View in browser

Weekly newsletter n°46

offsec.tools

A vast collection of security tools for bug bounty, pentest and red teaming
offsec.tools is a vast listing of security tools designed to help pentesters and bug hunters in their daily task. The list is organized by tags and provide a quick search engine. The list is feeded by the author and the community. Anyone can add a tool and be listed as a contributor, feel free to check the GitHub repository.

Go to offsec.tools

Tools featured this week

subjs
Fetches javascript file from a list of URLS or subdomains.
holehe
Check if the mail is used on different sites and retrieve informations on sites.
gitjacker
Leak git repositories from misconfigured websites.
theHarvester
E-mails, subdomains and names Harvester.
Kaeferjaeger
Lists of resources: cdn ranges, ips ranges, sni ip ranges...
The Social-Engineer Toolkit
Open-source penetration testing framework designed for social engineering.
ripgen
Rust-based high performance domain permutation generator.
hrekt
A really fast HTTP prober.
NTLMRecon
Enumerate information from NTLM authentication enabled web endpoints.
msLDAPDump
LDAP enumeration tool implemented in Python3.

Tools added last week

sulley
A pure-python fully automated and unattended fuzzing framework.

boofuzz
Network protocol fuzzing for humans.

RedEye
RedEye is a visual analytic tool supporting Red & Blue Team operations.

ThreatMapper
Open source cloud native security observability platform. Linux, K8s, AWS Fargate and more.

OSINT-Framework
OSINT Framework.

atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.

MITRE ATT&CK
Knowledge base of adversary tactics and techniques based on real-world observations.

kerbrute
Bruteforce and enumerate Active Directory accounts through Kerberos pre-authentication.

RedELK
Tool for Red Teams used for tracking and alarming about Blue Team activities.

DSStoreView
DS_Store file parser/viewer.

Want to see more tools?

Go to offsec.tools

Sponsors