◄ BACKDOCRED TEAM ARSENAL TOOL LIST

Red Team Arsenal Tool List

The following is a complete list of Red Team tools (Offensive Security) as posted in my Cyber Security Arsenal Catalog organized in a simple and logical way to make it easier to navigate.

Every Index node will take you the tool section. Every tool will also be linked to another Complete Command Reference post for the given tool, where you can learn how to use it fully.

I hope you enjoy.

Index

Reconnaissance (Passive)

Reconnaissance (Active)

Exploitation Frameworks

Payload Generation & Evasion

Post-Exploitation

Reverse Shells

  • sh
  • bash
  • Python
  • Perl
  • Ruby
  • Python
  • Netcat
  • Java
  • xterm

Command & Control (C2)

Social Engineering & Initial Access

Vulnerability Analysis

Web Application Pentesting

Wireless Pentesting

Cloud Pentesting

Network Attacks (MITM, sniffing, protocol)

Mobile Pentesting

IoT / Embedded Pentesting

AI / ML Pentesting

Reverse Engineering & Binary Analysis

Password Cracking & Credential Access


Red Team Complete Tool List

Reconnaissance (Passive)

People, identity & social OSINT

  • FOCA
  • Holehe
  • Intelx
  • Maigret
  • Maltego
  • Sherlock
  • Social Analyzer
  • SpiderFoot
  • theHarvester

Domain, DNS & certificate OSINT

  • Amass
  • Assetfinder
  • Chaos (ProjectDiscovery)
  • crt.sh workflows
  • dig
  • DNSDumpster-style sources
  • dnsenum
  • DNSRecon
  • fierce
  • Findomain
  • host
  • SecurityTrails / similar passive DNS (CLI/API use)
  • Subfinder
  • Sublist3r
  • URLCrazy
  • Whois

Web, URL & archive discovery

  • GAU (GetAllURLs)
  • gospider (passive crawl modes)
  • hakrawler (passive sources)
  • httpx (ProjectDiscovery)
  • Photon
  • urlfinder
  • waymore
  • Waybackurls

Code & secrets OSINT

  • GitDorker
  • GitHub code search workflows
  • GitLab / Bitbucket OSINT helpers
  • Gitleaks
  • Gitrob
  • TruffleHog

Frameworks & orchestration

  • FinalRecon
  • Maltego
  • OSINT Framework (reference map)
  • Recon-ng
  • ReconFTW
  • sn0int
  • SpiderFoot
  • TraceLabs OSINT VM tooling (reference)

Internet-wide search & exposure

  • BinaryEdge CLI
  • Censys CLI
  • FOFA / similar (API clients)
  • GreyNoise (passive context)
  • Onyphe
  • Shodan CLI
  • ZoomEye CLI

Reconnaissance (Active)

Host & port discovery

  • ARP-Scan
  • AutoRecon
  • Hping3
  • Legion
  • Masscan
  • Naabu
  • Netdiscover
  • Nmap
  • RustScan
  • Unicornscan
  • Zenmap
  • Zmap

Network service & protocol enum

  • Amap
  • CrackMapExec / NetExec (discovery)
  • enum4linux / enum4linux-ng
  • ike-scan
  • Kerbrute (user enum)
  • ldapsearch / windapsearch
  • nbtscan
  • onesixtyone
  • rpcclient
  • RPC / NFS enum helpers
  • SMBMap
  • snmp-check
  • SNMPwalk
  • sslscan / testssl (enum mode)

Web fingerprinting & mapping

  • Aquatone
  • builtwith CLI patterns
  • EyeWitness
  • GoWitness
  • gowitness
  • httpx (active probing)
  • nmap http-enum / http-headers scripts
  • Wafw00f
  • Wappalyzer CLI
  • webanalyze
  • Webscreenshot
  • WhatWeb

Network attack-surface interaction

  • Bettercap
  • llmnr/nbt-ns discovery tooling
  • mitm6 (discovery context)
  • Responder (poisoning / discovery)

Active DNS / name resolution

  • dnsenum (active queries)
  • dnsrecon (active brute modes)
  • dnsx (ProjectDiscovery)
  • fierce (active)
  • massdns
  • puredns
  • shuffledns

Exploitation Frameworks

  • Armitage
  • AutoSploit
  • BeEF
  • Canvas (commercial)
  • Core Impact (commercial)
  • ExploitDB papers
  • Metasploit Framework
  • RouterScan
  • RouterSploit
  • SearchSploit

Payload Generation & Evasion

  • Amber
  • ConfuserEx
  • Donut
  • Freeze
  • Hyperion
  • Inceptor
  • MSFPC
  • MSFvenom
  • Nimcrypt2
  • PEzor
  • PwnTools
  • ROPgadget
  • ROPper
  • ScareCrow
  • ScrubCrypt
  • Shellter
  • sRDI
  • Unicorn
  • UPX (packing)
  • Veil
  • SharpShooter

Post-Exploitation

Linux

  • Ansible (abusive use)
  • busybox (implant abuse)
  • Chisel
  • CrackMapExec / NetExec (Linux)
  • GTFOBins (reference)
  • ligolo-ng
  • LinEnum
  • LinPEAS
  • linux-exploit-suggester / linux-exploit-suggester-2
  • linux-smart-enumeration (lse)
  • Meterpreter (Linux)
  • pspy
  • pwncat
  • socat (pivoting)
  • ssh-auditor
  • sshuttle
  • traitor
  • Web shells collections
  • Weevely

Windows

  • ADCSPwn
  • Certify / Certipy
  • CrackMapExec modules
  • DonPAPI
  • Evil-WinRM
  • ForgeCert
  • GodPotato / SweetPotato / JuicyPotato / DeadPotato
  • Impacket suite
  • Internal-Monologue
  • Inveigh
  • KeeThief
  • LOLBAS (reference)
  • Lsassy
  • Mimikatz
  • NanoDump
  • NetExec / CrackMapExec
  • PowerUp / PowerUpSQL
  • PowerView
  • PrintSpoofer
  • PrivExchange
  • RDPThief
  • Rubeus
  • SafetyKatz
  • Seatbelt
  • SharpDPAPI
  • SharpGen
  • SharpHound / BloodHound / BloodHound CE
  • SharpMove
  • SharpRDP
  • SharpView
  • Watson
  • WES-NG
  • Whisker
  • WinPEAS

macOS

  • BlockBlock
  • chainbreaker
  • JXA tooling
  • KnockKnock
  • lulu (context)
  • macPEAS
  • Netiquette
  • Orchard
  • osascript abuse kits
  • ProcessMonitor (Objective-See)
  • Pseudoman
  • SwiftBelt

Reverse Shells

  • sh
  • bash
  • Python
  • Perl
  • Ruby
  • Python
  • Netcat
  • Java
  • xterm

Command & Control (C2)

  • AdaptixC2
  • BeEF (browser C2)
  • Brute Ratel C4
  • Caldera (C2 modes)
  • Cobalt Strike
  • Covenant
  • DeimosC2
  • Empire / PowerShell Empire
  • Empire 4 / BC-Security Empire
  • FactionC2
  • Havoc
  • Koadic
  • Merlin
  • Metasploit (handlers / sessions)
  • Mythic
  • Nighthawk
  • Nimplant
  • Octopus
  • PoshC2
  • Prelude Operator
  • Pupy
  • Quasar
  • Shad0w
  • SilentTrinity
  • Sliver
  • Starkiller
  • TrevorC2
  • Villain

Social Engineering & Initial Access

  • BlackEye
  • Coremail / phishing frameworks
  • CredSniper
  • Evilginx2
  • Evilginx3
  • Evilgophish
  • Gophish
  • HiddenEye
  • King Phisher
  • LuckyStrike
  • MacroPack
  • Modlishka
  • O365 Attack Toolkit
  • Office macro builders
  • Phishery
  • prefect / lure kits
  • Social-Engineer Toolkit (SET)
  • SocialFish
  • SprayingToolkit
  • Throttler / MFA bypass helpers
  • zphisher

