Categories
- Information Gathering
- Vulnerability Analysis
- Exploitation Tools
- Wireless Attacks
- Forensics Tools
- Web Applications
- Stress Testing
- Sniffing & Spoofing
- Password Attacks
- Maintaining Access
- Hardware Hacking
- Reverse Engineering
- Reporting Tools
- New Release Tools on Kali 2021.1
Information Gathering
- ace-voip
- Amap
- APT2
- arp-scan
- Uses the ARP protocol to discover and fingerprint IP hosts on the network layer 2 segment [Link].
- Automater
- bing-ip2hosts
- braa
- CaseFile
- CDPSnarf
- cisco-torch
- copy-router-config
- DMitry
- dnmap
- dnsenum
- dnsmap
- DNSRecon
- dnstracer
- dnswalk
- DotDotPwn
- enum4linux
- Combines the Samba tools smbclient, rpclient, net, and nmblookup for enumeration [Link].
- enumIAX
- EyeWitness
- Automates taking screenshots of websites and captures server headers [Link].
- Faraday
- Fierce
- Firewalk
- fragroute
- fragrouter
- Ghost Phisher
- GoLismero
- goofile
- hping3
- ident-user-enum
- InSpy
- InTrace
- iSMTP
- lbd
- Maltego Teeth
- masscan
- Mass SYN stealth scanner, faster and more aggressive than Nmap [Link].
- Metagoofil
- Miranda
- nbtscan-unixwiz
- Nikto
- Web server vulnerability scanner [Link].
- Nmap
- Powerful network scanner [Link].
- ntop
- OSRFramework
- p0f
- Parsero
- Recon-ng
- A web reconnaissance framework designed for open source web-based intelligence gathering [Link].
- SET
- The Social Engineering Toolkit is an open-source penetration testing framework with a large number of custom attack vectors [Link].
- SMBMap
- Allows users to enumerate Samba share drives across an entire domain [Link].
- smtp-user-enum
- snmp-check
- SPARTA
- sslcaudit
- SSLsplit
- sslstrip
- SSLyze
- Sublist3r
- Enumerates subdomains of websites using OSINT [Link].
- THC-IPV6
- theHarvester
- TLSSLed
- twofi
- Unicornscan
- URLCrazy
- Wireshark
- WOL-E
- Xplico
Vulnerability Analysis
- BBQSQL
- BED
- cisco-auditing-tool
- cisco-global-exploiter
- cisco-ocs
- cisco-torch
- copy-router-config
- Doona
- DotDotPwn
- HexorBase
- jSQL Injection
- Lynis
- An auditing tool for Unix-based systems that performs many security control checks [Link].
- Nmap
- A library of scripts that use Nmap to analyze networks and their devices. See also the Nmap Scripting Engine [Link].
- ohrwurm
- openvas
- A framework of services and tools for vulnerability scanning and management [Link].
- Oscanner
- Powerfuzzer
- sfuzz
- SidGuesser
- SIPArmyKnife
- sqlmap
- Automates the detection and exploitation of SQL injection flaws and database server takeover [Link].
- Sqlninja
- A SQL injection tool that targets web applications backed by a SQL Server database [Link].
- sqlsus
- An open-source MySQL injection and takeover tool [Link].
- THC-IPV6
- tnscmd10g
- unix-privesc-check
- Yersinia
- A DHCP starvation attack tool. Once attached, it can disable the DHCP server and take its place on the network, typically assigning itself as the DNS server and redirecting users to malicious websites, among other network protocol attacks [Link].
Exploitation Tools
- Armitage
- Graphical interface for MSF [Link].
- Backdoor Factory
- BeEF
- A penetration testing tool focused on the web browser. It can exploit web vulnerabilities and includes phishing features that mimic login pages for services like Gmail or Facebook [Link].
- cisco-auditing-tool
- cisco-global-exploiter
- cisco-ocs
- cisco-torch
- Commix
- crackle
- exploitdb
- A local archive of publicly known exploits [Link].
- jboss-autopwn
- Linux Exploit Suggester
- Maltego Teeth
- Metasploit Framework
- Metasploit (MSF) is the most widely used penetration testing framework [Documentation].
- MSFPC
- RouterSploit
- SET
- The Social Engineering Toolkit is an open-source penetration testing framework with a large number of custom attack vectors [Link].
- ShellNoob
- sqlmap
- Automates the detection and exploitation of SQL injection flaws and database server takeover [Link].
- THC-IPV6
- Yersinia
- A DHCP starvation attack tool. Once attached, it can disable the DHCP server and take its place on the network, typically assigning itself as the DNS server and redirecting users to malicious websites [Link].
Wireless Attacks
- Airbase-ng
- Aircrack-ng
- An 802.11 WEP and WPA-PSK key cracking program that recovers keys from captured packets.
- Airdecap-ng and Airdecloak-ng
- Aireplay-ng
- Injects wireless frames to generate traffic for cracking WEP and WPA-PSK keys. Also deauthenticates wireless clients to capture WPA 4-way handshakes.
- airgraph-ng
- Airmon-ng
- Enables and disables monitor mode on wireless interfaces.
