InSkillSecArsenal
Arsenal
62 ferramentas que fazem o trabalho de verdade em um teste, organizadas pela fase em que você as usa. Cada ficha diz para que serve e leva ao curso que a ensina. Ver o catálogo de cursos

Reconhecimento
Mapear o alvo sem tocá-lo: domínios, pessoas, ativos expostos.
8 ferramentasAmass
Deep subdomain enumeration from dozens of passive sources at once.
Ensinada em OSINT AutomationSubfinder
Fast passive subdomain discovery, built for large scopes.
Ensinada em OSINT AutomationtheHarvester
Collects e-mails, names and hosts from public search engines.
Ensinada em OSINT AutomationRecon-ng
Modular OSINT framework that stores findings in a workspace database.
Ensinada em OSINT AutomationMaltego
Graphs relationships between people, domains and infrastructure.
Ensinada em OSINT AutomationShodan
Search engine for exposed devices, banners and forgotten services.
Ensinada em OSINT AutomationSpiderFoot
Automates 200+ OSINT modules against a single target.
Ensinada em OSINT AutomationSocial-Engineer Toolkit
Builds phishing pages and pretexts for authorised awareness tests.
Ensinada em Social Engineering
Varredura e enumeração
Descobrir o que escuta, em qual versão e onde cede.
7 ferramentasNmap
The reference port scanner, with a scripting engine for enumeration.
Ensinada em Nmap AdvancedMasscan
Sweeps an entire /8 in minutes when Nmap would take days.
Ensinada em Nmap AdvancedRustScan
Finds open ports fast, then hands them to Nmap for the details.
Ensinada em Nmap AdvancedNuclei
Template-driven scanner for known exposures across many hosts.
Ensinada em Advanced Web AttacksNessus
Commercial vulnerability scanner, the baseline in most audit reports.
Ensinada em Advanced Penetration TestingOpenVAS
Open-source vulnerability scanner with its own feed of checks.
Ensinada em Advanced Penetration Testingenum4linux-ng
Pulls shares, users and policies out of SMB and LDAP services.
Ensinada em Active Directory Attacks
Exploração
Transformar um achado em acesso autenticado.
9 ferramentasMetasploit Framework
Exploits, payloads and post modules in one console.
Ensinada em Metasploit Prosqlmap
Automates SQL injection detection all the way to shell access.
Ensinada em Web HackingHydra
Online password attacks against dozens of network protocols.
Ensinada em Cryptography AttacksHashcat
GPU-accelerated hash cracking with rules and masks.
Ensinada em Cryptography AttacksJohn the Ripper
Cracks a very wide range of hash formats, CPU-first.
Ensinada em Cryptography AttacksImpacket
Python implementations of SMB, Kerberos and MSRPC you can script.
Ensinada em Active Directory AttacksNetExec
Sprays credentials and commands across a Windows network at scale.
Ensinada em Active Directory AttacksResponder
Poisons LLMNR and NBT-NS to capture and relay authentication.
Ensinada em Active Directory Attacksmsfvenom
Generates and encodes payloads for every target platform.
Ensinada em Advanced Payload Development
Pós-exploração
Escalar, colher credenciais, pivotar e manter o terreno.
9 ferramentasMimikatz
Extracts credentials, tickets and secrets from Windows memory.
Ensinada em Active Directory AttacksBloodHound
Graphs Active Directory to reveal the shortest path to Domain Admin.
Ensinada em Active Directory AttacksRubeus
Kerberos abuse toolkit: roasting, delegation, ticket forging.
Ensinada em Active Directory AttackslinPEAS
Enumerates every local privilege-escalation path on Linux.
Ensinada em Linux ExploitationwinPEAS
Same idea on Windows: services, tokens, unquoted paths, secrets.
Ensinada em Windows ExploitationChisel
Tunnels TCP over HTTP to reach segmented internal networks.
Ensinada em Network PivotingLigolo-ng
Builds a real network interface into the target subnet, no SOCKS pain.
Ensinada em Network PivotingSliver
Modern open-source command-and-control with mTLS implants.
