Home / Security Testing / Offensive Security

Offensive Security

Offensive security testing uncovers vulnerabilities through simulated attacks.

Try these 279 AI Offensive Security Tools

Burp-LFI-tests
Free

Burp-LFI-tests View Burp-LFI-tests

A unified repository for different Metasploit Framework payloads.

Burp Suite Professional
Free

Burp Suite Professional View Burp Suite Professional

A guide on using Apache mod_rewrite to strengthen phishing attacks and bypass mobile device restrictions

C2concealer
Free

C2concealer View C2concealer

Emulates Docker HTTP API with event logging and AWS deployment script.

C3
Free

C3 View C3

Preparation process for participating in the Pacific Rim CCDC 2015.

Caldera
Free

Caldera View Caldera

A black-box obfuscation tool for Android apps with Android App Bundle support.

cariddi
Free

cariddi View cariddi

APT Simulator is a tool for simulating a compromised system on Windows.

Charlotte
Free

Charlotte View Charlotte

Utilizing Alternate Data Streams (ADS) to bypass AppLocker default policies by loading DLL/CPL binaries.

Chaos Client
Free

Chaos Client View Chaos Client

A PowerShell toolkit for attacking Azure environments

Chameleon
Free

Chameleon View Chameleon

Skyhook facilitates obfuscated HTTP file transfers to bypass IDS detections, enhancing secure data exchange.

ClickOnce (Twice or Thrice): A Technique for Social Engineering and (Un)trusted Command Execution
Free

ClickOnce (Twice or Thrice): A Technique for Social Engineering and (Un)trusted Command Execution View ClickOnce (Twice or Thrice): A Technique for Social Engineering and (Un)trusted Command Execution

A document that helps inform red team planning by contrasting against the very specific red team style described in Red Teams.

CloakifyFactory
Free

CloakifyFactory View CloakifyFactory

A blog post discussing the often overlooked dangers of CSV injection in applications.

Cobalt Strike Malleable C2 Design and Reference Guide
Free

Cobalt Strike Malleable C2 Design and Reference Guide View Cobalt Strike Malleable C2 Design and Reference Guide

A framework for testing and exploiting race conditions in software

Cobalt Strike HTTP C2 Redirectors with Apache mod_rewrite
Free

Cobalt Strike HTTP C2 Redirectors with Apache mod_rewrite View Cobalt Strike HTTP C2 Redirectors with Apache mod_rewrite

A toolkit to attack Office365, including tools for password spraying, password cracking, token manipulation, and exploiting vulnerabilities in Office365 APIs and services.

Cobalt Strike's ExternalC2 framework
Free

Cobalt Strike's ExternalC2 framework View Cobalt Strike's ExternalC2 framework

Caldera is a cybersecurity framework by MITRE for automated security assessments and adversary emulation.

Combatting Incident Responders with Apache mod_rewrite
Free

Combatting Incident Responders with Apache mod_rewrite View Combatting Incident Responders with Apache mod_rewrite

A tool that visits suspected phishing pages, takes screenshots, and extracts interesting files.

Commix
Free

Commix View Commix

Tool for randomizing Cobalt Strike Malleable C2 profiles to evade static, signature-based detection controls.

Covert Red Team Attack Infrastructure
Free

Covert Red Team Attack Infrastructure View Covert Red Team Attack Infrastructure

A collection of resources for practicing penetration testing

tryharder
Free

tryharder View tryharder

A set of commands for exploit developers and reverse-engineers to enhance GDB functionality.

Covenant
Free

Covenant View Covenant

A managed code hooking template for .NET assemblies, enabling API hooking, code injection, and runtime manipulation.

CrackMapExec
Free

CrackMapExec View CrackMapExec

A list of useful payloads and bypasses for Web Application Security.

CrackMapExec (CME)
Free

CrackMapExec (CME) View CrackMapExec (CME)

Data exfiltration & infiltration tool using text-based steganography to evade security controls.

CredMaster
Free

CredMaster View CredMaster

A full-featured reconnaissance framework for web-based reconnaissance with a modular design.

CrossC2
Free

CrossC2 View CrossC2

Check if a domain is in the Alexa or Cisco top one million domain list.