InSkillSecArsenal
Arsenal
62 herramientas que hacen el trabajo real en una auditoría, ordenadas por la fase en que se usan. Cada ficha explica su propósito y enlaza al curso que la enseña. Ver el catálogo de cursos

Reconocimiento
Cartografiar el objetivo sin tocarlo: dominios, personas, activos expuestos.
8 herramientasAmass
Deep subdomain enumeration from dozens of passive sources at once.
Se enseña en OSINT AutomationSubfinder
Fast passive subdomain discovery, built for large scopes.
Se enseña en OSINT AutomationtheHarvester
Collects e-mails, names and hosts from public search engines.
Se enseña en OSINT AutomationRecon-ng
Modular OSINT framework that stores findings in a workspace database.
Se enseña en OSINT AutomationMaltego
Graphs relationships between people, domains and infrastructure.
Se enseña en OSINT AutomationShodan
Search engine for exposed devices, banners and forgotten services.
Se enseña en OSINT AutomationSpiderFoot
Automates 200+ OSINT modules against a single target.
Se enseña en OSINT AutomationSocial-Engineer Toolkit
Builds phishing pages and pretexts for authorised awareness tests.
Se enseña en Social Engineering
Escaneo y enumeración
Encontrar qué escucha, en qué versión y por dónde cede.
7 herramientasNmap
The reference port scanner, with a scripting engine for enumeration.
Se enseña en Nmap AdvancedMasscan
Sweeps an entire /8 in minutes when Nmap would take days.
Se enseña en Nmap AdvancedRustScan
Finds open ports fast, then hands them to Nmap for the details.
Se enseña en Nmap AdvancedNuclei
Template-driven scanner for known exposures across many hosts.
Se enseña en Advanced Web AttacksNessus
Commercial vulnerability scanner, the baseline in most audit reports.
Se enseña en Advanced Penetration TestingOpenVAS
Open-source vulnerability scanner with its own feed of checks.
Se enseña en Advanced Penetration Testingenum4linux-ng
Pulls shares, users and policies out of SMB and LDAP services.
Se enseña en Active Directory Attacks
Explotación
Convertir un hallazgo en un acceso autenticado.
9 herramientasMetasploit Framework
Exploits, payloads and post modules in one console.
Se enseña en Metasploit Prosqlmap
Automates SQL injection detection all the way to shell access.
Se enseña en Web HackingHydra
Online password attacks against dozens of network protocols.
Se enseña en Cryptography AttacksHashcat
GPU-accelerated hash cracking with rules and masks.
Se enseña en Cryptography AttacksJohn the Ripper
Cracks a very wide range of hash formats, CPU-first.
Se enseña en Cryptography AttacksImpacket
Python implementations of SMB, Kerberos and MSRPC you can script.
Se enseña en Active Directory AttacksNetExec
Sprays credentials and commands across a Windows network at scale.
Se enseña en Active Directory AttacksResponder
Poisons LLMNR and NBT-NS to capture and relay authentication.
Se enseña en Active Directory Attacksmsfvenom
Generates and encodes payloads for every target platform.
Se enseña en Advanced Payload Development
Post-explotación
Escalar, recolectar credenciales, pivotar y mantener el terreno.
9 herramientasMimikatz
Extracts credentials, tickets and secrets from Windows memory.
Se enseña en Active Directory AttacksBloodHound
Graphs Active Directory to reveal the shortest path to Domain Admin.
Se enseña en Active Directory AttacksRubeus
Kerberos abuse toolkit: roasting, delegation, ticket forging.
Se enseña en Active Directory AttackslinPEAS
Enumerates every local privilege-escalation path on Linux.
Se enseña en Linux ExploitationwinPEAS
Same idea on Windows: services, tokens, unquoted paths, secrets.
Se enseña en Windows ExploitationChisel
Tunnels TCP over HTTP to reach segmented internal networks.
Se enseña en Network PivotingLigolo-ng
Builds a real network interface into the target subnet, no SOCKS pain.
Se enseña en Network PivotingSliver
Modern open-source command-and-control with mTLS implants.
