XowiaScan
Tools
Free Tools
Pricing
Resources
Sign in Get started

Free online tools for bug bounty, recon & web security

40 curated tools across 7 categories. 12 work right here in your browser — no sign-up. The rest live in your free dashboard with scan history and projects.

Recon & Discovery (15)

Map your target's attack surface — domains, ports, ownership, tech.

Subdomain Discovery 5 tkPro

Aggregate subdomains from 11 passive sources (crt.sh, OTX, CertSpotter, Anubis, SubdomainCenter, RapidDNS, Wayback, urlscan.io, HackerTarget, Shodan and more) into one ranked list. Batch up to 3 domains, detect wildcard DNS, optionally resolve DNS or probe HTTP alive. Highlights interesting subdomain patterns and exports with handoff to ProbeMaster, DNS Recon Pro, Takeover Scan and Vuln Scanner.

Recon & Discovery Open →
subdomain discovery aggregate subdomains from 11 passive sources (crt.sh, otx, certspotter, anubis, subdomaincenter, rapiddns, wayback, urlscan.io, hackertarget, shodan and more) into one ranked list. batch up to 3 domains, detect wildcard dns, optionally resolve dns or probe http alive. highlights interesting subdomain patterns and exports with handoff to probemaster, dns recon pro, takeover scan and vuln scanner. subdomain recon & discovery server-side recon
WHOIS Lookup 2 tk

RDAP and port-43 WHOIS combined into one structured record. Batch up to 3 targets, accepts IDN, follows registrar referrals. Surfaces drop-catch and redemption alerts, groups EPP status codes, names the privacy provider, recognises 50+ DNS hosts and badges key signals (DNSSEC, lock, expiry, age). Harvested emails pivot in one click to ViewDNS, WhoXY, Hunter.io, HIBP and IntelX.

Recon & Discovery Open →
whois lookup rdap and port-43 whois combined into one structured record. batch up to 3 targets, accepts idn, follows registrar referrals. surfaces drop-catch and redemption alerts, groups epp status codes, names the privacy provider, recognises 50+ dns hosts and badges key signals (dnssec, lock, expiry, age). harvested emails pivot in one click to viewdns, whoxy, hunter.io, hibp and intelx. whois recon & discovery server-side recon
CNAME / DNS Checker 2 tk

Resolve all common DNS records (A, AAAA, CNAME, MX, NS, TXT, CAA, SOA, SRV) for up to 3 domains at once. Follows CNAME chains with NXDOMAIN takeover detection, fingerprints 45+ services, probes 15 DKIM selectors, parses SPF mechanism by mechanism and DMARC tag by tag, and checks DNSSEC, MTA-STS, TLS-RPT and BIMI. Markdown and JSON export.

Recon & Discovery Open →
cname / dns checker resolve all common dns records (a, aaaa, cname, mx, ns, txt, caa, soa, srv) for up to 3 domains at once. follows cname chains with nxdomain takeover detection, fingerprints 45+ services, probes 15 dkim selectors, parses spf mechanism by mechanism and dmarc tag by tag, and checks dnssec, mta-sts, tls-rpt and bimi. markdown and json export. cname recon & discovery server-side recon
DNS Recon Pro 5 tkPro

Full domain intelligence for up to 3 domains. DoH-based DNS records, DNSSEC, CAA, SRV, MTA-STS, TLS-RPT, BIMI, SPF mechanism breakdown, DMARC tag table, 15 DKIM selectors, TXT vendor classification, CNAME-chain takeover detection, per-IP ASN / ports / CVEs (Shodan + Team Cymru), RDAP registration, AXFR test and CT-log hostnames. Findings ranked by severity.

