Tools
Client-side builders, encoders and references β organised by the pentest kill chain. Everything runs in your browser. No accounts, no tracking. Authorized targets only.
Recon & OSINT
-
π΅οΈ Recon / OSINT Helper
Turn a domain or IP into instant pivot links across 25+ OSINT services β Shodan, Censys, VirusTotal, crt.sh and more.
-
π Google Dork Builder
Compose advanced search-engine queries with a live preview and a preset gallery for OSINT and bug bounty.
-
π‘ Nmap Command Builder
Tick scan type, timing, NSE categories and output; watch the Nmap command assemble live, then copy it. Builder only β never scans.
Initial Access
-
πΊ Reverse Shell Generator
Reverse/bind shell templates across common shells, with URL / Base64 / PowerShell encoders and listener helpers.
Password & Auth Attacks
-
π¨ Hashcat / John Rule & Mask Builder
Build Hashcat masks and rules, or John rules, with live sample preview and keyspace estimates. Builder only, no cracking.
-
π§ͺ Hash Identifier
Paste a hash to identify likely algorithms and get the matching Hashcat
-mmode and John format. Offline, in-browser. -
π« JWT Decoder & Analyzer
Decode a JSON Web Token's header, payload and claims and flag weak algorithms, expiry and common misconfigurations. No upload, no verification.
Reporting & Comms
-
π Pentest Report Builder
Draft a report with executive summary, scope, methodology and findings plus a CVSS 3.1 calculator. Export Markdown / HTML / PDF. Private by design β nothing stored or uploaded.
-
π¨ Red-Team Comms Builder
Fast engagement emails β kickoff, status, and especially incident/mistake, out-of-scope and deconfliction β exported as .eml, mailto, .txt, Markdown or copy.
References & Cheat Sheets
-
π» LOLBin / GTFOBins Browser
Searchable reference of living-off-the-land binaries by abuse function, with MITRE ATT&CK cross-links.