Information gathering
No tool matches.
-
0tracehome
Runs a traceroute inside an already-open TCP connection so intermediate hops show up when ICMP is filtered.
-
arpinghome
Sends ARP requests on the local link to see which MAC claims an IP when ICMP is filtered.
help
ARPing 2.29, by Thomas Habets <thomas@habets.se> usage: arping [ -0aAbdDeFpPqrRuUvzZ ] [ -w <sec> ] [ -W <sec> ] [ -S <host/ip> ] [ -T <host/ip ] [ -s <MAC> ] [ -t <MAC> ] [ -c <count> ] [ -C <count> ] [ -i <interface> ] [ -m <type> ] [ -g <group> ] [ -V <vlan> ] [ -Q <priority> ] <host/ip/MAC | -B> Options: -0 Use this option to ping with source IP address 0.0.0.0. Use this when you haven't configured your interface yet. Note that this may get the MAC-ping unanswered. This is an alias for -S 0.0.0.0. -a Audiable ping. -A Only count addresses matching requested address (This *WILL* break most things you do. Only useful if you are arpinging many hosts at once. See arping-scan-net.sh for an example). -b Like -0 but source broadcast source address (255.255.255.255). Note that this may get the arping unanswered since it's not nor- mal behavior for a host. -B Use instead of host if you want to address 255.255.255.255. -c count Only send count requests. -C count Only wait for this many replies, regardless of -c and -w. -d Find duplicate replies. Exit with 1 if there are answers from two different MAC addresses. -D Display answers as exclamation points and missing packets as dots. -e Like -a but beep when there is no reply. -F Don't try to be smart about the interface name. (even if this switch is not given, -i overrides smartness) -g group setgid() to this group instead of the nobody group. -h Displays a help message and exits. -i interface Use the specified interface. -m type Type of timestamp to use for incoming packets. Use -vv when pinging to list available ones. -q Does not display messages, except error messages. -Q pri 802.1p priority to set. Should be used with 802.1Q (-V). Defaults to 0. -r Raw output: only the MAC/IP address is displayed for each reply. -R Raw output: Like -r but shows "the other one", can be combined with -r. -s MAC Set source MAC address. You may need to use -p with this. … (28 more lines — see the tool's home page) -
braahome
Mass SNMP walker for querying many agents quickly once communities are known and authorized.
-
dmitryhome
Deepmagic info-gathering for whois, emails, subdomains, and port hints from a single host or domain name.
help
dmitry: invalid option -- 'h' Deepmagic Information Gathering Tool "There be some deep magic going on" Usage: dmitry [-winsepfb] [-t 0-9] [-o %host.txt] host -o Save output to %host.txt or to file specified by -o file -i Perform a whois lookup on the IP address of a host -w Perform a whois lookup on the domain name of a host -n Retrieve Netcraft.com information on a host -s Perform a search for possible subdomains -e Perform a search for possible email addresses -p Perform a TCP port scan on a host * -f Perform a TCP port scan on a host showing output reporting filtered ports * -b Read in the banner received from the scanned port * -t 0-9 Set the TTL in seconds when scanning a TCP port ( Default 2 ) *Requires the -p flagged to be passed -
dnsenumhome
Walks DNS for a domain: records, transfers when allowed, and name guesses that expand your map before you touch an app.