Vulnerability Analysis

Network & infrastructure scanners

  • Nessus
  • Nessus Essentials
  • Nikto
  • Nmap NSE (vuln scripts)
  • Nexpose / InsightVM
  • Nuclei
  • OpenVAS / Greenbone
  • Qualys (scanner family)
  • Vulscan (Nmap)

Host / OS audit

  • chkrootkit
  • CIS-CAT
  • Lynis
  • OpenSCAP
  • rkhunter
  • Tiger

Container & image scanning

  • Clair
  • cosign (verify)
  • Docker Scout
  • Grype
  • Syft
  • Trivy

Kubernetes

  • kube-bench
  • kube-hunter
  • kube-score
  • kubeaudit
  • Kubescape
  • Popeye

SCA / dependency & code analysis

  • Bandit
  • Brakeman
  • cargo-audit
  • Gosec
  • Grype (dir mode)
  • npm audit
  • OSV-Scanner
  • OWASP Dependency-Check
  • OWASP Dependency-Track
  • pip-audit
  • Retire.js
  • Semgrep
  • Snyk CLI
  • SpotBugs
  • Trivy FS/repo mode

Exploit & CVE intelligence

  • CIRCL CVE search
  • CVE Search tooling
  • cve-search
  • EPSS tooling
  • ExploitDB
  • NVD feeds
  • OSV
  • SearchSploit
  • Vulners

Web Application Pentesting

Intercepting proxies & platforms

  • Burp Suite
  • Caido
  • Charles Proxy
  • Fiddler
  • HTTP Toolkit
  • mitmproxy
  • OWASP ZAP
  • Paros
  • WATOBO
  • WebScarab

Content discovery & crawling

  • anew
  • Dirb
  • DirBuster
  • Dirsearch
  • Feroxbuster
  • ffuf
  • gau
  • Gobuster
  • Gospider
  • Hakrawler
  • Katana
  • meg
  • Photon
  • qsreplace
  • Skipfish
  • Uniscan
  • uro
  • Wapiti
  • waybackurls
  • Wfuzz

Parameter & input discovery

  • Arjun
  • Parameth
  • Param Miner (Burp)
  • ParamSpider
  • Querystring miners
  • x8

Injection testing

XSS

  • BruteXSS
  • BXSS
  • Dalfox
  • DOMInvader (Burp)
  • findom-xss
  • XSSCon
  • XSSer
  • XSS Hunter workflows
  • XSStrike

SQL

  • ghauri
  • jSQL
  • NoSQLMap (primary under NoSQL)
  • SQLiPy (Burp)
  • sqlmap
  • SQLmap Tamper scripts
  • sqlninja
  • sqlsus

NoSQL

  • CouchDB injection helpers
  • MongoBleed-style helpers
  • NoSQLMap
  • nosql-exploitation-framework

Other injection

  • Commix
  • CRLFuzz
  • expression-language injection helpers
  • LDAP injection helpers
  • SSI injection checks
  • tplmap / SSTIMap
  • XPath injection helpers
  • XXEinjector
  • xxe-workshop tooling

SSRF, smuggling & protocol abuse

  • Burp Collaborator
  • CRLFuzz
  • DotDotPwn
  • Gopherus
  • h2csmuggler
  • HTTP Request Smuggler
  • interactsh
  • Request Smuggler (Burp)
  • Smuggler
  • SSRFmap
  • Taborator

Auth, JWT & access control

  • Auth Analyzer (Burp)
  • AuthMatrix (Burp)
  • Autorize (Burp)
  • Autorepeater
  • c-jwt-cracker
  • JWT_Tool
  • oauth-toolkit helpers
  • Session Auth tools
  • Turbo Intruder (Burp)

API & GraphQL

  • BatchQL
  • Clairvoyance
  • Dredd
  • ffuf (API fuzz mode)
  • GraphQL Voyager
  • GraphQLmap
  • Graphw00f
  • graphql-cop
  • InQL (Burp)
  • Insomnia
  • Postman
  • REST-Attacker
  • Schemathesis

