Tools: scanner (277)
Pentesting tools tagged scanner. See all tools or the category key.
a2sv
Auto Scanning to SSL Vulnerability.
admsnmp
ADM SNMP audit scanner.
allthevhosts
A vhost discovery tool that scrapes various web applications.
anubis-netsec
Subdomain enumeration and information gathering tool.
apachetomcatscanner
Apache Tomcat vulnerability scanner.
assassingo
Web pentest framework for information gathering and vulnerability scanning.
athena-ssl-scanner
A SSL cipher scanner that checks all cipher codes. It can identify about 150 different ciphers.
atscan
Server, Site and Dork Scanner.
attk
Trend Micro Anti-Threat Toolkit.
aws-extender-cli
Script to test S3 buckets as well as Google Storage buckets and Azure Storage containers for common misconfiguration iss
aws-iam-privesc
AWS IAM policy scanner that helps determine where privilege escalation can be achieved.
barmie
Java RMI enumeration and attack tool.
bashscan
A port scanner built to utilize /dev/tcp for network and service discovery.
belati
The Traditional Swiss Army Knife for OSINT.
bingoo
A Linux bash based Bing and Google Dorking Tool.
birp
A tool that will assist in the security assessment of mainframe applications served over TN3270.
blackbox-scanner
Dork scanner & bruteforcing & hash cracker with blackbox framework.
bleah
A BLE scanner for "smart" devices hacking.
blindy
Simple script to automate brutforcing blind sql injection vulnerabilities.
bluto
Recon, Subdomain Bruting, Zone Transfers.
cameradar
Hacks its way into RTSP videosurveillance cameras.
camscan
A tool which will analyze the CAM table of Cisco switches to look for anamolies.
cangibrina
Dashboard Finder.
cecster
A tool to perform security testing against the HDMI CEC (Consumer Electronics Control) and HEC (HDMI Ethernet Channel) p
cero
Scrape domain names from SSL certificates of arbitrary hosts.
check-weak-dh-ssh
Debian OpenSSL weak client Diffie-Hellman Exchange checker.
chiron
An all-in-one IPv6 Penetration Testing Framework.
cipherscan
A very simple way to find out which SSL ciphersuites are supported by a target.
ciscos
Scans class A, B, and C networks for cisco routers which have telnet open and have not changed the default password from
clair
Vulnerability Static Analysis for Containers.
climber
Check UNIX/Linux systems for privilege escalation.
cloudflare-enum
Cloudflare DNS Enumeration Tool for Pentesters.
cloudsploit
AWS security scanning checks.
cmsmap
A python open source Content Management System scanner that automates the process of detecting security flaws of the mos
configpush
This is a tool to span /8-sized networks quickly sending snmpset requests with default or otherwise specified community
corstest
A simple CORS misconfigurations checker.
cpfinder
Simple script that looks for administrative web interfaces.
ct-exposer
An OSINT tool that discovers sub-domains by searching Certificate Transparency logs.
cvechecker
The goal of cvechecker is to report about possible vulnerabilities on your system, by scanning the installed software an
d-tect
Pentesting the Modern Web.
darkbing
A tool written in python that leverages bing for mining data on systems that may be susceptible to SQL injection.
dbusmap
Simple utility for enumerating D-Bus endpoints, an nmap for D-Bus.
dcrawl
Simple, but smart, multi-threaded web crawler for randomly gathering huge lists of unique domain names.
deblaze
Performs method enumeration and interrogation against flash remoting end points.
delldrac
DellDRAC and Dell Chassis Discovery and Brute Forcer.
dirscanner
This is a python script that scans webservers looking for administrative directories, php shells, and more.
dirstalk
Modern alternative to dirbuster/dirb.
dnmap
The distributed nmap framework.
dns2geoip
A simple python script that brute forces DNS and subsequently geolocates the found subdomains.
dnsa
A dns security swiss army knife.
dnsbf
Search for available domain names in an IP range.
dnscan
A python wordlist-based DNS subdomain scanner.
dnsgoblin
Nasty creature constantly searching for DNS servers. It uses standard dns querys and waits for the replies.
dnspredict
DNS prediction.
