InSkillSecArsenal
Arsenal
62 outils qui font le vrai travail sur une mission, rangés selon la phase où vous les sortez. Chaque fiche dit à quoi sert l'outil et renvoie vers le cours qui l'enseigne. Voir le catalogue de cours

Reconnaissance
Cartographier la cible sans y toucher : domaines, personnes, actifs exposés.
8 outilsAmass
Deep subdomain enumeration from dozens of passive sources at once.
Enseigné dans OSINT AutomationSubfinder
Fast passive subdomain discovery, built for large scopes.
Enseigné dans OSINT AutomationtheHarvester
Collects e-mails, names and hosts from public search engines.
Enseigné dans OSINT AutomationRecon-ng
Modular OSINT framework that stores findings in a workspace database.
Enseigné dans OSINT AutomationMaltego
Graphs relationships between people, domains and infrastructure.
Enseigné dans OSINT AutomationShodan
Search engine for exposed devices, banners and forgotten services.
Enseigné dans OSINT AutomationSpiderFoot
Automates 200+ OSINT modules against a single target.
Enseigné dans OSINT AutomationSocial-Engineer Toolkit
Builds phishing pages and pretexts for authorised awareness tests.
Enseigné dans Social Engineering
Balayage et énumération
Trouver ce qui écoute, dans quelle version, et où ça cède.
7 outilsNmap
The reference port scanner, with a scripting engine for enumeration.
Enseigné dans Nmap AdvancedMasscan
Sweeps an entire /8 in minutes when Nmap would take days.
Enseigné dans Nmap AdvancedRustScan
Finds open ports fast, then hands them to Nmap for the details.
Enseigné dans Nmap AdvancedNuclei
Template-driven scanner for known exposures across many hosts.
Enseigné dans Advanced Web AttacksNessus
Commercial vulnerability scanner, the baseline in most audit reports.
Enseigné dans Advanced Penetration TestingOpenVAS
Open-source vulnerability scanner with its own feed of checks.
Enseigné dans Advanced Penetration Testingenum4linux-ng
Pulls shares, users and policies out of SMB and LDAP services.
Enseigné dans Active Directory Attacks
Exploitation
Transformer une trouvaille en accès authentifié.
9 outilsMetasploit Framework
Exploits, payloads and post modules in one console.
Enseigné dans Metasploit Prosqlmap
Automates SQL injection detection all the way to shell access.
Enseigné dans Web HackingHydra
Online password attacks against dozens of network protocols.
Enseigné dans Cryptography AttacksHashcat
GPU-accelerated hash cracking with rules and masks.
Enseigné dans Cryptography AttacksJohn the Ripper
Cracks a very wide range of hash formats, CPU-first.
Enseigné dans Cryptography AttacksImpacket
Python implementations of SMB, Kerberos and MSRPC you can script.
Enseigné dans Active Directory AttacksNetExec
Sprays credentials and commands across a Windows network at scale.
Enseigné dans Active Directory AttacksResponder
Poisons LLMNR and NBT-NS to capture and relay authentication.
Enseigné dans Active Directory Attacksmsfvenom
Generates and encodes payloads for every target platform.
Enseigné dans Advanced Payload Development
Post-exploitation
Élever ses droits, moissonner les identifiants, rebondir et tenir le terrain.
9 outilsMimikatz
Extracts credentials, tickets and secrets from Windows memory.
Enseigné dans Active Directory AttacksBloodHound
Graphs Active Directory to reveal the shortest path to Domain Admin.
Enseigné dans Active Directory AttacksRubeus
Kerberos abuse toolkit: roasting, delegation, ticket forging.
Enseigné dans Active Directory AttackslinPEAS
Enumerates every local privilege-escalation path on Linux.
Enseigné dans Linux ExploitationwinPEAS
Same idea on Windows: services, tokens, unquoted paths, secrets.
Enseigné dans Windows ExploitationChisel
Tunnels TCP over HTTP to reach segmented internal networks.
Enseigné dans Network PivotingLigolo-ng
Builds a real network interface into the target subnet, no SOCKS pain.
Enseigné dans Network PivotingSliver
Modern open-source command-and-control with mTLS implants.
