Try searching for "database", "file", "API", or browse by category
77 Tools in Bug Bounty
urlF
by Boopath1
My script stands out by preserving the structure of duplicate URLs and handling complex query parameters, unlike standard tools that only filter alphabetically or deduplicate.
ipsourcebypass
by p0dalirius
This Python script can be used to bypass IP source restrictions using HTTP headers.
InterceptSuite
by Anof-cyber
A powerful SOCKS5 proxy based network traffic interception tool for Windows that enables TLS/SSL inspection, analysis, and manipulation at the network level.
web_app_recon_ci-cd_public
by onurcangnc
This project delivers a fully automated **Recon-as-Code** workflow for passive reconnaissance for web application environments. It combines GitHub Actions-based CI/CD automation, powerful recon tools, and a Flask-powered dashboard for visualized and authenticated access to the findings.
S3BucketMisconf
by Atharv834
S3BucketMisconf is an advanced tool designed to scan AWS S3 buckets for misconfigurations. It identifies publicly accessible buckets, checks permissions, and detects sensitive data leaks. Ideal for bug bounty hunters and pentesters, it automates the recon process and enhances cloud storage security assessment efficiently.
osmedeus
by j3ssie
A Workflow Engine for Offensive Security
Gf-Patterns
by 1ndianl33t
GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep
snallygaster
by hannob
Tool to scan for secret files on HTTP servers
ChopChop
by michelin
ChopChop is a CLI to help developers scanning endpoints and identifying exposition of sensitive services/files/folders.
ParamSpider
by devanshbatham
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
bbot
by blacklanternsecurity
The recursive internet scanner for hackers. 🧡
knock
by guelfoweb
Knock Subdomain Scan
shosubgo
by incogbyte
Small tool to Grab subdomains using Shodan api.
cero
by glebarez
Scrape domain names from SSL certificates of arbitrary hosts
hades
by joelindra
Automate your hacking
Infosec Certifications Resources
Discover the best cybersecurity certifications to advance your career








































Frequently Asked Questions about InfosecMania
Learn more about Cybersecurity Tools and how they can enhance your security posture
InfoSecMania is a comprehensive directory of cybersecurity tools and resources designed to help security professionals find the right tools for their needs.
You can submit a tool by clicking on the 'Submit Tool' link in the navigation menu and filling out the submission form with details about your tool.
Feel free to connect with us on LinkedIn, Discord, or just write to us at [email protected].
Tools are categorized based on their primary function, such as penetration testing, vulnerability assessment, network security, etc. Many tools may appear in multiple categories if they serve multiple purposes.
We only list tools and resources from publicly available, reputable sources — most of which are open-source and widely used in the cybersecurity community. However, always review and test tools in a safe, legal environment, like your lab or VM.
We actively monitor public repositories, GitHub, and community forums to keep our tool listings fresh. Many tools are auto-sourced from open-source feeds and security communities.