# Tool catalog Every tool hackingtool can install, launch, or point you at โ€” **215 active tools across 21 categories**, plus 59 archived entries kept out of this list (they are unmaintained or dead upstream and are hidden in the app unless you set `show_archived true` via `/config`). Tags under each entry come from the fixed taxonomy in `src/hackingtool/tags.py` (63 tags in use). Inside the app you can filter by any of them with `@tag:`, or search names/descriptions/tags with `/search `. Entries marked as a link point at the upstream project; a few are curated reference resources (labs, cheat sheets, online services) rather than installable binaries โ€” hackingtool opens those instead of installing them. > **Authorized targets only.** Every tool here is for systems you own or have > written permission to test. Back to the [README](../README.md) ยท [How to use hackingtool](HOW-TO-USE.md) --- ## ๐Ÿ›ก Anonymously Hiding Tools - [Anonymously Surf](https://github.com/Und3rf10w/kali-anonsurf) โ€” anonymity, tunneling, network - [Multitor](https://github.com/trimstray/multitor) โ€” anonymity, tunneling, network - [Tor + torsocks (SOCKS anonymity proxy)](https://gitlab.torproject.org/tpo/core/torsocks) โ€” anonymity, tunneling, network - [proxychains-ng (chain traffic through proxies/Tor)](https://github.com/rofl0r/proxychains-ng) โ€” anonymity, tunneling, network - [Whonix โ€” Anonymity & Tor OpSec (docs)](https://www.whonix.org/wiki/Documentation) โ€” anonymity, reference, learning ## ๐Ÿ” Information gathering tools - [Network Map (nmap)](https://github.com/nmap/nmap) โ€” scanner, port-scan, recon, network - Port scanning โ€” port-scan, scanner, network - Host to IP โ€” recon, dns, lookup - [RED HAWK (All In One Scanning)](https://github.com/Tuhinshubhra/RED_HAWK) โ€” web, recon, scanner, fingerprint - [ReconSpider(For All Scanning)](https://github.com/bhavsec/reconspider) โ€” osint, recon, crawler - IsItDown (Check Website Down/Up) โ€” recon, online-service, web - [SecretFinder (like API & etc)](https://github.com/m4ll0k/SecretFinder) โ€” web, recon, credentials, git-secrets - [Port Scanner - rang3r](https://github.com/floriankunushevci/rang3r) โ€” port-scan, scanner, network - [Breacher](https://github.com/s0md3v/Breacher) โ€” web, recon, enumeration - [theHarvester (OSINT)](https://github.com/laramies/theHarvester) โ€” osint, email, subdomain-enum, recon - [Amass (Attack Surface Mapping)](https://github.com/owasp-amass/amass) โ€” subdomain-enum, recon, osint, dns - [Masscan (Fast Port Scanner)](https://github.com/robertdavidgraham/masscan) โ€” port-scan, scanner, network - [RustScan (Modern Port Scanner)](https://github.com/RustScan/RustScan) โ€” port-scan, scanner, network - [Holehe (Email โ†’ Social Accounts)](https://github.com/megadose/holehe) โ€” osint, email, recon, lookup - [Maigret (Username OSINT)](https://github.com/soxoj/maigret) โ€” osint, recon, lookup - [httpx (HTTP Toolkit)](https://github.com/projectdiscovery/httpx) โ€” web, recon, scanner, fingerprint - [SpiderFoot (OSINT Automation)](https://github.com/smicallef/spiderfoot) โ€” osint, recon, subdomain-enum - [Subfinder (Subdomain Enumeration)](https://github.com/projectdiscovery/subfinder) โ€” subdomain-enum, recon, osint, dns - [TruffleHog (Secret Scanner)](https://github.com/trufflesecurity/trufflehog) โ€” git-secrets, credentials, recon - [Gitleaks (Git Secret Scanner)](https://github.com/gitleaks/gitleaks) โ€” git-secrets, credentials, reporting - [naabu (fast port scanner)](https://github.com/projectdiscovery/naabu) โ€” port-scan, recon, network - [dnsx (DNS toolkit)](https://github.com/projectdiscovery/dnsx) โ€” dns, recon, enumeration - [reconFTW (Automated Recon)](https://github.com/six2dez/reconftw) โ€” recon, osint, subdomain-enum, scanner, dns - [gowitness (Web Screenshots)](https://github.com/sensepost/gowitness) โ€” web, recon, fingerprint, reporting - [EyeWitness (Web Screenshots + Headers)](https://github.com/RedSiege/EyeWitness) โ€” web, recon, fingerprint, reporting - [Sn1per (Attack Surface Scanner)](https://github.com/1N3/Sn1per) โ€” scanner, recon, vuln-scan, enumeration, web ## ๐Ÿ“š Wordlist Generator - [Cupp](https://github.com/Mebus/cupp) โ€” wordlist, password-attack, credentials, osint - [Hashcat (Password Cracker)](https://github.com/hashcat/hashcat) โ€” hash-crack, password-attack, credentials - [John the Ripper](https://github.com/openwall/john) โ€” hash-crack, password-attack, credentials - [haiti (Hash Type Identifier)](https://github.com/noraj/haiti) โ€” hash-crack, lookup, reference - [crunch (Wordlist Generator)](https://sourceforge.net/projects/crunch-wordlist/) โ€” wordlist, bruteforce, password-attack - [CeWL (Custom Word List)](https://github.com/digininja/CeWL) โ€” wordlist, osint, recon, credentials - [SecLists (Wordlist Collection)](https://github.com/danielmiessler/SecLists) โ€” wordlist, reference, bruteforce - [Kali wordlists package (rockyou etc.)](https://gitlab.com/kalilinux/packages/wordlists) โ€” wordlist, reference, password-attack ## ๐Ÿ“ก Wireless attack tools - [WiFi-Pumpkin](https://github.com/P0cL4bs/wifipumpkin3) โ€” wireless, mitm, phishing, credentials - [pixiewps](https://github.com/wiire/pixiewps) โ€” wireless, bruteforce, password-attack - [Bluetooth Honeypot GUI Framework](https://github.com/andrewmichaelsmith/bluepot) โ€” wireless, sniffing - [Fluxion](https://github.com/FluxionNetwork/fluxion) โ€” wireless, phishing, social-engineering, credentials - [Wifiphisher](https://github.com/wifiphisher/wifiphisher) โ€” wireless, phishing, social-engineering, mitm - [Wifite](https://github.com/derv82/wifite2) โ€” wireless, password-attack, bruteforce, credentials - Howmanypeople โ€” wireless, sniffing, recon - [Airgeddon (Wireless Attack Suite)](https://github.com/v1s1t0r1sh3r3/airgeddon) โ€” wireless, password-attack, mitm, credentials - [hcxdumptool (PMKID Capture)](https://github.com/ZerBea/hcxdumptool) โ€” wireless, sniffing, pcap, credentials - [hcxtools (PMKID/Hash Conversion)](https://github.com/ZerBea/hcxtools) โ€” wireless, hash-crack, pcap, credentials - [Bettercap (Network/WiFi/BLE MITM)](https://github.com/bettercap/bettercap) โ€” wireless, mitm, sniffing, network - [aircrack-ng (WiFi security suite)](https://github.com/aircrack-ng/aircrack-ng) โ€” wireless, password-attack, bruteforce, sniffing - [Kismet (wireless detector / WIDS)](https://github.com/kismetwireless/kismet) โ€” wireless, sniffing, recon, network - [Reaver (WPS PIN attack)](https://github.com/t6x/reaver-wps-fork-t6x) โ€” wireless, bruteforce, password-attack, credentials - [WiGLE (wardriving map & API)](https://wigle.net/) โ€” wireless, osint, online-service, lookup - [hashcat example hashes (WPA mode 22000)](https://hashcat.net/wiki/doku.php?id=example_hashes) โ€” wireless, hash-crack, reference - [Aircrack-ng: cracking WPA (tutorial)](https://www.aircrack-ng.org/doku.php?id=cracking_wpa) โ€” wireless, learning, reference ## ๐Ÿ’‰ SQL Injection Tools - [Sqlmap tool](https://github.com/sqlmapproject/sqlmap) โ€” web, sql-injection, exploitation, scanner - [NoSqlMap](https://github.com/codingo/NoSQLMap) โ€” web, sql-injection, exploitation - [Damn Small SQLi Scanner](https://github.com/stamparm/DSSS) โ€” web, sql-injection, scanner - [SQLScan](https://github.com/Cvar1984/sqlscan) โ€” web, sql-injection, scanner - [Ghauri (Modern SQLi Tool)](https://github.com/r0oth3x49/ghauri) โ€” web, sql-injection, exploitation, scanner - [PortSwigger โ€” SQL Injection Labs](https://portswigger.net/web-security/sql-injection) โ€” learning, web, sql-injection, reference - [PayloadsAllTheThings โ€” SQL Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/SQL%20Injection) โ€” cheatsheet, reference, sql-injection, web ## ๐ŸŽฃ Phishing attack tools - [AdvPhishing](https://github.com/Ignitetch/AdvPhishing) โ€” phishing, social-engineering, credentials - [Setoolkit](https://github.com/trustedsec/social-engineer-toolkit) โ€” social-engineering, phishing, credentials - [SocialFish](https://github.com/UndeadSec/SocialFish) โ€” phishing, credentials, web - [HiddenEye](https://github.com/Morsmalleo/HiddenEye) โ€” phishing, credentials, social-engineering - [Evilginx3](https://github.com/kgretzky/evilginx2) โ€” phishing, mitm, credentials, web - [SayCheese](https://github.com/hangetzzu/saycheese) โ€” social-engineering, phishing - [QR Code Jacking](https://github.com/cryptedwolf/ohmyqr) โ€” phishing, social-engineering - [QRLJacking](https://github.com/OWASP/QRLJacking) โ€” phishing, social-engineering, credentials - [Maskphish](https://github.com/jaykali/maskphish) โ€” phishing, social-engineering - [dnstwist](https://github.com/elceef/dnstwist) โ€” osint, dns, phishing - [GoPhish (Phishing Simulation)](https://getgophish.com/) โ€” phishing, social-engineering, email, credentials, web - [GoPhish Documentation](https://docs.getgophish.com/) โ€” phishing, reference, learning - [MITRE ATT&CK โ€” Phishing (T1566)](https://attack.mitre.org/techniques/T1566/) โ€” phishing, social-engineering, reference ## ๐ŸŒ Web Attack tools - Skipfish โ€” web, vuln-scan, scanner, crawler - [SubDomain Finder](https://github.com/aboul3la/Sublist3r) โ€” subdomain-enum, recon, osint, dns - [Sub-Domain TakeOver](https://github.com/edoardottt/takeover) โ€” subdomain-enum, web, vuln-scan - [Dirb](https://gitlab.com/kalilinux/packages/dirb) โ€” web, enumeration, bruteforce, wordlist - [Nuclei (Vulnerability Scanner)](https://github.com/projectdiscovery/nuclei) โ€” web, vuln-scan, scanner - [ffuf (Web Fuzzer)](https://github.com/ffuf/ffuf) โ€” web, fuzzing, enumeration, wordlist - [Feroxbuster (Directory Brute Force)](https://github.com/epi052/feroxbuster) โ€” web, enumeration, bruteforce, wordlist - [Nikto (Web Server Scanner)](https://github.com/sullo/nikto) โ€” web, vuln-scan, scanner - [wafw00f (WAF Detector)](https://github.com/EnableSecurity/wafw00f) โ€” web, fingerprint, recon - [Katana (Web Crawler)](https://github.com/projectdiscovery/katana) โ€” web, crawler, recon, enumeration - [Gobuster (Dir/DNS/Vhost Brute Force)](https://github.com/OJ/gobuster) โ€” web, enumeration, bruteforce, dns, wordlist - [Dirsearch (Web Path Discovery)](https://github.com/maurosoria/dirsearch) โ€” web, enumeration, bruteforce, wordlist - [OWASP ZAP (Web App Scanner)](https://github.com/zaproxy/zaproxy) โ€” web, vuln-scan, scanner, fuzzing - [testssl.sh (TLS/SSL Checker)](https://github.com/drwetter/testssl.sh) โ€” web, scanner, fingerprint - [Arjun (HTTP Parameter Discovery)](https://github.com/s0md3v/Arjun) โ€” web, fuzzing, enumeration - [Caido (Web Security Auditing)](https://github.com/caido/caido) โ€” web, scanner, crawler - [mitmproxy (Intercepting Proxy)](https://github.com/mitmproxy/mitmproxy) โ€” web, mitm, sniffing - [WhatWeb (Web Fingerprinter)](https://github.com/urbanadventurer/WhatWeb) โ€” web, fingerprint, recon, scanner - [WPScan (WordPress Scanner)](https://github.com/wpscanteam/wpscan) โ€” web, vuln-scan, scanner, enumeration - [PortSwigger Web Security Academy](https://portswigger.net/web-security) โ€” learning, web, reference - [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) โ€” cheatsheet, reference, payload, web - [HackTricks](https://book.hacktricks.xyz/) โ€” cheatsheet, reference, web, privesc - [revshells.com (Reverse Shell Generator)](https://www.revshells.com/) โ€” reverse-shell, cheatsheet, online-service, web ## ๐Ÿ”ง Post exploitation tools - [pwncat-cs (Reverse Shell Handler)](https://github.com/calebstewart/pwncat) โ€” post-exploitation, reverse-shell, persistence, privesc - [Sliver (C2 Framework)](https://github.com/BishopFox/sliver) โ€” c2, post-exploitation, payload - [PEASS-ng โ€” LinPEAS/WinPEAS (Priv Esc)](https://github.com/peass-ng/PEASS-ng) โ€” privesc, post-exploitation, enumeration - [Ligolo-ng (Tunneling/Pivoting)](https://github.com/nicocha30/ligolo-ng) โ€” tunneling, lateral-movement, post-exploitation, network - [Chisel (HTTP Tunnel)](https://github.com/jpillora/chisel) โ€” tunneling, lateral-movement, post-exploitation, network - [Evil-WinRM (Windows Remote Shell)](https://github.com/Hackplayers/evil-winrm) โ€” lateral-movement, credentials, post-exploitation, active-directory - [Mythic (C2 Platform)](https://github.com/its-a-feature/Mythic) โ€” c2, post-exploitation, lateral-movement - [pspy (unprivileged process snooping)](https://github.com/DominicBreuker/pspy) โ€” post-exploitation, privesc, enumeration - [linux-smart-enumeration (lse.sh)](https://github.com/diego-treitos/linux-smart-enumeration) โ€” privesc, post-exploitation, enumeration - [LaZagne (Local Credential Recovery)](https://github.com/AlessandroZ/LaZagne) โ€” credentials, post-exploitation, password-attack - [HackTricks (post-ex / privesc playbook)](https://book.hacktricks.xyz/) โ€” post-exploitation, privesc, reference, cheatsheet - [LOLBAS (Windows living-off-the-land binaries)](https://lolbas-project.github.io/) โ€” privesc, post-exploitation, reference, cheatsheet - [revshells.com (reverse shell generator)](https://www.revshells.com/) โ€” reverse-shell, post-exploitation, online-service, reference - [PayloadsAllTheThings (payload + technique cheatsheets)](https://github.com/swisskyrepo/PayloadsAllTheThings) โ€” payload, post-exploitation, reference, cheatsheet - [mimikatz (Windows credential dumping โ€” reference)](https://github.com/gentilkiwi/mimikatz) โ€” credentials, post-exploitation, active-directory, reference ## ๐Ÿ•ต Forensic tools - Autopsy โ€” forensics, metadata - Wireshark โ€” network, forensics, sniffing, pcap - [Bulk extractor](https://github.com/simsong/bulk_extractor) โ€” forensics, memory-dump, metadata - [Disk Clone and ISO Image Acquire](https://guymager.sourceforge.io/) โ€” forensics, binary - [Toolsley](https://www.toolsley.com/) โ€” reference, online-service, forensics - [Volatility 3 (Memory Forensics)](https://github.com/volatilityfoundation/volatility3) โ€” forensics, memory-dump, malware-analysis - [Binwalk (Firmware Analysis)](https://github.com/ReFirmLabs/binwalk) โ€” forensics, binary, reversing - [pspy (Process Monitor โ€” No Root)](https://github.com/DominicBreuker/pspy) โ€” forensics, post-exploitation, enumeration - [ExifTool (Metadata)](https://exiftool.org/) โ€” forensics, metadata, image, document - [Foremost (File Carving)](http://foremost.sourceforge.net/) โ€” forensics, binary - [Eric Zimmerman's Tools](https://ericzimmerman.github.io/) โ€” reference, forensics, online-service - [MalwareBazaar (Sample Database)](https://bazaar.abuse.ch/) โ€” online-service, reference, malware-analysis ## ๐Ÿ“ฆ Payload creation tools - [The FatRat](https://github.com/Screetsec/TheFatRat) โ€” payload, reverse-shell, apk, c2 - [Stitch](https://nathanlopez.github.io/Stitch) โ€” payload, c2, reverse-shell, persistence - [Venom Shellcode Generator](https://github.com/r00t-3xp10it/venom) โ€” payload, reverse-shell, c2 - [Mob-Droid](https://github.com/kinghacker0/Mob-Droid) โ€” payload, mobile, apk, reverse-shell - [msfvenom (Payload Generator)](https://github.com/rapid7/metasploit-framework) โ€” payload, reverse-shell, c2, apk - [LOLBAS (Living Off The Land Binaries)](https://lolbas-project.github.io/) โ€” reference, payload, post-exploitation ## ๐Ÿงฐ Exploit framework - [RouterSploit](https://github.com/threat9/routersploit) โ€” network, iot, exploitation, scanner - [Commix](https://github.com/commixproject/commix) โ€” web, exploitation, payload - [Metasploit Framework](https://github.com/rapid7/metasploit-framework) โ€” exploitation, post-exploitation, payload, c2, scanner - [SearchSploit (Exploit-DB CLI)](https://gitlab.com/exploit-database/exploitdb) โ€” exploitation, recon, reference - [Exploit-DB (Online Archive)](https://www.exploit-db.com/) โ€” online-service, reference, exploitation - [Metasploit Unleashed (Free Course)](https://www.offsec.com/metasploit-unleashed/) โ€” learning, reference, exploitation ## ๐Ÿ” Reverse engineering tools - [Androguard](https://github.com/androguard/androguard) โ€” reversing, apk, mobile, malware-analysis - [Apk2Gold](https://github.com/lxdvs/apk2gold) โ€” reversing, apk, mobile - [JadX](https://github.com/skylot/jadx) โ€” reversing, apk, mobile - [Ghidra (NSA Reverse Engineering)](https://github.com/NationalSecurityAgency/ghidra) โ€” reversing, binary, malware-analysis - [Radare2 (RE Framework)](https://github.com/radareorg/radare2) โ€” reversing, binary - [apktool (APK Decode/Rebuild)](https://apktool.org/) โ€” reversing, apk, mobile - [GDB (GNU Debugger)](https://www.sourceware.org/gdb/) โ€” reversing, binary - [binutils (strings / objdump / readelf)](https://www.gnu.org/software/binutils/) โ€” reversing, binary - [crackmes.one (RE Practice)](https://crackmes.one/) โ€” reference, learning, reversing - [Malware Unicorn RE101 (Workshop)](https://malwareunicorn.org/workshops/re101.html) โ€” reference, learning, reversing, malware-analysis ## โšก DDOS Attack Tools - [DDoS](https://github.com/the-deepnet/ddos) โ€” ddos, network, web - SlowLoris โ€” ddos, web - [UFOnet](https://github.com/epsylon/ufonet) โ€” ddos, web, network - [SaphyraDDoS](https://github.com/anonymous24x7/Saphyra-DDoS) โ€” ddos, web - [hping3 (Packet Crafter / Flooder)](https://github.com/antirez/hping) โ€” ddos, network - [slowhttptest (Slow-HTTP DoS Tester)](https://github.com/shekyan/slowhttptest) โ€” ddos, web - [OWASP Denial of Service Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Denial_of_Service_Cheat_Sheet.html) โ€” ddos, web, reference ## ๐Ÿ–ฅ Remote Administrator Tools (RAT) - [Villain (Reverse Shell / C2 Manager)](https://github.com/t3l3machus/Villain) โ€” c2, reverse-shell, post-exploitation, payload - [hoaxshell (HTTP(S) PowerShell Reverse