A Complete Penetration Testing
A Complete Penetration Testing
Tools
penetration-testing-hacking-tools
Penetration testing & Hacking Tools are more often used by security industries to test the
vulnerabilities in network and applications. Here you can find the Comprehensive Penetration testing
& Hacking Tools list that covers Performing Penetration testing Operation in all the Environment.
Penetration testing and ethical hacking tools are a very essential part of every organization to test
the vulnerabilities and patch the vulnerable system.
Also, Read What is Penetration Testing? How to do Penetration Testing?
Penetration Testing & Hacking Tools ListOnline Resources – Hacking ToolsPenetration Testing
Resources
Metasploit Unleashed – Free Offensive Security Metasploit course.
Penetration Testing Execution Standard (PTES) – Documentation designed to provide a
common language and scope for performing and reporting the results of a penetration test.
Open Web Application Security Project (OWASP) – Worldwide not-for-profit charitable
organization focused on improving the security of especially Web-based and Application-
layer software.
PENTEST-WIKI – Free online security knowledge library for pen-testers and researchers.
Penetration Testing Framework (PTF) – Outline for performing penetration tests compiled
as a general framework usable by vulnerability analysts and penetration testers alike.
XSS-Payloads – Ultimate resource for all things cross-site including payloads, tools,
games, and documentation.
Open Source Security Testing Methodology Manual (OSSTMM) – Framework for
providing test cases that result in verified facts on which to base decisions that impact an
organization’s security.
MITRE’s Adversarial Tactics, Techniques & Common Knowledge (ATT&CK) – Curated
knowledge base and model for cyber adversary behavior.
Exploit Development
Shellcode Tutorial – Tutorial on how to write shellcode.
Shellcode Examples – Shellcodes database.
Exploit Writing Tutorials – Tutorials on how to develop exploits.
OSINT Resources
OSINT Framework – Collection of various OSINT Hacking Tools broken out by category.
Intel Techniques – Collection of OSINT tools. The menu on the left can be used to
navigate through the categories.
NetBootcamp OSINT Tools – Collection of OSINT links and custom Web interfaces to
other services such as Facebook Graph Search and various paste sites.
WiGLE.net – Information about wireless networks worldwide, with user-friendly desktop
and web applications.
Social Engineering Resources
Social Engineering Framework – the Information resource for social engineers.
Lock Picking Resources
Schuyler Towne channel – Lockpicking videos and security talks.
bosnianbill – More lockpicking videos.
/r/lockpicking – Resources for learning lockpicking, equipment recommendations.
Operating Systems
Security-related Operating Systems @ Rawsec – Penetration testing tools & Hacking
Tools list Related Complete list of security operating systems.
Best Linux Penetration Testing Distributions @ CyberPunk – Description of main
penetration testing distributions.
Security @ Distrowatch – Website dedicated to talking about, reviewing, and keeping up
to date with open-source operating systems.
cuckoo – Open source automated malware analysis system.
Computer-Aided Investigative Environment (CAINE) – Italian GNU/Linux live distribution
created as a digital forensics project.
Digital Evidence & Forensics Toolkit (DEFT) – Live CD for forensic analysis runnable
without tampering or corrupting connected devices where the boot process takes place.
Tails – Live OS aimed at preserving privacy and anonymity.
Hacking ToolsPenetration Testing Distributions
Kali – GNU/Linux distribution designed for digital forensics and penetration testing
Hacking Tools
ArchStrike – Arch GNU/Linux repository for security professionals and enthusiasts.
BlackArch – Arch GNU/Linux-based distribution with best Hacking Tools for penetration
testers and security researchers.
Network Security Toolkit (NST) – Fedora-based bootable live operating system designed
to provide easy access to best-of-breed open source network security applications.
Pentoo – Security-focused live CD based on Gentoo.
BackBox – Ubuntu-based distribution for penetration tests and security assessments.
Parrot – Distribution similar to Kali, with multiple architectures with 100 of Hacking Tools.
Buscador – GNU/Linux virtual machine that is pre-configured for online investigators.
Fedora Security Lab – provides a safe test environment to work on security auditing,
forensics, system rescue, and teaching security testing methodologies.
