Arsenal // Security Toolkit v2.0

Pentesting Arsenal

Kurasi tools keamanan dan penetration testing - 192 tools dalam 16 domain, dari web application hingga AI-driven pentesting.

// Showing 192 of 192 tools

Burp Suite Pro ⭐

Advanced web vulnerability scanning and manipulation.

Docs ↗

Acunetix

Automated web security scanning for vulnerabilities.

Docs ↗

HCL AppScan

Enterprise-grade web application security testing.

Docs ↗

Invicti Netsparker

AI-powered web vulnerability assessment.

Docs ↗

Fortify WebInspect

Static and dynamic web app security testing.

Docs ↗

W3af

Open-source web application attack and audit framework.

Docs ↗

Nikto

Web server scanner for vulnerabilities.

Docs ↗

Nuclei

Fast and customizable vulnerability scanner.

Docs ↗

SQLMap

Automated SQL injection and database takeover tool.

Docs ↗

OWASP ZAP

Open-source web app security testing tool.

Docs ↗

Caido

Modern web security auditing proxy toolkit.

Docs ↗

ffuf

Fast web fuzzer written in Go.

Docs ↗

MobSF (Mobile Security Framework)

Static and dynamic analysis for mobile apps.

Docs ↗

Frida

Dynamic instrumentation toolkit for apps.

Docs ↗

APKTool

Reverse engineering tool for Android APKs.

Docs ↗

JADX-gui

Decompiler for Android apps.

Docs ↗

Android Studio/Genymotion

Development and emulation for Android testing.

Docs ↗

Drozer

Security assessment tool for Android.

Docs ↗

Magisk Root

Rooting and customization tool for Android.

Docs ↗

mitmproxy

Intercept and manipulate HTTP/HTTPS traffic.

Docs ↗

Objection

Runtime mobile exploration tool.

Docs ↗

adb

Android Debug Bridge for device interaction.

Docs ↗

Androguard

Static analysis and reverse engineering of Android apps.

Docs ↗

APKLeaks

Finds hidden URIs and secrets inside APK files.

Docs ↗

MobSF

Static and dynamic analysis for iOS apps.

Docs ↗

Frida

Dynamic instrumentation toolkit for iOS.

Docs ↗

Objection

Runtime mobile exploration for iOS.

Docs ↗

Cycript

iOS runtime inspection and manipulation.

Docs ↗

iOS Hooking – Needle

iOS security assessment tool.

Docs ↗

Class-dump

Tool to extract Objective-C runtime information.

Docs ↗

Frida iOS Dump

Dump decrypted iOS IPA binaries at runtime via Frida.

Docs ↗

iMazing

iOS device management and backup tool.

Docs ↗

Passionfruit

iOS app analysis and exploitation tool.

Docs ↗

checkra1n

Jailbreak toolkit for deep iOS security research.

Docs ↗

r2frida

Radare2 and Frida powered dynamic analysis.

Docs ↗

Clutch

Decrypts iOS applications to dump IPA files.

Docs ↗

Postman

API development and testing platform.

Docs ↗

Burp Suite Pro ⭐

API security testing and manipulation.

Docs ↗

Swagger UI

Interactive API documentation tool.

Docs ↗

Kite Runner

API endpoint enumeration tool.

Docs ↗

Insomnia

REST API client for testing.

Docs ↗

GraphQL Voyager

GraphQL schema visualization tool.

Docs ↗

GraphQLMap

Injection and exploitation framework for GraphQL endpoints.

Docs ↗

APIsec

Automated API security testing platform.

Docs ↗

OWASP API Fuzzer

Fuzzing tool for API vulnerability testing.

Docs ↗

42Crunch

API security auditing and monitoring.

Docs ↗

Astra

Automated REST API security scanning toolkit.

Docs ↗

Hoppscotch

Open-source API development ecosystem for testing.

Docs ↗

SonarQube

Static code analysis for vulnerabilities.

Docs ↗

Snyk

Dependency and code security scanning.

Docs ↗

Semgrep

Lightweight static analysis tool.

Docs ↗

Fortify Workbench

Enterprise source code security analysis.

Docs ↗

Checkmarx

Static application security testing (SAST).

Docs ↗

Veracode

Cloud-based code security scanning.

Docs ↗

CodeQL

Semantic code analysis for vulnerabilities.

Docs ↗

Bandit

Python security linter.

Docs ↗

FindSecBugs

Security audit tool for Java.

Docs ↗

Retire.js

JavaScript library vulnerability scanner.

Docs ↗

Gitleaks

Detects hardcoded secrets in git repositories.

Docs ↗

Infer

Static analyzer for Java, C++, and Objective-C.

Docs ↗

Fiddler

HTTP debugging proxy for thick clients.

Docs ↗

Sysinternals Suite

Tools for Windows system debugging.

