


Discover the cybersecurity tools used by penetration testers, bug bounty hunters, SOC analysts, digital forensics experts, malware researchers, cloud security engineers and ethical hackers. 302 curated tools - every link goes to the official source.
25 tools
The leading web app testing proxy - intercept, fuzz and exploit.
Free web app scanner and intercepting proxy from OWASP.
Automated SQL injection detection and database takeover.
Fast web fuzzer for content discovery, params and virtual hosts.
Brute-force URIs, DNS subdomains and vhosts.
Commercial DAST for web app, API and network-exposure vulnerabilities.
WordPress security scanner for vulnerable plugins, themes and users.
API client widely used to test and probe API endpoints and auth.
Content discovery built for modern APIs and routes.
Fast, recursive content discovery for web apps.
Web path scanner for hidden files and directories.
Powerful, fast XSS scanning and parameter analysis.
Advanced XSS detection with fuzzing and payload generation.
Test, tamper and attack JSON Web Tokens.
Automated OS command-injection detection and exploitation.
Fingerprint web technologies behind a site.
Identify and fingerprint the WAF protecting a web app.
Modern web security auditing proxy (a lightweight Burp alternative).
Mine parameters from a target's URLs for fuzzing.
Scan for CRLF injection vulnerabilities.
Detect and exploit server-side template injection (SSTI).
Powerful, signature-based web application scanner.
Official sources only.Every link goes straight to the vendor's official website, documentation or GitHub releases. We never mirror or host binaries. Use these tools only on systems you own or are authorized to test.