Recon & Discovery Open →
dns recon pro full domain intelligence for up to 3 domains. doh-based dns records, dnssec, caa, srv, mta-sts, tls-rpt, bimi, spf mechanism breakdown, dmarc tag table, 15 dkim selectors, txt vendor classification, cname-chain takeover detection, per-ip asn / ports / cves (shodan + team cymru), rdap registration, axfr test and ct-log hostnames. findings ranked by severity. dnspro recon & discovery server-side recon
Dork Builder Free

120+ recon dorks across 10 engines (Google, Bing, DuckDuckGo, Yandex, Brave, GitHub, GitLab, SourceGraph, grep.app, Shodan). Covers files, secrets, employees, SaaS webhooks, exposed services and cloud storage. Includes a custom dork builder with operator dropdown, multi-engine launch, favourites, history, regex filter, keyboard shortcuts and CSV / MD export.

Recon & Discovery Open →
dork builder 120+ recon dorks across 10 engines (google, bing, duckduckgo, yandex, brave, github, gitlab, sourcegraph, grep.app, shodan). covers files, secrets, employees, saas webhooks, exposed services and cloud storage. includes a custom dork builder with operator dropdown, multi-engine launch, favourites, history, regex filter, keyboard shortcuts and csv / md export. dork recon & discovery
Wayback URL Extractor 4 tkPro

Pull historical URLs from the Internet Archive and AlienVault OTX for up to 3 domains, with date-range filter. Mines parameters with risk tags (open-redirect, SSRF, LFI), groups URLs into endpoint patterns, categorises sensitive files (.env, .bak, .sql), and surfaces a Tokens-in-URLs view (JWT, AWS, Google, Stripe, Slack, GitHub keys). Advanced filters, archive replay, copy-as-ffuf and MD / CSV / TXT export.

Recon & Discovery Open →
wayback url extractor pull historical urls from the internet archive and alienvault otx for up to 3 domains, with date-range filter. mines parameters with risk tags (open-redirect, ssrf, lfi), groups urls into endpoint patterns, categorises sensitive files (.env, .bak, .sql), and surfaces a tokens-in-urls view (jwt, aws, google, stripe, slack, github keys). advanced filters, archive replay, copy-as-ffuf and md / csv / txt export. wayback recon & discovery server-side recon
SiteMapper Pro Free

Turn a URL list into 4 views: hierarchical host/path tree, sortable flat list, pattern-frequency (collapses /users/1, /users/2 to /users/{id}) and per-host stats. 10 categories (API, Auth, Params, JS, Sensitive paths/files, Backups, Documents, JSON/XML). Advanced filter (regex, exclude, host pattern, depth), saved lists and one-click handoff to ProbeMaster, Takeover and more.

Recon & Discovery Try it →
sitemapper pro turn a url list into 4 views: hierarchical host/path tree, sortable flat list, pattern-frequency (collapses /users/1, /users/2 to /users/{id}) and per-host stats. 10 categories (api, auth, params, js, sensitive paths/files, backups, documents, json/xml). advanced filter (regex, exclude, host pattern, depth), saved lists and one-click handoff to probemaster, takeover and more. sitemapper recon & discovery free no-login no-signup
Robots & Sitemap Harvester 3 tk

Harvest robots.txt (per user-agent), recurse gzipped sitemap indexes, fetch lastmod-sorted URLs, and pull 14 well-known files (security.txt, Asset Links, AASA, OIDC, OAuth metadata, host-meta, JWKS, NodeInfo) plus ads.txt. Classifies disclosed paths into 13 categories with uniqueness scoring, generates probe variants and validates security.txt against RFC 9116. Batch up to 3 domains.

Recon & Discovery Open →
robots & sitemap harvester harvest robots.txt (per user-agent), recurse gzipped sitemap indexes, fetch lastmod-sorted urls, and pull 14 well-known files (security.txt, asset links, aasa, oidc, oauth metadata, host-meta, jwks, nodeinfo) plus ads.txt. classifies disclosed paths into 13 categories with uniqueness scoring, generates probe variants and validates security.txt against rfc 9116. batch up to 3 domains. robots recon & discovery server-side recon
Owner Footprint 5 tkPro

Map every web asset likely owned by the same entity. Scrapes analytics, AdSense, GTM and Pixel IDs from the homepage, computes the favicon hash, does reverse-IP and ASN, then hands you the reverse-WHOIS, PublicWWW, SpyOnWeb and Shodan pivots.