dockerscan
Docker security analysis & hacking tools.
dorkbot
Command-line tool to scan Google search results for vulnerabilities.
dorkme
Tool designed with the purpose of making easier the searching of vulnerabilities with Google Dorks, such as SQL Injectio
dpscan
Drupal Vulnerability Scanner.
dripper
A fast, asynchronous DNS scanner; it can be used for enumerating subdomains and enumerating boxes via reverse DNS.
dvcs-ripper
Rip web accessible (distributed) version control systems: SVN/GIT/BZR/CVS/HG.
eazy
This is a small python tool that scans websites to look for PHP shells, backups, admin panels, and more.
enum-shares
Tool that enumerates shared folders across the network and under a custom user account.
eternal-scanner
An internet scanner for exploit CVE-0144 (Eternal Blue).
faradaysec
Collaborative Penetration Test and Vulnerability Management Platform.
fernmelder
Asynchronous mass DNS scanner.
fgscanner
An advanced, opensource URL scanner.
fi6s
IPv6 network scanner designed to be fast.
find-dns
A tool that scans networks looking for DNS servers.
flashscanner
Flash XSS Scanner.
flunym0us
A Vulnerability Scanner for Wordpress and Moodle.
forkingportscanner
Simple and fast forking port scanner written in perl. Can only scan on host at a time, the forking is done on the specif
fortiscan
A high performance FortiGate SSL-VPN vulnerability scanning and exploitation tool.
fs-nyarl
A network takeover & forensic analysis tool - useful to advanced PenTest tasks & for fun and profit.
fscan
A Security Auditing Tool.
fsnoop
A tool to monitor file operations on GNU/Linux systems by using the Inotify mechanism. Its primary purpose is to help de
ftp-spider
FTP investigation tool - Scans ftp server for the following: reveal entire directory tree structures, detect anonymous a
ftpscout
Scans ftps for anonymous access.
gcpbucketbrute
A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privi
gethsploit
Finding Ethereum nodes which are vulnerable to RPC-attacks.
gggooglescan
A Google scraper which performs automated searches and returns results of search queries in the form of URLs or hostname
ghost-phisher
GUI suite for phishing and penetration attacks.
git-dump
Dump the contents of a remote git repository without directory listing enabled.
git-dumper
A tool to dump a git repository from a website.
gitrob
Reconnaissance tool for GitHub organizations.
gloom
Linux Penetration Testing Framework.
glpwnme
GLPI vulnerabilities checking tool.
grabbb
Clean, functional, and fast banner scanner.
graphql-cop
GraphQL vulnerability scanner.
grepforrfi
Simple script for parsing web logs for RFIs and Webshells v1.2
grype
A vulnerability scanner for container images and filesystems.
gtp-scan
A small python script that scans for GTP (GPRS tunneling protocol) speaking hosts.
h2buster
A threaded, recursive, web directory brute-force scanner over HTTP/2.
habu
Python Network Hacking Toolkit.
hakku
Simple framework that has been made for penetration testing tools.
halberd
Halberd discovers HTTP load balancers. It is useful for web application security auditing and for load balancer configur
hbad
This tool allows you to test clients on the heartbleed bug.
hellraiser
Vulnerability Scanner.
hexhttp
Perform tests on HTTP headers and analyze the results to identify vulnerabilities and interesting behaviors.
hikpwn
A simple scanner for Hikvision devices with basic vulnerability scanning capabilities written in Python 3.8.
homepwn
Swiss Army Knife for Pentesting of IoT Devices.
hoppy
A python script which tests http methods for configuration issues leaking information or just to see if they are enabled
host-extract
Ruby script tries to extract all IP/Host patterns in page response of a given URL and JavaScript/CSS files of that URL.
hsecscan
A security scanner for HTTP response headers.
http-enum
A tool to enumerate the enabled HTTP methods supported on a webserver.
httpsscanner
A tool to test the strength of a SSL web server.
iaxscan
A Python based scanner for detecting live IAX/2 hosts and then enumerating (by bruteforce) users on those hosts.
icmpquery
Send and receive ICMP queries for address mask and current time.
iis-shortname-scanner
An IIS shortname Scanner.
