45 curated tools for recon, technical vulnerabilities and the kind of logic flaws automated scanners miss. 13 run right here in your browser, no sign-up. Server-side scans, projects and the API kick in when you need them.
For authorized security testing & education only. Built by XowiaLabs 🇮🇳.
Queries two passive certificate-transparency sources. We never connect to your target.
Enter any domain. We query two passive sources (Anubis + HackerTarget) and return up to 8 subdomains. No active scan of your target. Full enum (10 sources, alive-probing, takeover-risk) is one sign-up away.
All client-side. Nothing leaves your device. Click any card to use it.
Turn a URL list into 4 views: hierarchical host/path tree, sortable flat list, pattern-frequency (collapses /users/1, /users/2 to /users/{id}) and per-host stats. 10 categories (API, Auth, Params, JS, Sensitive paths/files, Backups, Documents, JSON/XML). Advanced filter (regex, exclude, host pattern, depth), saved lists and one-click handoff to ProbeMaster, Takeover and more.
Mine URLs, JS endpoints, domains and parameters from pasted source code or a fetched remote file. Categorises findings by type and exports the clean set.
IPv4 and IPv6 subnet math. Expand CIDRs, parse ranges and netmasks, aggregate lists into covering CIDRs, split subnets, classify RFC scope (private, CGNAT, public), and build reverse-DNS and scanner targets.
Audit cookie flags (Secure, HttpOnly, SameSite, __Host- / __Secure- prefixes, Domain scope) and JWT attacks (alg=none, alg-confusion, jku/jwk/x5u/kid, expiry, privilege claims). Live JWT editor re-signs (none / HMAC) so you can forge and test. Fully client-side.
Paste or drop an OpenAPI 3 / Swagger 2 spec and map its attack surface in your browser. Flags endpoints with no auth requirement, BOLA / IDOR candidates (object-returning routes keyed by id), mass-assignment surface, overly-permissive schemas, verbose error shapes and deprecated routes. Summarises servers, auth schemes and tags, and generates a ready-to-run curl request collection for Burp handoff. Fully client-side, nothing is uploaded.
Generate (MD5, NTLM, SHA) and identify 60+ hash types with ranked candidates. Builds tailored hashcat and John commands (wordlist, rules, mask), with file-extraction helpers and crack-speed guidance. Fully client-side.
Realistic-looking test data across 22 countries: names, emails, phone numbers (fiction-reserved ranges), addresses, postal codes and format-valid sample IDs. Safety-reserved ranges so values look real but never collide with live data. Cards, text, JSON and CSV export.
Custom-charset strings (1-512 chars, up to 5000 at a time), passwords with entropy scoring, preset tokens (UUID v4, ULID, hex, base64, JWT secrets, Stripe / Slack / GitHub / AWS-style API keys, Luhn-valid test cards) and bulk numeric ranges.
4-tab workbench: 20+ encodings (URL, double-URL, percent-all, Base64, Base64URL, HTML, JS \xXX / \uXXXX, CSS, Hex, Binary, Octal, ASCII, ROT-N, Atbash, Morse), all-encodings multi-view, hashes (MD5, SHA family, HMAC), and Unix-timestamp / ISO 8601 conversions.
Convert HTTP requests between 6 formats: Raw HTTP (Burp), curl, fetch(), HAR, JSON spec and form / query string. Auto-detects input, handles full shell quoting, JSON bodies, multi-line curl and HAR entries from DevTools.
Format, validate (with line / col error), minify, sort keys, unescape stringified, convert to YAML / XML / CSV / PHP / JS / JSONL / query, JSONPath query, two-pane diff, extract secrets (URLs / emails / JWTs / AWS / Stripe / private keys), depth and type stats. 100% client-side.
7-tab text workbench: regex find/replace, sort/dedupe/sample, keep-drop line filter, set operations (A−B, ∩, ∪), URL-parts extraction, case conversion (camel, snake, kebab and more), per-line transforms, secret extraction and stats. Per-tab undo (10 steps), drag-drop import.
