{"id":669,"date":"2020-12-29T16:48:20","date_gmt":"2020-12-29T16:48:20","guid":{"rendered":"https:\/\/dft.wiki\/?p=669"},"modified":"2026-06-09T13:24:26","modified_gmt":"2026-06-09T17:24:26","slug":"cyber-security-sites-and-tools-you-need-to-know-about","status":"publish","type":"post","link":"https:\/\/dft.wiki\/?p=669","title":{"rendered":"Cyber Security Sites, Tools and Tips"},"content":{"rendered":"<p><a href=\"https:\/\/darknetdiaries.com\/\">Darknet Diaries<\/a> &#8211; An excellent bi-weekly podcast about cybersecurity, hackers, the dark web, and much more.<\/p>\n<p><a href=\"https:\/\/twit.tv\/shows\/security-now\">Security Now<\/a> &#8211; A weekly technical cybersecurity podcast (by <a href=\"https:\/\/www.grc.com\/securitynow.htm\">GRC<\/a>) available in video and audio.<\/p>\n<p><a href=\"https:\/\/www.gog.show\/\">Grumpy Old Geeks<\/a> &#8211; A weekly humor show on cybersecurity and the Internet. &#8220;What went wrong on the Internet and who is to blame!&#8221;<\/p>\n<p><a href=\"https:\/\/thecyberwire.com\/podcasts\">The Cyber Wire<\/a> &#8211; A daily source of cyber news and IT career content.<\/p>\n<p><a href=\"https:\/\/www.social-engineer.org\/category\/podcast\/\">The Social-Engineer Podcast<\/a> &#8211; The title speaks for itself.<\/p>\n<p><a href=\"https:\/\/www.virustotal.com\/\">Virus Total<\/a> &#8211; A website from a cybersecurity company that provides information about viruses, worms, malware, and more.<\/p>\n<p><a href=\"https:\/\/otx.alienvault.com\/\">Alien Vault<\/a> &#8211; Similar to Virus Total, but claims to be a fully open threat intelligence community.<\/p>\n<p><a href=\"https:\/\/viz.greynoise.io\/\">GrayNoise<\/a> &#8211; Collects, analyzes, and labels data from IPs that scan the internet and saturate security tools with noise.<\/p>\n<p><a href=\"https:\/\/antiscan.me\/\">AntiScan<\/a> and <a href=\"https:\/\/dyncheck.com\/\">DynCheck<\/a> &#8211; Free online multi-antivirus scanners.<\/p>\n<p><a href=\"https:\/\/gtmetrix.com\/\">GTmetrix<\/a> &#8211; Designed to test website loading speed, it also reports on page content and the percentage of each language used.<\/p>\n<p><a href=\"https:\/\/pagespeed.web.dev\/\">PageSpeed Insights<\/a> &#8211; Generates performance reports for a page on both mobile and desktop devices, and provides suggestions for improvement.<\/p>\n<p><a href=\"https:\/\/web.dev\/measure\/\">Web.Dev<\/a> &#8211; Test your pages in a lab environment and get tips and recommendations to improve the user experience.<\/p>\n<p><a href=\"https:\/\/seositecheckup.com\/\">SEO SiteCheckup<\/a> &#8211; A supercharged analysis and monitoring tool for SEO (Search Engine Optimization).<\/p>\n<p><a href=\"https:\/\/ipv6-test.com\/\">IPv6 Test<\/a> &#8211; Checks your IPv6 and IPv4 connectivity and speed, and can also test whether your website (DNS and Host) is IPv6-ready.<\/p>\n<p><a href=\"https:\/\/securityheaders.com\/\">Security Header<\/a> &#8211; Check the security headers of a website.<\/p>\n<p><a href=\"https:\/\/www.torproject.org\/\">Tor Browser<\/a> &#8211; An encrypted browser that routes traffic through relays and proxies around the world to protect user privacy.<\/p>\n<p><a href=\"https:\/\/tails.boum.org\/\">Tails Linux<\/a> &#8211; A Linux distribution designed to leave no trace after shutdown.<\/p>\n<p><a href=\"https:\/\/www.kali.org\/\">Kali Linux<\/a> &#8211; A Linux distribution designed for network and system security testing.<\/p>\n<p><a href=\"https:\/\/www.parrotsec.org\/\">Parrot OS<\/a> &#8211; A lightweight but powerful offensive distribution, comparable to Kali. Based on Debian 13 and uses Plasma 6 with Wayland by default.<\/p>\n<p><a href=\"https:\/\/pentest.ws\/\">Pentest.WS<\/a> &#8211; A collaborative interface for working with NMAP scans, inventory, and vulnerabilities. A useful tool for team CTFs.