The Pentesters Framework – Distro organized around the Penetration Testing Execution
Standard (PTES), providing a curated collection of utilities that eliminates often unused
toolchains.
AttifyOS – GNU/Linux distribution focused on tools useful during the Internet of Things
(IoT) security assessments.
Docker for Penetration Testing
docker pull kalilinux/kali-linux-dockerofficial Kali Linux
docker pull owasp/zap2docker-stable – official OWASP ZAP
docker pull wpscanteam/wpscan – official WPScan
docker pull citizenstig/dvwa – Damn Vulnerable Web Application (DVWA)
docker pull wpscanteam/vulnerablewordpress – Vulnerable WordPress Installation
docker pull hmlio/vaas-cve-2014-6271 – Vulnerability as a service: Shellshock
docker pull hmlio/vaas-cve-2014-0160 – Vulnerability as a service: Heartbleed
docker pull opendns/security-ninjas – Security Ninjas
docker pull diogomonica/docker-bench-security – Docker Bench for Security
docker pull ismisepaul/securityshepherd – OWASP Security Shepherd
docker pull danmx/docker-owasp-webgoat – OWASP WebGoat Project docker image
docker-compose build && docker-compose up – OWASP NodeGoat
docker pull citizenstig/nowasp – OWASP Mutillidae II Web Pen-Test Practice Application
docker pull bkimminich/juice-shop – OWASP Juice Shop
docker pull kalilinux/kali-linux-docker – Kali Linux Docker Image
docker pull phocean/msf – docker-Metasploit
Multi-paradigm Frameworks
Metasploit – post-exploitation Hacking Tools for offensive security teams to help verify
vulnerabilities and manage security assessments.
Armitage – Java-based GUI front-end for the Metasploit Framework.
Faraday – Multiuser integrated pentesting environment for red teams performing
cooperative penetration tests, security audits, and risk assessments.
ExploitPack – Graphical tool for automating penetration tests that ships with many pre-
packaged exploits.
Pupy – Cross-platform (Windows, Linux, macOS, Android) remote administration and
post-exploitation tool,
Vulnerability Scanners
Nexpose – Commercial vulnerability and risk management assessment engine that
integrates with Metasploit, sold by Rapid7.
Nessus – Commercial vulnerability management, configuration, and compliance
assessment platform, sold by Tenable.
OpenVAS – Free software implementation of the popular Nessus vulnerability assessment
system.
Vuls – Agentless vulnerability scanner for GNU/Linux and FreeBSD, written in Go.
Static Analyzers
Brakeman – Static analysis security vulnerability scanner for Ruby on Rails applications.
cppcheck – Extensible C/C++ static analyzer focused on finding bugs.
FindBugs – Free software static analyzer to look for bugs in Java code.
sobelow – Security-focused static analysis for the Phoenix Framework.
bandit – Security oriented static analyzer for Python code.
Web Scanners
Nikto – Noisy but fast black box web server and web application vulnerability scanner.
Arachni – Scriptable framework for evaluating the security of web applications.
w3af – Hacking Tools for Web application attack and audit framework.
Wapiti – Black box web application vulnerability scanner with built-in fuzzer.
SecApps – In-browser web application security testing suite.
WebReaver – Commercial, graphical web application vulnerability scanner designed for
macOS.
WPScan – Hacking Tools of the Black box WordPress vulnerability scanner.
cms-explorer – Reveal the specific modules, plugins, components and themes that
various websites powered by content management systems are running.
joomscan – one of the best Hacking Tools for Joomla vulnerability scanner.
ACSTIS – Automated client-side template injection (sandbox escape/bypass) detection for
AngularJS.
Network Tools
zmap – Open source network scanner that enables researchers to easily perform Internet-
wide network studies.
nmap – Free security scanner for network exploration & security audits.
pig – one of the Hacking Tools forGNU/Linux packet crafting.
scanless – Utility for using websites to perform port scans on your behalf so as not to
reveal your own IP.
tcpdump/libpcap – Common packet analyzer that runs under the command line.
Wireshark – Widely-used graphical, cross-platform network protocol analyzer.
