/PentestingTools

This repository contains a collection of tools designed for automating penetration testing, while also being valuable for manual testing. Leveraging these tools can enhance both the efficiency and effectiveness of your security assessments.

MIT LicenseMIT

GitHub stars GitHub forks GitHub issues GitHub license

Advance Penetration Testing Tools

Welcome to the Advance Penetration Testing Tools repository. This comprehensive collection of tools is designed to enhance both automated and manual penetration testing. These tools cover a wide range of tasks, from subdomain enumeration and vulnerability scanning to web crawling and visual reconnaissance.

Tools

General Tools

VPS-Bug-Bounty-Tools

For a comprehensive installation script and toolset, visit the VPS-Bug-Bounty-Tools GitHub page.

Installation Instructions

cd /tmp && git clone https://github.com/drak3hft7/VPS-Bug-Bounty-Tools
cd VPS-Bug-Bounty-Tools
sudo ./Tools-BugBounty-installer.sh

Example Installation

Installation Example

Tool Categories

  • Network Scanners:

    • Nmap - Network scanner.
    • Masscan - High-speed port scanner.
    • Naabu - Port scanning tool.
  • Subdomain Enumeration and DNS Resolver:

  • Subdomain Takeovers:

    • SubOver - Subdomain takeover tool.
  • Web Fuzzers:

  • Wordlists:

  • CMS Scanners:

    • Wpscan - WordPress vulnerability scanner.
    • Droopescan - Drupal and Joomla scanner.
  • SQL Vulnerability Tools:

  • JavaScript Enumeration:

  • Visual Recon:

    • Aquatone - Visual reconnaissance tool.
  • Web Crawlers:

  • XSS Vulnerability Tools:

    • XSStrike - XSS vulnerability scanner.
    • XSS-Loader - XSS payload loader.
    • Freq - Frequency analysis tool for XSS.
    • Gxss - XSS vulnerability scanner.
    • Dalfox - XSS scanning tool.
  • SSRF Vulnerability Tools:

  • Vulnerability Scanners:

    • Nuclei - Vulnerability scanner.
  • Virtual Host Discovery:

  • Additional Useful Tools:

    • Anew - Append unique lines to files.
    • Unew - Unique newline processing.
    • Gf - GitHub fuzzing tool.
    • Httprobe - HTTP probe tool.
    • Httpx - HTTP probing tool.
    • Waybackurls - Retrieve URLs from the Wayback Machine.
    • Arjun - HTTP parameter discovery tool.
    • Gau - Get all URLs.
    • GauPlus - Enhanced version of Gau.
    • Uro - URL-related operations tool.
    • Qsreplace - URL parameter replacement.
    • SocialHunter - Social media reconnaissance tool.

Additional Resources

Note

I am merely a script kiddie and all credits go to the respective tool creators. Special thanks to The Cyberboy for their comprehensive overview on YouTube: Watch Here.