Tool directory
Every operator tool — with when, how, and why
A living catalog of 273 offensive, defensive, lab, and automation tools. Filter by engagement phase or category, then open any entry for commands and official links.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Phase
Difficulty
Category
Showing 273 of 273 tools
Frameworks
8- Kali Linuxbeginner
Debian-based distro preloaded with hundreds of offensive security tools.
When: You need a ready attack platform for labs, CTFs, or authorized assessments.
Detailspreplab - Parrot OSbeginner
Security-focused Debian derivative with Privacy and Security editions.
When: You want a lighter alternative to Kali with strong privacy tooling.
Detailspreplab - Metasploit Frameworkintermediate
Modular exploitation framework with payloads, auxiliaries, and post modules.
When: You have a confirmed vulnerability and authorized scope to validate exploitability.
Detailsexploitationpost-exploitationlateral - Cobalt Strikeadvanced
Commercial adversary simulation platform with Beacon C2.
When: Red team engagements requiring stealthy C2 and OPSEC-aware workflows.
Detailsexploitationpost-exploitationlateral - Sliveradvanced
Open-source adversary emulation C2 framework (implants, listeners, pivots).
When: You need a free C2 lab for red team practice after initial access.
Detailsexploitationpost-exploitationlateral - Mythic C2advanced
Collaborative multi-agent C2 platform with modular agents.
When: Learning multi-operator red team ops or custom agent development.
Detailspost-exploitationlateral - PowerShell Empire / Starkilleradvanced
Post-exploitation framework with PowerShell/Python agents and GUI (Starkiller).
When: Windows-heavy lab environments after you have a foothold.
Detailspost-exploitationlateralpersistence - Havocadvanced
Modern open-source C2 with Demon agent and graphical teamserver client.
When: Practicing modern C2 concepts in a home lab.
Detailspost-exploitationlateral
OSINT
21- Maltegointermediate
Graph-based link analysis for people, domains, infrastructure, and relationships.
When: Mapping attack surface and relationships during passive recon.
Detailsrecon - theHarvesterbeginner
Gathers emails, subdomains, hosts, and employee names from public sources.
When: Early passive recon on a domain in scope.
Detailsrecon - Recon-ngintermediate
Modular recon framework with workspace DB and API-backed modules.
When: Structured multi-module OSINT campaigns you want stored and queryable.
Detailsrecon - SpiderFootbeginner
Automated OSINT scanner with web UI covering 200+ data sources.
When: You want broad passive footprinting with minimal manual scripting.
Detailsrecon - Sherlockbeginner
Hunt usernames across hundreds of social sites.
When: Username/handle discovery for authorized OSINT cases.
Detailsrecon - Maigretbeginner
Username OSINT tool with report generation across many sites.
When: Deeper username investigations than basic checkers.
Detailsrecon - holehebeginner
Checks if an email is registered on various sites.
When: Email footprinting during authorized OSINT.
Detailsrecon - Photonbeginner
Fast web crawler that extracts URLs, emails, secrets patterns, and files.
When: Crawling a public site for intel and sensitive exposures.
Detailsrecon - OWASP Amassintermediate
In-depth attack surface mapping and subdomain discovery.
When: Building a complete external asset inventory for a domain in scope.
Detailsreconenumeration - subfinderbeginner
Fast passive subdomain discovery by ProjectDiscovery.
When: Quick passive subdomain collection before active scanning.
Detailsrecon - Chaos / Chaos Clientbeginner
ProjectDiscovery dataset client for known subdomain datasets.
When: Enriching recon with historical subdomain data.
Detailsrecon - Shodanbeginner
Search engine for internet-connected devices and services.
When: Finding exposed services related to in-scope assets (authorized use).
Detailsreconscanning - Censysbeginner
Internet-wide scan data and certificate transparency search.
When: Certificate and host discovery for external attack surface.
Detailsrecon - Hunter.iobeginner
Find and verify professional email addresses for a domain.
When: Authorized phishing simulations or contact discovery in scope.
Detailsrecon - whoisbeginner
Query domain and IP registration records.
When: Identifying registrants, name servers, and netblocks.
Detailsrecon - dig / nslookup / hostbeginner
DNS query tools for records, zone transfer attempts, and resolution checks.
When: Validating DNS records and discovering misconfigurations.
Detailsreconenumeration - crt.shbeginner
Certificate Transparency log search for subdomains.
When: Finding subdomains issued certificates historically.
Detailsrecon - waybackurls / gau / waymorebeginner
Pull historical URLs from Wayback Machine and similar archives.
When: Finding forgotten endpoints, parameters, and old assets.
Detailsreconenumeration - Google Dorking (Search Operators)beginner
Advanced search operators to find exposed files, logins, and indexed secrets.
When: Passive discovery of public exposures related to a target org.
Detailsrecon - TruffleHogbeginner
Finds leaked secrets in git repos and filesystems.
When: Code review, OSINT on public repos, or local secret scanning.
Detailsreconenumeration - Gitleaksbeginner
SAST tool for detecting secrets in git repos.
When: Preventive scanning of codebases and historical commits.
Detailsrecondefense
Reconnaissance
4- dnsrecon / dnsenumbeginner
DNS enumeration scripts for records, zone transfers, and brute force.
When: Deepening DNS recon beyond dig one-liners.
Detailsreconenumeration - Fiercebeginner
DNS reconnaissance tool for locating non-contiguous IP space.
When: Finding related network blocks for an organization.
Detailsrecon - massdnsintermediate
High-performance DNS stub resolver for bulk lookups.
When: Resolving huge subdomain lists efficiently.
Detailsrecon - purednsintermediate
Fast domain resolver and subdomain bruteforcing with wildcard filtering.
When: Accurate subdomain resolution at scale.
Detailsrecon
Network Scanning
14- Nmapbeginner
The definitive network mapper for host discovery, ports, and service/version detection.
When: Mapping live hosts and services on networks you are authorized to test.
Detailsscanningenumeration - Masscanintermediate
Asynchronous ultra-fast port scanner for large address spaces.
