Try searching for "database", "file", "API", or browse by category
313 Tools in InfoSec Tools
BugBountyBooks
by akr3ch
A collection of PDF/books about the modern web application security and bug bounty.
aem-hacker
by 0ang3el
An MCP server implementation
SubEnum
by bing0o
bash script for Subdomain Enumeration
VulnerableLightApp
by Aif4thah
Vulnerable API for research and education
dvta
by srini0x00
Damn Vulnerable Thick Client App developed in C# .NET
vulnerable-nginx
by detectify
An intentionally vulnerable NGINX setup
log-snare
by sea-erkin
LogSnare: A playground for testing, preventing, and logging IDOR vulnerabilities.
skf-labs
by blabla1337
Repo for all the SKF Docker lab examples
Damn-Vulnerable-GraphQL-Application
by dolevf
Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.
exploit-workshop
by snyk-labs
A step by step workshop to exploit various vulnerabilities in Node.js and Java applications
dvws-node
by snoopysecurity
Damn Vulnerable Web Services is a vulnerable application with a web service and an API that can be used to learn about webservices/API related vulnerabilities.
dvwp
by vavkamil
Damn Vulnerable WordPress
docker-java-xxe
by pimps
Docker image to test XXE attacks in java with tomcat.
xxelab
by jbarone
A simple web app with a XXE vulnerability.
xssable
by kiwicom
A vulnerable blogging platform used to demonstrate XSS vulnerabilities.
Infosec Certifications Resources
Discover the best cybersecurity certifications to advance your career








































Frequently Asked Questions about InfosecMania
Learn more about Cybersecurity Tools and how they can enhance your security posture
InfoSecMania is a comprehensive directory of cybersecurity tools and resources designed to help security professionals find the right tools for their needs.
You can submit a tool by clicking on the 'Submit Tool' link in the navigation menu and filling out the submission form with details about your tool.
No, InfoSecMania includes both free and commercial tools. Each tool listing indicates whether it's free, paid, or offers a freemium model.
Tools are categorized based on their primary function, such as penetration testing, vulnerability assessment, network security, etc. Many tools may appear in multiple categories if they serve multiple purposes.
We only list tools and resources from publicly available, reputable sources — most of which are open-source and widely used in the cybersecurity community. However, always review and test tools in a safe, legal environment, like your lab or VM.
We actively monitor public repositories, GitHub, and community forums to keep our tool listings fresh. Many tools are auto-sourced from open-source feeds and security communities.