Lista elaborada y documentada originalmente por Gordon Lyon en sectools.org sin duda un gran esfuerzo de su parte.
- Nessus : Premier UNIX vulnerability assessment tool
- Wireshark : Sniffing the glue that holds the Internet together
- Snort : Everyone’s favorite open source IDS
- Netcat : The network Swiss army knife
- Metasploit Framework : Hack the Planet
- Hping2 : A network probing utility like ping on steroids
- Kismet : A powerful wireless sniffer
- Tcpdump : The classic sniffer for network monitoring and data acquisition
- Cain and Abel : The top password recovery tool for Windows
- John the Ripper : A powerful, flexible, and fast multi-platform password hash cracker
- Ettercap : In case you still thought switched LANs provide much extra security
- Nikto : A more comprehensive web scanner
- Ping/telnet/dig/traceroute/whois/netstat : The basics
- OpenSSH / PuTTY / SSH : A secure way to access remote computers
- THC Hydra : A Fast network authentication cracker which support many different services
- Paros proxy : A web application vulnerability assessment proxy
- Dsniff : A suite of powerful network auditing and penetration-testing tools
- NetStumbler : Free Windows 802.11 Sniffer
- THC Amap : An application fingerprinting scanner
- GFI LANguard : A commercial network security scanner for Windows
- Aircrack : The fastest available WEP/WPA cracking tool
- Superscan : A Windows-only port scanner, pinger, and resolver
- Netfilter : The current Linux kernel packet filter/firewall
- Sysinternals : An extensive collection of powerful windows utilities
- Retina : Commercial vulnerability assessment scanner by eEye
- Perl / Python / Ruby : Portable, general-purpose scripting languages
- L0phtcrack : Windows password auditing and recovery application
- Scapy : Interactive packet manipulation tool
- Sam Spade : Freeware Windows network query tool
- GnuPG / PGP : Secure your files and communication w/advanced encryption
- Airsnort : 802.11 WEP Encryption Cracking Tool
- BackTrack : An Innovative Penetration Testing live Linux distribution
- P0f : A versatile passive OS fingerprinting tool
- Google : Everyone’s Favorite Search Engine
- WebScarab : A framework for analyzing applications that communicate using the HTTP and HTTPS protocols
- Ntop : A network traffic usage monitor
- Tripwire : The grand-daddy of file integrity checkers
- Ngrep : Convenient packet matching & display
- Nbtscan : Gathers NetBIOS info from Windows networks
- WebInspect : A Powerful Web Application Scanner
- OpenSSL : The premier SSL/TLS encryption library
- Xprobe2 : Active OS fingerprinting tool
- EtherApe : EtherApe is a graphical network monitor for Unix modeled after etherman
- Core Impact : An automated, comprehensive penetration testing product
- IDA Pro : A Windows or Linux disassembler and debugger
- SolarWinds : A plethora of network discovery/monitoring/attack tools
- Pwdump : A window password recovery tool
- LSoF : LiSt Open Files
- RainbowCrack : An Innovative Password Hash Cracker
- Firewalk : Advanced traceroute
- Angry IP Scanner : IP address and port scanner
- RKHunter : An Unix Rootkit Detector
- Ike-scan : VPN detector/scanner
- Arpwatch : Keeps track of ethernet/IP address pairings and can detect certain monkey business
- KisMAC : A A GUI passive wireless stumbler for Mac OS X
- OSSEC HIDS : An Open Source Host-based Intrusion Detection System
- Openbsd PF : The OpenBSD Packet Filter
- Nemesis : Packet injection simplified
- Tor : An anonymous Internet communication system
- Knoppix : A general-purpose bootable live system on CD or DVD
- ISS Internet Scanner : Application-level vulnerability assessment
- Fport : Foundstone’s enhanced netstat
- chkrootkit : Locally checks for signs of a rootkit
- SPIKE Proxy : HTTP Hacking
- OpenBSD : The Proactively Secure Operating System
- Yersinia : A multi-protocol low-level attack tool
- Nagios : An open source host, service and network monitoring program
- Fragroute/Fragrouter : A network intrusion detection evasion toolkit
- X-scan : A general scanner for scanning network vulnerabilities
- Whisker/libwhisker : Rain.Forest.Puppy’s CGI vulnerability scanner and library
- Socat : A relay for bidirectional data transfer
- Sara : Security Auditor’s Research Assistant
- QualysGuard : A web-based vulnerability scanner
- ClamAV : A GPL anti-virus toolkit for UNIX
- cheops / cheops-ng : Gives a simple interface to many network utilities, maps local or remote networks and identifies OS of machine
- Burpsuite : An integrated platform for attacking web applications
- Brutus : A network brute-force authentication cracker
- Unicornscan : Not your mother’s port scanner
- Stunnel : A general-purpose SSL cryptographic wrapper
- Honeyd : Your own personal honeynet
- Fping : A parallel ping scanning program
- BASE : The Basic Analysis and Security Engine
- Argus : A generic IP network transaction auditing tool
- Wikto : Web Server Assessment Tool
- Sguil : The Analyst Console for Network Security Monitoring
- Scanrand : An unusually fast stateless network service and topology discovery system
- IP Filter : Portable UNIX Packet Filter
- Canvas : A Comprehensive Exploitation Framework
- VMware : Multi-platform Virtualization Software
- Tcptraceroute : A traceroute implementation using TCP packets
- SAINT : Security Administrator’s Integrated Network Tool
- OpenVPN : A full-featured SSL VPN solution
- OllyDbg : An assembly level Windows debugger
- Helix : A Linux Distribution with Computer Forensics in Mind
- Bastille : Security hardening script for Linux, Mac OS X, and HP-UX
- Acunetix Web Vulnerability Scanner : Commercial Web Vulnerability Scanner
- TrueCrypt : Open-Source Disk Encryption Software for Windows and Linux
- Watchfire AppScan : Commercial Web Vulnerability Scanner
- N-Stealth : Web server scanner
- MBSA : Microsoft Baseline Security Analyzer
Etiquetas: herramientas, Redes, tools