When: You need speed across large scopes; follow up with Nmap for depth.
Detailsscanning - RustScanbeginner
Fast port discovery that pipes open ports into Nmap automatically.
When: You want Masscan-like speed with Nmap depth in one flow.
Detailsscanning - naabubeginner
Fast port scanner from ProjectDiscovery, pipeline-friendly.
When: Building modern recon pipelines with httpx/nuclei.
Detailsscanning - AutoReconintermediate
Multi-threaded automatic enumeration of services based on open ports.
When: CTFs and time-boxed engagements where thorough default enum helps.
Detailsscanningenumeration - Netdiscoverbeginner
ARP reconnaissance tool for local network host discovery.
When: On a LAN lab without reliable DHCP host lists.
Detailsscanning - arp-scanbeginner
Sends ARP requests to enumerate hosts on local subnets.
When: Finding devices on your home lab network including those that block ICMP.
Detailsscanning - Angry IP Scannerbeginner
Cross-platform GUI IP/port scanner for quick network views.
When: Beginners mapping a home network without CLI.
Detailsscanning - fpingbeginner
Parallel ICMP ping sweeper for host discovery.
When: Quick alive checks across ranges.
Detailsscanning - hping3advanced
Craft custom TCP/UDP/ICMP packets for firewall and stack testing.
When: Testing firewall rules, idle scans, or path behavior under authorization.
Detailsscanningenumeration - ZMapadvanced
Internet-scale single-packet network scanner used in research.
When: Large-scale research with proper authorization and rate controls.
Detailsscanning - Nmap NSE Scriptsintermediate
Nmap Scripting Engine for service-specific enumeration and vuln checks.
When: After finding open ports — go deeper per protocol.
Detailsenumeration - OpenVAS / Greenboneintermediate
Full-featured open-source vulnerability management scanner.
When: Broad authenticated/unauthenticated vuln scanning for enterprise-style labs.
Detailsscanning - Nessusbeginner
Commercial vulnerability scanner widely used in professional assessments.
When: Compliance-oriented or broad vuln discovery with polished reporting.
Detailsscanning
Home Network & IoT
65- Zenmapbeginner
Official Nmap GUI for visual topology and profile-based scanning.
When: You want Nmap power with an easier UI while mapping your home LAN.
Detailsscanninglab - Fingbeginner
Consumer-friendly network scanner for device inventory and internet checks.
When: Quick phone/desktop inventory of what is on your Wi-Fi.
Detailsscanningrecon - Advanced IP Scannerbeginner
Fast Windows LAN scanner with remote RDP/HTTP shortcuts for found hosts.
When: Windows-centric home labs needing quick live host lists.
Detailsscanning - nbtscanbeginner
Scans for NetBIOS name information on Windows/Samba hosts.
When: Finding Windows PCs, NAS boxes, and printers advertising NetBIOS on your LAN.
Detailsscanningenumeration - avahi-browse / dns-sd (mDNS)beginner
Discovers mDNS/Bonjour services (Chromecast, printers, HomeKit, NAS).
When: Inventorying IoT and Apple/Google devices that speak mDNS on your LAN.
Detailsreconscanning - ss / netstat / lsofbeginner
Show listening ports and connections on your own machines.
When: Checking what services your PC, Pi, or NAS is actually exposing.
Detailsenumerationdefense - arpwatch / arp-scan continuousintermediate
Monitors ARP activity and alerts on new MAC addresses.
When: Detecting new/rogue devices joining your home LAN over time.
Detailsdefensescanning - arpingbeginner
ARP-level ping to check L2 reachability and duplicate IPs.
When: Diagnosing IP conflicts or devices that ignore ICMP.
Detailsscanning - traceroute / mtr / pathpingbeginner
Path discovery tools for hops between you and the internet.
When: Understanding your ISP path, CGNAT, and where latency appears.
Detailsreconscanning - testssl.shbeginner
Checks TLS configuration of HTTPS endpoints (routers, NAS, home labs).
When: Auditing TLS on your router admin page, NAS, or self-hosted apps.
Detailsenumerationscanning - sslscanbeginner
Fast SSL/TLS cipher and protocol enumerator.
When: Quick TLS posture check for home services and lab HTTPS.
Detailsenumeration - onesixtyonebeginner
Fast SNMP community string scanner.
When: Checking printers, routers, switches, UPS devices for default SNMP communities.
Detailsscanningenumeration - snmpwalk / snmp-checkintermediate
Walks SNMP MIBs to pull system info, interfaces, and configs.
When: After finding a working community string on gear you own.
Detailsenumeration - RouterSploitintermediate
Exploitation framework focused on embedded devices and routers.
When: Testing routers/cameras/IoT you own for known default creds and vulns.
Detailsexploitationscanning - Cameradarintermediate
Detects and attacks RTSP camera streams with dictionary routes/creds.
When: Auditing your own IP cameras for default credentials and open RTSP.
Detailsscanningenumeration - IoTSeeker / default-cred scannersintermediate
Scripts that check IoT devices for factory default credentials.
When: Bulk-checking cameras, NVRs, and smart gear on your LAN after inventory.
Detailsscanning - UPnP discovery (upnpc / miranda)intermediate
Discovers UPnP/IGD devices and port mappings on the LAN.
When: Checking whether games/apps punched holes through your router.
Detailsenumerationdefense - Nmap home-LAN script packsbeginner
Targeted Nmap NSE usage for SMB, UPnP, HTTP titles, and vuln checks on owned gear.
When: After host discovery — deepen enum on routers, NAS, printers, smart TVs.
Detailsenumerationscanning - smbclient / showmount / rpcinfobeginner
Manual clients for SMB shares, NFS exports, and RPC services on NAS/PCs.
When: Checking what your NAS or old PC shares to the whole LAN.
Detailsenumeration - macchangerbeginner
Changes interface MAC addresses for lab privacy and filter testing.
When: Testing MAC filters on your own Wi-Fi AP or lab isolation demos.
Detailslabrecon - wavemon / iw / iwlistbeginner
Live Wi-Fi signal, channel, and scan utilities for site surveys.
