EN
ENNA
Open-Source Intelligence Tool Index

ENNA

Discover, compare, and deploy the best open-source OSINT and reconnaissance tools. Curated. Categorized. Live stats.

en-na.com

210
Tools
16
Categories
12
Languages
210 results

Aircrack-ng

C
Featured

Complete suite for WiFi network security assessment. Monitoring, attacking, testing, and cracking.

wifiwpapacket-captureclassic
7.1k1.3k8mo ago

Amass

Go
Featured

In-depth attack surface mapping and asset discovery. DNS enumeration, network mapping, OSINT data sources.

dnsattack-surfaceowaspasset-discovery
14.3k2.1k9d ago
AR

Arkham Intelligence

TypeScript
Featured

Entity-based blockchain analytics. Ultra system maps on-chain activity to real-world entities across chains.

entity-mappingintelligencemulti-chaindeanonymization
BE

BeEF

Ruby
OffensiveFeatured

Browser Exploitation Framework. Hook browsers via XSS, then pivot into the network using browser-based attacks.

browserxsshooksocial-engineering
BE

Bettercap

Go
Featured

Swiss army knife for WiFi, Bluetooth, and ethernet network recon and MITM. Scriptable with JS.

mitmwifibluetoothscriptable
BI

Bitcoin Core CLI

C++
Featured

Official Bitcoin node with full RPC interface. Query the blockchain directly — raw transactions, mempool, UTXO lookups.

bitcoinfull-noderpcmempool
BL

BlockScout

Elixir
Featured

Open-source blockchain explorer for Ethereum and EVM chains. Full-featured with smart contract verification.

explorerethereumevmsmart-contracts

BloodHound

Go
Featured

Active Directory attack path mapping. Visualizes privilege escalation paths using graph theory.

active-directorygraphprivilege-escalationattack-path
2.9k306today
BR

Breadcrumbs

TypeScript
Featured

Blockchain analytics and investigation tool. Trace Bitcoin and Ethereum transactions through multiple hops.

bitcoinethereumtraceinvestigation
BU

Burp Suite Community

Java
Featured

Web vulnerability scanner and proxy. Intercept, modify, and replay HTTP/S traffic for web app testing.

proxyweb-appinterceptorscanner
CA

Cast (Foundry)

Rust
Featured

Swiss army knife for Ethereum. Send transactions, query chain data, decode calldata, compute hashes — all from CLI.

clicalldata-decodetransactionfoundry
CE

Certipy

Python
OffensiveFeatured

Active Directory Certificate Services (AD CS) abuse tool. Find and exploit certificate template misconfigurations.

active-directorycertificatesadcsprivilege-escalation
CR

CrackMapExec

Python
Featured

Swiss army knife for pentesting Active Directory. SMB, LDAP, MSSQL, WinRM enumeration and exploitation.

active-directorysmblateral-movementcredential-spraying
CR

Cryo

Rust
Featured

Extract blockchain data into Parquet or CSV. High-performance bulk exporter for blocks, transactions, logs, and traces.

data-extractionparquetbulk-exportparadigm
DN

dnscat2

Ruby
Dual UseFeatured

Create an encrypted C2 channel over DNS. Tunnel data through DNS queries when all other protocols are blocked.

dns-tunnelc2exfiltrationencrypted
DO

Donut

C
OffensiveFeatured

Generates position-independent shellcode from .NET assemblies, PE files, and DLLs. Load anything in memory.

shellcodein-memoryevasiondotnet
DU

Dune Analytics CLI

Python
Featured

Query blockchain data with SQL. Ethereum, Polygon, Optimism, Arbitrum, Solana, and more. Community dashboards.

sqlanalyticsdashboardsmulti-chain
EM

Empire

Python
Dual UseFeatured

Post-exploitation agent built on PowerShell and Python. Cryptologically-secure communications and flexible architecture.

c2post-exploitationpowershellpython-agent
EV

Evilginx2

Go
Featured

Man-in-the-middle attack framework for phishing credentials and session cookies, bypassing 2FA.

mitm2fa-bypasssession-hijackreverse-proxy

Feroxbuster

Rust
Featured

Fast, recursive content discovery tool written in Rust. Like gobuster on steroids with auto-recursion.

directory-bruterecursiverustfast
7.6k6091mo ago

ffuf

Go
Featured

Fast web fuzzer written in Go. Fuzz anything — URLs, headers, POST data — with blazing speed.

fuzzingdirectory-brutefastflexible
15.8k1.5k11mo ago
FL

Flipper Zero Firmware

C
Featured

Custom firmware for Flipper Zero. Sub-GHz, RFID, NFC, infrared, and GPIO hacking multi-tool.

flipperrfidnfcsub-ghz
FO

Forta

TypeScript
Featured

Real-time threat detection for blockchain. Community-built detection bots monitoring for exploits, scams, and anomalies.

threat-detectionreal-timebotsexploit-monitor
FR

Frida

C
Featured

Dynamic instrumentation toolkit for developers and security researchers to inject scripts into native apps.

instrumentationhookingdynamic-analysisinjection
GE

Geth (Go Ethereum)

Go
Featured

Official Go implementation of Ethereum. Full node, archive node, and light client with rich JSON-RPC API.

ethereumfull-noderpcarchive

Ghidra

Java
Featured

NSA's reverse engineering framework. Disassembly, decompilation, graphing, and scripting for binary analysis.

reverse-engineeringdecompilerbinary-analysisnsa
66.4k7.3k3d ago

GoPhish

Go
Featured

Open-source phishing framework. Create campaigns, track results, and train users with realistic simulations.

phishing-simulationcampaignawareness-training
13.7k2.9k1y ago
GR

GraphSense

Python
Featured

Cryptoasset analytics platform. Address clustering, entity mapping, and flow analysis for Bitcoin and Ethereum.

clusteringentity-mappingflow-analysismulti-chain
GT

GTFOBins

Shell
Dual UseFeatured

Curated list of Unix binaries that can be used to bypass security restrictions. Living off the land, documented.

lolbinsprivescshell-escapeliving-off-the-land
HA

HackRF One

C
OffensiveFeatured

Open-source software-defined radio platform. Transmit and receive 1 MHz to 6 GHz. The hardware hacker's SDR.

sdrradiohardwaresub-ghz

Hashcat

C
Featured

World's fastest password recovery tool. GPU-accelerated with support for 300+ hash types.

gpuhash-crackingrule-basedfast
25.7k3.4k1mo ago
HA

Havoc

C/C++
OffensiveFeatured

Modern C2 framework. Qt-based GUI, BOF support, custom agents, and a Cobalt Strike-inspired workflow.

c2red-teamguibof
LI

LinPEAS

Shell
Featured

Linux privilege escalation enumeration script. Finds misconfigs, SUID bins, creds, and escalation paths.

privescenumerationlinuxsuid
LO

LOLBAS

Shell
Dual UseFeatured

Living Off The Land Binaries, Scripts and Libraries for Windows. Documenting every Windows binary with offensive potential.

lolbinswindowsevasionliving-off-the-land

Metasploit Framework

Ruby
Featured

The world's most used penetration testing framework. Exploit development, payload delivery, post-exploitation.

exploitpayloadpost-exploitationclassic
37.8k14.8ktoday
ME

mev-inspect-py

Python
Featured

Detect and analyze MEV (Maximal Extractable Value) on Ethereum. Finds arbitrage, liquidations, and sandwiches.

mevarbitragesandwichflashbots
MI

Mimikatz

C
Featured

Extract plaintext passwords, hashes, PIN codes, and Kerberos tickets from Windows memory.

credential-dumpkerberoswindowslsass
MI

MistTrack

TypeScript
Featured

SlowMist's crypto tracking platform. Cross-chain fund tracing, address labeling, and risk scoring for AML.

cross-chainamlrisk-scoringfund-tracing
MO

MobSF

Python
Featured

Automated mobile security framework for static and dynamic analysis of Android, iOS, and Windows apps.

static-analysisdynamic-analysisandroidios
MY

Mythic

Go
OffensiveFeatured

Collaborative, multi-platform C2 framework. Docker-based with web UI, multiple agent types, and plugin architecture.

c2red-teammulti-operatordocker
MY

Mythril

Python
Featured

Security analysis tool for EVM bytecode. Detects reentrancy, integer overflow, and access control vulnerabilities.

smart-contractsecurityevmvulnerability-detection
NE

NetExec

Python
Dual UseFeatured

Network execution tool — the maintained successor to CrackMapExec. SMB, LDAP, WinRM, SSH, MSSQL, and more.

smbldapwinrmcredential-spray
NG

ngrok

Go
Dual UseFeatured

Expose local servers to the internet via secure tunnels. Instant public URLs for localhost services.

tunnelingreverse-proxynat-bypasswebhook

Nmap

C/C++
Featured

The gold standard network scanner. Host discovery, port scanning, service/version detection, OS fingerprinting.

port-scanservice-detectionos-fingerprintscripting-engine
12.6k2.8k3d ago

Nuclei

Go
Featured

Fast vulnerability scanner driven by YAML templates. Thousands of community-contributed detection templates.

template-basedcvemisconfigprojectdiscovery
27.7k3.3ktoday

OpenVAS

C
Featured

Full-featured vulnerability scanner. 50,000+ NVTs, credentialed scanning, compliance checks.

enterprisenvtcompliancecredentialed
4.5k766today
PA

Pacu

Python
OffensiveFeatured

AWS exploitation framework. Enumerate, escalate, and exfiltrate across AWS services. The Metasploit of cloud.

awscloudprivilege-escalationiam
PR

ProxyChains-ng

C
Dual UseFeatured

Force any TCP connection through SOCKS4/5 or HTTP proxies. Chain multiple proxies for anonymity.

