Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tools (4958)

Individual pentesting tools, auto-synced from each official tool listing documented in the project's README — searchable by name and filterable by category/purpose. What do the badge icons mean? · Browse by goal

Team (best effort)

Team is guessed from each tool's category tags (falling back to the team of the OS it's bundled with) — not sourced from Kali/BlackArch/etc.'s own taxonomy, since none of them tag tools by team. A handful of generic desktop apps bundled with privacy-focused OSes like Tails (GIMP, LibreOffice) aren't team tools at all and are left unclassified rather than guessed.

Platform

010editor

010 Editor is a text and hex editor with Binary Templates technology.

hex-editors Blue Team

0d1n

Web security tool to make fuzzing at HTTP inputs, made in C with libCurl.

webapp Red Team

0trace

Traceroute tool that can run within an existing TCP connection

system-network-configuration-discovery Red Team

1768.py

Analyze Cobalt Strike beacons.

deobfuscation Blue Team

3proxy

Tiny free proxy server.

proxy Red Team

3proxy-win32

Tiny free proxy server.

windows Red Team

42zip

Recursive Zip archive bomb.

dos Red Team

7-Zip

Compress and decompress files using a variety of algorithms.

general Blue Team

7Photos.net

Unclear image-related web service with an active domain but limited publicly verifiable functionality.

images-videos-docs

7zip

7-Zip file archiver with a high compression ratio

uncategorized Red Team

a2sv

Auto Scanning to SSL Vulnerability.

scanner Red Team

AADInternals (T)

PowerShell toolkit for Azure AD and Entra ID assessment, including tenant reconnaissance and hybrid identity attack-path analysis.

cloud-infrastructure

abcd

ActionScript ByteCode Disassembler.

disassembler Blue Team

above

Network security sniffer for finding vulnerabilities in the network

network-sniffing Red Team

abuse-ssl-bypass-waf

Bypassing WAF by abusing SSL/TLS Ciphers.

webapp Red Team

abuseACL

A python script to automatically list vulnerable Windows ACEs/ACLs.

ad

acccheck

A password dictionary attack tool that targets windows authentication via the SMB protocol.

cracker Red Team

accept-all-ips

Accept connections to all IPv4 and IPv6 addresses and redirect it to the corresponding local port.

services Blue Team

ace

A simple yet powerful VoIP Corporate Directory enumeration tool that mimics the behavior of an IP Phone in order to down

voip Red Team

aclpwn

Active Directory ACL exploitation with BloodHound.

exploitation Red Team

activedirectoryenum

Enumerate AD through LDAP.

recon Red Team

ad-ldap-enum

An LDAP based Active Directory user and group enumeration tool.

recon Red Team

ad-miner

Active Directory audit tool that extract data from Bloodhound to uncover security weaknesses and generate an HTML report

recon Red Team

adape-script

Active Directory Assessment and Privilege Escalation Script.

windows Red Team

adaptix-c2

Extensible post-exploitation and adversarial emulation framework.

exploitation Red Team

adaptixc2

Extensible post-exploitation and adversarial emulation framework

command-and-control Red Team

adassault

An Active Directory environments pentest tool complementary to existing ones like NetExec.

networking Red Team

adbhoney

adbhoney honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

Addresses.com

Free people search engine for name, phone, and address lookups. Basic results are free; detailed reports redirect to Intelius (paid).

people-search-engines

adenum

A pentesting tool that allows to find misconfiguration through the the protocol LDAP and exploit some of those weaknesse

exploitation Red Team

adexplorersnapshot

AD Explorer snapshot parser.

recon Red Team

adfind

Simple admin panel finder for php,js,cgi,asp and aspx admin panels.

webapp Red Team

adfspray

Python3 tool to perform password spraying against Microsoft Online service using various methods.

cracker Red Team

adidnsdump

Active Directory Integrated DNS dumping by any authenticated user.

recon Red Team

admid-pack

ADM DNS spoofing tools - Uses a variety of active and passive methods to spoof DNS packets. Very powerful.

spoof Red Team

adminpagefinder

This python script looks for a large amount of possible administrative interfaces on a given site.

webapp Red Team

admsnmp

ADM SNMP audit scanner.

scanner Red Team

adpeas

winPEAS, but for Active Directory.

windows Red Team

ADS-B Exchange

Large community-driven unfiltered ADS-B flight tracking network with broad global aircraft coverage.

transportation

ADS-B.NL

Netherlands-focused ADS-B tracking portal with emphasis on military and regional aviation movements.

transportation

AdultFriendFinder

Adult-oriented social and dating platform with searchable profiles and preference-driven discovery.

dating

adversarial-robustness-toolbox

Python Library for Machine Learning Security.

ai Red Team

adwsdomaindump

A tool for dumping domain data via ADWS for evasion purposes.

ad

aesfix

Tool for correcting bit errors in an AES key schedule

uncategorized Red Team

aeskeyfind

Tool for locating AES keys in a captured memory image

uncategorized Red Team

AESKeyFinder

Find 128-bit and 256-bit AES keys in a memory image.

perform-memory-forensics Blue Team

aespipe

Reads data from stdin and outputs encrypted or decrypted results to stdout.

crypto Red Team

aesshell

A backconnect shell for Windows and Unix written in python and uses AES in CBC mode in conjunction with HMAC-SHA256 for

backdoor Red Team

afflib

Advanced Forensics Format Library (utilities)

forensic-imaging-tools Blue Team

aflplusplus

Instrumentation-driven fuzzer for binary formats

resource-development Red Team

agafi

A gadget finder and a ROP-Chainer tool for x86 platforms.

windows Red Team

against

A very fast ssh attacking script which includes a multithreaded port scanning module (tcp connect) for discovering possi

cracker Red Team

aggroargs

Bruteforce commandline buffer overflows, linux, aggressive arguments.

exploitation Red Team

Ahmia

Well-known Tor search engine indexing onion services with clearnet accessibility for discovery workflows.

dark-web

AI or Not

AI content detection tool that analyzes images and audio to determine whether they were generated by AI or created by humans.

ai-tools

aiengine

A packet inspection engine with capabilities of learning without any human intervention.

networking Red Team

aimage

A tool to create aff-images.

forensic Blue Team

aimap

Security scanner and fingerprinter for AI/ML infrastructure. Identifies 23 service types including LLMs, vector database

ai Red Team

aiodnsbrute

Python 3 DNS asynchronous brute force utility.

recon Red Team

air

A GUI front-end to dd/dc3dd designed for easily creating forensic images.

forensic Blue Team

aircrack-ng

Wireless WEP/WPA cracking utilities

wifi-credential-access Red Team

airflood

A modification of aireplay that allows for a DoS of the AP. This program fills the table of clients of the AP with rando

wireless Red Team

airgeddon

Multi-use bash script for Linux systems to audit wireless networks

wifi-credential-access Red Team

airgeddon-git

Multi-use bash script for Linux systems to audit wireless networks.

networking Red Team

airopy

Get (wireless) clients and access points.

wireless Red Team

airoscript

A script to simplify the use of aircrack-ng tools.

wireless Red Team

airoscript-git

Script to simplify the use of aircrack-ng tools

uncategorized Red Team

airpwn

A tool for generic packet injection on an 802.11 network.

wireless Red Team

airspyhf

Host code for AirspyHF+ SDR.

radio Red Team

ajpfuzzer

A command-line fuzzer for the Apache JServ Protocol (ajp13).

fuzzer Red Team

Akana Android Malware

Online Android Interactive Analysis Environment with plugins for analyzing malicious Android applications and APKs for suspicious behavior and…

malicious-file-analysis

albatar

A SQLi exploitation framework in Python.

webapp Red Team

aliasr

Aliasr is a modern and feature-rich TUI launcher for penetration testing commands inspired by Arsenal but with significantly improved functionality.

ad osint web Red Team

AlienVault Open Threat Exchange

Community-driven threat intelligence platform enabling collaborative defense with 180K+ participants sharing 19M+ threats daily.

domain-name

All My Tweets

Twitter/X account history viewer for reviewing public tweet timelines in a single interface.

social-networks

allthevhosts

A vhost discovery tool that scrapes various web applications.

scanner Red Team

altdns

Subdomain discovery through alterations and permutations

uncategorized Red Team

AltDNS (T)

Permutation-based DNS tool that generates and resolves alternative subdomains from known names.

domain-name

alterx

Fast and customizable subdomain wordlist generator using DSL.

misc Red Team

amap

Next-generation scanning tool for pentesters

uncategorized Red Team

amass

In-depth DNS Enumeration and Network Mapping

network-information network-service-discovery discovery Red Team

Amass (T)

Advanced attack surface mapping framework for DNS and subdomain enumeration with graph correlation and extensive data-source support.

cloud-infrastructure

Amazon Registry Search

Amazon gift registry search for wedding, baby, and other registries.

people-search-engines

amber

Reflective PE packer.

binary Red Team

amoco

Yet another tool for analysing binaries.

binary Red Team

Analyst Research Tools

Comprehensive web-based OSINT platform with 40+ integrated tools for people search, social media analysis, username enumeration, and archive…

tools

AnalyzeID

Reverse lookup service for tracking IDs such as Google Analytics, AdSense, and affiliate identifiers.

domain-name

analyzemft

Parse the MFT file from an NTFS filesystem.

forensic Blue Team

analyzepesig

Analyze digital signature of PE file.

windows Red Team

Ancestry.com

World's largest genealogy platform with over 40 billion historical records including census, immigration, military, and vital records across 80+…

people-search-engines

androbugs

An efficient Android vulnerability scanner that helps developers or hackers find potential security vulnerabilities in A

mobile Red Team

androguard

Reverse engineering, Malware and goodware analysis of Android applications and more.

binary Red Team

androick

A python tool to help in forensics analysis on android.

mobile Red Team

android-apktool

A tool for reverse engineering Android apk files.

reversing Blue Team

android-backup-extractor

Android backup extractor

mobile Red Team

android-ndk

Android C/C++ developer kit

mobile Red Team

android-sdk

Google Android SDK

mobile Red Team

android-sdk-meta

Software development kit for Android platform

uncategorized Red Team

android-tools-adb

A collection of tools for debugging Android applications

general

android-udev-rules

Android udev rules.

mobile Red Team

androidmeda

AI tool to deobfuscate and find any potential vulnerabilities in android apps.

mobile Red Team

androidpincrack

Bruteforce the Android Passcode given the hash and salt.

mobile Red Team

AndroidProjectCreator

Convert an Android APK application file into an Android Studio project for easier analysis.

android Red Team

androidsniffer

A perl script that lets you search for 3rd party passwords, dump the call log, dump contacts, dump wireless configuratio

mobile Red Team

androwarn

Yet another static code analyzer for malicious Android applications.

mobile Red Team

anew

A simple tool for filtering and manipulating text data / such as log files and other outputs.

ad web

angr

The next-generation binary analysis platform from UC Santa Barbaras Seclab.

binary Red Team

angr-management

The official angr GUI.

binary Red Team

angr-py2

The next-generation binary analysis platform from UC Santa Barbaras Seclab.

binary Red Team

angrop

A rop gadget finder and chain builder.

exploitation Red Team

AnnualReports.com

Free directory of annual reports for thousands of public companies worldwide. Allows browsing and downloading official investor relations documents.

business-records

Anomy

A wrapper around wget, ssh, sftp, ftp, and telnet to route these connections through Tor to anonymize your traffic.

connecting Blue Team

anontwi

A free software python client designed to navigate anonymously on social networks. It supports Identi.ca and Twitter.com

social Red Team

Anonymouth - Document Anonymization (T)

Java-based authorship anonymization tool that analyzes and modifies writing style features to reduce stylometric identification of document authors.

opsec

AntennaSearch

FCC-backed lookup for antenna structure and tower records used in RF and telecom investigations.

geolocation-tools-maps

anti-xss

A XSS vulnerability scanner.

webapp Red Team

antiransom

A tool capable of detect and stop attacks of Ransomware using honeypots.

windows Red Team

anubis-netsec

Subdomain enumeration and information gathering tool.

scanner Red Team

Any Run

Interactive malware analysis sandbox allowing real-time manual interaction with Windows, macOS, Linux, and Android environments. Fast report…

malicious-file-analysis

apache-tika

Toolkit for detecting and extracting metadata and structured text content

uncategorized Red Team

Apache Tika (T)

Apache content analysis framework for extracting metadata and text across a very broad set of file formats.

images-videos-docs

apache-users

Enumerate usernames on systems with Apache UserDir module

account-discovery Red Team

apache2

Apache HTTP Server

uncategorized Red Team

apachetomcatscanner

Apache Tomcat vulnerability scanner.

scanner Red Team

apacket

Sniffer syn and backscatter packets.

networking Red Team

aphopper

A program that automatically hops between access points of different wireless networks.

wireless Red Team

apimonitor

API Monitor lets you monitor and control API calls made by applications and services.

utilities Blue Team

apkid

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities.

mobile Red Team

apkleaks

Scanning APK file for URIs, endpoints & secrets.

mobile Red Team

apksigner

arguably the most important step to optimize your APK file

general

apkstat

Automated Information Retrieval From APKs For Initial Analysis.

mobile Red Team

apkstudio

An IDE for decompiling/editing & then recompiling of android application binaries.

reversing Blue Team

apktool

Tool for reverse engineering Android apk files

resource-development Red Team

apkurlgrep

Extract endpoints from APK files.

mobile Red Team

apnbf

A small python script designed for enumerating valid APNs (Access Point Name) on a GTP-C speaking device.

wireless Red Team

apple-bleee

Scripts to show what an attacker get from Apple devices

uncategorized Red Team

appmon

A runtime security testing & profiling framework for native apps on macOS, iOS & android and it is built using Frida.

mobile Red Team

apt2

Automated penetration toolkit.

automation Red Team

aptdec

NOAA APT satellite imagery decoder.

radio Red Team

aquatone

A Tool for Domain Flyovers.

recon Red Team

Aquatone (T)

Go-based tool for domain reconnaissance that automates subdomain discovery, HTTP service scanning, screenshot capture, and visual HTML report…

domain-name

arachni

A feature-full, modular, high-performance Ruby framework aimed towards helping penetration testers and administrators ev

webapp Red Team

aranea

A fast and clean dns spoofing tool.

spoof Red Team

arcane

Backdoor iOS packages and create the necessary resources for APT repositories.

mobile Red Team

archinstall-git

Just another guided/automated Arch Linux installer with a twist

uncategorized Red Team

Archive.is

On-demand web snapshot service that preserves point-in-time copies of pages and shortens archive links.

archives documentation-evidence-capture

archivebox

The open source self-hosted web archive. Takes browser history/bookmarks/Pocket/Pinboard/etc., saves HTML, JS, PDFs, med

misc Red Team

archversion-envconfig-git

Archlinux Version Controller (Git version patched for runtime config using environment variables)

uncategorized Red Team

Arctic Shift

Search and access layer for Reddit datasets with tools for historical content retrieval and analysis.

online-communities

ares

Automated decoding of encrypted text without knowing the key or ciphers used.

cracker Red Team

argus

Network monitoring tool with flow control.

networking Red Team

argus-clients

Network monitoring client for Argus.

networking Red Team

arjun

HTTP parameter discovery suite

web-scanning Red Team

Arkham Intelligence

AI-powered blockchain intelligence platform mapping 300+ million address labels and 150K+ entity pages using proprietary Ultra system for entity…

blockchain-cryptocurrency

armitage

Cyber attack management for Metasploit

execution command-and-control Red Team

armor

A simple Bash script designed to create encrypted macOS payloads capable of evading antivirus scanners.

exploitation Red Team

armscgen

ARM Shellcode Generator (Mostly Thumb Mode).

exploitation Red Team

arp-scan

Arp scanning and fingerprinting tool

uncategorized Red Team

arpalert

Monitor ARP changes in ethernet networks.

networking Red Team

arping

Sends IP and/or ARP pings (to the MAC address)

remote-system-discovery discovery Red Team

arping-th

ARP Ping from Thomas Habets (aka Debian arping).

networking Red Team

arpoison

The UNIX arp cache update utility

exploitation Red Team

arpon

A host-based solution to secure the ARP protocol and prevent MITM attacks via ARP spoofing or cache poisoning.

defensive Blue Team

arpspoof-smikims

Performs an ARP spoofing attack using the Linux kernel's raw sockets.

spoof Red Team

arpstraw

Arp spoof detection tool.

defensive Blue Team

arptools

A simple tool about ARP broadcast, ARP attack, and data transmission.

networking Red Team

arpwatch

Ethernet/FDDI station activity monitor

remote-system-discovery Red Team

arpwner

GUI-based python tool for arp poisoning and dns poisoning attacks.

networking Red Team

arsenal-ng

Go-based command library equipped with 200+ cybersecurity cheat-sheets

services-and-other-tools Red Team

artillery

Blue team tool designed to protect Linux and Windows operating systems through multiple methods.

defensive Blue Team

artlas

Apache Real Time Logs Analyzer System.

defensive Blue Team

asar

asar decompresses .asar archives

packers Blue Team

asciinema

Terminal session recorder

ad light osint web Red Team

asdf

Extendable version manager with support for ruby python go etc

ad light osint web Red Team

asleap

A tool for exploiting Cisco LEAP networks

wifi Red Team

asn

ASN, RPKI validity, BGP stats, IPv4v6, Prefix, URL, ASPath, Organization, IP reputation, IP geolocation, IP fingerprinti

recon Red Team

asnmap

Map organization network ranges using ASN information.

networking Red Team

asp-audit

An ASP fingerprinting tool and vulnerability scanner.

fingerprint Red Team

aspisec

Removes the traces left by offensive security tools.

misc Red Team

asrepcatcher

Make your VLAN ASREProastable.

ad

assassingo

Web pentest framework for information gathering and vulnerability scanning.

scanner Red Team

assetfinder

Find domains and subdomains related to a given domain

web-scanning Red Team

assetnote-wordlists

Assetnote generated wordlists.

wordlist Red Team

astra

Automated Security Testing For REST API's.

webapp Red Team

Astrometry

Astrometry.net solves star-field images to estimate where and when a photo was taken.

geolocation-tools-maps

atear

Wireless Hacking, WiFi Security, Vulnerability Analyzer, Pentestration.

wireless Red Team

atftp

Advanced TFTP client

uncategorized Red Team

athena-ssl-scanner

A SSL cipher scanner that checks all cipher codes. It can identify about 150 different ciphers.

scanner Red Team

atlas

Open source tool that can suggest sqlmap tampers to bypass WAF/IDS/IPS.

webapp Red Team

atomic-operator

Module to execute Atomic Red Team tests (Python 3)

uncategorized Red Team

atscan

Server, Site and Dork Scanner.

scanner Red Team

atstaketools

This is an archive of various @Stake tools that help perform vulnerability scanning and analysis, information gathering,

windows Red Team

ATT&CK Navigator

The ATT&CK Navigator is designed to provide basic navigation and annotation of ATT&CK matrices, something that people are already doing today in…

network-security-monitoring Blue Team

attacksurfacemapper

Tool that aims to automate the reconnaissance process.

recon Red Team

attk

Trend Micro Anti-Threat Toolkit.

scanner Red Team

Audacity

for recording and editing sounds

desktop-edition

aurebeshjs

Translate JavaScript to Other Alphabets.

misc Red Team

auto-eap

Automated Brute-Force Login Attacks Against EAP Networks.

wireless Red Team

auto-xor-decryptographyr-git

Automatic XOR decryptographyr tool.

crypto Red Team

auto-xor-decryptor

Automatic XOR decryptor tool.

crypto Red Team

autobloody

Automatically exploit Active Directory privilege escalation paths shown by BloodHound.

ad

autoconf

Tool for producing shell scripts to configure source code packages

general

autoDNA VIN Lookup

Vehicle history lookup platform with records from European and North American markets and paid report expansion.

transportation

Autoheal

a tool to automatically restart containers with failed healthchecks.

network-monitoring Blue Team

AutoIt-Ripper

Extract AutoIt scripts embedded in PE binaries.

scripts Blue Team

automato

Should help with automating some of the user-focused enumeration tasks during an internal penetration test.

automation Red Team

autonessus

This script communicates with the Nessus API in an attempt to help with automating scans.

automation Red Team

autonse

Massive NSE (Nmap Scripting Engine) AutoSploit and AutoScanner.

automation Red Team

autopsy

Graphical interface to SleuthKit

sleuth-kit-suite forensics Blue Team

autopwn

Specify targets and run sets of tools against them.

automation Red Team

autorecon

Multi-threaded network reconnaissance tool

network-information network-service-discovery Red Team

AutoRef (EU)

European VIN and plate intelligence service with free and paid tiers for technical vehicle profile data.

transportation

autosint

Tool to automate common osint tasks.

recon Red Team

autosploit

Automate the exploitation of remote hosts.

exploitation Red Team

autovpn

Easily connect to a VPN in a country of your choice.

networking Red Team

avaloniailspy

.NET Decompiler (port of ILSpy)

decompiler Blue Team

avet

AntiVirus Evasion Tool.

binary Red Team

avml

A portable volatile memory acquisition tool for Linux.

misc Red Team

avrdude

AVRDUDE is a command-line program that allows you to download/upload/manipulate the ROM and EEPROM contents of AVR microcontrollers using the…

general

Awesome Opt-Out Guide 2026

Community GitHub repository compiling data broker opt-out procedures, privacy request templates, and removal links for 2026.

opsec

Awesome OSINT

Large curated OSINT resource list covering investigation tools, techniques, and training references.

instant-messaging

aws-extender-cli

Script to test S3 buckets as well as Google Storage buckets and Azure Storage containers for common misconfiguration iss

scanner Red Team

aws-iam-privesc

AWS IAM policy scanner that helps determine where privilege escalation can be achieved.

scanner Red Team

aws-inventory

Discover resources created in an AWS account.

recon Red Team

awsbucketdump

A tool to quickly enumerate AWS S3 buckets to look for loot.

automation Red Team

AWSBucketDump (T)

Python tool that enumerates AWS S3 buckets and optionally downloads accessible objects using keyword and pattern-based discovery.

cloud-infrastructure

awscli

Command-line interface for Amazon Web Services.

general

axel

Light command line download accelerator

uncategorized Red Team

AYI.com

Online community for real-time meeting and chatting with singles across web and mobile platforms.

dating

azazel

A userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit.

backdoor Red Team

aztarna

A footprinting tool for ROS and SROS systems.

recon Red Team

azure-cli

A great cloud needs great tools; we're excited to introduce Azure CLI our next generation multi-platform command line experience for Azure.

general

azurehound

BloodHound data collector for Microsoft Azure (program)

active-directory Red Team

b374k

Remote management tool

uncategorized Red Team

backcookie

Small backdoor using cookie.

backdoor Red Team

backdoor-apk

Shell script that simplifies the process of adding a backdoor to any Android APK file

mobile Red Team

backdoor-factory

Patch win32/64 binaries with shellcode.

backdoor Red Team

backdoorme

A powerful utility capable of backdooring Unix machines with a slew of backdoors.

backdoor Red Team

backdoorppt

Transform your payload.exe into one fake word doc (.ppt).

backdoor Red Team

backfuzz

A network protocol fuzzing toolkit.

fuzzer Red Team

backhack

Tool to perform Android app analysis by backing up and extracting apps, allowing you to analyze and modify file system c

mobile Red Team

backoori

Tool aided persistence via Windows URI schemes abuse.

exploitation Red Team

backorifice

A remote administration system which allows a user to control a computer across a tcpip connection using a simple consol

windows Red Team

bad-pdf

Steal NTLM Hashes with Bad-PDF.

exploitation Red Team

badkarma

Advanced network reconnaissance toolkit.

recon Red Team

badministration

A tool which interfaces with management or administration applications from an offensive standpoint.

webapp Red Team

Badoo

Global social dating platform with swipe-based matching, nearby discovery, and in-app messaging.

dating

badsecrets

A library for detecting known secrets across many web frameworks.

webapp Red Team

bagbak

Yet another frida based App decryptor.

mobile Red Team

Baidu Images

Chinese reverse image search platform useful for discovering image reuse on China-centric websites.

images-videos-docs

Baidu Maps

Major Chinese mapping platform with strong POI and routing coverage in mainland China.

geolocation-tools-maps

baksmali

Disassembler for the dex format used by Dalvik, Android's Java VM implementation.

android Red Team

balbuzard

A package of malware analysis tools in python to extract patterns of interest from suspicious files (IP addresses, domai

malware Blue Team

Balbuzard (T)

Python malware analysis toolkit that extracts indicators and brute-forces common obfuscation patterns including XOR and rotation transforms.

encoding-decoding

bamf-framework

A modular framework designed to be a platform to launch attacks against botnets.

malware Blue Team

bandicoot

A toolbox to analyze mobile phone metadata.

mobile Red Team

barf

A multiplatform open source Binary Analysis and Reverse engineering Framework.

binary Red Team

barmie

Java RMI enumeration and attack tool.

scanner Red Team

barq

An AWS Cloud Post Exploitation framework.

exploitation Red Team

base64dump

Extract and decode base64 strings from files.

misc Red Team

base64dump.py

Locate and decode strings encoded in Base64 and other common encodings.

deobfuscation Blue Team

basedomainname

Tool that can extract TLD (Top Level Domain), domain extensions (Second Level Domain + TLD), domain name, and hostname f

recon Red Team

bashfuscator

Fully configurable and extendable Bash obfuscation framework.

automation Red Team

bashscan

A port scanner built to utilize /dev/tcp for network and service discovery.

scanner Red Team

Batch Geocoding

Bulk geocoding workflow that converts large address lists into latitude/longitude pairs.

geolocation-tools-maps

Batch Reverse Geocoding

Bulk reverse-geocoding workflow that converts coordinate lists into human-readable addresses.

geolocation-tools-maps

batman-adv

Batman kernel module, (included upstream since .38)

wireless Red Team

batman-alfred

Almighty Lightweight Fact Remote Exchange Daemon.

wireless Red Team

bbot

Multipurpose scanner built to automate your Recon, Bug Bounties, and ASM.

recon Red Team

bbqsql

SQL injection exploit tool.

webapp Red Team

bbscan

A tiny Batch web vulnerability Scanner.

webapp Red Team

bdfproxy

Patch Binaries via MITM: BackdoorFactory + mitmProxy

proxy Red Team

bdlogparser

This is a utility to parse a Bit Defender log file, in order to sort them into a malware archive for easier maintenance

malware Blue Team

beaconDB

Open geolocation database for Wi-Fi/Bluetooth/cell beacons used in location inference.

geolocation-tools-maps

bearparser

Parse PE file contents.

pe-files Blue Team

bed

A network protocol fuzzer

resource-development Red Team

beebug

A tool for checking exploitability.

decompiler Blue Team

beef

The Browser Exploitation Framework that focuses on the web browser.

exploitation Red Team

beef-git

Pentesting framework that focuses on web-browser exploitation

exploit Red Team

beef-xss

Browser Exploitation Framework (BeEF)

execution system-services Red Team

beelzebub

beelzebub honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

beeswarm

Honeypot deployment made easy.

honeypot Blue Team

beholder

A wireless intrusion detection tool that looks for anomalies in a wifi environment.

wireless Red Team

belati

The Traditional Swiss Army Knife for OSINT.

scanner Red Team

Belati (T)

Open-source OSINT data collection and automation framework for gathering information from multiple sources.

domain-name

beleth

A Multi-threaded Dictionary based SSH cracker.

cracker Red Team

beleth-git

A Multi-threaded Dictionary based SSH cracker

crackers Red Team

Bellingcat Meta Content Library

Guide to Meta Content Library access for researching public Facebook, Instagram, and Threads content.

social-networks

berate-ap

Script for orchestrating mana rogue Wi-Fi Access Points

uncategorized Red Team

beroot

A post exploitation tool to check common misconfigurations to find a way to escalate our privilege.

exploitation Red Team

bettercap

Complete, modular, portable and easily extensible MITM framework

bluetooth wifi reconnaissance Red Team

bettercap-ui

Bettercap’s web UI

uncategorized Red Team

bfac

An automated tool that checks for backup artifacts that may disclose the web-application's source code.

recon Red Team

bfbtester

Perform checks of single and multiple argument command line overflows and environment variable overflows.

exploitation Red Team

bfuzz

Input based fuzzer tool for browsers.

fuzzer Red Team

BGP Malicious Content Ranking

Platform ranking ASNs and BGP prefixes by malicious content and security threats.

ip-mac-address

bgp-md5crack

RFC2385 password cracker

cracker Red Team

bgrep

Binary grep.

binary Red Team

Bielefeld Academic Search Engine

Academic search engine indexing over 400 million documents from 12,000+ content providers including institutional repositories, open-access journals,…

search-engines

billcipher

Information Gathering tool for a Website or IP address.

recon Red Team

BIN Base

Business Identification Number database for company registration lookups. Provides business registration and compliance information.

public-records

BinaryEdge (R)

Commercial security research platform with internet-wide scanning and module-based detection.

ip-mac-address

binaryninja

A new kind of reversing platform (demo version).

reversing Blue Team

bind9

Internet Domain Name Server

uncategorized Red Team

bindead

A static analysis tool for binaries

binary Red Team

bindead-git

A static analysis tool for binaries

analysis Red Team

bindiff

A comparison tool for binary files, that assists vulnerability researchers and engineers to quickly find differences and

binary Red Team

binee (Binary Emulation Environment)

Analyze I/O operations of a suspicious PE file by emulating its execution.

pe-files Blue Team

binex

Format String exploit building tool.

exploitation Red Team

binflow

POSIX function tracing. Much better and faster than ftrace.

binary Red Team

Bing Images

Microsoft visual search engine with reverse image lookup and crop-based matching for partial-object analysis.

images-videos-docs

bing-ip2hosts

Enumerate hostnames for an IP using bing.com

uncategorized Red Team

bing-lfi-rfi

Python script for searching Bing for sites that may have local and remote file inclusion vulnerabilities.

webapp Red Team

Bing Maps

Microsoft web mapping service with road, aerial, and route layers for location analysis.

geolocation-tools-maps

Bing Translate

Microsoft's neural translation service for text and web content across 100+ languages.

language-translation

bingoo

A Linux bash based Bing and Google Dorking Tool.

scanner Red Team

binnavi

A binary analysis IDE that allows to inspect, navigate, edit and annotate control flow graphs and call graphs of disasse

disassembler Blue Team

binproxy

A proxy for arbitrary TCP connections.

proxy Red Team

binwalk

Tool library for analyzing binary blobs and executable code

forensics Blue Team

binwalk3

Tool library for analyzing binary blobs and executable code

forensics Blue Team

binwally

Binary and Directory tree comparison tool using the Fuzzy Hashing concept (ssdeep).

binary Red Team

bios_memimage

A tool to dump RAM contents to disk (aka cold boot attack).

cracker Red Team

Birdwatcher (T)

Open-source Twitter data harvesting and analysis framework for collecting tweets and producing offline analytical artifacts.

social-networks

birp

A tool that will assist in the security assessment of mainframe applications served over TN3270.

scanner Red Team

Bitcoin Abuse Database

Community-curated Bitcoin address abuse database tracking addresses associated with ransomware, fraud, scams, and illicit activities.

blockchain-cryptocurrency

Bitcoin Who's Who

Bitcoin address profiling and scam reporting platform with community-driven address tagging for fraud detection and wallet identification.

blockchain-cryptocurrency

bitdump

A tool to extract database data from a blind SQL injection vulnerability.

exploitation Red Team

BitRef

Bitcoin address balance checker and transaction analyzer supporting address clustering, mempool data, mining statistics, and developer API.

blockchain-cryptocurrency

bittwist

A simple yet powerful libpcap-based Ethernet packet generator. It is designed to complement tcpdump, which by itself has

sniffer Red Team

bkcrack

Crack legacy zip encryption with Biham and Kocher known plaintext attack.

cracker Red Team

bkhive

Program for dumping the syskey bootkey from a Windows NT/2K/XP system hive.

cracker Red Team

Black Book Online - Criminal Search

Free public records search portal covering 37,000+ types of records including criminal records, court records, property records, and background…

public-records

blackarch-officials

Meta package for installing official security tools from the Arch Linux repository.

uncategorized Red Team

Blackbird

An OSINT tool to search fast for accounts by username across 581 sites.

osint web Red Team

blackbox-scanner

Dork scanner & bruteforcing & hash cracker with blackbox framework.

scanner Red Team

blackeye

Ultimate phishing tool with ngrok and serveo.

social Red Team

blackhash

Creates a filter from system hashes.

cracker Red Team

blacknurse

A low bandwidth ICMP attack that is capable of doing denial of service to well known firewalls.

dos Red Team

Blackweb

Open-source project consolidating public malware domain blacklists optimized for Squid-Cache compatibility.

domain-name

bleah

A BLE scanner for "smart" devices hacking.

scanner Red Team

bless

High-quality, full-featured hex editor.

misc Red Team

bletchley

A collection of practical application cryptanalysis tools.

crypto Red Team

blind-sql-bitshifting

A blind SQL injection module that uses bitshfting to calculate characters.

exploitation Red Team

blindelephant

A web application fingerprinter. Attempts to discover the version of a (known) web application by comparing static files

fingerprint Red Team

blindsql

Set of bash scripts for blind SQL injection attacks.

database Red Team

blindy

Simple script to automate brutforcing blind sql injection vulnerabilities.

scanner Red Team

blisqy

Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

webapp Red Team

blobrunner

BlobRunner is a simple tool to quickly debug shellcode extracted during malware analysis.

shellcode Blue Team

blobrunner64

BlobRunner is a simple tool to quickly debug shellcode extracted during malware analysis.

shellcode Blue Team

Blocklist.de

Community-contributed blocklist of IP addresses involved in attacks and malicious activity.

ip-mac-address

Blockonomics

Bitcoin payment API and OSINT platform providing address monitoring, wallet balance tracking, and transaction alerts for developers and enterprises.

blockchain-cryptocurrency

Blockscan

Multichain EVM blockchain explorer aggregating 25+ EVM-compatible chains with portfolio tracking, real-time data, and in-depth analytics.

blockchain-cryptocurrency

bloodbash

BloodBash is a powerful standalone BloodHound / SharpHound + AzureHound JSON analyzer written in Python

ad

bloodhound

Six Degrees of Domain Admin, BloodHound CE

active-directory discovery Red Team

BloodHound-CE

Active Directory security tool for reconnaissance and attacking AD environments (Community Edition)

ad

bloodhound-ce.py

BloodHound-CE ingestor in Python.

ad

bloodhound-ce-python

Python based ingestor for BloodHound CE

active-directory Red Team

bloodhound-cli

Command-line interface for BloodHound v5.

misc Red Team

bloodhound-import

Import data into BloodHound for analyzing active directory trust relationships

ad

bloodhound.py

BloodHound ingestor in Python.

ad light

bloodhound-python

Python data collector for Bloodhound legcacy (v4)

recon Red Team

bloodhound-quickwin

A tool for BloodHounding on Windows machines without .NET or Powershell installed

ad

bloodhound.py

Ingestor for BloodHound, based on Impacket (Python 3)

active-directory Red Team

bloodyad

Active Directory privilege escalation framework

privilege-escalation Red Team

blue-hydra

Bluetooth device discovery service

uncategorized Red Team

bluebox-ng

A GPL VoIP/UC vulnerability scanner.

voip Red Team

bluebugger

An implementation of the bluebug technique which was discovered by Martin Herfurt.

bluetooth Red Team

BlueCoat WebPulse

Web reputation filtering service rating URLs with 50+ language support. Processes 180+ million rating requests daily with Dynamic Link Analysis for…

domain-name

bluediving

A Bluetooth penetration testing suite.

bluetooth Red Team

bluefog

A tool that can generate an essentially unlimited number of phantom Bluetooth devices.

bluetooth Red Team

bluelog

Bluetooth scanner and logger

bluetooth Red Team

bluepot

A Bluetooth Honeypot written in Java, it runs on Linux.

bluetooth Red Team

blueprint

A perl tool to identify Bluetooth devices.

bluetooth Red Team

blueranger

Simple Bash script to locate Bluetooth devices

bluetooth Red Team

bluescan

A Bluetooth Device Scanner.

bluetooth Red Team

bluesnarfer

Bluesnarfing utility

bluetooth Red Team

BlueStacks 2 (T)

Free, lightweight Android emulator for desktop. Includes built-in forensic capabilities for data extraction from installed apps.

mobile-osint Red Team

bluez

Bluetooth tools and daemons

uncategorized Red Team

bluffy

Convert shellcode into different formats.

exploitation Red Team

bluphish

Bluetooth device and service discovery tool that can be used for security assessment and penetration testing.

bluetooth Red Team

bluto

Recon, Subdomain Bruting, Zone Transfers.

scanner Red Team

Bluto (T)

Recon utility for domain intelligence including DNS records, email patterns, and infrastructure clues.

domain-name

bmap-tools

Tool for copying largely sparse files using information from a block map file.

forensic Blue Team

bmc-tools

RDP Bitmap Cache parser.

forensic Blue Team

bob-the-butcher

A distributed password cracker package.

cracker Red Team

bof-detector

A simple detector of BOF vulnerabilities by source-code-level check.

code-audit Red Team

bolt

Bolt crawls the target website to the specified depth and stores all the HTML forms found in a database for further processing.

ad web

bonesi

The DDoS Botnet Simulator.

dos Red Team

boofuzz

boofuzz

fuzzer Red Team

BookletImposer

to convert linear PDF documents into booklets, and vice-versa

desktop-edition

boopsuite

A Suite of Tools written in Python for wireless auditing and security testing.

wireless Red Team

boost-bloom-filters-git

A collection of generic, C++ Bloom Filter classes developed for the Boost C++ Libraries.

uncategorized Red Team

bopscrk

Generate smart and powerful wordlists

password-profiling-wordlists Red Team

botb

A container analysis and exploitation tool for pentesters and engineers.

exploitation Red Team

bowcaster

A framework intended to aid those developing exploits.

exploitation Red Team

box-js

A tool for studying JavaScript malware.

malware Blue Team

bpf-linker

Simplify building modern BPF programs

uncategorized Red Team

bqm

Download BloudHound query lists, deduplicate entries and merge them in one file.

misc Red Team

braa

Mass SNMP scanner

snmp Red Team

braces

A Bluetooth Tracking Utility.

bluetooth Red Team

brainstorm

A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery.

fuzzer Red Team

brakeman

A static analysis security vulnerability scanner for Ruby on Rails applications.

code-audit Red Team

Brasero

to burn CD/DVDs

desktop-edition

Brave

Privacy-focused search engine with independent index. Offers Goggles for custom search result ranking. First search API with zero data retention…

search-engines

BRB Public Records

BRB Publications portal linking to public records sources across US. Reference guide with 20K+ government agencies and vendors.

public-records

Breadcrumbs.app

Community-powered blockchain analytics platform with fund-flow visualization (PathFinder), address investigation, and crypto transaction network…

blockchain-cryptocurrency

bridgekeeper

Scrape employee names from search engine LinkedIn profiles. Convert employee names to a specified username format.

recon Red Team

brosec

An interactive reference tool to help security professionals utilize useful payloads and commands.

exploitation Red Team

browselist

Retrieves the browse list ; the output list contains computer names, and the roles they play in the network.

windows Red Team

browser-fuzzer

Browser Fuzzer 3

fuzzer Red Team

brut3k1t-git

Brute-force attack that supports multiple protocols and services

crackers Red Team

brute-force

Brute-Force attack tool for Gmail Hotmail Twitter Facebook Netflix.

cracker Red Team

brute12

A tool designed for auditing the cryptography container security in PKCS12 format.

windows Red Team

bruteforce-luks

Try to find a password of a LUKS encrypted volume

uncategorized Red Team

bruteforce-salted-openssl

Try to find the passphrase for files encrypted with OpenSSL

uncategorized Red Team

bruteforce-wallet

Try to find the password of an encrypted wallet file

uncategorized Red Team

brutemap

Penetration testing tool that automates testing accounts to the site's login page.

webapp Red Team

bruteshark

Network Forensic Analysis Tool (NFAT)

uncategorized Red Team

brutespray

Bruteforcing from various scanner output

uncategorized Red Team

brutessh

A simple sshd password bruteforcer using a wordlist, it's very fast for internal networks. It's multithreads.

cracker Red Team

brutex

Automatically brute force all services running on a target.

automation Red Team

brutexss

Cross-Site Scripting Bruteforcer.

webapp Red Team

brutus

One of the fastest, most flexible remote password crackers you can get your hands on.

windows Red Team

brxor.py

Bruteforce XOR'ed strings to find those that are English words.

deobfuscation Blue Team

bsdiff

Tools for building and applying patches to binary files.

binary Red Team

bsqlbf

Blind SQL Injection Brute Forcer.

webapp Red Team

bsqlinjector

Blind SQL injection exploitation tool written in ruby.

webapp Red Team

bss

Bluetooth stack smasher / fuzzer.

bluetooth Red Team

bt_audit

Bluetooth audit

bluetooth Red Team

btcrack

The world's first Bluetooth Pass phrase (PIN) bruteforce tool. Bruteforces the Passkey and the Link key from captured Pa

bluetooth Red Team

btlejack

Bluetooth Low Energy Swiss-army knife.

bluetooth Red Team

btproxy-mitm

Man in the Middle analysis tool for Bluetooth.

bluetooth Red Team

btscanner

Ncurses-based scanner for Bluetooth devices

bluetooth Red Team

BucketLoot (T)

Open-source cloud bucket discovery utility with limited current documentation and unclear maintenance signals.

cloud-infrastructure

buildhosts-git

Download and use custom hosts sources to build /etc/hosts

misc Red Team

BuiltWith

Technology profiling platform that identifies web stacks, frameworks, analytics, and hosting signals.

domain-name

bulk-extractor

Extracts information without parsing filesystem

forensics Blue Team

bully

Implementation of the WPS brute force attack, written in C

wifi-credential-access Red Team

Bumble (R)

Swipe-based dating app with women-first messaging rules and location-based recommendations.

dating

bunny

A closed loop, high-performance, general purpose protocol-blind fuzzer for C programs.

fuzzer Red Team

Burner Email Providers (T)

Curated list of temporary email service domains with API references and detection library implementations across multiple languages.

email-address

Burp Suite Community Edition

Investigate website interactions using this web proxy.

monitoring Blue Team

Burp Suite (T)

Industry-standard web application security testing platform for manual and automated vulnerability assessment.

documentation-evidence-capture domain-name

burpsuite

Platform for security testing of web applications

web-vulnerability-scanning reconnaissance Red Team

buster

Find emails of a person and return info associated with them.

social Red Team

buttinsky

Provide an open source framework for automated botnet monitoring.

networking Red Team

Buzzfile

US company database providing business profiles, SIC codes, employee counts, and contact information for millions of US businesses.

business-records

bvi

A display-oriented editor for binary files operate like "vi" editor.

binary Red Team

byepass

Automates password cracking tasks using optimized dictionaries and mangling rules.

automation Red Team

byp4xx

A Swiss Army knife for bypassing web application firewalls and filters.

ad web

bypass-firewall-dns-history

Firewall bypass script based on DNS history records.

networking Red Team

bytecode-viewer

Java 8+ Jar & Android APK Reverse Engineering Suite

resource-development Red Team

bytecodeviewer

A lightweight user-friendly Java/Android Bytecode Viewer, Decompiler and more.

java-and-android Red Team

Bytehist

Generate byte-usage-histograms for all types of files with a focus on PE files.

unpacking Blue Team

c5scan

Vulnerability scanner and information gatherer for the Concrete5 CMS.

webapp Red Team

c7decrypt

Cisco password type encryptor and decryptor.

crypto Red Team

CA Salary DB

Comprehensive California government salary database covering state, local, schools, universities, and special districts.

public-records

cabextract

Microsoft Cabinet file unpacker

uncategorized Red Team

cacdec-git

The hidden RDP client recorder

exploit Red Team

Cached Pages

Web cache lookup utility that surfaces archived and cached versions of a target page from multiple sources.

archives

Cached View

Simple cache-checking service that retrieves copies of pages from search engine and archive caches.

archives

cachedump

A tool that demonstrates how to recover cache entry information: username and hashed password (called MSCASH).

windows Red Team

cadaver

Command-line WebDAV client

application-layer-protocol Red Team

cafebabe

Java bytecode editor & decompiler.

decompiler Blue Team

cai

The framework for AI Security.

ai Red Team

caido

Security auditing toolkit (desktop)

web-vulnerability-scanning reconnaissance Red Team

caido-cli

Security auditing toolkit (CLI)

web-vulnerability-scanning Red Team

caido-desktop

Intercepting proxy to replay, inject, scan and fuzz HTTP requests.

webapp Red Team

caldera

Scalable Automated Adversary Emulation Platform

uncategorized Red Team

calico

Networking and network security solution for Kubernetes

uncategorized Red Team

CallerID Test

Caller ID and number-validation utility for checking formatting and telecom metadata responses.

telephone-numbers

Cambridge Dictionary

Dictionary and learner reference platform with translation support across multiple language pairs.

language-translation

cameradar

Hacks its way into RTSP videosurveillance cameras.

scanner Red Team

CamFind App

Mobile visual search app that identifies objects, landmarks, and products from photos.

images-videos-docs

camover

A camera exploitation tool that allows to disclosure network camera admin password.

exploitation Red Team

camscan

A tool which will analyze the CAM table of Cisco switches to look for anamolies.

scanner Red Team

can-utils

Linux-CAN / SocketCAN user space applications.

automobile Red Team

canalyzat0r

Security analysis toolkit for proprietary car protocols.

automobile Red Team

canari

Maltego rapid transform development and execution framework.

forensic Blue Team

cangibrina

Dashboard Finder.

scanner Red Team

cansina

A python-based Web Content Discovery Tool.

webapp Red Team

cantoolz

Framework for black-box CAN network analysis.

automobile Red Team

capa

The FLARE team's open-source tool to identify capabilities in executable files.

defensive Blue Team

capa-explorer-web

Web interface for exploring and understanding capa results

utilities Blue Team

capfuzz

Capture, fuzz and intercept web traffic.

sniffer Red Team

capstone

Lightweight multi-architecture disassembly framework - command line tool

resource-development Red Team

captipper

Malicious HTTP traffic explorer tool.

forensic Blue Team

carbon14

OSINT tool for estimating when a web page was written.

osint web Red Team

cardpwn

OSINT Tool to find Breached Credit Cards Information.

social Red Team

cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, token.

webapp Red Team

Carnet.ai

AI vehicle image recognition platform that identifies make/model/generation from submitted photos.

transportation

carVertical VIN Decoder

International VIN and registration decoder with vehicle history reporting across accident, theft, and ownership datasets.

transportation

carwhisperer

Sensibilise manufacturers of carkits and other Bluetooth appliances without display and keyboard for the possible securi

bluetooth Red Team

casefile

The little brother to Maltego without transforms, but combines graph and link analysis to examine links between manually

forensic Blue Team

Caselaw Access Project

Harvard-hosted comprehensive free legal database with 6M+ court opinions. Digitized legal decisions from centuries of US case law.

public-records

catana

Filter your wordlist according to the specified password policy.

misc Red Team

catnthecanary

An application to query the canary.pw data set for leaked data.

recon Red Team

catphish

For phishing and corporate espionage.

social Red Team

Catphish (T)

Red team tool for generating phishing domains using homoglyphs, punycode, and domain manipulation techniques.

domain-name

CC Search

Creative Commons search portal for discovering openly licensed and public-domain images.

images-videos-docs

ccrawldns

Retrieves from the CommonCrawl data set unique subdomains for a given domain name.

recon Red Team

ccrypt

Secure encryption and decryption of files and streams

defense-evasion Red Team

cdpsnarf

Cisco discovery protocol sniffer.

sniffer Red Team

cecster

A tool to perform security testing against the HDMI CEC (Consumer Electronics Control) and HEC (HDMI Ethernet Channel) p

scanner Red Team

Censys

Internet-wide scanner and search engine for hosts, certificates, and services.

domain-name

cent

Community edition nuclei templates.

webapp Red Team

centry

Cold boot & DMA protection

misc Red Team

centry-git

A Panic button for protection against cold boot attacks

misc Red Team

cero

Scrape domain names from SSL certificates of arbitrary hosts.

scanner Red Team

certgraph

Tool to crawl the graph of certificate Alternate Names

uncategorized Red Team

certgraph (T)

CLI tool that crawls SSL certificates via Certificate Transparency logs to create a directed graph of domain relationships. Supports multiple drivers…

domain-name

certi

Tool to ask certificates to ADCS and discover templates

uncategorized Red Team

certipy

Active Directory Certificate Services enumeration and abuse.

windows Red Team

certipy-ad

Tool for attacking AD Certificate Services

uncategorized Red Team

CertKit - Certificate Transparency Log Search

Fast Certificate Transparency log search tool using Clickhouse for sub-second queries. Discover all certificates issued to a domain, including…

domain-name

certsync

Dump NTDS remotely without DRSUAPI: using golden certificate and UnPAC the hash.

exploitation Red Team

cewl

Custom word list generator

password-profiling-wordlists credential-access Red Team

CeWL (T)

Ruby-based web spider that generates custom wordlists by crawling target websites to specified depth and extracting unique words for password…

tools

cewler

CeWL alternative in Python

ad web

cflow

A C program flow analyzer.

code-audit Red Team

cfr

Java decompiler.

java Blue Team

chainsaw

Rapidly search and hunt through Windows forensic artefacts

uncategorized Red Team

chameleon

A tool for evading Proxy categorisation.

networking Red Team

chameleonmini

Official repository of ChameleonMini, a freely programmable, portable tool for NFC security analysis that can emulate an

social Red Team

Change Detection

Open-source change-monitoring system for tracking updates on websites over time.

domain-name

ChangeDetect

Open-source website change detection platform with both self-hosted and hosted options. Supports visual diffs, notifications, and automation…

domain-name

changeme

Default credential scanner

uncategorized Red Team

chankro

Tool that generates a PHP capable of run a custom binary (like a meterpreter) or a bash script (p.e. reverse shell) bypa

webapp Red Team

chaos

A Go client to communicate with Chaos dataset API from ProjectDiscovery.

ad web

chaos-client

Go client to communicate with Chaos dataset API.

recon Red Team

chaosmap

An information gathering tool and dns / whois / web server scanner

forensic Blue Team

chaosreader

Trace network sessions and export it to html format

uncategorized Red Team

chapcrack

A tool for parsing and decrypting MS-CHAPv2 network handshakes.

cracker Red Team

Charles Proxy

Commercial HTTP/HTTPS proxy for traffic analysis. Captures and analyzes network traffic between apps and servers.

mobile-osint Red Team

cheat-sh

The only cheat sheet you need.

automation Red Team

check-weak-dh-ssh

Debian OpenSSL weak client Diffie-Hellman Exchange checker.

scanner Red Team

checkiban

Checks the validity of an International Bank Account Number (IBAN).

misc Red Team

checkip (T)

Command-line utility for checking local machine IP address and network connectivity.

ip-mac-address

checkov

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images a

code-audit Red Team

Checkov (T)

Infrastructure-as-code security scanner that checks Terraform, CloudFormation, Kubernetes, and other cloud configs against policy rules.

cloud-infrastructure

checksec-py

Python wrapper script for checksec.sh from paX.

general

CheckShortURL

Preview service for shortened URLs with destination and threat-check context.

domain-name

Chepy

Decode and otherwise analyze data using this command-line tool and Python library.

deobfuscation Blue Team

cherrytree

Hierarchical note taking application

reporting-tools Red Team

chiasm-shell

Python-based interactive assembler/disassembler CLI, powered byKeystone/Capstone.

disassembler Blue Team

chipsec

Platform Security Assessment Framework.

hardware Red Team

chiron

An all-in-one IPv6 Penetration Testing Framework.

scanner Red Team

chirp

Configuration tool for amateur radios

uncategorized Red Team

chisel

Fast TCP/UDP tunnel over HTTP (program)

protocol-tunneling Red Team

chisel-common-binaries

Prebuilt binaries for chisel

protocol-tunneling Red Team

chkrootkit

Rootkit detector

forensics Blue Team

chntpw

NT SAM password recovery utility

os-credential-dumping Red Team

chopshop

Protocol Analysis/Decoder Framework.

networking Red Team

choronzon

An evolutionary knowledge-based fuzzer.

fuzzer Red Team

chownat

Allows two peers behind two separate NATs with no port forwarding and no DMZ setup on their routers to directly communic

tunnel Red Team

chrome-decode

Chrome web browser decoder tool that demonstrates recovering passwords.

windows Red Team

chromefreak

A Cross-Platform Forensic Framework for Google Chrome

forensic Blue Team

chromensics

A Google chrome forensics tool.

windows Red Team

chromium

Web browser

uncategorized Red Team

chronoleak

ICMP Timestamp Remote Time Leaker.

recon Red Team

chw00t

Unices chroot breaking tool.

exploitation Red Team

cidr2range

Script for listing the IP addresses contained in a CIDR netblock.

networking Red Team

cifs-utils

Common Internet File System utilities

uncategorized Red Team

cilium-cli

Cilium CLI (program)

uncategorized Red Team

cintruder

An automatic pentesting tool to bypass captchas.

cracker Red Team

cipherscan

A very simple way to find out which SSL ciphersuites are supported by a target.

scanner Red Team

ciphertest

A better SSL cipher checker using gnutls.

crypto Red Team

ciphertest-git

A better SSL cipher checker using gnutls

crypto Red Team

ciphey

Automated decryption/decoding/cracking tool (Python 3)

uncategorized Red Team

ciphr

A CLI tool for encoding, decoding, encryption, decryption, and hashing streams of data.

crypto Red Team

cirt-fuzzer

A simple TCP/UDP protocol fuzzer.

fuzzer Red Team

cisco-auditing-tool

Scans Cisco routers for vulnerabilities

vulnerability-scanning brute-force Red Team

cisco-global-exploiter

Simple and fast Cisco exploitation tool

cisco-tools Red Team

cisco-ocs

Mass Cisco scanner

cisco-tools Red Team

cisco-router-config

Tools to copy and merge Cisco Routers Configuration.

misc Red Team

cisco-scanner

Multithreaded Cisco HTTP vulnerability scanner. Tested on Linux, OpenBSD and Solaris.

cracker Red Team

cisco-snmp-enumeration

Automated Cisco SNMP Enumeration, Brute Force, Configuration Download and Password Cracking.

automation Red Team

cisco-snmp-slap

IP address spoofing tool in order to bypass an ACL protecting an SNMP service on Cisco IOS devices.

spoof Red Team

Cisco Talos

Cisco's comprehensive IP and domain reputation intelligence system with real-time threat detection spanning millions of sensors.

domain-name

cisco-torch

Cisco device scanner

cisco-tools Red Team

Cisco Umbrella Popularity List

Domain popularity ranking based on Cisco Umbrella DNS telemetry.

domain-name

cisco5crack

Crypt and decrypt the cisco enable 5 passwords.

cracker Red Team

cisco7crack

Crypt and decrypt the cisco type 7 passwords

uncategorized Red Team

ciscoasa

ciscoasa honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

ciscos

Scans class A, B, and C networks for cisco routers which have telnet open and have not changed the default password from

scanner Red Team

citadel

A library of OSINT tools.

recon Red Team

citrixhoneypot

citrixhoneypot honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

cjdns-git

A routing engine designed for security, scalability, speed and ease of use

networking Red Team

cjdnsify-git

Limit network access of bind-compatible programs to the local cjdns network

networking Red Team

cjexploiter

Drag and Drop ClickJacking exploit development assistance tool.

webapp Red Team

clair

Vulnerability Static Analysis for Containers.

scanner Red Team

clairvoyance

Obtain GraphQL API Schema even if the introspection is not enabled.

webapp Red Team

clamav

Anti-virus utility for Unix - command-line interface

uncategorized Red Team

clamscanlogparser

This is a utility to parse a Clam Anti Virus log file, in order to sort them into a malware archive for easier maintanen

malware Blue Team

ClearImage Barcode Reader

Web-based barcode and QR code recognition tool using Inlite Research ClearImage technology for common image and document formats.

encoding-decoding

ClearWebStats.com

Public site-statistics index showing traffic and rank snapshots for domains.

domain-name

cleverhans

Python library to benchmark machine learning systems vulnerability to adversarial examples.

ai Red Team

climber

Check UNIX/Linux systems for privilege escalation.

scanner Red Team

cloakify

Data Exfiltration In Plain Sight; Evade DLP/MLS Devices; Social Engineering of Analysts; Evade AV Detection.

misc Red Team

cloud-buster

A tool that checks Cloudflare enabled sites for origin IP leaks.

recon Red Team

Cloud Custodian (T)

Policy-as-code engine for cloud governance and security that can detect and remediate risky cloud configurations.

cloud-infrastructure

cloud-enum

Multi-cloud open source intelligence tool

uncategorized Red Team

cloud_enum (T)

Multi-cloud enumeration tool that looks for exposed AWS, Azure, and GCP storage assets from target naming patterns.

cloud-infrastructure

cloudbrute

Awesome cloud enumerator (program)

uncategorized Red Team

cloudfail

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network.

recon Red Team

CloudFail (T)

Tool for finding origin IPs of Cloudflare-protected websites through enumeration techniques.

ip-mac-address

cloudflare-enum

Cloudflare DNS Enumeration Tool for Pentesters.

scanner Red Team

CloudFlare Watch

Tool for identifying and analyzing websites protected by Cloudflare's CDN and security services.

ip-mac-address

cloudget

Python script to bypass cloudflare from command line. Built upon cfscrape module.

webapp Red Team

cloudlist

A tool for listing Assets from multiple Cloud Providers.

recon Red Team

cloudmapper

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

general

cloudmare

A simple tool to find origin servers of websites protected by CloudFlare with a misconfiguration DNS.

recon Red Team

cloudsplaining

AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

general

cloudsploit

AWS security scanning checks.

scanner Red Team

cloudunflare

Reconnaissance Real IP address for Cloudflare Bypass.

