InSkillSecArsenal
Arsenal
62 tools that do the actual work on an engagement, ordered by the phase you reach for them. Every entry says what the tool is for and links to the course that teaches it. See the course catalog

Reconnaissance
Map the target without touching it: domains, people, exposed assets.
8 toolsAmass
Deep subdomain enumeration from dozens of passive sources at once.
Taught in OSINT AutomationSubfinder
Fast passive subdomain discovery, built for large scopes.
Taught in OSINT AutomationtheHarvester
Collects e-mails, names and hosts from public search engines.
Taught in OSINT AutomationRecon-ng
Modular OSINT framework that stores findings in a workspace database.
Taught in OSINT AutomationMaltego
Graphs relationships between people, domains and infrastructure.
Taught in OSINT AutomationShodan
Search engine for exposed devices, banners and forgotten services.
Taught in OSINT AutomationSpiderFoot
Automates 200+ OSINT modules against a single target.
Taught in OSINT AutomationSocial-Engineer Toolkit
Builds phishing pages and pretexts for authorised awareness tests.
Taught in Social Engineering
Scanning & enumeration
Find what listens, what version it runs, and where it is weak.
7 toolsNmap
The reference port scanner, with a scripting engine for enumeration.
Taught in Nmap AdvancedMasscan
Sweeps an entire /8 in minutes when Nmap would take days.
Taught in Nmap AdvancedRustScan
Finds open ports fast, then hands them to Nmap for the details.
Taught in Nmap AdvancedNuclei
Template-driven scanner for known exposures across many hosts.
Taught in Advanced Web AttacksNessus
Commercial vulnerability scanner, the baseline in most audit reports.
Taught in Advanced Penetration TestingOpenVAS
Open-source vulnerability scanner with its own feed of checks.
Taught in Advanced Penetration Testingenum4linux-ng
Pulls shares, users and policies out of SMB and LDAP services.
Taught in Active Directory Attacks
Exploitation
Turn a finding into an authenticated foothold.
9 toolsMetasploit Framework
Exploits, payloads and post modules in one console.
Taught in Metasploit Prosqlmap
Automates SQL injection detection all the way to shell access.
Taught in Web HackingHydra
Online password attacks against dozens of network protocols.
Taught in Cryptography AttacksHashcat
GPU-accelerated hash cracking with rules and masks.
Taught in Cryptography AttacksJohn the Ripper
Cracks a very wide range of hash formats, CPU-first.
Taught in Cryptography AttacksImpacket
Python implementations of SMB, Kerberos and MSRPC you can script.
Taught in Active Directory AttacksNetExec
Sprays credentials and commands across a Windows network at scale.
Taught in Active Directory AttacksResponder
Poisons LLMNR and NBT-NS to capture and relay authentication.
Taught in Active Directory Attacksmsfvenom
Generates and encodes payloads for every target platform.
Taught in Advanced Payload Development
Post-exploitation
Escalate, harvest credentials, pivot, and hold the ground.
9 toolsMimikatz
Extracts credentials, tickets and secrets from Windows memory.
Taught in Active Directory AttacksBloodHound
Graphs Active Directory to reveal the shortest path to Domain Admin.
Taught in Active Directory AttacksRubeus
Kerberos abuse toolkit: roasting, delegation, ticket forging.
Taught in Active Directory AttackslinPEAS
Enumerates every local privilege-escalation path on Linux.
Taught in Linux ExploitationwinPEAS
Same idea on Windows: services, tokens, unquoted paths, secrets.
Taught in Windows ExploitationChisel
Tunnels TCP over HTTP to reach segmented internal networks.
Taught in Network PivotingLigolo-ng
Builds a real network interface into the target subnet, no SOCKS pain.
Taught in Network PivotingSliver
Modern open-source command-and-control with mTLS implants.
Taught in C2 Framework DevelopmentCovenant
.NET command-and-control framework with a collaborative interface.
Taught in C2 Framework Development
Web & API
Intercept, fuzz and break applications and their endpoints.
8 toolsBurp Suite
The proxy every web test runs through: intercept, repeat, fuzz.
Taught in Burp Suite ProOWASP ZAP
Free intercepting proxy and scanner, scriptable for CI pipelines.
Taught in OWASP ZAP Proffuf
Fuzzes paths, parameters and hosts at very high request rates.
Taught in Advanced Web Attacksgobuster
Brute-forces directories, DNS names and virtual hosts.
Taught in Web HackingNikto
Quick sweep for dangerous files, stale software and misconfigurations.
Taught in Web HackingPostman
Replays and tampers with REST and GraphQL calls collection by collection.
Taught in REST API PenetrationGraphQL Voyager
Renders an introspected schema so you can see what is reachable.
Taught in GraphQL Securityjwt_tool
Inspects, tampers with and cracks JSON Web Tokens.
Taught in Web Authentication Attacks
Wireless & hardware
Attack what travels through the air and what you can hold.
7 toolsAircrack-ng
The classic Wi-Fi suite: capture, replay, crack WEP and WPA.
Taught in WiFi Security — From Zero to Pentesterhcxdumptool
Captures PMKID and handshakes straight into a Hashcat-ready file.
Taught in WiFi Security — From Zero to PentesterKismet
Passive wireless survey across Wi-Fi, Bluetooth and more.
Taught in WiFi Security — From Zero to PentesterBettercap
Swiss army knife for network and wireless man-in-the-middle.
Taught in Bluetooth HackingHackRF One
Software-defined radio to listen to and replay 1 MHz-6 GHz signals.
Taught in SDR & Radio HackingProxmark3
Reads, clones and emulates RFID and NFC access badges.
Taught in Hardware HackingBus Pirate
Talks UART, SPI and I2C to the chips on a board you opened.
Taught in Hardware Hacking
Cloud & containers
Audit IAM, buckets, clusters and images before someone else does.
6 toolsPacu
AWS exploitation framework: enumerate, escalate, persist.
Taught in AWS Penetration TestingScoutSuite
Multi-cloud security audit that reports on IAM, storage and network.
Taught in Cloud Penetration FundamentalsROADtools
Explores Entra ID (Azure AD) relationships the way BloodHound does AD.
Taught in Azure Penetration Testingkube-hunter
Hunts for exposed Kubernetes components and weak defaults.
Taught in Container EscapeTrivy
Scans images, filesystems and IaC for known vulnerabilities.
Taught in Container Escape AdvancedPeirates
Post-exploitation inside a pod: steal tokens, move across the cluster.
Taught in Container Escape
Analysis & forensics
Read traffic, binaries and memory to understand what happened.
8 toolsWireshark
Dissects captured traffic packet by packet, protocol by protocol.
Taught in Wireshark Masterytcpdump
Captures on the wire from any shell, no interface needed.
Taught in Wireshark MasteryGhidra
Free decompiler that turns machine code back into readable C.
Taught in Reverse EngineeringIDA Free
The industry disassembler, with the graph view everyone learned on.
Taught in Reverse Engineeringradare2
Scriptable reverse-engineering framework that lives in the terminal.
Taught in Reverse Engineeringx64dbg
Windows debugger for watching a binary misbehave in real time.
Taught in Buffer Overflow AdvancedVolatility
Rebuilds processes, connections and secrets from a memory dump.
Taught in Memory ForensicsAutopsy
Disk forensics workbench: timelines, deleted files, artefacts.
Taught in Memory ForensicsThese tools are listed for authorised testing and education. Running them against systems you do not own or have written permission to test is illegal in most jurisdictions.