7z
List and extract zip, 7z, rar, and other archives found on a host or in loot.
- Enumeration
- Post-exploitation
- Productivity
- LGPL
- Free
FIELD KIT
A curated catalog of pentesting tools. Content stays in the language you pick; nothing falls back in silence.
List and extract zip, 7z, rar, and other archives found on a host or in loot.
Attack-surface mapping and discovery of domains, ASNs, and infrastructure.
Cross-platform GUI client for managing an authorized web shell left on a compromised host during post-exploitation.
Classic ARP cache poisoning tool from the dsniff suite, used to redirect traffic on a switched LAN segment for on-path testing.
Free Burp extension that automates authorization testing by replaying every request with a lower-privileged session.
Web console for manually inspecting AWS IAM, S3, EC2, and other services in scope.
Official command-line interface for scripting and enumerating AWS resources — IAM, S3, EC2, and more.
Official command-line tool for enumerating and managing Azure resources — RBAC, storage, VMs, and more.
Browser Exploitation Framework for demonstrating real-world impact once an authorized XSS finding hooks a browser.
Java-based GUI client for administering an authorized web shell over a dynamically encrypted, memory-capable channel.
Active Directory graphs for abuse paths and privilege relationships.
Out-of-band interaction service built into Burp Suite Pro/Enterprise for confirming blind SSRF, XXE, and command injection.
PortSwigger's free BApp Store extension for detecting and exploiting HTTP request smuggling and desync vulnerabilities.
Burp Suite's built-in customizable attack tool for automating fuzzing, brute-force, and parameter-manipulation attacks.
PortSwigger's free BApp Store extension that discovers hidden, unlinked HTTP parameters and web cache poisoning vectors.
Intercepting proxy and web lab; Community is free, Professional is paid.
PortSwigger's free, Python-scriptable Burp extension for high-throughput HTTP requests — built for race conditions and large-scale attacks.
Bash helper from Bishop Fox's badPods that batch-runs kubectl auth can-i to map what a pod's service account can actually do.
Capability shell wrapper from libcap, used to inspect and test the Linux capabilities available to a process.
Fast TCP/UDP tunnel over HTTP, used to pivot traffic through a compromised host into an internal network segment.
Chrome's built-in developer tools for inspecting network traffic, storage, and JavaScript execution live in the browser.
Automated command-injection detection and exploitation tool that turns a vulnerable parameter into a semi-interactive shell.
Go CLI that checks a project's dependency manifest against public registries to flag packages that could be hijacked via dependency confusion.
Python scanner that sends crafted Origin headers to find and confirm CORS misconfigurations at scale.
Signs and verifies container images and artifacts as part of the Sigstore supply-chain project.
Swiss-army-knife tool for validating credentials and enumerating access across many Windows/AD hosts at once over SMB, WinRM, MSSQL, and LDAP.
CLI for pulling, pushing, and inspecting container images and manifests straight from a registry, no daemon required.
CLI for any CRI-compatible runtime, used to inspect and debug pods and containers at the Kubernetes node level.
Certificate Transparency log search engine used to enumerate subdomains from issued TLS certificates.
Low-level CLI for containerd, used to inspect and manage containers directly when Docker is not present.
Transfer data to or from a URL — the default way to probe HTTP, APIs, and TLS by hand.
Fast, parameter-analysis-based XSS scanner written in Go, built for automation and pipeline use.
Query DNS records directly — A, AAAA, MX, NS, TXT, and the rest — from BIND’s CLI.
Explores a container image layer by layer to find secrets, bloat, or misconfigurations baked into the build.
The standard container CLI and daemon for running, inspecting, and breaking out of containers on a compromised host.
Client-side testing tool built into Burp Suite's embedded browser for finding DOM XSS and DOM clobbering.
Perl-based fuzzer that automates directory-traversal and file-inclusion payload testing across HTTP, FTP, TFTP, and more.
Platform for centralizing evidence and assembling the engagement report.
Official CLI for creating and managing Amazon EKS clusters, used to enumerate cluster and node-group configuration.
Modernized rewrite of enum4linux for enumerating SMB/RPC shares, users, groups, and password policy on Windows/Samba hosts.
Official command-line client for etcd, the key-value store behind Kubernetes, used to enumerate and read data from an exposed or misconfigured cluster.
Offline etcd maintenance utility for inspecting and restoring cluster snapshots without a running etcd server.
Ruby-based WinRM client for opening an authenticated remote PowerShell session on a Windows host.
