Submit your favorite resources for free.
Browse all offensive security tools, platforms, and services in one place.
Responder is a LLMNR, NBT-NS and MDNS poisoner with built-in rogue authentication servers for capturing credentials and performing relay attacks.
Retire.js: Scans web/Node.js apps for vulnerable JS libraries & generates SBOMs, aiding in identifying & mitigating security risks.
Rubeus is a C# toolset for raw Kerberos interaction and abuses, heavily adapted from Kekeo and MakeMeEnterpriseAdmin projects.
AI-driven pentesting platform automating hacker intuition to find vulnerabilities before exploits, reducing discovery costs.
RustScan: lightning-fast port scanner automating Nmap integration with adaptive learning for efficient network reconnaissance and security audits.
S3Scanner finds misconfigured S3 buckets across various cloud providers, enhancing cloud security posture and data leak prevention.
Stealthy In-Memory Local Password Harvester (SILPH) dumps LSA secrets, SAM hashes, and DCC2 credentials without writing to disk.
Sparrows Lock Picks offers quality lock picks, covert entry tools, beginner sets, practice locks, and tutorials for lock picking success.
AI-infused API Security solution for the entire API lifecycle, from discovery and posture management to threat protection, including AI Agents.
Schemathesis is a tool that automatically generates API tests from OpenAPI and GraphQL schemas to find bugs.
ScoutSuite: Multi-cloud security auditing tool for AWS, Azure, and GCP. Gathers configuration data and highlights risk areas.
Offline security checklist & report generator with 200+ tests across web, cloud, WiFi, firmware, and AI security domains.