During the course of our assessments, we use many different tools for data collection, analysis, and reporting. Often times, if a tool does not exist, we will write it ourselves. Hopefully if it solved a problem for us, it will do so for you too. We appreciate any feedback.
SQL support has been a much requested feature of NMAP in the Redspin office. While a number of tools exist to support NMAP SQL output, their database format has left much to be desired. Using SQLite, Perl's DB and the NMAP Parser module, our tool extracts all supported fields in an NMAP XML file and creates a user-friendly database format. The resulting database can then be queried directly using SQLite in order to extract relevant information.

fTrace is a security assessment tool to trace local function calls and identify security vulnerabilities in Linux binaries. It dynamically traces a non-stripped binary until it exits and prints to stderr all the local function calls which the program calls and reports possible arguments and return values of each function. It was programmed with intentional compatibility with such tools as strace(1) and ltrace(1) but is oriented toward secure program development.

The Crackulator is a password policy auditor. It computes the amount of time it would take to crack a password given its complexity requirements and compares it to the password age policy. Use this security assessment tool to verify that your password policy is strict enough for a given purpose. If it is possible to crack a password before the password is required to be changed, then this tool will indicate that the password policy should be revised.