help
dnsenum VERSION:1.3.1 Usage: dnsenum [Options] <domain> [Options]: Note: If no -f tag supplied will default to /usr/share/dnsenum/dns.txt or the dns.txt file in the same directory as dnsenum GENERAL OPTIONS: --dnsserver <server> Use this DNS server for A, NS and MX queries. --enum Shortcut option equivalent to --threads 5 -s 15 -w. -h, --help Print this help message. --noreverse Skip the reverse lookup operations. --nocolor Disable ANSIColor output. --private Show and save private ips at the end of the file domain_ips.txt. --subfile <file> Write all valid subdomains to this file. -t, --timeout <value> The tcp and udp timeout values in seconds (default: 10s). --threads <value> The number of threads that will perform different queries. -v, --verbose Be verbose: show all the progress and all the error messages. GOOGLE SCRAPING OPTIONS: -p, --pages <value> The number of google search pages to process when scraping names, the default is 5 pages, the -s switch must be specified. -s, --scrap <value> The maximum number of subdomains that will be scraped from Google (default 15). BRUTE FORCE OPTIONS: -f, --file <file> Read subdomains from this file to perform brute force. (Takes priority over default dns.txt) -u, --update <a|g|r|z> Update the file specified with the -f switch with valid subdomains. a (all) Update using all results. g Update using only google scraping results. r Update using only reverse lookup results. z Update using only zonetransfer results. -r, --recursion Recursion on subdomains, brute force all discovered subdomains that have an NS record. WHOIS NETRANGE OPTIONS: -d, --delay <value> The maximum value of seconds to wait between whois queries, the value is defined randomly, default: 3s. -w, --whois Perform the whois queries on c class network ranges. **Warning**: this can generate very large netranges and it will take lot of time to perform reverse lookups. REVERSE LOOKUP OPTIONS: -e, --exclude <regexp> Exclude PTR records that match the regexp expression from reverse lookup results, useful on invalid hostnames. OUTPUT OPTIONS: -o --output <file> Output in XML format. Can be imported in MagicTree (www.gremwell.com) -
dnsmaphome
Brute-forces DNS names under a domain from a wordlist so hidden hosts show up beside the ones in public records.
help
dnsmap 0.36 - DNS Network Mapper [+] error: entered domain is not valid! -
dnsreconhome
DNS enumeration helper for records, zone transfer attempts, and common name patterns.
help
usage: dnsrecon [-h] [-d DOMAIN] [-iL INPUT_LIST] [-n NS_SERVER] [-r RANGE] [-D DICTIONARY] [-f] [-a] [-s] [-b] [-y] [-k] [-w] [--shodan] [--shodan-active] [--shodan-key SHODAN_KEY] [-z] [--threads THREADS] [--lifetime LIFETIME] [--loglevel {DEBUG,INFO,WARNING,ERROR,CRITICAL}] [--tcp] [--db DB] [-x XML] [-c CSV] [-j JSON] [--iw] [--disable_check_nxdomain] [--disable_check_recursion] [--disable_recurs] [--disable_check_bindversion] [-V] [-v] [-t TYPE] options: -h, --help show this help message and exit -d, --domain DOMAIN Target domain. -iL, --input-list INPUT_LIST File containing a list of domains to perform DNS enumeration on, one per line. -n, --name_server NS_SERVER Domain server to use. If none is given, the SOA of the target will be used. Multiple servers can be specified using a comma separated list. -r, --range RANGE IP range for reverse lookup brute force in formats (first-last) or in (range/bitmask). -D, --dictionary DICTIONARY Dictionary file of subdomain and hostnames to use for brute force. -f Filter out of brute force domain lookup, records that resolve to the wildcard defined IP address when saving records. -a Perform AXFR with standard enumeration. -s Perform a reverse lookup of IPv4 ranges in the SPF record with standard enumeration. -b Perform Bing enumeration with standard enumeration. -y Perform Yandex enumeration with standard enumeration. -k Perform crt.sh enumeration with standard enumeration. -w Perform deep whois record analysis and reverse lookup of IP ranges found through Whois when doing a standard enumeration. --shodan Use Shodan to query netblocks discovered via SPF (-s) and/or Whois (-w) during standard enumeration. --shodan-active Actively validate Shodan-discovered names by resolving them and confirming they still match the queried netblock. --shodan-key SHODAN_KEY Shodan API key. If omitted, SHODAN_API_KEY environment variable is used. -z Performs a DNSSEC zone walk with standard enumeration. --threads THREADS Number of threads to use in reverse lookups, forward lookups, brute force and SRV record enumeration. --lifetime LIFETIME Time to wait for a server to respond to a query. default is 3.0 --loglevel {DEBUG,INFO,WARNING,ERROR,CRITICAL} Log level to use. default is INFO --tcp Use TCP protocol to make queries. --db DB SQLite 3 file to save found records. -x, --xml XML XML file to save found records. -c, --csv CSV Save output to a comma separated value file. -j, --json JSON save output to a JSON file. --iw Continue brute forcing a domain even if a wildcard record is discovered. --disable_check_nxdomain Disables check for NXDOMAIN hijacking on name servers. --disable_check_recursion … (22 more lines — see the tool's home page) -
dnstracerhome
Follows DNS delegation from the root toward an answer so broken chains become visible.
