Less Googling, More Hacking!

381 InfoSec Tools in Our Directory

19 Tools in Web Security

ELcazad0r-XSS

ELcazad0r-XSS

by nihaltikka

A powerful and comprehensive XSS vulnerability scanner with an intuitive GUI interface.

security tool
0
View Details
toxssin

toxssin

by t3l3machus

An XSS exploitation command-line interface and payload generator.

cross-site-scripting exploitation hacking
1380
View Details
words-scraper

words-scraper

by dariusztytko

Selenium based web scraper to generate passwords list

security tool
51
View Details
headi

headi

by mlcsec

Customisable and automated HTTP header injection

bugbounty golang header-injection
253
View Details
Verified
archerysec

archerysec

by archerysec

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

asoc aspm devops
2380
View Details
Verified
Advanced-SQL-Injection-Cheatsheet

Advanced-SQL-Injection-Cheatsheet

by kleiton0x00

A cheat sheet that contains advanced queries for SQL Injection of all types.

cheatsheet mssql-dump mysql-injection
3015
View Details
New
filter-shell

filter-shell

by tuckerweibell

Interactive CLI tool for exploiting LFI via PHP filter chaining — a wrapper around Synacktiv’s php_filter_chain_generator.

security tool
6
View Details
ppmap

ppmap

by kleiton0x00

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.

bug-bounty bugbounty bugbounty-tool
508
View Details
wpprobe

wpprobe

by Chocapikk

A fast WordPress plugin enumeration tool

security tool
423
View Details
cariddi

cariddi

by edoardottt

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

bugbounty crawler crawling
1715
View Details
Verified
Raccoon

Raccoon

by evyatarmeged

A high performance offensive security tool for reconnaissance and vulnerability scanning

enumeration fuzzing hacking
3185
View Details
Verified
ghauri

ghauri

by r0oth3x49

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

security tool
3528
View Details
angularjs-csti-scanner

angularjs-csti-scanner

by tijme

Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x.

angularjs angularjs-csti-scanner angularjs-sandbox-escape
316
View Details
Featured
web-check

web-check

by Lissy93

🕵️‍♂️ All-in-one OSINT tool for analysing any website

osint privacy security
25099
View Details
Featured
sqlmap

sqlmap

by sqlmapproject

Automatic SQL injection and database takeover tool

database detection exploitation
34233
View Details

Frequently Asked Questions about InfosecMania

Learn more about Cybersecurity Tools and how they can enhance your security posture

InfoSecMania is a comprehensive directory of cybersecurity tools and resources designed to help security professionals find the right tools for their needs.

You can submit a tool by clicking on the 'Submit Tool' link in the navigation menu and filling out the submission form with details about your tool.

Feel free to connect with us on LinkedIn, Discord, or just write to us at [email protected].

Tools are categorized based on their primary function, such as penetration testing, vulnerability assessment, network security, etc. Many tools may appear in multiple categories if they serve multiple purposes.

We only list tools and resources from publicly available, reputable sources — most of which are open-source and widely used in the cybersecurity community. However, always review and test tools in a safe, legal environment, like your lab or VM.

We actively monitor public repositories, GitHub, and community forums to keep our tool listings fresh. Many tools are auto-sourced from open-source feeds and security communities.