When: Optimizing home AP placement and spotting neighboring channel congestion.
Detailsreconscanning - LinSSID / wifi analyzer appsbeginner
Graphical Wi-Fi scanner for channels, strength, and security types.
When: Visualizing the Wi-Fi neighborhood around your apartment/house.
Detailsrecon - Airgeddonintermediate
Multi-tool wireless auditing menu for WPA/WPS and related tests.
When: Learning Wi-Fi audit workflows against an AP you own.
Detailsexploitationscanning - Wifiphisheradvanced
Rogue AP framework for phishing Wi-Fi clients in controlled labs.
When: Demonstrating evil-twin risks to household members in a consenting lab demo.
Detailsexploitationlab - termsharkbeginner
Terminal UI for tshark — inspect PCAPs without a full desktop.
When: Analyzing home captures on a Pi or SSH session.
Detailsforensicsenumeration - ntopngintermediate
High-performance network traffic probe with web dashboards.
When: Always-on visibility into which devices talk where on your home LAN.
Detailsdefensescanning - iftop / nethogs / bmon / nloadbeginner
Live bandwidth monitors by host, process, or interface.
When: Finding which device or process is saturating your home uplink.
Detailsdefenseenumeration - Pi-holebeginner
Network-wide DNS sinkhole that blocks ads and known malicious domains.
When: Hardening home DNS and gaining query logs for every device.
Detailsdefenselab - AdGuard Homebeginner
Network-wide DNS filtering and tracking protection with a clean UI.
When: Alternative to Pi-hole for family network DNS security.
Detailsdefenselab - OPNsense / pfSenseintermediate
Full-featured open-source firewalls/routers for serious home labs.
When: Replacing consumer routers to get VLANs, IDS, VPN, and proper logs.
Detailsdefensepreplab - OpenWrtintermediate
Linux-based free firmware for many consumer routers.
When: Unlocking VLANs, packages, and better firewalling on supported hardware.
Detailsdefenselab - WireGuardbeginner
Modern high-performance VPN for remote access to your home lab.
When: Replacing risky WAN-exposed RDP/SSH with a VPN you control.
Detailsdefenseprep - Tailscale / Headscalebeginner
Mesh WireGuard network that's easy for multi-device home labs.
When: You want zero-config secure access across laptops, Pi, and phone.
Detailsdefenseprep - Fail2ban (home SSH/web)beginner
Bans abusive IPs hitting SSH/web services on self-hosted home servers.
When: You expose any self-hosted service (even via reverse proxy).
Detailsdefense - UFW / firewalld / Windows Firewallbeginner
Host firewalls to restrict inbound services on PCs and servers.
When: Hardening every always-on machine after you inventory listeners.
Detailsdefenseprep - Shodan / Censys self-checkbeginner
Search what the internet already knows about your public IP.
When: After setup — verify you did not expose RDP/cameras/NAS to WAN.
Detailsrecondefense - GRC ShieldsUP! / port external testsbeginner
Browser-based external port probe against your public IP.
When: Quick sanity check that common ports are stealth/closed from WAN.
Detailsdefensescanning - Masscan (owned subnets)intermediate
Ultra-fast port sweeps — useful for large home labs / multiple VLANs.
When: You run multiple /24 lab VLANs and need a quick open-port census.
Detailsscanning - iperf3beginner
Measures LAN/WLAN throughput between two hosts you control.
When: Validating Wi-Fi vs ethernet performance after security changes (VLAN/AP).
Detailslabenumeration - Nmap vuln scripts (owned gear)intermediate
NSE vuln category for checking known issues on devices you own.
When: After identifying software versions on NAS/routers/IP cameras.
Detailsscanningenumeration - Yersiniaadvanced
Layer-2 attack toolkit (STP, DHCP, CDP, etc.) for lab switches.
When: Learning L2 weaknesses on a lab switch — not on production home gear carelessly.
Detailsexploitationlab - Bettercap LAN discovery modulesintermediate
Bettercap net.recon/net.probe for live LAN mapping and passive recon.
When: Interactive discovery of hosts and MDNS/NBNS chatter on your network.
Detailsscanningenumeration - mitm6 (lab dual-stack)advanced
IPv6 DNS takeover technique relevant to Windows dual-stack LANs.
When: Lab demonstration of why IPv6 RA/DNS security matters on home/SOHO Windows nets.
Detailsexploitationlab - Inveighadvanced
Windows MITM/spoofing tool for LLMNR/NBNS/mDNS educational labs.
When: Windows-only home lab demonstrating name resolution poisoning risks.
Detailsexploitationlab - Packet Senderbeginner
GUI to send/receive TCP/UDP/SSL packets for IoT protocol tinkering.
When: Manually probing weird device ports (ESP modules, DIY IoT) on your LAN.
Detailsenumerationlab - ngrepintermediate
grep-like tool for live packet payloads on the wire.
When: Hunting cleartext credentials or IoT chatter on a mirrored home segment.
Detailsenumerationforensics - tcpflowintermediate
Reconstructs TCP streams to files for easy inspection.
When: Analyzing captured home traffic for cleartext protocols.
Detailsforensicsenumeration - Zeek (Bro)advanced
Network analysis framework producing rich connection/DNS/HTTP logs.
When: Building a serious home SOC-lite on a span port or gateway tap.
Detailsdefenseforensics - Home Assistant security checklist toolingbeginner
Hardening practices and add-ons around popular home automation hubs.
When: You run Home Assistant or similar automation that holds house control.
Detailsdefenseenumeration - mosquitto_sub / MQTT explorersintermediate
Subscribe/publish tools for MQTT brokers common in IoT stacks.
When: Your smart home uses MQTT — check for anonymous access and sensitive topics.
Detailsenumerationlab - firmwalkerintermediate
Searches extracted firmware images for passwords, keys, and interesting files.
When: You extracted router/IoT firmware (binwalk) and want quick secret hunting.
Detailsenumerationlab - EMBAadvanced
Automated firmware security analyzer for embedded devices.
When: Deep analysis of router/camera firmware images you legally obtained.
