


Discover the cybersecurity tools used by penetration testers, bug bounty hunters, SOC analysts, digital forensics experts, malware researchers, cloud security engineers and ethical hackers. 302 curated tools - every link goes to the official source.
22 tools
The de-facto network scanner for host discovery, port scanning and service/OS fingerprinting.
Internet-scale TCP port scanner that can sweep huge ranges extremely fast.
OWASP in-depth attack-surface mapping and subdomain enumeration.
Fast passive subdomain discovery using many public sources.
Fast, multi-purpose HTTP toolkit for probing live web servers.
Fast SYN/CONNECT port scanner focused on reliability and simplicity.
Query domain, IP and registrar registration records for recon.
Fast, multi-purpose DNS toolkit for resolving and probing records.
Next-generation crawling and spidering framework for web recon.
Find domains and subdomains related to a given target.
Pull historical URLs for a domain from the Wayback Machine.
Fetch known URLs from AlienVault, Wayback and Common Crawl.
DNS enumeration and zone-transfer testing.
Enumerate subdomains using OSINT search engines.
Fast web spider for crawling and endpoint discovery.
Quick web crawler for gathering URLs and JS endpoints.
Mass DNS resolver and subdomain brute-forcer.
grep wrapper with patterns to find interesting URLs/params.
Fast, accurate subdomain brute-forcing and resolving with wildcard filtering.
Query ProjectDiscovery's Chaos dataset of subdomains.
Scrape domain names from TLS certificates of live hosts.
Out-of-band interaction gathering (detect blind SSRF/RCE via callbacks).
Official sources only.Every link goes straight to the vendor's official website, documentation or GitHub releases. We never mirror or host binaries. Use these tools only on systems you own or are authorized to test.