Expect wrote: » really depends what type of security consulting you're doing...there are hundreds of tools out there.mastering Burp/OWASP ZAP, Metasploit and enumeration tools is usually a good start.and its not all about tools, it's about techniques, your knowledge your methodologies and your OOB thinking that would lead you to find the security gems. sometimes automated tools don't hit.