<\/p>\n<p><a href=\"https:\/\/github.com\/trustedsec\/ptf\/\">The PenTesters Framework<\/a> &#8211; Regardless of the distribution, PTF is a toolset that makes it easy to install and keep all the most popular pentesting applications up to date.<\/p>\n<p><a href=\"https:\/\/crackstation.net\/\">CrackStation<\/a> &#8211; A free web-based password hash cracker, and a downloadable password list called <strong>RealUniq<\/strong> with over 1.4 billion entries.<\/p>\n<p><a href=\"http:\/\/tunnelsup.com\/\">TunnelsUp<\/a> &#8211; A source of cybersecurity information and tools, including a web hash analyzer [<a href=\"https:\/\/www.tunnelsup.com\/hash-analyzer\/\">Link<\/a>].<\/p>\n<p><a href=\"https:\/\/github.com\/danielmiessler\/SecLists\">SecLists<\/a> &#8211; A collection of multiple types of lists (such as password lists) used during security assessments, all in one place.<\/p>\n<p><a href=\"https:\/\/project-rainbowcrack.com\/table.htm\">Project RainbowCrack<\/a> &#8211; A source of rainbow tables with pre-cracked passwords. It is simply a matter of cross-checking the hashes.<\/p>\n<p><a href=\"https:\/\/github.com\/philipperemy\/tensorflow-1.4-billion-password-analysis\">1.4 Billion Text Credentials Analysis (NLP)<\/a> &#8211; Also available to download via torrent.<\/p>\n<p><a href=\"https:\/\/github.com\/malwaredllc\/byob\">BYOB<\/a> &#8211; A framework for building command-and-control zombie bots (for educational purposes only).<\/p>\n<p><a href=\"https:\/\/github.com\/ReclaimYourPrivacy\/eschalot\">Eschalot<\/a> &#8211; A tool for generating a vanity .onion address for your service on the Tor network.<\/p>\n<p><a href=\"http:\/\/onion.ly\/\">Onion.ly<\/a> &#8211; Tor2Web proxy (try *****.onion<strong>.ly<\/strong>).<\/p>\n<p><a href=\"https:\/\/xerosecurity.com\/\">Sn1per<\/a> &#8211; An automated scanner for enumerating and finding vulnerabilities during penetration tests. Also available as a Docker image [<a href=\"https:\/\/github.com\/1N3\/Sn1per\">Link<\/a>].<\/p>\n<p><a href=\"https:\/\/www.tenable.com\/products\/nessus\/nessus-essentials\">Nessus<\/a> &#8211; A powerful professional vulnerability scanner.<\/p>\n<p><a href=\"http:\/\/dvwa.co.uk\/\">DVWA<\/a> &#8211; Damn Vulnerable Web App is an intentionally vulnerable PHP\/MySQL web application. Also available for Docker [<a href=\"https:\/\/hub.docker.com\/r\/vulnerables\/web-dvwa\">Link<\/a>].<\/p>\n<p><a href=\"http:\/\/ironwasp.org\/\">IronWASP<\/a> &#8211; An open-source tool for web application vulnerability testing, crawling, and more.<\/p>\n<p><a href=\"https:\/\/github.com\/reconness\/reconness\">ReconNess<\/a> &#8211; Helps run and manage all your reconnaissance in one place, focusing on potentially vulnerable targets.<\/p>\n<p><a href=\"https:\/\/github.com\/j3ssie\/Osmedeus\">Osmedeus<\/a> &#8211; A collection of tools for reconnaissance and vulnerability scanning against a target.<\/p>\n<p><a href=\"https:\/\/nc110.sourceforge.io\/\">Netcat<\/a> &#8211; A tool for tunneling connections (file transfers, remote shell, etc).<\/p>\n<p><a href=\"https:\/\/www.cvedetails.com\/\">CVE Details<\/a> &#8211; Security vulnerability database.<\/p>\n<p><a href=\"https:\/\/hunter.io\/\">Hunter<\/a> &#8211; An information-gathering tool for OSINT.<\/p>\n<p><a href=\"https:\/\/www.offensive-security.com\/metasploit-unleashed\/\">Metasploit Unleashed<\/a> &#8211; The official Metasploit documentation and manual.<\/p>\n<p><a href=\"https:\/\/information.rapid7.com\/download-metasploitable-2017.html\">Metasploitable<\/a> &#8211; An intentionally vulnerable target machine for exploitation exercises.<\/p>\n<p><a href=\"https:\/\/github.com\/Veil-Framework\/Veil-Evasion\">Veil-Evasion<\/a> &#8211; A pentesting framework.<\/p>\n<p><a href=\"https:\/\/www.offensive-security.com\/metasploit-unleashed\/msfvenom\/\">MSFvenom<\/a> &#8211; A combination of Msfpayload and Msfencode in a single framework.<\/p>\n<p><a href=\"http:\/\/www.fastandeasyhacking.com\/\">Armitage<\/a> &#8211; A free graphical interface for MSF.