Skip to content

Commit 24918f8

Browse files
authored
Merge pull request #80 from ThePorgs/dev-images
Add tools list for Exegol image 3.1.6
2 parents 4fadc88 + 58b4a99 commit 24918f8

12 files changed

+1914
-0
lines changed

source/assets/installed_tools/lists/ad_3.1.6_amd64.csv

Lines changed: 269 additions & 0 deletions
Large diffs are not rendered by default.

source/assets/installed_tools/lists/ad_3.1.6_arm64.csv

Lines changed: 268 additions & 0 deletions
Large diffs are not rendered by default.

source/assets/installed_tools/lists/full_3.1.6_amd64.csv

Lines changed: 397 additions & 0 deletions
Large diffs are not rendered by default.

source/assets/installed_tools/lists/full_3.1.6_arm64.csv

Lines changed: 390 additions & 0 deletions
Large diffs are not rendered by default.
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
Tool,Link,Description
2+
asdf,https://github.com/asdf-vm/asdf,Extendable version manager with support for ruby python go etc
3+
autorecon,https://github.com/Tib3rius/AutoRecon,Multi-threaded network reconnaissance tool which performs automated enumeration of services.
4+
bloodhound,https://github.com/BloodHoundAD/BloodHound,Active Directory security tool for reconnaissance and attacking AD environments.
5+
bloodhound.py,https://github.com/fox-it/BloodHound.py,BloodHound ingestor in Python.
6+
cloudfail,https://github.com/m0rtem/CloudFail,a reconnaissance tool for identifying misconfigured CloudFront domains.
7+
coercer,https://github.com/p0dalirius/coercer,DFS-R target coercion tool
8+
CyberChef,https://github.com/gchq/CyberChef/,The Cyber Swiss Army Knife
9+
droopescan,https://github.com/droope/droopescan,Scan Drupal websites for vulnerabilities.
10+
drupwn,https://github.com/immunIT/drupwn,Drupal security scanner.
11+
enum4linux-ng,https://github.com/cddmp/enum4linux-ng,Tool for enumerating information from Windows and Samba systems.
12+
evilwinrm,https://github.com/Hackplayers/evil-winrm,Tool to connect to a remote Windows system with WinRM.
13+
exegol-history,https://github.com/ThePorgs/Exegol-history,Credentials management for Exegol
14+
eyewitness,https://github.com/FortyNorthSecurity/EyeWitness,a tool to take screenshots of websites / provide some server header info / and identify default credentials if possible.
15+
fcrackzip,https://github.com/hyc/fcrackzip,Password cracker for zip archives.
16+
ffuf,https://github.com/ffuf/ffuf,Fast web fuzzer written in Go.
17+
firefox,https://www.mozilla.org,A web browser
18+
fzf,https://github.com/junegunn/fzf,🌸 A command-line fuzzy finder
19+
gf,https://github.com/tomnomnom/gf,A wrapper around grep to avoid typing common patterns
20+
gittools,https://github.com/internetwache/GitTools,A collection of Git tools including a powerful Dumper for dumping Git repositories.
21+
hashcat,https://hashcat.net/hashcat,A tool for advanced password recovery
22+
hydra,https://github.com/vanhauser-thc/thc-hydra,Hydra is a parallelized login cracker which supports numerous protocols to attack.
23+
impacket,https://github.com/ThePorgs/impacket,Set of tools for working with network protocols (ThePorgs version).
24+
john,https://github.com/openwall/john,John the Ripper password cracker.
25+
joomscan,https://github.com/rezasp/joomscan,A tool to enumerate Joomla-based websites
26+
jwt,https://github.com/ticarpi/jwt_tool,a command-line tool for working with JSON Web Tokens (JWTs)
27+
mdcat,https://github.com/swsnr/mdcat,Fancy cat for Markdown
28+
metasploit,https://github.com/rapid7/metasploit-framework,A popular penetration testing framework that includes many exploits and payloads
29+
neo4j,https://github.com/neo4j/neo4j,Database.
30+
neovim,https://neovim.io/,hyperextensible Vim-based text editor
31+
netexec,https://github.com/Pennyw0rth/NetExec,Network scanner (Crackmapexec updated).
32+
nmap,https://nmap.org,The Network Mapper - a powerful network discovery and security auditing tool
33+
nuclei,https://github.com/projectdiscovery/nuclei,A fast and customizable vulnerability scanner that can detect a wide range of issues / including XSS / SQL injection / and misconfigured servers.
