๐Ÿ•ต๏ธ
VeryLazyTech
๐Ÿ“œ Medium๐Ÿ›’ My Shop๐Ÿ‘พ Github๐Ÿ“ฉ Telegram ๐Ÿ“บ YouTubeโœ– Twitter
  • ๐Ÿ•ต๏ธWelcome!
    • VeryLazyTech
    • Support VeryLazyTech
      • ๐Ÿ‘พ GitHub
      • ๐Ÿ“œ Medium
      • โ˜• My Shop
      • ๐Ÿ“บ YouTube
      • โœ– Twitter
      • ๐Ÿ“ฉ Telegram
  • ๐Ÿ›ก๏ธ Vulnerabilities and Exploits
    • CVE - POC
      • Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692
      • POC - CVE-2024โ€“4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal
      • POC - CVE-2024-45241: Path Traversal in CentralSquare's CryWolf
      • Telerik Auth Bypass CVE-2024-4358
      • Check Point Security Gateways Information Disclosure - CVE-2024-24919
      • CVE-2024-23897 - Jenkins File Read Vulnerability
      • CVE-2024โ€“10914- Command Injection Vulnerability in name parameter for D-Link NAS
      • POC - CVE-2024-21534 Jsonpath-plus vulnerable to Remote Code Execution (RCE)
      • CVE-2024-9935 - PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Unauthenticated Arbitrary
      • CVE-2024-50623- Cleo Unrestricted file upload and download
      • POC - WordPress File Upload plugin, in the wfu_file_downloader.php file before version <= 4.24.11
      • POC - Remote and unauthenticated attacker can send crafted HTTP requests to RCE - cve-2025-3248
      • POCโ€Š-โ€ŠCVE-2025โ€“2539 File Away <= 3.9.9.0.1โ€Š-โ€ŠMissing Authorization to Unauthenticated Arbitrary File
      • POC - CVE-2025-29306 FOXCMS /images/index.html Code Execution Vulnerability
  • ๐Ÿ•ต๏ธโ€โ™‚๏ธDorks
    • GitHub Dorks
    • Google Dork Online Tool
  • ๐Ÿ“š Resources
    • Top Hacking Books for 2024: FREE and Paid
    • How to Study for OSCP with the PWK Book PDF
    • Top 20 phishing tools to use in 2024
    • Top 8 Bug Bounty Books for 2025: Must-Reads for Ethical Hackers
    • Top Hacking Tools and Skills You Need to Learn in 2025
    • Offensive Cloud
    • Penetration Testing & Hacking Tools List
    • Top Cybersecurity Books by Topic
  • The Ultimate Penetration Testing Methodology (2025 Edition)
  • ๐Ÿ•ธ๏ธPentesting Web
    • Client Side Template Injection (CSTI)
    • Identify a Serverโ€™s Origin IP
    • 2FA/MFA/OTP Bypass
  • IDOR
  • Open Redirect
  • Subdomain Takeover
  • Penetration Testing WiFi Networks
  • Client-Side Path Traversal
  • Clickjacking
  • Command Injection
  • JWT Vulnerabilities
  • Bypass rating limit
  • CORS - Misconfigurations & Bypass
  • LDAP Injection
  • File upload vulnerabilities
  • Content Security Policy (CSP) bypass
  • ๐ŸงLinux
    • Practical Linux Commands
    • Bypassing Bash Restrictions - Rbash
    • Privilege escalation - Linux
  • Linux Environment Variables
  • ๐ŸชŸWindows
    • Active Directory Methodology
  • ๐ŸŒNetwork Pentesting
    • FTP - Port 21
    • SSH- Port 22
    • Telnet - Port 23
    • SMTP/s - Port 25,465,587
    • WHOIS - Port 43
    • TACACS+ - Port 49
    • DNS - Port 53
    • TFTP/Bittorrent-tracker - Port 69/UDP
    • Finger - Port 79
    • Web - Port 80,443
    • Kerberos - Port 88
    • POP - Port 110/995
    • Portmapper - Port 111/TCP/UDP
    • Ident - Port 113
    • NTP - Port 123/UDP
    • MSRPC - Port 135, 539
    • NetBios - Port 137,138,139
    • SMB - Port 139 445
    • IMAP - Port 143, 993
    • SNMP - Ports 161, 162, 10161, and 10162/UDP
    • IRC - Ports 194,6667,6660-7000
    • Check Point Firewall - Port 264
    • LDAP - Ports 389, 636, 3268, 3269
    • IPsec/IKE VPN - Port 500/UDP
    • Modbus - Port 502
    • Rexec - Port 512
    • Rlogin - Port 513
    • Rsh - Port 514
    • Line Printer Daemon (LPD) - Port 515
    • Apple Filing Protocol (AFP) - PORT 548
    • RTSP - Port 554, 8554
    • IPMI - Port 623/UDP/TCP
    • Internet Printing Protocol (IPP) - Port 631
    • EPP - Port 700
    • Rsync - Port 873
    • Rusersd Service - Port 1026
    • Socks - Port 1080
    • Java RMI - RMI-IIOP - Port 1098/1099/1050
    • MSSQL (Microsoft SQL Server) - Port 1433
    • Oracle TNS Listener - Port 1521,1522-1529
  • PPTP - Port 1723
  • MQTT (Message Queuing Telemetry Transport) - Port 1883
  • Compaq HP Insight Manager - Port 2301, 2381
  • NFS Service - Port 2049
  • Docker - Port 2375,2376
  • Squid - Port 3128
  • iScsi - Port 3260
  • SAPRouter - Port 3299
  • ๐Ÿ˜ŽPost-exploitation
    • File Transfer Cheatsheet: Windows andย Linux
  • ๐Ÿง‘โ€๐Ÿ”งTechnical guides
    • Kali Linux - Installation
Powered by GitBook
On this page
  • Online Resources โ€“ Hacking Tools
  • Penetration Testing Resources
  • Exploit Development
  • OSINT Resources
  • Social Engineering Resources
  • Lock Picking Resources
  • Operating Systems
  • Hacking Tools
  • Penetration Testing Distributions
  • Docker for Penetration Testing
  • Multi-paradigm Frameworks
  • Vulnerability Scanners
  • Static Analyzers
  • Web Scanners
  • Network Tools
  • Wireless Network Hacking Tools
  • Transport Layer Security Tools
  • Web Exploitation
  • Hex Editors
  • File Format Analysis Tools
  • Defense Evasion Tools
  • Hash Cracking Hacking Tools
  • Windows Utilities
  • GNU/Linux Utilities
  • macOS Utilities
  • DDoS Tools
  • Social Engineering Tools
  • OSINT Tools
  • Anonymity Tools
  • Reverse Engineering Tools
  • Physical Access Tools
  • Side-channel Tools
  • CTF Tools
  • Penetration Testing Report Templates
  • Vulnerability Databases โ€“ Hacking Tools
  • Information Security Conferences โ€“ Hacking Tools
  • Information Security Magazines โ€“ Hacking Tools
  • Awesome Lists โ€“ Hacking Tools โ€“