-
dnswalkhome
Checks zone data via nameserver queries for inconsistencies during DNS review.
-
enum4linuxhome
Talks SMB/NetBIOS to list shares, users, and groups on Windows and Samba hosts during early recon.
help
./enum4linux.pl version [unknown] calling Getopt::Std::getopts (version 1.14 [paranoid]), running under Perl version 5.42.2. Usage: enum4linux.pl [-OPTIONS [-MORE_OPTIONS]] [--] [PROGRAM_ARG1 ...] The following single-character options are accepted: With arguments: -u -p -f -R -s -k -w -K Boolean (without arguments): -U -M -N -S -P -G -l -L -D -d -r -v -A -o -h -n -a -i -P Options may be merged together. -- stops processing of options. Space is not required between options and their arguments. [Now continuing due to backward compatibility and excessive paranoia. See 'perldoc Getopt::Std' about $Getopt::Std::STANDARD_HELP_VERSION.] enum4linux v0.9.1 (http://labs.portcullis.co.uk/application/enum4linux/) Copyright (C) 2011 Mark Lowe (mrl@portcullis-security.com) Simple wrapper around the tools in the samba package to provide similar functionality to enum.exe (formerly from www.bindview.com). Some additional features such as RID cycling have also been added for convenience. Usage: ./enum4linux.pl [options] ip Options are (like "enum"): -U get userlist -M get machine list* -S get sharelist -P get password policy information -G get group and member list -d be detailed, applies to -U and -S -u user specify username to use (default "") -p pass specify password to use (default "") The following options from enum.exe aren't implemented: -L, -N, -D, -f Additional options: -a Do all simple enumeration (-U -S -G -P -r -o -n -i). This option is enabled if you don't provide any other options. -h Display this help message and exit -r enumerate users via RID cycling -R range RID ranges to enumerate (default: 500-550,1000-1050, implies -r) -K n Keep searching RIDs until n consective RIDs don't correspond to a username. Impies RID range ends at 999999. Useful against DCs. -l Get some (limited) info via LDAP 389/TCP (for DCs only) -s file brute force guessing for share names … (20 more lines — see the tool's home page) -
fiercehome
Looks for non-contiguous IP space tied to a domain by DNS brute force and adjacent network guesses.
help
usage: fierce [-h] [--domain DOMAIN] [--connect] [--wide] [--traverse TRAVERSE] [--search SEARCH [SEARCH ...]] [--range RANGE] [--delay DELAY] [--subdomains SUBDOMAINS [SUBDOMAINS ...] | --subdomain-file SUBDOMAIN_FILE] [--dns-servers DNS_SERVERS [DNS_SERVERS ...] | --dns-file DNS_FILE] [--tcp] A DNS reconnaissance tool for locating non-contiguous IP space. options: -h, --help show this help message and exit --domain DOMAIN domain name to test --connect attempt HTTP connection to non-RFC 1918 hosts --wide scan entire class c of discovered records --traverse TRAVERSE scan NUMBER IPs before and after discovered records. This respects Class C boundaries and won't enter adjacent subnets. --search SEARCH [SEARCH ...] filter on these domains when expanding lookup --range RANGE scan an internal IP range, use cidr notation --delay DELAY time to wait between lookups --subdomains SUBDOMAINS [SUBDOMAINS ...] use these subdomains --subdomain-file SUBDOMAIN_FILE use subdomains specified in this file (one per line) --dns-servers DNS_SERVERS [DNS_SERVERS ...] use these dns servers for reverse lookups --dns-file DNS_FILE use dns servers specified in this file for reverse lookups (one per line) --tcp use TCP instead of UDP -
firewalkhome
Uses crafted packets to infer ACL rules on intermediate hops during authorized network mapping.
