SEC504 Tools Report

Generated 2021/08/27

A

Tool Description Tags
Acunetix Web Vulnerability Scanner Acunetix Web Vulnerability Scanner is a complete web application security testing solution that can be used both standalone and as part of complex environments. It offers built-in vulnerability assessment and vulnerability management. Commercial, Defense, Multi-platform
Aircrack-ng Aircrack-ng is a Wi-Fi network attack tool, targeting WEP and WPA-PSK/WPA2-PSK networks. Free, Open Source, Offense, Windows, Linux, macOS
Airdecap-ng Part of Aircrack-ng, decrypt the packets from a Wi-Fi WEP or WPA-PSK/WPA2-PSK packet capture following key recovery. Free, Open Source, Offense, Windows, Linux, macOS
Anki Anki is a flexible flash card system that applies spaced repetition theory for improved long-term retention development. Free, Utility, Windows, Linux, macOS, Multi-platform, Cloud Service

B

Tool Description Tags
Basic Blob Finder Search for public Azure Blobs, enumerating the files. Free, Open Source, Offense, Multi-platform
BCDedit BCDEdit is a Windows command line tool for managing Boot Configuration Data (BCD). BCD files provide a store that is used to describe boot applications and boot application settings. BCDEdit can be used for a variety of purposes, including creating new stores, modifying existing stores, adding boot menu options, and so on. Commercial, Utility, Windows
Beats Server-side tools for ingesting and shipping data to identified sources (commonly Elasticsearch; faster and less complex than Logstash but less functional). Includes Filebeat, Packetbeat, Winlogbeat, and others. Free, Open Source, Defense, Utility, Multi-platform
BeEF The Browser Exploitation Framework is a suite of tools for exploiting vulnerabilities in browsers delivered through several attack vectors. Free, Open Source, Offense, Multi-platform
Bettercap Bettercap is a multi-functional attack took that targets Wi-Fi, Bluetooth Low Energy, wireless keyboards Ethernet networks including reconnaissance and MITM attacks. Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform
Bloodhound Bloodhound graphically maps the relationships to systems, permissions on those systems, and the permissions of the users logged onto those systems to help an attacker identify the most direct route to elevating the permissions of the system they have access to into a domain admin account. Free, Open Source, Offense, Linux
Bucket Finder Search for AWS S3 storage buckets, identifying them as protected, public, or not found. Free, Open Source, Offense, Multi-platform
Burp Proxy Cross-platform web proxy for inspecting, attacking web sites and clients. Free, Commercial, Offense, Windows, Linux, macOS, Multi-platform

C

Tool Description Tags
Certificate Transparency Search Examine certificate registration data for host and system discovery. Free, Offense, Defense, Cloud Service
Certutil Certutil is a utility that ships with Windows for managing certificates. Certutil can also download content from an arbitrary URL, can encode and decode Base64 data, and can calculate hashes. Commercial, Offense, Defense, Utility, Windows
CeWL CeWL crawls a target website and collect all web pages and common document formats (MS Office, PDF, images) Free, Open Source, Offense, Utility, Multi-platform
CloudMapper CloudMapper is an open-source tool for visualizing AWS and auditing AWS cloud deployments. Free, Open Source, Offense, Defense, Multi-platform
Crazyradio PA Hardware tool for wireless keyboard and mouse keystroke sniffing and injection attacks. Commercial, Offense, Hardware
Curl cURL is a library and command line tool for transferring data using various network protocols including HTTP, HTTPS, FTP, and more. Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS, Multi-platform
Cyber Chef The Cyber Swiss Army Knife; a web app for encryption, encoding, compression and data analysis. Free, Open Source, Offense, Defense, Multi-platform
CyberCPR CyberCPR is an incident response and case management built with a focus on security and need-to-know information disclosure enforcement by SANS instructor Steve Armstrong. Free, Commercial, Defense, Multi-platform, Cloud Service