Detailsenumerationscanning - IoTGoatintermediate
Deliberately insecure IoT firmware project from OWASP for practice.
When: Learning IoT/firmware testing without risking your real thermostat.
Detailslab - DVRP / vulnerable router firmware labsadvanced
Community vulnerable firmware images for embedded exploit practice.
When: Practicing router exploitation techniques offline.
Detailslab - Nmap OS/service fingerprint (LAN inventory)beginner
Use -O/-sV carefully to label device types on your home network.
When: Building a spreadsheet of every device: phone, TV, cam, PC, Pi.
Detailsscanningenumeration - MAC OUI lookup (wireshark manuf / curl APIs)beginner
Identify device vendors from MAC address prefixes.
When: You see unknown MACs on the router client list or arp table.
Detailsreconscanning - Router admin hardening checklistbeginner
Practical checklist toolset: DNS, admin password, WPS, UPnP, remote mgmt, firmware.
When: First hour on any new home router or after factory reset.
Detailsdefenseprep - IoT / guest VLAN segmentationintermediate
Segment untrusted smart devices onto isolated SSIDs/VLANs.
When: You have cameras, TVs, bulbs that should not touch laptops/NAS.
Detailsdefenseprep - UniFi / Omada / consumer controller suitesbeginner
Vendor controllers that inventory clients, SSIDs, and firewall rules.
When: You run managed APs/gateways and want centralized client visibility.
Detailsdefenseenumeration - tcpdump home capture recipesbeginner
Practical capture filters for home gateways and SPAN sessions.
When: Investigating a noisy device or verifying DNS/VPN traffic paths.
Detailsforensicsenumeration - DHCP lease table auditingbeginner
Review DHCP leases to find unknown devices and sticky squatters.
When: Weekly home hygiene or after guests leave.
Detailsrecondefense - Local DNS / internal name checksbeginner
Probe your home DNS resolver for rebinding protections and internal names.
When: Validating Pi-hole/AdGuard/router DNS behavior.
Detailsenumerationrecon - nc / nmap one-port probesbeginner
Quick interactivity checks against a single host/port on your LAN.
When: Confirming a service is reachable after firewall changes.
Detailsscanning - curl / httpie against home admin APIsintermediate
Manual HTTP probing of router/NAS APIs and device web UIs.
When: Checking for unauthenticated JSON endpoints on home devices.
Detailsenumeration - Home asset inventory (sheet + tags)beginner
Living spreadsheet: IP, MAC, vendor, owner, ports, last firmware, trust tier.
When: Before and after every home audit — the real deliverable for yourself.
Detailsprepreportingdefense
Web Application
31- ffufbeginner
Fast web fuzzer for directories, vhosts, parameters, and more.
When: Discovering hidden paths, virtual hosts, or parameter values.
Detailsenumeration - Gobusterbeginner
Directory/DNS/vhost brute-forcing tool written in Go.
When: Classic content discovery and DNS subdomain brute force.
Detailsenumeration - Feroxbusterbeginner
Recursive content discovery tool with smart filtering.
When: You want recursive directory brute force out of the box.
Detailsenumeration - dirsearchbeginner
Feature-rich web path scanner in Python.
When: Content discovery with flexible extensions and reports.
Detailsenumeration - Wfuzzintermediate
Flexible web application fuzzer for params, headers, auth, etc.
When: Complex injection point fuzzing beyond simple path brute force.
Detailsenumerationexploitation - Nucleibeginner
Template-based vulnerability scanner with huge community template set.
When: Fast, repeatable vulnerability checks across many hosts/URLs.
Detailsscanningenumerationexploitation - Niktobeginner
Classic web server scanner for dangerous files, misconfigs, outdated software.
When: Quick noisy checks of web server hygiene on authorized targets.
Detailsscanning - WhatWebbeginner
Identifies web technologies, CMS, frameworks, and plugins.
When: Fingerprinting stack before selecting exploits/tests.
Detailsenumeration - Wappalyzerbeginner
Technology profiler for websites (CMS, analytics, frameworks).
When: Quick passive stack identification in browser.
Detailsenumeration - httpxbeginner
Fast multi-purpose HTTP toolkit for probing hosts and tech.
When: Validating which hosts speak HTTP and grabbing titles/status/tech.
Detailsreconenumeration - Katanabeginner
Crawling framework by ProjectDiscovery for endpoint discovery.
When: Mapping application URLs and JS-linked endpoints.
Detailsenumeration - sqlmapintermediate
Automatic SQL injection detection and exploitation tool.
When: You have a potentially injectable parameter and written authorization.
Detailsexploitationenumeration - Commixintermediate
Automated command injection exploitation tool.
When: Suspected OS command injection in web parameters.
Detailsexploitation - Dalfoxintermediate
Powerful XSS scanning and parameter analysis tool.
When: Testing reflected/stored XSS candidates at scale.
Detailsexploitationenumeration - XSStrikeintermediate
Advanced XSS detection suite with context-aware payloads.
When: Manual-assist XSS testing on specific endpoints.
Detailsexploitation - WPScanbeginner
WordPress vulnerability scanner for plugins, themes, users.
When: Target runs WordPress and is in scope.
Detailsenumerationexploitation - JoomScanbeginner
OWASP Joomla vulnerability scanner.
When: Target is Joomla CMS.
Detailsenumeration - droopescanbeginner
Scanner for Drupal and other CMS platforms.
When: Drupal (or supported CMS) fingerprinting and plugin enum.
Detailsenumeration - Arjunbeginner
HTTP parameter discovery tool.
When: You need hidden parameters for injection testing.
Detailsenumeration - ParamSpiderbeginner
Mines parameters from web archives for a domain.
When: Building param-rich URL lists for XSS/SQLi testing.
Detailsreconenumeration - jwt_toolintermediate
Toolkit for validating, forging, and attacking JWTs.
When: App uses JWT auth and you need to test algo confusion, secrets, claims.
Detailsexploitationenumeration - Postman / Insomniabeginner
API client for manual REST/GraphQL testing.
When: Working through API endpoints, auth flows, and business logic.
