InSkillSecArsenal
Arsenal
62 Werkzeuge, die die eigentliche Arbeit erledigen, geordnet nach der Phase, in der man sie braucht. Jeder Eintrag erklärt den Zweck und verlinkt den passenden Kurs. Zum Kurskatalog

Aufklärung
Das Ziel kartieren, ohne es zu berühren: Domains, Personen, exponierte Assets.
8 WerkzeugeAmass
Deep subdomain enumeration from dozens of passive sources at once.
Gelehrt in OSINT AutomationSubfinder
Fast passive subdomain discovery, built for large scopes.
Gelehrt in OSINT AutomationtheHarvester
Collects e-mails, names and hosts from public search engines.
Gelehrt in OSINT AutomationRecon-ng
Modular OSINT framework that stores findings in a workspace database.
Gelehrt in OSINT AutomationMaltego
Graphs relationships between people, domains and infrastructure.
Gelehrt in OSINT AutomationShodan
Search engine for exposed devices, banners and forgotten services.
Gelehrt in OSINT AutomationSpiderFoot
Automates 200+ OSINT modules against a single target.
Gelehrt in OSINT AutomationSocial-Engineer Toolkit
Builds phishing pages and pretexts for authorised awareness tests.
Gelehrt in Social Engineering
Scanning und Enumeration
Finden, was lauscht, in welcher Version, und wo es nachgibt.
7 WerkzeugeNmap
The reference port scanner, with a scripting engine for enumeration.
Gelehrt in Nmap AdvancedMasscan
Sweeps an entire /8 in minutes when Nmap would take days.
Gelehrt in Nmap AdvancedRustScan
Finds open ports fast, then hands them to Nmap for the details.
Gelehrt in Nmap AdvancedNuclei
Template-driven scanner for known exposures across many hosts.
Gelehrt in Advanced Web AttacksNessus
Commercial vulnerability scanner, the baseline in most audit reports.
Gelehrt in Advanced Penetration TestingOpenVAS
Open-source vulnerability scanner with its own feed of checks.
Gelehrt in Advanced Penetration Testingenum4linux-ng
Pulls shares, users and policies out of SMB and LDAP services.
Gelehrt in Active Directory Attacks
Exploitation
Aus einem Fund einen authentifizierten Zugang machen.
9 WerkzeugeMetasploit Framework
Exploits, payloads and post modules in one console.
Gelehrt in Metasploit Prosqlmap
Automates SQL injection detection all the way to shell access.
Gelehrt in Web HackingHydra
Online password attacks against dozens of network protocols.
Gelehrt in Cryptography AttacksHashcat
GPU-accelerated hash cracking with rules and masks.
Gelehrt in Cryptography AttacksJohn the Ripper
Cracks a very wide range of hash formats, CPU-first.
Gelehrt in Cryptography AttacksImpacket
Python implementations of SMB, Kerberos and MSRPC you can script.
Gelehrt in Active Directory AttacksNetExec
Sprays credentials and commands across a Windows network at scale.
Gelehrt in Active Directory AttacksResponder
Poisons LLMNR and NBT-NS to capture and relay authentication.
Gelehrt in Active Directory Attacksmsfvenom
Generates and encodes payloads for every target platform.
Gelehrt in Advanced Payload Development
Post-Exploitation
Rechte ausweiten, Zugangsdaten ernten, weiterspringen, Stellung halten.
9 WerkzeugeMimikatz
Extracts credentials, tickets and secrets from Windows memory.
Gelehrt in Active Directory AttacksBloodHound
Graphs Active Directory to reveal the shortest path to Domain Admin.
Gelehrt in Active Directory AttacksRubeus
Kerberos abuse toolkit: roasting, delegation, ticket forging.
Gelehrt in Active Directory AttackslinPEAS
Enumerates every local privilege-escalation path on Linux.
Gelehrt in Linux ExploitationwinPEAS
Same idea on Windows: services, tokens, unquoted paths, secrets.
Gelehrt in Windows ExploitationChisel
Tunnels TCP over HTTP to reach segmented internal networks.
Gelehrt in Network PivotingLigolo-ng
Builds a real network interface into the target subnet, no SOCKS pain.
Gelehrt in Network PivotingSliver
Modern open-source command-and-control with mTLS implants.
