TOOLS Flashcards
BeEF
browser exploitation framework –> XSS & Injection
Netcat
TCP/UDP connections
Nikto
web application vulnerability scanner.
Androzer
test android apps
Swagger
API testing
open-source framework with large system of tools to design, build, doc, etc, REST Web Services
W3AF
open source we application security scanner
Shodan
cloud based tool for finding open ports and unpatched PCs
CeWL
CeWL (Custom Word List generator) is a ruby app which spiders a given URL, up to a specified depth, and returns a list of words which can then be used for password crackers such as John the Ripper. Optionally, CeWL can follow external links.
OpenVAS
open source vulnerability scanner
SET
social engineering toolkit
Reponder
Poisons LLMNR / NBT-NS/ MDNS traffic.
If a client/target cannot resolve a name via DNS it will fall back to name resolution via LLMNR (introduced in Windows Vista) and NBT-NS.
Responder is a toolkit that is used to answer NetBIOS queries from Windows systems on a network. Responder is a powerful tool when exploiting NetBIOS responses.
Mimikatz
a popular post-exploitation tool that dumps passwords, hashes, PINs, and Kerberos tickets from memory.
It also allows for pass-the-hash, pass-the-ticket, and the creation of Golden Kerberos tickets,
NCRACK
Ncrack is a very fast ONLINE password brute-force tool from the Nmap team.
But it can only be used for a limited set of protocols: • FTP • Telnet • SSH • RDP • VNC • HTTP(S) (basic authentication)
Hydra
Hydra is a brute-forcing tool that can crack systems using password guessing.
Maltego
OSINT
visualization of data relationships gathered from OSINT efforts.