Privacy
Resources.
0 curated tools
AI & Local LLM
Ollama
Run open-source LLMs locally
Run open-source LLMs locally with one command. Query your private documents or generate sensitive code on an air-gapped machine without any data leaving your machine.
Query your private documents or generate sensitive code on an air-gapped or hardened MacBook without any data leaving your machine.
Jan AI
Open-source ChatGPT alternative, runs offline
Open-source desktop app to run and manage local LLMs easily. Daily private research and writing while keeping the option for optional cloud fallback.
Daily private research and writing while keeping the option for optional cloud fallback without permanent storage of prompts.
Open WebUI
Self-hosted web UI for local LLMs
Self-hosted beautiful web UI for any local LLM (Ollama, etc.). Deploy your own private ChatGPT-like interface on a home server.
Deploy your own private ChatGPT-like interface on a home server for family or trusted team use.
LM Studio
Discover and run LLMs locally
User-friendly desktop app for discovering, downloading and running LLMs with GPU support.
Test multiple models locally before choosing one for long-term sensitive workflows.
PrivateGPT
Claude API-compatible backend for private AI apps
Open-source API layer for building private AI applications on any local or self-hosted model server. Claude API-compatible endpoints for messages, file ingestion with citations, retrieval-augmented generation, tools, MCP, and agent workflows — all on your own infrastructure.
Build private AI applications with a Claude-compatible API on your own hardware: document Q&A with source citations, custom toolchains, MCP-powered agent workflows, and sensitive data processing without anything leaving your control.
Duck.ai
AI search powered by DuckDuckGo
DuckDuckGo's AI search that combines real-time web results with AI-powered answers. No tracking, no profile building.
Private AI-assisted search for security research without query history correlation.
Xprivo
Privacy-focused LLM assistant
Privacy-first AI assistant. No data retention, no training on user data, zero-knowledge architecture.
Draft security reports, incident analysis, and sensitive documentation with full privacy guarantees.
OpenRouter
Unified API for 400+ LLMs
OpenAI-compatible unified API aggregating 400+ models from 60+ providers including major labs and open hosts. Provides smart routing for cost, speed, and uptime with automatic fallbacks, plus per-provider data retention and logging policies.
Access multiple frontier and open models through a single key and SDK for red teaming, automated analysis, or agent workflows while routing prompts only to trusted providers and enforcing no-training policies.
DeepInfra
OpenAI-compatible inference API for 100+ open models
AI inference cloud hosting 100+ open-source models via an OpenAI-compatible API. Drop-in replacement — swap your base URL to api.deepinfra.com/v1/openai and your code works unchanged. SOC 2 and ISO 27001 certified with zero data retention policy. Also offers dedicated GPU clusters (B200/B300) for private model deployments. Backed by NVIDIA. Raised $107M Series B in May 2026.
Route prompts through DeepInfra when you lack local GPU hardware for the latest open models, or deploy a private inference endpoint for sensitive agent workloads with contractual zero-retention guarantees — no training on your data, no stored prompts.
Lumo
Privacy-first AI assistant (Proton)
Proton's privacy-first AI assistant with end-to-end encryption. Conversations are never stored or used to train models. Swiss-based with zero-knowledge architecture.
Secure AI assistance for drafting incident reports, threat analysis summaries, and security documentation without data leaving your control.
Communication
Signal
Gold standard for encrypted messaging
The gold standard for end-to-end encrypted messaging. Open-source protocol, minimal metadata retention.
Primary secure channel for team communications, incident coordination, and sharing time-sensitive security alerts.
Session
Anonymous messenger, no phone number required
Decentralized messenger with no phone number or email required. Routes messages through an onion network.
Anonymous communication channel for whistleblowers, confidential sources, and high-risk operational coordination.
Element / Matrix
Self-hostable encrypted communication
Self-hostable team communication platform built on the Matrix protocol with end-to-end encryption and federation.
Self-hosted SOC chat platform with full message encryption, audit trails, and bridging to other secure channels.
Threema
Swiss encrypted messenger, phone-number-free
Swiss-made end-to-end encrypted messenger that requires no phone number or email. Open-source audited client with minimal data collection.
European alternative to Signal for teams requiring Swiss jurisdiction, no phone-number linking, and full auditability.
Meshtastic
Open-source mesh networking for off-grid communication
Open-source mesh radio network for off-grid, encrypted text communication without cellular or internet.
Off-grid team communication during on-site assessments, red team exercises, and emergency response scenarios.
Crypton.sh
Encrypted SMS & virtual phone numbers
End-to-end encrypted SMS service using real physical SIM cards with zero-access encryption and personal keypair. No email required for signup, TOR support, open-source encryption module. Also offers virtual numbers, Crypton Travel eSIM in 145+ countries, Crypton Mobile (permanent eSIM with voice & data), email aliases, BYOD (bring your own device), and a powerful REST API. Accepts crypto (XMR, BTC, ETH) and credit cards.
Anonymous phone numbers for account verifications, 2FA, and secure messaging without linking personal identity. Ideal for burner setups, operational security, and high-risk communications.
Meshtastic Map
Live public map of Meshtastic nodes
Community-run public map of Meshtastic nodes heard on MQTT with real-time positions, telemetry graphs, traceroutes, device metrics (battery, voltage, utilization), and environmental sensor data. Open-source, no affiliation with the official Meshtastic project.
Monitor Meshtastic node coverage and node health in your operational area during field exercises, red team deployments, and disaster response scenarios.
SMS4Sats
Lightning-paid SMS without phone number
Send and receive SMS messages without giving away your phone number. Pay per message via Lightning (Bitcoin) — no account, no KYC, no personal data required. Rent virtual numbers globally to receive SMS verification codes.
Anonymous SMS verification for burner accounts and operational aliases — pay with Lightning, no phone number exposure, no paper trail.
SimpleX Chat
E2E-encrypted chat without user IDs
Decentralized messaging platform with no user identifiers — no phone number, no username, no email required. Uses disposable queue addresses and relay servers. Supports E2E encryption, file sharing, voice messages, and group chats. Open-source client and server.
Operational comms with zero identity linkage — one-time chat addresses per contact, no profile, no server-side user database to subpoena or compromise.
Briar
Peer-to-peer encrypted messenger
Open-source peer-to-peer messaging app for activists, journalists, and anyone needing secure communication without central servers. Messages sync directly between devices over Tor, Bluetooth, or Wi-Fi. End-to-end encrypted with support for private messaging, forums, and blogs. No phone number or email required for signup. Survives internet blackouts via mesh sync. Audited by Cure53 and Radically Open Security.
Operational comms in high-risk environments or during internet shutdowns. P2P sync over Bluetooth or Wi-Fi keeps teams connected when infrastructure is down, while Tor routing prevents metadata surveillance and traffic analysis.
Cwtch
Metadata-resistant messaging over Tor
Decentralized, privacy-preserving messaging protocol built on Tor v3 onion services. All communication is end-to-end encrypted with no central servers, no phone number or email required. Supports peer-to-peer chat and group conversations via untrusted disposable servers. Developed by Open Privacy Research Society. Data stored locally on device with full encryption.
