Penetration Testing

Penetration testing tools and frameworks for manual security testing, exploit development, and vulnerability validation.

Explore 34 curated cybersecurity tools, with 14,630+ visitors searching for solutions

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

Dradis Community Edition (CE) Logo

Open-source platform for pentest reporting and security team collaboration

0
Pentesting Payloads Logo

A web-based payload repository that generates and encodes ready-to-use exploits for SQL injection, XSS, file inclusion, and command injection vulnerabilities.

0
PlexTrac Logo

PlexTrac is a centralized platform for penetration test reporting and threat exposure management that helps security teams streamline assessment workflows, prioritize remediation, and track security posture improvements.

0
Cyver Core Logo

A pentest management platform that automates reporting workflows, provides client collaboration tools, and streamlines the entire penetration testing lifecycle from scoping to remediation.

0
Burp Suite Professional Logo

A web application security testing platform that combines manual and automated testing tools for conducting comprehensive security assessments and penetration testing.

1
Interlace Logo

A tool to easily automate and multithread your pentesting and bug bounty workflow without any coding

0
Metasploit Logo

A penetration testing framework for identifying and exploiting vulnerabilities.

1
GraphQLmap Logo

A scripting engine for interacting with GraphQL endpoints for pentesting purposes.

0
SQLi-Hunter Logo

SQLi-Hunter is an HTTP/HTTPS proxy server and SQLMAP API wrapper that simplifies the identification and exploitation of SQL injection vulnerabilities in web applications.

0
dotdotpwn Logo

A directory traversal fuzzer for finding and exploiting directory traversal vulnerabilities.

0
headi Logo

A tool for automated HTTP header injection

0
xsshunter_client Logo

A correlated injection proxy tool that integrates with XSS Hunter for automated cross-site scripting vulnerability testing and payload tracking.

0
bugcrowd-levelup-subdomain-enumeration Logo

Educational repository containing materials on advanced subdomain enumeration techniques from Bugcrowd LevelUp 2017 conference.

0
NoSql Injection CLI tool Logo

A command-line tool for identifying NoSQL injection vulnerabilities in MongoDB databases through automated scanning and reporting.

0
Sudomy Logo

A subdomain enumeration tool for bug hunting and pentesting

0
Turbo Intruder Logo

A Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.

0
xxexploiter Logo

A tool to help exploit XXE vulnerabilities by sending a crafted XML file to the server and parsing it to extract the data.

0
off-by-slash Logo

A Burp Suite extension that detects NGINX alias traversal vulnerabilities by analyzing HTTP traffic patterns to identify path traversal misconfigurations.

0
URO Logo

A tool to declutter URL lists for crawling and pentesting

0
Turbo Intruder Scripts Logo

A collection of customizable automation scripts for Turbo Intruder that facilitate vulnerability scanning, exploitation, and data extraction in penetration testing workflows.

0
eyeballer Logo

A tool for analyzing pentest screenshots using a convolutional neural network

0
ghauri Logo

An advanced cross-platform tool for detecting and exploiting SQL injection security flaws

0
FuzzDB Logo

FuzzDB is an open-source dictionary of attack patterns and predictable resource locations for dynamic application security testing and vulnerability discovery.

0
WS-Attacker Logo

Modular framework for web services penetration testing with support for various attacks.

0

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

10
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

6
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →