Offensive Security & Pentesting
Tools for actively testing systems you are authorised to test: exploitation and adversary-simulation frameworks, network and infrastructure testing, password auditing and wireless testing. Listed for authorised security work and education only.
3 listings
Cobalt Strike
Commercial adversary-simulation platform for red teams, built around the Beacon post-exploitation agent and a shared team server.

Burp Suite
Web application security testing toolkit built around an intercepting proxy, with a free Community Edition and paid professional and enterprise editions.

Nmap
Free network scanner for discovering hosts, open ports, running services and operating systems across networks of any size.