Detailsenumerationexploitation - GraphQLmap / InQL / graphql-copintermediate
Tooling for GraphQL introspection, query fuzzing, and misconfig checks.
When: Target exposes GraphQL endpoint.
Detailsenumerationexploitation - git-dumper / gittoolsintermediate
Recover exposed .git directories from web servers.
When: Web server exposes /.git/ — reconstruct source.
Detailsenumerationexploitation - Interactshintermediate
OOB interaction server for detecting blind vulnerabilities.
When: Testing blind SSRF, XXE, RCE where response is not reflected.
Detailsexploitationenumeration - SSRFmapintermediate
Automated SSRF testing and exploitation assistant.
When: You found a parameter that fetches URLs server-side.
Detailsexploitation - Tplmapintermediate
Server-Side Template Injection detection and exploitation tool.
When: Suspect SSTI in template-driven apps (Jinja, Twig, etc.).
Detailsexploitation - NoSQLMapintermediate
Automated NoSQL injection testing (MongoDB-focused).
When: Apps using MongoDB/NoSQL with injectable inputs.
Detailsexploitation - Wapitibeginner
Web application vulnerability scanner (black-box).
When: Automated web vuln pass complementary to ZAP/Nuclei.
Detailsscanning - Skipfishintermediate
Active web application security reconnaissance tool by Google (legacy but educational).
When: Historical tool practice and recursive discovery experiments.
Detailsscanning - DIRB / dirbusterbeginner
Classic content scanners still found in many courses.
When: Following older training material or simple path brute force.
Detailsenumeration
Proxy & Intercept
5- Burp Suitebeginner
Industry-standard intercepting proxy for web/app security testing.
When: Any web application assessment — manual testing core.
Detailsenumerationexploitation - OWASP ZAPbeginner
Free intercepting proxy and automated web scanner.
When: Budget-friendly web testing and CI security scans.
Detailsenumerationexploitationscanning - Caidointermediate
Modern lightweight web security auditing toolkit (proxy).
When: You want a fast modern proxy workflow for manual web testing.
Detailsenumerationexploitation - mitmproxyintermediate
Interactive CLI/web intercepting proxy with Python scripting.
When: Scriptable traffic modification and mobile app proxying.
Detailsenumerationexploitation - FoxyProxy + Browser DevToolsbeginner
Browser proxy switching and built-in developer tools for web testing.
When: Daily web testing workflow with Burp/ZAP.
Detailsenumeration
Exploitation
3- SearchSploit (Exploit-DB)beginner
Offline search of Exploit Database scripts and advisories.
When: You identified software versions and need public exploits for lab validation.
Detailsexploitation - msfvenomintermediate
Payload generator/encoder from Metasploit project.
When: You need a shellcode/payload for a lab exploit or handler.
Detailsexploitation - ysoserial / ysoserial.netadvanced
Generate payloads for exploiting unsafe Java/.NET deserialization.
When: Confirmed deserialization gadget chains on Java or .NET apps.
Detailsexploitation
Password Attacks
12- Hashcatintermediate
GPU-accelerated password recovery tool supporting hundreds of hash types.
When: You have authorized password hashes to assess password policy strength.
Detailsexploitationpost-exploitation - John the Ripperbeginner
CPU-focused password cracker with jumbo community builds.
When: Cracking common hashes without GPU or using format-specific helpers.
Detailsexploitationpost-exploitation - Hydrabeginner
Online password brute-forcer for many network services.
When: Authorized credential testing against login services with lockout awareness.
Detailsexploitation - Medusaintermediate
Parallel, modular online credential brute-forcing tool.
When: Alternative to Hydra for multi-threaded service auth testing.
Detailsexploitation - Crowbarintermediate
Brute force tool specializing in RDP, VPN, VNC key/password attacks.
When: Testing RDP or OpenVPN auth in labs where Hydra struggles.
Detailsexploitation - CeWLbeginner
Custom wordlist generator from target website wording.
When: Building org-specific password lists from public web content.
Detailsreconexploitation - Crunchbeginner
Wordlist generator for charsets and patterns.
When: You need patterned lists (e.g., SeasonYear!).
Detailsexploitation - SecListsbeginner
Curated wordlists for discovery, passwords, fuzzing, and more.
When: You need quality lists for any enumeration or cracking task.
Detailsenumerationexploitation - rockyou.txtbeginner
Famous leaked password list used as baseline dictionary.
When: First-pass dictionary attacks and training demos.
Detailsexploitation - haitibeginner
Hash type identifier — tells you what hash you're looking at.
When: Before cracking — identify correct hashcat/john mode.
Detailsexploitation - Name-That-Hashbeginner
Modern hash identifier with hashcat/john mode suggestions.
When: Quickly map unknown hashes to cracking tools.
Detailsexploitation - OneRuleToRuleThemAll / rulesetsintermediate
Popular hashcat rule files that mutate dictionaries effectively.
When: Dictionary attack plateaued; need smarter mutations.
Detailsexploitation
Wireless
5- Aircrack-ng Suiteintermediate
Wi-Fi auditing suite: capture, inject, crack WEP/WPA handshakes.
When: Authorized wireless assessments on networks you own or have permission to test.
Detailsscanningexploitation - Wifite2beginner
Automated wireless audit tool wrapping aircrack and related tools.
When: Learning Wi-Fi attacks with more automation in a private lab.
Detailsexploitation - Kismetintermediate
Wireless network detector, sniffer, and IDS for 802.11 and more.
When: Passive wireless survey and rogue AP detection.
Detailsscanningrecon - Reaver / Bullyintermediate
WPS PIN attack tools against vulnerable access points.
When: Testing WPS-enabled APs you own for WPS weakness.
Detailsexploitation - hcxdumptool / hcxtoolsadvanced
Modern tools to capture WPA handshakes/PMKID for hashcat.
When: Advanced Wi-Fi capture workflows for offline cracking labs.
Detailsexploitation
Sniffing & MITM
3- Responderintermediate
LLMNR/NBT-NS/MDNS poisoner that captures NetNTLM hashes on LANs.
