Open dataset · v1.0.0
Cybersecurity Tools.
Commands. Knowledge.
A curated directory of security tooling: what a tool actually does, how to install it on your platform, the commands that matter and what they mean — plus the learning paths that put them in order.
Start here
Explore by category
Seven areas of practice. Each category breaks into subtopics, and each tool sits in exactly one of them.
OSINT
Investigate publicly available information.
5 documented·6 subtopics
Pentesting
Assess systems and applications in authorized environments.
9 documented·5 subtopics
Networking
Analyze networks, traffic, protocols and infrastructure.
6 documented·5 subtopics
Forensics
Analyze digital evidence and investigate incidents.
2 documented·4 subtopics
Wireless
Analyze wireless and radio-related environments.
2 documented·3 subtopics
Cloud / DevSecOps
Security tooling for cloud infrastructure and pipelines.
2 documented·4 subtopics
Misc
Encoding, cryptography and supporting utilities.
1 documented·3 subtopics
Most referenced entries
The tools readers open first, and the entries with the deepest documentation in this dataset.
- Verified
Burp Suite
Intercepting web proxy and testing workbench
Pentesting·Web Application Testing
- Windows
- macOS
- Linux
- Kali
4 commands·Intermediate7 Jan 2026 - Verified
CyberChef
Local encoding, hashing and cipher workbench
Misc·Encoding & Decoding
- Web
- Docker
- Linux
- macOS
- +2 more
4 commands·Beginner27 Dec 2025 - Verified
ExifTool
Read, write and strip file metadata
OSINT·Metadata & Documents
- Linux
- macOS
- Windows
- Kali
- +5 more
8 commands·Beginner9 Jan 2026 - Verified
ffuf
Fast web fuzzer written in Go
Pentesting·Content Discovery
- Linux
- macOS
- Windows
- Kali
- +4 more
9 commands·Beginner19 Jan 2026 - Verified
Gobuster
Directory, DNS and vhost brute forcer
Pentesting·Content Discovery
- Linux
- macOS
- Windows
- Kali
- +4 more
5 commands·Beginner13 Jan 2026 - Verified
Hashcat
GPU-accelerated password recovery benchmark
Pentesting·Credential & Hash Auditing
- Windows
- macOS
- Linux
- Kali
- +4 more
8 commands·Advanced10 Jan 2026 - Verified
Netcat
Read and write network connections from the terminal
Networking·Connectivity & Transfer
- Linux
- macOS
- Windows
- Kali
- +4 more
5 commands·Beginner8 Jan 2026 - Verified
Nmap
v7.95Network discovery and security auditing
Networking·Discovery & Recon
- Windows
- macOS
- Linux
- Kali
- +5 more
11 commands·Beginner18 Jan 2026
Learning paths
Ordered stages, each with the concepts, tools and exercises that belong to it. A path structures study; it does not certify competence.
- Beginner08 stages
Absolute Beginner
The foundations everything else assumes: how machines address each other, how a shell works, and how to read what a program actually outputs. No prior security knowledge required.
- Audience
- Complete newcomers, students, developers moving into security
- Time
- 4–6 weeks at 4–6 hours per week
- Prerequisites
- 2 listed
- Outcome
- You can set up a lab, navigate Linux comfortably, ex…
- Beginner → Intermediate06 stages
OSINT Investigator
Structured, defensible research using public information: method, source discipline, verification and reporting about people and infrastructure.
- Audience
- Analysts, journalists, defenders, anyone doing public-record research
- Time
- 5–8 weeks
- Prerequisites
- 2 listed
- Outcome
- You can run a repeatable research process, distingui…
- Intermediate → Advanced08 stages
Web Pentester
Application testing from an honest methodology: scope, exploration, verification, impact and retest. Tooling supports the method rather than replacing it.
- Audience
- Developers moving into appsec, junior testers, bug bounty newcomers
- Time
- 10–16 weeks
- Prerequisites
- 3 listed
- Outcome
- You can plan a test, find and verify issues manually…
- Intermediate07 stages
Network Pentester
Internal and external network assessment: discovery, enumeration, exposure review, evidence and the conversations that follow.
- Audience
- Infrastructure testers, sysadmins moving into assessment work
- Time
- 8–12 weeks
- Prerequisites
- 3 listed
- Outcome
- You can map an authorized segment, describe exposure…
- Intermediate06 stages
Bug Bounty
A realistic route into responsible disclosure: program rules, asset knowledge, a repeatable testing loop, and report quality.
- Audience
- Self-directed learners aiming at public disclosure programs
- Time
- Ongoing; 6–12 weeks to a first solid report
- Prerequisites
- 2 listed
- Outcome
- You read a policy before you touch a target, focus o…
- Beginner → Intermediate06 stages
Blue Team Foundations
Detection and response basics: logging you can trust, reading traffic, triaging alerts, and writing the timeline that survives review.
- Audience
- SOC newcomers, sysadmins, developers owning production
- Time
- 8–10 weeks
- Prerequisites
- 1 listed
- Outcome
- You can tell whether an alert corresponds to real ac…
Recently revised entries
Dates refer to this dataset's documentation, not to upstream releases.
Built with the community
Every entry is content in a repository: typed data files, reviewed before they are marked verified. Corrections, extra commands and new tools are the whole point of the project.
- Add a tool or extend an existing entry
- Flag documentation that has fallen behind
- Improve examples, filters and accessibility