Recon & Discovery Open →
owner footprint map every web asset likely owned by the same entity. scrapes analytics, adsense, gtm and pixel ids from the homepage, computes the favicon hash, does reverse-ip and asn, then hands you the reverse-whois, publicwww, spyonweb and shodan pivots. footprint recon & discovery server-side recon
URL & Endpoint Extractor Free

Mine URLs, JS endpoints, domains and parameters from pasted source code or a fetched remote file. Categorises findings by type and exports the clean set.

Recon & Discovery Try it →
url & endpoint extractor mine urls, js endpoints, domains and parameters from pasted source code or a fetched remote file. categorises findings by type and exports the clean set. urlextractor recon & discovery free no-login no-signup
Image EXIF Extractor 2 tk

Batch-extract EXIF / IPTC / XMP from uploads, URLs or pasted images. Pulls GPS (reverse-geocoded, GPX / KML export), device serials, owner, embedded thumbnail (hidden-crop) and edit / tamper signals.

Recon & Discovery Open →
image exif extractor batch-extract exif / iptc / xmp from uploads, urls or pasted images. pulls gps (reverse-geocoded, gpx / kml export), device serials, owner, embedded thumbnail (hidden-crop) and edit / tamper signals. exif recon & discovery server-side recon
CIDR / IP Calculator Free

IPv4 and IPv6 subnet math. Expand CIDRs, parse ranges and netmasks, aggregate lists into covering CIDRs, split subnets, classify RFC scope (private, CGNAT, public), and build reverse-DNS and scanner targets.

Recon & Discovery Try it →
cidr / ip calculator ipv4 and ipv6 subnet math. expand cidrs, parse ranges and netmasks, aggregate lists into covering cidrs, split subnets, classify rfc scope (private, cgnat, public), and build reverse-dns and scanner targets. cidr recon & discovery free no-login no-signup
Port Intelligence 3 tkPro

Passive open-port and CVE exposure lookup (Shodan InternetDB), plus ready-to-run nmap, naabu and rustscan commands you can run from your own machine.

Recon & Discovery Open →
port intelligence passive open-port and cve exposure lookup (shodan internetdb), plus ready-to-run nmap, naabu and rustscan commands you can run from your own machine. port recon & discovery server-side recon
HTTP ProbeMaster 5 tkPro

Bulk-probe hosts in parallel for status, redirects, title, tech stack, server, IP and timing. Flags notable findings (directory listing, phpinfo, API docs) with filtering and export.

Recon & Discovery Open →
http probemaster bulk-probe hosts in parallel for status, redirects, title, tech stack, server, ip and timing. flags notable findings (directory listing, phpinfo, api docs) with filtering and export. probemaster recon & discovery server-side recon
Tech Fingerprint 3 tk

Fingerprint the stack (server, CMS, frameworks, JS libs, CDN / WAF) with versions, confidence and inline CVE flags. Deep scan reads assets for exact versions, leaked keys and favicon hash. Bulk mode maps a list of hosts.

Recon & Discovery Open →
tech fingerprint fingerprint the stack (server, cms, frameworks, js libs, cdn / waf) with versions, confidence and inline cve flags. deep scan reads assets for exact versions, leaked keys and favicon hash. bulk mode maps a list of hosts. techfp recon & discovery server-side recon

Web Security Audit (7)

Find misconfigurations and weaknesses on live web apps.

Vulnerability Scanner 15 tkPro

All-in-one passive and opt-in active scanner. Feed a URL or a raw HTTP request and surface misconfigurations and vulnerabilities, graded by severity.

Web Security Audit Open →
vulnerability scanner all-in-one passive and opt-in active scanner. feed a url or a raw http request and surface misconfigurations and vulnerabilities, graded by severity. audit web security audit server-side recon
Security Header Analyzer 2 tk

Grade a URL's security posture across HSTS, CSP, XFO and cookies. Audits cookie flags (Secure, HttpOnly, SameSite), info-disclosure leaks, CORS exposure and redirect chains, with prioritised findings.

