Discover
Find tools for your stack. Pick an audience — we handle the noise.
Discover picks for Offensive & Pentesting
See all tools in Offensive & Pentesting →On Hacker News
Ranked by discussion
tailscale
HealthyThe easiest, most secure way to use WireGuard and 2FA.
CyberChef
MixedThe Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
caddy
At RiskFast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS
netbird
MixedConnect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.
pocketbase
HealthyOpen Source realtime backend in 1 file
opensnitch
At RiskOpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch.
pangolin
HealthyIdentity-aware VPN and proxy for remote access to anything, anywhere.
Maigret
Mixed♂ Collect a dossier on a person by username from 3000+ sites
certificates
MixedA private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.
keycloak
HealthyOpen Source Identity and Access Management For Modern Applications and Services
mitmproxy
HealthyAn interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
headscale
At RiskAn open source, self-hosted implementation of the Tailscale control server
Trending now
See all →-
4
Prowler
Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.
Healthy -
3
pentest-ai
Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.
Healthy -
1
sysreptor
A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.
Healthy -
1
Recog
Pattern recognition for hosts, services, and content
Mixed -
1
cyntrisec/cyntrisec-cli
Local-first AWS security analyzer that discovers attack paths and generates remediations using graph theory.
Healthy -
0
Stratus Red Team | DataDog
cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
Healthy -
Anubis
Web AI firewall utility which protects upstream resources from scraper bots.
At Risk -
jadx
Dex to Java decompiler
At Risk -
Lonkero
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
At Risk -
Amass
In-depth attack surface mapping and asset discovery
At Risk -
frida
Clone this repo to build Frida
Mixed -
NullSec Linux
Security-focused Linux distribution with 140+ pre-installed forensic and offensive security tools, custom hardened kernel, and integrated incident response workflows.
At Risk