When: On internal Windows networks (authorized) where name resolution poisoning is in scope.
Detailsexploitationenumeration - Bettercapintermediate
Network attack framework for recon, MITM, sniffing, and wireless.
When: LAN MITM labs, ARP spoofing demos, Wi-Fi experiments in isolated labs.
Detailsscanningexploitation - Ettercapintermediate
Classic suite for MITM attacks on LAN.
When: Teaching ARP spoofing concepts in a closed lab.
Detailsexploitation
Post-Exploitation
5- Mimikatzintermediate
Extracts credentials, tickets, and secrets from Windows memory/LSASS.
When: High-privilege access on Windows lab machines to demonstrate credential theft.
Detailspost-exploitationlateral - Seatbeltintermediate
C# project for host situational awareness safety checks.
When: Windows foothold — gather host security posture quickly.
Detailspost-exploitation - PowerSploitadvanced
PowerShell post-exploitation module collection.
When: Windows environments where PowerShell tradecraft is in scope.
Detailspost-exploitationlateral - Netcat / ncat / socatbeginner
TCP/UDP Swiss army knife for shells, file transfer, and port checks.
When: Reverse/bind shells, banner grabs, quick file moves in labs.
Detailsexploitationpost-exploitation - Evil-WinRMbeginner
WinRM shell for pentesting Windows remote management.
When: You have credentials and WinRM (5985/5986) is open.
Detailspost-exploitationlateral
Privilege Escalation
9- LinPEASbeginner
Linux privilege escalation enumeration script with color-coded findings.
When: You have a low-priv Linux shell and need escalation paths.
Detailspost-exploitation - WinPEASbeginner
Windows privilege escalation enumeration (PEASS suite).
When: Low-priv Windows shell; hunting misconfigs and credentials.
Detailspost-exploitation - pspyintermediate
Monitor Linux processes without root to catch cron jobs and short-lived commands.
When: Looking for processes/cron commands that expose credentials.
Detailspost-exploitation - GTFOBinsbeginner
Curated list of Unix binaries usable for bypasses and privilege escalation.
When: You can run a binary with elevated privileges (sudo/SUID).
Detailspost-exploitation - LOLBASbeginner
Living Off The Land Binaries and Scripts for Windows.
When: Windows post-ex when you need proxy execution or data movement.
Detailspost-exploitation - linux-exploit-suggesterintermediate
Suggests kernel exploits based on uname and OS details.
When: Kernel is old and local privilege escalation may be possible.
Detailspost-exploitation - WES-NGintermediate
Windows Exploit Suggester Next Generation based on systeminfo.
When: You have Windows systeminfo output and need missing patch intel.
Detailspost-exploitation - SharpUpintermediate
C# port of common Windows privilege escalation checks.
When: Need lighter Windows privesc checks in-memory friendly form.
Detailspost-exploitation - PowerUp (PowerSploit)intermediate
PowerShell scripts for Windows privilege escalation checks.
When: PowerShell is available on compromised Windows host.
Detailspost-exploitation
Active Directory
12- Impacketintermediate
Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).
When: Anything involving Windows/AD auth abuse in labs and authorized tests.
Detailsenumerationexploitationlateral - CrackMapExec / NetExecintermediate
Swiss army knife for pentesting Windows/Active Directory networks (NetExec successor).
When: Spraying creds, enumerating SMB/WinRM/LDAP, and validating access at scale.
Detailsenumerationlateralpost-exploitation - BloodHound / SharpHound / AzureHoundintermediate
Maps Active Directory attack paths using graph theory.
When: After domain foothold to find shortest path to Domain Admin.
Detailsenumerationlateral - Rubeusadvanced
C# toolset for Kerberos abuse (AS-REP, kerberoast, tickets, etc.).
When: Windows host access in domain environments for Kerberos attacks.
Detailsexploitationlateralpost-exploitation - enum4linux-ngbeginner
SMB/Windows enumeration tool wrapping common Samba tools.
When: Windows/Samba hosts with open SMB — users, shares, policies.
Detailsenumeration - SMBMapbeginner
Enumerates Samba share drives across networks with permissions.
When: Finding readable/writable shares quickly.
Detailsenumeration - ldapsearch / windapsearchintermediate
Query LDAP/Active Directory directory data.
When: Domain-joined recon for users, groups, computers, policies.
Detailsenumeration - Kerbruteintermediate
Kerberos pre-auth enumeration and password spraying tool.
When: Validating usernames and careful password sprays against AD.
Detailsenumerationexploitation - Certipyadvanced
Active Directory Certificate Services (AD CS) enumeration and abuse.
When: AD CS is present — ESC1-ESC8 style attack paths.
Detailsenumerationexploitation - ntlmrelayx (Impacket)advanced
Relays NTLM authentications to other services for auth abuse.
When: Combined with Responder/coercion when signing is disabled.
Detailsexploitationlateral - Coercer / PetitPotam techniquesadvanced
Force Windows hosts to authenticate to you for relay attacks.
When: Authorized internal tests combining coercion + relay.
Detailsexploitation - RustHoundintermediate
BloodHound data collector written in Rust.
When: Collecting AD graph data from Linux without SharpHound.
Detailsenumeration
Cloud
7- Pacuadvanced
AWS exploitation framework for post-compromise cloud assessment.
When: You have AWS credentials in scope for cloud penetration testing.
Detailsenumerationexploitationpost-exploitation - Prowlerintermediate
Cloud security best-practice assessment tool (AWS/Azure/GCP).
When: Auditing cloud accounts for misconfigurations (often purple/blue too).
Detailsenumerationdefense - ScoutSuiteintermediate
Multi-cloud security auditing tool producing HTML reports.
When: Point-in-time cloud posture review across providers.
Detailsenumerationdefense - CloudMapperintermediate
Network visualization and analysis for AWS environments.
When: Understanding AWS network exposure and trust relationships.
Detailsenumeration - enumerate-iamintermediate
Enumerates permissions for AWS access keys by trying API calls.
When: You found AWS keys and need to know what they can do.
