse.Informations gathering
Extract domains/subdomains from URLs en masse.Informations gathering
Golang client for querying SecurityTrails API data.Informations gathering
Discover the netblocks or ranges (in CIDR notation) owned by the target organization.Informations gathering
CLI tool for open source and threat intelligence.Informations gathering
Identify the different types of hashesCryptography
Hash cracking tool using rainbow tablesCracking
Analyze the security headers returned by a web page and report dangerous configurations.Network
Small tool to capture packets from wlan devices.Network
Fuzzer for analyzing how servers respond to different HTTP headersWeb Application Exploitation
Customisable and automated HTTP header injection.Network
Bounded model checking framework for Heap-implementationsBinary Exploitation
An HTTP toolkit for security research.Network
CLI tool for ephemeral penetration testing, rapidly deploy and manage various cloud servicesOther
Windows reverse shell payload generator and handler that abuses the http(s) protocol.Operating systems
Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shellNetworking
Check if the mail is used on different sites like twitter, instagram and will retrieve information on sites with the forgotten password functionOSINT and Reconnaissance
A security oriented software fuzzer.Auth & perms
Identify the different types of hashesCryptography
Network tool able to send custom TCP/IP packets.Informations gathering
A really fast HTTP prober.Informations gathering
Differential testing and fuzzing of HTTP servers and proxiesWeb Application Exploitation
HTTP Request Smuggling Detection Tool.Vulnerabilities
Nmap NSE script that scans for http server, takes a screenshot of them, and organizes the results into an HTML reportPlugins
Automatic tool for DNS rebinding-based SSRF attacks.Cloud & services
Take a list of domains and probe for working HTTP and HTTPS servers.Informations gathering
Grabs screenshots and HTML of large numbers of websites.Informations gathering
Take screenshots of websitesWeb Application Exploitation
HTTP toolkit that allows running multiple probes using the retryablehttp library.Informations gathering
Multi-purpose HTTP toolkit allows to run multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threadsWeb Application Exploitation
Internet search engines for security researchers.Informations gathering
An ICMP reverse shell written in Python3 and scapy.Auth & perms
Discover and fingerprint IKE hosts.Informations gathering
Command line IPSEC VPN brute forcing tool for Linux.Network
Collection of Python classes for working with network protocols.Network
A static analyzer for Java, C, C++, and Objective-C.Development
User-friendly OSINT tool that allows you to quickly and easily gather informations.Informations gathering
Scan QR-code, 1D, DataMatrix, Postal, PDF417, and moreOther
Research tools developed for Intel Wi-Fi chips : decode firmware files, communicate with the chip through Linux's debug filesystemWireless
An OOB interaction gathering server and client libraryVulnerabilities
Bypass IP source restrictions using HTTP headers.Auth & perms
Finds publicly known security vulnerabilities in a website's frontend JavaScript libraries.Development
Is This Domain In Scope; a small tool that allows you to check if a list of domains you have been provided is in the scope of your pentest or notOther
Java application for automatic SQL database injection.Development
Create SSL client fingerprints in an easy to produce and shareable way.Cryptanalysis
Gather gather gather.Informations gathering
DEX to Java decompilerReverse Engineering
Dex to Java decompiler.Operating systems
GUI frontend to John the RipperCracking
Network and Web Pentest Automation Framework.Informations gathering
Beautifier for JavaScript.Development
Fetches JavaScript files quickly and comprehensively from a defined list of URLs or domains.Development
Find secrets, paths or links in the source code.Informations gathering
Extract URLs, paths, secrets, and other interesting bits from JavaScript.Informations gathering
JSON Web Tokens Support for Burp Suite.Development
Improve your web application aecurity testing with rich data from static analysis.Development
Simple JWT token brute force cracker.Auth & perms
JWT encoding/decoding, generates payloads for JWT attack and very fast cracking.Auth & perms
A toolkit for JWT tokens security testingWeb Application Exploitation
Burp Suite extension to check JWT for using keys from known from public sources.Auth & perms
A toolkit for validating, forging and cracking JWT tokensWeb Application Exploitation
JWT brute-force crackerWeb Application Exploitation
Modular command-line tool to parse, create and manipulate JWT tokens.Auth & perms
Script for Kali Linux which use iptables settings to create a transparent proxy through Tor NetworkNetworking
Passive open source intelligence automated reconnaissance.Informations gathering
A next-generation crawling and spidering framework.Informations gathering
Get your favourite Kali Linux tools on Debian/Ubuntu/Linux Mint.Virtualization
Series of tools for attacking MS Kerberos implementations.Auth & perms
Bruteforce and enumerate Active Directory accounts through Kerberos pre-authentication.Auth & perms
Linux kernel CVE exploit analysis report and relative debug environment.Operating systems
Automation of tokens/api keys testing.Development
Convert OpenSSH known_hosts file hashed with HashKnownHosts to hashes crackable by HashcatCracking
