Arsenly
Tools
Free Tools
Pricing
Resources
Sign in Get started
Free during preview · 45 tools

Web & API security testing
for hunters, pentesters & AppSec teams

45 curated tools for recon, technical vulnerabilities and the kind of logic flaws automated scanners miss. 13 run right here in your browser, no sign-up. Server-side scans, projects and the API kick in when you need them.

For authorized security testing & education only. Built by XowiaLabs 🇮🇳.

Live demo

Passive subdomain discovery

Queries two passive certificate-transparency sources. We never connect to your target.

Enter any domain. We query two passive sources (Anubis + HackerTarget) and return up to 8 subdomains. No active scan of your target. Full enum (10 sources, alive-probing, takeover-risk) is one sign-up away.

45Curated tools
7Categories
13No-sign-up tools
APIREST + CLI for automation

13 tools you can use right now - no sign-up

All client-side. Nothing leaves your device. Click any card to use it.

SiteMapper Pro

Turn a URL list into 4 views: hierarchical host/path tree, sortable flat list, pattern-frequency (collapses /users/1, /users/2 to /users/{id}) and per-host stats. 10 categories (API, Auth, Params, JS, Sensitive paths/files, Backups, Documents, JSON/XML). Advanced filter (regex, exclude, host pattern, depth), saved lists and one-click handoff to ProbeMaster, Takeover and more.

Recon & Discovery Open →
URL & Endpoint Extractor

Mine URLs, JS endpoints, domains and parameters from pasted source code or a fetched remote file. Categorises findings by type and exports the clean set.

Recon & Discovery Open →
CIDR / IP Calculator

IPv4 and IPv6 subnet math. Expand CIDRs, parse ranges and netmasks, aggregate lists into covering CIDRs, split subnets, classify RFC scope (private, CGNAT, public), and build reverse-DNS and scanner targets.

Recon & Discovery Open →
Cookie / JWT Auditor

Audit cookie flags (Secure, HttpOnly, SameSite, __Host- / __Secure- prefixes, Domain scope) and JWT attacks (alg=none, alg-confusion, jku/jwk/x5u/kid, expiry, privilege claims). Live JWT editor re-signs (none / HMAC) so you can forge and test. Fully client-side.

Web Security Audit Open →
OpenAPI / Swagger Analyzer

Paste or drop an OpenAPI 3 / Swagger 2 spec and map its attack surface in your browser. Flags endpoints with no auth requirement, BOLA / IDOR candidates (object-returning routes keyed by id), mass-assignment surface, overly-permissive schemas, verbose error shapes and deprecated routes. Summarises servers, auth schemes and tags, and generates a ready-to-run curl request collection for Burp handoff. Fully client-side, nothing is uploaded.

Web Security Audit Open →
Hash Toolkit

Generate (MD5, NTLM, SHA) and identify 60+ hash types with ranked candidates. Builds tailored hashcat and John commands (wordlist, rules, mask), with file-extraction helpers and crack-speed guidance. Fully client-side.

Cryptography & Generators Open →
Test Data Generator

Realistic-looking test data across 22 countries: names, emails, phone numbers (fiction-reserved ranges), addresses, postal codes and format-valid sample IDs. Safety-reserved ranges so values look real but never collide with live data. Cards, text, JSON and CSV export.

Cryptography & Generators Open →
Code / Password / Token Generator

Custom-charset strings (1-512 chars, up to 5000 at a time), passwords with entropy scoring, preset tokens (UUID v4, ULID, hex, base64, JWT secrets, Stripe / Slack / GitHub / AWS-style API keys, Luhn-valid test cards) and bulk numeric ranges.

Cryptography & Generators Open →
Encoder / Decoder

4-tab workbench: 20+ encodings (URL, double-URL, percent-all, Base64, Base64URL, HTML, JS \xXX / \uXXXX, CSS, Hex, Binary, Octal, ASCII, ROT-N, Atbash, Morse), all-encodings multi-view, hashes (MD5, SHA family, HMAC), and Unix-timestamp / ISO 8601 conversions.

Encoders & Converters Open →
HTTP Request Converter

Convert HTTP requests between 6 formats: Raw HTTP (Burp), curl, fetch(), HAR, JSON spec and form / query string. Auto-detects input, handles full shell quoting, JSON bodies, multi-line curl and HAR entries from DevTools.

Encoders & Converters Open →
JSON Workbench

Format, validate (with line / col error), minify, sort keys, unescape stringified, convert to YAML / XML / CSV / PHP / JS / JSONL / query, JSONPath query, two-pane diff, extract secrets (URLs / emails / JWTs / AWS / Stripe / private keys), depth and type stats. 100% client-side.

Encoders & Converters Open →
Text Suite

7-tab text workbench: regex find/replace, sort/dedupe/sample, keep-drop line filter, set operations (A−B, ∩, ∪), URL-parts extraction, case conversion (camel, snake, kebab and more), per-line transforms, secret extraction and stats. Per-tab undo (10 steps), drag-drop import.

