L00king for a tool / link / command? Find it here ... by {THUGS}

Tool name Tags Description

Bettercap

Framework to perform MITM (Man in the Middle) attacks

LINK

Yersinia

Attack various protocols on layer 2

LINK

Featherduster

For breaking crypto; It tries to make the process of identifying and exploiting weak cryptosystems as easy as possible

LINK

CrackStation

Crack known hashes LM, NTLM, md2, md4, md5, md5(md5_hex), md5-half, sha1, sha224, sha256, sha384, sha512, ripeMD160, whirlpool, MySQL 4.1+

LINK

Hashes.com

Decrypt MD5, SHA1, MySQL, NTLM, SHA256, SHA512 hashes

LINK

Hash_extender

Hash length extension attack

LINK

PkCrack

Breaking PkZip-encryption ciphers

LINK

RsaCtfTool

RSA multi attacks tool : uncipher data from weak public key and try to recover private key

LINK

Rsatool

Calculates RSA (p, q, n, d, e) and RSA-CRT (dP, dQ, qInv) parameters given either two primes (p, q) or modulus and private exponent (n, d)

LINK

Hashcat

World’s fastest and most advanced password recovery tool. CPU/GPU brute forcing

LINK

Metasploit

World’s most used penetration testing framework

LINK

Pwntools

CTF framework and exploit development library. Written in Python

LINK

Aircrack-ng

Complete suite to assess WiFi network security (replay attacks, deauth, fakeap and packet injection etc) Cracking: WEP and WPA PSK (WPA 1 and 2)

LINK

Commix

Commix (short for [comm]and [i]njection e[x]ploiter) is an open source penetration testing tool

LINK

Sqlmap

Open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws

LINK

W3af

Web application security scanner which helps developers and penetration testers identify and exploit vulnerabilities in their web applications

LINK

XSSer

Cross Site Scripter (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications

LINK

Reverse Shell

Payloads All The Things- Reverse Shell Cheatsheet

LINK

Reverse Shell #2

d4t4s3c - Reverse Shell Cheat Sheet

LINK

Hydra

Parallelized login cracker which supports numerous protocols to attack

LINK

Searchsploit

Command line search tool for Exploit-DB that also allows you to take a copy of Exploit Database with you, everywhere you go

LINK

Wordpress brute #1

hydra -V -l <wordlist> -p 123 <ip_host> http-post-form '/wp-login.php:log=^USER^&pwd=^PASS^&wp-submit=Log+In:F=Invalid Username'

Dirtycow

Dirty COW (CVE-2016-5195) is a privilege escalation vulnerability in the Linux Kernel (Old exploit) 2.6.22 and below

LINK

Reconnoitre

A reconnaissance tool made for the OSCP labs to automate information gathering and service enumeration whilst creating a directory structure to store results, findings and exploits used for each host

LINK

DefaultCreds

One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password

LINK

Cross-Site Scripting

Cross-Site Scripting (XSS) - Good cheat sheet over many options

LINK

SQL Injections

Somewhat good SQL injections cheatsheet

LINK

Default-passwords 2

Default Passwords cheatsheet by CIRT

LINK

Default-passwords 1

List of default passwords for many vendors. Always use multiple sites to gather default passwords.

LINK

CMSmap

Python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs

LINK

Recon-ct

CTRECON - Certificate Transparency Reconnaissance

LINK

Recon-ntoo

NTOORECON - Number To Operator Reconnaissance

LINK

Recon

Small little RCON suite by me!

LINK

Beef

The Browser Exploitation Framework Project

LINK

Ettercap

Ettercap is a comprehensive suite for man in the middle attacks

LINK

Wifiphisher

Wifiphisher is a rogue Access Point framework for conducting red team engagements or Wi-Fi security testing

LINK

Rootend

A *nix Enumerator & Auto Privilege Escalation tool

LINK

Dns-black-cat

Multi platform toolkit for an interactive DNS shell commands exfiltration

LINK

LinEnum

Best scripted local Linux enumeration & privilege escalation checks

LINK

CiLocks

Crack Interface lockscreen, Metasploit and More Android/IOS Hacking

LINK

Red-kube

Red Kube is a collection of kubectl commands written to evaluate the security posture of Kubernetes clusters from the attacker's perspective

LINK

Wpscan

WordPress security scanner. Written for security professionals and blog maintainers to test the security of their Wordpress

LINK

Skipfish

Web application security scanner created by lcamtuf for google

LINK

King-phisher

Phishing Campaign Toolkit

LINK

Truecrack

TrueCrack is a brute-force password cracker for TrueCrypt (Copyrigth) volumes (GPU support)

LINK

Exploit-db

Exploit Database is a CVE compliant archive of public exploits and corresponding vulnerable software

LINK

Dsniff

Dsniff is a collection of tools for network auditing and penetration testing

LINK

Kismet

Kismet is a wireless network and device detector, sniffer, wardriving tool, and WIDS (wireless intrusion detection) framework

LINK

Gps-sdr-sim

Software-Defined GPS Signal Simulator

LINK

Hackingtool

ALL IN ONE Hacking Tool For Hackers (It's okay and works but i would use it just a yey an option for a tool)

LINK

Nessus Essentials

Vulnerability assessment solution for security practitioners. Scan, detect, report, fix exploits, EOL, Risks etc. Utilizing over 65000 CVEs in it's scans. Free version allow 16 ip's to be scanned as much as you want every 90 days.

LINK

Pupy

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python

LINK