CMS scanners

  • a2sv
  • CMSeeK
  • CMSmap
  • CMSScanner
  • Droopescan
  • JoomlaVS
  • JoomScan
  • Typo3Scan
  • WPForce
  • WPScan

TLS / HTTPS assessment

  • cipherscan
  • Mozilla Observatory
  • SSLScan
  • SSLyze
  • TestSSL.sh
  • tls-scan

WebDAV & specialized

  • ActiveScan++ (Burp)
  • Cadaver
  • Davtest
  • dumpsterdiver
  • GitTools
  • git-dumper
  • Gitleaks (repo leak in app context)
  • JSParser
  • LinkFinder
  • NikoToGo
  • S3Scanner (primary under Cloud → AWS)
  • SecretFinder
  • TruffleHog (JS/endpoints)
  • Upload Scanner (Burp)

Wireless Pentesting

WiFi

  • Aircrack-ng suite
  • Airgeddon
  • airgraph-ng
  • Bettercap (WiFi)
  • Bully
  • Cowpatty
  • EAPHammer / eaphammer
  • Fern WiFi Cracker
  • Fluxion
  • hashcat (WPA modes)
  • hcxdumptool
  • hcxtools
  • Hostapd-wpe
  • john (WPA modes)
  • Kismet
  • MDK4
  • PixieWPS
  • Reaver
  • WiFi-Honey
  • wifipumpkin3
  • Wifiphisher
  • Wifite / Wifite2

Bluetooth

  • Bettercap BLE tools
  • Bluelog
  • BlueMaho
  • Blueranger
  • Bluesnarfer
  • Bluetoothctl
  • BlueZ tools
  • btlejack
  • Btscanner
  • Crackle
  • GATTacker
  • Spooftooph
  • Ubertooth tools

RFID / NFC / hardware-adjacent

  • ChameleonMini
  • Flipper Zero companion tooling
  • HID tools
  • libnfc tools
  • mfoc / mfcuk
  • nfc-list tools
  • Proxmark3 suite
  • RFIDIOt

Cloud Pentesting

Multi-cloud assessment

  • Cartography
  • CloudFox
  • CloudGraph
  • CloudMapper (inventory modes)
  • CloudQuery
  • Cloudsplaining
  • PolicySentry
  • PurplePanda
  • Steampipe

Cloud configuration assessment

  • aws-security-hub findings export tooling
  • cfn-nag
  • Checkov
  • CloudMapper
  • CloudQuery (compliance queries)
  • CloudSploit / WaterSecurity
  • KICS
  • Pacu (assessment modules)
  • Prowler
  • ScoutSuite
  • Steampipe (compliance)
  • Terrascan
  • tfsec
  • Trivy IaC

AWS

  • aws-vault
  • AWSBucketDump
  • barq
  • bucket-stream
  • CloudBrute
  • CloudGoat
  • Cloudsplaining
  • ConsoleMe
  • Endgame
  • enumerate-iam
  • Inductor
  • Pacu
  • PolicySentry
  • Principal Mapper (pmapper)
  • Rhino Security Labs tools
  • S3Scanner
  • s3cr3t
  • Scout2 (legacy)
  • SkyArk
  • WeirdAAL

Azure / Entra ID / M365

  • AADInternals
  • Azucar
  • Azure CLI enum patterns
  • AzureHound
  • CrowdStrike Azure reporting scripts
  • GraphRunner
  • Hawk
  • MFASweep
  • MicroBurst
  • MSOLSpray
  • PowerZure
  • Prowler (Azure)
  • RoadTools / ROADtools
  • ScoutSuite (Azure)
  • Sparrow
  • Stormspotter
  • TeamFiltration

GCP

  • gcp_enum
  • gcp-iam-collector
  • GCPBucketBrute
  • gcloud security tooling
  • G-Scout (legacy)
  • Hayat
  • Prowler (GCP)
  • ScoutSuite (GCP)