- Airodump-ng
- Captures raw 802.11 frames. Can collect WEP IVs and WPA2 4-way handshakes.
- airodump-ng-oui-update
- Airolib-ng
- Airserv-ng
- Airtun-ng
- Asleap
- Besside-ng
- Bluelog
- BlueMaho
- Bluepot
- BlueRanger
- Bluesnarfer
- Bully
- coWPAtty
- crackle
- eapmd5pass
- Easside-ng
- Fern Wifi Cracker
- FreeRADIUS-WPE
- Ghost Phisher
- GISKismet
- Gqrx
- gr-scan
- hostapd-wpe
- ivstools
- kalibrate-rtl
- KillerBee
- Kismet
- makeivs-ng
- mdk3
- Exploits common Wi-Fi weaknesses, including brute-force hidden SSID discovery, beacon flooding, authentication DoS, WPA downgrade, and continuous traffic disruption.
- mfcuk
- mfoc
- mfterm
- Multimon-NG
- Packetforge-ng
- PixieWPS
- Pyrit
- Reaver
- redfang
- RTLSDR Scanner
- Spooftooph
- Tkiptun-ng
- Wesside-ng
- Wifi Honey
- wifiphisher
- Wifitap
- Wifite
- wpaclean
Forensics Tools
- Binwalk
- A tool for analyzing, reverse engineering, and extracting firmware images [Link].
- bulk-extractor
- Capstone
- chntpw
- Cuckoo
- dc3dd
- ddrescue
- A data recovery tool for drives with damaged sectors and blocks [Link].
- DFF
- diStorm3
- Dumpzilla
- extundelete
- Foremost
- Recovers files from disk or image files based on headers and footers [Link].
- Galleta
- Guymager
- iPhone Backup Analyzer
- p0f
- pdf-parser
- pdfid
- pdgmail
- peepdf
- RegRipper
- Volatility
- Xplico
Web Applications
- apache-users
- Arachni
- BBQSQL
- BlindElephant
- Burp Suite
- CutyCapt
- DAVTest
- deblaze
- DIRB
- DirBuster
- A multi-threaded Java application for brute-forcing directories and file names on web and application servers [Link].
- fimap
- FunkLoad
- Gobuster
- Brute-forces and discovers directories, files, and subdomains [Link].
- Grabber
- A web spider/crawler that tests for SQL injection and cross-site scripting (XSS).
- hURL
- jboss-autopwn
- joomscan
- jSQL Injection
- Maltego Teeth
- Nikto
- Web server vulnerability scanner [Link].
- PadBuster
- Paros
- Parsero
- plecost
- Powerfuzzer
- ProxyStrike
- Recon-ng
- A web reconnaissance framework designed for open source web-based intelligence gathering [Link].
- Skipfish
- A web spider/crawler that tests for vulnerable parameters and configurations.
- sqlmap
- Automates the detection and exploitation of SQL injection flaws and database server takeover [Link].
- Sqlninja
- A SQL injection tool that targets web applications backed by a SQL Server database [Link].
- sqlsus
- An open-source MySQL injection and takeover tool [Link].
- ua-tester
- Uniscan
- w3af
- WebScarab
- Webshag
- WebSlayer
- WebSploit
- Wfuzz
- A fuzzing tool for testing web applications [Link].
- WhatWeb
- Fingerprints websites by identifying blogging platforms, analytics packages, JavaScript libraries, web servers, embedded devices, and more [Link].
- WPScan
- WordPress security scanner [Link].
- XSSer
- An automated framework for detecting, exploiting, and reporting XSS vulnerabilities in web applications.
- zaproxy
- The OWASP Zed Attack Proxy (ZAP) is an easy-to-use integrated penetration testing tool for finding vulnerabilities in web applications [Link].
Stress Testing
- DHCPig
- FunkLoad
- iaxflood
- Inundator
- inviteflood
- ipv6-toolkit
- mdk3
- Exploits common Wi-Fi weaknesses, including brute-force hidden SSID discovery, beacon flooding, authentication DoS, WPA downgrade, and continuous traffic disruption.
- Reaver
- rtpflood
- SlowHTTPTest
- t50
- Termineter
- THC-IPV6
- THC-SSL-DOS
Sniffing & Spoofing
- bettercap
- An alternative to Ettercap with additional features including Wi-Fi support [Link].
- Burp Suite
- DNSChef
- fiked
- hamster-sidejack
- HexInject
- iaxflood
- inviteflood
- iSMTP
- isr-evilgrade
- mitmproxy
- ohrwurm
- protos-sip
- rebind
- responder
- Built into Kali, it poisons the Windows network by responding to any broadcast request and immediately requesting the credential hash. This attack is known as LLMNR/NBT-NS/DNS/MDNS poisoning [Link].
- rtpbreak
- rtpinsertsound
- rtpmixsound
- sctpscan
- SIPArmyKnife
- SIPp
- SIPVicious
- SniffJoke
- SSLsplit
- sslstrip
- THC-IPV6
- VoIPHopper
- WebScarab
- Wifi Honey
- Wireshark
- The Swiss Army knife of packet sniffers [Link].
