Home / Security Testing / Offensive Security

Offensive Security

Offensive security testing uncovers vulnerabilities through simulated attacks.

Try these 279 AI Offensive Security Tools

shad0w
Free

shad0w

A script to enumerate Google Storage buckets and determine access and privilege escalation

Shadow Workers
Free

Shadow Workers

A standalone man-in-the-middle attack framework used for phishing login credentials and bypassing 2-factor authentication.

SharpEDRChecker
Free

SharpEDRChecker

Pwndrop is a self-deployable file hosting service for red teamers, allowing easy upload and sharing of payloads over HTTP and WebDAV.

SharpC2
Free

SharpC2

AzureC2Relay enhances security by validating and relaying Cobalt Strike beacon traffic through Azure Functions.

SharpPrinter
Free

SharpPrinter

A tool that simplifies the installation of tools and configuration for Kali Linux

SharpShares
Free

SharpShares

A tool for detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities

SharpSploit
Free

SharpSploit

A collection of Python scripts for password spraying attacks against Lync/S4B & OWA, featuring Atomizer, Vaporizer, Aerosol, and Spindrift tools.

SigThief
Free

SigThief

Generates randomized C2 profiles for Cobalt Strike to evade detection.

SILENTTRINITY
Free

SILENTTRINITY

A comprehensive malware-analysis tool that utilizes external AV scanners to identify malicious elements in binary files.

Simulator
Free

Simulator

Generates randomized C2 profiles for Cobalt Strike to evade detection.

sixnet-tools
Free

sixnet-tools

A modern post-exploitation command and control framework with a client-server architecture and extensibility features.

Skyhook
Free

Skyhook

A repository containing material for Android greybox fuzzing with AFL++ Frida mode

Sliver
Free

Sliver

A guide on basic Linux privilege escalation techniques including enumeration, data analysis, exploit customization, and trial and error.

SmashTheStack Wargaming Network
Free

SmashTheStack Wargaming Network

OWASP OWTF is a penetration testing framework focused on efficiency and alignment with security standards.

SMOD
Free

SMOD

GNU/Linux Wireless distribution for security testing with XFCE desktop environment.

Social Engineering Attacks
Free

Social Engineering Attacks

Metta is an information security preparedness tool for adversarial simulation.

Social-Engineer Toolkit (SET)
Free

Social-Engineer Toolkit (SET)

A practical guide on NTLM relaying for Active Directory attacks.

Splunk Attack Range
Free

Splunk Attack Range

Interactive online malware sandbox for real-time analysis and threat intelligence

SSH MITM v2.3-dev
Free

SSH MITM v2.3-dev

Collection of vulnerable ARM binaries for beginner vulnerability researchers & exploit developers.

SSRF-Sheriff
Free

SSRF-Sheriff

A front-end JavaScript toolkit for creating DNS rebinding attacks

SSTImap
Free

SSTImap

An exploration of a new method to abuse DCOM for remote payload execution and lateral movement.