S3 bucket finder from html,js and bucket misconfiguration testing tool.Cloud & services
Phishing Campaign Toolkit.Auth & perms
Contextual content discovery tool.Development
Hunts for phishing kit source code by traversing URL folders and searching in open directories for zip files; supports list of URLs or PhishTankOSINT and Reconnaissance
Cloud resources manager designed to analyze and manage cloud cost, usage, security, and more!.Cloud & services
Checks whether Kubernetes is deployed according to security best practices.Virtualization
Adaption of tomnomnom's kxss tool with a different output format.Vulnerabilities
Crack Windows passwords from hashes.Auth & perms
Terminal based phishing campaign toolRed Teaming
Powerful tool for extracting various types of data from a target URL.Informations gathering
Ruby script to bruteforce for AWS s3 buckets using different permutations.Cloud & services
Tool that print shared library dependenciesReverse Engineering
Active Directory LDAP enumeration utilityNetworking
Set of tools to process and visualize huge text files containing credentials.Informations gathering
Set of tools to process and visualize huge text files containing credentialsOSINT and Reconnaissance
Library to simplify format string exploitationBinary Exploitation
Cross-platform sandboxing libraryDefensive
Reverse tunneling made easy for pentesters.Auth & perms
Automates a number of Active Directory enumeration and vulnerability.Operating systems
Script that automates a number of Active Directory enumeration and vulnerability checksNetworking
Command and control framework; HTTPS communication, process injection, in-memory .NET assembly execution, SharpCollection tools, sRDI implementation for shellcode generation, Windows link reloads DLLs from disk into current processRed Teaming
Linux privilege escalation auditing tool.Operating systems
Linux kernel exploit suggesterSystem Exploitation
Linux enumeration tool for pentesting and CTFs with verbosity levels.Auth & perms
A Linux privilege escalation check script.Auth & perms
Linux privilege escalation check scriptSystem Exploitation
Reveals invisible links within JavaScript files.Development
A multi-platform fuzzer for poking at userland binaries and servers.Auth & perms
A fully configurable LinkedIn scraper: scrape anything within LinkedIn.Cloud & services
Malicious shortcut generator for collecting NTLM hashes from insecure file shares.Informations gathering
String-based secret-searching tool, high entropy and regexes.Informations gathering
Password wordlist generator based on target informationCracking
Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load.Vulnerabilities
Python tool to remotely extract credentials on a set of hosts.Auth & perms
CLI tool and library to extract credentials from lsass remotelyNetworking
Locate and attack Lync and Skype for Business.Cloud & services
Security auditing tool for Linux, macOS, and UNIX-based systems.Operating systems
Tool to generate wordlists based on lyricsCracking
Makes the maniputation of MAC addresses of network interfaces easier.Auth & perms
Obfuscation and generation of retro formats such as MS Office documents or VBS like formatRed Teaming
A portable device that can spoof/emulate any magnetic stripe, credit card or hotel card wirelessly.Auth & perms
Generates a bunch of malicious pdf files with phone-home functionality.Informations gathering
Malicious traffic detection system.Auth & perms
Wifi rogue AP attacks and MitM.Network
Command-line framework designed to automate the workflow of asset discovery, reconnaissance, and scanningOSINT and Reconnaissance
Small utility program to perform multiple operations for a given subnet/CIDR ranges.Informations gathering
Tests a list of s3 buckets to see if they have dir listings enabled or if they are uploadable.Cloud & services
MassExploitConsole; mass reconnaissance and exploitation frameworkOther
Fetch many paths for many hosts, without killing the hosts.Informations gathering
Graphical tool for custom wordlist generation.Informations gathering
Cross-platform post-exploitation HTTP/2 Command & Control server and agent.Network
Script that automates the scanning of a target network for HTTP resources through XXE.Vulnerabilities
VM that is built from the ground up with a large amount of security vulnerabilities.Resources
Mifare classic offline cracker.Operating systems
Aggregates results from Shodan, Censys, VirusTotal, SecurityTrail, etc. and extracts artifacts (IP addresses, domains, URLs or hashes)OSINT and Reconnaissance
A little tool to play with Windows security.Auth & perms
Extract plaintext passwords, hash, PIN code and kerberos tickets from memory; perform pass-the-hash, pass-the-ticket or build Golden ticketsSystem Exploitation
A post-exploitation powershell tool for extracting juicy info from memory.Informations gathering
Library and CLI to parse and read Microsoft minidump file formatSystem Exploitation
pwning IPv4 via IPv6.Network
A python program to create a fake AP and sniff data.Network
Interactive HTTPS proxyWeb Application Exploitation
An interactive TLS-capable intercepting HTTP proxy.Cryptanalysis
Generate tens of thousands of subdomain combinations in a matter of seconds.Informations gathering
Aid operators in modifying ADCS certificate templates so that a created vulnerable state can be leveraged for privilege escalationNetworking
Leverage crt.sh website to monitor domains of a target.Informations gathering
MD5-monomorphic shellcode packer, all payloads have the same MD5 hashRed Teaming
