Submit your favorite resources for free.
Browse all offensive security tools, platforms, and services in one place.
Rust-based Windows PE manual loader supporting x86/x64. Implements manual mapping, base relocations, and import resolution for memory-based execution.
JWT Debugger is a web application to create, encode, decode, and debug JWT (JSON Web Tokens). It helps developers inspect claims and test token integrity.
John the Ripper jumbo is an advanced password cracker supporting hundreds of hash types and running on various platforms.
Julius is an open-source LLM service fingerprinting tool that identifies Ollama, vLLM, LiteLLM, and 30+ other AI services running on network endpoints.
Kali Linux is a Debian-based distribution for penetration testing, ethical hacking, and network security assessments, offering a vast array of tools.
Kerbrute is a tool for bruteforcing and enumerating valid Active Directory accounts via Kerberos pre-authentication.
Kiterunner is a contextual content discovery tool for modern web applications and APIs, excelling in route/endpoint bruteforcing.
KittySploit is a modular exploitation framework featuring a web proxy and AI-powered analysis to help red teams automate recon and vulnerability research.
KnowBe4 HRM+ is a human risk management platform with security awareness training, cloud email protection, and AI-driven defense agents.
The CISA KEV Catalog lists exploited vulnerabilities used in active attacks. It is a vital resource for red teams to prioritize high-impact security flaws.
A distributed password cracking system designed for security professionals and red teams to coordinate GPU/CPU resources for high-speed hash cracking.
Extract credentials from PPL-protected LSASS by leveraging a vulnerable, Microsoft-signed Defender driver (KslD.sys) for arbitrary memory access.