Skip to content
Paul Marinos
Menu

Tools & Commands

The working toolkit organized by phase, in command → what it does → what the output means → what next form, with the judgment that decides which tool to reach for.

Tools are the easiest part of the discipline to list and the least of what makes a tester effective — knowing which one to reach for, and reading its output correctly, is the skill. This section is organized by phase, in the format that actually helps throughout: what the command does, what the output means, and what it sets up next.

An engagement moves through phases, and the toolkit is best read the same way. Each page below is a command reference for one phase, in the same command → output → next format.

Phase What the tools do
Recon & Enumeration Build the attack surface — hosts, ports, services, subdomains, content — before touching anything hard
Web Application Testing The Burp-centered workbench, injection, and template scanning — where most manual testing happens
Cloud Posture assessment and, after a foothold, provider-specific enumeration and privesc across AWS, Azure and GCP
Active Directory & Identity Graphing the domain, spraying and relaying, and the Kerberos and AD CS primitives most escalations are built from
C2 & Post-Exploitation Command-and-control frameworks and what happens after the first session — the loudest, most detectable phase

Which tool, and how loud, is the actual decision, and it is the one part of this section that does not reduce to a command:

  • Passive before active: every active tool touches the target and may be logged. Exhaust the sources that don’t before the ones that do.
  • Loud has a place. In a pentest with detection out of scope, run the noisy efficient tool. In a red team engagement, that same tool ends the exercise.
  • Read the output, don’t just collect it. A tool that reports “no findings” against a surface you know is vulnerable is misconfigured, not authoritative. The interpretation is the work; the scan is not.
  • Everything you run is detectable. Which of your actions were caught is itself a finding — see detection quality.

These hold across every phase, which is why they live here rather than in any one page.

These tools execute the methods in web and cloud testing, and the defensive mirror of the identity toolkit is Active Directory & Hybrid Identity. Their detectability is the raw material of purple teaming, and how loud to be is set by the engagement type.

Graph View

Spotted an error on this page? Report it.