ilo4-toolbox
Toolbox for HPE iLO4 analysis.
infip
A python script that checks output from netstat against RBLs from Spamhaus.
inurlbr
Advanced search in the search engines - Inurl scanner, dorker, exploiter.
ipscan
A very fast IP address and port scanner.
iptv
Search and brute force illegal iptv server.
jaadas
Joint Advanced Defect assEsment for android applications.
knock
Subdomain scanner.
knxmap
KNXnet/IP scanning and auditing tool for KNX home automation installations.
kscan
Asset mapping tool that can perform port scanning, TCP fingerprinting and banner capture for specified assets.
kube-hunter
Hunt for security weaknesses in Kubernetes clusters.
kubesploit
Cross-platform post-exploitation HTTP/2 Command & Control server.
kubestriker
A Blazing fast Security Auditing tool for Kubernetes.
laf
Login Area Finder: scans host/s for login panels.
leaklooker
Find open databases with Shodan.
letmefuckit-scanner
Scanner and Exploit Magento.
leviathan
A mass audit toolkit which has wide range service discovery, brute force, SQL injection detection and running custom exp
lfi-scanner
This is a simple perl script that enumerates local file inclusion attempts when given a specific target.
lfisuite
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner.
linenum
Scripted Local Linux Enumeration & Privilege Escalation Checks
linux-smart-enumeration
Linux enumeration tool for pentesting and CTFs with verbosity levels.
littleblackbox
Penetration testing tool, search in a collection of thousands of private SSL keys extracted from various embedded device
locasploit
Local enumeration and exploitation framework.
logmepwn
A fully automated, reliable, super-fast, mass scanning and validation toolkit for the Log4J RCE CVE-44228 vulnerability.
lotophagi
a relatively compact Perl script designed to scan remote hosts for default (or common) Lotus NSF and BOX databases.
lunar
A UNIX security auditing tool based on several security frameworks.
maligno
An open source penetration testing tool written in python, that serves Metasploit payloads. It generates shellcode with
manspider
Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!
mantra
Hunt down API key leaks in JS files and pages.
modscan
A new tool designed to map a SCADA MODBUS TCP based network.
mongoaudit
A powerful MongoDB auditing and pentesting tool .
mqtt-pwn
A one-stop-shop for IoT Broker penetration-testing and security assessment operations.
msmailprobe
Office 365 and Exchange Enumeration tool.
mssqlscan
A small multi-threaded tool that scans for Microsoft SQL Servers.
multiscanner
Modular file scanning/analysis framework.
navgix
Multi-threaded golang tool that will check for nginx alias traversal vulnerabilities.
netbios-share-scanner
This tool could be used to check windows workstations and servers if they have accessible shared resources.
netscan
Tcp/Udp/Tor port scanner with: synpacket, connect TCP/UDP and socks5 (tor connection).
netscan2
Active / passive network scanner.
netz
Discover internet-wide misconfigurations while drinking coffee.
nili
Tool for Network Scan, Man in the Middle, Protocol Reverse Engineering and Fuzzing.
nimux
Pure-Nim network enumeration and remote execution toolkit.
nmbscan
Tool to scan the shares of a SMB/NetBIOS network, using the NMB/SMB/NetBIOS protocols.
nox-framework
OSINT & CTI Framework with 120+ sources, async performance, identity pivoting, and automated risk analysis.
nray
Distributed port scanner.
ntlm-challenger
Parse NTLM over HTTP challenge messages.
ntlm-scanner
A simple python tool based on Impacket that tests servers for various known NTLM vulnerabilities.
ntlmrecon
A tool to enumerate information from NTLM authentication enabled web endpoints.
nuclei-templates
Community curated list of template files for the nuclei engine.
o-saft
A tool to show informations about SSL certificate and tests the SSL connection according given list of ciphers and vario
ocs
Compact mass scanner for Cisco routers with default telnet/enable passwords.
onetwopunch
Use unicornscan to quickly scan all open ports, and then pass the open ports to nmap for detailed scans.
onionscan
Scan Onion Services for Security Issues.
openvas
Meta package for installing all OpenVAS components.
pagodo
Google dork script to collect potentially vulnerable web pages and applications on the Internet.