recon Red Team

clusterd

Automates the fingerprinting, reconnaissance, and exploitation phases of an application server attack.

automation Red Team

cminer

A tool for enumerating the code caves in PE files.

binary Red Team

cmloot

cmloot.py is built to aid penetration testers to search and find sensitive files in Configuration Manager's complex file share structure.

ad

cmospwd

Decrypt BIOS passwords from CMOS

password-cracking Red Team

cms-explorer

Designed to reveal the specific modules, plugins, components and themes that various cms driven websites are running.

fingerprint Red Team

cms-few

Joomla, Mambo, PHP-Nuke, and XOOPS CMS SQL injection vulnerability scanning tool written in Python.

webapp Red Team

cmseek

CMS Detection and Exploitation suite

uncategorized Red Team

cmsfuzz

Fuzzer for wordpress, cold fusion, drupal, joomla, and phpnuke.

webapp Red Team

cmsmap

A python open source Content Management System scanner that automates the process of detecting security flaws of the mos

scanner Red Team

cmsscan

CMS scanner to identify and find vulnerabilities for Wordpress, Drupal, Joomla, vBulletin.

webapp Red Team

cmsscanner

CMS Scanner Framework.

webapp Red Team

cnamulator

A phone CNAM lookup utility using the OpenCNAM API.

mobile Red Team

cntlm

Fast NTLM authentication proxy with tunneling

uncategorized Red Team

Cobalt Strike Configuration Extractor (CSCE) and Parser <a href="#csce" id="csce"></a>

Analyze Cobalt Strike beacons.

deobfuscation Blue Team

code-oss

Open Source package of vscode

resource-development services-and-other-tools Red Team

codecrypt

A GnuPG-like program for encryption and signing that uses only quantum-computer-resistant algorithms

crypto Red Team

codeql

The CLI tool for GitHub CodeQL

automation Red Team

codetective

A tool to determine the crypto/encoding algorithm used according to traces of its representation.

crypto Red Team

codetrack

CodeTrack is a free .NET Performance Profile and Execution Analyzer.

dotnet Blue Team

coercer

Coerce a Windows server to authenticate on an arbitrary machine

uncategorized Red Team

colly

Elegant Scraper and Crawler Framework for Golang (program)

uncategorized Red Team

comission

WhiteBox CMS analysis.

webapp Red Team

command-not-found

Suggest installation of packages in interactive bash sessions

uncategorized Red Team

commentor

Extract all comments from the specified URL resource.

webapp Red Team

Commercial Register - Worldwide

Canton of St. Gallen (Switzerland) official commercial register, providing a searchable database of businesses registered in the canton.

business-records

commix

Automated All-in-One OS Command Injection and Exploitation Tool

initial-access Red Team

commix-git

Find and exploit a command injection vulnerability in a certain vulnerable parameter or string.

webapps Red Team

Common Crawl

Open repository of large-scale web crawl data published as monthly WARC datasets.

archives

commonspeak

Leverages publicly available datasets from Google BigQuery to generate wordlists.

automation Red Team

Comms Analyzer Toolbox (T)

Open-source toolkit for forensic analysis of communication archives with Elasticsearch/Kibana dashboards for message timelines and pattern analysis.

instant-messaging

Companies House

Official UK government company registry for England, Wales, Scotland, and Northern Ireland. Provides free access to company filings, officers, and…

business-records

Companies House (R)

Official UK government register for searching company information, officer appointments, and disqualified directors across all UK-registered…

compliance-risk-intelligence

Companies In The UK

UK company search engine aggregating information from Companies House, providing easy lookup of registered UK businesses.

business-records

Company Data Rex (EU)

European company data aggregation platform providing business intelligence on EU-registered companies from multiple national registries.

business-records

compp

Company Passwords Profiler helps making a bruteforce wordlist for a targeted company.

cracker Red Team

configpush

This is a tool to span /8-sized networks quickly sending snmpset requests with default or otherwise specified community

scanner Red Team

conn

Small C library usefull to easy build ipv4/ipv6 network daemons/clients

uncategorized Red Team

conpass

Password spraying in AD environment avoing account locking.

windows Red Team

conpot

ICS honeypot with the goal to collect intelligence about the motives and methods of adversaries targeting industrial con

honeypot Blue Team

conscan

A blackbox vulnerability scanner for the Concre5 CMS.

fuzzer Red Team

constellation

Find and exploit vulnerabilities in mobile applications.

osint web Red Team

cook

Easily create word's permutation and combination to generate complex wordlists and passwords.

automation Red Team

cookie-cadger

An auditing tool for Wi-Fi or wired Ethernet connections.

fuzzer Red Team

cookiejar

Cookiecutter templates discovery and management.

uncategorized Red Team

copy-router-config

Copies Cisco configs via SNMP

cisco-tools collection Red Team

Copyleaks

Plagiarism and AI-generated content detection platform that checks text against web sources and AI writing patterns across multiple languages.

ai-tools

Copyscape Plagiarism Checker

Online plagiarism detection service that searches the web for copies of submitted text or URLs; useful for verifying content originality or tracing…

search-engines

Corona

Access point for historical CORONA-era satellite imagery used in long-range change analysis.

geolocation-tools-maps

corscanner

Fast CORS misconfiguration vulnerabilities scanner.

webapp Red Team

corstest

A simple CORS misconfigurations checker.

scanner Red Team

corsy

CORS Misconfiguration Scanner.

webapp Red Team

cosign

Code signing/transparency for containers and binaries (program)

uncategorized Red Team

cottontail

Capture all RabbitMQ messages being sent through a broker.

sniffer Red Team

country-ip-blocks

CIDR country-level IP data, straight from the Regional Internet Registries, updated hourly.

wordlist Red Team

covenant-kbx

.NET command and control framework

uncategorized Red Team

cowpatty

Brute-force WPA dictionary attack

wifi-credential-access Red Team

cowrie

cowrie honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

cpfinder

Simple script that looks for administrative web interfaces.

scanner Red Team

cpp2il

A tool to reverse unity's IL2PP toolchain

binary Red Team

cpptest

A portable and powerful, yet simple, unit testing framework for handling automated tests in C++.

code-audit Red Team

cpublaster

This library tries to intercept the memory allocations to skew the allocations to different offsets, so the performance penalty to disappear

uncategorized Red Team

cr3dov3r

Search for public leaks for email addresses + check creds against 16 websites.

recon Red Team

cr3dov3r-git

Your best friend in credential reuse attacks

social-engineering Red Team

crabstick

Automatic remote/local file inclusion vulnerability analysis and exploit tool.

webapp Red Team

crack

Password guessing program (crypt() variant)

uncategorized Red Team

cracken

A ast password wordlist generator, Smartlist creation and password hybrid-mask analysis tool written in pure safe Rust.

misc Red Team

crackhor

A Password cracking utility.

cracker Red Team

crackhound

A fast WPA/WPA2/WPA3 WiFi Handshake capture / password recovery and analysis tool

ad

crackle

Crack and decrypt BLE encryption

password-cracking Red Team

crackle-git

Crack and decrypt BLE encryption

crackers Red Team

crackmapexec

Swiss army knife for pentesting networks

pass-the-hash brute-force network-share-discovery lateral-movement application-layer-protocol Red Team

crackmapexec-pingcastle

NetExec & CrackMapExec module that execute PingCastle on a remote machine.

windows Red Team

crackpkcs12

A multithreaded program to crack PKCS#12 files (p12 and pfx extensions).

cracker Red Team

crackq

Hashcrack.org GPU-accelerated password cracker.

cracker Red Team

crackql

GraphQL password brute-force and fuzzing utility

webapp Red Team

crackserver

An XMLRPC server for password cracking.

cracker Red Team

crawlic

Web recon tool (find temporary files, parse robots.txt, search folders, google dorks and search domains hosted on same s

webapp Red Team

creak

Poison, reset, spoof, redirect MITM script.

networking Red Team

create_ap

A shell script to create a NATed/Bridged Software Access Point.

wireless Red Team

creddump

A python tool to extract various credentials and secrets from Windows registry hives.

cracker Red Team

creddump7

Python tool to extract credentials and secrets from Windows registry hives

os-credential-dumping Red Team

Credit Freeze

Intel Techniques tutorial covering the complete process for freezing credit at all major and specialty bureaus to prevent identity theft and data…

opsec

credmap

The Credential mapper - Tool that was created to bring awareness to the dangers of credential reuse.

misc Red Team

credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and be

cracker Red Team

creds

Harvest FTP/POP/IMAP/HTTP/IRC credentials along with interesting data from each of the protocols.

sniffer Red Team

creds.py-git

Harvest FTP/POP/IMAP/HTTP/IRC credentials along with interesting data from each of the protocols.

bruteforce Red Team

credsniper

Phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA toke

social Red Team

cri-tools

Command line tool used for creating OCI images

uncategorized Red Team

cribdrag

An interactive crib dragging tool for cryptanalysis on ciphertext generated with reused or predictable stream cipher key

crypto Red Team

Criminal IP Search

Cyber threat intelligence search engine for exposed assets, domains, vulnerabilities, and risk indicators.

domain-name ip-mac-address

crlf-injector

A python script for testing CRLF injecting issues.

fuzzer Red Team

crlfuzz

Fast tool to scan CRLF vulnerability written in Go

web-vulnerability-scanning Red Team

crosslinked

LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping.

social Red Team

crowbar

Brute forcing tool

brute-force Red Team

crozono

A modular framework designed to automate the penetration testing of wireless networks from drones and such unconventiona

drone Red Team

crt.sh - Certificate Search

CT log viewer aggregating certificate data from multiple Certificate Transparency logs. Search for all certificates ever issued to a domain to…

domain-name

crunch

Tool for creating wordlist

password-profiling-wordlists credential-access Red Team

Crunchbase

Leading startup and investment intelligence platform tracking company funding rounds, acquisitions, investors, and executive profiles.

business-records

cryptcat

Lightweight version netcat extended with twofish encryption

uncategorized Red Team

crypthook

TCP/UDP symmetric encryption tunnel wrapper.

crypto Red Team

crypthook-git

A TCP/UDP symmetric encryption tunnel wrapper

misc Red Team

cryptmount

Utility which allows an ordinary user to mount an encrypted file system

crypto Red Team

cryptohazemultiforcer

High performance multihash brute forcer with CUDA support.

cracker Red Team

Cryptome

Long-running disclosure archive hosting leaked or hard-to-find government, intelligence, and policy documents.

archives

cryptonark

SSL security checker.

crypto Red Team

cryptotester

Utility tool for performing cryptanalysis with a focus on ransomware cryptography

utilities Blue Team

cryptsetup

Disk encryption support - startup scripts

uncategorized Red Team

cryptsetup-nuke-password

Erase the LUKS keys with a special password on the unlock prompt

uncategorized Red Team

cs-analyze-processdump.py

Analyze Cobalt Strike beacon process dumps to detect sleep mask encoding.

deobfuscation Blue Team

cs-decrypt-metadata.py

Decrypt Cobalt Strike metadata.

deobfuscation Blue Team

cs-extract-key.py

Extract AES and HMAC keys from Cobalt Strike beacon process memory.

deobfuscation Blue Team

cs-parse-traffic.py

Decrypt and parse Cobalt Strike beacon network traffic.

monitoring Blue Team

csdr

A simple DSP library and command-line tool for Software Defined Radio.

radio Red Team

cSploit

The most complete and advanced IT security professional toolkit on Android.

exploitation sniffing-spoofing Red Team

csrft-git

In few words, this is a simple HTTP Server in NodeJS that will communicate with the clients (victims) and send them payload that will be executed usin

uncategorized Red Team

csrftester

The OWASP CSRFTester Project attempts to give developers the ability to test their applications for CSRF flaws.

webapp Red Team

ct-exposer

An OSINT tool that discovers sub-domains by searching Certificate Transparency logs.

scanner Red Team

ctf-party

A CLI tool & library to enhance and speed up script/exploit writing for CTF players.

misc Red Team

ctunnel

Tunnel and/or proxy TCP or UDP connections via a cryptographic tunnel.

tunnel Red Team

ctypes-sh

Allows you to call routines in shared libraries from within bash.

reversing Blue Team

cubicsdr

Cross-Platform Software-Defined Radio Application.

radio Red Team

cudahashcat

Worlds fastest WPA cracker with dictionary mutation engine.

cracker Red Team

cupid-wpa

Fork of hostapd to exploit hertbleed vulnerability on wireless networks

uncategorized Red Team

cupp

Common User Password Profiler

cracker Red Team

cupp-git

Common User Password Profiler

crackers Red Team

Cupp (T)

Python utility that generates targeted password wordlists by profiling personal information to create customized password candidates for security…

tools

curl

Command line tool for transferring data with URL syntax

uncategorized Red Team

curlie

Curlie is a frontend to curl that adds the ease of use of httpie without compromising on features and performance

ad web

Current Location

Location-based photo discovery tool that aggregates geotagged images from public platforms on an interactive map.

images-videos-docs

cut-bytes.py

Cut out a part of a data stream.

deobfuscation Blue Team

cutecom

Graphical serial terminal, like minicom

uncategorized Red Team

Cutter

Reverse engineering platform powered by Rizin.

general Blue Team

cutycapt

Utility to capture WebKit’s rendering of a web page

reporting-tools Red Team

cve-api

Unofficial api for cve.mitre.org.

misc Red Team

cve-search

A tool to perform local searches for known vulnerabilities.

exploitation Red Team

cvechecker

The goal of cvechecker is to report about possible vulnerabilities on your system, by scanning the installed software an

scanner Red Team

cvemap

CLI tool designed to provide a structured and easily navigable interface to various vulnerability databases.

exploitation Red Team

CyberChef

Decode and otherwise analyze data using this browser app.

deobfuscation Blue Team

cybercrowl

A Python Web path scanner tool.

webapp Red Team

cyberscan

A Network Pentesting Tool.

networking Red Team

cymothoa

Stealth backdooring tool

persistence Red Team

cyperoth

Automated extensible toolset that runs cypher queries against Bloodhound's Neo4j backend and saves output to spreadsheets.

ad

d-tect

Pentesting the Modern Web.

scanner Red Team

daclsearch

Exhaustive search and flexible filtering of Active Directory ACEs

ad

dagon

Advanced Hash Manipulation.

crypto Red Team

Daily DNS Changes

DomainTools service monitoring DNS record changes across domains, detecting newly registered subdomains and tracking DNS infrastructure modifications.

domain-name

dalfox

Powerful open-source XSS scanner and utility focused on automation.

webapp Red Team

damm

Differential Analysis of Malware in Memory.

malware Blue Team

daredevil

A tool to perform (higher-order) correlation power analysis attacks (CPA).

crypto Red Team

dark-dork-searcher

Dark-Dork Searcher.

windows Red Team

darkarmour

Store and execute an encrypted windows binary from inside memory, without a single bit touching disk.

windows Red Team

darkbing

A tool written in python that leverages bing for mining data on systems that may be susceptible to SQL injection.

scanner Red Team

darkd0rk3r

Python script that performs dork searching and searches for local file inclusion and SQL injection errors.

exploitation Red Team

darkdump

Open Source Intelligence interface for Deep Web scraping.

webapp Red Team

darkjumper

This tool will try to find every website that host at the same server at your target.

webapp Red Team

darkmysqli

Multi-Purpose MySQL Injection Tool

exploitation Red Team

darkscrape

OSINT Tool For Scraping Dark Websites.

webapp Red Team

darkspiritz

A penetration testing framework for Linux, MacOS, and Windows systems.

exploitation Red Team

darkstat

Network traffic analyzer

network-sniffing Red Team

darm-git

An ARMv7 disassembling library written in C.

uncategorized Red Team

Data24-7 (R)

Commercial data enrichment provider supporting phone-based identity and risk intelligence lookups.

telephone-numbers

Databases.Today

Breach data discovery portal indexing exposed databases and leaked credential collections.

archives

datajackproxy

A proxy which allows you to intercept TLS traffic in native x86 applications across platform.

proxy Red Team

datasploit

Performs automated OSINT and more.

recon Red Team

davoset

A tool for using Abuse of Functionality and XML External Entities vulnerabilities on some websites to attack other websi

dos Red Team

davscan

Fingerprints servers, finds exploits, scans WebDAV.

webapp Red Team

davtest

Testing tool for WebDAV servers

web-vulnerability-scanning Red Team

dawnscanner

A static analysis security scanner for ruby written web applications.

webapp Red Team

DB-IP

Lightweight IP geolocation API covering 46M+ IPv4/IPv6 blocks with city-level accuracy.

ip-mac-address

dbd

Netcat clone with encryption

non-application-layer-protocol Red Team

dbeaver

Universal Database Manager and SQL Client

uncategorized Red Team

dbpwaudit

A Java tool that allows you to perform online audits of password quality for several database engines.

cracker Red Team

dbusmap

Simple utility for enumerating D-Bus endpoints, an nmap for D-Bus.

scanner Red Team

DC3-MWCP

Parsing configuration information from malware.

deobfuscation Blue Team

dc3dd

Patched version of GNU dd with forensic features

digital-forensics forensic-imaging-tools Blue Team

dcdetector

Spot all domain controllers in a Microsoft Active Directory environment. Find computer name, FQDN, and IP address(es) of

networking Red Team

dcfldd

Enhanced version of dd for forensics and security

digital-forensics forensic-imaging-tools Blue Team

dcrawl

Simple, but smart, multi-threaded web crawler for randomly gathering huge lists of unique domain names.

scanner Red Team

ddosify

High-performance load testing tool, written in Golang.

dos Red Team

ddospot

ddospot honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

ddrescue

Data recovery and protection tool

forensic-imaging-tools Blue Team

de4dot

.NET deobfuscator and unpacker.

windows Red Team

de4dot-cex

de4dot CEx is a de4dot fork with full support for vanilla ConfuserEx.

dotnet Blue Team

de4dotex

.NET deobfuscator and unpacker.

windows Red Team

Death Check

Directory of online death indexes, obituaries, and cemetery records. Aggregates links to state and national obituary databases.

public-records

deathstar

Automate getting Domain Admin using Empire.

automation Red Team

debinject

Inject malicious code into *.debs.

backdoor Red Team

deblaze

Performs method enumeration and interrogation against flash remoting end points.

scanner Red Team

debloat

Remove junk contents from bloated Windows executables.

pe-files Blue Team

decode-vbe.py

Decode encoded VBS scripts (VBE).

scripts Blue Team

decodify

Tool that can detect and decode encoded strings, recursively.

crypto Red Team

Decompyle++

Python bytecode disassembler and decompiler.

python Blue Team

Decopy AI Image Detector

AI image detection tool that analyzes photographs and graphics to identify signatures of AI generation from models like Midjourney, DALL-E, and…

ai-tools

deen

Generic data encoding/decoding application built with PyQt5.

crypto Red Team

DeepAI AI Image Detector

DeepAI's image authenticity classifier that detects whether an image was generated by an AI model or captured by a camera.

ai-tools

deepce

Docker Enumeration, Escalation of Privileges and Container Escapes.

exploitation Red Team

DeepFake-Detect

Open-source deepfake detection project built with PyTorch and ResNet18 for classifying manipulated media.

disinformation-media-verification

DeepfakeBench

Benchmark framework for deepfake detection with multiple datasets and standardized evaluation pipelines.

disinformation-media-verification

DeepfakeDetector

Open-source deepfake detector with EfficientNet-based models and a web-facing analysis workflow.

disinformation-media-verification

DeepL Translator

AI-powered machine translation service focused on high-quality translation with document support.

language-translation

DeepSafe

Containerized deepfake detection suite combining multiple models with both web and extension interfaces.

disinformation-media-verification

DeepSeek

Chinese open-source large language model and chat assistant offering competitive reasoning capabilities with free access for research and analysis…

ai-tools

defectdojo

Security orchestration and vulnerability management platform

system-services Red Team

DefiLlama

DeFi analytics platform aggregating Total Value Locked (TVL), yields, protocol revenue, and fees across 7000+ protocols on 500+ chains.

blockchain-cryptocurrency

DeHashed (R)

Modern breach search engine indexing historical breach data over a decade old, enabling searches by email, username, password, domain, phone, and IP…

email-address

delldrac

DellDRAC and Dell Chassis Discovery and Brute Forcer.

scanner Red Team

delorean

NTP Main-in-the-Middle tool.

exploitation Red Team

Delphi Forum Search

Forum platform with searchable user communities across niche interest categories.

online-communities

demiguise

HTA encryption tool for RedTeams.

crypto Red Team

densityscout

Calculates density for files of any file-system-path to finally output an accordingly descending ordered list.

misc Red Team

depant

Check network for services with default passwords.

cracker Red Team

depdep

A merciless sentinel which will seek sensitive files containing critical info leaking through your network.

networking Red Team

dependency-check

A tool that attempts to detect publicly disclosed vulnerabilities contained within a project's dependencies.

code-audit Red Team

dependencywalker

Scans PE files and builds a hierarchical tree diagram of all dependent modules

pe Blue Team

depix

A tool for recovering passwords from pixelized screenshots.

misc Red Team

der-ascii

A reversible DER and BER pretty-printer.

misc Red Team

derrick

Simple tool for recording data streams of TCP and UDP traffic.

logging Red Team

deskhpsdr

SDR App for HPSDR protocol and Soapy-API.

radio Red Team

det

(extensible) Data Exfiltration Toolkit.

networking Red Team

detect-it-easy

Program for determining types of files

uncategorized Red Team

Detect-It-Easy <a href="#detect-it-easy" id="detect-it-easy"></a>

Determine types of files and examine file properties.

general Blue Team

detect-secrets

An enterprise friendly way of detecting and preventing secrets in code.

code-audit Red Team

detect-sniffer

Tool that detects sniffers in the network.

defensive Blue Team

detectem

Detect software and its version on websites.

fingerprint Red Team

Deteque (R)

Real-time IP, domain, and threat intelligence from Spamhaus and abuse.ch alliance. Provides comprehensive malware, botnet, and abuse data with…

domain-name

detux Linux Sandbox

Open-source multiplatform Linux sandbox for analyzing Linux malware across multiple CPU architectures (x86, x86-64, ARM, MIPS) using QEMU emulation…

malicious-file-analysis

Deutsche Bahn Open-Data-Portal (German)

German rail open-data portal for station, network, timetable, and real-time transportation datasets.

transportation

devaudit

An open-source, cross-platform, multi-purpose security auditing tool targeted at developers and teams.

code-audit Red Team

device-pharmer

Opens 1K+ IPs or Shodan search results and attempts to login.

cracker Red Team

dex2jar

Tools to work with android .dex and java .class files

resource-development Red Team

dexpatcher

Modify Android DEX/APK files at source-level using Java.

mobile Red Team

DeXRAY

Extract and decode data from antivirus quarantine files.

gather-and-analyze-data Red Team

dfdatetime

Digital Forensics date and time library for Python 3

uncategorized Red Team

dff-scanner

Tool for finding path of predictable resource locations.

webapp Red Team

dfir-ntfs

An NTFS parser for digital forensics & incident response.

forensic Blue Team

dfscoerce

DFS-R target coercion tool

ad

dftimewolf

Framework for orchestrating forensic collection, processing and data export.

forensic Blue Team

dfvfs

Digital Forensics Virtual File System

uncategorized Red Team

dfwinreg

Digital Forensics Windows Registry library for Python 3

uncategorized Red Team

dga-detection

DGA Domain Detection using Bigram Frequency Analysis.

recon Red Team

dharma

Generation-based, context-free grammar fuzzer.

fuzzer Red Team

dhcdrop

Remove illegal dhcp servers with IP-pool underflow.

misc Red Team

dhcpf

Passive DHCP fingerprinting implementation.

fingerprint Red Team

dhcpig

DHCP exhaustion script using scapy network library

impact Red Team

dhcpoptinj

DHCP option injector.

networking Red Team

dicompot

dicompot honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

didier-stevens-beta

DidierStevensSuiteBeta is a collection of beta malware analysis tools by Didier Stevens.

documents Blue Team

didier-stevens-suite

Didier Stevens Suite.

uncategorized Red Team

die

DIE (Detect It Easy) is a tool for file type identification with signature-based and heuristic analysis.

file-information Blue Team

dilisense

AML compliance platform that screens individuals and entities against sanctions, PEP, and watchlist data sources with fuzzy matching and confidence…

compliance-risk-intelligence

dinouml

A network simulation tool, based on UML (User Mode Linux) that can simulate big Linux networks on a single PC

networking Red Team

dionaea

dionaea honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

dirb

URL bruteforcing tool

web-scanning reconnaissance Red Team

dirble

Fast directory scanning and scraping tool.

webapp Red Team

dirbuster

Web server directory brute-forcer

web-scanning reconnaissance Red Team

dirbuster-ng

C CLI implementation of the Java dirbuster tool.

webapp Red Team

directorytraversalscan

Detect directory traversal vulnerabilities in HTTP servers and web applications.

windows Red Team

dirhunt

Find web directories without bruteforce.

webapp Red Team

dirscanner

This is a python script that scans webservers looking for administrative directories, php shells, and more.

scanner Red Team

dirscraper

OSINT Scanning tool which discovers and maps directories found in javascript files hosted on a website.

webapp Red Team

dirsearch

Web path scanner

web-scanning Red Team

dirstalk

Modern alternative to dirbuster/dirb.

scanner Red Team

Disboard

Public Discord server discovery platform used to find communities by topic, language, and popularity.

instant-messaging

Discord Bot List

Searchable directory of Discord bots with listings, categories, and discovery metadata.

online-communities

DiscordOSINT (T)

GitHub repository of Discord investigation techniques, queries, and tooling references for OSINT workflows.

instant-messaging

disitool

Tool to work with Windows executables digital signatures.

forensic Blue Team

disitool.py

Extract, delete, copy, and inject digital signatures in PE files.

pe-files Blue Team

dislocker

Read/write encrypted BitLocker volumes

uncategorized Red Team

Disposable Email Domains (T)

Community-maintained blocklist of 5,000+ disposable email domains with allowlist support and multi-language implementation examples. Used by PyPI and…

email-address

Disposable Emails Registry

Searchable registry of disposable email domains with bulk download support for threat intelligence integration.

email-address

dissect

Perform a variety of forensics and incident response tasks using this DFIR framework and toolset.

gather-and-analyze-data Red Team

dissector

This code dissects the internal data structures in ELF files. It supports x86 and x86_64 archs and runs under Linux.

binary Red Team

distorm3

Powerful disassembler library for x86/AMD64 binary streams (runtime)

uncategorized Red Team

divideandscan

Advanced subdomain scanner

ad

dizzy

A Python based fuzzing framework with many features.

fuzzer Red Team

dkmc

Dont kill my cat - Malicious payload evasion tool.

exploitation Red Team

dll-to-exe

Converts a DLL into a ready-to-use EXE

pe Blue Team

dllcharacteristics.py

Read and set DLL characteristics of a PE file.

pe-files Blue Team

dmde

Disk Editor and Data Recovery Software.

forensic Blue Team

dmg2img

A CLI tool to uncompress Apple's compressed DMG files to the HFS+ IMG format.

forensic Blue Team

DMI-TCAT (T)

Twitter Capture and Analysis Toolset for collecting and analyzing Twitter datasets using self-hosted infrastructure.

social-networks

dmitry

Deepmagic Information Gathering Tool

network-information Red Team

dnfile

Analyze static properties of .NET files.

net Blue Team

dnlib

dnlib is a .NET module/assembly reader/writer library.

dotnet Blue Team

dnmap

The distributed nmap framework.

scanner Red Team

DNS Dumpster

Free domain research tool that discovers hosts and subdomains related to a domain. Provides DNS record enumeration (MX, TXT, Host) with a visual map…

domain-name

DNS Leak Tests

Alternative DNS leak testing service that identifies whether DNS requests bypass your VPN tunnel and expose your real ISP’s DNS servers.

opsec

dns-parallel-prober

PoC for an adaptive parallelised DNS prober.

recon Red Team

DNS Recon (T)

Python-based DNS enumeration script supporting zone transfers, standard record enumeration, TLD expansion, DNS brute force, and PTR lookups.

domain-name

dns-reverse-proxy

A reverse DNS proxy written in Go.

proxy Red Team

dns-spoof

Yet another DNS spoof utility.

spoof Red Team

dns-spoof-git

DNS Spoof

dns Red Team

DNS Twist (T)

Domain name permutation engine for detecting homograph phishing attacks and typosquatting with fuzzy hashing.

domain-name

dns2geoip

A simple python script that brute forces DNS and subsequently geolocates the found subdomains.

scanner Red Team

dns2tcp

TCP-over-DNS tunnel server and client

protocol-tunneling Red Team

dnsa

A dns security swiss army knife.

scanner Red Team

dnsbf

Search for available domain names in an IP range.

scanner Red Team

dnsbrute

Multi-theaded DNS bruteforcing, average speed 80 lookups/second with 40 threads.

recon Red Team

dnscan

A python wordlist-based DNS subdomain scanner.

scanner Red Team

dnscat2

DNS tunnel (metapackage)

protocol-tunneling Red Team

dnschef

DNS proxy for penetration testers

network-sniffing Red Team

dnscobra

DNS subdomain bruteforcing tool with Tor support through torsocks.

recon Red Team

dnsdiag

DNS Diagnostics and Performance Measurement Tools.

networking Red Team

dnsdrdos

Proof of concept code for distributed DNS reflection DoS.

dos Red Team

dnsenum

Tool to enumerate domain DNS information

network-information-dns Red Team

dnsfilexfer

File transfer via DNS.

networking Red Team

dnsgen

DNS generator

uncategorized Red Team

dnsgoblin

Nasty creature constantly searching for DNS servers. It uses standard dns querys and waits for the replies.

scanner Red Team

dnsgrep

A utility for quickly searching presorted DNS names.

recon Red Team

dnslib

Python library to encode/decode DNS wire-format packets.

gather-and-analyze-data Red Team

dnsmap

DNS domain name brute forcing tool

network-information-dns Red Team

dnsobserver

A handy DNS service written in Go to aid in the detection of several types of blind vulnerabilities.

networking Red Team

dnspop (T)

DNS reconnaissance utility for enumerating records and identifying domain-related infrastructure.

domain-name

dnspredict

DNS prediction.

scanner Red Team

dnsprobe

Allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.

recon Red Team

dnspy

.NET debugger and assembly editor.

windows Red Team

dnspyex

dnSpyEx is a unofficial continuation of the dnSpy project which is a debugger and .NET assembly editor.

dotnet Blue Team

dnsrecon

Powerful DNS enumeration script

network-information-dns Red Team

dnsrecon (T)

DNS enumeration script for recon workflows, supporting record discovery, zone transfer checks, brute-force, and reverse lookups.

cloud-infrastructure

dnsresolver.py

DNS resolver tool for dynamic analysis with wildcard and tracking support.

services Blue Team

dnssearch

A subdomain enumeration tool.

recon Red Team

DNSSEC Analyzer

Verisign's DNSSEC validation tool that checks the DNSSEC chain of trust for a domain.

domain-name

dnsspider

A fast multithreaded bruteforcer of subdomains that leverages a wordlist and/or character permutation.

recon Red Team

DNSstuff

Suite of free DNS and network tools providing lookups, DNS checks, and WHOIS information for domain reconnaissance.

domain-name

dnsteal

DNS Exfiltration tool for stealthily sending files over DNS requests..

networking Red Team

dnstracer

Trace DNS queries to the source

network-information-dns Red Team

dnstwist

Domain name permutation engine

uncategorized Red Team

dnstwister

Web-based domain permutation tool with free lookup and paid monitoring plans for typosquatting detection.

domain-name

dnsvalidator

Maintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses.

networking Red Team

DNSViz

DNS and DNSSEC analysis platform that visualizes delegation chains and cryptographic validation paths. Helps diagnose trust and signing issues in…

domain-name

dnswalk

Checks dns zone information using nameserver lookups

network-information-dns Red Team

dnswatch

DNS Traffic Sniffer and Analyzer.

sniffer Red Team

dnsx

Perform multiple dns queries

uncategorized Red Team

docem

Uility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids).

webapp Red Team

Docker

Run and manage containers.

general-utilities Blue Team

dockerscan

Docker security analysis & hacking tools.

scanner Red Team

DocMind AI

Open-source local LLM-powered document analysis tool for querying and summarizing documents using locally running language models via LangChain.

ai-tools

Document Scanner

to scan documents

desktop-edition

domain-analyzer

Finds all the security information for a given domain name.

recon Red Team

Domain Dossier

Free web-based tool that aggregates WHOIS, DNS, and network information for domains and IP addresses into a single consolidated report.

domain-name

domain-stats

A web API to deliver domain information from whois and alexa.

recon Red Team

Domaincrawler.com

Enterprise-grade domain database covering 1.4+ billion registered and unregistered domains with 80+ billion historical records since 2008. Used by…

domain-name

domained

Multi Tool Subdomain Enumeration.

recon Red Team

domainhunter

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing a

recon Red Team

domainIQ

Comprehensive domain intelligence platform offering reverse lookups, ownership history, and related domain discovery. Trusted by government agencies,…

domain-name

DomainTools Whois

Enterprise-grade WHOIS API with decades of historical domain data and rapid query response. The industry leader for threat intelligence and domain…

domain-name

domato

DOM fuzzer.

fuzzer Red Team

domi-owned

A tool used for compromising IBM/Lotus Domino servers.

webapp Red Team

domlink

A tool to link a domain with registered organisation names and emails, to other domains.

misc Red Team

donpapi

Dumping revelant information on compromised targets without AV detection with DPAPI.

windows Red Team

dontgo403

Tool to bypass 40X response codes..

webapp Red Team

donut

Generates x86, x64 or AMD64+x86 P.I. shellcode loading .NET Assemblies from memory.

backdoor Red Team

donut-shellcode

Generates position-independent shellcode from memory and runs them

resource-development defense-evasion Red Team

doona

Network fuzzer forked from bed

uncategorized Red Team

doona-git

A fork of the Bruteforce Exploit Detector Tool (BED).

fuzzers Red Team

doork

Passive Vulnerability Auditor.

webapp Red Team

doozer

A Password cracking utility.

cracker Red Team

dorkbot

Command-line tool to scan Google search results for vulnerabilities.

scanner Red Team

dorkme

Tool designed with the purpose of making easier the searching of vulnerabilities with Google Dorks, such as SQL Injectio

scanner Red Team

dorknet

Selenium powered Python script to automate searching for vulnerable web apps.

webapp Red Team

dorkscout

Golang tool to automate google dork scan against the entire internet or specific targets.

automation Red Team

dos2unix

Convert text file line endings between CRLF and LF

uncategorized Red Team

dotdotpwn

Directory Traversal Fuzzer.

uncategorized Red Team

dotdumper

DotDumper is an automatic unpacker and logger for DotNet Framework targeting files.

dotnet Blue Team

dotnetfile

Analyze static properties of .NET files.

net Blue Team

dotpeek

Free .NET Decompiler and Assembly Browser.

windows Red Team

dpeparser

Default password enumeration project

cracker Red Team

dploot

Python rewrite of SharpDPAPI

uncategorized Red Team

dpscan

Drupal Vulnerability Scanner.

scanner Red Team

dr-checker

A Soundy Vulnerability Detection Tool for Linux Kernel Drivers.

exploitation Red Team

dr0p1t-framework

A framework that creates a dropper that bypass most AVs, some sandboxes and have some tricks.

backdoor Red Team

dracnmap

Tool to exploit the network and gathering information with nmap help.

automation Red Team

dradis

Collaboration tools for penetration testing

reporting-tools system-services Red Team

dradis-ce

An open source framework to enable effective information sharing.

recon Red Team

dragon-backdoor

A sniffing, non binding, reverse down/exec, portknocking service Based on cd00r.c.

backdoor Red Team

driftnet

Picks out and displays images from network traffic

network-sniffing Red Team

drinkme

A shellcode testing harness.

exploitation Red Team

dripcap

Caffeinated Packet Analyzer.

networking Red Team

dripper

A fast, asynchronous DNS scanner; it can be used for enumerating subdomains and enumerating boxes via reverse DNS.

scanner Red Team

dripper-git

A fast, asynchronous DNS scanner; it can be used for enumerating subdomains and enumerating boxes via reverse DNS

scanners Red Team

DriveDroid

Allows you to boot your PC from ISO/IMG files stored on your phone.

usb-misc

DroidLysis

Perform static analysis of Android applications.

general Blue Team

droopescan

A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstr

webapp Red Team

drozer

A security testing framework for Android - Precompiled binary from official repository.

mobile Red Team

drupal-module-enum

Enumerate on drupal modules.

webapp Red Team

drupalscan

Simple non-intrusive Drupal scanner.

webapp Red Team

drupwn

Drupal enumeration & exploitation tool.

webapp Red Team

dscan

Wrapper around nmap

uncategorized Red Team

dsd

Digital Speech Decoder.

misc Red Team

dsd-fme

Digital Speech Decoder - Florida Man Edition.

misc Red Team

dsfs

A fully functional File inclusion vulnerability scanner (supporting GET and POST parameters) written in under 100 lines

webapp Red Team

dshell

A network forensic analysis framework.

forensic Blue Team

DShield API

API and database of security events and IPs involved in attacks monitored by SANS.

ip-mac-address

dsjs

A fully functional JavaScript library vulnerability scanner written in under 100 lines of code.

webapp Red Team

dsniff

Various tools to sniff network traffic for cleartext insecurities

network-sniffing Red Team

dsss

A fully functional SQL injection vulnerability scanner (supporting GET and POST parameters) written in under 100 lines o

webapp Red Team

dsstore-crawler

A parser + crawler for .DS_Store files exposed publically.

webapp Red Team

dsxs

A fully functional Cross-site scripting vulnerability scanner (supporting GET and POST parameters) written in under 100

webapp Red Team

dtp-spoof

Python script/security tool to test Dynamic Trunking Protocol configuration on a switch.

networking Red Team

dtrx

Do The Right eXtraction - don't remember what set of tar flags or where to pipe the output to extract it? no worries!

ad osint web Red Team

Dual Maps

Dual-pane map viewer for side-by-side comparison of basemaps and imagery.

geolocation-tools-maps

dublin-traceroute

NAT-aware multipath tracerouting tool.

networking Red Team

DuckDuckGo

Privacy-focused search engine that doesn't track users or store personal data. Processes ~3 billion queries monthly with enhanced privacy protections…

search-engines

DuckDuckGo AI Chat

Privacy-focused AI chat interface by DuckDuckGo that proxies conversations through multiple LLMs without tying them to user identity or storing them.

ai-tools

ducktoolkit

Encoding Tools for Rubber Ducky.

exploitation Red Team

dufflebag

Search exposed EBS volumes for secrets (program)

uncategorized Red Team

Duke Reporters' Lab

Duke University journalism lab tracking global fact-checking initiatives, tools, and ecosystem trends.

disinformation-media-verification

dumb0

A simple tool to dump users in popular forums and CMS.

automation Red Team

dump1090

A simple Mode S decoder for RTLSDR devices.

networking Red Team

dumpacl

Dumps NTs ACLs and audit settings.

windows Red Team

dumpsmbshare

A script to dump files and folders remotely from a Windows SMB share.

misc Red Team

dumpsterdiver

Tool to analyze big volumes of data in search of hardcoded secrets

uncategorized Red Team

dumpusers

Dumps account names and information even though RestrictAnonymous has been set to 1.

windows Red Team

dumpzilla

Mozilla browser forensic tool

uncategorized Red Team

Dune Analytics

Onchain data analytics platform enabling SQL queries against indexed blockchain data for 100+ blockchains with interactive dashboard and…

blockchain-cryptocurrency

dupdump

Finds duplicat files and directories and outputs a parsable list that can be used to delete them

uncategorized Red Team

duplicut

Remove duplicates from massive wordlist, without sorting it (for dictionnary-based password cracking).

misc Red Team

dutas

Analysis PE file or Shellcode.

binary Red Team

dvcs-ripper

Rip web accessible (distributed) version control systems: SVN/GIT/BZR/CVS/HG.

scanner Red Team

dvcs-ripper-git

Rip web accessible (distributed) version control systems: SVN/GIT/...

misc Red Team

dvwa

Damn Vulnerable Web Application

laboratories system-services Red Team

dwarf

Full featured multi arch/os debugger built on top of PyQt5 and frida.

binary Red Team

dwarf2json

Utility to generat volatility 3 Intermediate Symbol File (ISF) JSON

uncategorized Red Team

dynamorio

A dynamic binary instrumentation framework.

binary Red Team

eapeak

Analysis Suite For EAP Enabled Wireless Networks.

wireless Red Team

eaphammer

Toolkit for targeted evil twin attacks against WPA2-Enterprise networks

uncategorized Red Team

eapmd5pass

Tool for extracting and cracking EAP-MD5

wifi-credential-access Red Team

EarthExplorer

USGS portal for Landsat, Sentinel, and other earth observation datasets.

geolocation-tools-maps

easy-creds

A bash script that leverages ettercap and other tools to obtain credentials.

automation Red Team

easyda

Easy Windows Domain Access Script.

automation Red Team

easyfuzzer

A flexible fuzzer, not only for web, has a CSV output for efficient output analysis (platform independent).

fuzzer Red Team

easyWhois

Free domain WHOIS lookup and DNS tools service. Now operated under the DomainHelp platform, providing domain registration information and DNS lookups.

domain-name

eazy

This is a small python tool that scans websites to look for PHP shells, backups, admin panels, and more.

scanner Red Team

ecfs

Extended core file snapshot format.

binary Red Team

edb

A cross platform AArch32/x86/x86 debugger.

debugger Red Team

edb-debugger

Cross platform x86/x86-64 debugger

resource-development Red Team

eggshell

iOS/macOS/Linux Remote Administration Tool.

backdoor Red Team

eHarmony

Personality-based matchmaking platform focused on long-term relationships with curated compatibility-driven pairings.

dating

eigrp-tools

This is a custom EIGRP packet generator and sniffer developed to test the security and overall operation quality of this

sniffer Red Team

eindeutig

Examine the contents of Outlook Express DBX email repository files.

forensic Blue Team

eksctl

Official CLI for Amazon EKS (program)

uncategorized Red Team

ElastAlert 2

ElastAlert 2 is a simple framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch.

network-security-monitoring Blue Team

Elastic Agent

With Elastic Agent you can collect all forms of data from anywhere with a single unified agent per host.

network-security-monitoring Blue Team

Elastic Stack

to beautifully visualize all the events captured by T-Pot.

network-monitoring Blue Team

elasticpot

elasticpot honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

Elasticsearch

An index template is a way to tell Elasticsearch how to configure an index when it is created.

network-security-monitoring Blue Team

Elasticvue

a web front end for browsing and interacting with an Elasticsearch cluster.

network-monitoring Blue Team

electric-fence

A malloc(3) debugger that uses virtual memory hardware to detect illegal memory accesses.

debugger Red Team

Electrum

an easy-to-use bitcoin client

networking

elettra

A plausible deniable cryptography tool that supports a dynamic number of files and requires a password for each file.

misc Red Team

elettra-gui

Gui for the elettra crypto application.

misc Red Team

elevate

Horizontal domain discovery tool you can use to discover other domains owned by a given company.

recon Red Team

elfparser

Cross Platform ELF analysis.

binary Red Team

elidecode

A tool to decode obfuscated shellcodes using the unicorn-engine for the emulation and the capstone-engine to print the a

reversing Blue Team

elidecode-git

A tool to decode obfuscated shellcodes using the unicorn-engine for the emulation and the capstone-engine to print the asm code

debugging Red Team

elite-proxy-finder

Finds public elite anonymity proxies and concurrently tests them.

proxy Red Team

Email Domain Validation

Free email domain validation tool checking DNS records, MX records, and mail server connectivity.

domain-name

Email Format

Tool for analyzing and discovering corporate email address patterns and formats to predict valid employee email addresses within an organization.

email-address

Email Leak Tests

Tests whether your email client or webmail service leaks your real IP address in email headers when sending messages.

opsec

Email Reputation

Tool that checks email reputation, risk scoring, and breach history to identify phishing emails, compromised accounts, and risky addresses.

email-address

Email to Address (R)

Melissa.com's data quality and verification service that validates and enriches email addresses with supplementary contact information.

email-address

email2phonenumber

OSINT tool to obtain a target’s phone number by having their email address

identity-information Red Team

Email2WhatsApp (T)

OSINT utility for correlating email addresses to potential WhatsApp identifiers and account traces.

instant-messaging

emailharvester

Email addresses harvester

identity-information Red Team

emldump

Analyze MIME files.

forensic Blue Team

emldump.py

Parse and analyze EML files.

email-messages Blue Team

emp3r0r

Linux post-exploitation framework made by linux user.

automation Red Team

empire

A PowerShell and Python post-exploitation agent.

automation Red Team

enabler

Attempts to find the enable password on a cisco system via brute force.

cracker Red Team

encodeshellcode

This is an encoding tool for 32-bit x86 shellcode that assists a researcher when dealing with character filter or byte r

exploitation Red Team

endlessh

endlessh honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

ent

Pseudorandom number sequence test.

misc Red Team

enteletaor

Message Queue & Broker Injection tool that implements attacks to Redis, RabbitMQ and ZeroMQ.

exploitation Red Team

entropy

A set of tools to exploit Netwave and GoAhead IP Webcams.

exploitation Red Team

enum-shares

Tool that enumerates shared folders across the network and under a custom user account.

scanner Red Team

enum4linux

Enumerates info from Windows and Samba systems

network-share-discovery discovery Red Team

enum4linux-ng

Next generation version of enum4linux

network-share-discovery Red Team

enum4linux-ng-git

A next generation version of enum4linux

recon Red Team

enumerate-iam

Enumerate the permissions associated with an AWS credential set.

recon Red Team

enumerid

Enumerate RIDs using pure Python.

recon Red Team

enumiax

IAX protocol username enumerator

voip-credential-access Red Team

enyelkm

Rootkit for Linux x86 kernels v2.6.

backdoor Red Team

enyx

Framework for building offensive security tools.

ad

eos

Enemies Of Symfony - Debug mode Symfony looter.

webapp Red Team

EPIC IRC Client

Examine IRC activities with this IRC client.

connecting Blue Team

epicwebhoneypot

Tool which aims to lure attackers using various types of web vulnerability scanners by tricking them into believing that

webapp Red Team

Epstein Exposed

Comprehensive searchable database of Epstein case documents including court records, flight logs, emails, and financial records.

public-records

erase-registrations

An IAX flooder.

voip Red Team

eraser

Windows tool which allows you to completely remove sensitive data from your hard drive by overwriting it several times w

windows Red Team

eresi

The ERESI Reverse Engineering Software Interface.

binary Red Team

erl-matter

Tool to exploit epmd related services such as rabbitmq, ejabberd and couchdb by bruteforcing the cookie and gaining RCE

exploitation Red Team

espionage

A Network Packet and Traffic Interceptor For Linux. Sniff All Data Sent Through a Network.

sniffer Red Team

eternal-scanner

An internet scanner for exploit CVE-0144 (Eternal Blue).

scanner Red Team

Ether

Georgia Tech malware analysis framework using Intel VT hardware virtualization for transparent, stealthy malware analysis resistant to anti-analysis…

malicious-file-analysis

etherchange

Can change the Ethernet address of the network adapters in Windows.

windows Red Team

etherflood

Floods a switched network with Ethernet frames with random hardware addresses.

windows Red Team

Etherscan

Leading blockchain explorer, analytics, and API platform for Ethereum and 60+ EVM-compatible chains with comprehensive smart contract interaction…

blockchain-cryptocurrency

Etherscan NFT Tracker

NFT-specific section of Etherscan for tracking ERC-721 and ERC-1155 token transfers, marketplace activities, and collection-level statistics.

blockchain-cryptocurrency

ethtool

Display or change Ethernet device settings

uncategorized Red Team

etl-parser

Parse Windows Event Trace Log (ETL) files.

gather-and-analyze-data Red Team

eTools.ch

Swiss privacy-focused metasearch engine aggregating 14+ sources (Google, Bing, Brave, DuckDuckGo, Yandex, etc.) simultaneously. Fast results…

search-engines

ettercap

Multipurpose sniffer/interceptor/logger for switched LAN

collection Red Team

EVENmonitor

Monitor the Windows Event Log with grep-like features or filtering for specific Event IDs

ad

Every Politician

Open data project aggregating politician information globally. Structured data on politicians, positions, and affiliations.

public-records

EveryPolitician

Global database of political office-holders now operated as part of the OpenSanctions project, providing structured data on politicians and public…

compliance-risk-intelligence

evil-ssdp

Spoof SSDP replies to phish for NTLM hashes on a network

uncategorized Red Team

evil-winrm

Ultimate WinRM shell for hacking/pentesting

pass-the-hash lateral-movement application-layer-protocol Red Team

evil-winrm-py

Execute commands on remote Windows machines using WinRM

pass-the-hash Red Team

evilclippy

A cross-platform assistant for creating malicious MS Office documents.

exploitation Red Team

evilginx2

Man-in-the-middle attack framework

collection Red Team

evilgrade

Modular framework that takes advantage of poor upgrade implementations by injecting fake updates.

misc Red Team

evilgrade-git

Modular framework that takes advantage of poor upgrade implementations by injecting fake updates

misc Red Team

evilize

Tool to create MD5 colliding binaries.

cracker Red Team

evillimiter

Tool that limits bandwidth of devices on the same network without access.

networking Red Team

evilmaid

TrueCrypt loader backdoor to sniff volume password.

cracker Red Team

evilpdf

Embedding executable files in PDF Documents.

backdoor Red Team

evilwinrm

Tool to connect to a remote Windows system with WinRM.

ad light

Evince

View documents in a variety of formats, including PDF.

view-or-edit-files Blue Team

evine

Interactive CLI Web Crawler.

webapp Red Team

evtkit

Fix acquired .evt - Windows Event Log files (Forensics).

forensic Blue Team

Ewhois

Web WHOIS lookup utility for registration, registrar, and nameserver details.

domain-name

ex_pe_xor.py

Search an XOR'ed file for indications of executable binaries.

deobfuscation Blue Team

exabgp

The BGP swiss army knife of networking.

networking Red Team

exe2hex

Inline file transfer using in-built Windows tools (DEBUG.exe or PowerShell).

disassembler Blue Team

exe2hexbat

Convert EXE to bat

defense-evasion Red Team

exe2image

A simple utility to convert EXE files to JPEG images and vice versa.

backdoor Red Team

exegol-history

Credentials management for Exegol

ad light osint web Red Team

exeinfope

Exeinfo PE displays metadata for a variety of file types and identifies many executable packers.

file-information Blue Team

exescan

A tool to detect anomalies in PE (Portable Executable) files.

binary Red Team

exif

Utility to read / write and edit metadata in image / audio and video files

general

ExifEditor

Browser-based EXIF metadata viewer and editor for quick image metadata inspection or sanitization.

images-videos-docs

exiflooter

Finds geolocation on all image urls and directories

uncategorized Red Team

exifprobe

Read metadata from digital pictures

uncategorized Red Team

ExifTool

Tool to read from, write to, and edit EXIF metadata of various file types.

general Blue Team

ExifTool (T)

Widely used command-line toolkit for reading and writing EXIF, IPTC, XMP, and other metadata formats.

images-videos-docs

exitmap

A fast and modular scanner for Tor exit relays.

recon Red Team

exiv2

EXIF/IPTC/XMP metadata manipulation tool

uncategorized Red Team

Exiv2 (T)

Cross-platform library and CLI for reading and modifying EXIF, IPTC, XMP, and ICC metadata.

images-videos-docs

ExoneraTor

Tool for checking if an IP address belonged to Tor at a specific date.

ip-mac-address

expect

Automates interactive applications

uncategorized Red Team

expimp-lookup

Looks for all export and import names that contain a specified string in all Portable Executable in a directory tree.

binary Red Team

exploit-curation-git

Curated exploits mapped by LEM

uncategorized Red Team

exploit-db

The Exploit Database (EDB) – an ultimate archive of exploits and vulnerable software - A collection of hacks

exploitation Red Team

exploitdb

Searchable Exploit Database archive

resource-development Red Team

exploitdb-bin-sploits

The Exploit Database’s archive of binary exploits

uncategorized Red Team

exploitdb-papers

The Exploit Database’s archive of papers & ezines

resource-development Red Team

exploitpack

Exploit Pack - The next generation exploit framework.

exploitation Red Team

explorersuite

A suite of tools including CFF Explorer and a process viewer.

pe Blue Team

expose

A Dynamic Symbolic Execution (DSE) engine for JavaScript

binary Red Team

exrex

Irregular methods on regular expressions.

misc Red Team

ext3grep

Tool to help recover deleted files on ext3 filesystems

forensic-carving-tools Blue Team

ext4magic

Recover deleted files from ext3 or ext4 partitions

forensic-carving-tools Blue Team

extended-ssrf-search

Smart ssrf scanner using different methods like parameter brute forcing in post and get.

webapp Red Team

extractbitlockerkeys

Script to automatically extract the bitlocker recovery keys from a domain.

windows Red Team

extracthosts

Extracts hosts (IP/Hostnames) from files.

misc Red Team

extractusnjrnl

Tool to extract the $UsnJrnl from an NTFS volume.

forensic Blue Team

extreme_dumper

ExtremeDumper is a .NET Assembly Dumper from memory of processes.

dotnet Blue Team

extundelete

Utility to recover deleted files from ext3/ext4 partition

forensic-carving-tools Blue Team

eyeballer

Convolutional neural network for analyzing pentest screenshots.

misc Red Team

eyepwn

Exploit for Eye-Fi Helper directory traversal vulnerability

exploitation Red Team

eyewitness

Rapid web application triage tool

reporting-tools Red Team

eyewitness-git

designed to take screenshots of websites, provide some server header info, and identify default credentials is possible

recon Red Team

EyeWitness (T)

Open-source tool for automated website screenshotting, service header collection, and default credential identification.

domain-name

EZR OSINT Sidebar (T)

Chrome extension providing integrated OSINT tools in a browser sidebar; extracts and documents images, emails, IPs, and metadata from web content.

documentation-evidence-capture

ezviewer

Ezviewer is a standalone, zero dependency document viewer and hex editor.

documents Blue Team

f-scrack

A single file bruteforcer supports multi-protocol.

cracker Red Team

facebash

Facebook Brute Forcer in shellscript using TOR.

social Red Team

facebookosint

OSINT tool to replace facebook graph search.

social Red Team

facebot

A facebook profile and reconnaissance system.

recon Red Team

facebrok

Social Engineering Tool Oriented to facebook.

social Red Team

facebrute

This script tries to guess passwords for a given facebook account using a list of passwords (dictionary).

cracker Red Team

FaceCheck Facial Recognition Search

Facial recognition search engine that finds publicly indexed face matches across web and social sources.

images-videos-docs

FaceCheckID

Reverse image face search engine that matches uploaded photos against social media, news, and mugshot databases to identify individuals.

people-search-engines

FaceForensics++

Academic deepfake forensics dataset with manipulated video samples, masks, and aligned benchmarks.

disinformation-media-verification

FaceSeek Face Search Engine

Face-matching web tool for locating visually similar faces across indexed online content.

images-videos-docs

factordb-pycli

CLI for factordb and Python API Client.

crypto Red Team

Fake Identity Generator

Generates random fake identities including names, addresses, and personal details for use in anonymous account creation and persona testing.

opsec

Fake Name Generator

Generates realistic synthetic identities including names, addresses, SSNs, and biographical details for persona creation during OSINT operations.

opsec

fakeap

Black Alchemy's Fake AP generates thousands of counterfeit 802.11b access points. Hide in plain sight amongst Fake AP's

honeypot Blue Team

fakedns

A regular-expression based python MITM DNS server with correct DNS request passthrough and "Not Found" responses.

proxy Red Team

fakedns-git

A regular-expression based python MITM DNS server with correct DNS request passthrough and "Not Found" responses.

spoof Red Team

fakemail

Fake mail server that captures e-mails as files for acceptance testing.

misc Red Team

fakenet-ng

Next Generation Dynamic Network Analysis Tool.

malware Blue Team

fakenetbios

A family of tools designed to simulate Windows hosts (NetBIOS) on a LAN.

spoof Red Team

fakenetbios-git

A Simulation of NetBIOS hosts (Windows-like)

fuzzers Red Team

Familywatchdog - Sex Offender Search

Free sex offender registry aggregator combining data from all US state registries. Interactive mapping of registered offenders.

public-records

fang

A multi service threaded MD5 cracker.

cracker Red Team

faraday-agent-dispatcher

Helper to develop integrations with Faraday (Python 3)

uncategorized Red Team

faraday-cli

Faraday on the terminal

uncategorized Red Team

faradaysec

Collaborative Penetration Test and Vulnerability Management Platform.

scanner Red Team

Farmers Only

Niche dating service for rural communities including farmers and ranchers with lifestyle-focused matching.

dating

fastnetmon

High performance DoS/DDoS load analyzer built on top of multiple packet capture engines.

defensive Blue Team

fatback

A *nix tool for recovering files from FAT file systems.

uncategorized Red Team

fatcat

FAT filesystem explore, extract, repair, and forensic tool

uncategorized Red Team

Fatt

a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic.

network-monitoring Blue Team

fav-up

IP lookup by favicon using Shodan.

recon Red Team

favfreak

Weaponizing favicon.ico for BugBounties , OSINT and what not.

recon Red Team

FB Email Search

Facebook public search pattern used to test whether an email identifier resolves to matching profiles. Useful for quick account existence checks with…

social-networks

FB Identify (Requires Logout)

Facebook identify endpoint used in recovery workflows to resolve account records from submitted identifiers; typically works best when not logged in.

social-networks

FB Lookup ID

Web utility that resolves Facebook profile, page, or group URLs into numeric Facebook IDs for downstream investigation tools.

social-networks

fbht

A Facebook Hacking Tool

webapp Red Team

fbi

An accurate facebook account information gathering.

