Red Team Arsenal Tool List
The following is a complete list of Red Team tools (Offensive Security) as posted in my Cyber Security Arsenal Catalog organized in a simple and logical way to make it easier to navigate.
Every Index node will take you the tool section. Every tool will also be linked to another Complete Command Reference post for the given tool, where you can learn how to use it fully.
I hope you enjoy.
Index
Reconnaissance (Passive)
- People, identity & social OSINT
- Domain, DNS & certificate OSINT
- Web, URL & archive discovery
- Code & secrets OSINT
- Frameworks & orchestration
- Internet-wide search & exposure
Reconnaissance (Active)
- Host & port discovery
- Network service & protocol enum
- Web fingerprinting & mapping
- Network attack-surface interaction
- Active DNS / name resolution
Exploitation Frameworks
Payload Generation & Evasion
Post-Exploitation
Reverse Shells
- sh
- bash
- Python
- Perl
- Ruby
- Python
- Netcat
- Java
- xterm
Command & Control (C2)
Social Engineering & Initial Access
Vulnerability Analysis
- Network & infrastructure scanners
- Host / OS audit
- Container & image scanning
- Kubernetes
- SCA / dependency & code analysis
- Exploit & CVE intelligence
Web Application Pentesting
- Intercepting proxies & platforms
- Content discovery & crawling
- Parameter & input discovery
- Injection testing
- SSRF, smuggling & protocol abuse
- Auth, JWT & access control
- API & GraphQL
- CMS scanners
- TLS / HTTPS assessment
- WebDAV & specialized
Wireless Pentesting
Cloud Pentesting
Network Attacks (MITM, sniffing, protocol)
Mobile Pentesting
- Platforms & all-in-one
- Android static analysis
- Android dynamic & instrumentation
- iOS static analysis
- iOS dynamic & instrumentation
- Traffic, API & storage
- Reverse engineering (mobile-focused)
- iOS / Android vuln scanners & checklists
IoT / Embedded Pentesting
- Firmware acquisition & unpacking
- Emulation & dynamic firmware
- Hardware interfaces
- Radio & wireless IoT
- Network Service & Device Enumeration
- Binary RE for embedded
- Protocols & smart-home stacks
- Collections & frameworks
AI / ML Pentesting
- LLM application & prompt attack tooling
- Model red-teaming & safety eval
- Adversarial ML (classical models)
- Privacy / extraction / membership inference
- ML supply chain & artifact security
- Data pipeline & training attacks (lab)
- Inference API & endpoint abuse
- Frameworks & platforms (targets / testbeds)
- Supporting RE / inspection
Reverse Engineering & Binary Analysis
- Disassemblers & decompilers
- Debuggers
- Engines & analysis frameworks
- Android / Java / Dalvik
- .NET
- PE / Windows utilities
- Firmware & embedded
Password Cracking & Credential Access
- Hash identification
- Offline hash cracking
- Online brute-force & spray
- Wordlist generation & mutation
- Network credential capture & relay
- Credential dumping & extraction
Red Team Complete Tool List
Reconnaissance (Passive)
People, identity & social OSINT
- FOCA
- Holehe
- Intelx
