Home / Security Testing / Offensive Security

Offensive Security

Offensive security testing uncovers vulnerabilities through simulated attacks.

Try these 279 AI Offensive Security Tools

ExploitDB
Free

ExploitDB

Insights on Red Teaming for Pacific Rim CCDC 2016 competition, focusing on preparation, operations plan, and automation.

external_c2 framework
Free

external_c2 framework

Sublist3r is a python tool for enumerating subdomains using OSINT and various search engines.

ezXSS
Free

ezXSS

Back-end component for red team operations with crucial design considerations.

FDsploit
Free

FDsploit

A macOS Initial Access Payload Generator for penetration testing and red teaming exercises.

Finshir
Free

Finshir

A Ruby framework designed to aid in the penetration testing of WordPress systems.

FOCA (Fingerprinting Organizations with Collected Archives)
Free

FOCA (Fingerprinting Organizations with Collected Archives)

A command that builds and executes command lines from standard input, allowing for the execution of commands with multiple arguments.

GadgetToJScript
Free

GadgetToJScript

A post-exploitation framework designed to operate covertly on heavily monitored environments.

Gato
Free

Gato

A digital archive of the internet, allowing users to capture and browse archived web pages.

GCPBucketBrute
Free

GCPBucketBrute

SauronEye helps in identifying files containing sensitive data such as passwords through targeted directory searches.

GEF (pronounced ʤɛf - 'Jeff')
Free

GEF (pronounced ʤɛf - 'Jeff')

Abusing SCF files to gather user hashes from an unauthenticated writable Windows-based file share.

GitHub Actions Attack Diagram
Free

GitHub Actions Attack Diagram

PwnAuth is an open-source tool for generating and managing authentication tokens for penetration testing and red teaming exercises.

Gospider
Free

Gospider

A tool for iOS pentesting and research with a GUI version available.

GraphQLmap
Free

GraphQLmap

Rip web accessible (distributed) version control systems: SVN, GIT, Mercurial/hg, bzr, ...

GraphSpy
Free

GraphSpy

A DNS rebinding attack framework for security researchers and penetration testers.

Grendel-Scan
Free

Grendel-Scan

Collection of penetration testing scripts for AWS with a focus on reconnaissance.

Habu Hacking Toolkit
Free

Habu Hacking Toolkit

A wargaming network for penetration testers to practice their skills in a realistic environment.

hakrawler
Free

hakrawler

BeEF is a specialized penetration testing tool for exploiting web browser vulnerabilities to assess security.

Harpoon
Free

Harpoon

A scripting engine for interacting with GraphQL endpoints for pentesting purposes.

Hash Extender
Free

Hash Extender

A collection of payloads and methodologies for web pentesting.

httprebind
Free

httprebind

SauronEye helps in identifying files containing sensitive data such as passwords through targeted directory searches.