Level: beginner. This is a categorised tour of the 15 penetration testing tools worth learning first, in the order that builds skill, plus an honest note on what each is for. Every tool named here is used against systems you own or have written authorisation to test. If that condition is not met, no tool makes the activity legal, and the legal position is covered in our methodology guide.
One framing point before the list. Tools are not the skill. A scanner will tell you what a database told it to look for, and it will be wrong often enough to teach you nothing if you do not already understand what it found. Every entry below is paired with the skill it practises, because that is what makes one of these penetration testing tools worth learning.
How to Read the 15 Tools
The 15 fall into six categories: reconnaissance, scanning and enumeration, web application testing, network and traffic analysis, exploitation, and reporting. Learn them in that order. Each depends on the one before it, and a beginner who jumps to an exploitation framework first will spend months guessing.
One practical warning. Distributions such as Kali Linux package hundreds of security utilities, and installing everything at once is a common, expensive mistake. You end up with a menu you cannot navigate and no idea what any entry does.
Reconnaissance Tools
Reconnaissance answers one question before you touch anything: what exists? It is the cheapest phase and the one beginners skip most, which is why their findings are thin. Two of the 15 below cover it well enough to start.
| Tool | Category | Problem it solves | Skill it practises |
|---|---|---|---|
| 1. theHarvester | Recon | Collects emails, hostnames and subdomains from public sources | Reading OSINT without over-collecting |
| 2. Amass | Recon | Maps subdomains and the DNS records behind them | Asset discovery and naming conventions |
| 3. Nmap | Scanning | Finds live hosts, open ports, services and versions | Reading network topology and service banners |
| 4. OpenVAS | Scanning | Broad, scheduled vulnerability checks across a range | Triage: separating real findings from noise |
| 5. Nuclei | Scanning | Runs focused, template-based checks against known issues | Choosing what to test and why |
| 6. ffuf | Scanning | Discovers hidden paths, files and parameters on a web server | Understanding how web applications expose resources |
| 7. Burp Suite | Web application | Intercepts, inspects and replays browser traffic | How HTTP really works, request by request |
| 8. OWASP ZAP | Web application | The same interception idea, free and scriptable | Automating repeatable web checks |
| 9. sqlmap | Web application | Tests whether input handling is unsafe, carefully throttled | Parameterised queries and why they exist |
| 10. Wireshark | Network | Captures and decodes packets so you can see the protocol | TCP/IP, DNS, TLS and HTTP at packet level |
| 11. Netcat | Network | Opens raw TCP and UDP connections for banner grabs and handshakes | Ports, protocols and connection states |
| 12. Metasploit Framework | Exploitation | Structured, logged validation of known weaknesses | Proving a finding with a repeatable procedure |
| 13. Impacket | Exploitation | Exercises Windows and directory service protocols directly | How Windows authentication actually negotiates |
| 14. BloodHound | Exploitation | Maps who can reach what across a directory hierarchy | Privilege and path reasoning, not just holes |
| 15. hashcat | Exploitation | Audits password hashes you already hold, offline | Password storage, salting and cost factors |
Scanning and Enumeration Tools in Practice
Nmap is the first tool most people install and the one they understand least. Its default output is a list of ports, but the value is the service and version data underneath, because that tells you what to test next. The skill it practises is patience: a fast scan of a large range produces output you cannot read, while a deliberate scan of a known range produces a picture you can reason about. The official Nmap documentation is genuinely readable.
OpenVAS and Nuclei do different jobs and beginners conflate them. OpenVAS is broad, slow and noisy, which makes it useful for scheduled estate-wide checks and poor for a focused assessment. Nuclei runs small, specific checks described as templates, which makes it fast and precise when you know what you want. The skill it practises is judgement: a template is a hypothesis, and one you cannot explain is a finding you cannot report.
Enumeration is where much real risk lives, and it is mostly manual. Ask for a directory listing. Check whether a forgotten backup, a version control directory or a configuration file is reachable. Read error messages properly, because a verbose stack trace is free reconnaissance. The OWASP Web Security Testing Guide catalogues these checks by weakness class.
Web Application Testing Tools
A web proxy is the most useful thing a beginner can learn, because it makes HTTP visible. With Burp Suite or the free OWASP ZAP, you watch every request the browser makes, see which parameters exist, and replay them one at a time. That habit teaches cookies, sessions, redirects, headers, encoding and access control faster than any course, and the PortSwigger Web Security Academy gives you the exploitation side of the same curriculum free.
sqlmap is the one beginners reach for too early. It automates a single question, whether a parameter is concatenated unsafely into a query, and it is good at that question. The lesson is on the other side: understanding why SQL injection happens, and why parameterised queries remove the class of bug rather than each instance. Learn the mechanism, then automate it.
