Offsec.tools – A vast collection of security tools

0d1n on offsec.tools

0d1n

Tool for automating customized attacks against web applications.

2tearsinabucket on offsec.tools

4-ZERO-3 on offsec.tools

ActiveScan++ on offsec.tools

ActiveScan++

Extends Burp Suite’s active and passive scanning capabilities.

Acunetix on offsec.tools

Acunetix

Quickly find and fix the vulnerabilities that put your web applications at risk of attack.

ADAPE Script on offsec.tools

ADAPE Script

Active Directory assessment and privilege escalation script.

ADenum on offsec.tools

ADenum

Find misconfiguration through LDAP to exploit weaknesses with Kerberos.

ADReaper on offsec.tools

ADReaper

Enumerate an Active Directory environment with LDAP queries.

ADRT on offsec.tools

ADRT

Active Directory Report Tool.

airbash on offsec.tools

airbash

Fully automated WPA PSK PMKID and handshake capture script.

aircrack-ng on offsec.tools

aircrack-ng

Complete suite of tools to assess WiFi network security.

AllAboutBugBounty on offsec.tools

Altdns on offsec.tools

Altdns

Generates permutations, alterations and mutations of subdomains and then resolves them.

Amass on offsec.tools

Amass

In-depth Attack Surface Mapping and Asset Discovery.

andor on offsec.tools

andor

Blind SQL Injection Tool with Golang.

Angry IP Scanner on offsec.tools

Angry IP Scanner

Fast and simple-to-use open-source/cross-platform network scanner.

APKEnum on offsec.tools

APKEnum

Passive enumeration utility For Android applications.

apkurlgrep on offsec.tools

Aquatone on offsec.tools

Arachni on offsec.tools

Arachni

Web Application Security Scanner Framework.

archaeologit on offsec.tools

archaeologit

Scans the history of GitHub repositories to find sensitive things.

Arjun on offsec.tools

Arjun

HTTP parameter discovery suite.

As3nt on offsec.tools

As3nt

Another Subdomain ENumeration Tool.

ASNLookup on offsec.tools

ASNLookup

Leverage ASN to look up IP addresses owned by a specific organization.

ASNmap on offsec.tools

ASNmap

Quickly maps organization network ranges using ASN information.

assetfinder on offsec.tools

assetfinder

Find domains and subdomains related to a given domain.

Async DNS Brute on offsec.tools

ATOR on offsec.tools

ATOR

Authentication Token Obtain and Replace Extender.

AttackSurfaceMapper on offsec.tools

AttackSurfaceMapper

AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.

Auth Analyzer on offsec.tools

Auth Analyzer

The Burp extension helps you to find authorization bugs.

AuthMatrix on offsec.tools

AuthMatrix

Provides a simple way to test authorization in web applications and web services.

authz on offsec.tools

authz

Burp Suite plugin to test for authorization flaws.

AutoRecon on offsec.tools

AutoRecon

Multi-threaded network reconnaissance tool which performs automated enumeration of services.

AutoRepeater on offsec.tools

AutoRepeater

Automated HTTP Request Repeating With Burp Suite.

Autorize on offsec.tools

Autorize

Automatic authorization enforcement detection extension for Burp Suite.

AutoSploit on offsec.tools

autoSubTakeover on offsec.tools

autoSubTakeover

A tool used to check if a CNAME resolves to the scope address.

Autowasp on offsec.tools

Autowasp

A one-stop pentesting checklist and logger tool.

Awesome Bug Bounty on offsec.tools

Awesome Bug Bounty

A comprehensive curated list of available Bug Bounty & disclosure programs and writeups.

Awesome BugBounty Writeups on offsec.tools

AWS Extender CLI on offsec.tools

AWS Extender CLI

Command-line script to test cloud storage for common misconfiguration issues.

AWS security checks on offsec.tools

AWS security checks

This Burp Suite provides additional Scanner checks for AWS security issues.

AWSBucketDump on offsec.tools

AWSBucketDump

Security Tool to Look For Interesting Files in S3 Buckets.

B-XSSRF on offsec.tools

B-XSSRF

Toolkit to detect and keep track on Blind XSS, XXE & SSRF.

backslash-powered-scanner on offsec.tools

barq on offsec.tools

barq

The AWS Cloud Post Exploitation framework!

BeEF on offsec.tools

BeEF

The Browser Exploitation Framework is a penetration testing tool that focuses on the web browser.

BeRoot on offsec.tools

BeRoot

Multiplaform privilege escalation project.

bettercap on offsec.tools

bettercap

The Swiss Army knife for WiFi, BLE, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Betterscan on offsec.tools

Betterscan

Code Scanning/SAST/static analysis/linting using many tools/scanners with one report.

BFAC on offsec.tools

BFAC

Check for backup artifacts that may disclose the web-application’s source code.

BitBlinder on offsec.tools

BitBlinder

Injects custom XSS payloads on every form/request submitted to detect blind XSS.

BlackWidow on offsec.tools

BlackWidow

Web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

bounty-targets-data on offsec.tools

bounty-targets-data

Hourly-updated data dumps of bug bounty platform scopes that are eligible for reports.

bountyplz on offsec.tools

bountyplz

Automated security reporting from markdown templates.

brutesubs on offsec.tools

brutesubs

Automation framework for running multiple open sourced subdomain bruteforcing tools in parallel.

BruteX on offsec.tools

BruteX

Automatically brute force all services running on a target.

BruteXSS on offsec.tools

BruteXSS

Tool written in Python simply to find XSS vulnerabilities in web application.

Bug Bounty Guide on offsec.tools

Bug Bounty Reference on offsec.tools

BugBountyHunter on offsec.tools

Bugcrowd VRT on offsec.tools

Bugcrowd VRT

Bugcrowd’s baseline priority ratings for common security vulnerabilities.

Burp Extender API on offsec.tools

Burp NTLM Challenge Decoder on offsec.tools

Burp Suite on offsec.tools

Burp Suite

The class-leading vulnerability scanning, penetration testing, and web app security platform.

Burp WP on offsec.tools

Burp WP

Find known vulnerabilities in WordPress plugins and themes, WPScan like plugin for Burp.

Burp-AnonymousCloud on offsec.tools

Burp-AnonymousCloud

Performs passive scan to identify buckets and test them for publicly accessible vulnerabilities.

burp-exporter on offsec.tools

burp-exporter

Copy a Burp Suite request to a file or the clipboard as multiple programming languages functions.

Burp-to-SQLMap on offsec.tools

Burp-to-SQLMap

Performing SQLInjection test on Burp Suite Bulk Requests using SQLMap.

burp-vulners-scanner on offsec.tools

BurpBeautifier on offsec.tools

BurpBeautifier

Burpsuite extension for beautifying request/response body.

BurpBounty on offsec.tools

BurpBounty

Improve the active and passive Burp Suite scanner by means of custom rules through GUI.

BurpJSLinkFinder on offsec.tools

BurpJSLinkFinder

Burp Extension for a passive scanning JS files for endpoint links.

BurpSentinel on offsec.tools

BurpSentinel

GUI Burp Plugin to ease discovering of security holes in web applications.

BurpSmartBuster on offsec.tools

BurpSmartBuster

A Burp Suite content discovery plugin that add the smart into the Buster.