Network-Tools.com – Website offering an interface to numerous basic network utilities
like ping, traceroute, whois, and more.
netsniff-ng – Swiss army knife for network sniffing.
Intercepter-NG – Multifunctional network toolkit.
SPARTA – Graphical interface offering scriptable, configurable access to existing network
infrastructure scanning and enumeration tools.
dnschef – Highly configurable DNS proxy for pentesters.
DNSDumpster – one of the Hacking Tools for Online DNS recon and search service.
CloudFail – Unmask server IP addresses hidden behind Cloudflare by searching old
database records and detecting misconfigured DNS.
dnsenum – Perl script that enumerates DNS information from a domain, attempts zone
transfers, performs a brute force dictionary style attack and then performs reverse look-ups
on the results.
dnsmap – One of the Hacking Tools for Passive DNS network mapper.
dnsrecon – One of the Hacking Tools for DNS enumeration script.
dnstracer – Determines where a given DNS server gets its information from, and follows
the chain of DNS servers.
passivedns-client – Library and query tool for querying several passive DNS providers.
passivedns – Network sniffer that logs all DNS server replies for use in a passive DNS
setup.
Mass Scan – best Hacking Tools for TCP port scanner, spews SYN packets
asynchronously, scanning the entire Internet in under 5 minutes.
Zarp – Network attack tool centered around the exploitation of local networks.
mitmproxy – Interactive TLS-capable intercepting HTTP proxy for penetration testers and
software developers.
Morpheus – Automated ettercap TCP/IP Hacking Tools .
mallory – HTTP/HTTPS proxy over SSH.
SSH MITM – Intercept SSH connections with a proxy; all plaintext passwords and
sessions are logged to disk.
Netzob – Reverse engineering, traffic generation and fuzzing of communication protocols.
DET – Proof of concept to perform data exfiltration using either single or multiple
channel(s) at the same time.
pwnat – Punches holes in firewalls and NATs.
dsniff – Collection of tools for network auditing and pentesting.
tgcd – Simple Unix network utility to extend the accessibility of TCP/IP based network
services beyond firewalls.
smbmap – Handy SMB enumeration tool.
scapy – Python-based interactive packet manipulation program & library.
Dshell – Network forensic analysis framework.
Debookee – Simple and powerful network traffic analyzer for macOS.
Dripcap – Caffeinated packet analyzer.
Printer Exploitation Toolkit (PRET) – Tool for printer security testing capable of IP and
USB connectivity, fuzzing, and exploitation of PostScript, PJL, and PCL printer language
features.
Praeda – Automated multi-function printer data harvester for gathering usable data during
security assessments.
routersploit – Open source exploitation framework similar to Metasploit but dedicated to
embedded devices.
evilgrade – Modular framework to take advantage of poor upgrade implementations by
injecting fake updates.
XRay – Network (sub)domain discovery and reconnaissance automation tool.
Ettercap – Comprehensive, mature suite for machine-in-the-middle attacks.
BetterCAP – Modular, portable and easily extensible MITM framework.
CrackMapExec – A swiss army knife for pentesting networks.
impacket – A collection of Python classes for working with network protocols.
Wireless Network Hacking Tools
Aircrack-ng – Set of Penetration testing & Hacking Tools list for auditing wireless
networks.
Kismet – Wireless network detector, sniffer, and IDS.
Reaver – Brute force attack against Wifi Protected Setup.
Wifite – Automated wireless attack tool.
Fluxion – Suite of automated social engineering-based WPA attacks.
Transport Layer Security Tools
SSLyze – Fast and comprehensive TLS/SSL configuration analyzer to help identify
security misconfigurations.
tls_prober – Fingerprint a server’s SSL/TLS implementation.
testssl.sh – Command-line tool which checks a server’s service on any port for the support
of TLS/SSL ciphers, protocols as well as some cryptographic flaws.
Web Exploitation
OWASP Zed Attack Proxy (ZAP) – Feature-rich, scriptable HTTP intercepting proxy and
fuzzer for penetration testing web applications.
Fiddler – Free cross-platform web debugging proxy with user-friendly companion tools.