proxysockspivotinganonymity
PW

pwncat

Python
OffensiveFeatured

Post-exploitation platform and target management. Automatic privesc, persistence, file transfer — the smart reverse shell.

post-exploitationreverse-shellprivescpersistence
RC

Rclone

Go
Dual UseFeatured

rsync for cloud storage. Sync, copy, and mount 70+ cloud providers. Command-line Swiss army knife for cloud data.

cloud-storagesyncexfiltrations3
RU

Rubeus

C#
OffensiveFeatured

C# toolset for raw Kerberos interaction and abuse. AS-REP roasting, Kerberoasting, ticket manipulation, delegation attacks.

kerberosactive-directoryroastingdelegation
SC

ScareCrow

Go
OffensiveFeatured

Payload creation framework for EDR bypass. Generates loaders using WinAPI syscalls to evade userland hooks.

edr-bypasssyscallsloaderevasion
SE

SecLists

Shell
Featured

The security tester's companion. Huge collection of wordlists — usernames, passwords, URLs, fuzzing payloads, shells.

wordlistsfuzzingpayloadscollection

Sherlock

Python
Featured

Hunt down social media accounts by username across 400+ social networks simultaneously.

usernamesocial-mediaaccount-discovery
74.5k8.8ktoday
SL

Slither

Python
Featured

Solidity static analysis framework. Detects vulnerabilities, prints contract info, and suggests optimizations.

soliditystatic-analysisvulnerabilityoptimization
SL

Sliver

Go
Featured

Open-source C2 framework by BishopFox. mTLS, HTTP(S), DNS, WireGuard implants with multi-operator support.

c2red-teammulti-operatorimplant
SO

Social-Engineer Toolkit

Python
OffensiveFeatured

Open-source social engineering framework. Spear-phishing, web attacks, USB/HID attacks, and credential harvesting.

social-engineeringphishingcredential-harvestusb-attack

SpiderFoot

Python
Featured

Automated OSINT with 200+ modules. Web UI for scanning IPs, domains, emails, names, and more.

automatedweb-uimodulesall-in-one
17.2k2.9k1y ago

Subfinder

Go
Featured

Fast passive subdomain enumeration tool. Uses multiple sources including certificate transparency logs.

passivecertificate-transparencyprojectdiscovery
13.3k1.5k5d ago
SY

Sysinternals Suite

C/C++
Dual UseFeatured

Microsoft's advanced system utilities. PsExec, Process Monitor, Autoruns, TCPView — essential for both ops and offense.

psexeclateral-movementprocess-monitorwindows
TH

THC Hydra

C
Featured

Fast online password brute-forcer. Supports 50+ protocols including SSH, FTP, HTTP, SMB, MySQL.

brute-forceonlinemulti-protocolclassic
TO

Tor

C
Dual UseFeatured

Anonymous communication network. Routes traffic through multiple relays to conceal location and usage.

anonymityonion-routingprivacydark-web
TR

TrueBlocks

Go
Featured

Local-first Ethereum indexer. Decentralized, censorship-resistant access to blockchain data with rich APIs.

ethereumindexerlocal-firstdecentralized
TR

TruffleHog

Go
Featured

Find leaked credentials in Git repos, S3 buckets, and filesystems. Regex and entropy-based detection.

secretscredentialsgits3
VE

Velociraptor

Go
Featured

Endpoint visibility and collection tool. Hunt for artifacts across thousands of endpoints simultaneously.

endpointhuntingdfirartifact-collection

Volatility 3

Python
Featured

Advanced memory forensics framework. Extracts artifacts from RAM dumps — processes, network connections, registry.

memoryram-dumpartifact-extractionincident-response
4.0k64113d ago
WE

Web3.py

Python
Featured

Python library for interacting with Ethereum. Query blocks, decode transactions, call contracts, trace calls.

ethereumlibrarysmart-contractsrpc

Wireshark

C/C++
Featured

The world's foremost network protocol analyzer. Deep packet inspection for hundreds of protocols.

packet-captureprotocol-analysisguiclassic
9.1k2.1ktoday
YA

YARA

C
Featured

Pattern matching swiss knife for malware researchers. Create rules to identify and classify malware samples.

malwarepattern-matchingrulesclassification
AL

Alchemy SDK

TypeScript

Enhanced blockchain API. NFT metadata, token balances, transaction receipts, and webhook notifications.

apinfttoken-balanceswebhooks
AL

Altdns

Python

Subdomain discovery through alterations and permutations. Generates mutated wordlists from known subdomains.

permutationmutationwordlistdns
AP

APKTool

Java

Reverse engineer Android APK files — decode resources, rebuild, and step-through debug smali code.

androidapkreverse-engineeringsmali

Arjun

Python

HTTP parameter discovery suite. Finds hidden query parameters in web applications using smart heuristics.