Metadata-resistant team communication for sensitive operations — no server-side user database, no IP leakage, no phone number linkage. Use disposable group servers for one-off conversations with minimal trust assumptions.
MySudo
Virtual phone numbers & privacy suite
All-in-one privacy app providing virtual phone numbers, encrypted email, private browsing, and virtual payment cards. Create up to 9 digital identities (Sudos), each with its own phone number, email, and private browser. End-to-end encrypted calls and messaging between MySudo users. Standard SMS, calling, and email with everyone else. No personal phone number required for signup. PCI-DSS compliant and SOC 2 Type II certified.
Burner phone numbers for account verification without exposing your real number. Compartmentalize identities per engagement — one Sudo for client work, one for research, one for personal, each with isolated phone, email, and browser with no cross-contamination.
Proton Mail
Swiss encrypted email
Swiss-based encrypted email with zero-access encryption, open-source clients, and optional anonymous signup. Includes calendar, drive, and VPN suite.
Primary secure email for client communications, encrypted file sharing for sensitive reports, and anonymous account registration.
Tuta
German end-to-end encrypted email
German-based encrypted email with full end-to-end encryption for subject lines, body, and attachments. Open-source, no tracking, and GDPR-compliant.
Alternative to Proton with stricter encryption defaults. Ideal for EU-based operations requiring subject line encryption.
Mailfence
Belgian privacy-focused email
Belgian-based encrypted email with optional OpenPGP encryption, integrated calendar, documents, and drive. No ads, no tracking. Note: encryption is opt-in via manual PGP key management — default storage is not zero-access encrypted.
European-hosted email with custom domain support. Good for operational aliases and team communication with PGP compatibility.
StartMail
Private email from Startpage creators
Dutch-based encrypted email from the creators of Startpage. PGP integration, disposable aliases, and custom domain support. No personal data required for signup.
Burner alias generation for operational security. Custom domain hosting for anonymous team communication infrastructure.
SimpleLogin
Open-source email alias service
Open-source email alias service by Proton. Create unlimited aliases to protect your real inbox, send and reply from aliases, with custom domain support, PGP encryption, and catch-all aliases. Based in Switzerland.
One unique alias per service to detect data breaches, prevent cross-site email tracking, and compartmentalize identities during research and operations.
addy.io
Open-source anonymous email forwarding
Open-source email alias service for anonymous email forwarding. Create unlimited aliases with custom domains, catch-all addresses, browser extension, and PGP encryption. Based in the UK with a freemium model.
Per-service unique aliases to compartmentalize identities during research and operations — detect data breaches and prevent email-based tracking.
Security
Bitwarden
Open-source password manager
Open-source password manager with zero-knowledge encryption, self-hosting support, and cross-platform sync.
Self-hosted vault for managing client credentials, API keys, and operational access tokens with full audit control.
KeePassXC
Local encrypted password manager
Local, offline password manager with strong AES-256 encryption. No cloud dependency, full data control.
Air-gapped credential storage for high-value accounts, root passwords, and offline access to critical infrastructure.
VeraCrypt
Disk encryption software
Open-source disk encryption for full volumes, partitions, or virtual encrypted disks. Supports plausible deniability.
Encrypt forensic images, sensitive case files, and portable drives used during on-site security assessments.
Cryptomator
Client-side cloud encryption
Open-source client-side encryption for cloud storage. Zero-knowledge, transparent encryption before upload to Google Drive, Dropbox, OneDrive, etc.
Encrypt sensitive client files before cloud sync. Protect proprietary code, credentials, and documentation stored in Dropbox/Google Drive.
Objective-See
macOS security tools
Free open-source macOS security tools including malware detection, firewall monitoring, and persistence analysis.
macOS endpoint hardening and malware detection for team workstations and forensic analysis on Apple hardware.
VirusTotal
URL & file scanner
Multi-engine file and URL scanner aggregating results from 70+ antivirus engines and domain reputation services.
Rapid threat intel triage for suspicious files, URLs, and hashes encountered during incident response and investigations.
urlscan.io
URL scanner & threat intel
Automated URL analysis tool that screenshots web pages and extracts IOCs. Generous free tier (50 private, 1,000 unlisted, 5,000 public scans per day), API available.
Quick triage of suspicious links - captures screenshot, scripts, cookies, and domain info for threat assessment.
Bitdefender
Enterprise endpoint protection
Romanian cybersecurity company providing advanced endpoint detection, network threat prevention, and cloud security for enterprises.
Enterprise endpoint protection for client infrastructure, managed detection & response, and compliance hardening.
Cover Your Tracks
Browser fingerprint analyzer (EFF)
EFF's browser fingerprinting test to measure how uniquely identifiable your browser configuration is online.
Validate browser hardening configurations and verify anonymity posture before conducting sensitive OSINT operations.
DNS Checker
Global DNS propagation checker
Global DNS propagation checker to verify DNS records across multiple servers worldwide.
Verify DNS changes during infrastructure migrations and detect potential DNS hijacking or poisoning attempts.
MetaDefender
Multi-engine malware analysis
Multi-scanning malware analysis with 20+ AV engines (free tier) or 70+ (enterprise). Deep packet inspection and threat intelligence aggregation.
Analyze suspicious files with multiple AV engines and AI behavioral analysis before deployment.
AlienVault OTX
Threat intelligence platform (now LevelBlue OTX)
Open threat intelligence platform (now LevelBlue Open Threat Exchange). Pulse indicators, malware analysis, and collaborative threat research from global users. Formerly AlienVault.
Query IOC databases during incident response, track threat actor campaigns, and contribute to community threat intel.
URLhaus
Malware URL database
Swiss project tracking malware distribution URLs. Focuses on collecting and sharing URLs used for malware distribution.
Check suspicious URLs against known malware distribution sites. Quick triage for phishing and malware URLs in client investigations.
Hybrid Analysis
Malware sandbox analysis
Free malware analysis service using sandbox execution. Submits samples for behavioral analysis and provides detailed reports.
Analyze suspicious binaries, documents, and links in sandbox. No account required for basic analysis.
ANY.RUN
Interactive malware sandbox
Interactive online malware sandbox with real-time process monitoring. Allows full interaction with malware during execution for detailed behavioral analysis.
Interactive analysis for complex malware. Stealth sandbox option available. Good for live malware behavior observation.
iVerify
Mobile EDR platform
Enterprise mobile endpoint detection and response (EDR) with OS-level telemetry, behavioral baselining, and AI-driven threat hunting. Detects Pegasus, DarkSword, and mobile zero-day exploits across iOS and Android. Used by SOC teams for mobile DFIR and supply chain threat detection.
Monitor mobile devices for nation-state spyware (Pegasus, DarkSword) during high-risk travel — OS-level telemetry catches compromises that MDM and network monitoring miss.
Hardware
Yubico
Hardware security keys
FIDO2/WebAuthn hardware keys for phishing-resistant authentication. Used by major tech companies and governments worldwide.