-
fpinghome
Pings many hosts in parallel to learn which addresses answer before deeper scans.
help
Usage: fping [options] [targets...] Probing options: -4, --ipv4 only ping IPv4 addresses -6, --ipv6 only ping IPv6 addresses -b, --size=BYTES amount of ping data to send, in bytes (default: 56) -B, --backoff=N set exponential backoff factor to N (default: 1.5) -c, --count=N count mode: send N pings to each target -f, --file=FILE read list of targets from a file ( - means stdin) -g, --generate generate target list (only if no -f specified) (give start and end IP in the target list, or a CIDR address) (ex. fping -g 192.168.1.0 192.168.1.255 or fping -g 192.168.1.0/24) -H, --ttl=N set the IP TTL value (Time To Live hops) -I, --iface=IFACE bind to a particular interface -l, --loop loop mode: send pings forever -m, --all use all IPs of provided hostnames (e.g. IPv4 and IPv6), use with -A -M, --dontfrag set the Don't Fragment flag -O, --tos=N set the type of service (tos) flag on the ICMP packets -p, --period=MSEC interval between ping packets to one target (in ms) (in loop and count modes, default: 1000 ms) -r, --retry=N number of retries (default: 3) -R, --random random packet data (to foil link data compression) -S, --src=IP set source address -t, --timeout=MSEC individual target initial timeout (default: 500 ms, except with -l/-c/-C, where it's the -p period up to 2000 ms) Output options: -a, --alive show targets that are alive -A, --addr show targets by address -C, --vcount=N same as -c, report results in verbose format -d, --rdns show targets by name (force reverse-DNS lookup) -D, --timestamp print timestamp before each output line -e, --elapsed show elapsed time on return packets -i, --interval=MSEC interval between sending ping packets (default: 10 ms) -n, --name show targets by name (reverse-DNS lookup for target IPs) -N, --netdata output compatible for netdata (-l -Q are required) -o, --outage show the accumulated outage time (lost packets * packet interval) -q, --quiet quiet (don't show per-target/per-ping results) -Q, --squiet=SECS same as -q, but add interval summary every SECS seconds -s, --stats print final stats -u, --unreach show targets that are unreachable -v, --version show version -x, --reachable=N shows if >=N hosts are reachable or not -
fragrouterhome
Fragmenting IDS evasion router for lab tests against detection gear you own.
-
hping3home
Crafts custom ICMP/TCP/UDP packets for firewall mapping and path tests in a scoped lab.
help
usage: hping3 host [options] -h --help show this help -v --version show version -c --count packet count -i --interval wait (uX for X microseconds, for example -i u1000) --fast alias for -i u10000 (10 packets for second) --faster alias for -i u1000 (100 packets for second) --flood sent packets as fast as possible. Don't show replies. -n --numeric numeric output -q --quiet quiet -I --interface interface name (otherwise default routing interface) -V --verbose verbose mode -D --debug debugging info -z --bind bind ctrl+z to ttl (default to dst port) -Z --unbind unbind ctrl+z --beep beep for every matching packet received Mode default mode TCP -0 --rawip RAW IP mode -1 --icmp ICMP mode -2 --udp UDP mode -8 --scan SCAN mode. Example: hping --scan 1-30,70-90 -S www.target.host -9 --listen listen mode IP -a --spoof spoof source address --rand-dest random destionation address mode. see the man. --rand-source random source address mode. see the man. -t --ttl ttl (default 64) -N --id id (default random) -W --winid use win* id byte ordering -r --rel relativize id field (to estimate host traffic) -f --frag split packets in more frag. (may pass weak acl) -x --morefrag set more fragments flag -y --dontfrag set don't fragment flag -g --fragoff set the fragment offset -m --mtu set virtual mtu, implies --frag if packet size > mtu -o --tos type of service (default 0x00), try --tos help -G --rroute includes RECORD_ROUTE option and display the route buffer --lsrr loose source routing and record route --ssrr strict source routing and record route -H --ipproto set the IP protocol field, only in RAW IP mode ICMP -C --icmptype icmp type (default echo request) -K --icmpcode icmp code (default 0) … (42 more lines — see the tool's home page) -
ike-scanhome
Discovers and fingerprints IKE VPN gateways so you can see which IPsec proposals they offer.
