Free, browser-based offensive security toolkit for pentesters, red teamers, and bug bounty hunters.
Every tool runs 100% client-side — no data leaves your browser. No accounts, no tracking, no BS.
| Tool | Web | CLI |
|---|---|---|
| Reverse Shell Generator | Use it | osk revshell |
| Encoding/Decoding Multi-Tool | Use it | osk encode |
| Hash Identifier & Generator | Use it | osk hash |
| JWT Decoder & Analyzer | Use it | osk jwt |
| Nmap Command Builder | Use it | osk nmap |
| XSS Payload Generator | Use it | osk xss |
| SQL Injection Payload Generator | Use it | osk sqli |
| HTTP Header Security Analyzer | Use it | osk headers |
| CVSS Calculator | Use it | osk cvss |
| Subnet/CIDR Calculator | Use it | osk subnet |
| CLI Output Formatter | Use it | osk format |
| Wordlist / Password Mutation Generator | Use it | osk wordlist |
All tools are available via osk, our unified CLI toolkit:
pip install offseckitosk revshell -i 10.10.10.10 -l python
osk encode -o base64-encode "Hello World"
osk hash id 5d41402abc4b2a76b9719d911017c592
osk jwt decode eyJhbGciOiJIUzI1NiIs...
osk nmap build -t 10.10.10.0/24 --syn --top-ports 1000
osk xss gen --context html-attr --action alert
osk sqli gen -d mysql -t union -c 3
curl -sI https://example.com | osk headers analyzeSee offseckit/osk for full documentation.
git clone https://github.com/offseckit/offseckit.com.git
cd offseckit.com
npm install
npm run devOpen http://localhost:3000.
- Framework: Next.js (App Router, static export)
- Language: TypeScript
- Styling: Tailwind CSS
- Theme: Dracula-inspired dark UI
Found a bug? Missing a feature? PRs welcome.
MIT