Offensive Security Tools
Curated penetration testing and offensive security tools with verified official sources, practical workflows, limitations, and defensive context. Every profile separates official facts, editorial analysis, safe validation, and operational limitations.
Nmap
Network discovery, service fingerprinting, and extensible security auditing
Burp Suite
Integrated manual and automated web application security testing
Nuclei
Template-driven vulnerability and exposure validation
Metasploit Framework
Modular exploit validation and security assessment framework
sqlmap
Automated SQL injection detection and controlled validation
BloodHound
Graph-based analysis of Active Directory and identity attack paths
Impacket
Python implementations of network protocols for security testing
MobSF
Automated static and dynamic analysis for mobile applications
Frida
Dynamic instrumentation toolkit for applications and processes
Ghidra
Software reverse-engineering framework with collaborative analysis
OWASP Amass
Attack-surface mapping and external asset discovery
Caido
Modern intercepting proxy for web and API security testing
Wireshark
Deep packet inspection and protocol analysis for networks and applications
OWASP ZAP
Open-source web proxy and dynamic application security scanner
hashcat
Hardware-accelerated offline password hash auditing and recovery
Semgrep Community Edition
Pattern-based static analysis with readable, code-aware security rules
Trivy
Vulnerability, misconfiguration, secret, license, and SBOM scanning
MITRE CALDERA
Automated adversary emulation and defensive control assessment
Verified sources
Profiles lead with official projects, repositories, and documentation rather than copied release descriptions.
Professional context
Capabilities are balanced with limitations, evidence requirements, and defensive interpretation.
Authorized research
Examples use local labs, reserved addresses, or non-operational documentation commands.