4-tab diff workbench: true LCS line / word / char diff, side-by-side, Git-style unified, inline word-level, and stats (added, removed, similarity %). Trim, case-insensitive, ignore-blank-lines toggles. Drag-drop file import, live recompare.
Browser tools, server-side scans, projects, API and CLI - the same surface used for daily recon, paid engagements and CI.
HackerOne / Bugcrowd scopes pre-loaded. Subdomain → ProbeMaster → Takeover handoffs for the technical bugs, plus OOB canaries, JWT auditor, CSRF and auth-flow tools for the logic vulnerabilities automated scanners can't see. Burp issues XML export ready for submissions.
Per-engagement project with newline scope rules (wildcards + CIDR). 90-day scan history. Markdown, HTML and CSV exports ready for client deliverables. Passive by default - safe on shared egress IPs.
Bearer-auth API for CI gates. xowia run js-secrets -target $URL from any pipeline. Async job queue with Slack / Discord / generic webhook notifications. Scoped per-key permissions.
The categories you're probably already using - and what Arsenly adds on top.
| Pentest-Tools browser SaaS |
Burp / Nuclei desktop & CLI |
Arsenly | |
|---|---|---|---|
| Browser-based tool grid | ✓ | - | ✓ 13 free, no sign-up |
| H1 / Bugcrowd scope intake | - | - | ✓ one-click project |
| Scope-aware projects & history | limited | manual | ✓ enforced, 90 days |
| REST API & CLI for CI | paid plans | CLI yes | ✓ both, scoped keys |
| Burp-issues XML export | - | native | ✓ from scan history |
| Passive-only by default | opt-in | active | ✓ enforced |
| Starting price | ~$80 / mo | $475 / yr (Burp) | Free · Pro ₹799 / mo |
Comparison reflects publicly-listed tiers as of 2026. Burp Suite Professional, ProjectDiscovery Nuclei and Pentest-Tools.com are trademarks of their respective owners.
Free forever for client-side tools. Pay only when you need the server-side stack.
No. All server-side tools query passive third-party sources (Shodan InternetDB, crt.sh, OTX, urlscan, certificate-transparency logs). Anything that needs an active connection generates a CLI command you copy-paste and run from your own machine. Your target's WAF never sees our IP.
Yes - both. For bounty work, the Programs directory lets you start a project from any public HackerOne or Bugcrowd scope in one click. For engagements, projects with scope rules and per-target history give you the artefact trail clients ask for. Always check the program's or client's own acceptable-use rules before running anything.
Yes. The REST API is Bearer-auth with per-key scopes (limit each key to specific tools). The CLI is a single binary - xowia run js-secrets --target $URL - reads ~/.xowia/config and prints JSON or pretty tables. Both are available on Pro and Max plans.
On our managed MariaDB (private to your account). Retention is 7 days on Free, 90 days on Pro, configurable on Max. Nothing is shared with third parties, and you can export everything as Markdown / JSON / CSV at any time or delete on demand.
13 client-side tools forever (encoders, decoders, payload generators, lookups). 5 server-side free-tier tools (WHOIS, headers, CVE lookup, CNAME, CSP analyzer). 30 tokens every 6 hours. 1 project with scope. 7-day history. No credit card.
A note from the maker
I'm a security researcher running XowiaLabs from India. I built Arsenly after spending years juggling 27 separate browser tabs across recon, every bounty engagement starting with the same 40 minutes of setup before the actual hunting could begin. The goal here is simple: one workspace that has the tools, projects, scope, history and exports a working hunter or pentester actually uses, without the bloat.
Everything that ships is something I use on real targets. If a tool drifts from useful to noisy, it goes. If you spot a bug or want a tool that isn't here, reply to any Arsenly email - it comes straight to me.
40+ tools, scope-aware projects, REST API and CLI. Free forever for browser tools - paid plans kick in when you need the server-side stack.