social Red Team

fbid

Show info about the author by facebook photo url.

recon Red Team

fcrackzip

Password cracker for zip archives

password-cracking Red Team

fdisk

Collection of basic system utilities / including fdisk partitioning tool

general

fdsploit

A File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

webapp Red Team

featherduster

An automated, modular cryptanalysis tool.

crypto Red Team

Federal Inmate Locator

Bureau of Prisons official inmate search tool covering federal inmates 1982-present. Daily database updates with release dates.

public-records

Fedica

Social analytics platform with audience and engagement insights across multiple social networks.

social-networks

Fediverse Observer

Real-time dashboard tracking Fediverse instances across Mastodon, Pleroma, Misskey, PeerTube, and other ActivityPub platforms with server statistics…

social-networks

Fediverse_OSINT (T)

Python CLI tool for checking whether a domain belongs to the Fediverse and hunting usernames across discoverable Fediverse servers.

social-networks

feh

View images.

view-or-edit-files Blue Team

fern-wifi-cracker

Automated Wi-Fi cracker

wifi-credential-access Red Team

fern-wifi-cracker-git

WEP, WPA wifi cracker for wireless penetration testing

wireless Red Team

fernflower

An analytical decompiler for Java.

decompiler Blue Team

fernmelder

Asynchronous mass DNS scanner.

scanner Red Team

feroxbuster

Fast, simple, recursive content discovery tool written in Rust

web-scanning Red Team

ferret-sidejack

Monitors data and extracts interesting data

collection Red Team

ffm

A hacking harness that you can use during the post-exploitation phase of a red-teaming engagement.

exploitation Red Team

FFmpeg

to record and convert audio and video

encryption-and-privacy

ffuf

Fast web fuzzer written in Go (program)

web-scanning reconnaissance Red Team

ffuf-scripts

Scripts and snippets for ffuf payloads.

misc Red Team

fgscanner

An advanced, opensource URL scanner.

scanner Red Team

fhttp

This is a framework for HTTP related attacks. It is written in Perl with a GTK interface, has a proxy for debugging and

webapp Red Team

fi6s

IPv6 network scanner designed to be fast.

scanner Red Team

fiddler

Intercepts, decrypts, and analyzes HTTPS traffic

networking Blue Team

Fiddler (T)

Web debugging proxy that monitors, inspects, and logs HTTPS/WebSocket traffic between a computer and the internet for analysis.

documentation-evidence-capture

fierce

Domain DNS scanner

remote-system-discovery discovery Red Team

Fierce Domain Scanner (T)

DNS reconnaissance tool focused on subdomain discovery and non-contiguous IP space mapping.

domain-name

fierce-git

A DNS scanner

scanners Red Team

fiked

Cisco VPN attack tool

collection Red Team

file

Identify file type using "magic" numbers.

general Blue Team

file-magic.py

Identify file types using the Python magic module.

general Blue Team

filebuster

An extremely fast and flexible web fuzzer.

webapp Red Team

filefuzz

A binary file fuzzer for Windows with several options.

windows Red Team

filegps

A tool that help you to guess how your shell was renamed after the server-side script of the file uploader saved it.

webapp Red Team

fileintel

A modular Python application to pull intelligence about malicious files.

malware Blue Team

filibuster

A Egress filter mapping application with additional functionality.

networking Red Team

filter_audio-git

An easy to use audio filtering library made from webrtc code

uncategorized Red Team

fimap

A little tool for local and remote file inclusion auditing and exploitation.

webapp Red Team

finalrecon

Fast and simple Python script for web reconnaissance

web-scanning Red Team

Find A Grave

Largest online cemetery database with 615M+ grave records from 250M+ graves in 500K+ cemeteries worldwide.

public-records

find-dns

A tool that scans networks looking for DNS servers.

scanner Red Team

find3

High-precision indoor positioning framework.

misc Red Team

FindByPlate

US license plate lookup service for basic vehicle identification and ownership-related investigation leads.

transportation

findmyhash

Crack different types of hashes using free online services.

crypto Red Team

findmyiphone

Locates all devices associated with an iCloud account

mobile Red Team

findmypast.com

UK-focused genealogy and historical records platform with billions of records covering census, birth, marriage, death, military, and immigration…

people-search-engines

findomain

Fastest and most complete solution for domain recognition

web-scanning Red Team

findsploit

Find exploits in local and online databases instantly.

automation Red Team

finduncommonshares

Python script allowing to quickly find uncommon shares in vast Windows Domains.

windows Red Team

fingerprinter

CMS/LMS/Library etc Versions Fingerprinter.

webapp Red Team

Finnik (NL)

Dutch license plate intelligence service using official RDW-linked records for vehicle profile and APK history.

transportation

firebaseenum

Tool to mass analyse potentially exposed Firebase databases on Android apps.

mobile Red Team

firecat

A penetration testing tool that allows you to punch reverse TCP tunnels out of a compromised network.

networking Red Team

Firefox

Web browser.

general-utilities Blue Team

firefox-decrypt

Extract passwords from Mozilla Firefox, Waterfox, Thunderbird, SeaMonkey profiles.

forensic Blue Team

firefox-developer-edition-kbx

Mozilla Firefox web browser - Developer Edition - en-US

uncategorized Red Team

firefox-security-toolkit

A tool that transforms Firefox browsers into a penetration testing suite.

misc Red Team

FireHOL IP Lists

Collection of firewall-friendly IP lists for blocking malicious and spam sources.

ip-mac-address

fireprox

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation.

proxy Red Team

firewalk

Active reconnaissance network security tool

network-security-appliances Red Team

firmwalker

Script for searching the extracted firmware file system for goodies.

firmware Red Team

firmwalker-git

Simple bash script for searching the extracted or mounted firmware file system

forensics Blue Team

firmware-mod-kit

Deconstruct and reconstruct firmware images

uncategorized Red Team

firstexecution

A Collection of different ways to execute code outside of the expected entry points.

exploitation Red Team

firstexecution-git

A Collection of different ways to execute code outside of the expected entry points

exploit Red Team

firstorder

A traffic analyzer to evade Empire communication from Anomaly-Based IDS.

sniffer Red Team

fl0p

A passive L7 flow fingerprinter that examines TCP/UDP/ICMP packet sequences, can peek into cryptographic tunnels, can te

fingerprint Red Team

flare

Flare processes an SWF and extracts all scripts from it.

misc Red Team

flare-floss

Obfuscated String Solver - Automatically extract obfuscated strings from malware.

malware Blue Team

Flash Earth

Zoom Earth interface for rapidly reviewing weather and satellite imagery timelines.

geolocation-tools-maps

flashlight

Automated Information Gathering Tool for Penetration Testers.

recon Red Team

flashrom

Identify, read, write, erase, and verify BIOS/ROM/flash chips

uncategorized Red Team

flashscanner

Flash XSS Scanner.

scanner Red Team

flashsploit

Exploitation Framework for ATtiny85 Based HID Attacks.

exploitation Red Team

flask-session-cookie-manager2

Decode and encode Flask session cookie.

webapp Red Team

flask-session-cookie-manager3

Decode and encode Flask session cookie.

webapp Red Team

flask-unsign

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys

cracker Red Team

flasm

Disassembler tool for SWF bytecode.

decompiler Blue Team

Flickr

Photo hosting platform that often preserves useful image metadata and geotags for OSINT workflows.

images-videos-docs

Flickr Hive Mind

Advanced Flickr search and data-mining interface for tags, users, text, and date filters.

images-videos-docs

Flickr Map

Flickr map interface for browsing geotagged photos by area and time.

images-videos-docs

Flightradar24.com

Global real-time flight tracking platform built on ADS-B and radar feeds with airport and route intelligence views.

transportation

FLOSS

Extract and deobfuscate strings from PE executables.

deobfuscation Blue Team

flowinspect

A network traffic inspection tool.

networking Red Team

flunym0us

A Vulnerability Scanner for Wordpress and Moodle.

scanner Red Team

fluxion

Security auditing and social-engineering research tool

collection Red Team

flyr

Block-based software vulnerability fuzzing framework.

fuzzer Red Team

FOCA (T)

Desktop reconnaissance tool that gathers public documents from target domains and extracts embedded metadata.

images-videos-docs

fockcache

Tool to make cache poisoning by trying X-Forwarded-Host and X-Forwarded-Scheme headers on web pages.

webapp Red Team

Foller.me Analytics

Web analytics tool for summarizing public Twitter profile behavior, including hashtags, mentions, topics, and activity cadence.

social-networks

Follow That Page

Website monitoring service that checks pages for changes and sends alerts when tracked content updates. Supports keyword-based notifications for…

domain-name

Followerwonk (R)

Follower analytics platform (now under Fedica) for examining X/Twitter audience demographics, account overlaps, and engagement trends.

social-networks

FootprintIQ

Ethical digital footprint scanner that searches usernames, emails, and phone numbers across 500+ platforms. Includes breach detection, data broker…

username

forager

Multithreaded threat Intelligence gathering utilizing.

recon Red Team

force_bind

Force binding on a specific IP and/or port, change TTL/TOS/KA/MSS/REUSEADDR/FWMARK/PRIORITY. Works with both IPv4 and IPv6. Also, you can enforce band

uncategorized Red Team

foremost

Forensic program to recover lost files

forensic-carving-tools forensics Blue Team

forensic-artifacts

Knowledge base of forensic artifacts (data files)

uncategorized Red Team

Forensic OSINT (T)

Chrome extension for full-page web capture with evidence preservation; timestamps and disclosure-ready exports for legal investigations.

documentation-evidence-capture

forensics-colorize

Show differences between files using color graphics

uncategorized Red Team

foresight

A tool for predicting the output of random number generators.

crypto Red Team

forkingportscanner

Simple and fast forking port scanner written in perl. Can only scan on host at a time, the forking is done on the specif

scanner Red Team

format-bytes.py

Decompose structured binary data with format strings.

deobfuscation Blue Team

formatstringexploiter

Helper script for working with format string bugs.

exploitation Red Team

FortiGuard Reputation Service

Fortinet's IP reputation service aggregating malicious source IP data from global threat sensors and collaborators. Blocks botnets, DDoS sources, and…

domain-name

fortiscan

A high performance FortiGate SSL-VPN vulnerability scanning and exploitation tool.

scanner Red Team

FotoForensics

Image forensics platform with error level analysis and metadata-oriented integrity checks.

disinformation-media-verification

fpdns

Program that remotely determines DNS server versions.

fingerprint Red Team

fpdns-git

Program that remotely determines DNS server versions

analysis Red Team

fping

Sends ICMP ECHO_REQUEST packets to network hosts

remote-system-discovery Red Team

fport

Identify unknown open ports and their associated applications.

windows Red Team

fprotlogparser

This is a utility to parse a F-Prot Anti Virus log file, in order to sort them into a malware archive for easier maintan

malware Blue Team

fragrouter

IDS evasion toolkit

defense-evasion Red Team

framework2

Metasploit Framework 2

uncategorized Red Team

fraud-bridge

ICMP and DNS tunneling via IPv4 and IPv6.

tunnel Red Team

fred

Cross-platform M$ registry hive editor.

windows Red Team

Free Translation

Multi-provider web translator for quick text translation across many language pairs.

language-translation

freeipscanner

A simple bash script to enumerate stale ADIDNS entries

ad

Freenet Project (T)

Hyphanet (formerly Freenet) is a decentralized, privacy-oriented network for anonymous publishing and file sharing.

dark-web opsec

freeradius

High-performance and highly configurable RADIUS server

wifi-credential-access Red Team

freeradius-wpe

FreeRadius Wireless Pawn Edition

uncategorized Red Team

freerdp2-x11

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP) released under the Apache license.

ad

freerdp3

FreeRDP proxy server

pass-the-hash lateral-movement application-layer-protocol Red Team

freewifi

How to get free wifi.

wireless Red Team

Frida

Trace the execution of a process to analyze its behavior.

general Blue Team

frida-extract

Frida.re based RunPE (and MapViewOfSection) extraction tool.

reversing Blue Team

frida-ios-dump

Pull decrypted ipa from jailbreak device.

mobile Red Team

frida-tools

Frida CLI tools

uncategorized Red Team

fridump

A universal memory dumper using Frida.

forensic Blue Team

frisbeelite

A GUI-based USB device fuzzer.

fuzzer Red Team

fs

Filesystem abstraction layer

uncategorized Red Team

fs-exploit

Format string exploit generation.

exploitation Red Team

fs-nyarl

A network takeover & forensic analysis tool - useful to advanced PenTest tasks & for fun and profit.

scanner Red Team

fscan

A Security Auditing Tool.

scanner Red Team

fsnoop

A tool to monitor file operations on GNU/Linux systems by using the Inotify mechanism. Its primary purpose is to help de

scanner Red Team

fssb

A low-level filesystem sandbox for Linux using syscall intercepts.

defensive Blue Team

fstealer

Automates file system mirroring through remote file disclosure vulnerabilities on Linux machines.

automation Red Team

ftester

Tool for testing firewalls and Intrusion Detection System (IDS)

defense-evasion Red Team

ftp-fuzz

The master of all master fuzzing scripts specifically targeted towards FTP server software.

fuzzer Red Team

ftp-scanner

Multithreaded ftp scanner/brute forcer. Tested on Linux, OpenBSD and Solaris.

cracker Red Team

ftp-spider

FTP investigation tool - Scans ftp server for the following: reveal entire directory tree structures, detect anonymous a

scanner Red Team

ftpmap

Scans remote FTP servers to identify what software and what versions they are running.

fingerprint Red Team

ftpscout

Scans ftps for anonymous access.

scanner Red Team

fuddly

Fuzzing and Data Manipulation Framework (for GNU/Linux).

fuzzer Red Team

Full Page Screen Capture Chrome Extension (T)

Chrome extension for one-click full-page screenshot capture of entire scrollable page content.

documentation-evidence-capture

Functions Online

PHP-oriented online utility suite for common encoding, decoding, hashing, and string-manipulation function tests.

encoding-decoding

fusil

A Python library used to write fuzzing programs.

fuzzer Red Team

fuxploider

Tool that automates the process of detecting and exploiting file upload forms flaws.

webapp Red Team

fuzzap

A python script for obfuscating wireless networks.

wireless Red Team

fuzzball2

A fuzzer for TCP and IP protocol options. It sends a bunch of more or less bogus packets to the target.

fuzzer Red Team

fuzzbunch

NSA Exploit framework

exploitation Red Team

fuzzdb

Attack and Discovery Pattern Dictionary for Application Fault Injection Testing.

fuzzer Red Team

fuzzdiff

A simple tool designed to help out with crash analysis during fuzz testing. It selectively 'un-fuzzes' portions of a fuz

fuzzer Red Team

fuzzowski

A Network Protocol Fuzzer made by NCCGroup based on Sulley and BooFuzz.

fuzzer Red Team

fuzztalk

An XML driven fuzz testing framework that emphasizes easy extensibility and reusability.

windows Red Team

fwbuilder

Firewall administration tool GUI

uncategorized Red Team

fzf

🌸 A command-line fuzzy finder

ad light osint web Red Team

g711conversions

A library needed by rtpinsertsound and rtpmixsound.

voip Red Team

g72x++

Decoder for the g72x++ codec.

wireless Red Team

gadgetinspector

A byte code analyzer for finding deserialization gadget chains in Java applications.

decompiler Blue Team

gadgettojscript

.NET serialized gadgets that can trigger .NET assembly from JS/VBS/VBA based scripts.

exploitation Red Team

galah

galah honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

galleta

Internet Explorer cookie forensic analysis tool

forensics Blue Team

garak

The LLM vulnerability scanner.

ai Red Team

garbageman

GarbageMan is a set of tools designed for .NET heap analysis.

dotnet Blue Team

garminplugin

Garmin Communicator Plugin for Linux

uncategorized Red Team

garmintools

This software provides Linux users with the ability to communicate with the Garmin Forerunner 305 via the USB interface.

uncategorized Red Team

gasmask

All in one Information gathering tool - OSINT.

recon Red Team

gatecrasher

Network auditing and analysis tool developed in Python.

recon Red Team

gau

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

webapp Red Team

gcat

A fully featured backdoor that uses Gmail as a C&C server.

malware Blue Team

gcpbucketbrute

A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privi

scanner Red Team

GCPBucketBrute (T)

Google Cloud Storage bucket enumeration utility for identifying publicly accessible or weakly protected buckets.

cloud-infrastructure

gcrypt

Simple, secure and performance file encryption tool written in C

crypto Red Team

gdb

GNU Debugger

resource-development Red Team

gdb-peda

Python Exploit Development Assistance for GDB

uncategorized Red Team

gdbgui

Browser-based gdb frontend using Flask and JavaScript to visually debug C, C++, Go, or Rust.

debugger Red Team

gdir.pl

Perl wrapper on gcrypt for directory encryption/decryption.

crypto Red Team

gdisk

GPT fdisk text-mode partitioning tool

uncategorized Red Team

gdns (T)

Google DNS-focused command-line tool for DNS lookup and domain record exploration.

domain-name

gef

Modern experience for GDB with advanced debugging capabilities

resource-development Red Team

gef-git

Provides additional features to GDB using the Python API to assist during the process of dynamic analysis or exploit development.

exploit Red Team

gemini-cli

Open-source AI agent

services-and-other-tools Red Team

gene

Signature Engine for Windows Event Logs.

windows Red Team

genisys

Powerful Telegram Members Scraping and Adding Toolkit.

social Red Team

genlist

Generates lists of IP addresses.

misc Red Team

genusernames

GenUsername is a Python tool for generating a list of usernames based on a name or email address.

ad web

Genymotion (T)

Cloud-based and desktop Android emulator platform for app testing and forensic analysis. Supports multi-instance deployment and integration with…

mobile-osint Red Team

geoedge

This little tools is designed to get geolocalization information of a host, it get the information from two sources (max

recon Red Team

geoipgen

A country to IP addresses generator.

misc Red Team

GeoPincer

GeoPincer is a script that leverages OpenStreetMap's Overpass API in order to search for locations.

osint web Red Team

GeoSetter

Windows desktop utility for viewing and editing photo geotags and EXIF/XMP metadata fields in bulk.

images-videos-docs

GeoSpy

AI-assisted image geolocation tool for estimating where a photo was taken.

geolocation-tools-maps

geowordlists

tool to generate wordlists of passwords containing cities at a defined distance around the client city.

ad web

gerix-wifi-cracker

A graphical user interface for aircrack-ng and pyrit.

wireless Red Team

getallurls

Fetch known URLs from AlienVault’s Open Threat Exchange (gau)

uncategorized Red Team

gethsploit

Finding Ethereum nodes which are vulnerable to RPC-attacks.

scanner Red Team

getsids

Enumerate Oracle Sids by sending the services command to the Oracle TNS listener.

database Red Team

getsploit

Command line utility for searching and downloading exploits

uncategorized Red Team

gf

A wrapper around grep, to help you grep for things.

misc Red Team

gg-images

The application was created to allow anyone to easily download profile pictures from GG.

social Red Team

gggooglescan

A Google scraper which performs automated searches and returns results of search queries in the form of URLs or hostname

scanner Red Team

gh-dork

Github dorking tool.

recon Red Team

ghauri

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws.

webapp Red Team

ghettotooth

Ghettodriving for bluetooth.

bluetooth Red Team

ghidra

Software Reverse Engineering Framework

resource-development Red Team

Ghidra (T)

Free and open-source reverse engineering framework from NSA for analyzing compiled software. Includes disassembly, decompilation, scripting, and…

malicious-file-analysis

GhidrAssistMCP

MCP server for AI-assisted reverse engineering in Ghidra.

use-artificial-intelligence Blue Team

ghidriff

Python Command-Line Ghidra Binary Diffing Engine.

reversing Blue Team

ghost

Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device.

mobile Red Team

ghost-phisher

GUI suite for phishing and penetration attacks.

scanner Red Team

ghost-py

Webkit based webclient (relies on PyQT).

webapp Red Team

ghostdelivery

Python script to generate obfuscated .vbs script that delivers payload (payload dropper) with persistence and windows an

exploitation Red Team

ghostpack

Compiled Binaries for Ghostpack (.NET v4.8.1).

windows Red Team

ghostpop3

A program that simulates an 'always no messages' POP3 server

honeypots Blue Team

ghunt

An offensive OSINT Google framework.

recon Red Team

GHunt (T)

Offensive Google framework that investigates Google accounts using email addresses to uncover YouTube channels, Google Photos, Maps reviews, and…

email-address

gibberish-detector

Train a model and detect gibberish strings with it.

misc Red Team

GIMP

and Inkscape to edit images

desktop-edition

girsh

Automatically spawn a reverse shell fully interactive for Linux or Windows victim.

networking Red Team

giskismet

A program to visually represent the Kismet data in a flexible manner.

wireless Red Team

git

Fast, scalable, distributed revision control system

uncategorized Red Team

git-dump

Dump the contents of a remote git repository without directory listing enabled.

scanner Red Team

git-dumper

A tool to dump a git repository from a website.

scanner Red Team

git-hound

Pinpoints exposed API keys on GitHub. A batch-catching, pattern-matching, patch-attacking secret snatcher.

recon Red Team

git-wild-hunt

A tool to hunt for credentials in github wild AKA git*hunt.

recon Red Team

gitdorker

Python program to scrape secrets from GitHub through usage of a large repository of dorks.

recon Red Team

gitdump

A pentesting tool that dumps the source code from .git even when the directory traversal is disabled.

webapp Red Team

gitem

A Github organization reconnaissance tool.

recon Red Team

GitFive (T)

OSINT CLI tool for investigating GitHub profiles. Tracks username/name history, maps emails to accounts, extracts SSH public keys, and exports…

username

gitgraber

Monitor GitHub to search and find sensitive data in real time for different online services.

recon Red Team

githack

A `.git` folder disclosure exploit.

recon Red Team

githound

Find secret information in git repositories.

code-audit Red Team

github-dorks

Collection of github dorks and helper tool to automate the process of checking dorks.

recon Red Team

github-subdomains

Find subdomains on GitHub.

recon Red Team

githubcloner

A script that clones Github repositories of users and organizations automatically.

misc Red Team

githubemail

a command-line tool to retrieve a user's email from Github.

osint web Red Team

gitleaks

Protect and discover secrets using Gitleaks 🔑 (program)

uncategorized Red Team

gitmails

An information gathering tool to collect git commit emails in version control host services.

recon Red Team

gitminer

Tool for advanced mining for content on Github.

recon Red Team

gitminer-git

Tool for advanced mining for content on Github

scanners Red Team

gitrecon

OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked on commits.

recon Red Team

gitrob

Reconnaissance tool for GitHub organizations.

scanner Red Team

Gitrob (T)

CLI tool for reconnaissance on GitHub organizations and users; clones repositories and scans commit history for sensitive files, exposed credentials,…

search-engines

gittools

A repository with 3 tools for pwn'ing websites with .git repositories available'.

webapp Red Team

gitxray

Scan GitHub repositories and contributors to collect data

unsecured-credentials Red Team

glibc

GNU C Library: Documentation

uncategorized Red Team

Global EDGE Resource Directory

MSU GlobalEdge curated directory of international business resources, organized by topic including trade, investment, finance, and country data.

business-records

Global Fishing Watch

Nonprofit maritime transparency platform that maps global fishing activity from AIS/VMS-derived signals.

transportation

GlobalFile

FTP file search engine that indexes publicly accessible FTP servers; allows searching for specific file types including images, videos, software, and…

search-engines

gloom

Linux Penetration Testing Framework.

scanner Red Team

glow

glow is a tool to render Markdown inside the terminal.

ad osint web Red Team

glpwnme

GLPI vulnerabilities checking tool.

scanner Red Team

glue

A framework for running a series of tools.

automation Red Team

glutton

glutton honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

gmsadumper

A tool that Reads any gMSA password blobs the user can access and parses the values.

misc Red Team

GNOME

an intuitive and attractive desktop environment

general

GNOME Calculator

Calculator.

general-utilities Blue Team

GNOME Screen Keyboard

for accessibility and protection against hardware keyloggers

encryption-and-privacy

GNOME Secrets

password manager

encryption-and-privacy

GNOME Sound Recorder

for recording sound

desktop-edition

GNU Project Debugger

Multi-language debugger.

elf-files Blue Team

GNU Wget

Interact with servers via HTTP, HTTPS, FTP, and FTPS using this command-line tool.

connecting Blue Team

GnuPG

the GNU implementation of OpenPGP for email and data encryption and signing

encryption-and-privacy

gnuradio

GNU Radio Software Radio Toolkit

uncategorized Red Team

go-exploitdb

Tool for searching Exploits from Exploit Databases, etc.

automation Red Team

go-pot

go-pot honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

go-windapsearch

Utility to enumerate users, groups and computers from a Windows domain through LDAP queries.

recon Red Team

gobd

A Golang covert backdoor.

backdoor Red Team

goblob (T)

Go-based Azure blob storage enumeration utility designed for fast discovery of publicly exposed containers and blobs.

cloud-infrastructure

gobuster

High-performance discovery tool for directories, DNS and cloud storage

web-scanning reconnaissance Red Team

Gobuster (T)

Multi-mode brute-force tool for DNS subdomain, virtual host, and directory discovery.

domain-name

gocabrito

Super organized and flexible script for sending phishing campaigns.

social Red Team

godap

A complete TUI for LDAP.

ad

goddi

Dumps Active Directory domain information.

recon Red Team

godoh

DNS-over-HTTPS Command & Control Proof of Concept

uncategorized Red Team

GoExec

GoExec is a new take on some of the methods used to gain remote execution on Windows devices. GoExec implements a number of largely unrealized…

ad

golang-github-binject-go-donut

Donut Injector in Go

uncategorized Red Team

goldencopy

Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket

ad

goldeneye

HTTP DoS test tool

impact Red Team

goldeneye-git

Modular framework that takes advantage of poor upgrade implementations by injecting fake updates

networking Red Team

golismero

Opensource web security testing framework.

webapp Red Team

gomapenum

User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin.

cracker Red Team

goodork

A python script designed to allow you to leverage the power of google dorking straight from the comfort of your command

recon Red Team

goofile

Command line filetype search

uncategorized Red Team

goofuzz

A Bash script that uses advanced Google search techniques to obtain sensitive information in files or directories withou

fuzzer Red Team

goog-mail

Enumerate domain emails from google.

recon Red Team

Google CSE for Telegram links

Preconfigured Google Custom Search Engine focused on public Telegram links and channel discovery.

instant-messaging

Google Earth

3D globe and historical imagery platform for terrain and time-based visual analysis.

geolocation-tools-maps

Google Earth Overlays

Overlay workflow for layering KML/KMZ data onto Google Earth views.

geolocation-tools-maps

google-explorer

Google mass exploit robot - Make a google search, and parse the results for a especific exploit you define.

automation Red Team

google-explorer-git

Google mass exploit robot in python

scanners Red Team

Google Finance

Google's financial data platform providing stock quotes, financial statements, news, and company overviews for publicly traded companies.

business-records

Google Guide Cheat Sheet

Quick-reference cheat sheet for Google search operators and advanced search syntax from Google Guide.

search-engines

Google Images

Google's reverse image and visual search via Lens for finding matches, source pages, and related images across the web.

images-videos-docs

Google Input Tools

Google input method utility for typing and transliteration across many scripts and languages.

language-translation

Google Maps

Google web mapping suite with satellite, terrain, route, and place intelligence layers.

geolocation-tools-maps

google-nexus-tools

ADB and Fastboot for use with Nexus devices

uncategorized Red Team

Google Patent Search

Google's searchable patent database covering US, EU, WIPO and other international patents. Full-text search with categorization.

public-records

Google's Certificate Transparency

Directory of all known Certificate Transparency logs monitored by Chrome and other browsers. Browse CT log records to discover issued certificates,…

domain-name

Google Safe Browsing API

Google's free API detecting malicious URLs and phishing sites with protection across billions of devices.

domain-name

Google Scholar

Multidisciplinary academic search engine indexing journal articles, theses, books, conference papers, and patents; includes citation counts and…

search-engines

Google Scholar Case Law

Google's free legal research tool indexing millions of court opinions from US federal and state courts.

public-records

Google Search Operators Guide

Official Google documentation covering all supported search operators, syntax, and advanced search techniques.

search-engines

Google Street View - Hyperlapse

Tool for creating timelapse and hyperlapse videos from Google Street View images along selected routes for geographic visualization.

documentation-evidence-capture

Google Translate

Google's web translation platform covering hundreds of languages for text and website translation.

language-translation

Google Trends

Google's search trend analysis tool for tracking keyword popularity and comparing search interest over time.

domain-name search-engines

googlesub

A python script to find domains by using google dorks.

recon Red Team

goohak

Automatically Launch Google Hacking Queries Against A Target Domain.

recon Red Team

goop

Perform google searches without being blocked by the CAPTCHA or hitting any rate limits.

recon Red Team

goop-dump

Tool to dump a git repository from a website, focused on as-complete-as-possible dumps and handling weird edge-cases.

webapp Red Team

gooscan

A tool that automates queries against Google search appliances, but with a twist.

automation Red Team

GootLoaderAutoJsDecode.py

Statically deobfuscate GootLoader (GOOTLOADER) malicious JScript to recover the payload and extract C2 domains.

scripts Blue Team

gopherus

Tool generates gopher link for exploiting SSRF and gaining RCE in various servers.

webapp Red Team

gophish

Open-Source Phishing Toolkit

initial-access system-services Red Team

GoReSym

Extract metadata and symbols from Go binaries, including stripped ones.

go Blue Team

gosecretsdump

Implements NTLMSSP network authentication protocol in Go

ad

goshs

SimpleHTTPServer written in Go

exfiltration Red Team

gosint

OSINT framework in Go.

recon Red Team

gospider

Fast web spider written in Go

web-scanning Red Team

gostringsr2

Extract strings from a Go binary using radare2.

reversing Blue Team

gostringungarbler

GoStringUngarbler deobfuscates strings in Go binaries obfuscated by garble.

go Blue Team

Gov Data Canada

Government of Canada Open Data Portal. Federal open data including demographics, business info, and statistics.

public-records

GOVDATA - Das Datenportal für Deutschland (German)

Official German government open data portal with 120K+ datasets. Centralized access to federal, state, and local administrative data.

public-records

gowitness

Web screenshot utility using Chrome Headless

uncategorized Red Team

gowitness-git

A golang web screenshot utility using Chrome Headless

recon Red Team

gpart

Guess PC disk partition table, find lost partitions

uncategorized Red Team

gparted

GNOME partition editor

uncategorized Red Team

gplist

Lists information about the applied Group Policies.

windows Red Team

gpocrack

Active Directory Group Policy Preferences cpassword cracker/decrypter.

cracker Red Team

GPOddity

Aiming at automating GPO attack vectors through NTLM relaying (and more)

ad

gpoParser

Tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

ad

gpowned

GPOs manipulation tool.

windows Red Team

gpp-decrypt

Group Policy Preferences decrypter

uncategorized Red Team

gpredict

A real-time satellite tracking and orbit prediction application.

radio Red Team

gps-sdr-sim

Software-Defined GPS Signal Simulator.

radio Red Team

GPSVisualizer

Coordinate and GPS utility for mapping, conversion, and geocoding operations.

geolocation-tools-maps

GPTZero

AI text detection tool specifically designed to identify ChatGPT and large language model-generated content with sentence-level granularity.

ai-tools

gqrx

Software defined radio receiver powered by GNU Radio and Qt

general

gqrx-scanner

A frequency scanner for Gqrx Software Defined Radio receiver.

radio Red Team

gqrx-sdr

Software defined radio receiver

radio-frequency Red Team

gr-air-modes

Gnuradio Mode-S/ADS-B radio

uncategorized Red Team

gr-dect2

Real-time DECT voice channel decoding by Gnuradio.

radio Red Team

gr-gsm

Gnuradio blocks and tools for receiving GSM transmissions.

radio Red Team

gr-iqbal

GNU Radio Blind IQ imbalance estimator and correction

uncategorized Red Team

gr-osmosdr

GNU Radio blocks from the OsmoSDR project

uncategorized Red Team

gr-paint

An OFDM Spectrum Painter for GNU Radio.

radio Red Team

grabbb

Clean, functional, and fast banner scanner.

scanner Red Team

grabber

A web application scanner. Basically it detects some kind of vulnerabilities in your website.

webapp Red Team

Grabify

URL shortener service that logs IP addresses and device information of link clickers.

ip-mac-address

grabing

Counts all the hostnames for an IP adress

recon Red Team

grabitall

Performs traffic redirection by sending spoofed ARP replies.

windows Red Team

graffiti

A tool to generate obfuscated one liners to aid in penetration testing.

misc Red Team

grammarinator

A random test generator / fuzzer that creates test cases according to an input ANTLR v4 grammar.

fuzzer Red Team

Grammarly AI Detector

Grammarly's AI content detection tool that identifies text likely generated by AI writing assistants, with percentage breakdown of human vs. AI…

ai-tools

graphinder

GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce.

recon Red Team

graphql-cop

GraphQL vulnerability scanner.

scanner Red Team

graphql-path-enum

Tool that lists the different ways of reaching a given type in a GraphQL schema.

webapp Red Team

graphqlmap

Scripting engine to interact with a graphql endpoint for pentesting purposes.

webapp Red Team

graphw00f

GraphQL endpoint detection and engine fingerprinting.

webapp Red Team

graudit

Grep rough audit - source code auditing tool

uncategorized Red Team

GraveInfo

Cemetery records database with GPS-marked grave locations and gravestone photos. Aggregates cemetery information with mobile crowdsourcing.

public-records

Greenshot (T)

Free and open-source screenshot program for Windows and macOS with annotation, highlighting, and multi-format export capabilities.

documentation-evidence-capture

grepforrfi

Simple script for parsing web logs for RFIs and Webshells v1.2

scanner Red Team

grokevt

Scripts for reading Microsoft Windows event log files

sleuth-kit-suite Red Team

gron

Make JSON greppable!

osint web Red Team

grpc-pentest-suite

Set of tools for pentesting gRPC-Web Applications.

webapp Red Team

grr

High-throughput fuzzer and emulator of DECREE binaries.

fuzzer Red Team

grype

A vulnerability scanner for container images and filesystems.

scanner Red Team

gsd

Gives you the Discretionary Access Control List of any Windows NT service you specify as a command line option.

windows Red Team

gsmevil2

Python web-based tool which use for capturing imsi numbers and sms.

radio Red Team

gsocket

Allows two machines on different networks to communicate with each other

uncategorized Red Team

gspoof

A simple GTK/command line TCP/IP packet generator.

networking Red Team

gspy

Forensic goroutine-to-syscall inspector for live Go processes.

forensic Blue Team

gss-ntlmssp

GSSAPI NTLMSSP Mechanism – MIT GSSAPI plugin

uncategorized Red Team

gtalk-decode

Google Talk decoder tool that demonstrates recovering passwords from accounts.

windows Red Team

gtfo

Search gtfobins and lolbas files from your terminal.

misc Red Team

gtfoblookup

Offline command line lookup utility for GTFOBins and LOLBAS.

misc Red Team

gtkhash

GTK+ utility for computing checksums and more

uncategorized Red Team

gtp-scan

A small python script that scans for GTP (GPRS tunneling protocol) speaking hosts.

scanner Red Team

guymager

Forensic imaging tool based on Qt

forensic-imaging-tools Blue Team

gvm

Remote network security auditor - metapackage and useful scripts

vulnerability-scanning system-services Red Team

gwcheck

A simple program that checks if a host in an ethernet network is a gateway to Internet.

networking Red Team

gwtenum

Enumeration of GWT-RCP method calls.

recon Red Team

h0neytr4p

h0neytr4p honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

h2buster

A threaded, recursive, web directory brute-force scanner over HTTP/2.

scanner Red Team

h2csmuggler

HTTP Request Smuggling over HTTP/2 Cleartext (h2c).

webapp Red Team

h2spec

A conformance testing tool for HTTP/2 implementation.

misc Red Team

h2t

Scans a website and suggests security headers to apply.

webapp Red Team

h8mail

Email open source intelligence and breach hunting tool

uncategorized Red Team

habu

Python Network Hacking Toolkit.

scanner Red Team

Hachoir

View, edit, and carve contents of various binary file types.

general Blue Team

hack_library

A library needed by rtpmixsound and rtpinsertsound

voip Red Team

hackersh

A shell for with Pythonect-like syntax, including wrappers for commonly used security tools.

automation Red Team

hackredis

A simple tool to scan and exploit redis servers.

exploitation Red Team

hackrf

Software defined radio peripheral - utilities

radio-frequency Red Team

hacktv

Analogue TV transmitter for the HackRF.

radio Red Team

haiti

Hash type identifier (CLI & lib).

crypto Red Team

hak5-wifi-coconut

Userspace driver for the Hak5 Wi-Fi Coconut

uncategorized Red Team

haka

A collection of tool that allows capturing TCP/IP packets and filtering them based on Lua policy files.

networking Red Team

hakku

Simple framework that has been made for penetration testing tools.

scanner Red Team

hakrawler

Web crawler designed for easy, quick discovery of endpoints and assets

uncategorized Red Team

hakrevdns

Small, fast tool for performing reverse DNS lookups en masse.

recon Red Team

halberd

Halberd discovers HTTP load balancers. It is useful for web application security auditing and for load balancer configur

scanner Red Team

halcyon

A repository crawler that runs checksums for static files found within a given git repository.

recon Red Team

halcyon-ide

First IDE for Nmap Script (NSE) Development.

misc Red Team

hamster

Tool for HTTP session sidejacking.

exploitation Red Team

hamster-sidejack

Sidejacking tool

collection Red Team

handle

An small application designed to analyze your system searching for global objects related to running process and display

windows Red Team

harness

Interactive remote PowerShell Payload.

backdoor Red Team

harpoon

CLI tool for open source and threat intelligence.

automation Red Team

hasere

Discover the vhosts using google and bing.

recon Red Team

hash-buster

A python script which scraps online hash crackers to find cleartext of a hash.

crypto Red Team

Hash Droid

Verify file integrity

forensics Blue Team

hash-extender

A hash length extension attack tool.

crypto Red Team

Hash ID

Identify different types of hashes.

general Blue Team

hash-identifier

Tool to identify hash types

hash-identification Red Team

hashcat

World’s fastest and most advanced password recovery utility

password-cracking credential-access Red Team

hashcat-utils

Set of small utilities for advanced password cracking

uncategorized Red Team

hashcatch

Capture handshakes of nearby WiFi networks automatically.

wireless Red Team

hashcheck

Search for leaked passwords while maintaining a high level of privacy using the k-anonymity method.

crypto Red Team

hashdb

A block hash toolkit.

crypto Red Team

hashdeep

Recursively compute hashsums or piecewise hashings

forensics Blue Team

hasher

A tool that allows you to quickly hash plaintext strings, or compare hashed values with a plaintext locally.

cracker Red Team

hashfind

A tool to search files for matching password hash types and other interesting data.

crypto Red Team

hashid

Identify the different types of hashes used to encrypt data

hash-identification Red Team

hashid-git

dentify the different types of hashes used to encrypt data and especially passwords.

uncategorized Red Team

hashmyfiles

HashMyFiles calculates and exports various file hashes (MD5, SHA256, etc.) to clipboard and multiple file formats.

file-information Blue Team

hashonymize

This small tool is aimed at anonymizing hashes files for offline but online cracking like Google Collab for instance (see…

ad

hashpeek

A fast Go-based CLI tool to identify, extract, and classify hash types from structured data/files with JSON/CSV output a

crypto Red Team

hashpump

A tool to exploit the hash length extension attack in various hashing algorithms.

crypto Red Team

hashpump-git

A tool to exploit the hash length extension attack in various hashing algorithms

uncategorized Red Team

hashrat

Hashing tool supporting several hashes and recursivity

uncategorized Red Team

hashtag

A python script written to parse and identify password hashes.

cracker Red Team

hatcloud

Bypass CloudFlare with Ruby.

recon Red Team

hate-crack

A tool for automating cracking methodologies through Hashcat.

automation Red Team

Have I been pwned?

Database of breached credentials and email addresses from known data breaches.

email-address

havoc

Modern and malleable post-exploitation C2 framework

command-and-control Red Team

havoc-c2

Modern and malleable post-exploitation command and control framework.

automation Red Team

haystack

A Python framework for finding C structures from process memory - heap analysis - Memory structures forensics.

binary Red Team

hb-honeypot

Heartbleed Honeypot Script

uncategorized Red Team

hbad

This tool allows you to test clients on the heartbleed bug.

scanner Red Team

hcraft

HTTP Vuln Request Crafter.

exploitation Red Team

hcxdumptool

Small tool to capture packets from wlan devices.

general

hcxtools

Tools for converting captures to use with hashcat or John the Ripper

uncategorized Red Team

hd2u

Dos2Unix text file converter

uncategorized Red Team

hdcp-genkey

Generate HDCP source and sink keys from the leaked master key.

crypto Red Team

hdmi-sniff

HDMI DDC (I2C) inspection tool. It is designed to demonstrate just how easy it is to recover HDCP crypto keys from HDMI

hardware Red Team

heaptrace

Helps visualize heap operations for pwn and debugging.

debugger Red Team

heartbleed-git

Test whether a host is vulnerable to the Heartbleed attack

uncategorized Red Team

heartbleed-honeypot

Script that listens on TCP port 443 and responds with completely bogus SSL heartbeat responses, unless it detects the st

honeypot Blue Team

heartleech

Scanner detecting systems vulnerable to the heartbleed OpenSSL bug

vulnerability-scanning Red Team

hekatomb

Extract and decrypt all credentials from all domain computers

uncategorized Red Team

hellcat-git

netcat that takes unfair advantage of traffic shaping systems that don't initially ratelimit

uncategorized Red Team

hellpot

hellpot honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

hellraiser

Vulnerability Scanner.

scanner Red Team

hemingway

A simple and easy to use spear phishing helper.

social Red Team

heralding

heralding honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

hercules-payload

A special payload generator that can bypass all antivirus software.

binary Red Team

HERE Maps

Enterprise-grade mapping platform with routing and global cartographic coverage.

geolocation-tools-maps

hetty

HTTP toolkit for security research. Aims to become an open source alternative to commercial software like Burp Suite Pro

webapp Red Team

hex-to-bin.py

Convert hexadecimal text dumps to binary data.

deobfuscation Blue Team

hex2bin

Converts Motorola and Intel hex files to binary.

binary Red Team

hexedit

View and edit binary files

general

hexhttp

Perform tests on HTTP headers and analyze the results to identify vulnerabilities and interesting behaviors.

scanner Red Team

hexinject

Versatile packet injector and sniffer

network-sniffing Red Team

hexodus

Python framework project designed to enumerate and help in Active Directory attacks through Windows protocols like SMB,

windows Red Team

hexorbase

A database application designed for administering and auditing multiple database servers simultaneously from a centraliz

fuzzer Red Team

hexstrike-ai

AI-Powered MCP Cybersecurity Automation Platform

services-and-other-tools Red Team

hexwalk

Hex analyzer, editor and viewer

digital-forensics Blue Team

hharp

This tool can perform man-in-the-middle and switch flooding attacks. It has 4 major functions, 3 of which attempt to man

networking Red Team

hidattack

HID Attack (attacking HID host implementations).

bluetooth Red Team

hiddeneye

Modern phishing tool with advanced functionality.

social Red Team

hiddeneye-legacy

Modern Phishing Tool With Advanced Functionality.

social Red Team

Hijacker

Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android.

wifi Red Team

Hiking & Biking Map

OSM-based map optimized for trails, cycling routes, and terrain context.

geolocation-tools-maps

hikpwn

A simple scanner for Hikvision devices with basic vulnerability scanning capabilities written in Python 3.8.

scanner Red Team

Hinge

Relationship-oriented dating app focused on prompt-driven profiles and conversation-first matching.

dating

Historic Aerials

Historical aerial imagery archive for property and infrastructure change analysis.

geolocation-tools-maps

Hive AI Generated Content Detection

Enterprise-grade AI content detection API from Hive Moderation that detects AI-generated text, images, and video at scale.

ai-tools

Hivemapper

Decentralized, crowdsourced street imagery map network with expanding coverage.

geolocation-tools-maps

hivex

Utilities for reading and writing Windows Registry hives

uncategorized Red Team

Hiya (R$)

Caller-ID and spam-protection platform with reverse lookup capabilities and mobile integrations.

telephone-numbers

hlextend

Pure Python hash length extension module.

crypto Red Team

HLR Lookup Portal (R)

HLR lookup service for telecom reachability, network, and carrier status checks.

telephone-numbers

hoaxshell

Windows reverse shell payload generator and handler that abuses http(s)

command-and-control Red Team

Hob0Rules rules

Password cracking rules for Hashcat based on statistics and industry patterns

ad web

hodor

A general-use fuzzer that can be configured to use known-good input and delimiters in order to fuzz specific locations.

fuzzer Red Team

holehe

A tool for Efficiently finding registered accounts from emails.

social Red Team

Holehe (T)

Python-based email enumeration tool that checks if an email is registered across 120+ websites and services using password-reset mechanisms.

email-address

hollows-hunter

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, sh

windows Red Team

hollowshunter

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory pa

memory Blue Team

homepwn

Swiss Army Knife for Pentesting of IoT Devices.

scanner Red Team

honeyaml

honeyaml honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

honeycreds

Network credential injection to detect responder and other network poisoners.

defensive Blue Team

honeyd

A small daemon that creates virtual hosts on a network.

honeypot Blue Team

honeypots

honeypots honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

honeypy

A low interaction Honeypot.

honeypot Blue Team

honeytrap

honeytrap honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

honggfuzz

A general-purpose fuzzer with simple, command-line interface.

fuzzer Red Team

honssh

A high-interaction Honey Pot solution designed to log all SSH communications between a client and server.

honeypot Blue Team

hookanalyser

A hook tool which can be potentially helpful in reversing applications and analyzing malware. It can hook to an API in a

windows Red Team

hookshot

Integrated web scraper and email account data breach comparison tool.

webapp Red Team

hoover

Wireless Probe Requests Sniffer.

wireless Red Team

hoper

Trace URL's jumps across the rel links to obtain the last URL.

recon Red Team

hopper

Reverse engineering tool that lets you disassemble, decompile and debug your applications.

reversing Blue Team

hoppy

A python script which tests http methods for configuration issues leaking information or just to see if they are enabled

scanner Red Team

horst

Highly Optimized Radio Scanning Tool

uncategorized Red Team

horusec

Static code analysis to identify security flaws for many languages.

code-audit Red Team

host-extract

Ruby script tries to extract all IP/Host patterns in page response of a given URL and JavaScript/CSS files of that URL.

scanner Red Team

hostapd-mana

Featureful rogue access point

uncategorized Red Team

hostapd-wpe

Modified hostapd to facilitate AP impersonation attacks

uncategorized Red Team

hostbox-ssh

A ssh password/account scanner.

cracker Red Team

hosthunter

Tool to discover and extract hostnames providing a set of target IP addresses

uncategorized Red Team

hostsman

Cross-platform command line tool for handling hosts files

uncategorized Red Team

hotpatch

Hot patches Linux executables with .so file injection

uncategorized Red Team

hotpatch-git

Hot patches executables on Linux using .so file injection

backdoors Red Team

hotspotter

Passively monitor the network for probe request frames to identify the preferred networks of Windows XP clients, and com

wireless Red Team

howmanypeoplearearound

Count the number of people around you by monitoring wifi signals.

recon Red Team

hpfeeds

Honeynet Project generic authenticated datafeed protocol.

honeypot Blue Team

hpfeeds-git

Honeynet Project generic authenticated datafeed protocol

uncategorized Red Team

hping3

Active Network Smashing Tool

remote-system-discovery discovery Red Team

hqlmap

A tool to exploit HQL Injections.

exploitation Red Team

hsecscan

A security scanner for HTTP response headers.

scanner Red Team

htcap

A web application analysis tool for detecting communications between javascript and the server.

webapp Red Team

htexploit

A Python script that exploits a weakness in the way that .htaccess files can be configured to protect a web directory wi

exploitation Red Team

htpwdscan

A python HTTP weak pass scanner.

cracker Red Team

htrosbif

Active HTTP server fingerprinting and recon tool.

fingerprint Red Team

htshells

Self contained htaccess shells and attacks

uncategorized Red Team

htshells-git

Self contained web shells and other attacks via .htaccess files.

exploit Red Team

http-enum

A tool to enumerate the enabled HTTP methods supported on a webserver.

scanner Red Team

http-fuzz

A simple http fuzzer.

fuzzer Red Team

http-put

Simple http put perl script.

misc Red Team

http-traceroute

This is a python script that uses the Max-Forwards header in HTTP and SIP to perform a traceroute-like scanning function

networking Red Team

http2smugl

Http2Smugl - Tool to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -> HTTP/1.1 conver

webapp Red Team

httpbog

A slow HTTP denial-of-service tool that works similarly to other attacks, but rather than leveraging request headers or

windows Red Team

httpforge

A set of shell tools that let you manipulate, send, receive, and analyze HTTP messages. These tools can be used to test,

webapp Red Team

httpgrep

Async HTTP(S) scanner that greps response bodies and headers for strings or regex across hosts, ports, CIDR/ranges and T

webapp Red Team

httpmethods

Tool for exploiting HTTP methods (e.g. PUT / DELETE / etc.)

ad web

httppwnly

"Repeater" style XSS post-exploitation tool for mass browser control.

webapp Red Team

httprecon

Tool for web server fingerprinting, also known as http fingerprinting.

windows Red Team

httprint

Web server fingerprinting tool

uncategorized Red Team

httprint-win32

A web server fingerprinting tool (Windows binaries).

windows Red Team

httprobe

Take a list of domains and probe for working HTTP and HTTPS servers

uncategorized Red Team

httpry

A specialized packet sniffer designed for displaying and logging HTTP traffic.

sniffer Red Team

httpscreenshot

A tool for grabbing screenshots and HTML of large numbers of websites.

misc Red Team

httpsniff

Tool to sniff HTTP responses from TCP/IP based networks and save contained files locally for later review.

sniffer Red Team

httpsscanner

A tool to test the strength of a SSL web server.

scanner Red Team

httpx

A fast and multi-purpose HTTP toolkit allow to run multiple probers using retryablehttp library.

webapp Red Team

httpx-toolkit

Fast and multi-purpose HTTP toolkit

uncategorized Red Team

httrack

Copy websites to your computer (Offline browser)

collection Red Team

hubbit-sniffer

Simple application that listens for WIFI-frames and records the mac-address of the sender and posts them to a REST-api.

sniffer Red Team

hubble

Network, Service & Security Observability for Kubernetes using eBPF (program)

uncategorized Red Team

Hudson Rock

Infostealer threat intelligence platform that searches a database of compromised devices and stolen credentials to identify if emails have been…

email-address

Hulbee

Corporate site and product page for Hulbee AG. NOT a search engine itself - Hulbee is the company behind Swisscows. URL/category mismatch issue.

search-engines

hulk

A webserver DoS tool (Http Unbearable Load King) ported to Go with some additional features.

dos Red Team

hulk-git

HULK DoS tool ported to Go with some additional features.

ddos Red Team

humble

HTTP Headers Analyzer

uncategorized Red Team

hungry-interceptor

Intercepts data, does something with it, stores it.

sniffer Red Team

Hunter

Email finder and verifier that discovers business email addresses from company domains, names, and social profiles with up to 98% accuracy rate.

email-address

Hunting-New-Registered-Domains (T)

Open-source tool for identifying newly registered domains matching patterns, useful for phishing and brand threat detection.

domain-name

hurl

Hexadecimal & URL encoder + decoder

uncategorized Red Team

hurl-encoder

Hexadecimal & URL (en/de)coder.

misc Red Team

Hurricane Electric BGP Toolkit

BGP and network routing analysis tools including AS to prefix lookup and BGP prefix information.

ip-mac-address

hwk

Collection of packet crafting and wireless network flooding tools

wireless Red Team

hxd

Freeware Hex Editor and Disk Editor.

misc Red Team

Hybrid Analysis

Free automated malware analysis service powered by CrowdStrike Falcon Sandbox. Combines runtime data with memory dump analysis to extract execution…

malicious-file-analysis

hyde

Just another tool in C to do DDoS (with spoofing).

networking Red Team

hydra

Very fast network logon cracker

brute-force credential-access Red Team

hyenae

Flexible platform independent packet generator.

networking Red Team

hyperfox

A security tool for proxying and recording HTTP and HTTPs traffic.

networking Red Team

hyperfox-git

A security tool for proxying and recording HTTP and HTTPs traffic.

proxy Red Team

hyperion

Runtime encrypter for 32-bit portable executables

uncategorized Red Team

hyperion-crypter

A runtime encrypter for 32-bit and 64-bit portable executables.

windows Red Team

Hyperlapse (T)

Open-source JavaScript library for creating Street View hyperlapse animations.

geolocation-tools-maps

i2c-tools

Heterogeneous set of I2C tools for Linux

uncategorized Red Team

i2OCR

Free browser OCR service with broad multilingual support for extracting text from image and document files.

language-translation

I2P Anonymous Network (T)

I2P is an anonymous overlay network supporting eepsites, messaging, and peer-to-peer services.

dark-web opsec

IACA Dark Web Investigation Support

International Anti Crime Academy dark web investigation support portal for federated search workflows.

dark-web

iaxflood

VoIP flooder tool

impact Red Team

iaxscan

A Python based scanner for detecting live IAX/2 hosts and then enumerating (by bruteforce) users on those hosts.

scanner Red Team

ibombshell

Dynamic Remote Shell

uncategorized Red Team

ibrute

An AppleID password bruteforce tool. It uses Find My Iphone service API, where bruteforce protection was not implemented

cracker Red Team

IBus

Adjust input methods for the GUI.

general-utilities Blue Team

ICIJ Offshore Leaks Database

Searchable database of 800,000+ offshore entities from ICIJ investigations including Panama Papers, Paradise Papers, and Pandora Papers.

compliance-risk-intelligence

icloudbrutter

Tool for AppleID Bruteforce.

cracker Red Team

icmpquery

Send and receive ICMP queries for address mask and current time.

scanner Red Team

icmpsh

Simple reverse ICMP shell.

backdoor Red Team

icmptx

IP over ICMP tunnel.

tunnel Red Team

id-entify

Search for information related to a domain: Emails - IP addresses - Domains - Information on WEB technology - Type of Fi

recon Red Team

ID Ransomware

Free ransomware identification tool that analyzes ransom notes and encrypted file samples to identify variants and provide decryption guidance.…

malicious-file-analysis

ida

Interactive disassembler for software analysis.

general

ida-free

Freeware version of the world's smartest and most feature-full disassembler.

reversing Blue Team

ida.plugin.capa

capa explorer is an IDAPython plugin that integrates capa with IDA Pro.

ida-plugins Blue Team

ida.plugin.comida

ComIDA is an IDAPython Plugin that help analyzing modules using COM.

ida-plugins Blue Team

ida.plugin.delphihelper

DelphiHelper

ida-plugins Blue Team

ida.plugin.dereferencing

deREferencing is an IDAPython plugin that enhances registers and stack views by adding dereferenced pointers, colors, and other useful information.

ida-plugins Blue Team

ida.plugin.diaphora

Diaphora is an IDAPython plugin that performs advanced program diffing by comparing assembler, pseudo-code, functions, and data structures.

ida-plugins Blue Team

ida.plugin.flare

FLARE IDAPython plugins include Shellcode Hashes to find API calls from hashes and ApplyCalleeType to apply function prototypes to indirect calls.

ida-plugins Blue Team

ida.plugin.flare-emu

A user friendly scriptable emulation framework that supports multiple binary analysis tools.

ida-plugins Blue Team

ida.plugin.hashdb

HashDB is an IDAPython plugin that connects to an online community library to look up hashes, identifying API names and strings in malware.

ida-plugins Blue Team

ida.plugin.hrtng

hrtng is an IDA Pro plugin with features such as decryption, automation, deobfuscation, patching, lib code recognition and pseudocode transformations.

ida-plugins Blue Team

ida.plugin.ifl

IFL (Interactive Functions List) is an IDAPython plugin for navigating function references and importing reports from tools like PE-sieve.

ida-plugins Blue Team

ida.plugin.xray

xray is an IDAPython plugin that filters and colorizes Hexrays decompiler output based on regular expressions to highlight interesting code patterns.

ida-plugins Blue Team

ida.plugin.xrefer

XRefer is an IDAPython plugin that provides a custom navigation interface with path graphs and Gemini-powered descriptions to speed up analysis.

ida-plugins Blue Team

idafree

IDA Free is the free version of IDA Pro, a powerful Interactive DisAssembler and debugger.

disassemblers Blue Team

idb

A tool to simplify some common tasks for iOS pentesting and research.

mobile Red Team

IDCrawl

Free people search aggregator that finds social media profiles, photos, and public records across major platforms including Instagram, Facebook, and…

people-search-engines

ident-user-enum

Query ident to determine the owner of a TCP network process

uncategorized Red Team

identywaf

Blind WAF identification tool.

webapp Red Team

idGettr

Web utility for resolving Instagram usernames to numeric account IDs.

images-videos-docs

idr

IDR (Interactive Delphi Reconstructor) is a decompiler for Delphi-written Windows32 EXEs and DLLs.

delphi Blue Team

idswakeup

A collection of tools that allows to test network intrusion detection systems.

recon Red Team

ifchk

A network interface promiscuous mode detection tool.

defensive Blue Team

ifenslave

Configure network interfaces for parallel routing (bonding)

uncategorized Red Team

ifpstools

IFPSTools.NET creates, modifies, assembles, and disassembles RemObjects compiled bytecode files.

innosetup Blue Team

IFTTT

No-code automation platform connecting 900+ apps and services with trigger-action applets for automating workflows and data collection.

tools

ifuzz

A binary file fuzzer with several options.