Was this helpful?

  1. ๐Ÿ“š Resources

Penetration Testing & Hacking Tools List

PreviousTop Hacking Tools and Skills You Need to Learn in 2025NextTop Cybersecurity Books by Topic

Last updated 2 months ago

Was this helpful?

Support VeryLazyTech ๐ŸŽ‰
  • Become VeryLazyTech ! ๐ŸŽ

  • Follow us on:

    • โœ– Twitter .

    • ๐Ÿ‘พ Github .

    • ๐Ÿ“œ Medium .

    • ๐Ÿ“บ YouTube .

    • ๐Ÿ“ฉ Telegram .

    • ๐Ÿ•ต๏ธโ€โ™‚๏ธ My Site .

  • Visit our for e-books and courses. ๐Ÿ“š

Online Resources โ€“ Hacking Tools

Penetration Testing Resources

  • Metasploit Unleashed โ€“ Free Offensive Security Metasploit course.

  • โ€“ Documentation designed to provide a common language and scope for performing and reporting the results of a penetration test.

  • โ€“ Worldwide not-for-profit charitable organization focused on improving the security of especially Web-based and Application-layer software.

  • โ€“ Free online security knowledge library for pentesters and researchers.

  • โ€“ Outline for performing penetration tests compiled as a general framework usable by vulnerability analysts and penetration testers alike.

  • โ€“ Ultimate resource for all things cross-site including payloads, tools, games, and documentation.

  • โ€“ Framework for providing test cases that result in verified facts on which to base decisions that impact an organizationโ€™s security.

  • โ€“ Curated knowledge base and model for cyber adversary behavior.

Exploit Development

  • โ€“ Tutorial on how to write shellcode.

  • โ€“ Shellcodes database.

  • โ€“ Tutorials on how to develop exploits.

OSINT Resources

Social Engineering Resources

Lock Picking Resources

Operating Systems

Hacking Tools

Penetration Testing Distributions

Docker for Penetration Testing

Multi-paradigm Frameworks

Vulnerability Scanners

Static Analyzers

Web Scanners

Network Tools

Wireless Network Hacking Tools

Transport Layer Security Tools

Web Exploitation

Hex Editors

File Format Analysis Tools

Defense Evasion Tools

Hash Cracking Hacking Tools

Windows Utilities

GNU/Linux Utilities

macOS Utilities

DDoS Tools

Social Engineering Tools

OSINT Tools

Anonymity Tools

Reverse Engineering Tools

Physical Access Tools

Side-channel Tools

CTF Tools

Penetration Testing Report Templates

Vulnerability Databases โ€“ Hacking Tools

Information Security Conferences โ€“ Hacking Tools

Information Security Magazines โ€“ Hacking Tools

Awesome Lists โ€“ Hacking Tools โ€“

Support VeryLazyTech ๐ŸŽ‰
  • Follow us on:

โ€“ Collection of various OSINT Hacking Tools broken out by category.

โ€“ Collection of OSINT tools. The menu on the left can be used to navigate through the categories.

โ€“ Collection of OSINT links and custom Web interfaces to other services such as and .

โ€“ Information about wireless networks worldwide, with user-friendly desktop and web applications.

โ€“ the Information resource for social engineers.

โ€“ Lockpicking videos and security talks.

โ€“ More lockpicking videos.

โ€“ Resources for learning lockpicking, equipment recommendations.

โ€“ Penetration testing tools & Hacking Tools list Related Complete list of security operating systems.

โ€“ Description of main penetration testing distributions.

โ€“ Website dedicated to talking about, reviewing, and keeping up to date with open-source operating systems.

