Kali Linux is really the de facto penetration testing toolkit for anyone interested in this space.
Some tools that are already built-in to Kali Linux:
- dnsenum: enumerates DNS information of a domain and to discover non-contiguous ip blocks
- dnsmap: DNS domain name brute forcing tool
- nmap: utility for network discovery and security auditing
- Burp Suite: Web vulnerability scanner and related tooling. Kali bundles the free “community edition”, but you’ll want to buy a license for Pro