parameter-discoveryhidden-paramsfuzzing
6.2k8541y ago
AR

arp-scan

C

Send ARP requests to discover and fingerprint hosts on the local network segment.

arphost-discoverylanfingerprinting

Assetfinder

Go

Find domains and subdomains potentially related to a given domain. Pulls from multiple passive sources.

passivesubdomainfasttomnomnom
3.6k5381y ago

Autopsy

Java

Digital forensics platform with GUI. Disk image analysis, timeline analysis, keyword search, hash filtering.

disk-forensicsguitimelinefile-carving
3.1k6567d ago
BI

Binwalk

Python

Firmware analysis tool. Searches binary images for embedded files, executables, and file systems.

firmwarebinaryextractionembedded
BI

Bitcoin-Abe

Python

Block chain browser for Bitcoin and similar currencies. Self-hosted explorer with search and API.

bitcoinexplorerself-hosteddatabase
BI

BitcoinLib

Python

Python Bitcoin library. Create wallets, parse transactions, interact with nodes, and analyze the UTXO set.

bitcoinlibraryutxowallet
BL

Blackbird

Python

OSINT tool to search for user accounts across 500+ social networks and websites.

usernamesocial-networksaccount-searchosint
CD

cdncheck

Go

Detect whether an IP belongs to a CDN, cloud provider, or WAF to identify origin servers.

cdnwafcloudip-detection
CE

Censys CLI

Python

Search engine for internet-connected devices. Alternative to Shodan with certificate and host search.

search-enginecertificatesinternet-scanapi
CE

CeWL

Ruby

Custom wordlist generator. Spiders a target site and builds password lists from scraped words.

wordlistspidercustompassword-gen
CH

Chainalysis Reactor (Free)

JavaScript

Blockchain investigation tool. Transaction graph visualization, wallet clustering, and entity identification.

blockchaingraphwallet-clusteringentity-id
CH

ChainSight

Rust

Real-time monitoring of DEX trades, bridge transfers, and large movements. Custom alerts via webhook or Telegram.

dex-monitoringbridgesalertsreal-time
CH

Chisel

Go

Fast TCP/UDP tunnel over HTTP secured via SSH. Single binary, works behind firewalls and NAT.

tunnelingfirewall-bypasssshsingle-binary
CL

CloudBrute

Go

Cloud infrastructure enumerator to find company assets across multiple cloud providers.

cloudenumerationassetsmulti-cloud
CL

CloudMapper

Python

Analyze AWS environments to create network diagrams and identify security risks.

awsnetwork-diagramvisualizationsecurity
CO

CobaltStrike Parser

Python
Dual Use

Parse and extract configs from Cobalt Strike beacons. Identify C2 servers, watermarks, and malleable C2 profiles.

cobalt-strikebeaconc2-detectionconfig-extraction
CO

Coercer

Python
Offensive

Automatically find and exploit Windows authentication coercion vulnerabilities. PetitPotam, PrinterBug, and more.

authentication-coercionntlm-relaypetitpotamactive-directory

Commix

Python

Automated OS command injection exploitation tool. Tests web apps for command injection vulnerabilities.

command-injectionautomatedweb-app
5.7k9282d ago
CO

Covenant

C#

.NET C2 framework. Collaborative, web-based interface for red team operations and implant management.

c2red-teamdotnetimplant
CR

Creepy

Python
Offensive

Geolocation OSINT tool. Aggregates location data from social media, photos, and online services on a map.

geolocationosintsocial-mediagps
CR

Crystal Blockchain

TypeScript

Blockchain analytics platform for compliance and investigation with transaction flow visualization.

complianceanalyticstransaction-flowinvestigation
CU

Cutter

C++

GUI for Radare2. Makes reverse engineering accessible with graphs, decompiler, and hex editor built in.

reverse-engineeringguiradare2decompiler
CY

CyLR

C#

Live response collection tool for quickly gathering forensic artifacts from hosts during incident response.

incident-responseartifact-collectionlive-responsetriage
DE

DeBank API

TypeScript

Multi-chain DeFi portfolio tracker. Token holdings, protocol positions, NFTs, and approval management across 100+ chains.

defiportfoliomulti-chainapprovals
DN

DNSenum

Perl

Multithreaded DNS enumeration tool that discovers subdomains via dictionary brute-force, Google scraping, and zone transfers.

dnsenumerationbrute-forcezone-transfer
DN

DNSRecon

Python

DNS enumeration script. Zone transfers, reverse lookups, Google dorking, SRV records, and DNSSEC testing.

dnszone-transferdnssecenumeration

dnsx

Go

Fast multi-purpose DNS toolkit. Retries, wildcard filtering, and multiple resolver support.

dnsresolverwildcardprojectdiscovery
2.7k310today
DR

Drainer Detector

Python

Detect wallet drainer contracts and phishing approval signatures. Scans for SetApprovalForAll and Permit2 abuse.