โ€“ Open source automated malware analysis system.

โ€“ Italian GNU/Linux live distribution created as a digital forensics project.

โ€“ Live CD for forensic analysis runnable without tampering or corrupting connected devices where the boot process takes place.

โ€“ Live OS aimed at preserving privacy and anonymity.

โ€“ GNU/Linux distribution designed for digital forensics and penetration testing Hacking Tools

โ€“ Arch GNU/Linux repository for security professionals and enthusiasts.

โ€“ Arch GNU/Linux-based distribution with best Hacking Tools for penetration testers and security researchers.

โ€“ Fedora-based bootable live operating system designed to provide easy access to best-of-breed open source network security applications.

โ€“ Security-focused live CD based on Gentoo.

โ€“ Ubuntu-based distribution for penetration tests and security assessments.

โ€“ Distribution similar to Kali, with multiple architectures with 100 of Hacking Tools.

โ€“ GNU/Linux virtual machine that is pre-configured for online investigators.

โ€“ provides a safe test environment to work on security auditing, forensics, system rescue, and teaching security testing methodologies.

โ€“ Distro organized around the Penetration Testing Execution Standard (PTES), providing a curated collection of utilities that eliminates often unused toolchains.

โ€“ GNU/Linux distribution focused on tools useful during the Internet of Things (IoT) security assessments.

docker pull kalilinux/kali-linux-docker

docker pull owasp/zap2docker-stable โ€“

docker pull wpscanteam/wpscan โ€“

docker pull citizenstig/dvwa โ€“

docker pull wpscanteam/vulnerablewordpress โ€“

docker pull hmlio/vaas-cve-2014-6271 โ€“

docker pull hmlio/vaas-cve-2014-0160 โ€“

docker pull opendns/security-ninjas โ€“

docker pull diogomonica/docker-bench-security โ€“

docker pull ismisepaul/securityshepherd โ€“

docker pull danmx/docker-owasp-webgoat โ€“

docker-compose build && docker-compose up โ€“

docker pull citizenstig/nowasp โ€“

docker pull bkimminich/juice-shop โ€“

docker pull kalilinux/kali-linux-docker โ€“

docker pull phocean/msf โ€“

โ€“ post-exploitation Hacking Tools for offensive security teams to help verify vulnerabilities and manage security assessments.

โ€“ Java-based GUI front-end for the Metasploit Framework.

โ€“ Multiuser integrated pentesting environment for red teams performing cooperative penetration tests, security audits, and risk assessments.

โ€“ Graphical tool for automating penetration tests that ships with many pre-packaged exploits.

โ€“ Cross-platform (Windows, Linux, macOS, Android) remote administration and post-exploitation tool,

โ€“ Commercial vulnerability and risk management assessment engine that integrates with Metasploit, sold by Rapid7.

โ€“ Commercial vulnerability management, configuration, and compliance assessment platform, sold by Tenable.

โ€“ Free software implementation of the popular Nessus vulnerability assessment system.

โ€“ Agentless vulnerability scanner for GNU/Linux and FreeBSD, written in Go.

โ€“ Static analysis security vulnerability scanner for Ruby on Rails applications.

โ€“ Extensible C/C++ static analyzer focused on finding bugs.

โ€“ Free software static analyzer to look for bugs in Java code.

โ€“ Security-focused static analysis for the Phoenix Framework.

โ€“ Security oriented static analyzer for Python code.

โ€“ Noisy but fast black box web server and web application vulnerability scanner.

โ€“ Scriptable framework for evaluating the security of web applications.

โ€“ Hacking Tools for Web application attack and audit framework.

โ€“ Black box web application vulnerability scanner with built-in fuzzer.

โ€“ In-browser web application security testing suite.

โ€“ Commercial, graphical web application vulnerability scanner designed for macOS.

โ€“ Hacking Tools of the Black box WordPress vulnerability scanner.

โ€“ Reveal the specific modules, plugins, components and themes that various websites powered by content management systems are running.

โ€“ one of the best Hacking Tools for Joomla vulnerability scanner.

โ€“ Automated client-side template injection (sandbox escape/bypass) detection for AngularJS.

โ€“ Open source network scanner that enables researchers to easily perform Internet-wide network studies.

โ€“ Free security scanner for network exploration & security audits.

โ€“ one of the Hacking Tools forGNU/Linux packet crafting.

โ€“ Utility for using websites to perform port scans on your behalf so as not to reveal your own IP.

โ€“ Common packet analyzer that runs under the command line.

โ€“ Widely-used graphical, cross-platform network protocol analyzer.

โ€“ Website offering an interface to numerous basic network utilities like ping, traceroute, whois, and more.

โ€“ Swiss army knife for network sniffing.

โ€“ Multifunctional network toolkit.

โ€“ Graphical interface offering scriptable, configurable access to existing network infrastructure scanning and enumeration tools.

โ€“ Highly configurable DNS proxy for pentesters.

โ€“ one of the Hacking Tools for Online DNS recon and search service.

โ€“ Unmask server IP addresses hidden behind Cloudflare by searching old database records and detecting misconfigured DNS.

โ€“ Perl script that enumerates DNS information from a domain, attempts zone transfers, performs a brute force dictionary style attack and then performs reverse look-ups on the results.

โ€“ One of the Hacking Tools for Passive DNS network mapper.