fuzzer Red Team

ignorant

holehe but for phone numbers.

osint web Red Team

iheartxor

A tool for bruteforcing encoded strings within a boundary defined by a regular expression. It will bruteforce the key va

cracker Red Team

iheartxor.py (T)

Python script for brute-forcing XOR-obfuscated strings within defined boundaries to reveal hidden text in malware samples.

encoding-decoding

iis-shortname-scanner

An IIS shortname Scanner.

scanner Red Team

iisbruteforcer

HTTP authentication cracker. It's a tool that launchs an online dictionary attack to test for weak or simple passwords a

cracker Red Team

ike-scan

Discover and fingerprint IKE hosts (IPsec VPN Servers)

network-service-discovery Red Team

ikecrack

An IKE/IPSec crack tool designed to perform Pre-Shared-Key analysis of RFC compliant aggressive mode authentication

cracker Red Team

ikeforce

A command line IPSEC VPN brute forcing tool for Linux that allows group name/ID enumeration and XAUTH brute forcing capa

cracker Red Team

ikeprobe

Determine vulnerabilities in the PSK implementation of the VPN server.

windows Red Team

ikeprober

Tool crafting IKE initiator packets and allowing many options to be manually set. Useful to find overflows, error condit

fuzzer Red Team

Illuminarty

AI image detection tool that identifies AI-generated images and attempts to identify which AI model was used to create them.

ai-tools

ilo4-toolbox

Toolbox for HPE iLO4 analysis.

scanner Red Team

ILSpy

Examine and decompile .NET programs.

net Blue Team

ilty

An interception phone system for VoIP network.

voip Red Team

imagegrep

Grep word in pdf or image based on OCR.

misc Red Team

imagejs

Small tool to package javascript into a valid image file.

binary Red Team

imagejs-git

A Small tool to package javascript into a valid image file.

misc Red Team

ImageMagick

View and manipulate image and related files.

view-or-edit-files Blue Team

imagemounter

Command line utility and Python package to ease the (un)mounting of forensic disk images.

forensic Blue Team

ImageNet

Large-scale labeled image dataset used for computer vision and image classification research.

images-videos-docs

ImgOps

Meta-search utility that routes an image to multiple reverse search and forensic services.

disinformation-media-verification

Imgrab

Image download utility family used for saving individual or batch media from web pages.

images-videos-docs

Imgur Search

Search interface for Imgur-hosted public images, albums, and community media posts.

images-videos-docs

imhex

Hex Editor for Reverse Engineers, Programmers

uncategorized Red Team

impacket

Python3 module to easily build and dissect network protocols

uncategorized Red Team

impacket-ba

Collection of classes for working with network protocols.

exploitation Red Team

impacket-scripts

Links to useful impacket scripts examples

databases lateral-movement exfiltration Red Team

impulse

Modern Denial-of-service ToolKit.

dos Red Team

inception

A FireWire physical memory manipulation and hacking tool exploiting IEEE 1394 SBP DMA.

exploitation Red Team

inception-git

A FireWire physical memory manipulation and hacking tool exploiting IEEE 1394 SBP-2 DMA.

fuzzers Red Team

indx2csv

An advanced parser for INDX records.

forensic Blue Team

indxcarver

Carve INDX records from a chunk of data.

forensic Blue Team

indxparse

A Tool suite for inspecting NTFS artifacts.

forensic Blue Team

inetsim

Software suite for simulating common internet services

uncategorized Red Team

infection-monkey

Automated security testing tool for networks.

networking Red Team

infip

A python script that checks output from netstat against RBLs from Spamhaus.

scanner Red Team

Inflact Instagram Viewer (Anonymous)

Anonymous Instagram viewer for browsing public profiles, stories, and posts without authenticating to Instagram directly.

social-networks

Influence Explorer

Campaign finance, lobbying, and political data aggregator. Part of OpenSecrets ecosystem with federal and state data.

public-records

InfluxDB

InfluxDB is an open source time series platform.

network-security-monitoring Blue Team

Info Sniper

Multi-field reverse OSINT tool for IP, email, phone lookups with social media enumeration.

ip-mac-address

Info-ZIP

Compress and decompress files using the zip algorithm.

general-utilities Blue Team

InfoFlow Public People Search In Chilean

Chilean public records lookup service for vehicle registrations, personal ID numbers (RUN), company information, and reverse name-to-RUN lookups via…

people-search-engines

infoga

Tool for gathering e-mail accounts information from different public sources (search engines, pgp key servers).

recon Red Team

inguma

A free penetration testing and vulnerability discovery toolkit entirely written in python. Framework includes modules to

cracker Red Team

injectus

CRLF and open redirect fuzzer.

webapp Red Team

innounp

Inno Setup Unpacker.

reversing Blue Team

inquisitor

OSINT Gathering Tool for Companies and Organizations.

recon Red Team

insanity

Generate Payloads and Control Remote Machines .

exploitation Red Team

inspectrum

Tool for visualising captured radio signals

uncategorized Red Team

inspircd 3

Examine IRC activity with this IRC server.

services Blue Team

inspy

LinkedIn enumeration tool

uncategorized Red Team

InSpy (T)

LinkedIn-focused reconnaissance tool that combines profile discovery with email pattern generation.

social-networks

Instagram

Main Instagram platform used for public profile, hashtag, and location OSINT collection.

images-videos-docs

instagramosint

An Instagram Open Source Intelligence Tool.

social Red Team

instaloader

Instagram automatic photo downloader

identity-information Red Team

Instant Google Street View

Fast launcher for jumping directly into Google Street View at precise locations.

geolocation-tools-maps

instashell

Multi-threaded Instagram Brute Forcer without password limit.

cracker Red Team

Instya

eCommerce product search engine and shopping discovery platform. NOT suitable for general web OSINT research - category mismatch with Search Engines.

search-engines

Intel Techniques - Hiding from the Internet

Michael Bazzell’s OSINT workbook covering comprehensive personal data removal, digital footprint reduction, and operational security techniques.

opsec

IntelligenceX

Web-based intelligence search platform aggregating pastes, leaks, darknet content, stealer logs, and public records across Tor, I2P, and surface web.

tools

intelmq

A tool for collecting and processing security feeds using a message queuing protocol.

misc Red Team

intelplot

OSINT Tool to Mark Points on Offline Map.

recon Red Team

intensio-obfuscator

Obfuscate a python code 2 and 3.

misc Red Team

interactsh-client

Open-Source Solution for Out of band Data Extraction.

webapp Red Team

intercepter-ng

A next generation sniffer including a lot of features: capturing passwords/hashes, sniffing chat messages, performing ma

windows Red Team

interlace

Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support

networking Red Team

interlock-git

File encryption front-end

crypto Red Team

International Registries

UK government page listing official overseas company registries for countries worldwide, linking to each nation's official registration authority.

business-records

International White Pages

WAYP.com is an international white pages and business directory aggregating contact listings from multiple countries.

business-records

Internet Archive: Wayback Machine

Web archive providing historical snapshots of websites captured over time.

archives

internet_detector

Tool that changes the background and a taskbar icon if it detects internet connectivity

networking Blue Team

interrogate

A proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating syst

forensic Blue Team

intersect

Post-exploitation framework.

automation Red Team

intrace

Traceroute-like application piggybacking on existing TCP connections

system-network-configuration-discovery Red Team

intrace-git

Traceroute-like application piggybacking on existing TCP connections

recon Red Team

IntRec-Pack (T)

Bash script bundle for automated download, installation, and deployment of 14 OSINT and recon tools.

tools

inundator

An ids evasion tool, used to anonymously inundate intrusion detection logs with false positives in order to obfuscate a

misc Red Team

inurlbr

Advanced search in the search engines - Inurl scanner, dorker, exploiter.

scanner Red Team

InVID-WeVerify Verification Plugin

Journalist-focused browser plugin for media verification, reverse image search, metadata checks, and video keyframe analysis.

disinformation-media-verification

inviteflood

SIP/SDP INVITE message flooding over UDP/IP

impact Red Team

invoke-cradlecrafter

PowerShell Remote Download Cradle Generator & Obfuscator.

automation Red Team

invoke-dosfuscation

Cmd.exe Command Obfuscation Generator & Detection Test Harness.

automation Red Team

invoke-obfuscation

PowerShell Obfuscator.

automation Red Team

inzider

This is a tool that lists processes in your Windows system and the ports each one listen on.

windows Red Team

ioc_parser

Extract IOCs from security report PDFs.

gather-and-analyze-data Red Team

iodine

Tool for tunneling IPv4 data through a DNS server

protocol-tunneling Red Team

iosforensic

iOS forensic tool.

forensic Blue Team

IP / DNS Leak Detection

Comprehensive leak detection tool that tests for IP, DNS, WebRTC, and IPv6 leaks to verify VPN or Tor anonymization is working correctly.

opsec

IP Fingerprints

Reverse IP lookup service identifying all domains hosted on a given IP address.

ip-mac-address

IP Fingerprints - Reverse IP Lookup

Find all domains hosted on a shared IP address through reverse IP lookup.

ip-mac-address

ip-https-tools

Tools for the IP over HTTPS (IP-HTTPS) Tunneling Protocol.

tunnel Red Team

IP Logger

IP logging and URL shortening service tracking visitor IP, location, and browser data.

ip-mac-address

ip-tracer

Track and retrieve any ip address information.

recon Red Team

IP Void

IP reputation and threat intelligence service analyzing blacklist status and security risks.

ip-mac-address

ip2clue

A small memory/CPU footprint daemon to lookup country (and other info) based on IP (v4 and v6).

recon Red Team

IP2Location.com

Commercial IP geolocation service with free demo and database. Provides location, proxy detection, and network data.

ip-mac-address

IP2WHOIS

Free WHOIS lookup service for domain names and IP addresses, providing registration details, registrant information, location data, and API access.

domain-name

ipaudit

Monitors network activity on a network.

networking Red Team

ipba2

IOS Backup Analyzer.

forensic Blue Team

ipcountry

Fetches IPv4 ranges of given country in host and cidr format.

misc Red Team

ipdecap

Can decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, and can also remove IEEE 802.1Q (vir

networking Red Team

iphoneanalyzer

Allows you to forensically examine or recover date from in iOS device.

forensic Blue Team

ipinfo

Get information about an IP address or hostname.

osint web Red Team

ipmipwn

IPMI cipher 0 attack tool.

cracker Red Team

ipobfuscator

A simple tool to convert the IP to a DWORD IP.

misc Red Team

ipphoney

ipphoney honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

ipscan

A very fast IP address and port scanner.

scanner Red Team

ipsourcebypass

This Python script can be used to bypass IP source restrictions using HTTP headers.

webapp Red Team

ipsumdump

A tool that summarizes TCP/IP dump files into a self-describing ASCII format easily readable by humans and programs

uncategorized Red Team

iptables

Userspace command line tool for configuring kernel firewall

ad

iptodomain

This tool extract domains from IP address based in the information saved in virustotal.

recon Red Team

iptv

Search and brute force illegal iptv server.

scanner Red Team

IPv4 CIDR Report

Tool for analyzing IPv4 CIDR blocks and finding contained IP addresses and subnets.

ip-mac-address

IPv4/IPv6 lists by country code

Database of IPv4 and IPv6 address ranges organized by country for geographic IP filtering.

ip-mac-address

ipv4bypass

Using IPv6 to Bypass Security.

networking Red Team

IPv6 CIDR Report

CIDR block analysis tool for IPv6 address ranges and subnet enumeration.

ip-mac-address

IPv6 Leak Tests

Tests whether IPv6 connectivity is leaking your real IP address outside a VPN tunnel that only routes IPv4 traffic.

opsec

ipv666

Golang IPv6 address enumeration.

recon Red Team

ipv6toolkit

IPv6 assessment and troubleshooting tools

uncategorized Red Team

ipwhois

Retrieve and parse whois data for IP addresses.

gather-and-analyze-data Red Team

IRCP (T)

Python-based IRC probing utility for scanning servers and collecting network/channel metadata.

online-communities

ircsnapshot

Tool to gather information from IRC servers.

recon Red Team

irpas

Internetwork Routing Protocol Attack Suite

system-network-configuration-discovery Red Team

isd

Inno Setup Decompiler provides a useful UI to analyze Inno Setup compiled code scripts.

innosetup Blue Team

isf

An exploitation framework based on Python.

exploitation Red Team

isip

Interactive sip toolkit for packet manipulations, sniffing, man in the middle attacks, fuzzing, simulating of dos attack

voip Red Team

isme

Scans a VOIP environment, adapts to enterprise VOIP, and exploits the possibilities of being connected directly to an IP

voip Red Team

ismtp

SMTP user enumeration and testing tool

uncategorized Red Team

isr-evilgrade

Evilgrade framework

execution Red Team

isr-form

Simple html parsing tool that extracts all form related information and generates reports of the data. Allows for quick

recon Red Team

issniff

Internet Session Sniffer.

sniffer Red Team

itpp

C++ library of mathematical, signal processing and communication routines

uncategorized Red Team

ivre

Network recon framework IVRE or DRUNK

uncategorized Red Team

ivre-docs

Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (documentation)

recon Red Team

ivre-web

Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (web application)

recon Red Team

iw

Tool for configuring Linux wireless devices

uncategorized Red Team

iZito

Metasearch engine aggregating results from multiple sources including Wikipedia, videos, news, and products. Designed to support non-linear search…

search-engines

ja3

Standard for creating SSL client fingerprints in an easy to produce and shareable way.

crypto Red Team

jaadas

Joint Advanced Defect assEsment for android applications.

scanner Red Team

jackdaw

Collect all information in your domain, show you graphs on how domain objects interact with each-other and how to exploi

recon Red Team

jackit

Exploit to take over a wireless mouse and keyboard

general

jadx

Dex to Java decompiler

resource-development Red Team

jaeles

The Swiss Army knife for automated Web Application Testing.

webapp Red Team

jaidam

Penetration testing tool that would take as input a list of domain names, scan them, determine if wordpress or joomla pl

webapp Red Team

jast

Just Another Screenshot Tool.

webapp Red Team

Java IDX Parser

Analyze Java IDX files.

java Blue Team

JavaScript Deobfuscator

Deobfuscate JavaScript by removing common obfuscation techniques such as string arrays and proxy functions.

scripts Blue Team

javasnoop

Intercept Java applications locally

resource-development Red Team

Javassist

Java bytecode engineering toolkit/library.

java Blue Team

jbe

Java bytecode editor suitable for viewing and modifying java class files.

decompiler Blue Team

jboss-autopwn

JBoss script for obtaining remote shell access

initial-access Red Team

jboss-autopwn-git

A JBoss script for obtaining remote shell access

exploit Red Team

jbrofuzz

Web application protocol fuzzer that emerged from the needs of penetration testing.

fuzzer Red Team

jbrute

Open Source Security tool to audit hashed passwords.

cracker Red Team

jcrack

A utility to create dictionary files that will crack the default passwords of select wireless gateways

wireless Red Team

jd-cli

Command line Java Decompiler.

decompiler Blue Team

jd-gui

GUI Java .class decompiler

resource-development Red Team

JD-GUI Java Decompiler

Java decompiler with GUI.

java Blue Team

jdeserialize

A library that interprets Java serialized objects. It also comes with a command-line tool that can generate compilable c

webapp Red Team

jdwp

This exploitation script is meant to be used by pentesters against active JDWP service / in order to gain Remote Code Execution.

ad web

jdwp-knife

Advanced JDWP exploitation and data extraction tool with interactive shell.

exploitation Red Team

jeangrey

A tool to perform differential fault analysis attacks (DFA).

cracker Red Team

jeb-android

Android decompiler.

reversing Blue Team

jeb-arm

Arm decompiler.

reversing Blue Team

jeb-intel

Intel decompiler.

reversing Blue Team

jeb-mips

Mips decompiler.

reversing Blue Team

jeb-webasm

WebAssembly decompiler.

reversing Blue Team

jefferson

JFFS2 filesystem extraction tool.

forensic Blue Team

jeopardize

A low(zero) cost threat intelligence & response tool against phishing domains.

defensive Blue Team

jexboss

Jboss verify and Exploitation Tool.

webapp Red Team

jigsaw

A simple ruby script for enumerating information about a company's employees. It is useful for Social Engineering or Email Phishing. Source no long on

social-engineering Red Team

jinjector

Joomla modules backdoor injector.

backdoor Red Team

jira-scan

A simple remote scanner for Atlassian Jira

webapp Red Team

jndi-injection-exploit

A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability, like Jackson, Fastj

exploitation Red Team

jnetmap

A network monitor of sorts.

networking Red Team

john

Active password cracking tool

password-cracking credential-access Red Team

johnny

GUI for John the Ripper

password-cracking Red Team

jok3r

Network and Web Pentest Framework.

webapp Red Team

jomplug

This php script fingerprints a given Joomla system and then uses Packet Storm's archive to check for bugs related to the

webapp Red Team

jondo

Redirects internet traffic trough a mix of proxy servers to hide the origin of the requests.

proxy Red Team

JonDonym

Anonymization verification tool from the JonDonym project that checks IP, browser headers, cookies, and other identifiers for privacy leaks.

opsec

jooforce

A Joomla password brute force tester.

webapp Red Team

joomlascan

Joomla scanner scans for known vulnerable remote file inclusion paths and files.

webapp Red Team

joomlavs

A black box, Ruby powered, Joomla vulnerability scanner.

webapp Red Team

joomscan

OWASP Joomla Vulnerability Scanner Project

web-vulnerability-scanning Red Team

joplin

Open source note taking and to-do application

uncategorized Red Team

Jotti's Malware Scanner

Free multi-scanner malware analysis service that submits files for analysis against 14+ antivirus engines. No installation or account setup required.

malicious-file-analysis

jpegdump

Tool to analyzse JPEG images Reads binary files and parses the JPEG markers inside them.

binary Red Team

JPEGsnoop (T)

Windows forensic utility for deep JPEG structure analysis, recompression detection, and authenticity clues.

images-videos-docs

jpexs-decompiler

JPEXS Free Flash Decompiler.

decompiler Blue Team

JS Beautifier

Reformat JavaScript scripts for easier analysis.

scripts Blue Team

js-beautify

JavaScript beautifier and deobfuscator.

javascript Blue Team

js-deobfuscator

Deobfuscator to remove common JS obfuscation techniques.

javascript Blue Team

js_unshroud

Monitor and deobfuscate JavaScript behavior in a headless browser to analyze malicious web pages.

scripts Blue Team

jsearch

Simple script that grep infos from javascript files.

recon Red Team

jsfuck

Write any JavaScript with 6 Characters: []()!+.

misc Red Team

jshell

Get a JavaScript shell with XSS.

webapp Red Team

jsluice

Extract URLs / paths / secrets and other interesting data from JavaScript source code.

ad web

jsonbee

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP).

webapp Red Team

jsp-file-browser

File browser java server page

uncategorized Red Team

jsparser

Parse javascript using Tornado and JSBeautifier to discover interesting enpoints.

webapp Red Team

jsql

Java tool for automatic database injection

initial-access Red Team

jsql-injection

A Java application for automatic SQL database injection.

webapp Red Team

jstillery

Advanced JavaScript Deobfuscation via Partial Evaluation.

webapp Red Team

judyrecords

Free nationwide court case search engine with 760M+ US court cases. Covers federal and state courts with 10x more cases than PACER.

public-records

juice-shop

Insecure web application

laboratories system-services Red Team

juicy-potato

A sugared version of RottenPotatoNG, with a bit of juice.

windows Red Team

junkie

A modular packet sniffer and analyzer.

sniffer Red Team

JURN

Multidisciplinary search engine indexing freely accessible academic articles; covers arts, humanities, ecology, and social sciences with a focus on…

search-engines

justdecompile

The decompilation engine of JustDecompile.

windows Red Team

juumla

Python tool created to identify Joomla version, scan for vulnerabilities and search for config files.

webapp Red Team

jwscan

Scanner for Jar to EXE wrapper like Launch4j, Exe4j, JSmooth, Jar2Exe.

reversing Blue Team

jwt

a command-line tool for working with JSON Web Tokens (JWTs)

ad light web

jwt-cracker

JWT brute force cracker written in C.

cracker Red Team

jwt-hack

A tool for hacking / security testing to JWT.

webapp Red Team

jwt-key-recovery

Recovers the public key used to sign JWT tokens.

crypto Red Team

jwt-tool

Toolkit for validating, forging and cracking JWTs (JSON Web Tokens).

cracker Red Team

jwtcat

Script performs offline brute-force attacks against JSON Web Token (JWT)

cracker Red Team

jynx2

An expansion of the original Jynx LD_PRELOAD rootkit.

backdoor Red Team

k55

Linux x86_64 Process Injection Utility.

backdoor Red Team

k9s

TUI interface for managing Kubernetes clusters.

general

kacak

Tools for penetration testers that can enumerate which users logged on windows system.

recon Red Team

kadimus

LFI Scan & Exploit Tool.

webapp Red Team

kali-autopilot

Tool for automatic attack scripts in Kali

uncategorized Red Team

kali-community-wallpapers

Transitional package to install kali-wallpapers-community

uncategorized Red Team

kali-defaults

Kali default settings

uncategorized Red Team

Kali Linux OS (T)

Open-source Debian-based distribution with 600+ pre-installed security tools for penetration testing, security research, and reverse engineering.

tools

kali-tweaks

Tool to adjust advanced configuration settings for Kali Linux

services-and-other-tools Red Team

kali-wallpapers

Transitional package to install kali-wallpapers-legacy

uncategorized Red Team

kalibrate-rtl

Calculate local oscillator frequency offset using GSM base stations

uncategorized Red Team

kalibrate-rtl-git

Fork of http://thre.at/kalibrate/ for use with rtl-sdr devices

uncategorized Red Team

kamerka

Build interactive map of cameras from Shodan.

recon Red Team

karma-hostapd

a set of patches to access point software to get it to respond to probe requests not just for itself but for any ESSID requested

uncategorized Red Team

katana

Next-generation crawling and spidering framework.

uncategorized Red Team

katana-framework

A framework that seekss to unite general auditing tools, which are general pentesting tools (Network,Web,Desktop and oth

exploitation Red Team

katana-pd

Crawling and spidering framework.

webapp Red Team

katsnoop

Utility that sniffs HTTP Basic Authentication information and prints the base64 decoded form.

sniffer Red Team

kautilya

Pwnage with Human Interface Devices using Teensy++2.0 and Teensy 3.0 devices.

hardware Red Team

keepassxc

Cross-platform password manager

ad osint web Red Team

KeePwn

KeePwn is a tool that extracts passwords from KeePass 1.x and 2.x databases.

ad

keimpx

Tool to verify the usefulness of credentials across a network over SMB.

cracker Red Team

kekeo

A little toolbox to play with Microsoft Kerberos in C.

windows Red Team

kerbcrack

Kerberos sniffer and cracker for Windows.

windows Red Team

kerberoast

Tools for attacking MS Kerberos implementations

kerberoasting Red Team

kerbrute

A tool to perform Kerberos pre-auth bruteforcing.

cracker Red Team

kerbrute-git

A tool to quickly bruteforce and enumerate valid Active Directory accounts through Kerberos Pre-Authentication

enumeration Red Team

kernelpop

Kernel privilege escalation enumeration and exploitation framework.

exploitation Red Team

Keybase

Platform for cryptographic identity verification, linking social media accounts, PGP keys, and cryptocurrency addresses to a single profile. Acquired…

username

keye

Recon tool detecting changes of websites based on content-length differences.

recon Red Team

keystone

Keystone is a Python library providing a multi-platform, multi-architecture assembler.

utilities Blue Team

keytabextract

KeyTabExtract is a tool to extract valuable information from keytab files.

ad

kh2hc

Convert OpenSSH known_hosts file hashed with HashKnownHosts to hashes crackable by Hashcat.

crypto Red Team

khc

A small tool designed to recover hashed known_hosts fiels back to their plain-text equivalents.

cracker Red Team

Kibana

Kibana

network-security-monitoring Blue Team

kickthemout

Kick devices off your network by performing an ARP Spoof attack.

networking Red Team

Kik (T)

Messaging app with 300M+ registered users. Public username search and profile visibility.

mobile-osint Red Team

killcast

Manipulate Chromecast Devices in your Network.

exploitation Red Team

killerbee

Framework and tools for exploiting ZigBee and IEEE 802.15.4 networks.

exploitation Red Team

kimi

Script to generate malicious debian packages (debain trojans).

backdoor Red Team

kippo

A medium interaction SSH honeypot designed to log brute force attacks and most importantly, the entire shell interaction

honeypot Blue Team

kismet

Wireless network and device detector (metapackage)

wifi Red Team

kismet-earth

Various scripts to convert kismet logs to kml file to be used in Google Earth.

wireless Red Team

kismet2earth

A set of utilities that convert from Kismet logs to Google Earth .kml format.

wireless Red Team

kismon

GUI client for kismet (wireless scanner/sniffer/monitor).

wireless Red Team

kiterunner

Contextual Content Discovery Tool.

webapp Red Team

kitty-framework

Fuzzing framework written in python.

fuzzer Red Team

klar

Integration of Clair and Docker Registry.

exploitation Red Team

klee

A symbolic virtual machine built on top of the LLVM compiler infrastructure.

binary Red Team

klogger

A keystroke logger for the NT-series of Windows.

windows Red Team

knock

Subdomain scanner.

scanner Red Team

knocker

Simple and easy to use TCP security port scanner

uncategorized Red Team

knxmap

KNXnet/IP scanning and auditing tool for KNX home automation installations.

scanner Red Team

koadic

Windows post-exploitation rootkit

command-and-control Red Team

kolkata

A web application fingerprinting engine written in Perl that combines cryptography with IDS evasion.

fingerprint Red Team

konan

Advanced Web Application Dir Scanner.

webapp Red Team

Koodous

Collaborative platform for Android malware research and analysis with community-driven database of 70+ million Android applications with…

malicious-file-analysis

kraken

A project to encrypt A5/1 GSM signaling using a Time/Memory Tradeoff Attack.

crypto Red Team

kraken-git

A project to encrypt A5/1 GSM signaling using a Time/Memory Tradeoff Attack.

hardware Red Team

Kraken (T)

Open-source reconnaissance utility for domain and network intelligence gathering workflows.

domain-name

krbjack

DNS dynamic update abuse in ADIDNS and MitM attack using Kerberos AP-REQ hijacking.

networking Red Team

krbrelayx

Kerberos relaying and unconstrained delegation abuse toolkit

kerberoasting Red Team

kscan

Asset mapping tool that can perform port scanning, TCP fingerprinting and banner capture for specified assets.

scanner Red Team

kube-hunter

Hunt for security weaknesses in Kubernetes clusters.

scanner Red Team

kubectl

Command-line interface for managing Kubernetes clusters.

general

kubernetes-helm

Tool for managing Charts (helm)

uncategorized Red Team

kubesploit

Cross-platform post-exploitation HTTP/2 Command & Control server.

scanner Red Team

kubestriker

A Blazing fast Security Auditing tool for Kubernetes.

scanner Red Team

kubolt

Utility for scanning public kubernetes clusters.

webapp Red Team

kustomize

Customization of Kubernetes YAML configurations (program)

uncategorized Red Team

kwetza

Python script to inject existing Android applications with a Meterpreter payload.

backdoor Red Team

kwprocessor

Advanced keyboard-walk generator with configureable basechars, keymap and routes

crackers Red Team

l0l

The Exploit Development Kit.

exploitation Red Team

laf

Login Area Finder: scans host/s for login panels.

scanner Red Team

LandsatLook Viewer

USGS viewer for browsing Landsat scenes and multispectral imagery.

geolocation-tools-maps

lanmap2

Passive network mapping tool.

recon Red Team

lans

A Multithreaded asynchronous packet parsing/injecting arp spoofer.

spoof Red Team

lapsdumper

Tool that dumps LAPS passwords

uncategorized Red Team

latd

A LAT terminal daemon for Linux and BSD.

networking Red Team

laudanum

Collection of injectable web files

persistence Red Team

lazagne

An open source application used to retrieve lots of passwords stored on a local computer.

forensic Blue Team

Lazy Scholar (T)

Browser extension that automatically finds free legal full-text versions of academic papers when viewing paywalled content; checks open-access…

search-engines

lazydroid

Tool written as a bash script to facilitate some aspects of an Android Assessment

mobile Red Team

lazys3 (T)

S3 bucket brute-forcing utility that generates candidate names from permutations and checks bucket accessibility.

cloud-infrastructure

lbd

Load balancer detector

web-scanning Red Team

lbmap

Proof of concept scripts for advanced web application fingerprinting, presented at OWASP AppSecAsia 2012.

fingerprint Red Team

ld-shatner

ld-linux code injector.

backdoor Red Team

ldap-brute

A semi fast tool to bruteforce values of LDAP injections over HTTP.

cracker Red Team

ldapconsole

Script allows you to perform custom LDAP requests to a Windows domain.

networking Red Team

ldapdomaindump

Active Directory information dumper via LDAP

uncategorized Red Team

ldapenum

Enumerate domain controllers using LDAP.

recon Red Team

ldapmonitor

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!

windows Red Team

ldaprelayscan

Check Domain Controllers for LDAP server protections regarding the relay of NTLM authentication.

ad

ldapscripts

Simple shell scripts to handle POSIX entries in an LDAP directory.

automation Red Team

ldapsearch

Search for and display entries (ldap)

ad

ldapsearch-ad

LDAP search utility with AD support

ad

ldapwordlistharvester

Tool to generate wordlist from information present in LDAP, in order to crack passwords of domain accounts.

wordlist Red Team

ldeep

In-depth ldap enumeration utility

active-directory Red Team

ldsview

Offline search tool for LDAP directory dumps in LDIF format.

forensic Blue Team

leaklooker

Find open databases with Shodan.

scanner Red Team

leena

Symbolic execution engine for JavaScript

binary Red Team

legba

Multiprotocol credentials bruteforcer / password sprayer and enumerator

brute-force Red Team

legion

Semi-automated network penetration testing tool

network-information reconnaissance Red Team

Lenso.ai

AI reverse image and face matching platform designed to find similar or edited visual content.

images-videos-docs

leo

Literate programmer's editor, outliner, and project manager.

misc Red Team

leroy-jenkins

A python tool that will allow remote execution of commands on a Jenkins server and its nodes.

exploitation Red Team

lethalhta

Lateral Movement technique using DCOM and HTA.

windows Red Team

letmefuckit-scanner

Scanner and Exploit Magento.

scanner Red Team

leviathan

A mass audit toolkit which has wide range service discovery, brute force, SQL injection detection and running custom exp

scanner Red Team

levye

A brute force tool which is support sshkey, vnckey, rdp, openvpn.

cracker Red Team

lfi-autopwn

A Perl script to try to gain code execution on a remote server via LFI.

exploitation Red Team

lfi-exploiter

This perl script leverages /proc/self/environ to attempt getting code execution out of a local file inclusion vulnerabil

webapp Red Team

lfi-fuzzploit

A simple tool to help in the fuzzing for, finding, and exploiting of local file inclusion vulnerabilities in Linux-based

webapp Red Team

lfi-image-helper

A simple script to infect images with PHP Backdoors for local file inclusion attacks.

webapp Red Team

lfi-scanner

This is a simple perl script that enumerates local file inclusion attempts when given a specific target.

scanner Red Team

lfi-sploiter

This tool helps you exploit LFI (Local File Inclusion) vulnerabilities. Post discovery, simply pass the affected URL and

webapp Red Team

lfifreak

A unique automated LFi Exploiter with Bind/Reverse Shells.

webapp Red Team

lfimap

Local file inclusion discovery and exploitation tool.

webapp Red Team

lfisuite

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner.

scanner Red Team

lfle

Recover event log entries from an image by heurisitically looking for record structures.

forensic Blue Team

lft

A layer four traceroute implementing numerous other features.

recon Red Team

lhf

A modular recon tool for pentesting.

recon Red Team

libbde

A library to access the BitLocker Drive Encryption (BDE) format.

crypto Red Team

libbfio

Library to provide basic file input/output abstraction

uncategorized Red Team

libbtbb-git

A library to decode Bluetooth baseband packets, as produced by the Ubertooth and GR-Bluetooth projects.

uncategorized Red Team

libc-database

Database of libc offsets to simplify exploitation.

reversing Blue Team

libdaq-static

Data Acquisition library for packet I/O.

uncategorized Red Team

libdisasm

A disassembler library.

disassembler Blue Team

libemu

A library for x86 code emulation and shellcode detection.

shellcode Blue Team

libestr

essentials for string handling (and a bit more)

uncategorized Red Team

libevent-static

An event notification library static libs

uncategorized Red Team

libewf

Collection of tools for reading and writing EWF files

forensic-imaging-tools Blue Team

libfastjson

A small library with essential json handling functions

uncategorized Red Team

libfindrtp

Library required by multiple VoIP tools

uncategorized Red Team

libfixbuf

IPFIX Message Format Implementation

uncategorized Red Team

libfvde

Library and tools to access FileVault Drive Encryption (FVDE) encrypted volumes.

forensic Blue Team

libguytools

A small programming toolbox for Guymager

uncategorized Red Team

libhtp

LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces

uncategorized Red Team

libimage-exiftool-perl

Library and program to read and write meta information in multimedia files

uncategorized Red Team

liblognorm

log normalization library for rsyslog

uncategorized Red Team

libmspack

C library for Microsoft compression formats.

ad

libnacl

NaCl (pronounced 'salt') Networking and Cryptography library (works with pynacl)

uncategorized Red Team

libnfc

Library for Near Field Communication (NFC) devices

general

libnfc-crypto1-crack

Implementation of cryptographic attack on Mifare Classic RFID cards

general

libolecf

Microsoft Office OLE2 compound documents.

microsoft-office Blue Team

libosmocore

Collection of common code used in various sub-projects inside the Osmocom family of projects.

radio Red Team

libowfat

GPL reimplementation of libdjb

uncategorized Red Team

libparistraceroute

A library written in C dedicated to active network measurements with examples, such as paris-ping and paris-traceroute.

networking Red Team

libpfm4

The hardware-based performance monitoring interface for Linux.

uncategorized Red Team

libpst

Library for reading Microsoft Outlook PST files (development files)

digital-forensics Blue Team

libraries.python3

Python 3 libraries useful for common reverse engineering tasks.

python Blue Team

Library Databases

University of Florida Library's A-Z database directory providing access to hundreds of academic databases covering all disciplines; useful as a…

search-engines

LibreOffice

LibreOffice

desktop-edition

libsmali-java

Assembler/disassembler for Android’s dex format

uncategorized Red Team

libtins

High-level, multiplatform C++ network packet sniffing and crafting library.

networking Red Team

libusb-dev

Library for USB device access

general

lief

Library to instrument executable formats.

disassembler Blue Team

liffy

A Local File Inclusion Exploitation tool.

webapp Red Team

lightbulb

Python framework for auditing web applications firewalls.

webapp Red Team

ligolo-mp

Multiplayer pivoting solution

protocol-tunneling Red Team

ligolo-ng

Advanced, yet simple, tunneling/pivoting tool that uses a TUN interface

protocol-tunneling Red Team

ligolo-ng-common-binaries

Prebuilt binaries for Advanced ligolo-ng

protocol-tunneling Red Team

limeaide

Remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

forensic Blue Team

limelighter

A tool for generating fake code signing certificates or signing real ones.

exploitation Red Team

line-message-analyzer (T)

Local analysis utility for LINE chat exports that computes message statistics and conversational activity patterns.

instant-messaging

LINE (T)

Messaging app with 200M+ users, dominant in Asia. User search and public profile visibility.

mobile-osint Red Team

linelog2py (T)

Python parser for processing exported LINE chat logs into structured records for analysis.

instant-messaging

linenum

Scripted Local Linux Enumeration & Privilege Escalation Checks

scanner Red Team

linenum-git

Scripted Local Linux Enumeration & Privilege Escalation Checks

scanners Red Team

linikatz

Tool to attack AD on UNIX.

automation Red Team

linkedin2username

Generate username lists for companies on LinkedIn

identity-information Red Team

linkedint

LinkedIn Recon Tool.

social Red Team

linkfinder

Discovers endpoint and their parameters in JavaScript files.

webapp Red Team

linset

Evil Twin Attack Bash script - An automated WPA/WPA2 hacker.

automation Red Team

linux-exploit-suggester

LES: Linux privilege escalation auditing tool

uncategorized Red Team

linux-exploit-suggester-git

A Perl script that tries to suggest exploits based OS version number

recon Red Team

linux-exploit-suggester.sh

Linux privilege escalation auditing tool.

recon Red Team

linux-inject

Tool for injecting a shared object into a Linux process.

backdoor Red Team

linux-smart-enumeration

Linux enumeration tool for pentesting and CTFs with verbosity levels.

scanner Red Team

lisa.py

An Exploit Dev Swiss Army Knife.

exploitation Red Team

lisa.py-git

An Exploit Dev Swiss Army Knife.

exploit Red Team

list-urls

Extracts links from webpage.

webapp Red Team

littleblackbox

Penetration testing tool, search in a collection of thousands of private SSL keys extracted from various embedded device

scanner Red Team

littlebrother

OSINT tool to get informations on French, Belgian and Swizerland people.

recon Red Team

LittleSis

Free database mapping relationships between powerful people and organizations, tracking political donors, lobbyists, board members, and corporate…

business-records

Live Journal Seek

Search tool for LiveJournal journals and communities across public entries that are indexed.

online-communities

LiveUaMap

Conflict/event mapping platform that geolocates incidents from public reporting.

geolocation-tools-maps

llm-tools-nmap

Plugin for LLM tool hat provides Nmap network scanning capabilities

uncategorized Red Team

llvm-defaults

C, C++ and Objective-C compiler (LLVM based), clang binary

resource-development Red Team

lnkup

This tool will allow you to generate LNK payloads. Upon rendering or being run they will exfiltrate data.

ad

loadlibrary

Porting Windows Dynamic Link Libraries to Linux.

binary Red Team

local-php-security-checker

A command line tool that checks your PHP application packages with known security vulnerabilities.

code-audit Red Team

locasploit

Local enumeration and exploitation framework.

scanner Red Team

lodowep

Lodowep is a tool for analyzing password strength of accounts on a Lotus Domino webserver system.

cracker Red Team

log-file-parser

Parser for $LogFile on NTFS.

forensic Blue Team

log4cxx-svn

A C++ port of Log4j

uncategorized Red Team

log4j-bypass

Log4j web app tester that includes WAF bypasses.

webapp Red Team

log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-44228.

webapp Red Team

log4pot

log4pot honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

logkeys

A GNU/Linux keylogger that worked.

keylogger Red Team

logmepwn

A fully automated, reliable, super-fast, mass scanning and validation toolkit for the Log4J RCE CVE-44228 vulnerability.

scanner Red Team

Logstash

By default, Logstash uses in-memory bounded queues between pipeline stages (inputs → pipeline workers) to buffer events.

network-security-monitoring Blue Team

loic

An open source network stress tool for Windows.

networking Red Team

loki-scanner

Simple IOC and Incident Response Scanner.

forensic Blue Team

lolbas

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts).

windows Red Team

loot

Sensitive information extraction tool.

recon Red Team

lorg

Apache Logfile Security Analyzer.

defensive Blue Team

lorsrf

Find the parameters that can be used to find SSRF or Out-of-band resource load.

webapp Red Team

lotophagi

a relatively compact Perl script designed to scan remote hosts for default (or common) Lotus NSF and BOX databases.

scanner Red Team

lsassy

Windows secrets and passwords extraction tool.

ad

lsof

Utility to list open files

uncategorized Red Team

lsrtunnel

Spoofs connections using source routed packets.

spoof Red Team

lte-cell-scanner

An OpenCL accelerated TDD/FDD LTE Scanner.

radio Red Team

LTE Discovery

Advanced signal discovery and analysis

rf

ltrace

Trace library calls and signals.

elf-files Blue Team

LUKS

Support for both LUKS and VeraCrypt encrypted volumes (like USB sticks)

encryption-and-privacy

luksipc

A tool to convert unencrypted block devices to encrypted LUKS devices in-place.

crypto Red Team

Lullar

Free people search and username lookup tool that searches across 148+ social media platforms including Instagram, TikTok, Facebook, and LinkedIn.

people-search-engines username

lulzbuster

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl.

webapp Red Team

lunar

A UNIX security auditing tool based on several security frameworks.

scanner Red Team

luyten

An Open Source Java Decompiler Gui for Procyon.

decompiler Blue Team

lvm2

Linux Logical Volume Manager

uncategorized Red Team

lynis

Security auditing tool for Unix based systems

privilege-escalation Red Team

Lynxio OSINT

Mobile OSINT search tool for multi-identifier reconnaissance. Searches across phone numbers, email addresses, usernames, and social platforms.

mobile-osint Red Team

lyricpass

Tool to generate wordlists based on lyrics.

automation Red Team

m3-gen

Generates Malicious Macro and Execute Powershell or Shellcode via MSBuild Application Whitelisting Bypass, this tool int

exploitation Red Team

mac-robber

Collects data about allocated files in mounted filesystems

uncategorized Red Team

macchanger

Utility for manipulating the MAC address of network interfaces

defense-evasion Red Team

machinae

A tool for collecting intelligence from public sites/feeds about various security-related pieces of data.

recon Red Team

maclookup

Lookup MAC addresses in the IEEE MA-L/OUI public listing.

networking Red Team

magescan

Scan a Magento site for information.

webapp Red Team

magic-unicorn

A simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory

exploit Red Team

magicrescue

Recover files by looking for magic bytes

forensic-carving-tools Blue Team

magictree

A penetration tester productivity tool designed to allow easy and straightforward data consolidation, querying, external

misc Red Team

Magika

Identify file type using signatures.

general Blue Team

maigret

OSINT username checker. Collect a dossier on a person by username from a huge number of sites.

social Red Team

mail-crawl

Tool to harvest emails from website.

recon Red Team

mail-parser

Parse raw SMTP and .MSG email messages and generate a parsed object from them.

email-messages Blue Team

MailboxValidator

Email verification API that validates email deliverability, detects catch-all addresses, and provides risk scoring for bulk email list cleaning.

email-address

mailoney

mailoney honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

MailScrap

Email verification tool that connects to mail servers to verify mailbox existence and removes disposable email addresses from lists.

email-address

mailsend-go

A multi-platform command line tool to send mail via SMTP protocol.

spoof Red Team

make-pdf

This tool will embed javascript inside a PDF document.

forensic Blue Team

maketh

A packet generator that supports forging ARP, IP, TCP, UDP, ICMP and the ethernet header as well.

networking Red Team

malboxes

Builds malware analysis Windows VMs so that you don't have to.

malware Blue Team

Malcat Lite

Analyze binary files using a hex editor, disassembler, and file dissector.

general Blue Team

Malchive

Perform static analysis of various aspects of malicious code.

deobfuscation Blue Team

malcom

Analyze a system's network communication using graphical representations of network traffic.

networking Red Team

malheur

A tool for the automatic analyze of malware behavior.

forensic Blue Team

malice

VirusTotal Wanna Be - Now with 100% more Hipster.

defensive Blue Team

malicious-pdf

Generate a bunch of malicious pdf files with phone-home functionality.

webapp Red Team

maligno

An open source penetration testing tool written in python, that serves Metasploit payloads. It generates shellcode with

scanner Red Team

mallory

HTTP/HTTPS proxy over SSH.

proxy Red Team

malmon

Hosting exploit/backdoor detection daemon.

defensive Blue Team

malscan

A Simple PE File Heuristics Scanner.

malware Blue Team

maltego

Open source intelligence and forensics application

reconnaissance reporting-tools Red Team

maltego-teeth

Set of offensive Maltego transforms

uncategorized Red Team

maltrail

Malicious traffic detection system.

defensive Blue Team

maltrieve

Originated as a fork of mwcrawler. It retrieves malware directly from the sources as listed at a number of sites.

malware Blue Team

Malware Analysis Tools

Curated resource and reference guide for malware analysis tools with recommendations for virtualization, safety practices, and tool selection for…

malicious-file-analysis

malware-check-tool

Python script that detects malicious files via checking md5 hashes from an offline set or via the virustotal site. It ha

malware Blue Team

Malware Config

Database for searching and analyzing extracted malware configurations by hash, domain, or IP address to track C2 infrastructure and malware…

malicious-file-analysis

malware-jail

Sandbox for semi-automatic Javascript malware analysis, deobfuscation and payload extraction.

javascript Blue Team

Malware-Traffic-Analysis.net

Training resource and PCAP repository providing network traffic captures from malware infections since 2013. Includes tutorials and exercises for…

malicious-file-analysis

malwareanalyser

A freeware tool to perform static and dynamic analysis on malware.

windows Red Team

malwaredetect

Submits a file's SHA1 sum to VirusTotal to determine whether it is a known piece of malware

forensic Blue Team

MalwareURL (R)

Commercial malware URL reputation checker and blocklist service protecting networks from known malicious websites.

domain-name

malwoverview

Query public repositories of malware data (e.g., VirusTotal, HybridAnalysis).

gather-and-analyze-data Red Team

malybuzz

A Python tool focused in discovering programming faults in network software.

fuzzer Red Team

mana

A toolkit for rogue access point (evilAP) attacks first presented at Defcon 22.

wireless Red Team

Manalyze

Perform static analysis of suspicious PE files.

pe-files Blue Team

mando.me

Web Command Injection Tool.

webapp Red Team

manspider

Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!

scanner Red Team

manticore

Symbolic execution tool.

binary Red Team

mantra

Hunt down API key leaks in JS files and pages.

scanner Red Team

manul

A coverage-guided parallel fuzzer for open-source and blackbox binaries on Windows, Linux and MacOS.

fuzzer Red Team

map

Handful of small utility type applications useful for analyzing malicious code.

utilities Blue Team

mapcidr

Utility program to perform multiple operations for a given subnet/CIDR ranges.

misc Red Team

MapQuest

Web mapping and routing platform supporting multi-stop route planning.

geolocation-tools-maps

mara-framework

A Mobile Application Reverse engineering and Analysis Framework.

mobile Red Team

marc4dasm

A disassembler for the Atmel MARC4 (a 4 bit Harvard micro).

disassembler Blue Team

mariadb-client

MariaDB is a community-developed fork of the MySQL relational database management system. The mariadb-client package includes command-line utilities…

ad

MarkMonitor Whois Search

ICANN-accredited registrar and brand protection company offering WHOIS lookup and domain management services. Exclusively serves corporate clients…

domain-name

marshalsec

Java Unmarshaller Security - Turning your data into code execution.

exploitation Red Team

maryam

OWASP Maryam is a modular/optional open source framework bas

uncategorized Red Team

maskprocessor

High-performance word generator with a per-position configurable charset

uncategorized Red Team

masky

Masky is a python library providing an alternative way to remotely dump domain users' credentials thanks to an ADCS. A command line tool has been…

ad

massbleed

SSL Vulnerability Scanner.

recon Red Team

masscan

TCP port scanner

network-service-discovery discovery Red Team

masscan-automation

Masscan integrated with Shodan API.

automation Red Team

Masscan (T)

Ultra-fast TCP port scanner designed for scanning large IP ranges and entire networks.

ip-mac-address

massdns

High-performance DNS stub resolver

network-information-dns Red Team

massexpconsole

A collection of tools and exploits with a cli ui for mass exploitation.

automation Red Team

Masto (T)

Python-based Mastodon OSINT tool for investigating user accounts across instances. Retrieves profile details, toots, followers, and account metadata.

social-networks

mat

Metadata Anonymisation Toolkit composed of a GUI application, a CLI application and a library.

defensive Blue Team

MAT2 (T)

Metadata Anonymisation Toolkit v2 — command-line tool that strips metadata from documents, images, audio files, and archives before sharing to…

opsec

matahari

A reverse HTTP shell to execute commands on remote machines behind firewalls.

tunnel Red Team

matroschka

Python steganography tool to hide images or text in images.

stego Red Team

mausezahn

A free fast traffic generator written in C which allows you to send nearly every possible and impossible packet.

dos Red Team

mavlink-git

MAVLink micro air vehicle marshalling / communication libraries

drone Red Team

MaxMind Demo

Web-based IP geolocation demo with location, ASN, and network data from MaxMind's GeoIP database.

ip-mac-address

mbcscan

Scan a PE file to list the associated Malware Behavior Catalog (MBC) details.

pe-files Blue Team

mbenum

Queries the master browser for whatever information it has registered.

windows Red Team

mbox-git

A lightweight sandbox tool for non-root users

uncategorized Red Team

mboxgrep

A small, non-interactive utility that scans mail folders for messages matching regular expressions. It does matching aga

forensic Blue Team

mc

Midnight Commander - a powerful file manager

uncategorized Red Team

mcp-kali-server

API bridge connecting MCP Clients to the API server

uncategorized Red Team

mdbtools

JET / MS Access database (MDB) tools

databases Red Team

mdcat

Fancy cat for Markdown

ad light osint web Red Team

mdcrack

MD4/MD5/NTLM1 hash cracker

cracker Red Team

mdk3

Wireless attack tool for IEEE 802.11 networks

impact Red Team

mdk4

Wireless attack tool for IEEE 802.11 networks

uncategorized Red Team

mdns-recon

An mDNS recon tool written in Python.

recon Red Team

meanalyzer

Intel Engine Firmware Analysis Tool.

firmware Red Team

MediaInfo (T)

Cross-platform utility for extracting technical metadata from video and audio media files.

images-videos-docs

medpot

medpot honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

medusa

Fast, parallel, modular, login brute-forcer for network services

brute-force credential-access Red Team

Meetup

Community event platform for discovering local groups and activities that can support social and relationship networking.

dating

meg

Fetch many paths for many hosts - without killing the hosts.

webapp Red Team

Melissa Data - People Finder (R)

Enterprise data quality and identity verification platform offering people search, address verification, phone append, and email verification across…

people-search-engines

melkor

An ELF fuzzer that mutates the existing data in an ELF sample given to create orcs (malformed ELFs), however, it does no

fuzzer Red Team

meltdown-git

Meltdown Proof-of-Concept

exploit Red Team

memdump

Utility to dump memory contents to standard output

uncategorized Red Team

memfetch

Dumps any userspace process memory without affecting its execution.

forensic Blue Team

memimager

Performs a memory dump using NtSystemDebugControl.

windows Red Team

mentalist

Graphical tool for custom wordlist generation.

automation Red Team

mercurial

Easy-to-use, scalable distributed version control system

uncategorized Red Team

mercury

Network metadata capture and analysis.

fingerprint Red Team

merlin

Command & Control server & agent (metapackage)

uncategorized Red Team

merlin-agent

Cross-platform post-exploitation HTTP/2 Command & Control agent

uncategorized Red Team

merlin-server

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

automation Red Team

Mermaid Viewer

View Mermaid diagrams, such as AI-generated code-analysis workflow diagrams, in a local browser.

view-or-edit-files Blue Team

metabigor

Intelligence Tool but without API key.

recon Red Team

metacam

Extract EXIF information from digital camera files

uncategorized Red Team

metacoretex

MetaCoretex is an entirely JAVA vulnerability scanning framework for databases.

database Red Team

Metadata Cleaner

and mat2 to remove metadata from files

encryption-and-privacy

MetaDefender

OPSWAT's cloud-based multi-engine malware scanning platform with advanced threat detection using 30+ antivirus engines, CDR technology, and…

malicious-file-analysis

metafinder

Search for documents in a domain through Search Engines (Google, Bing and Baidu). The objective is to extract metadata.

recon Red Team

metaforge

Auto Scanning to SSL Vulnerability.

misc Red Team

metagoofil

Tool designed for extracting metadata of public documents

host-information Red Team

metame

A simple metamorphic code engine for arbitrary executables.

binary Red Team

MetaSleuth

Cross-chain cryptocurrency tracking and AML platform supporting 13 blockchains with fund-tracing through mixers using time/amount heuristics and…

blockchain-cryptocurrency

metasploit

A popular penetration testing framework that includes many exploits and payloads

ad light

metasploit-autopwn

db_autopwn plugin of metasploit.

automation Red Team

metasploit-framework

Framework for exploit development and vulnerability research

resource-development defense-evasion Red Team

metasploit-payload-creator

A wrapper to generate multiple types of payloads, based on users choice.

malware Blue Team

metasploitavevasion-git

Metasploit payload generator that avoids most Anti-Virus products.

exploit Red Team

metasploitmcp

MCP Server for Metasploit

uncategorized Red Team

meterssh

A way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of commun

backdoor Red Team

metoscan

Tool for scanning the HTTP methods supported by a webserver.

webapp Red Team

mfcuk

MIFARE Classic Universal toolKit.

wireless Red Team

mfdread

Tool for reading/writing Mifare RFID tags

general

mfoc

Implementation of 'offline nested' attack by Nethemba

general

mfsniffer

A python script for capturing unencrypted TSO login credentials.

sniffer Red Team

mft2csv

Extract $MFT record info and log it to a csv file.

forensic Blue Team

mftcarver

Carve $MFT records from a chunk of data (for instance a memory dump).

forensic Blue Team

mfterm

Terminal for working with Mifare Classic 1-4k tags

hardware Red Team

mftrcrd

Command line $MFT record decoder.

forensic Blue Team

mftref2name

Resolve file index number to name or vice versa on NTFS.

forensic Blue Team

mibble

An open-source SNMP MIB parser (or SMI parser) written in Java. It can be used to read SNMP MIB files as well as simple

misc Red Team

MicroBurst (T)

PowerShell collection focused on Azure security assessment, including subscription discovery and cloud service misconfiguration checks.

cloud-infrastructure

Microsoft Academic

Microsoft's academic search service indexing hundreds of millions of research papers; note that the original Microsoft Academic service was…

search-engines

Microsoft Copilot

Microsoft's AI assistant powered by GPT-4 with web search integration; useful for summarizing open-source intelligence and conducting research tasks.

ai-tools

Microsoft Flow

Microsoft cloud workflow automation platform enabling complex multi-step processes with 1000+ pre-built connectors for integrating OSINT workflows.

tools

microsploit

Fast and easy create backdoor office exploitation using module metasploit packet, Microsoft Office, Open Office, Macro a

backdoor Red Team

middler

A Man in the Middle tool to demonstrate protocol middling attacks.

networking Red Team

mikrotik-npk

Python tools for manipulating Mikrotik NPK format.

reversing Blue Team

mildew

Dotmil subdomain discovery tool that scrapes domains from official DoD website directories and certificate transparency

recon Red Team

Military Grid Reference System Coordinates

MGRS coordinate conversion utility for military-style grid references.

geolocation-tools-maps

mimikatz

Uses admin rights on Windows to display passwords in plaintext

pass-the-hash os-credential-dumping Red Team

mimikittenz-git

A post-exploitation powershell tool for extracting juicy info from memory

exploit Red Team

mimipenguin

A tool to dump the login password from the current linux user.

forensic Blue Team

mingsweeper

A network reconnaissance tool designed to facilitate large address space,high speed node discovery and identification.

windows Red Team

minicom

Menu-driven serial communication program

application-layer-protocol Red Team

minimodem

A command-line program which decodes (or generates) audio modem tones at any specified baud rate, using various framing

misc Red Team

minimysqlator

A multi-platform application used to audit web sites in order to discover and exploit SQL injection vulnerabilities.

exploitation Red Team

miniprint

miniprint honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

miranda-upnp

A Python-based Universal Plug-N-Play client application designed to discover, query and interact with UPNP devices.

exploitation Red Team

miredo

Teredo IPv6 tunneling through NATs

protocol-tunneling Red Team

missidentify

Find win32 applications

digital-forensics Blue Team

missionplanner

A GroundControl Station for Ardupilot.

drone Red Team

MistTrack

Comprehensive AML and fund-tracing platform with 400M+ labeled wallet addresses, compliance database integration (OFAC, NBCTF, UK HMT), and real-time…

blockchain-cryptocurrency

MIT PGP Key Server

MIT PGP Public Key Server for searching, submitting, and removing PGP public keys. Look up keys by name, email, or key ID to find associated…

username

mitm

A simple yet effective python3 script to perform DNS spoofing via ARP poisoning.

networking Red Team

mitm-relay

Hackish way to intercept and modify non-HTTP protocols through Burp & others.

proxy Red Team

mitm6

Pwning IPv4 via IPv6

collection Red Team

mitmap

A python program to create a fake AP and sniff data.

wireless Red Team

mitmap-old

Shell Script for launching a Fake AP with karma functionality and launches ettercap for packet capture and traffic manip

automation Red Team

mitmer

A man-in-the-middle and phishing attack tool that steals the victim's credentials of some web services like Facebook.

sniffer Red Team

mitmf

A Framework for Man-In-The-Middle attacks written in Python.

exploitation Red Team

mitmproxy

SSL-capable man-in-the-middle HTTP proxy

collection Red Team

mkbrutus

Password bruteforcer for MikroTik devices or boxes running RouterOS.

cracker Red Team

mkyara

Tool to generate YARA rules based on binary code.

misc Red Team

Mnemonic

Mnemonic's public PassiveDNS service providing historical and current DNS records collected from global sensor networks. Unauthenticated queries…

domain-name

mobiusft

An open-source forensic framework written in Python/GTK that manages cases and case items, providing an abstract interfa

forensic Blue Team

mobsf

An intelligent, all-in-one open source mobile application (Android/iOS) automated pen-testing framework capable of perfo

mobile Red Team

modifycerttemplate

Aid operators in modifying ADCS certificate templates so that a created vulnerable state can be leveraged for privilege

windows Red Team

modlishka

A powerful and flexible HTTP reverse proxy.

proxy Red Team

modscan

A new tool designed to map a SCADA MODBUS TCP based network.

scanner Red Team

moloch

An open source large scale IPv4 full PCAP capturing, indexing and database system.

networking Red Team

Monero Blocks

Monero blockchain explorer displaying blocks, transactions, and network statistics for the privacy-focused Monero cryptocurrency.

