0% found this document useful (0 votes)
5 views2 pages

Essential Tools for Ethical Hacking

The document outlines the prerequisite tools and phases for Vulnerability Assessment and Penetration Testing (VAPT). It lists essential software such as VirtualBox, Kali Linux, and various tools for reconnaissance, scanning, vulnerability assessment, exploitation, and post-exploitation. Each tool is accompanied by a link for download or further information.

Uploaded by

xan parker
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views2 pages

Essential Tools for Ethical Hacking

The document outlines the prerequisite tools and phases for Vulnerability Assessment and Penetration Testing (VAPT). It lists essential software such as VirtualBox, Kali Linux, and various tools for reconnaissance, scanning, vulnerability assessment, exploitation, and post-exploitation. Each tool is accompanied by a link for download or further information.

Uploaded by

xan parker
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

Prerequisite Tools

VirtualBox – To run VMs for lab setup


🔗 [Link]

Kali Linux ISO – Popular Linux distro for penetration testing


🔗 [Link]

VMware Workstation Player (Optional) – Alternative to VirtualBox


🔗 [Link]

OWASP Broken Web Applications (BWA) / DVWA / Metasploitable – Vulnerable machines


for practice

DVWA: [Link]

Metasploitable 2: [Link]

BWA: [Link]

🔍 VAPT Phases & Tools


1. Reconnaissance (Information Gathering)
Nmap – Network discovery and port scanning
🔗 [Link]

Recon-ng – Web reconnaissance framework


🔗 [Link]

theHarvester – Email, domain, and employee enumeration


🔗 [Link]

Shodan – Internet-connected device search


🔗 [Link]

2. Scanning & Enumeration


Nmap – (Again, for detailed service and OS detection)
🔗 [Link]

Nikto – Web server vulnerability scanner


🔗 [Link]

Dirb / Dirbuster – Directory brute-forcing

Dirb: [Link]

Dirbuster: [Link]

3. Vulnerability Assessment
OpenVAS (Greenbone) – Vulnerability scanner
🔗 [Link]

Nessus (by Tenable) – Comprehensive scanner (free trial available)


🔗 [Link]

Vulners – Search engine for known vulnerabilities


🔗 [Link]

4. Exploitation
Metasploit Framework – Exploitation toolkit
🔗 [Link]
SQLMap – SQL injection automation tool
🔗 [Link]

ExploitDB – Repository of public exploits and PoCs


🔗 [Link]

5. Post-Exploitation
Meterpreter (via Metasploit) – Post-exploitation shell
🔗 [Link]

You might also like