help
Usage: ike-scan [options] [hosts...] Target hosts must be specified on the command line unless the --file option is given, in which case the targets are read from the specified file instead. The target hosts can be specified as IP addresses or hostnames. You can also specify the target as IPnetwork/bits (e.g. 192.168.1.0/24) to specify all hosts in the given network (network and broadcast addresses included), or IPstart-IPend (e.g. 192.168.1.3-192.168.1.27) to specify all hosts in the inclusive range, or IPnetwork:NetMask (e.g. 192.168.1.0:255.255.255.0) to specify all hosts in the given network and mask. These different options for specifying target hosts may be used both on the command line, and also in the file specified with the --file option. In the options below a letter or word in angle brackets like <f> denotes a value or string that should be supplied. The corresponding text should indicate the meaning of this value or string. When supplying the value or string, do not include the angle brackets. Text in square brackets like [<f>] mean that the enclosed text is optional. This is used for options which take an optional argument. Options: --help or -h Display this usage message and exit. --file=<fn> or -f <fn> Read hostnames or addresses from the specified file instead of from the command line. One name or IP address per line. Use "-" for standard input. --sport=<p> or -s <p> Set UDP source port to <p>, default=500, 0=random. Some IKE implementations require the client to use UDP source port 500 and will not talk to other ports. Note that superuser privileges are normally required to use non-zero source ports below 1024. Also only one process on a system may bind to a given source port at any one time. Use of the --nat-t option changes the default source port to 4500 --dport=<p> or -d <p> Set UDP destination port to <p>, default=500. UDP port 500 is the assigned port number for ISAKMP and this is the port used by most if not all IKE implementations. Use of the --nat-t option changes the default destination port to 4500 … (115 more lines — see the tool's home page) -
intracehome
Traceroute that rides an existing TCP connection when ICMP is filtered on the path.
-
iputils-arpinghome
Sends ARP-based reachability probes on the local link when ICMP echo is the wrong question.
-
irpashome
Suite for abusing routing protocol behaviors in labs where you own the routers under test.
-
masscanhome
Very fast Internet-scale TCP port scanner; useful for wide lab ranges when you need coverage first.
help
MASSCAN is a fast port scanner. The primary input parameters are the IP addresses/ranges you want to scan, and the port numbers. An example is the following, which scans the 10.x.x.x network for web servers: masscan 10.0.0.0/8 -p80 The program auto-detects network interface/adapter settings. If this fails, you'll have to set these manually. The following is an example of all the parameters that are needed: --adapter-ip 192.168.10.123 --adapter-mac 00-11-22-33-44-55 --router-mac 66-55-44-33-22-11 Parameters can be set either via the command-line or config-file. The names are the same for both. Thus, the above adapter settings would appear as follows in a configuration file: adapter-ip = 192.168.10.123 adapter-mac = 00-11-22-33-44-55 router-mac = 66-55-44-33-22-11 All single-dash parameters have a spelled out double-dash equivalent, so '-p80' is the same as '--ports 80' (or 'ports = 80' in config file). To use the config file, type: masscan -c <filename> To generate a config-file from the current settings, use the --echo option. This stops the program from actually running, and just echoes the current configuration instead. This is a useful way to generate your first config file, or see a list of parameters you didn't know about. I suggest you try it now: masscan -p1234 --echo -
nbtscanhome
Scans for NetBIOS names on a network segment to learn Windows host names without a full directory yet.
help
"Human-readable service names" (-h) option cannot be used without verbose (-v) option. Usage: nbtscan [-v] [-d] [-e] [-l] [-t timeout] [-b bandwidth] [-r] [-q] [-s separator] [-m retransmits] (-f filename)|(<scan_range>) -v verbose output. Print all names received from each host -d dump packets. Print whole packet contents. -e Format output in /etc/hosts format. -l Format output in lmhosts format. Cannot be used with -v, -s or -h options. -t timeout wait timeout milliseconds for response. Default 1000. -b bandwidth Output throttling. Slow down output so that it uses no more that bandwidth bps. Useful on slow links, so that ougoing queries don't get dropped. -r use local port 137 for scans. Win95 boxes respond to this only. You need to be root to use this option on Unix. -q Suppress banners and error messages, -s separator Script-friendly output. Don't print column and record headers, separate fields with separator. -h Print human-readable names for services. Can only be used with -v option. -m retransmits Number of retransmits. Default 0. -f filename Take IP addresses to scan from file filename. -f - makes nbtscan take IP addresses from stdin. <scan_range> what to scan. Can either be single IP like 192.168.1.1 or range of addresses in one of two forms: xxx.xxx.xxx.xxx/xx or xxx.xxx.xxx.xxx-xxx. Examples: nbtscan -r 192.168.1.0/24 Scans the whole C-class network. nbtscan 192.168.1.25-137 Scans a range from 192.168.1.25 to 192.168.1.137 nbtscan -v -s : 192.168.1.0/24 Scans C-class network. Prints results in script-friendly format using colon as field separator. Produces output like that: 192.168.0.1:NT_SERVER:00U 192.168.0.1:MY_DOMAIN:00G 192.168.0.1:ADMINISTRATOR:03U 192.168.0.2:OTHER_BOX:00U ... nbtscan -f iplist … (1 more lines — see the tool's home page) -
ncathome
Nmap's netcat reimplementation for listeners, connects, SSL, and simple data transfer.