Docs ↗

dnSpy

.NET debugger and decompiler.

Docs ↗

IDA Pro

Disassembler and debugger for thick clients.

Docs ↗

Process Explorer

Advanced process monitoring tool.

Docs ↗

CF Explorer

PE file analyzer for Windows.

Docs ↗

OllyDbg

x86 debugger for reverse engineering.

Docs ↗

x64dbg

x64/x86 debugger for Windows.

Docs ↗

Ghidra

Open-source reverse engineering tool.

Docs ↗

dotPeek

Free .NET decompiler from JetBrains.

Docs ↗

API Monitor

Monitors and logs API calls of Windows applications.

Docs ↗

Nmap

Network scanning and enumeration.

Docs ↗

Wireshark

Network packet analysis tool.

Docs ↗

Metasploit Framework

Penetration testing and exploit framework.

Docs ↗

Nessus

Vulnerability scanner for networks.

Docs ↗

OpenVAS

Open-source vulnerability scanner.

Docs ↗

Responder

LLMNR, NBT-NS, and MDNS poisoner.

Docs ↗

tcpdump

Command-line packet analyzer for networks.

Docs ↗

Masscan

Fast network port scanner.

Docs ↗

Snort

Open-source network intrusion detection system.

Docs ↗

Netcat

Versatile networking tool for auditing.

Docs ↗

Angry IP Scanner

Fast cross-platform IP and port scanner.

Docs ↗

RustScan

Ultra-fast port scanner with scripting support.

Docs ↗

Bloodhound

Active Directory attack path mapping.

Docs ↗

Mimikatz

Credential extraction tool.

Docs ↗

CrackMapExec

Active Directory enumeration and attack tool.

Docs ↗

Impacket

Collection of Python scripts for AD attacks.

Docs ↗

Kerbrute

Kerberos brute-forcing tool.

Docs ↗

Rubeus

Kerberos ticket manipulation tool.

Docs ↗

LDAPDomainDump

LDAP enumeration tool for AD.

Docs ↗

SharpHound

Data collection tool for Bloodhound.

Docs ↗

PowerView

PowerShell tool for AD reconnaissance.

Docs ↗

ADRecon

Active Directory reconnaissance tool.

Docs ↗

Certipy

AD Certificate Services enumeration and abuse tooling.

Docs ↗

Coercer

Forces Windows machines to authenticate remotely.

Docs ↗

Prowler

AWS security assessment tool.

Docs ↗

ScoutSuite

Multi-cloud security auditing tool.

Docs ↗

Cloudsploit

Cloud security scanning for AWS, Azure, GCP.

Docs ↗

Pacu

AWS penetration testing framework.

Docs ↗

Steampipe

Query and monitor cloud resources.

Docs ↗

CloudMapper

Visualize cloud infrastructure security.

Docs ↗

NCC Group Scout

Cloud security assessment tool.

Docs ↗

kube-bench

Kubernetes security benchmarking.

Docs ↗

Azucar

Azure cloud security auditing tool.

Docs ↗

CloudBrute

Multi-cloud infrastructure and asset enumeration.

Docs ↗

CloudGoat

Deliberately vulnerable AWS environments to practice on.

Docs ↗

Checkov

IaC and cloud configuration misconfiguration scanner.

Docs ↗

Trivy

Vulnerability scanner for containers and images.

Docs ↗

Aqua Microscanner

Lightweight container security scanner.

Docs ↗

Sysdig

Container runtime security and monitoring.

Docs ↗

Clair

Static analysis for container vulnerabilities.

Docs ↗

Anchore

Container image security scanning.

Docs ↗

Docker Bench

Security benchmarking for Docker.

Docs ↗

kube-hunter

Kubernetes penetration testing tool.

Docs ↗

Twistlock

Container runtime security and policy enforcement.

Docs ↗

Dagda

Container image security analysis.

Docs ↗

OpenSCAP

Security compliance tool for containers.

Docs ↗

Grype

Vulnerability scanner for container images.

Docs ↗

Syft

Generates SBOM from container images and filesystems.

Docs ↗

hping3

Network packet crafting tool.

Docs ↗

NPing

Network packet generation tool.

Docs ↗

Scapy

Packet manipulation and analysis tool.

Docs ↗

Zmap

Network scanner for Internet-wide surveys.

Docs ↗

firewalk

Firewall rule mapping tool.

Docs ↗

FTester

Firewall and IDS filtering policy tester.

Docs ↗

Nmap (Firewall)

Firewall and service detection.

Docs ↗

Suricata

High performance IDS/IPS engine for firewall rule testing.

Docs ↗

Packet Sender

Network packet sender for testing.

Docs ↗

hping2

Legacy packet crafting tool for stress testing.

Docs ↗

wafw00f

Detects and fingerprints web application firewalls.