Secure your accounts with hardware 2FA that cannot be compromised by phishing or keyloggers.
Nitrokey
Open-source hardware keys
European-made open-source hardware security keys. Supports FIDO2, PGP, and TOTP. No proprietary cloud dependency.
Privacy-respecting alternative to Yubikey with fully open-source firmware and hardware designs.
Protectli
Hardware firewall appliances
Fanless mini PCs running VyOS or OPNsense. Dedicated hardware firewall for home or office network security.
Replace consumer routers with enterprise-grade firewall hardware for complete network control.
GL.iNet
Privacy travel routers
Mini travel routers with OpenWrt, built-in VPN clients, and DNS filtering. Create a secure network anywhere.
Secure all your devices on untrusted networks with your own VPN-protected router while traveling.
LilyGO
ESP32 dev boards & pentest hardware
Manufacturer of affordable ESP32-based development boards including T-Embed, T-Deck, T-Watch, and T-Display series. Popular platforms for running offensive security firmware like Bruce. Integrated displays, keyboards, CC1101 radios, and USB-C in compact form factors.
Hardware platform for portable red team tools. T-Embed CC1101 and T-Deck are ideal hosts for Bruce firmware — built-in screens, keyboards, and RF modules.
Firewalla
Smart firewall & DNS
Smart home firewall with built-in VPN, DNS filtering, and network monitoring. Protects all devices including IoT.
Network-wide protection for home users with easy VPN setup and ad/tracker blocking.
OnlyKey
PIN-protected hardware key
Open-source hardware security key with PIN entry on the device itself. Supports FIDO2, TOTP, PGP, and offline password storage. Brute-force self-destruct after 30 failed PIN attempts. Firmware is fully auditable and runs on ESP32.
High-assurance hardware key for field operations where physical coercion is a threat. PIN on device prevents forced authentication.
Mosequipment
Faraday bags & RF shielding
French manufacturer of high-quality Faraday bags, RF shielding pouches, and signal-blocking cases. Protects devices against remote wiping, tracking, and RF interception. Tested and certified shielding effectiveness across GSM, GPS, Wi-Fi, and Bluetooth frequencies.
Secure device isolation during field operations — prevent remote wiping, block RF tracking, and secure phones/radios when entering sensitive facilities.
SoloKeys
Open-source hardware security keys
Open-source FIDO2/WebAuthn security keys with fully transparent firmware. Supports FIDO2, U2F, and GPG. Available in USB-A, USB-C, and NFC form factors. Firmware is publicly auditable and community-reviewed. Solo V2 and Somu (NFC-only) models available.
Phishing-resistant hardware 2FA with fully open-source firmware. Ideal for security-conscious users who want auditable keys without proprietary black-box firmware.
CryptoSteel
Metal seed phrase & password backup
Durable metal backup system for cryptocurrency seed phrases, passwords, and private keys. Uses high-grade stainless steel capsules with engraved character tiles — fireproof, waterproof, and corrosion-proof. Supports 12- and 24-word BIP39 seed phrases via modular tile systems (Seed12, Seed24, Capsule, Cassette). Includes tamper-evident security seals. Made in Poland.
Fireproof offline backup of hardware wallet seed phrases — store in a safe or secondary location knowing it will survive fire, flood, and decades of environmental exposure. Essential redundancy for any self-custody crypto setup.
Billfodl
Steel seed phrase backup device
Stainless steel recovery seed backup device for cryptocurrency wallets. Uses sliding character tiles to spell out seed words. Holds up to 96 characters (full 24-word BIP39 phrase). Fireproof, waterproof, and corrosion-resistant. Compatible with Ledger, Trezor, and all BIP39 hardware wallets.
Tamper-resistant offline backup for hardware wallet seed phrases — store in a safe deposit box or secondary location as a durable fallback if the primary wallet is lost, damaged, or destroyed.
Browsing
DuckDuckGo
Private search engine
Search engine that doesn't track your queries, build profiles, or serve personalized results. No cookies, no logging.
Default search for all operational devices to prevent query profiling during OSINT and research.
Startpage
Anonymous search with Google results
European search engine delivering Google results without tracking. No cookies, no logging. Features Privacy Proxy for anonymous browsing.
Alternative for operational research. Privacy Proxy hides your IP from target sites.
Tor Browser
Onion-routed anonymous browsing
The original onion-routed browser for anonymous web access. Defends against traffic analysis and network surveillance.
Anonymous OSINT, dark web threat intel, and accessing .onion services for security research.
Whonix
Tor-based OS for anonymity
Security-focused OS that forces all connections through Tor using a gateway/workstation architecture. Provides network leak protection.
Isolated anonymous workspace for high-risk investigations, leak analysis, and sensitive research operations.
Browserling
Live browser testing
Live interactive browser testing in the cloud. Test across different browsers, OS, and screen resolutions without local VMs.
Cross-browser testing for security tools, XSS verification, and phishing page rendering analysis.
Mullvad Browser
Privacy-focused browser (with Tor Project)
Privacy-first browser developed with Tor Project. Private mode enabled by default, fingerprinting resistance via letterboxing, no telemetry. Works with any VPN.
Daily browsing with VPN. Blocks trackers, resists fingerprinting. No data collected, no account required.
Brave
Privacy-first browser with ad blocker
Privacy-first browser with built-in ad blocker, script blocker, and fingerprinting protection. Blocks trackers by default, offers Tor private windows.
Everyday browsing with strong tracker blocking. Good balance of privacy and compatibility.
LibreWolf
Privacy-hardened Firefox fork
Firefox fork focused on privacy and freedom. Removes telemetry, strengthens fingerprinting protection, includes uBlock Origin.
Privacy-focused daily browser. No Mozilla account required, strong anti-fingerprinting.
Kameleo
Anti-detect browser for multi-accounting
Advanced anti-detect browser with real fingerprint profiles from actual devices. Supports desktop and Android mobile emulation. Unlimited profiles.
Multi-account management on social platforms, e-commerce, and affiliate marketing. Uses real device fingerprints to bypass detection.
Octo Browser
Anti-detect browser with fingerprint spoofing
Anti-detect browser with high-quality fingerprint spoofing at Chromium kernel level. Passes Pixelscan, BrowserLeaks, Whoer. Supports mobile fingerprints, API automation.
Multi-accounting for social media, e-commerce, and automation. Team collaboration, cookie management, and integrated proxy shop.
Ahmia
Tor hidden service search engine
Search engine for Tor hidden services (.onion sites). Open-source, indexes clearnet-accessible .onion addresses, and filters illegal content. Provides anonymity-friendly search for the Tor network.
Discover and verify legitimate .onion services during OSINT investigations and dark web threat intelligence research.
NewPipe
Privacy-friendly YouTube frontend
Open-source Android YouTube client without ads, tracking, or Google Play Services. Supports background playback, downloading, subscribing without an account, and importing from PeerTube and other federated platforms.
Watch and download videos without Google tracking your watch history or device. Essential for OSINT video research without attribution.
