Offensive Security for Security Testing

Task: Security Testing

Explore 77 curated cybersecurity tools, with 15,538+ visitors searching for solutions

FEATURED

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

Filter by:
PTJunior Logo

AI agent that autonomously discovers, exploits, and documents vulnerabilities.

3
weaponised-XSS-payloads Logo

A collection of XSS payloads designed to turn alert(1) into P1

0
xssor2 Logo

A tool for testing and exploiting Cross-Site Scripting (XSS) vulnerabilities.

0
IntruderPayloads Logo

A collection of payloads and methodologies for web pentesting.

0
surf Logo

A tool for identifying and exploiting SSRF vulnerabilities in modern cloud environments by filtering host lists to find viable attack candidates.

0
LinksDumper Logo

LinksDumper extracts links and endpoints from HTTP responses to support web application security testing and reconnaissance activities.

0
Razzer Logo

A Kernel fuzzer focusing on race bugs

0
s3reverse Logo

A format conversion tool for S3 buckets designed to assist bug bounty hunters and security testers in standardizing bucket data during reconnaissance activities.

0
vaf Logo

A cross-platform web fuzzer written in Nim

0
takeover Logo

A tool for testing subdomain takeover possibilities at a mass scale.

0
Fuzzilli Logo

Fuzzilli is a JavaScript engine fuzzer that helps identify vulnerabilities in JavaScript engines.

0
parameth Logo

A brute force parameter discovery tool for identifying hidden GET and POST parameters in web applications during security assessments.

0
ysoserial.net Logo

A payload generator that creates malicious deserialization payloads for testing .NET applications against insecure deserialization vulnerabilities.

0
qsreplace Logo

A command-line tool that replaces all query string parameter values in URLs with a user-supplied value for security testing purposes.

0
AWSBucketDump Logo

A security tool for discovering and analyzing interesting files in AWS S3 buckets across multiple regions and bucket types.

0
racepwn Logo

A framework for testing and exploiting race condition vulnerabilities through concurrent request analysis and timing attack automation.

0
GitTools Logo

A collection of three tools for extracting, dumping, and scanning exposed .git repositories on websites to identify sensitive information and security vulnerabilities.

0
screenshoteer Logo

A command-line tool for capturing automated screenshots of websites and mobile applications with support for multiple browsers and device emulations.

0
Whonow Logo

A malicious DNS server that executes DNS Rebinding attacks on-demand to bypass same-origin policy restrictions and access internal network resources.

0
requests-racer Logo

A Python library that simplifies testing and exploiting race conditions in web applications using concurrent HTTP requests.

0
jwt-key-id-injector Logo

A simple Python script to test for a hypothetical JWT vulnerability

0
getsploit Logo

A command line utility for searching and downloading exploits from multiple exploit databases including Exploit-DB and Packet Storm.

0
Yar Logo

Yar is a reconnaissance tool for scanning organizations, users, and repositories to identify vulnerabilities and security risks during security assessments.

0
OneFuzz Logo

OneFuzz is a self-hosted Fuzzing-As-A-Service platform developed by Microsoft that enables continuous developer-driven security testing through automated fuzzing capabilities.

0