Networking & Reconnaissance
pkg-lists/10-networking.listDefault scripts, version detection, all ports
$ nmap -sC -sV -p- -oN scan.txt <target>Default scripts, version detection, all ports
Ultra-fast mass network port discovery
$ sudo masscan -p1-65535 <subnet> --rate=10000Ultra-fast mass network port discovery
Command-line network packet capture
$ sudo tcpdump -i eth0 -nn -s0 -w capture.pcapCommand-line network packet capture
Interactive protocol inspection & analysis
$ wireshark # or: tshark -i anyInteractive protocol inspection & analysis
Multi-purpose port forwarding / bidirectional relay
$ socat TCP-LISTEN:8080,fork TCP:target:80Multi-purpose port forwarding / bidirectional relay
Tunnel TCP traffic through SOCKS proxies
$ proxychains4 nmap -sT -Pn -p80 <target>Tunnel TCP traffic through SOCKS proxies
Identify alive hosts on local Ethernet/WiFi
$ sudo arp-scan --localnetIdentify alive hosts on local Ethernet/WiFi
Comprehensive DNS enumeration & subdomains
$ dnsenum --enum target.comComprehensive DNS enumeration & subdomains
Custom TCP/IP packet assembler and tester
$ sudo hping3 -S -p 80 -c 5 <target>Custom TCP/IP packet assembler and tester
Ultra-fast port discovery piped directly to Nmap
$ rustscan -a <target> -- -A -sCUltra-fast port discovery piped directly to Nmap
Fast TCP SYN/CONNECT port scanner (ProjectDiscovery)
$ naabu -host <target> -p -Fast TCP SYN/CONNECT port scanner (ProjectDiscovery)
Web Application Security
pkg-lists/20-web.listFast web directory & parameter fuzzing
$ ffuf -u http://target/FUZZ -w /usr/share/wordlists/seclists/Discovery/Web-Content/common.txtFast web directory & parameter fuzzing
URI & directory brute-forcing
$ gobuster dir -u http://target -w /usr/share/wordlists/seclists/Discovery/Web-Content/raft-medium-directories.txtURI & directory brute-forcing
Web technology, server & CMS fingerprinting
$ whatweb -a 3 http://targetWeb technology, server & CMS fingerprinting
Clean, colored terminal HTTP client
$ http GET http://target/api/v1 Authorization:"Bearer token"Clean, colored terminal HTTP client
Password Cracking & Auditing
pkg-lists/40-auditing.listOnline network brute-force (SSH/FTP/HTTP)
$ hydra -l admin -P rockyou.txt ssh://targetOnline network brute-force (SSH/FTP/HTTP)
Modular, parallel network login cracking
$ medusa -h target -u admin -P wordlist.txt -M rdpModular, parallel network login cracking
Offline password & shadow hash cracker
$ john --wordlist=rockyou.txt hashes.txtOffline password & shadow hash cracker
GPU-accelerated hash cracking (-m 1000 = NTLM)
$ hashcat -m 1000 -a 0 ntlm_hashes.txt rockyou.txtGPU-accelerated hash cracking (-m 1000 = NTLM)
Reverse Engineering & Forensics
pkg-lists/30-forensics.listCommand-line reverse engineering & disassembler
$ r2 -d ./binary # then: aaa -> pdf @mainCommand-line reverse engineering & disassembler
Analyze and extract embedded files / firmware
$ binwalk -e firmware.binAnalyze and extract embedded files / firmware
File carving based on headers and footers
$ foremost -i image.dd -o /tmp/recovered/File carving based on headers and footers
Partition repair and deleted file recovery
$ sudo testdisk # or: sudo photorecPartition repair and deleted file recovery
Wireless Security
pkg-lists/50-wireless.list802.11 monitor mode, capture, and WPA-PSK key cracking
$ sudo airmon-ng start wlan0 && sudo airodump-ng wlan0mon802.11 monitor mode, capture, and WPA-PSK key cracking
Passive wireless device and packet sniffer
$ kismet # then open http://localhost:2501Passive wireless device and packet sniffer
Isolated Python Pentest Tools
pipx-lists/pipx-tools.listModern Active Directory & network execution tool
$ nxc smb 192.168.1.0/24 -u user -p passModern Active Directory & network execution tool
Network protocol testing suite (70 tools: secretsdump, psexec, wmiexec)
$ impacket-secretsdump domain/user:pass@targetNetwork protocol testing suite (70 tools: secretsdump, psexec, wmiexec)
Active Directory Certificate Services (AD CS) auditing
$ certipy find -vulnerable -u user@domain -p passActive Directory Certificate Services (AD CS) auditing
Automated SQL injection & database takeover
$ sqlmap -u "http://target/page.php?id=1" --batch --dbsAutomated SQL injection & database takeover
SSL/TLS intercepting HTTP proxy
$ mitmproxy # interactive TUI on port 8080SSL/TLS intercepting HTTP proxy
HTTP parameter discovery suite
$ arjun -u http://target/api/endpoint -m GETHTTP parameter discovery suite
Advanced recursive web path brute-forcer
$ dirsearch -u http://target -e php,html,jsAdvanced recursive web path brute-forcer
Instant HTTP/S file transfer server with uploads
$ updog -p 9090 -d /path/to/shareInstant HTTP/S file transfer server with uploads
Upstreams & Enterprise Suites
upstreams/Full Metasploit penetration testing framework
$ msfconsoleFull Metasploit penetration testing framework
Burp Suite Community Edition proxy & scanner
$ burpsuite # GUIBurp Suite Community Edition proxy & scanner
Zed Attack Proxy web vulnerability suite
$ zap # GUI via FlatpakZed Attack Proxy web vulnerability suite
Windows Remote Management shell
$ evil-winrm -i target_ip -u Administrator -p passWindows Remote Management shell
LLMNR / NBT-NS / mDNS poisoning & hash capture
$ sudo responder -I eth0 -dwvLLMNR / NBT-NS / mDNS poisoning & hash capture
Massive collection of wordlists, payloads, usernames
$ /usr/share/wordlists/seclists/Massive collection of wordlists, payloads, usernames
Secure port forwarding to expose local ports publicly
$ devtunnel host -p 8000Secure port forwarding to expose local ports publicly
Web Dashboards & Container Stacks
upstreams/ & 60-docker.listContainer management UI (admin; setup token in /opt/portainer/admin_setup.txt)
$ https://localhost:7999Container management UI (admin; setup token in /opt/portainer/admin_setup.txt)
Pentest reporting platform (user reptor; password in /opt/sysreptor/admin_credentials.txt)
$ http://localhost:8000Pentest reporting platform (user reptor; password in /opt/sysreptor/admin_credentials.txt)
AD attack-path mapping (user admin; password in /opt/bloodhound/admin_credentials.txt)
$ http://localhost:8080AD attack-path mapping (user admin; password in /opt/bloodhound/admin_credentials.txt)
full guide with flags & credentials: assets/TOOL_REFERENCE.md