blockchain-cryptocurrency

mongo-tools

MongoDB tools (program)

uncategorized Red Team

mongoaudit

A powerful MongoDB auditing and pentesting tool .

scanner Red Team

monitor-network

Monitor traffic on the first active network interface using tshark, printing a live summary to the screen or saving it t

monitoring Blue Team

monocle

A local network host discovery tool. In passive mode, it will listen for ARP request and reply packets. In active mode,

recon Red Team

monodis

Disassemble and extract resources from .NET assemblies.

net Blue Team

monsoon

A fast HTTP enumerator that allows you to execute a large number of HTTP requests.

webapp Red Team

moodlescan

Scan Moodle sites for information and vulnerabilities.

ad web

moonwalk

Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.

exploitation Red Team

mooscan

A scanner for Moodle LMS.

webapp Red Team

morxbook

A password cracking tool written in perl to perform a dictionary-based attack on a specific Facebook user through HTTPS.

cracker Red Team

morxbrute

A customizable HTTP dictionary-based password cracking tool written in Perl.

cracker Red Team

morxbtcrack

Single Bitcoin private key cracking tool released.

cracker Red Team

morxcoinpwn

Mass Bitcoin private keys brute forcing/Take over tool released.

cracker Red Team

morxcrack

A cracking tool written in Perl to perform a dictionary-based attack on various hashing algorithm and CMS salted-passwor

cracker Red Team

morxkeyfmt

Read a private key from stdin and output formatted data values.

crypto Red Team

morxtraversal

Path Traversal checking tool.

webapp Red Team

morxtunel

Network Tunneling using TUN/TAP interfaces over TCP tool.

tunnel Red Team

mosca

Static analysis tool to find bugs like a grep unix command.

code-audit Red Team

mosquito

XSS exploitation tool - access victims through HTTP proxy.

exploitation Red Team

Most Wanted Criminal Pages

FBI's official wanted fugitives database featuring the Ten Most Wanted list and expanded fugitive database with photos and details.

public-records

mots

Man on the Side Attack - experimental packet injection and detection.

sniffer Red Team

motsa-dns-spoofing

ManOnTheSideAttack-DNS Spoofing.

spoof Red Team

mousejack

Wireless mouse/keyboard attack with replay/transmit poc.

wireless Red Team

mp3nema

A tool aimed at analyzing and capturing data that is hidden between frames in an MP3 file or stream, otherwise noted as

forensic Blue Team

mptcp

A tool for manipulation of raw packets that allows a large number of options.

networking Red Team

mptcp-abuse

A collection of tools and resources to explore MPTCP on your network. Initially released at Black Hat USA 2014.

networking Red Team

mqtt-pwn

A one-stop-shop for IoT Broker penetration-testing and security assessment operations.

scanner Red Team

mrkaplan

Help red teamers to stay hidden by clearing evidence of execution.

windows Red Team

mrsip

SIP-Based Audit and Attack Tool.

voip Red Team

mrtparse

A module to read and analyze the MRT format data.

misc Red Team

mrtparse-git

a module to read and analyze the MRT format data.

uncategorized Red Team

ms-sys

A tool to write Win9x- master boot records (mbr) under linux - RTM!

backdoor Red Team

msf-mpc

Msfvenom payload creator.

automation Red Team

msfdb

Manage the metasploit framework database.

misc Red Team

msfenum

A Metasploit auto auxiliary script.

automation Red Team

msfpc

MSFvenom Payload Creator (MSFPC)

resource-development Red Team

msg-extractor

Extract emails and attachments from MSG files.

email-messages Blue Team

msgconvert

Convert MSG files to MBOX files.

email-messages Blue Team

msitools

Windows Installer file manipulation tool

resource-development Red Team

msitools <a href="#msitools" id="msitools"></a>

Create, inspect and extract Windows Installer (.msi) files.

general Blue Team

msmailprobe

Office 365 and Exchange Enumeration tool.

scanner Red Team

msoffcrypto-crack.py

Recover the password of an encrypted Microsoft Office document.

microsoft-office Blue Team

msoffcrypto-tool

Decrypt a Microsoft Office file with password, intermediate key, or private key which generated its escrow key.

microsoft-office Blue Team

msoffice-crypt

Encrypt and decrypt OOXML Microsoft Office documents.

microsoft-office Blue Team

msprobe

msprobe is a tool to identify Microsoft Windows hosts and servers that are running certain services.

ad

mssqlpwner

Advanced and versatile pentesting tool

uncategorized Red Team

mssqlrelay

Microsoft SQL Relay is an offensive tool for auditing and abusing Microsoft SQL (MSSQL) services.

windows Red Team

mssqlscan

A small multi-threaded tool that scans for Microsoft SQL Servers.

scanner Red Team

msvpwn

Bypass Windows' authentication via binary patching.

windows Red Team

mt-st-git

Utilities for managing magnetic tape storage devices

uncategorized Red Team

mtscan

Mikrotik RouterOS wireless scanner.

wireless Red Team

mubeng

An incredibly fast proxy checker & IP rotator with ease.

proxy Red Team

Mugshots.com

Searchable mugshot database aggregating arrest records and booking photos from law enforcement agencies nationwide.

public-records

multiforcer

GPU accelerated password cracking tool

uncategorized Red Team

multiinjector

Automatic SQL injection utility using a lsit of URI addresses to test parameter manipulation.

webapp Red Team

multimac

Create multiple MACs on an adapter

uncategorized Red Team

multimon-ng

Digital radio transmission decoder

uncategorized Red Team

multiscanner

Modular file scanning/analysis framework.

scanner Red Team

multitun

Tunnel arbitrary traffic through an innocuous WebSocket.

tunnel Red Team

munin-git

Online hash checker for Virustotal and other services

uncategorized Red Team

munin-hashchecker

Online hash checker for Virustotal and other services

defensive Blue Team

muraena

Almost-transparent reverse proxy to automate phishing and post-phishing activities.

social Red Team

MurMurHash

This little tool is to calculate a MurmurHash value of a favicon to hunt phishing websites on the Shodan platform.

osint web Red Team

mutator

This project aims to be a wordlist mutator with hormones, which means that some mutations will be applied to the result

automation Red Team

mutool

Examine, convert, and manipulate PDF files, including extracting embedded streams and repairing malformed documents.

pdf Blue Team

mwebfp

Mass Web Fingerprinter.

fingerprint Red Team

mxcheck

Info and security scanner for e-mail servers

smtp Red Team

MxToolbox

Email deliverability diagnostics tool that checks MX records, SPF, DKIM, DMARC configuration, and server health to prevent email delivery issues.

email-address

mxtract

Memory Extractor & Analyzer.

forensic Blue Team

My Registry

Universal gift registry platform allowing users to add gifts from any store worldwide into one shareable registry for weddings, babies, and other…

people-search-engines

MyAccident - traffic accident map

Free database of redacted US traffic accident reports with searchable crash records and location details.

transportation

mybff

A Brute Force Framework.

cracker Red Team

myip

Determine the IP address of the default network interface.

general-utilities Blue Team

myjson-filter.py

Filter data formatted using the JSON format used by Didier Stevens' tools.

general-utilities Blue Team

myjwt

This cli is for pentesters, CTF players, or dev. You can modify your jwt, sign, inject, etc.

exploitation Red Team

mylg

Network Diagnostic Tool.

networking Red Team

myrescue

Rescue data from damaged disks

forensic-carving-tools Blue Team

Myspace

Legacy social network originally used for profile sharing. Still operational with archived data, music discovery, and profile search capabilities.

social-networks

mysql-defaults

MySQL database development files (metapackage)

uncategorized Red Team

mysql2sqlite

Converts a mysqldump file into a Sqlite 3 compatible file.

database Red Team

n1qlmap

An N1QL exploitation tool.

exploitation Red Team

naabu

Fast port scanner with a focus on reliability and simplicity

uncategorized Red Team

nacker

A tool to circumvent 802.1x Network Access Control on a wired LAN.

networking Red Team

NACo County Explorer

Interactive mapping tool with 1000+ demographic and economic indicators for all 3,069 US counties. National Association of Counties data portal.

public-records

naft

Network Appliance Forensic Toolkit.

forensic Blue Team

name-that-hash

Identify MD5, SHA256 and 300+ other hash types

uncategorized Red Team

NameCheckup

Free web-based username and domain availability checker that searches across 20+ social media platforms and 40+ domain extensions with WHOIS lookup…

username

Namechk

Web-based username and domain availability checker that searches 100+ social media platforms and 36 domain extensions simultaneously.

username

Names Directory

Searchable database of 1B+ name combinations collected from public sources. Allows bidirectional lookup to find first names by surname or surnames by…

username

NameScan

Compliance screening platform providing sanctions checks, PEP screenings, and adverse media searches against global government databases with a free…

compliance-risk-intelligence

narthex

Modular personalized dictionary generator.

misc Red Team

nasm

General-purpose x86 assembler

uncategorized Red Team

nasnum

Script to enumerate network attached storages.

recon Red Team

nassl

Experimental Python wrapper for OpenSSL

misc Red Team

nasty

Tool which helps you to recover your GPG passphrase

uncategorized Red Team

National Sex Offender Search

Official National Sex Offender Public Website aggregating state registry data. Comprehensive multi-state sex offender search tool.

public-records

Nationwide County Court Records

Directory and aggregator linking to county court record systems across the United States. Provides navigation to local court databases.

public-records

Nautilus

Graphical file manager.

general-utilities Blue Team

Naver (Korean)

Korea-focused mapping platform with strong local POI and transit coverage.

geolocation-tools-maps

navgix

Multi-threaded golang tool that will check for nginx alias traversal vulnerabilities.

scanner Red Team

nbname

Decodes and displays all NetBIOS name packets it receives on UDP port 137 and more!

windows Red Team

nbnspoof

NetBIOS Name Service Spoofer.

spoof Red Team

nbtenum

A utility for Windows that can be used to enumerate NetBIOS information from one host or a range of hosts.

windows Red Team

nbtool

Some tools for NetBIOS and DNS investigation, attacks, and communication.

networking Red Team

nbtool-git

Some tools for NetBIOS and DNS investigation, attacks, and communication.

networking Red Team

nbtscan

Scan networks searching for NetBIOS information

network-share-discovery Red Team

nbtscan-unixwiz

Scanner for open NETBIOS nameservers

uncategorized Red Team

NC Salary DB

Official North Carolina state employee salary database. Published by Office of State Controller for transparency.

public-records

ncat-w32

Netcat for the 21st century

uncategorized Red Team

ncp

A fast file copy tool for LANs

uncategorized Red Team

ncpfs

Allows you to mount volumes of NetWare servers under Linux.

networking Red Team

ncrack

High-speed network authentication cracking tool

brute-force credential-access Red Team

ncurses-hexedit

Edit files/disks in hex, ASCII and EBCDIC

uncategorized Red Team

necromant

Python Script that search unused Virtual Hosts in Web Servers.

recon Red Team

needle

The iOS Security Testing Framework.

mobile Red Team

neglected

Facebook CDN Photo Resolver.

recon Red Team

neighbor-cache-fingerprinter

An ARP based Operating System version scanner.

fingerprint Red Team

nemesis

A command-line network packet crafting and injection utility.

networking Red Team

neo-regeorg

Improved version of reGeorg, HTTP tunneling pivot tool

tunnel Red Team

neo4j

Database.

ad light

neovim

hyperextensible Vim-based text editor

ad light osint web Red Team

nerva

Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP).

fingerprint Red Team

net-creds

Sniffs sensitive data from interface or pcap.

sniffer Red Team

net-reactor-slayer

NETReactorSlayer is a deobfuscator and unpacker for Eziriz .NET Reactor.

dotnet Blue Team

net-snmp

SNMP (Simple Network Management Protocol) trap library

uncategorized Red Team

net-tools

NET-3 networking toolkit

uncategorized Red Team

netactview

A graphical network connections viewer similar in functionality to netstat.

networking Red Team

netattack

Python script to scan and attack wireless networks.

wireless Red Team

netbase

Basic TCP/IP networking system

uncategorized Red Team

netbios-share-scanner

This tool could be used to check windows workstations and servers if they have accessible shared resources.

scanner Red Team

netbus

NetBus remote administration tool

windows Red Team

netcat

TCP/IP swiss army knife

uncategorized Red Team

netcommander

An easy-to-use arp spoofing tool.

spoof Red Team

netcon

A network connection establishment and management script.

networking Red Team

netdiscover

Active/passive network address scanner using ARP requests

system-network-configuration-discovery discovery Red Team

netexec

Network Execution Tool

pass-the-hash brute-force credential-access network-share-discovery lateral-movement application-layer-protocol Red Team

netexec-pingcastle

NetExec & CrackMapExec module that execute PingCastle on a remote machine.

windows Red Team

NetHunter

NetHunter App (for Android)

nethunter

NetHunter KeX

Kali NetHunter Desktop Experience Client

nethunter

NetHunter Terminal

NetHunter terminal emulator

nethunter system utilities

NetHunter VNC

GUI desktop experience for Kali Linux on Android

nethunter system

netkit-bsd-finger

BSD-finger ported to Linux.

recon Red Team

netkit-rusers

Logged in users; Displays who is logged in to machines on local network.

recon Red Team

netkit-rwho

Remote who client and server (with Debian patches).

recon Red Team

Netlas.io

Comprehensive internet-wide scanning and OSINT platform providing DNS, WHOIS, SSL, and network reconnaissance with attack surface discovery…

domain-name ip-mac-address

netmap

Can be used to make a graphical representation of the surrounding network.

networking Red Team

netmask

Helps determine network masks

system-network-configuration-discovery Red Team

NETR Online

Nationwide property records portal linking to county assessors and county recorders. Provides property tax, deed, and parcel data.

public-records

netreconn

A collection of network scan/recon tools that are relatively small compared to their larger cousins.

networking Red Team

netripper

Smart traffic sniffing for penetration testers.

windows Red Team

netscan

Tcp/Udp/Tor port scanner with: synpacket, connect TCP/UDP and socks5 (tor connection).

scanner Red Team

netscan2

Active / passive network scanner.

scanner Red Team

netscanner

Network scanner & diagnostic tool with modern TUI

uncategorized Red Team

netscout

OSINT tool that finds domains, subdomains, directories, endpoints and files.

recon Red Team

netsed

Network packet-altering stream editor

uncategorized Red Team

netsniff-ng

Linux network packet sniffer toolkit

network-sniffing Red Team

netspionage

Network Forensics CLI utility that performs Network Scanning, OSINT, and Attack Detection.

forensic Blue Team

netstumbler

Well-known wireless AP scanner and sniffer.

windows Red Team

nettacker

Automated Penetration Testing Framework.

automation Red Team

netw-ib-ox-ag

Graphical frontend for netwox

uncategorized Red Team

network-app-stress-tester

Network Application Stress Testing Yammer.

dos Red Team

Network Miner Free Edition

Examine network traffic and carve PCAP capture files.

monitoring Blue Team

NetworkManager

for easy network configuration

networking

networkmap

Post-exploitation network mapper.

networking Red Team

networkminer

A Network Forensic Analysis Tool for advanced Network Traffic Analysis, sniffer and packet analyzer.

forensic Blue Team

netz

Discover internet-wide misconfigurations while drinking coffee.

scanner Red Team

netzob

An open source tool for reverse engineering, traffic generation and fuzzing of communication protocols.

reversing Blue Team

New OCR

Web OCR utility powered by Tesseract for text extraction from multiple file formats and scanned images.

language-translation

nexfil

OSINT tool for finding profiles by username.

social Red Team

Nexmon

Enables Monitor Mode, Frame Injection and much more for Broadcom/Cypress.

nethunter wifi Red Team

NEXRAD Data Inventory Search

NOAA/NCDC index for searching archived NEXRAD radar datasets.

geolocation-tools-maps

nextnet

Pivot point discovery tool in Go

uncategorized Red Team

nfct

Tool for Near Field Communication (NFC) devices

general

nfcutils

A simple command that lists tags which are in your NFC device field.

nfc Red Team

nfdump

A set of tools to collect and process netflow data.

networking Red Team

nfex

A tool for extracting files from the network in real-time or post-capture from an offline tcpdump pcap savefile.

forensic Blue Team

nfs-utils

Header files and docs for libnfsidmap

uncategorized Red Team

nfspy

A Python library for automating the falsification of NFS credentials when mounting an NFS share.

automation Red Team

nfsshell

Userland NFS command tool.

automation Red Team

Nginx

Web server.

services Blue Team

ngrep

Grep for network traffic

uncategorized Red Team

ngrok

A tunneling, reverse proxy for developing and understanding networked, HTTP services.

tunnel Red Team

NHTSA Vehicle API

Official US government VIN decoder API with vehicle specification and manufacturer data for model years 1981 onward.

transportation

nield

A tool to receive notifications from kernel through netlink socket, and generate logs related to interfaces, neighbor ca

networking Red Team

nightfall

Cjdns inet auto-peering tracker

networking Red Team

nikto

Web server security scanner

web-vulnerability-scanning Red Team

nili

Tool for Network Scan, Man in the Middle, Protocol Reverse Engineering and Fuzzing.

scanner Red Team

nimbostratus

Tools for fingerprintinging and exploiting Amazon cloud infrastructures.

fingerprint Red Team

nimrm

Native WinRM shell client with NTLM, Kerberos, file transfers, in-memory operations, and multi-session support.

windows Red Team

nimux

Pure-Nim network enumeration and remote execution toolkit.

scanner Red Team

nipe

A script to make Tor Network your default gateway.

defensive Blue Team

nipper

Network Infrastructure Parser

networking Red Team

nipper-ng

Device security configuration review tool

uncategorized Red Team

nirsoft

Unique collection of small and useful freeware utilities.

windows Red Team

nishang

Collection of PowerShell scripts and payloads

execution Red Team

njsscan

A static application testing (SAST) tool that can find insecure code patterns in your node.js applications.

code-audit Red Team

nkiller2

A TCP exhaustion/stressing tool.

dos Red Team

nmap

The Network Mapper

network-information vulnerability-scanning reconnaissance network-service-discovery discovery non-application-layer-protocol Red Team

nmap-parse-ouptut

Converts/manipulates/extracts data from a Nmap scan output.

ad

nmap-parse-output

Converts/manipulates/extracts data from a nmap scan output.

misc Red Team

Nmap (T)

Open-source network mapping and port scanning tool with OS detection and service version identification.

ip-mac-address

nmapsi4

Graphical interface to nmap, the network scanner

uncategorized Red Team

nmbscan

Tool to scan the shares of a SMB/NetBIOS network, using the NMB/SMB/NetBIOS protocols.

scanner Red Team

nohidy

The system admins best friend, multi platform auditing tool.

recon Red Team

nomorexor

Tool to help guess a files 256 byte XOR key by using frequency analysis.

crypto Red Team

NoMoreXOR.py

Help guess a file's 256-byte XOR by using frequency analysis.

deobfuscation Blue Team

NoMoreXOR.py (T)

Python utility for recovering long XOR keys using character frequency heuristics and YARA-assisted pattern matching.

encoding-decoding

noPac

Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user.

ad

noriben

Portable, Simple, Malware Analysis Sandbox.

malware Blue Team

nosqlattack

Python tool to automate exploit MongoDB server IP on Internet anddisclose the database data by MongoDB default configura

automation Red Team

nosqli

NoSQL scanner and injector.

webapp Red Team

nosqli-user-pass-enum

Script to enumerate usernames and passwords from vulnerable web applications running MongoDB.

exploitation Red Team

nosqlmap

Automated Mongo database and NoSQL web application exploitation tool

webapp Red Team

notepadpp.plugin.compare

ComparePlus is a Notepad++ plugin to compare files.

productivity-tools Blue Team

notepadpp.plugin.jstool

JSTool is a Notepad++ plugin to format JavaScript and JSON.

productivity-tools Blue Team

notepadpp.plugin.xmltools

XMLTools is a Notepad++ plugin for editing XML.

productivity-tools Blue Team

notspikefile

A Linux based file format fuzzing tool

fuzzer Red Team

novahot

A webshell framework for penetration testers.

webapp Red Team

Nox App Player

Free Android emulator with support for multiple Android versions and root access. Used for app analysis and testing.

mobile-osint Red Team

nox-framework

OSINT & CTI Framework with 120+ sources, async performance, identity pivoting, and automated risk analysis.

scanner Red Team

nray

Distributed port scanner.

scanner Red Team

NSAKEY rules

Password cracking rules and masks for hashcat

ad web

nsdtool

A netgear switch discovery tool. It contains some extra features like bruteoforce and setting a new password.

networking Red Team

nsearch

Minimal script to help find script into the nse database.

misc Red Team

nsec3map

A tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain.

recon Red Team

nsec3walker

Enumerate domain names using DNSSEC.

recon Red Team

nsntrace

Perform network trace of a single process by using network namespaces.

sniffer Red Team

nsoq

A Network Security Tool for packet manipulation that allows a large number of options.

networking Red Team

nsrllookup

Look up MD5 file hashes in the NIST National Software Reference Library (NSRL).

gather-and-analyze-data Red Team

ntds-decode

This application dumps LM and NTLM hashes from active accounts stored in an Active Directory database.

windows Red Team

ntdsxtract

Active Directory forensic framework.

forensic Blue Team

ntfs-file-extractor

Extract files off NTFS.

forensic Blue Team

ntfs-log-tracker

This tool can parse $LogFile, $UsnJrnl of NTFS.

forensic Blue Team

ntlm-challenger

Parse NTLM over HTTP challenge messages.

scanner Red Team

ntlm-scanner

A simple python tool based on Impacket that tests servers for various known NTLM vulnerabilities.

scanner Red Team

ntlm-theft

A tool for generating multiple types of NTLMv2 hash theft files.

exploitation Red Team

ntlmrecon

A tool to enumerate information from NTLM authentication enabled web endpoints.

scanner Red Team

ntlmrecon-git

A tool to enumerate information from NTLM authentication enabled web endpoints.

recon Red Team

ntlmv1-multi

NTLMv1 Multitool.

crypto Red Team

ntp-fingerprint

An active fingerprinting utility specifically designed to identify the OS the NTP server is running on.

fingerprint Red Team

ntp-ip-enum

Script to pull addresses from a NTP server using the monlist command. Can also output Maltego resultset.

recon Red Team

ntpdos

PoC for distributed NTP reflection DoS (CVE-5211)

dos Red Team

nuclei

Fast and customizable vulnerability scanner based on simple YAML based DSL

web-vulnerability-scanning Red Team

nuclei-templates

Community curated list of template files for the nuclei engine.

scanner Red Team

nullinux

Tool that can be used to enumerate OS information, domain information, shares, directories, and users through SMB null s

recon Red Team

nullscan

A modular framework designed to chain and automate security tests.

automation Red Team

Numbering Plans

International numbering reference for E.164 plans, carrier codes, and dialing metadata.

telephone-numbers

numbers-to-string.py

Translate number sequences into ASCII characters.

deobfuscation Blue Team

numbers-to-string.py <a href="#numbers-to-string" id="numbers-to-string"></a>

Convert decimal numbers to strings.

general Blue Team

Numberway

Reverse phone lookup resource used to resolve ownership and location context from a phone number.

telephone-numbers

nxcrypt

Python backdoor framework.

backdoor Red Team

nzyme

WiFi defense system.

wireless Red Team

o-saft

A tool to show informations about SSL certificate and tests the SSL connection according given list of ciphers and vario

scanner Red Team

o-saft-git

An easy to use tool to show informations about SSL certificate and tests the SSL connection according given list of ciphers and various SSL configurat

scanners Red Team

o365enum

Username enumeration and password enuming tool aimed at Microsoft O365.

cracker Red Team

o365spray

Username enumeration and password spraying tool aimed at Microsoft O365.

cracker Red Team

oaburl

Find Open redirects and other vulnerabilities.

ad

oat

A toolkit that could be used to audit security within Oracle database servers.

fuzzer Red Team

obevilion

Another archive cracker created in python, cracking [zip/7z/rar].

cracker Red Team

obexstress

Script for testing remote OBEX service for some potential vulnerabilities.

bluetooth Red Team

obfs4proxy

A pluggable transport proxy written in Go.

proxy Red Team

obfuscator-io-deobfuscator

A deobfuscator for scripts obfuscated by Obfuscator.io

javascript Blue Team

objdump

Disassemble binary files.

general Blue Team

objdump2shellcode

A tool I have found incredibly useful whenever creating custom shellcode.

binary Red Team

objection

Instrumented Mobile Pentest Framework.

mobile Red Team

objects.js

Emulate common browser and PDF viewer objects, methods, and properties when deobfuscating JavaScript.

scripts Blue Team

objectwalker

A python module to explore the object tree to extract paths to interesting objects in memory.

ad osint web Red Team

obmenu-generator

A fast pipe/static menu generator for the Openbox Window Manager (with icons support).

uncategorized Red Team

obsidian

Private and flexible writing app that adapts to the way you think

reporting-tools Red Team

OCCRP Aleph (R)

Global archive of research material for investigative reporting, aggregating public records, court filings, company registries, and leaks from 200+…

compliance-risk-intelligence

oclgausscrack

Cracks verification hashes of the Gauss Virus

uncategorized Red Team

oclhashcat

Worlds fastest WPA cracker with dictionary mutation engine.

cracker Red Team

ocs

Compact mass scanner for Cisco routers with default telnet/enable passwords.

scanner Red Team

octopwnweb

Internal pentest framework running in your browser via WebAssembly, powerd by Pyodide

automation Red Team

od1n-git

A Web security tool to make fuzzing at HTTP inputs, made in C with libCurl

fuzzers Red Team

odat

Oracle Database Attacking Tool

uncategorized Red Team

Odnoklassniki

Russian social network with millions of users. Supports direct user search by username and profile lookup.

social-networks

OFAC Sanctions List Search

Official U.S. Treasury tool for searching OFAC Specially Designated Nationals and related sanctions lists with approximate string matching.

blockchain-cryptocurrency compliance-risk-intelligence

office-dde-payloads

Collection of scripts and templates to generate Office documents embedded with the DDE, macro-less command execution tec

exploitation Red Team

offsec-courses

Resources for OffSec’s AWAE/WEB-300

uncategorized Red Team

offvis

OffVis is an office visualization tool for understanding and deconstructing targeted attacks in .doc, .xls, and .ppt files.

documents Blue Team

OffVis (T)

Microsoft Office Visualization Tool for analyzing Office binary files to identify exploits and malicious structures. Displays hex and object tree…

malicious-file-analysis

ofp-sniffer

An OpenFlow sniffer to help network troubleshooting in production networks.

sniffer Red Team

ohrwurm

RTP fuzzer

voip Red Team

ohrwurm-git

A small and simple RTP fuzzer

fuzzers Red Team

okadminfinder

Tool to find admin panels / admin login pages.

webapp Red Team

oledump

Analyze OLE files (Compound File Binary Format). These files contain streams of data. This tool allows you to analyze th

binary Red Team

oledump.py

Analyze OLE2 Structured Storage files.

microsoft-office Blue Team

olefile

Python package to parse, read and write MS OLE2 files.

microsoft-office Blue Team

oletools

Analyze MS OLE2 files and MS Office documents

resource-development Red Team

oletools (T)

Python toolkit for analyzing OLE and Office documents, including macro extraction and suspicious object detection.

images-videos-docs

Ollama

Local LLM runner that enables privacy-preserving AI inference on personal hardware by downloading and running open-source models like Llama 3,…

ai-tools

ollydbg

32-bit assembler level analysing debugger

resource-development Red Team

omen

Ordered Markov ENumerator - Password Guesser.

cracker Red Team

omnibus

OSINT tool for intelligence collection, research and artifact management.

recon Red Team

Omnibus (T)

Interactive CLI OSINT tool for investigating artifacts (IPs, domains, emails, usernames, hashes, Bitcoin addresses) with over 25 integrated OSINT…

tools

omnihash

Hash files, strings, input streams and network resources in various common algorithms simultaneously.

crypto Red Team

one-lin3r

Gives you one-liners that aids in penetration testing and more.

misc Red Team

One Million Tweet Map

Interactive map for viewing recent geolocated tweets and filtering by keyword and region.

social-networks

onedump.py

Extract and analyze embedded files from OneNote documents.

microsoft-office Blue Team

oneforall

a powerful subdomain collection tool.

ad web

onelistforall

Rockyou for web fuzzing

ad web

onenoteanalyzer

OneNoteAnalyzer is a C# based tool for analyzing malicious OneNote documents.

documents Blue Team

OneRuleToRuleThemStill rules

One rule to crack all passwords. A revamped - optimised and updated version of the original OneRuleToRuleThemAll hashcat rule

ad web

onesixtyone

Fast and simple SNMP scanner

snmp Red Team

onetwopunch

Use unicornscan to quickly scan all open ports, and then pass the open ports to nmap for detailed scans.

scanner Red Team

onetwopunch-git

Script combining the speed of unicornscan w/ the versitility of nmap

scanners Red Team

onioff

An onion url inspector for inspecting deep web links.

recon Red Team

oniongrok

Onion addresses for anything.

tunnel Red Team

onionscan

Scan Onion Services for Security Issues.

scanner Red Team

onionscan-git

Tool to scan onion services

scanners Red Team

onionsearch

Script that scrapes urls on different .onion search engines.

webapp Red Team

OnionShare

for anonymous file sharing

networking

Online OCR (onlineocr.net)

Browser OCR service for converting scanned images and PDFs to editable document formats.

language-translation

Online OCR (SodaPDF)

SodaPDF's online OCR workflow for converting scanned PDFs and images into searchable text output.

language-translation

Online Port scanner

Web-based port scanner checking open ports on target IP addresses without installation.

ip-mac-address

Onyphe

Cyber defense search engine with internet scanning, threat intelligence, and attack surface management.

ip-mac-address

OONI Probe

Open Observatory of Network Interference

privacy

Open Access Scholarly Journals

PAGEPress open-access publisher hosting peer-reviewed journals across biomedical, natural, and social sciences; provides free access to published…

search-engines

Open-Data-Portal München (German)

City of Munich open data portal with 331+ datasets. Provides administrative data from Munich government at city level.

public-records

Open Library

Internet Archive's open catalog of over 3 million books with borrowable digital editions; provides bibliographic data and full-text access for many…

search-engines

OpenAIP World Aeronautical Database

Open, community-maintained aeronautical dataset for airfields, airspace, navaids, and runway metadata.

transportation

OpenCelliD

Collaborative global cell-tower database used for telecom-based geolocation.

geolocation-tools-maps

OpenCellid: Database of Cell Towers

Open database of cellular tower locations and coverage for mobile network geolocation.

ip-mac-address

OpenCode

Open-source AI coding agent for the terminal.

use-artificial-intelligence Blue Team

OpenCorporates

The world's largest open database of companies, covering 200+ jurisdictions with over 200 million company records sourced directly from official…

business-records

opendoor

OWASP WEB Directory Scanner.

webapp Red Team

OpenInfrastructureMap

OSM-derived map overlays for power, telecom, water, and industrial infrastructure.

geolocation-tools-maps

openocd

Open on-chip JTAG/SWD debug solution for embedded target devices

uncategorized Red Team

OpenOwnership

Global hub for beneficial ownership transparency, providing data standards and a register linking corporate ownership data across jurisdictions.

compliance-risk-intelligence

openpuff

Yet not another steganography SW.

stego Red Team

OpenRailwayMap

OpenStreetMap-based global railway map visualizing rail lines, infrastructure characteristics, and operations context.

geolocation-tools-maps transportation

openrisk

Generates a risk score based on the results of a Nuclei scan using OpenAI's GPT model.

misc Red Team

OpenSanctions

Aggregated database of sanctioned entities, politically exposed persons, and persons of criminal interest from 329 global data sources.

compliance-risk-intelligence

openscap

Open Source Security Compliance Solution.

automation Red Team

OpenScreening

Free graph-based PEP and sanctions screening tool by Linkurious that visualizes connections across persons of interest using OpenSanctions and ICIJ…

compliance-risk-intelligence

OpenSea

Multi-chain NFT marketplace supporting 22+ blockchains (Ethereum, Solana, Arbitrum, Optimism, etc.) with transaction history, collection analytics,…

blockchain-cryptocurrency

OpenSeaMap - The free nautical chart

Open nautical chart map built on collaborative maritime data for ports, aids to navigation, and coastal context.

transportation

OpenSignal

Crowdsourced mobile coverage and signal quality map from user telemetry.

geolocation-tools-maps

openssh

Secure shell (SSH) client, for secure access to remote machines

uncategorized Red Team

openssh-gssapi

Secure shell (SSH) client, with GSS-API support

uncategorized Red Team

openssh-ssh1

Secure shell (SSH) client for legacy SSH1 protocol

uncategorized Red Team

openssl

Secure Sockets Layer toolkit - cryptographic utility

uncategorized Red Team

openstego

A tool implemented in Java for generic steganography, with support for password-based encryption of the data.

crypto Red Team

OpenStreetCam

KartaView crowdsourced street-level imagery platform for geospatial verification.

geolocation-tools-maps

OpenStreetMap

Open-source global map edited by the community and widely reused in OSINT workflows.

geolocation-tools-maps

opensvp

A security tool implementing "attacks" to be able to the resistance of firewall to protocol level attack.

exploitation Red Team

opentaxii

TAXII server implementation from EclecticIQ

uncategorized Red Team

openvas

Meta package for installing all OpenVAS components.

scanner Red Team

openvpn

Virtual private network daemon

uncategorized Red Team

OpenVPN for Android

OpenVPN without root

privacy

openwebrx

Open source, multi-user SDR receiver software with a web interface.

radio Red Team

operative

Framework based on fingerprint action, this tool is used for get information on a website or a enterprise target with mu

fingerprint Red Team

operative-framework

OSINT investigation framework

recon Red Team

ophcrack

Microsoft Windows password cracker using rainbow tables (gui)

password-cracking credential-access Red Team

OPSWAT Meta Defender

Multi-engine malware scanning service using 20+ antivirus engines with advanced threat analysis, content disarm & reconstruction, and emulation-based…

malicious-file-analysis

orakelcrackert

This tool can crack passwords which are encrypted using Oracle's latest SHA1 based password protection algorithm.

windows Red Team

Orbit (T)

Python CLI tool for Bitcoin wallet network analysis that visualizes transaction relationships through recursive crawling and graph rendering.

blockchain-cryptocurrency

Orbot

Tor on Android

privacy

origami

Aims at providing a scripting tool to generate and analyze malicious PDF files.

malware Blue Team

Origami Framework (T)

Ruby framework for parsing, analyzing, and forging PDF documents. Includes PDF Walker GUI and PDFcop heuristic checker for detecting dangerous PDF…

malicious-file-analysis

Origamindee

Parse, modify, generate PDF files.

pdf Blue Team

orjail

A more secure way to force programs to exclusively use tor network.

defensive Blue Team

oscanner

Oracle assessment framework

databases Red Team

osert

Markdown Templates for Offensive Security exam reports.

misc Red Team

osfooler-ng

Prevents remote active/passive OS fingerprinting by tools like nmap or p0f.

defensive Blue Team

osi.ig

Instagram OSINT Tool gets a range of information from an Instagram account.

social Red Team

OSINT Analyser

Open-source OSINT data aggregation and AI analysis tool that collects information from multiple sources and uses LLMs to generate intelligence…

ai-tools

OSINT Industries

Account linking service that extracts all registered accounts tied to an email or phone across 500+ platforms including social media, messaging apps,…

email-address instant-messaging

OSINT Researcher

iOS app for GitHub organization reconnaissance and open-source intelligence. Limited to App Store distribution.

mobile-osint Red Team

osint-spy

Performs OSINT scan on email/domain/ip_address/organization.

recon Red Team

osinterator

Open Source Toolkit for Open Source Intelligence Gathering.

recon Red Team

osintgram

OSINT tool offering an interactive shell to perform analysis on Instagram account of any users by its nickname.

recon Red Team

Osintgram (T)

Python-based Instagram OSINT toolkit for extracting data from public accounts, including posts, hashtags, and follower relationships.

social-networks

osrframework

Open Sources Research Framework

uncategorized Red Team

osslsigncode

A small tool that implements part of the functionality of the Microsoft tool signtool.exe.

windows Red Team

ostinato

An open-source, cross-platform packet/traffic generator and analyzer with a friendly GUI. It aims to be "Wireshark in Re

sniffer Red Team

osueta

A simple Python script to exploit the OpenSSH User Enumeration Timing Attack.

exploitation Red Team

otori

Toolbox intended to allow useful exploitation of XML external entity ("XXE") vulnerabilities.

exploitation Red Team

outguess

A universal steganographic tool.

crypto Red Team

outlook-webapp-brute

Microsoft Outlook WebAPP Brute.

cracker Red Team

Overpass Turbo

Query interface for extracting targeted OpenStreetMap features via Overpass API.

geolocation-tools-maps

Overview

Self-hosted document analysis and management platform for investigating large document collections through search, tagging, and plugin-based analysis…

tools

owabf

Outlook Web Access bruteforcer tool.

cracker Red Team

owasp-bywaf

A web application penetration testing framework (WAPTF).

webapp Red Team

OWASP D4N155 (T)

Intelligent OSINT-based wordlist generator that analyzes website content and metadata to create dynamic, context-aware wordlists for penetration…

tools

owasp-mantra-ff

Web application security testing framework built on top of Firefox

vulnerability-scanning Red Team

OWASP Maryam (T)

Modular OWASP OSINT framework with footprinting and search modules for multi-source reconnaissance.

domain-name

owasp-zsc

Shellcode/Obfuscate Code Generator.

exploitation Red Team

owl

Open Apple Wireless Direct Link (AWDL)

uncategorized Red Team

owtf

The Offensive (Web) Testing Framework.

webapp Red Team

p0f

Passive OS fingerprinting tool

remote-system-discovery Red Team

pacemaker-git

A CVE-2014-0160 client exploit

scanners Red Team

PACER

Public Access to Court Electronic Records. Official US federal court records system with fee-based access to documents.

public-records

pack

Password analysis and cracking kit

password-profiling-wordlists Red Team

pack2

Password analysis and cracking kit 2

uncategorized Red Team

packerid

Script which uses a PEiD database to identify which packer (if any) is being used by a binary.

binary Red Team

packerid-git

Script which uses a PEiD database to identify which packer (if any) is being used by a binary.

reverse Blue Team

packet-o-matic

A real time packet processor. Reads the packet from an input module, match the packet using rules and connection trackin

networking Red Team

packetq

A tool that provides a basic SQL-frontend to PCAP-files.

networking Red Team

packetsender

An open source utility to allow sending and receiving TCP and UDP packets.

networking Red Team

packit

A network auditing tool with the ability to customize, inject, monitor, and manipulate IP traffic.

networking Red Team

pacu

Open Source AWS Exploitation Framework

uncategorized Red Team

pacumen

Packet Acumen - Analyse encrypted network traffic and more (side-channel attacks).

crypto Red Team

padbuster

Script for performing Padding Oracle attacks

defense-evasion Red Team

padoracle

Padding Oracle Attack with Node.js.

crypto Red Team

padre

Padding Oracle attack tool.

crypto Red Team

pafish

A demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as ma

windows Red Team

Page2Images (T)

Website screenshot and full-page capture API that converts URLs to images for various devices including desktop, mobile, and tablet.

documentation-evidence-capture

pagodo

Google dork script to collect potentially vulnerable web pages and applications on the Internet.

scanner Red Team

paketto

Advanced TCP/IP Toolkit.

scanner Red Team

panhunt

Searches for credit card numbers (PANs) in directories.

scanner Red Team

panoptic

A tool that automates the process of search and retrieval of content for common log and config files through LFI vulnera

automation Red Team

Panopticlick

EFF browser fingerprinting test (now Cover Your Tracks at coveryourtracks.eff.org) that measures how uniquely identifiable your browser is across the…

opsec

Pantagrule rules

large hashcat rulesets generated from real-world compromised passwords

ad web

pappy-proxy

An intercepting proxy for web application testing.

webapp Red Team

parameth

This tool can be used to brute discover GET and POST parameters.

webapp Red Team

parampampam

This tool for brute discover GET and POST parameters.

webapp Red Team

paramspider

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing.

webapp Red Team

paranoic

A simple vulnerability scanner written in Perl.

scanner Red Team

paros

Web application proxy

web-vulnerability-scanning Red Team

ParrotSec OS (T)

Efficient, lightweight security-focused Linux distribution with strong privacy and anonymity features for penetration testing and privacy-conscious…

tools

parse-evtx

A tool to parse the Windows XML Event Log (EVTX) format.

forensic Blue Team

parsero

Robots.txt audit tool

web-scanning Red Team

parsero-git

A Robots.txt audit tool

recon Red Team

parted

Disk partition manipulator

uncategorized Red Team

pasco

Internet Explorer cache forensic analysis tool

forensic-carving-tools Blue Team

pass

TODO

ad web

pass-station

CLI & library to search for default credentials among thousands of Products / Vendors.

misc Red Team

passdetective

CLI tool that scans shell command history

uncategorized Red Team

passe-partout

Tool to extract RSA and DSA private keys from any process linked with OpenSSL. The target memory is scanned to lookup sp

cracker Red Team

passgan

A Deep Learning Approach for Password Guessing.

cracker Red Team

passhunt

Search drives for documents containing passwords.

scanner Red Team

passing-the-hash

Patched tools to use password hashes as authentication input

uncategorized Red Team

passivedns

A network sniffer that logs all DNS server replies for use in a passive DNS setup.

sniffer Red Team

PassTheCert

PassTheCert is a tool to extract Active Directory user password hashes from a domain controller's local certificate store.

ad

pastejacker

Hacking systems with the automation of PasteJacking attacks.

automation Red Team

pastemonitor

Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match..

recon Red Team

pasv-agrsv

Passive recon / OSINT automation script.

automation Red Team

patator

Multi-purpose brute-forcer

brute-force Red Team

patchkit

Powerful binary patching from Python.

binary Red Team

patchleaks

Go from a CVE number to the exact patched code and its vulnerability analysis

uncategorized Red Team

Paterva / Maltego (T)

Enterprise-grade OSINT and cyber investigations platform that visualizes relationships between data entities across multiple sources for threat…

tools

pathzuzu

Checks for PATH substitution vulnerabilities and logs the commands executed by the vulnerable executables.

exploitation Red Team

pax-oracle

CLI tool for PKCS7 padding oracle attacks.

crypto Red Team

payloadmask

Web Payload list editor to use techniques to try bypass web application firewall.

webapp Red Team

payloadsallthethings

Collection of useful payloads and bypasses

uncategorized Red Team

pblind

Little utility to help exploiting blind sql injection vulnerabilities.

exploitation Red Team

pbscan

Faster and more efficient stateless SYN scanner and banner grabber due to userland TCP/IP stack usage.

scanner Red Team

pcapfex

Packet CAPture Forensic Evidence eXtractor.

networking Red Team

pcapfix

Tries to repair your broken pcap and pcapng files.

networking Red Team

pcapsipdump

A tool for dumping SIP sessions (+RTP traffic, if available) to disk in a fashion similar to 'tcpdump -w' (format is exa

voip Red Team

pcapteller

A tool designed for traffic manipulation and replay.

sniffer Red Team

pcapxray

A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, h

forensic Blue Team

pcileech

Tool, which uses PCIe hardware devices to read and write from the target system memory.

hardware Red Team

pcode2code

VBA p-code decompiler.

decompiler Blue Team

pcodedmp

Disassemble VBA p-code.

microsoft-office Blue Team

pcredz

A tool that extracts credit card numbers and more from a pcap file or from a live interface.

scanner Red Team

pcsc

Middleware for smart card readers

general

pdblaster

Extract PDB file paths from large sample sets of executable files.

forensic Blue Team

pdbresym

PDBReSym simplifies and optimizes interacting with the Microsoft Symbol Server to download PDBs.

utilities Blue Team

PDF My URL

Converts web pages into downloadable PDF captures for documentation and evidence preservation.

archives

pdf-parser

Parses PDF files to identify fundamental elements

pdf-forensics-tools Blue Team

pdf-parser.py

Examine elements of the PDF file.

pdf Blue Team

PDF Tools (T)

Free suite of PDF analysis tools by Didier Stevens including pdfid (keyword scanning) and pdf-parser.py for analyzing malicious PDF documents and…

malicious-file-analysis

pdfbook-analyzer

Utility for facebook memory forensics.

forensic Blue Team

pdfcrack

PDF files password cracker

uncategorized Red Team

pdfgrab

Tool for searching pdfs withthin google and extracting pdf metadata.

recon Red Team

pdfid

Scans PDF files for certain PDF keywords

pdf-forensics-tools Blue Team

pdfid.py

Identify suspicious elements of the PDF file.

pdf Blue Team

pdfminer3k

A python3 port of pdfminer

uncategorized Red Team

pdfresurrect

A tool aimed at analyzing PDF documents.

forensic Blue Team

pdfstreamdumper

PDFStreamDumper is a free, open source tool to analyze malicious PDF documents.

documents Blue Team

pdftk-java

Edit, create, and examine PDF files.

pdf Blue Team

pdftool.py

Analyze PDF files to identify incremental updates to the document.

pdf Blue Team

pdfwalker

Frontend to explore the internals of a PDF document with Origami

misc Red Team

pdgmail

A password dictionary attack tool that targets windows authentication via the SMB protocol.

cracker Red Team

pdnstool

Query passive DNS databases for DNS data.

gather-and-analyze-data Red Team

pe-bear

A freeware reversing tool for PE files.

windows Red Team

pe-sieve

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcod

windows Red Team

PE Tree

Examine contents and structure of PE files.

pe-files Blue Team

pe_unmapper

Small tool to convert beteween the PE alignments (raw and virtual)

pe Blue Team

peach

A SmartFuzzer that is capable of performing both generation and mutation based fuzzing.

fuzzer Red Team

peach-fuzz

Simple vulnerability scanning framework.

fuzzer Red Team

peass

Privilege Escalation Awesome Scripts SUITE (with colors).

scanner Red Team

peass-ng

Privilege Escalation Awesome Scripts SUITE

privilege-escalation Red Team

pebear

Delivers fast and flexible "first view" for malware analysts

pe Blue Team

pecheck.py

Analyze static properties of PE files.

pe-files Blue Team

peda

Python Exploit Development Assistance for GDB.

general

pedump

Statically analyze PE files and extract their components (e.g., resources).

pe-files Blue Team

peepdf

A Python tool to explore PDF files in order to find out if the file can be harmful or not.

forensic Blue Team

peepdf-3

Examine elements of the PDF file.

pdf Blue Team

peepingtom

A tool to take screenshots of websites. Much like eyewitness.

webapp Red Team

PeeringDB

Database of internet exchange points, member networks, and AS relationships for network mapping.

ip-mac-address

pefile

Python library for analyzing static properties of PE files.

pe-files Blue Team

peframe

Tool to perform static analysis on (portable executable) malware.

malware Blue Team

peid

PEiD detects most common packers, cryptors and compilers for PE files.

pe Blue Team

peirates

Kubernetes Penetration Testing tool

uncategorized Red Team

pemcrack

Cracks SSL PEM files that hold encrypted private keys. Brute forces or dictionary cracks.

cracker Red Team

pemcracker

Tool to crack encrypted PEM files.

cracker Red Team

penbox

A Penetration Testing Framework - The Tool With All The Tools.

automation Red Team

pencode

Complex payload encoder.

misc Red Team

penelope

Advanced shell handler for penetration testing and CTFs

non-application-layer-protocol Red Team

pentbox

A security suite that packs security and stability testing oriented tools for networks and systems.

fuzzer Red Team

Pentest-tools.com Subdomains

Web-based subdomain finder that enumerates subdomains for a given domain through hosted scanning.

domain-name

pentestgpt

A penetration testing tool empowered by ChatGPT. It is designed to automate the penetration testing process.

automation Red Team

pentestly

Python and Powershell internal penetration testing framework.

scanner Red Team

pentmenu

A bash script for recon and DOS attacks.

automation Red Team

PepChecker (R)

PEP and sanctions screening tool offering checks against comprehensive PEP lists and global sanctions databases with a free tier of limited searches.

compliance-risk-intelligence

pepe

Collect information about email addresses from Pastebin.

social Red Team

pepper

An open source script to perform malware static analysis on Portable Executable.

malware Blue Team

periscope

A PE file inspection tool.

windows Red Team

Periscope (T)

Live video streaming app merged into Twitter. Limited standalone value; functionality integrated into Twitter.

mobile-osint Red Team

perl-algorithm-c3

Algorithm::C3

uncategorized Red Team

perl-algorithm-generatesequence

A sequence generator.

uncategorized Red Team

perl-algorithm-permute

Perl module for handy and fast permutations with object oriented interface

uncategorized Red Team

perl-alien-gmp

Alien package for the GNU Multiple Precision library

uncategorized Red Team

perl-array-uniq

Perl extension for managing list of values.

uncategorized Red Team

perl-cisco-copyconfig

Provides methods for manipulating Cisco devices

uncategorized Red Team

perl-class-errorhandler

Base class for error handling

uncategorized Red Team

perl-class-gomor

Another class and object builder

uncategorized Red Team

perl-class-loader

Loads modules and creates objects on demand

uncategorized Red Team

perl-convert-ascii-armour

Converts binary octets into ASCII armoured messages

uncategorized Red Team

perl-convert-pem

Read/write encrypted ASN.1 PEM files

uncategorized Red Team

perl-crypt-des_ede3

Perl module for triple-DES EDE encryption/decryption

uncategorized Red Team

perl-crypt-dh

Perl/CPAN Module Crypt::DH: Diffie-Hellman key exchange system

uncategorized Red Team

perl-crypt-dsa

DSA Signatures and Key Generation

uncategorized Red Team

perl-crypt-idea

Perl interface to IDEA block cipher

uncategorized Red Team

perl-crypt-primes

Provable Prime Number Generator suitable for Cryptographic Applications

uncategorized Red Team

perl-crypt-random

Cryptographically Secure, True Random Number Generator

uncategorized Red Team

perl-crypt-rsa

RSA public-key cryptographysystem.

uncategorized Red Team

perl-crypt-x

Cryptographically secure random number generator

uncategorized Red Team

perl-data-buffer

Read/write buffer class

uncategorized Red Team

perl-devel-overloadinfo

introspect overloaded operators

uncategorized Red Team

perl-digest-crc

Generic interface to CRC algorithms

uncategorized Red Team

perl-digest-md2

Perl interface to the MD2 Algorithm

uncategorized Red Team

perl-digest-md4

Digest::MD4::Perl - Perl interface to the MD4 Algorithm

uncategorized Red Team

perl-digest-perl-md5

Perl implementation of Ron Rivests MD5 Algorithm

uncategorized Red Team

perl-expect

Automate interactions with command line programs that expose a text terminal interface.

uncategorized Red Team

perl-geography-countries

2-letter, 3-letter, and numerical codes for countries.

uncategorized Red Team

perl-html-linkextractor

Extract links from an HTML document

uncategorized Red Team

perl-html-tagparser

Yet another HTML document parser with DOM-like methods

uncategorized Red Team

perl-http-dav

A client module for the WebDAV protocol

uncategorized Red Team

perl-io-socket

IO::Socket - Object interface to socket communications for perl

uncategorized Red Team

perl-io-socket-socks

Provides a way to create socks client or server both 4 and 5 version

uncategorized Red Team

perl-ip-country

fast lookup of country codes from IP addresses

uncategorized Red Team

perl-iptables-parse

IPTables::Parse - Perl extension for parsing iptables and ip6tables firewall rulesets

uncategorized Red Team

perl-libwhisker2

A full-featured Perl library used for HTTP-related functions, including vulnerability scanning and exploit

uncategorized Red Team

perl-linux-desktopfiles

Perl module to get and parse the Linux .desktop files

uncategorized Red Team

perl-lwp-protocol-socks

Adds support for the socks protocol and proxy facility

uncategorized Red Team

perl-math-bigint-gmp

Big integer calculations using the GNU Multiple Precision Arithmetic Library.

uncategorized Red Team

perl-math-gmp

High speed arbitrary size integer math

uncategorized Red Team

perl-math-pari

Perl interface to PARI

uncategorized Red Team

perl-modern-perl

enable all of the features of Modern Perl with one command

uncategorized Red Team

perl-moose

A postmodern object system for Perl 5

uncategorized Red Team

perl-net-cidr

Manipulate IPv4/IPv6 netblocks in CIDR notation

uncategorized Red Team

perl-net-frame

The base framework for frame crafting.

uncategorized Red Team

perl-net-frame-device

Get network device information and gateway.

uncategorized Red Team

perl-net-frame-dump

Base-class for a tcpdump like implementation.

uncategorized Red Team

perl-net-frame-layer-icmp6

Internet Control Message Protocol v6 layer object.

uncategorized Red Team

perl-net-frame-layer-ipv6

Internet Protocol v6 layer object.

uncategorized Red Team

perl-net-frame-layer-sinfp3

Frame crafting made easy.

uncategorized Red Team

perl-net-frame-simple

Frame crafting made easy.

uncategorized Red Team

perl-net-libdnet

Binding for Dug Song's libdnet

uncategorized Red Team

perl-net-libdnet6

Adds IPv6 support to Net::Libdnet.

uncategorized Red Team

perl-net-netmask

Parse, manipulate and lookup IP network blocks.

uncategorized Red Team

perl-net-nslookup

Provide nslookup(1)-like capabilties.

uncategorized Red Team

perl-net-pcap

Perl/CPAN Module Net::Pcap

uncategorized Red Team

perl-net-pcaputils

Perl/CPAN Module Net::PcapUtils

uncategorized Red Team

perl-net-rawip

Perl extension to manipulate raw IP packets with interface to B<libpcap>

uncategorized Red Team

perl-net-socks

TCP/IP access through firewalls using SOCKS

uncategorized Red Team

perl-net-ssh-perl

Perl client interface to SSH

uncategorized Red Team

perl-net-whois-ip

Perl extension for looking up the whois information for ip addresses

uncategorized Red Team

perl-net-write

Net::Write - a portable interface to open and send raw data to network

uncategorized Red Team

perl-netpacket

Assemble/disassemble network packets at the protocol level

uncategorized Red Team

perl-nmap-parser

Nmap::Parser

uncategorized Red Team

perl-number-range

Perl extension defining ranges of numbers and testing if a

uncategorized Red Team

perl-rpc-xml

A set of classes for core data, message and XML handling

uncategorized Red Team

perl-string-random

Perl module to generate random strings based on a pattern

uncategorized Red Team

perl-test-checkdeps

Check for presence of dependencies

uncategorized Red Team

perl-text-csv-xs

comma-separated values manipulation routines

uncategorized Red Team

perl-tftp

TFTP - TFTP Client class for perl

networking Red Team

perl-tie-encryptedhash

Hashes (and objects based on hashes) with encrypting fields

uncategorized Red Team

perl-time-interval

Converts time intervals of days, hours, minutes, and seconds.

uncategorized Red Team

perl-uri-fetch

Smart URI fetching/caching

uncategorized Red Team

perl-xml-dom

Implements Level 1 of W3's DOM

uncategorized Red Team

persistencesniper

Hunt persistences implanted in Windows machines.

defensive Blue Team

pesieve

pe-sieve recognizes and dumps variety of implants within the scanned process.

memory Blue Team

pestudio

The goal of pestudio is to spot artifacts of executable files in order to ease and accelerate Malware Initial Assessment.

pe Blue Team

petitpotam

Windows machine account manipulation

ad

petools

Portable executable (PE) manipulation toolkit.

windows Red Team

pev

Command line based tool for PE32/PE32+ file analysis.

forensic Blue Team

pextractor

A forensics tool that can extract all files from an executable file created by a joiner or similar.

windows Red Team

pftriage

Python tool and library to help analyze files during malware triage and analysis.

malware Blue Team

pgdbf

Convert XBase / FoxPro databases to PostgreSQL

database Red Team

phantap

An 'invisible' network tap aimed at red teams.

networking Red Team

phantom-evasion

Antivirus evasion tool written in python.

exploitation Red Team

phantomcollect

Lightweight stealth web data collection framework for ethical security testing.

webapp Red Team

phemail

A python open source phishing email tool that automates the process of sending phishing emails as part of a social engin

social Red Team

phishery

Basic Auth Credential Harvester with Word Doc Template Injector

uncategorized Red Team

phishingkithunter

Find phishing kits which use your brand/organization's files and image'.

social Red Team

Phone Validator

Number-validation utility focused on format, line-type, and carrier checks.

telephone-numbers

phoneinfoga

Information gathering & OSINT framework for phone numbers.

social Red Team

PhoneInfoga (T)

Go-based phone number reconnaissance framework validating numbers and aggregating metadata from phone directories, search engines, and reputation…

tools

Phonerator

Phone number generation and testing utility for telephony research workflows.

telephone-numbers

phonesploit

Adb exploiting tools.

mobile Red Team

phonia

Advanced toolkits to scan phone numbers using only free resources.

social Red Team

phoss

Sniffer designed to find HTTP, FTP, LDAP, Telnet, IMAP4, VNC and POP3 logins.

cracker Red Team

Photobucket

Long-running image hosting platform with public galleries and legacy web-hosted photo content.

images-videos-docs

photon

Incredibly fast crawler designed for open source intelligence

identity-information reconnaissance Red Team

Photon (T)

Fast Python web crawler designed for OSINT that extracts URLs, emails, social media accounts, files, API keys, JavaScript endpoints, and DNS records…

tools

php-defaults

Server-side, HTML-embedded scripting language (Apache 2 module) (default)

uncategorized Red Team

PHP filter chain generator

A CLI to generate PHP filters chain / get your RCE without uploading a file if you control entirely the parameter passed to a require or an include…

ad web

php-findsock-shell

A Findsock Shell implementation in PHP + C.

webapp Red Team

php-malware-finder

Detect potentially malicious PHP files.

webapp Red Team

php-mt-seed

PHP mt_rand() seed cracker.

