Researcher Resources - Tools


I have a plethora of tools i can link and talk about, maybe a tools subforum would be appropriate instead of s thread?


Yeah, that may be something that we do eventually as the forum grows and this thread grows along with it. In these early stages of the forum’s launch I’d like to keep things relatively consolidated and then spread out as the need arises.

For now, please feel free to start new threads discussing particular tools and sets of tools. You can use the “Security Research” category for those threads. Then from those threads we can start consolidating lists and pull them into this master thread :smile:


I highly recommend people use the latest data to find additional hosts that may be in scope for those * targets!


I’ll toss in R & (when your data gets HUGE) Spark as some “out of the box” thinking when it comes to “tools”. Don’t get me wrong, I :heart: a great deal of the infosec-specific ones listed, but we also need more statistical analysis & better visuals coming out of our space. There are many, many packages in R that can help in the infosec domain. We post alot on and talk abt them quite a bit on the twitterz.

Also, don’t forget PhantomJS (unless I missed seeing it in the lists above) [can’t post a third link, too n00b here].


As demonstrated at Shmoocon this year, httpscreenshot is a fantastic tool to quickly and visually identify targets.


At the office this morning we had a micro-ctf, two challenges required de-obsfucating javascript. Many used and =)


iOS App Security Assessment Tool : idb
Comprehensive security and attack framework for Android : drozer


Here… My open redirect scanner… works like a charm…




You should add pen test box. (