BurpSuiteHTTPSmuggler on offsec.tools

BurpSuiteHTTPSmuggler

A Burp Suite extension to bypass WAFs or test their effectiveness using a number of techniques.

bXSS on offsec.tools

bXSS

bXSS is a utility which can be used identify Blind Cross-Site Scripting.

bypasswaf on offsec.tools

bypasswaf

Add headers to all Burp requests to bypass some WAF products.

Can I take over XYZ? on offsec.tools

cariddi on offsec.tools

cariddi

Crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more.

cc.py on offsec.tools

cc.py

Extracting URLs of a specific target based on the results of commoncrawl.org.

Censys Enumeration on offsec.tools

Censys Enumeration

Extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.

Censys subdomain finder on offsec.tools

cero on offsec.tools

cero

Scrape domain names from SSL certificates of arbitrary hosts.

CertCrunchy on offsec.tools

CertCrunchy

Uses data from SSL Certificates to find potential host names.

Certificate Ripper on offsec.tools

Certificate Search on offsec.tools

CeWL on offsec.tools

CeWL

Custom Word List Generator.

changeme on offsec.tools

Chaos Client on offsec.tools

ChopChop on offsec.tools

ChopChop

Scan endpoints and identify exposition of sensitive services/files/folders.

clairvoyance on offsec.tools

clairvoyance

Obtain GraphQL API Schema even if the introspection is not enabled.

cloud_enum on offsec.tools

cloud_enum

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

CloudBrute on offsec.tools

CloudFail on offsec.tools

CloudFail

Utilize misconfigured DNS and old database records to find hidden IPs behind CloudFlare network.

cloudflare-origin-ip on offsec.tools

Cloudfox on offsec.tools

Cloudfox

Automating situational awareness for cloud penetration tests.

cloudlist on offsec.tools

cloudlist

Cloudlist is a tool for listing Assets from multiple Cloud Providers.

CloudScraper on offsec.tools

CloudScraper

Tool to enumerate targets in search of cloud resources.

CMSmap on offsec.tools

CMSmap

CMS scanner that automates the process of detecting security flaws of the most popular CMSs.

cnames on offsec.tools

cnames

Take a list of resolved subdomains and output any corresponding CNAMES en masse.

Coercer on offsec.tools

Coercer

Automatically coerce a Windows server to authenticate on an arbitrary machine.

Collaborator Everywhere on offsec.tools

commit-stream on offsec.tools

commit-stream

OSINT tool for finding Github repositories by extracting commit logs in real time.

Commix on offsec.tools

Commix

Automated All-in-One OS Command Injection Exploitation Tool.

cook on offsec.tools

cook

Overpower wordlist generator, words permutation and combinations, encoding/decoding…

CORS Scanner on offsec.tools

CORS Scanner

A multi-threaded scanner that helps identify CORS flaws/misconfigurations.

CorsMe on offsec.tools

CorsMe

CORS misconfiguration scanner tool with speed and precision in mind!

CORStest on offsec.tools

CORStest

A simple CORS misconfiguration scanner.

Corsy on offsec.tools

Corsy

CORS Misconfiguration Scanner.

Covenant on offsec.tools

Covenant

Collaborative C2 framework for red teamers.

Cr3dOv3r on offsec.tools

Cr3dOv3r

Know the dangers of credential reuse attacks.

Crawlergo on offsec.tools

Crawlergo

A powerful browser crawler for web vulnerability scanners

crawley on offsec.tools

crithit on offsec.tools

crithit

Takes a single wordlist item and tests it one by one over a large collection of websites.

CRLF-Injection-Scanner on offsec.tools

CRLFMap on offsec.tools

CRLFMap

CRLFMap is a tool to find HTTP Splitting vulnerabilities.

CRLFsuite on offsec.tools

CRLFsuite

The most powerful CRLF injection scanner.

CRLFuzz on offsec.tools

CRLFuzz

A fast tool to scan CRLF vulnerability written in Go.

Cross-site scripting cheat sheet on offsec.tools

crtndtry on offsec.tools

crunch on offsec.tools

crunch

Wordlist generator where you can specify a character set or any set of characters to be used.

csp-analyzer on offsec.tools

csprecon on offsec.tools

csprecon

Discover new target domains using Content Security Policy.

cstc on offsec.tools

cstc

Burp Suite extension that allows request/response modification using a GUI.

ctf-tools on offsec.tools

ctf-tools

Some setup scripts for security research tools.

CTFR on offsec.tools

CTFR

Abusing Certificate Transparency logs for getting HTTPS websites subdomains.

curate on offsec.tools

curate

A tool for fetching archived URLs.

DalFox on offsec.tools

DalFox

Powerful open source XSS scanning tool and parameter analyzer, utility.

Dangerous Methods on offsec.tools

Dangerous Methods

A Burp Suite extension for finding the use of potentially dangerous methods/functions.

Dastardly Scan Action on offsec.tools

Dastardly Scan Action

Runs a scan using Dastardly by Burp Suite against a target site and generates a report.

DataExtractor on offsec.tools

DataExtractor

A Burp Suite extension to extract data from source code while browsing.

Default Credentials Cheat Sheet on offsec.tools

default-http-login-hunter on offsec.tools

DefaultPassword on offsec.tools

Demiguise on offsec.tools

DependencyCheck on offsec.tools

DependencyCheck

Utility that detects publicly disclosed vulnerabilities in application dependencies.

Depix on offsec.tools

Depix

Recovers passwords from pixelized screenshots.

detectify-cves on offsec.tools

differer on offsec.tools

differer

differer finds how URLs are parsed by different languages in order to help bug hunters break filters.

Dirb on offsec.tools

dirhunt on offsec.tools

dirhunt

Find web directories without bruteforce.

dirlstr on offsec.tools

dirlstr

Finds Directory Listings or open S3 buckets from a list of URLs.

dirsearch on offsec.tools

DirSearch on offsec.tools

Dirstalk on offsec.tools

Dirstalk

Multi threaded application designed to brute force paths on web servers.

Distribute Damage on offsec.tools

dnscan on offsec.tools

dnscan

Python wordlist-based DNS subdomain scanner.

dnsenum on offsec.tools

dnsenum

Enumerates DNS information of a domain and to discover non-contiguous ip blocks.

dnsgen on offsec.tools

dnsgen

Generates combination of domain names from the provided input.

DNSProbe on offsec.tools

DNSProbe

Allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.

dnsReaper on offsec.tools

dnsReaper

Subdomain takeover tool for attackers, bug bounty hunters and the blue team!

DNSRecon on offsec.tools

DNSTake on offsec.tools

DNSTake

A fast tool to check missing hosted DNS zones that can lead to subdomain takeover.

dnsX on offsec.tools

dnsX

Fast and multi-purpose DNS toolkit designed for running DNS queries.

docem on offsec.tools

docem

Utility to embed XXE and XSS payloads in docx, odt, pptx…

DOM based XSS finder on offsec.tools

DOM XSS Scanner on offsec.tools

DOM XSS Scanner

A tool to scan source code for DOM based XSS vulnerabilities.

dom-red on offsec.tools

dom-red

Small script to check a list of domains against open redirect vulnerability.

Domain Analyzer on offsec.tools

Domain Analyzer

Analyze the security of any domain by finding all the information possible. Made in python.

