Unified application security platform — 12 scanners including SAST, DAST, SCA, and pen-testing in one on-premise deployment. Replaces your entire AppSec stack.
A self-hosted multi-tool pentest platform with a perfect toolset. It's designed to help pentesters, bug hunters, or CTF players to make their work efficient and convenient. Especially to simplify the way of writing reports.


+9
Directory/File, DNS and VHost busting tool written in Go - GitHub - OJ/gobuster: Directory/File, DNS and VHost busting tool written in Go
Cost / License
- Free
- Open Source (Apache-2.0)
Platforms
- Linux



To provide materials that allows anyone to gain practical 'hands-on' experience in digital security, computer software & network administration.
Cost / License
- Free
- Proprietary
Application type
Platforms
- Windows
- Linux
- VirtualBox
- VMware Workstation
- VMware Fusion
- VMware Player


+3
Matriux is a fully featured security distribution consisting of a bunch of powerful, open source and free tools that can be used for various purposes including, but not limited to, penetration testing, ethical hacking, system and network administration, cyber forensics...
Cost / License
- Free
- Open Source
Application types
Alerts
- Discontinued
Platforms
- Linux


+3
Vulnerable Client-Server Application (VuCSA) is made for learning/presenting how to perform penetration tests of non-http thick clients. It is written in Java (with JavaFX graphical user interface).

HunterX is an open-source, AI-assisted vulnerability scanner and red team framework designed to automate and orchestrate modern security testing workflows.

Reconmap is an open-source tool for InfoSec teams to collaborate on pentest and other security projects. They can create projects from templates, keep track of tasks, upload results and get automatic insights that are available on the browser and in customisable HTML and PDF...
Cost / License
- Free
- Open Source
Application type
Platforms
- Online
- Self-Hosted
- Software as a Service (SaaS)


+6
BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.



Fully customisable, offensive security reporting tool designed for pentesters, red teamers and other security-related people alike.
Cost / License
- Freemium
- Open Source
Application type
Platforms
- Linux
- Online
- Software as a Service (SaaS)
Immunity's CANVAS makes available hundreds of exploits, an automated exploitation system, and a comprehensive, reliable exploit development framework to penetration testers and security professionals worldwide.
Find security vulnerabilities right from your browser. Experience the next generation security tools without the need to install any additional software.
Cost / License
- Freemium
- Proprietary
Application types
Platforms
- Mac
- Windows
- Linux
- Online
- Chrome OS


+6
DIRB is a Web Content Scanner. It looks for existing (and/or hidden) Web Objects. It basically works by launching a dictionary based attack against a web server and analyzing the response.
Cost / License
- Free
- Open Source
Alerts
- Discontinued
Platforms
- Mac
- Linux
Collaborative Penetration Test and Vulnerability Management Platform that increases transparency, speed and efficiency for your audits & team.
Cost / License
- Free Personal
- Open Source (GPL-3.0)
Application type
Platforms
- Mac
- Windows
- Linux
- BSD
- Software as a Service (SaaS)



Websecurify is a powerful web application security testing environment designed from the ground up to provide the best combination of automatic and manual vulnerability testing technologies.
BreachDirectory allows you to search through all public data breaches to make sure your emails, usernames, passwords, and domains haven't been compromised.


+2
The most advanced, powerful and yet beautiful penetration testing distribution ever created.Lined up with ultimate collection of tools for pro Ethical Hackers and Cyber Security Experts.
Cost / License
- Free
- Open Source
Application types
Alerts
- Discontinued
Platforms
- Linux


+5
Hack This Site is a free training ground for users to test and expand their hacking skills. Our community is dedicated to facilitating an open learning environment by providing a series of hacking challenges, articles, resources, and discussion of the latest happenings in hacker...


Elevate your hacking skills at Parrot CTFs! We provide premier ethical hacking training and labs, catering to beginners and pros. Join our global community and level up your cybersecurity skills with our realistic hacking labs and challenges.


+2
Probely is a top-tier cloud-based DAST Scanner designed for DevOps, empowering Security and Development teams to work together to secure their web applications and APIs.
Cost / License
- Freemium
- Proprietary
Application types
Platforms
- Online


+2
Core Impact Pro is the most comprehensive software solution assessing and testing security vulnerabilities throughout your organization. Core Impact Pro tests across a broad spectrum of risk areas including:
Cost / License
- Paid
- Proprietary
Application types
Platforms
- Windows
- Linux
PENTESTON is a cloud-based Cybersecurity platform that allows you to oversee the complete secure development lifecycle of your application. It functions as a cyber security reporting and workflow management system, providing you with the necessary tools to manage the entire...
Cost / License
- Paid
- Proprietary
Application types
Platforms
- Online


Echo Mirage, a freeware tool that hooks into an application’s process and enables us to monitor the network interactions being done. This process can be done with a running process, or it can run the application on the user’s behalf.


Wireless Air Cut is a WPS wireless, portable and free network audit software for Ms Windows. It is used to check the security of our WPS wireless networks and to detect possible security breaches.


+3




































