D

Tool Description Tags
DeepBlueCLI PowerShell script that parses Windows event logs for threat hunting. Free, Open Source, Defense, Windows
DefenderCheck Assess an executable file to identify the location where Windows Defender characterizes it as malware. Free, Open Source, Offense, Windows
dig DNS interrogation tool (the UNIX/Linux/macOS version of nslookup). Free, Open Source, Offense, Defense, Utility, Windows, macOS
DNSCat2 DNSCat2 is a Command & Control framework operating over DNS. Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform
DNSStuff Various tools for interrogating Internet-connected systems including DNS information, IP address information, and various network configuration settings. Free, Cloud Service
Domain Password Audit Tool Report on the results of Windows domain password cracking results. Free, Open Source, Defense, Windows, Linux, macOS, Multi-platform
DuckyScript Scripting language to automate keyboard attacks (over USB or wireless keyboard/mouse peripherals). Free, Open Source, Offense, Multi-platform

E

Tool Description Tags
Elastic Stack Collection of tools including Elasticsearch, Kibana, Logstash, Beats for data collection, interrogation, reporting. Suitable for log analysis for multiple log sources. Free, Open Source, Commercial, Defense, Multi-platform
Elasticsearch Elasticsearch is a distributed, RESTful search and analytics engine. Free, Open Source, Commercial, Defense, Multi-platform
Etl2pcapng Microsoft tool to convert ETL packet capture traces collected with netsh into Libpcap-ng compatible packet captures. Free, Open Source, Utility, Windows
Eventlogedit-evtx Evolution Remove individual lines from Windows XML Event Log (EVTX) files. Free, Open Source, Offense, Windows
Exiftool Exiftool is a Perl script that extracts metadata from many different file types including Microsoft Office, PDF, many different image file types, and more. Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS, Multi-platform
EyeWitness EyeWitness scans a range of hosts, recording a screenshot of web server content. Free, Open Source, Offense, Linux

F

Tool Description Tags
FakeLogonScreen Displays a fake Windows login screen to harvest credentials from a user. Free, Open Source, Offense, Windows
fgdump fgdump is a legacy password hash extraction tool for Windows systems. It has largely been superseded by Mimikatz. Free, Open Source, Offense, Defense, Windows
Flamingo Flamingo is a server process impersonation tool, running on the attacker system and starting listening server services for SSH, HTTP, LDAP, FTP, and SNMP.
FOCA FOCA automates the process of discovering these files, downloading them, and extracting the metadata from the files. Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform
FortiSOAR FortiSOAR is a commercial option for Incident tracking. Commercial, Defense, Multi-platform
FTK Imager FTK Imager is a forensic data imaging and inspection tool. Free, Defense, Windows

G

Tool Description Tags
GCPBucketFinder Identify and enumerate the permissions associated with Google Compute Buckets. Free, Open Source, Offense, Multi-platform
Ghidra Ghidra is a software reverse engineering suite of tools developed by the NSA's Research Directorate. Free, Open Source, Offense, Defense, Windows
GNU Debugger The GNU Debugger is a portable debugger that runs on many Unix-like systems and works for many programming languages. Free, Open Source, Commercial, Utility, Windows, Linux, macOS
Google Hacking Database Search tool to use Google to identify vulnerabilities in public websites. Free, Cloud Service
Google Rapid Response (GRR) GRR is a tool for assisting with scoping, and performing large-scale incident response and hunt teaming. GRR is client-server, with an endpoint on Windows host systems that report to a centralized web console. Free, Open Source, Defense, Windows

H

Tool Description Tags
Hashcat Multi-functional password hash recovery tool; predominantly uses GPUs for cracking functionality. Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform
Have I Been Pwned Service to determine if an email address or username is known to have been included in a major breach. Free, Offense, Defense, Cloud Service
Hostapd-WPE Hostapd-WPE impersonates enterprise Wi-Fi access points to collect authentication credentials from users. Free, Open Source, Offense, Linux
Hydra Online password guessing tool. Free, Open Source, Offense, Windows, Linux, macOS

