Three tools tied at the top of this category: Burp Suite, Nmap, and Wireshark were each named in 5 of the 6 answers (83%) when we asked ChatGPT and Gemini for the best penetration testing tools. No single tool was named in all six.
Kali Linux came next, named in 4 of 6 answers (67%), and Metasploit followed at 3 of 6 (50%). After that the list falls off a cliff. We recorded 23 distinct tools across the six answers, but only 5 of them cleared the halfway mark of three answers or more. Everything else was named once or twice, so the settled core of this category is small and the long tail is large.
We put six buyer-style questions to ChatGPT and Gemini, gave each question one live web search, and recorded every product named and every source domain cited. Every number on this page is a plain count out of those six answers. Nothing is modeled, weighted, or guessed.
How the shortlist changed across the six questions
The bare "best penetration testing tools" question and the "penetration testing tools recommendations" question returned almost the same answer. Both named Kali Linux, Burp Suite, Wireshark, John the Ripper, Hashcat, Nmap, and Invicti. The only difference between the two was the eighth name: "best" added Nikto, "recommendations" added OWASP ZAP. Two phrasings, seven identical picks.
The "best free" answer is where three tools showed up that appeared in no other question: FFUF, Dirsearch, and Gobuster, each named once (1 of 6). All three are content-discovery and fuzzing tools, and the free framing was the only place the engines reached for them. That answer still kept the core of Burp Suite, Nmap, Wireshark, Metasploit, and Nikto, so "best free" reads as the staples plus three specialists.
The "most affordable" answer pulled in its own two one-offs: Zeropath and RapidFireTools, each named once (1 of 6) and nowhere else. It was also one of only two answers to name Pentest-Tools.com (2 of 6 overall). So "affordable" was the single framing that leaned toward commercial, paid products instead of the open-source staples, even while it still opened with Kali Linux and Nmap.
The "small teams" answer was the biggest outlier of the six. It was the only answer that named neither Burp Suite nor Nmap, the two tools that appeared in five answers each. In their place it produced three names seen nowhere else: Angry IP Scanner, Iron Fox Inc., and Metasploit Framework (the full-name label). Add "for small teams" to the question and the engines went shopping in a different set of pages.
The "what penetration testing tools should I use" answer added three more one-offs of its own: Nessus, Aircrack-ng, and ZAP (Zed Attack Proxy), each named once (1 of 6). Tallied up, 12 of the 23 named tools appeared in exactly one of the six answers. More than half the names on this page are one-question wonders, which is the whole point of measuring the fan-out: the shortlist a buyer sees depends heavily on how they word the question.
The source map
Two domains fed every single answer: reddit.com and pentest-tools.com were each cited in all 6 questions (100%). A community forum and one vendor's roundup content are, between them, the backbone of what ChatGPT and Gemini read before answering in this category.
After those two, hackerone.com was cited in 4 of 6 answers (67%) and intruder.io in 3 of 6 (50%). Then came a long tail of security-company and media domains cited once or twice each: sentinelone.com, vikingcloud.com, plextrac.com, complyjet.com, github.com, and youtube.com at two apiece, with single citations from csoonline.com, cyberdefensemagazine.com, thectoclub.com, eccouncil.org, blackduck.com, checkpoint.com, and others. In total, 24 distinct domains fed the six answers.
The one to notice is pentest-tools.com. It is a vendor's own domain, it was cited in all 6 answers, and the product Pentest-Tools.com was itself named in 2 of 6 answers. That is the loop every marketer in this space wants: your own published content gets read by the assistant, and your own product lands in the recommendation. It is the clearest case in this dataset of a vendor's site feeding an answer that names the vendor.
The counter-example sits right beside it. Intruder's domain, intruder.io, was cited in 3 of 6 answers, but the Intruder product was named 0 times. Publishing a roundup got the domain read; it did not get the product into the answer. Being a source and being a pick are two different outcomes.
Worth stating plainly: G2 and Capterra did not appear at all. The classic software review directories fed none of the six answers. The only review-style directory that showed up was trustradius.com, and only once (1 of 6). In this category the answers are assembled from Reddit threads, GitHub, and vendor and security-media roundups, not from the review sites many marketing teams pour their time into.
What it takes to get named here
If you sell in this category, the practical takeaway is narrow: be present in the exact pages these answers are built from. That means the Reddit threads that fed all 6 answers, the roundup posts on domains like pentest-tools.com, hackerone.com, and intruder.io, and the GitHub repositories the engines pulled from twice. The source list, not your market share, is what decides whether your name appears.
The Pentest-Tools.com versus Intruder contrast is the lesson in a single line. Getting your domain cited is step one, and getting your product named inside the third-party sources (the Reddit threads and other roundups) is step two, and only the second step puts you in the answer. A tool can be genuinely excellent and still be invisible here if the pages the assistant reads never mention it.
The full list, counted
| Product | Named in | Share |
|---|---|---|
| Burp Suite | 5 of 6 | 83% |
| Nmap | 5 of 6 | 83% |
| Wireshark | 5 of 6 | 83% |
| Kali Linux | 4 of 6 | 67% |
| Metasploit | 3 of 6 | 50% |
| Metasploit Framework | 1 of 6 | 17% |
| Hashcat | 2 of 6 | 33% |
| Invicti | 2 of 6 | 33% |
| John the Ripper | 2 of 6 | 33% |
| Nikto | 2 of 6 | 33% |
| Pentest-Tools.com | 2 of 6 | 33% |
| SQLmap | 2 of 6 | 33% |
Two entries in that table are the same tool under two labels, and we have not merged them, because no single answer treated them as one line. Metasploit was named 3 times as "Metasploit" and once more as "Metasploit Framework" in the small-teams answer, so we show both rows rather than invent a Metasploit total of 4. The Zed Attack Proxy was split the same way, across "OWASP ZAP" (1 of 6) and "ZAP (Zed Attack Proxy)" (1 of 6) in two different answers. The engines are not consistent about names, and summing the labels would report a number the measurement never produced.
Where Glotier fits
Glotier does not sell penetration testing tools, so we are correctly absent from all six answers, and we are not going to pretend otherwise. We measure AI visibility; we do not build security scanners.
But the measurement on this page is exactly the thing we run for a customer's own category. We ask the assistants the questions your buyers actually type, we record who gets named and which sources fed each answer, and we hand you the same kind of source map you just read, pointed at your competitors and at you. If you want to see it for your own category, the check is free, needs no account, and takes about a minute.