- Maigret
- Maltego
- Sherlock
- Social Analyzer
- SpiderFoot
- theHarvester
Domain, DNS & certificate OSINT
- Amass
- Assetfinder
- Chaos (ProjectDiscovery)
- crt.sh workflows
- dig
- DNSDumpster-style sources
- dnsenum
- DNSRecon
- fierce
- Findomain
- host
- SecurityTrails / similar passive DNS (CLI/API use)
- Subfinder
- Sublist3r
- URLCrazy
- Whois
Web, URL & archive discovery
- GAU (GetAllURLs)
- gospider (passive crawl modes)
- hakrawler (passive sources)
- httpx (ProjectDiscovery)
- Photon
- urlfinder
- waymore
- Waybackurls
Code & secrets OSINT
- GitDorker
- GitHub code search workflows
- GitLab / Bitbucket OSINT helpers
- Gitleaks
- Gitrob
- TruffleHog
Frameworks & orchestration
- FinalRecon
- Maltego
- OSINT Framework (reference map)
- Recon-ng
- ReconFTW
- sn0int
- SpiderFoot
- TraceLabs OSINT VM tooling (reference)
Internet-wide search & exposure
- BinaryEdge CLI
- Censys CLI
- FOFA / similar (API clients)
- GreyNoise (passive context)
- Onyphe
- Shodan CLI
- ZoomEye CLI
Reconnaissance (Active)
Host & port discovery
- ARP-Scan
- AutoRecon
- Hping3
- Legion
- Masscan
- Naabu
- Netdiscover
- Nmap
- RustScan
- Unicornscan
- Zenmap
- Zmap
Network service & protocol enum
- Amap
- CrackMapExec / NetExec (discovery)
- enum4linux / enum4linux-ng
- ike-scan
- Kerbrute (user enum)
- ldapsearch / windapsearch
- nbtscan
- onesixtyone
- rpcclient
- RPC / NFS enum helpers
- SMBMap
- snmp-check
- SNMPwalk
- sslscan / testssl (enum mode)
Web fingerprinting & mapping
- Aquatone
- builtwith CLI patterns
- EyeWitness
- GoWitness
- gowitness
- httpx (active probing)
- nmap http-enum / http-headers scripts
- Wafw00f
- Wappalyzer CLI
- webanalyze
- Webscreenshot
- WhatWeb
Network attack-surface interaction
- Bettercap
- llmnr/nbt-ns discovery tooling
- mitm6 (discovery context)
- Responder (poisoning / discovery)
Active DNS / name resolution
- dnsenum (active queries)
- dnsrecon (active brute modes)
- dnsx (ProjectDiscovery)
- fierce (active)
- massdns
- puredns
- shuffledns
Exploitation Frameworks
- Armitage
- AutoSploit
- BeEF
- Canvas (commercial)
- Core Impact (commercial)
- ExploitDB papers
- Metasploit Framework
- RouterScan
- RouterSploit
- SearchSploit
Payload Generation & Evasion
- Amber
- ConfuserEx
- Donut
- Freeze
- Hyperion
- Inceptor
- MSFPC
- MSFvenom
- Nimcrypt2
- PEzor
- PwnTools
- ROPgadget
- ROPper
- ScareCrow
- ScrubCrypt
- Shellter
- sRDI
- Unicorn
- UPX (packing)
- Veil
- SharpShooter
Post-Exploitation
Linux
- Ansible (abusive use)
- busybox (implant abuse)
- Chisel
- CrackMapExec / NetExec (Linux)
- GTFOBins (reference)
- ligolo-ng
- LinEnum
- LinPEAS
- linux-exploit-suggester / linux-exploit-suggester-2
- linux-smart-enumeration (lse)
- Meterpreter (Linux)
- pspy
- pwncat
- socat (pivoting)
- ssh-auditor
- sshuttle
- traitor
- Web shells collections
- Weevely
Windows
- ADCSPwn
- Certify / Certipy
- CrackMapExec modules
- DonPAPI
- Evil-WinRM
- ForgeCert
- GodPotato / SweetPotato / JuicyPotato / DeadPotato
- Impacket suite