Web directory and file scanner (wordlist bruteforce)Web Application Exploitation
Cover your tracks during Linux exploitation by leaving zero traces on the exploited system.Operating systems
Morphing Cobalt Strike's evil.HTA.Well known products
LDAP enumeration tool implemented in Python3.Auth & perms
A quick way to generate various basic Meterpreter payloads via MSFvenom.Well known products
LDAP library for auditing Microsoft Active Directory.Auth & perms
Perform lateral movement in restricted environments through a compromised MSSQL Server.Auth & perms
An open source tool focused on software supply chain security.Informations gathering
Helps with conducting forensics of mobile devices in order to find signs of a potential compromise.Operating systems
Focuses DNS MX records and detects misconfigured MX records.Informations gathering
Security analysis tool for EVM bytecode that supports smart contracts builds.Auth & perms
Port scanner with a focus on reliability and simplicityNetworking
A cross-platform x86 assembler with an Intel-like syntax.Auth & perms
Scan networks searching for NetBIOS information.Network
Improved reimplementation of Netcat by nmap team; Supports TCP and UDP, IPv4 and IPv6, SSL, proxy (HTTP and SOCKS4)Networking
Open source tool for network authentication cracking.Auth & perms
Packet manipulation CLI tool; craft and inject packets of several protocolsNetworking
A framework for secure and scalable network traffic analysis.Network
Network address discovering tool.Auth & perms
Protocol reverse engineering, modeling and fuzzingReverse Engineering
OSINT tool for finding profiles by username.Informations gathering
ngrok collaborator linkNetworking
Very light web security scannerWeb Application Exploitation
Network infrastructure configuration parser.Auth & perms
Converts / manipulates / extracts data from a nmap scan outputNetworking
A simple program to query nmap XML files in the terminal.Informations gathering
Automate the process of enumeration & recon that is run every time.Informations gathering
A static security code scanner for Node.js applications.Development
Distributed hash cracking platform meant to be deployed on AWS (Cognito, DynamoDB, S3) so you pay only when you have a task runningCracking
Retrieve information on linkedin profiles, companies on linkedin and search on linkedin companies/personsOSINT and Reconnaissance
Generate multiple types of NTLMv2 hash theft filesNetworking
A Burp Suite plugin intended to help with Nuclei template generation.Well known products
Collection of Nuclei templates dedicated to WordPress core, plugins and themes vulnerabilities.CMS
A ruby API for NVD CVE feeds management, the library will help you to download and manage NVD Data Feeds, search for CVEs, build your vulerability assesment platform or vulnerability databaseVulnerability Assessment
Retrieve information via O365 and AzureAD with valid credentials.Cloud & services
Runtime mobile exploration toolkit, powered by Frida, built to help you assess the security posture of your mobile applications, without needing a jailbreakOther
Runtime mobile exploration.Operating systems
CLI tool which lets you query a plethora of databases and file formats.Databases
An all-in-one GitHub open-source intelligence framework.Informations gathering
Burp extension to detect alias traversal via NGINX misconfiguration at scale.Well known products
Enumerate valid o365 users.Cloud & services
SNMP scannerNetworking
Contains HackerOne disclosed reports and other bug bounty writeups.Bug bounty
Bypass Kerberoast detections with modified KDC options and encryption types.Auth & perms
Generate emails and usernames.Informations gathering
On The Outside, Reaching In, exploitation toolbox for XXE attacksWeb Application Exploitation
Hydra wrapper for bruteforcing Microsoft Outlook Web ApplicationNetworking
Comprehensive manual for mobile application security testing and reverse engineering.Informations gathering
The industry standard for mobile application security.Operating systems
Embeds XXE/XML exploits into different filetypes.Vulnerabilities
Tool for embedding XXE/XML exploits into different filetypes (docx/xlsx, odt/ods, svg, xml, etc.)Web Application Exploitation
An analysis tool for smart contracts.Auth & perms
Identify the operating system of a target host simply by examining captured packets.Network
PowerShell runspace post exploitation toolkitSystem Exploitation
Execute padding oracle attacks with support for concurrent network requests and an elegant UI.Informations gathering
Automate google hacking database scraping and searching.Cloud & services
Identifies hidden, unlinked parameters, useful for finding web cache poisoning vulnerabilities.Informations gathering
Brute discover GET and POST parameters.Informations gathering
HTTP parameter discovery suiteWeb Application Exploitation
CLI & library to search for default credentials among thousands of products/vendors.Informations gathering
A network sniffer that logs all DNS server replies for use in a passive DNS setup.Informations gathering
PHP Secure Configuration Checker; parse php.ini to find security misconfigurationConfiguration Audit
Converts PE into a shellcodeRed Teaming
Python Exploit Development Assistance for GDB.Auth & perms
A compiled checklist of 300+ tips for protecting digital security and privacy.Auth & perms
Command & Controll framework which silently persists on webserver via polymorphic PHP onelinerRed Teaming
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor.Auth & perms