Web Security Audit Open →
security header analyzer grade a url's security posture across hsts, csp, xfo and cookies. audits cookie flags (secure, httponly, samesite), info-disclosure leaks, cors exposure and redirect chains, with prioritised findings. headers web security audit server-side recon
CSP Evaluator 2 tk

Deep Content-Security-Policy analysis with per-directive source classification and real bypass detection (unsafe-inline, unsafe-eval, wildcards, data:, JSONP and AngularJS whitelist bypasses). Includes a graded score and a hardened-policy generator.

Web Security Audit Open →
csp evaluator deep content-security-policy analysis with per-directive source classification and real bypass detection (unsafe-inline, unsafe-eval, wildcards, data:, jsonp and angularjs whitelist bypasses). includes a graded score and a hardened-policy generator. csp web security audit server-side recon
CORS Misconfig Tester 3 tkPro

Fire a battery of crafted-Origin probes (reflection, null, sub-domain, prefix/suffix and HTTP-downgrade bypasses) plus a pre-flight check, with a credentials-aware verdict and an auto-generated exploit PoC.

Web Security Audit Open →
cors misconfig tester fire a battery of crafted-origin probes (reflection, null, sub-domain, prefix/suffix and http-downgrade bypasses) plus a pre-flight check, with a credentials-aware verdict and an auto-generated exploit poc. cors web security audit server-side recon
Cookie / JWT Auditor Free

Audit cookie flags (Secure, HttpOnly, SameSite, __Host- / __Secure- prefixes, Domain scope) and JWT attacks (alg=none, alg-confusion, jku/jwk/x5u/kid, expiry, privilege claims). Live JWT editor re-signs (none / HMAC) so you can forge and test. Fully client-side.

Web Security Audit Try it →
cookie / jwt auditor audit cookie flags (secure, httponly, samesite, __host- / __secure- prefixes, domain scope) and jwt attacks (alg=none, alg-confusion, jku/jwk/x5u/kid, expiry, privilege claims). live jwt editor re-signs (none / hmac) so you can forge and test. fully client-side. cookiejwt web security audit free no-login no-signup
Subdomain Takeover Scanner 5 tkPro

Resolve CNAME chains and match against 30+ takeover-prone services (S3, GitHub, Heroku, Azure, Netlify and more). Detects NXDOMAIN dangling, verifies with a live error-fingerprint, and ranks verdicts with the claim method.

Web Security Audit Open →
subdomain takeover scanner resolve cname chains and match against 30+ takeover-prone services (s3, github, heroku, azure, netlify and more). detects nxdomain dangling, verifies with a live error-fingerprint, and ranks verdicts with the claim method. takeover web security audit server-side recon
Open-Redirect Scanner & SSRF Toolkit 5 tkPro

Automated open-redirect scan (rich bypass payloads, external canary), plus an SSRF toolkit with any-IP encoder (decimal, hex, octal, IPv6), localhost / metadata / protocol-smuggling payloads, curl / ffuf / Burp commands and OOB guidance.

Web Security Audit Open →
open-redirect scanner & ssrf toolkit automated open-redirect scan (rich bypass payloads, external canary), plus an ssrf toolkit with any-ip encoder (decimal, hex, octal, ipv6), localhost / metadata / protocol-smuggling payloads, curl / ffuf / burp commands and oob guidance. ssrffuzz web security audit server-side recon

Exploitation & OOB (3)

Generate working PoCs, listeners and out-of-band canaries.

XowiaTrack — OOB Interaction 10 tkPro

Out-of-Band interaction listener (Burp-Collaborator-style canary tokens) for SSRF, blind XSS, XXE, Log4Shell, CSV injection and email-pixel tracking. Generate a unique URL, plant it during testing, then see every inbound hit in real-time with full method, headers, body, IP, UA and referer. 12 ready-to-copy payload templates and cURL reproduction.

