{"id":669,"date":"2020-12-29T16:48:20","date_gmt":"2020-12-29T16:48:20","guid":{"rendered":"https:\/\/dft.wiki\/?p=669"},"modified":"2025-12-28T12:06:23","modified_gmt":"2025-12-28T17:06:23","slug":"cyber-security-sites-and-tools-you-need-to-know-about","status":"publish","type":"post","link":"https:\/\/dft.wiki\/?p=669","title":{"rendered":"Cyber Security Sites, Tools and Tips"},"content":{"rendered":"<p><a href=\"https:\/\/darknetdiaries.com\/\">Darknet Diaries<\/a> &#8211; An excellent bi-weekly podcast about cybersecurity, hackers, the dark web, and much more.<\/p>\n<p><a href=\"https:\/\/twit.tv\/shows\/security-now\">Security Now<\/a> &#8211; A weekly technical cybersecurity podcast (by <a href=\"https:\/\/www.grc.com\/securitynow.htm\">GRC<\/a>) over Video and Audio.<\/p>\n<p><a href=\"https:\/\/www.gog.show\/\">Grumpy Old Geeks<\/a> &#8211; A weekly humor show on the cybersecurity and Internet theme. &#8220;What went wrong on the Internet and who is to blame!&#8221;<\/p>\n<p><a href=\"https:\/\/thecyberwire.com\/podcasts\">The Cyber Wire<\/a> &#8211; A daily source of cyber news and IT careers.<\/p>\n<p><a href=\"https:\/\/www.social-engineer.org\/category\/podcast\/\">The Social-Engineer Podcast<\/a> &#8211; The title already talks for itself.<\/p>\n<p><a href=\"https:\/\/www.virustotal.com\/\">Virus Total<\/a> &#8211; A website created by a cybersecurity company that has information about viruses, worms, malware, etc.<\/p>\n<p><a href=\"https:\/\/otx.alienvault.com\/\">Alien Vault<\/a> &#8211; Similar to Virus Total but claims to the a fully open threat intelligence community.<\/p>\n<p><a href=\"https:\/\/viz.greynoise.io\/\">GrayNoise<\/a> &#8211; It collects, analyzes, and labels data by IPs that scan the internet and saturate security tools with noise.<\/p>\n<p><a href=\"https:\/\/antiscan.me\/\">AntiScan<\/a> and <a href=\"https:\/\/dyncheck.com\/\">DynCheck<\/a> &#8211; Free online multi-antivirus scanners.<\/p>\n<p><a href=\"https:\/\/gtmetrix.com\/\">GTmetrix<\/a> &#8211; Designed to test the speed of loading a website, but also gives reports of the content and the percentage of each language used in it.<\/p>\n<p><a href=\"https:\/\/pagespeed.web.dev\/\">PageSpeed Insights<\/a> &#8211; Creates reports on the performance of a page on both mobile and desktop devices, and provides suggestions on how that page may be improved.<\/p>\n<p><a href=\"https:\/\/web.dev\/measure\/\">Web.Dev<\/a> &#8211; Test your pages in a lab environment, then get tips and recommendations to improve your user experience.<\/p>\n<p><a href=\"https:\/\/seositecheckup.com\/\">SEO SiteCheckup<\/a> Supercharged analysis &amp; monitoring tool for SEO (Search Engine Optimization).<\/p>\n<p><a href=\"https:\/\/ipv6-test.com\/\">IPv6 Test<\/a> &#8211; Checks your IPv6 and IPv4 connectivity and speed, but can also test if your website (DNS and Host) is &#8220;IPv6 Ready&#8221;.<\/p>\n<p><a href=\"https:\/\/securityheaders.com\/\">Security Header<\/a> &#8211; Check the security header of a website.<\/p>\n<p><a href=\"https:\/\/www.torproject.org\/\">Tor Browser<\/a> &#8211; an encryption browser that uses relays and proxies all over the world to protect the privacy of users.<\/p>\n<p><a href=\"https:\/\/tails.boum.org\/\">Tails Linux<\/a> &#8211; a Linux distribution designed to forget everything during the shutdown.<\/p>\n<p><a href=\"https:\/\/www.kali.org\/\">Kali Linux<\/a> &#8211; a Linux distribution designed to test the security of networks and systems.<\/p>\n<p><a href=\"https:\/\/www.parrotsec.org\/\">Parrot OS<\/a> &#8211; A lightweight but as powerful as Kali offensive distribution. It is based on Debian 13 and uses Plasma 6 with Wayland by default.<\/p>\n<p><a href=\"https:\/\/pentest.ws\/\">Pentest.WS<\/a> &#8211; A collaborative interface to work with NMAP scans and Inventory + Vulnerabilities. Good tool for a Team CTF.