cracker Red Team

php-rfi-payload-decoder

Decode and analyze RFI payloads developed in PHP.

cracker Red Team

php-vulnerability-hunter

An whitebox fuzz testing tool capable of detected several classes of vulnerabilities in PHP web applications.

windows Red Team

phpggc

Generate payloads that exploit unsafe object deserialization

persistence Red Team

phpsploit

Stealth post-exploitation framework

uncategorized Red Team

phpstan

PHP Static Analysis Tool - discover bugs in your code without running it.

code-audit Red Team

phpstress

A PHP denial of service / stress test for Web Servers running PHP-FPM or PHP-CGI.

dos Red Team

phrasendrescher

A modular and multi processing pass phrase cracking tool.

cracker Red Team

Picarta

AI geolocation tool that estimates likely photo capture locations from visual scene analysis.

images-videos-docs

pidense

Monitor illegal wireless network activities. (Fake Access Points)

wireless Red Team

Pidgin

preconfigured with OTR for Off-the-Record Messaging

networking

PimEyes Face Search Engine

Commercial reverse face search engine for locating appearances of a face on publicly indexed websites.

images-videos-docs

pin

A dynamic binary instrumentation tool.

automation Red Team

pingcastle

Active Directory scanning tool.

windows Red Team

PinGroupie

Pinterest group analysis and discovery tool. Tracks Pinterest user statistics, board content, and group discussions.

social-networks

pinkerton

JavaScript file crawler and secret finder.

webapp Red Team

pintool

This tool can be useful for solving some reversing challenges in CTFs events.

reversing Blue Team

pintool2

Improved version of pintool.

reversing Blue Team

pip3line

The Swiss army knife of byte manipulation.

crypto Red Team

pipal

Statistical analysis on password dumps

reporting-tools Red Team

pipal-git

THE password analyzer

analysis Red Team

pipeline

Designed to aid in targeted brute force password cracking attacks.

cracker Red Team

pirana

Exploitation framework that tests the security of a email content filter.

exploitation Red Team

pius-pi

Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional

recon Red Team

pivotsuite

A portable, platform independent and powerful network pivoting toolkit.

networking Red Team

pixd

Colourful visualization tool for binary files.

binary Red Team

PixelKnot

Hidden Messages

privacy

pixiewps

Offline WPS bruteforce tool

wifi-credential-access Red Team

pixload

Image Payload Creating/Injecting tools.

webapp Red Team

pkcrack

A PkZip encryption cracker.

cracker Red Team

pkg-unpacker

Unpacker for pkg applications.

packers Blue Team

pkinittools

Tools for Kerberos PKINIT and relaying to AD CS.

exploitation Red Team

pkt2flow

A simple utility to classify packets into flows.

networking Red Team

Places2

MIT CSAIL scene-recognition dataset containing millions of place-labeled images for visual analysis.

images-videos-docs

plasma-disasm

An interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax.

disassembler Blue Team

plasma-git

Interactive disassembler for x86/ARM/MIPS. Generates indented pseudo-code with colored syntax code.

analysis Red Team

plaso

Super timeline all the things – metapackage

uncategorized Red Team

platypus

A modern multiple reverse shell sessions manager written in go.

backdoor Red Team

plcscan

This is a tool written in Python that will scan for PLC devices over s7comm or modbus protocols.

scanner Red Team

plecost

Wordpress finger printer Tool.

webapp Red Team

Plenty Of Fish.com

Freemium dating platform with large membership and profile-based discovery through filters and recommendations.

dating

plocate

Much faster locate

uncategorized Red Team

plown

A security scanner for Plone CMS.

webapp Red Team

plumber.py

A python implementation of a grep friendly ftrace wrapper.

misc Red Team

plutil

Converts .plist files between binary and UTF (editable) text formats.

misc Red Team

pma-labs

Binaries for the book Practical Malware Analysis

utilities Blue Team

pmacct

Small set of multi-purpose passive network monitoring tools [NetFlow IPFIX sFlow libpcap BGP BMP IGP Streaming Telemetry

networking Red Team

pmap

Passively discover, scan, and fingerprint link-local peers by the background noise they generate (i.e. their broadcast a

windows Red Team

pmapper

A tool for quickly evaluating IAM permissions in AWS.

recon Red Team

pmcma

Automated exploitation of invalid memory writes (being them the consequences of an overflow in a writable section, of a

exploitation Red Team

pmdump

A tool that lets you dump the memory contents of a process to a file without stopping the process.

windows Red Team

pngcheck

Verifies the integrity of PNG, JNG and MNG files by checking the CRCs and decompressing the image data.

stego Red Team

pnscan

Multi threaded port scanner

uncategorized Red Team

pocsuite

An open-sourced remote vulnerability testing framework developed by the Knownsec Security Team.

exploitation Red Team

pocsuite3

Open-sourced remote vulnerability testing framework

uncategorized Red Team

poison

A fast, asynchronous syn and udp scanner.

scanner Red Team

PolarProxy

Intercept and decrypt TLS traffic.

monitoring Blue Team

polenum

Extracts the password policy from a Windows system

uncategorized Red Team

Political MoneyLine

Campaign finance and political money database aggregating federal election contributions and lobbying data.

public-records

PolitiFact

Fact-checking publication that rates political claims and documents supporting evidence.

disinformation-media-verification

poly

Polymorphic webshells.

webapp Red Team

polyswarm

An interface to the public and private PolySwarm APIs.

malware Blue Team

pompem

Exploit and Vulnerability Finder

resource-development Red Team

pompem-git

A python exploit tool finder

exploit Red Team

poracle

A tool for demonstrating padding oracle attacks.

crypto Red Team

Port scanner Online

Simple web-based port scanner for checking common ports on target IPs.

ip-mac-address

PortEx

Statically analyze PE files.

pe-files Blue Team

portia

Automate a number of techniques commonly performed on internal network penetration tests after a low privileged account

automation Red Team

portmanteau

An experimental unix driver IOCTL security tool that is useful for fuzzing and discovering device driver attack surface.

fuzzer Red Team

portspoof

Enhance OS security through a set of techniques

system-services Red Team

portspoof-git

A lightweight, fast, portable and secure addition to any firewall system or security infrastructure.

uncategorized Red Team

poshc2

Proxy aware C2 framework

uncategorized Red Team

postenum

Clean, nice and easy tool for basic/advanced privilege escalation techniques.

recon Red Team

postman

API platform for testing APIs

ad web

posttester

A jar file that will send POST requests to servers in order to test for the hash collision vulnerability discussed at th

crypto Red Team

powercat

Netcat features all in powershell v2

non-application-layer-protocol Red Team

powercloud

Deliver powershell payloads via DNS TXT via CloudFlare using PowerShell.

windows Red Team

powerfuzzer

Powerfuzzer is a highly automated web fuzzer based on many other Open Source fuzzers available (incl. cfuzzer, fuzzled,

fuzzer Red Team

powerlessshell

Run PowerShell command without invoking powershell.exe.

windows Red Team

powermft

Powerful commandline $MFT record editor.

forensic Blue Team

powerops

PowerShell Runspace Portable Post Exploitation Tool aimed at making Penetration Testing with PowerShell "easier".

windows Red Team

powershdll

Run PowerShell with rundll32. Bypass software restrictions.

windows Red Team

powershell

PowerShell is an automation and configuration management platform.

services-and-other-tools Red Team

PowerShell Core

Run PowerShell scripts and commands.

scripts Blue Team

powershell-empire

PowerShell and Python post-exploitation agent

command-and-control system-services Red Team

powershell-payload-excel-delivery-git

A VBA macro that uses invoke-shellcode to execute a powershell payload in memory.

exploit Red Team

powersploit

PowerShell Post-Exploitation Framework

execution Red Team

powersploit-git

A PowerShell Post-Exploitation Framework

exploit Red Team

powerstager

A payload stager using PowerShell.

binary Red Team

powerupsql-git

Powershell Toolkit for Attacking SQL Server

webapps Red Team

Powerview.py

PowerView.py is an alternative for the awesome original PowerView.ps1 script.

ad

pown

Security testing and exploitation toolkit built on top of Node.js and NPM.

webapp Red Team

pp-finder

Prototype pollution finder tool for javascript. pp-finder lets you find prototype pollution candidates in your code.

web

ppee

A Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in

windows Red Team

ppfuzz

A fast tool to scan client-side prototype pollution vulnerability written in Rust.

webapp Red Team

ppmap

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known ga

webapp Red Team

ppscan

Yet another port scanner with HTTP and FTP tunneling support.

scanner Red Team

pr0cks

python script setting up a transparent proxy to forward all TCP and DNS traffic through a SOCKS / SOCKS5 or HTTP(CONNECT

proxy Red Team

prads

A "Passive Real-time Asset Detection System".

scanner Red Team

praeda

An automated data/information harvesting tool designed to gather critical information from various embedded devices.

scanner Red Team

pre2k

Query for existence of pre-windows 2000 computer objects which can be leveraged to gain a foothold in a target domain.

windows Red Team

preeny

Some helpful preload libraries for pwning stuff.

exploitation Red Team

pret

Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.

exploitation Red Team

pretender

an mitm tool for helping with relay attacks.

ad

princeprocessor

Standalone password candidate generator using the PRINCE algorithm

uncategorized Red Team

prips

A utility for quickly generating IP ranges or enumerating hosts within a specified range.

ad web

Privacy Tools

Privacy-focused tool recommendation site covering encrypted messaging, VPNs, browsers, operating systems, and email providers; now largely redirects…

opsec

privexchange

a tool to perform attacks against Microsoft Exchange server using NTLM relay techniques

ad

ProcDOT

Visualize and examine the output of Process Monitor.

investigate-system-interactions Blue Team

procdump

Generate coredumps based off performance triggers.

binary Red Team

processdump

Process Dump is a Windows reverse-engineering command-line tool to dump malware memory components back to disk for analysis.

memory Blue Team

ProcmonMCP

MCP server that lets AI assistants analyze Process Monitor (Procmon) XML captures.

investigate-system-interactions Blue Team

procps

/proc file system utilities

uncategorized Red Team

procscope

Process-scoped runtime investigation tool using eBPF.

defensive Blue Team

proctal

Provides a command line interface and a C library to manipulate the address space of a running program on Linux.

binary Red Team

procyon

A suite of Java metaprogramming tools focused on code generation and analysis.

decompiler Blue Team

profuzz

Simple PROFINET fuzzer based on Scapy.

fuzzer Red Team

Project Honey Pot

Global honeypot network collecting spam and attack data with IP reputation service.

ip-mac-address

prometheus-firewall

A Firewall analyzer written in ruby

networking Red Team

prometheus-git

A Firewall analyzer written in ruby

networking Red Team

promiscdetect

Checks if your network adapter(s) is running in promiscuous mode, which may be a sign that you have a sniffer running on

windows Red Team

promptfoo

Test and evaluate LLM outputs - AI red teaming, pentesting, and vulnerability scanning.

ai Red Team

ProtonMail Domains (M)

Queries ProtonMail's HKP key server with a full email address to check for a PGP public key. Useful for identifying ProtonMail users on custom…

username

ProtonMail users (M)

Queries ProtonMail's HKP-compatible PGP key server to look up the public key for a ProtonMail username. A successful response confirms the account…

username

protos-sip

SIP test suite

voip Red Team

protosint

Python script that helps you investigate Protonmail accounts and ProtonVPN IP addresses.

recon Red Team

prowler

Tool for AWS security assessment, auditing and hardening.

defensive Blue Team

Prowler (T)

Cloud security posture and compliance assessment framework covering AWS, Azure, GCP, Kubernetes, and SaaS surfaces.

cloud-infrastructure

proxenet

THE REAL hacker friendly proxy for web application pentests.

webapp Red Team

proxify

Swiss Army knife Proxy tool for HTTP/HTTPS traffic capture, manipulation

uncategorized Red Team

proximoth

Control Frame Attack Vulnerability Detection Tool

uncategorized Red Team

proxmark3

Firmware, flasher, and client for the Proxmark3

uncategorized Red Team

proxybroker2

Proxy [Finder

checker Red Team

proxychains

Proxy chains - redirect connections through proxy servers.

ad light

proxychains-ng

Runtime shared library for proxychains-ng

protocol-tunneling Red Team

proxycheck

This is a simple proxy tool that checks for the HTTP CONNECT method and grabs verbose output from a webserver.

scanner Red Team

proxyp

Small multithreaded Perl script written to enumerate latency, port numbers, server names, & geolocations of proxy IP add

proxy Red Team

proxyscan

A security penetration testing tool to scan for hosts and ports through a Web proxy server.

scanner Red Team

proxytunnel

Help SSH and other protocols through HTTP(S) proxies

protocol-tunneling Red Team

ps1encode

A tool to generate and encode a PowerShell based Metasploit payloads.

exploitation Red Team

ps1encode-git

A tool to generate and encode a PowerShell based Metasploit payloads

exploit Red Team

pscan

A limited problem scanner for C source files

code-audit Red Team

pshitt

A lightweight fake SSH server designed to collect authentication data sent by intruders.

honeypot Blue Team

pshitt-git

A lightweight fake SSH server designed to collect authentication data sent by intruders.

uncategorized Red Team

pskracker

Collection of WPA/WPA2/WPS default keys generators/pingens

uncategorized Red Team

psnotify

psnotify is a POC tool to fight .NET anti-dumping tricks.

dotnet Blue Team

pspy

Monitor Linux processes without root permissions

process-discovery Red Team

pst-utils

pst-utils is a set of tools for working with Outlook PST files.

general

pstoreview

Lists the contents of the Protected Storage.

windows Red Team

psychopath-git

an advanced path traversal tool

uncategorized Red Team

ptf

The Penetration Testers Framework: Way for modular support for up-to-date tools.

exploitation Red Team

pth-toolkit

Modified version of the passing-the-hash tool collection made to work straight out of the box.

sniffer Red Team

pth-tools

A toolkit to perform pass-the-hash attacks

ad

ptp

Ranks the discoveries listed in security tool reports.

uncategorized Red Team

ptunnel

Tunnel TCP connections over ICMP packets

protocol-tunneling Red Team

Public Buckets

Search interface for publicly indexed cloud object storage buckets and files across multiple providers.

cloud-infrastructure

Public Records?

Ambiguous entry - likely refers to BRB Publications' public records portal or aggregator. See BRB Public Records below for clarification.

public-records

PublicWWW

Source code search engine for HTML, JavaScript, CSS, and plaintext across 509+ million web pages. Find websites using specific analytics IDs, ad…

search-engines

PubMed - National Center for Biotechnology Information

Free biomedical and life sciences literature database maintained by the NCBI with over 40 million citations; includes abstracts and links to…

search-engines

PubPeer

Post-publication peer review platform where researchers comment on and flag issues with published scientific papers; useful for identifying retracted…

search-engines

pulledpork

Snort rule management.

misc Red Team

pulledpork-git

Snort rule management

misc Red Team

punk

A post-exploitation tool meant to help network pivoting from a compromised unix box.

exploitation Red Team

punter

Hunt domain names using DNSDumpster, WHOIS, Reverse WHOIS, Shodan, Crimeflare.

recon Red Team

pupy

Opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly writte

automation Red Team

pureblood

A Penetration Testing Framework created for Hackers / Pentester / Bug Hunter.

automation Red Team

puredns

Fast domain resolver and subdomain bruteforcing with accurate wildcard filtering.

recon Red Team

pwatch

An ncurses tool that can be run by root to give information about processes

analysis Red Team

pwcrack

Password hash automatic cracking framework.

cracker Red Team

pwd-hash

A password hashing tool that use the crypt function to generate the hash of a string given on standard input.

crypto Red Team

pwdlogy

A target specific wordlist generating tool for social engineers and security researchers.

misc Red Team

pwdlyser

Python-based CLI Password Analyser (Reporting Tool).

crypto Red Team

pwdump

Extracts the binary SAM and SYSTEM file from the filesystem and then the hashes.

windows Red Team

pwfuzz-rs

Rust-based password mutator for brute force attacks.

misc Red Team

pwnat

NAT to NAT client-server communication

protocol-tunneling Red Team

pwnat-git

Punches holes in firewalls and NATs allowing any numbers of clients behind NATs to directly connect to a server behind a different NAT with no 3rd par

networking Red Team

pwncat

Netcat on steroids

uncategorized Red Team

pwncat-caleb

A post-exploitation platform.

exploitation Red Team

pwncat-vl

Maintained fork of pwncat-cs with recent fixes and enhancements.

ad

pwndb

A command-line tool for searching the pwndb database of compromised credentials.

osint web Red Team

pwndbg

a GDB plugin that makes debugging with GDB suck less

general

pwndbg-git

A collection of python that makes debugging with gdb suck less

decompile Blue Team

pwndora

Massive IPv4 scanner, find and analyze internet-connected devices in minutes, create your own IoT search engine at home.

scanner Red Team

pwndrop

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

webapp Red Team

pwned

A command-line tool for querying the 'Have I been pwned?' service.

recon Red Team

pwned-search

Pwned Password API lookup.

recon Red Team

pwned-search-git

Pwned Password API lookup

uncategorized Red Team

pwnedornot

Tool to find passwords for compromised email addresses.

recon Red Team

pwnedornot-git

OSINT Tool to Find Passwords for Compromised Email Accounts

uncategorized Red Team

pwnedpasswords

Generate and verify pwnedpasswords check digits.

misc Red Team

pwninit

A tool for automating starting binary exploit challenges

general

pwnloris

An improved slowloris DOS tool which keeps attacking until the server starts getting exhausted.

dos Red Team

pwntools

The CTF framework used by #Gallopsled in every CTF

exploit Red Team

PXEThief

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

ad

pyadrecon

Gathers information about the Active Directory and generates a report which can provide a holistic picture of the curren

windows Red Team

pyaxmlparser

A simple parser to parse Android XML file.

mobile Red Team

pybozocrack

A silly & effective MD5 cracker in Python.

cracker Red Team

pycdas

pycdas is a Python byte-code disassembler.

python Blue Team

pycdc

pycdc is a Python decompiler.

python Blue Team

pydictor

A useful hacker dictionary builder for a brute-force attack.

misc Red Team

pyelftools

Python library for parsing and analyzing ELF files and DWARF debugging information.

elf-files Blue Team

pyersinia

Network attack tool like yersinia but written in Python.

networking Red Team

pyew

A python tool to analyse malware.

malware Blue Team

pyexfil

A couple of beta stage tools for data exfiltration.

networking Red Team

pyFindUncommonShares

Script that can help identify shares that are not commonly found on a Windows system.

ad

pyfiscan

Free web-application vulnerability and version scanner.

webapp Red Team

pyftpdlib

Extremely fast and scalable Python FTP server library

ad light osint web Red Team

pyfuscation

Obfuscate powershell scripts by replacing Function names, Variables and Parameters.

automation Red Team

pygoldengmsa

Cross-platform Python implementation of the GoldenGMSA attack for exploiting Group Managed Service Accounts (gMSA) in Active Directory.

ad

pygpoabuse

RCE via GPO scheduled tasks.

windows Red Team

pyinstaller

Utility to bundle a Python application into a single package

resource-development Red Team

PyInstaller Extractor

Extract contents of a PyInstaller-generated PE files.

python Blue Team

pyinstaller-hooks-contrib

PyInstaller community hooks.

misc Red Team

pyinstxtractor

PyInstalller Extractor

uncategorized Red Team

pyinstxtractor-ng

Extract contents of PyInstaller-generated executables without requiring a matching Python version.

python Blue Team

pyjfuzz

Python JSON Fuzzer.

fuzzer Red Team

pykek

Kerberos Exploitation Kit.

exploitation Red Team

pylaps

Utility for enumerating and querying LDAP servers.

ad

pylingual

Python decompiler for modern Python versions.

python Blue Team

pylnk3

Python library for reading and writing Windows shortcut files

uncategorized Red Team

pymeta

Auto Scanning to SSL Vulnerability.

recon Red Team

pyminifakedns

Minimal DNS server written in Python; it always replies with a 127.0.0.1 A-record.

networking Red Team

pypykatz

a Python library for mimikatz-like functionality

ad

pyrasite

Code injection and introspection of running Python processes.

backdoor Red Team

pyrdp

Python 3 RDP MITM and library.

sniffer Red Team

pyrit

The famous WPA precomputed cracker.

cracker Red Team

pysnaffler

Snaffler. But in python.

ad

pyssltest

A python multithreaded script to make use of Qualys ssllabs api to test SSL flaws.

scanner Red Team

pytacle

Automates the task of sniffing GSM frames

sniffer Red Team

pytbull

Next generation of pytbull, IDS/IPS testing framework.

scanner Red Team

pythem

Python2 penetration testing framework.

scanner Red Team

python-aiomultiprocess

asyncio version of the standard multiprocessing module

uncategorized Red Team

python-ajpy

aims to craft AJP requests in order to communicate with AJP connectors

uncategorized Red Team

python-altgraph

fork of graphlib: a graph (network) package for constructing graphs

uncategorized Red Team

python-amoco

yet another tool for analysing binaries

malware Blue Team

python-api-dnsdumpster

Unofficial Python API for http://dnsdumpster.com/.

recon Red Team

python-arpreq

Python C extension to query the Kernel ARP cache for the MAC address of a given IP address.

uncategorized Red Team

python-artifacts

Digital Forensics Artifact Repository

uncategorized Red Team

python-async

Async aims to make writing asyncronous processing easier.

uncategorized Red Team

python-async_timeout

Timeout context manager for asyncio programs

uncategorized Red Team

python-backports.lzma

Backport of Python 3 standard library module lzma for LZMA/XY compressed files

uncategorized Red Team

python-bacpypes

BACpypes provides a BACnet application layer and network layer written in Python for daemons, scripting, and graphical interfaces.

uncategorized Red Team

python-bandicoot

A toolbox to analyze mobile phone metadata.

uncategorized Red Team

python-bfac-git

Advanced Backup-File Artifacts Testing for Web-Applications

uncategorized Red Team

python-bintrees

Package provides Binary-, RedBlack- and AVL-Trees in Python and Cython.

uncategorized Red Team

python-bumpversion

Version-bump your software with a single command

uncategorized Red Team

python-cfscrape

A Python module to bypass Cloudflare's anti-bot page

uncategorized Red Team

python-chart-studio

An interactive, browser-based graphing library for Python

uncategorized Red Team

python-coloredlogs

Colored stream handler for Python's logging module

uncategorized Red Team

python-crcelk

Updated fork of CrcMoose.

uncategorized Red Team

python-crysp

A crypto related pkg for amoco

uncategorized Red Team

python-cx_oracle

Python interface to Oracle Database conforming to the Python DB API 2.0 specification

uncategorized Red Team

python-cybox

A Python library for parsing and generating CybOX 2.1.0 content.

uncategorized Red Team

python-cymruwhois

Python client for the whois.cymru.com service

networking Red Team

python-defaults

Package depending on all supported Python2 debugging packages

uncategorized Red Team

python-delegator.py

Subprocesses for Humans 2.0.

uncategorized Red Team

python-dicttoxml

Converts a Python dictionary or other native data type into a valid XML string

uncategorized Red Team

python-dpkt-git

Python library for interacting with and creating packets.

uncategorized Red Team

python-dtfabric

Tooling for data type and structure management

uncategorized Red Team

python-ed25519

Python Bindings to the Ed25519 Digital Signature System

uncategorized Red Team

python-emailprotectionslib

Python library to interact with SPF and DMARC

uncategorized Red Team

python-fake-useragent

Up to date simple useragent faker with real world database

uncategorized Red Team

python-faraday

Collaborative Penetration Test IDE

reporting-tools system-services Red Team

python-filemagic

Provides a Python API for libmagic, the library behind Unix file command

uncategorized Red Team

python-flake8-per-file-ignores

An extension for flake8 that lets you configure (out-of-source) individual error codes to be ignored per file

uncategorized Red Team

python-flake8-polyfill

Provides the poly fill for Flake8 plugins

uncategorized Red Team

python-flake8-quotes

Flake8 extension for checking quotes in python

uncategorized Red Team

python-flow.record

Recordization library.

forensic Blue Team

python-frida

Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.

reversing Blue Team

python-frida-tools

Frida CLI tools.

mobile Red Team

python-fusepy

Python module that provides a simple interface to FUSE and MacFUSE

uncategorized Red Team

python-fuzzywuzzy-git

Fuzzy string matching in python

uncategorized Red Team

python-google-streetview

A command line tool and module for Google Street View Image API.

misc Red Team

python-googletransx

Free Google Translate API for Python

uncategorized Red Team

python-grandalf

A graph and drawing algorithms framework

uncategorized Red Team

python-http_request

A small python library to parse and build HTTP requests

uncategorized Red Team

python-iampoliciesgonewild

Optical character recognition (OCR) tool for Python 3.x

uncategorized Red Team

python-ipcalc

IP subnet calculator for Python.

uncategorized Red Team

python-iptools

Python utilites for manipulating IPv4 and IPv6 addresses

uncategorized Red Team

python-ishell

Build Interactive Shells with Python

uncategorized Red Team

python-itanium_demangler

Parser for the Itanium C++ ABI symbol mangling language

uncategorized Red Team

python-ivre

Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (library)

recon Red Team

python-jinja2-time

Jinja2 Extension for Dates and Times

uncategorized Red Team

python-keyboard

A small python library to parse and build HTTP requests

uncategorized Red Team

python-keylogger

Simple keystroke logger.

keylogger Red Team

python-ldapdomaindump

Active Directory information dumper via LDAP (Python 3)

uncategorized Red Team

python-libnmap

Python NMAP library enabling you to start async nmap tasks, parse and compare/diff scan results

uncategorized Red Team

python-libpcap

Cython libpcap

uncategorized Red Team

python-libtaxii

TAXII Library.

uncategorized Red Team

python-lief

Library to instrument executable formats.

disassembler Blue Team

python-litecli

CLI for SQLite Databases with auto-completion and syntax highlighting.

uncategorized Red Team

python-macholib

Mach-O header analysis and editing

uncategorized Red Team

python-maec

An API for parsing and creating MAEC content.

uncategorized Red Team

python-magic-git

A python wrapper for libmagic

uncategorized Red Team

python-maryam-git

OWASP Maryam is a modular/optional open source framework based on OSINT and data gathering.

intel Red Team

python-mechanicalsoup

A Python library for automating interaction with websites

uncategorized Red Team

python-miasm-git

A Reverse engineering framework in Python

analysis Red Team

python-mixbox

Utility library for cybox, maec, and stix packages

uncategorized Red Team

python-mmbot

Powerful malicious file triage tool for cyber responders.

malware Blue Team

python-mrbob

creates directory skeletons

uncategorized Red Team

python-msoffcrypto-tool

Python tool and library for decrypting MS Office files with passwords or other keys

uncategorized Red Team

python-neo4j

Neo4j Bolt Driver for Python

uncategorized Red Team

python-nmap

Python3 library which helps in using the nmap port scanner.

uncategorized Red Team

python-oletools

Tools to analyze Microsoft OLE2 files.

binary Red Team

python-owasp-zap-v2.4

OWASP ZAP API client

uncategorized Red Team

python-pager

Terminal/console pager module for Python

uncategorized Red Team

python-pcodedmp

A VBA p-code disassembler.

disassembler Blue Team

python-peid

Python implementation of the Packed Executable iDentifier (PEiD).

binary Red Team

python-pep8-naming

Naming Convention checker for Python

uncategorized Red Team

python-pip

Python package installer

uncategorized Red Team

python-pipx

Execute binaries from Python packages in isolated environments

uncategorized Red Team

python-plotly

An interactive, browser-based graphing library for Python

uncategorized Red Team

python-pluginbase

A support library for building plugins sytems in Python.

uncategorized Red Team

python-poster-git

Pprovides a set of classes and functions to faciliate making HTTP POST (or PUT) requests using the standard multipart/form-data encoding

uncategorized Red Team

python-prompt-toolkit

Library for building powerful interactive command lines in Python

uncategorized Red Team

python-puttykeys

A module to convert SSH keys from the Putty format to the OpenSSH format

uncategorized Red Team

python-pydeep

This is the Python interface to ssdeep.

uncategorized Red Team

python-pyghmi

a pure Python (mostly IPMI) server management library

uncategorized Red Team

python-pygraphviz

PyGraphviz is a Python interface to the Graphviz graph layout and visualization package.

uncategorized Red Team

python-pykcp-git

A module to convert SSH keys from the Putty format to the OpenSSH format

uncategorized Red Team

python-pylzma-git

Python bindings for the LZMA library

uncategorized Red Team

python-pyminifier

A Python code minifier, obfuscator, and compressor

uncategorized Red Team

python-pymisp

Python library using the MISP Rest API

uncategorized Red Team

python-pyodbc

Python ODBC bridge

uncategorized Red Team

python-pypdns

Python API for PDNS.

uncategorized Red Team

python-pypsrp

Python client for the PowerShell Remoting Protocol (PSRP) and Windows Remove Management (WinRM) service

uncategorized Red Team

python-pypykatz-git

Mimikatz implementation in pure Python

uncategorized Red Team

python-pyric

Python Wireless Library

uncategorized Red Team

python-pyshark

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

uncategorized Red Team

python-pysmb

an experimental SMB/CIFS library written in Python

uncategorized Red Team

python-pysqlcipher3

Python interface to SQLCipher

uncategorized Red Team

python-pystrich

A Python module to generate 1D and 2D barcodes (Code 128, DataMatrix, QRCode and EAN13).Forked from huBarcode.

uncategorized Red Team

python-pyuv-git

Python module which provides an interface to libuv

uncategorized Red Team

python-pyvex

A Python interface to libVEX and VEX IR.

uncategorized Red Team

python-r2pipe

A Pipe interface for radare2

uncategorized Red Team

python-roguehostapd-git

Hostapd wrapper for hostapd

uncategorized Red Team

python-rq

Simple job queues for Python

uncategorized Red Team

python-safedexml

A defusedxml version of dead-simple Object-XML mapper for Python

uncategorized Red Team

python-scandir

A directory iteration function

uncategorized Red Team

python-schedule

Python job scheduling for humans

uncategorized Red Team

python-search-engine-parser

Scrapes search engine pages for query titles, descriptions and links.

uncategorized Red Team

python-selenium

A browser automation framework and ecosystem

uncategorized Red Team

python-smoke-zephyr

Python utility collection

uncategorized Red Team

python-spark

An Early-Algorithm Context-free grammar Parser

uncategorized Red Team

python-sqlalchemy-utc

SQLAlchemy type to store aware datetime values

uncategorized Red Team

python-ssh-mitm

SSH mitm server for security audits supporting public key authentication, session hijacking and file manipulation.

exploitation Red Team

python-stix

An API for parsing and generating STIX content.

uncategorized Red Team

python-stringcase

String case converter

uncategorized Red Team

python-tinyec-git

A tiny library to perform arithmetic operations on elliptic curves in pure python

uncategorized Red Team

python-tls_parser

Small library to parse TLS records

misc Red Team

python-trackerjacker

Finds and tracks wifi devices through raw 802.11 monitoring.

wireless Red Team

python-trio-websocket

WebSocket client and server implementation for Python Trio

uncategorized Red Team

python-uncompyle6

A Python cross-version decompiler.

decompiler Blue Team

python-urllib-auth-git

library that provides NTLM/SPNEGO/SSPI support

uncategorized Red Team

python-vipermonkey-git

A VBA parser and emulation engine to analyze malicious macros

uncategorized Red Team

python-virtualenv

Python virtual environment creator

uncategorized Red Team

python-virustotal-api

Virus Total Public/Private/Intel API

uncategorized Red Team

python-win_inet_pton-git

Native inet_pton and inet_ntop implementation for Python on Windows

uncategorized Red Team

python-win-unicode-console

PA Python package to enable Unicode support when running Python from Windows console

uncategorized Red Team

python-witnessme

Web Inventory tool, takes screenshots of webpages using Pyppeteer.

webapp Red Team

python-xbee

Python tools for working with XBee radios

uncategorized Red Team

python-xdis

Python cross-version byte-code disassembler and marshal routines.

uncategorized Red Team

python-xlutils

Utilities for working with Excel files

uncategorized Red Team

python-xpath-expressions

Treat XPath expressions as Python objects

uncategorized Red Team

python-yaswfp

Yet Another SWF Parser

uncategorized Red Team

python-zlib_wrapper

Wrapper around zlib with custom header crc32.

uncategorized Red Team

python2-api-dnsdumpster

Unofficial Python API for http://dnsdumpster.com/.

recon Red Team

python2-capstone

A disassembly framework with the target of becoming the ultimate disasm engine for binary analysis and reversing in the

disassembler Blue Team

python2-cymruwhois

Python client for the whois.cymru.com service

networking Red Team

python2-darts.util.lru

Simple dictionary with LRU behaviour.

misc Red Team

python2-exrex

Irregular methods on regular expressions.

misc Red Team

python2-frida

Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.

reversing Blue Team

python2-frida-tools

Frida CLI tools.

mobile Red Team

python2-google-streetview

A command line tool and module for Google Street View Image API.

misc Red Team

python2-hpfeeds

Honeynet Project generic authenticated datafeed protocol.

honeypot Blue Team

python2-instalooter

A program that can download any picture or video associated from an Instagram profile

uncategorized Red Team

python2-ivre

Network recon framework based on Nmap, Masscan, Zeek (Bro), Argus, Netflow,... (library)

recon Red Team

python2-jsbeautifier

JavaScript unobfuscator and beautifier.

webapp Red Team

python2-ldapdomaindump

Active Directory information dumper via LDAP.

scanner Red Team

python2-minidump

Python library to parse and read Microsoft minidump file format.

windows Red Team

python2-minikerberos

Kerberos manipulation library in pure Python.

windows Red Team

python2-oletools

Tools to analyze Microsoft OLE2 files.

binary Red Team

python2-pcodedmp

A VBA p-code disassembler.

disassembler Blue Team

python2-peepdf

A Python tool to explore PDF files in order to find out if the file can be harmful or not.

forensic Blue Team

python2-ropgadget

Pythonic argument parser, that will make you smile.

exploitation Red Team

python2-shodan

Python library and command-line utility for Shodan (https://developer.shodan.io).

recon Red Team

python2-utidylib

Python bindings for Tidy HTML parser/cleaner.

misc Red Team

pywerview

A (partial) Python rewriting of PowerSploit's PowerView.

ad

pywhisker

PyWhisker is a Python equivalent of the original Whisker made by Elad Shamir and written in C#. This tool allows users to manipulate the…

ad

pywsus

Python implementation of a WSUS client

ad

qark

Tool to look for several security related Android application vulnerabilities.

mobile Red Team

qbdi

A Dynamic Binary Instrumentation framework based on LLVM.

binary Red Team

qemu

Extra block backend modules for qemu-system and qemu-utils

uncategorized Red Team

Qiling

Emulate code execution of PE files, shellcode, etc. for a variety of OS and hardware platforms.

general Blue Team

qpdf

Manipulate (merge, convert, transform) PDF files.

pdf Blue Team

qradiolink

Multimode SDR transceiver for GNU radio, ADALM-Pluto, LimeSDR, USRP.

radio Red Team

qrgen

Simple script for generating Malformed QRCodes.

misc Red Team

qrljacker

QRLJacker is a highly customizable exploitation framework to demonstrate "QRLJacking Attack Vector".

social Red Team

qsreplace

Accept URLs on stdin, replace all query string values with a user-supplied value, only output each combination of query

misc Red Team

qsslcaudit

Test SSL/TLS clients how secure they are

uncategorized Red Team

quark-engine

Android Malware (Analysis | Scoring System)

uncategorized Red Team

quickrecon

A python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gather

recon Red Team

quicksand-lite

Command line tool for scanning streams within office documents plus xor db attack.

defensive Blue Team

quickscope

Statically analyze windows, linux, osx, executables and also APK files.

binary Red Team

r2decomp

Decompile the function behind a capa match using radare2 and the Ghidra decompiler.

general Blue Team

r2pipe

Examine binary files, including disassembling and debugging.

general Blue Team

rabid

A CLI tool and library allowing to simply decode all kind of BigIP cookies.

webapp Red Team

raccoon

A high performance offensive security tool for reconnaissance and vulnerability scanning.

recon Red Team

radare2

Free and advanced command line hexadecimal editor

resource-development Red Team

radare2-keystone

Keystone assembler plugins for radare2.

reversing Blue Team

radare2-unicorn

Unicorn Emulator Plugin for radare2.

disassembler Blue Team

radiography

A forensic tool which grabs as much information as possible from a Windows system.

windows Red Team

rainbowcrack

Rainbow table password cracker

password-cracking Red Team

rake

Ruby make-like utility

uncategorized Red Team

Random User Generator

Open-source API that generates randomized user profiles including names, photos, addresses, and credentials for development and OSINT persona…

opsec

ranger-scanner

A tool to support security professionals to access and interact with remote Microsoft Windows based systems.

scanner Red Team

rapidscan

The Multi-Tool Web Vulnerability Scanner.

webapp Red Team

RAR

Compress and decompress files using a variety of algorithms.

general-utilities Blue Team

rarcrack

Password cracker for rar archives

uncategorized Red Team

rasenum

A small program which lists the information for all of the entries in any phonebook file (.pbk).

windows Red Team

rat-king-parser

multi-family RAT config parser/extractor

utilities Blue Team

ratproxy

A passive web application security assessment tool

fuzzer Red Team

rats

A rough auditing tool for security in source code files.

code-audit Red Team

raven

Python tool that extends the capabilities of the http.server Python module

exfiltration Red Team

raven (T)

LinkedIn information gathering utility for automated employee enumeration and role filtering.

social-networks

rawr

Rapid Assessment of Web Resources. A web enumerator.

scanner Red Team

rawsec-cli

Rawsec Inventory search CLI to find security tools and resources.

misc Red Team

RBA - Business Information Resources

Curated directory maintained by Researching Business Activities, linking to free and paid business information sources organized by category.

business-records

rbac-lookup

A CLI that allows you to easily find Kubernetes roles and cluster roles bound to any user.

scanner Red Team

rbasefind

A firmware base address search tool.

binary Red Team

rbkb

A miscellaneous collection of command-line tools related to pen-testing and reversing.

misc Red Team

rbndr

Simple DNS Rebinding Service.

spoof Red Team

rcracki-mt

Version of rcrack that supports hybrid and indexed tables

password-cracking Red Team

rcrdcarver

Carve RCRD records ($LogFile) from a chunk of data..

forensic Blue Team

rdesktop

RDP client for Windows NT/2000 Terminal Server and Windows Servers

lateral-movement Red Team

rdesktop-brute

It connects to windows terminal servers - Bruteforce patch included.

cracker Red Team

rdp-cipher-checker

Enumerate the encryption protocols supported by the server and the cipher strengths supported using native RDP encryptio

scanner Red Team

rdp-sec-check

Script to enumerate security settings of an RDP Service.

scanner Red Team

rdpassspray

Python3 tool to perform password spraying using RDP.

cracker Red Team

rdphoneypot

rdphoneypot honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

rdwatool

A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application.

recon Red Team

re-search.py

Search the file for built-in regular expressions of common suspicious artifacts.

general Blue Team

Reacher Demo

Hosted demo of the Reacher email verification API allowing free testing of email validation and deliverability checks online.

email-address

Reacher Github (T)

Open-source Rust-based email verification API that checks email deliverability without sending messages, detecting catch-all and disposable addresses.

email-address

Read Notify

Email tracking and read receipt service that monitors email opens and engagement, useful for confirming email validity through delivery.

email-address

readpe

Command-line tools to manipulate Windows PE files

forensic-carving-tools Blue Team

readpe (formerly pev)

Analyze PE files and extract strings from them.

pe-files Blue Team

reaver

Brute force attack tool against Wi-Fi Protected Setup PIN number

wifi wifi-credential-access Red Team

reaver-wps-fork-t6x-git

Brute force attack against Wifi Protected Setup forked w/ added Pixie Dust Attack

uncategorized Red Team

rebind

DNS rebinding tool

initial-access Red Team

recaf

Modern Java bytecode editor.

decompiler Blue Team

recentfilecache-parser

Python parser for the RecentFileCache.bcf on Windows.

forensic Blue Team

recollapse

Tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications.

webapp Red Team

recomposer

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

automation Red Team

recon-ng

Web Reconnaissance framework written in Python

web-scanning reconnaissance Red Team

recon-ng-git

A full-featured Web Reconnaissance framework written in Python.

recon Red Team

Recon-ng (T)

Full-featured web reconnaissance framework with independent modules for data gathering.

domain-name

recondog

a reconnaissance tool for performing information gathering on a target.

osint web Red Team

reconnoitre

A security tool for multithreaded information gathering and service enumeration.

recon Red Team

reconscan

Network reconnaissance and vulnerability assessment tools.

recon Red Team

reconspider

OSINT Framework for scanning IP Address, Emails, Websites, Organizations

uncategorized Red Team

ReconXplorer (T)

Open-source reconnaissance toolkit with modules for IP, email, and Discord-focused lookups.

online-communities

recordmydesktop

Captures audio-video data of a Linux desktop session

reporting-tools Red Team

Recover FB Account

Facebook account recovery endpoint that confirms whether an email or phone number is linked to an account and presents recovery options.

social-networks

recoverdm

Recover files on disks with damaged sectors

forensic-carving-tools Blue Team

recoverjpeg

Recover JFIF (JPEG) pictures and MOV movies

forensic-carving-tools Blue Team

recsech

Tool for doing Footprinting and Reconnaissance on the target web.

recon Red Team

recuperabit

A tool for forensic file system reconstruction.

forensic Blue Team

red-hawk

All in one tool for Information Gathering, Vulnerability Scanning and Crawling.

recon Red Team

redasm

Interactive, multiarchitecture disassembler written in C++ using Qt5 as UI Framework.

disassembler Blue Team

Reddit Comment History

Visualization utility for reviewing Reddit account comment history and timing patterns.

social-networks

Reddit Darknet

Community forum discussing darknet marketplaces, ecosystem events, and related threat activity.

dark-web

Reddit Deep Web

Subreddit focused on dark web discussions, beginner guidance, and community-sourced OSINT references.

dark-web

Reddit Metis

Reddit user analyzer summarizing posting behavior, language patterns, and subreddit activity.

social-networks

Reddit Onions

Subreddit for .onion service discussion, availability reports, and tool recommendations.

dark-web

redeye

Tool to help you manage your data during a pentest operation

reporting-tools system-services Red Team

redfang

Locates non-discoverable bluetooth devices

bluetooth Red Team

Redfin

Real estate marketplace with comprehensive property history, MLS data, and market analytics. Includes tax history and public records.

public-records

Redirect Detective

Web tool that traces URL redirect chains and final destinations across multi-hop redirects.

domain-name

redirectpoison

A tool to poison a targeted issuer of SIP INVITE requests with 301 (i.e. Moved Permanently) redirection responses.

voip Red Team

Redis

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache and message broker.

network-security-monitoring Blue Team

redis-tools

redis-tools is a collection of Redis client utilities including redis-cli and redis-benchmark.

ad

redishoneypot

redishoneypot honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

redpoint

Digital Bond's ICS Enumeration Tools.

misc Red Team

redpoint-git

Digital Bond's ICS Enumeration Tools

scanners Red Team

redress

A tool for analyzing stripped Go binaries.

binary Red Team

redsnarf

Pentesting tool for retrieving credentials from Windows workstations

uncategorized Red Team

redsocks

Arbitrary TCP connection redirector to a SOCKS or HTTPS proxy server

uncategorized Red Team

reelphish

A Real-Time Two-Factor Phishing Tool.

social Red Team

reg_export

A CLI that exports the raw content of a registry value to a file

registry Blue Team

regcool

RegCool is a flexible editor for the Windows registry database.

registry Blue Team

regeorg

The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.

tunnel Red Team

regipy

Library for parsing offline registry hives.

forensic Blue Team

Registry Finder

Gift registry search aggregator searching across partner retailers including Amazon, Target, and Zola for wedding, baby, birthday, and other…

people-search-engines

reglookup

Utility to analysis for Windows NT-based registry

digital-forensics Blue Team

regreport

Windows registry forensic analysis tool.

windows Red Team

Regrid (US Only)

Interactive property mapping and parcel data tool covering most US counties. Provides parcel boundaries, assessment data, and ownership information.

public-records

regripper

Perform forensic analysis of registry hives

digital-forensics Blue Team

regrippy

Framework for reading and extracting useful forensics data from Windows registry hives.

forensic Blue Team

regshot

Regshot is a registry comparison tool for tracking system changes by comparing registry snapshots.

registry Blue Team

regview

Open raw Windows NT 5 Registry files (Windows 2000 or higher).

windows Red Team

rej

An API and a graphical tool for inspection and manipulation of classfiles for the Java platform.

decompiler Blue Team

rekall

Memory Forensic Framework.

forensic Blue Team

rekono-kbx

Automation platform for pentesting

uncategorized Red Team

relay-scanner

An SMTP relay scanner.

scanner Red Team

remmina

Remote desktop client.

ad

REMnux Installer

Install and update the REMnux distro.

general-utilities Blue Team

REMnux MCP Server

MCP server for using the REMnux malware analysis toolkit via AI assistants.

use-artificial-intelligence Blue Team

remot3d

An Simple Exploit for PHP Language.

webapp Red Team

remote-method-guesser

Java RMI vulnerability scanner.

scanner Red Team

RemoteMonologue

A tool to coerce NTLM authentications via DCOM

ad

rephrase

Specialized passphrase recovery tool for GnuPG

uncategorized Red Team

replayproxy

Forensic tool to replay web-based attacks (and also general HTTP traffic) that were captured in a pcap file.

forensic Blue Team

reptor

CLI tool to automate pentest reporting with SysReptor.

misc Red Team

requests

Elegant and simple HTTP library for Python (Documentation)

uncategorized Red Team

resourcehacker

Resource compiler and decompiler for Windows® applications.

windows Red Team

responder

LLMNR/NBT-NS/mDNS Poisoner

credential-access Red Team

restler-fuzzer

First stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding securi

webapp Red Team

restrict-egress

Restrict outbound network access to an allowlist of domains and CIDRs using an nftables default-deny egress policy. It i

general-utilities Blue Team

retdec

Retargetable machine-code decompiler based on LLVM.

decompiler Blue Team

retire

Scanner detecting the use of JavaScript libraries with known vulnerabilities.

scanner Red Team

rev-proxy-grapher

Reverse proxy grapher

uncategorized Red Team

Reveddit

Interface for viewing Reddit content removals using archived and moderation-related visibility signals.

online-communities

reverseip

Ruby based reverse IP-lookup tool.

recon Red Team

RevEye Reverse Image Search (T)

Open-source browser extension that launches reverse image searches across multiple engines from one menu.

images-videos-docs

revipd

A simple reverse IP domain scanner.

recon Red Team

revsh

A reverse shell with terminal support, data tunneling, and advanced pivoting capabilities.

backdoor Red Team

rex

Shellphish's automated exploitation engine, originally created for the Cyber Grand Challenge.

exploitation Red Team

rext

Router EXploitation Toolkit - small toolkit for easy creation and usage of various python scripts that work with embedde

exploitation Red Team

RF Analyzer

Spectrum Analyzer for Android using the HackRF.

rf

rfcat

Swiss army knife of sub-GHz radio

radio-frequency Red Team

rfcrack

A Software Defined Radio Attack Tool.

cracker Red Team

rfdump

Tool to decode RFID tag data

uncategorized Red Team

rfidiot

An open source python library for exploring RFID devices.

wireless Red Team

rfidtool

An open source tool to read / write rfid tags.

wireless Red Team

Rhino Debugger

GUI JavaScript debugger.

scripts Blue Team

rhodiola

Personalized wordlist generator with NLP, by analyzing tweets (A.K.A crunch2049).

automation Red Team

richsploit

Exploitation toolkit for RichFaces.

exploitation Red Team

ridenum

Null session RID cycle attack tool

uncategorized Red Team

ridenum-git

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

crackers Red Team

ridrelay

Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.

recon Red Team

rifiuti

MS Windows recycle bin analysis tool

forensic-carving-tools Blue Team

rifiuti2

Replacement for rifiuti, a MS Windows recycle bin analysis tool

forensic-carving-tools Blue Team

rinetd

Internet redirection server.

networking Red Team

Riot.im - Communicate, your way (T)

Open-source Matrix client for decentralized messaging. Limited public data but useful for community monitoring.

mobile-osint Red Team

ripdc

A script which maps domains related to an given ip address or domainname.

recon Red Team

rita

Real Intelligence Threat Analytics.

recon Red Team

RiteTag

Hashtag intelligence platform that scores and recommends social tags based on trend velocity and engagement potential.

social-networks

riwifshell

Web backdoor - infector - explorer.

webapp Red Team

rizin

Reverse engineering framework and command-line toolset

resource-development Red Team

rizin-cutter

Reverse engineering platform powered by rizin

resource-development Red Team

rkhunter

Rootkit, backdoor, sniffer and exploit scanner

forensics Blue Team

rling

Better rli

uncategorized Red Team

rlogin-scanner

Multithreaded rlogin scanner. Tested on Linux, OpenBSD and Solaris.

cracker Red Team

rlwrap

rlwrap is a small utility that wraps input and output streams of executables / making it possible to edit and re-run input history

ad osint web Red Team

rmiscout

Enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities.

exploitation Red Team

roadlib

Azure AD and O365 exploration framework.

windows Red Team

roadoidc

Azure AD and O365 exploration framework.

windows Red Team

roadrecon

Azure AD and O365 exploration framework.

windows Red Team

ROADtools (T)

Azure AD exploration framework for dumping tenant objects, principals, and permissions to support attack-path and privilege analysis.

cloud-infrastructure

roadtx

Azure AD and O365 exploration framework.

windows Red Team

roastinthemiddle

RoastInTheMiddle is a tool to intercept and relay NTLM authentication requests.

ad

RobotsDisallowed

Curated wordlist of top disallowed paths harvested from robots.txt files across high-traffic websites.

domain-name

robotstester

Utility for testing whether a website's robots.txt file is correctly configured.

ad web

robotstxt

Robots.txt exclusion protocol implementation for Go language

uncategorized Red Team

Robtex (R)

Comprehensive free DNS lookup and network intelligence tool with decade-spanning database containing billions of documents of internet data. Useful…

domain-name

rogue-mysql-server

A rogue MySQL server written in Python.

misc Red Team

roguehostapd

Hostapd fork including Wi-Fi attacks and providing Python bindings with ctypes.

wireless Red Team

rombuster

A router exploitation tool that allows to disclosure network router admin password.

exploitation Red Team

rookie

Load cookies from your web browsers.

webapp Red Team

rootbrute

Local root account bruteforcer.

cracker Red Team

ropeadope

A linux log cleaner.

anti-forensic Blue Team

ropeme

A set of python scripts to generate ROP gadgets and payload.

exploitation Red Team

ropper

Rop gadget finder and binary information tool

uncategorized Red Team

roputils

A Return-oriented Programming toolkit.

exploitation Red Team

Router Keygen

Free Internet access anywhere, anytime.

exploitation Red Team

routerhunter

Tool used to find vulnerable routers and devices on the Internet and perform tests.

scanner Red Team

routerkeygenpc

Router Keygen generate default WPA/WEP keys

uncategorized Red Team

routersploit

Exploitation Framework for Embedded Devices

uncategorized Red Team

rp

A full-cpp written tool that aims to find ROP sequences in PE/Elf/Mach-O x86/x64 binaries.

exploitation Red Team

rpak

A collection of tools that can be useful for doing attacks on routing protocols.

windows Red Team

rpcsniffer

Sniffs WINDOWS RPC messages in a given RPC server process.

windows Red Team

rpctools

Contains three separate tools for obtaining information from a system that is running RPC services

windows Red Team

rpdscan

Remmina Password Decoder and scanner.

cracker Red Team

rpivot

Socks4 reverse proxy for penetration testing.

proxy Red Team

rr

A Record and Replay Framework.

debugger Red Team

rr-git

A Record and Replay Framework

misc Red Team

rrs

A reverse (connecting) remote shell. Instead of listening for incoming connections it will connect out to a listener (rr

backdoor Red Team

RsaCracker

Powerful RSA cracker for CTFs. Supports RSA - X509 - OPENSSH in PEM and DER formats.

general

rsactftool

RSA tool for ctf - retrieve private key from weak public key and/or uncipher data.

crypto Red Team

rsakeyfind

Locates BER-encoded RSA private keys in memory images

uncategorized Red Team

RSAKeyFinder

Find BER-encoded RSA private keys in a memory image.

perform-memory-forensics Blue Team

rsatool

Tool that can be used to calculate RSA and RSA-CRT parameters.

crypto Red Team

rshack

Python tool which allows to carry out some attacks on RSA, and offer a few tools to manipulate RSA keys.

crypto Red Team

rsmangler

Wordlist mangling tool

password-profiling-wordlists Red Team

rspet

A Python based reverse shell equipped with functionalities that assist in a post exploitation scenario.

exploitation Red Team

rspet-git

Python based reverse shell equipped with functionalities that assist in a post exploitation scenario

malware Blue Team

rsync

File synchronization tool for efficiently copying and updating data between local or remote locations

ad osint web Red Team

rtfdump.py

Analyze a suspicious RTF file.

microsoft-office Blue Team

rtfm

A database of common, interesting or useful commands, in one handy referable form.

misc Red Team

rtl

A generic software defined radio data receiver, mainly for the 433.92 MHz, 868 MHz (SRD), 315 MHz, 345 MHz, and 915 MHz

radio Red Team

rtl-433

Tool for decoding various wireless protocols/ signals such as those used by weather stations

general

Rtl-sdr driver

rtl_tcp & libusb-1.0 port supporting opening devices from Linux file descriptors

development rf

rtl-wmbus

Software defined receiver for wireless M-Bus with RTL-SDR.

radio Red Team

rtl8814au-dkms-git

RTL8814AU and RTL8813AU chipset driver with firmware v5.8.5.1.

wireless Red Team

rtlamr

An rtl-sdr receiver for smart meters operating in the 900MHz ISM band.

radio Red Team

rtlamr-git

An rtl-sdr receiver for smart meters operating in the 900MHz ISM band.

hardware Red Team

rtlizer

Simple spectrum analyzer.

scanner Red Team

rtlsdr-scanner

A cross platform Python frequency scanning GUI for the OsmoSDR rtl-sdr library.

scanner Red Team

rtp-flood

RTP flooder

voip Red Team

rtpbreak

Detects, reconstructs, and analyzes RTP sessions

voip Red Team

rtpflood

Tool to flood any RTP device

impact Red Team

rtpinsertsound

Inserts audio into a specified stream

voip Red Team

rtpmixsound

Mixes pre-recorded audio in real-time

voip Red Team

rubeus

Raw Kerberos interaction and abuses

pass-the-hash os-credential-dumping Red Team

rubilyn

64bit Mac OS-X kernel rootkit that uses no hardcoded address to hook the BSD subsystem in all OS-X Lion & below. It uses

backdoor Red Team

ruby-artii

A little Figlet-based ASCII art generator.

uncategorized Red Team

ruby-colored

>> puts 'this is red'.red >> puts 'this is red with a blue background (read: ugly)'.red_on_blue...

uncategorized Red Team

ruby-gtkhex

A ruby GTK2 hexadecimal widget

uncategorized Red Team

ruby-highline

A high-level text user interface toolkit for Ruby

uncategorized Red Team

ruby-http_configuration

Gem that provides the ability to set defaults for proxies and timeouts for Net::HTTP.

uncategorized Red Team

ruby-mime

library for building RFC compliant Multipurpose Internet Mail Extensions (MIME) messages.

uncategorized Red Team

ruby-mini_exiftool

This library is wrapper for the Exiftool command-line application (http://www.sno.phy.queensu.ca/~phil/exiftool).

uncategorized Red Team

ruby-pedump

Dump win32 PE executable files with a pure ruby

uncategorized Red Team

ruby-rubyzip

A ruby module for reading and writing zip files.

uncategorized Red Team

ruby-spider

A Web spidering library

uncategorized Red Team

ruby-zip

zip is a Ruby library for reading and writing Zip files

uncategorized Red Team

Rucky

A simple to use USB HID Rubber Ducky Launch Pad for Android.

exploitation usb-hid wifi Red Team

ruler

A tool to abuse Exchange services.

webapp Red Team

ruler-git

A tool that allows you to interact with Exchange servers through the MAPI/HTTP protocol.

scanners Red Team

rulesfinder

Machine-learn password mangling rules.

misc Red Team

rundotnetdll

RunDotNetDll is a utility to list all methods of a given .NET Assembly and to invoke them.

dotnet Blue Team

runsc

Run shellcode to trace and analyze its execution.

shellcode Blue Team

rupture

A framework for BREACH and other compression-based crypto attacks.

crypto Red Team

Rusprofile

Russian company registry and business intelligence platform providing information on Russian legal entities from official government sources.

business-records

rustbuster

DirBuster for Rust.

webapp Red Team

rustcat

A modern port listener and reverse shell.

networking Red Team

rusthound

BloodHound ingestor in Rust.

ad

rusthound-ce

Active Directory data collector for BloodHound community edition (v5).

recon Red Team

rustpad

Multi-threaded Padding Oracle attacks against any service.

crypto Red Team

rustscan

Modern Port Scanner

uncategorized Red Team

rvi-capture

Capture packets sent or received by iOS devices.

sniffer Red Team

rww-attack

Performs a dictionary attack against a live Microsoft Windows Small Business Server.

webapp Red Team

rz-ghidra

Ghidra decompiler and sleigh disassembler for rizin

uncategorized Red Team

s3-fuzzer

A concurrent, command-line AWS S3 Fuzzer.

fuzzer Red Team

s3enum

Amazon S3 bucket enumeration.

recon Red Team

s3scanner

Tool to find open S3 buckets and dump their contents

uncategorized Red Team

S3Scanner (T)

Command-line scanner for enumerating and checking S3 bucket misconfigurations across AWS and compatible object storage services.

