AI Offensive Security Certification
AU · CA · NZ · UK · US
StrikeOps Academy
CurriculumPathwaysCertificationsPricing
Search/Start learning
CurriculumREF · Reference LibraryThe tool index
REFReference Library

The tool index

A quick-reference catalogue of the tools referenced across the Academy: what each does, when to reach for it, and the job it belongs to.

Foundational3 min readfoundation streamUpdated Sat Aug 01 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
On this page
  • Reconnaissance and enumeration
  • Active Directory
  • Credential cracking
  • Web and API
  • Cloud
  • Mobile
  • Phishing
  • AI and LLM testing
  • A note on responsible use
  • Related reading

Learning objectives

  • Match a task to the right tool across recon, AD, cracking, web, cloud, mobile and phishing
  • Understand at a high level what each tool does before you read the technique pages
  • Apply the safety principle that credential-class and destructive uses warrant explicit sign-off

A catalogue of the tooling referenced throughout the attack-techniques material, grouped by job. This is a map, not a manual: each entry says what the tool does so you recognise it when a technique page reaches for it. A standing safety principle runs through all of it: the credential-class and destructive uses of these tools (spraying, cracking, relay, roasting, state-changing writes) warrant explicit sign-off and careful logging, never a casual run.

Reconnaissance and enumeration

ToolWhat it does
subfinder / dnsx / shufflednsPassive and active subdomain and DNS discovery
httpx / tlsx / cdncheckHTTP probing, TLS inspection, CDN and WAF detection
naabu / nmapPort scanning plus service and version detection
katana / urlfinderCrawling and endpoint or URL discovery (including JS)
nucleiTemplate-based vulnerability and fingerprint scanning
crt.sh / Shodan / CensysCertificate transparency and internet asset search
HIBP / breach sourcesBreach and credential-exposure lookups

Active Directory

ToolWhat it does
ResponderPoison LLMNR, NBT-NS and mDNS to capture or relay auth
mitm6IPv6 DNS poisoning to capture auth
ntlmrelayx (Impacket)Relay captured NTLM auth to a useful target
PetitPotam / PrinterBug / DFSCoerceCoerce a host (often a DC) to authenticate
CertipyEnumerate and exploit AD CS misconfig (ESC1 to ESC11)
RubeusKerberos primitives: roast, ticket forge and reuse
Impacket (GetUserSPNs, GetNPUsers, secretsdump, ticketer)Kerberoast, AS-REP roast, dump secrets, forge tickets
BloodHound (SharpHound / bloodhound.py)Map AD as a graph; find the shortest path to Domain Admin
NetExec (nxc)Spray, auth, execute and dump across a subnet at scale
MimikatzExtract creds and tickets from Windows (LSASS, DPAPI)

Credential cracking

ToolWhat it does
hashcatGPU offline hash cracking (NTLM, Kerberos, MD5)
john (John the Ripper)CPU and flexible offline cracking

Web and API

ToolWhat it does
Intercepting proxy (for example Burp Suite, ZAP)Inspect and modify HTTP requests and responses
Content discovery (directory and endpoint brute)Find hidden routes, panels and files
nucleiKnown-CVE and misconfig templates against web

Cloud

ToolWhat it does
ScubaGear / MaesterM365 and Entra configuration benchmarking
ProwlerAWS, Azure and GCP posture and compliance scanning
Monkey365Microsoft 365 and Azure security review

Mobile

ToolWhat it does
jadx / apktoolDecompile and inspect Android packages
Frida / objectionRuntime instrumentation, pinning bypass

Phishing

ToolWhat it does
evilginx (AiTM proxy)MFA-bypass phishing via session-token capture
Static lander kitsCredential-harvesting clone pages

AI and LLM testing

As more targets embed LLMs, a few categories of tooling have become standard for probing them.

ToolWhat it does
Prompt-injection test kits (for example garak)Probe an LLM for prompt injection, jailbreaks and unsafe output
LLM red-team frameworks (for example PyRIT, promptfoo)Automate adversarial prompts and score model responses at scale
MCP and agent inspectorsEnumerate an agent's exposed tools and test for excessive agency or unsafe tool use

A note on responsible use

Reach for these tools only against systems you are authorised to test, and keep the destructive and credential-class uses behind deliberate approval and clear evidence logging. The techniques are identical to an attacker's; the authorisation and the record are what make the work a profession.

Related reading

  • Frameworks and standards
  • Glossary
Module anatomy

Knowledge check

Answer without AI. This is your own recall. 70% to pass.

  1. 1.Which tool models Active Directory as a graph and computes the shortest path to Domain Admin?

  2. 2.You need to crack captured NTLM hashes offline using a GPU. Which tool fits?

  3. 3.Which tool is used for AiTM phishing that can capture a session token and bypass OTP or push MFA?

PreviousFrameworks and standardsNextSeverity and CVSS rubric

On this page

  • Reconnaissance and enumeration
  • Active Directory
  • Credential cracking
  • Web and API
  • Cloud
  • Mobile
  • Phishing
  • AI and LLM testing
  • A note on responsible use
  • Related reading
AI tutorComing soon

Ask questions and get hints as you work through this module, without leaving the page.

Ready when you are

Certify the dual mandate.

Start free, learn on subscription, and earn a verifiable credential recognised across the Five Eyes.

Start learningCompare certifications
STRIKEOPS ACADEMYPROFESSIONALSOCPCERTIFIED
StrikeOps Academy

The certification for operators who wield AI in offensive engagements and attack the AI systems inside every target.

Recognised across
AUCANZUKUS
Learn
  • Curriculum
  • Learning pathways
  • Search
Certify
  • Certifications
  • Pricing
  • Certification exams
Credentials
  • Associate · Silver
  • Professional · Gold
  • Expert · Platinum

Questions, or planning a team rollout?

Talk to our team and we will point you to the right track or credential.

Contact us

© 2026 StrikeOps Academy. A StrikeOps company. All rights reserved.

Privacy PolicyTerms of Service

The offensive techniques taught here are for authorised security testing only. The StrikeOps Academy labs are the sole sanctioned target unless you hold explicit written authorisation.