Cybersecurity Tools Guide
Explore 43 tools for network discovery, security assessments, forensics, and defensive analysis. Follow each available link to the tool’s official site.
Use security testing tools only on systems you own or are authorized to assess. Listings are for reference; inclusion is not an endorsement or a claim that every tool was tested by LX5.
Network Scanning & Discovery
- Nmap
Advanced network mapping and vulnerability discovery tool.
Official site ↗ - Angry IP Scanner
Fast, lightweight IP address and port scanner.
Official site ↗ - Netcat
Utility for reading and writing data across network connections.
- Zenmap
GUI frontend for Nmap with profile support.
Vulnerability Scanners
- OpenVAS
Open-source vulnerability scanner.
Official site ↗ - Nikto
Web server vulnerability scanner.
Official site ↗ - Nessus
Professional vulnerability scanner with broad plugin support.
Official site ↗ - Wapiti
Web application vulnerability scanner.
Penetration Testing Frameworks
- Metasploit Framework
Framework for authorized exploit validation and testing.
Official site ↗ - BeEF
Browser security testing framework.
Official site ↗ - Canvas
Commercial penetration testing tool offering exploits and automation.
- Core Impact
Enterprise penetration testing platform.
Password Auditing Tools
- John the Ripper
Password recovery tool supporting many hash types.
Official site ↗ - Hashcat
GPU-accelerated password recovery.
Official site ↗ - Hydra
Online password auditing tool.
Official site ↗ - Cain & Abel
Legacy Windows password recovery tool.
Wireless Security Tools
- Aircrack-ng
Suite for auditing wireless networks.
Official site ↗ - Reaver
WPS security assessment tool.
- Kismet
Wireless network detector, sniffer, and IDS.
Official site ↗ - Wifite
Automated wireless security testing tool.
Web App Security Testing
- Burp Suite
Integrated platform for testing web application security.
Official site ↗ - OWASP ZAP
Open-source web app scanner with active and passive modes.
Official site ↗ - SQLMap
Automated SQL injection testing tool.
Official site ↗ - W3af
Web application attack and audit framework.
Forensics and Reverse Engineering
- Autopsy
GUI digital forensics platform based on Sleuth Kit.
Official site ↗ - Volatility
Memory forensics framework.
Official site ↗ - Binwalk
Firmware analysis tool.
- Radare2
Open-source reverse engineering framework.
Official site ↗
Packet Analysis
- Wireshark
Network protocol analyzer.
Official site ↗ - Tcpdump
Command-line packet analyzer.
- Ettercap
Network security testing and traffic analysis tool.
- Fiddler
HTTP debugging proxy.
Social Engineering Simulation
- Social-Engineer Toolkit (SET)
Framework for authorized social engineering simulations.
- Gophish
Open-source phishing awareness campaign framework.
Official site ↗ - King Phisher
Phishing simulation campaign tool.
- Evilginx2
Reverse-proxy phishing framework for controlled security research.
Other Specialized Tools
- Maltego
Graph-based link analysis and OSINT tool.
Official site ↗ - Recon-ng
Web reconnaissance framework.
- Shodan
Search engine for internet-connected devices.
Official site ↗ - Cuckoo Sandbox
Malware analysis sandbox.
Security Testing Operating Systems
- Kali Linux
Security testing distribution with a broad toolset.
Official site ↗ - Parrot Security OS
Distribution focused on security and forensics.
Official site ↗ - BackBox Linux
Ubuntu-based distribution for security assessments.
Official site ↗