Detailsenumeration - AWS CLI / Azure CLI / gcloudbeginner
Official cloud CLIs — primary interface for cloud assessments.
When: Any cloud test; know the provider CLI before specialized tools.
Detailsenumerationpost-exploitation - S3Scanner / cloud_enumbeginner
Find open storage buckets and cloud assets by name mutation.
When: External recon for public cloud storage exposures.
Detailsreconenumeration
Container & K8s
6- kube-hunterintermediate
Hunts for security weaknesses in Kubernetes clusters.
When: K8s cluster is in scope for assessment.
Detailsscanningenumeration - kube-benchintermediate
Checks Kubernetes against CIS benchmarks.
When: Hardening reviews and purple team K8s assessments.
Detailsenumerationdefense - Trivybeginner
Vulnerability scanner for containers, filesystems, git repos, and more.
When: Assessing image CVEs and IaC misconfigs.
Detailsscanningdefense - Docker Bench for Securitybeginner
Script checking Docker host configuration against best practices.
When: Hardening Docker hosts in labs and production reviews.
Detailsenumerationdefense - amicontainedintermediate
Container introspection tool — what capabilities/profile do you have?
When: Inside a container foothold assessing breakout potential.
Detailspost-exploitation - CDK (Container Depth Kit)advanced
Toolkit for container penetration testing and escape evaluation.
When: Advanced container security labs with authorization.
Detailspost-exploitationexploitation
Mobile
5- Mobile Security Framework (MobSF)beginner
Automated mobile app (Android/iOS) static and dynamic analysis.
When: Assessing mobile APK/IPA files in a mobile security engagement.
Detailsenumerationscanning - Fridaadvanced
Dynamic instrumentation toolkit for apps (mobile & desktop).
When: Bypassing root/jailbreak detection, hooking functions, runtime analysis.
Detailsexploitationenumeration - Objectionintermediate
Runtime mobile exploration toolkit powered by Frida.
When: Interactive mobile app exploration without writing hooks from scratch.
Detailsexploitation - Apktoolbeginner
Disassemble and rebuild Android APK resources and smali.
When: Static analysis and patching of Android apps.
Detailsenumeration - JADXbeginner
Dex to Java decompiler with GUI for Android apps.
When: Reading Android app logic as Java-like source.
Detailsenumeration
Reverse Engineering
3- Ghidraadvanced
NSA-originated free reverse engineering suite (disassembler/decompiler).
When: Analyzing malware samples or closed binaries in RE labs.
Detailsenumerationexploitation - IDA Free / IDA Proadvanced
Industry-leading interactive disassembler (Pro is commercial).
When: Deep binary analysis where IDA's workflow/plugins matter.
Detailsenumerationexploitation - Radare2 / Cutteradvanced
Unix-like reverse engineering framework and GUI (Cutter).
When: CLI-centric RE, scripting, and CTF binary challenges.
Detailsenumerationexploitation
Binary Analysis
6- GDB + pwndbg / GEF / pedaadvanced
Debugger with exploit-dev UX enhancements for binary exploitation.
When: Developing/understanding memory corruption exploits in labs.
Detailsexploitation - pwntoolsadvanced
CTF framework and exploit development library for Python.
When: Writing reliable exploits against challenge binaries.
Detailsexploitation - checksecbeginner
Checks binary security features (NX, PIE, Canary, RelRO).
When: Before exploiting a binary — know mitigations.
Detailsenumeration - Binwalkintermediate
Firmware analysis tool for embedded images and file carving.
When: IoT/firmware assessments and unknown binary blobs.
Detailsenumerationforensics - strings / xxd / hexdumpbeginner
Basic binary inspection utilities every analyst uses daily.
When: First look at unknown files for secrets, URLs, and headers.
Detailsenumerationforensics - ROPgadget / ropperadvanced
Find ROP gadgets in binaries for exploit development.
When: Building ROP chains against NX-protected binaries.
Detailsexploitation
Forensics
7- Volatility 3advanced
Memory forensics framework for RAM dumps.
When: Analyzing memory images for malware, credentials, or incident response.
Detailsforensics - Autopsybeginner
GUI digital forensics platform on The Sleuth Kit.
When: Disk image investigation and timeline analysis.
Detailsforensics - The Sleuth Kitintermediate
CLI tools for disk image forensic analysis.
When: Scriptable disk forensics and learning filesystem internals.
Detailsforensics - Wireshark / tsharkbeginner
World-class packet capture and protocol analysis tool.
When: Analyzing network traffic, protocols, and evidence PCAP files.
Detailsscanningforensicsenumeration - tcpdumpbeginner
CLI packet capture utility.
When: Capturing traffic on remote/headless systems.
Detailsscanningforensics - ExifToolbeginner
Read/write metadata in files (images, docs, etc.).
When: OSINT on documents/images or scrubbing metadata.
Detailsforensicsrecon - steghide / zsteg / steghide toolsbeginner
Steganography detection and extraction tools for CTFs and investigations.
When: Images may hide data in CTF/forensics challenges.
Detailsforensicslab
Tunneling & Pivoting
6- Chiselintermediate
Fast TCP/UDP tunnel over HTTP secured with SSH-like crypto.
When: You need to pivot into internal networks through a foothold.
Detailslateralpost-exploitation - Ligolo-ngintermediate
Advanced pivoting tool using a TUN interface — no SOCKS headaches.
When: Complex multi-network pivots where native routing is nicer than SOCKS.
Detailslateralpost-exploitation - sshuttlebeginner
Transparent proxy VPN over SSH without needing admin on remote.
When: You have SSH access and need to reach remote subnets quickly.
Detailslateral - socatintermediate
Multipurpose relay for bidirectional data transfer (sockets, files, exec).
When: Port forwards, simple shells, protocol bridging in constrained envs.
Detailspost-exploitationlateral - Proxychains-ngbeginner
Force TCP connections from dynamic tools through a proxy/SOCKS.
When: You have a SOCKS pivot and need nmap/browser/tools through it.
Detailslateral - SSH Tunnelingbeginner
Local/remote/dynamic port forwarding built into SSH.
