My own list of CTF tools (ongoing WIP)
- https://gchq.github.io/CyberChef/
- https://emn178.github.io/online-tools/index.html
- https://www.freeformatter.com/javascript-beautifier.html
- https://github.com/Gallopsled/pwntools
- https://github.com/danielmiessler/SecLists
- https://github.com/AlessandroZ/LaZagne
- https://app.any.run
- https://ctftime.org/
- https://ctfsites.github.io/
- https://github.com/ctfs
- https://codepoints.net/
- Unix (GTFOBINS) https://gtfobins.github.io
- Windows (LOLBAS) https://lolbas-project.github.io
- AD (WADComs https://wadcoms.github.io
- Living Off Trusted Sites https://lots-project.com/
- https://theasciicode.com.ar/ascii-control-characters/start-of-header-ascii-code-1.html
- https://unicodedecode.com/
- Bandit-HaxUnit/haxunit : combines multiple active and passive subdomain enumeration tools and port scanning tools with vulnerability discovery tools.
- https://dorksearch.com/ : Faster Google Dorking
- Example hashes & mode
- https://godbolt.org/ (Compiler Explorer)
- Cisco Type 7 Password Cracker
- Cisco Type 5 Password Cracker
- androidpatternlock : A little Python tool to crack the Pattern Lock on Android devices
- dd : convert and copy a file
- convert : convert between image formats as well as resize an image, blur, crop, despeckle, dither, draw on, flip, join, re-sample, and much more
- identify : describes the format and characteristics of one or more image files
- stegbreak : launches brute-force dictionary attacks on JPG image
- https://k-lfa.info/quelques-tools-forensics/
- https://www.osforensics.com/tools/volatility-workbench.html
- https://github.com/TZK-/ctf/find/master
- File Identifier : identify file types from their binary signatures
- binwalk
- foremost : Console program to recover files based on their headers, footers, and internal data structures
- ExifTool
- Computer Aided INvestigative Environment (CAINE) Linux forensics live distribution
- The Sleuth Kit (TSK) (repo)
- volatility
- FTK-Imager
- dd_rescue : data recovery tool man page
- ntfsundelete
- fatback
- (unix/linux tool) photorec Recover lost files from harddisk, digital camera and cdrom
- (unix/linux tool) kpartx Create device maps from partition tables
- (unix/linux tool) udisksctl : Shows high-level information about disk drives and block devices.
- (unix/linux tool) Mmls : displays the contents of a volume system (media management) man page
- (unix/linux tool) fls : lists the files and directory names in a file system man page
- (unix/linux tool) file : determine file type
- strings : print the strings of printable characters in files
- (unix/linux tool)
- chainbreaker : Mac OS X Keychain Forensic Tool
- plistutil : Python utilities related to plists (Apple Property List files)
- MacInHash : Convert MacOS plist password file to hash file for password crackers
- dumpzilla : Analyze the Mozilla profile folder and dump everything except the DOM data (–All)
- ANSSI-FR/bmc-tools : *RDP Bitmap Cache parser *
- (Online) https://www.dcode.fr/
- (Online) http://multiencoder.com/
- (Online) https://hashgenerator.de/
- (Online) https://cryptii.com/ : Modular conversion, encoding and encryption online
- (Online) http://rumkin.com/tools/cipher/ : Cipher list
- (Online) run-length encoder/decoder (RLE)
- RsaCtfTool : retreive private key from weak public key and/or uncipher data
- Rail Fence: https://crypto.interactive-maths.com/rail-fence-cipher.html
- Ceasar; https://www.xarg.org/tools/caesar-cipher/
- Vigenère: https://f00l.de/hacking/vigenere.php / https://www.mygeocachingprofile.com/codebreaker.vigenerecipher.aspx / Vigenere Solver
- https://www.quipqiup.com/ (automated cryptogram solver)
- http://pi.math.cornell.edu/~mec/Summer2008/lundell/lecture1.html Lecture 1: Shift Ciphers
- https://www.apprendre-en-ligne.net/crypto/subst/
- https://www.cryptool.org/en/cto/
- http://rumkin.com/tools/cipher/
- https://github.com/bwall/HashPump
- http://www.openwall.com/john/
- https://github.com/hellman/xortool
- https://copy.sh/brainfuck/ : Encode/Decode Brainfuck
- Try It Online : online interpreters for a list of practical and recreational programming languages
