View in browser

Weekly newsletter n°21

offsec.tools

A vast collection of security tools for bug bounty, pentest and red teaming
offsec.tools is a vast listing of security tools designed to help pentesters and bug hunters in their daily task. The list is organized by tags and provide a quick search engine. The list is feeded by the author and the community. Anyone can add a tool and be listed as a contributor, feel free to check the GitHub repository.

Go to offsec.tools

Tools featured this week

JWT Tool
A toolkit for testing, tweaking and cracking JSON Web Tokens.
nmap-query-xml
A simple program to query nmap XML files in the terminal.
badsecrets
A library for detecting known secrets across many web frameworks.
webscreenshot
A simple script to screenshot a list of websites.
PCredz
This tool extracts secrets from a pcap file or from a live interface.
DNSTracer
Trace the path of a DNS query.
Eyeballer
Convolutional neural network for analyzing pentest screenshots.
autopwn
Specify targets and run sets of tools against them.
w3af
Web Application Attack and Audit Framework.
xray
Security assessment tool that supports common web security issue scanning and custom PoC.

Tools added last week

karma v2
Passive open source intelligence automated reconnaissance.

shosubgo
Small tool to grab subdomains using Shodan API.

bbot
OSINT automation for hackers.

resolvers
The most exhaustive list of reliable DNS resolvers.

FavFreak
Making favicon.ico based recon great again.

Kaeferjaeger
.

caido
A lightweight web security auditing toolkit.

BurpGPT
A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan.

ripgen
Rust-based high performance domain permutation generator.

go-stare
A fast & light web screenshot without headless browser but Chrome DevTools protocol.

evilgophish
Combination of evilginx3 and GoPhish.

GoPhish
Open-source phishing toolkit.

Want more to see more tools?

Go to offsec.tools

Sponsors