Information Gathering
Maltego Visuelle OSINT- und Link-Analyse
theHarvester E-Mail- und Subdomain-Sammlung
Recon-ng Modulares OSINT-Framework
SpiderFoot Automatisierte OSINT-Recherche
Shodan Suchmaschine für IoT-Geräte
Dmitry Deepmagic Information Gathering
whois / dnsenum / fierce DNS-Aufklärung
Password Attacks
crunch Wordlist-Generator
CeWL Custom Wordlist Generator
hashcat GPU-basiertes Hash-Cracking (schnellstes)
john the ripper CPU-basiertes Hash-Cracking
ncrack
hydra Online-Brute-Force (SSH, FTP, HTTP, etc.)
medusa Paralleles Brute-Force-Tool
Mimikatz Windows-Credential-Extraktion
wordlists
cull, seclists, rockyou
Wireless Attacks
aircrack-ng Toolbox WEP/WPA/WPA2-Cracking Suite
kismet WLAN-Detektor und Sniffer
wifite2 Automatisierter WLAN-Angriff
iw (dev)
sniffing
bettercap Netzwerk Schweizer Taschenmesser
netsniff-ng
tcpdump Paket Sniffer
Reverse Shell
msfconsole
metasploit
powersploit
WEB
BurpSuite --> GUI Der Standard-Web-Proxy
Cap --> GUI
nikto Web-Server-Scanner
gobuster / dirb / ffuf FUZZen von HTTP(S) Zielen. Directory Bruteforcing
Firewall entdecken
wafw00f -l --> Liste aller Firewalls
Netzwerk
nmap
sudo nmap -sV 192.168.1.100 --reason
sudo nmap -sS(U)V -sC scanme.nmap.org (U = UDP)
sudo nmap -p 80,443 scanme.nmap.org --open -sV
netcat
nc -nv <IP:PORT>
nslookup
whois
dig
hping3
Datenbank
sqlmap Automatisierte SQL-Injection
Es ist laut, es erzeugt viel Verkehr und aggressive Flaggen (--risk=3 --level=5) kann die Zieldatenbank abstürzen lassen
SSH
WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! (ssh-keygen -R 192.168.1.1)
Mobile
apktool --> Tool für Reengineering Android apk files
Links
https://kennyvn.com/top-10-kali-linux-tools/
https://itgrundlagen.com/13-praktische-tools/kali-linux-tools.html
https://hacking-kurse.de/white-hat-hacker/kali-linux-tools-uebersicht
https://redteamguide.com/guides/kali-linux-tools-beginners-2026/
https://phoenixnap.com/kb/kali-linux-tools