Do Pentesters Have Too Many Tools or Not Enough?

https://hackernoon.imgix.net/images/IKXzMIRzuqcRvy8v7VsXkDPhvBK2-r483a2k.jpeg

Ask five pentesters how many tools they touch in a single engagement, and you'll get five different answers, and none of them will sound especially organized. One's still running a spreadsheet next to a scanner next to three separate chat threads with the client. Another swears by a stack they built themselves over a decade and won't touch anything new. The honest answer to "too many or not enough" is probably both, depending on which hour of the engagement you catch them in.

The case for more tools is easy to make. Attack surfaces keep growing, cloud environments sprawl in directions nobody planned for, and every new API or mobile app is one more thing that needs its own specialized testing approach. A generalist scanner just won't catch what a purpose-built tool for, say, container security or API fuzzing will catch. So teams keep adding. New client, new tech...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE