Tools / Cybersecurity
Understand your exposure.Know what to fix.
Networks, applications, access and domains. See what each tool examines and how its results help identify issues, validate findings and prioritize improvements.
One tool.One clear purpose.
Nine short explanations with narration, captions and transcripts. The diagrams explain each tool; they do not represent a client audit.
Nmap
Nmap identifies hosts, ports and visible network services. It helps explain what is exposed.
Read the transcript
What it examines
Nmap identifies hosts, ports and visible network services. It helps explain what is exposed.
How it works
It sends probes and classifies responses. Version detection adds context to each discovered service.
What it contributes
It provides an inventory for reviewing unnecessary services and prioritizing updates. An open port requires interpretation.
Gobuster
Gobuster discovers web paths and DNS names using wordlists. It expands the map of an application.
Read the transcript
What it examines
Gobuster discovers web paths and DNS names using wordlists. It expands the map of an application.
How it works
It tests candidates and filters responses by mode. Results need comparison with normal application behavior.
What it contributes
It provides paths or names worth reviewing. Discovering a path does not prove its data is accessible.
DIRB
DIRB looks for web content missing from public navigation. It works with dictionaries of paths.
Read the transcript
What it examines
DIRB looks for web content missing from public navigation. It works with dictionaries of paths.
How it works
It requests candidate paths and examines HTTP responses. Depending on configuration, it can explore discovered directories.
What it contributes
It helps locate forgotten content for permission and publishing reviews. Each match needs verification before reporting.
Nikto
Nikto examines web servers for problematic settings, outdated components and files worth investigating.
Read the transcript
What it examines
Nikto examines web servers for problematic settings, outdated components and files worth investigating.
How it works
It combines known checks with header and response information. Coverage depends on the server and selected options.
What it contributes
It produces findings to validate and prioritize. Review helps define configuration, permission and update improvements.
sqlmap
sqlmap automates SQL injection testing. It examines how application inputs interact with the database.
Read the transcript
What it examines
sqlmap automates SQL injection testing. It examines how application inputs interact with the database.
How it works
It compares responses using different testing techniques. Configuration and context determine what can be confirmed.
What it contributes
It provides evidence for fixing queries and data access. Remediation often includes parameterized queries and appropriate permissions.
Hydra
Hydra evaluates authentication on network services. It helps review resilience against repeated login attempts.
Read the transcript
What it examines
Hydra evaluates authentication on network services. It helps review resilience against repeated login attempts.
How it works
It tests accounts and credential lists. Attempt frequency and protocol are adjusted to the defined scope.
What it contributes
Results inform password, lockout and attempt-limit reviews. Multifactor authentication requires separate evaluation.
Wfuzz
Wfuzz varies parts of web requests to compare responses. It explores paths, parameters and application behavior.
Read the transcript
What it examines
Wfuzz varies parts of web requests to compare responses. It explores paths, parameters and application behavior.
How it works
It substitutes candidate values and filters by status, size or content. Differences require analysis.
What it contributes
It provides cases for investigating inputs and controls. A different response is a clue, not a confirmed vulnerability.
DNSutils / dig
DNSutils includes dig for querying DNS records. It helps explain how a domain publishes services and addresses.
Read the transcript
What it examines
DNSutils includes dig for querying DNS records. It helps explain how a domain publishes services and addresses.
How it works
It queries records such as A, MX and TXT. Comparing DNS responses helps investigate resolution inconsistencies.
What it contributes
It provides a configuration map for website and email diagnosis. Public records need interpretation in service context.
Netcat
Netcat reads and writes data over network connections. It helps diagnose communication between services.
Read the transcript
What it examines
Netcat reads and writes data over network connections. It helps diagnose communication between services.
How it works
It opens connections or listens on a port, depending on mode. Options vary between implementations.
What it contributes
It helps verify connectivity and protocol responses. Results complement network and configuration diagnosis.
Babel13
From findings to fixes.
Automated results need context and validation. Tell us which website, application or infrastructure you want reviewed so we can define the scope and priorities.
Chat on WhatsApp