Penetration Testing Tools

A curated directory of penetration testing tools — from web application security scanners and network reconnaissance utilities, to exploitation frameworks, password crackers, and mobile security testing platforms used by ethical hackers and security teams.

Web Application Security Scanners

Dynamic and static scanners that crawl, fuzz, and probe web applications and APIs for OWASP Top 10 vulnerabilities, business-logic flaws, and misconfigurations.

  1. Burp Suite Professional

    The world's #1 web penetration testing toolkit, pairing a powerful vulnerability scanner with best-in-class manual tools trusted by pentesters everywhere.

  2. OWASP ZAP

    The world's most widely used free and open-source web app scanner, now backed by Checkmarx and a large community-driven add-on marketplace.

  3. Netsparker (now Invicti)

    Accurate, automated DAST for web applications and APIs, delivering proof-based scanning that eliminates false positives at enterprise scale.

  4. Acunetix

    A fast, accurate DAST scanner with 20+ years of pedigree, now part of Invicti, covering single-page apps, APIs, and AI-powered risk correlation.

  5. Nikto

    An open-source web server scanner checking for 8,000+ potentially dangerous files, outdated components, and common server misconfigurations.

  6. Sboxr

    A specialized scanner purpose-built to find DOM-based XSS and other client-side vulnerabilities that many traditional scanners miss.

  7. WPScan

    An enterprise vulnerability database and scanner purpose-built for WordPress core, plugins, and themes, cataloging tens of thousands of known issues.

  8. w3af

    A Python-based Web Application Attack and Audit Framework designed to help find and exploit vulnerabilities in web applications.

  9. Indusface

    Autonomous application security combining WAAP, DAST scanning, and AI-assisted penetration testing across web, API, and AI application surfaces.

  10. Intruder.io

    Always-on exposure management unifying vulnerability scanning, attack surface monitoring, and cloud security posture management for lean security teams.

Network & Wireless Security Tools

Utilities for host discovery, packet capture, wireless auditing, and internet-scale scanning that form the reconnaissance backbone of any penetration test.

  1. Nmap

    The free, open-source network mapper for host discovery, port scanning, OS detection, and security auditing of networks large and small.

  2. Wireshark

    The world's leading network protocol analyzer, letting you capture and interactively browse live traffic for deep packet-level inspection.

  3. Aircrack-ng

    A complete suite of command-line tools to assess WiFi network security: monitoring, attacking, testing, and cracking WEP and WPA/WPA2.

  4. ZMap

    A fast, stateless single-packet network scanner capable of surveying the entire public IPv4 address space on a single port in minutes.

  5. Ettercap

    A comprehensive suite for man-in-the-middle attacks, featuring live connection sniffing, content filtering on the fly, and protocol dissection.

  6. SolarWinds (Traceroute & Network Tools)

    SolarWinds' observability and IT management portfolio, including free traceroute and diagnostic utilities for mapping and troubleshooting network paths.

Exploitation & Password Cracking Frameworks

Frameworks and utilities for exploiting discovered vulnerabilities, auditing password strength, and simulating real-world attacker techniques.

  1. Metasploit

    The world's most used penetration testing framework, combining an open-source module library with Rapid7-backed commercial support and tooling.

  2. Hashcat

    The world's fastest and most advanced password recovery utility, supporting 450+ hash types across CPU, GPU, and APU hardware.

  3. John the Ripper

    A fast, widely used password cracker supporting hundreds of hash and cipher types, ideal for auditing password strength across systems.

  4. sqlmap

    Open-source automation for detecting and exploiting SQL injection flaws and taking over the databases behind them, across 40+ backends.

  5. Sqlninja

    A SQL Server injection and takeover tool that provides remote access to a vulnerable DB server, with built-in Metasploit integration.

  6. BeEF

    The Browser Exploitation Framework, hooking web browsers to assess client-side attack vectors that lie beyond the hardened network perimeter.

OS Distributions, Mobile & Vulnerability Management

Purpose-built operating systems, mobile app security frameworks, and vulnerability management platforms that anchor a penetration tester's toolkit.

  1. Kali Linux

    The industry-standard, Debian-based penetration testing distribution, preloaded with hundreds of security research and forensics tools.

  2. MobSF

    Mobile Security Framework — an automated, all-in-one mobile app pen-testing, malware analysis, and security assessment framework for Android, iOS, and Windows.

  3. Tenable (Nessus)

    A leading exposure management platform, with Nessus providing comprehensive vulnerability scanning across IT, cloud, OT, and identity attack surfaces.

  4. FuzzDB

    The first and most comprehensive open dictionary of attack patterns, predictable resource paths, and regex for black-box fault-injection testing.