34+
proxychains,https://github.com/rofl0r/proxychains,Proxy chains - redirect connections through proxy servers.
35+
pyftpdlib,https://github.com/giampaolo/pyftpdlib/,Extremely fast and scalable Python FTP server library
36+
responder,https://github.com/lgandx/Responder,a LLMNR / NBT-NS and MDNS poisoner.
37+
seclists,https://github.com/danielmiessler/SecLists,A collection of multiple types of lists used during security assessments
38+
simplyemail,https://github.com/SimplySecurity/SimplyEmail,a scriptable command line tool for sending emails
39+
smbclient,https://github.com/samba-team/samba,SMBclient is a command-line utility that allows you to access Windows shared resources
40+
smbmap,https://github.com/ShawnDEvans/smbmap,A tool to enumerate SMB shares and check for null sessions
41+
sqlmap,https://github.com/sqlmapproject/sqlmap,Sqlmap is an open-source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws
42+
sslscan,https://github.com/rbsec/sslscan,a tool for testing SSL/TLS encryption on servers
43+
subfinder,https://github.com/projectdiscovery/subfinder,Tool to find subdomains associated with a domain.
44+
testssl,https://github.com/drwetter/testssl.sh,a tool for testing SSL/TLS encryption on servers
45+
theharvester,https://github.com/laramies/theHarvester,Tool for gathering e-mail accounts / subdomain names / virtual host / open ports / banners / and employee names from different public sources
46+
wafw00f,https://github.com/EnableSecurity/wafw00f,a Python tool that helps to identify and fingerprint web application firewall (WAF) products.
47+
waybackurls,https://github.com/tomnomnom/waybackurls,Fetch all the URLs that the Wayback Machine knows about for a domain.
48+
weevely,https://github.com/epinna/weevely3,a webshell designed for post-exploitation purposes that can be extended over the network at runtime.
49+
weevely,https://github.com/epinna/weevely3,a webshell designed for post-exploitation purposes that can be extended over the network at runtime.
50+
wpscan,https://github.com/wpscanteam/wpscan,A tool to enumerate WordPress-based websites
51+
ysoserial,https://github.com/frohoff/ysoserial,A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
Tool,Link,Description
2+
asdf,https://github.com/asdf-vm/asdf,Extendable version manager with support for ruby python go etc
3+
autorecon,https://github.com/Tib3rius/AutoRecon,Multi-threaded network reconnaissance tool which performs automated enumeration of services.
4+
bloodhound,https://github.com/BloodHoundAD/BloodHound,Active Directory security tool for reconnaissance and attacking AD environments.
5+
bloodhound.py,https://github.com/fox-it/BloodHound.py,BloodHound ingestor in Python.
6+
cloudfail,https://github.com/m0rtem/CloudFail,a reconnaissance tool for identifying misconfigured CloudFront domains.
7+
coercer,https://github.com/p0dalirius/coercer,DFS-R target coercion tool
8+
CyberChef,https://github.com/gchq/CyberChef/,The Cyber Swiss Army Knife
9+
droopescan,https://github.com/droope/droopescan,Scan Drupal websites for vulnerabilities.
10+
drupwn,https://github.com/immunIT/drupwn,Drupal security scanner.
11+
enum4linux-ng,https://github.com/cddmp/enum4linux-ng,Tool for enumerating information from Windows and Samba systems.
12+
evilwinrm,https://github.com/Hackplayers/evil-winrm,Tool to connect to a remote Windows system with WinRM.
13+
exegol-history,https://github.com/ThePorgs/Exegol-history,Credentials management for Exegol
14+
eyewitness,https://github.com/FortyNorthSecurity/EyeWitness,a tool to take screenshots of websites / provide some server header info / and identify default credentials if possible.
15+
fcrackzip,https://github.com/hyc/fcrackzip,Password cracker for zip archives.
16+
ffuf,https://github.com/ffuf/ffuf,Fast web fuzzer written in Go.
17+
firefox,https://www.mozilla.org,A web browser
18+
fzf,https://github.com/junegunn/fzf,🌸 A command-line fuzzy finder
19+
gf,https://github.com/tomnomnom/gf,A wrapper around grep to avoid typing common patterns
20+
