Tools
109 security tools integrated with GITEST
amass
goIn-depth attack surface mapping. OWASP tool for network asset discovery using OSINT and active techniques.
amass (GitHub)assetfinder
goFast subdomain finder from Tomnomnom. Finds domains related to a target from various sources.
assetfinder (GitHub)dnstwist
pipDomain name permutation engine to detect typosquatting, phishing, and corporate espionage. Generates and checks variations of domain names.
dnstwist (GitHub)gitleaks
goSAST tool for detecting hardcoded secrets (API keys, passwords, tokens) in git repos. Fast and configurable with built-in and custom rules.
gitleaks (GitHub)holehe
pipCheck if an email address is registered on 120+ online platforms including Twitter, Instagram, GitHub and more.
holehe (GitHub)httpx
goFast and multi-purpose HTTP toolkit. Probes for alive hosts, tech stack, status codes, and more.
httpx (GitHub)maigret
pipCollect user information by username from 3000+ sites. Profiles social network footprint with detailed metadata extraction.
maigret (GitHub)masscan
aptUltra-fast TCP port scanner. Scans the entire internet in under 6 minutes. Transmit-only design with custom TCP/IP stack for maximum speed.
masscan (GitHub)massdns
makeHigh-performance DNS stub resolver. Resolves millions of domains per second for bulk operations.
massdns (GitHub)naabu
goFast port scanner written in Go. Designed for reliability and speed with SYN/TCP/CONNECT scan modes.
naabu (GitHub)prowler
pipSecurity assessment tool for AWS, GCP, and Azure. Performs 300+ checks for CIS benchmarks, GDPR, HIPAA, and custom compliance frameworks.
prowler (GitHub)rustscan
cargoModern port scanner written in Rust. Scans all 65k ports in 3 seconds then feeds results to nmap for service detection.
rustscan (GitHub)scoutsuite
pipMulti-cloud security auditing tool. Gathers data from AWS, GCP, Azure, Alibaba Cloud, and Oracle Cloud to identify misconfigurations and risks.
scoutsuite (GitHub)secretfinder
git+pipPython tool to discover sensitive data (API keys, tokens, passwords) in JavaScript files via regex patterns.
secretfinder (GitHub)sherlock
pipHunt down social media accounts by username across 400+ platforms including Twitter, GitHub, Instagram, LinkedIn and more.
sherlock (GitHub)spiderfoot
pipAutomated OSINT framework with 200+ modules. Correlates data from DNS, WHOIS, social media, threat intelligence, and more.
spiderfootsubfinder
goPassive subdomain discovery tool. Finds valid subdomains using online sources like crt.sh, SecurityTrails, and more.
subfinder (GitHub)sublist3r
pipSubdomain enumeration tool using search engines (Google, Bing, Yahoo, DNSDumpster, VirusTotal) and brute-force.
sublist3r (GitHub)theHarvester
pipOSINT tool for gathering emails, subdomains, hosts, employee names, open ports from public sources like search engines and DNS.
theHarvester (GitHub)trufflehog
goFind credentials and secrets in git repos, S3 buckets, and filesystems. Verifies secrets against APIs to eliminate false positives.
trufflehog (GitHub)arjun
pipHTTP parameter discovery suite. Finds hidden GET/POST parameters using wordlists and multi-threaded probing.
arjun (GitHub)dirsearch
git+pipWeb path brute-force scanner. Python-based directory and file enumeration tool.
dirsearch (GitHub)ffuf
goFast web fuzzer written in Go. Directory/file discovery, vhost discovery, and parameter fuzzing.
ffuf (GitHub)gospider
goFast web spider for web application recon. Discovers URLs from sitemaps, JavaScript, robots.txt, forms, and external sources.
gospider (GitHub)katana
goFast and configurable web crawler and spider from ProjectDiscovery. Supports headless mode, JS rendering, and scope control.
katana (GitHub)mitmproxy
pipInteractive man-in-the-middle HTTP/HTTPS proxy. Intercept, inspect, modify, and replay web traffic. Scriptable via Python addons.
