CrackMapExec
Swiss army knife for pentesting Active Directory networks (now NetExec in many repos).
Empire
Post-exploitation framework with PowerShell and Python agents (check current maintained forks).
LinPEAS
Linux privilege escalation enumeration script. Find misconfigs quickly on compromised hosts.
Mimikatz
Windows credential extraction classic. Often used via Metasploit or wine on Kali for research labs.
Netcat
Swiss army knife of networking — debug, transfer files, and simple reverse shells (lab).
Socat
Advanced multipurpose relay — more flexible than netcat for complex tunnels.