Essential instruments for a pen test toolkit (original) (raw)

Does your penetration testing toolkit have the proper contents? Learn the must-have tool for any pen tester, as well as specific tools for wireless, network and web app pen testing.

Like every other profession, penetration testers use many different methodologies and tools, each for different reasons. Although what's listed below is not the complete list of pen testing tools, they are tools penetration testers should be comfortable with when they start conducting pen tests.

Every pen test toolkit should include Kali Linux. Pen testers use Kali Linux as their base pen testing OS in large part because it includes a broad range of pen testing utilities and is optimized for use in pen testing engagements. While Kali Linux can run on its own hardware, it's far more common to see pen testers using Kali VMs running on Windows or OS X.

In addition to Kali, pen testers' toolkits may vary a bit depending on whether the focus is on wireless network pen testing, general network pen testing or web application pen testing.

Wireless penetration testing toolkit

Pen testers working on engagements that include testing for one or more wireless access points will find the following tools especially useful:

Network pen test toolkit

Traditional network pen testing calls for a different set of tools than wireless pen testing. The primary tools pen testers use for network pen testing include the following:

Web application pen testing

A different set of tools and skills constitute a web application pen test toolkit, mostly because it targets specific servers rather than the networks over which server traffic is carried. The primary tools for web application pen testing include the following:

Dig Deeper on Risk management