SEC504 Tools Report
Generated 2021/08/27
A
| Tool | Description | Tags |
|---|---|---|
| Acunetix Web Vulnerability Scanner | Acunetix Web Vulnerability Scanner is a complete web application security testing solution that can be used both standalone and as part of complex environments. It offers built-in vulnerability assessment and vulnerability management. | Commercial, Defense, Multi-platform |
| Aircrack-ng | Aircrack-ng is a Wi-Fi network attack tool, targeting WEP and WPA-PSK/WPA2-PSK networks. | Free, Open Source, Offense, Windows, Linux, macOS |
| Airdecap-ng | Part of Aircrack-ng, decrypt the packets from a Wi-Fi WEP or WPA-PSK/WPA2-PSK packet capture following key recovery. | Free, Open Source, Offense, Windows, Linux, macOS |
| Anki | Anki is a flexible flash card system that applies spaced repetition theory for improved long-term retention development. | Free, Utility, Windows, Linux, macOS, Multi-platform, Cloud Service |
B
| Tool | Description | Tags |
|---|---|---|
| Basic Blob Finder | Search for public Azure Blobs, enumerating the files. | Free, Open Source, Offense, Multi-platform |
| BCDedit | BCDEdit is a Windows command line tool for managing Boot Configuration Data (BCD). BCD files provide a store that is used to describe boot applications and boot application settings. BCDEdit can be used for a variety of purposes, including creating new stores, modifying existing stores, adding boot menu options, and so on. | Commercial, Utility, Windows |
| Beats | Server-side tools for ingesting and shipping data to identified sources (commonly Elasticsearch; faster and less complex than Logstash but less functional). Includes Filebeat, Packetbeat, Winlogbeat, and others. | Free, Open Source, Defense, Utility, Multi-platform |
| BeEF | The Browser Exploitation Framework is a suite of tools for exploiting vulnerabilities in browsers delivered through several attack vectors. | Free, Open Source, Offense, Multi-platform |
| Bettercap | Bettercap is a multi-functional attack took that targets Wi-Fi, Bluetooth Low Energy, wireless keyboards Ethernet networks including reconnaissance and MITM attacks. | Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform |
| Bloodhound | Bloodhound graphically maps the relationships to systems, permissions on those systems, and the permissions of the users logged onto those systems to help an attacker identify the most direct route to elevating the permissions of the system they have access to into a domain admin account. | Free, Open Source, Offense, Linux |
| Bucket Finder | Search for AWS S3 storage buckets, identifying them as protected, public, or not found. | Free, Open Source, Offense, Multi-platform |
| Burp Proxy | Cross-platform web proxy for inspecting, attacking web sites and clients. | Free, Commercial, Offense, Windows, Linux, macOS, Multi-platform |
C
| Tool | Description | Tags |
|---|---|---|
| Certificate Transparency Search | Examine certificate registration data for host and system discovery. | Free, Offense, Defense, Cloud Service |
| Certutil | Certutil is a utility that ships with Windows for managing certificates. Certutil can also download content from an arbitrary URL, can encode and decode Base64 data, and can calculate hashes. | Commercial, Offense, Defense, Utility, Windows |
| CeWL | CeWL crawls a target website and collect all web pages and common document formats (MS Office, PDF, images) | Free, Open Source, Offense, Utility, Multi-platform |
| CloudMapper | CloudMapper is an open-source tool for visualizing AWS and auditing AWS cloud deployments. | Free, Open Source, Offense, Defense, Multi-platform |
| Crazyradio PA | Hardware tool for wireless keyboard and mouse keystroke sniffing and injection attacks. | Commercial, Offense, Hardware |
| Curl | cURL is a library and command line tool for transferring data using various network protocols including HTTP, HTTPS, FTP, and more. | Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS, Multi-platform |
| Cyber Chef | The Cyber Swiss Army Knife; a web app for encryption, encoding, compression and data analysis. | Free, Open Source, Offense, Defense, Multi-platform |
| CyberCPR | CyberCPR is an incident response and case management built with a focus on security and need-to-know information disclosure enforcement by SANS instructor Steve Armstrong. | Free, Commercial, Defense, Multi-platform, Cloud Service |
D
| Tool | Description | Tags |
|---|---|---|
| DeepBlueCLI | PowerShell script that parses Windows event logs for threat hunting. | Free, Open Source, Defense, Windows |
