Penetration testing tools make sense when you sort them by the job they do in a test, not by fame. An authorised test moves through phases, from scoping to reporting, and each phase has two or three tools that do most of the work.
For each tool below you’ll get what it’s for, where it sits in an engagement, and how defenders see it. The early phases include commands for your own lab. The later phases deliberately don’t: you learn those on intentionally vulnerable machines.
Legal note: only test systems you own or have written permission to test. Every example here targets a private lab range (10.10.10.0/24), the fictional
acme-fintech.test, orscanme.nmap.org, which the Nmap project allows for light test scans.
What tools do penetration testers actually use?
Most testers work from Kali Linux, which ships with these tools preinstalled. But knowing which tool answers which question matters far more than the distribution:
| Phase | Question you’re answering | Beginner tools |
|---|---|---|
| Scoping and notes | What am I allowed to touch, and what have I found? | CherryTree, Obsidian |
| Reconnaissance and OSINT | What does the target expose before I touch it? | dig, crt.sh, theHarvester |
| Scanning and enumeration | Which hosts, ports, services and paths exist? | Nmap, Nikto, Gobuster, ffuf |
| Web testing | How does the application really behave? | Burp Suite Community, ZAP |
| Password auditing | Are the passwords strong enough? | Hashcat, John the Ripper |
| Exploitation | Can this weakness actually be used? | Metasploit Framework |
| Post-exploitation and AD | How far could an attacker get from here? | BloodHound |
| Wireless | Is the Wi-Fi configured safely? | Aircrack-ng suite |
| Reporting | What did I find, and how is it fixed? | Report templates, CVSS |
NIST SP 800-115, NIST’s technical guide to security testing, describes the same flow of planning, discovery, attack and reporting. For a walkthrough on a fictional company, see the phases of a penetration test.
Scoping and notes: CherryTree or Obsidian
The first tool isn’t a hacking tool. A test starts with a signed scope: the ranges, domains and applications you may test, the dates, and what’s off limits. Every command you run should trace back to it.
A note-taking app holds it together. CherryTree keeps everything in one hierarchical file; Obsidian uses plain Markdown files that are easy to back up. Either way, set up sections for scope, recon, each host, findings and evidence before you scan anything, and save raw output as you go. When you write the report a week later, “I think port 8080 was open” is no use to anyone.
Reconnaissance and OSINT
Reconnaissance means learning about the target, ideally before sending it a packet. Passive OSINT (open-source intelligence) uses public sources: DNS records, certificate transparency logs, job adverts that name the tech stack, and public code.
In a lab with its own DNS server, dig shows you what the domain publishes:
$ dig @10.10.10.53 acme-fintech.test MX +short
10 mail.acme-fintech.test.
$ dig @10.10.10.53 acme-fintech.test AXFR
acme-fintech.test. 3600 IN NS ns1.acme-fintech.test.
api.acme-fintech.test. 3600 IN A 10.10.10.20
dev.acme-fintech.test. 3600 IN A 10.10.10.25
mail.acme-fintech.test. 3600 IN A 10.10.10.30
The second command is a zone transfer. A well-configured DNS server refuses it; when it succeeds, you get every name at once, including dev, which nobody meant to advertise. You’d also check certificate transparency logs (crt.sh) for subdomains, and theHarvester gathers names, emails and hosts from public sources.
How defenders see it: passive OSINT is largely invisible, which is why defenders should run it on themselves. Zone transfer attempts do show up in DNS server logs.
Scanning and enumeration: Nmap, Nikto, Gobuster and ffuf
Now you touch the target. Scanning finds live hosts and open ports; enumeration digs into what each service is and what it gives away.
Nmap
Nmap is the tool every tester learns first. A host discovery sweep of the lab:
$ sudo nmap -sn 10.10.10.0/24
Nmap scan report for 10.10.10.20
Host is up (0.00041s latency).
Nmap scan report for 10.10.10.25
Host is up (0.00038s latency).
Nmap scan report for 10.10.10.30
Host is up (0.00044s latency).
Nmap scan report for 10.10.10.53
Host is up (0.00036s latency).
Nmap done: 256 IP addresses (4 hosts up) scanned in 2.31 seconds
Then service and version detection on one host:
$ sudo nmap -sV -sC -p- 10.10.10.20
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.52 ((Ubuntu))
|_http-title: Acme Fintech - Customer Portal
3306/tcp open mysql MySQL 8.0.39
A database port reachable from the network is a finding in itself. Against a real internet host, keep it light: nmap -F scanme.nmap.org scans the 100 most common ports. Our Nmap commands cheat sheet covers 25 more commands with output.
Nikto
Nikto checks a web server for known risky files, outdated software and missing security headers:
$ nikto -h http://10.10.10.20
+ Target IP: 10.10.10.20
+ Target Port: 80
+ Server: Apache/2.4.52 (Ubuntu)
+ /: The X-Content-Type-Options header is not set.
+ /phpinfo.php: Output from the phpinfo() function was found.
+ /backup/: Directory indexing found.
Nikto is a noisy first pass with false positives; confirm every item by hand.
Gobuster and ffuf
These find unlinked content by trying names from a wordlist (this one ships with Kali):
$ gobuster dir -u http://10.10.10.20 -w /usr/share/wordlists/dirb/common.txt
/admin (Status: 301) [Size: 316] [--> http://10.10.10.20/admin/]
/backup (Status: 301) [Size: 317] [--> http://10.10.10.20/backup/]
/server-status (Status: 403) [Size: 276]
$ ffuf -u http://10.10.10.20/FUZZ -w /usr/share/wordlists/dirb/common.txt -mc 200,301,302
admin [Status: 301, Size: 316, Words: 20, Lines: 10, Duration: 3ms]
backup [Status: 301, Size: 317, Words: 20, Lines: 10, Duration: 2ms]
Gobuster is simpler; ffuf is more flexible, because FUZZ can sit in a parameter, header or subdomain.