help
Ncat 7.99 ( https://nmap.org/ncat ) Usage: ncat [options] [hostname] [port] Options taking a time assume seconds. Append 'ms' for milliseconds, 's' for seconds, 'm' for minutes, or 'h' for hours (e.g. 500ms). -4 Use IPv4 only -6 Use IPv6 only -U, --unixsock Use Unix domain sockets only --vsock Use vsock sockets only -C, --crlf Use CRLF for EOL sequence -c, --sh-exec <command> Executes the given command via /bin/sh -e, --exec <command> Executes the given command --lua-exec <filename> Executes the given Lua script -g hop1[,hop2,...] Loose source routing hop points (8 max) -G <n> Loose source routing hop pointer (4, 8, 12, ...) -m, --max-conns <n> Maximum <n> simultaneous connections -h, --help Display this help screen -d, --delay <time> Wait between read/writes -o, --output <filename> Dump session data to a file -x, --hex-dump <filename> Dump session data as hex to a file -i, --idle-timeout <time> Idle read/write timeout -p, --source-port port Specify source port to use -s, --source addr Specify source address to use (doesn't affect -l) -l, --listen Bind and listen for incoming connections -k, --keep-open Accept multiple connections in listen mode -n, --nodns Do not resolve hostnames via DNS -t, --telnet Answer Telnet negotiations -u, --udp Use UDP instead of default TCP --sctp Use SCTP instead of default TCP -v, --verbose Set verbosity level (can be used several times) -w, --wait <time> Connect timeout -z Zero-I/O mode, report connection status only --append-output Append rather than clobber specified output files --send-only Only send data, ignoring received; quit on EOF --recv-only Only receive data, never send anything --no-shutdown Continue half-duplex when receiving EOF on stdin -q <time> After EOF on stdin, wait <time> then quit. --allow Allow only given hosts to connect to Ncat --allowfile A file of hosts allowed to connect to Ncat --deny Deny given hosts from connecting to Ncat --denyfile A file of hosts denied from connecting to Ncat --broker Enable Ncat's connection brokering mode --chat Start a simple Ncat chat server --proxy <addr[:port]> Specify address of host to proxy through --proxy-type <type> Specify proxy type ("http", "socks4", "socks5") … (13 more lines — see the tool's home page) -
netdiscoverhome
Active/passive ARP reconnaissance for finding live hosts on a local network.
help
Netdiscover 0.21 [Active/passive ARP reconnaissance tool] Written by: Jaime Penalba <jpenalbae@gmail.com> Usage: netdiscover [-i device] [-r range | -l file | -p] [-m file] [-F filter] [-s time] [-c count] [-n node] [-dfPLNS] -i device: your network device -r range: scan a given range instead of auto scan. 192.168.6.0/24,/16,/8 -l file: scan the list of ranges contained into the given file -p passive mode: do not send anything, only sniff -m file: scan a list of known MACs and host names -F filter: customize pcap filter expression (default: "arp") -s time: time to sleep between each ARP request (milliseconds) -c count: number of times to send each ARP request (for nets with packet loss) -n node: last source IP octet used for scanning (from 2 to 253) -d ignore home config files for autoscan and fast mode -R assume user is root or has the required capabilities without running any checks -f enable fastmode scan, saves a lot of time, recommended for auto -P print results in a format suitable for parsing by another program and stop after active scan -L similar to -P but continue listening after the active scan is completed -N Do not print header. Only valid when -P or -L is enabled. -S enable sleep time suppression between each request (hardcore mode) If -r, -l or -p are not enabled, netdiscover will scan for common LAN addresses. -
netmaskhome
Helps derive and explain network masks and ranges when scoping or reading address plans.