โ€“ One of the Hacking Tools for DNS enumeration script.

โ€“ Determines where a given DNS server gets its information from, and follows the chain of DNS servers.

โ€“ Library and query tool for querying several passive DNS providers.

โ€“ Network sniffer that logs all DNS server replies for use in a passive DNS setup.

โ€“ best Hacking Tools for TCP port scanner, spews SYN packets asynchronously, scanning the entire Internet in under 5 minutes.

โ€“ Network attack tool centered around the exploitation of local networks.

โ€“ Interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

โ€“ Automated ettercap TCP/IP Hacking Tools .

โ€“ HTTP/HTTPS proxy over SSH.

โ€“ Intercept SSH connections with a proxy; all plaintext passwords and sessions are logged to disk.

โ€“ Reverse engineering, traffic generation and fuzzing of communication protocols.

โ€“ Proof of concept to perform data exfiltration using either single or multiple channel(s) at the same time.

โ€“ Punches holes in firewalls and NATs.

โ€“ Collection of tools for network auditing and pentesting.

โ€“ Simple Unix network utility to extend the accessibility of TCP/IP based network services beyond firewalls.

โ€“ Handy SMB enumeration tool.

โ€“ Python-based interactive packet manipulation program & library.

โ€“ Network forensic analysis framework.

โ€“ Simple and powerful network traffic analyzer for macOS.

โ€“ Caffeinated packet analyzer.

โ€“ Tool for printer security testing capable of IP and USB connectivity, fuzzing, and exploitation of PostScript, PJL, and PCL printer language features.

โ€“ Automated multi-function printer data harvester for gathering usable data during security assessments.

โ€“ Open source exploitation framework similar to Metasploit but dedicated to embedded devices.

โ€“ Modular framework to take advantage of poor upgrade implementations by injecting fake updates.

โ€“ Network (sub)domain discovery and reconnaissance automation tool.

โ€“ Comprehensive, mature suite for machine-in-the-middle attacks.

โ€“ Modular, portable and easily extensible MITM framework.

โ€“ A swiss army knife for pentesting networks.

โ€“ A collection of Python classes for working with network protocols.

โ€“ Set of Penetration testing & Hacking Tools list for auditing wireless networks.

โ€“ Wireless network detector, sniffer, and IDS.

โ€“ Brute force attack against Wifi Protected Setup.

โ€“ Automated wireless attack tool.

โ€“ Suite of automated social engineering-based WPA attacks.

โ€“ Fast and comprehensive TLS/SSL configuration analyzer to help identify security misconfigurations.

โ€“ Fingerprint a serverโ€™s SSL/TLS implementation.

โ€“ Command-line tool which checks a serverโ€™s service on any port for the support of TLS/SSL ciphers, protocols as well as some cryptographic flaws.

โ€“ Feature-rich, scriptable HTTP intercepting proxy and fuzzer for penetration testing web applications.

โ€“ Free cross-platform web debugging proxy with user-friendly companion tools.

โ€“ One of the Hacking Tools ntegrated platform for performing security testing of web applications.

โ€“ Easy to install a test browser with all the appropriate settings needed for web application testing with native Burp support, from NCCGroup.

โ€“ Command and control server for delivering exploits to commandeered Web browsers.

โ€“ Python-based framework for pentesting Web applications based on the OWASP Testing Guide.

โ€“ Ruby framework for developing and using modules which aid in the penetration testing of WordPress powered websites and systems.

โ€“ Exploit WordPress-powered websites with Metasploit.

โ€“ Automatic SQL injection and database takeover tool.

โ€“ Automatic server-side template injection and Web server takeover Hacking Tools.

โ€“ Weaponized web shell.

โ€“ Wappalyzer uncovers the technologies used on websites.

โ€“ Website fingerprinter.

โ€“ Web application fingerprinter.

โ€“ Identifies and fingerprints Web Application Firewall (WAF) products.

โ€“ Find, prepare, audit, exploit and even google automatically for LFI/RFI bugs.

โ€“ Automatic LFI exploiter and scanner.

โ€“ LFI scan and exploit tool.

โ€“ LFI exploitation tool.

โ€“ Automated all-in-one operating system command injection and exploitation tool.

โ€“ Rip web-accessible (distributed) version control systems: SVN/GIT/HG/BZR.

โ€“ One of the Hacking Tools that Automatically find and download Web-accessible .git repositories.

โ€“ One of the Hacking Tools Demonstration of the HTTPS stripping attacks.

โ€“ SSLStrip version to defeat HSTS.

โ€“ Automatic NoSQL injection and database takeover tool.

โ€“ A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, aliases, and dynamic default pages.

โ€“ Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

โ€“ Tool to take screenshots of websites, provide some server header info, and identify default credentials if possible.

โ€“ A simple script to take screenshots of the list of websites.

โ€“ Browser-based hex editing.

โ€“ Worldโ€™s finest (proprietary, commercial) Hex Editor.

โ€“ Binary file editor for Windows.

โ€“ Native macOS hex editor that supports plug-ins to display custom data types.

โ€“ File formats and network protocols dissection language and web IDE, generating parsers in C++, C#, Java, JavaScript, Perl, PHP, Python, Ruby.

โ€“ Binary data visualization and analysis tool.

โ€“ Python library to view and edit a binary stream as the tree of fields and tools for metadata extraction.