Helium
Privacy-focused Chromium browser
Open-source Chromium fork with built-in ad and tracker blocking via uBlock Origin, no telemetry, zero web requests on first launch, and anonymized Chrome Web Store requests to prevent Google from tracking extension downloads. Features !bangs for instant search, split view, and no cloud sync or account system. Available on macOS, Windows, and Linux.
Dedicated browser for sensitive research and OSINT work without leaking browser fingerprint or extension data to Google. Use split view for side-by-side threat intel analysis and !bangs for rapid lookups across platforms.
Psylo
Privacy browser with per-tab silos & proxies
Psylo isolates every tab into its own silo — separate storage, cookies, and a unique IP address from the Mysk zero-log proxy network (40+ servers). Spoofs timezone, locale, and user agent to match proxy location. Canvas randomization, ad blocker, URL tracker cleaner, and no account required. Built by Mysk, a team of privacy researchers from Canada and Germany.
Compartmentalize iOS browsing — run OSINT research, social media reconnaissance, and personal browsing in isolated silos with different IPs and fingerprints. Access web apps (X, Instagram, LinkedIn) each in its own silo to use multiple accounts simultaneously without cross-contamination.
Operating Systems
Qubes OS
Security-by-compartmentalization OS
Security-focused OS that uses virtualization to isolate your digital life into secure compartments called "qubes." If one qube is compromised, the others remain safe. Uses Xen hypervisor for strong isolation between domains.
High-security computing environment for sensitive operations. Separate qubes for banking, work, browsing. Disposable VMs for untrusted files.
Tails
Amnesic live OS for anonymity
Portable OS that runs from a USB stick without leaving any trace on the computer. All traffic routed through Tor, no data saved after shutdown (amnesic). Based on Debian with privacy tools pre-installed.
Anonymous field operations, whistle-blowing, untrusted computers. Leaves zero trace on host machine.
Parrot Security
Debian-based security distro
Debian-based Linux distro for ethical hacking, penetration testing, and digital forensics. Includes 800+ pre-installed security tools. Available in Security and Home editions. Lightweight and privacy-focused.
Penetration testing, vulnerability assessment, red team operations. Home edition for everyday privacy.
Security Onion
Network security monitoring
Distro for network security monitoring, intrusion detection, and log management. Includes Suricata, Zeek, Wazuh, TheHive, and Playbook. Full SOC platform for blue team operations.
Blue team monitoring, incident response lab, SOC deployment, threat hunting.
UTM
Virtual machines for macOS/iOS
Full-featured system emulator and virtual machine host for macOS and iOS based on QEMU. Uses Apple's Hypervisor framework for near-native performance. Supports x86_64, ARM64, RISC-V, and dozens of other architectures.
Isolated testing environments on Mac. Run Windows, Linux, legacy OS in sandboxed VMs. macOS VM support for developers.
Pentesting
Flipper Zero
Portable multi-tool for pentesters
All-in-one portable multi-tool for pentesting, hardware hacking, and RFID/NFC analysis. Features sub-GHz frequency analysis, RFID cloning (125kHz, 13.56MHz), NFC, iButton, infrared remote control, BadUSB, and GPIO for custom hardware interfacing. Extensive open-source ecosystem with custom firmware (Xtreme, Unleashed, RogueMaster).
Physical pentesting toolkit for access control assessment — RFID badge cloning, infrared signal replay, sub-GHz brute-force, and BadUSB payload delivery during on-site engagements.
Bruce Firmware
Offensive ESP32 firmware for red team ops
Open-source ESP32 firmware for offensive security and red team operations. Runs on M5Stack Cardputer, LilyGo T-Embed, and other ESP32 devices. Features Wi-Fi attacks (deauth, evil portal, beacon spam), BLE attacks, BadUSB/DuckyScript payloads, RFID/NFC cloning via PN532, Sub-GHz RF via CC1101, IR tools, and more. AGPL-licensed with fully open hardware designs.
Portable red team toolkit for physical assessments — Wi-Fi deauth testing, BadUSB payload delivery, RFID/NFC cloning, and RF replay attacks. Low-cost Flipper Zero alternative (~$40-65).
Shodan
IoT & exposed service search engine
The search engine for internet-connected devices. Scans and indexes every publicly accessible service: webcams, routers, servers, industrial control systems, and more. Filter by port, country, OS, product, or vulnerability.
Reconnaissance phase of penetration testing — discover exposed services, identify vulnerable devices, and map client attack surface from the outside.
Pentagi
AI-powered pentesting platform
AI-driven penetration testing platform that automates vulnerability discovery, exploitation chains, and reporting. Combines machine learning with traditional pentest methodologies for faster, deeper assessments.
Accelerate pentest engagements with AI-assisted vulnerability chaining and automated proof-of-concept generation.
Penligent
Autonomous attack simulation
AI-powered breach and attack simulation platform. Continuously tests defenses with realistic adversary tactics, techniques, and procedures (TTPs). Maps findings to MITRE ATT&CK framework.
Continuous security validation between pentests. Measure detection coverage and response readiness against real-world attack patterns.
PentestGPT
AI-assisted pentest companion
GPT-powered penetration testing assistant that guides through the testing methodology. Provides real-time suggestions for enumeration, exploitation, and post-exploitation based on context and findings.
Interactive pentest assistant for methodology guidance, command suggestions, and lateral movement strategy during engagements.
Kali Tools
Directory of 600+ security tools
Official Kali Linux tools directory — 600+ penetration testing and security tools organized by category: information gathering, vulnerability analysis, exploitation, wireless attacks, reverse engineering, and more. Each tool has documentation and package details.
Find the right tool for each pentest phase. Browse by attack category or search for specific techniques. Reference for tool installation and usage.
Lab401
Hardware hacking & pentest gear
European retailer specializing in hardware hacking and cybersecurity equipment. Stocks Flipper Zero, Proxmark3, ChameleonUltra, HackRF, RTL-SDR, BadUSB devices, RFID/NFC tools, lockpicks, WiFi deauthers, and development boards. Ships from France with EU/UK coverage.
One-stop shop for hardware pentesting equipment — RFID cloning tools, SDRs, BadUSB devices, and RF analysis gear for physical assessments and red team ops.
Network Analyzer Pro
iOS network diagnostics & LAN scanner
Advanced iOS network diagnostics tool with LAN scanner (IP, NetBIOS, mDNS, Bonjour), ping with geolocation, traceroute on map, port scanner, DNS lookup (all record types + DNSSEC), whois, and internet speed test. Detects all connected devices on WiFi/VPN, supports Wake-on-LAN, full IPv6. Privacy-friendly: analytics data not linked to identity.
Mobile network reconnaissance during physical assessments — scan client LAN from iOS, identify all connected devices, discover open ports via cellular tethering to avoid leaving WiFi logs.
ImmuniWeb WebSec
AI-powered web security scanner
AI-driven web security scanner that tests for OWASP Top 10 vulnerabilities, configuration weaknesses, PCI DSS compliance, and data exposure. Generates compliance-ready reports with remediation advice.
