GITEST

Tools

109 security tools integrated with GITEST

amass

go

In-depth attack surface mapping. OWASP tool for network asset discovery using OSINT and active techniques.

amass (GitHub)

assetfinder

go

Fast subdomain finder from Tomnomnom. Finds domains related to a target from various sources.

assetfinder (GitHub)

dnstwist

pip

Domain name permutation engine to detect typosquatting, phishing, and corporate espionage. Generates and checks variations of domain names.

dnstwist (GitHub)

gitleaks

go

SAST tool for detecting hardcoded secrets (API keys, passwords, tokens) in git repos. Fast and configurable with built-in and custom rules.

gitleaks (GitHub)

holehe

pip

Check if an email address is registered on 120+ online platforms including Twitter, Instagram, GitHub and more.

holehe (GitHub)

httpx

go

Fast and multi-purpose HTTP toolkit. Probes for alive hosts, tech stack, status codes, and more.

httpx (GitHub)

maigret

pip

Collect user information by username from 3000+ sites. Profiles social network footprint with detailed metadata extraction.

maigret (GitHub)

masscan

apt

Ultra-fast TCP port scanner. Scans the entire internet in under 6 minutes. Transmit-only design with custom TCP/IP stack for maximum speed.

masscan (GitHub)

massdns

make

High-performance DNS stub resolver. Resolves millions of domains per second for bulk operations.

massdns (GitHub)

naabu

go

Fast port scanner written in Go. Designed for reliability and speed with SYN/TCP/CONNECT scan modes.

naabu (GitHub)

prowler

pip

Security assessment tool for AWS, GCP, and Azure. Performs 300+ checks for CIS benchmarks, GDPR, HIPAA, and custom compliance frameworks.

prowler (GitHub)

rustscan

cargo

Modern port scanner written in Rust. Scans all 65k ports in 3 seconds then feeds results to nmap for service detection.

rustscan (GitHub)

scoutsuite

pip

Multi-cloud security auditing tool. Gathers data from AWS, GCP, Azure, Alibaba Cloud, and Oracle Cloud to identify misconfigurations and risks.

scoutsuite (GitHub)

secretfinder

git+pip

Python tool to discover sensitive data (API keys, tokens, passwords) in JavaScript files via regex patterns.

secretfinder (GitHub)

sherlock

pip

Hunt down social media accounts by username across 400+ platforms including Twitter, GitHub, Instagram, LinkedIn and more.

sherlock (GitHub)

spiderfoot

pip

Automated OSINT framework with 200+ modules. Correlates data from DNS, WHOIS, social media, threat intelligence, and more.

spiderfoot

subfinder

go

Passive subdomain discovery tool. Finds valid subdomains using online sources like crt.sh, SecurityTrails, and more.

subfinder (GitHub)

sublist3r

pip

Subdomain enumeration tool using search engines (Google, Bing, Yahoo, DNSDumpster, VirusTotal) and brute-force.

sublist3r (GitHub)

theHarvester

pip

OSINT tool for gathering emails, subdomains, hosts, employee names, open ports from public sources like search engines and DNS.

theHarvester (GitHub)

trufflehog

go

Find credentials and secrets in git repos, S3 buckets, and filesystems. Verifies secrets against APIs to eliminate false positives.

trufflehog (GitHub)

arjun

pip

HTTP parameter discovery suite. Finds hidden GET/POST parameters using wordlists and multi-threaded probing.

arjun (GitHub)

dirsearch

git+pip

Web path brute-force scanner. Python-based directory and file enumeration tool.

dirsearch (GitHub)

feroxbuster

curl

Fast, simple, recursive content discovery tool written in Rust.

feroxbuster (GitHub)

ffuf

go

Fast web fuzzer written in Go. Directory/file discovery, vhost discovery, and parameter fuzzing.

ffuf (GitHub)

gobuster

go

Directory/file, DNS, and vhost brute-forcing tool written in Go.

gobuster (GitHub)

gospider

go

Fast web spider for web application recon. Discovers URLs from sitemaps, JavaScript, robots.txt, forms, and external sources.

gospider (GitHub)

katana

go

Fast and configurable web crawler and spider from ProjectDiscovery. Supports headless mode, JS rendering, and scope control.

