OSINTDFIRRoadmapsToolsCareercyber security

89 Offensive Linux Security Tools Every Ethical Hacker Must Know in 2026

89 Offensive Linux Security Tools Every Ethical Hacker Must Know in 2026

Complete Cheat Sheet + What Each Tool Does

If you open Kali Linux for the first time, you’ll see 600+ tools and panic.

Which one do I use? What does this even do?

So I broke down the 89 most important Offensive Linux Security Tools into 14 categories. This is the exact toolkit that real Penetration Testers and Red Teamers use in 2026.

Disclaimer: Only use these tools on systems you own or have written permission to test. Ethical hacking only.

THE 14 CATEGORIES 89 TOOLS

  • RECONNAISSANCE 14 Tools

Goal: Gather info about the target before attacking

This is 80% of a real pentest.

  • Recon-ngvWeb recon framework. Like Google Dorking on steroids
  • theHarvester Find emails, subdomains, employees from public sources
  • Nmap The king. Port scanning service detection
  • Zenmap GUI for Nmap
  • DNSRecon DNS enumeration and zone transfers
  • Mitaka OSINT tool for domains and IPs
  • Maltego Link analysis. Map relationships between people/companies
  • Fierce Domain scanner for subdomains
  • SpiderFoot Automate OSINT collection
  • Masscan Nmap but 10x faster. Scan entire internet
  • ZMap Network scanner for research
  • Amass n-depth subdomain discovery
  • VULNERABILITY SCANNING 6 Tools

Goal: Find weaknesses automatically

  • OpenVAS Free enterprise vulnerability scanner
  • Wapiti Black-box web app scanner
  • Nikto Web server vulnerability scanner
  • Vuls Vulnerability scanner for Linux/FreeBSD
  • Nessus Industry standard. Paid but worth it
  • Nuclei Fast vulnerability scanner with templates
  • NETWORK-BASED ATTACKS - 9 Tools

Goal: Attack networks directly

  • Wireshark Packet sniffer. See everything on the network
  • Ettercap Man-in-the-Middle attacks
  • ArpSpoof ARP poisoning tool
  • NetCat Swiss Army knife for networking
  • Scapy Python packet manipulation
  • hping3 TCP/IP packet crafter
  • Yersinia Attack STP, CDP, DTP protocols
  • NetExec Network exploitation tool
  • mitmproxy Intercept and modify HTTP/HTTPS traffic
  • PASSWORD & BRUTE FORCE ATTACKS 11 Tools

Goal: Crack passwords

  • John the Ripper Classic password cracker
  • Hashcat GPU password cracker. Fastest in the world
  • Crunch Wordlist generator
  • Hydra Online brute force for logins
  • Medusa Parallel login brute forcer
  • CeWL Generate wordlists from websites
  • Patator Multi-purpose brute forcer
  • Hashtopolis Distributed password cracking
  • pydictor Python dictionary builder
  • Kraken Network password cracker
  • L0phtCrack Windows password auditor
  • EXPLOITATION 18 Tools

Goal: Exploit the vulnerabilities you found

  • Metasploit The 1 exploitation framework
  • Ghauri SQL Injection exploitation tool
  • PTF PenTesters Framework. Install all tools
  • jSQL Injection Automatic SQLi tool with GUI
  • sqlmap Automatic SQL injection + DB takeover
  • Armitage GUI for Metasploit
  • BeEF Browser Exploitation Framework
  • RouterSploit Exploit embedded devices
  • ShellNoob Shellcode compiler
  • ysoserial Deserialization payload generator
  • Ropper Gadget finder for ROP attacks
  • Commix Command injection exploiter
  • Exploit-DB Database of public exploits
  • Pwntools CTF and exploit development library
  • SearchSploit Search Exploit-DB from terminal
  • XSSer Automatic XSS scanner
  • Impacket Python classes for network protocols
  • POST-EXPLOITATION - 12 Tools

Goal: What to do after you get access

  • Empire PowerShell post-exploitation agent
  • Pupy Cross platform remote admin tool
  • Bloodhound Map Active Directory attack paths
  • Mimikatz Extract passwords from Windows memory
  • Dnscat2 Command and control over DNS
  • Havoc Modern C2 framework
  • Meterpreter Advanced payload from Metasploit
  • BeRoot Privilege escalation checker
  • Pwncat Netcat on steroids
  • Silver Cross-platform C2 agent
  • Mythic C2 framework for red teams
  • PEASS-ng Privilege Escalation Awesome Scripts
  • WIRELESS ATTACKS - 8 Tools
  • Kismet Wireless network detector
  • PixieWPS Offline WPS attack
  • Wifite Automated wireless attack tool
  • Reaver Brute force WPS PINs
  • Aircrack-ng WiFi password cracking suite
  • airgeddon Multi-use bash script for WiFi
  • Wifi Pumpkin Rogue AP framework
  • hcxdumptool Capture WPA handshakes
  • SOCIAL ENGINEER & PHISHING - 4 Tools
  • SET Social Engineer Toolkit
  • Gophish Phishing campaign framework
  • King Phisher Phishing campaign tool
  • PhishX Modern phishing framework
  • WEB APP PEN TESTING - 5 Tools
  • Burp Suite The 1 web app proxy $ Industry standard
  • OWASP ZAP Free alternative to Burp
  • Arachni Web application security scanner
  • Wfuzz Web application fuzzer
  • Katana Fast web crawler
  • ffuf Fast web fuzzer
  • MOBILE SECURITY - 9 Tools
  • Drozer Android security assessment
  • Androguard Reverse engineering for Android
  • Frida Dynamic instrumentation toolkit
  • MobSF Mobile Security Framework
  • APKiD Android app identifier
  • NetHunter Kali Linux for Android
  • JADX Decompile Android APKs
  • Apktool Reverse engineer Android apps
  • Quark Engine Android malware analysis
  • REVERSE ENGINEERING - 3 Tools
  • Radare2 Unix-like reverse engineering framework
  • Ghidra NSA’s free reverse engineering tool
  • Angr Binary analysis platform
  • REPORTING & DOCUMENTATION - 5 Tools

Pentesters spend 40% of time here. Clients pay for reports.

  • Dradis Collaboration and reporting
  • Faraday Vulnerability management platform
  • Ghostwriter Reporting tool for pentesters
  • PwnDoc Pentest reporting app
  • SysReptor Modern reporting platform

HOW TO USE THIS LIST AS A BEGINNER: 200 words

Don’t try to learn all 89. You’ll burn out.

90-Day Learning Path:

Month 1: Recon + Scanning. Master Nmap, Recon-ng, Nuclei

Month 2: Web + Exploitation. Master Burp Suite, sqlmap, Metasploit

Month 3: Post-Exploit + Reporting. Master Bloodhound, Mimikatz, Dradis

Build 3 projects with these and you can apply for Jr Pentester jobs.

CONCLUSION

This is the offensive toolkit for 2026. Every tool here is free except Nessus and Burp Pro.

Save this page. It’s your roadmap.

0 Comments

Leave a comment

Funded seats · Limited intake

Scholarship Courses Registration

Mentor-led tracks in OSINT, DFIR, and offensive security — with funded seats for qualifying students.