| DefenderCheck | Assess an executable file to identify the location where Windows Defender characterizes it as malware. | Free, Open Source, Offense, Windows |
| dig | DNS interrogation tool (the UNIX/Linux/macOS version of nslookup). | Free, Open Source, Offense, Defense, Utility, Windows, macOS |
| DNSCat2 | DNSCat2 is a Command & Control framework operating over DNS. | Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform |
| DNSStuff | Various tools for interrogating Internet-connected systems including DNS information, IP address information, and various network configuration settings. | Free, Cloud Service |
| Domain Password Audit Tool | Report on the results of Windows domain password cracking results. | Free, Open Source, Defense, Windows, Linux, macOS, Multi-platform |
| DuckyScript | Scripting language to automate keyboard attacks (over USB or wireless keyboard/mouse peripherals). | Free, Open Source, Offense, Multi-platform |
E
| Tool | Description | Tags |
|---|---|---|
| Elastic Stack | Collection of tools including Elasticsearch, Kibana, Logstash, Beats for data collection, interrogation, reporting. Suitable for log analysis for multiple log sources. | Free, Open Source, Commercial, Defense, Multi-platform |
| Elasticsearch | Elasticsearch is a distributed, RESTful search and analytics engine. | Free, Open Source, Commercial, Defense, Multi-platform |
| Etl2pcapng | Microsoft tool to convert ETL packet capture traces collected with netsh into Libpcap-ng compatible packet captures. | Free, Open Source, Utility, Windows |
| Eventlogedit-evtx Evolution | Remove individual lines from Windows XML Event Log (EVTX) files. | Free, Open Source, Offense, Windows |
| Exiftool | Exiftool is a Perl script that extracts metadata from many different file types including Microsoft Office, PDF, many different image file types, and more. | Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS, Multi-platform |
| EyeWitness | EyeWitness scans a range of hosts, recording a screenshot of web server content. | Free, Open Source, Offense, Linux |
F
| Tool | Description | Tags |
|---|---|---|
| FakeLogonScreen | Displays a fake Windows login screen to harvest credentials from a user. | Free, Open Source, Offense, Windows |
| fgdump | fgdump is a legacy password hash extraction tool for Windows systems. It has largely been superseded by Mimikatz. | Free, Open Source, Offense, Defense, Windows |
| Flamingo | Flamingo is a server process impersonation tool, running on the attacker system and starting listening server services for SSH, HTTP, LDAP, FTP, and SNMP. | |
| FOCA | FOCA automates the process of discovering these files, downloading them, and extracting the metadata from the files. | Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform |
| FortiSOAR | FortiSOAR is a commercial option for Incident tracking. | Commercial, Defense, Multi-platform |
| FTK Imager | FTK Imager is a forensic data imaging and inspection tool. | Free, Defense, Windows |
G
| Tool | Description | Tags |
|---|---|---|
| GCPBucketFinder | Identify and enumerate the permissions associated with Google Compute Buckets. | Free, Open Source, Offense, Multi-platform |
| Ghidra | Ghidra is a software reverse engineering suite of tools developed by the NSA's Research Directorate. | Free, Open Source, Offense, Defense, Windows |
| GNU Debugger | The GNU Debugger is a portable debugger that runs on many Unix-like systems and works for many programming languages. | Free, Open Source, Commercial, Utility, Windows, Linux, macOS |
| Google Hacking Database | Search tool to use Google to identify vulnerabilities in public websites. | Free, Cloud Service |
| Google Rapid Response (GRR) | GRR is a tool for assisting with scoping, and performing large-scale incident response and hunt teaming. GRR is client-server, with an endpoint on Windows host systems that report to a centralized web console. | Free, Open Source, Defense, Windows |
H
| Tool | Description | Tags |
|---|---|---|
| Hashcat | Multi-functional password hash recovery tool; predominantly uses GPUs for cracking functionality. | Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform |
| Have I Been Pwned | Service to determine if an email address or username is known to have been included in a major breach. | Free, Offense, Defense, Cloud Service |
| Hostapd-WPE | Hostapd-WPE impersonates enterprise Wi-Fi access points to collect authentication credentials from users. | Free, Open Source, Offense, Linux |
| Hydra | Online password guessing tool. | Free, Open Source, Offense, Windows, Linux, macOS |
I
| Tool | Description | Tags |
|---|---|---|
