Aircrack-ng
Suite for cracking Wi-Fi passwords and analyzing 802.11 wireless traffic.
Android Debug Bridge (ADB)
Command-line tool to interact with and debug Android devices.
Atomic Red Team
Library of adversary simulation tests mapped to MITRE ATT&CK.
BeEF (Browser Exploitation Framework)
Tool for client-side attacks via web browsers.
BloodHound
Graph-based tool for analyzing Active Directory trust relationships.
Bluestrike
Framework for assessing Bluetooth vulnerabilities and attacks.
Burp Suite
Web vulnerability scanner and proxy for testing web apps.
Caldera
Automated adversary emulation platform from MITRE.
Certify
Tool for attacking and abusing Active Directory Certificate Services (AD CS).
Cloud-native vendor tools
Security assessment utilities built into cloud providers (e.g., AWS CLI, Azure Security Center).
CrackMapExec (CME)
Swiss army knife for pentesting Active Directory and SMB environments.
DirBuster / Gobuster
Tools for brute-forcing directories/files on web servers.
Docker Bench
Security scanner for Docker container configurations.
Drozer
Android security testing framework for assessing mobile applications.
Evil-WinRM
Remote management tool for exploiting and administering Windows systems.
Evilginx
Reverse proxy tool for phishing and man-in-the-middle attacks against authentication flows.
Gophish
Phishing framework for creating and running phishing campaigns.
hashcat
Advanced GPU-based password cracking tool.
Hydra
Fast brute-force login cracker for multiple protocols.
Impacket
Python library for crafting and executing network protocols (often used for AD attacks).
Infection Monkey
Breach and attack simulation (BAS) tool to test lateral movement.
InSSIDer
Wi-Fi scanner for analyzing wireless signals and networks.
John the Ripper
Popular open-source password cracking tool.
Kismet
Wireless network detector and packet sniffer.