Microland Ltd
Details of the Information Security Audit Tools
Freeware Tools
Vulnerability Assessment and Penetration Testing
- Nessus : Vulnerability scanner - Port scan/ Vulnerability scan /web application security scan
- Nikto : Web application vulnerability scanner
- Superscan : Port scanner
- Dsniff : collection of tools for network auditing and penetration testing
- Whisker/Libwhisker : CGI vulnerability scanner
- Network Stumbler : Tool to find open wireless access points
- SARA : vulnerability assessment tool
- Achillies : Web application security - proxy
- Brutus : Password brute forcing tool
- SPIKE Proxy : HTTP proxy for finding security flaws in web sites
- Winfingerprint : Win32 Host/Network Enumeration Scanner
- Auditor : Collection of Tools to conduct security audit.
Footprinting
- Greenwhich
- Whois
- Gnetutil : Network Utilities
- Itrace : ICMP traceroot
- Tctrace : TCP traceroute
- Traceroute
- DNSwalk : DNS verification
- Dig : DNS lookup
- Host : DNS lookup
- NSTXCD : IP over DNS client
- NSTXD : IP over DNS server
- Oxyman : DNS tunnel
- Curl : URL transfer
- Elinks : Console web browser
- Konqueror : Web browser
- Socat : Socket Cat
- Stunnel : Universal SSL tunnel
- Arpfetch : SNMP ARP/IP fetcher
- SNMP Walk : SNMP tree walk
- TKMib : Mib brower
- Komba2 : KDE SMB browser
- LinNeighborhood : Graphical SMB browser
- Net utils : NET utilities
- SMBClient : SMB client
- SMBGet : SMB downloader
- Smb4K : SMB share browser
- Xsmbrowser : Graphical SMB browser
- nmblookup : Netbios name lookup
- smbdumpusers : User browser
- smbgetserverinfo : Get server info
- Cheops : Network neighborhood
- NTP-fingerprint : Detection based on ntp fingerprint
- Nmap : Network scanner
- NmapFE : Graphical network scanner
- P0f : Passive OS detection
- Queso : OS detection
- XProbe2 : OS detection
Scanning
- Cisco global exploiter : Cisco scanner
- Cisco torch : Cisco oriented scanner
- ExploitTree search : ExploitTree collection
- Metasploit : Metasploit commandline
- Metasploit : Metasploit console GUI
- Metasploit : Metasploit web interface
- Nessus : security Scanner
- Raccess : remote Scanner
- Httprint : Webserver fingerprinting
- Nikto : Webserver scanner
- Stunnel : Universal SSL tunnel
- Cheops : Network neighborhood
- GTK-Knocker : Simple GUI portscanner
- IKE-Scan : IKE scanner
- Knocker : Simple portscanner
- Netenum : Pingsweep
- Netmask : Request neetmask
- Nmap : Network Scanner
- NmapFE : Graphical network scanner
- Proxychains : Proxifier
- Scanrand : Stateless scanner
- Timestamp : Requests timestamp
- Unicornscan : Fast port scanner
- Isrscan : Source routed packets scanner
- Amap : Application identification
- Bed.pl : Application fuzzer
- SNMP-Fuzzer : SNMP protocol fuzzer
- ScanSSH : SSH identification
- Nbtscan : Netbios scanner
- SMB-Nat : SMB access scanner
- Ozyman : DNS tunnel
- Ass : Autonomous system scanner
- Protos : Protocol identification
Analyzer
- AIM-SNIFF : AIM sniffer
- Driftnet : Image sniffer
- Mailsnart : Mail sniffer
- Paros : HTTP interception proxy
- URLsnarf : URL sniffer
- smbspy : SMB sniffer
- Etherape : Network monitor
- Ethereal : Network analyzer
- Ettercap : Sniffer/Interceptor/Logger
- Hunt : Sniffer/Interceptor