Enseigné dans C2 Framework DevelopmentCovenant
.NET command-and-control framework with a collaborative interface.
Enseigné dans C2 Framework Development
Web et API
Intercepter, fuzzer et casser les applications et leurs points d’entrée.
8 outilsBurp Suite
The proxy every web test runs through: intercept, repeat, fuzz.
Enseigné dans Burp Suite ProOWASP ZAP
Free intercepting proxy and scanner, scriptable for CI pipelines.
Enseigné dans OWASP ZAP Proffuf
Fuzzes paths, parameters and hosts at very high request rates.
Enseigné dans Advanced Web Attacksgobuster
Brute-forces directories, DNS names and virtual hosts.
Enseigné dans Web HackingNikto
Quick sweep for dangerous files, stale software and misconfigurations.
Enseigné dans Web HackingPostman
Replays and tampers with REST and GraphQL calls collection by collection.
Enseigné dans REST API PenetrationGraphQL Voyager
Renders an introspected schema so you can see what is reachable.
Enseigné dans GraphQL Securityjwt_tool
Inspects, tampers with and cracks JSON Web Tokens.
Enseigné dans Web Authentication Attacks
Sans-fil et matériel
Attaquer ce qui circule dans l’air et ce qui tient dans la main.
7 outilsAircrack-ng
The classic Wi-Fi suite: capture, replay, crack WEP and WPA.
Enseigné dans WiFi Security — From Zero to Pentesterhcxdumptool
Captures PMKID and handshakes straight into a Hashcat-ready file.
Enseigné dans WiFi Security — From Zero to PentesterKismet
Passive wireless survey across Wi-Fi, Bluetooth and more.
Enseigné dans WiFi Security — From Zero to PentesterBettercap
Swiss army knife for network and wireless man-in-the-middle.
Enseigné dans Bluetooth HackingHackRF One
Software-defined radio to listen to and replay 1 MHz-6 GHz signals.
Enseigné dans SDR & Radio HackingProxmark3
Reads, clones and emulates RFID and NFC access badges.
Enseigné dans Hardware HackingBus Pirate
Talks UART, SPI and I2C to the chips on a board you opened.
Enseigné dans Hardware Hacking
Cloud et conteneurs
Auditer IAM, buckets, clusters et images avant quelqu’un d’autre.
6 outilsPacu
AWS exploitation framework: enumerate, escalate, persist.
Enseigné dans AWS Penetration TestingScoutSuite
Multi-cloud security audit that reports on IAM, storage and network.
Enseigné dans Cloud Penetration FundamentalsROADtools
Explores Entra ID (Azure AD) relationships the way BloodHound does AD.
Enseigné dans Azure Penetration Testingkube-hunter
Hunts for exposed Kubernetes components and weak defaults.
Enseigné dans Container EscapeTrivy
Scans images, filesystems and IaC for known vulnerabilities.
Enseigné dans Container Escape AdvancedPeirates
Post-exploitation inside a pod: steal tokens, move across the cluster.
Enseigné dans Container Escape
Analyse et forensique
Lire le trafic, les binaires et la mémoire pour comprendre ce qui s’est passé.
8 outilsWireshark
Dissects captured traffic packet by packet, protocol by protocol.
Enseigné dans Wireshark Masterytcpdump
Captures on the wire from any shell, no interface needed.
Enseigné dans Wireshark MasteryGhidra
Free decompiler that turns machine code back into readable C.
Enseigné dans Reverse EngineeringIDA Free
The industry disassembler, with the graph view everyone learned on.
Enseigné dans Reverse Engineeringradare2
Scriptable reverse-engineering framework that lives in the terminal.
Enseigné dans Reverse Engineeringx64dbg
Windows debugger for watching a binary misbehave in real time.
Enseigné dans Buffer Overflow AdvancedVolatility
Rebuilds processes, connections and secrets from a memory dump.
Enseigné dans Memory ForensicsAutopsy
Disk forensics workbench: timelines, deleted files, artefacts.
Enseigné dans Memory ForensicsCes outils sont listés pour des tests autorisés et pour l'enseignement. Les lancer contre des systèmes qui ne vous appartiennent pas, sans autorisation écrite, est illégal dans la plupart des pays.