Offensive Security Toolkit

A centralized index of custom-developed utilities, configurations, and industry-standard security tools mapped to security specialties.

πŸ› οΈ

myrepo

In-house custom tools and developer automations including Vulntrace (syscall tracer), Kali Master, and Lab Manager.

Explore My Repo β†’
🌐

Reconnaissance & OSINT

Passive footprinting and active service mapping tools (Shodan, Naabu, Nmap, RustScan).

Explore Recon & OSINT β†’
πŸ”

Subdomain Enumeration & DNS

Subdomain harvesting and active DNS resolution (Subfinder, Amass, Shuffledns, Massdns).

Explore Subdomains & DNS β†’
πŸ•ΈοΈ

Web Application Security

Path fuzzing, tech fingerprinting, and script parsing (Nuclei, FFUF, Gobuster, Arjun, x8).

Explore Web Security β†’
πŸ’‰

Vulnerability Exploitation

Automating SQL injection, command execution, and XSS checks (SQLMap, XSStrike, Commix).

Explore Exploitation β†’
πŸ”

Authentication & Session

Audit credentials rate limiting and session tokens (Hydra, Medusa, jwt_tool).

Explore Auth & Session β†’
🏹

Network Penetration Testing

Ethernet MITM, sniffing, WiFi auditing, and tunnel proxies (Bettercap, Responder, Hashcat).

Explore Network Pentest β†’
πŸ–₯️

Post-Exploitation & Red Team

C2 frameworks, lateral movement, and local checks (Sliver, Metasploit, WinPEAS, Mimikatz).

Explore Post-Exploitation β†’
🌩️

Cloud Security

Audit cloud configurations, IAM access, and exposed buckets (Pacu, ROADtools, ScoutSuite).

Explore Cloud Security β†’
πŸ›

Bug Bounty Specific Tools

Automation pipelines, subdomain takeover, and reporting (ReconFTW, Subjack, Pwndoc).

Explore Bug Bounty Tools β†’
πŸ”¬

Reverse Engineering

Decompilers, debuggers, static analysis, and malware sandboxes (Ghidra, IDA, x64dbg).

Explore Reverse Engineering β†’
🏁

CTF Tools

Crypto, stego, forensics, and binary exploitation (CyberChef, Volatility, pwntools).

Explore CTF Tools β†’
πŸ›‘οΈ

Active Directory

Domain path sweeps and Windows network testing (BloodHound, Impacket, CrackMapExec).

Explore Active Directory β†’
πŸ“±

Mobile Security

Decompilation and dynamic hooks on Android/iOS (MobSF, APKTool, Frida, objection).

Explore Mobile Security β†’
πŸ”§

Proxy & Interception

Interception web proxies, request encoders, and debuggers (Burp Suite, OWASP ZAP, Caido).

Explore Proxy & Interception β†’
🧰

General Purpose Utilities

Terminal multiplexers, JSON formatters, and piping scripts (CyberChef, tmux, jq, anew).

Explore Utilities β†’

πŸ“Š Quick Reference Matrix

Category Top Tool Runner-up
Subdomain Enum Subfinder Amass
Port Scanning Nmap RustScan
Web Fuzzing ffuf Feroxbuster
Vuln Scanning Nuclei Jaeles
SQLi SQLmap Ghauri
XSS Dalfox XSStrike
C2 Framework Cobalt Strike Havoc
Disassembler IDA Pro Ghidra
Debugger x64dbg pwntbg
Memory Forensics Volatility Autopsy
Pwn pwntools GEF
Password Cracking Hashcat John
AD Attacks BloodHound Impacket
Mobile MobSF Frida
Proxy Burp Suite Caido