Fast, recursive content-discovery scanner for directories and files, written in Rust.
Fast web fuzzer for directories, files, parameters, and virtual hosts.
Walk a filesystem and match files by name, type, or permission — the usual loot search on Linux.
Fast parallel ICMP ping sweeper for discovering live hosts across large ranges.
Dynamic code instrumentation toolkit for Android, iOS, and Linux x86/ARM/MIPS.
Burp extension and Java library that fingerprints which classes sit on a remote Java classpath via blind deserialization, before firing a full gadget chain.
Fetches known URLs for a domain from the Wayback Machine, Common Crawl, and AlienVault OTX.
Official command-line tool from the Google Cloud SDK for enumerating and managing GCP resources — IAM, storage, compute.
Built-in search across public GitHub repositories, used to spot leaked secrets and exposed config.
Scans git repositories and commit history for hardcoded secrets and credentials.
Run the same command against a list of hosts, URLs, or files in parallel.
Directory, DNS, and vhost brute-forcing against web targets.
Local privilege-escalation tool that turns SeImpersonatePrivilege into SYSTEM across most modern Windows versions.
General-purpose search engine used for OSINT recon via advanced operators ('Google dorking').
Vulnerability scanner for container images, filesystems, and SBOMs.
GPU-accelerated cracker for auditing the strength of password hashes recovered during an engagement.
Kubernetes package manager, used in a cloud assessment to inspect chart configurations and installed releases for misconfigurations.
Fast HTTP probing toolkit for confirming which hosts are alive and fingerprinting them at scale.
Parallelized network login cracker that tests credentials against dozens of protocols, from SSH and RDP to web forms.
Python library and collection of example scripts implementing Windows/AD network protocols, the base for secretsdump, psexec.py, and dozens of other tools.
Open-source out-of-band interaction (OAST) tool for detecting blind vulnerabilities like SSRF, blind XXE, and blind SSTI.
Filter and reshape JSON from APIs, cloud CLIs, and loot files in a one-liner.
Go library and CLI that parses JavaScript into an AST to extract URLs, endpoints, and secrets more accurately than regex-based extractors.
Python toolkit for validating, tampering with, and forging JSON Web Tokens to probe common signing and claim flaws.
Fast web crawler for discovering endpoints, JavaScript files, and forms across an application.
Kerberos pre-authentication tool for enumerating valid Active Directory usernames and testing passwords.
Proof-of-concept that hijacks CoreDNS resolution from a compromised pod to demonstrate cluster-internal DNS spoofing and MITM.
Aqua Security scanner that hunts for known Kubernetes security weaknesses from outside the cluster, from a pod, or from a node.
The official Kubernetes CLI for querying, and where authorized, controlling cluster resources during an assessment.
kubectl plugin that lists every user, group, or service account with RBAC permission to run a given verb on a resource.
CLI that talks directly to a node's Kubelet API to list pods, exec into containers, and pull logs — most valuable against a kubelet left open to anonymous access.
Standard OpenLDAP command-line client for querying and enumerating LDAP directories, including Active Directory.
TUN-interface pivoting tool that turns a compromised host's reachable network into routable subnets on the attacker box.
Python tool that extracts endpoints and URLs from JavaScript files to expand a web application's attack surface.
Linux enumeration script that surfaces local privilege-escalation vectors: SUID binaries, cron jobs, credentials, and more.
Suggests known Linux kernel and package privilege-escalation exploits based on version and patch level.
List a directory with hidden files, modes, and timestamps — first look at a foothold.
Asynchronous, raw-packet port scanner built to sweep huge ranges at extremely high speed.
Open-source exploitation framework for developing and running exploits, generating payloads, and running post-exploitation modules.
Post-exploitation tool for extracting Windows credentials, hashes, and Kerberos tickets from memory.
Standalone Metasploit payload generator for building and encoding custom payloads in various formats.
Open a TCP or UDP connection by hand — probe a port, grab a banner, or move a file.
Automated vulnerability scanner with a huge, daily-updated plugin library covering CVEs, misconfigs, and compliance checks.
Network scanner for discovering hosts, ports, and services in scope.
Inspect Node package manifests, scripts, and lockfiles without installing the app.
Part of util-linux; enters the namespaces of an existing process, the classic way to attach to or escape a container.
Template-based scanner for known findings across HTTP and other protocols.
Reverse proxy that puts OAuth/OIDC login in front of HTTP apps that have none.