- Internal-Monologue
- Inveigh
- KeeThief
- LOLBAS (reference)
- Lsassy
- Mimikatz
- NanoDump
- NetExec / CrackMapExec
- PowerUp / PowerUpSQL
- PowerView
- PrintSpoofer
- PrivExchange
- RDPThief
- Rubeus
- SafetyKatz
- Seatbelt
- SharpDPAPI
- SharpGen
- SharpHound / BloodHound / BloodHound CE
- SharpMove
- SharpRDP
- SharpView
- Watson
- WES-NG
- Whisker
- WinPEAS
macOS
- BlockBlock
- chainbreaker
- JXA tooling
- KnockKnock
- lulu (context)
- macPEAS
- Netiquette
- Orchard
- osascript abuse kits
- ProcessMonitor (Objective-See)
- Pseudoman
- SwiftBelt
Reverse Shells
- sh
- bash
- Python
- Perl
- Ruby
- Python
- Netcat
- Java
- xterm
Command & Control (C2)
- AdaptixC2
- BeEF (browser C2)
- Brute Ratel C4
- Caldera (C2 modes)
- Cobalt Strike
- Covenant
- DeimosC2
- Empire / PowerShell Empire
- Empire 4 / BC-Security Empire
- FactionC2
- Havoc
- Koadic
- Merlin
- Metasploit (handlers / sessions)
- Mythic
- Nighthawk
- Nimplant
- Octopus
- PoshC2
- Prelude Operator
- Pupy
- Quasar
- Shad0w
- SilentTrinity
- Sliver
- Starkiller
- TrevorC2
- Villain
Social Engineering & Initial Access
- BlackEye
- Coremail / phishing frameworks
- CredSniper
- Evilginx2
- Evilginx3
- Evilgophish
- Gophish
- HiddenEye
- King Phisher
- LuckyStrike
- MacroPack
- Modlishka
- O365 Attack Toolkit
- Office macro builders
- Phishery
- prefect / lure kits
- Social-Engineer Toolkit (SET)
- SocialFish
- SprayingToolkit
- Throttler / MFA bypass helpers
- zphisher
Vulnerability Analysis
Network & infrastructure scanners
- Nessus
- Nessus Essentials
- Nikto
- Nmap NSE (vuln scripts)
- Nexpose / InsightVM
- Nuclei
- OpenVAS / Greenbone
- Qualys (scanner family)
- Vulscan (Nmap)
Host / OS audit
- chkrootkit
- CIS-CAT
- Lynis
- OpenSCAP
- rkhunter
- Tiger
Container & image scanning
- Clair
- cosign (verify)
- Docker Scout
- Grype
- Syft
- Trivy
Kubernetes
- kube-bench
- kube-hunter
- kube-score
- kubeaudit
- Kubescape
- Popeye
SCA / dependency & code analysis
- Bandit
- Brakeman
- cargo-audit
- Gosec
- Grype (dir mode)
- npm audit
- OSV-Scanner
- OWASP Dependency-Check
- OWASP Dependency-Track
- pip-audit
- Retire.js
- Semgrep
- Snyk CLI
- SpotBugs
- Trivy FS/repo mode
Exploit & CVE intelligence
- CIRCL CVE search
- CVE Search tooling
- cve-search
- EPSS tooling
- ExploitDB
- NVD feeds
- OSV
- SearchSploit
- Vulners
Web Application Pentesting
Intercepting proxies & platforms
- Burp Suite
- Caido
- Charles Proxy
- Fiddler
- HTTP Toolkit
- mitmproxy
- OWASP ZAP
- Paros
- WATOBO
- WebScarab
Content discovery & crawling
- anew
- Dirb
- DirBuster
- Dirsearch
- Feroxbuster
- ffuf
- gau
- Gobuster
- Gospider
- Hakrawler
- Katana
- meg
- Photon
- qsreplace
- Skipfish
- Uniscan
- uro
- Wapiti
- waybackurls
- Wfuzz
Parameter & input discovery
- Arjun
- Parameth
- Param Miner (Burp)
- ParamSpider
- Querystring miners
- x8
Injection testing
XSS
- BruteXSS
- BXSS
- Dalfox
- DOMInvader (Burp)
- findom-xss
- XSSCon
- XSSer
- XSS Hunter workflows
- XSStrike
SQL
- ghauri
- jSQL
