Resources

Web Tools:

Base 64 Decode + EncodeFast Decoder/ Encoder for Base64 with multiple character sets.
AbuseIPDBDatabase checker for malicious wesites or IP addresses. Great for validating new websites and unfamiliar markets.
Have I Been PwnedChecks for data breaches associated with an email.
WhoIsWho Is Domain lookup hosted by github.
KeyCodePhotoExtracts key codes from photographs of physical keys.
KeygenUses key codes to generate a 3d key and STL file for 3d printing.

Downloadable Tools:

MetasploitPowerful penetration testing framework.
OSINT4ALLAn absolute fuck ton of OSINT tools for fun and fuckery.
ZAPZed Attack Proxy (ZAP), web application for vulnerability, penetration, and runtime testing along with code review. – Open Source.
ZenMapA GUI NMAP too used for port scanning and device discovery.

References:

OSSTMM3Open Source Security Testing Methodology Manual – PDF.
OWASPOpen source initiative to improve software security and education.
CVECommon Vulnerability and Exposures website, this is THE list, used to patch systems and stay ahead of common vulnerabilities. This is also the website that most vulnerabiltiy scanners will refer to when enumerating ports.