Offensive Security Toolkit
A centralized index of custom-developed utilities, configurations, and industry-standard security tools mapped to security specialties.
myrepo
In-house custom tools and developer automations including Vulntrace (syscall tracer), Kali Master, and Lab Manager.
Explore My Repo βReconnaissance & OSINT
Passive footprinting and active service mapping tools (Shodan, Naabu, Nmap, RustScan).
Explore Recon & OSINT βSubdomain Enumeration & DNS
Subdomain harvesting and active DNS resolution (Subfinder, Amass, Shuffledns, Massdns).
Explore Subdomains & DNS βWeb Application Security
Path fuzzing, tech fingerprinting, and script parsing (Nuclei, FFUF, Gobuster, Arjun, x8).
Explore Web Security βVulnerability Exploitation
Automating SQL injection, command execution, and XSS checks (SQLMap, XSStrike, Commix).
Explore Exploitation βAuthentication & Session
Audit credentials rate limiting and session tokens (Hydra, Medusa, jwt_tool).
Explore Auth & Session βNetwork Penetration Testing
Ethernet MITM, sniffing, WiFi auditing, and tunnel proxies (Bettercap, Responder, Hashcat).
Explore Network Pentest βPost-Exploitation & Red Team
C2 frameworks, lateral movement, and local checks (Sliver, Metasploit, WinPEAS, Mimikatz).
Explore Post-Exploitation βCloud Security
Audit cloud configurations, IAM access, and exposed buckets (Pacu, ROADtools, ScoutSuite).
Explore Cloud Security βBug Bounty Specific Tools
Automation pipelines, subdomain takeover, and reporting (ReconFTW, Subjack, Pwndoc).
Explore Bug Bounty Tools βReverse Engineering
Decompilers, debuggers, static analysis, and malware sandboxes (Ghidra, IDA, x64dbg).
Explore Reverse Engineering βCTF Tools
Crypto, stego, forensics, and binary exploitation (CyberChef, Volatility, pwntools).
Explore CTF Tools βActive Directory
Domain path sweeps and Windows network testing (BloodHound, Impacket, CrackMapExec).
Explore Active Directory βMobile Security
Decompilation and dynamic hooks on Android/iOS (MobSF, APKTool, Frida, objection).
Explore Mobile Security βProxy & Interception
Interception web proxies, request encoders, and debuggers (Burp Suite, OWASP ZAP, Caido).
Explore Proxy & Interception βGeneral Purpose Utilities
Terminal multiplexers, JSON formatters, and piping scripts (CyberChef, tmux, jq, anew).
Explore Utilities βπ Quick Reference Matrix
| Category | Top Tool | Runner-up |
|---|---|---|
| Subdomain Enum | Subfinder | Amass |
| Port Scanning | Nmap | RustScan |
| Web Fuzzing | ffuf | Feroxbuster |
| Vuln Scanning | Nuclei | Jaeles |
| SQLi | SQLmap | Ghauri |
| XSS | Dalfox | XSStrike |
| C2 Framework | Cobalt Strike | Havoc |
| Disassembler | IDA Pro | Ghidra |
| Debugger | x64dbg | pwntbg |
| Memory Forensics | Volatility | Autopsy |
| Pwn | pwntools | GEF |
| Password Cracking | Hashcat | John |
| AD Attacks | BloodHound | Impacket |
| Mobile | MobSF | Frida |
| Proxy | Burp Suite | Caido |