⚠ These tools are for educational and authorized use only. Always get permission before scanning or testing any system you don't own.
Nmap
The gold standard for network discovery and security auditing. Scan hosts, detect open ports, identify services and OS versions.
Shodan
Search engine for internet-connected devices. Discover exposed servers, webcams, routers, and more across the public internet.
DNSRecon
DNS enumeration tool for gathering DNS records, performing zone transfers, and identifying subdomains.
Sublist3r
Fast subdomain enumeration tool using OSINT sources like Google, Bing, VirusTotal, and more.
Nessus
Industry-leading vulnerability scanner. Identifies vulnerabilities, misconfigurations, and compliance issues across systems.
OWASP ZAP
Free web application security scanner. Great for finding XSS, SQL injection, and other OWASP Top 10 vulnerabilities.
ffuf
Fast web fuzzer written in Go. Use it for directory and file brute-forcing, parameter fuzzing, and more.
RustScan
The modern port scanner. Scans all 65,535 ports in under 3 seconds then hands off to Nmap for deeper analysis.
Metasploit
The world's most used penetration testing framework. Contains hundreds of exploits, payloads, and auxiliary modules.
sqlmap
Automatic SQL injection and database takeover tool. Supports MySQL, Oracle, PostgreSQL, MSSQL, and more.
Hashcat
World's fastest and most advanced password recovery tool. Supports 300+ hash types with GPU acceleration.
SecLists
Collection of multiple types of lists used during security assessments — usernames, passwords, URLs, fuzzing payloads, and more.
Wireshark
The world's foremost network protocol analyzer. Capture and interactively analyze network traffic in real time.
Burp Suite
The leading web security testing platform. Intercept, inspect, and modify HTTP/S traffic between browser and server.
tcpdump
Powerful command-line packet analyzer. Lightweight alternative to Wireshark for terminal-based analysis.
TryHackMe
Beginner-friendly cybersecurity training platform with guided rooms, learning paths, and CTF-style challenges.
Hack The Box
Advanced penetration testing labs. Hack real machines in a safe, legal environment and earn rankings.
PortSwigger Web Academy
Free, world-class web security training from the makers of Burp Suite. Covers all OWASP Top 10 and beyond.
picoCTF
Free computer security game targeted at middle and high school students. Great starting point for beginners.
Proxmox VE
Open-source server virtualization platform we use for building our own lab infrastructure and server environments.
Kali Linux
Debian-based Linux distribution designed for digital forensics and penetration testing. Comes pre-loaded with 600+ tools.
VirtualBox
Free and open-source virtualization software. Run Kali Linux, Windows, or any OS safely inside your main machine.