katana (GitHub)

mitmproxy

pip

Interactive man-in-the-middle HTTP/HTTPS proxy. Intercept, inspect, modify, and replay web traffic. Scriptable via Python addons.

mitmproxy

nmap

apt

Network exploration and security auditing utility. Port scanning, service detection, OS fingerprinting, and NSE scripts.

nmap

nuclei

go

Fast and customizable vulnerability scanner based on YAML templates. Community-driven template library.

nuclei (GitHub)

testssl

git

Free command-line tool to check SSL/TLS encryption. Tests ciphers, protocols, vulnerabilities (BEAST, POODLE, Heartbleed) and certificate issues.

testssl

trivy

apt

All-in-one security scanner for containers, filesystems, git repos, and cloud configs. Detects CVEs, misconfigurations, secrets, and generates SBOMs.

trivy (GitHub)

wafw00f

pip

Web Application Firewall detection tool. Identifies WAF products protecting a target.

wafw00f (GitHub)

whatweb

apt

Web technology fingerprinting tool. Identifies CMS, web servers, JavaScript frameworks, and more.

whatweb (GitHub)

airgeddon

git

Multi-use bash menu-driven wireless auditing framework. Handshake capture, evil twin attacks, PMKID attacks, and captive portal attacks in one script.

airgeddon (GitHub)

bettercap

apt

Swiss army knife for network attacks and monitoring. ARP spoofing, DNS spoofing, HTTP/HTTPS MITM, WiFi scanning, BLE scanning, and scriptable modules.

bettercap

bloodhound

pip+apt

Active Directory attack path mapping. Identifies privilege escalation paths and trust relationships.

bloodhound (GitHub)

burpsuite

manual

Web application security testing platform. Proxy, scanner, intruder, repeater, and more.

burpsuite

certipy

pip

Tool for enumerating and exploiting Active Directory Certificate Services (AD CS). Finds vulnerable certificate templates for privilege escalation.

certipy (GitHub)

chisel

go

Fast TCP/UDP tunnel over HTTP, secured with SSH. Enables port forwarding and SOCKS proxy through firewalls and restricted networks.

chisel (GitHub)

commix

git+pip

Automated OS command injection and exploitation tool.

commix (GitHub)

crackmapexec

pipx

Post-exploitation lateral movement tool. SMB, WinRM, MSSQL, and Active Directory enumeration.

crackmapexec (GitHub)

dalfox

go

Powerful open-source XSS scanner and exploitation tool. Parameter analysis, DOM XSS detection, blind XSS support, and custom payload injection.

dalfox (GitHub)

evil-winrm

gem

WinRM shell for pentesting Windows targets. Supports pass-the-hash, pass-the-ticket, Kerberos authentication, file upload/download, and PowerShell remoting.

evil-winrm (GitHub)

evilginx3

go

MITM attack framework for phishing credentials while bypassing 2FA. Proxies target website to capture session cookies.

evilginx3 (GitHub)

hashcat

apt

Advanced password recovery tool. GPU-accelerated hash cracking with support for 300+ hash types.

hashcat

havoc

make

Modern C2 framework with an advanced GUI and extensible shellcode loaders. Supports multiple agents and post-exploitation modules.

havoc (GitHub)

hcxdumptool

apt

Capture WiFi packets and PMKID hashes from WPA/WPA2 networks. Designed for offline WPA password cracking with hcxtools and hashcat.

hcxdumptool (GitHub)

hydra

apt

Fast and flexible online password brute-forcing tool. Supports numerous protocols.

hydra (GitHub)

impacket

pip

Network protocols implementation. SMB, Kerberos, MSRPC, WMI, DCE/RPC for lateral movement.

impacket (GitHub)

john

apt

John the Ripper password cracker. Supports many hash formats and attack modes.

john

kerbrute

go

Kerberos brute-force and user enumeration tool. Performs AS-REP roasting, password spraying, and user enumeration against Active Directory.

kerbrute (GitHub)

ligolo-ng

go

Advanced tunneling and pivoting tool using TUN interfaces. No SOCKS proxy needed — agents create real network interfaces for seamless pivoting.

ligolo-ng (GitHub)

metasploit

apt

Penetration testing framework. Exploit development, payload generation, post-exploitation, and pivoting.

metasploit

mythic

docker

Collaborative multi-user C2 framework with a web UI. Plugin-based architecture supporting multiple agents (Athena, Apollo, Merlin) and C2 profiles.

