Try searching for "database", "file", "API", or browse by category
303 Tools in InfoSec Tools
JavaSerialKiller
by NetSPI
Burp extension to perform Java Deserialization Attacks
Java-Deserialization-Scanner
by federicodotta
All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
AutoRepeater
by nccgroup
Automated HTTP Request Repeating With Burp Suite
Autorize
by Quitten
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
AuthMatrix
by SecurityInnovation
AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.
reflector
by elkokc
Burp plugin able to find reflected XSS on page in real-time while browsing on site
4-ZERO-3
by Dheerajmadhukar
403/401 Bypass Methods + Bash Automation + Your Support ;)
back-me-up
by Dheerajmadhukar
This tool will check for Sensitive Data Leakage with some useful patterns/RegEx. The patterns are mostly targeted on waybackdata and filter everything accordingly.
karma_v2
by Dheerajmadhukar
⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)
Damn-vulnerable-sca
by harekrishnarai
Damn Vulnerable SCA Application
recox
by samhaxr
Master script for web reconnaissance
socialhunter
by utkusen
crawls the website and finds broken social media links that can be hijacked
ImpulsiveDLLHijack
by knight0x07
C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be weaponized during Red Team Operations to evade EDR's.
linux-smart-enumeration
by diego-treitos
Linux enumeration tool for pentesting and CTFs with verbosity levels
Crassus
by vu-ls
An MCP server implementation
Infosec Certifications Resources
Discover the best cybersecurity certifications to advance your career








































Frequently Asked Questions about InfosecMania
Learn more about Cybersecurity Tools and how they can enhance your security posture
InfoSecMania is a comprehensive directory of cybersecurity tools and resources designed to help security professionals find the right tools for their needs.
You can submit a tool by clicking on the 'Submit Tool' link in the navigation menu and filling out the submission form with details about your tool.
No, InfoSecMania includes both free and commercial tools. Each tool listing indicates whether it's free, paid, or offers a freemium model.
Tools are categorized based on their primary function, such as penetration testing, vulnerability assessment, network security, etc. Many tools may appear in multiple categories if they serve multiple purposes.
We only list tools and resources from publicly available, reputable sources — most of which are open-source and widely used in the cybersecurity community. However, always review and test tools in a safe, legal environment, like your lab or VM.
We actively monitor public repositories, GitHub, and community forums to keep our tool listings fresh. Many tools are auto-sourced from open-source feeds and security communities.