View in browser

Weekly newsletter n°31

offsec.tools

A vast collection of security tools for bug bounty, pentest and red teaming
offsec.tools is a vast listing of security tools designed to help pentesters and bug hunters in their daily task. The list is organized by tags and provide a quick search engine. The list is feeded by the author and the community. Anyone can add a tool and be listed as a contributor, feel free to check the GitHub repository.

Go to offsec.tools

Tools featured this week

droopescan
A plugin-based scanner that aids security researchers in identifying issues with several CMSs.
depsdev
CLI client for deps.dev API.
GatherContacts
Burp Suite extension to pull employee names from Google and Bing LinkedIn search results.
MassDNS
A high-performance DNS stub resolver for bulk lookups and reconnaissance.
CloudFrunt
A tool for identifying misconfigured CloudFront domains.
GhostTrack
Useful tool to track location or mobile number.
dnsReaper
Subdomain takeover tool for attackers, bug bounty hunters and the blue team!
Legitify
Detect misconfigurations and security risks across GitHub and GitLab assets.
Burp-Encode-IP
Burp Suite extension to encode an IP address focused to bypass application IP/domain blacklist.
LinkedInDumper
Script that dumps employee data from the LinkedIn social networking platform.

Tools added last week

bxss.net
Web service that allows for detection Blind XSS vulnerabilities within web applications.

PrivacyNet
Allow users to route Internet traffic through Tor and hide their real IP address.

BounceBack
Stealth redirector for your red team operation security.

macchanger
Makes the maniputation of MAC addresses of network interfaces easier.

dnswalk
A DNS database debugger.

evil-winrm
The ultimate WinRM shell for hacking/pentesting.

netdiscover
Network address discovering tool.

volatility
The volatile memory extraction framework.

Want more to see more tools?

Go to offsec.tools

Sponsors