Ensinada em C2 Framework DevelopmentCovenant
.NET command-and-control framework with a collaborative interface.
Ensinada em C2 Framework Development
Web e API
Interceptar, fuzzear e quebrar aplicações e seus endpoints.
8 ferramentasBurp Suite
The proxy every web test runs through: intercept, repeat, fuzz.
Ensinada em Burp Suite ProOWASP ZAP
Free intercepting proxy and scanner, scriptable for CI pipelines.
Ensinada em OWASP ZAP Proffuf
Fuzzes paths, parameters and hosts at very high request rates.
Ensinada em Advanced Web Attacksgobuster
Brute-forces directories, DNS names and virtual hosts.
Ensinada em Web HackingNikto
Quick sweep for dangerous files, stale software and misconfigurations.
Ensinada em Web HackingPostman
Replays and tampers with REST and GraphQL calls collection by collection.
Ensinada em REST API PenetrationGraphQL Voyager
Renders an introspected schema so you can see what is reachable.
Ensinada em GraphQL Securityjwt_tool
Inspects, tampers with and cracks JSON Web Tokens.
Ensinada em Web Authentication Attacks
Wireless e hardware
Atacar o que viaja pelo ar e o que cabe na mão.
7 ferramentasAircrack-ng
The classic Wi-Fi suite: capture, replay, crack WEP and WPA.
Ensinada em WiFi Security — From Zero to Pentesterhcxdumptool
Captures PMKID and handshakes straight into a Hashcat-ready file.
Ensinada em WiFi Security — From Zero to PentesterKismet
Passive wireless survey across Wi-Fi, Bluetooth and more.
Ensinada em WiFi Security — From Zero to PentesterBettercap
Swiss army knife for network and wireless man-in-the-middle.
Ensinada em Bluetooth HackingHackRF One
Software-defined radio to listen to and replay 1 MHz-6 GHz signals.
Ensinada em SDR & Radio HackingProxmark3
Reads, clones and emulates RFID and NFC access badges.
Ensinada em Hardware HackingBus Pirate
Talks UART, SPI and I2C to the chips on a board you opened.
Ensinada em Hardware Hacking
Nuvem e contêineres
Auditar IAM, buckets, clusters e imagens antes de outro.
6 ferramentasPacu
AWS exploitation framework: enumerate, escalate, persist.
Ensinada em AWS Penetration TestingScoutSuite
Multi-cloud security audit that reports on IAM, storage and network.
Ensinada em Cloud Penetration FundamentalsROADtools
Explores Entra ID (Azure AD) relationships the way BloodHound does AD.
Ensinada em Azure Penetration Testingkube-hunter
Hunts for exposed Kubernetes components and weak defaults.
Ensinada em Container EscapeTrivy
Scans images, filesystems and IaC for known vulnerabilities.
Ensinada em Container Escape AdvancedPeirates
Post-exploitation inside a pod: steal tokens, move across the cluster.
Ensinada em Container Escape
Análise e forense
Ler tráfego, binários e memória para entender o que aconteceu.
8 ferramentasWireshark
Dissects captured traffic packet by packet, protocol by protocol.
Ensinada em Wireshark Masterytcpdump
Captures on the wire from any shell, no interface needed.
Ensinada em Wireshark MasteryGhidra
Free decompiler that turns machine code back into readable C.
Ensinada em Reverse EngineeringIDA Free
The industry disassembler, with the graph view everyone learned on.
Ensinada em Reverse Engineeringradare2
Scriptable reverse-engineering framework that lives in the terminal.
Ensinada em Reverse Engineeringx64dbg
Windows debugger for watching a binary misbehave in real time.
Ensinada em Buffer Overflow AdvancedVolatility
Rebuilds processes, connections and secrets from a memory dump.
Ensinada em Memory ForensicsAutopsy
Disk forensics workbench: timelines, deleted files, artefacts.
Ensinada em Memory ForensicsEstas ferramentas são listadas para testes autorizados e para ensino. Usá-las contra sistemas sem autorização por escrito é ilegal na maioria dos países.