Fast SNMP scanner that brute-forces community strings across many hosts in parallel.
Standard TLS/crypto toolkit CLI for inspecting certificates, testing cipher and protocol support, and manually interacting with TLS services.
Open-source vulnerability scanner from Greenbone, driven by a continuously updated feed of network vulnerability tests.
AWS exploitation framework for post-compromise enumeration and privilege-escalation testing within an account.
Library of pre-built PHP unserialize() gadget chains and a CLI to generate ready-to-use deserialization payloads for common frameworks and libraries.
PowerShell script that enumerates and abuses common Windows privilege-escalation misconfigurations.
Go scanner that detects client-side prototype pollution and turns known gadgets into a working XSS payload.
Exploits SeImpersonatePrivilege via the Print Spooler bug to escalate a service account to SYSTEM.
Signed Microsoft Sysinternals utility for capturing process memory dumps, including LSASS.
Prowler is a security tool for AWS, Azure, and GCP.
Run small scripts and stdlib helpers — JSON, HTTP, encoding — already on most hosts.
kubectl plugin that renders a full access matrix — every resource type against every verb — for the current or an impersonated identity.
Evaluates a cluster's effective RBAC permissions against a Rego policy library to flag identities with real, documented privilege-escalation paths.
CLI for managing and syncing files across cloud storage providers, used to enumerate and validate access to misconfigured buckets.
LLMNR/NBT-NS/mDNS poisoner that captures NTLM authentication attempts broadcast on a local network segment.
Query and inspect Windows services in place — names, states, and binary paths.
Python library and interactive shell for crafting, sending, and dissecting arbitrary network packets.
List Windows scheduled tasks, their triggers, and the commands they run.
Command-line search tool for a local mirror of Exploit-DB, matching a service or version against known public exploits.
Impacket script for remotely dumping SAM, LSA secrets, and NTDS.dit hashes.
Hunts for a username across hundreds of social media and web platforms for OSINT.
Search engine for internet-connected devices and services, indexed by banner and port.
CLI to inspect, copy, and sign container images and registries without a Docker daemon.
FTP-like command-line client, bundled with Samba, for browsing and interacting with SMB/CIFS shares.
Standalone Python CLI that fingerprints HTTP request smuggling and desync issues through differential server responses.
Part of Net-SNMP, walks an SNMP MIB tree to enumerate device details, often via a default community string.
Scans open-source dependencies for malware, typosquatting, and other supply-chain risk.
Analyzes JavaScript source maps shipped to the client to reveal original, unminified source code and file structure.
Automated SQL injection detection and exploitation, with controlled dumps.
Reach a remote shell and forward ports over an encrypted OpenSSH session.
Python tool that takes a confirmed SSRF and automates exploitation against cloud metadata, internal services, and more.
System stress-testing tool that loads CPU, memory, I/O, and network resources to test availability under an authorized DoS test.
Pull printable text out of binaries, dumps, and firmware images.
Passive subdomain discovery tool that aggregates results from dozens of public sources.
Generates a Software Bill of Materials (SBOM) from container images and filesystems.
Command-line packet capture and analysis tool for inspecting live network traffic or saved pcap files.
Gathers emails, subdomains, names, and IPs from public sources like search engines and PGP servers.
Automates detection and exploitation of server-side template injection (SSTI).
Trivy is a security tool for containers, Kubernetes, and more.
Scans git history, filesystems, and cloud sources for secrets, then actively verifies them.
Identifies and fingerprints which WAF, if any, is protecting a web target.
Browser extension and lookup service that fingerprints a site's CMS, frameworks, and analytics stack.
Enumerates missing Windows patches and suggests matching known privilege-escalation exploits.
Standalone Go CLI scanner from Hackmanit that tests for web cache poisoning and web cache deception across multiple techniques.
Python tool that generates a lightweight, obfuscated PHP web shell and includes the client to manage it, in one package.
Query Windows Event Log channels for evidence without opening Event Viewer.
Web technology fingerprinting scanner that identifies CMSs, frameworks, servers, and libraries.
Look up domain and IP registration records during passive recon.
Windows enumeration script that surfaces local privilege-escalation vectors: misconfigured services, credentials, and more.
Context-aware XSS detection and exploitation suite with its own fuzzing engine and payload generator.
Automates exploitation of XXE injection, including blind/out-of-band data exfiltration techniques.
The standard proof-of-concept tool for generating Java deserialization gadget-chain payloads from libraries already on a target's classpath.
No tools match this filter.