Get Active Directory security at 80% in 20% of the time.Auth & perms
Collect HTTP or webhook requests and inspect them in a human-friendly way.Network
A tool to make socks connections through HTTP agents.Auth & perms
Interactive disassembler that generates indented pseudo-code with colored syntax.Informations gathering
Prototype pollution scanner using headless chrome.Informations gathering
An extensible multilanguage static code analyzer.Development
Phone number wordlist generatorCracking
Port scanner and banner grabberNetworking
A Chrome Extension to track postMessage usage (url, domain and stack).Vulnerabilities
Search for sensitive data in Postman public library.Informations gathering
Postman OSINT tool to extract creds, token, username, email & more from Postman Public Workspaces.Informations gathering
Security testing and exploitation toolkit.Informations gathering
Scan for client-side prototype pollutionWeb Application Exploitation
A fast tool to scan client-side prototype pollution vulnerability written in Rust.Auth & perms
Client-side prototype pollution scannerWeb Application Exploitation
The most advanced client-side prototype pollution scanner.Auth & perms
Exploitation tool which leverages client-side Prototype Pollution to XSS.Vulnerabilities
Prototype Pollution exploits collection.Vulnerabilities
Swiss Army knife Proxy tool for HTTP(S) traffic capture, manipulation, and replay on the go.Network
RFID tool designed to snoop, listen and emulate everything from Low to High Frequency tags.Auth & perms
Force any TCP connection made by any given application to follow through proxy.Network
Continuation of the unmaintained proxychains project.Network
CLI tool designed to snoop on processes without need for root permissions; it allows to see commands run by other users, cron jobs, etc. as they executeSystem Exploitation
Password list generator for orchestrating brute force attacks.Informations gathering
Persistent multi reverse shell handlerNetworking
Opensource, cross-platform C2 and post-exploitation framework written in python and C.Operating systems
Puredns is a fast domain resolver & subdomain bruteforcing tool.Informations gathering
Deep reinforcement learning instrumenting bettercap for WiFi pwning.Network
Punch holes through firewalls/NATs where both clients and servers can be behind separate NATs.Network
Sophisticated bind and reverse shell handler with many features as well as a drop-in replacement or compatible complement to netcat, ncat or socatNetworking
Netcat on steroids with many extra features.Auth & perms
Fancy reverse and bind shell handler, can perform automated actions on the remote host including enumeration, implant installation and privilege escalation; attempt to spawn a pseudoterminal (pty) for a full interactive sessionNetworking
Self-deployable file hosting service allowing to easily upload and share payloads over HTTP and WebD.Network
CTF framework and exploit development library.Auth & perms
Framework and exploit development libraryBinary Exploitation
Framework and exploit development library, ported onto rubyBinary Exploitation
A multi-target URL bruteforcer.Informations gathering
Partial python implementation of SharpGPOAbuse; modify an existing GPO by creating an immediate scheduled task as SYSTEM on the remote computer for computer GPO or logged in user for user GPONetworking
A powerful and useful hacker dictionary builder for a brute-force attack.Resources
Multi-method password wordlist generatorCracking
Free web-application vulnerability and version scanner.Informations gathering
Protocol demuxed honeypot and wordlists collected from itHoneypot and Decoy
Platform idependent Mimikatz implementationSystem Exploitation
Mimikatz implementation in pure Python.Auth & perms
A (partial) Python rewriting of PowerSploit's PowerView.Auth & perms
A partial Python rewriting of PowerSploit's PowerViewNetworking
Look for several security related Android application vulnerabilities.Operating systems
A generic and open source machine emulator and virtualizer.Virtualization
QEMU Interactive Runtime Analyser.Auth & perms
Quick network scanner library.Informations gathering
qsfuzz is a tool that allows to write simple rules in YAML that define what value to injectAuth & perms
Allows you to quickly substitute query string values with regex matches, one-at-a-time.Informations gathering
Accept URLs on stdin, replace all query string values with a user-supplied value.Auth & perms
UNIX-like reverse engineering framework and command-line toolset.Auth & perms
Crossplatform binary analysis framework, disassembler, decompiler and debugger, support collaborative analysisReverse Engineering
Check whether the domain has a rate limit enabled.Vulnerabilities
A semi-automated largely passive web application security audit tool.Vulnerabilities
Rawsec Inventory search CLI to find security tools and resourcesOther
Ruby BlackBag; a miscellaneous collection of command-line tools and ruby library helpers related to pen-testing and reversingReverse Engineering
Server for testing software against DNS rebinding vulnerabilitiesNetworking
Script to enumerate security settings of an RDP ServiceNetworking
Remote Desktop Protocol in twisted Python.Network
Create a TCP circuit through validly formed HTTP requests.Network
SOCKS proxies through the DMZ for pivotingNetworking
Pwn a bastion webserver and create SOCKS proxies through the DMZ.Network
Automated recon framework for web applications; customizable scan engines & pipeline of reconnaissanceOSINT and Reconnaissance
