My main use case for Kali Linux is for security testing, checking websites, security, analyzing malware, and open-source intelligence gathering.
I have WordPress websites, so I want to identify whether they are vulnerable or not. Kali Linux has many inbuilt tools such as WPScan, which I can use readily and analyze whether a website is secure or not, and whether the code running on it is up-to-date or has vulnerabilities. I have used it for checking Wi-Fi security, identifying whether the SSIDs are vulnerable to brute-force attacks or any other cracking attempts.
I have used Kali Linux for penetration testing, bypassing antivirus and gaining access to machines, virtual machines for testing. I have used Metasploit, which is in-built with Kali Linux, and I have utilized many Metasploit exploits and modules to achieve this.