Virtual machines
Drives
Reconnaissance
Enumeration
Web applications
APIs
Cloud
Static analysis
Disassemblers
Debuggers
Decompilers
Program editing tools
Analysis automation programming
Exploitation tools
Exploit development
Assemblers
Compilers
Steganography
Social engineering
Additional hardware
Network
Wireless
Mobile tools
Data exfiltration
Cryptanalysis
Security information and event management
Threat intelligence
Threat hunting
Vulnerability management
Network traffic analysis
Endpoint detection and response
Digital forensics and incident response
Phishing analysis
Malware analysis
Active defence
Most of these tools are Open Source, free, and together meet these requirements of a SIEM stack:
Wazuh
Graylog
Grafana
OpenCTI
MISP
Praeco
TheHIVE
Cortex
Velociraptor
Shuffle
InfluxDB
ELK stack
Splunk
Wazuh single-node deployment with docker (bare-bones)
Wazuh multi-node deployment with docker
Building Wazuh images