I

Tool Description Tags
IDA Pro IDA Pro is a commercial disassembler, useful for malware analysis and many other reverse-engineering tasks. Commercial, Offense, Defense, Windows, Linux, macOS
inSSIDer inSSIDer collects and reports on information observed in beacon frames and probe (active scanning) (requires registration for use). Free, Windows
inSSIDer2 inSSIDer collects and reports on information observed in beacon frames (passive scanning) and probe response frames (active scanning). Free, Offense, Defense, Windows

J

Tool Description Tags
Jackit Software to use the hardware device Crazyradio PA to sniff and inject keystrokes from unencrypted wireless keyboards. Free, Open Source, Linux
John the Ripper Multi-functional password hash recovery tool; predominantly uses the local CPU for cracking functionality. Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform
JQ JQ is a command line tool for processing JSON data. Free, Open Source, Utility, Windows, Linux, macOS

K

Tool Description Tags
Kibana Kibana is an open source data visualization dashboard for Elasticsearch. Free, Open Source, Defense, Multi-platform
Kismet Kismet uses a standard wireless card in monitor mode, allowing the card to capture any available wireless packets within range of the antenna and passing them to Kismet for analysis Free, Open Source, Offense, Defense, Linux
Kon-boot Bypass local system authentication by booting from alternate media. Commercial, Offense, Windows, macOS, Multi-platform

L

Tool Description Tags
LADS List Alternate Data Streams is a tool to identify the presence of ADS data on Windows systems. Free, Defense, Utility, Windows
LAN Turtle The LAN Turtle is a covert Systems Administration and Penetration Testing tool providing stealth remote access, network intelligence gathering, and man-in-the-middle surveillance capabilities through a simple graphic shell. Housed within a generic USB Ethernet adapter case, the LAN Turtle's covert appearance allows it to blend into many IT environments. Commercial, Offense, Hardware
LaZagne LaZagne is a modular framework for retrieving passwords and password hashes from Windows, macOS, and Linux systems. Free, Open Source, Offense, Windows, Linux, macOS
LogonTracer Investigate malicious Windows logon by visualizing and analyzing Windows event log. Free, Open Source, Defense, Linux, macOS, Multi-platform
Logstash Logstash is a server-side data processing tool that ingests data from a many data sources, sending it to identified output sources including Elasticsearch databases. Free, Open Source, Defense, Multi-platform
lsof LiSt Open Files, including open TCP and UDP port usage. Free, Open Source, Defense, Linux
Lusrmgr.msc Lusrmgr.msc is the snap in configuration utility to manage local users and groups. Commercial, Defense, Utility, Windows

M

Tool Description Tags
Massscan Port scanning tool designed to scan large quantities of IP addresses. Free, Open Source, Offense, Linux
Metasm A free assembler, disassembler, and compiler written in Ruby. Metasm can be used for Ghostwriting attacks. Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform
Metasploit Framework Attack framework for combining exploits, payloads, auxiliary modules, and post-exploitation modules against identified targets. Free, Open Source, Offense, Multi-platform
Metasploit Meterpreter Advanced Command & Control framework that is part of the Metasploit Framework. Free, Open Source, Offense, Multi-platform
Mimikatz Mimikatz is a well-known password and password hash extraction tool for Windows. Free, Open Source, Offense, Windows
MSBuild MSBuild.exe is a built-in Windows tool for building and executing C/C++/C# code. Commercial, Offense, Utility, Windows
Msconfig The Msconfig.exe utility is the Windows System Configuration utility, intended for managing configuration and troubleshooting tasks on Windows. Commercial, Defense, Utility, Windows
MsfVenom MsfVenom is a part of the Metasploit Framework, capable of generating and encoding Metasploit Framework payloads into independent executables. Free, Open Source, Offense, Utility, Windows, Linux, macOS, Multi-platform