Exploitation & OOB Open →
xowiatrack — oob interaction out-of-band interaction listener (burp-collaborator-style canary tokens) for ssrf, blind xss, xxe, log4shell, csv injection and email-pixel tracking. generate a unique url, plant it during testing, then see every inbound hit in real-time with full method, headers, body, ip, ua and referer. 12 ready-to-copy payload templates and curl reproduction. track exploitation & oob server-side recon
Reverse Shell Generator Free

Reverse, bind and MSFVenom shells across ~30 languages (Linux / Windows / macOS) with matched listeners, Base64 / URL encoding and a TTY-stabilisation cheat sheet.

Exploitation & OOB Open →
reverse shell generator reverse, bind and msfvenom shells across ~30 languages (linux / windows / macos) with matched listeners, base64 / url encoding and a tty-stabilisation cheat sheet. revshell exploitation & oob
KeyHacks Free

Validate leaked API keys across 153 services (AWS, GCP, Stripe, OpenAI, Slack, GitHub, Twilio, MongoDB and many more). Each entry has severity, impact, regex pattern and a one-liner curl validation. Paste-and-scan mode finds known key formats in source code, .env or JS bundles, fully client-side.

Exploitation & OOB Open →
keyhacks validate leaked api keys across 153 services (aws, gcp, stripe, openai, slack, github, twilio, mongodb and many more). each entry has severity, impact, regex pattern and a one-liner curl validation. paste-and-scan mode finds known key formats in source code, .env or js bundles, fully client-side. keyhacks exploitation & oob

Payloads & Wordlists (3)

Curated payloads and CLI builders for active testing.

Payload Generator Free

15 payload categories: XSS, SQLi, NoSQLi, cmd-injection, LFI, SSTI, XXE, CRLF, LDAP, XPath, SSI, CSV, Host-header, GraphQL and polyglots. Includes WAF-bypass variants, your own value plus OOB host substitution, and 9 encoders.

Payloads & Wordlists Open →
payload generator 15 payload categories: xss, sqli, nosqli, cmd-injection, lfi, ssti, xxe, crlf, ldap, xpath, ssi, csv, host-header, graphql and polyglots. includes waf-bypass variants, your own value plus oob host substitution, and 9 encoders. payloadgen payloads & wordlists
Payload Lists Free

Curated payload library: 26 vulnerability classes, 140+ sections, 700+ payloads. Covers XSS, SQLi, NoSQLi, Command-Injection, SSRF, XXE, SSTI, LFI / RFI, JWT, GraphQL, CORS, File-Upload, Auth-Bypass, OAuth, HTTP-Smuggling, Deserialization, Prototype-Pollution, CSV-Injection and WAF-bypass.

Payloads & Wordlists Open →
payload lists curated payload library: 26 vulnerability classes, 140+ sections, 700+ payloads. covers xss, sqli, nosqli, command-injection, ssrf, xxe, ssti, lfi / rfi, jwt, graphql, cors, file-upload, auth-bypass, oauth, http-smuggling, deserialization, prototype-pollution, csv-injection and waf-bypass. payload-lists payloads & wordlists
Recon Command Builder Free

Parametrised CLI generator for 30+ pentest tools across 9 categories (subdomain, port, HTTP probe, crawler, fuzzer, vuln scan, exploitation, brute force, hash crack, secrets, TLS), with wordlist presets and a downloadable .sh script.

Payloads & Wordlists Open →
recon command builder parametrised cli generator for 30+ pentest tools across 9 categories (subdomain, port, http probe, crawler, fuzzer, vuln scan, exploitation, brute force, hash crack, secrets, tls), with wordlist presets and a downloadable .sh script. cmdbuilder payloads & wordlists

Crypto & Generators (3)

Hashes, identifiers, test data and tokens.

Hash Toolkit Free

Generate (MD5, NTLM, SHA) and identify 60+ hash types with ranked candidates. Builds tailored hashcat and John commands (wordlist, rules, mask), with file-extraction helpers and crack-speed guidance. Fully client-side.