Quick external vulnerability assessment of client web applications — automated OWASP scanning with compliance reporting for audit evidence.
Pentest-Tools Website Scanner
Online vulnerability scanner for web apps
Cloud-based vulnerability scanner that detects OWASP Top 10, SQLi, XSS, and misconfigurations in web applications. Supports authenticated scanning, API testing, and generates executive reports with remediation guidance.
On-demand web app scanning without local tooling — run authenticated scans against client apps during remote assessments.
Sucuri SiteCheck
Free website malware & security scanner
Free remote website security scanner that checks for malware, blacklisting, injected spam, defacements, and outdated software. Scans DNS records, domain headers, and JavaScript integrity. Quick triage tool for initial website compromise assessment.
First-response website compromise triage — check if a client site is blacklisted, injected with malware, or running outdated software without installing any local tools.
SSL Labs SSL Server Test
Deep SSL/TLS configuration analysis
Qualys SSL Labs' comprehensive SSL/TLS server test. Evaluates certificate validity, protocol support, cipher strength, and known vulnerabilities (Heartbleed, POODLE, etc.). Grades servers A-F with detailed remediation steps. Industry standard for TLS assessment.
Validate TLS hardening of client infrastructure before deployment and during security audits — ensure no weak ciphers, expired certs, or protocol downgrade risks.
Anonymity
OnionShare
Anonymous file sharing via Tor
Secure, anonymous file sharing and website hosting over the Tor network with no central servers.
Secure transfer of forensic evidence, large log files, and sensitive documents to clients or legal counsel.
Silent.link
Anonymous eSIM & data
Anonymous eSIM data plans with crypto payment support and no personal information required.
Anonymous mobile connectivity for field operations, travel security, and isolated network access.
GrapheneOS
Hardened Android OS with enhanced security
Hardened Android OS with enhanced privacy, security, and sandboxing. Designed for Pixel devices.
Secure mobile platform for field operatives, mobile pentesting, and running sensitive security apps in hardened sandboxes.
NadaNada
No-KYC eSIM, VPN & phone numbers
No-KYC eSIM, VPN, and virtual phone number services for anonymous mobile connectivity without identity verification.
Anonymous mobile data for field operations, burner device provisioning, and untraceable network access.
VoidMob
Mobile proxies, SMS & eSIM unified
Real 4G/5G mobile proxies from carrier networks, carrier-based SMS verifications, and global eSIMs unified in a privacy-focused, crypto-friendly platform. No KYC required, 99.9% uptime, API access with MCP support for AI agents. Pay with BTC, ETH, SOL and more.
Mobile proxy IPs for geo-obfuscation during remote assessments, anonymous SMS verification for account creation, and untraceable eSIM data for field operations — all from one dashboard.
VPN / DNS
Mullvad VPN
Anonymous VPN, no account needed
Privacy-first VPN with anonymous account creation (no email required), crypto and cash payment options, and strict no-logs policy independently audited. WireGuard and OpenVPN on 500+ servers across 40+ countries.
Primary VPN for operational traffic and geo-obfuscation during remote assessments. Anonymous payment with Monero for non-attributable subscriptions.
NymVPN
Decentralized mixnet VPN with two privacy modes
Next-generation VPN with two modes: Fast mode (2-hop decentralized WireGuard) for daily use, and Anonymous mode (5-hop mixnet) for high-stakes operations where traffic correlation protection is critical. Traffic is mixed, delayed, and re-ordered to defeat timing analysis. Post-quantum key exchange via Lewes Protocol.
Enhanced network anonymity for reconnaissance operations where metadata protection and traffic analysis resistance are critical.
Obscura
Provably private VPN
VPN with blind relay architecture — servers never see your decrypted traffic. Unlike "no-log" VPNs that rely on policy promises, Obscura is provably private by design. Uses WireGuard with cryptographically enforced blind relays that physically cannot decrypt your traffic. Now available on iOS and Android. QUIC-based stealth protocol for censorship circumvention. Exit partners include Mullvad. Accepts Bitcoin and Monero.
High-assurance VPN for threat models requiring provable technical privacy guarantees rather than policy trust. Anonymous payment via Monero.
NextDNS
Privacy-focused DNS resolver
Cloud-based DNS resolver with ad blocking, tracker prevention, and customizable security filters. Supports DNS-over-HTTPS, DNS-over-TLS, and DNSCrypt. Configurable blocklists, allow/deny lists, and analytics dashboard. Free tier covers 300,000 queries/month.
Network-wide DNS filtering for lab environments, blocking telemetry, trackers, and known malicious domains at the DNS level across all devices.
Proton VPN
Swiss VPN with free tier
Swiss-based VPN from the creators of Proton Mail. Strong no-logs policy, Secure Core architecture (traffic routed through privacy-friendly countries), Ad-blocker (NetShield), Stealth protocol for censorship bypass, VPN Accelerator (up to 400% speed increase), and full-disk encrypted servers. 20,000+ servers in 140+ countries. Free tier available with no data caps. WireGuard and OpenVPN protocols. Part of the Proton ecosystem (Mail, Drive, Calendar, Pass).
Integrated privacy stack for ops — pair with Proton Mail for unified secure communications. Secure Core for high-risk environments where adversary controls the local ISP.
AdGuard
DNS filtering & ad blocking
Comprehensive ad blocking and privacy protection suite with DNS filtering at its core. AdGuard DNS is a free, privacy-focused DNS resolver that blocks ads, trackers, and malicious domains across all devices. Self-hosted AdGuard Home for network-wide filtering. Also available as browser extensions, desktop/mobile apps, VPN, and email alias service.
DNS-level filtering for lab and operational networks. Block telemetry, tracking, and malware domains without per-device setup. Self-host on Raspberry Pi for full control.
RethinkDNS
DNS firewall and content blocker
Open-source DNS firewall with 100+ configurable blocklists for blocking trackers, malware, phishing, and adult content. Available as Android/iOS app, desktop client, and public DNS resolvers. Supports encrypted DNS (DoH, DoT, DoQ) with per-app filtering on mobile and real-time traffic inspection. Community-maintained threat intelligence feeds. Rethink Proxy Network launching soon.
Deploy DNS-based threat blocking across all devices as a first line of defense — block C2 callbacks, phishing domains, and telemetry at the DNS layer before they reach the network perimeter. Combine with a VPN for layered traffic control.
Is My ISP Spying?
Free ISP surveillance & browser leak test suite
Free browser-based privacy audit with 7 checks: supercookies (UIDH), HTTP header injection, DNS hijacking, DNS encryption status, TLS middlebox interception, ECH detection, and Quad9 DNS detection. All checks run client-side in under 10 seconds. No sign-up required. IP addresses are hashed with daily-rotating salt and never stored in plaintext. Includes an ISP reputation leaderboard based on real test results.
Baseline ISP surveillance check before deploying a VPN or encrypted DNS — verify your provider isn't injecting headers, hijacking DNS, or intercepting TLS. Run monthly to detect ISP behavior changes.