Domain Hunter on offsec.tools

Domain Hunter

Try to find all subdomains, similar-domains and related-domains of an organization.

domained on offsec.tools

domained

Multi Tool Subdomain Enumeration.

DOMDig on offsec.tools

DOMDig

DOM XSS scanner for Single Page Applications.

DotDotPwn on offsec.tools

DotGit on offsec.tools

DotGit

An extension for checking if .git is exposed in visited websites.

DroneSploit on offsec.tools

Drupwn on offsec.tools

Drupwn

Drupal enumeration & exploitation tool.

dsieve on offsec.tools

dsieve

Filter and enrich a list of subdomains by level.

DTD Finder on offsec.tools

DTD Finder

List DTDs and generate XXE payloads using those local DTDs.

dufflebag on offsec.tools

dufflebag

Search exposed EBS volumes for secrets.

DumpsterDiver on offsec.tools

dvcs-ripper on offsec.tools

dvcs-ripper

Rip web accessible version control systems: svn, git…

Eagle on offsec.tools

Eagle

Vulnerability scanner for mass detection of web-based applications vulnerabilities.

EDD on offsec.tools

EDD

Ultimate domain enumeration tool.

eLdap-Ldap-Search-and-Filter on offsec.tools

EMBA on offsec.tools

EMBA

The security analyzer for firmware of embedded devices.

eos on offsec.tools

eos

Enemies Of Symfony – debug mode Symfony looter.

espionage on offsec.tools

espionage

Collects informations related to domains whois, history, dns records and more.

Evil SQL Client on offsec.tools

Evil SQL Client

Interactive .NET SQL console client with enhanced SQL Server discovery/access/exfiltration features.

evil SSDP on offsec.tools

evil SSDP

Spoof SSDP replies to phish for credentials and NetNTLM challenge/response.

exfilkit on offsec.tools

exfilkit

Data exfiltration utility for testing detection capabilities.

ExifTool on offsec.tools

ExifTool

ExifTool meta information reader/writer.

Exploitalert on offsec.tools

Extended SSRF search on offsec.tools

Extended SSRF search

Smart SSRF scanner using different methods like parameter brute forcing in POST and GET.

Extended XSS Searcher and Finder on offsec.tools

extract-endpoints on offsec.tools

Eyeballer on offsec.tools

Eyeballer

Convolutional neural network for analyzing pentest screenshots.

EyeWitness on offsec.tools

EyeWitness

Take screenshots of websites, provide server header info and identify default credentials.

ezXSS on offsec.tools

ezXSS

An easy way for penetration testers and bug bounty hunters to test (blind) XSS.

Faraday security on offsec.tools

Faraday security

Open source sulnerability management and orchestration platform.

favicon-hashtrick on offsec.tools

favicon-hashtrick

Python script implementing the favicon hash trick to find subdomains.

fcrackzip on offsec.tools

FDsploit on offsec.tools

FDsploit

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

Femida on offsec.tools

Femida

Automated blind-xss search for Burp Suite.

Feroxbuster on offsec.tools

Feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

FestIN on offsec.tools

FestIN

The powered S3 bucket finder and content discover.

ffuf on offsec.tools

ffuf

Fast web fuzzer written in Go.

Fierce on offsec.tools

Fierce

A DNS reconnaissance tool for locating non-contiguous IP space.

Filebuster on offsec.tools

Filebuster

An extremely fast and flexible web fuzzer.

FinDOM-XSS on offsec.tools

FinDOM-XSS

A fast DOM based XSS vulnerability scanner with simplicity.

Findomain on offsec.tools

Findomain

The complete solution for domain recognition.

findsecuritycontacts.com on offsec.tools

Findsploit on offsec.tools

Findsploit

Find exploits in local and online databases instantly.

Fingerprinter on offsec.tools

fingerprintx on offsec.tools

fingerprintx

Standalone utility for service discovery on open ports!

Firebase-Extractor on offsec.tools

FireShodanMap on offsec.tools

FireShodanMap

Realtime map that integrates Firebase, Google Maps and Shodan.

flan on offsec.tools

flan

A pretty sweet vulnerability scanner.

Flow on offsec.tools

Flow

Provides view with filtering capabilities for all requests from all Burp Suite tools.

Fluxion on offsec.tools

Fluxion

Fluxion is the future of MITM WPA attacks.

FOCA on offsec.tools

FOCA

Tool to find metadata and hidden information in the documents.

Freddy Deserialization Bug Finder on offsec.tools

FridaAndroidTracer on offsec.tools

fuzzagotchi on offsec.tools

fuzzagotchi

A fuzzing tool written in Go. It helps your pentesting journey.

Fuzzapi on offsec.tools

Fuzzapi

Used for REST API pentesting and provide UI solution for gem.

FuzzDB on offsec.tools

FuzzDB

Attack patterns and primitives for black-box application fault injection and resource discovery.

fuzzuli on offsec.tools

fuzzuli

Find critical backup files by creating a dynamic wordlist based on the domain.

GadgetProbe on offsec.tools

GadgetProbe

Probe endpoints consuming Java serialized objects for fingerprinting.

GAP on offsec.tools

GAP

A Burp Suite extension to find potential endpoints and parameters.

gau on offsec.tools

gau

Fetch known URLs from several sources.

gaussrf on offsec.tools

gaussrf

Fetch known URLs from several sources and Filter Urls With OpenRedirection or SSRF Parameters.

GET-ACQ on offsec.tools

GET-ACQ

Gather all companies acquired by a given company domain name.

getJS on offsec.tools

getJS

A tool to fastly get all javascript sources/files.

getsploit on offsec.tools

getsploit

Command line utility for searching and downloading exploits.

gf on offsec.tools

gf

A wrapper around grep to avoid typing common patterns.

Ghauri on offsec.tools

Ghauri

Automates the process of detecting and exploiting SQL injection security flaws.

GHunt on offsec.tools

GHunt

Offensive Google framework.

git-all-secrets on offsec.tools

git-all-secrets

Capture all the git secrets by leveraging multiple open source git searching tools.

git-dumper on offsec.tools

git-dumper

A tool to dump a git repository from a website.

git-vuln-finder on offsec.tools

git-vuln-finder

Find potential software vulnerabilities from git commit messages.

git-wild-hunt on offsec.tools

git-wild-hunt

A tool to hunt for credentials in GitHub wild AKA git*hunt.

GitFive on offsec.tools

GitFive

An OSINT tool to investigate GitHub profiles.

GitGot on offsec.tools

GitGot

Rapidly search through troves of public data on GitHub for sensitive secrets.

gitGraber on offsec.tools

gitGraber

Monitor GitHub to search and find sensitive data in real time.

github-subdomains on offsec.tools

GitHunter on offsec.tools

GitHunter

A tool for searching a Git repository for interesting content.

gitjacker on offsec.tools

gitjacker

Leak git repositories from misconfigured websites.

gitlab-subdomains on offsec.tools

GitMiner on offsec.tools

GitMiner

Tool for advanced mining for content on Github.

gitpillage on offsec.tools

Gitrob on offsec.tools

Gitrob

Reconnaissance tool for GitHub organizations.

gitscraper on offsec.tools

gitscraper

Scrapes public GitHub repositories for common naming conventions in variables, folders and files.

GitTools on offsec.tools

GitTools

A repository with 3 tools for pwn’ing websites with .git repositories available.

