Command
nmap Netzwerk - und Port-Scanner
sudo nmap -sC -sV 192.168.1.100
sudo nmap -sS(U)V -sC scanme.nmap.org (U = UDP) --reason
sudo nmap -sV -p 80,443 scanme.nmap.org --open
Vulnerability Analysis
openVAS / Greenbone Vollständiger Vulnerability Scanner
nikto Web-Server-Schwachstellenscanner
nuclei Template-basierter Vulnerability Scanner
nessus Industriestandard (kommerziell)
lynis Security Auditing für Unix/Linux
wpScan WordPress-Schwachstellenscanner
Web Application Analysis
burpSuite Der Standard-Web-Proxy (Community/Pro)
owasp zap Kostenloser Web-App-Scanner
sqlmap Automatisierte SQL-Injection
nikto Web-Server-Scanner
gobuster / Dirb / ffuf Directory Bruteforcing
commix Command Injection Exploitation
xsStrike XSS-Detection und Exploitation
Test
Information Gathering
nmap Netzwerk - und Port-Scanner
sudo nmap -sC -sV 192.168.1.100
sudo nmap -sS(U)V -sC scanme.nmap.org (U = UDP) --reason
sudo nmap -sV -p 80,443 scanme.nmap.org --open
maltego Visuelle OSINT- und Link-Analyse
theHarvester E-Mail- und Subdomain-Sammlung
recon-ng Modulares OSINT-Framework
spiderFoot Automatisierte OSINT-Recherche
shodan Suchmaschine für IoT-Geräte
dmitry Deepmagic Information Gathering
whois / dnsenum / fierce DNS-Aufklärung
Vulnerability Analysis
openVAS / Greenbone Vollständiger Vulnerability Scanner
nikto Web-Server-Schwachstellenscanner
nuclei Template-basierter Vulnerability Scanner
nessus Industriestandard (kommerziell)
lynis Security Auditing für Unix/Linux
wpScan WordPress-Schwachstellenscanner
Web Application Analysis
burpSuite Der Standard-Web-Proxy (Community/Pro)
owasp zap Kostenloser Web-App-Scanner
sqlmap Automatisierte SQL-Injection
nikto Web-Server-Scanner
gobuster / Dirb / ffuf Directory Bruteforcing
commix Command Injection Exploitation
xsStrike XSS-Detection und Exploitation
Password Attacks
crunch Wordlist-Generator
cewl Custom Wordlist Generator
hashcat GPU-basiertes Hash-Cracking (schnellstes)
john the ripper CPU-basiertes Hash-Cracking
ncrack
hydra Online-Brute-Force (SSH, FTP, HTTP, etc.)
medusa Paralleles Brute-Force-Tool
mimikatz Windows-Credential-Extraktion
wordlists
cull, seclists, rockyou
Wireless Attacks
aircrack-ng Toolbox WEP/WPA/WPA2-Cracking Suite
kismet WLAN-Detektor und Sniffer
wifite2 Automatisierter WLAN-Angriff
reaver / Bully – WPS-PIN-Brute-Force
fern wifiCracker – GUI-basiertes WLAN-Tool
bettercap Netzwerk Schweizer Taschenmesser
Exploitation Tools
metasploit Framework Das mächtigste Exploitation-Framework
searchsploit Offline-Exploit-Datenbank (Exploit-DB)
beef Browser Exploitation Framework
armitage Metasploit Oberfläche --> GUI
msfvenom Payload Generator
empire / covenant Post Exploitation Frameworks
Sniffing & Spoofing
wireshark Netzwerk Protokoll Analyzer
tcpdump Paket Sniffer
responder LLMNR / NBT - NS / mDNS Poisoning
ettercap MITM-Framework
bettercap Modernes MITM-Tool
mitmproxy HTTP(S) Proxy
sniffing
netsniff-ng
Post Exploitation
inPEAS / WinPEAS Privilege Escalation Enumeration
mimikatz Windows Passwörter extrahieren
bloodHound Active Directory Angriffs Pfade
crackMapExec Netzwerk Penetration (SMB, WMI)
impacket Netzwerkprotokoll Toolkit
powerSploit PowerShell Post Exploitation
Forensics Tools
autopsy Grafische Forensik-Plattform
volatility RAM-Analyse (Memory Forensics)
sleuth Kit Dateisystem-Forensik
binwalk Firmware-Analyse
foremost / Scalpel File Carving
dd / dcfldd Forensische Disk Images
Reverse Engineering
ghidra NSA Reverse Engineering Framework
radare2 / r2 Kommandozeilen Disassembler
ollyDbg / x64dbg Windows Debugger
gdb GNU Debugger
idaFree Disassembler (kommerziell/Free)
jd-GUI Java Decompiler
Social Engineering
set (Social - Engineer - Toolkit) Phishing-Kampagnen
gophish Open - Source Phishing Framework
kingPhisher Phishing Kampagnen Manager
evilginx2 MITM Phishing Framework
Reporting Tools
faraday Collaborative Pentest-Plattform
dradis Reporting Framework
cherryTree Hierarchische Notiz App
keepNote Pentest Notizbuch
pwndoc Pentest Report Generator
Reverse Shell
msfconsole
metasploit
powersploit
WEB
burpSuite --> GUI Der Standard-Web-Proxy
cap --> GUI
nikto Web-Server-Scanner
gobuster / dirb / ffuf FUZZen von HTTP(S) Zielen. Directory Bruteforcing
Firewall entdecken
wafw00f -l --> Liste aller Firewalls
Netzwerk
netcat
nc -lnvp <PORT>
nslookup
whois
dig
hping3
Datenbank
sqlmap Automatisierte SQL-Injection
Es ist laut, es erzeugt viel Verkehr und aggressive Flaggen (--risk=3 --level=5) kann die Zieldatenbank abstürzen lassen
SSH
WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! (ssh-keygen -R 192.168.1.1)
Mobile
apktool --> Tool für Reengineering Android apk files
Links
https://kennyvn.com/top-10-kali-linux-tools/
https://itgrundlagen.com/13-praktische-tools/kali-linux-tools.html
https://hacking-kurse.de/white-hat-hacker/kali-linux-tools-uebersicht
https://redteamguide.com/guides/kali-linux-tools-beginners-2026/
https://phoenixnap.com/kb/kali-linux-tools