- NoSQLMap (primary under NoSQL)
- SQLiPy (Burp)
- sqlmap
- SQLmap Tamper scripts
- sqlninja
- sqlsus
NoSQL
- CouchDB injection helpers
- MongoBleed-style helpers
- NoSQLMap
- nosql-exploitation-framework
Other injection
- Commix
- CRLFuzz
- expression-language injection helpers
- LDAP injection helpers
- SSI injection checks
- tplmap / SSTIMap
- XPath injection helpers
- XXEinjector
- xxe-workshop tooling
SSRF, smuggling & protocol abuse
- Burp Collaborator
- CRLFuzz
- DotDotPwn
- Gopherus
- h2csmuggler
- HTTP Request Smuggler
- interactsh
- Request Smuggler (Burp)
- Smuggler
- SSRFmap
- Taborator
Auth, JWT & access control
- Auth Analyzer (Burp)
- AuthMatrix (Burp)
- Autorize (Burp)
- Autorepeater
- c-jwt-cracker
- JWT_Tool
- oauth-toolkit helpers
- Session Auth tools
- Turbo Intruder (Burp)
API & GraphQL
- BatchQL
- Clairvoyance
- Dredd
- ffuf (API fuzz mode)
- GraphQL Voyager
- GraphQLmap
- Graphw00f
- graphql-cop
- InQL (Burp)
- Insomnia
- Postman
- REST-Attacker
- Schemathesis
CMS scanners
- a2sv
- CMSeeK
- CMSmap
- CMSScanner
- Droopescan
- JoomlaVS
- JoomScan
- Typo3Scan
- WPForce
- WPScan
TLS / HTTPS assessment
- cipherscan
- Mozilla Observatory
- SSLScan
- SSLyze
- TestSSL.sh
- tls-scan
WebDAV & specialized
- ActiveScan++ (Burp)
- Cadaver
- Davtest
- dumpsterdiver
- GitTools
- git-dumper
- Gitleaks (repo leak in app context)
- JSParser
- LinkFinder
- NikoToGo
- S3Scanner (primary under Cloud → AWS)
- SecretFinder
- TruffleHog (JS/endpoints)
- Upload Scanner (Burp)
Wireless Pentesting
WiFi
- Aircrack-ng suite
- Airgeddon
- airgraph-ng
- Bettercap (WiFi)
- Bully
- Cowpatty
- EAPHammer / eaphammer
- Fern WiFi Cracker
- Fluxion
- hashcat (WPA modes)
- hcxdumptool
- hcxtools
- Hostapd-wpe
- john (WPA modes)
- Kismet
- MDK4
- PixieWPS
- Reaver
- WiFi-Honey
- wifipumpkin3
- Wifiphisher
- Wifite / Wifite2
Bluetooth
- Bettercap BLE tools
- Bluelog
- BlueMaho
- Blueranger
- Bluesnarfer
- Bluetoothctl
- BlueZ tools
- btlejack
- Btscanner
- Crackle
- GATTacker
- Spooftooph
- Ubertooth tools
RFID / NFC / hardware-adjacent
- ChameleonMini
- Flipper Zero companion tooling
- HID tools
- libnfc tools
- mfoc / mfcuk
- nfc-list tools
- Proxmark3 suite
- RFIDIOt
Cloud Pentesting
Multi-cloud assessment
- Cartography
- CloudFox
- CloudGraph
- CloudMapper (inventory modes)
- CloudQuery
- Cloudsplaining
- PolicySentry
- PurplePanda
- Steampipe
Cloud configuration assessment
- aws-security-hub findings export tooling
- cfn-nag
- Checkov
- CloudMapper
- CloudQuery (compliance queries)
- CloudSploit / WaterSecurity
- KICS
- Pacu (assessment modules)
- Prowler
- ScoutSuite
- Steampipe (compliance)
- Terrascan
- tfsec
- Trivy IaC
AWS
- aws-vault
- AWSBucketDump
- barq
- bucket-stream
- CloudBrute
- CloudGoat
- Cloudsplaining
- ConsoleMe
- Endgame
- enumerate-iam
- Inductor
- Pacu
- PolicySentry
- Principal Mapper (pmapper)
- Rhino Security Labs tools
- S3Scanner
- s3cr3t
- Scout2 (legacy)
- SkyArk
- WeirdAAL
Azure / Entra ID / M365
- AADInternals
- Azucar
