Pentest Tools

Introduction

https://binsec.tools provides a collection of free, web-based utilities for penetration testing. The tools support reconnaissance, configuration checks (security settings) and validation (utilities) — the same tools the binsec team uses in real engagements.

Free Online Tools

  • SubDomainFinder — Discovers subdomains of a domain (CertWatch, DNS queries, wordlists, search engines).
  • WebCompScan — Identifies web technologies via DOM, headers and assets; attempts to detect versions and known issues.
  • SSLCheck (TLS/SSL) — Checks TLS/SSL configuration: protocols, cipher suites and certificate metadata; supports StartTLS checks.
  • HTTPHeaderCheck — Verifies HTTP security headers (CSP, HSTS, X-Frame-Options) against OWASP recommendations.
  • DNSCheck — Tests DNS settings (SOA, AXFR/zone transfer, SPF, DMARC, DNSSEC).
  • CertWatch — Searches Certificate Transparency logs to find additional subdomains.
  • WhatIsMyIP — Shows public IPv4/IPv6 and traceroute info.
  • MailCheck — Validates mail delivery settings (SPF, DKIM, TLS) via reception checks.
  • SPFValidator — Validates SPF records for a given sender and sending mail server.
  • SSHCheck — Reviews SSH banners, supported KEX/ciphers and fingerprints.
  • HashLookup — Reverse-lookup for MD5/SHA1/NTLM hashes against a large database.
  • PasswordListCheck — Checks passwords against public password lists (client-side SHA1 hashing).
  • Password Quality Check — Rates password complexity/quality.
  • CVSS4Calculator — CVSS 4.0 calculator for vulnerability scoring.
  • CVSS4VectorDecoder — Decodes CVSS vectors and explains scoring.

Note

These tools are built for information gathering and configuration verification — they do not perform active exploits against targets. Use them only on systems for which you have explicit authorization.

Sub Articles

binsec academy GmbH – Advanced Pentest Training Lab

binsec academy GmbH operates the Pentest Training Lab, a highly practical online platform dedicated to real penetration testing. Simulating complex corporate networks and advanced real-world attack scenarios within isolated lab environments, it is engineered to sharpen the skills of aspiring and professional penetration testers. Upon conquering our rigorous, fully practical examination, participants earn the distinguished Binsec Academy Certified Pentest Professional (BACPP) designation — proving their technical capability to methodically uncover and evaluate vulnerabilities in modern IT infrastructures.

Explore the Pentest Training Lab

binsec GmbH – Experts in Penetration Testing

As the operative pentesting core of the binsec group, binsec GmbH has provided high-end, human-led penetration testing since 2013. Rejecting automated scans, our permanently employed, certified senior pentest experts deliver manual deep-dive assessments of web applications, APIs, mobile apps, complex network infrastructures, cloud environments, and advanced red team simulations. Specializing in high-regulation sectors like Payment, Banking, and Healthcare, we provide clear risk evaluations and actionable reports to effectively assess your business-critical systems.

Get Manual Expert Penetration Testing Services

Contact

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808