Squashed rework of hackingtool from a tool launcher into an AI-guided operator
console for authorized security testing. 93 commits collapsed into this one;
the pre-rework tree is tagged v2.0.0.
CATALOG & ENGINE
- Data-driven YAML catalog (21 categories, 215 live tools + 59 archived) with a
registry/overlay loader and a fixed 66-tag taxonomy (63 in use). Adding a tool
is one YAML entry, not edits across the codebase.
- Engine honesty: real exit codes, truthful install success/failure, reuse-first
skip, EOF-safe prompts, command audit logging.
- Safe installs: sha256-required safe-fetch (killed `curl | bash` in feroxbuster,
Caido and Sliver), list-form subprocess only, no forced sudo.
AI LAYER (bring-your-own-key or local model; degrades offline, never fabricates)
- AI1 intent -> tools; AI2 tool+goal -> command, curated-first with a grounded
fallback; AI3 findings summary and engagement report; AI4 per-finding impact
and remediation. Prompt-injection hardened per OWASP LLM01.
- /goal plans an objective and runs it one step at a time, showing every command
before it runs, with a plan.json + run.log audit trail.
/find TOOL DISCOVERY (this branch's headline feature)
- Suggests real GitHub projects when the catalog has no tool for a need.
Deterministic: zero model calls, structured API fields only, suggest-only —
it never clones, installs or runs anything.
- A charter filter refuses destructive/DoS/jamming/mass-targeting/evasion asks
before any network I/O, while a defensive-intent guard keeps blue-team and
DFIR phrasing ("detect a SYN flood in a pcap") from being false-refused.
- Query rewriting proved to be the dominant quality lever (the first design
measured 29% precision with no results on 5 of 8 needs): a curated 41-row
intent table maps plain English to canonical jargon plus a GitHub topic, and
a two-arm search unions topic coverage with jargon precision.
- Explainable additive ranking: log-flattened stars, license/age/language,
trusted-author bonus derived from owners we already ship, docs-repo demotion
by name, staleness as a soft demotion rather than a filter (a hard cutoff
would delete THC-Hydan and John the Ripper), and a relevance term weighting
curated topics above free-text description.
- Optional no-scope GitHub token purely as a rate-limit lever (10 -> 30 req/min);
it reaches only an Authorization header, never a cache key, log or output.
- `[a]` saves a pick to ~/.hackingtool/found.yaml as a structurally inert entry,
and the loader strips executable keys from user catalogs at read time so a
hand-edited file cannot become a runnable command.
CONSOLE & PACKAGING
- REPL with a / command palette, @ tool mentions, tag filters, history and
completion; background tmux panes; settings and first-run scaffolding.
- src-layout package with catalog and pipelines as package data, console entry
point, Docker image, signed releases with SBOM and build provenance.
- Health docs (SECURITY, CONTRIBUTING, CHANGELOG, CODE_OF_CONDUCT), a CI gate
(ruff + pytest + catalog/taxonomy conformance) and a pre-push hook.
- README rewritten with a section index, the tool catalog split into
docs/TOOLS.md and a step-by-step docs/HOW-TO-USE.md.
278 tests passing; scripts/check.sh green.
27 KiB
Tool catalog
Every tool hackingtool can install, launch, or point you at — 215 active tools
across 21 categories, plus 59 archived entries kept out of this list (they are
unmaintained or dead upstream and are hidden in the app unless you set
show_archived true via /config).
Tags under each entry come from the fixed taxonomy in src/hackingtool/tags.py
(63 tags in use). Inside the app you can filter by any of them with
@tag:<name>, or search names/descriptions/tags with /search <keyword>.
Entries marked as a link point at the upstream project; a few are curated reference resources (labs, cheat sheets, online services) rather than installable binaries — hackingtool opens those instead of installing them.
Authorized targets only. Every tool here is for systems you own or have written permission to test.
