Tools I use on a daily basis:
-
dnsmap - DNS record enumeration using dictionary brute forcing. I have a host list. Find all kinds of infrastructure with this tool. Opensource.
-
Spiderfoot - Full intelligence gathering suite. Open source. Nice UI.
-
Arachni - Web application scanner. Has a nice web interface and can run distributely.
-
WPScan - WordPress specific attack tool