Skip to content
@offsec-toolkit

Offensive Security Tools Hub

Offensive security tooling for red teamers, pentesters and security researchers. CLI-first, automation-ready tools.

Popular repositories Loading

  1. mvctrace mvctrace Public

    A production-grade CLI tool for detecting ASP.NET MVC applications and inferring their versions. Designed for security reconnaissance, penetration testing, and web application analysis. MVCTrace he…

    Go 4

  2. linksleuth linksleuth Public

    LinkSleuth is a fast, reliable, and extendable URL discovery and analysis tool written in Go. It allows security researchers and developers to discover endpoints, analyze HTTP responses, and detect…

    Go 2

  3. socialrecon socialrecon Public

    SocialRecon is a high-performance, open-source social media reconnaissance and OSINT security scanner. It identifies social media presence, abandoned profiles, impersonation risks, and brand abuse …

    Go 1

  4. shodansploit shodansploit Public

    shodansploit is a powerful CLI tool for interacting with the Shodan API. It provides both an interactive menu-driven interface and robust command-line capabilities for security researchers, penetra…

    Python

  5. pingscope pingscope Public

    PingScope is a modern, feature-rich, and visually enhanced version of the classic ping tool. It allows you to perform advanced network diagnostics via both a professional CLI and a sleek web dashbo…

    Python

  6. hackertarget hackertarget Public

    Modern command-line interface for HackerTarget network reconnaissance and security testing toolkit. Use open source tools and network intelligence to help organizations with attack surface discover…

    Python

Repositories

Showing 10 of 14 repositories
  • smbseeker Public

    Proactive SMB scanning, discovery, and content analysis tool.

    offsec-toolkit/smbseeker’s past year of commit activity
    Python 0 0 0 0 Updated Jan 7, 2026
  • text-encoder Public

    A powerful, developer-focused text encoding and security utility library and web application. Zero-dependency core library (suitable for Node.js/Browser) + Premium modern Web Interface.

    offsec-toolkit/text-encoder’s past year of commit activity
    TypeScript 0 0 0 0 Updated Jan 5, 2026
  • mvctrace Public

    A production-grade CLI tool for detecting ASP.NET MVC applications and inferring their versions. Designed for security reconnaissance, penetration testing, and web application analysis. MVCTrace helps identify MVC frameworks with high accuracy while minimizing false positives.

    offsec-toolkit/mvctrace’s past year of commit activity
    Go 4 MIT 0 0 0 Updated Jan 5, 2026
  • headersentinel Public

    HeaderSentinel is a high-performance, professional HTTP security analyzer written in Go. It performs deep inspection of HTTP response headers and status behavior to identify security misconfigurations, calculate risk scores, and provide actionable remediation advice.

    offsec-toolkit/headersentinel’s past year of commit activity
    Go 0 0 0 0 Updated Jan 4, 2026
  • socialrecon Public

    SocialRecon is a high-performance, open-source social media reconnaissance and OSINT security scanner. It identifies social media presence, abandoned profiles, impersonation risks, and brand abuse from domains or usernames.

    offsec-toolkit/socialrecon’s past year of commit activity
    Go 1 0 0 0 Updated Jan 4, 2026
  • domainguardian Public

    DomainGuardian is a high-performance, accurate subdomain takeover detection platform. Designed for security researchers, bug bounty hunters, and red teams, it focuses on minimizing false positives through multi-layer validation.

    offsec-toolkit/domainguardian’s past year of commit activity
    Go 0 MIT 0 0 0 Updated Jan 4, 2026
  • linksleuth Public

    LinkSleuth is a fast, reliable, and extendable URL discovery and analysis tool written in Go. It allows security researchers and developers to discover endpoints, analyze HTTP responses, and detect sensitive exposure through a modular and multi-threaded approach.

    offsec-toolkit/linksleuth’s past year of commit activity
    Go 2 0 0 0 Updated Jan 4, 2026
  • jwtscout Public

    JWTScout is an offensive security CLI tool designed to analyze, audit, and exploit JSON Web Token (JWT) vulnerabilities including alg:none, weak secrets, key confusion, and claim manipulation.

    offsec-toolkit/jwtscout’s past year of commit activity
    Go 0 MIT 0 0 0 Updated Jan 4, 2026
  • teensy-redops Public

    Advanced Red Team & Adversary Simulation Research with Teensy Microcontrollers

    offsec-toolkit/teensy-redops’s past year of commit activity
    C++ 0 MIT 0 0 0 Updated Jan 1, 2026
  • ssrfforge Public

    SSRFForge is a high-performance, asynchronous security framework designed for the automated discovery and advanced exploitation of Server-Side Request Forgery (SSRF) vulnerabilities. It serves as a more powerful and modular alternative to legacy tools like SSRFmap.

    offsec-toolkit/ssrfforge’s past year of commit activity
    Python 0 MIT 0 0 0 Updated Jan 1, 2026

Top languages

Loading…

Most used topics

Loading…