drainerphishingapprovalspermit2
DR

Drozer

Python

Android security testing framework for identifying vulnerabilities in apps and devices.

androidvulnerabilityapp-securitytesting
EI

EigenPhi Tools

Python

DeFi attack and MEV analysis. Visualizes flash loan attacks, rug pulls, and arbitrage with transaction decoding.

flash-loanrug-pullattack-analysisdefi
EL

Elliptic Lens

TypeScript

Crypto compliance and investigation tool. Cross-chain tracing, sanctions screening, and risk profiling.

compliancesanctionscross-chainrisk-profile
EM

EmailHarvester

Python

Email harvesting from search engines. Supports Google, Bing, Yahoo, and ASK with proxy rotation.

emailsearch-engineharvestingproxy
EN

enum4linux-ng

Python

Windows/Samba enumeration tool. Extracts user lists, share info, group policies, and OS details via SMB.

smbenumerationwindowssamba
ET

Ethers.js

TypeScript

Complete Ethereum library for JavaScript. Wallet management, contract interaction, ENS resolution, and ABI encoding.

ethereumlibrarywalletens
ET

Etherscan API Tools

Python

Python wrapper for Etherscan API. Query balances, transactions, token transfers, contract ABIs, and gas prices.

ethereumapitransactionstoken-transfers
ET

Ethtective

JavaScript

Ethereum transaction explorer and visualizer. Graph-based exploration of addresses and transaction flows.

ethereumgraphvisualizationexplorer
EV

Evil-WinRM

Ruby

Ultimate WinRM shell for pentesting. Upload/download, in-memory PowerShell, DLL injection, pass-the-hash.

winrmpowershellpass-the-hashpost-exploitation
EV

evm-trace

Python

Python library for parsing and analyzing EVM call traces. Decode internal transactions and visualize call trees.

evmcall-traceinternal-txdebugging

ExifTool

Perl

Read, write, and edit metadata in files. Supports EXIF, GPS, IPTC, XMP, and more across dozens of formats.

metadataexifgpsphoto
4.5k4289d ago
FI

Fierce

Python

DNS reconnaissance tool for locating non-contiguous IP space and hostnames against specified domains.

dnsreconnaissancedomainip-discovery
FL

Fluxion

Shell

WPA security auditing tool that uses social engineering for handshake capture via evil twin attacks.

wpaevil-twinsocial-engineeringwifi

gau

Go

Get All URLs. Fetches known URLs from AlienVault OTX, Wayback Machine, Common Crawl, and URLScan.

url-discoverypassivemulti-source
4.9k50610d ago
GH

GHunt

Python

Offensive Google framework to extract information from Google accounts using emails.

googleemailaccount-analysisosint
GI

Gitleaks

Go

Scan Git repos for hardcoded secrets like passwords, API keys, and tokens. CI/CD ready.

secretsgitci-cdapi-keys

Gobuster

Go

Directory/file, DNS, and vhost busting tool. Brute-forces URIs, DNS subdomains, virtual host names, and S3 buckets.

directory-brutedns-brutevhosts3
13.6k1.6k3d ago

GoBuster DNS

Go

DNS subdomain bruting using Go. Concurrent queries with wildcard detection and custom resolvers.

dns-bruteconcurrentwildcardresolvers
13.6k1.6k3d ago
GO

GoSpider

Go

Fast web spider written in Go for crawling and collecting URLs, subdomains, and endpoints.

crawlerspiderurl-collectionendpoints
HA

Hakrawler

Go

Simple Go web crawler for quick discovery of endpoints and assets within a web application.

crawlerendpointsdiscoveryweb-app

Holehe

Python

Check if an email is registered on 120+ sites. Uses password recovery mechanisms to verify without logging in.

emailaccount-discoverypassive
10.6k1.3k1y ago

httpx

Go

Fast multi-purpose HTTP toolkit. Probes for running HTTP servers with retries and fallbacks.

http-probetech-detectionprojectdiscovery
9.8k1.0ktoday

Impacket

Python

Collection of Python classes for working with network protocols. Essential for Windows/AD pentesting.

smbactive-directoryprotocolwindows
15.6k3.9k4d ago
IN

Instaloader

Python

Download Instagram photos, videos, stories, and metadata. Profile archiving and OSINT data extraction.

instagramscrapingstoriesmetadata
JA

JADX

Java

DEX to Java decompiler producing readable Java source from Android APK and DEX files.

decompilerandroiddexjava

John the Ripper

C

Fast password cracker. Supports hundreds of hash types and ciphers. CPU and GPU modes.

hash-crackingbrute-forcewordlistclassic
12.9k2.5k10d ago
JS

JSFScan

Shell

Automation framework combining multiple JS analysis tools for comprehensive JavaScript recon.

javascriptautomationreconendpoints

Katana

Go

Next-gen crawling and spidering framework. Headless browser and standard mode with automatic form fill.