When: You have SSH and need access to internal services.
Detailslateralpost-exploitation
Reporting
5- Dradisintermediate
Collaboration and reporting platform for security assessments.
When: Team engagements needing centralized findings and exportable reports.
Detailsreporting - SysReptorbeginner
Modern pentest reporting platform with templates.
When: Building professional findings reports efficiently.
Detailsreporting - PwnDocintermediate
Pentest report generator with reusable finding templates.
When: Standardizing findings language across reports.
Detailsreporting - Serpicointermediate
Penetration testing report generation and collaboration tool.
When: Legacy but educational reporting workflow practice.
Detailsreporting - Markdown + Pandoc / LaTeXbeginner
Lightweight reporting pipeline using Markdown converted to PDF/DOCX.
When: Solo labs and CTF writeups that still look professional.
Detailsreporting
Lab Environments
15- Metasploitable 2/3beginner
Intentionally vulnerable Linux/Windows VMs for exploit practice.
When: Learning scanning and exploitation safely on disposable VMs.
Detailslab - DVWAbeginner
Damn Vulnerable Web Application for learning OWASP bugs.
When: Practicing SQLi, XSS, CSRF, file inclusion at adjustable difficulty.
Detailslab - OWASP Juice Shopbeginner
Modern insecure web app with gamified challenges.
When: Learning contemporary web vulnerabilities with scoreboard.
Detailslab - OWASP WebGoatbeginner
Deliberately insecure app teaching common web flaws lesson-by-lesson.
When: Guided learning path for web security concepts.
Detailslab - VulnHubbeginner
Free downloadable vulnerable machines for offline practice.
When: Building home lab experience with boot2root VMs.
Detailslab - Hack The Boxintermediate
Online pentest labs with machines, challenges, and careers path.
When: Structured progression from beginner to advanced real-world boxes.
Detailslab - TryHackMebeginner
Guided cybersecurity learning rooms and hands-on labs.
When: Absolute beginners needing structured paths and tutorials.
Detailslab - PortSwigger Web Security Academybeginner
Free high-quality web vulnerability labs from Burp's creators.
When: Mastering web attacks with precise, reliable labs.
Detailslab - PentesterLabintermediate
Exercise-based pentest learning from basics to advanced badges.
When: Skill-focused drills (especially web and Unix).
Detailslab - OverTheWire Wargamesbeginner
SSH-based wargames teaching Linux, security, and exploitation basics.
When: Learning Linux command line and security thinking from zero.
Detailslab - picoCTFbeginner
Beginner-friendly CTF platform from Carnegie Mellon.
When: Introduction to CTF categories: crypto, forensics, web, pwn, rev.
Detailslab - DetectionLabadvanced
Automated lab with Windows domain + logging/detection stack.
When: Learning purple team: attack and see detections.
Detailslabdefense - GOAD (Game of Active Directory)advanced
Complex vulnerable Active Directory lab for realistic AD attacks.
When: Ready to practice BloodHound paths, trusts, and AD tradecraft.
Detailslab - VirtualBox / VMware / Proxmoxbeginner
Hypervisors for isolated home labs and vulnerable VMs.
When: Always — isolation is mandatory for offensive practice.
Detailspreplab - Dockerbeginner
Container runtime for spinning vulnerable apps quickly.
When: Local web labs (Juice Shop, DVWA, WebGoat) in seconds.
Detailspreplab
Defensive / Blue
5- Sigma Rulesintermediate
Generic detection rule format convertible to SIEM queries.
When: Writing detections for techniques you just learned to attack.
Detailsdefense - osqueryintermediate
SQL-powered endpoint visibility agent.
When: Querying host state for IR or baseline hardening verification.
Detailsdefenseforensics - Suricataadvanced
Network IDS/IPS and network security monitoring engine.
When: Detecting attack traffic in lab or production networks.
Detailsdefense - Wazuhintermediate
Open-source XDR/SIEM platform for log analysis and FIM.
When: Building a free detection stack in a home lab.
Detailsdefense - Fail2banbeginner
Bans IPs that show malicious signs (e.g., too many SSH failures).
When: Hardening internet-facing lab services against noisy scans.
Detailsdefense
Scripting & Automation
8- Python 3beginner
Primary scripting language for security automation and exploit tooling.
When: Automating recon, parsing output, writing custom exploits/tools.
Detailsprepreconexploitation - Bash / POSIX Shellbeginner
Shell scripting for glue logic, loops over targets, and quick ops.
When: Pipelines of CLI tools and remote Linux automation.
Detailspreppost-exploitation - PowerShellintermediate
Windows automation and offensive/defensive scripting environment.
When: Anything Windows/AD — enum, admin, and modern tooling.
Detailsenumerationpost-exploitationlateral - Scapyadvanced
Python packet manipulation library for custom protocol work.
When: You need packets that scanners don't craft.
Detailsscanningexploitation - jq / yqbeginner
JSON/YAML processors for parsing tool output at scale.
When: Modern tools output JSON — you need to filter and join data.
Detailsreconreporting - Ansibleintermediate
Automation engine useful for lab provisioning and hardening baselines.
When: Building repeatable vulnerable/hardened lab environments.
Detailsprepdefense - CyberChefbeginner
The Cyber Swiss Army Knife — encode/decode/compress/parse in-browser.
When: Transforming data: base64, hex, JWT, hashes, compression, magic.
Detailsreconforensicsexploitation - anew / unfurl / qsreplacebeginner
Tomnomnom-style pipeline utilities for recon data wrangling.
When: Building shell recon pipelines like a pro.
Detailsrecon
Official project links
Every tool page includes the upstream URL. Prefer official sources and package managers over random mirrors. Verify checksums for binaries when your engagement requires it.
Social Engineering
3Open-source phishing framework for awareness campaigns.
When: Authorized phishing simulations for security awareness programs.
Framework for social engineering labs (credential harvesters, payloads).
When: Training environments teaching SE concepts under supervision.
MITM phishing framework for testing MFA bypass resilience (authorized only).
When: Advanced red team phishing simulations with strict RoE.