Supercharge your testing
Get hand curated best software testing tools and articles. Every Week β for free!



Join 3000+ people getting hand-picked round-up of best resources and articles on Software Testing.
The best Security Testing tools and resources on the internet.
Over 48+ awesome Security Testing tools and resources on the internet to supercharge your testing.

WAF Checker
FreeCheck how well your Web Application Firewall (WAF) protects your product against common web attacks.
RedCoffee
FreeGenerate insightful PDF Reports for code analysis done using SonarQube Community Edition
Metasploit
FreeThe worldβs most used penetration testing framework

NetExec
FreeUltimate Network Service Exploitation Tool
Mobile Security Framework (MobSF)
FreeAll-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework.

Web Check
Freeπ΅οΈββοΈ All-in-one OSINT tool for analysing any website

Indetectables Toolkit
Free98 apps to perform reverse engineering and binary/malware analysis.
Lynis
FreeSecurity auditing and hardening tool, for UNIX-based systems.
Payloads All The Things
FreeA list of useful payloads and bypasses for Web Application Security

Burp Suite Logger++
FreeAdvanced Logging for Burp Suite.
Postman Security Test Generator
FreeExecute role based security tests on APIs
Open CRE
FreeA platform that interactively links resources together using connecting threats, weaknesses, standards, code samples, and test instructions.
MalwareBazaar
FreeThe purpose of the project is to collect and share malware samples.

Trufflehog
FreeSniffing out credentials.
XSSHunter
FreeUse Docker and Dockery Compose to test and find blind cross-site scripting vulnerabilities.

GradeJS
FreeAnalyze webpack production bundle

Cherrybomb
FreeA CLI tool that helps you avoid undefined user behaviour by validating your API specifications.

BITB
FreeBrowser templates for Browser In The Browser (BITB) attack.
Lockfile Lint
FreeLint an npm or Yarn lockfile to analyze and detect security issues via predefined security policies.
RapiDAST
FreeSimple, continuous and fully automated application security testing.
Nogotofail
FreeAn on-path blackbox network traffic security testing tool
Wfuzz
FreeAutomate web applications security assessments

beef
FreeIt is a penetration testing tool that focuses on the web browser.

Arachni
FreeWeb Application Security Scanner Framework
Wapiti
FreeWeb vulnerability scanner written in Python3

Security List
FreeCurated lists of tools, tips and resources for protecting digital security and privacy
Violating GDPR
FreeEnter a URL and this tool will tell you if the website is violating GDPR laws.
Static Code Analysis
FreeList of Static Code Analyzers
DenyHosts
FreeDenyHosts is a script intended to be run by Linux system administrators to help thwart SSH server attacks (also known as dictionary based attacks and brute force attacks).

Fail2ban
FreeIt scans log files (e.g. /var/log/apache/error_log) and bans IPs that show the malicious signs -- too many password failures, seeking for exploits, etc

Mozilla Observatory
Freeonline tool that you can use to check any websiteβs header status.

PrivacyTests
Freeopen source tests of web browser privacy.
Semgrep
FreeStatic analysis at ludicrous speed.

Terrascan
FreeStatic code analyzer for Infrastructure as Code

gitleaks
FreeScan git repos (or files) for secrets using regex and entropy π

Deepfence ThreatMapper
FreeIdentify vulnerabilities in running containers, images, hosts and repositories
Awesome Penetration Testing
FreeA collection of awesome penetration testing and offensive cybersecurity resources.

Mariana Trench
FreeMariana Trench is a security focused static analysis platform targeting Android.

SonarLint
FreeClean Code starts in your IDE
Nuclei Templates
FreeCommunity curated list of templates for the nuclei engine to find security vulnerabilities in applications.
Pentest Bookmarkz
FreeA collection of useful links for Pentesters

Mobile Security Framework
FreeMobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

Nmap Security Scanner
FreeSecurity Testing

security.txt
FreeSecurity standard
sqlmap
FreeAutomatic SQL injection and database takeover tool
Tails
FreeOperating System
Kali Linux
FreeOperatng System

Zap
FreeScanning tool for security vulnerabilities