- Azure CLI enum patterns
- AzureHound
- CrowdStrike Azure reporting scripts
- GraphRunner
- Hawk
- MFASweep
- MicroBurst
- MSOLSpray
- PowerZure
- Prowler (Azure)
- RoadTools / ROADtools
- ScoutSuite (Azure)
- Sparrow
- Stormspotter
- TeamFiltration
GCP
- gcp_enum
- gcp-iam-collector
- GCPBucketBrute
- gcloud security tooling
- G-Scout (legacy)
- Hayat
- Prowler (GCP)
- ScoutSuite (GCP)
Kubernetes
- amicontained
- botb
- CDK (Container Diagnosis Kit)
- deepce
- Helm secrets audit helpers
- kdigger
- kube-bench
- kube-hunter
- kube-pirate
- kubectl-score
- kubectl-who-can
- kubeletctl
- KubiScan
- Peirates
- rakkess
Network Attacks (MITM, sniffing, protocol)
Sniffing & MITM
- Bettercap
- driftnet
- Dsniff suite
- Ettercap
- mitm6
- mitmproxy
- netsniff-ng
- Responder
- Sslstrip
- SSLsplit
- tcpdump
- tshark
- urlsnarf
- Wireshark
Packet & protocol tooling
- hping3
- Netcat / Ncat
- nping
- ostinato
- packETH
- Scapy
- Socat
- VLAN hopping tools
- Yersinia
VoIP
- ace
- enumIAX
- RTPBreak
- SIPCrack
- SIPp
- SIPVicious
- VoipHopper
Mobile Pentesting
Platforms & all-in-one
- MobSF (Mobile Security Framework)
- AppCrawl / automated lab stacks
- Corellium (virtual devices)
- Android Emulator / AVD
- iOS Simulator
- Genymotion
- Frida
- Objection
- Runtime Mobile Security (RMS)
Android static analysis
- APKTool
- JADX / JADX-GUI
- Bytecode Viewer
- dex2jar
- androguard
- apkleaks
- quark-engine
- QARK
- SUPER Android Analyzer
- Mobile Audit
- APKLeaks
- secret-tooling for strings/API keys
Android dynamic & instrumentation
- Frida
- Objection
- House
- r2frida
- Xposed / LSPosed modules (lab)
- Magisk (lab root)
- adb
- scrcpy
- pidcat / logcat workflows
- HTTP Toolkit (mobile)
- mitmproxy / Burp with Android user CA
iOS static analysis
- class-dump / class-dump-z
- otool
- nm / strings
- Hopper
- Ghidra (Mach-O)
- Radare2 / Cutter
- Swift / ObjC demystify helpers
- bagbak / frida-ios-dump
- ipatool / Apple archive tooling
iOS dynamic & instrumentation
- Frida
- Objection
- cycript (legacy)
- lldb
- FLEX
- Grapefruit
- Needle (legacy)
- checkra1n / palera1n (lab jailbreak context)
- mitmproxy / Burp with iOS trust workflows
Traffic, API & storage
- Burp Suite
- OWASP ZAP
- mitmproxy
- HTTP Toolkit
- Proxyman
- Charles Proxy
- Wireshark
- apk-mitm
- ios-ssl-kill-switch style lab tools
- Realm / SQLite browsers
- Frida scripts for Keychain / SharedPreferences
Reverse engineering (mobile-focused)
- Ghidra
- IDA
- Binary Ninja
- Radare2 / rizin / Cutter
- Hopper
- dnSpy (Xamarin/.NET mobile)
- JEB (commercial)
iOS / Android vuln scanners & checklists
- MobSF
- NOWSecure-style workflows (reference)
- OWASP MASVS / MASTG (methodology)
- AppSweep
- ImmuniWeb Mobile (service/reference)
IoT / Embedded Pentesting
Firmware acquisition & unpacking
- Binwalk
- Firmware-Mod-Kit
- FACT (Firmware Analysis and Comparison Tool)
- EMBA
- Firmwalker
- binwalk-ng workflows
- jefferson / jffs2 tools
- ubi_reader
- sasquatch
- yaffshiv
- firmware-analysis-toolkit
