Kali Linux includes a large range of security tools, organized into categories aligned with penetration testing workflows. These include tooling for information gathering, vulnerability analysis, web application testing, password attacks, wireless attacks, exploitation, sniffing and spoofing, post-exploitation, forensics, reporting, and social engineering. Notable tools bundled with Kali Linux include
Nmap for network discovery and port scanning,
Metasploit for exploit development and delivery,
Wireshark for network protocol analysis,
Burp Suite for web application security testing,
John the Ripper and
Hashcat for password cracking,
Aircrack-ng for wireless network auditing, and
Nessus (trial version). Kali also includes
sqlmap for automated SQL injection testing and OWASP ZAP for dynamic web application security scanning. Kali Linux includes tooling for browser exploitation, reverse engineering, and general exploit development. == Kali Purple ==