N

Tool Description Tags
Namechk Check multiple online sources for registered usernames. Free, Offense, Defense, Cloud Service
Nbtstat Nbtstat is a built-in Windows tool for collecting information on SMB servers over the NetBIOS protocol, over TCP. Commercial, Offense, Defense, Utility, Windows
Nessus Vulnerability assessment scanner and management tool. Commercial, Defense, Multi-platform
Net Net Commands can be used to perform operations on Groups, users, account policies, shares etc. Commercial, Offense, Defense, Utility, Windows
Netcat Netcat is a featured networking utility which reads and writes data across network connections, using the TCP/IP protocol. Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS, Multi-platform
Netsh Netsh is a command line scripting utility that allows you to display or modify the network configuration of a computer that is currently running. Netsh can be used to create local packet captures on Windows hosts. Commercial, Offense, Defense, Utility, Windows
Netstat Identify listening services, connections on a host system. Free, Open Source, Commercial, Offense, Defense, Utility, Windows, Linux, macOS, Multi-platform
NetworkMiner NetworkMiner is a passive network packet capture tool in to detect operating systems, sessions, hostnames, and open ports. NetworkMiner can also parse libpcap files for offline analysis and to regenerate transmitted files sent over the network. Free, Open Source, Offense, Windows
Nmap Network port scan, mapping, and assessment tool. Free, Open Source, Offense, Windows, Linux, macOS
Ntdsutil Ntdsutil.exe is a command line tool that provides management facilities for Active Directory Domain Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS). Widely used by attackers to retrieve domain password hash data for processing with Impacket secretsdump.py. Commercial, Offense, Defense, Utility, Windows

O

Tool Description Tags
OpenSSL OpenSSL is a programming library for encryption and encoding operations, implementing several common network protocols (such as TLS and SSL). OpenSSL also has a command-line companion tool openssl that can be used as a listener or a client. Free, Open Source, Utility, Windows, Linux, macOS

P

Tool Description Tags
Pacu Pacu is a aodular collection of exploits for multiple cloud enumeration, privilege escalation, and data exfiltration.
Free, Open Source, Offense, Multi-platform
passwd Passwd is a Linux utility to change your password, or other user's passwords when you have root privileges. Free, Open Source, Offense, Defense, Utility, Linux
PowerView PowerShell cmdlets for interrogating Windows systems including multiple scanning and enumeration functions. Free, Open Source, Offense, Windows
ProcDOT ProcDOT takes output from Process Monitor, and optionally a PCAP file, and displays the events graphically. Free, Open Source, Defense, Windows, Linux
Procdump Procdump is part of the SysInternals suite for Windows, allowing an administrator to dump the memory from running processes. Procdump is often used with Mimikatz for password and password hash retrieval. Free, Offense, Defense, Utility, Windows
Process Explorer Process Explorer of a part of the Microsoft SysInternals suite of tools, used for tracking process execution for Windows executables. Free, Defense, Utility, Windows
Process Monitor (Procmon) Procmon is a component of the Microsoft SysInternals suite of tools, used for real-time file system, Registry and process monitoring. It replaces the two legacy SysInternals utilities, Filemon and Regmon. Free, Defense, Utility, Windows
Ptunnel Ptunnel tunnels TCP connections through ICMP to exfiltrate egress filters in some networks. Free, Open Source, Offense, Linux

Q

Tool Description Tags
Qualys VM Vulnerability identification and management tool. Commercial, Multi-platform, Cloud Service

R

Tool Description Tags
Rapid7 InsightVM Vulnerability management, assessment tool. Commercial, Defense, Multi-platform
Real Intelligence Threat Analytics RITA is an open source framework for network traffic analysis and threat hunting. Free, Open Source, Defense, Windows, Linux, macOS, Multi-platform
Reg The reg utility reads and writes to the Windows registry from the command line. Commercial, Offense, Defense, Utility, Windows
Regshot Regshot is a snapshot recording tool for Windows. It allows you to record a snapshot of the registry and optionally the file system at two points in time. Regshot provides a high level summary of the changes, showing the registry keys that were added, removed, and modified. It will also summarize the files that were added, removed, and modified. Free, Open Source, Utility, Windows
Request Tracker for Incident Response (RTIR) RTIR is a free tool for incident response management and tracking. Free, Open Source, Defense, Multi-platform
Responder Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. Responder is commonly used to steal authentication credentials from Windows victims on the LAN through the LLMNR protocol. Free, Open Source, Offense, Windows, Linux, macOS
Reverse Whois Lookup Gather limited domain information (domain name, creation date, and registrar) using a registrant name or email address Free, Offense, Cloud Service
Rpcclient Interrogate Windows RPC services from Linux. Free, Open Source, Utility, Linux
Rubber Ducky USB hardware device that acts as a keyboard, sending scripted keystroke attack combinations to the target system. Commercial, Offense, Multi-platform, Hardware