<\/p>\n<p><a href=\"https:\/\/www.cobaltstrike.com\/download\">Cobalt Strike<\/a> &#8211; A licensed graphical interface for MSF.<\/p>\n<p><a href=\"https:\/\/github.com\/EmpireProject\/Empire\">Empire<\/a> &#8211; A Windows and macOS post-exploitation framework featuring a pure PowerShell 2.0 Windows agent and a pure Python 2.6\/2.7 Linux\/OS X agent.<\/p>\n<p><a href=\"https:\/\/hub.docker.com\/r\/koutto\/jok3r\/\">Jok3r<\/a> &#8211; A framework that assists penetration testers with network infrastructure and web security assessments.<\/p>\n<p><a href=\"https:\/\/www.exploit-db.com\/\">Exploit Database<\/a> &#8211; An archive of public exploits and their corresponding vulnerable software.<\/p>\n<p><a href=\"https:\/\/www.hackthebox.eu\/\">HackTheBox<\/a> &#8211; An online platform for practicing penetration testing skills.<\/p>\n<p><a href=\"https:\/\/www.vulnhub.com\/\">VulnHub<\/a> &#8211; Hundreds of pre-configured virtual machines set up for vulnerability and penetration testing exercises.<\/p>\n<p><a href=\"https:\/\/cmdchallenge.com\/\">Command Challenge<\/a> &#8211; Practice commands and learn how to solve problems in the CLI.<\/p>\n<p><a href=\"https:\/\/picoctf.org\/\">picoCFT<\/a> &#8211; Compete or practice using picoGym, a non-competitive space to explore and solve challenges from past picoCTF competitions.<\/p>\n<p><a href=\"http:\/\/deftlinux.net\/\">DEFT Linux<\/a> &#8211; DEFT (Digital Evidence &amp; Forensic Toolkit) is a Ubuntu-based live distribution for incident response and computer forensics.<\/p>\n<p><a href=\"https:\/\/github.com\/mandiant\/flare-wmi\">python-cim<\/a> &#8211; A forensics tool for analyzing WMI event logs.<\/p>\n<p><a href=\"https:\/\/www.cloudflare.com\/\">Cloudflare<\/a> &#8211; A free CDN (Content Delivery Network) and web application firewall that uses a proxy network and offers optimization features such as caching, code optimization, and more.<\/p>\n<p><a href=\"https:\/\/sourceforge.net\/projects\/owaspbwa\/\">OWASP Broken Web Application Project<\/a> &#8211; A collection of vulnerable web applications distributed as a VMware virtual machine.<\/p>\n<p><a href=\"https:\/\/owasp.org\/www-project-webgoat\/\">OWASP Web Goat<\/a> &#8211; Lets developers test vulnerabilities commonly found in Java-based applications that rely on popular open-source components.<\/p>\n<p><a href=\"https:\/\/owasp.org\/www-project-juice-shop\/\">OWASP Juice Shop<\/a> &#8211; Contains vulnerabilities from the entire <a href=\"https:\/\/owasp.org\/www-project-top-ten\/\">OWASP Top Ten<\/a>, along with many other security flaws found in real-world applications.<\/p>\n<p><a href=\"https:\/\/www.jsonwebtoken.io\/\">JSON Web Token<\/a> and <a href=\"https:\/\/jwt.io\/\">JWT<\/a> &#8211; Encode and decode JSON Web Tokens.<\/p>\n<p><a href=\"https:\/\/chrome.google.com\/webstore\/detail\/wappalyzer\/gppongmhjkpfnbhagpmjfkannfbllamg?hl=en\">Wappalyzer<\/a> &#8211; A technology profiler that shows you what a website is built with.<\/p>\n<p><a href=\"https:\/\/www.unixtimestamp.com\/\">Dan&#8217;s Tools<\/a> &#8211; Epoch and Unix timestamp conversion tools. Also includes tools for conversion, encoding\/decoding, and formatting.<\/p>\n<p><a href=\"https:\/\/gchq.github.io\/CyberChef\/\">CyberChef<\/a> &#8211; An online encryption and decryption tool.<\/p>\n<p><a href=\"https:\/\/getoutline.org\/\">Outline VPN<\/a> &#8211; An open-source VPN that runs on Docker, created by Google and partners.<\/p>\n<p><a href=\"https:\/\/www.shodan.io\/\">Shodan<\/a> &#8211; A search engine for internet-connected devices. A great OSINT source for open ports and exposed services. Also available via the Kali CLI.<\/p>\n<p><a href=\"https:\/\/censys.io\/\">Censys<\/a> &#8211; An internet scanner similar to Shodan, but more focused on specific addresses rather than broad searches.