
SecLists
Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Fast multi-purpose DNS toolkit for querying A, AAAA, CNAME, MX, TXT, and other records with custom resolvers, wildcard filtering, brute-force…

Portable DNS resolver with ad blocking, local .numa domains, developer overrides, and ODoH privacy. Supports recursive resolution, DNSSEC, DoT/DoH…

Fast passive subdomain enumeration tool.

The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules,…

High-performance web fuzzer for content discovery, virtual host enumeration, and parameter fuzzing. Supports recursive scanning, multi-wordlist…

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

A fork and successor of the Sulley Fuzzing Framework

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain…

DNS server that converts threat intelligence feeds into Response Policy Zones (RPZ) for automated DNS-layer blocking of malware, C2 domains, and…

CLI MITM proxy that converts SOCKS4/SOCKS5 into HTTP/HTTPS/HTTP2/HTTP3 proxy with transparent TCP/UDP redirection, ARP/NDP/DNS spoofing, traffic…

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

LLMNR, NBT-NS, and MDNS poisoner with 17+ rogue authentication servers for capturing NetNTLM hashes, cleartext credentials, and Kerberos AS-REP…

A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

The modern, high-speed successor to nsec3walker. A specialized NSEC3 forensics engine built in Go for rapid zone harvesting and automated hash…

In-depth attack surface mapping and asset discovery

Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second