Submit your favorite resources for free.
Browse all offensive security tools, platforms, and services in one place.
Vulners.com: A comprehensive vulnerability database enriched with CVEs, exploits, articles, and tools for proactive cybersecurity management.
WAFW00F identifies and fingerprints Web Application Firewall (WAF) products protecting a website using various detection methods.
WPScan is a vulnerability database and security scanner for WordPress, helping users identify and address security risks in their WP sites.
A tool to dump the LSASS process on modern Windows 11 using the old WerfaultSecure.exe program, outputting in Windows MINIDUMP format.
Wappalyzer is a web technology profiler that reveals the software stack behind websites for reconnaissance and competitive analysis.
The Wayback Machine archives billions of web pages, allowing users to view historical snapshots and track changes over time.
Web-Check is a powerful open-source OSINT tool for analyzing website configurations, security headers, DNS, and more.
Webhook.site allows red teams to capture and inspect HTTP requests in real-time. It is essential for testing blind OOB vulnerabilities and exfiltration.
Web-based OSINT tool to find usernames across 732 platforms. Essential for target enumeration, digital footprint mapping, and identity verification.
The WiFi Pineapple Mark VII is the industry-standard WiFi pentest platform, refined and enterprise-ready for red teams.
Virtualized WiFi pentesting lab using Docker and mac80211_hwsim for practicing WiFi attacks without physical cards.
WiGLE is a wireless network mapping platform that aggregates data on Wi-Fi and cellular networks from user submissions and wardriving efforts.