Free Cybersecurity Tools

Find the right solution for your security needs without any cost.

Explore 2630 curated cybersecurity tools, with 16,024+ visitors searching for solutions

FEATURED

Hudson Rock Cybercrime Intelligence Tools Logo

Cybercrime intelligence tools for searching compromised credentials from infostealers

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

FREE

XSStrike Logo

A powerful tool for identifying and exploiting Cross-Site Scripting (XSS) vulnerabilities.

0
Can I take over XYZ? Logo

A list of services and how to claim (sub)domains with dangling DNS records.

0
Blinder Logo

A Python library for automating time-based blind SQL injection attacks

0
s3tk Logo

A security toolkit for Amazon S3 that provides bucket scanning, policy validation, ACL management, and encryption features to identify and remediate S3 security vulnerabilities.

0
BlackWidow Logo

BlackWidow is a Python-based web application scanner that combines OSINT gathering with automated fuzzing to identify OWASP vulnerabilities in target websites.

0
Andor Logo

A blind SQL injection tool written in Golang

0
censys-enumeration Logo

A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.

0
oxml_xxe Logo

A tool for embedding XXE/XML exploits into different filetypes

0
httprebind Logo

Automatic tool for DNS rebinding-based SSRF attacks

0
python-builtwith Logo

A Python API client for BuiltWith that enables programmatic access to website technology profiling and reconnaissance data.

0
2tearsinabucket Logo

A tool for enumerating and analyzing Amazon S3 buckets associated with specific targets to identify potential security misconfigurations.

0
surf Logo

A tool for identifying and exploiting SSRF vulnerabilities in modern cloud environments by filtering host lists to find viable attack candidates.

0
fuzz.txt Logo

A GitHub repository for fuzzing and testing file formats

0
HostileSubBruteforcer Logo

A tool for bruteforcing subdomains of a given domain

0
DOMdig Logo

DOMdig is a DOM XSS scanner that uses static analysis, dynamic analysis, and fuzz testing to detect and exploit Cross-Site Scripting vulnerabilities in Single Page Applications.

0
BurpJSLinkFinder Logo

A Burp Suite extension that passively scans JavaScript files to discover endpoint links and potential attack surfaces in web applications.

0
cariddi Logo

An automated reconnaissance tool that crawls domains to discover URLs and scan for exposed secrets, API keys, and sensitive files during security assessments.

0
Nosey Parker Logo

A command-line tool that scans textual data and Git history to identify and locate secrets, API keys, passwords, and other sensitive information.

0
XSSOauthPersistence Logo

Maintaining account persistence via XSS and Oauth

0
jwt_tool Logo

A toolkit for testing, tweaking and cracking JSON Web Tokens

0
ysoserial Logo

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

0
Secret Bridge Logo

Secret Bridge monitors GitHub repositories to detect and alert on leaked secrets and sensitive data exposure.

0
Nuclei Logo

Fast and customizable vulnerability scanner

0
censys-subdomain-finder Logo

A tool for performing subdomain enumeration using Censys API

0