cloud-infrastructure

safecopy

Data recovery tool for problematic or damaged media

forensic-carving-tools Blue Team

sagan

A snort-like log analysis engine.

ids Red Team

sagan-rules

Rules package for Sagan

uncategorized Red Team

sakis3g

Tool for establishing 3G connections

uncategorized Red Team

saleae-logic

Debug happy.

debugger Red Team

salsapipe-git

Encrypted network tunneling using salsa20 from libnettle and GPG from libgpgme

networking Red Team

Salt

Built on Python, Salt is an event-driven automation tool and framework to deploy, configure, and manage complex IT systems.

network-security-monitoring Blue Team

samba

SMB/CIFS file, print, and login server for Unix

network-share-discovery application-layer-protocol Red Team

sambascan

Allows you to search an entire network or a number of hosts for SMB shares. It will also list the contents of all public

scanner Red Team

samdump2

Dump Windows 2k/NT/XP password hashes

os-credential-dumping Red Team

samesame

Command line tool to generate crafty homograph strings.

fuzzer Red Team

samhain

File integrity / intrusion detection system

networking Red Team

samplicator

Send copies of (UDP) datagrams to multiple receivers, with optional sampling and spoofing.

networking Red Team

samydeluxe

Automatic samdump creation script.

cracker Red Team

sandcastle

A Python script for AWS S3 bucket enumeration.

scanner Red Team

sandfly-processdecloak

Find hidden processes on the local Linux system.

investigate-system-interactions Blue Team

sandmap

Simple CLI with the ability to run pure Nmap engine, 31 modules with 459 scan profiles.

scanner Red Team

sandsifter

The x86 processor fuzzer.

fuzzer Red Team

sandy

An open-source Samsung phone encryption assessment framework

scanner Red Team

sara

RouterOS Security Inspector

system-network-configuration-discovery Red Team

saruman

ELF anti-forensics exec, for injecting full dynamic executables into process image (With thread injection).

binary Red Team

sasm

A simple crossplatform IDE for NASM, MASM, GAS and FASM assembly languages.

misc Red Team

sasquatch-git

Tools for squashfs, a highly compressed read-only filesystem for Linux.

uncategorized Red Team

Satellite Tracking

Satellite orbit tracking entry point for monitoring spacecraft position, trajectory, and pass predictions.

transportation

SauceNAO

Reverse image source finder widely used to trace artwork, anime frames, and reposted media to origin sites.

images-videos-docs

savvycan

QT-based CAN bus analysis tool.

automobile Red Team

sawef

Send Attack Web Forms.

webapp Red Team

sb0x

A simple and Lightweight framework for Penetration testing.

scanner Red Team

sbd

Secure backdoor for Linux and Windows

non-application-layer-protocol Red Team

sc-make

Tool for automating shellcode creation.

exploitation Red Team

scalpel

Fast filesystem-independent file recovery

forensic-carving-tools Blue Team

scamper

A tool that actively probes the Internet in order to analyze topology and performance.

scanner Red Team

scanless

Utility for using websites that can perform port scans on your behalf.

scanner Red Team

Scanless (T)

Command-line tool for port scanning without leaving traces on target using third-party services.

ip-mac-address

scannerl

The modular distributed fingerprinting engine.

fingerprint Red Team

scannerl-git

The modular distributed fingerprinting engine

scanner Red Team

scanqli

SQLi scanner to detect SQL vulns.

webapp Red Team

Scans.io

Archive of internet-wide scan data including censys scans and other reconnaissance data.

ip-mac-address

scansploit

Exploit using barcodes, QRcodes, earn13, datamatrix.

exploitation Red Team

scansploit-git

An Exploit using barcodes, QRcodes, earn13, datamatrix

scanners Red Team

scanssh

Fast SSH server and open proxy scanner.

scanner Red Team

scap-security-guide

Security compliance content in SCAP, Bash, Ansible, and other formats.

automation Red Team

scap-workbench

SCAP Scanner And Tailoring Graphical User Interface.

automation Red Team

scapy

Packet generator/sniffer and network scanner/discovery (Python 3)

network-sniffing impact Red Team

scavenger

Crawler (Bot) searching for credential leaks on different paste sites.

recon Red Team

sccmhunter

Identifying, profiling, and attacking SCCM related assets in an Active Directory domain.

windows Red Team

sccmsecrets

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting and initial access and lateral movement.

ad

sccmwtf

This code is designed for exploring SCCM in a lab.

ad

scdbg

Analyze shellcode by emulating its execution.

shellcode Blue Team

schnappi-dhcp

Can fuck network with no DHCP.

misc Red Team

SciCheck

FactCheck.org section dedicated to scientific and health misinformation analysis.

disinformation-media-verification

SciTE

Edit text files.

view-or-edit-files Blue Team

sclauncher

A small program to load 32-bit shellcode and allow for execution or debugging. Can also output PE files from shellcode.

shellcode Blue Team

sclauncher64

A small program to load 64-bit shellcode and allow for execution or debugging. Can also output PE files from shellcode.

shellcode Blue Team

scout

Scout Suite is an open source multi-cloud security-auditing tool which enables security posture assessment of cloud environments.

general

scout2

Security auditing tool for AWS environments.

scanner Red Team

scoutsuite

Multi-Cloud Security Auditing Tool.

scanner Red Team

ScoutSuite (T)

Multi-cloud auditing tool that inventories cloud resources and highlights security risks in an interactive HTML report.

cloud-infrastructure

scrape-dns

Searches for interesting cached DNS entries.

scanner Red Team

scrape-dns-git

Searches for interesting cached DNS entries.

scanners Red Team

ScrapedIn (T)

Open-source LinkedIn scraping utility for extracting profile and contact-style data from search results.

social-networks

scratchabit

Easily retargetable and hackable interactive disassembler with IDAPython-compatible plugin API.

disassembler Blue Team

scrcpy

Display and control your Android device.

general

screamer

Fast Subnet Discovery.

recon Red Team

screen

Terminal multiplexer with VT100/ANSI terminal emulation

uncategorized Red Team

ScribbleMaps

Collaborative web map editor for annotations, overlays, and shared incident maps.

geolocation-tools-maps

scrounge-ntfs

Data recovery program for NTFS filesystems

forensic-carving-tools Blue Team

Scrummage (T)

Python/Flask OSINT aggregator centralizing search plugins for blockchain, domains, breaches, darkweb, threat intelligence, IP geolocation, and social…

tools

scrying

Collect RDP, web, and VNC screenshots smartly.

webapp Red Team

sctpscan

SCTP network scanner for discovery and security

network-service-discovery Red Team

scumware.org

Free malware and spyware tracking domain blacklist maintained by security community for 18+ years.

domain-name

scylla

Find Advanced Information on a Username, Website, Phone Number, etc.

recon Red Team

sdn-toolkit

Discover, Identify, and Manipulate SDN-Based Networks

networking Red Team

sdnpwn

An SDN penetration testing toolkit.

scanner Red Team

sdrangel

Qt6/OpenGL SDR and signal analyzer frontend.

radio Red Team

sdrangelove-git

A project that allows you to control all the process inside a GNSS receiver, from the raw bits at the output of an analog-to-digital converter to the

hardware Red Team

sdrpp

The bloat-free SDR receiver.

radio Red Team

sdrsharp

The most popular SDR program.

radio Red Team

sdrtrunk

A cross-platform java application for decoding, monitoring, recording and streaming trunked mobile and related radio pro

radio Red Team

sea

A tool to help to create exploits of binary programs.

malware Blue Team

Search Tempest

Nationwide Craigslist search tool that searches all Craigslist cities simultaneously with advanced filtering by distance, price range, and category.

classifieds

search1337

1337Day Online Exploit Scanner.

automation Red Team

Searchcode

Code search engine that indexes public source code from GitHub, GitLab, Bitbucket, and other repositories; useful for finding code examples and…

search-engines

searchsploit

A command line search tool for Exploit-DB

ad osint web Red Team

seat

Next generation information digging application geared toward the needs of security professionals. It uses information s

scanner Red Team

sec

A logfile monitoring tool with support for event correlation, written in perl

misc Red Team

seccomp-tools

Seccomp analysis toolkit.

reversing Blue Team

seclists

Collection of multiple types of security lists

persistence password-profiling-wordlists Red Team

SecLists DNS Subdomains (T)

Community-maintained DNS wordlist collection used to power subdomain brute-force workflows.

domain-name

seclists-git

A collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings,

uncategorized Red Team

second-order

Second-order subdomain takeover scanner.

webapp Red Team

secretfinder

A python script to find sensitive data (apikeys, accesstoken, jwt,..) in javascript files.

webapp Red Team

secscan

Web Apps Scanner and Much more utilities.

webapp Red Team

secure-delete

Secure file, disk, swap, memory erasure utilities.

anti-forensic Blue Team

secure-socket-funneling

SSF - windows binaries

uncategorized Red Team

secure2csv

Decode security descriptors in $Secure on NTFS.

forensic Blue Team

see-surf

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

webapp Red Team

see-surf-git

A Python based scanner to find potential SSRF parameters in a web application.

webapps Red Team

seeker

Accurately Locate People using Social Engineering.

social Red Team

seekr

A multi-purpose OSINT toolkit with a neat web-interface.

recon Red Team

sees

Increase the success rate of phishing attacks by sending emails to company users as if they are coming from the very sam

social Red Team

semgrep

Lightweight static analysis for many languages.

code-audit Red Team

SEMrush

SEO intelligence platform for domain analytics, keyword intelligence, backlinks, and competitor profiling.

domain-name

sendemail

Lightweight, command line SMTP email client

uncategorized Red Team

sensepost-xrdp

A rudimentary remote desktop tool for the X11 protocol exploiting unauthenticated x11 sessions.

exploitation Red Team

sentrypeer

SIP peer to peer honeypot for VoIP

uncategorized Red Team

sergio-proxy

A multi-threaded transparent HTTP proxy for manipulating web traffic.

proxy Red Team

serialbrute

Java serialization brute force attack tool.

exploitation Red Team

serializationdumper

A tool to dump Java serialization streams in a more human readable form.

webapp Red Team

server-status-pwn

A script that monitors and extracts requested URLs and clients connected to the service by exploiting publicly accessibl

recon Red Team

sessionlist

Sniffer that intents to sniff HTTP packets and attempts to reconstruct interesting authentication data from websites tha

networking Red Team

set

Social-Engineer Toolkit

initial-access Red Team

set-git

Social-engineer toolkit. Aimed at penetration testing around Social-Engineering

social-engineering Red Team

seth

Perform a MitM attack and extract clear text credentials from RDP connections.

networking Red Team

setowner

Allows you to set file ownership to any account, as long as you have the "Restore files and directories" user right.

windows Red Team

sets.py

Perform set operations on lines or bytes in text files.

deobfuscation Blue Team

sfextract

sfextract extracts contents (assemblies, configuration, etc.) from .NET single file bundles.

dotnet Blue Team

sfuzz

Black Box testing utilities

resource-development Red Team

sgn

Shikata ga nai encoder ported into go with several improvements.

binary Red Team

sh00t

A Testing Environment for Manual Security Testers.

misc Red Team

sha1collisiondetection

Library and command line tool to detect SHA collision in a file

crypto Red Team

shad0w

A modular C2 framework designed to successfully operate on mature environments.

windows Red Team

shadowcoerce

Utility for bypassing the Windows Defender antivirus by hiding a process within a legitimate process.

ad

shadowexplorer

Browse the Shadow Copies created by the Windows Vista / 7 / 8 / 10 Volume Shadow Copy Service.

forensic Blue Team

shadowfinder

Find possible locations of shadows around the world.

misc Red Team

Shadowserver Foundation

Nonprofit providing comprehensive IP reputation intelligence and automated abuse reporting through daily network scanning.

domain-name

shard

A command line tool to detect shared passwords.

recon Red Team

Share Secret Feedback (M)

Anonymous feedback and messaging platform where users collect candid messages from friends and coworkers. Supports 30+ languages and integrates with…

social-networks

shareenum

Tool to enumerate shares from Windows hosts.

scanner Red Team

sharesniffer

Network share sniffer and auto-mounter for crawling remote file systems.

scanner Red Team

ShareX (T)

Free and open-source screenshot and screen recording tool for Windows supporting 80+ upload destinations and extensive automation workflows.

documentation-evidence-capture

sharker

A fast and reliable network capture analyzer

ad

sharpfuzz

AFL-based fuzz testing for .NET.

fuzzer Red Team

sharphound

C# Data Collector for BloodHound

active-directory Red Team

sharpshooter

Payload Generation Framework

uncategorized Red Team

shcode2exe

Convert 32 and 64-bit shellcode to a Windows executable file.

shellcode Blue Team

shed

Simple hex editor with a pico-style interface

uncategorized Red Team

shell-gpt

Command-line productivity tool powered by AI large language models

uncategorized Red Team

shellcode-compiler

Compiles C/C++ style code into a small, position-independent and NULL-free shellcode for Windows & Linux.

exploitation Red Team

shellcode-factory

Tool to create and test shellcodes from custom assembly sources.

exploitation Red Team

shellcode_launcher

Shellcode launcher utility

shellcode Blue Team

shellcode2exe.bat

Convert 32 and 64-bit shellcode to a Windows executable file.

shellcode Blue Team

shellcodecs

A collection of shellcode, loaders, sources, and generators provided with documentation designed to ease the exploitatio

exploitation Red Team

shellen

Interactive shellcoding environment to easily craft shellcodes.

exploitation Red Team

shellerator

Simple command-line tool aimed to help pentesters quickly generate one-liner reverse/bind shells in multiple languages.

automation Red Team

shellfire

Exploiting LFI, RFI, and command injection vulnerabilities

uncategorized Red Team

shellinabox

Implements a web server that can export arbitrary command line tools to a web based terminal emulator.

backdoor Red Team

shelling

An offensive approach to the anatomy of improperly written OS command injection sanitisers.

misc Red Team

shellme

Because sometimes you just need shellcode and opcodes quickly. This essentially just wraps some nasm/objdump calls into

exploitation Red Team

shellnoob

Shellcode writing toolkit

resource-development Red Team

shellpop

Generate easy and sophisticated reverse or bind shell commands.

automation Red Team

shellsploit-framework

New Generation Exploit Development Kit.

exploitation Red Team

shellter

Dynamic shellcode injection tool and dynamic PE infector

defense-evasion Red Team

shellz

A script for generating common revshells fast and easy.

automation Red Team

sherlock

Find usernames across social networks

identity-information Red Team

Sherlock (T)

Python CLI tool that hunts down social media accounts by username across 400+ social networks. Supports Tor routing, proxy configuration, and…

username

sherlocked

Universal script packer-- transforms any type of script into a protected ELF executable, encrypted with anti-debugging.

packer Red Team

shhgit

Find committed secrets and sensitive files across GitHub, Gists, GitLab and BitBucket or your local repositories in real

recon Red Team

Ship AIS

UK-centered AIS ship tracker with live map views, movement details, and vessel identification data.

transportation

shitflood

A Socks5 clone flooder for the Internet Relay Chat (IRC) protocol.

dos Red Team

shocker

A tool to find and exploit servers vulnerable to Shellshock.

exploitation Red Team

Shodan

Search engine for internet-exposed devices, services, and security-relevant banners.

domain-name ip-mac-address

Shodan.io

World's first search engine for Internet-connected devices

information-gathering Red Team

shodanhat

Search for hosts info with shodan.

recon Red Team

shootback

A reverse TCP tunnel let you access target behind NAT or firewall.

backdoor Red Team

shortfuzzy

A web fuzzing script written in perl.

webapp Red Team

shortscan

An IIS short filename enumeration tool.

scanner Red Team

shosubgo

Small tool to Grab subdomains using Shodan API.

recon Red Team

shreder

A powerful multi-threaded SSH protocol password bruteforce tool.

cracker Red Team

shuffledns

A wrapper around massdns written in GO.

webapp Red Team

shuji

Reverse engineering JavaScript and CSS sources from sourcemaps.

decompiler Blue Team

sickle

A shellcode development tool, created to speed up the various steps needed to create functioning shellcode.

exploitation Red Team

sickle-pdk

Payload development kit

resource-development Red Team

sidguesser

Guesses sids against an Oracle database

databases Red Team

siege

HTTP regression testing and benchmarking utility

impact Red Team

sigma

Generic Signature Format for SIEM Systems

defensive Blue Team

sigma-cli

Sigma command line interface

uncategorized Red Team

sign

Automatically signs an apk with the Android test certificate.

mobile Red Team

Signal Private Messenger (T)

End-to-end encrypted messaging app with 40M+ users. Limited OSINT value due to privacy-first design.

mobile-osint Red Team

signsrch

Find patterns of common encryption, compression, or encoding algorithms.

general Blue Team

sigploit

Telecom Signaling Exploitation Framework - SS7, GTP, Diameter & SIP.

exploitation Red Team

sigspotter

A tool that search in your HD to find which publishers has been signed binaries in your PC.

windows Red Team

sigthief

Stealing Signatures and Making One Invalid Signature at a Time.

exploitation Red Team

silenteye

A cross-platform application design for an easy use of steganography.

stego Red Team

silenttrinity

Asynchronous, collaborative post-exploitation agent

uncategorized Red Team

silk

A collection of traffic analysis tools developed by the CERT NetSA to facilitate security analysis of large networks.

networking Red Team

SimilarWeb

Digital intelligence platform for traffic estimates, referrals, and audience insights.

domain-name

simple-ducky

A payload generator.

automation Red Team

simple-ducky-git

A payload generator

autonomous Red Team

simple-lan-scan

A simple python script that leverages scapy for discovering live hosts on a network.

scanner Red Team

simple-lan-scan3

A simple python3 script that leverages scapy for discovering live hosts on a network.

scanner Red Team

simpleemailspoofer

A simple Python CLI to spoof emails.

social Red Team

simplify

Generic Android Deobfuscator.

mobile Red Team

simplyemail

Email recon made fast and easy, with a framework to build on CyberSyndicates.

recon Red Team

simtrace2

Host utilities to communicate with SIMtrace2 USB Devices.

radio Red Team

sinfp

A full operating system stack fingerprinting suite.

fingerprint Red Team

siparmyknife

SIP fuzzing tool

voip Red Team

sipbrute

A utility to perform dictionary attacks against the VoIP SIP Register hash.

voip Red Team

sipcrack

SIP login dumper/cracker

password-cracking Red Team

sipffer

SIP protocol command line sniffer.

sniffer Red Team

sipi

Simple IP Information Tools for Reputation Data Analysis.

recon Red Team

sipp

Traffic generator for the SIP protocol

voip Red Team

sippts

Set of tools to audit SIP based VoIP Systems

voip Red Team

sipsak

SIP Swiss army knife

voip Red Team

sipscan

A sip scanner.

windows Red Team

sipshock

A scanner for SIP proxies vulnerable to Shellshock.

scanner Red Team

sipvicious

Tools to audit SIP based VoIP systems

voip-credential-access voip Red Team

sireprat

Remote Command Execution as SYSTEM on Windows IoT Core.

exploitation Red Team

sitadel

Web Application Security Scanner.

webapp Red Team

sitediff

Fingerprint a web app using local files as the fingerprint sources.

webapp Red Team

Sitediff (T)

Command-line utility for comparing website versions to detect content and structural changes.

domain-name

Siteliner

Website crawler that highlights duplicate content, broken links, and SEO quality issues.

domain-name

SiteSleuth

OSINT domain analytics tool tracking Google Analytics, AdSense, and Stripe keys across 32+ million websites.

domain-name

sj

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

webapp Red Team

sjet

Siberas JMX exploitation toolkit.

exploitation Red Team

skipfish

Fully automated, active web application security reconnaissance tool

web-vulnerability-scanning Red Team

skiptracer

OSINT python2 webscraping framework. Skipping the needs of API keys.

social Red Team

skul

A PoC to bruteforce the Cryptsetup implementation of Linux Unified Key Setup (LUKS).

cracker Red Team

skydive

An open source real-time network topology and protocols analyzer.

networking Red Team

SkyFi.com - Satellite Open Data (R)

Satellite imagery marketplace and open-data discovery interface for earth observation assets.

geolocation-tools-maps

skyjack

Takes over Parrot drones, deauthenticating their true owner and taking over control, turning them into zombie drones und

drone Red Team

Skymem

Email finder that discovers company and personal email addresses by domain or name, with bulk search, email list creation, and advanced filtering…

email-address

skype-dump

This is a tool that demonstrates dumping MD5 password hashes from the configuration file in Skype.

windows Red Team

skypefreak

A Cross Platform Forensic Framework for Skype.

forensic Blue Team

slack-intelbot (T)

Slack bot that enriches indicators such as domains, IPs, and hashes by querying external threat intelligence services.

instant-messaging

slack-web-scraper (T)

Automation script for collecting Slack channel history and metadata from accessible workspaces.

instant-messaging

slackpirate

Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace.

social Red Team

SlackPirate (T)

Security testing tool for Slack workspaces that enumerates channels and extracts accessible messages/files from authenticated sessions.

instant-messaging

Slang Dictionary & Translator

NoSlang provides internet slang definitions and reverse translation for common texting shorthand.

language-translation

Slangit - The Slang Dictionary

Online slang dictionary focused on modern internet and texting terminology with usage context.

language-translation

Slash

Automated OSINT tool for username enumeration across 187+ social media platforms, forums, and pastebin searches with phone/email extraction.

tools

Sleuth Kit

Analyze disk images and recover files from them.

general Blue Team

sleuthkit

Tools for forensics analysis on volume and filesystem data

sleuth-kit-suite Red Team

sleuthkit-java

Java dependencies for The Sleuth Kit.

uncategorized Red Team

sleuthql

Python3 Burp History parsing tool to discover potential SQL injection points. To be used in tandem with SQLmap.

misc Red Team

slimtoolkit

Optimization of your containers

uncategorized Red Team

slipit

Utility for creating archives with path traversal elements for ZipSlip attacks.

misc Red Team

slither

Solidity static analysis framework written in Python 3.

code-audit Red Team

sliver

Implant framework

uncategorized Red Team

sloth-fuzzer

A smart file fuzzer.

fuzzer Red Team

slowhttptest

Application layer Denial of Service attacks simulation tool

impact Red Team

slowloris

A tool which is written in perl to test http-server vulnerabilities for connection exhaustion denial of service (DoS) at

dos Red Team

slowloris-py

Low bandwidth DoS tool.

dos Red Team

slowloris6

IPv6 version - Slowloris HTTP DoS is a tool which is written in perl to test http-server vulnerabilites for connection exhaustion denial of service (D

uncategorized Red Team

slurp-scanner

Evaluate the security of S3 buckets.

scanner Red Team

Slydial

Voicemail drop service that connects directly to a recipient voicemail box without ringing the handset.

telephone-numbers

smali

A tool to disassemble and assemble Android's dex files

general

smali-cfgs

Smali Control Flow Graph's.

mobile Red Team

smalisca

Static Code Analysis for Smali files.

mobile Red Team

smap

Shellcode mapper - Handy tool for shellcode analysis.

exploitation Red Team

smap-scanner

Passive port scanner built with shodan free API.

scanner Red Team

smartbrute

The smart password spraying and bruteforcing tool for Active Directory Domain Services.

ad

smartphone-pentest-framework

Repository for the Smartphone Pentest Framework (SPF).

mobile Red Team

smbbf

SMB password bruteforcer.

cracker Red Team

smbclient

SMBclient is a command-line utility that allows you to access Windows shared resources

ad light

smbclient-ng

Interact with SMB shares.

networking Red Team

smbcrunch

3 tools that work together to simplify reconnaissance of Windows File Shares.

recon Red Team

smbexec

A rapid psexec style attack with samba tools.

scanner Red Team

smbmap

Handy SMB enumeration tool

pass-the-hash network-share-discovery Red Team

smbmap-git

A handy SMB enumeration tool

enumeration Red Team

smbrelay

SMB / HTTP to SMB replay attack toolkit.

windows Red Team

smbspider

A lightweight python utility for searching SMB/CIFS/Samba file shares.

scanner Red Team

smbsr

Lookup for interesting stuff in SMB shares.

scanner Red Team

smod

A modular framework with every kind of diagnostic and offensive feature you could need in order to pentest modbus protoc

scanner Red Team

smplshllctrlr

PHP Command Injection exploitation tool.

webapp Red Team

smtp-fuzz

Simple smtp fuzzer.

fuzzer Red Team

smtp-test

Automated testing of SMTP servers for penetration testing.

scanner Red Team

smtp-user-enum

Username guessing tool for the SMTP service

account-discovery smtp Red Team

smtp-vrfy

An SMTP Protocol Hacker.

scanner Red Team

smtpmap

Tool to identify the running smtp software on a given host.

fingerprint Red Team

smtpscan

An SMTP scanner

fingerprint Red Team

smtptester

Small python3 tool to check common vulnerabilities in SMTP servers.

exploitation Red Team

smtptx

A very simple tool used for sending simple email and do some basic email testing from a pentester perspective.

scanner Red Team

smuggler

An HTTP Request Smuggling / Desync testing tool written in Python 3.

webapp Red Team

smuggler-py

Python tool used to test for HTTP Desync/Request Smuggling attacks.

webapp Red Team

SmugMug Search

Photo hosting and portfolio platform with searchable public galleries and photographer profiles.

images-videos-docs

sn00p

A modular tool written in bourne shell and designed to chain and automate security tools and tests.

automation Red Team

sn0int

Semi-automatic OSINT framework and package manager

uncategorized Red Team

sn1per

Automated Pentest Recon Scanner.

automation Red Team

Sn1per (T)

Automated reconnaissance and penetration testing framework combining multiple scanning tools for full-scope target enumeration.

domain-name

snaffler-ng

SMB share credential and sensitive data scanner

uncategorized Red Team

snallygaster

Tool to scan for secret files on HTTP servers.

webapp Red Team

snapception

Intercept and decrypt all snapchats received over your network.

sniffer Red Team

Snapchat (T)

Ephemeral messaging app with 400M+ users. Limited historical data due to auto-deletion, but real-time activity visible.

mobile-osint Red Team

Snapper (T)

Open-source Linux-based tool for automated batch website screenshotting and file capture across multiple hosts.

documentation-evidence-capture

snare

Super Next generation Advanced Reactive honeypot.

honeypot Blue Team

snarf-git

man-in-the-middle / relay suite

mitm Red Team

snarf-mitm

SMB Man in the Middle Attack Engine / relay suite.

exploitation Red Team

sniff-probe-req

Wi-Fi Probe Requests Sniffer.

wireless Red Team

sniffer

Packet Trace Parser for TCP, SMTP Emails, and HTTP Cookies.

networking Red Team

sniffjoke

Transparent TCP connection scrambler

defense-evasion Red Team

sniffles

A Packet Capture Generator for IDS and Regular Expression Evaluation.

networking Red Team

snitch

Turn back the asterisks in password fields to plaintext passwords.

windows Red Team

snmp-brute

SNMP brute force, enumeration, CISCO config downloader and password cracking script.

cracker Red Team

snmp-fuzzer

SNMP fuzzer uses Protos test cases with an entirely new engine written in Perl.

fuzzer Red Team

snmpattack

SNMP scanner and attacking tool.

networking Red Team

snmpcheck

SNMP service enumeration tool

snmp Red Team

snmpenum

SNMP tabledump

uncategorized Red Team

snmpscan

A free, multi-processes SNMP scanner.

scanner Red Team

snoopbrute

Multithreaded DNS recursive host brute-force tool.

scanner Red Team

snoopy-ng

A distributed, sensor, data collection, interception, analysis, and visualization framework.

drone Red Team

Snopes

Long-running debunking site covering rumors, hoaxes, and viral misinformation claims.

disinformation-media-verification

snort

Flexible Network Intrusion Detection System

uncategorized Red Team

snow

Steganography program for concealing messages in text files.

crypto Red Team

snowdrop

Plain text watermarking and watermark recovery

uncategorized Red Team

snowman

A native code to C/C++ decompiler, see the examples of generated code.

windows Red Team

snscan

A Windows based SNMP detection utility that can quickly and accurately identify SNMP enabled devices on a network.

windows Red Team

snscrape

A social networking service scraper in Python.

recon Red Team

snuck

Automatic XSS filter bypass.

webapp Red Team

snyk

CLI and build-time tool to find and fix known vulnerabilities in open-source dependencies.

code-audit Red Team

soapui

The Swiss-Army Knife for SOAP Testing.

proxy Red Team

socat

Multipurpose relay for bidirectional data transfer

non-application-layer-protocol Red Team

social-analyzer

Analyzing & finding a person's profile across social media websites.

social Red Team

social-mapper

A social media enumeration and correlation tool.

social Red Team

Social Media Fingerprint

Browser-based tool that detects which social media platforms you are currently logged into by exploiting cross-origin image loading timing…

opsec

Social Searcher

Multi-platform social media search engine aggregating content from Twitter, Facebook, Instagram, Tumblr, and other networks. Supports real-time and…

social-networks

social-vuln-scanner

Gathers public information on companies to highlight social engineering risk.

social Red Team

socialfish

Ultimate phishing tool with Ngrok integrated.

social Red Team

socialpwned

OSINT tool that allows to get the emails, from a target, published in social networks.

social Red Team

socialscan

Check email address and username availability on online platforms.

recon Red Team

socketfuzz

Simple socket fuzzer.

fuzzer Red Team

sockstat

A tool to let you view information about open connections. It is similar to the tool of the same name that is included i

networking Red Team

Sogou WeChat Search

Chinese search portal indexing publicly accessible WeChat articles and official account content.

instant-messaging

sonar-scanner

Generic CLI tool to launch project analysis on SonarQube servers.

code-audit Red Team

soot

A Java Bytecode Analysis and Transformation Framework.

binary Red Team

sooty

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

defensive Blue Team

sortcanon.py

Sort text files using canonicalization functions built into this tool.

general-utilities Blue Team

Sorted by Birth Date

Refers to inmate search filters available in state and federal inmate databases. Searchable by date of birth field.

public-records

Sound Juicer

to rip audio CDs

desktop-edition

sourcemapper

Extract JavaScript source trees from Sourcemap files.

webapp Red Team

spade

A general-purpose Internet utility package, with some extra features to help in tracing the source of spam and other for

windows Red Team

spaf

Static Php Analysis and Fuzzer.

webapp Red Team

Spark.com

Long-running relationship-focused dating service with profile filtering and compatibility-oriented matching tools.

dating

sparrow-wifi

Graphical Wi-Fi Analyzer for Linux

wifi Red Team

sparta

Python GUI application which simplifies network infrastructure penetration testing by aiding the penetration tester in t

scanner Red Team

spartan

Frontpage and Sharepoint fingerprinting and attack tool.

fingerprint Red Team

sparty

An open source tool written in python to audit web applications using sharepoint and frontpage architecture.

webapp Red Team

Speakeasy

Emulate code execution, including shellcode, Windows drivers, and Windows PE files.

pe-files Blue Team

spectools

Spectrum-Tools is a set of utilities for using the Wi-Spy USB spectrum analyzer hardware.

wireless Red Team

speedpwn

An active WPA/2 Bruteforcer, original created to prove weak standard key generation in different ISP labeled routers wit

cracker Red Team

spektrum

rtl-sdr spectrum analyzer.

radio Red Team

spf

A python tool designed to allow for quick recon and deployment of simple social engineering phishing exercises.

social Red Team

spfmap

A program to map out SPF and DKIM records for a large number of domains.

recon Red Team

spiderfoot

OSINT collection and reconnaissance tool

host-information Red Team

SpiderFoot (T)

Automated OSINT collection tool with 200+ modules for reconnaissance and threat intelligence.

cloud-infrastructure

SpiderMonkey

Execute and deobfuscate JavaScript using Mozilla's standalone JavaScript engine.

scripts Blue Team

SpiderMonkey (Patched)

Execute and deobfuscate JavaScript using a patched version of Mozilla's standalone JavaScript engine.

scripts Blue Team

spiderpig-pdffuzzer

A javascript pdf fuzzer.

fuzzer Red Team

spiga

Configurable web resource scanner.

webapp Red Team

spike

Network protocol fuzzer

resource-development Red Team

spike-fuzzer

IMMUNITYsec's fuzzer creation kit in C.

fuzzer Red Team

spike-proxy

A Proxy for detecting vulnerabilities in web applications

webapp Red Team

spipscan

SPIP (CMS) scanner for penetration testing purpose written in Python.

webapp Red Team

spire

Toolchain of APIs for establishing trust between software systems

uncategorized Red Team

sploitctl

Fetch, install and search exploit archives from exploit sites like exploit-db and packetstorm.

automation Red Team

sploitego

Maltego Penetration Testing Transforms.

fuzzer Red Team

sploitscan

Search for CVE information

uncategorized Red Team

spoofcheck

Simple script that checks a domain for email protections.

recon Red Team

spooftooph

Automates spoofing or cloning Bluetooth devices

bluetooth Red Team

spoofy

Check if a list of domains can be spoofed based on SPF and DMARC records.

spoof Red Team

spookflare

Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures.

automation Red Team

spotbugs

A tool for static analysis to look for bugs in Java code.

code-audit Red Team

spray

Password Spraying tool for Active Directory Credentials

uncategorized Red Team

spray365

Makes spraying Microsoft accounts (Office 365 / Azure AD) easy through its customizable two-step password spraying appro

cracker Red Team

spraycharles

Low and slow password spraying tool, designed to spray on an interval over a long period of time.

cracker Red Team

sprayhound

Password spraying tool and Bloodhound integration

uncategorized Red Team

sprayingtoolkit

Scripts to make password spraying attacks against Lync/S4B, OWA & O365

uncategorized Red Team

spraykatz

Tool able to retrieve credentials on Windows machines

uncategorized Red Team

sps

A Linux packet crafting tool. Supports IPv4, IPv6 including extension headers, and tunneling IPv6 over IPv4.

networking Red Team

SpyDialer

Reverse phone lookup platform with caller intelligence and voicemail-related lookup features.

telephone-numbers

spyse

Python API wrapper and command-line client for the tools hosted on spyse.com.

recon Red Team

sqid

A SQL injection digger.

webapp Red Team

sqlbrute

Brute forces data out of databases using blind SQL injection.

fuzzer Red Team

sqldict

Dictionary attack tool for SQL Server

brute-force Red Team

SQLite

Manage and interact with SQL database files.

general-utilities Blue Team

sqlitebrowser

GUI editor for SQLite databases

databases Red Team

sqlivulscan

This will give you the SQLi Vulnerable Website Just by Adding the Dork.

scanner Red Team

sqlmap

Automatic SQL injection tool

initial-access Red Team

sqlmc

Check all urls of a domain for SQL injections

uncategorized Red Team

sqlninja

SQL server injection and takeover tool

initial-access Red Team

sqlpat

This tool should be used to audit the strength of Microsoft SQL Server passwords offline.

cracker Red Team

sqlping

SQL Server scanning tool that also checks for weak passwords using wordlists.

windows Red Team

sqlpowerinjector

Application created in .Net 1.1 that helps the penetration tester to find and exploit SQL injections on a web page.

windows Red Team

sqlsus

MySQL injection tool

initial-access Red Team

squashfuse-git

FUSE filesystem to mount squashfs archives

misc Red Team

sr

Perform subdomain enumeration, endpoint recognition, and more.

recon Red Team

ssdeep

Recursive piecewise hashing tool

forensics Blue Team

ssdp-scanner

SSDP amplification scanner written in Python. Makes use of Scapy.

scanner Red Team

ssh-audit

ssh-audit is a tool to test SSH server configuration for best practices.

ad

ssh-honeypot

Fake sshd that logs ip addresses, usernames, and passwords.

honeypot Blue Team

ssh-mitm

SSH man-in-the-middle tool.

exploitation Red Team

ssh-privkey-crack

A SSH private key cracker.

cracker Red Team

ssh-user-enum

SSH User Enumeration Script in Python Using The Timing Attack.

scanner Red Team

sshatter

Password bruteforcer for SSH.

cracker Red Team

sshfuzz

A SSH Fuzzing utility written in Perl that uses Net::SSH2.

fuzzer Red Team

sshpass

Supply a password to SSH non-interactively for automated logins.

general-utilities Blue Team

sshprank

A fast SSH mass-scanner, login cracker, banner grabber and password auth checker tool using the python-masscan and shoda

cracker Red Team

sshscan

A horizontal SSH scanner that scans large swaths of IPv4 space for a single SSH user and pass.

cracker Red Team

sshtrix

A very fast multithreaded SSH login cracker.

cracker Red Team

sshuttle

Transparent proxy server for VPN over SSH

protocol-tunneling Red Team

ssl-hostname-resolver

CN (Common Name) grabber on X.509 Certificates over HTTPS.

recon Red Team

sslcaudit

Utility to perform security audits of SSL/TLS clients.

scanner Red Team

ssldump

SSLv3/TLS network protocol analyzer

collection Red Team

ssldump-git

an SSLv3/TLS network protocol analyzer

sniffers Red Team

sslh

Applicative protocol multiplexer

protocol-tunneling Red Team

ssllabs-scan

Command-line client for the SSL Labs APIs

scanner Red Team

sslmap

A lightweight TLS/SSL cipher suite scanner.

scanner Red Team

sslnuke

Transparent proxy that decrypts SSL traffic and prints out IRC messages.

cracker Red Team

sslscan

Tests SSL/TLS enabled services to discover supported cipher suites

ssl-tls Red Team

sslscan2

Tests SSL/TLS enabled services to discover supported cipher suites.

scanner Red Team

sslsniff

SSL/TLS man-in-the-middle attack tool

collection Red Team

sslsplit

Transparent and scalable SSL/TLS interception

collection Red Team

sslstrip

SSL/TLS man-in-the-middle attack tool

uncategorized Red Team

sslyze

Fast and full-featured SSL scanner

ssl-tls Red Team

ssma

Simple Static Malware Analyzer.

malware Blue Team

ssma-git

Simple Static Malware Analyzer

analysis Red Team

ssrf-proxy

Facilitates tunneling HTTP communications through servers vulnerable to Server-Side Request Forgery.

proxy Red Team

ssrf-sheriff

A simple SSRF-testing sheriff written in Go.

webapp Red Team

ssrfmap

Automatic SSRF fuzzer and exploitation tool.

webapp Red Team

ssss

Split and Combine Secrets using Shamir's Secret Sharing Scheme

crypto Red Team

sstat-git

Check the status of a server while fuzzing or DDoSing

misc Red Team

sstimap

Automatic SSTI detection tool with interactive interface

web-vulnerability-scanning Red Team

SSView

Analyze OLE2 Structured Storage files.

microsoft-office Blue Team

stackflow

Universal stack-based buffer overfow exploitation tool.

exploitation Red Team

stacoan

Crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobil

mobile Red Team

stacs

Static Token And Credential Scanner.

scanner Red Team

staekka

This plugin extends Metasploit for some missing features and modules allowing interaction with other/custom exploits/way

exploitation Red Team

Stanford Large Network Dataset Collection

SNAP repository of graph/network datasets spanning social networks, web graphs, and communication systems.

archives

stardox

Github stargazers information gathering tool.

recon Red Team

starkiller

Frontend for Powershell Empire

uncategorized Red Team

starttls-mitm

A mitm proxy that will transparently proxy and dump both plaintext and TLS traffic.

proxy Red Team

StatsCrop

Website statistics portal with traffic rank snapshots and related metadata.

domain-name

statsprocessor

Word generator based on per-position Markov chains

uncategorized Red Team

SteamOSINT (T)

Python tool for OSINT on Steam user profiles. Collects public profile data including games owned, achievements, playtime, and trade history.

social-networks

Steampipe (T)

SQL interface over cloud APIs and services, enabling ad hoc querying of AWS, Azure, GCP, and many other data sources.

cloud-infrastructure

stegcracker

Steganography brute-force tool

uncategorized Red Team

stegdetect

An automated tool for detecting steganographic content in images.

stego Red Team

steghide

Steganography hiding tool

defense-evasion Red Team

stegolego

Simple program for using stegonography to hide data within BMP images.

stego Red Team

stegolsb

Steganography tool to hide data in BMP images using least significant bit algorithm

general

stegosip

TCP tunnel over RTP/SIP.

tunnel Red Team

stegosuite

Steganography tool to hide information in image files

defense-evasion Red Team

stegseek

Lightning fast steghide cracker.

stego Red Team

stegsnow

Steganography using ASCII files

defense-evasion Red Team

stegsolve

Steganography Solver.

stego Red Team

stenographer

A packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets o

sniffer Red Team

stepic

A python image steganography tool.

stego Red Team

stews

A Security Tool for Enumerating WebSockets.

webapp Red Team

sticky-keys-hunter

Script to test an RDP host for sticky keys and utilman backdoor.

scanner Red Team

stickykeyshunter-git

Script to test an RDP host for sticky keys and utilman backdoor

scanners Red Team

stig-viewer

XCCDF formatted SRGs and STIGs files viewer for SCAP validation tools.

scanner Red Team

stompy

An advanced utility to test the quality of WWW session identifiers and other tokens that are meant to be unpredictable.

misc Red Team

Stop Fake Tools

Ukrainian anti-disinformation initiative publishing fact-checks, analysis, and media literacy resources.

disinformation-media-verification

stoq

An open source framework for enterprise level automated analysis.

code-audit Red Team

storm-ring

This simple tool is useful to test a PABX with "allow guest" parameter set to "yes" (in this scenario an anonymous calle

voip Red Team

Stormspotter (T)

Graph-based Azure reconnaissance platform that maps cloud attack paths and trust relationships using Neo4j-backed visualization.

cloud-infrastructure

stowaway

A Multi-hop proxy tool for security researchers and pentesters.

proxy Red Team

STPyV8

Python3 and JavaScript interop engine, fork of the original PyV8 project.

scripts Blue Team

strace

Trace process' system calls and signals.

elf-files Blue Team

strdeob.pl

Locate and decode stack strings in executable files.

deobfuscation Blue Team

streamfinder

Searches for Alternate Data Streams (ADS).

windows Red Team

Strelka

Strelka is a real-time file scanning system used for threat hunting, threat detection, and incident response.

network-security-monitoring Blue Team

striker

An offensive information and vulnerability scanner.

webapp Red Team

strings.py

Extract ASCII and Unicode strings from binary files with length sorting and filtering.

general Blue Team

stringsifter

Machine learning tool that automatically ranks strings based on their relevance for malware analysis.

binary Red Team

striptls

Proxy PoC implementation of STARTTLS stripping attacks.

proxy Red Team

strutscan

Apache Struts2 vulnerability scanner written in Perl.

scanner Red Team

stunnel

Universal SSL tunnel for network daemons

protocol-tunneling Red Team

stunner

Test and exploit STUN, TURN and TURN over TCP servers.

networking Red Team

sub7

A remote administration tool. No further comments ;-)

windows Red Team

subbrute

A DNS meta-query spider that enumerates DNS records, and subdomains.

scanner Red Team

subdomainer

A tool designed for obtaining subdomain names from public sources.

recon Red Team

subfinder

Subdomain discovery tool

web-scanning Red Team

Subfinder (T)

Fast passive subdomain discovery utility that aggregates results from many curated OSINT and API-backed sources.

cloud-infrastructure

subjack

Subdomain Takeover tool

web-vulnerability-scanning Red Team

subjs

Fetches javascript file from a list of URLS or subdomains.

webapp Red Team

sublert

A security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains depl

recon Red Team

sublist3r

Fast subdomains enumeration tool for penetration testers

web-scanning Red Team

sublist3r-git

A Fast subdomains enumeration tool for penetration testers

dns Red Team

Sublist3r (T)

Passive subdomain enumeration tool that aggregates subdomains from public search engines and certificate-related sources.

cloud-infrastructure

subover

A Powerful Subdomain Takeover Tool.

scanner Red Team

subreddits

Subreddit discovery index for identifying communities by topic and interest area.

social-networks

subscraper

Tool that performs subdomain enumeration through various techniques.

recon Red Team

subterfuge

Automated Man-in-the-Middle Attack Framework.

exploitation Red Team

subversion

Advanced version control system

uncategorized Red Team

subzy

Subdomain takeover vulnerability checker.

scanner Red Team

sucrack

Multithreaded su bruteforcer

password-cracking Red Team

Sucuri SiteCheck

Free remote website scanner that checks for malware, security threats, blacklisting, and vulnerabilities. Detects outdated CMS versions, insecure…

domain-name

sudo

Provide limited super user privileges to specific users

uncategorized Red Team

suid3num

Python script which utilizes python's built-in modules to enumerate SUID binaries.

exploitation Red Team

sulley

A pure-python fully automated and unattended fuzzing framework.

fuzzer Red Team

SunCalc

Solar position calculator for estimating time and orientation from shadows in imagery.

geolocation-tools-maps

superscan

Powerful TCP port scanner, pinger, resolver.

windows Red Team

Surfface Face & People Search Engine

AI-based face and people search platform focused on open-source identity discovery and correlation.

images-videos-docs

suricata

An Open Source Next Generation Intrusion Detection and Prevention Engine.

defensive Blue Team

suricata-verify

Suricata Verification Tests - Testing Suricata Output.

misc Red Team

svn-extractor

A simple script to extract all web resources by means of .SVN folder exposed over network.

recon Red Team

swaks

SMTP command-line test tool

smtp Red Team

swamp

An OSINT tool for discovering associated sites through Google Analytics Tracking IDs.

recon Red Team

swap-digger

A tool used to automate Linux swap analysis during post-exploitation or forensics.

forensic Blue Team

swarm

A distributed penetration testing tool.

scanner Red Team

swfintruder

First tool for testing security in Flash movies. A runtime analyzer for SWF external movies. It helps to find flaws in F

reversing Blue Team

Swisscows

Swiss privacy-focused search engine using semantic AI. Stores all data in Swiss Alps facility. No cookies, no tracking, no user profiles. Includes…

search-engines

SWITCH Internet Domains Whois (.ch)

Official Swiss domain registry WHOIS lookup service operated by SWITCH for .ch and .li country-code domains. Public registry with all owner contact…

domain-name

syborg

Recursive DNS Subdomain Enumerator with dead-end avoidance system.

recon Red Team

syft

CLI tool for generating a SBOM from container images and filesystems

uncategorized Red Team

sylkie

IPv6 address spoofing with the Neighbor Discovery Protocol.

spoof Red Team

Sylva Identity Discovery (T)

Open-source CLI tool for username and identity discovery with branch discovery to expand searches as additional linked identities are uncovered.

email-address username

symfony-exploits

Collection of Symfony exploits and PoCs.

ad web

syms2elf

A plugin for Hex-Ray's IDA Pro and radare2 to export the symbols recognized to the ELF symbol table.

reversing Blue Team

synflood

A very simply script to illustrate DoS SYN Flooding attack.

dos Red Team

synner

A custom eth->ip->tcp packet generator (spoofer) for testing firewalls and dos attacks.

spoof Red Team

synscan

fast asynchronous half-open TCP portscanner

scanner Red Team

syringe

A General Purpose DLL & Code Injection Utility.

backdoor Red Team

sysinternals

Sysinternals suite.

utilities Blue Team

sysinternals-suite

Sysinternals tools suite.

windows Red Team

SysLog

A tool to grab Android system and kernel logs

development forensics Blue Team

systeminformer

A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware.

utilities Blue Team

T-Pot-Attack-Map

a beautifully animated attack map for T-Pot.

network-monitoring Blue Team

t50

Multi-protocol packet injector tool

impact Red Team

tabi

BGP Hijack Detection.

defensive Blue Team

tachyon-scanner

Fast Multi-Threaded Web Discovery Tool.

scanner Red Team

tactical-exploitation

Modern tactical exploitation toolkit.

scanner Red Team

TAGSExplorer

Browser-based visualization layer for TAGS archives that maps mentions, replies, and retweet relationships from collected Twitter datasets.

social-networks

Tails Live OS (T)

Portable Debian-based operating system designed for anonymous communication and privacy protection, running entirely from USB with no traces left…

tools

tailscale

Secure connectivity platform

services-and-other-tools Red Team

taipan

Web application security scanner.

scanner Red Team

takeover

Sub-Domain TakeOver Vulnerability Scanner.

scanner Red Team

Talkwalker Social Media Search (R)

Enterprise social media monitoring and search platform. Tracks mentions across social networks, forums, and news sources with sentiment analysis.

social-networks

talon

A password guessing tool that targets the Kerberos and LDAP services within the Windows Active Directory environment.

cracker Red Team

tanner

tanner honeypot, bundled with T-Pot's multi-honeypot platform.

honeypot Blue Team

Tantan (R)

Swipe-based Asian-focused dating app with geolocation and algorithmic profile recommendations.

dating

taof

A GUI cross-platform Python generic network protocol fuzzer.

fuzzer Red Team

targetedkerberoast

Kerberoast with ACL abuse capabilities.

windows Red Team

tbear

Transient Bluetooth Environment Auditor includes an ncurses-based Bluetooth scanner (a bit similar to kismet), a Bluetoo

bluetooth Red Team

tcgetkey

A set of tools that deal with acquiring physical memory dumps via FireWire and then scan the memory dump to locate TrueC

dos Red Team

tchunt-ng

Reveal encrypted files stored on a filesystem.

forensic Blue Team

TCP/IP Utils - Domain Neighbors

Find all domains on the same IP and subdomain information via reverse IP lookups.

ip-mac-address

tcpcontrol-fuzzer

2^6 TCP control bit fuzzer (no ECN or CWR).

fuzzer Red Team

tcpcopy

A TCP stream replay tool to support real testing of Internet server applications.

networking Red Team

tcpdstat

Get protocol statistics from tcpdump pcap files.

networking Red Team

tcpdump

Command-line network traffic analyzer

network-sniffing discovery Red Team

tcpextract

Extracts files from captured TCP sessions. Support live streams and pcap files.

networking Red Team

tcpflow

TCP flow recorder

network-sniffing Red Team

tcpick

TCP stream sniffer and connection tracker

uncategorized Red Team

tcpjunk

A general tcp protocols testing and hacking utility.

exploitation Red Team

tcpreplay

Tool to replay saved tcpdump files at arbitrary speeds

network-security-appliances Red Team

tcptrace

A TCP dump file analysis tool.

networking Red Team

tcptraceroute

A traceroute implementation using TCP packets.

networking Red Team

tcpwatch

A utility written in Python that lets you monitor forwarded TCP connections or HTTP proxy connections.

networking Red Team

tcpxtract

A tool for extracting files from network traffic.

misc Red Team

tdo_dump

Proof-of-Concept tool to dump trusted domain objects and extract trust credentials for lateral movement across domain boundaries

ad

Team Cymru IP to ASN

IP to ASN mapping tool providing autonomous system ownership and prefix information.

ip-mac-address

TeamsPhisher

TeamsPhisher is a Python3 program that facilitates the delivery of phishing messages and attachments to Microsoft Teams users whose organizations…

ad

teamsploit

Tools for group based penetration testing

uncategorized Red Team

teamsuserenum

User enumeration with Microsoft Teams API

recon Red Team

teardown

Command line tool to send a BYE request to tear down a call.

voip Red Team

tekdefense-automater

IP URL and MD5 OSINT Analysis

forensic Blue Team

Telegago (T)

Telegram-focused search interface built on Google CSE to discover public channels, groups, and related pages.

instant-messaging

Telegram-OSINT (T)

Curated Telegram OSINT repository linking tools, techniques, and investigative references.

instant-messaging

Telegram (T)

Messaging platform with 700M+ users. Extensive public data through public channels, groups, and user searches.

mobile-osint Red Team

tell-me-your-secrets

Find secrets on any machine from over 120 Different Signatures.

code-audit Red Team

tempomail

Tool to create a temporary email address in 1 Second and receive emails.

misc Red Team

termineter

Smart meter testing framework

non-application-layer-protocol Red Team

Termux

Terminal emulator application for Android OS extendible by variety of packages.

development system

Termux:API

Add-on app which exposes device functionality as API to command line programs.

development system

terraform

Tool for building, changing, and versioning infrastructure

uncategorized Red Team

Tesseract OCR

Examine images to identify and extract text using optical character recognition (OCR).

general Blue Team

testdisk

Partition scanner and disk recovery tool, and PhotoRec file recovery tool

forensic-carving-tools Blue Team

testssl

a tool for testing SSL/TLS encryption on servers

ad light web

testssl.sh

Command line tool to check TLS/SSL ciphers, protocols and cryptographic flaws

uncategorized Red Team

tetragon

EBPF-based Security Observability and Runtime Enforcement (tetra CLI)

uncategorized Red Team

texteditor.py

Edit text files from the command line using search-and-replace commands.

general-utilities Blue Team

tfsec

Security scanner for your Terraform code.

defensive Blue Team

tftp-bruteforce

A fast TFTP filename bruteforcer written in perl.

cracker Red Team

tftp-fuzz

Master TFTP fuzzing script as part of the ftools series of fuzzers.

fuzzer Red Team

tftp-hpa

HPA’s tftp client

uncategorized Red Team

tftp-proxy

This tool accepts connection on tftp and reloads requested content from an upstream tftp server.

proxy Red Team

tftpd32

Open source ipv6-ready TFTP server for Windows

uncategorized Red Team

tgcd

TCP/IP Gender Changer Daemon utility.

networking Red Team

TGStat

Telegram analytics platform indexing public channels and chats with growth, engagement, and content metrics.

instant-messaging

Thats Them

Free people search engine aggregating data from 50+ sources. Supports lookups by name, address, phone number, or email.

username

thc-ipv6

The Hacker Choice’s IPv6 Attack Toolkit

remote-system-discovery Red Team

thc-keyfinder

Finds crypto keys, encrypted data and compressed data in files by analyzing the entropy of parts of the file.

cracker Red Team

thc-pptp-bruter

THC PPTP Brute Force

brute-force Red Team

thc-smartbrute

This tool finds undocumented and secret commands implemented in a smartcard.

cracker Red Team

thc-ssl-dos

Stress tester for the SSL handshake

impact Red Team

thcrut

Network discovery and OS Fingerprinting tool.

fingerprint Red Team

thcsmartbrute

A tool that finds undocumented and secret commands implemented in a smartcard.

crackers Red Team

The Bump

Baby registry finder from The Bump parenting platform. Search for baby registries by name to find gift lists.

people-search-engines

The Inmate Locator

Federal Bureau of Prisons official inmate search tool. Covers federal inmates incarcerated from 1982 to present with daily updates.

public-records

The World Bank Open Data Catalog

World Bank open development data portal with datasets on economics, demographics, and global development indicators.

public-records

thedorkbox

Comprehensive collection of Google Dorks & OSINT techniques to find Confidential Data.

recon Red Team

thefatrat

TheFatRat a massive exploiting tool: easy tool to generate backdoor and easy tool to post exploitation attack.

automation Red Team

thefuzz

CLI fuzzing tool.

fuzzer Red Team

theharvester

Tool for gathering e-mail accounts and subdomain names from public sources

network-information Red Team

theharvester-git

Python tool for gathering e-mail accounts and subdomain names from different public sources (search engines, pgp key servers)

recon Red Team

theHarvester (T)

Command-line tool for gathering emails, subdomains, IPs, and URLs from public sources.

cloud-infrastructure domain-name email-address

themole

Automatic SQL injection exploitation tool.

webapp Red Team

thezoo

A project created to make the possibility of malware analysis open and available to the public.

malware Blue Team

This Person Does Not Exist

Generates photorealistic AI-synthesized human faces using StyleGAN2; each page load produces a unique, non-existent person’s portrait.

opsec

thr

THR (The Hacker Recipes) is aimed at providing technical guides on various hacking topics.

ad osint web Red Team

Threads Dashboard

Analytics and insights platform for Threads accounts using the official API. Tracks audience demographics, engagement metrics, and historical posting…

social-networks

Threads-Scraper (T)

Python browser automation tool that scrapes public Threads posts and profiles without authentication, outputting structured data in JSON, CSV, or…

social-networks

ThreadsRecon (T)

Python OSINT tool for Threads profile analysis including sentiment analysis, network visualization, and automated PDF reporting.

social-networks

threat-dragon

Electron Threat Modelling and diagramming tool.

threat-model Red Team

threatspec

Project to integrate threat modelling into development process.

defensive Blue Team

thug

Examine suspicious website using this low-interaction honeyclient.

connecting Blue Team

thumbcacheviewer

Extract Windows thumbcache database files.

forensic Blue Team

tidos-framework

Offensive Web Application Penetration Testing Framework.

webapp Red Team

tig

Tig is an ncurses-based text-mode interface for git.

ad osint web Red Team

tiger

Security auditing and intrusion detection tools for Linux

uncategorized Red Team

tightvnc

Virtual network computing password tool

uncategorized Red Team

TikTok (M)

Manual TikTok profile URL pattern for direct lookup of public account pages.

social-networks

TikTok-OSINT (T)

Python tool for extracting TikTok profile metadata and video-linked OSINT artifacts.

social-networks

tilt

An easy and simple tool implemented in Python for ip reconnaissance, with reverse ip lookup.

recon Red Team

tilt-git

Terminal Ip Lookup Tool

uncategorized Red Team

time-decode

Decode and encode date and timestamps.

gather-and-analyze-data Red Team

timegen

This program generates a *.wav file to "send" an own time signal to DCF77 compatible devices.

wireless Red Team

Timeline JS3

Open-source JavaScript timeline tool by Knight Lab that creates interactive multimedia timelines from Google Sheets or JSON data.

documentation-evidence-capture

timeverter

Bruteforce time-based tokens and to convert several time domains.

cracker Red Team

timing

Tool to generate a timing profile for a given command.

ad web

Tinder (R)

Swipe-based dating platform emphasizing quick location-aware matching and in-app messaging.

dating

Tinder Usernames (M)

Accesses a Tinder user's public web profile via their username. The gotinder.com domain redirects to tinder.com.

username

TinEye Reverse Image Search

Reverse image search engine that finds where an image appears online and identifies modified versions.

disinformation-media-verification

tinfoleak

Get detailed information about a Twitter user activity.

