// arsenal

Hack Tools

Tools we use in meetings, labs, and CTF competitions

⚠ These tools are for educational and authorized use only. Always get permission before scanning or testing any system you don't own.

Reconnaissance
Network Scanner

Nmap

The gold standard for network discovery and security auditing. Scan hosts, detect open ports, identify services and OS versions.

OSINT

Shodan

Search engine for internet-connected devices. Discover exposed servers, webcams, routers, and more across the public internet.

DNS Recon

DNSRecon

DNS enumeration tool for gathering DNS records, performing zone transfers, and identifying subdomains.

Subdomain Enum

Sublist3r

Fast subdomain enumeration tool using OSINT sources like Google, Bing, VirusTotal, and more.

Vulnerability Scanning
Vuln Scanner

Nessus

Industry-leading vulnerability scanner. Identifies vulnerabilities, misconfigurations, and compliance issues across systems.

Web App Scanner

OWASP ZAP

Free web application security scanner. Great for finding XSS, SQL injection, and other OWASP Top 10 vulnerabilities.

Web Fuzzer

ffuf

Fast web fuzzer written in Go. Use it for directory and file brute-forcing, parameter fuzzing, and more.

Port Scanner

RustScan

The modern port scanner. Scans all 65,535 ports in under 3 seconds then hands off to Nmap for deeper analysis.

Exploitation
Exploit Framework

Metasploit

The world's most used penetration testing framework. Contains hundreds of exploits, payloads, and auxiliary modules.

SQL Injection

sqlmap

Automatic SQL injection and database takeover tool. Supports MySQL, Oracle, PostgreSQL, MSSQL, and more.

Password Cracking

Hashcat

World's fastest and most advanced password recovery tool. Supports 300+ hash types with GPU acceleration.

Wordlists

SecLists

Collection of multiple types of lists used during security assessments — usernames, passwords, URLs, fuzzing payloads, and more.

Traffic Analysis
Packet Analyzer

Wireshark

The world's foremost network protocol analyzer. Capture and interactively analyze network traffic in real time.

Proxy

Burp Suite

The leading web security testing platform. Intercept, inspect, and modify HTTP/S traffic between browser and server.

CLI Sniffer

tcpdump

Powerful command-line packet analyzer. Lightweight alternative to Wireshark for terminal-based analysis.

Practice Platforms
CTF / Labs

TryHackMe

Beginner-friendly cybersecurity training platform with guided rooms, learning paths, and CTF-style challenges.

CTF / Labs

Hack The Box

Advanced penetration testing labs. Hack real machines in a safe, legal environment and earn rankings.

Web Security

PortSwigger Web Academy

Free, world-class web security training from the makers of Burp Suite. Covers all OWASP Top 10 and beyond.

CTF Archive

picoCTF

Free computer security game targeted at middle and high school students. Great starting point for beginners.

Virtualization & Labs
Hypervisor

Proxmox VE

Open-source server virtualization platform we use for building our own lab infrastructure and server environments.

Pen Test OS

Kali Linux

Debian-based Linux distribution designed for digital forensics and penetration testing. Comes pre-loaded with 600+ tools.

VM Platform

VirtualBox

Free and open-source virtualization software. Run Kali Linux, Windows, or any OS safely inside your main machine.