πŸŽ‰ Over 430 submissions and growing

Discover the Best
InfoSec Resources

Community-driven platform for discovering, sharing, and reviewing the latest cybersecurity resources.

237
Security Tools
193
Content Submissions
1,459
Active Users
9
Utilities

Featured Tools

Top-rated tools trusted by the cybersecurity community

PAID

Vulnetic AI

Vulnetic Penetration Testing is an automated penetration testing platform that uses AI agents to conduct security assessments of web applications, APIs, and Active Directory environments. The platform performs vulnerability discovery and exploitation, testing for issues including authentication bypasses, injection flaws, cross-site scripting, server-side request forgery, and privilege escalation paths. The system conducts Active Directory assessments on networks with 500+ IP addresses, performing domain enumeration and identifying privilege escalation paths to domain admin. For web applications and APIs, the agents test for and exploit vulnerabilities rather than only flagging potential issues. The platform includes a reporting engine that generates evidence-backed penetration testing reports after assessments complete. Users can build custom penetration testing methodologies by defining tasks, setting parameters, and configuring how AI agents conduct tests. Vulnetic has identified and exploited vulnerabilities in production environments including stored XSS, SSRF exposing credentials, Active Directory misconfigurations like AS-REP roasting and Kerberoasting, broken access control, local file inclusion, and NTLM hash disclosure attacks. The platform operates on a credit-based pricing model with free credits available at signup, but also offers pro and enterprise licenses for heavy users.

πŸŸ₯ Red Team
πŸ•ΈοΈ Web / API
0.0
0
FREE

Flashingestor

A terminal user interface (TUI) for Active Directory collection compatible with BloodHound CE.

πŸ–₯️ Infrastructure
πŸŸ₯ Red Team
0.0
0
FREE

Responder

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication.

πŸ–₯️ Infrastructure
4.0
1
FREE

AdPack

AdPack is a state-aware Active Directory (AD) attack orchestration framework designed for security professionals. Unlike traditional point-and-shoot tools, AdPack maintains a persistent record of the target environment's topology, identities, and credentials to intelligently guide an operator from initial discovery to domain dominance. AdPack serves as a centralised "brain" for AD engagements, automating the connective tissue between disparate tools like NetExec, Mimikatz, and BloodHound. 1. State Persistence: Tracks hosts, users, groups, credentials, and sessions in a local SQLite database 2. Gap Detection: Analyses current ADState to identify missing prerequisites for advanced phases 3. Evasion-First Orchestration: Supports 11 distinct evasion profiles, ranging from standard in-memory execution to kernel-level PPL bypasses and 0-day exploits 4. Multi-Protocol Validation: Automatically verifies acquired credentials across SMB, LDAP, WinRM, and RDP to determine "Pwn3d!" status and administrative reach

πŸŸ₯ Red Team
πŸ–₯️ Infrastructure
0.0
0

Browse Content

Videos, podcasts, and articles about penetration testing

Join the Community

Contribute to the largest collection of penetration testing tools and help fellow security professionals.