Enterprise Security & Auditing Toolkit
Most tool round-ups are affiliate lists with the trade-offs removed. This one keeps them: every entry below says what the thing is good at, what it costs you elsewhere, and where it quietly fails. Hardware, platforms and privacy tooling that security engineers, researchers and SOC analysts actually run — rated, and written up at length on its own page.
> ERROR: 404_NO_SIGNATURES_MATCHED
VPNs & Privacy Tools
3NordVPN
Fast, everywhere, and heavily marketed — good throughput, ordinary privacy story
ProtonVPN
Swiss jurisdiction, independently audited apps, and the only credible free tier
Mullvad
Your account is a random number. No email, flat monthly price, cash accepted
Penetration Testing Hardware
4Flipper Zero
Sub-GHz, NFC, infrared and iButton in one pocket device — a superb teaching tool, not a professional radio
USB Armory MkII
An ARM computer in a USB stick, with secure boot and open firmware — for people who care how trust is rooted
HackerBoxes Subscription
Monthly SDR and IoT kits. The parts arrive; building a curriculum around them is your job
Home Lab Setup Guide
Detonation VMs and a throwaway AD forest — the cheapest way to practise attacks nobody can prosecute you for
Courses & Training
4Hack The Box
Unguided machines. You get stuck for hours, which is the entire point and the reason most people quit
TryHackMe
Guided rooms with hints — fast early progress, easily mistaken for competence
Udemy
Cheap in the permanent sale. Quality swings hard by instructor — check the last-updated date before buying
Coursera
Vendor- and university-badged paths from Google, IBM and Johns Hopkins. Broad coverage, shallow hands-on
Professional Tools
3Burp Suite Professional
The proxy findings get reported from. Repeater and Intruder alone justify the licence
Tenable Nessus
Dependable coverage and credentialed scanning — the output is still a triage queue, not a report
Ghidra
A decompiler good enough to skip the IDA licence, with a UI that will remind you why IDA charges
Red/Blue Team Cloud Environments
4AWS Attack & Defence Infrastructure
Redirectors, C2 and VPC traffic mirroring at scale — watch the bill and read the customer testing policy first
DigitalOcean Red Team Droplets
Disposable droplets for redirectors and lab boxes, priced so you destroy them rather than nurse them
Azure Active Directory (Entra ID) Pentest Labs
Stand up an Entra ID tenant and attack it — hybrid joins, SAML, conditional access, consent phishing
GCP Security & Kubernetes Auditing
Service account impersonation chains and GKE container escapes, in an environment you are allowed to break
Wireless Testing Gear
3Hak5 WiFi Pineapple Nano
Rogue AP and client-attack tooling in a tidy package. Legal only on networks you own
Alfa WiFi Adapters (AWUS036)
Monitor mode and injection that reliably work — verify the chipset, not the model number
Hak5 USB Rubber Ducky
Keystroke injection over USB HID. The demo that ends the argument about unattended laptops
Network & Monitoring
4Managed Switches (TP-Link / MikroTik)
SPAN and port mirroring are where your IDS gets its packets from, plus VLAN segmentation to break
pfSense / OPNsense Router
pfSense or OPNsense as the lab edge — rule auditing, VPN gateways and segmentation you can actually test
Raspberry Pi Kits (SOC Sim)
Always-on sensors, honeypots and sinkholes. The microSD card is what eventually kills it, so plan for that
Suricata / Zeek Hosting
Packets in, alerts out. The tuning burden stays with you regardless of who runs the box
Privacy Browsers
3Vanadium
The hardened Chromium that ships with GrapheneOS. Tied to that OS, which is the point and the limitation
LibreWolf
Firefox with telemetry stripped and uBlock preinstalled. Expect the occasional site broken by the defaults
Tor Browser
Anti-fingerprinting done properly, routed over Tor. Slow, and logging in anywhere undoes most of it
Encrypted Email
2Password Managers
3NordPass
XChaCha20 vault with passkey support and breach alerts. Closed source, so you are trusting the audit
Bitwarden
Open source, audited annually, self-hostable. The apps are functional rather than pleasant
KeePassXC
One encrypted file, no server, no account. Sync and mobile parity are now your problem
Encrypted Cloud Storage
3MEGA
Client-side encryption and 20 GB free. Lose the recovery key and the data is gone — that is the design working
Proton Drive
End-to-end encrypted storage that fits the rest of Proton. Slower sync than the mainstream alternatives
Filen
Open-source clients, 10 GB free, German hosting. Smaller operation than the incumbents, priced accordingly
Encrypted Messengers
5Signal
The protocol everyone else copied. Still requires a phone number, which is the trade nobody has solved
Threema
No phone number, no email, a paid one-off licence. The network effect is the cost of that anonymity
Briar
Runs over Tor, Bluetooth or local Wi-Fi with no servers at all. Both devices must be online to exchange anything
Element
Federated, bridgeable, self-hostable. Key verification across many devices is where users give up
Jitsi Meet
No account, no time limit, self-hostable. End-to-end encryption only holds for small peer-to-peer calls
Encrypted DNS
4NextDNS
The most configurable resolver available — at the cost of handing one company your full query log
AdGuard DNS
Set once and forget. Blocklists you cannot tune, so the occasional broken checkout page is unattributable
Quad9
Malicious-domain filtering from a non-profit, fed by commercial threat intelligence. No blocking of ads
Pi-hole
Network-wide blocking with a query log you own. A second resolver on the router is a bypass, not a fallback
Encryption Software
3VeraCrypt
Containers and full-disk encryption with hidden volumes. Plausible deniability is weaker than the marketing
GnuPG
The OpenPGP reference implementation. Cryptographically sound, and key management defeats most people
Cryptomator
Encrypts a folder inside whatever cloud you already use. Filenames are hidden; file sizes and timings are not