


Discover the cybersecurity tools used by penetration testers, bug bounty hunters, SOC analysts, digital forensics experts, malware researchers, cloud security engineers and ethical hackers. 302 curated tools - every link goes to the official source.
16 tools
The knowledge base of adversary tactics and techniques.
Annotate and visualize your ATT&CK technique coverage.
ATT&CK-style matrix for adversarial threats to AI systems.
A knowledge graph of defensive countermeasures.
Living-off-the-land binaries and scripts on Windows.
Unix binaries that can be abused to bypass local restrictions.
The canonical list of the most critical web application risks.
Vast community wiki of pentest techniques and cheatsheets.
The security tester's companion: wordlists, payloads and more.
A huge collection of payloads and bypasses by vuln class.
Application Security Verification Standard - a testing checklist.
Mobile Application Security Verification Standard.
The NIST CSF - identify, protect, detect, respond, recover.
Prioritized set of safeguards to mitigate common attacks.
Concise, high-value guidance on specific security topics.
The Web Security Testing Guide - a methodology for web app testing.
Official sources only.Every link goes straight to the vendor's official website, documentation or GitHub releases. We never mirror or host binaries. Use these tools only on systems you own or are authorized to test.