Penetration Testing Tools

0.0(0)
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/29

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

30 Terms

1
New cards

Hashcat

Password-cracking tool for GPU-driven brute-force attacks.

2
New cards

John the Ripper

Open-source password cracker supporting multiple hash types.

3
New cards

Mimikatz

Extracts Windows credentials, hashes, and Kerberos tickets.

4
New cards

Patator

Brute-force tool for protocols like SSH, FTP, and SMTP.

5
New cards

Hydra

Network login cracker for rapid credential brute-forcing.

6
New cards

Burp Suite

Web proxy for manual/automated vulnerability testing.

7
New cards

OWASP ZAP

Open-source web app scanner for vulnerabilities like XSS and SQLi.

8
New cards

Nmap

Network mapper for host discovery, port scanning, and OS detection.

9
New cards

Nessus

Vulnerability scanner for identifying misconfigurations and exploits.

10
New cards

BeEF

Browser Exploitation Framework for client-side attacks.

11
New cards

SQLmap

Automated SQL injection detection and exploitation tool.

12
New cards

DirBuster

Brute-forces web server directories/files.

13
New cards

w3af

Web application attack and audit framework.

14
New cards

Nikto

Web server scanner for outdated software and misconfigurations.

15
New cards

Metasploit

Exploitation framework for developing/deploying payloads.

16
New cards

OpenVAS

Open-source vulnerability scanner (fork of Nessus).

17
New cards

Cain and Abel

Password recovery tool with network sniffing capabilities.

18
New cards

Medusa

Parallelized login brute-forcer for protocols.

19
New cards

SearchSploit

CLI tool for querying Exploit-DB.

20
New cards

Netcat

Networking utility for reading/writing TCP/UDP data.

21
New cards

GDB

GNU Debugger for analyzing software crashes.

22
New cards

Responder

LLMNR/NBT-NS poisoner for credential harvesting.

23
New cards

Impacket

Python library for network protocol exploitation (e.g., SMB).

24
New cards

Empire

PowerShell/post-exploitation framework.

25
New cards

PowerSploit

PowerShell scripts for penetration testing.

26
New cards

BloodHound

Maps Active Directory attack paths.

27
New cards

Drozer

Android security assessment framework.

28
New cards

Covenant

.NET command-and-control (C2) framework.

29
New cards

Cobalt Strike

Red-team toolkit for adversary emulation.

30
New cards

Reaver

Exploits WPS vulnerabilities in Wi-Fi routers.