The Armory

The tools I actually reach for on a test, grouped by what they’re for, with honest notes on where each one shines and where it falls down.

Web

Burp Suite

The proxy most web testing runs through.

ffuf

Fast web fuzzer for content and parameter discovery.

wpscan

WordPress-focused scanner.

nuclei

Template-driven scanner with a huge community library.

Recon & Enumeration

Nmap

Port and service discovery. Usually the first thing a test runs.

enum4linux

SMB enumeration of Windows/Samba hosts.

sslscan

Checks a server’s SSL/TLS configuration.

Active Directory

BloodHound

Maps AD attack paths to high-value targets.

NetExec (nxc)

Sweep networks to check creds and run actions at scale.

Responder

Captures hashes by answering LLMNR/NBT-NS.

Impacket

A swiss-army toolkit for AD and network protocols.

Rubeus

A Kerberos toolkit for ticket abuse.

PowerView

PowerShell recon for Active Directory.

Wireless

airgeddon

A menu-driven wrapper for wifi auditing.

wifite

Automates attacking nearby wifi networks.

Cracking

hashcat / John

Offline password crackers. Each has its strengths.

Scanning

Nessus

Commercial vulnerability scanner.

Frameworks & LOLBins

Metasploit

Exploitation framework. I reach for it rarely.

GTFOBins / LOLBins

Reference lists for living off the land.