Network and Traffic Analysis Tools
Wireshark teaches by observation. Open it against a capture of traffic to a server you run yourself and you can watch a DNS lookup, a TCP handshake, a TLS negotiation and an HTTP request appear in sequence. That is the same material as the networking in our career guide, learned by looking rather than memorising, and it is the fastest route to explaining why a connection failed.
Netcat looks trivial and teaches the fundamentals. Opening a raw connection by hand, reading a banner, and understanding why a port is open or filtered builds the mental model every other network tool assumes. Use it only against hosts inside your authorised scope. The Cloudflare fundamentals documentation is a good free reference for the concepts underneath.
Exploitation and Post-Exploitation Tools
Metasploit is the best way to see what validated exploitation looks like, because every action is logged and repeatable. That repeatability is the point: a report saying “this module was run, here is the evidence, here is the cleanup” is defensible, whereas a claim of compromise with no procedure is not. Use it to prove a finding inside your scope, never to discover targets.
Impacket and BloodHound address the same subject from two sides. Impacket lets you speak the Windows and directory service protocols directly, which is how you learn that authentication is a negotiation rather than a single check. BloodHound takes the resulting graph and shows which accounts can reach which systems, which is why it changes how you think: a modest misconfiguration can be the shortest path to domain-wide compromise. The BloodHound documentation explains the graph model. hashcat belongs here because it audits passwords you already hold, and understanding why GPU cracking is fast explains why password policy and MFA are the real control, as our password security guide sets out.
Reporting and Why the Toolkit Is the Easy Part
Reporting is a category, and the one beginners under-invest in. There is no scanner for “can a non-technical manager act on this”, which is why a report template is worth more than another of these penetration testing tools. Keep the structure our methodology guide sets out: scope, method, findings with reproducible evidence, severity and impact, remediation, and a retest result.
An honest ranking, if your time is limited. Learn the proxy and Wireshark first, because they build understanding rather than output. Learn Nmap next, because everything else assumes you know your targets. Add a scanner after that. Leave Metasploit, Impacket and hashcat until you can read what a finding means, since a tool used without judgement produces noise a paying client will charge you for.
The limits are worth stating. These tools have legal uses and illegal ones, and the difference is authorisation, not software. The Kali package list is not a curriculum. A clean scan proves nothing about systems you did not test, and a finding you cannot explain is a finding you cannot fix. For the theory behind the list, start with the methodology.
Frequently Asked Questions
Do I need Kali Linux to learn penetration testing?
No. Kali is a convenient packaging of other people’s tools, and its default is a very large menu you will not learn. Any Linux distribution, macOS or a Windows VM runs the tools in this article individually. A plain distribution plus a handful of deliberate installations is a better learning environment.
Is a free alternative available for Burp Suite?
Yes, and it is the recommended starting point. The OWASP ZAP project is free, open source, intercepts the same traffic and can be scripted for repeatable checks. The paid Burp editions add convenience and automation, which matter once you are doing this professionally rather than learning.
Can penetration testing tools damage the systems they test?
Yes, and that is the honest answer to why scoping comes first. Some checks send malformed input, some attempt authentication at volume, and some are explicitly designed to be disruptive. All 15 are safe against systems you own, which is exactly why you should practise there first.
Do I need to learn all 15 before starting a job?
No. Four will get you surprisingly far: a web proxy, Wireshark, Nmap and one scanner. Depth in a specialism beats breadth across a list, and on a real engagement the report and the judgement behind it count for more than the tool used.
Key Takeaways
- Tools are not the skill. Each one teaches a technique, and the technique is what transfers.
- Learn in order: reconnaissance, scanning, web, network, exploitation, reporting.
- Install one and learn it properly rather than installing everything on day one.
- A web proxy and Wireshark teach more than any scanner, because they make protocols visible.
- Scanner output is a hypothesis. A finding you cannot explain is one you cannot remediate.
- Every tool here is safe against systems you own, and unsafe everywhere else.
- Reporting is a category, and the one beginners under-invest in.
Once you have the toolkit, learn the order of operations in penetration testing methodology, then put it to work on your own network with network penetration testing step by step.
For the defensive side of the same ground, see our guides to email security and phishing and router security.
Sources: Nmap; Wireshark; OWASP ZAP; PortSwigger Web Security Academy; OWASP Web Security Testing Guide; Metasploit; BloodHound; hashcat; Kali Linux tools.
0 Comments