Top Penetration Testing Tools

What Are Some of the Best Penetration Testing Tools You Should be Using?

Alec Auer, Falanx Cyber, conducts various types of penetration and compliance testing, including web application, internal infrastructure, email phishing, and Cyber Essentials. He has also achieved the Offensive Security Certified Professional (OSCP) qualification and is a CREST Registered Tester. Alec shares some of his top penetration testing tools.

The number of penetration testing tools, both open-source and commercial, is vast. However, over the years I have narrowed them down to the necessary essentials which can be used for almost any penetration test.

Each tool can serve multiple purposes and have a variety of uses; however, they stand out in certain categories and are my first option for penetration tests as a result. While other options are available, these are the ones I’ve personally found effective and easy-to-use.

Port Scanning

The first stage of a penetration test is to determine the attack surface and for this I like to use the Nmap port scanner.

Not only can it perform different port scans, it has an added scripting engine that gives a significant amount of information about open services.

The output of scans is also in several useful formats that can be manipulated and combined with other tools, and since it’s quite popular there are lots of additional plugins that have been developed for increased functionality.

Vulnerability Scanning

To help make penetration tests more time-efficient, a vulnerability scanner is essential. I tend to choose Nessus as it is straightforward to use and has different vulnerability scans for an added level of flexibility, depending on the test.

The scan is quick, provides an easy-to-read output and also has a good coverage of vulnerability plugins. This, plus Nmap, will be my first stage of a penetration test to find some juicy targets ripe for exploitation.

Click to view all articles for the EPIC:
Or click to view the full company profile:
Facebook
Twitter
LinkedIn
Falanx Cyber Security

More articles like this

Falanx Cyber Security

Ransomware fueled record year for UK cyber response

The U.K. National Cyber Security Centre fought a record number of digital intrusions in the past year, the agency reported, driven by a surge in ransomware and hackers targeting the health care sector during the COVID-19

Falanx Cyber Security

Top cybersecurity threats and emerging trends

Navigating the new threat landscape that is constantly evolving is certainly both a challenge and an opportunity for organisations to prepare and address the growing cyber-attacks and mitigate risks. Introduction and increase in remote working culture,

Falanx Cyber Security

How to build a culture of cyber security in your business

Cyber-attacks are more prominent, far-reaching and impactful than ever. From the major incidents that dominate front pages and cause geopolitical confrontations, through to the plague of scam emails that businesses and individuals deal with on a

Falanx Cyber Security

Latest Cyber Security Incident: Angling Direct

Angling Direct, one of the largest fishing tackle specialists, has announced that it is currently managing a cyber security incident. Links on their website were replaced with links to adult content, and the company’s Facebook and

Falanx Cyber Security

How schools can take cybersecurity to the next level

Establishing security measures to prevent further cyberattacks is an important step in a district’s cybersecurity strategy—particularly in the wake of security risks from at-home learning during the global pandemic In early March, 15 schools in the

Falanx Cyber Security

Sector In Focus: Education

The education sector is being increasingly targeted with ransomware attacks, as evidenced by the recent attack on the University of Sunderland. Although the university has not officially announced that the problems were caused by ransomware, the

Falanx Cyber Security

October is Cybersecurity Awareness Month

October is Cybersecurity Awareness Month to raise awareness of the many ways individuals and organizations can be targeted by criminals online. According to the Federal Bureau of Investigation, 16,000 Nevadans were targeted by cybercriminals and online

Falanx Cyber Security

Biden signs school cybersecurity bill

The Cybersecurity and Infrastructure Security Agency will study the cyber risks facing elementary and secondary schools and develop recommendations to assist schools in facing those risks. President Joe Biden has signed a bill into law aimed at helping