GoAltdns on offsec.tools

GoAltdns

A permutation generation tool written in golang.

Gobuster on offsec.tools

Gobuster

Directory/File, DNS and VHost busting tool written in Go.

GoCloud on offsec.tools

GoCloud

Checks whether a domain is hosted on a cloud service.

GoLinkFinder on offsec.tools

Gopherus on offsec.tools

Gopherus

Generates gopher link for exploiting SSRF and gaining RCE in various servers.

gospider on offsec.tools

gotator on offsec.tools

gotator

Generates DNS wordlists through permutations.

gowitness on offsec.tools

gowitness

A golang, web screenshot utility using Chrome Headless.

grafana-ssrf on offsec.tools

GraphQL Beautifier on offsec.tools

GraphQL Threat Matrix on offsec.tools

graphql-introspection-analyzer on offsec.tools

graphql-path-enum on offsec.tools

graphql-path-enum

Lists the different ways of reaching a given type in a GraphQL schema.

GraphQLmap on offsec.tools

GraphQLmap

Scripting engine to interact with a graphql endpoint for pentesting purposes.

graphw00f on offsec.tools

graphw00f

GraphQL Server Engine Fingerprinting utility for software security professionals.

GrayhatWarfare on offsec.tools

GRecon on offsec.tools

GRecon

Run a Google based passive recon against your scope.

grep.app on offsec.tools

grep.app

Searches code from over a half million public repositories on GitHub.

Ground control on offsec.tools

Ground control

A collection of scripts mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.

GSAN on offsec.tools

GSAN

Extract subdomains from SSL certificates in HTTPS sites.

gwdomains on offsec.tools

gwdomains

Sub domain wild card filtering tool.

GyoiThon on offsec.tools

GyoiThon

Growing penetration test tool using Machine Learning.

H1 Report Finder on offsec.tools

H1 Report Finder

A burpsuite extension to find security reports published on HackerOne based on the selected host.

h1-search on offsec.tools

h1-search

Request the public disclosures on a specific HackerOne program.

h2cSmuggler on offsec.tools

h2cSmuggler

HTTP Request Smuggling over HTTP/2 Cleartext.

Hackability on offsec.tools

Hackability

Probe a rendering engine for vulnerabilities and other features.

Hacker101 on offsec.tools

Hackingtool on offsec.tools

Hackvertor on offsec.tools

Hackvertor

Tag based conversion tool written in Java implemented as a Burp Suite extension.

Hakrawler on offsec.tools

Hakrawler

Simple, fast web crawler designed for discovery of endpoints and assets within a web application.

hakrevdns on offsec.tools

hakrevdns

Small, fast tool for performing reverse DNS lookups en masse.

haktldextract on offsec.tools

Hamburglar on offsec.tools

Hamburglar

Collect useful information from urls, directories, and files.

Hash Buster on offsec.tools

Hashcat on offsec.tools

Hashcat

World’s fastest and most advanced password recovery utility

Have i been pwned? on offsec.tools

Hawkeye on offsec.tools

Hawkeye

Filesystem analysis tool/directory looking for interesting stuff.

headi on offsec.tools

headi

Customisable and automated HTTP header injection.

Headless Burp on offsec.tools

Headless Burp

Provides a suite of extensions and a maven plugin to automate security tests using Burp Suite.

HostileSubBruteforcer on offsec.tools

House on offsec.tools

House

A runtime mobile application analysis toolkit with a Web GUI.

HTTP Request Smuggler on offsec.tools

HTTP Request Smuggler

Extension for Burp Suite designed to help you launch HTTP Request Smuggling attacks.

http-request-smuggling on offsec.tools

HTTPoxy Scanner on offsec.tools

HTTPoxy Scanner

A Burp Suite extension that checks for the HTTPoxy vulnerability.

httprebind on offsec.tools

httprebind

Automatic tool for DNS rebinding-based SSRF attacks.

httprobe on offsec.tools

httprobe

Take a list of domains and probe for working HTTP and HTTPS servers.

httpscreenshot on offsec.tools

httpscreenshot

Grabs screenshots and HTML of large numbers of websites.

httpx on offsec.tools

httpx

HTTP toolkit that allows running multiple probes using the retryablehttp library.

Hydra on offsec.tools

Hydra

Very fast password cracking tool.

IDontSpeakSSL on offsec.tools

IDontSpeakSSL

Simple tool to scan large scope and provide SSL/TLS vulnerabilities.

Injectify on offsec.tools

Injectify

Perform advanced MiTM attacks on websites with ease.

Injectus on offsec.tools

InQL on offsec.tools

InQL

Burp Extension for GraphQL Security Testing.

interactsh on offsec.tools

interactsh

An OOB interaction gathering server and client library

Interlace on offsec.tools

Interlace

Turn single threaded command line applications into a fast, multi-threaded application.

IntruderPayloads on offsec.tools

IntruderPayloads

Payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

IPRotate on offsec.tools

IPRotate

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

J2EEScan on offsec.tools

J2EEScan

Improve the test coverage during web application penetration tests on J2EE applications.

Jaeles on offsec.tools

Jaeles

The Swiss Army knife for automated Web Application Testing

Java Deserialization Scanner on offsec.tools

John The Ripper on offsec.tools

JoomScan on offsec.tools

JoomScan

OWASP Joomla Vulnerability Scanner Project.

JOSEPH on offsec.tools

JOSEPH

JavaScript Object Signing and Encryption Pentesting Helper.

JS-Scan on offsec.tools

JS-Scan

A .js scanner, built in PHP, designed to scrape urls and other info.

JSgen on offsec.tools

JSgen

Generate javascript code to be injected in case you find a Server Side Javascript Injection.

JSONBeautifier on offsec.tools

JSONBee on offsec.tools

JSONBee

A ready to use JSONP endpoints/payloads to help bypass Content Security Policy.

JSParser on offsec.tools

JSParser

Python script to parse relative URLs from JavaScript files.

jSQL Injection on offsec.tools

JSShell on offsec.tools

JSShell

An interactive multi-user web JS shell.

JWT cracker on offsec.tools

JWT Key ID Injector on offsec.tools

JWT Tool on offsec.tools

JWT Tool

A toolkit for testing, tweaking and cracking JSON Web Tokens.

jwt-hack on offsec.tools

jwt-hack

JWT encoding/decoding, generates payloads for JWT attack and very fast cracking.

jwt-heartbreaker on offsec.tools

jwt-heartbreaker

Burp Suite extension to check JWT for using keys from known from public sources.

JWT4B on offsec.tools

JWT4B

JWT Support for Burp Suite.

jwtear on offsec.tools

jwtear

Modular command-line tool to parse, create and manipulate JWT tokens.

JWTweak on offsec.tools

JWTweak

Detects JWT algorithm and provides options to generate a new JWT based on another algorithm.

Kadimus on offsec.tools

Kadimus

Check for and exploit LFI vulnerabilities with a focus on PHP systems.

katana on offsec.tools

katana

A next-generation crawling and spidering framework.

Keyfinder on offsec.tools

Keyfinder

Find and analyze private/public key files and Android APK files.

kicks3 on offsec.tools

kicks3

S3 bucket finder from html,js and bucket misconfiguration testing tool.

Knockpy on offsec.tools

Knoxnl on offsec.tools

Knoxnl

This is a python wrapper around the amazing KNOXSS.