AmneziaVPN
Open-source VPN: self-hosted, premium, or free
Open-source VPN platform with three tiers: Self-hosted (turn any VPS into a personal VPN server with one-click setup), Premium (paid, 20 countries, $4/mo), and Free (speed-limited, for censored regions). Supports WireGuard, OpenVPN, IKEv2, Shadowsocks, XRay (REALITY/VLESS), and AmneziaWG 2.0 with traffic obfuscation. Client apps for Windows, macOS, Linux, Android, and iOS.
Deploy your own VPN on a rented VPS to avoid shared VPN IP blacklists, prevent logs from reaching a VPN provider, and tunnel through deep packet inspection using obfuscated protocols like AmneziaWG or Cloak — essential for operations in high-censorship regions.
IVPN
Privacy-first VPN, no-logs audited
Gibraltar-registered VPN with independently audited no-logs policy (annual Cure53 audits since 2021, 7th audit underway), dedicated IPs via Multi-hop, anti-tracker DNS, and WireGuard/OpenVPN on servers across 34 countries. RAM-only server infrastructure transition in progress. Accepts anonymous payment via Monero (XMR), Bitcoin, and cash. Open-source clients with full source transparency. IVPN Privacy Guides provide technical privacy education.
Long-term VPN trust anchor for persistent operational infrastructure. Registered in a privacy-friendly jurisdiction (Gibraltar) with annual independent audits and Multi-hop for layered connection routing during sensitive assignments.
Passepartout
Open-source VPN client for Apple devices
Open-source VPN client for iOS, macOS, iPadOS, and tvOS supporting OpenVPN (with XOR obfuscation) and WireGuard protocols. Features on-demand rules, custom routing, DNS over HTTPS/TLS, iCloud sync, Shortcuts automation, presets for major providers (Mullvad, IVPN, NordVPN, etc.), and interactive login with OTP support. No ads, no trackers, no background activities.
Turn any Apple device into a hardened VPN endpoint — import custom WireGuard/OpenVPN configs for operational infrastructure, use on-demand rules to auto-connect on untrusted networks, and leverage Shortcuts automation for VPN state control during field operations.
Privacy Tools
Privacy.com
Virtual cards for online purchases (US only)
Generate virtual payment cards to mask your real card details and limit merchant exposure. US-only (requires US bank account). Supports single-use, merchant-locked, and category-locked cards. Chrome/Firefox browser extension for instant card generation at checkout.
Isolated payment cards for tool subscriptions, burner accounts, and operational expenses without exposing primary financial data.
PrivateBin
Self-hosted encrypted pastebin
Self-hosted encrypted pastebin with zero-knowledge architecture. Data is encrypted/decrypted in the browser. Supports burn-after-reading, discussion threads, file attachment support, Markdown formatting with syntax highlighting, and Tor .onion service. No JavaScript required to view pastes. Used by journalists and security researchers globally.
Secure sharing of configuration snippets, IoCs, and temporary credentials with auto-expiring encrypted pastes.
KYC Not Me
KYC-free service alternatives
Curated directory of services that don't require KYC (Know Your Customer) identity verification. Categorized by service type with user ratings and comments. Community-maintained — anyone can submit new listings.
Find identity-free alternatives for operational infrastructure, payment processing, and service provisioning.
Ad Nauseam
Anti-ad obfuscation extension
Browser extension that fights back against advertising tracking by automatically clicking every blocked ad. Built atop uBlock Origin, it creates noise in ad networks' data, rendering user profiling futile. No data collected, no servers, fully local. Compatible with Manifest V3 workarounds via uBO-Scope.
Active defense against ad trackers. Obfuscates your profile by generating fake click streams that make targeting useless.
Organic Maps
Offline navigation maps
Open-source offline maps app using OpenStreetMap data. No tracking, no ads, no account required. Full offline navigation with turn-by-turn directions, voice guidance, hiking trails, cycling routes, public transit info, speed limits, and Wikipedia integration. Uses crowd-sourced map data from the community.
Navigate without cellular signal or GPS tracking. Use for field operations where location privacy is critical and network access is unreliable.
dnsleaktest.com
DNS leak test for VPN users
Simple DNS leak checker that tests whether your VPN or proxy is leaking DNS queries to your ISP. Shows your detected DNS servers, ISP, and location. Includes a WebRTC leak test. Operated by IVPN with a clear privacy policy. No sign-up needed.
Quick DNS leak validation after connecting to a new VPN — confirm your DNS queries are routed through the VPN tunnel and not exposed to your ISP.
BrowserLeaks
Comprehensive browser privacy leak tests
Suite of client-side browser privacy testing tools covering IP address leaks, WebRTC leaks, Canvas, WebGL, and font fingerprinting, TLS/HTTPS client tests, QUIC/HTTP/3 fingerprinting, Chrome extension detection, DNS leak testing, geolocation API, content filter detection, audio fingerprinting, and more. No user tracking — no personal data collection, no non-essential cookies.
Full browser attack surface assessment — run all tests after hardening your browser to verify fingerprinting countermeasures, confirm WebRTC/IP leaks are blocked, and audit TLS/ECH behavior before conducting sensitive operations.
Immich
Self-hosted photo & video management
Open-source self-hosted alternative to Google Photos with AI-powered smart search (CLIP), facial recognition, automatic mobile backup, timeline view, map view, multi-user support with sharing, video transcoding, and OAuth/OpenID Connect support. Runs via Docker with hardware acceleration for ML inference. v2.0 stable release with semantic versioning, mobile apps for iOS and Android, and a built-in web interface.
Self-host photo evidence, surveillance footage, and operational documentation without exposing them to cloud providers. Full control over storage location with on-device ML for content search across thousands of assets.
Legal
Have I Been Pwned
Check if your data was breached
Search across hundreds of breached databases to check if your email, phone, or password has been exposed.
Quick breach checks during client onboarding, credential hygiene audits, and post-incident exposure assessment.
ToS;DR
Terms of Service analyzer
Community-driven analysis of Terms of Service agreements, rating services on privacy, rights, and data handling.
Evaluate privacy posture of third-party services before integration, and assess legal risk for client tool recommendations.
DataBreach.com
Breach tracking & alerts
Real-time breach notifications, historical breach database, and security incident tracking platform.
Monitor emerging breach trends, client exposure alerts, and post-incident tracking for incident response.
Bitdefender Reverse Phone Lookup
Reverse phone lookup
Free reverse phone lookup tool to identify unknown callers. Helps block unwanted telemarketing and scam calls.
Identify unknown numbers before answering. Essential for operational security and call screening.
DarkOwl
Dark web intelligence platform
Dark web monitoring and intelligence platform that crawls illicit forums, marketplaces, and paste sites for compromised credentials, leaked data, and threat actor activity.
Proactive dark web threat detection for client credentials, leaked documents, and early warning of targeted attacks in underground forums.
Data Removal
DeleteMe
Manual data broker removal
Premium service with human researchers who manually submit opt-out requests to data brokers on your behalf.