gittools,https://github.com/internetwache/GitTools,A collection of Git tools including a powerful Dumper for dumping Git repositories.
21+
hashcat,https://hashcat.net/hashcat,A tool for advanced password recovery
22+
hydra,https://github.com/vanhauser-thc/thc-hydra,Hydra is a parallelized login cracker which supports numerous protocols to attack.
23+
impacket,https://github.com/ThePorgs/impacket,Set of tools for working with network protocols (ThePorgs version).
24+
john,https://github.com/openwall/john,John the Ripper password cracker.
25+
joomscan,https://github.com/rezasp/joomscan,A tool to enumerate Joomla-based websites
26+
jwt,https://github.com/ticarpi/jwt_tool,a command-line tool for working with JSON Web Tokens (JWTs)
27+
mdcat,https://github.com/swsnr/mdcat,Fancy cat for Markdown
28+
metasploit,https://github.com/rapid7/metasploit-framework,A popular penetration testing framework that includes many exploits and payloads
29+
neo4j,https://github.com/neo4j/neo4j,Database.
30+
neovim,https://neovim.io/,hyperextensible Vim-based text editor
31+
netexec,https://github.com/Pennyw0rth/NetExec,Network scanner (Crackmapexec updated).
32+
nmap,https://nmap.org,The Network Mapper - a powerful network discovery and security auditing tool
33+
nuclei,https://github.com/projectdiscovery/nuclei,A fast and customizable vulnerability scanner that can detect a wide range of issues / including XSS / SQL injection / and misconfigured servers.
34+
proxychains,https://github.com/rofl0r/proxychains,Proxy chains - redirect connections through proxy servers.
35+
pyftpdlib,https://github.com/giampaolo/pyftpdlib/,Extremely fast and scalable Python FTP server library
36+
responder,https://github.com/lgandx/Responder,a LLMNR / NBT-NS and MDNS poisoner.
37+
seclists,https://github.com/danielmiessler/SecLists,A collection of multiple types of lists used during security assessments
38+
simplyemail,https://github.com/SimplySecurity/SimplyEmail,a scriptable command line tool for sending emails
39+
smbclient,https://github.com/samba-team/samba,SMBclient is a command-line utility that allows you to access Windows shared resources
40+
smbmap,https://github.com/ShawnDEvans/smbmap,A tool to enumerate SMB shares and check for null sessions
41+
sqlmap,https://github.com/sqlmapproject/sqlmap,Sqlmap is an open-source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws
42+
sslscan,https://github.com/rbsec/sslscan,a tool for testing SSL/TLS encryption on servers
43+
subfinder,https://github.com/projectdiscovery/subfinder,Tool to find subdomains associated with a domain.
44+
testssl,https://github.com/drwetter/testssl.sh,a tool for testing SSL/TLS encryption on servers
45+
theharvester,https://github.com/laramies/theHarvester,Tool for gathering e-mail accounts / subdomain names / virtual host / open ports / banners / and employee names from different public sources
46+
wafw00f,https://github.com/EnableSecurity/wafw00f,a Python tool that helps to identify and fingerprint web application firewall (WAF) products.
47+
waybackurls,https://github.com/tomnomnom/waybackurls,Fetch all the URLs that the Wayback Machine knows about for a domain.
48+
weevely,https://github.com/epinna/weevely3,a webshell designed for post-exploitation purposes that can be extended over the network at runtime.
49+
weevely,https://github.com/epinna/weevely3,a webshell designed for post-exploitation purposes that can be extended over the network at runtime.
50+
wpscan,https://github.com/wpscanteam/wpscan,A tool to enumerate WordPress-based websites
51+
ysoserial,https://github.com/frohoff/ysoserial,A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
Tool,Link,Description
2+
arsenal,https://github.com/Orange-Cyberdefense/arsenal,Powerful weapons for penetration testing.
3+
asdf,https://github.com/asdf-vm/asdf,Extendable version manager with support for ruby python go etc
4+
assetfinder,https://github.com/tomnomnom/assetfinder,Tool to find subdomains and IP addresses associated with a domain.
5+
carbon14,https://github.com/Lazza/carbon14,OSINT tool for estimating when a web page was written.
6+