KNOXSS on offsec.tools

KNOXSS

Online XSS tool with demonstration of vulnerability.

kxss on offsec.tools

kxss

Adaption of tomnomnom’s kxss tool with a different output format.

LazyHunter on offsec.tools

LazyHunter

A framework that provides a web UI to commonly used Bug Hunting/Pentesting tools.

lazys3 on offsec.tools

lazys3

Ruby script to bruteforce for AWS s3 buckets using different permutations.

leakScraper on offsec.tools

leakScraper

Set of tools to process and visualize huge text files containing credentials.

LFI Suite on offsec.tools

LFI Suite

Totally Automatic LFI Exploiter and Scanner.

LFI-Enum on offsec.tools

LFI-Enum

Scripts to execute enumeration via LFI

Liffy on offsec.tools

Liffy

Local file inclusion exploitation tool.

LinEnum on offsec.tools

LinEnum

Scripted Local Linux Enumeration & Privilege Escalation Checks.

LinkFinder on offsec.tools

LinkFinder

A python script that finds endpoints in JavaScript files.

linWinPwn on offsec.tools

linWinPwn

Automates a number of Active Directory enumeration and vulnerability.

linx on offsec.tools

linx

Reveals invisible links within JavaScript files.

LiveOverflow on offsec.tools

lk_scraper on offsec.tools

lk_scraper

A fully configurable LinkedIn scraper: scrape anything within LinkedIn.

lnkbomb on offsec.tools

lnkbomb

Malicious shortcut generator for collecting NTLM hashes from insecure file shares.

localdataHog on offsec.tools

localdataHog

String-based secret-searching tool, high entropy and regexes.

Logger++ on offsec.tools

Logger++

Log activities of all the tools in Burp Suite.

lorsrf on offsec.tools

lorsrf

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load.

MagicRecon on offsec.tools

MagicRecon

A powerful shell script to maximize the recon and data collection process.

Maigret on offsec.tools

Maigret

????️‍♂️ Collect a dossier on a person by username from thousands of sites.

Malicious PDF Generator on offsec.tools

Maltego on offsec.tools

Maltego

Open source intelligence and forensics application.

mapcidr on offsec.tools

mapcidr

Small utility program to perform multiple operations for a given subnet/CIDR ranges.

Maryam on offsec.tools

Maryam

Open-source Intelligence Framework.

mass-s3-bucket-tester on offsec.tools

mass-s3-bucket-tester

Tests a list of s3 buckets to see if they have dir listings enabled or if they are uploadable.

Mass3 on offsec.tools

Mass3

Enumerate through a pre-compiled list of AWS S3 buckets using DNS instead of HTTP.

Masscan on offsec.tools

Masscan

TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.

MassDNS on offsec.tools

MassDNS

A high-performance DNS stub resolver for bulk lookups and reconnaissance.

meg on offsec.tools

meg

Fetch many paths for many hosts, without killing the hosts.

Metagoofil on offsec.tools

Metagoofil

Search Google and download specific file types.

metahttp on offsec.tools

metahttp

Script that automates the scanning of a target network for HTTP resources through XXE.

Metasploit on offsec.tools

Metasploit

The world’s most used penetration testing framework.

mitmproxy on offsec.tools

mitmproxy

An interactive TLS-capable intercepting HTTP proxy.

mksub on offsec.tools

mksub

Generate tens of thousands of subdomain combinations in a matter of seconds.

MSDNSScan on offsec.tools

MSDNSScan

Identify DNS records, check for zone transfers and conduct subdomain enumeration.

MSDorkDump on offsec.tools

msldap on offsec.tools

msldap

LDAP library for auditing Microsoft Active Directory.

MSSQLi-DUET on offsec.tools

MSSQLi-DUET

SQL injection script for Microsoft SQL Server.

mx-takeover on offsec.tools

mx-takeover

Focuses DNS MX records and detects misconfigured MX records.

Naabu on offsec.tools

Naabu

A fast port scanner written in go with a focus on reliability and simplicity.

NahamSec on offsec.tools

Namechk on offsec.tools

Namechk

Check usernames on more than 100 websites, forums and social networks.

Nessus database export on offsec.tools

Nessus database export

Export Nessus results to a relational database for use in reports, analysis, or whatever else.

Nginxpwner on offsec.tools

Nginxpwner

Simple tool to look for common Nginx misconfigurations and vulnerabilities.

Nikto on offsec.tools

Nikto

Nikto web server scanner.

Nmap on offsec.tools

Nmap

Nmap – the Network Mapper.

nmap-query-xml on offsec.tools

nmap-query-xml

A simple program to query nmap XML files in the terminal.

NoSQL Injector on offsec.tools

NoSQL Injector

NoSql Injection CLI tool for finding vulnerable websites using MongoDB.

NoSQLMap on offsec.tools

NoSQLMap

Automated NoSQL database enumeration and web application exploitation tool.

Nozaki on offsec.tools

Nozaki

HTTP fuzzer engine security oriented.

NSBrute on offsec.tools

NSBrute

Python utility to takeover domains vulnerable to AWS NS Takeover.

NSDetect on offsec.tools

NSDetect

Utility to detect AWS NS Takeover.

Nuclei on offsec.tools

Nuclei

Fast and customizable vulnerability scanner based on simple YAML based DSL.

Nuclei templates on offsec.tools

Nuclei templates

Community curated list of templates for the Nuclei engine to find security vulnerabilities.

OAUTHScan on offsec.tools

OAUTHScan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security.

off-by-slash on offsec.tools

off-by-slash

Burp extension to detect alias traversal via NGINX misconfiguration at scale.

Oh365UserFinder on offsec.tools

OneForAll on offsec.tools

OneForAll

A powerful subdomain integration tool.

open-sesame on offsec.tools

open-sesame

Contains HackerOne disclosed reports and other bug bounty writeups.

OpenAPI on offsec.tools

OpenAPI

Parse OpenAPI specifications into the BurpSuite for automating RESTful API testing.

OpenRedireX on offsec.tools

OpenVAS on offsec.tools

OpenVAS

This repository contains the scanner component for Greenbone Community Edition.

Oralyzer on offsec.tools

Osmedeus on offsec.tools

Osmedeus

A Workflow Engine for Offensive Security

OWASP on offsec.tools

OWASP

A nonprofit foundation that works to improve the security of software.

oxml_xxe on offsec.tools

oxml_xxe

Embeds XXE/XML exploits into different filetypes.

Pacu on offsec.tools

Pacu

The exploitation framework designed for testing the security of AWS environments.

padding-oracle-attacker on offsec.tools

padding-oracle-attacker

Execute padding oracle attacks with support for concurrent network requests and an elegant UI.

param-miner on offsec.tools

param-miner

Identifies hidden, unlinked parameters, useful for finding web cache poisoning vulnerabilities.

parameth on offsec.tools

parameth

Brute discover GET and POST parameters.

ParamPamPam on offsec.tools

ParamPamPam

This tool for brute discover GET and POST parameters.

ParamSpider on offsec.tools

ParamSpider

Mining parameters from dark corners of Web Archives.

Patator on offsec.tools

Patator

Multi-purpose brute-forcer, with a modular design and a flexible usage.

Payloads All The Things on offsec.tools

PCredz on offsec.tools

PCredz

This tool extracts secrets from a pcap file or from a live interface.