โ€“ Generate Metasploit payloads that bypass common anti-virus solutions.

โ€“ Generates custom shellcode, backdoors, injectors, optionally obfuscates every byte via encoders.

โ€“ Runtime encryptor for 32-bit portable executables (โ€œPE .exesโ€).

โ€“ Post-process exploits containing executable files targeted for Windows machines to avoid being recognized by antivirus software.

โ€“ Automates the process of hiding a malicious Windows executable from antivirus (AV) detection.

โ€“ Multi-platform fork of the peCloak.py automated malware antivirus evasion tool.

โ€“ Simple obfuscator that takes raw shellcode and generates Anti-Virus friendly executables by using a brute-forcable, 32-bit XOR key.

โ€“ One of the best Hacking Tools for Fast password cracker.

โ€“ Another One of the Hacking Tools The more fast hash cracker.

โ€“ Generates custom wordlists by spidering a targetโ€™s website and collecting unique words.

โ€“ Simple HS256 JWT token brute force cracker.

โ€“ RAR brute force cracker.

โ€“ Find the password of an encrypted wallet file (i.e. wallet.dat).

โ€“ The Sysinternals Troubleshooting Utilities.

โ€“ Inspect logon sessions and add, change, list, and delete associated credentials, including Kerberos tickets.

โ€“ Credentials extraction tool for Windows operating system.

โ€“ PowerShell Post-Exploitation Framework.

โ€“ Detects potential missing patches on the target.

โ€“ LLMNR, NBT-NS and MDNS poisoner.

โ€“ Graphical Active Directory trust relationship explorer.

โ€“ Pure PowerShell post-exploitation agent.

โ€“ Tool for exploration and tracing of the Windows kernel.

โ€“ Generates architecture-independent VBA code to be used in Office documents or templates and automates bypassing application control and exploit mitigation software.

โ€“ Post-exploitation tool for retrieving password hashes and credentials from Windows workstations, servers, and domain controllers.

โ€“ Shellcode generator for numerous attack vectors, including Microsoft Office macros, PowerShell, HTML applications (HTA), or certutil (using fake certificates).

โ€“ Python script that uses Empireโ€™s RESTful API to automate gaining Domain Admin rights in Active Directory environments.

โ€“ Heuristic reporting on potentially viable exploits for a given GNU/Linux system.

โ€“ Pure Python post-exploitation data mining and remote administration tool for macOS.

โ€“ Open source network stress tool for Windows.

โ€“ JavaScript in-browser version of LOIC.

โ€“ DoS tool that uses low bandwidth on the attacking side.

โ€“ Updated version of Low Orbit Ion Cannon, has โ€˜boostersโ€™ to get around common countermeasures.

โ€“ Faster network stress tool.

โ€“ Abuses OSI layer 7 HTTP to create/manage โ€˜zombiesโ€™ and to conduct different attacks using; GET/POST, multithreading, proxies, origin spoofing methods, cache evasion techniques, etc.

โ€“ Open source pentesting framework designed for social engineering featuring a number of custom attack vectors to make believable attacks quickly.

โ€“ One of the Hacking Tools for Phishing campaign toolkit used for creating and managing multiple simultaneous phishing attacks with custom email and server content.

โ€“ MITM attack framework used for phishing credentials and session cookies from any Web service.

โ€“ Automated phishing attacks against WiFi networks.

โ€“ Tool for phishing and corporate espionage written in Ruby.

โ€“ Tool for generating keyloggers.

โ€“ One of the Hacking Tools and Proprietary software for open-source intelligence and forensics, from Paterva.

โ€“ E-mail, subdomain, and people names harvester.

โ€“ Geolocation OSINT tool.

โ€“ Metadata harvester.

โ€“ Database of Google dorks; can be used for recon.

โ€“ Common Google dorks and others you probably donโ€™t know.

โ€“ Command-line Google Dorking tool.

โ€“ Command-line Google dork tool.

โ€“ collects data on hosts and websites through daily ZMap and ZGrab scans.

โ€“ Worldโ€™s first search engine for Internet-connected devices.

โ€“ One of the Hacking Tools Full-featured Web Reconnaissance framework written in Python.

โ€“ CLI tool to scan Github Repos/organizations for potential sensitive information leak.

โ€“ Plugin-based tool to scan public version control systems for sensitive information.

โ€“ Multi-source OSINT automation tool with a Web UI and report visualizations

โ€“ GNU/Linux bash based Bing and Google Dorking Tool.

โ€“ Perform Google dorks against a domain.

โ€“ Information gathering via dorks.

โ€“ one of the Hacking Tools for Automated Pentest Recon Scanner.

โ€“ Search engine for threats.

โ€“ VirusTotal is a free service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware.

โ€“ OSINT visualizer utilizing Shodan, Censys, Clearbit, EmailHunter, FullContact, and Zoomeye behind the scenes.

โ€“ Subdomain discovery tool utilizing various open sources producing a report that can be used as input to other tools.

โ€“ Automated OSINT & Attack Surface discovery framework with powerful API, UI, and CLI.

โ€“ Search engine for cyberspace that lets the user find specific network components.

โ€“ Free software and onion routed overlay network that helps you defend against traffic analysis.

โ€“ One of the Hacking Tools for investigating the Dark Web by finding operational security issues introduced by Tor hidden service operators.

โ€“ The Invisible Internet Project.

