Loading...
Penetration Testing tools for Enumeration: the Penetration Testing options most relevant when Enumeration is the priority, compared side by side so you can shortlist faster. Filter by pricing or specialization. Independent and vendor-neutral: our scores and rankings are earned, never bought — sponsored placement is always labeled.
We cover 16 cybersecurity tools
A format conversion tool for S3 buckets designed to assist bug bounty hunters and security testers in standardizing bucket data during reconnaissance activities.
A security tool for discovering and analyzing interesting files in AWS S3 buckets across multiple regions and bucket types.
ESC is an interactive .NET SQL console client with enhanced SQL Server discovery and data exfiltration features designed for penetration testing and red team engagements.
Scripts to automate the process of enumerating a Linux system through a Local File Inclusion (LFI) vulnerability.
A brute force parameter discovery tool for identifying hidden GET and POST parameters in web applications during security assessments.
A subdomain enumeration tool for penetration testers and security researchers.
A security assessment tool that identifies AWS IAM permissions by systematically testing API calls to determine the actual scope of access granted to specific credentials.
LinEnum is a tool for Linux enumeration that provides detailed system information and performs various checks and tasks.
A Python script that performs security testing attacks against AWS Cognito services including account creation, user enumeration, and privilege escalation vulnerabilities.
A next generation version of enum4linux with enhanced features for enumerating information from Windows and Samba systems.
A script to enumerate Google Storage buckets and determine access and privilege escalation
PowerUp aims to be a clearinghouse of common Windows privilege escalation vectors that rely on misconfigurations.
A tool for analyzing and visualizing control relationships and privilege escalation paths within Active Directory environments using graph-based representations.
A toolkit to attack Office365, including tools for password spraying, password cracking, token manipulation, and exploiting vulnerabilities in Office365 APIs and services.