Back to the README · How to use hackingtool
🛡 Anonymously Hiding Tools
- Anonymously Surf — anonymity, tunneling, network
- Multitor — anonymity, tunneling, network
- Tor + torsocks (SOCKS anonymity proxy) — anonymity, tunneling, network
- proxychains-ng (chain traffic through proxies/Tor) — anonymity, tunneling, network
- Whonix — Anonymity & Tor OpSec (docs) — anonymity, reference, learning
🔍 Information gathering tools
- Network Map (nmap) — scanner, port-scan, recon, network
- Port scanning — port-scan, scanner, network
- Host to IP — recon, dns, lookup
- RED HAWK (All In One Scanning) — web, recon, scanner, fingerprint
- ReconSpider(For All Scanning) — osint, recon, crawler
- IsItDown (Check Website Down/Up) — recon, online-service, web
- SecretFinder (like API & etc) — web, recon, credentials, git-secrets
- Port Scanner - rang3r — port-scan, scanner, network
- Breacher — web, recon, enumeration
- theHarvester (OSINT) — osint, email, subdomain-enum, recon
- Amass (Attack Surface Mapping) — subdomain-enum, recon, osint, dns
- Masscan (Fast Port Scanner) — port-scan, scanner, network
- RustScan (Modern Port Scanner) — port-scan, scanner, network
- Holehe (Email → Social Accounts) — osint, email, recon, lookup
- Maigret (Username OSINT) — osint, recon, lookup
- httpx (HTTP Toolkit) — web, recon, scanner, fingerprint
- SpiderFoot (OSINT Automation) — osint, recon, subdomain-enum
- Subfinder (Subdomain Enumeration) — subdomain-enum, recon, osint, dns
- TruffleHog (Secret Scanner) — git-secrets, credentials, recon
- Gitleaks (Git Secret Scanner) — git-secrets, credentials, reporting
- naabu (fast port scanner) — port-scan, recon, network
- dnsx (DNS toolkit) — dns, recon, enumeration
- reconFTW (Automated Recon) — recon, osint, subdomain-enum, scanner, dns
- gowitness (Web Screenshots) — web, recon, fingerprint, reporting
- EyeWitness (Web Screenshots + Headers) — web, recon, fingerprint, reporting
- Sn1per (Attack Surface Scanner) — scanner, recon, vuln-scan, enumeration, web
📚 Wordlist Generator
- Cupp — wordlist, password-attack, credentials, osint
- Hashcat (Password Cracker) — hash-crack, password-attack, credentials
- John the Ripper — hash-crack, password-attack, credentials
- haiti (Hash Type Identifier) — hash-crack, lookup, reference
- crunch (Wordlist Generator) — wordlist, bruteforce, password-attack
- CeWL (Custom Word List) — wordlist, osint, recon, credentials
- SecLists (Wordlist Collection) — wordlist, reference, bruteforce
- Kali wordlists package (rockyou etc.) — wordlist, reference, password-attack
📡 Wireless attack tools
- WiFi-Pumpkin — wireless, mitm, phishing, credentials
- pixiewps — wireless, bruteforce, password-attack
- Bluetooth Honeypot GUI Framework — wireless, sniffing
- Fluxion — wireless, phishing, social-engineering, credentials
- Wifiphisher — wireless, phishing, social-engineering, mitm
- Wifite — wireless, password-attack, bruteforce, credentials
- Howmanypeople — wireless, sniffing, recon
- Airgeddon (Wireless Attack Suite) — wireless, password-attack, mitm, credentials
- hcxdumptool (PMKID Capture) — wireless, sniffing, pcap, credentials
- hcxtools (PMKID/Hash Conversion) — wireless, hash-crack, pcap, credentials
- Bettercap (Network/WiFi/BLE MITM) — wireless, mitm, sniffing, network
- aircrack-ng (WiFi security suite) — wireless, password-attack, bruteforce, sniffing
- Kismet (wireless detector / WIDS) — wireless, sniffing, recon, network
- Reaver (WPS PIN attack) — wireless, bruteforce, password-attack, credentials
- WiGLE (wardriving map & API) — wireless, osint, online-service, lookup
- hashcat example hashes (WPA mode 22000) — wireless, hash-crack, reference
- Aircrack-ng: cracking WPA (tutorial) — wireless, learning, reference