paketto
Advanced TCP/IP Toolkit.
panhunt
Searches for credit card numbers (PANs) in directories.
paranoic
A simple vulnerability scanner written in Perl.
passhunt
Search drives for documents containing passwords.
pbscan
Faster and more efficient stateless SYN scanner and banner grabber due to userland TCP/IP stack usage.
pcredz
A tool that extracts credit card numbers and more from a pcap file or from a live interface.
peass
Privilege Escalation Awesome Scripts SUITE (with colors).
pentestly
Python and Powershell internal penetration testing framework.
plcscan
This is a tool written in Python that will scan for PLC devices over s7comm or modbus protocols.
poison
A fast, asynchronous syn and udp scanner.
ppscan
Yet another port scanner with HTTP and FTP tunneling support.
prads
A "Passive Real-time Asset Detection System".
praeda
An automated data/information harvesting tool designed to gather critical information from various embedded devices.
proxycheck
This is a simple proxy tool that checks for the HTTP CONNECT method and grabs verbose output from a webserver.
proxyscan
A security penetration testing tool to scan for hosts and ports through a Web proxy server.
pwndora
Massive IPv4 scanner, find and analyze internet-connected devices in minutes, create your own IoT search engine at home.
pyssltest
A python multithreaded script to make use of Qualys ssllabs api to test SSL flaws.
pytbull
Next generation of pytbull, IDS/IPS testing framework.
pythem
Python2 penetration testing framework.
python2-ldapdomaindump
Active Directory information dumper via LDAP.
ranger-scanner
A tool to support security professionals to access and interact with remote Microsoft Windows based systems.
rawr
Rapid Assessment of Web Resources. A web enumerator.
rbac-lookup
A CLI that allows you to easily find Kubernetes roles and cluster roles bound to any user.
rdp-cipher-checker
Enumerate the encryption protocols supported by the server and the cipher strengths supported using native RDP encryptio
rdp-sec-check
Script to enumerate security settings of an RDP Service.
relay-scanner
An SMTP relay scanner.
remote-method-guesser
Java RMI vulnerability scanner.
retire
Scanner detecting the use of JavaScript libraries with known vulnerabilities.
routerhunter
Tool used to find vulnerable routers and devices on the Internet and perform tests.
rtlizer
Simple spectrum analyzer.
rtlsdr-scanner
A cross platform Python frequency scanning GUI for the OsmoSDR rtl-sdr library.
sambascan
Allows you to search an entire network or a number of hosts for SMB shares. It will also list the contents of all public
sandcastle
A Python script for AWS S3 bucket enumeration.
sandmap
Simple CLI with the ability to run pure Nmap engine, 31 modules with 459 scan profiles.
sandy
An open-source Samsung phone encryption assessment framework
sb0x
A simple and Lightweight framework for Penetration testing.
scamper
A tool that actively probes the Internet in order to analyze topology and performance.
scanless
Utility for using websites that can perform port scans on your behalf.
scannerl-git
The modular distributed fingerprinting engine
scanssh
Fast SSH server and open proxy scanner.
scout2
Security auditing tool for AWS environments.
scoutsuite
Multi-Cloud Security Auditing Tool.
scrape-dns
Searches for interesting cached DNS entries.
sdnpwn
An SDN penetration testing toolkit.
seat
Next generation information digging application geared toward the needs of security professionals. It uses information s
shareenum
Tool to enumerate shares from Windows hosts.
sharesniffer
Network share sniffer and auto-mounter for crawling remote file systems.
shortscan
An IIS short filename enumeration tool.
simple-lan-scan
A simple python script that leverages scapy for discovering live hosts on a network.
simple-lan-scan3
A simple python3 script that leverages scapy for discovering live hosts on a network.
sipshock
A scanner for SIP proxies vulnerable to Shellshock.
slurp-scanner
Evaluate the security of S3 buckets.
smap-scanner
Passive port scanner built with shodan free API.
smbexec
A rapid psexec style attack with samba tools.
smbspider
A lightweight python utility for searching SMB/CIFS/Samba file shares.
smbsr
Lookup for interesting stuff in SMB shares.