Executive-level personal data removal with guaranteed results. Best for high-profile individuals and corporate executives.
PrivacyBee
Browser extension + removal
Combines browser extension tracking blocking with data broker removal services. Continuous monitoring and re-submission.
Dual approach: block trackers while removing existing data. Good for ongoing privacy maintenance.
OneRep
Automated broker removal (controversial CEO)
Monitors 190+ people-search sites and automatically submits opt-out requests. Provides removal progress dashboard. ⚠️ CEO controversy: founder Dmitri Shelest was previously investigated by the FTC for running people-search sites before pivoting to removal — effectively creating and then selling the cure for the same problem. Use Optery or Incogni instead for an ethical alternative.
Automated, hands-off approach. Good baseline protection for teams wanting to reduce exposure without ongoing manual work.
Optery
Enterprise-grade removal
B2B-focused data removal with bulk employee protection, exposure reports, and custom removal strategies.
Best for organizations. Protect entire workforce with centralized dashboard, exposure scoring, and enterprise SLAs.
Incogni
Auto-removes personal data
Automated service that contacts data brokers to remove your personal information from their databases.
Reduce digital footprint of team members and clients to minimize doxxing risk and social engineering attack surface.
Cryptocurrencies
Unstoppable Wallet
Multi-chain crypto wallet
Non-custodial multi-chain crypto wallet. Supports Bitcoin, Ethereum, Polygon, BNB Chain, and 80+ chains. No KYC required, open-source, self-custody with your keys.
Privacy-first crypto storage for operational funds. Self-custody, no identity verification, supports multiple chains in one app.
Cake Wallet
Multi-coin wallet
Non-custodial multi-chain mobile wallet with built-in exchange. Supports Monero, Bitcoin, Ethereum, Solana, Zcash, and 17+ native chains with thousands of tokens. No KYC required for basic usage.
Privacy-first crypto storage for operational funds. No identity verification for basic usage.
Bisq
Decentralized P2P bitcoin exchange
Security Incident — Hacked
Bisq suffered a protocol exploit on May 1, 2026 that drained ~11 BTC (~$876K) from open offers via a negative miner fee vulnerability in the multisig trade protocol, confirmed by Bisq's post-mortem. The vulnerability has been patched. Exercise caution and verify you are running the latest patched version before trading.
Decentralized peer-to-peer bitcoin exchange. Trade BTC for fiat or altcoins without intermediaries. No KYC, no registration, runs as Tor hidden service. Funds held in 2-of-2 multisig.
Privacy-first bitcoin trading without identity verification. Peer-to-peer, no exchange custody, censorship-resistant.
Privacy Pools
Private Bitcoin pool
Bitcoin privacy protocol using zero-knowledge proofs. Enable private, unlinkable transactions through a cooperative pool.
Privacy-preserving Bitcoin transactions without on-chain analysis. For operational Bitcoin security.
SmolRefuel
Gas refueling across 80+ chains
Multi-chain gas refueling service. Swap any token for gas (ETH, BNB, MATIC, etc.) across 80+ supported chains with zero gas fees. No KYC, anonymous wallet refill. Also supports bridging gas from other chains when the destination has none.
Refuel operational wallets that have tokens but no gas for transactions. No KYC, no upfront gas fee, multi-chain support.
Mixero
Bitcoin CoinJoin mixer
Bitcoin mixer using CoinJoin technology for anonymous transactions. No logs, Tor-ready, ETH mixing, XMR bridge, and letter of guarantee for every order.
Operational bitcoin privacy — mix UTXOs before use in operational spending to prevent chain analysis.
RetoSwap
Peer-to-peer Monero exchange
Security Incident — Hacked
RetoSwap suffered security breaches in 2025 and a larger Haveno protocol exploit on May 20, 2026 that drained ~7,000 XMR (~$2.7M). Trading was suspended and PeckShield identified the exploit. The platform cannot be considered safe for operations until a verified security audit confirms remediation. Do not use for sensitive transactions. Consider Bisq instead for P2P Monero trades.
Non-custodial P2P Monero exchange built on Haveno. Desktop client with Tor integration, end-to-end encrypted trades, and support for multiple fiat and crypto payment methods. Open-source with arbitration-based dispute resolution.
Acquire Monero privately without KYC or centralized exchange exposure — source operational funds through direct P2P trades while maintaining complete financial privacy.
Keystone
Air-gapped hardware wallet
Open-source hardware wallet with air-gapped QR-based signing. Supports Bitcoin, Ethereum, Solana, and 200+ chains. Companion app for desktop and mobile with multi-sig support. Fully air-gapped via QR code exchange — no USB, Bluetooth, or network connection required to sign.
Store operational crypto on a device with zero electronic attack surface — sign transactions by scanning animated QR codes from a companion app, keeping the private key permanently isolated from any networked system.
Blockchair
Multi-chain blockchain explorer
Blockchain search engine supporting Bitcoin, Ethereum, Solana, and 18+ other chains. Features advanced search filters, privacy-focused API, transaction graph visualization, and address monitoring. No JavaScript required for basic queries.
Track blockchain transactions across multiple networks without running a full node — verify payments and trace fund flow during operational security assessments without exposing wallet addresses to third-party tracking.
Solscan
Solana blockchain explorer
Comprehensive Solana block explorer with token analytics, NFT tracking, DeFi protocol data, and real-time transaction monitoring. Supports SPL tokens, Metaplex NFT metadata, and program interaction analysis.
Monitor Solana wallet activity and token movements during operational security assessments — verify transactions without exposing wallet addresses to centralized tracking services.
Mempool.space
Open-source Bitcoin block explorer
Open-source Bitcoin block explorer and mempool visualizer. Real-time fee estimates, mempool congestion tracking, block details, address lookup, Lightning Network statistics. Self-hostable, no JavaScript required, Tor-friendly.
Monitor Bitcoin network congestion and estimate optimal transaction fees for operational fund movements — verify on-chain activity without relying on centralized block explorers that may log IPs.
Arbiscan
Arbitrum block explorer
Official block explorer for Arbitrum One, built by Etherscan. Tracks L1→L2 transactions, token transfers, smart contract interactions, and gas fees. Supports the full Arbitrum ecosystem including cross-chain messaging and batch verification.
Monitor Arbitrum L2 transactions and cross-chain activity during operational workflows — verify smart contract interactions and token movements on the leading Ethereum L2 without relying on centralized API providers.
Trocador
Private crypto exchange aggregator
Privacy-focused exchange aggregator that compares rates across 30+ providers for 300+ cryptocurrencies. No account required, no KYC, supports direct wallet-to-wallet swaps with built-in Tor support. Routes trades through non-custodial platforms to minimize counterparty tracking.
Exchange operational crypto across chains without exposing identity — route through the cheapest privacy-preserving provider from a single interface, useful when converting between coins during multi-hop fund movements.