Burp Suite – One of the Hacking Tools ntegrated platform for performing security testing
of web applications.
autochrome – Easy to install a test browser with all the appropriate settings needed for
web application testing with native Burp support, from NCCGroup.
Browser Exploitation Framework (BeEF) – Command and control server for delivering
exploits to commandeered Web browsers.
Offensive Web Testing Framework (OWTF) – Python-based framework for pentesting
Web applications based on the OWASP Testing Guide.
WordPress Exploit Framework – Ruby framework for developing and using modules which
aid in the penetration testing of WordPress powered websites and systems.
WPSploit – Exploit WordPress-powered websites with Metasploit.
SQLmap – Automatic SQL injection and database takeover tool.
tplmap – Automatic server-side template injection and Web server takeover Hacking
Tools.
weevely3 – Weaponized web shell.
Wappalyzer – Wappalyzer uncovers the technologies used on websites.
WhatWeb – Website fingerprinter.
BlindElephant – Web application fingerprinter.
wafw00f – Identifies and fingerprints Web Application Firewall (WAF) products.
fimap – Find, prepare, audit, exploit and even google automatically for LFI/RFI bugs.
Kadabra – Automatic LFI exploiter and scanner.
Kadimus – LFI scan and exploit tool.
liffy – LFI exploitation tool.
Commix – Automated all-in-one operating system command injection and exploitation tool.
DVCS Ripper – Rip web-accessible (distributed) version control systems:
SVN/GIT/HG/BZR.
GitTools – One of the Hacking Tools that Automatically find and download Web-
accessible .git repositories.
sslstrip –One of the Hacking Tools Demonstration of the HTTPS stripping attacks.
sslstrip2 – SSLStrip version to defeat HSTS.
NoSQLmap – Automatic NoSQL injection and database takeover tool.
VHostScan – A virtual host scanner that performs reverse lookups, can be used with pivot
tools, detect catch-all scenarios, aliases, and dynamic default pages.
FuzzDB – Dictionary of attack patterns and primitives for black-box application fault
injection and resource discovery.
EyeWitness – Tool to take screenshots of websites, provide some server header info, and
identify default credentials if possible.
webscreenshot – A simple script to take screenshots of the list of websites.
Hex Editors
HexEdit.js – Browser-based hex editing.
Hexinator – World’s finest (proprietary, commercial) Hex Editor.
Frhed – Binary file editor for Windows.
0xED – Native macOS hex editor that supports plug-ins to display custom data types.
File Format Analysis Tools
Kaitai Struct – File formats and network protocols dissection language and web IDE,
generating parsers in C++, C#, Java, JavaScript, Perl, PHP, Python, Ruby.
Veles – Binary data visualization and analysis tool.
Hachoir – Python library to view and edit a binary stream as the tree of fields and tools for
metadata extraction.
read more https://oyeitshacker.blogspot.com/2020/01/penetration-testing-hacking-tools.html
29 Comments
Give Award
Share
UnsaveHideReport
99% Upvoted
This thread is archived
New comments cannot be posted and votes cannot be cast
SORT BY
BEST
View discussions in 6 other communities
level 1
cyber0pb0b
23 points·6 months ago
Wow this is beast! Great post! Thanks for taking the time to share this 🙏🏽
Give Award
Share
ReportSave
level 2
icssindia
5 points·6 months ago
Thanks man
Give Award
Share
ReportSave
level 1
maga_ot_oz
14 points·6 months ago
Wow man. The community needs people like you. This is going to be so helpful thank you so
much.🙏
Give Award
Share
ReportSave
level 2
icssindia
3 points·6 months ago
Thanks man 😃
Give Award
Share
ReportSave
level 1
doyoueatspam
6 points·6 months ago
🥇🥇🥇
Please accept my poor man’s gold, this is absolutely incredible.
Give Award
Share
ReportSave
level 2
NubShakeZ
1 point·6 months ago
I got u
Give Award
Share
ReportSave
level 3
icssindia
2 points·6 months ago
Thanks, Comment your next topic below 👇🏻
ʟɪᴋᴇ ᴀɴᴅ ᴛᴇʟʟ ᴜs ᴡʜᴀᴛ ᴍᴏʀᴇ ʏᴏᴜ ᴡᴀɴᴛ ᴛᴏ ᴋɴᴏᴡ, ᴡʜɪᴄʜ ᴛᴏᴘɪᴄ sʜᴏᴜʟᴅ ɪ ᴘᴏsᴛ.
