Toolkit

InfoSec tools

The tools I actually reach for on penetration tests, red team engagements and forensic work. Nothing here is affiliate-linked or sponsored — every entry points at the project's own site, and I have run all of them in anger.

Several of these are classified as hack tools, unwanted programs or even malware by endpoint security products. That is expected: they do exactly what their descriptions say and nothing more. Use them only against systems you are authorised to test.

Reconnaissance and OSINT

Everything the outside world can already see, assembled before an attacker assembles it.

Web application testing

OWASP-aligned testing of applications and APIs.

Network analysis and monitoring

Seeing the traffic — on an engagement, and in the SOC afterwards.

Exploitation and post-exploitation

Objective-led work, against systems you are authorised to test.

Password and credential auditing

Proving that the policy on paper is the policy in the directory.

Wireless

The estate most organisations audit least often.

Digital forensics and incident response

Acquisition and analysis that has to survive scrutiny — defensible chain of custody, not a screenshot.

Malware analysis and reverse engineering

Understanding a binary without trusting it.

Windows process and PE analysis

The original toolkit on this page, kept because these still earn their place on a suspect Windows host.

No longer maintained

Listed on this page for years and since withdrawn by the vendor. Kept so the record is honest rather than quietly deleted.

McAfee GetSuspRetiredIsolated suspected undetected malware using heuristics and the McAfee GTI file reputation database, without needing deep systems knowledge. Withdrawn after the Trellix transition.
McAfee Ransomware InterceptorRetiredA pilot early-detection tool that used heuristics and machine learning to block ransomware encryption attempts. The pilot ended and the download is gone.
McAfee Real ProtectRetiredReal-time behavioural detection using cloud-side machine learning to catch zero-day malware. Absorbed into the commercial product and no longer a free standalone tool.

How I use these Library