githubEdit

Tool Index

Quick reference to all tools mentioned throughout the pentest-book, organized by category.

Reconnaissance

Subdomain Enumeration

Tool
Description
Link

amass

In-depth DNS enumeration

subfinder

Fast subdomain discovery

assetfinder

Find related domains

findomain

Cross-platform subdomain finder

github-subdomains

Find subdomains in GitHub

crt.sh

Certificate transparency

DNS Tools

Tool
Description
Link

dnsrecon

DNS enumeration script

dnsx

Fast DNS toolkit

massdns

High-performance DNS resolver

puredns

Fast domain resolver/bruteforcer

Network Scanning

Tool
Description
Link

nmap

Network exploration and security auditing

masscan

Fast port scanner

rustscan

Modern port scanner

naabu

Fast port scanner

OSINT

Tool
Description
Link

theHarvester

Email, subdomain, IP gathering

Shodan

Internet-connected device search

Censys

Internet asset discovery

SpiderFoot

OSINT automation

Web Application Testing

Scanners

Tool
Description
Link

Burp Suite

Web security testing platform

OWASP ZAP

Web app security scanner

Nikto

Web server scanner

nuclei

Vulnerability scanner

Caido

Modern web security tool

Fuzzing

Tool
Description
Link

ffuf

Fast web fuzzer

feroxbuster

Recursive content discovery

gobuster

Directory/DNS/VHost brute-forcer

dirsearch

Web path scanner

wfuzz

Web application fuzzer

SQL Injection

Tool
Description
Link

sqlmap

Automatic SQL injection

ghauri

Advanced SQL injection

NoSQLMap

NoSQL injection

XSS

Tool
Description
Link

XSStrike

XSS detection suite

dalfox

Parameter analysis/XSS scanner

kxss

Reflection checker

CMS Scanners

Tool
Description
Link

WPScan

WordPress scanner

Droopescan

CMS scanner (Drupal, etc.)

joomscan

Joomla scanner

Exploitation

Frameworks

Tool
Description
Link

Metasploit

Exploitation framework

Cobalt Strike

Adversary simulation

Sliver

Open-source C2

Havoc

Modern C2 framework

Binary Exploitation

Tool
Description
Link

pwntools

CTF/exploit development

ROPgadget

ROP chain builder

ropper

ROP gadget finder

GEF

GDB enhanced features

pwndbg

GDB for hackers

Post-Exploitation

Windows

Tool
Description
Link

Mimikatz

Credential extraction

Rubeus

Kerberos abuse

SharpCollection

Compiled .NET tools

Seatbelt

Host survey tool

PowerSploit

PowerShell post-exploitation

Linux

Tool
Description
Link

LinPEAS

Linux privilege escalation

linEnum

Linux enumeration

pspy

Process monitor (no root)

GTFOBins

Unix binary exploitation

Active Directory

Tool
Description
Link

BloodHound

AD attack path mapping

Impacket

Network protocols in Python

CrackMapExec

AD Swiss army knife

NetExec

CrackMapExec successor

Certipy

AD CS abuse

ldapdomaindump

AD LDAP dumper

Pivoting

Tool
Description
Link

Chisel

TCP/UDP tunnel

ligolo-ng

Tunneling/pivoting

proxychains

Proxy through chains

sshuttle

VPN over SSH

Cloud Security

AWS

Tool
Description
Link

Pacu

AWS exploitation framework

Prowler

AWS security assessment

ScoutSuite

Multi-cloud auditing

CloudMapper

AWS visualization

Azure

Tool
Description
Link

ROADtools

Azure AD recon

AzureHound

BloodHound for Azure

PowerZure

Azure exploitation

MicroBurst

Azure security tools

GCP

Tool
Description
Link

GCPBucketBrute

GCS bucket brute-force

gcp_scanner

GCP security scanner

Kubernetes

Tool
Description
Link

kube-hunter

K8s penetration testing

kubeletctl

Kubelet exploitation

peirates

K8s pentest tool

Trivy

Container scanner

Mobile

Android

Tool
Description
Link

Frida

Dynamic instrumentation

Objection

Runtime mobile exploration

jadx

Dex to Java decompiler

apktool

APK reverse engineering

MobSF

Mobile security framework

iOS

Tool
Description
Link

Frida

Dynamic instrumentation

Objection

Runtime mobile exploration

ipatool

IPA download

ios-deploy

iOS app deployment

Wireless

WiFi

Tool
Description
Link

aircrack-ng

WiFi security suite

Wifite2

Automated WiFi auditing

hcxdumptool

Capture PMKID/handshakes

Bettercap

MITM framework

Bluetooth

Tool
Description
Link

Ubertooth

Bluetooth sniffing

BlueHydra

Bluetooth discovery

RFID/NFC

Tool
Description
Link

Proxmark3

RFID/NFC research

Flipper Zero

Multi-tool

Password Cracking

Tool
Description
Link

Hashcat

Advanced password recovery

John the Ripper

Password cracker

CeWL

Custom wordlist generator

Hydra

Network login cracker

Social Engineering

Tool
Description
Link

Gophish

Phishing framework

Evilginx2

MITM phishing

SET

Social engineering toolkit

King Phisher

Phishing campaigns

Reporting

Tool
Description
Link

Ghostwriter

Engagement management

Pwndoc

Pentest report generation

PlexTrac

Pentest reporting platform

Dradis

Collaboration/reporting

Wordlists

Resource
Description
Link

SecLists

Security wordlists

PayloadsAllTheThings

Useful payloads

fuzzdb

Attack patterns

wordlists

Common wordlists

Last updated

Was this helpful?