Arbitrum Bridge
Official Arbitrum cross-chain bridge
Official bridge for transferring assets between Ethereum and Arbitrum One. Supports ETH, ERC-20 tokens, and custom tokens with native Arbitrum messaging. Includes canonical token list and standard bridging with fraud-proof confirmation window.
Move funds between Ethereum and Arbitrum L2 without intermediaries — bridge operational capital using the canonical route with native security guarantees, avoiding wrapped tokens and third-party bridge risks.
Zodl
Self-custodial Zcash mobile wallet
Zcash-powered mobile wallet with shielded transactions, CrossPay private cross-chain payments, built-in swaps via NEAR Intents, and Keystone hardware wallet integration. Formerly Zashi, rebranded to Zodl in 2026. Developed by Zcash Open Development Lab (ZODL). No tracking, no accounts, open-source.
Store and spend shielded ZEC privately on mobile — use CrossPay to send ZEC to recipients who prefer BTC or stablecoins, swap ZEC without CEX exposure, and connect to Keystone for cold storage. Ideal for operational privacy where Bitcoin's transparent blockchain is insufficient.
Godex
No-KYC cryptocurrency exchange
No-KYC cryptocurrency exchange supporting 936+ coins with fixed and floating rates. Operates since 2018 with no registration, no volume limits, and 24/7 support. Registered in Seychelles.
Swap cryptocurrencies without KYC or account creation — ideal for privacy-focused conversions between Monero, Bitcoin, and altcoins without linking identity.
Revoke.cash
Revoke ERC20 token approvals
Check and revoke ERC20 token approvals across Ethereum, Polygon, Arbitrum, Optimism, and 100+ EVM chains. Supports batch revoking, approval risk scoring, exploit monitoring, and a browser extension that warns before signing dangerous transactions. Open-source tool maintained since 2021.
Audit and revoke dapp token approvals after every DeFi interaction to prevent drainer attacks and limit exposure from compromised or malicious smart contracts.
Jumper
Multi-chain bridge & swap aggregator
Multi-chain liquidity aggregator connecting 20+ chains through 15+ bridges and 50+ DEXs. Finds optimal routes for cross-chain swaps, token transfers, and native gas bridging. 4x audited by leading security firms.
Bridge assets across L2s and alt-L1s while aggregating liquidity for best rates — essential for moving funds between chains without manual DEX comparison or exposing swap history to a single bridge.
ChangeNOW
Instant non-custodial crypto swaps
Non-custodial instant cryptocurrency exchange with 1,248+ currencies and 50,000+ trading pairs. Supports fixed and floating rates, routes orders across CEXs and DEX liquidity pools (Uniswap, PancakeSwap), and offers optional Pro accounts for cashback and AML checks. No registration required for basic swaps.
Execute rapid privacy coin conversions or operational funding swaps without creating exchange accounts or triggering KYC on standard flows — rotate assets across chains while minimizing on-chain and custodial footprints.
SimpleSwap
Instant crypto exchange without registration
Non-custodial instant cryptocurrency exchange supporting over 2,800 coins and fiat pairs with floating and fixed rate options. No sign-up required for standard swaps; trades execute directly wallet-to-wallet via aggregated liquidity. Optional accounts unlock loyalty cashback and history across devices.
Swap funds into privacy-preserving assets or between chains for one-off operational needs without registering or storing balances on the platform — ideal for compartmentalizing payment flows in sensitive engagements.
Feather Wallet
Free open-source Monero desktop wallet
Lightweight Monero wallet with built-in Tor and I2P support, fast sync (minutes, not hours), coin control, subaddress management, and hardware wallet integration (Ledger). Supports multi-signature wallets and offline signing. Reproducible builds for supply-chain verification. Available on Linux, Tails, Windows, and macOS. Onion and I2P addresses available for download.
Self-custody Monero wallet for operational payments — use with Tor/I2P to mask IP, connect to your own node for full privacy, manage subaddresses per engagement to prevent balance aggregation, and sign transactions offline from an air-gapped machine.
THORSwap
Cross-chain DEX aggregator — native Bitcoin swaps, no wrapping
Multi-chain DEX aggregator powered by THORChain. Swap native assets across 26+ blockchains (Bitcoin, Ethereum, Solana, XRP, Zcash, Dogecoin, etc.) without wrapping, bridging, or KYC. Compares pricing from 1inch, Matcha, Uniswap, and others to find the best cross-chain route. Also offers THORChain LP yields with impermanent loss protection, THOR staking, multi-sig vaults (THORSafe), and a cross-chain name service. Non-custodial — swap directly from your own wallet.
Swap native Bitcoin for Monero or any cross-chain pair without wrapping or KYC — move operational funds across blockchains in a single non-custodial transaction while comparing prices across aggregators and DEXs for the best rate.
OSINT
WhatsMyName
Username enumeration across websites
Search for usernames across 500+ websites to discover social media accounts, forum profiles, and platform presence. Useful for identifying an individual's online footprint across the web.
Enumerate target usernames across platforms during reconnaissance to map online identity and uncover forgotten or secondary accounts.
Epieos
Email OSINT & phone lookup
Search an email address or phone number for associated Google accounts, Gravatar profiles, data breaches, and other public records. Includes Google IDs, Drive files, and Calendar exposure checks.
Reverse email lookup to identify account registrations, associated services, and breach history during OSINT investigations and incident response.
TinEye
Reverse image search engine
Industry-leading reverse image search by computer vision. Finds where an image appears online, tracks modified versions, and identifies the original source. No cookies, no tracking.
Reverse image search for source verification, profile picture tracking, and detecting manipulated media during investigations.
Criminal IP
Attack surface & asset search
Attack surface management search engine that maps internet-connected assets, open ports, vulnerabilities, and IoT devices. Scans IPs, domains, and URLs for security posture assessment.
Rapid external reconnaissance on target infrastructure — identify open ports, exposed services, and known vulnerabilities from an attacker's perspective.
DeHashed
Breach & leak database search
Comprehensive breach and leak database search engine with advanced filtering and alerting capabilities.
Deep breach intelligence for incident response, credential compromise investigations, and threat actor research.
WiGLE
Wireless network mapping & intelligence
Aggregates wireless network data from wardriving contributions worldwide. Query by SSID, BSSID, or location with encryption, frequency, and geolocation details. Powers the Network Intel tool on this site.
Wireless reconnaissance for physical security assessments — identify nearby networks, detect rogue APs, and map wireless coverage zones in target areas.
OSINT Framework
Curated OSINT tool directory
Web-based directory of OSINT tools organized by data type and source. Covers social media, public records, business intelligence, and technical reconnaissance tools.
Navigation hub for OSINT investigations — quickly find the right tool for the data type you need, from email searches to geolocation and dark web monitoring.
IntelX
Intelligence search engine (unreachable)
Deep-web intelligence search engine — indexing public web, dark web, document repositories, and paste sites. Currently unreachable (connection refused). Domain may be available in the future or alternatives (Shodan, Censys, Criminal IP) can be used.
Cross-source intelligence gathering — search leaked databases, dark web forums, and document dumps from a single interface for comprehensive threat intelligence.