pongoOS
Pre-boot environment for Apple boards built on checkra1n, useful in post-exploitation.
dnSpy
Debugger and editor for .NET and Unity assemblies, even without source code access.
HackTools
Browser extension with payloads, cheatsheets, shells for web app penetration testing.
MaskPhish
Bash script to hide phishing URLs under legit-looking links like google.com or facebook.com.
MUD Visualizer
Tool to visualize MUD (Manufacturer Usage Description) files in JSON format for IoT auditing.
PIDRILA
Fast async web path scanner focused on deepweb link analysis for ethical netstalkers.
longtongue
Generates custom password lists using target info for brute-force or dictionary attacks.
Open GApps
Pre-built GApps packages for custom Android ROMs, available at opengapps.org.
Exif GPS Tracer
Python script to extract geolocation from images, outputs to CSV and Google Maps HTML.
InfraChart
InfraChart maps and visualizes attack surfaces using graphs during penetration testing.
WP Recon
Tool for vulnerability recognition and blackbox info gathering on WordPress sites.
emp3r0r
Advanced post-exploitation framework for Linux/Windows with integrated C2 capabilities.
ProtOSINT
Python script to investigate ProtonMail accounts and ProtonVPN IP addresses.
Umbrella
Android app with security guides and tools for human rights defenders in risky situations.
Elkeid
Open-source EDR for hosts, containers, K8s, and serverless based on ByteDance's internal practices.
SysWhispers2
Generates direct syscall headers/ASM for evasion and privilege escalation in post-exploitation.
MemProcFS
Analyzes physical memory via virtual filesystem with easy access and feature-rich API.
ImHex
Modern hex editor for reverse engineers and programmers, retina-friendly for late hours.
Token-Hunter
Collect OSINT from GitLab groups and scan for sensitive data in GitLab assets.
JD-GUI
Graphical tool to view Java source code from .class files quickly and conveniently.
bundletool
Manipulates Android App and SDK Bundles for analysis and publishing on platforms like Play Store.