View in browser

Weekly newsletter n°2

offsec.tools

A vast collection of security tools for bug bounty, pentest and red teaming
offsec.tools is a vast listing of security tools designed to help pentesters and bug hunters in their daily task. The list is organized by tags and provide a quick search engine. The list is feeded by the author and the community. Anyone can add a tool and be listed as a contributor, feel free to check the GitHub repository.
Go to offsec.tools

Tools featured this week

Yoga
Your OSINT Graphical Analyzer.
ffuf
Fast web fuzzer written in Go.
qsreplace
Accept URLs on stdin, replace all query string values with a user-supplied value.
Fingerprinter
CMS/LMS/Library etc Versions Fingerprinter.
Masscan
TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
AWSBucketDump
Security Tool to Look For Interesting Files in S3 Buckets.
XSStrike
Most advanced XSS scanner.
pypykatz
Mimikatz implementation in pure Python.
BeEF
The Browser Exploitation Framework is a penetration testing tool that focuses on the web browser.
Sherlock
Hunt down social media accounts by username across social networks.

Tools added this week

hunter.how
Internet search engines for security researchers.

sslstrip
A tool for exploiting Moxie Marlinspike's SSL "stripping" attack.

Splunk
The unified security and observability platform.

NetWitness
Rapidly detect and respond to any threat, anywhere. See Everything. Fear Nothing.

Nagios
The industry standard in IT infrastructure monitoring.

Invicti
Web Application Security For Enterprise.

WebInspect
An automated dynamic testing solution that provides comprehensive vulnerability detection.

nipper-ng
Network infrastructure configuration parser.

NetworkMiner
Network forensic analysis tool for Windows.

wikto
Nikto for Windows with some extra features.

p0f
Identify the operating system of a target host simply by examining captured packets.

Sguil
The analyst console for network security monitoring.

Samurai WTF
The best security training environment for developers and AppSec professionals.

Tamper Data
View and modify HTTP requests before they are sent.

Tamper Dev
Allows you to intercept and edit HTTP/HTTPS requests and responses.

ratproxy
A semi-automated largely passive web application security audit tool.

KisMac
A free, open source wireless stumbling and security tool for Mac OS X.

ike-scan
Discover and fingerprint IKE hosts.

amap
Identify applications even if they are running on a different port than normal.

Grendel-Scan
A tool for automated security scanning of web applications.

Dradis
Collaboration and reporting for infosec teams made simple.

nbtscan
Scan networks searching for NetBIOS information.

Unicornscan
An asynchronous TCP and UDP port scanner.

Kali Linux
The most advanced penetration testing distribution.

upload_bypass
File upload restrictions bypass by using different techniques!

Quickjack
Point-and-click tool for producing advanced clickjacking and frame-slicing attacks.

Want more to see more tools?

Go to offsec.tools

Sponsors