- Universal Leet Converter
- https://md5hashing.net/
- https://www.md5online.org/
- https://decryptpassword.com/home/
- Cipher Identifier and Analyzer
- unode/firefox_decrypt : xtract passwords from Mozilla (Firefox™, Waterfox™, Thunderbird®, SeaMonkey®) profiles
- https://book.hacktricks.xyz/stego/stego-tricks
- https://en.wikipedia.org/wiki/Steganography_tools
- https://www.kitploit.com/2018/06/stego-toolkit-collection-of.html
- stego-toolkit : Docker image with Collection of steganography tools
- (Online) https://aperisolve.fr/ : layer analysis on image. Uses zsteg, steghide, outguess, exiftool, binwalk, foremost and strings
- (Online) https://stegonline.georgeom.net/upload
- (Online)Unicode Text Steganography
- (Online) npiet online (piet)
- (Online) https://futureboy.us/stegano/
- (Online) https://incoherency.co.uk/image-steganography/
- (Audio) Sonic-Visualizer
- (Audio) danielcardeenas/AudioStego - hideme
- (Audio) Audacity
- (Audio) spectrology
- (Audio) mp3stego
- (Audio) WavePad
- (Audio) QSSTV - https://charlesreid1.com/wiki/Qsstv
- (Audio) MP3Stego
- (Audio) Wavsteg
- (Video) FFmpeg
- (PDF) pdf-parser
- (PDF) peepdf - https://eternal-todo.com/tools/peepdf-pdf-analysis-tool
- LSB-Steganography
- https://exiftool.org/
- (Online) http://exif.regex.info/exif.cgi
- Exiv2 repo
- Steganabara
- Steghide - repo
- Stegsolve - Stegsolve.jar
- Foremost - repo
- pngcheck
- stegoVeritas
- zsteg
- LSBSteg
- stegdetect (Unmaintained)
- jphide & jpseek - http://linux01.gwdg.de/~alatham/stego.html
- jsteg
- OpenStego - syvaidya/openstego
- OutGuess : universal steganographic tool - https://outguess.rbcafe.com/
- cedricbonhomme/Stegano - https://sr.ht/~cedric/stegano/ : pure Python Steganography module
- Cloacked-Pixel
- stegsnow : conceal messages in ASCII text by appending whitespaces to the end of lines
- StegFS
- Twitter Secret Messages
- Deogol : HTML steganography too
- Stegpy : steganalysis script writen in Python
- StegCracker : Steganography brute-force utility to uncover hidden data inside files
- (Online) A-Packets : Online pcap file analyzer
- (Online) Google Admin Toolbox : dig / Check MX / HAR Analyzer / Log Analyzer / Browserinfo
- (Online) SMS PDU Decoder
- Wireshark / tshark
- OpenSSL
- tcpdump
- netcat
- nmap
- jopohl/urh : Universal Radio Hacker: Investigate Wireless Protocols Like A Boss
- miek/inspectrum : Radio signal analyser
- snmp0wn-md5 : ash script to bruteforce snmpv3 authentication passwords using MD5 (usmHMACMD5AuthProtocol)
Online
Windows:
Linux:
- (Online) https://book.hacktricks.xyz/reversing/reversing-tools-basic-methods
- (Online) disassembler.io : Online Disassembler
- (Online) http://www.javadecompilers.com/ : .JAR and .Class to Java decompiler
- (Online) https://www.hybrid-analysis.com/ :
- GDB : The GNU Project Debugger
- IDA Pro
- Immunity Debugger / Download
- OllyDbg
- radare2 / repo
- Hopper
- (unix/linux tool) nm : list symbols from object files
- (unix/linux tool) objdump : display information from object files
- (unix/linux tool) strace : trace system calls and signals
- (unix/linux tool) ltrace : A library call tracer
- ILSpy / (old website)
- JD-GUI
- JPEXS Free Flash Decompiler / (old website)
- dex2jar / repo
- uncompyle2
- https://reqbin.com/ : online API testing tool for REST and SOAP APIs
- js-beautifier : Beautify, unpack or deobfuscate JavaScript and HTML, make JSON/JSONP readable, etc
- http://jsonviewer.stack.hu/
- https://pentest-tools.com/
- TableConvert : Convert CSV to [everything] Table
- https://jsconsole.com/ : **
- https://osintframework.com/ (repo)
- https://inteltechniques.com/
- ProtOSINT : Python script that helps you investigate Protonmail accounts and ProtonVPN IP addresses
- iknowwhatyoudownload.com
- https://amccormack.net/2012-01-22-anatomy-of-a-pdf-document.html
- http://nicob.net/insomnihack_2010/epreuves_pdf.html
- http://nicob.net/insomnihack_2010/1.pdf
- Didier Stevens' Tools : https://blog.didierstevens.com/programs/pdf-tools/
- Origami : http://seclabs.org/origami/
- QPDF : http://qpdf.sourceforge.net/