Verified tool intelligence

    Offensive Security Tools

    Curated penetration testing and offensive security tools with verified official sources, practical workflows, limitations, and defensive context. Every profile separates official facts, editorial analysis, safe validation, and operational limitations.

    $ catalog --status
    18
    profiles
    9
    clusters
    last editorial pass: 2026-07-20
    security-tools.db --query
    Active

    Nmap

    Network discovery, service fingerprinting, and extensible security auditing

    ReconnaissanceNetwork
    open profile
    Active

    Burp Suite

    Integrated manual and automated web application security testing

    Web Application
    open profile
    Active

    Nuclei

    Template-driven vulnerability and exposure validation

    Web ApplicationReconnaissance
    open profile
    Active

    Metasploit Framework

    Modular exploit validation and security assessment framework

    Adversary Emulation
    open profile
    Active

    sqlmap

    Automated SQL injection detection and controlled validation

    Web Application
    open profile
    Active

    BloodHound

    Graph-based analysis of Active Directory and identity attack paths

    Active Directory
    open profile
    Active

    Impacket

    Python implementations of network protocols for security testing

    Active DirectoryNetwork
    open profile
    Active

    MobSF

    Automated static and dynamic analysis for mobile applications

    Mobile Security
    open profile
    Active

    Frida

    Dynamic instrumentation toolkit for applications and processes

    Mobile Security
    open profile
    Active

    Ghidra

    Software reverse-engineering framework with collaborative analysis

    Mobile Security
    open profile
    Active

    OWASP Amass

    Attack-surface mapping and external asset discovery

    Reconnaissance
    open profile
    Active

    Caido

    Modern intercepting proxy for web and API security testing

    Web Application
    open profile
    Active

    Wireshark

    Deep packet inspection and protocol analysis for networks and applications

    Network
    open profile
    Active

    OWASP ZAP

    Open-source web proxy and dynamic application security scanner

    Web Application
    open profile
    Active

    hashcat

    Hardware-accelerated offline password hash auditing and recovery

    Password Auditing
    open profile
    Active

    Semgrep Community Edition

    Pattern-based static analysis with readable, code-aware security rules

    Code Security
    open profile
    Active

    Trivy

    Vulnerability, misconfiguration, secret, license, and SBOM scanning

    Cloud & ContainerCode Security
    open profile
    Active

    MITRE CALDERA

    Automated adversary emulation and defensive control assessment

    Adversary Emulation
    open profile

    Verified sources

    Profiles lead with official projects, repositories, and documentation rather than copied release descriptions.

    Professional context

    Capabilities are balanced with limitations, evidence requirements, and defensive interpretation.

    Authorized research

    Examples use local labs, reserved addresses, or non-operational documentation commands.