View in browser

Weekly newsletter n°19

offsec.tools

A vast collection of security tools for bug bounty, pentest and red teaming
offsec.tools is a vast listing of security tools designed to help pentesters and bug hunters in their daily task. The list is organized by tags and provide a quick search engine. The list is feeded by the author and the community. Anyone can add a tool and be listed as a contributor, feel free to check the GitHub repository.

Go to offsec.tools

Tools featured this week

extract-endpoints
Extract endpoints from source files.
yersinia
A framework for layer 2 attacks.
IAMagic
Advanced AWS access credentials scanner.
SSRFTest
SSRF testing tool.
msldap
LDAP library for auditing Microsoft Active Directory.
Tamper Data
View and modify HTTP requests before they are sent.
ADenum
Find misconfiguration through LDAP to exploit weaknesses with Kerberos.
Caldera
Automated adversary emulation platform.
STÖK Fredrik
STÖK Fredrik YouTube channel.
Striker
Offensive information and vulnerability scanner.

Tools added last week

AttifyOS
Distribution for pentesting IoT devices.

Empire
Post-exploitation and adversary emulation framework that is used to aid Red Teams and pentesters.

Starkiller
Starkiller is a frontend for Empire.

Caldera
Automated adversary emulation platform.

BloodHound
Six Degrees of Domain Admin.

CrackMapExec
A swiss army knife for pentesting networks.

Want more to see more tools?

Go to offsec.tools

Sponsors