Encoders & Converters Open →
Text Comparer

4-tab diff workbench: true LCS line / word / char diff, side-by-side, Git-style unified, inline word-level, and stats (added, removed, similarity %). Trim, case-insensitive, ignore-blank-lines toggles. Drag-drop file import, live recompare.

Encoders & Converters Open →
See all 45 tools →

One platform, three workflows

Browser tools, server-side scans, projects, API and CLI - the same surface used for daily recon, paid engagements and CI.

Bug bounty hunters

From recon to business-logic bugs

HackerOne / Bugcrowd scopes pre-loaded. Subdomain → ProbeMaster → Takeover handoffs for the technical bugs, plus OOB canaries, JWT auditor, CSRF and auth-flow tools for the logic vulnerabilities automated scanners can't see. Burp issues XML export ready for submissions.

Pentesters & consultancies

Scope-aware projects with reports

Per-engagement project with newline scope rules (wildcards + CIDR). 90-day scan history. Markdown, HTML and CSV exports ready for client deliverables. Passive by default - safe on shared egress IPs.

AppSec & DevSecOps

REST API, CLI, webhook callbacks

Bearer-auth API for CI gates. xowia run js-secrets -target $URL from any pipeline. Async job queue with Slack / Discord / generic webhook notifications. Scoped per-key permissions.

How Arsenly compares

The categories you're probably already using - and what Arsenly adds on top.

Pentest-Tools
browser SaaS
Burp / Nuclei
desktop & CLI
Arsenly
Browser-based tool grid - ✓ 13 free, no sign-up
H1 / Bugcrowd scope intake - - ✓ one-click project
Scope-aware projects & history limited manual ✓ enforced, 90 days
REST API & CLI for CI paid plans CLI yes ✓ both, scoped keys
Burp-issues XML export - native ✓ from scan history
Passive-only by default opt-in active ✓ enforced
Starting price ~$80 / mo $475 / yr (Burp) Free · Pro ₹799 / mo

Comparison reflects publicly-listed tiers as of 2026. Burp Suite Professional, ProjectDiscovery Nuclei and Pentest-Tools.com are trademarks of their respective owners.

Pricing

Free forever for client-side tools. Pay only when you need the server-side stack.

Free

Free

Free forever
  • All 19 client-side tools (forever free)
  • 8 free-tier server tools (WHOIS, DNS, CVE lookup and more)
  • 30 tokens / 6 hours (~120/day)
Get started free
Max

Max

2,999 / month
  • Everything in Pro
  • Unmetered scans (no token budget)
  • Unlimited projects with scope
Talk to sales

Compare every feature →

🔒
Cancel anytimeStops at end of current period. No retention games.
7-day refundFull refund within the first week. No questions.
🔐
Secure paymentsRazorpay or Stripe handle every cent. We never see card data.
💬
Real humansReply to any email - answered within one working day.

Frequent questions

Will your servers actively scan my target?

No. All server-side tools query passive third-party sources (Shodan InternetDB, crt.sh, OTX, urlscan, certificate-transparency logs). Anything that needs an active connection generates a CLI command you copy-paste and run from your own machine. Your target's WAF never sees our IP.

Can I use this on bug bounty programs and paid engagements?

Yes - both. For bounty work, the Programs directory lets you start a project from any public HackerOne or Bugcrowd scope in one click. For engagements, projects with scope rules and per-target history give you the artefact trail clients ask for. Always check the program's or client's own acceptable-use rules before running anything.

Do you offer API and CLI for CI integration?

Yes. The REST API is Bearer-auth with per-key scopes (limit each key to specific tools). The CLI is a single binary - xowia run js-secrets --target $URL - reads ~/.xowia/config and prints JSON or pretty tables. Both are available on Pro and Max plans.

Where does my scan data live, and for how long?

On our managed MariaDB (private to your account). Retention is 7 days on Free, 90 days on Pro, configurable on Max. Nothing is shared with third parties, and you can export everything as Markdown / JSON / CSV at any time or delete on demand.

What if I don't pay - what do I actually get for free?

13 client-side tools forever (encoders, decoders, payload generators, lookups). 5 server-side free-tier tools (WHOIS, headers, CVE lookup, CNAME, CSP analyzer). 30 tokens every 6 hours. 1 project with scope. 7-day history. No credit card.

Full docs & FAQ →

A note from the maker

I'm a security researcher running XowiaLabs from India. I built Arsenly after spending years juggling 27 separate browser tabs across recon, every bounty engagement starting with the same 40 minutes of setup before the actual hunting could begin. The goal here is simple: one workspace that has the tools, projects, scope, history and exports a working hunter or pentester actually uses, without the bloat.

Everything that ships is something I use on real targets. If a tool drifts from useful to noisy, it goes. If you spot a bug or want a tool that isn't here, reply to any Arsenly email - it comes straight to me.

Find your first issue in 60 seconds

40+ tools, scope-aware projects, REST API and CLI. Free forever for browser tools - paid plans kick in when you need the server-side stack.