|
| 1 | +Tool,Link,Description |
| 2 | +arsenal,https://github.com/Orange-Cyberdefense/arsenal,Powerful weapons for penetration testing. |
| 3 | +asdf,https://github.com/asdf-vm/asdf,Extendable version manager with support for ruby python go etc |
| 4 | +assetfinder,https://github.com/tomnomnom/assetfinder,Tool to find subdomains and IP addresses associated with a domain. |
| 5 | +carbon14,https://github.com/Lazza/carbon14,OSINT tool for estimating when a web page was written. |
| 6 | +Censys,https://github.com/censys/censys-python,An easy-to-use and lightweight API wrapper for Censys APIs |
| 7 | +constellation,https://github.com/constellation-app/Constellation,Find and exploit vulnerabilities in mobile applications. |
| 8 | +creds,https://github.com/ihebski/DefaultCreds-cheat-sheet,One place for all the default credentials to assist pentesters during an engagement. This document has several products default login/password gathered from multiple sources. |
| 9 | +CyberChef,https://github.com/gchq/CyberChef/,The Cyber Swiss Army Knife |
| 10 | +dnsenum,https://github.com/fwaeytens/dnsenum,dnsenum is a tool for enumerating DNS information about a domain. |
| 11 | +exegol-history,https://github.com/ThePorgs/Exegol-history,Credentials management for Exegol |
| 12 | +exifprobe,https://github.com/hfiguiere/exifprobe,Exifprobe is a command-line tool to parse EXIF data from image files. |
| 13 | +exiftool,https://github.com/exiftool/exiftool,ExifTool is a Perl library and command-line tool for reading / writing and editing meta information in image / audio and video files. |
| 14 | +finalrecon,https://github.com/thewhiteh4t/FinalRecon,A web reconnaissance tool that gathers information about web pages |
| 15 | +findomain,https://github.com/findomain/findomain,The fastest and cross-platform subdomain enumerator. |
| 16 | +firefox,https://www.mozilla.org,A web browser |
| 17 | +fzf,https://github.com/junegunn/fzf,🌸 A command-line fuzzy finder |
| 18 | +GeoPincer,https://github.com/tloja/GeoPincer,GeoPincer is a script that leverages OpenStreetMap's Overpass API in order to search for locations. |
| 19 | +gf,https://github.com/tomnomnom/gf,A wrapper around grep to avoid typing common patterns |
| 20 | +githubemail,https://github.com/paulirish/github-email,a command-line tool to retrieve a user's email from Github. |
| 21 | +GoMapEnum,https://github.com/nodauf/GoMapEnum,Nothing new but existing techniques are brought together in one tool. |
| 22 | +goshs,https://github.com/patrickhener/goshs,Goshs is a replacement for Python's SimpleHTTPServer. It allows uploading and downloading via HTTP/S with either self-signed certificate or user provided certificate and you can use HTTP basic auth. |
| 23 | +gron,https://github.com/tomnomnom/gron,Make JSON greppable! |
| 24 | +h8mail,https://github.com/khast3x/h8mail,Email OSINT and breach hunting. |
| 25 | +holehe,https://github.com/megadose/holehe,mail osint tool finding out if it is used on websites. |
| 26 | +ignorant,https://github.com/megadose/ignorant,holehe but for phone numbers. |
| 27 | +imagemagick,https://github.com/ImageMagick/ImageMagick,ImageMagick is a free and open-source image manipulation tool used to create / edit / compose / or convert bitmap images. |
| 28 | +ipinfo,https://github.com/ipinfo/cli,Get information about an IP address or hostname. |
| 29 | +linkedin2username,https://github.com/initstring/linkedin2username,Generate a list of LinkedIn usernames from a company name. |
| 30 | +maigret,https://github.com/soxoj/maigret,Collects information about a target email (or domain) from Google and Bing search results |
| 31 | +maltego,https://www.paterva.com/web7/downloads.php,A tool used for open-source intelligence and forensics |
| 32 | +mdcat,https://github.com/swsnr/mdcat,Fancy cat for Markdown |
| 33 | +MurMurHash,https://github.com/QU35T-code/MurMurHash,This little tool is to calculate a MurmurHash value of a favicon to hunt phishing websites on the Shodan platform. |
| 34 | +neovim,https://neovim.io/,hyperextensible Vim-based text editor |
| 35 | +ngrok,https://github.com/inconshreveable/ngrok,Expose a local server behind a NAT or firewall to the internet |
| 36 | +objectwalker,https://github.com/p0dalirius/objectwalker,A python module to explore the object tree to extract paths to interesting objects in memory. |
| 37 | +osrframework,https://github.com/i3visio/osrframework,Include references to a bunch of different applications related to username checking / DNS lookups / information leaks research / deep web search / regular expressions extraction and many others. |