Kubernetes

  • amicontained
  • botb
  • CDK (Container Diagnosis Kit)
  • deepce
  • Helm secrets audit helpers
  • kdigger
  • kube-bench
  • kube-hunter
  • kube-pirate
  • kubectl-score
  • kubectl-who-can
  • kubeletctl
  • KubiScan
  • Peirates
  • rakkess

Network Attacks (MITM, sniffing, protocol)

Sniffing & MITM

  • Bettercap
  • driftnet
  • Dsniff suite
  • Ettercap
  • mitm6
  • mitmproxy
  • netsniff-ng
  • Responder
  • Sslstrip
  • SSLsplit
  • tcpdump
  • tshark
  • urlsnarf
  • Wireshark

Packet & protocol tooling

  • hping3
  • Netcat / Ncat
  • nping
  • ostinato
  • packETH
  • Scapy
  • Socat
  • VLAN hopping tools
  • Yersinia

VoIP

  • ace
  • enumIAX
  • RTPBreak
  • SIPCrack
  • SIPp
  • SIPVicious
  • VoipHopper

Mobile Pentesting

Platforms & all-in-one

  • MobSF (Mobile Security Framework)
  • AppCrawl / automated lab stacks
  • Corellium (virtual devices)
  • Android Emulator / AVD
  • iOS Simulator
  • Genymotion
  • Frida
  • Objection
  • Runtime Mobile Security (RMS)

Android static analysis

  • APKTool
  • JADX / JADX-GUI
  • Bytecode Viewer
  • dex2jar
  • androguard
  • apkleaks
  • quark-engine
  • QARK
  • SUPER Android Analyzer
  • Mobile Audit
  • APKLeaks
  • secret-tooling for strings/API keys

Android dynamic & instrumentation

  • Frida
  • Objection
  • House
  • r2frida
  • Xposed / LSPosed modules (lab)
  • Magisk (lab root)
  • adb
  • scrcpy
  • pidcat / logcat workflows
  • HTTP Toolkit (mobile)
  • mitmproxy / Burp with Android user CA

iOS static analysis

  • class-dump / class-dump-z
  • otool
  • nm / strings
  • Hopper
  • Ghidra (Mach-O)
  • Radare2 / Cutter
  • Swift / ObjC demystify helpers
  • bagbak / frida-ios-dump
  • ipatool / Apple archive tooling

iOS dynamic & instrumentation

  • Frida
  • Objection
  • cycript (legacy)
  • lldb
  • FLEX
  • Grapefruit
  • Needle (legacy)
  • checkra1n / palera1n (lab jailbreak context)
  • mitmproxy / Burp with iOS trust workflows

Traffic, API & storage

  • Burp Suite
  • OWASP ZAP
  • mitmproxy
  • HTTP Toolkit
  • Proxyman
  • Charles Proxy
  • Wireshark
  • apk-mitm
  • ios-ssl-kill-switch style lab tools
  • Realm / SQLite browsers
  • Frida scripts for Keychain / SharedPreferences

Reverse engineering (mobile-focused)

  • Ghidra
  • IDA
  • Binary Ninja
  • Radare2 / rizin / Cutter
  • Hopper
  • dnSpy (Xamarin/.NET mobile)
  • JEB (commercial)

iOS / Android vuln scanners & checklists

  • MobSF
  • NOWSecure-style workflows (reference)
  • OWASP MASVS / MASTG (methodology)
  • AppSweep
  • ImmuniWeb Mobile (service/reference)

IoT / Embedded Pentesting

Firmware acquisition & unpacking

  • Binwalk
  • Firmware-Mod-Kit
  • FACT (Firmware Analysis and Comparison Tool)
  • EMBA
  • Firmwalker
  • binwalk-ng workflows
  • jefferson / jffs2 tools
  • ubi_reader
  • sasquatch
  • yaffshiv
  • firmware-analysis-toolkit

Emulation & dynamic firmware

  • QEMU
  • Firmadyne
  • FIRMAE
  • arma / avatar2
  • Ghidra + QEMU debug stubs
  • OpenWrt build VMs (lab targets)

