Offensive Security

Offensive security tools for penetration testing, red team exercises, exploit development, and ethical hacking activities.

Explore 455 curated cybersecurity tools, with 16,024+ visitors searching for solutions

FEATURED

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

Filter by:
tko-subs Logo

A tool for detecting and taking over subdomains with dead DNS records

0
Puredns Logo

A fast domain resolver and subdomain bruteforcing tool

0
docem Logo

A tool to embed XXE and XSS payloads in various file formats

0
DNS Rebind Toolkit Logo

A front-end JavaScript toolkit for creating DNS rebinding attacks

0
gowitness Logo

A Go-based command-line tool that uses Chrome Headless to automatically capture screenshots of web pages for reconnaissance and analysis purposes.

0
SSRFmap Logo

Automatic SSRF fuzzer and exploitation tool

0
LinkFinder Logo

A Python script that finds endpoints in JavaScript files to identify potential security vulnerabilities.

0
Razzer Logo

A Kernel fuzzer focusing on race bugs

0
sentrySSRF Logo

A tool to search for Sentry config on a page or in JavaScript files and check for blind SSRF

0
s3reverse Logo

A format conversion tool for S3 buckets designed to assist bug bounty hunters and security testers in standardizing bucket data during reconnaissance activities.

0
vaf Logo

A cross-platform web fuzzer written in Nim

0
takeover Logo

A tool for testing subdomain takeover possibilities at a mass scale.

0
getJS Logo

A tool to quickly get all JavaScript sources/files

0
Fuzzilli Logo

Fuzzilli is a JavaScript engine fuzzer that helps identify vulnerabilities in JavaScript engines.

0
parameth Logo

A brute force parameter discovery tool for identifying hidden GET and POST parameters in web applications during security assessments.

0
JSONBee Logo

A tool to bypass Content Security Policy (CSP) restrictions

0
dnsx Logo

A fast and multi-purpose DNS toolkit for DNS reconnaissance and testing

0
ysoserial.net Logo

A payload generator that creates malicious deserialization payloads for testing .NET applications against insecure deserialization vulnerabilities.

0
GoLinkFinder Logo

A fast and minimal JS endpoint extractor

0
qsreplace Logo

A command-line tool that replaces all query string parameter values in URLs with a user-supplied value for security testing purposes.

0
xxeserv Logo

A mini webserver with FTP support for XXE payloads

0
AWSBucketDump Logo

A security tool for discovering and analyzing interesting files in AWS S3 buckets across multiple regions and bucket types.

0
ESC Logo

ESC is an interactive .NET SQL console client with enhanced SQL Server discovery and data exfiltration features designed for penetration testing and red team engagements.

0
jwtear Logo

A command-line tool for parsing, creating, and manipulating JWT tokens

0

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

13
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

7
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

5
OSINTLeak Logo

OSINTLeak is a tool for discovering and analyzing leaked sensitive information across various online sources to identify potential security risks.

5
Mandos Brief Cybersecurity Newsletter Logo

Weekly cybersecurity newsletter for security leaders and professionals

5
View Popular Tools →

FEATURED

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Offensive Security Tools - FAQ

Common questions about Offensive Security tools including selection guides, pricing, and comparisons.

Offensive security tools for penetration testing, red team exercises, exploit development, and ethical hacking activities.

Have more questions? Browse our categories or search for specific tools.