Offensive Security
Offensive security testing uncovers vulnerabilities through simulated attacks.
Try these 279 AI Offensive Security Tools
LockBoxx
A project for demonstrating AWS attack techniques with a focus on ethical hacking practices.
Loading Alternate Data Stream (ADS) DLL/CPL Binaries to Bypass AppLocker
A project for demonstrating AWS attack techniques with a focus on ethical hacking practices.
Majestic Million
Python utility for testing the existence of domain names under different TLDs to find malicious subdomains.
MadKing Amazon Web Services Attack Platform
Offensive security tool for reconnaissance and information gathering with a wide range of features and future roadmap.
MagSpoof
GraphSpy is a token management tool that allows users to store and manage access and refresh tokens for multiple users and scopes in one location.
Maigret The Commissioner
A comprehensive .NET post-exploitation library designed for advanced security testing.
Metasploit Payloads
Local pentest lab using docker compose to spin up victim and attacker services.
Metasploit
FOCA is a tool used to find metadata and hidden information in scanned documents, with capabilities to analyze various file types and extract EXIF information.
MFFA - Media Fuzzing Framework for Android
Comprehensive host-survey tool for security checks in C#.
MicroBurst
Local pentest lab using docker compose to spin up victim and attacker services.
mimikatz
CLI tool for offensive and defensive security assessments on the Joi validator library with a wide range of attacks.
MimiPenguin 2.0
An exploration of a new method to abuse DCOM for remote payload execution and lateral movement.
MiniCPS
A tool for mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
MITRE Caldera™
Chameleon aids in evading proxy categorization to bypass internet filters.
Moki Linux
A modular, menu-driven tool for building repeatable, time-delayed, distributed security events.
Mod_Rewrite for Red Team Infrastructure
CTF toolkit for rapid exploit development and prototyping.
Modlishka
XAHICO Web Platform is a cloud-based solution for vulnerability detection, penetration testing, and adversary simulation, accessible through web browsers and suitable for various user levels.
Mortar
Learn how to create new Malleable C2 profiles for Cobalt Strike to avoid detection and signatured toolset