Hardware interfaces

  • OpenOCD
  • J-Link tools
  • Bus Pirate
  • Shikra
  • ChipWhisperer
  • Logic analyzers (PulseView / Sigrok)
  • Saleae Logic software
  • Tigard
  • FTDI / USB-UART tools
  • screen / minicom / picocom
  • esptool (Espressif)

Radio & wireless IoT

  • RTL-SDR tooling
  • HackRF / GNU Radio
  • Ubertooth
  • Bettercap
  • Zigbee: KillerBee, zigdiggity, Z3sec
  • Z-Wave: Yardstick, RFCat
  • BLE: GATTacker, btlejack, Bettercap BLE, nRF Connect
  • LoRa / LoRaWAN sniffers
  • Flipper Zero companion tooling
  • Proxmark3 (RFID/NFC adjacent IoT)

Network Service & Device Enumeration

  • Nmap
  • Masscan
  • RustScan
  • SNMP tooling (onesixtyone, snmpwalk)
  • UPnP tools (miranda, upnp-exploits helpers)
  • MQTT clients / fuzzers (mosquitto, mqtt-pwn)
  • CoAP tools
  • Routersploit
  • IoTSeeker-style scanners
  • Shodan / Censys (IoT queries)

Binary RE for embedded

  • Ghidra
  • IDA
  • Binary Ninja
  • Radare2 / Cutter
  • Binary Analysis tools for MIPS/ARM
  • checksec / hardening checks on firmware bins
  • busybox audit patterns

Protocols & smart-home stacks

  • MQTT.fx / MQTT Explorer
  • Wireshark (IoT protocol dissectors)
  • Home Assistant lab stacks (targets)
  • Zigbee2MQTT (lab)
  • OPC-UA test clients (industrial IoT edge)
  • Modbus tooling (industrial edge)

Collections & frameworks

  • EXPLIoT
  • IoTGoat (training target)
  • Damn Vulnerable Router / similar labs
  • Firmware Analysis Studio-style pipelines

AI / ML Pentesting

LLM application & prompt attack tooling

  • Garak
  • PyRIT (Microsoft)
  • Promptmap
  • LLM Guard (test/bypass lab)
  • PromptInject-style frameworks
  • jailbreak prompt corpora (lab)
  • custom eval harnesses (pytest + API clients)
  • LangChain / LlamaIndex test agents (as targets)
  • OWASP LLM Top 10 checklists (methodology)

Model red-teaming & safety eval

  • Hugging Face Evaluate / lmeval-style harnesses
  • EleutherAI lm-evaluation-harness
  • ART (Adversarial Robustness Toolbox) — relevant modes
  • IBM Adversarial Robustness Toolbox
  • TextAttack
  • OpenAttack
  • Counterfit (Microsoft)
  • Microsoft Counterfit
  • Giskard (ML testing)
  • DeepChecks
  • WhyLabs / whylogs (drift monitoring in test)

Adversarial ML (classical models)

  • Adversarial Robustness Toolbox (ART)
  • Foolbox
  • CleverHans (legacy/reference)
  • Advertorch
  • Torchattacks
  • Adversarial-Robustness-Toolbox pipelines
  • Alibi Detect

Privacy / extraction / membership inference

  • TensorFlow Privacy tools
  • PrivacyRaven
  • ML Privacy Meter
  • membership inference reference implementations
  • model extraction lab scripts
  • shadow-model training notebooks

ML supply chain & artifact security

  • ModelScan
  • PickleScan
  • Safetensors validation workflows
  • Hugging Face security scanners
  • SBOM for models (CycloneDX ML profiles)
  • Trivy / Grype on ML container images
  • Sigstore / cosign for model registry signing
  • ONNX vulnerability review helpers

Data pipeline & training attacks (lab)

  • Data poisoning test frameworks
  • Label-flip / backdoor lab notebooks
  • BadNets-style reproduction code
  • dataset integrity checks (hashing, DVC)
  • Great Expectations (data validation)