| 38 | +phoneinfoga,https://github.com/sundowndev/PhoneInfoga,Information gathering & OSINT framework for phone numbers. |
| 39 | +photon,https://github.com/s0md3v/Photon,a fast web crawler which extracts URLs / files / intel & endpoints from a target. |
| 40 | +pwndb,https://github.com/davidtavarez/pwndb,A command-line tool for searching the pwndb database of compromised credentials. |
| 41 | +pwnedornot,https://github.com/thewhiteh4t/pwnedOrNot,Check if a password has been leaked in a data breach. |
| 42 | +pyftpdlib,https://github.com/giampaolo/pyftpdlib/,Extremely fast and scalable Python FTP server library |
| 43 | +pymeta,https://github.com/m8sec/pymeta,Google and Bing scraping osint tool |
| 44 | +recon-ng,https://github.com/lanmaster53/recon-ng,External recon tool. |
| 45 | +recondog,https://github.com/s0md3v/ReconDog,a reconnaissance tool for performing information gathering on a target. |
| 46 | +rlwrap,https://github.com/hanslub42/rlwrap,rlwrap is a small utility that wraps input and output streams of executables / making it possible to edit and re-run input history |
| 47 | +rsync,https://packages.debian.org/sid/rsync,File synchronization tool for efficiently copying and updating data between local or remote locations |
| 48 | +searchsploit,https://gitlab.com/exploit-database/exploitdb,A command line search tool for Exploit-DB |
| 49 | +shellerator,https://github.com/ShutdownRepo/Shellerator,a simple command-line tool for generating shellcode |
| 50 | +Sherlock,https://github.com/sherlock-project/sherlock,Hunt down social media accounts by username across social networks. |
| 51 | +simplyemail,https://github.com/SimplySecurity/SimplyEmail,a scriptable command line tool for sending emails |
| 52 | +spiderfoot,https://github.com/smicallef/spiderfoot,A reconnaissance tool that automatically queries over 100 public data sources |
| 53 | +subfinder,https://github.com/projectdiscovery/subfinder,Tool to find subdomains associated with a domain. |
| 54 | +sublist3r,https://github.com/aboul3la/Sublist3r,a Python tool designed to enumerate subdomains of websites. |
| 55 | +theharvester,https://github.com/laramies/theHarvester,Tool for gathering e-mail accounts / subdomain names / virtual host / open ports / banners / and employee names from different public sources |
| 56 | +tig,https://github.com/jonas/tig,Tig is an ncurses-based text-mode interface for git. |
| 57 | +tor,https://github.com/torproject/tor,Anonymity tool that can help protect your privacy and online identity by routing your traffic through a network of servers. |
| 58 | +toutatis,https://github.com/megadose/Toutatis,Toutatis is a tool that allows you to extract information from instagrams accounts such as e-mails / phone numbers and more. |
| 59 | +trevorspray,https://github.com/blacklanternsecurity/TREVORspray,TREVORspray is a modular password sprayer with threading SSH proxying loot modules / and more |
| 60 | +TriliumNext,https://github.com/TriliumNext/Notes,Personal knowledge management system (successor to Trilium). |
| 61 | +uberfile,https://github.com/ShutdownRepo/Uberfile,Uberfile is a simple command-line tool aimed to help pentesters quickly generate file downloader one-liners in multiple contexts (wget / curl / powershell / certutil...). This project code is based on my other similar project for one-liner reverseshell generation Shellerator. |
| 62 | +uploader,https://github.com/Frozenka/uploader,Tool for quickly downloading files to a remote machine based on the target operating system |
| 63 | +waybackurls,https://github.com/tomnomnom/waybackurls,Fetch all the URLs that the Wayback Machine knows about for a domain. |
| 64 | +wesng,https://github.com/bitsadmin/wesng,WES-NG is a tool based on the output of Windows's systeminfo utility which provides the list of vulnerabilities the OS is vulnerable to including any exploits for these vulnerabilities. |
| 65 | +whatportis,https://github.com/ncrocfer/whatportis,Command-line tool to lookup port information |
| 66 | +whois,https://packages.debian.org/sid/whois,See information about a specific domain name or IP address. |
| 67 | +Yalis,https://github.com/EatonChips/yalis,Yet Another LinkedIn Scraper |
| 68 | +youtubedl,https://github.com/ytdl-org/youtube-dl,Download videos from YouTube and other sites. |
| 69 | +yt-dlp,https://github.com/yt-dlp/yt-dlp,A youtube-dl fork with additional features and fixes |
0 commit comments