Showing 1-28 of 1354 tool(s)
Page 1 of 49

PENTOO

Gentoo Linux Live CD/USB for pen-testing and security assessment with patched Wi-Fi drivers.

spiderfoot

Automates OSINT collection by integrating multiple public data sources.

Africana Framework

Open-source framework automating the detection of security flaws in network and web technologies.

Agartha

Generates payloads and assesses LFI, RCE, SQLi, auth, and access bypass issues.

pocsuite3

Remote vuln testing and PoC development framework with powerful engine and features.

SpamScanner

Spam Scanner is a drop-in replacement and the best alternative to SpamAssassin, rspamd, SpamTitan, and more.

Domain Analyzer

Security analysis tool for automated domain information discovery.

ScrapeGraphAI

Scraping API converting websites into structured data for AI agents and products.

ATENA SPLOIT

Penetration testing framework exploiting critical vulnerabilities with unique custom methods.

Proxy Google Translate

Python module for sending requests using Google Translate as a proxy.

JDS

Burp plugin to detect and exploit Java deserialization vulnerabilities.

Linux Exploit Suggester

Tool to detect security flaws in Linux kernels that may lead to local privilege escalation.

KICS

Open-source solution for static security analysis of Infrastructure as Code.

Open GApps

Pre-built GApps packages for custom Android ROMs, available at opengapps.org.

SRUM-DUMP

Extracts SRUM data and creates a spreadsheet of app usage over the past 30 days.

OSINT Industries

Real-time OSINT platform used by law enforcement worldwide.

SSJ

Script that uses Docker to provision hundreds of penetration testing and forensic tools.

PSOXY

Serverless DLP layer that pseudonymizes data and blocks sensitive fields in APIs.

SecOps Flow

A unified analyst toolkit for Security Operations teams. Investigate IOCs, analyze suspicious emails, explore the MITRE ATT&CK framework.

Fast Google Dork Scan

Automates Google Dork combinations to find admin panels, file types, and path traversal on sites.

twofa

macOS 2-factor authentication using Touch ID to secure logins.

grep

Quickly search code, files, and paths across millions of GitHub repositories.

Wordpress Attack Suite

WordPress attack suite for login brute-force and shell uploads.

PyCript

Burp extension to encrypt/decrypt traffic with custom logic in Python, Go, Node.js, etc.

CSET

CISA tool for assessing risks in critical infrastructure and control systems.

DARKUS

Searcher for .onion sites using deep/dark web search engines.

RAINK

There's power in AI in that you can "throw a problem at it" and get some result, without even fully defining the problem.

CheckPhish

Real-time email scanner detecting phishing, scams, and threats with deep threat intelligence.

GPT - RedTeam.Blue