For actual analysis of potential holes nothing beats nmap. If you plan on running a Windows machine as the attacking box, nmap can now be ran off of a Windows machine using the libpcap program.