help
This is netmask, an address netmask generation utility Usage: netmask spec [spec ...] -h, --help Print a summary of the options -v, --version Print the version number -d, --debug Print status/progress information -s, --standard Output address/netmask pairs -c, --cidr Output CIDR format address lists -i, --cisco Output Cisco style address lists -r, --range Output ip address ranges -x, --hex Output address/netmask pairs in hex -o, --octal Output address/netmask pairs in octal -b, --binary Output address/netmask pairs in binary -n, --nodns Disable DNS lookups for addresses -f, --files Treat arguments as input files Definitions: a spec can be any of: address address:address address:+address address/mask an address can be any of: N decimal number 0N octal number 0xN hex number N.N.N.N dotted quad hostname dns domain name a mask is the number of bits set to one from the left -
p0fhome
Passive OS fingerprinting from observed traffic without sending probes of your own.
-
Modular web reconnaissance framework for chaining public-data collectors with a workspace you can export.
help
usage: recon-cli [-h] [-w workspace] [-C command] [-c command] [-G] [-g name=value] [-M] [-m module] [-O] [-o name=value] [-x] [--no-version] [--no-analytics] [--no-marketplace] [--stealth] [--version] [--analytics] recon-cli - Tim Tomes (@lanmaster53) options: -h, --help show this help message and exit -w workspace load/create a workspace -C command runs a command at the global context -c command runs a command at the module context (pre-run) -G show available global options -g name=value set a global option (can be used more than once) -M show modules -m module specify the module -O show available module options -o name=value set a module option (can be used more than once) -x run the module --no-version disable version check. Already disabled by default in Debian --no-analytics disable analytics reporting. Already disabled by default in Debian --no-marketplace disable remote module management --stealth disable all passive requests (--no-*) --version displays the current version --analytics enable analytics reporting. Send analytics to google -
smtp-user-enumhome
Guesses valid users on SMTP services that leak existence via VRFY, EXPN, or RCPT quirks.
help
/usr/bin/smtp-user-enum version [unknown] calling Getopt::Std::getopts (version 1.14 [paranoid]), running under Perl version 5.42.2. Usage: smtp-user-enum [-OPTIONS [-MORE_OPTIONS]] [--] [PROGRAM_ARG1 ...] The following single-character options are accepted: With arguments: -m -u -U -s -S -r -t -T -M -f -D -p -w Boolean (without arguments): -d -v -h Options may be merged together. -- stops processing of options. Space is not required between options and their arguments. [Now continuing due to backward compatibility and excessive paranoia. See 'perldoc Getopt::Std' about $Getopt::Std::STANDARD_HELP_VERSION.] smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum ) Usage: smtp-user-enum [options] ( -u username | -U file-of-usernames ) ( -t host | -T file-of-targets ) options are: -m n Maximum number of processes (default: 5) -M mode Method to use for username guessing EXPN, VRFY or RCPT (default: VRFY) -u user Check if user exists on remote system -f addr MAIL FROM email address. Used only in "RCPT TO" mode (default: user@example.com) -D dom Domain to append to supplied user list to make email addresses (Default: none) Use this option when you want to guess valid email addresses instead of just usernames e.g. "-D example.com" would guess foo@example.com, bar@example.com, etc. Instead of simply the usernames foo and bar. -U file File of usernames to check via smtp service -t host Server host running smtp service -T file File of hostnames running the smtp service -p port TCP port on which smtp service runs (default: 25) -d Debugging output -w n Wait a maximum of n seconds for reply (default: 5) -v Verbose -h This help message Also see smtp-user-enum-user-docs.pdf from the smtp-user-enum tar ball. Examples: $ smtp-user-enum -M VRFY -U users.txt -t 10.0.0.1 $ smtp-user-enum -M EXPN -u admin1 -t 10.0.0.1 $ smtp-user-enum -M RCPT -U users.txt -T mail-server-ips.txt $ smtp-user-enum -M EXPN -D example.com -U users.txt -t 10.0.0.1 -
Enumerates an SNMP agent once you have a community string: interfaces, processes, and software claims.