mythic (GitHub)

netexec

pip

Network execution tool — successor to CrackMapExec for SMB, WinRM, LDAP, MSSQL, SSH. Mass credential testing and lateral movement automation.

netexec (GitHub)

nikto

apt

Web server vulnerability scanner. Tests for dangerous files, outdated software, and server misconfigurations.

nikto

nosqlmap

git+pip

Automated NoSQL database exploitation tool. Tests for NoSQL injection vulnerabilities in MongoDB, Redis, CouchDB, and other NoSQL systems.

nosqlmap (GitHub)

owasp-zap

apt+pip

OWASP Zed Attack Proxy. Free, open-source web application security scanner.

owasp-zap

pacu

pip

AWS exploitation framework. Post-exploitation and persistence in AWS environments — privilege escalation, data exfiltration, and lateral movement.

pacu (GitHub)

peass-ng

curl

Privilege Escalation Awesome Scripts (LinPEAS/WinPEAS). Automated local privilege escalation enumeration for Linux, Windows, and macOS.

peass-ng (GitHub)

pwncat-cs

pip

Netcat replacement with persistence-focused post-exploitation. Handles shell stabilization, file upload/download, and automated enumeration on connection.

pwncat-cs (GitHub)

pwntools

pip

CTF exploitation framework. Python library for exploit development, binary exploitation, and crypto challenges.

pwntools

responder

apt

LLMNR/NBT-NS/mDNS poisoner. Captures NTLM hashes from network traffic.

responder (GitHub)

routersploit

git+pip

Exploitation framework for embedded devices and routers. Modules for exploiting CVEs in Cisco, Huawei, D-Link, TP-Link, and other network devices.

routersploit (GitHub)

setoolkit

git+pip

Social Engineering Toolkit. Comprehensive suite for social engineering attacks: spear-phishing, website cloning, credential harvesting, and payload delivery.

setoolkit (GitHub)

sliver

curl

Open-source cross-platform C2 framework by BishopFox. Generates implants, manages sessions, and supports MTLS/HTTP/DNS/WireGuard C2 channels.

sliver (GitHub)

slowloris

pip

Slow HTTP denial-of-service attack tool. Keeps many connections open to the target web server simultaneously by sending partial HTTP requests.

slowloris (GitHub)

sqlmap

apt

Automatic SQL injection and database takeover tool. Detects and exploits SQL injection flaws.

sqlmap

wifiphisher

apt

Automated WiFi phishing framework. Creates rogue access points with realistic captive portals to capture WPA credentials via social engineering.

wifiphisher (GitHub)

wifite

apt

Automated wireless auditing tool. Attacks WEP, WPA, WPA2, and WPS networks. Captures handshakes and cracks with built-in Hashcat/Aircrack-ng support.

wifite (GitHub)

xsstrike

git+pip

Advanced XSS detection suite with intelligent payload generation, context analysis, and WAF bypass capabilities.

xsstrike (GitHub)

anew

go

Append lines to a file only if they don't already exist. Perfect for deduplication in pipelines.

anew (GitHub)

autopsy

apt

Digital forensics platform. Disk image analysis, file recovery, timeline generation.

autopsy

cupp

pip

Common User Passwords Profiler. Generates targeted password lists based on personal information gathered through social engineering or OSINT.

cupp (GitHub)

curl

apt

Command-line tool for transferring data with URL syntax. Essential for HTTP testing and API interaction.

curl

grep

system

Pattern matching utility. Essential for filtering and searching output from security tools.

grep

haiti

gem

Hash type identifier. Detects hash algorithms from a given hash string and provides hashcat/john mode numbers.

haiti (GitHub)

jq

apt

Command-line JSON processor. Essential for parsing JSON output from security tools.

jq

notify

go

Send notifications to multiple platforms (Discord, Slack, Telegram, etc.) from pipelines.

notify (GitHub)

sort

system

Sort lines of text. Essential for organizing output from security tools.

sort

uniq

system

Remove duplicate adjacent lines. Usually used after sort for deduplication.

uniq

volatility

pip

Memory forensics framework. Analyzes RAM dumps for malware, artifacts, and incident response.

volatility (GitHub)

wireshark

apt

Network protocol analyzer. Deep packet inspection, traffic analysis, and protocol decoding.