| IDA Pro | IDA Pro is a commercial disassembler, useful for malware analysis and many other reverse-engineering tasks. | Commercial, Offense, Defense, Windows, Linux, macOS |
| inSSIDer | inSSIDer collects and reports on information observed in beacon frames and probe (active scanning) (requires registration for use). | Free, Windows |
| inSSIDer2 | inSSIDer collects and reports on information observed in beacon frames (passive scanning) and probe response frames (active scanning). | Free, Offense, Defense, Windows |
J
| Tool | Description | Tags |
|---|---|---|
| Jackit | Software to use the hardware device Crazyradio PA to sniff and inject keystrokes from unencrypted wireless keyboards. | Free, Open Source, Linux |
| John the Ripper | Multi-functional password hash recovery tool; predominantly uses the local CPU for cracking functionality. | Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform |
| JQ | JQ is a command line tool for processing JSON data. | Free, Open Source, Utility, Windows, Linux, macOS |
K
| Tool | Description | Tags |
|---|---|---|
| Kibana | Kibana is an open source data visualization dashboard for Elasticsearch. | Free, Open Source, Defense, Multi-platform |
| Kismet | Kismet uses a standard wireless card in monitor mode, allowing the card to capture any available wireless packets within range of the antenna and passing them to Kismet for analysis | Free, Open Source, Offense, Defense, Linux |
| Kon-boot | Bypass local system authentication by booting from alternate media. | Commercial, Offense, Windows, macOS, Multi-platform |
L
| Tool | Description | Tags |
|---|---|---|
| LADS | List Alternate Data Streams is a tool to identify the presence of ADS data on Windows systems. | Free, Defense, Utility, Windows |
| LAN Turtle | The LAN Turtle is a covert Systems Administration and Penetration Testing tool providing stealth remote access, network intelligence gathering, and man-in-the-middle surveillance capabilities through a simple graphic shell. Housed within a generic USB Ethernet adapter case, the LAN Turtle's covert appearance allows it to blend into many IT environments. | Commercial, Offense, Hardware |
| LaZagne | LaZagne is a modular framework for retrieving passwords and password hashes from Windows, macOS, and Linux systems. | Free, Open Source, Offense, Windows, Linux, macOS |
| LogonTracer | Investigate malicious Windows logon by visualizing and analyzing Windows event log. | Free, Open Source, Defense, Linux, macOS, Multi-platform |
| Logstash | Logstash is a server-side data processing tool that ingests data from a many data sources, sending it to identified output sources including Elasticsearch databases. | Free, Open Source, Defense, Multi-platform |
| lsof | LiSt Open Files, including open TCP and UDP port usage. | Free, Open Source, Defense, Linux |
| Lusrmgr.msc | Lusrmgr.msc is the snap in configuration utility to manage local users and groups. | Commercial, Defense, Utility, Windows |
M
| Tool | Description | Tags |
|---|---|---|
| Massscan | Port scanning tool designed to scan large quantities of IP addresses. | Free, Open Source, Offense, Linux |
| Metasm | A free assembler, disassembler, and compiler written in Ruby. Metasm can be used for Ghostwriting attacks. | Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform |
| Metasploit Framework | Attack framework for combining exploits, payloads, auxiliary modules, and post-exploitation modules against identified targets. | Free, Open Source, Offense, Multi-platform |
| Metasploit Meterpreter | Advanced Command & Control framework that is part of the Metasploit Framework. | Free, Open Source, Offense, Multi-platform |
| Mimikatz | Mimikatz is a well-known password and password hash extraction tool for Windows. | Free, Open Source, Offense, Windows |
| MSBuild | MSBuild.exe is a built-in Windows tool for building and executing C/C++/C# code. | Commercial, Offense, Utility, Windows |
| Msconfig | The Msconfig.exe utility is the Windows System Configuration utility, intended for managing configuration and troubleshooting tasks on Windows. | Commercial, Defense, Utility, Windows |
| MsfVenom | MsfVenom is a part of the Metasploit Framework, capable of generating and encoding Metasploit Framework payloads into independent executables. | Free, Open Source, Offense, Utility, Windows, Linux, macOS, Multi-platform |
N
| Tool | Description | Tags |
|---|---|---|
| Namechk | Check multiple online sources for registered usernames. | Free, Offense, Defense, Cloud Service |
| Nbtstat | Nbtstat is a built-in Windows tool for collecting information on SMB servers over the NetBIOS protocol, over TCP. | Commercial, Offense, Defense, Utility, Windows |