Give Award
Share
ReportSave
level 1
LongNgN
5 points·6 months ago
Thanks for sharing
Give Award
Share
ReportSave
level 2
icssindia
3 points·6 months ago
Welcome 😃
Give Award
Share
ReportSave
level 1
binaryslut
4 points·6 months ago
this is fucking epic
Give Award
Share
ReportSave
level 2
icssindia
1 point·6 months ago
If you Guys want to thank us, just give us a Like, and Follow my page.
This really motivates us. 😊 u/icssindia
Give Award
Share
ReportSave
level 1
s3cur1t1
2 points·6 months ago
Damn. 🙏🏾🙏🏾🙏🏾
Give Award
Share
ReportSave
level 2
icssindia
2 points·6 months ago
😃😃😃
Give Award
Share
ReportSave
level 1
a-dippy
2 points·6 months ago
Shet man 🙏🏼✌🏼 Too cool, for real.
Give Award
Share
ReportSave
level 2
icssindia
1 point·6 months ago
If you Guys want to thank us, just give us a Like, and Follow my page.
This really motivates us. 😊 u/icssindia
Give Award
Share
ReportSave
level 1
TotesMessenger
2 points·6 months ago
I'm a bot, bleep, bloop. Someone has linked to this thread from another place on reddit:
[r/u_obie_01] Complete penetration testing tool list
If you follow any of the above links, please respect the rules of reddit and don't vote in the other threads. (Info / ^Contact)
Give Award
Share
ReportSave
level 1
trimeismine
1 point·6 months ago
Great post!
Give Award
Share
ReportSave
level 2
icssindia
1 point·6 months ago
If you Guys want to thank us, just give us a Like, and Follow my page.
This really motivates us. 😊 u/icssindia
Give Award
Share
ReportSave
level 1
4hk2
1 point·6 months ago
AWESOME TOOLS!
Give Award
Share
ReportSave
level 2
icssindia
1 point·6 months ago
If you Guys want to thank us, just give us a Like, and Follow my page.
This really motivates us. 😊 u/icssindia
Give Award
Share
ReportSave
level 1
MagentaManny
1 point·6 months ago
Next, forensics tool kit list? Awesome post!
Give Award
Share
ReportSave
level 2
icssindia
1 point·6 months ago
If you Guys want to thank us, just give us a Like, and Follow my page.
This really motivates us. 😊 u/icssindia
Give Award
Share
ReportSave
level 1
lsnark3223
1 point·6 months ago
This came at the perfect time before I do a security audit for a client.
Give Award
Share
ReportSave
level 2
icssindia
1 point·6 months ago
If you Guys want to thank us, just give us a Like, and Follow my page.
This really motivates us. 😊 u/icssindia
Give Award
Share
ReportSave
level 1
Warsmith40k
1 point·6 months ago
All I have to give is an upvote but this deserves so much more.
Give Award
Share
ReportSave
level 2
icssindia
1 point·6 months ago
If you Guys want to thank us, just give us a Like, and Follow my page.
This really motivates us. 😊 u/icssindia
Give Award
Share
ReportSave
level 1
hc024
1 point·6 months ago
Geez man thanks a lot! For relaying This detailed information.
Give Award
Share
ReportSave
level 1
c0r0n3r
1 point·6 months ago
Transport Layer Security Tools
CryptoLyzer - Fast and flexible server cryptographic (TLS/SSL) settings analyzer library
for Python 2.7/3.4+
Secure Shell Tools
ssh-audit - is a tool for ssh server auditing
Give Award
Share
ReportSave
level 1
c0r0n3r
1 point·6 months ago
On-Line Tools
CryptCheck
CypherCraft
DigiCert SSL Tools
ImmuniWeb SSL Security Test
NameCheap SSL Checker
Qualys SSL Labs
SSH Configuration Auditor
SSL Shopper