View in browser

Weekly newsletter n°53

offsec.tools

A vast collection of security tools for bug bounty, pentest and red teaming
offsec.tools is a vast listing of security tools designed to help pentesters and bug hunters in their daily task. The list is organized by tags and provide a quick search engine. The list is feeded by the author and the community. Anyone can add a tool and be listed as a contributor, feel free to check the GitHub repository.

Go to offsec.tools

Tools featured this week

Subjack
Subdomain Takeover tool written in Go.
PoshC2
A proxy aware C2 framework used to aid with post-exploitation and lateral movement.
dnscan
Python wordlist-based DNS subdomain scanner.
PhoneInfoga
Information gathering framework for phone numbers.
cnames
Take a list of resolved subdomains and output any corresponding CNAMES en masse.
Klyda
Highly configurable script for dictionary/spray attacks against online web applications.
S3Viewer
Publicly open storage viewer.
clairvoyance
Obtain GraphQL API Schema even if the introspection is not enabled.
X8
Hidden parameters discovery suite.
GPT_Vuln-Analyzer
A powerful network scanner, DNS recon, subdomain enumeration and IP Geolocator tool powered by GPT.

Tools added last week

Seatbelt
Performs security oriented safety checks relevant from offensive/defensive security perspectives.

Valid8Proxy
Tool designed for fetching, validating, and storing working proxies.

NetProbe
A tool you can use to scan for devices on your network.

SiCat
Advanced exploit search tool designed to identify and gather information about exploits.

Powermad
PowerShell MachineAccountQuota and DNS exploit tools.

Kekeo
A little toolbox to play with Microsoft Kerberos in C.

Invoke-ACLPwn
Automates the discovery and pwnage of ACLs in Active Directory that are unsafe configure.

Genzai
Helps to identify IoT related dashboards and scan them for default passwords.

Want to see more tools?

Go to offsec.tools

Sponsors