โ€“ Script to redirect all traffic from the machine to the Tor network.

โ€“ Comprehensive detection page to test your own Web browserโ€™s configuration for privacy and identity leaks.

โ€“ Proprietary multi-processor disassembler and debugger for Windows, GNU/Linux, or macOS; also has a free version, .

โ€“ Windows Driver Kit and WinDbg.

โ€“ x86 debugger for Windows binaries that emphasizes binary code analysis.

โ€“ Open source, cross-platform reverse engineering framework.

โ€“ Open source x64/x32 debugger for windows.

โ€“ Powerful way to write exploits and analyze malware.

โ€“ OllyDbg-like debugger for GNU/Linux.

โ€“ Open source, cross-platform interactive disassembler.

โ€“ Interactive disassembler for x86/ARM/MIPS. Generates indented pseudo-code with colored syntax code.

โ€“ Python Exploit Development Assistance for GDB.

โ€“ one of the Hacking Tools to reverse engineer .NET assemblies.

โ€“ Fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images.

โ€“ Python scriptable Reverse Engineering sandbox by Cisco-Talos.

โ€“ Extensible debugger UI toolkit written in Python.

โ€“ lightweight multi-platform, multi-architecture disassembly framework.

โ€“ Debugger on steroids; inspect userspace processes, kernel drivers, and preboot environments in a single tool.

โ€“ Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.

โ€“ Covert โ€œUSB Ethernet Adapterโ€ that provides remote access, network intelligence gathering, and MITM capabilities when installed in a local network.

โ€“ Customizable keystroke injection attack platform masquerading as a USB thumb drive.

โ€“ Siphons cookies, exposes internal (LAN-side) router and installs web backdoor on locked computers.

โ€“ Wireless auditing and penetration testing platform.

โ€“ RFID/NFC cloning, replay, and spoofing toolkit often used for analyzing and attacking proximity cards/readers, wireless keys/keyfobs, and more.

โ€“ Complete open-source toolchain for side-channel power analysis and glitching attacks.

โ€“ Collection of setup scripts to install various security research tools easily and quickly deployable to new machines.

โ€“ Rapid exploit development framework built for use in CTFs.

โ€“ Decrypt data enciphered using weak RSA keys, and recover private keys from public keys using a variety of automated attacks.

โ€“ Curated list of public penetration test reports released by several consulting firms and academic security groups.

โ€“ testandverification.com template.

โ€“ hitachi-systems-security.com template.

โ€“ lucideus.com template.

โ€“ crest-approved.org template.

โ€“ pcisecuritystandards.org template.

โ€“ Dictionary of common names (i.e., CVE Identifiers) for publicly known security vulnerabilities.

โ€“ United States governmentโ€™s National Vulnerability Database provides additional meta-data (CPE, CVSS scoring) of the standard CVE List along with a fine-grained search engine.

โ€“ Summaries, technical details, remediation information, and lists of vendors affected by software vulnerabilities, aggregated by the United States Computer Emergency Response Team (US-CERT).

โ€“ Public, vendor-neutral forum for a detailed discussion of vulnerabilities, often publishes details before many other sources.

โ€“ Software security bug identification database compiled from submissions to the SecurityFocus mailing Penetration testing tools list and other sources, operated by Symantec, Inc.

โ€“ Non-profit project hosting exploits for software vulnerabilities, provided as a public service by Offensive Security.

โ€“ Announcements of security issues discovered in Microsoft software, published by the Microsoft Security Response Center (MSRC).

โ€“ Archive of security advisories impacting Microsoft software.

โ€“ Archive of security advisories impacting Mozilla software, including the Firefox Web Browser.

โ€“ Compendium of exploits, advisories, tools, and other security-related resources aggregated from across the industry.

โ€“ Archive of published CVE and Bugtraq software vulnerabilities cross-referenced with a Google dork database for discovering the listed vulnerability.

โ€“ Independent source of software vulnerability information.

โ€“ Open forum for security advisories organized by category of exploit target.

โ€“ Bug bounty program with the publicly accessible archive of published security advisories, operated by TippingPoint.

โ€“ Security database of software vulnerabilities.

() โ€“ Exploit marketplace and vulnerability, information aggregator.

โ€“ Historical archive of security vulnerabilities in computerized equipment, no longer adding to its vulnerability database as of April, 2016.Hacking Tools

โ€“ Aggregator of cross-referenced software vulnerabilities offering free-of-charge API access, provided by the Hasso-Plattner Institute, Potsdam.Hacking Tools

โ€“ annual hacker convention in Las Vegas.

โ€“ Annual security conference in Las Vegas.

โ€“ Framework for organizing and holding security conferences.

โ€“ Annual meeting of the international hacker scene in Germany.

โ€“ Annual hacker conference based in Louisville.

โ€“ Technology conference held annually in middle Tennessee.

โ€“ Annual US East coast hacker convention.

โ€“ Infosec conference, held annually in North Carolina.

โ€“ Christchurch Hacker Con, Only South Island of New Zealand hacker con.

โ€“ One of the oldest hacker conventions, held during Summer.

โ€“ Annual conference held in Luxembourg.

โ€“ Largest hacking conference in Canada.

โ€“ Deep-knowledge security conference held in Malaysia and The Netherlands.

โ€“ Annual international IT Security event with workshops held in Heidelberg, Germany.

โ€“ Annual US hacker conference.

