Domain Hunter is a tool that checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names. It helps identify potential domains for malicious activities. The tool provides a comprehensive analysis of expired domains, including their categorization, reputation, and history on Archive.org. This information can be used to identify domains that could be used for phishing or as command and control (C2) servers. Domain Hunter is a useful tool for security professionals and researchers who want to identify and mitigate potential threats from expired domains.
FEATURES
ALTERNATIVES
Modlishka is a reverse proxy tool for intercepting and manipulating HTTP traffic, ideal for penetration testers, security researchers, and developers to analyze and test web applications.
A penetration testing tool for intercepting SSH connections and logging plaintext passwords.
A collection of resources for practicing penetration testing
Local pentest lab using docker compose to spin up victim and attacker services.
A collaborative, multi-platform, red teaming framework for simulating attacks and testing defenses.
A guide on basic Linux privilege escalation techniques including enumeration, data analysis, exploit customization, and trial and error.
A tool for mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
PINNED

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

PTJunior
An AI-powered penetration testing platform that autonomously discovers, exploits, and documents vulnerabilities while generating NIST-compliant reports.

CTIChef.com Detection Feeds
A tiered cyber threat intelligence service providing detection rules from public repositories with varying levels of analysis, processing, and guidance for security teams.

ImmuniWeb® Discovery
ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.