PEAS-ng on offsec.tools

PEAS-ng

Privilege Escalation Awesome Scripts SUITE.

PentesterLab on offsec.tools

PentesterLand on offsec.tools

PentesterLand

Sharing knowledge that makes your life as bug hunters and pentesters easier.

Photon on offsec.tools

Photon

Incredibly fast crawler designed for OSINT.

PHPGGC on offsec.tools

PHPGGC

PHP unserialize() payloads along with a tool to generate them.

pivotnacci on offsec.tools

pivotnacci

A tool to make socks connections through HTTP agents.

PortBender on offsec.tools

PortBender

A TCP port redirection utility that allows inbound traffic redirection.

PortSwigger Cross-Site Scripting cheatsheet data. on offsec.tools

PostMessage_Fuzz_Tool on offsec.tools

postMessage-tracker on offsec.tools

pown.js on offsec.tools

pown.js

Security testing and exploitation toolkit.

Print-My-Shell on offsec.tools

Print-My-Shell

Automate the process of generating various reverse shells.

Prowler on offsec.tools

Prowler

Open Source Security tool to perform Cloud Security best practices

proxify on offsec.tools

proxify

Swiss Army knife Proxy tool for HTTP(S) traffic capture, manipulation, and replay on the go.

psudohash on offsec.tools

psudohash

Password list generator for orchestrating brute force attacks.

puredns on offsec.tools

puredns

Puredns is a fast domain resolver & subdomain bruteforcing tool.

pwncat on offsec.tools

pwncat

Netcat on steroids with many extra features.

pyBuster on offsec.tools

pyBuster

A multi-target URL bruteforcer.

pyfiscan on offsec.tools

pyfiscan

Free web-application vulnerability and version scanner.

qsfuzz on offsec.tools

qsfuzz

qsfuzz is a tool that allows to write simple rules in YAML that define what value to inject

qsinject on offsec.tools

qsinject

Allows you to quickly substitute query string values with regex matches, one-at-a-time.

qsreplace on offsec.tools

qsreplace

Accept URLs on stdin, replace all query string values with a user-supplied value.

Raccoon on offsec.tools

Raccoon

A high performance offensive security tool for reconnaissance and vulnerability scanning.

Race The Web on offsec.tools

RacePWN on offsec.tools

RainbowCrack on offsec.tools

rate-limit-checker on offsec.tools

Reaver on offsec.tools

Reaver

Implements a brute force attack against Wifi Protected Setup (WPS) registrar PINs.

recollapse on offsec.tools

recollapse

REcollapse is a helper tool for black-box regex fuzzing to bypass validations

Recon-ng on offsec.tools

Recon-ng

OSINT tool aimed at reducing the time spent harvesting information from open sources.

reconFTW on offsec.tools

reconFTW

Runs the best set of tools to perform scanning and finding out vulnerabilities on a target domain.

ReconNess on offsec.tools

ReconNess

Continuous recon and pipeline tools setup.

RecurseBuster on offsec.tools

RecurseBuster

Rapid content discovery tool for recursively querying webservers.

regulator on offsec.tools

regulator

Automated learning of regexes for DNS discovery.

Rekono on offsec.tools

Rekono

Execute full pentesting processes combining multiple hacking tools automatically.

related-domains on offsec.tools

Rengine on offsec.tools

Rengine

Automated reconnaissance framework for webapps, highly configurable streamlined recon process.

Replicator on offsec.tools

Replicator

Burp Suite extension to help developers replicate findings from pentests.

Request Highlighter on offsec.tools

Request Highlighter

Burp Suite extension that automatically highlights different HTTP requests.

Requests-Racer on offsec.tools

Retire.js on offsec.tools

Retire.js

Detects the use of JavaScript libraries with known vulnerabilities.

RevShells on offsec.tools

RevShells

Hosted Reverse Shell generator with a ton of functionality.

rexsser on offsec.tools

rexsser

Burp Suite plugin that extracts keywords from response using and test for reflected XSS.

RouterSploit on offsec.tools

RsaCtfTool on offsec.tools

RsaCtfTool

RSA multi-attacks tool: uncypher data from a weak public key and try to recover a private key.

Rubeus on offsec.tools

Rubeus

Rubeus is a toolkit for Kerberos interaction and abuses.

Runtime Mobile Security on offsec.tools

rush on offsec.tools

rush

A cross-platform command-line tool for executing jobs in parallel.

RustScan on offsec.tools

RustScan

The Modern Port Scanner. Fast, smart, effective.

Rusty Hog on offsec.tools

Rusty Hog

A suite of secret scanners built in Rust for performance.

S3 Objects Check on offsec.tools

S3 Objects Check

Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.

s3-buckets-finder on offsec.tools

S3BucketList on offsec.tools

S3BucketList

Firefox plugin that lists Amazon S3 Buckets found in requests.

s3cario on offsec.tools

s3cario

Performs buckets checks from a given list of subdomains.

S3Cruze on offsec.tools

S3Cruze

All-in-one AWS S3 bucket tool.

s3reverse on offsec.tools

s3reverse

The format of various S3 buckets is convert in one format.

S3Scanner on offsec.tools

S3Scanner

Scan for open S3 buckets and dump the contents.

s3tk on offsec.tools

s3tk

A security toolkit for Amazon S3.

S3Viewer on offsec.tools

safecopy on offsec.tools

safecopy

Burp Extension for copying requests safely.

Sandcastle on offsec.tools

Sandcastle

A Python script for AWS S3 bucket enumeration.

scan-check-builder on offsec.tools

scan-check-builder

Burp Suite extension which helps to improve the active and passive scanner by yourself.

ScanCannon on offsec.tools

ScanCannon

Combines the speed of masscan with the reliability and detailed enumeration of nmap.

Scilla on offsec.tools

Scilla

Information Gathering tool – DNS / Subdomains / Ports / Directories enumeration.

Scout on offsec.tools

Scout

Discover a web server’s undisclosed files, directories and VHOSTs.

ScrapeIn on offsec.tools

ScrapeIn

Harvest employee email addresses from a specific company through LinkedIn.

ScreenShooter on offsec.tools

ScreenShooter

Convert your masscan/subdomain-scan results into screenshots for better analysis.

Screenshoteer on offsec.tools

Screenshoteer

Makes web screenshots and mobile emulations from the command line.

Scrying on offsec.tools

Scrying

Collects RDP, web and VNC screenshots all in one place.

SearchSploit on offsec.tools

SearchSploit

Cli tool for Exploit-DB that also allows you to take a copy of Exploit Database with you.

SecLists on offsec.tools

SecLists

Collection of multiple types of lists used during security assessments, collected in one place.

Second Order on offsec.tools

secret-bridge on offsec.tools

SecretMagpie on offsec.tools

SecurityTrails on offsec.tools

See-SURF on offsec.tools

See-SURF

Detect Vulnerable SSRF parameters.

sentrySSRF on offsec.tools

sentrySSRF

Searching for Sentry config on page or in Javascript files and check blind SSRF.

Shadow Workers on offsec.tools

Shadow Workers

C2 and proxy designed to help in the exploitation of XSS and malicious Service Workers.

ShapeShifter on offsec.tools

SharpHose on offsec.tools

SharpHose

Asynchronous password spraying tool for Windows environments.