Emulation & dynamic firmware
- QEMU
- Firmadyne
- FIRMAE
- arma / avatar2
- Ghidra + QEMU debug stubs
- OpenWrt build VMs (lab targets)
Hardware interfaces
- OpenOCD
- J-Link tools
- Bus Pirate
- Shikra
- ChipWhisperer
- Logic analyzers (PulseView / Sigrok)
- Saleae Logic software
- Tigard
- FTDI / USB-UART tools
- screen / minicom / picocom
- esptool (Espressif)
Radio & wireless IoT
- RTL-SDR tooling
- HackRF / GNU Radio
- Ubertooth
- Bettercap
- Zigbee: KillerBee, zigdiggity, Z3sec
- Z-Wave: Yardstick, RFCat
- BLE: GATTacker, btlejack, Bettercap BLE, nRF Connect
- LoRa / LoRaWAN sniffers
- Flipper Zero companion tooling
- Proxmark3 (RFID/NFC adjacent IoT)
Network Service & Device Enumeration
- Nmap
- Masscan
- RustScan
- SNMP tooling (onesixtyone, snmpwalk)
- UPnP tools (miranda, upnp-exploits helpers)
- MQTT clients / fuzzers (mosquitto, mqtt-pwn)
- CoAP tools
- Routersploit
- IoTSeeker-style scanners
- Shodan / Censys (IoT queries)
Binary RE for embedded
- Ghidra
- IDA
- Binary Ninja
- Radare2 / Cutter
- Binary Analysis tools for MIPS/ARM
- checksec / hardening checks on firmware bins
- busybox audit patterns
Protocols & smart-home stacks
- MQTT.fx / MQTT Explorer
- Wireshark (IoT protocol dissectors)
- Home Assistant lab stacks (targets)
- Zigbee2MQTT (lab)
- OPC-UA test clients (industrial IoT edge)
- Modbus tooling (industrial edge)
Collections & frameworks
- EXPLIoT
- IoTGoat (training target)
- Damn Vulnerable Router / similar labs
- Firmware Analysis Studio-style pipelines
AI / ML Pentesting
LLM application & prompt attack tooling
- Garak
- PyRIT (Microsoft)
- Promptmap
- LLM Guard (test/bypass lab)
- PromptInject-style frameworks
- jailbreak prompt corpora (lab)
- custom eval harnesses (pytest + API clients)
- LangChain / LlamaIndex test agents (as targets)
- OWASP LLM Top 10 checklists (methodology)
Model red-teaming & safety eval
- Hugging Face Evaluate / lmeval-style harnesses
- EleutherAI lm-evaluation-harness
- ART (Adversarial Robustness Toolbox) — relevant modes
- IBM Adversarial Robustness Toolbox
- TextAttack
- OpenAttack
- Counterfit (Microsoft)
- Microsoft Counterfit
- Giskard (ML testing)
- DeepChecks
- WhyLabs / whylogs (drift monitoring in test)
Adversarial ML (classical models)
- Adversarial Robustness Toolbox (ART)
- Foolbox
- CleverHans (legacy/reference)
- Advertorch
- Torchattacks
- Adversarial-Robustness-Toolbox pipelines
- Alibi Detect
Privacy / extraction / membership inference
- TensorFlow Privacy tools
- PrivacyRaven
- ML Privacy Meter
- membership inference reference implementations
- model extraction lab scripts
- shadow-model training notebooks
ML supply chain & artifact security
- ModelScan
- PickleScan
- Safetensors validation workflows
- Hugging Face security scanners
- SBOM for models (CycloneDX ML profiles)
- Trivy / Grype on ML container images
- Sigstore / cosign for model registry signing
- ONNX vulnerability review helpers
Data pipeline & training attacks (lab)
