Tools & Commands
The working toolkit organized by phase, in command → what it does → what the output means → what next form, with the judgment that decides which tool to reach for.
Tools are the easiest part of the discipline to list and the least of what makes a tester effective — knowing which one to reach for, and reading its output correctly, is the skill. This section is organized by phase, in the format that actually helps throughout: what the command does, what the output means, and what it sets up next.
The phases, and where each lives
Section titled “The phases, and where each lives”An engagement moves through phases, and the toolkit is best read the same way. Each page below is a command reference for one phase, in the same command → output → next format.
| Phase | What the tools do |
|---|---|
| Recon & Enumeration | Build the attack surface — hosts, ports, services, subdomains, content — before touching anything hard |
| Web Application Testing | The Burp-centered workbench, injection, and template scanning — where most manual testing happens |
| Cloud | Posture assessment and, after a foothold, provider-specific enumeration and privesc across AWS, Azure and GCP |
| Active Directory & Identity | Graphing the domain, spraying and relaying, and the Kerberos and AD CS primitives most escalations are built from |
| C2 & Post-Exploitation | Command-and-control frameworks and what happens after the first session — the loudest, most detectable phase |
The judgment the list can’t give you
Section titled “The judgment the list can’t give you”Which tool, and how loud, is the actual decision, and it is the one part of this section that does not reduce to a command:
- Passive before active: every active tool touches the target and may be logged. Exhaust the sources that don’t before the ones that do.
- Loud has a place. In a pentest with detection out of scope, run the noisy efficient tool. In a red team engagement, that same tool ends the exercise.
- Read the output, don’t just collect it. A tool that reports “no findings” against a surface you know is vulnerable is misconfigured, not authoritative. The interpretation is the work; the scan is not.
- Everything you run is detectable. Which of your actions were caught is itself a finding — see detection quality.
These hold across every phase, which is why they live here rather than in any one page.
Where this connects
Section titled “Where this connects”These tools execute the methods in web and cloud testing, and the defensive mirror of the identity toolkit is Active Directory & Hybrid Identity. Their detectability is the raw material of purple teaming, and how loud to be is set by the engagement type.
Graph View
Backlinks
Spotted an error on this page? Report it.