Burp Suite / Metasploit / Nmap
Also written as Burp Suite, Metasploit, Nmap, Kali Linux, Wireshark, OWASP ZAP
The standard toolkit of penetration testers and security analysts. Burp Suite and OWASP ZAP test web applications for weaknesses; Nmap scans networks to find which machines and services are exposed; Metasploit runs known attacks to prove a system is vulnerable; Wireshark captures and inspects network traffic. Kali Linux bundles them all.
Think of it like
A locksmith's kit: owning the picks is easy; knowing which lock to try, and why, is the skill.
Junior or senior?
Listing these tools is common among students and certification-seekers. Real experience shows up as findings: what they discovered, how serious it was, and how they reported it.
Senior sounds like
Can explain what they found by hand that automated scanners missed.
Ask them
“Walk me through a real vulnerability you found with these tools. How did you confirm it, and how did you report it?”