Command

Information Gathering

nmap   Netzwerk - und Port-Scanner

   sudo nmap -sC -sV 192.168.1.100

   sudo nmap -sS(U)V -sC scanme.nmap.org (U = UDP) --reason      

   sudo nmap -sV -p 80,443 scanme.nmap.org --open  

Vulnerability Analysis

openVAS / Greenbone   Vollständiger Vulnerability Scanner

nikto   Web-Server-Schwachstellenscanner

nuclei   Template-basierter Vulnerability Scanner

nessus   Industriestandard (kommerziell)

lynis   Security Auditing für Unix/Linux

wpScan   WordPress-Schwachstellenscanner  

Web Application Analysis

burpSuite   Der Standard-Web-Proxy (Community/Pro)

owasp zap   Kostenloser Web-App-Scanner

sqlmap   Automatisierte SQL-Injection

nikto   Web-Server-Scanner

gobuster / Dirb / ffuf   Directory Bruteforcing

commix   Command Injection Exploitation

xsStrike   XSS-Detection und Exploitation  

Test


Information Gathering

   nmap   Netzwerk - und Port-Scanner

      sudo nmap -sC -sV 192.168.1.100

      sudo nmap -sS(U)V -sC scanme.nmap.org (U = UDP) --reason

      sudo nmap -sV -p 80,443 scanme.nmap.org --open

   maltego   Visuelle OSINT- und Link-Analyse

   theHarvester   E-Mail- und Subdomain-Sammlung

   recon-ng   Modulares OSINT-Framework

   spiderFoot   Automatisierte OSINT-Recherche

   shodan   Suchmaschine für IoT-Geräte

   dmitry   Deepmagic Information Gathering

   whois / dnsenum / fierce   DNS-Aufklärung



Vulnerability Analysis

   openVAS / Greenbone   Vollständiger Vulnerability Scanner

   nikto   Web-Server-Schwachstellenscanner

   nuclei   Template-basierter Vulnerability Scanner

   nessus   Industriestandard (kommerziell)

   lynis   Security Auditing für Unix/Linux

   wpScan   WordPress-Schwachstellenscanner





 Web Application Analysis

   burpSuite   Der Standard-Web-Proxy (Community/Pro)

   owasp zap   Kostenloser Web-App-Scanner

   sqlmap   Automatisierte SQL-Injection

   nikto   Web-Server-Scanner

   gobuster / Dirb / ffuf   Directory Bruteforcing

   commix   Command Injection Exploitation

   xsStrike   XSS-Detection und Exploitation





Password Attacks

   crunch   Wordlist-Generator

   cewl   Custom Wordlist Generator

   hashcat   GPU-basiertes Hash-Cracking (schnellstes)

   john the ripper   CPU-basiertes Hash-Cracking

   ncrack

   hydra   Online-Brute-Force (SSH, FTP, HTTP, etc.)

   medusa   Paralleles Brute-Force-Tool

   mimikatz   Windows-Credential-Extraktion

   wordlists

      cull, seclists, rockyou



Wireless Attacks

   aircrack-ng Toolbox   WEP/WPA/WPA2-Cracking Suite

   kismet   WLAN-Detektor und Sniffer

   wifite2   Automatisierter WLAN-Angriff

   reaver / Bully – WPS-PIN-Brute-Force

   fern wifiCracker – GUI-basiertes WLAN-Tool

   bettercap   Netzwerk Schweizer Taschenmesser


   




Exploitation Tools

   metasploit Framework   Das mächtigste Exploitation-Framework

   searchsploit   Offline-Exploit-Datenbank (Exploit-DB)

   beef   Browser Exploitation Framework

   armitage   Metasploit Oberfläche   --> GUI

   msfvenom   Payload Generator

   empire / covenant   Post Exploitation Frameworks






Sniffing & Spoofing

   wireshark   Netzwerk Protokoll Analyzer

   tcpdump   Paket Sniffer

   responder   LLMNR / NBT - NS / mDNS Poisoning

   ettercap   MITM-Framework

   bettercap   Modernes MITM-Tool

   mitmproxy   HTTP(S) Proxy

   sniffing

   netsniff-ng





Post Exploitation

   inPEAS / WinPEAS   Privilege Escalation Enumeration

   mimikatz   Windows Passwörter extrahieren

   bloodHound   Active Directory Angriffs Pfade

   crackMapExec   Netzwerk Penetration (SMB, WMI)

   impacket   Netzwerkprotokoll Toolkit

   powerSploit   PowerShell Post Exploitation





Forensics Tools

   autopsy   Grafische Forensik-Plattform

   volatility   RAM-Analyse (Memory Forensics)

   sleuth Kit   Dateisystem-Forensik

   binwalk   Firmware-Analyse

   foremost / Scalpel   File Carving

   dd / dcfldd   Forensische Disk Images




 Reverse Engineering

   ghidra   NSA Reverse Engineering Framework

   radare2 / r2   Kommandozeilen Disassembler

   ollyDbg / x64dbg   Windows Debugger

   gdb   GNU Debugger

   idaFree   Disassembler (kommerziell/Free)

   jd-GUI   Java Decompiler






Social Engineering

   set   (Social - Engineer - Toolkit) Phishing-Kampagnen 

   gophish   Open - Source Phishing Framework

   kingPhisher   Phishing Kampagnen Manager

   evilginx2   MITM Phishing Framework





Reporting Tools

   faraday   Collaborative Pentest-Plattform

   dradis   Reporting Framework

   cherryTree   Hierarchische Notiz App

   keepNote   Pentest Notizbuch

   pwndoc   Pentest Report Generator





Reverse Shell

   msfconsole

   metasploit

   powersploit


WEB

   burpSuite  --> GUI   Der Standard-Web-Proxy

   cap              -->  GUI

   nikto   Web-Server-Scanner

   

   gobuster / dirb / ffuf   FUZZen von HTTP(S) Zielen. Directory Bruteforcing


Firewall entdecken

   wafw00f -l      --> Liste aller Firewalls


Netzwerk

   netcat

      nc -lnvp <PORT> 


   nslookup

   whois

   dig

   hping3


Datenbank

   sqlmap   Automatisierte SQL-Injection

      Es ist laut, es erzeugt viel Verkehr und aggressive Flaggen (--risk=3 --level=5) kann die Zieldatenbank abstürzen lassen



SSH

   WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! (ssh-keygen -R 192.168.1.1)


Mobile

   apktool        --> Tool für Reengineering Android apk files





Links

https://kennyvn.com/top-10-kali-linux-tools/

https://itgrundlagen.com/13-praktische-tools/kali-linux-tools.html

https://hacking-kurse.de/white-hat-hacker/kali-linux-tools-uebersicht

https://redteamguide.com/guides/kali-linux-tools-beginners-2026/

https://phoenixnap.com/kb/kali-linux-tools




Suchen