mitmproxynmap
aptNetwork exploration and security auditing utility. Port scanning, service detection, OS fingerprinting, and NSE scripts.
nmapnuclei
goFast and customizable vulnerability scanner based on YAML templates. Community-driven template library.
nuclei (GitHub)testssl
gitFree command-line tool to check SSL/TLS encryption. Tests ciphers, protocols, vulnerabilities (BEAST, POODLE, Heartbleed) and certificate issues.
testssltrivy
aptAll-in-one security scanner for containers, filesystems, git repos, and cloud configs. Detects CVEs, misconfigurations, secrets, and generates SBOMs.
trivy (GitHub)wafw00f
pipWeb Application Firewall detection tool. Identifies WAF products protecting a target.
wafw00f (GitHub)whatweb
aptWeb technology fingerprinting tool. Identifies CMS, web servers, JavaScript frameworks, and more.
whatweb (GitHub)airgeddon
gitMulti-use bash menu-driven wireless auditing framework. Handshake capture, evil twin attacks, PMKID attacks, and captive portal attacks in one script.
airgeddon (GitHub)bettercap
aptSwiss army knife for network attacks and monitoring. ARP spoofing, DNS spoofing, HTTP/HTTPS MITM, WiFi scanning, BLE scanning, and scriptable modules.
bettercapbloodhound
pip+aptActive Directory attack path mapping. Identifies privilege escalation paths and trust relationships.
bloodhound (GitHub)burpsuite
manualWeb application security testing platform. Proxy, scanner, intruder, repeater, and more.
burpsuitecertipy
pipTool for enumerating and exploiting Active Directory Certificate Services (AD CS). Finds vulnerable certificate templates for privilege escalation.
certipy (GitHub)chisel
goFast TCP/UDP tunnel over HTTP, secured with SSH. Enables port forwarding and SOCKS proxy through firewalls and restricted networks.
chisel (GitHub)crackmapexec
pipxPost-exploitation lateral movement tool. SMB, WinRM, MSSQL, and Active Directory enumeration.
crackmapexec (GitHub)dalfox
goPowerful open-source XSS scanner and exploitation tool. Parameter analysis, DOM XSS detection, blind XSS support, and custom payload injection.
dalfox (GitHub)evil-winrm
gemWinRM shell for pentesting Windows targets. Supports pass-the-hash, pass-the-ticket, Kerberos authentication, file upload/download, and PowerShell remoting.
evil-winrm (GitHub)evilginx3
goMITM attack framework for phishing credentials while bypassing 2FA. Proxies target website to capture session cookies.
evilginx3 (GitHub)hashcat
aptAdvanced password recovery tool. GPU-accelerated hash cracking with support for 300+ hash types.
hashcathavoc
makeModern C2 framework with an advanced GUI and extensible shellcode loaders. Supports multiple agents and post-exploitation modules.
havoc (GitHub)hcxdumptool
aptCapture WiFi packets and PMKID hashes from WPA/WPA2 networks. Designed for offline WPA password cracking with hcxtools and hashcat.
hcxdumptool (GitHub)hydra
aptFast and flexible online password brute-forcing tool. Supports numerous protocols.
hydra (GitHub)impacket
pipNetwork protocols implementation. SMB, Kerberos, MSRPC, WMI, DCE/RPC for lateral movement.
impacket (GitHub)kerbrute
goKerberos brute-force and user enumeration tool. Performs AS-REP roasting, password spraying, and user enumeration against Active Directory.
kerbrute (GitHub)ligolo-ng
goAdvanced tunneling and pivoting tool using TUN interfaces. No SOCKS proxy needed — agents create real network interfaces for seamless pivoting.
ligolo-ng (GitHub)metasploit
aptPenetration testing framework. Exploit development, payload generation, post-exploitation, and pivoting.
metasploitmythic
dockerCollaborative multi-user C2 framework with a web UI. Plugin-based architecture supporting multiple agents (Athena, Apollo, Merlin) and C2 profiles.
