Network & Protocol
Packets, MITM, SMB/LDAP, and classic network interaction tools.
Bettercap
NetworkModern network attack and monitoring framework for ARP/DNS spoofing, sniffing, and credential attacks on authorized LANs.
Ettercap
NetworkLAN MITM framework for ARP poisoning, sniffing, and filter-based traffic manipulation on authorized networks.
hping3
NetworkCustom TCP/UDP/ICMP packet crafting for firewall testing, traceroute, and port probing on authorized hosts.
Netcat
NetworkTCP/UDP connect, listen, and port relay for banners, shells, and file transfer on authorized networks.
Pivoting & Tunneling
NetworkSSH tunneling, port forwarding, SOCKS proxies, and pivoting with chisel/ligolo to reach internal networks during authorized engagements.
Proxychains
NetworkForce TCP connections through SOCKS4/5 or HTTP proxies for pivoting during authorized internal assessments.
Responder
NetworkLLMNR/NBT-NS/mDNS poisoner and rogue authentication server for capturing NetNTLM hashes on authorized Windows networks.
rpcclient
NetworkMS-RPC client for SAMR/LSA enumeration and user management via null or authenticated sessions on authorized domains.
SMB Enumeration
NetworkEnumerate SMB: shares, null sessions, users, and versions with nmap, netexec, smbclient, and enum4linux on authorized networks.
smbclient
NetworkSMB/CIFS client for share enumeration, file access, and null-session testing on authorized Windows hosts.
socat
NetworkBidirectional data relay for shells, port forwarding, and protocol bridging on authorized networks.
tcpdump
NetworkCommand-line packet capture and filtering for authorized network analysis and troubleshooting.
tshark
NetworkCLI Wireshark for capture, display filters, and protocol field extraction on authorized traffic.
Wireshark Filters
NetworkWireshark display and capture filter syntax for slicing packet captures during analysis and forensics.