โ€“ Annual US hacker conference held in Chicago.

โ€“ Annual US security conference held every spring in Los Angeles.

โ€“ Security Conference in Vienna, Austria.

โ€“ Technology conference in Nashville.

โ€“ Security Conference in .

โ€“ Largest Security Conference in Eastern Europe, held annually in Bucharest, Romania.

โ€“ Annual conference organized by OWASP.

โ€“ Annual security conference in Belgium.

โ€“ Europeโ€™s number one information security event, held in London, UK.

โ€“ Annual conference in Delhi and Goa, India.

โ€“ Annual security conference in San Francisco, California, USA.

โ€“ Annual security conference in Lucerne, Switzerland.

โ€“ Annual conference going to be held in Denver, the USA for 2016.

โ€“ Largest Security Conference in Latin America, held annually in Buenos Aires, Argentina.

โ€“ Annual Security Conference held in London.

โ€“ Balkan Computer Congress, annually held in Novi Sad, Serbia.

โ€“ FSec โ€“ Croatian Information Security Gathering in Varaลพdin, Croatia.

โ€“ American publication about technology and computer โ€œunderground.โ€

โ€“ By far the longest-running hacker zine.

โ€“ List of Hacking tools present in Kali Linux.

โ€“ Top 125 Network Security Hacking Tools.

โ€“ Awesome Pentest Cheat Sheets.

โ€“ One of the main language for open source security tools.

โ€“ Software framework for Microsoft Windows platform development.

โ€“ Command-line frameworks, toolkits, guides, and gizmos.

โ€“ The de-facto language for writing exploits.

โ€“ The de-facto language for writing exploits.

โ€“ The de-facto language for writing exploits.

โ€“ In-browser development and scripting.

โ€“ Curated list of delightful Node.js packages and resources.

โ€“ Lots of pentesting tools are written in Python.

โ€“ General Python programming.

โ€“ General Python programming.

โ€“ Collection of Android security-related resources.

โ€“ The List of the Lists.

โ€“ Resources for learning about application security.

โ€“ Capture The Flag frameworks, libraries, etc.

โ€“ Comprehensive directory of CTFs, wargames, hacking challenge websites, Penetration testing tools list practice lab exercises, and more.

โ€“ Tutorials, tools, and resources.

โ€“ Honeypots, tools, components, and more.

โ€“ Information security resources for pentesting, forensics, and more.

โ€“ Free (mostly open-source) forensic analysis tools and resources.

โ€“ Tools and resources for analysts.

โ€“ Tools for processing network traffic.

โ€“ Software, libraries, documents, and other resources.

โ€“ Awesome guides, tools, and other resources about the security and compromise of locks, safes, and keys.

โ€“ Collection of multiple types of lists used during security assessments.

โ€“ Curated list of security conferences.

โ€“ Awesome OSINT list containing great resources.

โ€“ YARA rules, tools, and people.

Learn & practice

Become VeryLazyTech ! ๐ŸŽ

โœ– Twitter .

๐Ÿ‘พ Github .

๐Ÿ“œ Medium .

๐Ÿ“บ YouTube .

๐Ÿ“ฉ Telegram .

๐Ÿ•ต๏ธโ€โ™‚๏ธ My Site .