<\/p>\n<p><a href=\"https:\/\/github.com\/trustedsec\/ptf\/\">The PenTesters Framework<\/a> &#8211; No matter the distribution, PTF is a toolset to easily install and keep all the most popular pentesting applications up-to-date all the time.<\/p>\n<p><a href=\"https:\/\/crackstation.net\/\">CrackStation<\/a> &#8211; Free web password hash cracker and passwords list file to download called <strong>RealUniq<\/strong> with over 1.4 Bi entries.<\/p>\n<p><a href=\"http:\/\/tunnelsup.com\/\">TunnelsUp<\/a> &#8211; a source of cybersecurity information and tools, including a web hash analyzer [<a href=\"https:\/\/www.tunnelsup.com\/hash-analyzer\/\">Link<\/a>].<\/p>\n<p><a href=\"https:\/\/github.com\/danielmiessler\/SecLists\">SecLists<\/a> &#8211; a collection of multiple types of lists (password lists, for example) used during security assessments, collected in one place.<\/p>\n<p><a href=\"https:\/\/project-rainbowcrack.com\/table.htm\">Project RainbowCrack<\/a> &#8211; a source of rainbow password lists. The huge list of passwords had already been cracked, and it is just a matter of cross-checking the hashes.<\/p>\n<p><a href=\"https:\/\/github.com\/philipperemy\/tensorflow-1.4-billion-password-analysis\">1.4 Billion Text Credentials Analysis (NLP)<\/a> &#8211; Also available to download via Torrent.<\/p>\n<p><a href=\"https:\/\/github.com\/malwaredllc\/byob\">BYOB<\/a> &#8211; Framework to build and create command and control zombie bots (use only for educational purposes).<\/p>\n<p><a href=\"https:\/\/github.com\/ReclaimYourPrivacy\/eschalot\">Eschalot<\/a> &#8211; It is a tool to create a secure address for your service using the .onion domain in the Tor network.<\/p>\n<p><a href=\"http:\/\/onion.ly\/\">Onion.ly<\/a> &#8211; Tor2Web Proxy (try *****.onion<strong>.ly<\/strong>).<\/p>\n<p><a href=\"https:\/\/xerosecurity.com\/\">Sn1per<\/a> &#8211; Automated scanner that can be used during a penetration test to enumerate and scan for vulnerabilities. Also able to run in a Docker [<a href=\"https:\/\/github.com\/1N3\/Sn1per\">Link<\/a>].<\/p>\n<p><a href=\"https:\/\/www.tenable.com\/products\/nessus\/nessus-essentials\">Nessus<\/a> &#8211; Powerful Professional Scanner.<\/p>\n<p><a href=\"http:\/\/dvwa.co.uk\/\">DVWA<\/a> &#8211; Damn Vulnerable Web App is a PHP\/MySQL web application that is damn vulnerable. Also available for Docker [<a href=\"https:\/\/hub.docker.com\/r\/vulnerables\/web-dvwa\">Link<\/a>].<\/p>\n<p><a href=\"http:\/\/ironwasp.org\/\">IronWASP<\/a> &#8211; An open-source tool used for web application vulnerability testing, crawling, and more.<\/p>\n<p><a href=\"https:\/\/github.com\/reconness\/reconness\">ReconNess<\/a> &#8211; It helps to run and keep all your reconnaissance in the same place, focusing on the potentially vulnerable targets.<\/p>\n<p><a href=\"https:\/\/github.com\/j3ssie\/Osmedeus\">Osmedeus<\/a> &#8211; A collection of awesome tools for reconnaissance and vulnerability scanning against the target.<\/p>\n<p><a href=\"https:\/\/nc110.sourceforge.io\/\">Netcat<\/a> &#8211; A Tool for tunneling connections (transfer files, remote shell, etc).<\/p>\n<p><a href=\"https:\/\/www.cvedetails.com\/\">CVE Details<\/a> &#8211; Security Vulnerability Database.<\/p>\n<p><a href=\"https:\/\/hunter.io\/\">Hunter<\/a> &#8211; Information Gathering Pool for OSINT.<\/p>\n<p><a href=\"https:\/\/www.offensive-security.com\/metasploit-unleashed\/\">Metasploit Unleashed<\/a> &#8211; Metasploit documentation manual.<\/p>\n<p><a href=\"https:\/\/information.rapid7.com\/download-metasploitable-2017.html\">Metasploitable<\/a> &#8211; intentionally vulnerable target machine for exploitation exercises.<\/p>\n<p><a href=\"https:\/\/github.com\/Veil-Framework\/Veil-Evasion\">Veil-Evasion<\/a> &#8211; Pentest Framework.<\/p>\n<p><a href=\"https:\/\/www.offensive-security.com\/metasploit-unleashed\/msfvenom\/\">MSFvenom<\/a> &#8211; A combination of Msfpayload and Msfencode in one Framework.<\/p>\n<p><a href=\"http:\/\/www.fastandeasyhacking.com\/\">Armitage<\/a> &#8211; Free graphic interface for MSF.