View in browser

Weekly newsletter n°43

offsec.tools

A vast collection of security tools for bug bounty, pentest and red teaming
offsec.tools is a vast listing of security tools designed to help pentesters and bug hunters in their daily task. The list is organized by tags and provide a quick search engine. The list is feeded by the author and the community. Anyone can add a tool and be listed as a contributor, feel free to check the GitHub repository.

Go to offsec.tools

Tools featured this week

SiteBroker
Utility for information gathering and penetration testing automation.
InsiderPhD
InsiderPhD Youtube channel.
Agartha
Burp Suite extension for dynamic payload generation to detect injection flaws.
CSRFT
A lightweight CSRF Toolkit for easy Proof of Concept.
Hackability
Probe a rendering engine for vulnerabilities and other features.
H1 Report Finder
A burpsuite extension to find security reports published on HackerOne based on the selected host.
FOCA
Tool to find metadata and hidden information in the documents.
jSQL Injection
Java application for automatic SQL database injection.
ILSpy
NET Decompiler with support for PDB generation, ReadyToRun, Metadata (&more) - cross-platform!.
git-dumper
A tool to dump a git repository from a website.

Tools added last week

tsunami-security-scanner
Network security scanner with an extensible plugin system.

sonarqube
Continuous inspection.

objection
Runtime mobile exploration.

peda
Python Exploit Development Assistance for GDB.

axiom
Distribute the workload of many different scanning tools with ease.

wifijammer
Continuously jam all wifi clients/routers.

EagleEye
Stalk your friends on social media using image recognition and reverse image search.

PhoneSploit-Pro
Remotely exploit Android devices using ADB and Metasploit.

nodejsscan
A static security code scanner for Node.js applications.

Modlishka
A powerful and flexible HTTP reverse proxy.

SocialFish
Phishing tool & information collector.

Want to see more tools?

Go to offsec.tools

Sponsors