💉 SQL Injection Tools
- Sqlmap tool — web, sql-injection, exploitation, scanner
- NoSqlMap — web, sql-injection, exploitation
- Damn Small SQLi Scanner — web, sql-injection, scanner
- SQLScan — web, sql-injection, scanner
- Ghauri (Modern SQLi Tool) — web, sql-injection, exploitation, scanner
- PortSwigger — SQL Injection Labs — learning, web, sql-injection, reference
- PayloadsAllTheThings — SQL Injection — cheatsheet, reference, sql-injection, web
🎣 Phishing attack tools
- AdvPhishing — phishing, social-engineering, credentials
- Setoolkit — social-engineering, phishing, credentials
- SocialFish — phishing, credentials, web
- HiddenEye — phishing, credentials, social-engineering
- Evilginx3 — phishing, mitm, credentials, web
- SayCheese — social-engineering, phishing
- QR Code Jacking — phishing, social-engineering
- QRLJacking — phishing, social-engineering, credentials
- Maskphish — phishing, social-engineering
- dnstwist — osint, dns, phishing
- GoPhish (Phishing Simulation) — phishing, social-engineering, email, credentials, web
- GoPhish Documentation — phishing, reference, learning
- MITRE ATT&CK — Phishing (T1566) — phishing, social-engineering, reference
🌐 Web Attack tools
- Skipfish — web, vuln-scan, scanner, crawler
- SubDomain Finder — subdomain-enum, recon, osint, dns
- Sub-Domain TakeOver — subdomain-enum, web, vuln-scan
- Dirb — web, enumeration, bruteforce, wordlist
- Nuclei (Vulnerability Scanner) — web, vuln-scan, scanner
- ffuf (Web Fuzzer) — web, fuzzing, enumeration, wordlist
- Feroxbuster (Directory Brute Force) — web, enumeration, bruteforce, wordlist
- Nikto (Web Server Scanner) — web, vuln-scan, scanner
- wafw00f (WAF Detector) — web, fingerprint, recon
- Katana (Web Crawler) — web, crawler, recon, enumeration
- Gobuster (Dir/DNS/Vhost Brute Force) — web, enumeration, bruteforce, dns, wordlist
- Dirsearch (Web Path Discovery) — web, enumeration, bruteforce, wordlist
- OWASP ZAP (Web App Scanner) — web, vuln-scan, scanner, fuzzing
- testssl.sh (TLS/SSL Checker) — web, scanner, fingerprint
- Arjun (HTTP Parameter Discovery) — web, fuzzing, enumeration
- Caido (Web Security Auditing) — web, scanner, crawler
- mitmproxy (Intercepting Proxy) — web, mitm, sniffing
- WhatWeb (Web Fingerprinter) — web, fingerprint, recon, scanner
- WPScan (WordPress Scanner) — web, vuln-scan, scanner, enumeration
- PortSwigger Web Security Academy — learning, web, reference
- PayloadsAllTheThings — cheatsheet, reference, payload, web
- HackTricks — cheatsheet, reference, web, privesc
- revshells.com (Reverse Shell Generator) — reverse-shell, cheatsheet, online-service, web
🔧 Post exploitation tools
- pwncat-cs (Reverse Shell Handler) — post-exploitation, reverse-shell, persistence, privesc
- Sliver (C2 Framework) — c2, post-exploitation, payload
- PEASS-ng — LinPEAS/WinPEAS (Priv Esc) — privesc, post-exploitation, enumeration
- Ligolo-ng (Tunneling/Pivoting) — tunneling, lateral-movement, post-exploitation, network
- Chisel (HTTP Tunnel) — tunneling, lateral-movement, post-exploitation, network
- Evil-WinRM (Windows Remote Shell) — lateral-movement, credentials, post-exploitation, active-directory
- Mythic (C2 Platform) — c2, post-exploitation, lateral-movement
- pspy (unprivileged process snooping) — post-exploitation, privesc, enumeration
- linux-smart-enumeration (lse.sh) — privesc, post-exploitation, enumeration
- LaZagne (Local Credential Recovery) — credentials, post-exploitation, password-attack
- HackTricks (post-ex / privesc playbook) — post-exploitation, privesc, reference, cheatsheet
- LOLBAS (Windows living-off-the-land binaries) — privesc, post-exploitation, reference, cheatsheet