<\/p>\n<p><a href=\"https:\/\/www.cobaltstrike.com\/download\">Cobalt Strike<\/a> &#8211; Licensed graphic interface for MSF.<\/p>\n<p><a href=\"https:\/\/github.com\/EmpireProject\/Empire\">Empire<\/a> &#8211; A Windows and macOS post-exploitation framework that includes a pure-PowerShell2.0 Windows agent, and a pure Python 2.6\/2.7 Linux\/OS X agent.<\/p>\n<p><a href=\"https:\/\/hub.docker.com\/r\/koutto\/jok3r\/\">Jok3r<\/a> &#8211; It is a framework that aids penetration testers for network infrastructure and web security assessments.<\/p>\n<p><a href=\"https:\/\/www.exploit-db.com\/\">Exploit Database<\/a> &#8211; An archive\u00a0of public exploits and corresponding vulnerable software.<\/p>\n<p><a href=\"https:\/\/www.hackthebox.eu\/\">HackTheBox<\/a> &#8211; An online platform allowing you to test your penetration testing skills.<\/p>\n<p><a href=\"https:\/\/www.vulnhub.com\/\">VulnHub<\/a> &#8211; Exercise hundreds of virtual machines with laboratory exercises already set up for vulnerability\/penetration testing.<\/p>\n<p><a href=\"https:\/\/cmdchallenge.com\/\">Command Challenge<\/a> &#8211; Exercise commands and learn how to solve issues in the CLI.<\/p>\n<p><a href=\"https:\/\/picoctf.org\/\">picoCFT<\/a> &#8211; Where you can compete or exercise using picoGym: a non-competitive practice space to explore and solve challenges from previously released picoCTF competitions.<\/p>\n<p><a href=\"http:\/\/deftlinux.net\/\">DEFT Linux<\/a> &#8211; DEFT (Digital Evidence &amp; Forensic Toolkit) is a Ubuntu-based Live distribution dedicated to incident response and computer forensics.<\/p>\n<p><a href=\"https:\/\/github.com\/mandiant\/flare-wmi\">python-cim<\/a> &#8211; Forensics for analyzing WMI (events log).<\/p>\n<p><a href=\"https:\/\/www.cloudflare.com\/\">Cloudflare<\/a> &#8211; It is a free CDN (Content Delivery Network) and Web App Firewall that uses a network of proxies and offers optimization features such as caching, code optimization, and more.<\/p>\n<p><a href=\"https:\/\/sourceforge.net\/projects\/owaspbwa\/\">OWASP Broken Web Application Project<\/a> &#8211; It is a collection of vulnerable web applications that is distributed on a Virtual Machine in VMware format.<\/p>\n<p><a href=\"https:\/\/owasp.org\/www-project-webgoat\/\">OWASP Web Goat<\/a> &#8211; It allows developers to test vulnerabilities commonly found in Java-based applications that use common and popular open-source components.<\/p>\n<p><a href=\"https:\/\/owasp.org\/www-project-juice-shop\/\">OWASP Juice Shop<\/a> &#8211; Contains vulnerabilities from the entire <a href=\"https:\/\/owasp.org\/www-project-top-ten\/\">OWASP Top Ten<\/a>, along with many other security flaws found in real-world applications.<\/p>\n<p><a href=\"https:\/\/www.jsonwebtoken.io\/\">JSON Web Token<\/a> and <a href=\"https:\/\/jwt.io\/\">JWT<\/a> &#8211; Encodes and Decodes JSON Web Tokens.<\/p>\n<p><a href=\"https:\/\/chrome.google.com\/webstore\/detail\/wappalyzer\/gppongmhjkpfnbhagpmjfkannfbllamg?hl=en\">Wappalyzer<\/a> &#8211; It is a technology profiler that shows you what websites are built with.<\/p>\n<p><a href=\"https:\/\/www.unixtimestamp.com\/\">Dan&#8217;s Tools<\/a> &#8211; Epoch &amp; Unix Timestamp Conversion Tools. See also the other tools for convert, encode\/decode, format&#8230;<\/p>\n<p><a href=\"https:\/\/gchq.github.io\/CyberChef\/\">CyberChef<\/a> &#8211; Online encryption and decryption tool.<\/p>\n<p><a href=\"https:\/\/getoutline.org\/\">Outline VPN<\/a> &#8211; It is an open-source VPN that runs on Docker and was created by Google and other partners.<\/p>\n<p><a href=\"https:\/\/www.shodan.io\/\">Shodan<\/a> &#8211; A search engine for Internet-connected devices. Great OSINT source of available ports and what may be available in there. Also available on Kali CLI.<\/p>\n<p><a href=\"https:\/\/censys.io\/\">Censys<\/a> &#8211; An Internet scanner similar to Shodan, but more focused on a specific address than random searches.