Explore 37 curated tools and resources
OpenVAS is an open-source vulnerability scanner that provides extensive testing capabilities for identifying security weaknesses in networks and systems.
A hosted web application security testing tool that enables security researchers to register, activate their accounts, and scan web applications for vulnerabilities.
SecurityVulnerability.io simplifies the process of collecting, enriching, and presenting vulnerability information for both human and machine consumption.
A powerful directory/file, DNS and VHost busting tool written in Go.
A simple snippet to increment ../ on the URL.
Fast passive subdomain enumeration tool
A tool for identifying and extracting parameters from HTTP requests and responses
A tool for brute-forcing GET and POST parameters to discover potential vulnerabilities in web applications.
A bash script for scanning a target network for HTTP resources through XXE
A tool to discover new target domains using Content Security Policy
Powerfully simple endpoint security solution that takes down threats without interrupting business.
OWASP Project for making vulnerability management easier.
A framework for exploiting Android-based devices and applications
Korean cyber-security challenge platform for exploiting and defending web application vulnerabilities.
Automate your reconnaissance process with AttackSurfaceMapper, a tool for mapping and analyzing network attack surfaces.
A vulnerability scanner that helps you identify and fix vulnerabilities in your code
A cheat sheet for default credentials to aid in penetration testing and vulnerability assessment
A list of Windows privilege escalation techniques, categorized and explained in detail.
HTB Academy offers guided cybersecurity training with industry certifications to help you become a market-ready professional.
CSET is a free software tool for identifying vulnerabilities in enterprise and industrial control cyber systems.
A comprehensive web application security testing solution that offers built-in vulnerability assessment and management, as well as integration options with popular software development tools.
Cloud Security Suite (cs-suite) - Version 3.0 Usage for cloud security audits on AWS, GCP, Azure, and DigitalOcean.
AlienVault OSSIM provides an all-in-one security management solution with asset discovery, vulnerability assessment, and SIEM capabilities.
CAPEC™ is a comprehensive dictionary of known attack patterns used by adversaries to exploit weaknesses in cyber-enabled capabilities.
A structured approach for conducting penetration tests with seven main sections covering all aspects of the test.
Vim syntax-highlighting plugin for YARA rules with support up to v4.3.
Hands-on cybersecurity training and testing platform with 1800+ labs
Kali Linux is a specialized Linux distribution for cybersecurity professionals, focusing on penetration testing and security auditing.
A platform providing an activity feed on exploited vulnerabilities.
Nessus efficiently scans for system vulnerabilities, misconfigurations, and compliance issues.
A wargaming network for penetration testers to practice their skills in a realistic environment.
Advanced vulnerability assessment tool for gaining visibility and preventing cyber attacks.
A vulnerability assessment and management tool that uses patented technology to accurately identify vulnerabilities and prioritize them by risk.
List of publicly disclosed vulnerabilities with security filters and detailed advisories.
A comprehensive IT infrastructure automation platform for managing hybrid infrastructure through configuration, patch, and security management.
A Java based HTTP/HTTPS proxy for assessing web application vulnerability with various useful features.
Vulnerable Android application for learning security concepts.
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.