Security Tools Library
A curated portal of the best free, open-source penetration-testing tools for websites — 16 tools across recon, web-app testing, passwords, network analysis and full platforms. Every entry has an official download link, a plain-English breakdown of what it does, and a step-by-step tutorial on using it safely.
For authorised testing only. Use these tools on systems you own or have written permission to assess.
This library is a Growth Lab Pro benefit
Unlock direct download links and full step-by-step tutorials for all 16 tools — plus unlimited audits, white-label reports, Search Console import, the AI content assistant and continuous monitoring.
€25/month or €200/year · cancel anytimeWhat's inside the library
Recon & OSINT
The industry-standard scanner for discovering live hosts, open ports, running services and OS fingerprints. The first step of almost every assessment.
Gathers emails, subdomains, hosts and names from public sources (search engines, certificate transparency) to map an organisation's footprint.
Web Application Testing
The OWASP flagship web proxy and scanner: intercept traffic, spider a site and run automated scans for XSS, injection and misconfiguration. The best free Burp alternative.
The most widely used web-security toolkit. The free Community Edition gives you the intercepting proxy, repeater and decoder for manual testing.
Fast web-server scanner that checks for thousands of dangerous files, outdated software and common server misconfigurations.
Automates detection and exploitation of SQL-injection flaws so you can prove — and then fix — database vulnerabilities in your own apps.
Scans WordPress sites for vulnerable core, plugins and themes, weak users and exposed configuration — essential if you run WordPress.
A fast, community-driven scanner that runs thousands of YAML vulnerability templates against your targets — great for catching known CVEs quickly.
A blazing-fast web fuzzer for discovering hidden directories, files and parameters that should not be publicly reachable.
Password & Authentication
Tests how resistant your own password hashes are to cracking, so you can enforce stronger policies. Use only on hashes you are authorised to audit.
The fastest password-recovery tool, GPU-accelerated. Ideal for auditing the real-world strength of stored credentials you are responsible for.
Tests login endpoints against weak credentials across many protocols, so you can confirm rate-limiting and lockout actually work on your services.
Network & Traffic
The world's most popular network protocol analyzer — capture and inspect traffic to spot cleartext data, misconfigurations and suspicious connections.
The standard framework for validating vulnerabilities safely in a lab, verifying patches and building repeatable proof-of-concept tests.
Platforms & Distros
A Debian-based distribution that ships hundreds of the tools above pre-installed and configured — the fastest way to get a full testing lab running.
A deliberately insecure web app you run yourself to practise every technique legally and safely — the perfect place to learn before touching real systems.