wireshark

yara

apt

Pattern matching for malware detection. Signature-based malware identification.

yara (GitHub)

binwalk

apt

Firmware analysis and embedded file extraction. Identifies and extracts files from binary images including file systems, compression artifacts, and bootloaders.

binwalk (GitHub)

bulk_extractor

apt

Fast digital forensics tool that extracts features from disk images without parsing the file system. Extracts emails, URLs, credit cards, phone numbers, and more.

bulk_extractor (GitHub)

exiftool

apt

Metadata extraction from files including images, audio, video, and documents. Essential for OSINT and forensic file analysis.

exiftool

foremost

apt

File carving tool for recovering deleted or hidden files from disk images. Recovers files based on headers, footers, and internal data structures.

foremost

pspy

manual

Monitor Linux processes without root privileges. Sniffs process creations by watching /proc. Useful for detecting cron jobs, privilege escalation vectors, and scheduled tasks.

pspy (GitHub)

stegcracker

pip

Steganography brute-force tool for uncovering hidden data in image files. Supports steghide and other steganography tools.

stegcracker (GitHub)

steghide

apt

Steganography tool for hiding data in JPEG, BMP, WAV, and AU files. Password-protected embedding and extraction of secret messages.

steghide

tcpdump

apt

Command-line network packet analyzer. Captures and analyzes network traffic. Essential for network forensics and protocol analysis.

tcpdump

tshark

apt

Wireshark's command-line interface. Powerful PCAP analysis with protocol dissection, field extraction, and filtering. Scriptable alternative to Wireshark GUI.

tshark

angr

pip

Python binary analysis framework. Symbolic execution, concolic testing, CFG recovery, and automated vulnerability discovery. Used for binary CTF challenges and security research.

angr

cutter

manual

Free and open-source GUI for radare2. Provides a visual interface for reverse engineering including disassembly view, decompiler (Ghidra plugin), graph view, and scripting.

cutter

gdb

apt

GNU Project Debugger. Full-featured debugger for C/C++, assembly, and other compiled languages. Core tool for dynamic binary analysis and exploit development.

gdb

ghidra

manual

NSA's open-source reverse engineering framework. Disassembly, decompilation, scripting, and binary analysis for multiple architectures including x86, ARM, MIPS, and more.

ghidra

ltrace

apt

Library call tracer. Intercepts and records dynamic library calls made by an executing process. Useful for reversing obfuscated binaries and understanding program behavior.

ltrace

pwndbg

make

GDB plugin for exploit development. Provides enhanced commands for heap analysis, ROP gadget search, memory visualization, and CTF/pwn challenge solving on top of GDB.

pwndbg (GitHub)

radare2

make

Open-source portable reverse engineering framework. Disassembly, debugging, hex editing, binary diffing, and scripting via r2pipe. Supports 40+ architectures.

radare2

strace

apt

System call tracer. Intercepts all system calls made by a process. Essential for understanding binary I/O behavior, file access, and privilege escalation analysis.

strace

adb

apt

Android Debug Bridge — command-line interface for communicating with Android devices. Essential for mobile pentest: install/pull APKs, logcat, shell access, port forwarding, and device management.

adb

androguard

pip

Python tool for reverse engineering Android applications. APK parsing, DEX disassembly, control flow analysis, and taint analysis.

androguard (GitHub)

apktool

apt

Android APK reverse engineering tool. Decompiles APK resources to near-original form, rebuilds APKs, and handles resource decoding (resources.arsc, XML manifests).

apktool

frida

pip

Dynamic instrumentation toolkit for Android, iOS, macOS, Windows, and Linux. Hook native functions, trace APIs, dump memory, bypass SSL pinning, and patch at runtime without source code.

frida

jadx

manual

DEX to Java decompiler. Produces Java source code from Android DEX and APK files. Includes a GUI (jadx-gui) for browsing decompiled code, searching strings, and cross-referencing.

jadx (GitHub)

mobsf

git+pip

Mobile Security Framework — automated all-in-one mobile application security assessment tool. Static and dynamic analysis for Android APK/AAB and iOS IPA. REST API for CI/CD integration.

mobsf

objection

pip

Runtime mobile exploration toolkit built on Frida. Automates common mobile pentest tasks: SSL pinning bypass, root/jailbreak detection bypass, memory dumping, file system exploration, and class intros

objection (GitHub)