Se enseña en C2 Framework DevelopmentCovenant
.NET command-and-control framework with a collaborative interface.
Se enseña en C2 Framework Development
Web y API
Interceptar, fuzzear y romper aplicaciones y sus endpoints.
8 herramientasBurp Suite
The proxy every web test runs through: intercept, repeat, fuzz.
Se enseña en Burp Suite ProOWASP ZAP
Free intercepting proxy and scanner, scriptable for CI pipelines.
Se enseña en OWASP ZAP Proffuf
Fuzzes paths, parameters and hosts at very high request rates.
Se enseña en Advanced Web Attacksgobuster
Brute-forces directories, DNS names and virtual hosts.
Se enseña en Web HackingNikto
Quick sweep for dangerous files, stale software and misconfigurations.
Se enseña en Web HackingPostman
Replays and tampers with REST and GraphQL calls collection by collection.
Se enseña en REST API PenetrationGraphQL Voyager
Renders an introspected schema so you can see what is reachable.
Se enseña en GraphQL Securityjwt_tool
Inspects, tampers with and cracks JSON Web Tokens.
Se enseña en Web Authentication Attacks
Inalámbrico y hardware
Atacar lo que viaja por el aire y lo que cabe en la mano.
7 herramientasAircrack-ng
The classic Wi-Fi suite: capture, replay, crack WEP and WPA.
Se enseña en WiFi Security — From Zero to Pentesterhcxdumptool
Captures PMKID and handshakes straight into a Hashcat-ready file.
Se enseña en WiFi Security — From Zero to PentesterKismet
Passive wireless survey across Wi-Fi, Bluetooth and more.
Se enseña en WiFi Security — From Zero to PentesterBettercap
Swiss army knife for network and wireless man-in-the-middle.
Se enseña en Bluetooth HackingHackRF One
Software-defined radio to listen to and replay 1 MHz-6 GHz signals.
Se enseña en SDR & Radio HackingProxmark3
Reads, clones and emulates RFID and NFC access badges.
Se enseña en Hardware HackingBus Pirate
Talks UART, SPI and I2C to the chips on a board you opened.
Se enseña en Hardware Hacking
Nube y contenedores
Auditar IAM, buckets, clústeres e imágenes antes que otro.
6 herramientasPacu
AWS exploitation framework: enumerate, escalate, persist.
Se enseña en AWS Penetration TestingScoutSuite
Multi-cloud security audit that reports on IAM, storage and network.
Se enseña en Cloud Penetration FundamentalsROADtools
Explores Entra ID (Azure AD) relationships the way BloodHound does AD.
Se enseña en Azure Penetration Testingkube-hunter
Hunts for exposed Kubernetes components and weak defaults.
Se enseña en Container EscapeTrivy
Scans images, filesystems and IaC for known vulnerabilities.
Se enseña en Container Escape AdvancedPeirates
Post-exploitation inside a pod: steal tokens, move across the cluster.
Se enseña en Container Escape
Análisis y forense
Leer tráfico, binarios y memoria para entender qué pasó.
8 herramientasWireshark
Dissects captured traffic packet by packet, protocol by protocol.
Se enseña en Wireshark Masterytcpdump
Captures on the wire from any shell, no interface needed.
Se enseña en Wireshark MasteryGhidra
Free decompiler that turns machine code back into readable C.
Se enseña en Reverse EngineeringIDA Free
The industry disassembler, with the graph view everyone learned on.
Se enseña en Reverse Engineeringradare2
Scriptable reverse-engineering framework that lives in the terminal.
Se enseña en Reverse Engineeringx64dbg
Windows debugger for watching a binary misbehave in real time.
Se enseña en Buffer Overflow AdvancedVolatility
Rebuilds processes, connections and secrets from a memory dump.
Se enseña en Memory ForensicsAutopsy
Disk forensics workbench: timelines, deleted files, artefacts.
Se enseña en Memory ForensicsEstas herramientas se listan para pruebas autorizadas y con fines educativos. Usarlas contra sistemas sin permiso escrito es ilegal en la mayoría de países.