You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
uniscan - useful for fingerprinting the webserver. The uniscan comes by default with Kali
nikto - useful for idetifying known web vulnerabilities. The nikto also comes by default with Kali. Start command: nikto -h example.com
subfinder - a passive tool to detect the subdomains of the domain by using several external source. Some sources requires API key.
Networking tools
nmap - tries to find the running services on the host. The nmap comes with Kali by default
netcat - swiss army knife for networking. The netcat comes with Kali by default
Social engineering tools
Trity - tool for social engineering
Wordlist
Assetnote organization provides list of wordlist. Link to the organization: here
crunch - can generate automatically the wordlist
Tips for KALI
In Kali you can change your MAC address
Exploitation tools
weevely - generate the PHP reverse shell script for file inclusion vulnerabilities. By default comes with KALI.
hydra - tool for the brute force attack
Windows
nishang - is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security, penetration testing and red teaming. Nishang is useful during all phases of penetration testing. Github link