Skip to main content

6 Tools you should know as a Cybersecurity Analyst/ Pen Tester

 

Wireshark

Wireshark logo
Wireshark

Having a solid foundation in Networking is essential to becoming a good penetration tester. 

Wireshark is the world’s best network analyzer tool. It is an open-source software that enables you to inspect real-time data on a live network.

Wireshark can dissect packets of data into frames and segments giving you detailed information about the bits and bytes in a packet. Wireshark supports all major network protocols and media types. Wireshark can also be used as a packet sniffing tool if you are in a public network. Wireshark will have access to the entire network connected to a router.

Image for post
Wireshark Packet Capture

Sites like Facebook and Twitter are encrypted now, thanks to https. This means that even though you can capture packets from a victim computer in transit to Facebook, those packets will be encrypted. Still, being able to capture data packets in realtime is an important utility for a penetration tester.

Nmap

Index of /images

Nmap is the first tool you will come across when you begin your career as a penetration tester. Nmap is a fantastic network scanning tool that can give you detailed information about a target. This includes open ports, services, and the operating system running on the victim’s computer.

Nmap is popular among penetration testers for many reasons. It is simple, flexible, and extensible. It offers a simple command-line interface where you can add a few flags to choose different types of scans. Nmap offers simple ping scans to aggressive scans that provide detailed ports and service information.

Image for post

                                Zenmap UI

Nmap also provides a GUI tool called Zenmap with added utilities. You can build visual network maps and choose scans via dropdowns. Zenmap is a great place to start playing with Nmap commands if you are a beginner.

Metasploit

Image for post

 Metasploit is not just a tool, but a complete framework that you can use during an entire penetration testing lifecycle.

Metasploit contains exploits for most of the vulnerabilities in the Common Vulnerabilities and Exposure database. Using Metasploit, you can send payloads to the target system and gain access to it through a command-line interface.

Metasploit is very advanced with the ability to do tasks such as port scanning, enumeration, and scripting in addition to exploitation. You can also build and test your own exploit using the Ruby programming language.

Metasploit was open-source till 2009 after which Rapid7 acquired the product. You can still access free community edition for free and use all its features.

Image for post
Armitage UI

Nessus

Image for post

A popular enterprise vulnerability scanner. Nessus is built to be a complete vulnerability analysis and reporting tool. While you can scan and find ports or services using Nmap, Nessus will tell you the list of vulnerabilities and how they can be exploited.

Nessus has an excellent user interface, tens of thousands of plugins, and supports embedded scripting. Nessus is favored by enterprises since it helps companies audit for various compliances like PCI and HIPPA. Nessus will also tell you the severity of the vulnerabilities so that you can focus on those threats accordingly.

Image for post
Nessus Sample Report

Nessus is not a free software but offers a limited free home edition. Nessus has an open-source alternative called Open-Vas that offers similar features to Nessus.

John the Ripper

Image for post

Passwords are still the de-facto standard of authentication in most systems. Even if you successfully get into a server or a database you will have to decrypt the password to gain privilege escalation.

John the Ripper is a simple tool used for cracking passwords. It is a super-fast password cracker with support for custom wordlists. It can run against most types of encryption methods like MD5 and SHA.

Aircrack-ng

Image for post

Aircrack-ng is a set of tools that help you to work with wireless networks. Aircrack comprises of tools that can capture wireless networks, crack WPA keys, inject packets, etc.

A few tools in Aircrack-ng suite include:

  • airodump — Captures packets
  • aireplay — Packet injection
  • aircrack — Crack WEP and WPA
  • airdecap — Decrypt WEP and WPA

Aircrack contains excellent algorithms for cracking WiFi passwords and to capture wireless traffic. It can also decrypt encrypted packets, making it a complete suite of tools for wireless penetration testing. In short, you can use Aircrack for monitoring, attacking, and debugging all types of wireless networks.

Comments

Popular posts from this blog

MY PEOPLE PLEASE I NEED YOUR ADVICE   Robbers enter a house, asks for all the money and valuables. After they collect what they can, they give the man of the house a gun with instructions to shoot his wife or else he be shot himself. The man gets the gun, points it at his wife and hesitates. He is thinking of what he has gone through in life with his wife and how she has suffered and sacrificed for him. He hands back the gun and says, “I am sorry I can’t do this… “The boss of the robbers silently grabs the gun from him and passes it on to the wife with the same instruction. The wife gets the gun and without any single hesitation points to her husband’s head and pulls the trigger. But alas, the gun had no bullets in it. The robbers get their gun and walk out of the house laughing. QUESTIONS FOR DISCUSSION 1. If you were the man in that house how would you react towards your wife? 2. If you were the wife, what explanation can you...
 Who Are You Trying to Impress? Can you imagine viewing criticism as ‘a very small thing’? Or being liberated from the need to impress people; your self-esteem no longer dependent on someone noticing how successful, smart, or attractive you are?  Think what it would be like to feel genuine love for someone who expresses their disapproval of you.  Is such a life even possible? With God’s help, yes!  One pastor says: ‘Years ago I wanted to lead a certain ministry. When I wasn’t chosen I became angry. Of course I didn’t show it. That’s not to say I didn’t love God. I just wanted to serve me more than Him! By saying no, God was correcting an attitude that would destroy any real ministry I might have later. When you represent God so visibly it’s nearly impossible for anyone to detect that you’re a fake…except God.’ Ever hear of ‘approval addiction’? Its symptoms include living in fear of what others think of you; being easily hurt by what they...
Top 20 Most Asked Third Party Risk Questions for Vendors  These questions help organizations assess the overall risk posed by third-party vendors, covering critical areas like data protection, regulatory compliance, and incident response. Here’s a list of the Top 20 Most Asked Third-Party Risk Management (TPRM) Questions for Vendors in TPRM questionnaires: 1. What types of sensitive data do you handle for our organization? Vendors should clarify the types of data they collect, process, or store, such as personal information, financial data, or intellectual property. 2. How do you protect data at rest and in transit? This question probes into the encryption methods, protocols, and security controls in place for safeguarding data during storage and transmission. 3. Do you have a formal Information Security Program in place? Vendors should describe their overall cybersecurity framework, including policies, procedures, and governance. 4. How do you manage user access to our data and s...