Censys,https://github.com/censys/censys-python,An easy-to-use and lightweight API wrapper for Censys APIs
7+
constellation,https://github.com/constellation-app/Constellation,Find and exploit vulnerabilities in mobile applications.
8+
creds,https://github.com/ihebski/DefaultCreds-cheat-sheet,One place for all the default credentials to assist pentesters during an engagement. This document has several products default login/password gathered from multiple sources.
9+
CyberChef,https://github.com/gchq/CyberChef/,The Cyber Swiss Army Knife
10+
dnsenum,https://github.com/fwaeytens/dnsenum,dnsenum is a tool for enumerating DNS information about a domain.
11+
exegol-history,https://github.com/ThePorgs/Exegol-history,Credentials management for Exegol
12+
exifprobe,https://github.com/hfiguiere/exifprobe,Exifprobe is a command-line tool to parse EXIF data from image files.
13+
exiftool,https://github.com/exiftool/exiftool,ExifTool is a Perl library and command-line tool for reading / writing and editing meta information in image / audio and video files.
14+
finalrecon,https://github.com/thewhiteh4t/FinalRecon,A web reconnaissance tool that gathers information about web pages
15+
findomain,https://github.com/findomain/findomain,The fastest and cross-platform subdomain enumerator.
16+
firefox,https://www.mozilla.org,A web browser
17+
fzf,https://github.com/junegunn/fzf,🌸 A command-line fuzzy finder
18+
GeoPincer,https://github.com/tloja/GeoPincer,GeoPincer is a script that leverages OpenStreetMap's Overpass API in order to search for locations.
19+
gf,https://github.com/tomnomnom/gf,A wrapper around grep to avoid typing common patterns
20+
githubemail,https://github.com/paulirish/github-email,a command-line tool to retrieve a user's email from Github.
21+
GoMapEnum,https://github.com/nodauf/GoMapEnum,Nothing new but existing techniques are brought together in one tool.
22+
goshs,https://github.com/patrickhener/goshs,Goshs is a replacement for Python's SimpleHTTPServer. It allows uploading and downloading via HTTP/S with either self-signed certificate or user provided certificate and you can use HTTP basic auth.
23+
gron,https://github.com/tomnomnom/gron,Make JSON greppable!
24+
h8mail,https://github.com/khast3x/h8mail,Email OSINT and breach hunting.
25+
holehe,https://github.com/megadose/holehe,mail osint tool finding out if it is used on websites.
26+
ignorant,https://github.com/megadose/ignorant,holehe but for phone numbers.
27+
imagemagick,https://github.com/ImageMagick/ImageMagick,ImageMagick is a free and open-source image manipulation tool used to create / edit / compose / or convert bitmap images.
28+
ipinfo,https://github.com/ipinfo/cli,Get information about an IP address or hostname.
29+
linkedin2username,https://github.com/initstring/linkedin2username,Generate a list of LinkedIn usernames from a company name.
30+
maigret,https://github.com/soxoj/maigret,Collects information about a target email (or domain) from Google and Bing search results
31+
maltego,https://www.paterva.com/web7/downloads.php,A tool used for open-source intelligence and forensics
32+
mdcat,https://github.com/swsnr/mdcat,Fancy cat for Markdown
33+
MurMurHash,https://github.com/QU35T-code/MurMurHash,This little tool is to calculate a MurmurHash value of a favicon to hunt phishing websites on the Shodan platform.
34+
neovim,https://neovim.io/,hyperextensible Vim-based text editor
35+
ngrok,https://github.com/inconshreveable/ngrok,Expose a local server behind a NAT or firewall to the internet
36+
objectwalker,https://github.com/p0dalirius/objectwalker,A python module to explore the object tree to extract paths to interesting objects in memory.
37+
osrframework,https://github.com/i3visio/osrframework,Include references to a bunch of different applications related to username checking / DNS lookups / information leaks research / deep web search / regular expressions extraction and many others.
38+
phoneinfoga,https://github.com/sundowndev/PhoneInfoga,Information gathering & OSINT framework for phone numbers.
39+
