source
Dalfox

XSS Scanning and Parameter Analysis tool.

Android Debug Bridge (ADB)

Android Debug Bridge (ADB).

ADExplorerSnapshot.py

ADExplorerSnapshot.py is an AD Explorer snapshot ingestor for BloodHound.

adPEAS

adPEAS is a Powershell tool to automate Active Directory enumeration.

BadBlood

BadBlood fills a Microsoft Active Directory Domain with a structure and thousands of objects.

ADReaper

A fast enumeration tool for Windows Active Directory Pentesting written in Go.

Crosslinked

Simplifies the processes of searching LinkedIn to collect valid employee names.

Arcmenu

ArcMenu is an application menu for GNOME Shell, designed to provide a more traditional user experience and workflow. This extension has many features, including multiple menu layout styles, GNOME search, quick access to system shortcuts, and more! If you are a new user to GNOME and are looking for a Windows style start menu, this extension will be perfect for you!

Other

Tools that are not directly classified under a section.

Aria2

Aria2 is a command line download client with resuming and segmented downloading. Supported protocols are HTTP/HTTPS/SFTP/FTP/BitTorrent and it also supports Metalink.

Grouper2

Tool for pentesters to help find security-related misconfigurations in Active Directory Group Policy.

AutoRecon

AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.

aws-rotate-key

Easily rotate your AWS access key.

Axel

Lightweight CLI download accelerator.

O365creeper

Enumerates valid email addresses from Office 365 without submitting login attempts.

BalenaEtcher

Flash OS images to SD cards & USB drives, safely and easily.

L333tlinked

Modified version of CrossLinked.

Brutedum

Is a SSH, FTP, Telnet, PostgreSQL, RDP, VNC brute forcing tool with Hydra, Medusa and Ncrack.

Burpsuite

WebProxy for analysis.

Certi

Utility to play with ADCS, allows to request tickets and collect information about related objects.

Certificate Ripper

A CLI tool to extract server certificates.

Certify

Active Directory certificate abuse.

Certipy

Active Directory Certificate Services enumeration and abuse.

Seatbelt

A C# project that performs a number of security oriented host-survey 'safety checks' relevant from both offensive and defensive security perspectives.

Chntpw

Change password of a user in a Windows SAM file.

Crowbar

Crowbar is a brute force tool which supports OpenVPN, Remote Desktop Protocol, SSH Private Keys and VNC Keys..

Cryptomator

Free client-side encryption for your cloud files. Open source software: No backdoors, no registration.

Curl

Is a tool to transfer data from or to a server, using one of the supported protocols. The command is designed to work without user interaction.

Cypherhound

Python3 terminal application that contains 260+ Neo4j cyphers for BloodHound data sets.

Dash-to-panel

Dash to Panel is an icon taskbar for Gnome Shell. This extension moves the dash into the gnome main panel so that the application launchers and system tray are combined into a single panel, similar to that found in KDE Plasma and Windows 7+. A separate dock is no longer needed for easy access to running and favorited applications.

dconf-editor

Graphical editor for gsettings and dconf.

DIRB

DIRB is a Web Content Scanner.

Dirsearch

An advanced web path brute-forcer.

DumpSMBShare

A script to dump files and folders remotely from a Windows SMB share.

DumpThatLSASS

Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation , it contains Anti-sandbox , if you run it under unperformant Virtual Machine you need to uncomment the code related to it and recompile.

Enum4linux

A tool for enumerating information from Windows and Samba systems.

ExchangeFinder

Find Microsoft Exchange instance for a given domain and identify the exact version.

Fio

Flexible I/O Tester.

Franz

Messaging app for WhatsApp, Slack, Telegram, HipChat, Hangouts and many many more.

Git

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals.

GitDump

GitDump dumps the source code from .git when the directory traversal is disabled.

Gittools

This repository contains three small python/bash scripts used for the Git research.

Gobuster

Directory/File, DNS and VHost busting tool written in Go.

HandBrake

HandBrake is a tool for converting video from nearly any format to a selection of modern, widely supported codecs.

IIS-ShortName-Scanner

Scanner for IIS Tilde vulnerability.

Just Perfection

Disable and Customize GNOME shell UI Elements.

KeeFarce

KeeFarce allows for the extraction of KeePass 2.x password database information from memory. The cleartext information, including usernames, passwords, notes and url's are dumped into a CSV file in %AppData%

Kerbrute

This tool is designed to assist in quickly bruteforcing valid Active Directory accounts through Kerberos Pre-Authentication.