mythic (GitHub)netexec
pipNetwork execution tool — successor to CrackMapExec for SMB, WinRM, LDAP, MSSQL, SSH. Mass credential testing and lateral movement automation.
netexec (GitHub)nikto
aptWeb server vulnerability scanner. Tests for dangerous files, outdated software, and server misconfigurations.
niktonosqlmap
git+pipAutomated NoSQL database exploitation tool. Tests for NoSQL injection vulnerabilities in MongoDB, Redis, CouchDB, and other NoSQL systems.
nosqlmap (GitHub)owasp-zap
apt+pipOWASP Zed Attack Proxy. Free, open-source web application security scanner.
owasp-zappacu
pipAWS exploitation framework. Post-exploitation and persistence in AWS environments — privilege escalation, data exfiltration, and lateral movement.
pacu (GitHub)peass-ng
curlPrivilege Escalation Awesome Scripts (LinPEAS/WinPEAS). Automated local privilege escalation enumeration for Linux, Windows, and macOS.
peass-ng (GitHub)pwncat-cs
pipNetcat replacement with persistence-focused post-exploitation. Handles shell stabilization, file upload/download, and automated enumeration on connection.
pwncat-cs (GitHub)pwntools
pipCTF exploitation framework. Python library for exploit development, binary exploitation, and crypto challenges.
pwntoolsresponder
aptLLMNR/NBT-NS/mDNS poisoner. Captures NTLM hashes from network traffic.
responder (GitHub)routersploit
git+pipExploitation framework for embedded devices and routers. Modules for exploiting CVEs in Cisco, Huawei, D-Link, TP-Link, and other network devices.
routersploit (GitHub)setoolkit
git+pipSocial Engineering Toolkit. Comprehensive suite for social engineering attacks: spear-phishing, website cloning, credential harvesting, and payload delivery.
setoolkit (GitHub)sliver
curlOpen-source cross-platform C2 framework by BishopFox. Generates implants, manages sessions, and supports MTLS/HTTP/DNS/WireGuard C2 channels.
sliver (GitHub)slowloris
pipSlow HTTP denial-of-service attack tool. Keeps many connections open to the target web server simultaneously by sending partial HTTP requests.
slowloris (GitHub)sqlmap
aptAutomatic SQL injection and database takeover tool. Detects and exploits SQL injection flaws.
sqlmapwifiphisher
aptAutomated WiFi phishing framework. Creates rogue access points with realistic captive portals to capture WPA credentials via social engineering.
wifiphisher (GitHub)wifite
aptAutomated wireless auditing tool. Attacks WEP, WPA, WPA2, and WPS networks. Captures handshakes and cracks with built-in Hashcat/Aircrack-ng support.
wifite (GitHub)xsstrike
git+pipAdvanced XSS detection suite with intelligent payload generation, context analysis, and WAF bypass capabilities.
xsstrike (GitHub)anew
goAppend lines to a file only if they don't already exist. Perfect for deduplication in pipelines.
anew (GitHub)autopsy
aptDigital forensics platform. Disk image analysis, file recovery, timeline generation.
autopsycupp
pipCommon User Passwords Profiler. Generates targeted password lists based on personal information gathered through social engineering or OSINT.
cupp (GitHub)curl
aptCommand-line tool for transferring data with URL syntax. Essential for HTTP testing and API interaction.
curlgrep
systemPattern matching utility. Essential for filtering and searching output from security tools.
grephaiti
gemHash type identifier. Detects hash algorithms from a given hash string and provides hashcat/john mode numbers.
haiti (GitHub)notify
goSend notifications to multiple platforms (Discord, Slack, Telegram, etc.) from pipelines.
notify (GitHub)volatility
pipMemory forensics framework. Analyzes RAM dumps for malware, artifacts, and incident response.
volatility (GitHub)wireshark
aptNetwork protocol analyzer. Deep packet inspection, traffic analysis, and protocol decoding.
wiresharkbinwalk
aptFirmware analysis and embedded file extraction. Identifies and extracts files from binary images including file systems, compression artifacts, and bootloaders.