<\/p>\n<p><a href=\"https:\/\/wigle.net\/\">Wigle<\/a> &#8211; A live map of all discovered wireless networks worldwide.<\/p>\n<p><a href=\"https:\/\/spyse.com\/\">Spyse<\/a> &#8211; A database of port scans with fingerprints that may reveal OS and application versions.<\/p>\n<p><a href=\"https:\/\/securitytrails.com\/\">Security Trails<\/a> &#8211; Another database of port scans and domain information.<\/p>\n<p><a href=\"https:\/\/intelx.io\/\">IntelligenceX<\/a> &#8211; An OSINT tool for retrieving information about data breaches, Bitcoin addresses, domain information, and more.<\/p>\n<p><a href=\"https:\/\/github.com\/swisskyrepo\/PayloadsAllTheThings\">Payloads All The Things<\/a> &#8211; A large collection of payloads of all types, along with instructions and exercises.<\/p>\n<p><a href=\"https:\/\/github.com\/payloadbox\/sql-injection-payload-list\">SQL Injection Payload List<\/a> &#8211; A collection of SQL injection exploits with instructions.<\/p>\n<p><a href=\"https:\/\/github.com\/payloadbox\/xxe-injection-payload-list\">XXE Injection Payloads List<\/a> &#8211; A collection of XXE injection exploits with instructions.<\/p>\n<p><a href=\"https:\/\/github.com\/pgaijin66\/XSS-Payloads\">XSS Payloads<\/a> &#8211; A collection of XSS payloads.<\/p>\n<p><a href=\"https:\/\/www.ssllabs.com\/ssltest\/index.html\">SSL Server Test<\/a> &#8211; A free web service for evaluating the SSL\/TLS configuration of your web server.<\/p>\n<p><a href=\"https:\/\/badssl.com\/\">Bad SSL<\/a> &#8211; A collection of non-compliant certificate samples for browser and client testing.<\/p>\n<p><a href=\"https:\/\/ondmarc.redsift.com\/\">ONDMARC<\/a> &#8211; Check the SPF and DKIM configuration of a mail server.<\/p>\n<p><a href=\"https:\/\/protonmail.com\/\">ProtonMail<\/a> &#8211; An encrypted and anonymous email provider.<\/p>\n<p><a href=\"https:\/\/tutanota.com\/\">Tutanota<\/a> &#8211; An encrypted and anonymous email provider.<\/p>\n<p><a href=\"https:\/\/coveryourtracks.eff.org\/\">CoverYourTracks<\/a> &#8211; A browser privacy tester from the EFF.<\/p>\n<p><a href=\"https:\/\/www.privacytools.io\/\">PrivacyTools.io<\/a> &#8211; Provides services, tools, and knowledge to protect your privacy against global mass surveillance.<\/p>\n<p><a href=\"https:\/\/justdeleteme.xyz\/\">JustDeleteMe.xyz<\/a> &#8211; A directory of direct links to delete your account from various web services.<\/p>\n<p><a href=\"https:\/\/builtwith.com\/\">BuiltWith<\/a> &#8211; A free web service for analyzing what framework a website is built with. Alternatively, check out the Wappalyzer browser extension [<a href=\"https:\/\/www.wappalyzer.com\/\">Link<\/a>].<\/p>\n<p><a href=\"https:\/\/transfer.sh\/\">Transfer.sh<\/a> &#8211; A CLI tool for uploading and downloading files via their free file-sharing service.<\/p>\n<p><a href=\"https:\/\/github.com\/andrew-d\/static-binaries\">Static-Binaries<\/a> &#8211; A collection of single executable files for various tasks (e.g., nmap, netcat) with no installation required.<\/p>\n<p><a href=\"https:\/\/github.com\/ollama\/ollama\">Ollama<\/a> &#8211; A single wrapper for running LLMs such as Llama 3.1, Phi 3, Mistral, Gemma 2, and other models.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Darknet Diaries &#8211; An excellent bi-weekly podcast about cybersecurity, hackers, the dark web, and much [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-669","post","type-post","status-publish","format-standard","hentry","category-hacking"],"_links":{"self":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/669","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=669"}],"version-history":[{"count":89,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/669\/revisions"}],"predecessor-version":[{"id":5806,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/669\/revisions\/5806"}],"wp:attachment":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}