Category Key
Every tool and OS card shows its own logo when one is available. When it isn't, we show one of these icons instead — a quick visual cue for what kind of tool it is, based on that tool's category tags. The color groups related categories together; the icon narrows it down further. Looking for tools by what they're for rather than what a badge means? See Browse by goal.
Exploitation
Offensive
Matches categories like: exploit, dos, denial
Reverse engineering
Offensive
Matches categories like: malware, revers, disassembl, decompil, …
Fuzzing
Offensive
Matches categories like: fuzz
Post-exploitation
Offensive
Matches categories like: backdoor, command-and-control, c2, post-exploitation, …
Password attacks
Credentials & crypto
Matches categories like: password, cracker, credential, brute
Cryptography
Credentials & crypto
Matches categories like: crypto, stego, encrypt
Forensics
Forensics & defense
Matches categories like: forensic, carving, memory-forensics, incident-response
Defensive
Forensics & defense
Matches categories like: defens, honeypot, evasion, detect
Web application
Recon & web
Matches categories like: webapp, web-app, web-scanning, web-vulnerability, …
Vulnerability scanning
Recon & web
Matches categories like: scanner, scanning, vulnerability, fingerprint-service, …
Reconnaissance
Recon & web
Matches categories like: recon, osint, gather, collection, …
Database
Recon & web
Matches categories like: database, sql-injection
Network analysis
Network, wireless & social
Matches categories like: network, sniff, spoof, proxy, …
Wireless
Network, wireless & social
Matches categories like: wireless, wifi, wi-fi, bluetooth, …
Social engineering
Network, wireless & social
Matches categories like: social, phish
Mobile
Network, wireless & social
Matches categories like: mobile, android, ios, apk
Platform-specific
Platform & utility
Matches categories like: windows, pe-files, microsoft-office, .net, …
Automation & utilities
Platform & utility
Matches categories like: automation, script, utilities, utility
Reporting
Platform & utility
Matches categories like: report, document
General
Platform & utility
Team Classification
Some OS and tool cards also show a Red Team or Blue Team badge. This is a separate, hand-judged axis from the category badges above — it classifies primary use (offense vs. defense), not what kind of tool it is.
Red Team
"A group of people authorized and organized to emulate a potential adversary's attack or exploitation capabilities against an enterprise's security posture." Tools that emulate, perform, or support an attack — reconnaissance, exploitation, credential access, lateral movement, command-and-control — are classified red here, matching how MITRE ATT&CK names adversary tactics.
Source: NIST CSRC Glossary, "red team" (CNSSI 4009-2022)
Blue Team
"The group responsible for defending an enterprise's use of information systems by maintaining its security posture against a group of mock attackers." Tools that detect, analyze, or respond to an attack — forensics, malware analysis, honeypots, SIEM/detection — are classified blue here, the domain MITRE D3FEND catalogs from the defensive side.
Source: NIST CSRC Glossary, "blue team" (CNSSI 4009-2022)
There's no "Purple Team" badge, deliberately. NIST's CNSSI 4009-2022 glossary formally defines Red Team, Blue Team, and White Team (a neutral referee for red-vs-blue exercises) — but has no equivalent Purple Team entry. Every industry source describing purple teaming (SANS, Orca Security, Cymulate) frames it the same way: a collaborative exercise where red and blue work together in real time, not a property a single tool or OS can hold. A platform that bundles both offensive and defensive tooling to support that kind of exercise is still, itself, defensive tooling — Kali Purple is tagged Blue Team here, matching its own vendor description ("defensive security," built around NIST CSF's Identify/Protect/Detect/Respond/Recover functions) rather than the exercises it can be used to run.
You may also see other roles referenced elsewhere in the industry — White Team (referees an exercise), Purple Team (the red/blue collaboration itself), and an informal "color wheel" extension covering Yellow (secure development), Green (dev/detection liaison), and Orange (attacker-mindset training for developers). None of those describe a standalone tool the way red/blue do, so this site doesn't use them as a filterable classification.