- xspy
- Yersinia
- A DHCP starvation attack tool. Once attached, it can disable the DHCP server and take its place on the network, typically assigning itself as the DNS server and redirecting users to malicious websites, among other network protocol attacks [Link].
- zaproxy
- The OWASP Zed Attack Proxy (ZAP) is an easy-to-use integrated penetration testing tool for finding vulnerabilities in web applications [Link].
Password Attacks
- BruteSpray
- Burp Suite
- CeWL
- chntpw
- cisco-auditing-tool
- CmosPwd
- creddump
- crowbar
- crunch
- findmyhash
- gpp-decrypt
- Decrypts and extracts passwords from Group Policy Preferences (GPP) files.
- hash-identifier
- Identifies the hash type from a sample.
- Hashcat
- A fast password cracker and recovery tool. Supports algorithms including LM, MD4, MD5, SHA-family, Unix Crypt, MySQL, Cisco PIX, and more [Link].
- HexorBase
- THC-Hydra
- A brute-force login cracker supporting many protocols including HTTP, FTP, and SSH [Link].
- John the Ripper
- Brute-force password hash cracker [Link].
- Johnny
- keimpx
- Maltego Teeth
- Maskprocessor
- multiforcer
- Ncrack
- A high-speed network authentication cracking tool developed by the Nmap team [Link].
- oclgausscrack
- ophcrack
- PACK
- patator
- phrasendrescher
- polenum
- RainbowCrack
- rcracki-mt
- RSMangler
- SecLists
- A collection of lists (such as password lists) used during security assessments, all in one place [Link].
- SQLdict
- Statsprocessor
- THC-pptp-bruter
- TrueCrack
- WebScarab
- wordlists
- zaproxy
- The OWASP Zed Attack Proxy (ZAP) is an easy-to-use integrated penetration testing tool for finding vulnerabilities in web applications [Link].
Maintaining Access
- CryptCat
- Cymothoa
- dbd
- dns2tcp
- HTTPTunnel
- Intersect
- Nishang
- polenum
- PowerSploit
- A collection of PowerShell scripts for post-exploitation, usable with Evil-WinRM [Link].
- pwnat
- RidEnum
- sbd
- shellter
- U3-Pwn
- Webshells
- Weevely
- Winexe
Hardware Hacking
- android-sdk
- apktool
- A reverse engineering tool that decompiles Android APK files [Link].
- Arduino
- dex2jar
- Sakis3G
- smali
Reverse Engineering
- apktool
- A reverse engineering tool that decompiles Android APK files [Link].
- dex2jar
- diStorm3
- edb-debugger
- jad
- javasnoop
- JD-GUI
- OllyDbg
- smali
- Valgrind
- YARA
Reporting Tools
New Release Tools on Kali 2021.1
- Airgeddon
- Audits wireless networks.
- AltDNS
- Generates permutations, alterations, and mutations of subdomains, then resolves them.
- Arjun
- HTTP parameter discovery suite.
- Chisel
- A fast TCP/UDP tunnel over HTTP and WebSocket [Link].
- DNSGen
- Generates combinations of domain names from provided input.
- DumpsterDiver
- Searches for secrets in various file types.
- GetAllUrls
- Fetches known URLs from AlienVault’s Open Threat Exchange, the Wayback Machine, and Common Crawl.
- GitLeaks
- Searches a Git repository’s history for secrets and keys.
- HTTProbe
- Takes a list of domains and probes for working HTTP and HTTPS servers.
- MassDNS
- A high-performance DNS stub resolver for bulk lookups and reconnaissance [Link].
- PSKracker
- A WPA/WPS toolkit for generating default keys and PINs.
- WordlistRaider
- Prepares existing wordlists.
New Release Tools on Kali 2022.1
- dnsx
- A multi-purpose DNS toolkit for running multiple DNS queries.
- email2phonenumber
- An OSINT tool for finding a target’s phone number from their email address.
- naabu
- A simple and reliable port scanner.
- nuclei
- Template-based targeted scanning.
- PoshC2
- A proxy-aware C2 framework with post-exploitation and lateral movement capabilities.
- proxify
- A Swiss Army knife proxy tool for capturing, manipulating, and replaying HTTP/HTTPS traffic.
New Release Tools on Kali 2023.1
- Arkime
- Packet capture.
- CyberChef
- Encryption tool.
- DefectDojo
- Vulnerability data reporting.
- Dscan
- Scanner.
- Kubernetes-Helm
- Kubernetes package manager.
- PACK2
- Attack tool.
- Redeye
- Analytics tool.
- Unicrypto
- Cryptographic libraries.
- Ciphey
New Release Tools on Kali 2024.1
- blue-hydra
- Bluetooth device discovery service.
- opentaxii
- TAXII server implementation from EclecticIQ.
- readpe
- Command-line tools for manipulating Windows PE files.
- snort
- Flexible network intrusion detection system.
The list of tools was taken from Kali’s official website [Link], but any comments or observations are personal and may not reflect the truth.