- IPTraf : Traffic monitor
- Ngrep : Network grep
- NetSed : Network edit
- SSLDump : SSLv3/TLS analyzer
- Sniffit : Sniffer
- TcPick : Packet stream editor
- Dsniff : Password sniffer
Spoofing
- Arpspoof : ARP spoofer
- Macof : ARP spoofer/generator
- Nemesis-ARP : ARP packet generator
- Nemesis-Ethernet : Ethernet packet generator
- CDP : CDP generator
- DNSSpoof : DNS spoofer
- Nemesis-DNS : DNS packet generator
- DHCPX : DHCP flooder
- Hping2 : Packet generator
- ICMRRedirect : ICMP redirect packet generator
- ICMPUSH : ICMP packet generator
- Nemesis-ICMP : ICMP packet generator
- Packit : Traffic inject/modify
- TcPick : Packet stream editor
- Yersinia : Layer 2 protocol injector
- Fragroute : Egress rewrite
- HSRP : HSRP generator
- IGRP : IGRP injector
- IRDP : IRDP generator
- IRDPresponder : IRDP response generator
- Nemesis-IGMP : IGMP generator
- Nemesis-RIP : RIP generator
- File2Cable : Traffic replay
- Fragrouter : IDS evasion toolkit
- Nemesis-IP : IP packet generator
- Nemesis-TCP : TCP packet generator
- Nemesis-UDP : UDP traffic generator
- SendIP : IP packet generator
- TCPReplay : Traffic replay
- Etherwake : Generate wake-on-LAN
Bluetooth
- BTScanner : Bluetooth scanner
- Bluesnarfer : Bluesnarf attack
- Ghettotooth : Bluetooth scanner
- Kandy : Mobile phone tool
- Obexftp Obexftp ftp client
- Phone manager
- RFComm : Bluetooth serial
- RedFang : Bluetooth bruteforce
- USSP-Push : Obex-push
- Xminicom : Terminal
Wireless
- apmde.sht : Act as accesspoin
- Airpwn : Client penetration
- Hotspotter : Client penetration
- GpsDrive
- start-gps-daemon : GPS daemon
- stop-gps-daemon : GPS daemon
- ASLeap : LEAP/PPTP cracker
- Genkeys : Hash generator for ASLeap
- Airforge
- File2air : Packet injector
- Void11
- Void11-Hopper : Channel hopper
- Gkismet : Graphical wireless scanner
- GPSMAP : wireless mapping
- KLV : Kismet Log Viewer
- Kismet : Ncurses wireless scanner
- Wellenreiter : Graphical Wireless scanner
- 802ether : Dumpfile format convertor
- airodump : Traffic recorder
- aircrack : Modern WEP cracker
- Aireplay : Wireless packet injector
- Wep-Crack : Wep Cracker
- Wep_Decrypt : Decrypt dump files
- Airsnort : GUI based WEP cracker
- ChopChop : Active WEP attack
- DWEPCrack : WEP cracker
- Decrypt : Dump file decrypter
- WEPAtttack : Dictionary attack
- WEPlab : Modem WEP cracker
- Cowpatty : WPA PSK bruteforcer
- changemac.sh : MAC address changer
Bruteforce
- ADMsnmp : SNMP bruteforce
- Guess-who : SSH bruteforce
- Hydra : Multi purpose bruteforce
- K0ldS : LDAP bruteforce
- Obiwan III : HTTP bruteforce
- SMB-Nat : SMB access scanner
- TFTP : bruteforce
- VNCrack : VNC bruteforce
- Xhydra : Graphical bruteforcer
Password Cracker
- BKHive : SAM recovery
- Fcrackzip : Zip password cracker
- John : Multi-purpose password cracker
- Default password list :
- Nasty : GPG secret key cracker
- Rainbowcrack : Hash cracker
- Samdump2 : SAM file dumper
- Wordlists : Collection of wordlists
Forensics
- Autopsy : Forensic GUI
- Recover : Ext2 file recovery
- Testdisk : Partition scanner
- Wipe : Securely delete files
Honeypot
- IMAP
- POP3
- Honeyd : Honeypot
- IISEmulator : Honeypot
- Tinyhoneypot : Simple honeypot
Commercial Tools
Proprietary Tools