help
snmp-check v1.9 - SNMP enumerator Copyright (c) 2005-2015 by Matteo Cantoni (www.nothink.org) Usage: snmp-check [OPTIONS] <target IP address> -p --port : SNMP port. Default port is 161; -c --community : SNMP community. Default is public; -v --version : SNMP version (1,2c). Default is 1; -w --write : detect write access (separate action by enumeration); -d --disable_tcp : disable TCP connections enumeration! -t --timeout : timeout in seconds. Default is 5; -r --retries : request retries. Default is 1; -i --info : show script version; -h --help : show help menu; -
socathome
Multipurpose relay for sockets, files, and pipes; handy for simple listeners and port forwards.
help
socat - Multipurpose relay Usage: socat [options] <address> <address> -
swakshome
SMTP Swiss army knife for crafting test mail transactions when email paths are in scope.
help
SWAKS(1) SWAKS SWAKS(1) NAME Swaks - Swiss Army Knife SMTP, the all-purpose SMTP transaction tester DESCRIPTION Swaks' primary design goal is to be a flexible, scriptable, transaction- oriented SMTP test tool. It handles SMTP features and extensions such as TLS, authentication, and pipelining; multiple version of the SMTP protocol including SMTP, ESMTP, and LMTP; and multiple transport methods including UNIX-domain sockets, internet-domain sockets, and pipes to spawned processes. Options can be specified in environment variables, configura‐ tion files, and the command line allowing maximum configurability and ease of use for operators and scripters. QUICK START Deliver a standard test email to user@example.com on port 25 of test-server.example.net: swaks --to user@example.com --server test-server.example.net Deliver a standard test email, requiring CRAM-MD5 authentication as user me@example.com. An "X-Test" header will be added to the email body. The authentication password will be prompted for if it cannot be obtained from your .netrc file. swaks --to user@example.com --from me@example.com --auth CRAM-MD5 --auth-user me@example.com --header-X-Test "test email" Test a virus scanner using EICAR in an attachment. Don't show the message DATA part.: swaks -t user@example.com --attach - --server test-server.example.com --suppress-data </path/to/eicar.txt Test a spam scanner using GTUBE in the body of an email, routed via the MX records for example.com: swaks --to user@example.com --body @/path/to/gtube/file Deliver a standard test email to user@example.com using the LMTP protocol via a UNIX domain socket file swaks --to user@example.com --socket /var/lda.sock --protocol LMTP Report all the recipients in a text file that are non-verifiable on a test server: … (115 more lines — see the tool's home page) -
IPv6 attack and discovery toolkit from THC for labs that actually route v6.
help
Error: neither a valid mac, IPv4 or IPv6 address -
Collects emails, names, and subdomains from public sources so OSINT starts from what the internet already admits.
help
usage: restfulHarvest [-h] [-H HOST] [-p PORT] [-l LOG_LEVEL] [-r] [--rate-limit RATE_LIMIT] options: -h, --help show this help message and exit -H, --host HOST IP address to listen on default is 127.0.0.1 -p, --port PORT Port to bind the web server to, default is 5000 -l, --log-level LOG_LEVEL Set logging level, default is info but [critical|error|warning|info|debug|trace] can be set -r, --reload Enable automatic reload used during development of the api --rate-limit RATE_LIMIT Set API rate limit (e.g., "10/minute", "100/hour"), default is 5/minute -
Userland asynchronous scanner for flexible TCP/UDP probing when you need alternate timing models.
help
FantaIP by Kiki Usage: fantaip (options) IP -d Detach from terminal and daemonize -H Hardware address like XX:XX:XX:XX:XX:XX (otherwise use nics hwaddr) -h help -i *interface -v verbose operation *: Argument required Example: fantaip -i eth0 192.168.1.7 -
urlcrazyhome
Generates domain typos and lookalikes to hunt phishing or brand-abuse registrations.
-
zenmaphome
Graphical front end for nmap when you want topology views and saved scan profiles instead of only CLI output.
Where an authored purpose exists, it is written for this path. Otherwise you see the package summary. Help text is captured live from a Kali system where available.