| Name/link | Short description | free | Addition comments |
| nmap | Network scanning discovery tool | Y | |
| wireshark | Network scanning discovery tool | ||
| exploitdb | Database with vulnerability’s | ||
| nikto | Web server/application scanner | ||
| burp | Vulnerability scanning, penetration testing, and web app security platform | Y/N | Most of the good stuff in payed version only |
| sqlmap | SQL injection/ database takeover | Y | |
| aircrack-ng | Wifi security/cracking/testing toolkit | Y | |
| airdecap | With airdecap-ng you can decrypt WEP/WPA/WPA2 | Y | |
| packetforge | Create encrypted packets that canĀ be used for injection | Y | |
| aireplay | Generate traffic for the later use in aircrack-ng | Y | |
| L0pthCrack | Password auditing and recovery | ||
| ZAP | Web app scanner | Y | |
| R57 shell | PHP shell | ||
| Dirb | Web Content Scanner | ||
| Vega | Web security scanner and web security testing platform for webapplications | ||
| THC Hydra | Password Cracker | ||
| inj3ctor | Discover GET and POST parameter |