Try searching for "database", "file", "API", or browse by category
297 Tools in InfoSec Tools
CVE-2017-8759
by bhdresh
Exploit toolkit CVE-2017-8759 - v1.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft .NET Framework RCE. It could generate a malicious RTF file and deliver metasploit / meterpreter / other payload to victim without any complex configuration.
shad0w
by bats3c
A post exploitation framework designed to operate covertly on heavily monitored environments
o365recon
by nyxgeek
retrieve information via O365 and AzureAD with a valid cred
RedTeaming_CheatSheet
by 0xJs
Pentesting cheatsheet with all the commands I learned during my learning journey. Will try to to keep it up-to-date.
osmedeus
by j3ssie
A Workflow Engine for Offensive Security
Gf-Patterns
by 1ndianl33t
GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep
snallygaster
by hannob
Tool to scan for secret files on HTTP servers
ChopChop
by michelin
ChopChop is a CLI to help developers scanning endpoints and identifying exposition of sensitive services/files/folders.
ParamSpider
by devanshbatham
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
FridaMe
by CognisysGroup
FridaMe is intentionally vulnerable android application developed to demonstrate the usage of Frida.
smbcrawler
by SySS-Research
smbcrawler is no-nonsense tool that takes credentials and a list of hosts and 'crawls' (or 'spiders') through those shares
Havoc
by HavocFramework
The Havoc Framework
sliver
by BishopFox
Adversary Emulation Framework
DojoLoader
by naksyn
Generic PE loader for fast prototyping evasion techniques
Nimbo-C2
by itaymigdal
Nimbo-C2 is yet another (simple and lightweight) C2 framework
Infosec Certifications Resources
Discover the best cybersecurity certifications to advance your career








































Frequently Asked Questions about InfosecMania
Learn more about Cybersecurity Tools and how they can enhance your security posture
InfoSecMania is a comprehensive directory of cybersecurity tools and resources designed to help security professionals find the right tools for their needs.
You can submit a tool by clicking on the 'Submit Tool' link in the navigation menu and filling out the submission form with details about your tool.
No, InfoSecMania includes both free and commercial tools. Each tool listing indicates whether it's free, paid, or offers a freemium model.
Tools are categorized based on their primary function, such as penetration testing, vulnerability assessment, network security, etc. Many tools may appear in multiple categories if they serve multiple purposes.
We only list tools and resources from publicly available, reputable sources — most of which are open-source and widely used in the cybersecurity community. However, always review and test tools in a safe, legal environment, like your lab or VM.
We actively monitor public repositories, GitHub, and community forums to keep our tool listings fresh. Many tools are auto-sourced from open-source feeds and security communities.