| Nessus | Vulnerability assessment scanner and management tool. | Commercial, Defense, Multi-platform |
| Net | Net Commands can be used to perform operations on Groups, users, account policies, shares etc. | Commercial, Offense, Defense, Utility, Windows |
| Netcat | Netcat is a featured networking utility which reads and writes data across network connections, using the TCP/IP protocol. | Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS, Multi-platform |
| Netsh | Netsh is a command line scripting utility that allows you to display or modify the network configuration of a computer that is currently running. Netsh can be used to create local packet captures on Windows hosts. | Commercial, Offense, Defense, Utility, Windows |
| Netstat | Identify listening services, connections on a host system. | Free, Open Source, Commercial, Offense, Defense, Utility, Windows, Linux, macOS, Multi-platform |
| NetworkMiner | NetworkMiner is a passive network packet capture tool in to detect operating systems, sessions, hostnames, and open ports. NetworkMiner can also parse libpcap files for offline analysis and to regenerate transmitted files sent over the network. | Free, Open Source, Offense, Windows |
| Nmap | Network port scan, mapping, and assessment tool. | Free, Open Source, Offense, Windows, Linux, macOS |
| Ntdsutil | Ntdsutil.exe is a command line tool that provides management facilities for Active Directory Domain Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS). Widely used by attackers to retrieve domain password hash data for processing with Impacket secretsdump.py. | Commercial, Offense, Defense, Utility, Windows |
O
| Tool | Description | Tags |
|---|---|---|
| OpenSSL | OpenSSL is a programming library for encryption and encoding operations, implementing several common network protocols (such as TLS and SSL). OpenSSL also has a command-line companion tool openssl that can be used as a listener or a client. |
Free, Open Source, Utility, Windows, Linux, macOS |
P
| Tool | Description | Tags |
|---|---|---|
| Pacu | Pacu is a aodular collection of exploits for multiple cloud enumeration, privilege escalation, and data exfiltration. | |
| Free, Open Source, Offense, Multi-platform | ||
| passwd | Passwd is a Linux utility to change your password, or other user's passwords when you have root privileges. | Free, Open Source, Offense, Defense, Utility, Linux |
| PowerView | PowerShell cmdlets for interrogating Windows systems including multiple scanning and enumeration functions. | Free, Open Source, Offense, Windows |
| ProcDOT | ProcDOT takes output from Process Monitor, and optionally a PCAP file, and displays the events graphically. | Free, Open Source, Defense, Windows, Linux |
| Procdump | Procdump is part of the SysInternals suite for Windows, allowing an administrator to dump the memory from running processes. Procdump is often used with Mimikatz for password and password hash retrieval. | Free, Offense, Defense, Utility, Windows |
| Process Explorer | Process Explorer of a part of the Microsoft SysInternals suite of tools, used for tracking process execution for Windows executables. | Free, Defense, Utility, Windows |
| Process Monitor (Procmon) | Procmon is a component of the Microsoft SysInternals suite of tools, used for real-time file system, Registry and process monitoring. It replaces the two legacy SysInternals utilities, Filemon and Regmon. | Free, Defense, Utility, Windows |
| Ptunnel | Ptunnel tunnels TCP connections through ICMP to exfiltrate egress filters in some networks. | Free, Open Source, Offense, Linux |
Q
| Tool | Description | Tags |
|---|---|---|
| Qualys VM | Vulnerability identification and management tool. | Commercial, Multi-platform, Cloud Service |
R
| Tool | Description | Tags |
|---|---|---|
| Rapid7 InsightVM | Vulnerability management, assessment tool. | Commercial, Defense, Multi-platform |
| Real Intelligence Threat Analytics | RITA is an open source framework for network traffic analysis and threat hunting. | Free, Open Source, Defense, Windows, Linux, macOS, Multi-platform |
| Reg | The reg utility reads and writes to the Windows registry from the command line. | Commercial, Offense, Defense, Utility, Windows |
| Regshot | Regshot is a snapshot recording tool for Windows. It allows you to record a snapshot of the registry and optionally the file system at two points in time. Regshot provides a high level summary of the changes, showing the registry keys that were added, removed, and modified. It will also summarize the files that were added, removed, and modified. | Free, Open Source, Utility, Windows |