crawlerspiderheadlessprojectdiscovery
16.4k1.1ktoday
KI

King Phisher

Python

Phishing campaign toolkit with web cloning, credential harvesting, and campaign analytics dashboard.

campaignweb-clonecredential-harvestanalytics
KI

Kismet

C++

Wireless network detector, sniffer, wardriving tool, and IDS. WiFi, Bluetooth, Zigbee, and more.

wardrivingidsbluetoothzigbee
KN

Knock

Python

Subdomain enumeration tool using wordlist and DNS resolution. Supports VirusTotal and zone transfers.

dnswordlistvirustotalzone-transfer
LA

LaZagne

Python

Password recovery tool. Retrieves stored passwords from browsers, WiFi, databases, sysadmin tools, and more.

credential-recoverybrowsersstored-passwordsmulti-source
LI

Ligolo-ng

Go

Advanced tunneling/pivoting tool. Creates a TUN interface for transparent proxying through compromised hosts.

tunnelingpivotingtunproxy
LI

LinkFinder

Python

Python script to discover endpoints and their parameters in JavaScript files.

javascriptendpointsparametersapi-discovery

Maigret

Python

Sherlock fork on steroids. Collects detailed info from 2500+ sites, builds a report with extracted data.

usernamesocial-mediadata-extractionreport
19.3k1.3ktoday
MA

Maltego CE

Java

Visual link analysis tool for OSINT. Maps relationships between people, companies, domains, and infrastructure.

graph-analysislink-analysisvisualtransforms

Masscan

C

Internet-scale port scanner. Transmits 10 million packets per second. Asynchronous, stateless scanning.

port-scanhigh-speedinternet-scale
25.5k3.2k9mo ago
ME

Medusa

C

Speedy, parallel, modular brute-forcer. Supports HTTP, MySQL, SMB, SSH, Telnet, and more.

brute-forceparallelmodular
MI

MicroBurst

PowerShell

PowerShell toolkit for attacking Azure services including storage, key vaults, and automation.

azurepowershellstoragekey-vault
MO

Modlishka

Go

Automated HTTP reverse proxy for 2FA phishing. Real-time credential and token harvesting.

reverse-proxy2fa-bypassautomatedreal-time
NA

Nansen Labels (Open)

Python

Open-source wallet labeling database. Identify wallets belonging to exchanges, whales, MEV bots, and funds.

labelswhale-trackingmevidentification

Ncat (Nmap)

C

Improved netcat with SSL support, IPv6, proxying, and connection brokering. The Swiss army knife of networking.

networkingtunnelingsslswiss-army-knife
12.6k2.8k3d ago
NE

Netdiscover

C

Active/passive ARP reconnaissance tool for network discovery without DNS traffic.

arpnetwork-discoverypassiveactive

Nikto

Perl

Classic web server scanner. Tests for dangerous files, outdated server software, and version-specific problems.

web-serverclassiccgi-scan
10.2k1.4k10d ago
NI

Nishang

PowerShell
Dual Use

PowerShell offensive security framework. Shells, backdoors, information gathering, and privilege escalation.

powershellshellsbackdoorprivilege-escalation
OB

Objection

Python

Runtime mobile exploration toolkit powered by Frida for iOS and Android security testing without jailbreak.

fridaiosandroidruntime-analysis
OP

OpenSSH

C
Dual Use

The SSH protocol implementation. Remote access, tunneling, port forwarding, SOCKS proxying — everywhere.

sshtunnelingport-forwardingsocks-proxy
OR

Orbit

JavaScript

Blockchain transaction visualizer. Generates interactive force-directed graphs of Ethereum address relationships.

visualizationgraphethereumforce-directed
OS

Osintgram

Python

Instagram OSINT tool. Gathers emails, phone numbers, user info, followers, and location data from profiles.

instagramgeolocationemailosint
PA

ParamSpider

Python

Mine parameters from web archives for any domain to find hidden attack surfaces.

parametersweb-archiveattack-surfacerecon
PE

Peirates

Go
Offensive

Kubernetes penetration testing tool. Exploit misconfigs, steal secrets, move laterally in K8s clusters.

kubernetescloudcontainer-escapesecrets

PhoneInfoga

Go

Advanced phone number OSINT. Scans phone numbers using free resources to gather standard and disposable info.

phonelookupcarriergeolocation
16.1k4.9k2mo ago
PH

Photon

Python

Incredibly fast crawler designed for OSINT. Extracts URLs, emails, files, JS, and secret keys from targets.

crawlerextractionfastsecrets
PL

Plaso (log2timeline)

Python

Super timeline creation engine. Extracts timestamps from multiple forensic artifact sources into a single timeline.

timelinelog-analysisartifactsuper-timeline
PO

PowerSploit

PowerShell
Dual Use

Collection of PowerShell post-exploitation modules. Credential theft, privilege escalation, persistence, exfiltration.

