Arsenal
Open security tools — PentX, FILEx, CSPy. Run free, read the source, open a pull request.
Recon
liveSubdomain enumeration via certificate transparency logs (crt.sh). Passive-only — no active scanning.
Web · crt.sh
PentX
livePassive recon through active testing — every finding ships with full request/response bytes, reflection offsets, a cURL repro, and OAST callbacks for blind classes.
Node.js
FILEx
betaA self-hosted document toolkit — convert, merge, split and process PDFs without sending a byte to a third party. Built for teams that cannot leak documents.
Python · FastAPI
CSPy
alphaA browser extension that audits the CSP and security headers of any site you visit and explains, in plain language, what an attacker could do with the gaps.
TypeScript
Subdomain Recon
Subdomain finder — certificate transparency