Home / Security Testing / Offensive Security

Offensive Security

Offensive security testing uncovers vulnerabilities through simulated attacks.

Try these 279 AI Offensive Security Tools

ExploitDB
Free

ExploitDB View ExploitDB

Insights on Red Teaming for Pacific Rim CCDC 2016 competition, focusing on preparation, operations plan, and automation.

exploit_me
Free

exploit_me View exploit_me

A PowerShell toolkit for attacking Azure environments

external_c2 framework
Free

external_c2 framework View external_c2 framework

Sublist3r is a python tool for enumerating subdomains using OSINT and various search engines.

ezXSS
Free

ezXSS View ezXSS

Back-end component for red team operations with crucial design considerations.

FDsploit
Free

FDsploit View FDsploit

A macOS Initial Access Payload Generator for penetration testing and red teaming exercises.

Finshir
Free

Finshir View Finshir

A Ruby framework designed to aid in the penetration testing of WordPress systems.

FOCA (Fingerprinting Organizations with Collected Archives)
Free

FOCA (Fingerprinting Organizations with Collected Archives) View FOCA (Fingerprinting Organizations with Collected Archives)

A command that builds and executes command lines from standard input, allowing for the execution of commands with multiple arguments.

GadgetToJScript
Free

GadgetToJScript View GadgetToJScript

A post-exploitation framework designed to operate covertly on heavily monitored environments.

Gato
Free

Gato View Gato

A digital archive of the internet, allowing users to capture and browse archived web pages.

GCPBucketBrute
Free

GCPBucketBrute View GCPBucketBrute

SauronEye helps in identifying files containing sensitive data such as passwords through targeted directory searches.

GEF (pronounced ʤɛf - 'Jeff')
Free

GEF (pronounced ʤɛf - 'Jeff') View GEF (pronounced ʤɛf - 'Jeff')

Abusing SCF files to gather user hashes from an unauthenticated writable Windows-based file share.

GitHub Actions Attack Diagram
Free

GitHub Actions Attack Diagram View GitHub Actions Attack Diagram

PwnAuth is an open-source tool for generating and managing authentication tokens for penetration testing and red teaming exercises.

Gospider
Free

Gospider View Gospider

A tool for iOS pentesting and research with a GUI version available.

GraphQLmap
Free

GraphQLmap View GraphQLmap

Rip web accessible (distributed) version control systems: SVN, GIT, Mercurial/hg, bzr, ...

GraphSpy
Free

GraphSpy View GraphSpy

A DNS rebinding attack framework for security researchers and penetration testers.

Grendel-Scan
Free

Grendel-Scan View Grendel-Scan

Collection of penetration testing scripts for AWS with a focus on reconnaissance.

Habu Hacking Toolkit
Free

Habu Hacking Toolkit View Habu Hacking Toolkit

A wargaming network for penetration testers to practice their skills in a realistic environment.

hakrawler
Free

hakrawler View hakrawler

BeEF is a specialized penetration testing tool for exploiting web browser vulnerabilities to assess security.

Harpoon
Free

Harpoon View Harpoon

A scripting engine for interacting with GraphQL endpoints for pentesting purposes.

Hash Extender
Free

Hash Extender View Hash Extender

A collection of payloads and methodologies for web pentesting.

httprebind
Free

httprebind View httprebind

SauronEye helps in identifying files containing sensitive data such as passwords through targeted directory searches.