Shelling on offsec.tools

Shelling

A comprehensive OS command injection payload generator.

Shells on offsec.tools

Shells

A script for generating common revshells fast and easily.

Sherlock on offsec.tools

Sherlock

Hunt down social media accounts by username across social networks.

shhgit on offsec.tools

shhgit

Secrets detection for your GitHub, GitLab and Bitbucket repositories.

Shotlooter on offsec.tools

Shotlooter

Find sensitive data inside the screenshots uploaded to prnt.sc.

shuffleDNS on offsec.tools

shuffleDNS

Enumerate valid subdomains using active bruteforce and DNS resolution.

Simple Basic Malware Scanner on offsec.tools

SiteBroker on offsec.tools

SiteBroker

Utility for information gathering and penetration testing automation.

skipfish on offsec.tools

skipfish

Web application security scanner.

Slack Watchman on offsec.tools

Slack Watchman

Monitoring your Slack workspaces for sensitive informations.

Sleepy Puppy on offsec.tools

SleuthQL on offsec.tools

SleuthQL

Burp History parsing tool to discover potential SQL injection points.

Slurp on offsec.tools

Slurp

A blazing fast & feature rich Amazon S3 bucket enumerator.

smap on offsec.tools

smap

A drop-in replacement for Nmap powered by shodan.io.

SMBploit on offsec.tools

SMBploit

Offensive tool to scan & exploit vulnerabilities in Windows over SMB using Metasploit.

Smogcloud on offsec.tools

Smogcloud

Find cloud assets that no one wants exposed.

Smuggler on offsec.tools

Smuggler

An HTTP Request Smuggling / Desync testing tool.

Sn1per on offsec.tools

Sn1per

Attack Surface Management Platform.

Sniff-Paste on offsec.tools

sns on offsec.tools

sns

IIS shortname scanner written in Go.

SonarSearch on offsec.tools

Sourcegraph on offsec.tools

Sourcegraph

Search millions of open source repositories.

spaces-finder on offsec.tools

spaces-finder

A tool to hunt for publicly accessible DigitalOcean Spaces.

SpiderFoot on offsec.tools

SpiderFoot

Automates OSINT for threat intelligence and mapping your attack surface.

Spoofy on offsec.tools

Spoofy

Checks if a list of domains can be spoofed based on SPF and DMARC records.

SprayCannon on offsec.tools

SprayCannon

Fast multithreaded password spraying tool with backend database.

SQLi-Hunter on offsec.tools

SQLi-Hunter

Simple HTTP(S) proxy server and a SQLMAP API wrapper that makes digging SQLi easy.

sqlipy on offsec.tools

sqlipy

Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

SQLiScanner on offsec.tools

SQLiScanner

Automatic SQL injection with Charles and sqlmap API.

SQLiv on offsec.tools

SQLiv

Massive SQL injection vulnerability scanner.

sqlmap on offsec.tools

sqlmap

Automatic SQL injection and database takeover tool.

SqlmapDnsCollaborator on offsec.tools

SQLninja on offsec.tools

SQLninja

Exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server.

SQLRecon on offsec.tools

SQLRecon

A C# MS-SQL toolkit designed for offensive reconnaissance and post-exploitation.

SQLTruncSanner on offsec.tools

SQLTruncSanner

Messy BurpSuite plugin for SQL Truncation vulnerabilities.

SSH PuTTY login bruteforcer on offsec.tools

ssh-audit on offsec.tools

ssh-audit

SSH server auditing: banner, key exchange, encryption, compatibility, security…

sslscan on offsec.tools

sslscan

Tests SSL/TLS enabled services to discover supported cipher suites.

SSLyze on offsec.tools

SSLyze

Fast and powerful SSL/TLS scanning library.

SSRF Detector on offsec.tools

SSRF Sheriff on offsec.tools

SSRFire on offsec.tools

SSRFire

An automated SSRF finder. Just give the domain name and your server and chill!

SSRFmap on offsec.tools

SSRFmap

Automatic SSRF fuzzer and exploitation tool.

SSRFTest on offsec.tools

StaCoAn on offsec.tools

StaCoAn

Crossplatform tool which help to perform static code analysis on mobile applications.

steghide on offsec.tools

steghide

Steganography program that hides secrets in the least significant bits of a file.

Stepper on offsec.tools

Stepper

A natural evolution of Burp Suite’s Repeater tool.

STÖK Fredrik on offsec.tools

sub-domain enumeration techniques on offsec.tools

Sub3 Suite on offsec.tools

Sub3 Suite

A free, open source, cross platform Intelligence gathering tool.

SubBrute on offsec.tools

SubBrute

A DNS meta-query spider that enumerates DNS records, and subdomains.

SubDomainizer on offsec.tools

SubDomainizer

A tool to find subdomains and interesting things hidden inside.

Subfinder on offsec.tools

Subfinder

Discovery tool that discovers valid subdomains for websites.

subHijack on offsec.tools

subHijack

Hijacking forgotten & misconfigured subdomains.

Subjack on offsec.tools

Subjack

Subdomain Takeover tool written in Go.

Sublert on offsec.tools

Sublert

Monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.

Sublist3r on offsec.tools

Sublist3r

Fast subdomains enumeration tool for penetration testers.

SubOver on offsec.tools

SubOver

A Powerful Subdomain Takeover Tool.

Substr3am on offsec.tools

Substr3am

Passive reconnaissance/enumeration of interesting targets by watching for SSL certificates.

subzuf on offsec.tools

subzuf

A smart DNS response-guided subdomain fuzzer.

Sudomy on offsec.tools

Sudomy

Collects subdomains and analyzes domains performing automated reconnaissance.

SweetPotato on offsec.tools

SweetPotato

A collection of various Windows privilege escalation techniques from service accounts to SYSTEM.

takeover on offsec.tools

takeover

A tool for testing subdomain takeover possibilities at a mass scale.

Teh S3 Bucketeers on offsec.tools

Th3inspector on offsec.tools

The Exploit Database on offsec.tools

The Social-Engineer Toolkit on offsec.tools

The XSS rat on offsec.tools

TheftFuzzer on offsec.tools

TheftFuzzer

Fuzz Cross-Origin Resource Sharing implementations for common misconfigurations.

theHarvester on offsec.tools

tko-subs on offsec.tools

tko-subs

A tool that can help detect and takeover subdomains with dead DNS records.

TLD Scanner on offsec.tools

TLD Scanner

Scan all possible TLD’s for a given domain name.

tlsx on offsec.tools

tlsx

Fast and configurable TLS grabber focused on TLS based data collection.

tplmap on offsec.tools

tplmap

Server-Side Template Injection and Code Injection Detection and Exploitation Tool.

Tracy on offsec.tools

Tracy

Assists with finding all sinks and sources of a webapp and display the results in a nice way.

Transformations on offsec.tools

Transformations

Understand how input is transformed on a system, which can help to craft payloads.

Trishul on offsec.tools

Trishul

Burp Suite Extension to hunt for common vulnerabilities found in websites.

TruffleHog on offsec.tools

TugaRecon on offsec.tools

TugaRecon

Subdomains enumeration tool for penetration testers.

Turbo Intruder on offsec.tools

Turbo Intruder

Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.