- revshells.com (reverse shell generator) — reverse-shell, post-exploitation, online-service, reference
- PayloadsAllTheThings (payload + technique cheatsheets) — payload, post-exploitation, reference, cheatsheet
- mimikatz (Windows credential dumping — reference) — credentials, post-exploitation, active-directory, reference
🕵 Forensic tools
- Autopsy — forensics, metadata
- Wireshark — network, forensics, sniffing, pcap
- Bulk extractor — forensics, memory-dump, metadata
- Disk Clone and ISO Image Acquire — forensics, binary
- Toolsley — reference, online-service, forensics
- Volatility 3 (Memory Forensics) — forensics, memory-dump, malware-analysis
- Binwalk (Firmware Analysis) — forensics, binary, reversing
- pspy (Process Monitor — No Root) — forensics, post-exploitation, enumeration
- ExifTool (Metadata) — forensics, metadata, image, document
- Foremost (File Carving) — forensics, binary
- Eric Zimmerman's Tools — reference, forensics, online-service
- MalwareBazaar (Sample Database) — online-service, reference, malware-analysis
📦 Payload creation tools
- The FatRat — payload, reverse-shell, apk, c2
- Stitch — payload, c2, reverse-shell, persistence
- Venom Shellcode Generator — payload, reverse-shell, c2
- Mob-Droid — payload, mobile, apk, reverse-shell
- msfvenom (Payload Generator) — payload, reverse-shell, c2, apk
- LOLBAS (Living Off The Land Binaries) — reference, payload, post-exploitation
🧰 Exploit framework
- RouterSploit — network, iot, exploitation, scanner
- Commix — web, exploitation, payload
- Metasploit Framework — exploitation, post-exploitation, payload, c2, scanner
- SearchSploit (Exploit-DB CLI) — exploitation, recon, reference
- Exploit-DB (Online Archive) — online-service, reference, exploitation
- Metasploit Unleashed (Free Course) — learning, reference, exploitation
🔁 Reverse engineering tools
- Androguard — reversing, apk, mobile, malware-analysis
- Apk2Gold — reversing, apk, mobile
- JadX — reversing, apk, mobile
- Ghidra (NSA Reverse Engineering) — reversing, binary, malware-analysis
- Radare2 (RE Framework) — reversing, binary
- apktool (APK Decode/Rebuild) — reversing, apk, mobile
- GDB (GNU Debugger) — reversing, binary
- binutils (strings / objdump / readelf) — reversing, binary
- crackmes.one (RE Practice) — reference, learning, reversing
- Malware Unicorn RE101 (Workshop) — reference, learning, reversing, malware-analysis
⚡ DDOS Attack Tools
- DDoS — ddos, network, web
- SlowLoris — ddos, web
- UFOnet — ddos, web, network
- SaphyraDDoS — ddos, web
- hping3 (Packet Crafter / Flooder) — ddos, network
- slowhttptest (Slow-HTTP DoS Tester) — ddos, web
- OWASP Denial of Service Cheat Sheet — ddos, web, reference
🖥 Remote Administrator Tools (RAT)
- Villain (Reverse Shell / C2 Manager) — c2, reverse-shell, post-exploitation, payload
- hoaxshell (HTTP(S) PowerShell Reverse Shell) — reverse-shell, c2, payload, post-exploitation
- Merlin (cross-platform C2) — c2, post-exploitation, reference
- Covenant (.NET C2) — c2, post-exploitation, reference
🧪 XSS Attack Tools
- DalFox (Finder of XSS) — web, xss, scanner, fuzzing
- XSS Payload Generator — web, xss, payload
- Advanced XSS Detection Suite — web, xss, scanner, fuzzing
- kxss (Reflection Finder) — web, xss, scanner, recon
- PortSwigger — XSS Labs — learning, web, xss, reference
- PayloadsAllTheThings — XSS Injection — cheatsheet, reference, xss, web
🖼 Steganography Tools
- SteganoHide — steganography, image, forensics
- Stegseek (fast steganography cracker) — steganography, hash-crack, bruteforce
- stegseek (fast steghide cracker) — steganography, bruteforce, password-attack, image
- zsteg (PNG/BMP LSB detector) — steganography, image, forensics