Inference API & endpoint abuse

  • ffuf / custom fuzzers on model APIs
  • schema fuzzing (Schemathesis) on ML services
  • rate-limit / cost-abuse test scripts
  • token/cost metering bypass checks
  • vector-DB prompt injection helpers (RAG)
  • embedding inversion research tools (lab)

Frameworks & platforms (targets / testbeds)

  • Garak
  • PyRIT
  • NVIDIA Garak integrations
  • Azure AI red team guidance tooling
  • AWS / GCP model endpoint test clients
  • local Ollama / vLLM / LocalAI lab stacks (targets)
  • RAG test apps (DVSA-style vulnerable AI apps when available)

Supporting RE / inspection

  • Netron (model graph viewer)
  • ONNX Runtime tools
  • TensorBoard (inspection)
  • weights & activations dump scripts
  • CUDA/GPU side-channel research tooling (advanced lab)

Reverse Engineering & Binary Analysis

Disassemblers & decompilers

  • Binary Ninja
  • Cutter
  • Ghidra
  • Hex-Rays (IDA decompiler)
  • Hopper
  • IDA Free / IDA Pro
  • Radare2
  • RetDec
  • Rizin
  • Snowman

Debuggers

  • edb-debugger
  • GDB
  • GEF
  • Immunity Debugger
  • LLDB
  • OllyDbg
  • peda
  • pwndbg
  • RR (record-replay)
  • WinDbg
  • x64dbg

Engines & analysis frameworks

  • angr
  • Binary Analysis Platform (BAP)
  • Capstone
  • Frida
  • Keystone
  • Manticore
  • Objection
  • Qiling
  • Symbolic execution helpers
  • Triton
  • Unicorn Engine

Android / Java / Dalvik

  • androguard
  • APKTool
  • apkleaks
  • Bytecode Viewer
  • dex2jar
  • Frida (mobile)
  • house
  • JADX
  • jd-gui
  • MobSF
  • Objection
  • quark-engine

.NET

  • de4dot
  • dnSpy
  • dnSpyEx
  • dotPeek
  • Extreme.NET dumpers
  • ILSpy

PE / Windows utilities

  • CFF Explorer
  • Detect It Easy
  • exeinfope
  • LordPE
  • PE-bear
  • PEStudio
  • ProtectionID
  • Resource Hacker
  • Stud_PE

Firmware & embedded

  • Binwalk
  • EMBA
  • FACT
  • Firmadyne
  • Firmware-Mod-Kit
  • Firmwalker
  • Ghidra firmware loaders
  • JTAG/SWD tooling
  • OpenOCD
  • QEMU

Password Cracking & Credential Access

Hash identification

  • haiti
  • Hash-Identifier
  • hashid
  • Name-That-Hash

Offline hash cracking

  • Cain-style suites (legacy)
  • Hashcat
  • HashcatUtils
  • John the Ripper
  • Johnny
  • Maskprocessor
  • Ophcrack
  • Princeprocessor

Online brute-force & spray

  • BruteSpray
  • CredMaster
  • Crowbar
  • DomainPasswordSpray
  • Hydra
  • Medusa
  • MSOLSpray (see also Cloud → Azure)
  • Ncrack
  • o365spray
  • Patator
  • Spray360
  • SprayHound
  • TREVORspray

Wordlist generation & mutation

  • CeWL
  • COOK
  • Crunch
  • CUPP
  • hashcat rule files
  • Kwprocessor
  • Mentalist
  • Pack
  • pydictor
  • Rockyou / rockyou202x (wordlists)
  • RSMangler
  • SecLists

Network credential capture & relay

  • Coercer
  • Inveigh
  • krbrelayx
  • mitm6
  • MultiRelay
  • NTLMRelayX (Impacket)
  • PetitPotam
  • PrinterBug helpers
  • Responder

Credential dumping & extraction

  • DonPAPI
  • DPAPI tools
  • hashdump tooling
  • Keepass attack tooling
  • LaZagne
  • lsassy
  • mimipenguin
  • Nanodump
  • procdump (abuse)
  • pypykatz
  • SecretsDump
  • SharpChromium
  • SharpWeb