binwalk (GitHub)bulk_extractor
aptFast digital forensics tool that extracts features from disk images without parsing the file system. Extracts emails, URLs, credit cards, phone numbers, and more.
bulk_extractor (GitHub)exiftool
aptMetadata extraction from files including images, audio, video, and documents. Essential for OSINT and forensic file analysis.
exiftoolforemost
aptFile carving tool for recovering deleted or hidden files from disk images. Recovers files based on headers, footers, and internal data structures.
foremostpspy
manualMonitor Linux processes without root privileges. Sniffs process creations by watching /proc. Useful for detecting cron jobs, privilege escalation vectors, and scheduled tasks.
pspy (GitHub)stegcracker
pipSteganography brute-force tool for uncovering hidden data in image files. Supports steghide and other steganography tools.
stegcracker (GitHub)steghide
aptSteganography tool for hiding data in JPEG, BMP, WAV, and AU files. Password-protected embedding and extraction of secret messages.
steghidetcpdump
aptCommand-line network packet analyzer. Captures and analyzes network traffic. Essential for network forensics and protocol analysis.
tcpdumptshark
aptWireshark's command-line interface. Powerful PCAP analysis with protocol dissection, field extraction, and filtering. Scriptable alternative to Wireshark GUI.
tsharkangr
pipPython binary analysis framework. Symbolic execution, concolic testing, CFG recovery, and automated vulnerability discovery. Used for binary CTF challenges and security research.
angrcutter
manualFree and open-source GUI for radare2. Provides a visual interface for reverse engineering including disassembly view, decompiler (Ghidra plugin), graph view, and scripting.
cuttergdb
aptGNU Project Debugger. Full-featured debugger for C/C++, assembly, and other compiled languages. Core tool for dynamic binary analysis and exploit development.
gdbghidra
manualNSA's open-source reverse engineering framework. Disassembly, decompilation, scripting, and binary analysis for multiple architectures including x86, ARM, MIPS, and more.
ghidraltrace
aptLibrary call tracer. Intercepts and records dynamic library calls made by an executing process. Useful for reversing obfuscated binaries and understanding program behavior.
ltracepwndbg
makeGDB plugin for exploit development. Provides enhanced commands for heap analysis, ROP gadget search, memory visualization, and CTF/pwn challenge solving on top of GDB.
pwndbg (GitHub)radare2
makeOpen-source portable reverse engineering framework. Disassembly, debugging, hex editing, binary diffing, and scripting via r2pipe. Supports 40+ architectures.
radare2strace
aptSystem call tracer. Intercepts all system calls made by a process. Essential for understanding binary I/O behavior, file access, and privilege escalation analysis.
straceadb
aptAndroid Debug Bridge — command-line interface for communicating with Android devices. Essential for mobile pentest: install/pull APKs, logcat, shell access, port forwarding, and device management.
adbandroguard
pipPython tool for reverse engineering Android applications. APK parsing, DEX disassembly, control flow analysis, and taint analysis.
androguard (GitHub)apktool
aptAndroid APK reverse engineering tool. Decompiles APK resources to near-original form, rebuilds APKs, and handles resource decoding (resources.arsc, XML manifests).
apktoolfrida
pipDynamic instrumentation toolkit for Android, iOS, macOS, Windows, and Linux. Hook native functions, trace APIs, dump memory, bypass SSL pinning, and patch at runtime without source code.
fridajadx
manualDEX to Java decompiler. Produces Java source code from Android DEX and APK files. Includes a GUI (jadx-gui) for browsing decompiled code, searching strings, and cross-referencing.
jadx (GitHub)mobsf
git+pipMobile Security Framework — automated all-in-one mobile application security assessment tool. Static and dynamic analysis for Android APK/AAB and iOS IPA. REST API for CI/CD integration.
mobsfobjection
pipRuntime mobile exploration toolkit built on Frida. Automates common mobile pentest tasks: SSL pinning bypass, root/jailbreak detection bypass, memory dumping, file system exploration, and class intros
objection (GitHub)