Shell)](https://github.com/t3l3machus/hoaxshell) โ€” reverse-shell, c2, payload, post-exploitation - [Merlin (cross-platform C2)](https://github.com/Ne0nd0g/merlin) โ€” c2, post-exploitation, reference - [Covenant (.NET C2)](https://github.com/cobbr/Covenant) โ€” c2, post-exploitation, reference ## ๐Ÿงช XSS Attack Tools - [DalFox (Finder of XSS)](https://github.com/hahwul/dalfox) โ€” web, xss, scanner, fuzzing - [XSS Payload Generator](https://github.com/capture0x/XSS-LOADER.git) โ€” web, xss, payload - [Advanced XSS Detection Suite](https://github.com/UltimateHackers/XSStrike) โ€” web, xss, scanner, fuzzing - [kxss (Reflection Finder)](https://github.com/Emoe/kxss) โ€” web, xss, scanner, recon - [PortSwigger โ€” XSS Labs](https://portswigger.net/web-security/cross-site-scripting) โ€” learning, web, xss, reference - [PayloadsAllTheThings โ€” XSS Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XSS%20Injection) โ€” cheatsheet, reference, xss, web ## ๐Ÿ–ผ Steganography Tools - SteganoHide โ€” steganography, image, forensics - [Stegseek (fast steganography cracker)](https://github.com/RickdeJager/stegseek) โ€” steganography, hash-crack, bruteforce - [stegseek (fast steghide cracker)](https://github.com/RickdeJager/stegseek) โ€” steganography, bruteforce, password-attack, image - [zsteg (PNG/BMP LSB detector)](https://github.com/zed-0xff/zsteg) โ€” steganography, image, forensics - [outguess (JPEG stego)](https://github.com/resurrecting-open-source-projects/outguess) โ€” steganography, image, forensics - [ExifTool (metadata reader)](https://exiftool.org/) โ€” steganography, metadata, image, forensics - [Aperi'Solve (all-in-one image stego)](https://www.aperisolve.com/) โ€” steganography, image, online-service, reference - [StegOnline (in-browser LSB explorer)](https://georgeom.net/StegOnline/upload) โ€” steganography, image, online-service - [Futureboy Stegano decoder](https://futureboy.us/stegano/decinput.html) โ€” steganography, online-service, reference - [stego-toolkit (Docker kit + checklist)](https://github.com/DominicBreuker/stego-toolkit) โ€” steganography, reference, cheatsheet ## ๐Ÿข Active Directory Tools - [BloodHound (AD Attack Paths)](https://github.com/BloodHoundAD/BloodHound) โ€” active-directory, enumeration, lateral-movement, credentials - [NetExec โ€” nxc (Network Pentesting)](https://github.com/Pennyw0rth/NetExec) โ€” active-directory, network, enumeration, credentials, password-attack - [Impacket (Network Protocol Tools)](https://github.com/fortra/impacket) โ€” active-directory, credentials, network, lateral-movement, kerberos - [Responder (LLMNR/NBT-NS Poisoner)](https://github.com/lgandx/Responder) โ€” active-directory, credentials, mitm, sniffing, network, poisoning, relay - [Certipy (AD Certificate Abuse)](https://github.com/ly4k/Certipy) โ€” active-directory, credentials, privesc, enumeration, adcs - [Kerbrute (Kerberos Brute Force)](https://github.com/ropnop/kerbrute) โ€” active-directory, bruteforce, password-attack, enumeration, credentials, kerberos - [ldapdomaindump (AD LDAP Dumper)](https://github.com/dirkjanm/ldapdomaindump) โ€” active-directory, enumeration, credentials - [Coercer (Authentication Coercion)](https://github.com/p0dalirius/Coercer) โ€” active-directory, relay, privesc, credentials - [PCredz (Credential Extractor)](https://github.com/lgandx/PCredz) โ€” active-directory, credentials, sniffing, pcap, kerberos - [The Hacker Recipes (AD)](https://www.thehacker.recipes/) โ€” reference, active-directory, learning ## โ˜ Cloud Security Tools - [Prowler (Cloud Security