<\/p>\n<p><a href=\"https:\/\/wigle.net\/\">Wigle<\/a> &#8211; A live map of all found wireless networks on the planet.<\/p>\n<p><a href=\"https:\/\/spyse.com\/\">Spyse<\/a> &#8211; Good database of port scans with fingerprints that may reveal OS and application versions.<\/p>\n<p><a href=\"https:\/\/securitytrails.com\/\">Security Trails<\/a> &#8211; One more database of port scans and domain information.<\/p>\n<p><a href=\"https:\/\/intelx.io\/\">IntelligenceX<\/a> &#8211; OSINT tool capable of retrieving information about data breaches, bitcoin addresses, domain information, and more.<\/p>\n<p><a href=\"https:\/\/github.com\/swisskyrepo\/PayloadsAllTheThings\">Payloads All The Things<\/a> &#8211; Huge collection of payloads of all types. Not only the list of payloads, but also a lot of instructions and exercises.<\/p>\n<p><a href=\"https:\/\/github.com\/payloadbox\/sql-injection-payload-list\">SQL Injection Payload List<\/a> &#8211; Collection and instructions of exploits.<\/p>\n<p><a href=\"https:\/\/github.com\/payloadbox\/xxe-injection-payload-list\">XXE Injection Payloads List<\/a> &#8211; Collection and instructions of exploits.<\/p>\n<p><a href=\"https:\/\/github.com\/pgaijin66\/XSS-Payloads\">XSS Payloads<\/a> &#8211; Collection of XSS payloads.<\/p>\n<p><a href=\"https:\/\/www.ssllabs.com\/ssltest\/index.html\">SSL Server Test<\/a> &#8211; Free web service to evaluate the SSL\/TLS configuration of your web server.<\/p>\n<p><a href=\"https:\/\/badssl.com\/\">Bad SSL<\/a> &#8211; This website is a collection of crafted samples of non-compliant certificates for browser and client tests.<\/p>\n<p><a href=\"https:\/\/ondmarc.redsift.com\/\">ONDMARC<\/a> &#8211; Check the configuration of SPF and DKIM of a mail server.<\/p>\n<p><a href=\"https:\/\/protonmail.com\/\">ProtonMail<\/a> &#8211; Encrypted and anonymous email provider.<\/p>\n<p><a href=\"https:\/\/tutanota.com\/\">Tutanota<\/a> &#8211; Encrypted and anonymous email provider.<\/p>\n<p><a href=\"https:\/\/coveryourtracks.eff.org\/\">CoverYourTracks<\/a> &#8211; Browser privacy tester from EFF ().<\/p>\n<p><a href=\"https:\/\/www.privacytools.io\/\">PrivacyTools.io<\/a> &#8211; Provides services, tools, and knowledge to protect your privacy against global mass surveillance.<\/p>\n<p><a href=\"https:\/\/justdeleteme.xyz\/\">JustDeleteMe.xyz<\/a>\u00a0&#8211; A directory of direct links to delete your account from web services.<\/p>\n<p><a href=\"https:\/\/builtwith.com\/\">BuiltWith<\/a> &#8211; Free web service to analyse what framework a website is of. Alternatively, check the browser extension called Wappalyzer [<a href=\"https:\/\/www.wappalyzer.com\/\">Link<\/a>].<\/p>\n<p><a href=\"https:\/\/transfer.sh\/\">Transfer.sh<\/a> &#8211; A CLI tool for uploading and downloading files to their free file sharing.<\/p>\n<p><a href=\"https:\/\/github.com\/andrew-d\/static-binaries\">Static-Binaries<\/a> &#8211; Contains a list of single executable files for performing multiple tasks (e.g., nmap, netcat&#8230;) with no installation needed.<\/p>\n<p><a href=\"https:\/\/github.com\/ollama\/ollama\">Ollama<\/a> &#8211; A single wrap for running LLMs like Llama 3.1, Phi 3, Mistral, Gemma 2, and other models.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Darknet Diaries &#8211; An excellent bi-weekly podcast about cybersecurity, hackers, the dark web, and much [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-669","post","type-post","status-publish","format-standard","hentry","category-hacking"],"_links":{"self":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/669","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=669"}],"version-history":[{"count":88,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/669\/revisions"}],"predecessor-version":[{"id":5199,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/669\/revisions\/5199"}],"wp:attachment":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}