LAPSdumper

Dump LAPS Passwords.

LDAPmonitor

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object.

LDAP Password Hunter

LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database.

LDAPDomainDump

Active Directory information dumper via LDAP.

LDAP Nom Nom

Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP).

ldapper

A GoLang tool to enumerate and abuse LDAP. Made simple.

LDAP Relay Scan

A tool to check Domain Controllers for LDAP server protections regarding the relay of NTLM authentication.

ldapsearch-ad.py

Active Directory LDAP Enumerator - Python3 script to quickly get various information from a domain controller through his LDAP service.

MACchanger

Change MAC address of a NIC.

MANSPIDER

Scan for juicy data on SMB shares. Matching files and logs are stored in $HOME/.manspider. All filters are case-insensitive.

Mattermost

Mattermost is a messaging and collaboration platform. With Mattermost, you can integrate the tools you use every day into one place and never miss a notification or task.

Nikto

Nikto is a pluggable web server and CGI scanner written in Perl, using rfp’s LibWhisker to perform fast security or informational checks.

NTLM_challenger

Fetch and parse NTLM challenge messages from HTTP and SMB services.

NTLMRecon

A fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains.

Ntlmscan

scan for NTLM directories.

Obsidian

Obsidian is a powerful and extensible knowledge base that works on top of your local folder of plain text files.

onesixtyone

onesixtyone is a simple SNMP scanner which sends SNMP requests for the sysDescr value asynchronously with user-adjustable sending times and then logs the responses which gives the description of the software running on the device.

osslsigncode

OpenSSL based Authenticode signing for PE/MSI/Java CAB files.

Pcredz

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP, IMAP, etc from a pcap file or from a live interface.

PowerView.py

Just another Powerview alternative.

RDesktop

A Remote Desktop Protocol client.

Remmina

The GTK Remote Desktop Client.

Resilio Sync

A fast, reliable, and simple file sync and share solution, powered by P2P technology.

Ruler

A tool to abuse Exchange Services.

Screenshot Tool

Conveniently create, copy, store and upload screenshots.

Shortscan

An IIS short filename enumeration tool.

Showmount

Show mount information for an NFS server.

Simple Net Speed

Simply showing network speed.

SMBclient

FTP-like client to access SMB/CIFS resources on servers.

smbclient-ng

smbclient-ng, a fast and user friendly way to interact with SMB shares.

SMBget

wget-like utility for download files over SMB.

SMBmap.py

Samba Share Enumerator.

SNMP

Simple Network Management Protocol.

snmp-check

Like to snmpwalk, snmpcheck allows you to enumerate the SNMP devices and places the output in a very human readable friendly format. It could be useful for penetration testing or systems monitoring.

snmpwalk

Retrieve a subtree of management values using SNMP GETNEXT requests.

Sosumi

Download and install macOS in a VM / macOS on Linux in one command.

Sound I/O Device Chooser

Shows a list of sound output and input devices (similar to gnome sound settings) in the status menu below the volume slider.

SQLmap

Automatic SQL injection and database takeover tool.

SSH-method-scanner

SSH method scanner. Reports password and publickey authentication.

SSHScan

A testing tool that enumerates SSH Ciphers. Using SSHScan, weak ciphers can be easily detected.

Tabby

Tabby (formerly Terminus) is a highly configurable terminal emulator, SSH and serial client for Windows, macOS and Linux.

TeraCopy

Copy your files faster and more securely.

Testdisk

Checks the partition and boot sectors of your disks. It is very useful in recovering lost partitions.

Testssl.sh

Is a free command line tool which checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws and more.

Tig

Text-mode interface for Git.

tilde_enum

Exploits and expands the file names found from the (IIS) tilde enumeration vuln.

TLScan

Scanner to enumerate SSL/TLS encryption protocol support.

TruffleHog

TruffleHog is a tool for finding credentials.

Trufflehog3

Searches through git repositories for secrets, digging deep into commit history and branches. This is effective at finding secrets accidentally committed.

Vitals

A glimpse into your computer's temperature, voltage, fan speed, memory usage and CPU load.

Visual Studio Code

Code editing. Redefined.

Wipe

The wipe command can be used to securely erase files from magnetic media.