Turbolist3r on offsec.tools

Turbolist3r

Subdomain enumeration tool with analysis features for discovered domains.

uncover on offsec.tools

uncover

Quickly discover exposed hosts on the internet using multiple search engines.

unfurl on offsec.tools

unfurl

An Entropy-Based Link Vulnerability Tool.

UploadScanner on offsec.tools

urlgrab on offsec.tools

urlgrab

A golang utility to spider through a website searching for additional links.

uro on offsec.tools

uro

Declutters url lists for crawling/pentesting.

userefuzz on offsec.tools

userefuzz

User-Agent, X-Forwarded-For and Referer SQLI Fuzzer.

vaf on offsec.tools

vaf

Cross-platform very advanced and fast web fuzzer written in nim.

vaya-ciego-nen on offsec.tools

vaya-ciego-nen

Detect, manage and exploit Blind Cross-site scripting (XSS) vulnerabilities.

Venom on offsec.tools

Venom

Popular Pentesting scanner for SQLi/XSS/LFI/RFI and other Vulns.

vhosts-sieve on offsec.tools

vhosts-sieve

Searching for virtual hosts among non-resolvable domains.

VHostScan on offsec.tools

VHostScan

Virtual host scanner that performs reverse lookups.

Virtual host scanner on offsec.tools

w3af on offsec.tools

w3af

Web Application Attack and Audit Framework.

wafw00f on offsec.tools

wafw00f

Identify and fingerprint Web Application Firewall products protecting a website.

Wapiti on offsec.tools

Wapiti

The web-application vulnerability scanner.

Wappalyzer on offsec.tools

Wayback Machine on offsec.tools

waybackSqliScanner on offsec.tools

waybackSqliScanner

Gather urls from wayback machine then test each GET parameter for SQL injection.

waybackurls on offsec.tools

waybackurls

Fetch all the URLs that the Wayback Machine knows about for a domain.

Waymore on offsec.tools

Waymore

Find way more from the Wayback Machine!

Web Crawler Security Tool on offsec.tools

webanalyze on offsec.tools

webanalyze

Uncovers technologies used on websites to automate mass scanning.

webscreenshot on offsec.tools

websy on offsec.tools

websy

Keep an eye on your targets to get quickly notified for any change they push on their server.

WeirdAAL on offsec.tools

Wfuzz on offsec.tools

Wfuzz

Web application fuzzer.

WhatsMyName on offsec.tools

WhatWeb on offsec.tools

WhatWeb

Next generation web scanner.

Whispers on offsec.tools

Whispers

Identify hardcoded secrets in static structured text.

wifipumpkin3 on offsec.tools

wifipumpkin3

Powerful framework for rogue access point attack.

wifite on offsec.tools

wifite

Runs existing wireless-auditing tools for you. Stop memorizing command arguments & switches!

windapsearch on offsec.tools

windapsearch

Enumerate users, groups and computers from a Windows domain through LDAP queries.

Wireshark on offsec.tools

Wireshark

Network sniffer that captures and analyzes packets off the wire.

WitnessMe on offsec.tools

WitnessMe

Web Inventory tool, takes screenshots and provides some extra bells&whistles to make life easier.

Words Scraper on offsec.tools

Words Scraper

Selenium based web scraper to generate passwords list.

WPRecon on offsec.tools

WPRecon

Tool for the recognition of vulnerabilities and blackbox information for WordPress.

WPScan on offsec.tools

WPScan

WPScan WordPress Security Scanner

WPSpider on offsec.tools

WPSpider

A centralized dashboard for running and scheduling WordPress scans powered by WPScan utility.

WSDL Wizard on offsec.tools

WSDL Wizard

Burp Suite plugin to detect current and discover new WSDL files.

X8 on offsec.tools

X8

Hidden parameters discovery suite.

XFFenum on offsec.tools

XFFenum

X-Forwarded-For [403 forbidden] enumeration.

xnLinkFinder on offsec.tools

xnLinkFinder

A python tool used to discover endpoints and potential parameters for a given target.

xray on offsec.tools

xray

Security assessment tool that supports common web security issue scanning and custom PoC.

XSpear on offsec.tools

XSpear

Powerfull XSS Scanning and Parameter analysis tool&gem.

XSRFProbe on offsec.tools

XSRFProbe

The Prime Cross Site Request Forgery Audit and Exploitation Toolkit.

XSS Hunter Express on offsec.tools

XSS Hunter Express

The fastest way to set up XSS Hunter to test and find blind XSS vulnerabilities.

XSS Radar on offsec.tools

XSS Radar

A Chrome extension for fast and easy XSS fuzzing.

Xss-Sql-Fuzz on offsec.tools

Xss-Sql-Fuzz

Burp Suite plugin for XSS and SQLi which add our payload to all parameters with one click.

XSS'OR on offsec.tools

xss2png on offsec.tools

xss2png

PNG IDAT chunks XSS payload generator.

XSSCon on offsec.tools

XSSCon

Simple XSS Scanner tool.

xsscrapy on offsec.tools

xsscrapy

Fast, thorough, XSS/SQLi spider.

XSSer on offsec.tools

XSSer

Automatic framework to detect, exploit and report XSS vulnerabilities in web-based applications.

XSSMap on offsec.tools

XSSMap

Detect XSS vulnerability in Web Applications.

XSStrike on offsec.tools

xssValidator on offsec.tools

xssValidator

A Burp Intruder extender designed for automation and validation of XSS vulnerabilities.

XSSwagger on offsec.tools

XSSwagger

A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks.

XXE-FTP on offsec.tools

XXE-FTP

A mini webserver with FTP support for XXE payloads.

XXEinjector on offsec.tools

XXEinjector

Exploitation of XXE vulnerability using direct and different out of band methods.

xxeserv on offsec.tools

xxeserv

A mini webserver with FTP support for XXE payloads.

XXExploiter on offsec.tools

Yet Another Robber on offsec.tools

Yet Another Robber

Yar is a tool for plunderin’ organizations, users and/or repositories…

Yet Another Sniffer on offsec.tools

Yet Another Sniffer

A network analyzer that make easy to extract informations about network traffic.

Yoga on offsec.tools

Yoga

Your OSINT Graphical Analyzer.

ysoserial on offsec.tools

ysoserial

Generates payloads that exploit unsafe Java object deserialization.

ysoserial.net on offsec.tools

ysoserial.net

Deserialization payload generator for a variety of .NET formatters.

Zed Attack Proxy on offsec.tools

Read More
Tyisha Grisby

Latest

YouTube’s Tuma Basa to Exit as Director of Black Music & Culture

MusicAfter eight years at the streaming giant, the...

Feza – Khanyisa

MusicDOWNLOAD MP3 SONG...

Newsletter

Don't miss

YouTube’s Tuma Basa to Exit as Director of Black Music & Culture

MusicAfter eight years at the streaming giant, the...

Feza – Khanyisa

MusicDOWNLOAD MP3 SONG...

Ciza launches ‘CIZA’s Palace’ with first Afrohouse mix

Music Ciza drops new mix on YouTube South African artist...

The Vogue Business Funding Tracker

Introducing the Vogue Business Funding Tracker, a running list highlighting the most notable and intriguing investment and M&A activity in fashion and beauty. From emerging disruptors to legacy giants undergoing major changes, we spotlight the deals that are shifting the dynamics of the sectors we cover, including fashion, beauty, tech and sustainability. April 2026 Icicle

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day