- Data poisoning test frameworks
- Label-flip / backdoor lab notebooks
- BadNets-style reproduction code
- dataset integrity checks (hashing, DVC)
- Great Expectations (data validation)
Inference API & endpoint abuse
- ffuf / custom fuzzers on model APIs
- schema fuzzing (Schemathesis) on ML services
- rate-limit / cost-abuse test scripts
- token/cost metering bypass checks
- vector-DB prompt injection helpers (RAG)
- embedding inversion research tools (lab)
Frameworks & platforms (targets / testbeds)
- Garak
- PyRIT
- NVIDIA Garak integrations
- Azure AI red team guidance tooling
- AWS / GCP model endpoint test clients
- local Ollama / vLLM / LocalAI lab stacks (targets)
- RAG test apps (DVSA-style vulnerable AI apps when available)
Supporting RE / inspection
- Netron (model graph viewer)
- ONNX Runtime tools
- TensorBoard (inspection)
- weights & activations dump scripts
- CUDA/GPU side-channel research tooling (advanced lab)
Reverse Engineering & Binary Analysis
Disassemblers & decompilers
- Binary Ninja
- Cutter
- Ghidra
- Hex-Rays (IDA decompiler)
- Hopper
- IDA Free / IDA Pro
- Radare2
- RetDec
- Rizin
- Snowman
Debuggers
- edb-debugger
- GDB
- GEF
- Immunity Debugger
- LLDB
- OllyDbg
- peda
- pwndbg
- RR (record-replay)
- WinDbg
- x64dbg
Engines & analysis frameworks
- angr
- Binary Analysis Platform (BAP)
- Capstone
- Frida
- Keystone
- Manticore
- Objection
- Qiling
- Symbolic execution helpers
- Triton
- Unicorn Engine
Android / Java / Dalvik
- androguard
- APKTool
- apkleaks
- Bytecode Viewer
- dex2jar
- Frida (mobile)
- house
- JADX
- jd-gui
- MobSF
- Objection
- quark-engine
.NET
- de4dot
- dnSpy
- dnSpyEx
- dotPeek
- Extreme.NET dumpers
- ILSpy
PE / Windows utilities
- CFF Explorer
- Detect It Easy
- exeinfope
- LordPE
- PE-bear
- PEStudio
- ProtectionID
- Resource Hacker
- Stud_PE
Firmware & embedded
- Binwalk
- EMBA
- FACT
- Firmadyne
- Firmware-Mod-Kit
- Firmwalker
- Ghidra firmware loaders
- JTAG/SWD tooling
- OpenOCD
- QEMU
Password Cracking & Credential Access
Hash identification
- haiti
- Hash-Identifier
- hashid
- Name-That-Hash
Offline hash cracking
- Cain-style suites (legacy)
- Hashcat
- HashcatUtils
- John the Ripper
- Johnny
- Maskprocessor
- Ophcrack
- Princeprocessor
Online brute-force & spray
- BruteSpray
- CredMaster
- Crowbar
- DomainPasswordSpray
- Hydra
- Medusa
- MSOLSpray (see also Cloud → Azure)
- Ncrack
- o365spray
- Patator
- Spray360
- SprayHound
- TREVORspray
Wordlist generation & mutation
- CeWL
- COOK
- Crunch
- CUPP
- hashcat rule files
- Kwprocessor
- Mentalist
- Pack
- pydictor
- Rockyou / rockyou202x (wordlists)
- RSMangler
- SecLists
Network credential capture & relay
- Coercer
- Inveigh
- krbrelayx
- mitm6
- MultiRelay
- NTLMRelayX (Impacket)
- PetitPotam
- PrinterBug helpers
- Responder
Credential dumping & extraction
- DonPAPI
- DPAPI tools
- hashdump tooling
- Keepass attack tooling
- LaZagne
- lsassy
- mimipenguin
- Nanodump
- procdump (abuse)
- pypykatz
- SecretsDump
- SharpChromium
- SharpWeb