| Request Tracker for Incident Response (RTIR) | RTIR is a free tool for incident response management and tracking. | Free, Open Source, Defense, Multi-platform |
| Responder | Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. Responder is commonly used to steal authentication credentials from Windows victims on the LAN through the LLMNR protocol. | Free, Open Source, Offense, Windows, Linux, macOS |
| Reverse Whois Lookup | Gather limited domain information (domain name, creation date, and registrar) using a registrant name or email address | Free, Offense, Cloud Service |
| Rpcclient | Interrogate Windows RPC services from Linux. | Free, Open Source, Utility, Linux |
| Rubber Ducky | USB hardware device that acts as a keyboard, sending scripted keystroke attack combinations to the target system. | Commercial, Offense, Multi-platform, Hardware |
S
| Tool | Description | Tags |
|---|---|---|
| s3logparse | Summarize and collect data from AWS S3 logs. | Free, Open Source, Defense, Utility, Multi-platform |
| SAINT Security Suite | SAINT Security Suite provides a fully-integrated set of capabilities to assess your network assets for the latest vulnerabilities across a wide variety of operating systems, software applications, databases, network devices and configurations. | Commercial, Defense, Multi-platform |
| Samba | Collection of tools to interact with Windows systems from Linux. | Free, Open Source, Offense, Utility, Linux |
| sc | Service Control, control Windows services from the command line. | Commercial, Offense, Defense, Utility, Windows |
| Schtasks | Schtasks is a Windows built-in utility for managing scheduled tasks. | Commercial, Offense, Defense, Utility, Windows |
| ScoutSuite | ScoutSuite is a dedicated vulnerability assessment tool for cloud environments | Free, Open Source, Offense, Defense, Multi-platform |
| Secretsdump.py | Part of Impacket, secretsdump.py extracts password hash information from the Windows domain SAM file and SYSTEM hive (typically from the output of ntdsutil). | Free, Open Source, Offense, Windows, Linux, macOS |
| SecuritySpace | Online vulnerability assessment/network security auditing services including network monitoring and notification. | Commercial, Cloud Service |
| services.msc | Services.msc is the command to open the snap-in control panel for managing Windows services in a GUI interface. | Commercial, Defense, Utility, Windows |
| SharpView | Interrogate Windows properties including users, platforms, domain settings, and more. | Free, Open Source, Offense, Windows |
| SHODAN | Use Shodan to discover Internet devices including vulnerable platforms and systems. | Free, Commercial, Cloud Service |
| Smbclient | FTP-like client to access SMB/CIFS resources on servers and to interrogate Windows settings. | Free, Open Source, Offense, Utility, Linux |
| SpiderFoot | SpiderFoot collets OSINT data from hundreds of online sources, using the collected data to seed additional searches. | Free, Open Source, Offense, Windows, Linux, macOS |
| Sqlmap | Sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws. | Free, Open Source, Defense, Windows, Linux, macOS, Multi-platform |
| Squid | Squid is a popular open source web proxy tool. | Free, Open Source, Defense, Windows, Linux, macOS |
| SRUM-Dump | A forensics tool to convert the data in the Windows SRUM (System Resource Usage Monitor) database to an xlsx spreadsheet. | Free, Open Source, Defense, Windows |
| Streams | Streams, part of SysInternals, is a tool to identify the presence of ADS data on Windows systems. | Free, Utility, Windows |
| Strings (Linux) | The Linux strings utility extracts plaintext strings from a specified file, supporting both ASCII and UTF-16 string data. | Free, Open Source, Defense, Utility, Linux |
| Strings (Windows) | The Strings utility for Windows is part of the SysInternals suite of tools. Strings can extract ASCII and UTF-16 string values from an arbitrary file. | Free, Defense, Utility, Windows |
| Sudo | Sudo is a program for Unix-like computer operating systems that allows users to run programs with the security privileges of another user. | Free, Open Source, Utility, Linux, macOS |
| Swipe | Remove logging evidence from binary UNIX and Linux authentication log files (btmp, wtmp, atmp, lastlog, atmp). | Free, Open Source, Offense, Linux |
| SysInternals | Sysinternals is a collection of tools to perform advanced management, diagnostics, troubleshooting, and monitoring in a Microsoft Windows environment. | Free, Defense, Utility, Windows |
| systemctl | Control Linux services. | Free, Open Source, Offense, Defense, Linux |
