Nmap
The gold standard network scanner. Port scanning, service detection, OS fingerprinting.
scanner
Masscan
Internet-scale port scanner. Scans the entire Internet in under 5 minutes.
scanner
Recon-ng
Full-featured web reconnaissance framework with modular design.
osint
theHarvester
E-mail, subdomain, and name harvester from public sources.
osint
Maltego
Interactive data mining and link analysis for OSINT investigations.
osint
Amass
In-depth attack surface mapping and asset discovery via DNS.
dns
Subfinder
Fast passive subdomain enumeration using multiple sources.
dns
Dmitry
Deepmagic information gathering tool for host intelligence.
osint
Enum4linux
SMB/Samba enumeration. Extract shares, users, groups.
smb
NBTscan
NetBIOS name network scanner for Windows host discovery.
smb
Onesixtyone
Fast SNMP community string scanner.
snmp
SNMPwalk
Retrieve full SNMP MIB tree from network devices.
snmp
DNSRecon
DNS enumeration: zone transfers, brute force, cache snooping.
dns
Fierce
DNS reconnaissance tool for locating non-contiguous IP space.
dns
Netdiscover
Active/passive ARP reconnaissance on local networks.
network
ARP-scan
Low-level ARP packet sender for Layer 2 host discovery.
network
Zenmap
Official Nmap GUI with topology mapping and scan comparison.
scanner
Nikto
Web server vulnerability scanner. 6,700+ dangerous files/CGIs.
web
WhatWeb
Website fingerprinter. Identifies CMS, frameworks, server tech.
web
wafw00f
Web Application Firewall detection and fingerprinting.
web