Visit our for e-books and courses. ๐Ÿ“š

member
@VeryLazyTech
@VeryLazyTech
@VeryLazyTech
@VeryLazyTech
@VeryLazyTech
@VeryLazyTech
shop
Penetration Testing Execution Standard (PTES)
Open Web Application Security Project (OWASP)
PENTEST-WIKI
Penetration Testing Framework (PTF)
XSS-Payloads
Open Source Security Testing Methodology Manual (OSSTMM)
MITREโ€™s Adversarial Tactics, Techniques & Common Knowledge (ATT&CK)
Shellcode Tutorial
Shellcode Examples
Exploit Writing Tutorials
OSINT Framework
Intel Techniques
NetBootcamp OSINT Tools
Facebook Graph Search
various paste sites
WiGLE.net
Social Engineering Framework
Schuyler Towne channel
bosnianbill
/r/lockpicking
Security-related Operating Systems @ Rawsec
Best Linux Penetration Testing Distributions @ CyberPunk
Security @ Distrowatch
cuckoo
Computer-Aided Investigative Environment (CAINE)
Digital Evidence & Forensics Toolkit (DEFT)
Tails
Kali
ArchStrike
BlackArch
Network Security Toolkit (NST)
Pentoo
BackBox
Parrot
Buscador
Fedora Security Lab
The Pentesters Framework
AttifyOS
official Kali Linux
official OWASP ZAP
official WPScan
Damn Vulnerable Web Application (DVWA)
Vulnerable WordPress Installation
Vulnerability as a service: Shellshock
Vulnerability as a service: Heartbleed
Security Ninjas
Docker Bench for Security
OWASP Security Shepherd
OWASP WebGoat Project docker image
OWASP NodeGoat
OWASP Mutillidae II Web Pen-Test Practice Application
OWASP Juice Shop
Kali Linux Docker Image
docker-Metasploit
Metasploit
Armitage
Faraday
ExploitPack
Pupy
Nexpose
Nessus
OpenVAS
Vuls
Brakeman
cppcheck
FindBugs
sobelow
bandit
Nikto
Arachni
w3af
Wapiti
SecApps
WebReaver
WPScan
cms-explorer
joomscan
ACSTIS
zmap
nmap
pig
scanless
tcpdump/libpcap
Wireshark
Network-Tools.com
netsniff-ng
Intercepter-NG
SPARTA
dnschef
DNSDumpster
CloudFail
dnsenum
dnsmap
dnsrecon
dnstracer
passivedns-client
passivedns
Mass Scan
Zarp
mitmproxy
Morpheus
mallory
SSH MITM
Netzob
DET
pwnat
dsniff
tgcd
smbmap
scapy
Dshell
Debookee
Dripcap
Printer Exploitation Toolkit (PRET)
Praeda
routersploit
evilgrade
XRay
Ettercap
BetterCAP
CrackMapExec
impacket
Aircrack-ng
Kismet
Reaver
Wifite
Fluxion
SSLyze
tls_prober
testssl.sh
OWASP Zed Attack Proxy (ZAP)
Fiddler
Burp Suite
autochrome
Browser Exploitation Framework (BeEF)
Offensive Web Testing Framework (OWTF)
WordPress Exploit Framework
WPSploit
SQLmap
tplmap
weevely3
Wappalyzer
WhatWeb
BlindElephant
wafw00f
fimap
Kadabra
Kadimus
liffy
Commix
DVCS Ripper
GitTools
sslstrip
sslstrip2
NoSQLmap
VHostScan
FuzzDB
EyeWitness
webscreenshot
HexEdit.js
Hexinator
Frhed
0xED
Kaitai Struct
Veles
Hachoir
Veil
shellsploit
Hyperion
AntiVirus Evasion Tool (AVET)
peCloak.py
peCloakCapstone
UniByAv
John the Ripper
Hashcat
CeWL
JWT Cracker
Rar Crack
BruteForce Wallet
Sysinternals Suite
Windows Credentials Editor
mimikatz
PowerSploit
Windows Exploit Suggester
Responder
Bloodhound
Empire
Fibratus
wePWNise
redsnarf
Magic Unicorn
DeathStar
Linux Exploit Suggester
Bella
LOIC
JS LOIC
SlowLoris
HOIC
T50
UFONet
Social Engineer Toolkit (SET)
King Phisher
Evilginx
wifiphisher
Catphish
Beelogger
Maltego
theHarvester
creepy
metagoofil
Google Hacking Database
Google-dorks
GooDork
dork-cli
Censys
Shodan
recon-ng
github-dorks
vcsmap
Spiderfoot
BinGoo
fast-recon
snitch
Sn1per
Threat Crowd
Virus Total
DataSploit
AQUATONE
Intrigue
ZoomEye
Tor
OnionScan
I2P
Nipe
What Every Browser Knows About You
Interactive Disassembler (IDA Pro)
IDA Free
WDK/WinDbg
OllyDbg
Radare2
x64dbg
Immunity Debugger
Evanโ€™s Debugger
Medusa
plasma
peda
dnSpy
binwalk
PyREBox
Voltron
Capstone
rVMI
Frida
LAN Turtle
USB Rubber Ducky
Poisontap
WiFi Pineapple
Proxmark3
ChipWhisperer
ctf-tools
Pwntools
RsaCtfTool
Public Pentesting Reports
Pentesting Report Template
Pentesting Report Template
Pentesting Report Template
Pentesting Report Template
Pentesting Report Template
Common Vulnerabilities and Exposures (CVE)
National Vulnerability Database (NVD)
US-CERT Vulnerability Notes Database
Full-Disclosure
Bugtraq (BID)
Exploit-DB
Microsoft Security Bulletins
Microsoft Security Advisories
Mozilla Foundation Security Advisories
Packet Storm
CXSecurity
SecuriTeam
Vulnerability Lab
Zero Day Initiative
Vulners
Inj3ct0r
Onion service
Open Source Vulnerability Database (OSVDB)
HPI-VDB
DEF CON
Black Hat
BSides
CCC
DerbyCon
PhreakNIC
ShmooCon
CarolinaCon
CHCon
SummerCon
Hack.lu
Hackfest
HITB
Troopers
Hack3rCon
ThotCon
LayerOne
DeepSec
SkyDogCon
SECUINSIDE
Seoul
DefCamp
AppSecUSA
BruCON
Infosecurity Europe
Nullcon
RSA Conference USA
Swiss Cyber Storm
Virus Bulletin Conference
Ekoparty
44Con
BalCCon
FSec
2600: The Hacker Quarterly
Phrack Magazine
Kali Linux Tools
SecTools
Pentest Cheat Sheets
C/C++ Programming
.NET Programming
Shell Scripting
Ruby Programming by @dreikanter
Ruby Programming by @markets
Ruby Programming by @Sdogruyol
JavaScript Programming
Node.js Programming by @sindresorhus
Python tools for penetration testers
Python Programming by @svaksha
Python Programming by @vinta
Android Security
Awesome Awesomness
AppSec
CTFs
InfoSec ยง Hacking challenges
Hacking
Honeypots
Infosec
Forensics
Malware Analysis
PCAP Tools
Security
Awesome Lockpicking
SecLists
Security Talks
OSINT
YARA
For the OSCP.
member
@VeryLazyTech
@VeryLazyTech
@VeryLazyTech
@VeryLazyTech
@VeryLazyTech
@VeryLazyTech
shop