OpenSource Poc && Vulnerable-Target Storage Box.Auth & perms
Bruteforce WPS toolWireless
Bruteforce WPS toolWireless
Helper tool for black-box regex fuzzing to bypass validations.Auth & perms
Perform automated recon on a target domain by running set of tools to perform scanning and finding out vulnerabilitiesOSINT and Reconnaissance
Runs the best set of tools to perform scanning and finding out vulnerabilities on a target domain.Auth & perms
Automated learning of regexes for DNS discovery.Informations gathering
Rekall Memory Forensic Framework.Auth & perms
Volatile memory extraction utilityDigital Forensics
Fork of rekall with support for Windows 10 memory compressionDigital Forensics
Find related domains of a given domain.Informations gathering
Scan your code for security misconfiguration, search for passwords and secrets.Informations gathering
The most exhaustive list of reliable DNS resolvers.Informations gathering
Hosted Reverse Shell generator with a ton of functionality.Auth & perms
Burp Suite plugin that extracts keywords from response using and test for reflected XSS.Vulnerabilities
Rust-based high performance domain permutation generator.Informations gathering
A micro-framework for writing and running exploitsExploits
A micro-framework for writing and running exploit payloadsExploits
Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open RedirectsWeb Application Exploitation
Library for nmap, allows automating nmap and parsing nmap XML filesNetworking
A tool to abuse Exchange services.Network
Machine-learn password mangling rules; finds efficient password mangling rules (for John the Ripper or Hashcat) for a given dictionary and a list of passwordsCracking
A cross-platform command-line tool for executing jobs in parallel.Auth & perms
Web directory, file and DNS scanner (wordlist bruteforce); but also a web fuzzerWeb Application Exploitation
Find AWS S3 buckets and test their permissions.Cloud & services
This extension will help you to detect GET/POST based XSS vulnerability in any website easily.Vulnerabilities
Performs buckets checks from a given list of subdomains.Cloud & services
Amazon S3 bucket finder and crawler.Cloud & services
The format of various S3 buckets is convert in one format.Cloud & services
A security toolkit for Amazon S3.Cloud & services
JMX Exploitation ToolkitNetworking
Burp Extension for copying requests safely.Network
Retrieves syskey and extract hashes from Windows 2k/NT/XP/Vista SAM, often used with bkhive, part of the ophcrack projectSystem Exploitation
Metasploit-like CLI interface for Nmap Script Engine (NSE)Networking
The x86 processor fuzzer.Auth & perms
x86 processor fuzzerReverse Engineering
Burp Suite extension which helps to improve the active and passive scanner by yourself.Well known products
Online port scan scraper.Informations gathering
multi-threaded post-exploitation scanning tool for scavenging systems, finding most frequently used files and folders as well as interesting files containing sensitive informationSystem Exploitation
The perfect butler for pentesters, bug-bounty hunters and security researchers.Network
Monitors Github for leaked secrets.Informations gathering
Continuous security scans based on kubernetes; orchestrate and automate a bunch of security-testing toolsWeb Application Exploitation
Free and open platform for threat hunting, enterprise security monitoring, and log management.Bug bounty
Searching for Sentry config on page or in Javascript files and check blind SSRF.Vulnerabilities
Identifies server-side prototype pollution vulnerabilities.Vulnerabilities
A post exploitation framework designed to operate covertly on heavily monitored environments.Auth & perms
Shellbag parser (Windows Registry Keys)Digital Forensics
Secrets detection for your GitHub, GitLab and Bitbucket repositories.Source code management
Small tool to grab subdomains using Shodan API.Cloud & services
Grab subdomains using Shodan apiOSINT and Reconnaissance
Enumerate valid subdomains using active bruteforce and DNS resolution.Informations gathering
Wrapper around massdns that allows you to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard handling and easy input-output supportOSINT and Reconnaissance
Distributed systems and infrastructure simulator for attacking and debugging Kubernetes, creates a Kubernetes cluster in AWS and runs scenarios which misconfigure it or leave it vulnerable to compromise to train in mitigating against these vulnerabilitiesIntentionally Vulnerable Applications
Swagger Jacker; audit API endpoints defined in exposed (Swagger/OpenAPI) definition filesWeb Application Exploitation
Active web application security reconnaissance tool.Informations gathering
Static analyzer for Solidity.Auth & perms
Adversary emulation framework.Auth & perms
A drop-in replacement for Nmap powered by shodan.io.Auth & perms
Samba scanning tool.Well known products
No-nonsense tool that takes credentials and a list of hosts and crawls through those shares.Auth & perms
A handy SMB enumeration tool.Informations gathering
Tool to scan for secret files on HTTP servers.Informations gathering
Web scanner that looks for files accessible on web servers that shouldn't be publicWeb Application Exploitation
Multithreaded script for bulk walking targeted host systems for SNMP dataNetworking
IIS shortname scanner written in Go.Well known products
Crawls the website and finds broken social media links that can be hijackedInformations gathering
Continuous inspection.Informations gathering