- outguess (JPEG stego) — steganography, image, forensics
- ExifTool (metadata reader) — steganography, metadata, image, forensics
- Aperi'Solve (all-in-one image stego) — steganography, image, online-service, reference
- StegOnline (in-browser LSB explorer) — steganography, image, online-service
- Futureboy Stegano decoder — steganography, online-service, reference
- stego-toolkit (Docker kit + checklist) — steganography, reference, cheatsheet
🏢 Active Directory Tools
- BloodHound (AD Attack Paths) — active-directory, enumeration, lateral-movement, credentials
- NetExec — nxc (Network Pentesting) — active-directory, network, enumeration, credentials, password-attack
- Impacket (Network Protocol Tools) — active-directory, credentials, network, lateral-movement, kerberos
- Responder (LLMNR/NBT-NS Poisoner) — active-directory, credentials, mitm, sniffing, network, poisoning, relay
- Certipy (AD Certificate Abuse) — active-directory, credentials, privesc, enumeration, adcs
- Kerbrute (Kerberos Brute Force) — active-directory, bruteforce, password-attack, enumeration, credentials, kerberos
- ldapdomaindump (AD LDAP Dumper) — active-directory, enumeration, credentials
- Coercer (Authentication Coercion) — active-directory, relay, privesc, credentials
- PCredz (Credential Extractor) — active-directory, credentials, sniffing, pcap, kerberos
- The Hacker Recipes (AD) — reference, active-directory, learning
☁ Cloud Security Tools
- Prowler (Cloud Security Scanner) — cloud, scanner, vuln-scan
- ScoutSuite (Multi-Cloud Auditing) — cloud, scanner, enumeration
- Pacu (AWS Exploitation Framework) — cloud, exploitation, post-exploitation
- Trivy (Container/K8s Scanner) — scanner, vuln-scan, cloud
- Checkov (IaC Misconfig Scanner) — cloud, scanner, vuln-scan
- HackTricks Cloud (cloud pentest playbook) — reference, cloud, learning
- flaws.cloud (AWS Security Challenge) — learning, cloud, online-service
📱 Mobile Security Tools
- MobSF (Mobile Security Framework) — mobile, apk, vuln-scan, scanner, malware-analysis
- Frida (Dynamic Instrumentation) — mobile, reversing, malware-analysis
- Objection (Mobile Runtime Exploration) — mobile, reversing
- adb (Android Debug Bridge) — mobile, apk
- OWASP MAS (Mobile App Security) — mobile, reference, learning
- Frida CodeShare — mobile, reversing, online-service, reference
✨ Other tools
- MySMS — payload, mobile, apk
- HatCloud(Bypass CloudFlare for IP) — recon, network, dns
- Hash Buster — hash-crack, lookup, online-service, credentials
- Sherlock — osint, recon, enumeration
- SocialScan | Username or Email — osint, recon, email, enumeration
- Pixload — payload, steganography, image
- Gospider — web, crawler, recon
- Terminal Multiplexer — cheatsheet, reference
- Crivo — network, recon
- CyberChef (Cyber Swiss-Army Knife) — reference, online-service
🔑 Password / Hash Cracking
- hashcat (GPU hash cracker) — hash-crack, password-attack, bruteforce
- John the Ripper (jumbo) — hash-crack, password-attack
- hydra (Network Login Cracker) — bruteforce, password-attack, credentials, network
- CrackStation (online lookup) — hash-crack, online-service, lookup
- hashes.com (hash identifier + lookup) — hash-crack, online-service, lookup
- CyberChef (the cyber swiss-army knife) — online-service, reference
- GTFOBins (unix binary abuse) — privesc, reference, cheatsheet
Adding a tool
Most tools are one YAML entry in src/hackingtool/catalog/ — no Python. See
CONTRIBUTING.md for the entry format, the tag taxonomy, and
the checks your PR has to pass (make check).
Can't find what you need? Ask the console: /find <what you're trying to do>
searches the catalog first, then GitHub, and shows real maintained repos with the
reason each was ranked. See HOW-TO-USE.md.