powershellpost-exploitationactive-directorycredential-theft
PR

Prowler

Python
Offensive

Cloud security assessment tool. 300+ checks for AWS, Azure, GCP, and Kubernetes against CIS benchmarks.

cloud-securityawsazuregcp
PS

pspy

Go

Monitor Linux processes without root. Detects cron jobs, user commands, and process events in real time.

process-monitorcronno-rootenumeration
PW

pwndrop

Go
Offensive

Self-deployable file hosting for red teams. Upload payloads, host phishing files, serve implants — with HTTPS and Let's Encrypt.

file-hostingpayload-deliveryred-teamhttps
QU

Quasar RAT

C#
Offensive

Open-source remote administration tool for Windows. Full remote desktop, keylogger, file manager, and reverse proxy.

ratremote-accesskeyloggerremote-desktop
RA

Radare2

C

Portable reversing framework. Disassembly, debugging, analysis, patching, and scripting in a single CLI.

reverse-engineeringdisassemblerdebuggerscripting

Recon-ng

Python

Full-featured reconnaissance framework. Modular design with a Metasploit-like interface for OSINT gathering.

frameworkmodularapi-keysreporting
5.5k8561y ago

Responder

Python

LLMNR/NBT-NS/mDNS poisoner and rogue authentication server. Captures NTLMv1/v2 hashes on the network.

ntlmpoisoncredential-captureactive-directory
6.4k8602mo ago
RE

Reth

Rust

High-performance Ethereum execution client in Rust. Blazing fast sync, archive mode, and modular architecture.

ethereumexecution-clientrustparadigm
RO

ROADtools

Python

Framework for Azure AD enumeration and exploitation via the internal ROADrecon and ROADlib modules.

azure-adenumerationactive-directoryexploitation
RT

RTL-SDR

C

Software-defined radio tools for RTL2832U-based DVB-T receivers, enabling wide-spectrum RF analysis.

sdrradiorf-analysisspectrum
RU

RugDoc Scanner

Python

Smart contract risk assessment. Reviews DeFi contracts for common rug pull patterns and backdoor functions.

risk-assessmentdefibackdoorrug-pull
RU

RustScan

Rust

Blazing fast port scanner that pipes into Nmap. Scans all 65k ports in 3 seconds flat.

port-scanfastnmap-integrationrust
S3

S3Scanner

Go

Scan for misconfigured S3 buckets across AWS regions and dump accessible contents.

s3awsbucketmisconfiguration
SC

Scorechain Analytics

Python

Blockchain analytics with risk scoring, transaction monitoring, and compliance reporting across 8000+ assets.

compliancerisk-scoringmonitoringaml
SC

ScoutSuite

Python

Multi-cloud security auditing tool for AWS, Azure, GCP, Alibaba Cloud, and Oracle Cloud.

awsazuregcpcloud-audit
SE

Seatbelt

C#
Offensive

C# safety checks for offensive operations. Enumerates host security config, credentials, and interesting data.

enumerationhost-surveysecurity-checkscredentials
SE

SecretFinder

Python

Discover sensitive data like API keys, tokens, and credentials in JavaScript files.

secretsapi-keysjavascriptcredentials
SH

SharpCollection

C#
Offensive

Nightly builds of common C# offensive tools. Pre-compiled Rubeus, Seatbelt, SharpUp, Certify, and 50+ more.

dotnetpre-compiledred-teamcollection
SH

SharpHound

C#
Offensive

Official BloodHound data collector. Enumerates Active Directory objects, sessions, ACLs, and trusts for graph analysis.

active-directoryenumerationbloodhoundgraph-data

Shodan CLI

Python

Command-line interface for Shodan, the search engine for internet-connected devices.

iotsearch-engineinternet-scanapi
2.8k6421y ago
SO

Socat

C
Dual Use

Multipurpose relay tool. Bidirectional data transfer between two data channels — sockets, files, pipes, devices.

relaysockettunnelingssl
SO

Social Analyzer

Python

API, CLI, and web app for analyzing and finding a person's profile across 1000+ social media sites.

profile-analysissocial-mediaapiweb-ui
SO

Solana CLI

Rust

Solana blockchain tools. Query accounts, transactions, programs, and stake info. Built-in token management.

solanacliprogramsstake

sqlmap

Python

Automatic SQL injection and database takeover tool. Detects and exploits SQL injection flaws.

sql-injectiondatabaseautomatedclassic
37.0k6.2ktoday
ST

Stegseek

C++
Offensive

Lightning fast steganography brute-forcer. Cracks steghide passwords at 200+ GB/s using wordlists.

steganographybrute-forcesteghidectf
SU

Subjack

Go

Subdomain takeover tool. Checks if CNAME records point to deprovisioned cloud services.

takeovercnameclouddangling-dns
TC

tcpdump

C

Command-line packet analyzer. The lightweight, scriptable alternative to Wireshark for capture and analysis.