smod
A modular framework with every kind of diagnostic and offensive feature you could need in order to pentest modbus protoc
smtp-test
Automated testing of SMTP servers for penetration testing.
smtp-vrfy
An SMTP Protocol Hacker.
smtptx
A very simple tool used for sending simple email and do some basic email testing from a pentester perspective.
snmpscan
A free, multi-processes SNMP scanner.
snoopbrute
Multithreaded DNS recursive host brute-force tool.
sparta
Python GUI application which simplifies network infrastructure penetration testing by aiding the penetration tester in t
sqlivulscan
This will give you the SQLi Vulnerable Website Just by Adding the Dork.
ssdp-scanner
SSDP amplification scanner written in Python. Makes use of Scapy.
ssh-user-enum
SSH User Enumeration Script in Python Using The Timing Attack.
sslcaudit
Utility to perform security audits of SSL/TLS clients.
ssllabs-scan
Command-line client for the SSL Labs APIs
sslmap
A lightweight TLS/SSL cipher suite scanner.
sslscan2
Tests SSL/TLS enabled services to discover supported cipher suites.
stacs
Static Token And Credential Scanner.
sticky-keys-hunter
Script to test an RDP host for sticky keys and utilman backdoor.
stig-viewer
XCCDF formatted SRGs and STIGs files viewer for SCAP validation tools.
strutscan
Apache Struts2 vulnerability scanner written in Perl.
subbrute
A DNS meta-query spider that enumerates DNS records, and subdomains.
subover
A Powerful Subdomain Takeover Tool.
subzy
Subdomain takeover vulnerability checker.
swarm
A distributed penetration testing tool.
synscan
fast asynchronous half-open TCP portscanner
tachyon-scanner
Fast Multi-Threaded Web Discovery Tool.
tactical-exploitation
Modern tactical exploitation toolkit.
taipan
Web application security scanner.
takeover
Sub-Domain TakeOver Vulnerability Scanner.
titus
High-performance secrets scanner based on NoseyParker.
tlsx
TLS grabber focused on TLS based data collection.
topera
An IPv6 security analysis toolkit, with the particularity that their attacks can't be detected by Snort.
traxss
Automated XSS Vulnerability Scanner.
udp-hunter
Network assessment tool for various UDP Services covering both IPv4 and IPv6 protocols.
udsim
A graphical simulator that can emulate different modules in a vehicle and respond to UDS request.
umap
The USB host security assessment tool.
upnpscan
Scans the LAN or a given address range for UPnP capable devices.
uptux
Linux privilege escalation checks (systemd, dbus, socket fun, etc).
uw-loveimap
Multi threaded imap bounce scanner.
uw-udpscan
Multi threaded udp scanner.
uw-zone
Multi threaded, randomized IP zoner.
v3n0m
Offensive Security Tool for Vulnerability Scanning & Pentesting
vault-scanner
Swiss army knife for hackers.
vcsmap
A plugin-based tool to scan public version control systems for sensitive information.
vhostscan
A virtual host scanner that can be used with pivot tools, detect catch-all scenarios, aliases and dynamic default pages.
videosnarf
A new security assessment tool for pcap analysis
visql
Scan SQL vulnerability on target site and sites of on server.
vscan
HTTPS / Vulnerability scanner.
vulmap
Vulmap Online Local Vulnerability Scanners Project
vuls
Vulnerability scanner for Linux/FreeBSD, agentless, written in Go.
webenum
Tool to enumerate http responses using dynamically generated queries and more.
webhunter
Tool for scanning web applications and networks and easily completing the process of collecting knowledge.
webpwn3r
A python based Web Applications Security Scanner.
webrute
Web server directory brute forcer.
whitewidow
SQL Vulnerability Scanner.
wolpertinger
A distributed portscanner.
wordpresscan
WPScan rewritten in Python + some WPSeku ideas.
xcname
A tool for enumerating expired domains in CNAME records.
xpire-crossdomain-scanner
Scans crossdomain.xml policies for expired domain names.
xsstracer
Python script that checks remote web servers for Clickjacking, Cross-Frame Scripting, Cross-Site Tracing and Host Header
yasat
Yet Another Stupid Audit Tool.