Docs ↗

WhatWaf

Detects and bypasses web application firewalls.

Docs ↗

Aircrack-ng

WiFi network security auditing tool.

Docs ↗

Kismet

Wireless network detector and analyzer.

Docs ↗

Bettercap

Swiss army knife for WiFi and network attacks.

Docs ↗

Reaver

WPS cracking tool for WiFi.

Docs ↗

Fluxion

Evil Twin attack framework for WiFi.

Docs ↗

Wireshark

WiFi packet analysis tool.

Docs ↗

hcxdtools

WiFi packet capture and analysis.

Docs ↗

Fern WiFi Cracker

WiFi security auditing tool.

Docs ↗

Evil Twin Attack Tools

Tools for creating rogue WiFi access points.

Docs ↗

MDK4

WiFi deauthentication and attack tool.

Docs ↗

Wifite2

Automated wireless attack suite.

Docs ↗

Hashcat

GPU-powered password and WPA handshake cracker.

Docs ↗

GitHub Advanced Security

Security features for GitHub repositories.

Docs ↗

Trivy

Vulnerability scanner for DevSecOps pipelines.

Docs ↗

Snyk

Dependency and code security scanning.

Docs ↗

Anchore

Container and image security for DevSecOps.

Docs ↗

OWASP Dependency-Check

Open-source dependency vulnerability checker.

Docs ↗

Jenkins + Bandit

CI/CD integration for Python security scanning.

Docs ↗

Checkmarx

SAST for DevSecOps pipelines.

Docs ↗

Veracode

Cloud-based code security for DevSecOps.

Docs ↗

SonarQube

Continuous code quality and security.

Docs ↗

Dagda

Container image security analysis.

Docs ↗

Trufflehog

Scans repos and pipelines for leaked credentials.

Docs ↗

OWASP Dependency-Track

Continuous SBOM component risk monitoring.

Docs ↗

theHarvester

Email, subdomain, and IP gathering tool.

Docs ↗

Maltego

Graphical link analysis tool for OSINT.

Docs ↗

SpiderFoot

Automated OSINT collection and analysis.

Docs ↗

Recon-ng

Web-based OSINT framework.

Docs ↗

Amass

Subdomain enumeration and network mapping.

Docs ↗

FOCA

Document metadata analysis tool.

Docs ↗

Google Dorking

Advanced search techniques for OSINT.

Docs ↗

OSINT Framework

Collection of OSINT tools and resources.

Docs ↗

Metagoofil

Metadata extraction from public documents.

Docs ↗

Sherlock

Username search across social platforms.

Docs ↗

Shodan

Search engine for internet-connected devices.

Docs ↗

Censys

Internet-wide host and certificate intelligence.

Docs ↗

AI-Powered Nessus

AI-enhanced vulnerability scanning.

Docs ↗

Darktrace Cyber AI

Self-learning AI for autonomous threat detection.

Docs ↗

AI-Burp Suite

AI-augmented web application testing.

Docs ↗

HackerGPT

AI assistant trained on cybersecurity knowledge.

Docs ↗

CrowdStrike Falcon

AI-powered threat detection and pentesting.

Docs ↗

IBM QRadar AI

AI-driven cloud security assessment.

Docs ↗

Proofpoint AI Simulator

AI-based phishing and pentesting simulation.

Docs ↗

Cylance AI

AI-driven malware analysis and pentesting.

Docs ↗

SentinelOne AI

AI-enhanced endpoint security testing.

Docs ↗

Rapid7 InsightVM AI

AI-supported vulnerability management.

Docs ↗

PentestGPT

LLM-driven interactive penetration testing guide.

Docs ↗

burp-gpt

Burp Suite extension adding LLM analysis to requests.

Docs ↗

Zscaler Zero Trust

Zero Trust Network Access (ZTNA) assessment.

Docs ↗

Okta Zero Trust

Identity verification for Zero Trust.

Docs ↗

BeyondTrust Zero Trust

Endpoint security for Zero Trust assessment.

Docs ↗

Cloudflare Zero Trust

Cloud-based Zero Trust security testing.

Docs ↗

Ping Identity Zero Trust

Access control for Zero Trust environments.

Docs ↗

Illumio Zero Trust

Network segmentation for Zero Trust.

Docs ↗

Tenable Zero Trust

Compliance auditing for Zero Trust.

Docs ↗

Symantec Zero Trust

Data protection under Zero Trust principles.

Docs ↗

F5 Zero Trust

Application security for Zero Trust.

Docs ↗

NIST SP 800-207

Official NIST Zero Trust Architecture standard.

Docs ↗

Tailscale

Zero-config mesh VPN built on zero trust principles.

Docs ↗

Teleport

Zero trust access plane for infrastructure.

Docs ↗

No tools found matching your search.

Try different keywords or press / to search again.