S

Tool Description Tags
s3logparse Summarize and collect data from AWS S3 logs. Free, Open Source, Defense, Utility, Multi-platform
SAINT Security Suite SAINT Security Suite provides a fully-integrated set of capabilities to assess your network assets for the latest vulnerabilities across a wide variety of operating systems, software applications, databases, network devices and configurations. Commercial, Defense, Multi-platform
Samba Collection of tools to interact with Windows systems from Linux. Free, Open Source, Offense, Utility, Linux
sc Service Control, control Windows services from the command line. Commercial, Offense, Defense, Utility, Windows
Schtasks Schtasks is a Windows built-in utility for managing scheduled tasks. Commercial, Offense, Defense, Utility, Windows
ScoutSuite ScoutSuite is a dedicated vulnerability assessment tool for cloud environments Free, Open Source, Offense, Defense, Multi-platform
Secretsdump.py Part of Impacket, secretsdump.py extracts password hash information from the Windows domain SAM file and SYSTEM hive (typically from the output of ntdsutil). Free, Open Source, Offense, Windows, Linux, macOS
SecuritySpace Online vulnerability assessment/network security auditing services including network monitoring and notification. Commercial, Cloud Service
services.msc Services.msc is the command to open the snap-in control panel for managing Windows services in a GUI interface. Commercial, Defense, Utility, Windows
SharpView Interrogate Windows properties including users, platforms, domain settings, and more. Free, Open Source, Offense, Windows
SHODAN Use Shodan to discover Internet devices including vulnerable platforms and systems. Free, Commercial, Cloud Service
Smbclient FTP-like client to access SMB/CIFS resources on servers and to interrogate Windows settings. Free, Open Source, Offense, Utility, Linux
SpiderFoot SpiderFoot collets OSINT data from hundreds of online sources, using the collected data to seed additional searches. Free, Open Source, Offense, Windows, Linux, macOS
Sqlmap Sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws. Free, Open Source, Defense, Windows, Linux, macOS, Multi-platform
Squid Squid is a popular open source web proxy tool. Free, Open Source, Defense, Windows, Linux, macOS
SRUM-Dump A forensics tool to convert the data in the Windows SRUM (System Resource Usage Monitor) database to an xlsx spreadsheet. Free, Open Source, Defense, Windows
Streams Streams, part of SysInternals, is a tool to identify the presence of ADS data on Windows systems. Free, Utility, Windows
Strings (Linux) The Linux strings utility extracts plaintext strings from a specified file, supporting both ASCII and UTF-16 string data. Free, Open Source, Defense, Utility, Linux
Strings (Windows) The Strings utility for Windows is part of the SysInternals suite of tools. Strings can extract ASCII and UTF-16 string values from an arbitrary file. Free, Defense, Utility, Windows
Sudo Sudo is a program for Unix-like computer operating systems that allows users to run programs with the security privileges of another user. Free, Open Source, Utility, Linux, macOS
Swipe Remove logging evidence from binary UNIX and Linux authentication log files (btmp, wtmp, atmp, lastlog, atmp). Free, Open Source, Offense, Linux
SysInternals Sysinternals is a collection of tools to perform advanced management, diagnostics, troubleshooting, and monitoring in a Microsoft Windows environment. Free, Defense, Utility, Windows
systemctl Control Linux services. Free, Open Source, Offense, Defense, Linux