T
| Tool | Description | Tags |
|---|---|---|
| Tasklist | Tasklist is a built-in Windows tool that enumerates running processes and services. | Commercial, Offense, Defense, Utility, Windows |
| Tcpdump | Tcpdump is a command line network packet capture and analysis tool. | Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS |
| TCPView | TCPView is part of the Microsoft SysInternals suite of tools that will show you detailed listings of all TCP and UDP endpoints on your system, including the local and remote addresses and state of TCP connections. | Free, Defense, Utility, Windows |
| TLS-Scan | TLS-Scan by Binu Ramakrishnan is a network scanning tool to extract SSL and TLS certificate details from servers, saving the output as a JSON file. TLS-Scan can be useful for identifying attribution for a server based on certificate details including the organization name and common name fields. | Free, Open Source, Offense, Utility, Linux, macOS |
| Tshark | Tshark is a command line version of Wireshark. | Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS |
U
| Tool | Description | Tags |
|---|---|---|
| Unshadow | Included with John the Ripper, unshadow merges the password and shadow files into a single unified file for password cracking efficiency. | Free, Open Source, Offense, Utility, Windows, Linux, macOS, Multi-platform |
| US Government SEC Database | The US Government Securities and Exchange Commission (SEC) can be a useful information source for collecting data for publicly traded US companies. | Free, Offense, Defense, Cloud Service |
| useradd | Useradd is a Linux tool to add new user accounts to the system. | Free, Open Source, Offense, Defense, Utility, Linux |
V
| Tool | Description | Tags |
|---|---|---|
| Velociraptor | Velociraptor uses client endpoint software to collect and report information on Windows, Linux, and macOS systems | Free, Open Source, Defense, Windows, Linux, macOS |
| Volatility | Volatility is an open-source memory forensics framework. | Free, Open Source, Defense, Windows, Linux, macOS |
| vpc-flow-log-analysis | Visualize AWS VPC flow logs; original source at https://github.com/FlorianPfisterer/vpc-flow-log-analysis (URL cited includes features added by Joshua Wright) | Free, Open Source, Commercial, Defense, Windows, Linux, macOS |
W
| Tool | Description | Tags |
|---|---|---|
| w3af | w3af is a Web Application Attack and Audit Framework. | Free, Open Source, Offense, Windows, Linux, macOS |
| WarVOX | WarVOX was a free, open-source VOIP-based war dialing tool for exploring, classifying, and auditing phone systems. | Free, Open Source, Offense, Linux |
| Wevtutil | Wevtutil is a command line tool that comes with Windows for managing event log data including purging event logs. | Commercial, Offense, Defense, Utility, Windows |
| wget | Web Get; retrieve content from a specified URL. | Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS |
| whois | Linux utility to interrogate DNS registration data. | Utility, Linux, macOS |
| Wi-Fi Pineapple | The WiFi Pineapple is an integrated Linux system and Wi-Fi attack platform in a small hardware form-factor. | Commercial, Offense, Hardware |
| Windows Credential Editor | Windows Credentials Editor (WCE) is a security tool to list logon sessions and add, change, list and delete associated credentials (ex.: LM/NT hashes, plaintext passwords and Kerberos tickets). | Free, Open Source, Offense, Windows |
| Windump | Windump is a port of the TCPDump tool to Windows. | Free, Open Source, Offense, Defense, Utility, Windows |
| Wireshark | Wireshark is the world’s foremost and widely-used network protocol analyzer. | Free, Open Source, Offense, Defense, Windows, Linux, macOS, Multi-platform |
| wmic | Windows Management Instrumentation Console, access several components of Windows systems and functionality form the command line. | Commercial, Offense, Defense, Utility, Windows |
X
| Tool | Description | Tags |
|---|---|---|
| xlek | xlek is a resource to search millions of online data records for free. | Free, Offense, Defense, Cloud Service |
Z
| Tool | Description | Tags |
|---|---|---|
| ZAP Proxy | Cross-platform web proxy for inspecting, attacking web sites and clients. | Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform |
| Zeek | Zeek is a free and open-source software network analysis framework. Zeek logging data is used to supply RITA with data for network threat hunting analysis. | Free, Open Source, Defense, Windows, Linux, macOS |
| Zenmap | GUI front-end and visualization tool for Nmap. | Free, Open Source, Offense, Windows, Linux, macOS |