How defenders see it: scanning is loud. A firewall or IDS sees one source touch hundreds of ports in seconds; web logs fill with 404s from one IP, often with a tool’s default user agent. That’s why testers agree the test window in advance, so the blue team isn’t chasing a “breach” that’s on the calendar.
Web testing: Burp Suite Community and ZAP
Most modern testing is web and API work, built around an intercepting proxy that sits between your browser and the application so you can see, pause and change every request.
Burp Suite Community Edition is free and comes with its own preconfigured browser (Proxy > Intercept > Open browser), which saves you installing certificates for a first lab. If you use your own browser instead, point it at the proxy on 127.0.0.1:8080, then visit http://burpsuite to download and trust Burp’s CA certificate. A quick check from the terminal that traffic is flowing through the proxy:
$ curl -x http://127.0.0.1:8080 -I http://10.10.10.20/login
HTTP/1.1 200 OK
Server: Apache/2.4.52 (Ubuntu)
Content-Type: text/html; charset=UTF-8
The request should appear under Proxy > HTTP history. Community throttles Intruder and has no automated scanner, but Proxy, Repeater and Decoder are enough to learn on. Our Burp Suite tutorial for beginners goes step by step.
ZAP (long known as OWASP ZAP) is the open-source alternative, with a free automated scanner. It also defaults to port 8080, so change one if you run both. Use the OWASP Web Security Testing Guide as your checklist for what to test once traffic is flowing.
How defenders see it: manual proxied testing can look like a normal user. The giveaways are in application logs: odd parameter values, one request repeated with small changes, bursts of errors. A web application firewall often flags automated scanning quickly.
Password auditing: Hashcat and John the Ripper
Password auditing tests whether stored hashes would resist an attacker who obtained them. Hashcat uses graphics cards to test huge numbers of candidates; John the Ripper is CPU-friendly and good at recognising hash formats. Testers use them on hashes recovered during an engagement, to show that “Summer2026!” passes the complexity rule yet is still weak.
Offline cracking works on a copy of the hashes, so the target never sees it. Online guessing hits a live login, is noisy and can lock real accounts, so it needs explicit permission in scope.
How defenders see it: offline cracking leaves no network trace, so defenders watch for the theft before it: access to LSASS or the NTDS.dit database, and Kerberos service ticket requests (event ID 4769) using RC4 encryption, a Kerberoasting pattern. Online guessing shows up as failed logons (event ID 4625) and lockouts.
Practise legally: TryHackMe and HackTheBox both have rooms on hash types and cracking, using hashes they hand you for the purpose.
Exploitation frameworks: Metasploit
The Metasploit Framework is a library of modules plus a console. Exploit modules target known vulnerabilities, auxiliary modules handle scanning and checks, payloads decide what runs after access, and post modules work on a compromised host.
A professional uses it to confirm, in a controlled way and inside scope, that a vulnerability is real. Plenty of tests barely touch it, and knowing why a module works matters more than firing it.
How defenders see it: Metasploit’s default payloads are heavily signatured, so endpoint tools flag them quickly. Defenders also watch the behaviour: a web server spawning a shell, outbound connections to unusual ports, and process creation events (Windows event ID 4688 or Sysmon event ID 1) that make no sense for that host.
Practise legally: Metasploitable 2 is a deliberately vulnerable virtual machine from Rapid7. Run it on a host-only network with no internet access. HackTheBox and TryHackMe also have beginner machines built for Metasploit.
Post-exploitation and Active Directory: BloodHound
Most organisations run Active Directory, where a small foothold often becomes full control. BloodHound collects users, groups, sessions and permissions and draws them as a graph that shows paths: this help-desk account can reset that user’s password, who is local admin where a domain admin is logged in.
Testers use it to show how one compromised account could lead to domain admin; defenders use it to find and cut those paths first.
How defenders see it: its collectors make many LDAP queries and SMB connections from one workstation in a short window. Identity detection tools such as Microsoft Defender for Identity alert on this kind of reconnaissance.
Practise legally: build a small AD lab (one domain controller, one workstation), or use the AD paths on TryHackMe and HackTheBox. See how to build a cybersecurity home lab for options.
Wireless: the Aircrack-ng suite
Wireless testing checks encryption, password strength, rogue access points and guest network separation. The Aircrack-ng suite is standard and needs an adapter that supports monitor mode.
Test only your own access point: capturing traffic from networks you don’t own is illegal in many countries. Wireless intrusion detection looks for floods of deauthentication frames and rogue access points copying the company’s network name.
Reporting: where the value is
The client never sees your terminal; the report is what they pay for. A good finding has a title, a severity (often CVSS), evidence, plain-language business impact, and an actionable fix. Templates or platforms such as Dradis or SysReptor keep this consistent. Our guide on how to write a penetration testing report goes deeper.
What order should a beginner learn these tools in?
Don’t try to learn all of them at once. A sensible order:
- Linux and networking basics. Every tool assumes terminal comfort and TCP/IP.
- Nmap. It shows how services and ports really look.
- Burp Suite or ZAP, with the OWASP Top 10. Most beginner work is web work.
- Gobuster or ffuf, and Nikto. Quick wins that reinforce how web servers behave.
- Notes and reporting habits. Start now.
- Metasploit, password auditing and BloodHound, in labs only, once you understand what they automate.
- Wireless last, unless your job needs it.
For the wider career route around these tools, see how to become a penetration tester from scratch.