Scanner)](https://github.com/prowler-cloud/prowler) โ€” cloud, scanner, vuln-scan - [ScoutSuite (Multi-Cloud Auditing)](https://github.com/nccgroup/ScoutSuite) โ€” cloud, scanner, enumeration - [Pacu (AWS Exploitation Framework)](https://github.com/RhinoSecurityLabs/pacu) โ€” cloud, exploitation, post-exploitation - [Trivy (Container/K8s Scanner)](https://github.com/aquasecurity/trivy) โ€” scanner, vuln-scan, cloud - [Checkov (IaC Misconfig Scanner)](https://github.com/bridgecrewio/checkov) โ€” cloud, scanner, vuln-scan - [HackTricks Cloud (cloud pentest playbook)](https://cloud.hacktricks.xyz/) โ€” reference, cloud, learning - [flaws.cloud (AWS Security Challenge)](http://flaws.cloud/) โ€” learning, cloud, online-service ## ๐Ÿ“ฑ Mobile Security Tools - [MobSF (Mobile Security Framework)](https://github.com/MobSF/Mobile-Security-Framework-MobSF) โ€” mobile, apk, vuln-scan, scanner, malware-analysis - [Frida (Dynamic Instrumentation)](https://github.com/frida/frida) โ€” mobile, reversing, malware-analysis - [Objection (Mobile Runtime Exploration)](https://github.com/sensepost/objection) โ€” mobile, reversing - [adb (Android Debug Bridge)](https://developer.android.com/tools/adb) โ€” mobile, apk - [OWASP MAS (Mobile App Security)](https://mas.owasp.org/) โ€” mobile, reference, learning - [Frida CodeShare](https://codeshare.frida.re/) โ€” mobile, reversing, online-service, reference ## โœจ Other tools - [MySMS](https://github.com/papusingh2sms/mysms) โ€” payload, mobile, apk - [HatCloud(Bypass CloudFlare for IP)](https://github.com/HatBashBR/HatCloud) โ€” recon, network, dns - [Hash Buster](https://github.com/s0md3v/Hash-Buster) โ€” hash-crack, lookup, online-service, credentials - [Sherlock](https://github.com/sherlock-project/sherlock) โ€” osint, recon, enumeration - [SocialScan | Username or Email](https://github.com/iojw/socialscan) โ€” osint, recon, email, enumeration - [Pixload](https://github.com/chinarulezzz/pixload) โ€” payload, steganography, image - [Gospider](https://github.com/jaeles-project/gospider) โ€” web, crawler, recon - Terminal Multiplexer โ€” cheatsheet, reference - [Crivo](https://github.com/GMDSantana/crivo) โ€” network, recon - [CyberChef (Cyber Swiss-Army Knife)](https://gchq.github.io/CyberChef/) โ€” reference, online-service ## ๐Ÿ”‘ Password / Hash Cracking - [hashcat (GPU hash cracker)](https://github.com/hashcat/hashcat) โ€” hash-crack, password-attack, bruteforce - [John the Ripper (jumbo)](https://github.com/openwall/john) โ€” hash-crack, password-attack - [hydra (Network Login Cracker)](https://github.com/vanhauser-thc/thc-hydra) โ€” bruteforce, password-attack, credentials, network - [CrackStation (online lookup)](https://crackstation.net/) โ€” hash-crack, online-service, lookup - [hashes.com (hash identifier + lookup)](https://hashes.com/en/tools/hash_identifier) โ€” hash-crack, online-service, lookup - [CyberChef (the cyber swiss-army knife)](https://gchq.github.io/CyberChef/) โ€” online-service, reference - [GTFOBins (unix binary abuse)](https://gtfobins.github.io/) โ€” privesc, reference, cheatsheet --- ## Adding a tool Most tools are **one YAML entry** in `src/hackingtool/catalog/` โ€” no Python. See [CONTRIBUTING.md](../CONTRIBUTING.md) for the entry format, the tag taxonomy, and the checks your PR has to pass (`make check`). Can't find what you need? Ask the console: `/find ` searches the catalog first, then GitHub, and shows real maintained repos with the reason each was ranked. See [HOW-TO-USE.md](HOW-TO-USE.md#4-find-a-tool-that-isnt-in-the-catalog-find).