Simple and flexible tool for managing secrets.Cryptanalysis
Extract JavaScript source trees from source map files.Informations gathering
A tool to hunt for publicly accessible DigitalOcean Spaces.Cloud & services
Node.js anti-spam, email filtering, and phishing prevention tool and service.Informations gathering
OSINT framework, collect and manage data, scan targetOSINT and Reconnaissance
Web spidering library that can spider a site, multiple domains, certain links or infinitelyWeb Application Exploitation
Fetch, install and search exploit archives from exploit sites like Packet Storm or Exploit-DBOther
Simple script that checks a domain for email protection.Informations gathering
Credentials gathering tool automating remote procdump and parse of lsass process.Auth & perms
SQLI labs to test error based, blind boolean based, time based.Resources
Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.Well known products
Automatic SQL injection and database takeoverWeb Application Exploitation
Automatic SQL injection and database takeover tool.Vulnerabilities
A friend of SQLmap which will do what you always expected from SQLmap.Vulnerabilities
SSH server auditing: banner, key exchange, encryption, compatibility, security...Cryptanalysis
SSH scanner that detects protocol, version, grab banner, recognize software and operating system, output algorithm information and recommendationsNetworking
The best way to scan for weak ssh passwords on your network.Informations gathering
Script to steal passwords from ssh.Informations gathering
It's the C version of sshLooter.Informations gathering
Brute force SSH public-key authentication interactivelyNetworking
CLI reference-implementation client for Qualys SSL Labs APIs, designed for automated and/or bulk testingWeb Application Exploitation
Tests SSL/TLS enabled services to discover supported cipher suites.Cryptanalysis
Tests SSL/TLS enabled services to discover supported cipher suitesWeb Application Exploitation
A tool for exploiting Moxie Marlinspike's SSL "stripping" attack.Cryptanalysis
Steganography program that hides secrets in the least significant bits of a file.Cryptanalysis
Debugger for LinuxReverse Engineering
Esoteric sub-domain enumeration techniques - Bugcrowd LevelUpBug bounty
A fast tool to check subdomain takeover vulnerability.Informations gathering
Hijacking forgotten & misconfigured subdomains.Informations gathering
Discovers valid subdomains for websites, designed as a passive framework to be useful for bug bounties and safe for penetration testingOSINT and Reconnaissance
Fetches javascript file from a list of URLS or subdomains.Informations gathering
A fast passive subdomain enumeration tool that uses various sources to gather data.Informations gathering
Extension of sublister tool to check for subdomain takeovers.Informations gathering
DNS response-guided subdomain fuzzerOSINT and Reconnaissance
A smart DNS response-guided subdomain fuzzer.Informations gathering
Subdomain takeover vulnerability checker.Informations gathering
A pure-python fully automated and unattended fuzzing framework.Network
Simple script to extract all web resources by means of .SVN folder exposed over network.Informations gathering
Extract and list API routes from Swagger files in YAML/JSON format.Informations gathering
Automated brute-forcing attack tool.Network
A tool for testing subdomain takeover possibilities at a mass scale.Informations gathering
Validate the outgoing changeset for things that look suspicious such as tokens, passwords and keys.Informations gathering
Enables you to safely and predictably create, change, and improve infrastructure.Auth & perms
TLS/SSL scanner to find weak ciphers, protocols or flawsWeb Application Exploitation
Testing TLS/SSL encryption anywhere on any port.Cryptanalysis
Security scanner for your Terraform code.Informations gathering
E-mails, subdomains and names Harvester.Informations gathering
Multi-purpose information gathering tool: emails, names, subdomains, IPs, URLsOSINT and Reconnaissance
Repository of live malwares for malware analysisReverse Engineering
Open-source threat intelligence feeds; sharing malware URLs, IP reputation, bad IPs, etc.Threat Intelligence
Collaborative forensic timeline analysis.Auth & perms
Twitter intelligence analysis toolOSINT and Reconnaissance
The most complete open-source tool for Twitter intelligence analysis.Cloud & services
A tool that can help detect and takeover subdomains with dead DNS records.Informations gathering
Fast and configurable TLS grabber focused on TLS based data collection.Informations gathering
Open-source penetration testing tool that automates the process of exploiting XSS.Vulnerabilities
XSS exploitation command-line interface and payload generatorWeb Application Exploitation
Server-Side Template Injection and Code Injection Detection and Exploitation Tool.Vulnerabilities
SSTI and code injection detection and exploitation toolWeb Application Exploitation
Like nmap for mapping wifi networks you're not connected to, plus device tracking.Network
Tool for mapping and tacking wifi networks and devices through raw 802.11 monitoringWireless
Automatic Linux privilege escalation via exploitation of low-hanging fruit.Auth & perms
Analysis and research tool, which allows people to track and execute intelligent social engineering attacks in real timeOSINT and Reconnaissance
People tracker on the Internet: OSINT analysis and research tool.Informations gathering
Command line tool for URL parsing and manipulation.Informations gathering
