cyberstars
cyberstars / purpose / pentest

Outils pour pentest

Scoped offensive engagements and assessments.

142 tools indexed

Nmap

The classic network mapper and port scanner.

ScanReconNetworksEndpoints
CNPSL

Template-based vulnerability scanner.

ScanWeb appsNetworks
GoMIT

In-depth attack surface mapping.

ReconScanWeb appsNetworks
GoApache-2.0

Modern intentionally vulnerable web app.

AutomateWeb apps
TypeScriptMIT

Automated pentest + vuln scanner.

ScanExploitWeb appsNetworks
PythonApache-2.0

Open-source web app scanner.

ScanInterceptWeb apps
JavaApache-2.0

Completely ridiculous API (training target).

AutomateWeb apps
JavaScriptApache-2.0

Runtime mobile exploration via Frida.

AnalyzeInterceptMobile apps
PythonGPL-3.0

PTF

Pentest Testers Framework installer.

AutomateEndpoints
PythonBSD-3-Clause

Pacu

Open-source AWS exploitation framework.

ExploitReconCloud
PythonBSD-3-Clause

Burp extension for parameter discovery.

ReconFuzzWeb apps
JavaApache-2.0

Active Directory health audit.

ScanHardenActive Directory
C#Proprietary

Offline WPS pin brute-force.

CrackWireless
CGPL-3.0

PowerShell post-exploitation framework.

ExploitReconActive DirectoryEndpoints
PowerShellBSD-3-Clause

MitM relay sidekick for AD.

InterceptExploitActive DirectoryNetworks
GoApache-2.0

PowerShell AD post-exploitation.

ExploitReconActive DirectoryEndpoints
PowerShellMIT

QARK

Quick Android Review Kit.

ScanAnalyzeMobile apps
PythonApache-2.0

WPS pin brute-force attack.

CrackExploitWireless
CMIT

Full-featured reconnaissance framework.

ReconAutomateWeb appsNetworks
PythonGPL-3.0

LLMNR, NBT-NS and MDNS poisoner.

InterceptExploitActive DirectoryNetworks
PythonGPL-3.0

C# Kerberos abuse toolkit.

ExploitCrackActive Directory
C#BSD-3-Clause

Abuse Exchange services from the outside.

ExploitInterceptActive DirectoryEndpoints
GoCustom

Modern port scanner in Rust.

ScanReconNetworks
RustGPL-3.0

Find misconfigured object storage buckets.

ScanReconCloud
GoMIT