MrYellowOwl

Security Tools Directory

A curated collection of the most effective offensive and defensive security tools, organised by phase.

99 Tools
11 Categories
Free All open source

Reconnaissance

9 tools

Gather intelligence before engaging a target. These tools help map attack surfaces, discover exposed assets, and collect OSINT.

Scanning

9 tools

Identify open ports, running services, and live hosts on a network. Scanning is the foundation of any active engagement.

Vulnerability Assessment

9 tools

Identify weaknesses in systems, applications, and networks before attackers can exploit them.

Exploitation

9 tools

Leverage discovered vulnerabilities to gain access. These tools are used in authorised penetration tests to simulate real attacks.

Password Cracking

9 tools

Recover plaintext passwords from captured hashes or brute force authentication services. Essential for credential testing.

Web Application Security

9 tools

Intercept, analyse, and manipulate web traffic. These tools are the backbone of every web application penetration test and bug bounty hunt.

Network Traffic Analysis

9 tools

Capture, filter, and dissect network packets to uncover credentials, plaintext data, and suspicious behaviour in real time.

Forensics & Reverse Engineering

9 tools

Analyse malware, disassemble binaries, recover deleted files, and extract artefacts from memory dumps. Core skills for CTF and incident response.

Cryptography & CTF Tools

9 tools

Encode, decode, crack ciphers, and solve CTF challenges. These tools cover everything from classical crypto to modern hash analysis and steganography.

Social Engineering

9 tools

The human element is the weakest link. These tools simulate phishing campaigns, credential harvesting, and social manipulation attacks.

Post-Exploitation

9 tools

Actions taken after gaining initial access — lateral movement, privilege escalation, persistence, and data exfiltration.