Tools by Category
Use every tool below only against systems you own or are authorized to test (labs, CTFs, intentionally vulnerable targets).
| Tool | Category | Typical Use |
| nmap | Recon/scan | Host discovery, port/service/version detection |
| masscan | Recon/scan | Fast large-range open-port sweep |
| Burp Suite | Web proxy | Intercept, spider, repeat, fuzz HTTP |
| OWASP ZAP | Web proxy | Free intercepting proxy + scanner |
| Wireshark | Packet analysis | GUI protocol dissection of captures |
| tcpdump | Packet analysis | CLI capture on servers/headless hosts |
| Nessus / OpenVAS | Vuln scanner | Full network vulnerability assessment |
| nuclei | Vuln scanner | Template-based, transparent checks |
| Metasploit | Exploitation | Validate vulns in labs (Metasploitable) |
| hashcat / john | Password audit | Audit strength of your OWN hashes |
| ffuf / gobuster | Content discovery | Directory/file/vhost brute-force |
Nmap Flags
| Flag | Meaning |
-sn | Ping/host discovery only, no port scan |
-sS | TCP SYN (stealth) scan |
-sU | UDP scan |
-sV | Service/version detection |
-sC | Run default NSE scripts |
-O | OS detection |
-p- | All 65535 ports |
-T4 | Timing template (faster) |
-oA | Output all formats (base name) |
Packet Filters
tcpdump Capture Filters
tcp port 80 # HTTP only
host 192.168.56.101 # to/from one host
src net 10.0.0.0/8 # from a subnet
tcp[tcpflags] & tcp-syn != 0 # SYN packets
-w out.pcap # write to file
-nn # no name/port resolution
Wireshark Display Filters
ip.addr == 192.168.56.101
tcp.flags.syn == 1 && tcp.flags.ack == 0 # handshake start
tcp.analysis.retransmission
http.request.method == "POST"
tls.handshake.type == 1 # ClientHello
dns.qry.name contains "example"
Web Proxies & Discovery
Burp / ZAP Quick Actions
| Action | Burp | ZAP |
| Toggle intercept | Proxy > Intercept | Break toolbar |
| Crawl/spider | Dashboard scan | Spider / AJAX Spider |
| Replay request | Repeater (Ctrl+R) | Manual Request Editor |
| Fuzz params | Intruder | Fuzzer |
ffuf / gobuster (Own Lab)
ffuf -w list.txt -u http://localhost:3000/FUZZ
ffuf -w list.txt -u http://TARGET/ -H "Host: FUZZ.lab" # vhost
gobuster dir -u http://localhost:3000 -w list.txt -x php,txt
gobuster dns -d lab.local -w subs.txt
Password Auditing (Your Own Hashes)
# hashcat mode examples (-m): 0=MD5 100=SHA1 1400=SHA256 3200=bcrypt 1800=sha512crypt
hashcat -m 3200 my_hashes.txt rockyou.txt
hashcat -m 0 my_hashes.txt -a 3 ?l?l?l?l?d?d # mask/brute
hashcat -m 3200 my_hashes.txt --show # show cracked
# John the Ripper
john --wordlist=rockyou.txt my_hashes.txt
john --format=bcrypt my_hashes.txt
john --show my_hashes.txt
Blue-Team Tooling
| Tool | Role | Notes |
| Splunk / ELK / Wazuh | SIEM | Log aggregation + correlation alerts |
| Suricata / Snort | IDS/IPS | Signature-based network detection/block |
| EDR agents | Endpoint | Process/file/network behavior on hosts |
| osquery | Endpoint visibility | SQL queries over live OS state |
| Kali / Parrot | Distro | Preloaded toolkit; keep on isolated network |