Pen testing: Burp Suite Pro, OWASP ZAP, Nuclei, Caido, Metasploit, Cobalt Strike, BloodHound, Mythic, Sliver, Mimikatz
Cloud security: Prowler, ScoutSuite, CloudSploit, AWS Security Hub, AWS Inspector, Wiz, Lacework, Orca
AppSec / SAST / SCA: Semgrep, CodeQL, Snyk, Mend, Socket, GitHub Advanced Security, Trivy, Grype, Checkov, Kubescape
AI security tooling: Garak (NVIDIA), PyRIT (Microsoft), Promptfoo red team, NeMo Guardrails, LangChain output parsers, Lakera Guard
SIEM & XDR: Splunk, Microsoft Sentinel, Elastic Security, Wazuh, Datadog Cloud SIEM, Panther, LimaCharlie
EDR / XDR: CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Sophos Intercept X, Huntress
Identity & zero trust: Okta, Microsoft Entra ID, Auth0, JumpCloud, BeyondTrust, CyberArk, HashiCorp Vault, Tailscale, Cloudflare Access
Compliance tooling: Vanta, Drata, Secureframe, Tugboat Logic, Hyperproof, AuditBoard for SOC 2 / ISO 27001 / HIPAA evidence
DLP & email security: Material, Sublime Security, Abnormal, Proofpoint, Microsoft Purview, Nightfall AI
Network: Next-gen firewalls (Palo Alto, Fortinet, Check Point), WAF (Cloudflare, AWS WAF, Akamai), DDoS protection