A vast collection of security tools for bug bounty, pentest and red teaming

Featured tools this week

socialhunter on offsec.tools
Featured
socialhunter

Crawls the website and finds broken social media links that can be hijacked

PyExfil on offsec.tools
Featured
PyExfil

Set as many exfiltration, techniques that CAN be used to bypass various.

Vajra on offsec.tools
Featured
Vajra

UI-based tool with multiple techniques for attacking and enumerating Azure and AWS environment.

brutespray on offsec.tools
Featured
brutespray

Automatically attempts default creds on found services based on Nmap output.

PortSwigger WebSecurity Academy on offsec.tools
Featured
PortSwigger WebSecurity Academy

Free, online web security training from the creators of Burp Suite.

Freddy Deserialization Bug Finder on offsec.tools
Featured
Freddy Deserialization Bug Finder

A Burp Suite extension to aid in detecting and exploiting serialisation libraries/APIs.

pyfiscan on offsec.tools
Featured
pyfiscan

Free web-application vulnerability and version scanner.

XSSwagger on offsec.tools
Featured
XSSwagger

A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks.

Shadow Workers on offsec.tools
Featured
Shadow Workers

C2 and proxy designed to help in the exploitation of XSS and malicious Service Workers.

mx-takeover on offsec.tools
Featured
mx-takeover

Focuses DNS MX records and detects misconfigured MX records.