Crypto & Generators Try it →
hash toolkit generate (md5, ntlm, sha) and identify 60+ hash types with ranked candidates. builds tailored hashcat and john commands (wordlist, rules, mask), with file-extraction helpers and crack-speed guidance. fully client-side. hashtoolkit crypto & generators free no-login no-signup
Test Data Generator Free

Realistic-looking test data across 22 countries: names, emails, phone numbers (fiction-reserved ranges), addresses, postal codes and format-valid sample IDs. Safety-reserved ranges so values look real but never collide with live data. Cards, text, JSON and CSV export.

Crypto & Generators Try it →
test data generator realistic-looking test data across 22 countries: names, emails, phone numbers (fiction-reserved ranges), addresses, postal codes and format-valid sample ids. safety-reserved ranges so values look real but never collide with live data. cards, text, json and csv export. identity crypto & generators free no-login no-signup
Code / Password / Token Generator Free

Custom-charset strings (1-512 chars, up to 5000 at a time), passwords with entropy scoring, preset tokens (UUID v4, ULID, hex, base64, JWT secrets, Stripe / Slack / GitHub / AWS-style API keys, Luhn-valid test cards) and bulk numeric ranges.

Crypto & Generators Try it →
code / password / token generator custom-charset strings (1-512 chars, up to 5000 at a time), passwords with entropy scoring, preset tokens (uuid v4, ulid, hex, base64, jwt secrets, stripe / slack / github / aws-style api keys, luhn-valid test cards) and bulk numeric ranges. code-generator crypto & generators free no-login no-signup

Encoders & Converters (5)

Encode, decode, format and convert anything.

Encoder / Decoder Free

4-tab workbench: 20+ encodings (URL, double-URL, percent-all, Base64, Base64URL, HTML, JS \xXX / \uXXXX, CSS, Hex, Binary, Octal, ASCII, ROT-N, Atbash, Morse), all-encodings multi-view, hashes (MD5, SHA family, HMAC), and Unix-timestamp / ISO 8601 conversions.

Encoders & Converters Try it →
encoder / decoder 4-tab workbench: 20+ encodings (url, double-url, percent-all, base64, base64url, html, js \xxx / \uxxxx, css, hex, binary, octal, ascii, rot-n, atbash, morse), all-encodings multi-view, hashes (md5, sha family, hmac), and unix-timestamp / iso 8601 conversions. encode encoders & converters free no-login no-signup
HTTP Request Converter Free

Convert HTTP requests between 6 formats: Raw HTTP (Burp), curl, fetch(), HAR, JSON spec and form / query string. Auto-detects input, handles full shell quoting, JSON bodies, multi-line curl and HAR entries from DevTools.

Encoders & Converters Try it →
http request converter convert http requests between 6 formats: raw http (burp), curl, fetch(), har, json spec and form / query string. auto-detects input, handles full shell quoting, json bodies, multi-line curl and har entries from devtools. json2rawhttp encoders & converters free no-login no-signup
JSON Workbench Free

Format, validate (with line / col error), minify, sort keys, unescape stringified, convert to YAML / XML / CSV / PHP / JS / JSONL / query, JSONPath query, two-pane diff, extract secrets (URLs / emails / JWTs / AWS / Stripe / private keys), depth and type stats. 100% client-side.

Encoders & Converters Try it →
json workbench format, validate (with line / col error), minify, sort keys, unescape stringified, convert to yaml / xml / csv / php / js / jsonl / query, jsonpath query, two-pane diff, extract secrets (urls / emails / jwts / aws / stripe / private keys), depth and type stats. 100% client-side. jsonbeautify encoders & converters free no-login no-signup
Text Suite Free

7-tab text workbench: regex find/replace, sort/dedupe/sample, keep-drop line filter, set operations (A−B, ∩, ∪), URL-parts extraction, case conversion (camel, snake, kebab and more), per-line transforms, secret extraction and stats. Per-tab undo (10 steps), drag-drop import.

