Stack Cost AI

Vulnerability Management And Penetration Testinghobby stack.

For each requirement below, pick the option that fits your build — recommended first, then free and cheaper alternatives — or skip what your project doesn't need. Tap the info icon next to any requirement to see why it matters.

Port Scanning & Service Enumeration

Pricing & free-tier limitsNmap/RustScan/Masscan: Free OSS unlimited. Nessus Essentials Free 16 IPs. Nessus Pro $3,990/yr. Tenable.io $2,500/yr 100 assets, $0.25/asset/day overage. Over 100 assets +$25/asset/yr

Asset Discovery / Attack Surface Management

Pricing & free-tier limitsShodan Free 100 queries/mo, 1 scan credit. Pro $59/mo 10k results/mo. Enterprise $299/mo 5k query credits, $0.10/query overage. Censys Free 250 queries/mo, Pro $199/mo 2.5k queries. AssetNote $500/mo 5k assets

Vulnerability Scanner (Network/Infrastructure)

Pricing & free-tier limitsOpenVAS Free OSS unlimited assets self-hosted. Tenable.io $2,500/yr 100 assets ($25/asset/yr), $0.25/asset/day over. Rapid7 InsightVM $2,000/yr 500 assets ($4/asset), $5/asset/yr over. Qualys VMDR $20k/yr 1000 assets $20/asset/yr over, $1.67/asset/mo

Web Application Vulnerability Scanner (DAST)

Pricing & free-tier limitsZAP/Nuclei Free OSS unlimited. Burp Pro $449/yr/user, Enterprise $6,995/yr 10 agents ($699/agent). Acunetix $4,495/yr 25 targets ($180/target), $150/target/yr over. Over scans $0.50/scan

Secrets Scanning & Leak Detection

Pricing & free-tier limitsTruffleHog/Gitleaks Free OSS unlimited repos. GitGuardian Free 25 devs, 1k commits, 1 historical scan. Business $20/dev/mo after ($240/dev/yr), 10k incidents/mo incl., $0.10/incident over. GitLab Secret Detection Free in Ultimate

SSL/TLS & Certificate Vulnerability Scanning

Pricing & free-tier limitsTestSSL.sh/SSLyze Free OSS. Qualys SSL Labs Free 400 scans/day. Detectify Starter $1,584/yr 250 domains ($6.3/domain/mo), $20/scan over. Over certs $2/cert/mo

DNS Security & Subdomain Enumeration / Takeover Detection

Pricing & free-tier limitsAmass/Subfinder/Sublist3r Free OSS unlimited. SecurityTrails Free 50 queries/mo. API $99/mo 2k queries ($0.05/query), $0.05/query overage. Enterprise $399/mo 20k queries

Exploitation Framework

Pricing & free-tier limitsMetasploit Framework/ExploitDB/SearchSploit Free OSS. Metasploit Pro $15,000/yr 1 user. Cobalt Strike $5,900/yr/user team server included. Brute Ratel C4 $2,499/yr/user. No overage, seat-based

Password Auditing / Credential Stuffing Testing

Pricing & free-tier limitsHashcat/John/Hydra/Medusa Free OSS unlimited. Hashcat.Team Server $0. Elcomsoft $599 one-time Pro, $299/yr maintenance, $99/node/yr over. Online hash check free

Remediation Workflow & Ticketing (SecOps)

Pricing & free-tier limitsJira Free 10 users, 2GB. Standard $8.15/user/mo $81.5/mo 10 users. Linear Free 250 issues. Standard $10/user/mo. ServiceNow SecOps $50k/yr starter (approx $120/user/mo enterprise min 20 users), $50/incident over

Penetration Testing Reporting & Documentation

Pricing & free-tier limitsDradis CE Free OSS self-hosted unlimited projects. PlexTrac Community Free 1 user. Starter $119/user/mo $1,428/yr/user. Faraday Pro $4,500/yr 10 users ($450/user/yr), $400/user/yr over

Options and prices come straight from our research sheets for a hobby vulnerability management and penetration testing project. Prices are estimates and change often — always confirm on the provider's page before committing.

How this hobby vulnerability management and penetration testing checklist works.

Each requirement below is something a hobby vulnerability management and penetration testing build typically needs. Pick one of the four researched options — recommended, free, cheaper or paid — add your own with "Other", or skip the requirement if your project doesn't need it. Nothing is mandatory; the plan on the right tracks what you've decided so nothing gets forgotten.

Your picks are saved in this browser automatically, so you can come back anytime. Options are researched per build level and refreshed as vendors change their plans — always verify details on the provider's page before committing.