Less Googling, More Hacking!

381 InfoSec Tools in Our Directory

77 Tools in Bug Bounty

csprecon

csprecon

by edoardottt

Discover new target domains using Content Security Policy

bounty-hunting bugbounty bugbounty-tool
442
View Details
favirecon

favirecon

by edoardottt

Use favicons to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.

bug-bounty bugbounty favicon
210
View Details
Verified
4-ZERO-3

4-ZERO-3

by Dheerajmadhukar

403/401 Bypass Methods + Bash Automation + Your Support ;)

security tool
1491
View Details
back-me-up

back-me-up

by Dheerajmadhukar

This tool will check for Sensitive Data Leakage with some useful patterns/RegEx. The patterns are mostly targeted on waybackdata and filter everything accordingly.

security tool
225
View Details
recox

recox

by samhaxr

Master script for web reconnaissance

security tool
319
View Details
socialhunter

socialhunter

by utkusen

crawls the website and finds broken social media links that can be hijacked

bug-bounty bugbounty osint
735
View Details
jxscout

jxscout

by francisconeves97

jxscout superpowers JavaScript analysis for security researchers

security tool
134
View Details
aem-hacker

aem-hacker

by 0ang3el

An MCP server implementation

security tool
791
View Details
SubEnum

SubEnum

by bing0o

bash script for Subdomain Enumeration

security tool
366
View Details
Verified
SecretFinder

SecretFinder

by m4ll0k

SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

security tool
2178
View Details
Verified
LinkFinder

LinkFinder

by GerbenJavado

A python script that finds endpoints in JavaScript files

endpoints infosec
3956
View Details
Verified
dnsx

dnsx

by projectdiscovery

dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.

cli dns-bruteforcer dns-client
2369
View Details
Verified
assetfinder

assetfinder

by tomnomnom

Find domains and subdomains related to a given domain

security tool
3291
View Details
Featured
Sublist3r

Sublist3r

by aboul3la

Fast subdomains enumeration tool for penetration testers

security tool
10371
View Details
Verified
dalfox

dalfox

by hahwul

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

bugbounty bugbounty-tool cicd-pipeline
4286
View Details

Frequently Asked Questions about InfosecMania

Learn more about Cybersecurity Tools and how they can enhance your security posture

InfoSecMania is a comprehensive directory of cybersecurity tools and resources designed to help security professionals find the right tools for their needs.

You can submit a tool by clicking on the 'Submit Tool' link in the navigation menu and filling out the submission form with details about your tool.

Feel free to connect with us on LinkedIn, Discord, or just write to us at [email protected].

Tools are categorized based on their primary function, such as penetration testing, vulnerability assessment, network security, etc. Many tools may appear in multiple categories if they serve multiple purposes.

We only list tools and resources from publicly available, reputable sources — most of which are open-source and widely used in the cybersecurity community. However, always review and test tools in a safe, legal environment, like your lab or VM.

We actively monitor public repositories, GitHub, and community forums to keep our tool listings fresh. Many tools are auto-sourced from open-source feeds and security communities.