Network security scanner with an extensible plugin system.Auth & perms
Time Travel Debugging IDA pluginPlugins
Handle all network traffic of any internet programs sent by the device through a proxy.Network
Twitter scraping & OSINT tool allowing you to scrape a user's followers, following, tweets and more.Cloud & services
Denial of Service Toolkit.Network
Translate sigma rules into various SIEM, EDR, and XDR formatsIncident Response
Python 2.7 binaries (.pyc) decompilerReverse Engineering
Python 1.5, 2.1 to 2.7, 3.1 to 3.6 binaries (.pyc) decompilerReverse Engineering
A cross-version Python bytecode decompiler.Auth & perms
Quickly discover exposed hosts on the internet using multiple search engines.Informations gathering
Discover exposed hosts on the internet using multiple search enginesOSINT and Reconnaissance
Optimized Selenium Chromedriver patch which does not trigger anti-bot services.Auth & perms
An Entropy-Based Link Vulnerability Tool.Informations gathering
Tool for using a PowerShell downgrade attack and inject shellcode into memorySystem Exploitation
Simple tool for using a PowerShell downgrade attack and inject shellcode into memory.Development
Toolkit for security research manipulating Unicode: confusables, homoglyphs, hexdump, code point, UTF-8, UTF-16, UTF-32, properties, regexp search, size, grapheme, surrogates, version, ICU, CLDR, UCDOther
Shell script to check for simple privilege escalation vectors on Unix systems.Auth & perms
File upload restrictions bypass by using different techniques!Vulnerabilities
De-clutter a list of URLs.Informations gathering
A golang utility to spider through a website searching for additional links.Informations gathering
Allows searching on URLs that are exposed via shortener services.Informations gathering
Declutters url lists for crawling/pentesting.Informations gathering
Tool and framework for securely reading untrusted USB mass storage devicesDefensive
User-Agent, X-Forwarded-For and Referer SQLI Fuzzer.Network
CTF toolkit / frameworkOther
Web directory and file scanner (wordlist bruteforce); but also a web fuzzerWeb Application Exploitation
Cross-platform very advanced and fast web fuzzer written in nim.Auth & perms
Hide any type of files inside a image of your choice using steganography.Cryptanalysis
Detect, manage and exploit Blind Cross-site scripting (XSS) vulnerabilities.Vulnerabilities
A black box vBulletin vulnerability scanner.Auth & perms
Vulnerability Compliance Report; parse Nessus CIS benchmark scan files and generate HTML reportsCollaboration and Report
Plugin-based tool to scan public version control systems for sensitive information.Source code management
Searching for virtual hosts among non-resolvable domains.Informations gathering
The volatile memory extraction framework.Auth & perms
Volatile memory extraction utilityDigital Forensics
Fork of volatility with support for Windows 10 memory compressionDigital Forensics
Volatility3 plugins that can retrieve partial and full gpg passphrases from gpg-agent's cachePlugins
Vulnerability Dashboard; vulnerability database, project management and report generationCollaboration and Report
Pre-built vulnerable environments based on docker-compose.Resources
Create a vulnerable active directory to test most of the active directory attacks in a local lab.Auth & perms
Vulnerability scanner based on vulners.com search APIPlugins
VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import Nmap/Nessus/Burp/OpenVAS/Bugcrowd/Trivy, Jira export, TXT/JSON/MARKDOWN/HTML/DOCX, attachments, automatic changelog, stats, vulnerability management, bugbounty, local ai/llm, super fast pentest reporting! Collaboration and Report
Web application attack and audit framework, web-oriented security scannerWeb Application Exploitation
Web Application Attack and Audit Framework.Auth & perms
A WPA3 dictionary cracker.Network
Check your WAF before an attacker does.Network
Identify and fingerprint Web Application Firewall products protecting a website.Network
Web-oriented vulnerability scanner, can generates reportsWeb Application Exploitation
Gather urls from wayback machine and test each GET parameter for SQL injection.Cloud & services
Fetch all the URLs that the Wayback Machine knows about for a domain.Cloud & services
Find links from Wayback Machine, Common Crawl, Alien Vault OTX and URLScan; download the archived responses for URLs on Wayback MachineOSINT and Reconnaissance
The open source security platform.Bug bounty
Database of wordlists for hash cracking and compilation of best wordlists.Informations gathering
A web hacking toolkit.Virtualization
Automate converting webshells into reverse shells.Vulnerabilities
Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanningWeb Application Exploitation
Uncovers technologies used on websites to automate mass scanning.Auth & perms
A lightweight incoming webhook server to run shell commands.Auth & perms
Easily test HTTP webhooks with this handy tool that displays requests instantly.Network
A very simple webhook server launching shell scripts.Auth & perms
A tool that traverses a website and generates a tree of all the webpages and their links.Informations gathering
A simple script to screenshot a list of websites.Informations gathering
Keep an eye on your targets to get quickly notified for any change they push on their server.Informations gathering
Weaponized web shell.Development
Semantic search tool for C and C++ designed to help security researchers identify interesting functionality in large codebasesCode Analysis