packet-captureclibpfclassic
TE

Tenderly CLI

Go

Smart contract debugging and simulation. Transaction trace inspection, gas profiling, and fork testing.

debuggingsimulationgas-profilingtrace
TE

testssl.sh

Shell

Command-line tool for checking TLS/SSL ciphers, protocols, and cryptographic flaws on any port.

tlssslcipher-checkheartbleed
TH

The Sleuth Kit

C

Collection of command-line tools for forensic analysis of disk images and file systems.

disk-forensicsfile-systemanalysisimaging
TH

TheFatRat

Shell

Exploit and payload generator. Creates backdoors with msfvenom, compiles with anti-AV evasion techniques.

payloadbackdoormsfvenomevasion

theHarvester

Python

Gathers emails, names, subdomains, IPs, and URLs from multiple public sources for passive recon.

emailsubdomainpassive-recon
15.9k2.5ktoday
TL

tlsx

Go

Fast TLS probe tool for grabbing TLS certificates, versions, and cipher information at scale.

tlssslcertificatesscanning
TO

Token Sniffer

TypeScript

Automated scam token detection. Analyzes contract code for honeypots, hidden mints, tax manipulation, and rug vectors.

scam-detectionhoneypotrug-pullcontract-audit
TO

Tornado Cash Tracker

Python

Track deposits and withdrawals through Tornado Cash mixer. Probabilistic linking of mixed transactions.

mixertornado-cashprobabilisticlinking
TR

Transpose

Python

SQL-based blockchain data API. Query decoded transactions, token transfers, NFT sales, and DeFi events.

sqldecoded-datanftdefi
TW

TweetFeed

Python

Real-time feed of IOCs shared on Twitter by the infosec community. Domains, IPs, URLs, SHA256 hashes.

iocthreat-inteltwitterreal-time
TW

Twint

Python

Advanced Twitter/X scraping tool. No API key needed. Scrapes tweets, followers, favorites, and more.

twitterscrapingno-apifollowers
TX

TxStreet

JavaScript

Real-time blockchain transaction visualizer. Animated street view of pending and confirmed transactions.

visualizationreal-timemempoolanimated
UN

Uncover

Go

Quickly discover exposed hosts on the internet using multiple search engines like Shodan, Censys, and Fofa.

search-enginesshodancensysfofa
UN

Unicornscan

C

Asynchronous UDP/TCP port scanner with advanced stimulus-response analysis and OS fingerprinting.

port-scannerasyncudptcp
UR

URLScan.io CLI

Python

Scan and analyze URLs for phishing indicators, malware, and suspicious behavior. Screenshot and DOM capture.

url-analysisscreenshotmalware-detectionapi
US

USB Rubber Ducky Payloads

DuckyScript
Offensive

Payload repository for USB Rubber Ducky and BadUSB devices. Keystroke injection scripts for every scenario.

badusbhidkeystroke-injectionphysical-access
VI

Villain

Python
Offensive

Windows and Linux backdoor generator and handler. Auto-obfuscation, multi-session, and reverse shell management.

backdoorreverse-shellobfuscationmulti-session
WA

WalletExplorer

Python

Bitcoin wallet clustering and labeling. Maps addresses to known entities — exchanges, mixers, markets, gambling.

bitcoinclusteringentity-labelingexchanges

waybackurls

Go

Fetch all URLs that the Wayback Machine knows about for a domain. Gold mine for hidden endpoints.

wayback-machineurl-discoveryarchivetomnomnom
4.4k5441y ago
WF

Wfuzz

Python

Web application fuzzer. Brute force parameters, directories, headers, and authentication credentials.

fuzzingbrute-forceweb-appflexible
WH

Whale Alert CLI

Python

Track large cryptocurrency transactions in real time across all major blockchains. API and alerting.

whale-watchingreal-timealertingmulti-chain
WH

WhatsMyName

Python

Username enumeration across hundreds of websites with community-maintained JSON data.

usernameenumerationsocial-mediaidentity
WH

WhatWeb

Ruby

Web technology fingerprinter. Identifies CMS, frameworks, JS libraries, servers, and analytics from HTTP responses.

fingerprinttech-detectioncmsframework
WI

Wifite2

Python

Automated wireless attack tool. Wraps aircrack-ng, reaver, and hashcat for streamlined WiFi auditing.

wifiautomatedwpawps

WPScan

Ruby

WordPress security scanner. Enumerates plugins, themes, users, and checks for known vulnerabilities.

wordpressplugin-enumcvecms
9.5k1.3k1mo ago

XSStrike

Python

Advanced XSS detection suite. Fuzzing engine, context analysis, and WAF detection/bypass capabilities.

xsswaf-bypassfuzzingcontext-analysis
14.8k2.1k11mo ago
ZM

ZMap

C

Internet-wide single-packet scanner. Scans the entire IPv4 address space in under 5 minutes.

internet-scalefastipv4research