recon Red Team

Tinfoleak.py (T)

Python command-line tool for collecting Twitter/X account intelligence and metadata from target profiles.

social-networks

Tinfoleak Web

Web-based platform for Twitter/X intelligence analysis, user profiling, and geolocation-oriented review of public activity.

social-networks

tinfoleak2

The most complete open-source tool for Twitter intelligence analysis.

recon Red Team

tinja

CLI tool for testing web pages for template injection

web-vulnerability-scanning Red Team

titus

High-performance secrets scanner based on NoseyParker.

scanner Red Team

tls-attacker

A Java-based framework for analyzing TLS libraries.

crypto Red Team

tls-fingerprinting

Tool and scripts to perform TLS Fingerprinting.

fingerprint Red Team

tls-map

CLI & library for TLS cipher suites manipulation.

crypto Red Team

tls-prober

A tool to fingerprint SSL/TLS servers.

fingerprint Red Team

tlsenum

A command line tool to enumerate TLS cipher-suites supported by a server.

crypto Red Team

tlsfuzzer

SSL and TLS protocol test suite and fuzzer.

crypto Red Team

tlshelpers

A collection of shell scripts that help handling X.509 certificate and TLS issues.

crypto Red Team

tlspretense

SSL/TLS client testing framework.

crypto Red Team

tlssled

Evaluates the security of a target SSL/TLS (HTTPS) server

ssl-tls Red Team

tlsx

TLS grabber focused on TLS based data collection.

scanner Red Team

tmux

Terminal multiplexer

uncategorized Red Team

tnftp

Enhanced ftp client

uncategorized Red Team

tnscmd

A lame tool to prod the oracle tnslsnr process (1521/tcp).

misc Red Team

tnscmd10g

Tool to prod the oracle tnslsnr process

databases Red Team

token-exploiter

Token Exploiter is a tool designed to analyze GitHub Personal Access Tokens.

ad web

token-hunter

OSINT Tool - Search the group and group members' snippets, issues, and issue discussions for sensitive data that may be

social Red Team

token-reverser

Word list generator to crack security tokens.

misc Red Team

tomb

A system for easy encryption and backup of personal files

uncategorized Red Team

tomcatwardeployer

Apache Tomcat auto WAR deployment & pwning penetration testing tool.

exploitation Red Team

tookie-osint

OSINT information gathering tool for finding social media accounts

identity-information Red Team

top-100

top-100

uncategorized Red Team

topera

An IPv6 security analysis toolkit, with the particularity that their attacks can't be detected by Snort.

scanner Red Team

tor

Obfuscate your origins by routing traffic through a network of anonymizing nodes.

connecting Blue Team

tor-autocircuit

Tor Autocircuit was developed to give users a finer control over Tor circuit creation. The tool exposes the functionalit

defensive Blue Team

tor-browser

Tor Browser Bundle: anonymous browsing using Firefox and Tor.

defensive Blue Team

Tor Download (T)

Official Tor Project distribution page for Tor Browser and related anonymity tooling.

dark-web opsec

tor-router

A tool that allow you to make TOR your default gateway and send all internet connections under TOR (as transparent proxy

defensive Blue Team

TorBot

Python-based crawler for discovering and indexing .onion links and related metadata.

dark-web

torcrawl

Crawl and extract (regular or onion) webpages through TOR network.

webapp Red Team

torctl

Script to redirect all traffic through tor network including dns queries for anonymizing entire system.

automation Red Team

torpy

Pure python Tor client implementation.

networking Red Team

torshammer

A slow POST Denial of Service testing tool written in Python.

dos Red Team

Tosint (T)

Telegram OSINT script for profiling bots, extracting public metadata, and correlating related infrastructure clues.

instant-messaging

TotalCraigSearch

Search tool that enables cross-city and nationwide searches across Craigslist, bypassing the site's single-city search limitation.

classifieds

#totalhash

Malware Hash Registry that searches against 30+ antivirus databases to validate malware hashes with detection percentage results. Updated daily.

malicious-file-analysis

toutatis

Toutatis is a tool that allows you to extract information from instagrams accounts such as e-mails / phone numbers and more.

osint web Red Team

tpcat

Tool based upon pcapdiff by the EFF.

misc Red Team

tplmap

Automatic Server-Side Template Injection Detection and Exploitation Tool.

webapp Red Team

traceroute

Traces the route taken by packets over an IPv4/IPv6 network

uncategorized Red Team

Track-Trace

Multi-carrier shipment tracking aggregator for parcel and freight status across global postal and logistics providers.

transportation

translate.py

Translate bytes according to a Python expression.

deobfuscation Blue Team

trape

People tracker on the Internet: OSINT analysis and research tool by Jose Pino.

social Red Team

Travel by Drone

Drone-route and aerial exploration resource useful for planning vantage-aware terrain review.

geolocation-tools-maps

traxss

Automated XSS Vulnerability Scanner.

scanner Red Team

treasure

Hunt for sensitive information through githubs code search.

recon Red Team

tree

Displays an indented directory tree, in color

uncategorized Red Team

Treeverse (T)

Thread visualization tool for exploring conversation trees on supported social platforms.

social-networks

Trend Micro Site Safety Center

Free service that checks website safety ratings from Trend Micro's research and reputation sources. Identifies websites with malware, phishing…

domain-name

trevorproxy

A SOCKS proxy written in Python that randomizes your source IP address.

proxy Red Team

trevorspray

A modular password sprayer with threading, clever proxying, loot modules, and more!

cracker Red Team

triad-decompiler

Capstone based x86 decompiler for ELF binaries

decompile Blue Team

trid

An utility designed to identify file types from their binary signatures.

forensic Blue Team

trid-defs

Definitions DB for trid that describes recurring patterns in supported file types

uncategorized Red Team

TriliumNext

Personal knowledge management system (successor to Trilium).

ad osint web Red Team

trinity

A Linux System call fuzzer.

fuzzer Red Team

triton

A Dynamic Binary Analysis (DBA) framework.

binary Red Team

trivy

Comprehensive and versatile security scanner

uncategorized Red Team

trixd00r

An advanced and invisible userland backdoor based on TCP/IP for UNIX systems.

backdoor Red Team

True Caller

Caller identification platform and mobile app for reverse lookup and spam-call context.

telephone-numbers

Truecaller (T)

Phone and contact verification app with 500M+ users. Reverse phone lookup and caller ID identification.

mobile-osint Red Team

truecrack

Bruteforce password cracker for TrueCrypt volumes

password-cracking Red Team

truecrack-git

Password cracking for truecrypt(c) volumes.

uncategorized Red Team

truegaze

Static analysis tool for Android/iOS apps focusing on security issues outside the source code.

mobile Red Team

truehunter

Detect TrueCrypt containers using a fast and memory efficient approach.

forensic Blue Team

TrueMedia

AI deepfake detection platform focused on political content that analyzes videos and images for synthetic media manipulation indicators.

ai-tools

trufflehog

Searches through git repositories for secrets

unsecured-credentials Red Team

trusttrees

A Tool for DNS Delegation Trust Graphing.

recon Red Team

TruthScan Deepfake Detector

Cloud-based deepfake detection platform offering forensic analysis for manipulated video and audio.

disinformation-media-verification

tsh

An open-source UNIX backdoor that compiles on all variants, has full pty support, and uses strong crypto for communicati

backdoor Red Team

tsh-sctp

An open-source UNIX backdoor.

backdoor Red Team

tshark

Capture and analyze network traffic with this console-based sniffer.

monitoring Blue Team

ttd

TTD is a time travel debugging command line utility.

debuggers Blue Team

ttpassgen

Highly flexible and scriptable password dictionary generator based on Python.

automation Red Team

Tumblr

Blogging and social network platform with tagging system. Supports keyword and tag-based content search.

social-networks

tundeep

Layer 2 VPN/injection tool

uncategorized Red Team

tunna

a set of tools which will wrap and tunnel any TCP communication over HTTP. It can be used to bypass network restrictions

networking Red Team

turner

Tunnels HTTP over a permissive/open TURN server; supports HTTP and SOCKS5 proxy.

networking Red Team

tuxcut

Netcut-like program for Linux written in PyQt

sniffers Red Team

TV Closed Caption Search

Internet Archive TV News collection for searching closed-caption text across broadcast recordings.

archives

Tweet Metadata

Reference document and workflow aid for interpreting metadata fields embedded in tweet payloads and exports.

social-networks

TweeterID

Bidirectional converter between X/Twitter usernames and numeric account IDs for correlation and API-ready pivots.

social-networks

tweets-analyzer

Tweets metadata scraper & activity analyzer.

social Red Team

tweetshell

Multi-thread Twitter BruteForcer in Shell Script.

cracker Red Team

TweetVacuum (T)

Tool for extracting larger Twitter/X timeline archives beyond default on-platform browsing constraints.

social-networks

Twilio Lookup

Twilio API endpoint for phone intelligence including line type, carrier, and validation data.

telephone-numbers

twint

An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a use

social Red Team

Twitonomy

Twitter analytics platform for profile activity, hashtag usage, and follower/following behavior over time.

social-networks

Twitter Date Search

Date-bounded X/Twitter search pattern using `since:` and `until:` operators to isolate tweets in a specific time window.

social-networks

Twitter Image Search (M)

Manual X/Twitter query template for finding tweets containing images for a target keyword or account.

images-videos-docs

Twitter Location Search

Operator-based X/Twitter search workflow for geotagged content using `geocode:` and location-focused query parameters.

social-networks

twofi

Twitter words of interest

password-profiling-wordlists Red Team

TYLabs QuickSand Framework

Python-based malware analysis framework for analyzing Office documents and PDFs to identify exploits in decoded streams using YARA signatures.

malicious-file-analysis

typo3scan

Enumerate Typo3 version and extensions.

webapp Red Team

tyton

Kernel-Mode Rootkit Hunter.

defensive Blue Team

tzdata

Time zone and daylight-saving time data

uncategorized Red Team

u3-pwn

A tool designed to automate injecting executables to Sandisk smart usb devices with default U3 software install.

backdoor Red Team

uacme

Defeating Windows User Account Control.

windows Red Team

uatester

User Agent String Tester

misc Red Team

uberfile

CLI tool for the generation of downloader oneliners for UNIX-like or Windows systems.

misc Red Team

ubertooth

2.4 GHz wireless development platform for Bluetooth experimentation

bluetooth Red Team

ubertooth-git

A 2.4 GHz wireless development board suitable for Bluetooth experimentation. Open source hardware and software. Tools only

bluetooth Red Team

ubiquiti-probing

A Ubiquiti device discovery tool.

recon Red Team

ubitack

Tool, which automates some of the tasks you might need on a (wireless) penetration test or while you are on the go.

wireless Red Team

UCI Spambase Data Set

Classic UCI machine-learning dataset for spam classification and email feature analysis.

archives

udis86

A minimalistic disassembler library.

reversing Blue Team

udork

Bash script that uses advanced Google search techniques to obtain sensitive information in files or directories, find Io

recon Red Team

udp-hunter

Network assessment tool for various UDP Services covering both IPv4 and IPv6 protocols.

scanner Red Team

udpastcp

This program hides UDP traffic as TCP traffic in order to bypass certain firewalls.

networking Red Team

udptunnel

Tunnel UDP packets over a TCP connection

protocol-tunneling Red Team

udpx

Fast and lightweight - UDPX is a single-packet UDP scanner written in Go that supports the discovery of over 45 services with the ability to add…

ad

udsim

A graphical simulator that can emulate different modules in a vehicle and respond to UDS request.

scanner Red Team

uefi-firmware-parser

Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc.

firmware Red Team

uff

Unleashed ffuf. A fork of ffuf with more functions & a modified HTTP stack.

fuzzer Red Team

ufo-wardriving

Allows you to test the security of wireless networks by detecting their passwords based on the router model.

cracker Red Team

ufonet

A tool designed to launch DDoS attacks against a target, using 'Open Redirect' vectors on third party web applications,

dos Red Team

uhd

Universal hardware driver for Ettus Research products - headers

uncategorized Red Team

uhd-images

Various UHD Images

uncategorized Red Team

uhoh365

Script to enumerate Office 365 users without performing login attempts

recon Red Team

UK Companies

Official UK government service providing free access to information about companies registered in England, Wales, Scotland, and Northern Ireland.

business-records

UK Data

UK company information and credit data service providing business intelligence on UK-registered companies.

business-records

UK National Archives

Official online catalog for the UK National Archives providing access to over 32 million records spanning 1,000 years of UK government, legal, and…

search-engines

ultimate-facebook-scraper

A bot which scrapes almost everything about a Facebook user's profile.

social Red Team

umap

The USB host security assessment tool.

scanner Red Team

umap-git

The USB host security assessment tool

uncategorized Red Team

umit

A powerful nmap frontend.

networking Red Team

unar

Unarchiver for a variety of file formats

uncategorized Red Team

unblob

Accurate, fast, and easy-to-use extraction suite (Python 3)

uncategorized Red Team

uncaptcha2

Defeating the latest version of ReCaptcha with 91% accuracy.

webapp Red Team

uncompyle6

Python cross-version bytecode decompiler for Python 1.0 through 3.8.

python Blue Team

uncover

Discover exposed hosts on the internet using multiple search engines.

recon Red Team

undbx

Tool to extract, recover and undelete e-mail messages from .dbx files

digital-forensics Blue Team

underscorejs

Underscore is a utility-belt library for JavaScript that provides a lot of the functional programming support that you would expect in Prototype.js (o

uncategorized Red Team

unfurl

Pull out bits of URLs provided on stdin.

misc Red Team

unhide

Forensic tool to find hidden processes and ports

forensics Blue Team

unhide.rb

Forensics tool to find processes hidden by rootkits

uncategorized Red Team

unibrute

Multithreaded SQL union bruteforcer.

exploitation Red Team

unicode

Display Unicode character properties.

deobfuscation Blue Team

unicorn-magic

Tool for a PowerShell downgrade attack and inject shellcode

uncategorized Red Team

unicorn-powershell

A simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory.

backdoor Red Team

unicornscan

Userland distributed TCP/IP stack

network-information network-service-discovery Red Team

UniCourt

Free nationwide litigation database and docket analyzer. Aggregates state and federal court records with smart search and case tracking.

public-records

uniextract2

Universal Extractor 2 is an unofficial updated and extended version of the original UniExtract by Jared Breland.

packers Blue Team

unifuzzer

A fuzzing tool for closed-source binaries based on Unicorn and LibFuzzer.

fuzzer Red Team

uniofuzz

The universal fuzzing tool for browsers, web services, files, programs and network services/ports

fuzzer Red Team

uniscan

LFI, RFI, and RCE vulnerability scanner

web-scanning Red Team

unisec

Unicode Security Toolkit.

misc Red Team

unix-privesc-check

Script to check for simple privilege escalation vectors

privilege-escalation Red Team

unpyc3

unpyc3 is a decompiler for Python 3.7+.

python Blue Team

unrar-free

Decompress files using a variety of algorithms.

general-utilities Blue Team

unrar-nonfree

Unarchiver for .rar files (non-free version) - development files

uncategorized Red Team

unsecure

Bruteforces network login masks.

windows Red Team

unstrip

ELF Unstrip Tool.

disassembler Blue Team

untwister

Seed recovery tool for PRNGs.

crypto Red Team

unXOR

Deobfuscate XOR'ed files.

deobfuscation Blue Team

unxor (T)

Known-plaintext XOR analysis utility for deriving keystreams and recovering original content from encoded samples.

encoding-decoding

updog

Simple replacement for Python's SimpleHTTPServer.

ad web

uploader

Tool for quickly downloading files to a remote machine based on the target operating system

ad osint web Red Team

upnp-pentest-toolkit

UPnP Pentest Toolkit for Windows.

windows Red Team

upnpscan

Scans the LAN or a given address range for UPnP capable devices.

scanner Red Team

uppwn

A script that automates detection of security flaws on websites' file upload systems'.

webapp Red Team

uptux

Linux privilege escalation checks (systemd, dbus, socket fun, etc).

scanner Red Team

UPX

Pack and unpack PE files.

unpacking Blue Team

upx-ucl

Efficient live-compressor for executables

uncategorized Red Team

Urban Dictionary

Crowdsourced slang reference that tracks contemporary colloquialisms and culture-specific definitions.

language-translation

URL Void

Free website reputation checker that scans URLs against 30+ blocklist engines and reputation services. Detects fraudulent and malicious websites with…

domain-name

urlcrazy

Domain typo generator

web-scanning Red Team

urldedupe

urldedupe is a c++ tool to quickly pass in a list of URLs and get back a list of deduplicated (unique) URL and query string combination.

ad web

urldigger

A python tool to extract URL addresses from different HOT sources and/or detect SPAM and malicious code

webapp Red Team

urlDNA

URL intelligence service for investigating domains, redirects, and related reputation indicators.

domain-name

urlextractor

Information gathering & website reconnaissance.

webapp Red Team

UrlQuery.net

Free online URL scanner that analyzes webpages for malware, suspicious elements, and phishing threats. Provides comprehensive threat detection…

domain-name

urlscan.io

URL and domain analysis service that captures page loads, requests, and security-relevant artifacts.

domain-name ip-mac-address

urlview

A curses URL parser for text files.

misc Red Team

Urlwatch

Open-source Python CLI tool for monitoring webpages and feeds for changes. Supports multiple filters, reporters, and scheduled checks via local…

domain-name

uro

Declutter URLs for crawling/pentesting

web-scanning Red Team

urx

Extracts URLs from OSINT Archives for Security Insights.

webapp Red Team

US Federal Election Commission

Official Federal Election Commission data portal. Searchable federal campaign finance disclosures and election data.

public-records

US Patent Office Search

Official US Patent and Trademark Office searchable patent database. Covers US patents and applications.

public-records

usa-people-search.com

US people search and background check service accessing public records. Reports are paid with significant consumer complaints about billing.

people-search-engines

usb-canary

A Linux or OSX tool that uses psutil to monitor devices while your computer is locked. In the case it detects someone pl

defensive Blue Team

USB Keyboard

Convert your Android device into USB keyboard/mouse.

usb-hid

usbkill-git

An anti-forensic kill-switch that waits for a change on your USB ports and then immediately shuts down your computer.

defense Red Team

usbrip

USB device artifacts tracker.

forensic Blue Team

User Agent String Decoder

Parses and decodes user agent strings into human-readable browser, OS, and device information components.

opsec

user-scanner

OSINT tool that analyzes username and email presence across multiple platforms, intended for security research, investig

social Red Team

UserAgentString.com

Database of known user agent strings for browsers, bots, and devices; helps identify what browser/OS a user agent string represents or find strings…

opsec

username-anarchy

Tools for generating usernames when penetration testing.

automation Red Team

usernamer

Pentest Tool to generate usernames/logins based on supplied names.

misc Red Team

userrecon

Find usernames across over 75 social networks.

recon Red Team

userrecon-py

Recognition usernames in 187 social networks.

social Red Team

usnjrnl2csv

Parser for $UsnJrnl on NTFS.

forensic Blue Team

usnparser

A Python script to parse the NTFS USN journal.

forensic Blue Team

util-linux

Miscellaneous system utilities

uncategorized Red Team

utrace

IP geolocation and reverse DNS lookup tool with network traceroute visualization.

ip-mac-address

uw-loveimap

Multi threaded imap bounce scanner.

scanner Red Team

uw-offish

Clear-text protocol simulator.

networking Red Team

uw-udpscan

Multi threaded udp scanner.

scanner Red Team

uw-zone

Multi threaded, randomized IP zoner.

scanner Red Team

v3n0m

Offensive Security Tool for Vulnerability Scanning & Pentesting

scanner Red Team

valhalla-api

Valhalla API Client.

automation Red Team

vane

A vulnerability scanner which checks the security of WordPress installations using a black box approach.

webapp Red Team

vanguard

A comprehensive web penetration testing tool written in Perl thatidentifies vulnerabilities in web applications.

webapp Red Team

VAT Number Validation

EU VIES (VAT Information Exchange System) allows validation of VAT numbers for businesses registered in EU member states.

business-records

VAT Research

Netherlands tax authorities (Belastingdienst) database. Allows VAT number verification through VIES system.

public-records

Vault

Career research platform providing company profiles, employee reviews, salary data, and industry guides for job seekers and researchers.

business-records

vault-scanner

Swiss army knife for hackers.

scanner Red Team

vb-decompiler-lite

VB Decompiler is a decompiler for Visual Basic, VB.NET and C# applications.

visual-basic Blue Team

vba2graph

Generate call graphs from VBA code, for easier analysis of malicious documents.

malware Blue Team

vbdec

VBDec is a VB File format viewer, P-Code Disassembler and debugger.

visual-basic Blue Team

VBinDiff

Compare binary files.

view-or-edit-files Blue Team

vboot-utils

Chrome OS verified u-boot utilities

uncategorized Red Team

vbrute

Virtual hosts brute forcer.

recon Red Team

vbrute-git

Virtual hosts brute forcer. Specify file containing domains and file containing IPs and will attempt to connect to IP with specific domain.

uncategorized Red Team

vbscan

A black box vBulletin vulnerability scanner written in perl.

webapp Red Team

vbscan-git

Black Box vBulletin Vulnerability Scanner

scanners Red Team

vbsmin

VBScript minifier.

packer Red Team

vcsmap

A plugin-based tool to scan public version control systems for sensitive information.

scanner Red Team

vega

An open source platform to test the security of web applications

webapps Red Team

veil

Generates payloads to bypass anti-virus solutions

defense-evasion Red Team

veles

New open source tool for binary data analysis.

binary Red Team

venom

A Multi-hop Proxy for Penetration Testers.

exploitation Red Team

Verification Handbook

Reference handbook for journalists covering verification methodologies for digital investigations.

disinformation-media-verification

verinice

Tool for managing information security.

misc Red Team

Vessel Finder

Global AIS vessel tracking service for ship positions, voyage progress, and historical movement review.

transportation

Vessel Tracker

Commercial maritime tracking platform combining AIS and satellite feeds for global vessel movement intelligence.

transportation

vfeed

Open Source Cross Linked and Aggregated Local Vulnerability Database main repository.

misc Red Team

vhostscan

A virtual host scanner that can be used with pivot tools, detect catch-all scenarios, aliases and dynamic default pages.

scanner Red Team

videosnarf

A new security assessment tool for pcap analysis

scanner Red Team

ViewDNS.info

Comprehensive DNS lookup and WHOIS service providing detailed DNS records, reverse IP lookups, reverse WHOIS searches, and API access for automated…

domain-name

Vigilante.pw

Breach database directory and search platform raising awareness of data breaches by aggregating publicly leaked database information and breach…

email-address

villain

High level C2 framework

command-and-control Red Team

vim

Vi IMproved - enhanced vi editor

uncategorized Red Team

VinDecodr

Free VIN decoder for quick extraction of standard vehicle characteristics from 17-character VIN values.

transportation

vinetto

Forensics tool to examine Thumbs.db files

digital-forensics Blue Team

viper

A Binary analysis framework.

disassembler Blue Team

vipermonkey

A VBA parser and emulation engine to analyze malicious macros.

forensic Blue Team

viproy-voipkit

VoIP Pen-Test Kit for Metasploit Framework.

exploitation Red Team

VirtualBox (T)

Open-source, general-purpose full virtualization software supporting x86_64 hardware across laptops, desktops, servers, and embedded systems.

tools

VirusShare.com

Repository of 111+ million live malware samples provided for security researchers, incident responders, forensic analysts, and researchers.

malicious-file-analysis

virustotal

Command-line utility to automatically lookup on VirusTotal all files recursively contained in a directory.

malware Blue Team

virustotal-search

Search VirusTotal for file hashes.

gather-and-analyze-data Red Team

virustotal-submit

Submit files to VirusTotal.

gather-and-analyze-data Red Team

visql

Scan SQL vulnerability on target site and sites of on server.

scanner Red Team

Visual Genome

Structured image dataset linking objects, attributes, and scene graph relationships for visual understanding research.

archives

Visual Site Mapper

Site-crawling mapper used to visualize website structure and page relationships.

domain-name

Visual Studio Code

Powerful source code editor.

view-or-edit-files Blue Team

visualize-logs

A Python library and command line tools to provide interactive log visualization.

misc Red Team

VisualPing

Website monitoring platform that alerts on page content or visual changes.

domain-name

vivisect

A Python based static analysis and reverse engineering framework.

debugger Red Team

vlan

Ifupdown legacy integration for vlan configuration

uncategorized Red Team

vlan-hopping

Easy 802.1Q VLAN Hopping

automation Red Team

vlany

Linux LD_PRELOAD rootkit (x86 and x86_64 architectures).

backdoor Red Team

vmap

A Vulnerability-Exploit desktop finder.

exploitation Red Team

vmcloak

Automated Virtual Machine Generation and Cloaking for Cuckoo Sandbox.

malware Blue Team

vnak

Aim is to be the one tool a user needs to attack multiple VoIP protocols.

voip Red Team

vnc-bypauth

Multi-threaded bypass authentication scanner for VNC smaller than v4.1.1 servers.

cracker Red Team

vncrack

What it looks like: crack VNC.

cracker Red Team

VoilaNorbert

Email finder and verifier with 98% success rate that discovers business emails by company/domain, person name, or LinkedIn profile with bulk upload…

email-address

voiper

A VoIP security testing toolkit incorporating several VoIP fuzzers and auxiliary tools to assist the auditor.

voip Red Team

voiphopper

Runs a VLAN hop security test

voip Red Team

voipong

A utility which detects all Voice Over IP calls on a pipeline, and for those which are G711 encoded, dumps actual conver

voip Red Team

volafox

Mac OS X Memory Analysis Toolkit.

forensic Blue Team

volana

Shell command obfuscation to avoid detection systems.

exploitation Red Team

volatility-extra

Volatility plugins developed and maintained by the community.

forensic Blue Team

Volatility Framework

Memory forensics tool and framework.

perform-memory-forensics Blue Team

volatility2

Volatile memory extraction utility framework

general

volatility3

Advanced memory forensics framework

general

voltron

UI for GDB, LLDB and Vivisect's VDB.

debugger Red Team

vopono

Run applications through VPN tunnels with temporary network namespaces

uncategorized Red Team

vpnc

Cisco-compatible VPN client

uncategorized Red Team

vpnpivot

Explore the network using this tool.

recon Red Team

vsaudit

VOIP Security Audit Framework.

voip Red Team

vscan

HTTPS / Vulnerability scanner.

scanner Red Team

vstt

VSTT is a multi-protocol tunneling tool. It accepts input by TCP stream sockets and FIFOs, and can send data via TCP, PO

tunnel Red Team

vsvbp

Black box tool for Vulnerability detection in web applications.

webapp Red Team

vt

A command-line interface for VirusTotal.

general

vt-cli

VirusTotal Command Line Interface.

malware Blue Team

vulmap

Vulmap Online Local Vulnerability Scanners Project

scanner Red Team

vulnerabilities-spider

A tool to scan for web vulnerabilities.

webapp Red Team

vulnx

Cms and vulnerabilites detector & An intelligent bot auto shell injector.

webapp Red Team

vuls

Vulnerability scanner for Linux/FreeBSD, agentless, written in Go.

scanner Red Team

vURL Online

URL and domain dissection tool providing detailed reputation analysis and security assessment.

domain-name

vwifi-dkms

Simple Virtual Wireless Driver for Linux in DKMS format

uncategorized Red Team

W Generator

Frontend-based wordlist generator for penetration testing that creates customized password dictionaries based on publicly available information using…

tools

w13scan

Passive Security Scanner.

webapp Red Team

w3af

Web Application Attack and Audit Framework.

fuzzer Red Team

wabt

The WebAssembly Binary Toolkit (WABT) is a suite of tools for WebAssembly (Wasm) including assembler and disassembler / a syntax checker / and a…

general

wafninja

A tool which contains two functions to attack Web Application Firewalls.

webapp Red Team

wafp

An easy to use Web Application Finger Printing tool written in ruby using sqlite3 databases for storing the fingerprints

webapp Red Team

wafpass

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

webapp Red Team

wafw00f

Identify and fingerprint Web Application Firewall products

network-security-appliances Red Team

waidps

Wireless Auditing, Intrusion Detection & Prevention System.

wireless Red Team

waldo

A lightweight and multithreaded directory and subdomain bruteforcer implemented in Python.

recon Red Team

Wallet Explorer

Bitcoin address clustering and wallet linking tool using multi-input heuristics to identify related addresses and track entity-level transaction…

blockchain-cryptocurrency

Walrus

Access control card cloning devices in the field

rf

wapiti

Web application vulnerability scanner

web-vulnerability-scanning Red Team

Wappalyzer

Technology detection platform and browser tooling for identifying frameworks, CMS, and SaaS usage.

domain-name

Wappalyzer (T)

Technology stack profiler that identifies CMS, frameworks, analytics, and infrastructure used by a website.

domain-name

wascan

Web Application Scanner.

webapp Red Team

WasItAI

Lightweight AI content detection tool that analyzes text and images to determine if they were created by AI, with a simple interface for quick checks.

ai-tools

watobo

Semi-automated web application scanner

web-vulnerability-scanning Red Team

Wayback Imagery

Esri Wayback archive for reviewing previous versions of world imagery basemaps.

geolocation-tools-maps

Wayback Machine Chrome Extension

Browser extension that detects missing pages and loads historical versions from the Wayback Machine.

archives

waybackpack

Download the entire Wayback Machine archive for a given URL.

webapp Red Team

Waybackpack (T)

Command-line tool for bulk downloading archived captures from the Internet Archive Wayback Machine.

archives

waybackpy

Access Wayback Machine’s API using Python

uncategorized Red Team

waybackurls

Fetch all the URLs that the Wayback Machine knows about for a domain.

recon Red Team

waymore

Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan & VirusTotal.

recon Red Team

wayparam

Fetch and normalize parameterized URLs from the Wayback CDX API.

webapp Red Team

wcc

The Witchcraft Compiler Collection.

binary Red Team

wcc-git

The Witchcraft Compiler Collection

misc Red Team

wce

Windows Credentials Editor

uncategorized Red Team

wcvs

Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning.

webapp Red Team

wdict

Create dictionaries by scraping webpages or crawling local files.

wordlist Red Team

Web Archive-RU

Regional web archiving service focused on preserving and browsing snapshots of selected websites.

archives

web-cache-vulnerability-scanner

Go-based CLI tool for testing for web cache poisoning

web-vulnerability-scanning Red Team

Web Data Exposure Scanner (T)

Open-source scanner for detecting exposed web application data and sensitive file disclosures on web servers.

domain-name

Web Inspector Online Scan

Free cloud-based website malware scanner with daily automated scanning and blacklist checking capabilities.

domain-name

Web Page Saver

Browser extension for saving complete webpages as single HTML files for offline access and evidence preservation.

documentation-evidence-capture

web-soul

A plugin based scanner for attacking and data mining web sites written in Perl.

webapp Red Team

web2ldap

Full-featured LDAP client running as web application.

misc Red Team

webacoo

Web backdoor cookie script kit

persistence Red Team

webanalyze

Port of Wappalyzer (uncovers technologies used on websites) in go to automate scanning.

webapp Red Team

webborer

A directory-enumeration tool written in Go.

webapp Red Team

webclientservicescanner

Scans for web service endpoints

ad

Webcrack

Deobfuscate, unminify, and unpack bundled JavaScript, including scripts protected with obfuscator.io.

scripts Blue Team

webenum

Tool to enumerate http responses using dynamically generated queries and more.

scanner Red Team

webexploitationtool

A cross platform web exploitation toolkit.

exploitation Red Team

webfixy

On-the-fly decryption proxy for MikroTik RouterOS WebFig sessions.

proxy Red Team

webhandler

A handler for PHP system functions & also an alternative 'netcat' handler.

webapp Red Team

webhunter

Tool for scanning web applications and networks and easily completing the process of collecting knowledge.

scanner Red Team

webkiller

Tool Information Gathering Write By Python.

webapp Red Team

Webmii

Free people search engine that calculates a web visibility score based on online presence across social networks, news, and web pages.

people-search-engines

webpwn3r

A python based Web Applications Security Scanner.

scanner Red Team

Webroot BrightCloud URL/IP Lookup

Web classification and reputation tool providing URL/IP threat and content analysis. Uses machine learning reputation scoring across 82 content…

domain-name

webrute

Web server directory brute forcer.

scanner Red Team

webscarab

Web application review tool

web-vulnerability-scanning Red Team

websearch

Search vhost names given a host range. Powered by Bing..

recon Red Team

webshag

A multi-threaded, multi-platform web server audit tool.

fuzzer Red Team

webshells

Collection of webshells

persistence Red Team

Website Informer

Free domain and website information aggregator providing visitor statistics, safety status, Alexa rankings, ownership data, and technical details…

domain-name

webslayer

A tool designed for brute forcing Web Applications.

webapp Red Team

websockify

WebSocket to TCP proxy/bridge.

networking Red Team

webspa

A web knocking tool, sending a single HTTP/S to run O/S commands.

backdoor Red Team

websploit

Web exploitation framework

uncategorized Red Team

webtech

Identify technologies used on websites.

webapp Red Team

webxploiter

An OWASP Top 10 Security scanner.

webapp Red Team

wechat-dump (T)

Tool for exporting WeChat chat data from rooted Android devices for forensic examination and recovery.

instant-messaging

wechat-text-backup (T)

WeChat database decryption and backup utility for exporting local message history into readable text formats.

instant-messaging

weebdns

DNS Enumeration with Asynchronicity.

recon Red Team

weeman

HTTP Server for phishing in python.

social Red Team

weevely

Stealth tiny web shell

persistence Red Team

weirdaal

AWS Attack Library.

webapp Red Team

wepbuster

script for automating aircrack-ng

wireless Red Team

wesng

Windows Exploit Suggester - Next Generation.

exploitation Red Team

wfuzz

Web application bruteforcer

web-scanning Red Team

wget

Retrieves files from the web

uncategorized Red Team

wgetpaste

Command-line interface to various online pastebin services

uncategorized Red Team

whapa

WhatsApp Parser Tool.

misc Red Team

What Font Is

AI-powered font identification tool that analyzes images against a database of 1.2M+ typefaces to identify fonts.

images-videos-docs

what-is-python

Symlinks /usr/bin/python-config to python3-config

uncategorized Red Team

whatbreach

OSINT tool to find breached emails and databases.

social Red Team

WhatIsMyBrowser.com

Detects and reports your current browser, operating system, and plugins as seen by websites; useful for verifying anonymization and user-agent…

opsec

whatmask

Helper for network settings

uncategorized Red Team

whatportis

A command to search port names and numbers.

misc Red Team

WhatsApp Messenger (T)

Messaging platform with 2B+ users. End-to-end encrypted, but profile data and metadata are accessible.

mobile-osint Red Team

WhatsApp-OSINT (T)

WhatsApp reconnaissance toolchain using API-backed lookups for account and device-related intelligence collection.

instant-messaging

whatsmyname

Tool to perform user and username enumeration on various websites.

social Red Team

WhatsMyName (T)

OSINT project maintaining a curated JSON database of website detection patterns for username enumeration. Web interface available at whatsmyname.app.

username

WhatTheFont

Image-based font identification service that matches uploaded text images against a large commercial font catalog.

language-translation

whatwaf

Detect and bypass web application firewalls and protection systems.

webapp Red Team

whatweb

Next generation web scanner

web-vulnerability-scanning Red Team

whatweb-git

Next generation web scanner that identifies what websites are running.

webapps Red Team

Where Does This Link Go?

Redirect-chain inspector that traces and visualizes final destination paths.

domain-name

whichcdn

Tool to detect if a given website is protected by a Content Delivery Network.

webapp Red Team

WHID Injector

Android Mobile App for Controlling WHID Injector remotely.

usb-hid

whispers

Identify hardcoded secrets in static structured text.

code-audit Red Team

Whitepages Reverse Phone

Reverse phone lookup product from Whitepages for US-focused identity and contact attribution.

telephone-numbers

whitewidow

SQL Vulnerability Scanner.

scanner Red Team

Who.is

Comprehensive WHOIS and RDAP lookup service with large database of domain registration, DNS records, and IP information. Provides both current and…

domain-name

whois

Intelligent WHOIS client

uncategorized Red Team

Whoisology

Searchable archive of billions of current and historical domain WHOIS records with cross-referencing capabilities. Designed for InfoSec, legal, and…

domain-name

Whonix (T)

Anonymous operating system using two virtual machines (Gateway/Workstation) enforcing network isolation, making DNS leaks impossible.

tools

whoxyrm

A reverse whois tool based on Whoxy API.

recon Red Team

wifi-autopwner

Script to automate searching and auditing Wi-Fi networks with weak security.

automation Red Team

wifi-honey

Wi-Fi honeypot

wifi-credential-access Red Team

wifi-monitor

Prints the IPs on your local network that're sending the most packets.

sniffer Red Team

wifi-pumpkin

Framework for Rogue Wi-Fi Access Point Attack.

wireless Red Team

wifibroot

A WiFi Pentest Cracking tool for WPA/WPA2 (Handshake, PMKID, Cracking, EAPOL, Deauthentication).

wireless Red Team

wifichannelmonitor

A utility for Windows that captures wifi traffic on the channel you choose, using Microsoft Network Monitor capture driv

windows Red Team

wificurse

WiFi jamming tool.

wireless Red Team

wifijammer

A python script to continuously jam all wifi clients within range.

wireless Red Team

wifiphisher

Automated phishing attacks against Wi-Fi networks

wifi-credential-access Red Team

wifiphisher-git

A tool for Fast automated phishing attacks against WPA networks

wireless Red Team

wifipumpkin3

Powerful framework for rogue access point attack

collection Red Team

wifiscanmap

Another wifi mapping tool.

wireless Red Team

wifitap

WiFi injection tool through tun/tap device.

wireless Red Team

wifite

Python script to automate wireless auditing using aircrack-ng tools

wifi-credential-access Red Team

wifite2

Script for auditing wireless networks.

general

wig

WebApp Information Gatherer

uncategorized Red Team

wig-git

WebApp Information Gatherer

webapps Red Team

wig-ng

Utility for Wi-Fi device fingerprinting

uncategorized Red Team

WiGLE WiFi Wardriving

Nethugging client for Android

wifi Red Team

WiGLE: Wireless Network Mapping

Global database of wireless networks (WiFi, Bluetooth, cellular) with mapping and signal strength data.

ip-mac-address

wikigen

A script to generate wordlists out of wikipedia pages.

automation Red Team

WikiLeaks

Global document leak publication platform containing diplomatic, military, and corporate disclosures.

archives

Wiktionary

Collaborative multilingual dictionary and translation reference hosted by the Wikimedia ecosystem.

language-translation

wildpwn

Unix wildcard attacks.

exploitation Red Team

windapsearch

Script to enumerate users, groups and computers from a Windows domain through LDAP queries.

recon Red Team

windapsearch-go

Active Directory enumeration tool.

ad

windbg

WinDbg is a debugger that can be used to analyze crash dumps, debug live user-mode and kernel-mode code, and examine CPU registers and memory.

debuggers Blue Team

windivert

A user-mode packet capture-and-divert package for Windows.

windows Red Team

windows-binaries

Various pentesting Windows binaries

uncategorized Red Team

Windows Defender Security Intelligence (WDSI)

Microsoft's security intelligence portal for reporting malicious URLs and checking Windows Defender threat assessments.

domain-name

windows-exploit-suggester

This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential miss

recon Red Team

windows-exploit-suggester-git

Compares a target patch levels against the Microsoft vulnerability database to detect potential missing patches on the target. Also notifies the user

exploit Red Team

windows-prefetch-parser

Parse Windows Prefetch files.

forensic Blue Team

windows-privesc-check

Windows privilege escalation checking tool

uncategorized Red Team

windowsspyblocker

Block spying and tracking on Windows.

windows Red Team

Wine

Run Windows applications.

general Blue Team

winexe

Remotely execute commands on Windows NT/2000/XP/2003 systems.

misc Red Team

winfo

Uses null sessions to remotely try to retrieve lists of and information about user accounts, workstation/interdomain/ser

windows Red Team

winhex

Hex Editor and Disk Editor.

windows Red Team

winpwn

Automation for internal Windows Penetrationtest / AD-Security.

windows Red Team

winregfs

Windows registry FUSE filesystem

uncategorized Red Team

winrelay

A TCP/UDP forwarder/redirector that works with both IPv4 and IPv6.

windows Red Team

wireguard

WireGuard is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography

ad light osint web Red Team

wireless-ids

Ability to detect suspicious activity such as (WEP/WPA/WPS) attack by sniffing the air for wireless packets.

wireless Red Team

wireshark

Network traffic analyzer - graphical interface

network-sniffing discovery Red Team

wirouter-keyrec

A platform independent software to recover the default WPA passphrases of the supported router models

wireless Red Team

witchxtool

A perl script that consists of a port scanner, LFI scanner, MD5 bruteforcer, dork SQL injection scanner, fresh proxy sca

webapp Red Team

witnessme

Web Inventory tool

reporting-tools Red Team

wlan2eth

Re-writes 802.11 captures into standard Ethernet frames.

wireless Red Team

wmat

Automatic tool for testing webmail accounts.

cracker Red Team

wmbusmeters

Read the wired or wireless mbus protocol to acquire utility meter readings.

radio Red Team

wmd

Python framework for IT security tools.

automation Red Team

wmi

DCOM/WMI client implementation

resource-development Red Team

wmi-forensics

Scripts used to find evidence in WMI repositories.

forensic Blue Team

wnmap

A shell script written with the purpose to automate and chain scans via nmap.

automation Red Team

wol-e

A suite of tools for the Wake on LAN feature of network attached computers.

misc Red Team

wolpertinger

A distributed portscanner.

scanner Red Team

wondershaper

Limit the bandwidth of one or more network adapters.

networking Red Team

Word Reference

Bilingual dictionary platform with conjugation tables, forum context, and language-pair references.

language-translation

wordbrutepress

Python script that performs brute forcing against WordPress installs using a wordlist.

cracker Red Team

wordlistctl

Fetch, install and search wordlist archives from websites.

misc Red Team

wordlister

A simple wordlist generator and mangler written in python.

misc Red Team

wordlistraider

Tool to prepare existing wordlists

uncategorized Red Team

wordlists

Contains the rockyou wordlist

password-profiling-wordlists credential-access Red Team

wordpot

A Wordpress Honeypot.

honeypot Blue Team

wordpress-exploit-framework

A Ruby framework for developing and using modules which aid in the penetration testing of WordPress powered websites and

webapp Red Team

wordpresscan

WPScan rewritten in Python + some WPSeku ideas.

scanner Red Team

World Monitor

AI-powered geopolitical event monitoring and intelligence platform that tracks global news and events relevant to national security and business risk.

ai-tools

wotmate

Reimplement the defunct PGP pathfinder with only your own keyring

uncategorized Red Team

wpa-bruteforcer

Attacking WPA/WPA encrypted access point without client.

wireless Red Team

wpa-sycophant

Tool to relay phase 2 authentication attempts to access corporate wireless

uncategorized Red Team

wpa2-halfhandshake-crack

A POC to show it is possible to capture enough of a handshake with a user from a fake AP to crack a WPA2 network without

wireless Red Team

wpbf

Multithreaded WordPress brute forcer.

cracker Red Team

wpbrute-rpc

Tool for amplified bruteforce attacks on wordpress based website via xmlrcp API.

cracker Red Team

wpbullet

A static code analysis for WordPress (and PHP).

code-audit Red Team

wpforce

Wordpress Attack Suite.

webapp Red Team

wpintel

Chrome extension designed for WordPress Vulnerability Scanning and information gathering.

webapp Red Team

wpprobe

Fast WordPress plugin enumeration tool

web-scanning Red Team

wpscan

Black box WordPress vulnerability scanner

web-vulnerability-scanning Red Team

wpseku

Simple Wordpress Security Scanner.

webapp Red Team

wpsik

WPS scan and pwn tool.

wireless Red Team

wpsweep

A simple ping sweeper, that is, it pings a range of IP addresses and lists the ones that reply.

windows Red Team

wreckuests

Yet another one hard-hitting tool to run DDoS attacks with HTTP-flood.

dos Red Team

ws-attacker

A modular framework for web services penetration testing.

webapp Red Team

wscript

Emulator/tracer of the Windows Script Host functionality.

code-audit Red Team

wsfuzzer

A Python tool written to automate SOAP pentesting of web services.

fuzzer Red Team

wsgidav

Generic and extendable WebDAV server (common documentation)

uncategorized Red Team

wssip

Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.

webapp Red Team

wsuspect-proxy

A tool for MITM'ing insecure WSUS connections.

exploitation Red Team

wups

An UDP port scanner for Windows.

windows Red Team

wuzz

Interactive cli tool for HTTP inspection.

webapp Red Team

wxhexeditor

A free hex editor / disk editor for Linux, Windows and MacOSX.

binary Red Team

wyd

Gets keywords from personal files. IT security/forensic tool.

cracker Red Team

x-rsa

Contains a many of attack types in RSA such as Hasted, Common Modulus, Chinese Remainder Theorem.

crypto Red Team

x-scan

A general network vulnerabilities scanner for scanning network vulnerabilities for specific IP address scope or stand-al

windows Red Team

X0rz Tweets_analyzer (T)

Python CLI analyzer for profiling Twitter user behavior, including posting rhythm, language distribution, and source-client usage.

social-networks

x3270

An IBM 3270 terminal emulator for the X Window System patched for birp(https://github.com/sensepost/birp)

uncategorized Red Team

x64dbg

An open-source x64/x32 debugger for windows.

windows Red Team

x64dbg Automate MCP (OpenCode skills)

Drive x64dbg on a remote Windows VM from OpenCode on REMnux, with eight AI commands for tracing, unpacking, state snapsh

general Blue Team

x64dbg Documentation

Read the official x64dbg documentation offline, including the command reference and format specifiers.

general Blue Team

x64dbg.plugin.dbgchild

DbgChild is an x64dbg plugin to automatically attach to spawned child processes.

debuggers Blue Team

x64dbg.plugin.ollydumpex

Ollydumpex is process memory dumper for OllyDbg and Immunity Debugger.

debuggers Blue Team

x64dbg.plugin.scyllahide

ScyllaHide is an advanced open-source x64/x86 user mode Anti-Anti-Debug library.

debuggers Blue Team

x64dbg.plugin.x64dbgpy

X64dbgpy is a a plugin to access the API of x64dbg using Python.

debuggers Blue Team

x8

Hidden parameters discovery suite.

webapp Red Team

xcat

A command line tool to automate the exploitation of blind XPath injection vulnerabilities.

exploitation Red Team

xcavator

Man-In-The-Middle and phishing attack tool that steals the victim's credentials of some web services like Facebook.

sniffer Red Team

xcavator-git

man-in-the-middle and phishing attack tool that steals the victim's credentials of some web services like Facebook

uncategorized Red Team

xclip

Command line interface to X selections

uncategorized Red Team

xcname

A tool for enumerating expired domains in CNAME records.

scanner Red Team

xerosploit

Efficient and advanced man in the middle framework.

networking Red Team

xeuledoc - Fetch metadata about any public Google document

Python tool that extracts metadata from public Google Docs, Sheets, and Slides links.

images-videos-docs

xfltreat

Tunnelling framework.

tunnel Red Team

XING (R)

European professional networking platform popular in German-speaking countries. Provides company profiles, employee listings, and career data.…

business-records

XLMMacroDeobfuscator

Deobfuscate XLM macros (also known as Excel 4.0 macros) from Microsoft Office files.

microsoft-office Blue Team

xmldump.py

Extract contents of XML files, in particular OOXML-formatted Microsoft Office documents.

microsoft-office Blue Team

xmlrpc-bruteforcer

An XMLRPC brute forcer targeting Wordpress written in Python 3.

webapp Red Team

xmount

Tool for crossmounting between disk image formats

uncategorized Red Team

XMRChain.net

Minimal Monero blockchain explorer with no JavaScript, cookies, or tracking; available via Tor with focus on privacy and open-source design.

blockchain-cryptocurrency

XMRChain.net (Monero)

Minimal Monero blockchain explorer with no JavaScript, cookies, or tracking; available via Tor with focus on privacy and open-source design.

blockchain-cryptocurrency

xor-kpa.py

Implement a XOR known plaintext attack.

deobfuscation Blue Team

xorbruteforcer

Script that implements a XOR bruteforcing of a given file, although a specific key can be used too.

crypto Red Team

xorBruteForcer.py

Bruteforce an XOR-encoded file.

deobfuscation Blue Team

XORBruteForcer.py (T)

Single-byte XOR brute-force Python script that iterates candidate key values and surfaces matching decoded output.

encoding-decoding

xorsearch

Program to search for a given string in an XOR, ROL or ROT encoded binary file.

crypto Red Team

xorsearch.py

Search for XOR, ROL, ROT, and SHIFT encoded strings with YARA and regex support.

deobfuscation Blue Team

XORSearch & XORStrings (T)

Didier Stevens command-line utilities for locating XOR, ROL, ROT, and SHIFT-encoded strings in suspicious binaries.

encoding-decoding

XORStrings

Search for XOR encoded strings in a file.

deobfuscation Blue Team

xortool

Analyze XOR-encoded data.

deobfuscation Blue Team

xortool (T)

Python-based XOR analysis tool that estimates key lengths and recovers likely multi-byte keys via frequency analysis.

encoding-decoding

xpire-crossdomain-scanner

Scans crossdomain.xml policies for expired domain names.

scanner Red Team

xpl-search

Search exploits in multiple exploit databases!.

exploitation Red Team

xplico

Network Forensic Analysis Tool (NFAT)

forensics system-services Blue Team

xprobe2

An active OS fingerprinting tool.

fingerprint Red Team

xray

A tool for recon, mapping and OSINT gathering from public networks.

recon Red Team

xrop

Tool to generate ROP gadgets for ARM, AARCH64, x86, MIPS, PPC, RISCV, SH4 and SPARC.

exploitation Red Team

xspear

Powerful XSS Scanning and Parameter analysis tool&gem.

webapp Red Team

xspy

X server sniffer

keylogger Red Team

xsrfprobe

Prime Cross Site Request Forgery Audit and Exploitation Toolkit

uncategorized Red Team

xss-callback-git

A lightweight HTTP Server that exploits XSS victim's session automatically

uncategorized Red Team

xss-freak

An XSS scanner fully written in Python3 from scratch.

webapp Red Team

xsscon

Simple XSS Scanner tool.

webapp Red Team

xsscrapy

XSS spider - 66/66 wavsep XSS detected.

webapp Red Team

xsser

XSS testing framework

execution Red Team

xssf

A Cross-Site Scripting Framework for metasploit

webapps Red Team

xssless

An automated XSS payload generator written in python.

webapp Red Team

xssless-git

An automated XSS payload generator written in python.

uncategorized Red Team

xsspy

Web Application XSS Scanner.

webapp Red Team

xsss

A brute force cross site scripting scanner.

webapp Red Team

xssscan

Command line tool for detection of XSS attacks in URLs. Based on ModSecurity rules from OWASP CRS.

webapp Red Team

xssscan-git

Command line tool for detection of XSS attacks in URLs. Based on ModSecurity rules from OWASP CRS.

webapps Red Team

xsssniper

An automatic XSS discovery tool

webapp Red Team

xsstracer

Python script that checks remote web servers for Clickjacking, Cross-Frame Scripting, Cross-Site Tracing and Host Header

scanner Red Team

xsstrike

Most advanced XSS scanner

uncategorized Red Team

xssya

A Cross Site Scripting Scanner & Vulnerability Confirmation.

webapp Red Team

xtightvncviewer

xtightvncviewer is an open source VNC client software.

ad

xwaf

Automatic WAF bypass tool.

webapp Red Team

xxeinjector

Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.

exploitation Red Team

xxeserv

A mini webserver with FTP support for XXE payloads.

networking Red Team

xxexploiter

It generates the XML payloads, and automatically starts a server to serve the needed DTD's or to do data exfiltration.

exploitation Red Team

xxxpwn

A tool Designed for blind optimized XPath 1 injection attacks.

webapp Red Team

xxxpwn-smart

A fork of xxxpwn adding further optimizations and tweaks.

webapp Red Team

yaaf

Yet Another Admin Finder.

webapp Red Team

yaf

Yet Another Flowmeter.

networking Red Team

Yalis

Yet Another LinkedIn Scraper

osint web Red Team

Yandex Images

Reverse image search engine with strong matching for Eastern European and Asian web sources.

images-videos-docs

Yandex.Maps

Regional mapping service with strong coverage in Russia and surrounding regions.

geolocation-tools-maps

yara

Pattern matching swiss knife for malware researchers

forensics Blue Team

YARA-Forge Rules

Scan files with curated YARA rules from 45+ sources for malware family identification.

general Blue Team

Yara Rules

Scan a file with YARA rules to identify capabilities and behaviors (packer detection, anti-debug, networking).

general Blue Team

YARA-X

Scan files using YARA rules, the next generation of YARA written in Rust.

gather-and-analyze-data Red Team

yararules-git

A Repository of yara rules

uncategorized Red Team

yarn

Yarn is a package manager that doubles down as project manager.

ad light osint web Red Team

yasat

Yet Another Stupid Audit Tool.

scanner Red Team

yasca

Multi-Language Static Analysis Toolset.

code-audit Red Team

Yasni

Free people search engine allowing searches by name, location, profession, company, or skills. Also offers professional Expose profile pages.

people-search-engines

yasuo

A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network.

webapp Red Team

yate-bts

An open source GSM Base Station software.

radio Red Team

yawast

The YAWAST Antecedent Web Application Security Toolkit.

webapp Red Team

yay

Yet another yogurt. Pacman wrapper and AUR helper written in go.

misc Red Team

ycrawler

A web crawler that is useful for grabbing all user supplied input related to a given website and will save the output. I

webapp Red Team

yersinia

Network vulnerabilities check software

system-network-configuration-discovery Red Team

yeti

A platform meant to organize observables, indicators of compromise, TTPs, and knowledge on threats in a single, unified

defensive Blue Team

Yik Yak (T)

Anonymous location-based social network. Public posts visible by location, useful for community sentiment and event tracking.

mobile-osint Red Team

yinjector

A MySQL injection penetration tool. It has multiple features, proxy support, and multiple exploitation methods.

exploitation Red Team

You.com

AI-powered search engine and assistant that combines web search with LLM-generated responses and source citations for research tasks.

ai-tools

youtubedl

Download videos from YouTube and other sites.

osint web Red Team

ysoserial

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

webapp Red Team

yt-dlp

A youtube-dl fork with additional features and fixes

ad osint web Red Team

yt-dlp (T)

Actively maintained command-line downloader for collecting video content and metadata from many platforms.

social-networks

zackattack

A new tool set to do NTLM Authentication relaying unlike any other tool currently out there.

networking Red Team

zaproxy

Testing tool for finding vulnerabilities in web applications

web-vulnerability-scanning Red Team

zarn

A lightweight static security analysis tool for modern Perl Apps.

code-audit Red Team

zarp

A network attack tool centered around the exploitation of local networks.

exploitation Red Team

zbarimg

Decode QR codes and barcodes from image files.

connecting Blue Team

zdns

Fast CLI DNS Lookup Tool.

networking Red Team

zeek

A powerful network analysis framework that is much different from the typical IDS you may know.

networking Red Team

zeek-aux

Handy auxiliary programs related to the use of the Zeek Network Security Monitor.

networking Red Team

ZeeMaps

Interactive map creation and sharing tool with unlimited markers, 3-level access control, and support for crowdsourced data input.

documentation-evidence-capture

Zehef

Zehef is an osint tool to track emails

osint web Red Team

zelos

A comprehensive binary emulation and instrumentation platform.

binary Red Team

zeratool

Automatic Exploit Generation (AEG) and remote flag capture for exploitable CTF problems.

exploitation Red Team

zerofree

Zero free blocks from ext2, ext3 and ext4 file-systems

uncategorized Red Team

zerologon

Exploit for the Zerologon vulnerability (CVE-2020-1472).

ad

zerowine

Malware Analysis Tool - research project to dynamically analyze the behavior of malware

malware Blue Team

zeus

AWS Auditing & Hardening Tool.

defensive Blue Team

zeus-scanner

Advanced dork searching utility.

recon Red Team

zgrab

Grab banners (optionally over TLS).

recon Red Team

zgrab2

Fast Application Layer Scanner.

fingerprint Red Team

zim

Graphical text editor based on wiki technologies

uncategorized Red Team

zipalign

arguably the most important step to optimize your APK file

general

zipdump

ZIP dump utility.

forensic Blue Team

zipdump.py

Analyze zip-compressed files.

microsoft-office Blue Team

zipexec

A unique technique to execute binaries from a password protected zip.

crypto Red Team

zirikatu

Fud Payload generator script.

exploitation Red Team

zizzania

Automated DeAuth attack.

wireless Red Team

Zone-H.org

Archive of reported website defacements and related incident metadata maintained by the Zone-H community.

domain-name

zonedb

Public Zone Database (program)

uncategorized Red Team

Zscaler Zulu URL Risk Analyzer

Free dynamic risk scoring engine for web content analysis. Assesses URLs from multiple perspectives: content analysis, URL patterns, and host…

domain-name

zsh

Shell with lots of features

uncategorized Red Team

zsh-autosuggestions

Fish-like fast/unobtrusive autosuggestions for zsh

uncategorized Red Team

zsh-syntax-highlighting

Fish shell like syntax highlighting for zsh

uncategorized Red Team

zsteg

Detect stegano-hidden data in PNG and BMP.

stego Red Team

zulu

A light weight 802.11 wireless frame generation tool to enable fast and easy debugging and probing of 802.11 networks.

cracker Red Team

zulucrypt

Front end to cryptsetup and tcplay and it allows easy management of encrypted block devices.

crypto Red Team

zykeys

Demonstrates how default wireless settings are derived on some models of ZyXEL routers.

wireless Red Team