Encoders & Converters Try it →
text suite 7-tab text workbench: regex find/replace, sort/dedupe/sample, keep-drop line filter, set operations (a−b, ∩, ∪), url-parts extraction, case conversion (camel, snake, kebab and more), per-line transforms, secret extraction and stats. per-tab undo (10 steps), drag-drop import. text-suite encoders & converters free no-login no-signup
Text Comparer Free

4-tab diff workbench: true LCS line / word / char diff, side-by-side, Git-style unified, inline word-level, and stats (added, removed, similarity %). Trim, case-insensitive, ignore-blank-lines toggles. Drag-drop file import, live recompare.

Encoders & Converters Try it →
text comparer 4-tab diff workbench: true lcs line / word / char diff, side-by-side, git-style unified, inline word-level, and stats (added, removed, similarity %). trim, case-insensitive, ignore-blank-lines toggles. drag-drop file import, live recompare. comparer encoders & converters free no-login no-signup

Reference & Reports (4)

Look things up. Write things up. Get paid.

CVE Lookup 2 tk

CVE detail and product search with prioritisation signals: CVSS, EPSS exploit-probability, CISA KEV (actively-exploited) status, SSVC, CWE and categorised exploit / patch references.

Reference & Reports Open →
cve lookup cve detail and product search with prioritisation signals: cvss, epss exploit-probability, cisa kev (actively-exploited) status, ssvc, cwe and categorised exploit / patch references. cvelookup reference & reports server-side recon
Bugcrowd VRT FreePro

Browse Bugcrowd's Vulnerability Rating Taxonomy with bug-class definitions, severity priorities and CVSS mappings. Searchable and filterable, useful for triaging finds and writing reports.

Reference & Reports Open →
bugcrowd vrt browse bugcrowd's vulnerability rating taxonomy with bug-class definitions, severity priorities and cvss mappings. searchable and filterable, useful for triaging finds and writing reports. bvrt reference & reports server-side recon
PoC / Report Generator FreePro

Submission-ready bug-bounty and pentest reports. 29 templates with CWE / OWASP / CVSS / VRT pre-mapped, platform-specific output (HackerOne, Bugcrowd, Intigriti, YesWeHack, Synack, Formal Pentest), CVSS 3.1 calculator, live Markdown preview, multi-format export (MD / HTML / JSON) and draft autosave.

Reference & Reports Open →
poc / report generator submission-ready bug-bounty and pentest reports. 29 templates with cwe / owasp / cvss / vrt pre-mapped, platform-specific output (hackerone, bugcrowd, intigriti, yeswehack, synack, formal pentest), cvss 3.1 calculator, live markdown preview, multi-format export (md / html / json) and draft autosave. pocgen reference & reports
WebPad FreePro

Pentest scratchpad with a Markdown editor, live preview, YAML frontmatter tags, pinning, full-text search across all notes, 5 templates (Recon log, Bug write-up, Engagement summary, Quick ref, OWASP checklist), 2-second auto-save, multi-format export (MD, HTML, TXT), keyboard shortcuts (Ctrl+S, Ctrl+N), saved to your account.

Reference & Reports Open →
webpad pentest scratchpad with a markdown editor, live preview, yaml frontmatter tags, pinning, full-text search across all notes, 5 templates (recon log, bug write-up, engagement summary, quick ref, owasp checklist), 2-second auto-save, multi-format export (md, html, txt), keyboard shortcuts (ctrl+s, ctrl+n), saved to your account. webpad reference & reports server-side recon

Sign up free

Unlock the full toolkit:

  • Server-side recon (subdomain, WHOIS, DNS, footprint, ports)
  • Scan history, saved across devices
  • Targets & projects with scope enforcement
  • CVE lookup, payload library, OOB canaries
Create free account →

Just want the free tools?

12 client-side utilities work right here, no sign-up needed. Encoders, hashes, JSON, diff, password & UUID, CIDR maths.

Show me the free tools →