A vast collection of security tools for bug bounty, pentest and red teaming

#domains

SDBF on offsec.tools
SDBF

Smart DNS Brute Forcer.

NTLMRecon on offsec.tools
NTLMRecon

Enumerate information from NTLM authentication enabled web endpoints.

catphish on offsec.tools
catphish

Generate similar-looking domains for phishing attacks.

ADRecon on offsec.tools
ADRecon

Gather information about the Active Directory and generates a report.

UserEnum on offsec.tools
UserEnum

Domain user enumeration tool.

Rock-ON on offsec.tools
Rock-ON

All in one recon tool that just get a single domain name and do all of the work alone.

jackdaw on offsec.tools
jackdaw

Gather gather gather.

RidRelay on offsec.tools
RidRelay

Enumerate usernames on a domain where you have no creds by using SMB relay.

Domain Hunter on offsec.tools
Domain Hunter

Checks expired domains to determine good candidates for phishing and C2 domain names.

CloudFrunt on offsec.tools
CloudFrunt

A tool for identifying misconfigured CloudFront domains.

dnstwist on offsec.tools
dnstwist

A tool to monitor for potential spear phishing domains and send to Slack.

ADRT on offsec.tools
ADRT

Active Directory Report Tool.

haktldextract on offsec.tools
haktldextract

Extract domains/subdomains from URLs en masse.

gwdomains on offsec.tools
gwdomains

Sub domain wild card filtering tool.

SonarSearch on offsec.tools
SonarSearch

A rapid API for the project Sonar dataset.

SecurityTrails on offsec.tools
SecurityTrails

Data for Security companies, researchers and teams.

windapsearch on offsec.tools
windapsearch

Enumerate users, groups and computers from a Windows domain through LDAP queries.

EDD on offsec.tools
EDD

Ultimate domain enumeration tool.

domain_hunter on offsec.tools
domain_hunter

Try to find all subdomains, similar-domains and related-domains of an organization.

TLD Scanner on offsec.tools
TLD Scanner

Scan all possible TLD's for a given domain name.

espionage on offsec.tools
espionage

Collects informations related to domains whois, history, dns records and more.

#dns   #domains   #osint  

Spoofy on offsec.tools
Spoofy

Checks if a list of domains can be spoofed based on SPF and DMARC records.

MSDorkDump on offsec.tools
MSDorkDump

Google Dork File Finder.

dnsenum on offsec.tools
dnsenum

Enumerates DNS information of a domain and to discover non-contiguous ip blocks.

SpiderFoot on offsec.tools
SpiderFoot

Automates OSINT for threat intelligence and mapping your attack surface.

related-domains on offsec.tools
related-domains

Find related domains of a given domain.