Tools Directory
Curated software disassemblers, decoders, exploit frameworks, and forensics suites.
Web Exploitation
// 17 entriesGraphical intercepting proxy for testing web application security.
Automatic SQL injection detection and database takeover tool.
Fast web fuzzer for directory/file/parameter discovery.
Web path scanner for finding hidden directories and files.
Intercepting proxy to replay, debug, and fuzz HTTP requests.
Automated XSS vulnerability detection and exploitation.
Automated OS command injection testing tool.
Dump an exposed .git repository from a website.
Generate gopher links for SSRF payload delivery.
HTTP request smuggling detection and testing.
Bypass 403 Forbidden responses with various techniques.
Library of PHP unserialize() payloads for gadget chains.
Generates payloads for Java deserialization vulnerabilities.
API testing and HTTP request debugging tool.
Inspect and debug incoming HTTP requests.
Expose local servers via secure tunnels for callbacks.
Web application attack and audit framework.
Cryptography
// 16 entriesBrowser-based Swiss Army knife for encoding, decoding, encryption and analysis.
Automated RSA attacks — FactorDB, Wiener, small-e, common factor, and 50+ more.
Analyse multi-byte XOR cipher and guess key length/key.
Automatically decrypt and decode ciphertext without knowing the cipher.
Online solvers for 200+ classical ciphers and encodings.
Fast automated cryptogram and substitution cipher solver.
Modular automated cryptanalysis tool.
Perform hash length extension attacks on MACs.
CLI tool for automating CBC padding oracle attacks.
Break PkZip encryption with known plaintext attack.
Modular online conversion, encoding, and encryption tool.
Online Vigenère cipher breaker using index of coincidence.
Interactive platform for learning modern cryptography through challenges.
Online hash lookup database for MD5, SHA1, and other common hashes.
Calculate RSA and RSA-CRT parameters from prime factors.
Encode and decode Morse code online.
Reverse Engineering
// 16 entriesNSA's free open-source RE suite — disassembler, decompiler, multi-architecture.
Industry-standard interactive disassembler and debugger (free version available).
Reverse engineering platform with a clean API and decompiler.
UNIX-like portable reverse engineering framework and disassembler.
Fork of radare2 focused on usability, with Cutter GUI.
The GNU Project debugger — standard for Linux binary debugging.
GDB plugin with context display, heap explorer, and ROP gadget finder.
Modern GDB plugin with advanced exploitation features.
Powerful binary analysis platform with symbolic execution.
Microsoft Research's theorem prover — solve constraints from RE challenges.
Dynamic instrumentation toolkit for hooking and tracing any process.
Decompile Android APKs to readable Java source code.
.NET debugger and assembly editor — decompile and patch .NET binaries.
See how compilers turn C/C++/Rust into assembly, online.
Lightweight online disassembly service for quick snippets.
Decompile Python 2 and 3 bytecode (.pyc) back to source.
Binary Exploitation
// 8 entriesPython CTF framework for exploit writing, service interaction, and shellcode.
Find ROP gadgets in ELF, PE, and Mach-O binaries.
Display file info and search for ROP/JOP/SYS gadgets.
Find one-shot execve gadgets in libc for quick RCE.
Simplify format string exploit construction.
Large collection of shellcodes for various architectures.
Check binary security mitigations: NX, PIE, canary, RELRO.
GDB enhanced with pwndbg for exploit development workflow.
Forensics
// 13 entriesAnalyse PCAP/PCAPNG network captures and dissect 100s of protocols.
Wireshark's CLI — scriptable packet filtering and field extraction.
Extract processes, files, credentials, and connections from RAM dumps.
End-to-end open source digital forensics platform with GUI.
Scan and extract embedded file signatures from any binary.
Read, write, and edit metadata in images, audio, video, and documents.
Recover files by their headers and footers from disk images.
File data recovery tool for lost/deleted files from any media.
Network forensics tool — extracts files and credentials from PCAPs.
Effortless PCAP analysis in the browser — no install needed.
Free online image forensics — error level analysis, metadata, clones.
High-performance digital forensics scanner for emails, URLs, and more.
CLI tools for disk image analysis and file system forensics.
OSINT
// 11 entriesHunt for a username across 400+ social networks in seconds.
Interactive tree of OSINT tools categorised by target type.
Search engine for internet-connected devices, banners, and services.
Search TLS certificates and IPv4 hosts for exposed services.
Certificate transparency log search — find all subdomains with certs.
Access cached snapshots of any website at any point in time.
Web UI for username enumeration across hundreds of platforms.
Geolocation-based OSINT investigation challenges.
Reverse image search to find locations, objects, and sources.
Collect a dossier on a person by username — checks 3000+ sites.
Gather emails, names, subdomains, and IPs from public sources.
Steganography
// 12 entriesAll-in-one image stego solver — runs zsteg, steghide, exiftool, binwalk automatically.
Online image steganography: bit-plane viewer, LSB extraction, channel splitting.
Hide and extract data in JPEG, BMP, WAV, and AU files with a passphrase.
PNG and BMP steganography analysis — checks all common bit-plane combinations.
Lightning-fast steghide passphrase cracker using a wordlist.
Java tool to visualise image bit planes and extract hidden data.
Audio file spectrogram viewer — find text/images in frequency domain.
Automated stego analysis — runs many checks on an image in one go.
Brute-force steghide passphrases with a wordlist.
Whitespace steganography — hide messages in trailing spaces and tabs.
Online digital photo forensics — error level analysis and metadata.
Hide and extract secret data inside audio files.
Networking
// 6 entriesNetwork discovery and security auditing — port scan, service detection, OS fingerprint.
Fastest TCP port scanner — can scan the full internet in under 6 minutes.
Open-source network security monitor and traffic analysis framework.
Single-packet network scanner for internet-wide surveys.
TCP/UDP networking Swiss Army knife — connect, listen, forward, pipe.
CLI packet capture and analysis — the Unix PCAP tool.
Miscellaneous
// 10 entriesGPU-accelerated password cracker supporting 300+ hash types.
Classic password security auditing and recovery tool.
Parallelized login brute-forcer supporting 50+ protocols.
CyberChef's Magic operation — auto-detects encoding and decodes recursively.
Run code in 600+ languages and esoteric interpreters in the browser.
Decode Brainfuck, Ook!, Malbolge, Piet, and other esoteric languages.
Test, tamper, and crack JSON Web Tokens.
Identify hash types from a hash string.
Upcoming CTF calendar, team rankings, and writeup archive.
Self-hosted jeopardy-style CTF platform.