Accunetix
An automated web application security testing tool
Amass
LinuxTool for Subdomain enumeration
Aquatone
RubyA set of tools for performing reconnaissance on domain names
Bettercap
goTool used for MITM attacks
Binwalk
PythonFirmware Analysis Tool
Brutexss
windows/linuxCross-Site Scripting Bruteforcer.
Builtwith
Find out what a website is built with
CMSmap
PythonCMS vulnerability scanner
Cain&abel
WindowsA password recovery tool for Microsoft Operating Systems
Cewl
rubyCustom wordlist generator
CloudFlair
PythonCloudFlair is a tool to find origin servers of websites protected by CloudFlare
Commix
Pythoncommand-injection detection exploitation pentesting vulnerability-scanner
Crunch
LinuxA wordlist generator
DOMxsscanner
PythonTool for finding potential DOM based XSS
Dirb
LinuxA command line based tool to brute force directories
Dirbuster
JavaApplication designed to brute force directories
Dirsearch
windows/linuxA command line tool designed to brute force directories
Dnscan
PythonA wordlist-based DNS subdomain scanner
Dnsdumpster
Website to find and lookup DNS records
Enumall
PythonScript to enumerate subdomains
Ettercap
linuxTool for man-in-the-middle attacks on LAN
ExifTool
Perlsoftware program for reading, writing, and manipulating image, audio, video, and PDF metadata
Eyewitness
PythonA tool used to capture screenshots
Fcrackzip
LinuxTool to crack zip passwords
Fern wifi cracker
LinuxCracking WiFi Password
Fiddler
WindowsA Web Debugging Proxy
Findsploit
windows/linuxFind Exploits In Local And Online Databases
Fuxploider
PythonFile Upload Vulnerability Scanner And Exploitation Tool
Genymotion
apk toolCross-platform Android emulator for developers & QA engineers
GoogD0rker
Pythongoogle dorks for a domain
Hashcat
LinuxPassword cracker
Httpscreenshot
PythonA tool for grabbing screenshots and HTML of websites
Joomscan
perlJoomla vulnerability scanner
Knockpy
PythonA python tool to enumerate subdomains
LFISuit
PythonTool able to scan and exploit Local File Inclusion
Maltego
Pythonopen-source intelligence and forensics tool
Masscan
Cvery fast network and port scanner like nmap
Massdns
PythonTool used to resolve lots of subdomains quickly
Mimikatz
WindowsA post-exploitation tool for windows
Mobsf
apk toolAll-in-one mobile application (Android/iOS/Windows) pen-testing framework
Nessus
RubyA vulnerability scanner
Nikto
PerlA Web server scanner
Nmap
CFree and open-source network scanner
Ophcrack
LinuxTool to crack passwords for windows login
Owasp zed
Windowsopen-source web application security scanner.
Parameth
PythonTool to brute discover GET and POST parameters
SQLmap
windows/linuxA software that is used to detect and exploit database vulnerabilities
Seclists
Collection of Wordlists
Shodan
search engine for Internet-connected devices
Sslcan
Windows/LinuxScan SSL services
Sublist3r
PythonTool designed to enumerate subdomains of websites
THC hydra
windows/linuxA brute force password cracking tool.
The harvester
PythonA tool for gathering e-mail accounts and subdomain names from public sources
Threatexpert
WindowsUpload any file to the servers of the program and they''ll tell you if the file is infected or not
Unicornscan
Linuxinformation gathering tool
Virustotal
free service that analyzes files and URLs for viruses, worms, trojans
WAFW00F
PythonIdentify and fingerprint Web Application Firewall products
Wappalyzer
Uncovers the technologies used on websites
Wayback Machine
A digital archive of the World Wide Web
Wfuzz
windows/linuxTool designed for bruteforcing Web Applications
Wifite
PythonTo attack multiple WEP, WPA, and WPS encrypted networks in a row.
Wireshark
windows/linuxopen-source packet analyzer.
Wpscan
ruby/curlWordPress vulnerability scanner
Wpsploit
LinuxTool to pentest wordpress plugins
XSS hunter
To find all kinds of cross-site scripting vulnerabilities
XSStrike
pythonTool to test websites for XSS vulnerabilities
Zenmap
Windows/linuxA GUI for nmap
Zoomeye
Search Engine for Cyberspace
fluxion
PythonTool for MITM WPA attacks
git-all-secrets
A tool used to find git secrets
john the ripper
Linux/WindowsA free password cracking software tool
social engineering toolkit
PythonAn open-source Python-driven tool aimed at penetration testing around Social-Engineering
waybackrobots
PythonFetch urls of webarchive
waybackurls
PythonFetch all the URLs that the Wayback Machine