T

Tool Description Tags
Tasklist Tasklist is a built-in Windows tool that enumerates running processes and services. Commercial, Offense, Defense, Utility, Windows
Tcpdump Tcpdump is a command line network packet capture and analysis tool. Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS
TCPView TCPView is part of the Microsoft SysInternals suite of tools that will show you detailed listings of all TCP and UDP endpoints on your system, including the local and remote addresses and state of TCP connections. Free, Defense, Utility, Windows
TLS-Scan TLS-Scan by Binu Ramakrishnan is a network scanning tool to extract SSL and TLS certificate details from servers, saving the output as a JSON file. TLS-Scan can be useful for identifying attribution for a server based on certificate details including the organization name and common name fields. Free, Open Source, Offense, Utility, Linux, macOS
Tshark Tshark is a command line version of Wireshark. Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS

U

Tool Description Tags
Unshadow Included with John the Ripper, unshadow merges the password and shadow files into a single unified file for password cracking efficiency. Free, Open Source, Offense, Utility, Windows, Linux, macOS, Multi-platform
US Government SEC Database The US Government Securities and Exchange Commission (SEC) can be a useful information source for collecting data for publicly traded US companies. Free, Offense, Defense, Cloud Service
useradd Useradd is a Linux tool to add new user accounts to the system. Free, Open Source, Offense, Defense, Utility, Linux

V

Tool Description Tags
Velociraptor Velociraptor uses client endpoint software to collect and report information on Windows, Linux, and macOS systems Free, Open Source, Defense, Windows, Linux, macOS
Volatility Volatility is an open-source memory forensics framework. Free, Open Source, Defense, Windows, Linux, macOS
vpc-flow-log-analysis Visualize AWS VPC flow logs; original source at https://github.com/FlorianPfisterer/vpc-flow-log-analysis (URL cited includes features added by Joshua Wright) Free, Open Source, Commercial, Defense, Windows, Linux, macOS

W

Tool Description Tags
w3af w3af is a Web Application Attack and Audit Framework. Free, Open Source, Offense, Windows, Linux, macOS
WarVOX WarVOX was a free, open-source VOIP-based war dialing tool for exploring, classifying, and auditing phone systems. Free, Open Source, Offense, Linux
Wevtutil Wevtutil is a command line tool that comes with Windows for managing event log data including purging event logs. Commercial, Offense, Defense, Utility, Windows
wget Web Get; retrieve content from a specified URL. Free, Open Source, Offense, Defense, Utility, Windows, Linux, macOS
whois Linux utility to interrogate DNS registration data. Utility, Linux, macOS
Wi-Fi Pineapple The WiFi Pineapple is an integrated Linux system and Wi-Fi attack platform in a small hardware form-factor. Commercial, Offense, Hardware
Windows Credential Editor Windows Credentials Editor (WCE) is a security tool to list logon sessions and add, change, list and delete associated credentials (ex.: LM/NT hashes, plaintext passwords and Kerberos tickets). Free, Open Source, Offense, Windows
Windump Windump is a port of the TCPDump tool to Windows. Free, Open Source, Offense, Defense, Utility, Windows
Wireshark Wireshark is the world’s foremost and widely-used network protocol analyzer. Free, Open Source, Offense, Defense, Windows, Linux, macOS, Multi-platform
wmic Windows Management Instrumentation Console, access several components of Windows systems and functionality form the command line. Commercial, Offense, Defense, Utility, Windows

X

Tool Description Tags
xlek xlek is a resource to search millions of online data records for free. Free, Offense, Defense, Cloud Service

Z

Tool Description Tags
ZAP Proxy Cross-platform web proxy for inspecting, attacking web sites and clients. Free, Open Source, Offense, Windows, Linux, macOS, Multi-platform
Zeek Zeek is a free and open-source software network analysis framework. Zeek logging data is used to supply RITA with data for network threat hunting analysis. Free, Open Source, Defense, Windows, Linux, macOS
Zenmap GUI front-end and visualization tool for Nmap. Free, Open Source, Offense, Windows, Linux, macOS