photon,https://github.com/s0md3v/Photon,a fast web crawler which extracts URLs / files / intel & endpoints from a target.
40+
pwndb,https://github.com/davidtavarez/pwndb,A command-line tool for searching the pwndb database of compromised credentials.
41+
pwnedornot,https://github.com/thewhiteh4t/pwnedOrNot,Check if a password has been leaked in a data breach.
42+
pyftpdlib,https://github.com/giampaolo/pyftpdlib/,Extremely fast and scalable Python FTP server library
43+
pymeta,https://github.com/m8sec/pymeta,Google and Bing scraping osint tool
44+
recon-ng,https://github.com/lanmaster53/recon-ng,External recon tool.
45+
recondog,https://github.com/s0md3v/ReconDog,a reconnaissance tool for performing information gathering on a target.
46+
rlwrap,https://github.com/hanslub42/rlwrap,rlwrap is a small utility that wraps input and output streams of executables / making it possible to edit and re-run input history
47+
rsync,https://packages.debian.org/sid/rsync,File synchronization tool for efficiently copying and updating data between local or remote locations
48+
searchsploit,https://gitlab.com/exploit-database/exploitdb,A command line search tool for Exploit-DB
49+
shellerator,https://github.com/ShutdownRepo/Shellerator,a simple command-line tool for generating shellcode
50+
Sherlock,https://github.com/sherlock-project/sherlock,Hunt down social media accounts by username across social networks.
51+
simplyemail,https://github.com/SimplySecurity/SimplyEmail,a scriptable command line tool for sending emails
52+
spiderfoot,https://github.com/smicallef/spiderfoot,A reconnaissance tool that automatically queries over 100 public data sources
53+
subfinder,https://github.com/projectdiscovery/subfinder,Tool to find subdomains associated with a domain.
54+
sublist3r,https://github.com/aboul3la/Sublist3r,a Python tool designed to enumerate subdomains of websites.
55+
theharvester,https://github.com/laramies/theHarvester,Tool for gathering e-mail accounts / subdomain names / virtual host / open ports / banners / and employee names from different public sources
56+
tig,https://github.com/jonas/tig,Tig is an ncurses-based text-mode interface for git.
57+
tor,https://github.com/torproject/tor,Anonymity tool that can help protect your privacy and online identity by routing your traffic through a network of servers.
58+
toutatis,https://github.com/megadose/Toutatis,Toutatis is a tool that allows you to extract information from instagrams accounts such as e-mails / phone numbers and more.
59+
trevorspray,https://github.com/blacklanternsecurity/TREVORspray,TREVORspray is a modular password sprayer with threading SSH proxying loot modules / and more
60+
TriliumNext,https://github.com/TriliumNext/Notes,Personal knowledge management system (successor to Trilium).
61+
uberfile,https://github.com/ShutdownRepo/Uberfile,Uberfile is a simple command-line tool aimed to help pentesters quickly generate file downloader one-liners in multiple contexts (wget / curl / powershell / certutil...). This project code is based on my other similar project for one-liner reverseshell generation Shellerator.
62+
uploader,https://github.com/Frozenka/uploader,Tool for quickly downloading files to a remote machine based on the target operating system
63+
waybackurls,https://github.com/tomnomnom/waybackurls,Fetch all the URLs that the Wayback Machine knows about for a domain.
64+
wesng,https://github.com/bitsadmin/wesng,WES-NG is a tool based on the output of Windows's systeminfo utility which provides the list of vulnerabilities the OS is vulnerable to including any exploits for these vulnerabilities.
65+
whatportis,https://github.com/ncrocfer/whatportis,Command-line tool to lookup port information
66+
whois,https://packages.debian.org/sid/whois,See information about a specific domain name or IP address.
67+
Yalis,https://github.com/EatonChips/yalis,Yet Another LinkedIn Scraper
68+
youtubedl,https://github.com/ytdl-org/youtube-dl,Download videos from YouTube and other sites.
69+
yt-dlp,https://github.com/yt-dlp/yt-dlp,A youtube-dl fork with additional features and fixes

0 commit comments

Comments
 (0)