| Data decoding and crypto puzzles | CyberChef, Python, openssl, xxd, base64, hashid, RsaCtfTool, hash_extender, xortool | Online decoders may expose secrets; prefer local CyberChef or CLI for sensitive artifacts. |
| Web proxying and manual inspection | Burp Suite Community/Pro, OWASP ZAP, mitmproxy, browser DevTools, Postman/Insomnia, httpie/xh | Manual browsing is safer than automated attack mode. Authenticated and mutating flows need scope confirmation. |
| Web discovery | katana, hakrawler, gau, waybackurls, ffuf, feroxbuster, gobuster, httpx, whatweb, nuclei templates for passive/low-impact checks | Content discovery, nuclei, and fuzzing are active. Set host allowlists, low rates, small wordlists, and stop conditions. |
| Injection validation | Manual curl/curl_cffi, Burp Repeater/Intruder, sqlmap, Commix, XSSer | Automated exploitation requires explicit approval. Start with benign differential tests and lowest risk/level settings. |
| Network inventory | dig, host, openssl s_client, testssl.sh, nmap, Wireshark/tshark, Zeek | nmap is active. masscan and zmap are high-volume and should be avoided unless the user explicitly approves broad scanning and rate limits. |
| Password/hash recovery | John the Ripper Jumbo, hashcat, hashid, cewl, SecLists wordlists | Only against provided hashes or explicitly authorized accounts. Never run online credential attacks without durable approval. |
| File and disk forensics | file, stat, sha256sum, strings, exiftool, binwalk, foremost, bulk_extractor, sleuthkit, photorec, KAPE | Mount images read-only. Preserve original hashes and work on copies. |
| Memory and malware-style triage | Volatility 3, Rekall only for legacy cases, YARA, capa, FLOSS, REMnux/FLARE VM | Unknown samples stay offline in a VM/container. No internet access unless explicitly approved. |
| PCAP and traffic analysis | Wireshark, tshark, Zeek, NetworkMiner, tcpdump -r | Only analyze owned/provided captures. Redact credentials and session tokens from reports. |
| Steganography and media | exiftool, pngcheck, zsteg, stegsolve, stegseek/StegCracker, ImageMagick, Audacity, binwalk, foremost | Prefer local tools for sensitive images/audio. Brute forcing hidden data can be expensive; record dictionaries and limits. |
| Native reversing | Ghidra, IDA, Binary Ninja, radare2/Rizin/Cutter, GDB with pwndbg/GEF, RetDec, objdump, readelf, nm | Dynamic debugging and packed samples require isolation. |
| Mobile/JVM/.NET reversing | apktool, jadx, Androguard, Frida, Objection, ILSpy, dnSpyEx, dotPeek, CFR/FernFlower/Procyon | Runtime mobile instrumentation may affect devices/services; use test devices and scoped apps. |
| Exploit development in labs | pwntools, ROPgadget, ropper, one_gadget, GDB + pwndbg/GEF, checksec, Metasploit in a lab | Do not point exploit frameworks at live Targets without explicit technique-level approval. |