Top Penetration Testing Tools

What Are Some of the Best Penetration Testing Tools You Should be Using?

Alec Auer, Falanx Cyber, conducts various types of penetration and compliance testing, including web application, internal infrastructure, email phishing, and Cyber Essentials. He has also achieved the Offensive Security Certified Professional (OSCP) qualification and is a CREST Registered Tester. Alec shares some of his top penetration testing tools.

The number of penetration testing tools, both open-source and commercial, is vast. However, over the years I have narrowed them down to the necessary essentials which can be used for almost any penetration test.

Each tool can serve multiple purposes and have a variety of uses; however, they stand out in certain categories and are my first option for penetration tests as a result. While other options are available, these are the ones I’ve personally found effective and easy-to-use.

Port Scanning

The first stage of a penetration test is to determine the attack surface and for this I like to use the Nmap port scanner.

Not only can it perform different port scans, it has an added scripting engine that gives a significant amount of information about open services.

The output of scans is also in several useful formats that can be manipulated and combined with other tools, and since it’s quite popular there are lots of additional plugins that have been developed for increased functionality.

Vulnerability Scanning

To help make penetration tests more time-efficient, a vulnerability scanner is essential. I tend to choose Nessus as it is straightforward to use and has different vulnerability scans for an added level of flexibility, depending on the test.

The scan is quick, provides an easy-to-read output and also has a good coverage of vulnerability plugins. This, plus Nmap, will be my first stage of a penetration test to find some juicy targets ripe for exploitation.

Click to view all articles for the EPIC:
Or click to view the full company profile:
Facebook
Twitter
LinkedIn
Falanx Cyber Security

More articles like this

Falanx Cyber Security

Rob Shapland speaking at International Cyber Security Expo 2022

Catch Rob Shapland our very own head of innovation and ethical hacker at this years International Cyber Security Expo. Where: Kensington Olympia, London.When: 28th September, 2022Session Time: 11.30am Rob will be presenting: How to Steal a Vaccine  The importance of

Falanx Cyber Security

Falanx Group expecting further growth in orders in H2 FY23

Falanx Group Ltd (LON:FLX), the AIM listed provider of cyber security services, has announced its audited results for the year-ended 31 March 2022.    Financial highlights • Revenues £3.54m (2021: £3.12m), an increase of 14% • Closing Monthly Recurring Revenues (“MRR”)

Falanx Cyber Security

Why cyber security operation centres should be UK based

The current financial environment has everyone money conscious, but many companies are still leaving themselves vulnerable to big pay-outs to cyber fraudsters. Cyber criminals earn three times the average salary of a FTSE 100 chief executive,

Falanx Cyber Security

You have to live and breathe entrepreneurship

Serial founder Nicola Hartland has scaled and sold several businesses from Aberdeen to Basingstoke. She reveals the secrets to her success. Falanx Cyber When Falanx Cyber – part of publicly listed Reading-headquartered Falanx Group – sought

Falanx Cyber Security

Transport operator Go-Ahead flags cyber security breach

British transport operator Go-Ahead (GOG.L) said that it had detected “unauthorised activity” on its network earlier in the week, adding that the cyber security incident had no impact on its UK or international rail services. The incident has

Falanx Cyber Security

The fallout from the NHS cyber attack

On August 4th, British software services provider, Advanced experienced a disruption to their systems that they have determined to be the result of a ransomware attack. It just so happens Advanced provides 85% of 111 services for the

Falanx Cyber Security

Rob Shapland speaking at International Cyber Security Expo 2022

Where: Kensington Olympia, London.When: 28th September, 2022Session Time: 11.30am Rob will be presenting: How to Steal a Vaccine  The importance of vaccines in the age of Covid-19 cannot be underestimated. This session will describe how the speaker planned and executed

Falanx Cyber Security

How to develop a data breach response plan

Data breaches happen at all organizations. Even the most effective defensive layers — endpoint and managed detection and response, multifactor authentication and employee awareness training programs — are beatable if the attacker is sufficiently skilled or

Falanx Cyber Security

Falanx Group optimistic about outlook of the business

Falanx Group Ltd (LON:FLX), the AIM listed provider of cyber security services, has provided an update on its results for the year ended 31 March 2022 and the first quarter’s trading to 30 June 2022. Results

Falanx Cyber Security

Why are charities falling behind on cyber security?

According to latest research, charity leaders are lagging behind their counterparts in the public and private sectors in their understanding of cyber security. This knowledge gap is across a raft of areas, from reporting breaches and providing staff

Falanx Cyber Security

How resilient is your business against cyber threats?

Be cyber ready with a security assessment Falanx Cyber’s security assessment service evaluates your current security maturity and ability to respond and recover from cyber attacks. We use the 5 pillars of cyber resilience as a

Falanx Cyber Security

Falanx Cyber’s Rob Shapland appears on DW’s The Day

Falanx Group plc (LON:FLX) is an AIM-listed security and intelligence provider based in London in the United Kingdom. Falanx Group is a team of security professionals and technology experts who work in close partnership with our clients to

Falanx Cyber Security

Could your business survive 21 days of downtime?

Business disruption All of our businesses have suffered a fair degree of disruption in recent years as we responded to the effects of the pandemic. But what would be the effect of losing access to all