Generate rich wordlists for targeted attacks online.Resources
A malicious DNS server for executing DNS Rebinding attacks on the fly.Informations gathering
Local Area Network discovery tool with a modern Terminal User Interface (TUI) written in Go. Discover, explore, and understand your LAN in an intuitive way. Whosthere performs unprivileged, concurrent scans using mDNS and SSDP scanners. Additionally, it sweeps the local subnet by attempting TCP/UDP connections to trigger ARP resolution, then reads the ARP cache to identify devices on your Local Area Network. This technique populates the ARP cache without requiring elevated privileges. All discovered devices are enhanced with OUI lookups to display manufacturers when available. Whosthere provides a friendly, intuitive way to answer the question every network administrator asks: "Who's there on my network?"Network
Android application to brute force WiFi passwords without requiring a rooted device.Network
Script to jam wifi clients and access pointsWireless
Continuously jam all wifi clients/routers.Network
The rogue access point framework.Network
Powerful framework for rogue access point attack.Network
Runs existing wireless-auditing tools for you. Stop memorizing command arguments & switches!Informations gathering
Script for auditing wireless networks that runs existing wireless-auditing toolsWireless
Nikto for Windows with some extra features.Informations gathering
Nikto for Windows; web security scannerWeb Application Exploitation
Crawls URL to get a better image of what is tied to a website.Informations gathering
Enumerate users, groups and computers from a Windows domain through LDAP queries.Auth & perms
Script to enumerate users, groups and computers from a Windows domain through LDAP queriesNetworking
A list of Windows kernel exploits.Operating systems
Standalone executable to check for simple privilege escalation vectors.Auth & perms
Automate building wordlists for AppSec directory/resource bruting.Resources
Perform different ways of command execution via WMI protocol (port 135) for AV evasionNetworking
The new generation of wmiexec.py with all operations performed on port 135 for antivirus evasion.Auth & perms
Modify version of impacket wmiexec.py, get output from registry.Auth & perms
Library for reading, combining, manipulating, and building wordlists, efficientlyCracking
Fetch, install and search wordlist archives from websites and torrent peers.Resources
Fetch, install and search wordlist archives from websites and torrent peersCracking
Generate context-specific wordlists for content discovery from lists of URLs or pathsCracking
Quickly generate context-specific wordlists for content discovery from lists of URLs or paths.Informations gathering
Static code analysis for WordPress Plugins and Themes (and PHP)Code Analysis
wpfinger is a red-team WordPress scanning tool.CMS
Generates a php://filter chain that adds a prefix and a suffix to the contents of a fileWeb Application Exploitation
Interactive websocket REPL designed specifically for penetration testingWeb Application Exploitation
Tunneling over websocket protocol - Static binary available.Network
Passive hostname, domain and IP lookup tool for non-robots.Informations gathering
Windows debuggerReverse Engineering
An open-source user mode debugger for Windows for reverse engineering and malware analysis.Informations gathering
HTTP parameter discovery suiteWeb Application Exploitation
Discover endpoints and potential parameters for a given targetWeb Application Exploitation
A python tool used to discover endpoints and potential parameters for a given target.Informations gathering
Security assessment tool that supports common web security issue scanning and custom PoC.Auth & perms
PNG IDAT chunks XSS payload generator.Vulnerabilities
A Burp Intruder extender designed for automation and validation of XSS vulnerabilities.Vulnerabilities
Fast, thorough, XSS/SQLi spider.Vulnerabilities
Hack with JavaScript.Vulnerabilities
A cli utility to find domain's known URLs from curated passive online sources.Informations gathering
HTTP and FTP server for OOB XXE attacksWeb Application Exploitation
A mini webserver with FTP support for XXE payloads.Network
XPath injection tool, designed for blind injectionWeb Application Exploitation
XPath injection tool, fork of xxxpwn adding further optimizations and tweaks, uses predictive text based on a dictionary of words/phrases vs frequencies of occurrenceWeb Application Exploitation
Small script for carving, scanning, compressing, decompressing and analyzing SWF filesReverse Engineering
Find secret information (secrets, tokens, passwords) in git repositoriesOSINT and Reconnaissance
Creates statistics on a yara rule set and files in a sample directoryIncident Response
YARA rules generatorIncident Response
Framework for layer 2 attacksNetworking
A framework for layer 2 attacks.Network
Generates payloads that exploit unsafe Java object deserialization.Development
Tool for generating payloads that exploit unsafe Java object deserializationSystem Exploitation
Deserialization payload generator for a variety of .NET formatters.Development
Network attack tool.Network
Fast CLI DNS lookup tool.Informations gathering
Fast Go application scanner.Network
Fast single packet network scanner designed for Internet-wide network surveys.Informations gathering
Detect stegano-hidden data in PNG & BMP.Cryptanalysis
Tool to detect hidden data in PNG and BMPSteganography
🛈 CONTRIBUTE: Add software