Gelehrt in C2 Framework DevelopmentCovenant
.NET command-and-control framework with a collaborative interface.
Gelehrt in C2 Framework Development
Web und API
Anwendungen und ihre Endpunkte abfangen, fuzzen und brechen.
8 WerkzeugeBurp Suite
The proxy every web test runs through: intercept, repeat, fuzz.
Gelehrt in Burp Suite ProOWASP ZAP
Free intercepting proxy and scanner, scriptable for CI pipelines.
Gelehrt in OWASP ZAP Proffuf
Fuzzes paths, parameters and hosts at very high request rates.
Gelehrt in Advanced Web Attacksgobuster
Brute-forces directories, DNS names and virtual hosts.
Gelehrt in Web HackingNikto
Quick sweep for dangerous files, stale software and misconfigurations.
Gelehrt in Web HackingPostman
Replays and tampers with REST and GraphQL calls collection by collection.
Gelehrt in REST API PenetrationGraphQL Voyager
Renders an introspected schema so you can see what is reachable.
Gelehrt in GraphQL Securityjwt_tool
Inspects, tampers with and cracks JSON Web Tokens.
Gelehrt in Web Authentication Attacks
Funk und Hardware
Angreifen, was durch die Luft geht und was man in der Hand hält.
7 WerkzeugeAircrack-ng
The classic Wi-Fi suite: capture, replay, crack WEP and WPA.
Gelehrt in WiFi Security — From Zero to Pentesterhcxdumptool
Captures PMKID and handshakes straight into a Hashcat-ready file.
Gelehrt in WiFi Security — From Zero to PentesterKismet
Passive wireless survey across Wi-Fi, Bluetooth and more.
Gelehrt in WiFi Security — From Zero to PentesterBettercap
Swiss army knife for network and wireless man-in-the-middle.
Gelehrt in Bluetooth HackingHackRF One
Software-defined radio to listen to and replay 1 MHz-6 GHz signals.
Gelehrt in SDR & Radio HackingProxmark3
Reads, clones and emulates RFID and NFC access badges.
Gelehrt in Hardware HackingBus Pirate
Talks UART, SPI and I2C to the chips on a board you opened.
Gelehrt in Hardware Hacking
Cloud und Container
IAM, Buckets, Cluster und Images prüfen, bevor es andere tun.
6 WerkzeugePacu
AWS exploitation framework: enumerate, escalate, persist.
Gelehrt in AWS Penetration TestingScoutSuite
Multi-cloud security audit that reports on IAM, storage and network.
Gelehrt in Cloud Penetration FundamentalsROADtools
Explores Entra ID (Azure AD) relationships the way BloodHound does AD.
Gelehrt in Azure Penetration Testingkube-hunter
Hunts for exposed Kubernetes components and weak defaults.
Gelehrt in Container EscapeTrivy
Scans images, filesystems and IaC for known vulnerabilities.
Gelehrt in Container Escape AdvancedPeirates
Post-exploitation inside a pod: steal tokens, move across the cluster.
Gelehrt in Container Escape
Analyse und Forensik
Verkehr, Binaries und Speicher lesen, um den Vorfall zu verstehen.
8 WerkzeugeWireshark
Dissects captured traffic packet by packet, protocol by protocol.
Gelehrt in Wireshark Masterytcpdump
Captures on the wire from any shell, no interface needed.
Gelehrt in Wireshark MasteryGhidra
Free decompiler that turns machine code back into readable C.
Gelehrt in Reverse EngineeringIDA Free
The industry disassembler, with the graph view everyone learned on.
Gelehrt in Reverse Engineeringradare2
Scriptable reverse-engineering framework that lives in the terminal.
Gelehrt in Reverse Engineeringx64dbg
Windows debugger for watching a binary misbehave in real time.
Gelehrt in Buffer Overflow AdvancedVolatility
Rebuilds processes, connections and secrets from a memory dump.
Gelehrt in Memory ForensicsAutopsy
Disk forensics workbench: timelines, deleted files, artefacts.
Gelehrt in Memory ForensicsDiese Werkzeuge sind für autorisierte Tests und Ausbildung aufgeführt. Der Einsatz gegen Systeme ohne schriftliche Erlaubnis ist in den meisten Ländern strafbar.