49 tools · 8 categories

Tool quick-reference

Every tool Pendora installs, with its go-to command and a link to the official documentation. Search by name, command, or use case.

01

Networking & Reconnaissance

pkg-lists/10-networking.list
Nmap

Default scripts, version detection, all ports

$ nmap -sC -sV -p- -oN scan.txt <target>
Ncat

Open raw TCP listener (modern Netcat)

$ ncat -lvnp 4444
Masscan

Ultra-fast mass network port discovery

$ sudo masscan -p1-65535 <subnet> --rate=10000
Tcpdump

Command-line network packet capture

$ sudo tcpdump -i eth0 -nn -s0 -w capture.pcap
Wireshark / TShark

Interactive protocol inspection & analysis

$ wireshark # or: tshark -i any
Socat

Multi-purpose port forwarding / bidirectional relay

$ socat TCP-LISTEN:8080,fork TCP:target:80
ProxyChains

Tunnel TCP traffic through SOCKS proxies

$ proxychains4 nmap -sT -Pn -p80 <target>
Arp-scan

Identify alive hosts on local Ethernet/WiFi

$ sudo arp-scan --localnet
Dnsenum

Comprehensive DNS enumeration & subdomains

$ dnsenum --enum target.com
Hping3

Custom TCP/IP packet assembler and tester

$ sudo hping3 -S -p 80 -c 5 <target>
RustScan

Ultra-fast port discovery piped directly to Nmap

$ rustscan -a <target> -- -A -sC
Naabu

Fast TCP SYN/CONNECT port scanner (ProjectDiscovery)

$ naabu -host <target> -p -
02

Web Application Security

pkg-lists/20-web.list
FFUF

Fast web directory & parameter fuzzing

$ ffuf -u http://target/FUZZ -w /usr/share/wordlists/seclists/Discovery/Web-Content/common.txt
Gobuster

URI & directory brute-forcing

$ gobuster dir -u http://target -w /usr/share/wordlists/seclists/Discovery/Web-Content/raft-medium-directories.txt
WhatWeb

Web technology, server & CMS fingerprinting

$ whatweb -a 3 http://target
HTTPie

Clean, colored terminal HTTP client

$ http GET http://target/api/v1 Authorization:"Bearer token"
03

Password Cracking & Auditing

pkg-lists/40-auditing.list
Hydra

Online network brute-force (SSH/FTP/HTTP)

$ hydra -l admin -P rockyou.txt ssh://target
Medusa

Modular, parallel network login cracking

$ medusa -h target -u admin -P wordlist.txt -M rdp
John the Ripper

Offline password & shadow hash cracker

$ john --wordlist=rockyou.txt hashes.txt
Hashcat

GPU-accelerated hash cracking (-m 1000 = NTLM)

$ hashcat -m 1000 -a 0 ntlm_hashes.txt rockyou.txt
04

Reverse Engineering & Forensics

pkg-lists/30-forensics.list
Radare2

Command-line reverse engineering & disassembler

$ r2 -d ./binary # then: aaa -> pdf @main
GDB

The GNU dynamic debugger

$ gdb -q ./binary # then: r, b *main
Binwalk

Analyze and extract embedded files / firmware

$ binwalk -e firmware.bin
Foremost

File carving based on headers and footers

$ foremost -i image.dd -o /tmp/recovered/
ExifTool

Inspect and extract file metadata

$ exiftool image.jpg
TestDisk

Partition repair and deleted file recovery

$ sudo testdisk # or: sudo photorec
Hexedit

Direct hexadecimal editor

$ hexedit binary_file
05

Wireless Security

pkg-lists/50-wireless.list
Aircrack-ng

802.11 monitor mode, capture, and WPA-PSK key cracking

$ sudo airmon-ng start wlan0 && sudo airodump-ng wlan0mon
Kismet

Passive wireless device and packet sniffer

$ kismet # then open http://localhost:2501
Reaver

WPS brute-force assessment

$ sudo reaver -i wlan0mon -b <BSSID> -vv
06

Isolated Python Pentest Tools

pipx-lists/pipx-tools.list
NetExec (nxc)

Modern Active Directory & network execution tool

$ nxc smb 192.168.1.0/24 -u user -p pass
Impacket

Network protocol testing suite (70 tools: secretsdump, psexec, wmiexec)

$ impacket-secretsdump domain/user:pass@target
Certipy

Active Directory Certificate Services (AD CS) auditing

$ certipy find -vulnerable -u user@domain -p pass
SQLmap

Automated SQL injection & database takeover

$ sqlmap -u "http://target/page.php?id=1" --batch --dbs
Mitmproxy

SSL/TLS intercepting HTTP proxy

$ mitmproxy # interactive TUI on port 8080
Arjun

HTTP parameter discovery suite

$ arjun -u http://target/api/endpoint -m GET
Dirsearch

Advanced recursive web path brute-forcer

$ dirsearch -u http://target -e php,html,js
Updog

Instant HTTP/S file transfer server with uploads

$ updog -p 9090 -d /path/to/share
Sublist3r

OSINT subdomain discovery

$ sublist3r -d domain.com
07

Upstreams & Enterprise Suites

upstreams/
Metasploit

Full Metasploit penetration testing framework

$ msfconsole
Burp Suite

Burp Suite Community Edition proxy & scanner

$ burpsuite # GUI
OWASP ZAP

Zed Attack Proxy web vulnerability suite

$ zap # GUI via Flatpak
Evil-WinRM

Windows Remote Management shell

$ evil-winrm -i target_ip -u Administrator -p pass
Responder

LLMNR / NBT-NS / mDNS poisoning & hash capture

$ sudo responder -I eth0 -dwv
SecLists

Massive collection of wordlists, payloads, usernames

$ /usr/share/wordlists/seclists/
DevTunnel

Secure port forwarding to expose local ports publicly

$ devtunnel host -p 8000
08

Web Dashboards & Container Stacks

upstreams/ & 60-docker.list
Portainer CE

Container management UI (admin; setup token in /opt/portainer/admin_setup.txt)

$ https://localhost:7999
SysReptor

Pentest reporting platform (user reptor; password in /opt/sysreptor/admin_credentials.txt)

$ http://localhost:8000
BloodHound CE

AD attack-path mapping (user admin; password in /opt/bloodhound/admin_credentials.txt)

$ http://localhost:8080

full guide with flags & credentials: assets/TOOL_REFERENCE.md