Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Category Key

Every tool and OS card shows its own logo when one is available. When it isn't, we show one of these icons instead — a quick visual cue for what kind of tool it is, based on that tool's category tags. The color groups related categories together; the icon narrows it down further. Looking for tools by what they're for rather than what a badge means? See Browse by goal.

Exploitation

Offensive

Matches categories like: exploit, dos, denial

Reverse engineering

Offensive

Matches categories like: malware, revers, disassembl, decompil, …

Fuzzing

Offensive

Matches categories like: fuzz

Post-exploitation

Offensive

Matches categories like: backdoor, command-and-control, c2, post-exploitation, …

Password attacks

Credentials & crypto

Matches categories like: password, cracker, credential, brute

Cryptography

Credentials & crypto

Matches categories like: crypto, stego, encrypt

Forensics

Forensics & defense

Matches categories like: forensic, carving, memory-forensics, incident-response

Defensive

Forensics & defense

Matches categories like: defens, honeypot, evasion, detect

Web application

Recon & web

Matches categories like: webapp, web-app, web-scanning, web-vulnerability, …

Vulnerability scanning

Recon & web

Matches categories like: scanner, scanning, vulnerability, fingerprint-service, …

Reconnaissance

Recon & web

Matches categories like: recon, osint, gather, collection, …

Database

Recon & web

Matches categories like: database, sql-injection

Network analysis

Network, wireless & social

Matches categories like: network, sniff, spoof, proxy, …

Wireless

Network, wireless & social

Matches categories like: wireless, wifi, wi-fi, bluetooth, …

Social engineering

Network, wireless & social

Matches categories like: social, phish

Mobile

Network, wireless & social

Matches categories like: mobile, android, ios, apk

Platform-specific

Platform & utility

Matches categories like: windows, pe-files, microsoft-office, .net, …

Automation & utilities

Platform & utility

Matches categories like: automation, script, utilities, utility

Reporting

Platform & utility

Matches categories like: report, document

General

Platform & utility

Team Classification

Some OS and tool cards also show a Red Team or Blue Team badge. This is a separate, hand-judged axis from the category badges above — it classifies primary use (offense vs. defense), not what kind of tool it is.

Red Team

"A group of people authorized and organized to emulate a potential adversary's attack or exploitation capabilities against an enterprise's security posture." Tools that emulate, perform, or support an attack — reconnaissance, exploitation, credential access, lateral movement, command-and-control — are classified red here, matching how MITRE ATT&CK names adversary tactics.

Source: NIST CSRC Glossary, "red team" (CNSSI 4009-2022)

Blue Team

"The group responsible for defending an enterprise's use of information systems by maintaining its security posture against a group of mock attackers." Tools that detect, analyze, or respond to an attack — forensics, malware analysis, honeypots, SIEM/detection — are classified blue here, the domain MITRE D3FEND catalogs from the defensive side.

Source: NIST CSRC Glossary, "blue team" (CNSSI 4009-2022)

There's no "Purple Team" badge, deliberately. NIST's CNSSI 4009-2022 glossary formally defines Red Team, Blue Team, and White Team (a neutral referee for red-vs-blue exercises) — but has no equivalent Purple Team entry. Every industry source describing purple teaming (SANS, Orca Security, Cymulate) frames it the same way: a collaborative exercise where red and blue work together in real time, not a property a single tool or OS can hold. A platform that bundles both offensive and defensive tooling to support that kind of exercise is still, itself, defensive tooling — Kali Purple is tagged Blue Team here, matching its own vendor description ("defensive security," built around NIST CSF's Identify/Protect/Detect/Respond/Recover functions) rather than the exercises it can be used to run.

You may also see other roles referenced elsewhere in the industry — White Team (referees an exercise), Purple Team (the red/blue collaboration itself), and an informal "color wheel" extension covering Yellow (secure development), Green (dev/detection liaison), and Orange (attacker-mindset training for developers). None of those describe a standalone tool the way red/blue do, so this site doesn't use them as a filterable classification.