Ethical Hacking Tools List

 


Reconnaissance Tools


NetScan Pro - Network Discovery & Security Tool

An interactive Bash-based network scanning tool that provides live host discovery, port scanning, traceroute, and ping tests, featuring visually appealing ASCII banners and fun messages.

Github Link


XSS Automation Script

This Bash script automates the process of collecting and analyzing domain reconnaissance data. It is designed for bug bounty hunting and penetration testing, utilizing various tools to gather URLs, subdomains, and potential XSS vulnerabilities for a given domain.

Github Link


XSS scanner

Dalfox is a powerful open-source XSS scanner and utility focused on automation.

Github Link


XSStrike

Most advanced XSS scanner.

Github Link


DOM based XSS

A fast DOM based XSS vulnerability scanner with simplicity.

Github Link


XSSFUZZ 

A tool for detecting XSS vulnerabilities in web applications.

Github Link


Web Application Firewall (WAF) Testing

A lightweight toolkit for testing Web Application Firewall (WAF) effectiveness and identifying security gaps. This repository is available as a template that you can quickly customize for your own WAF testing needs.

Github Link


Web Application Firewall WAF Identifier

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Github Link


Osintgram 

Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname

Github Link 


Exploit Tools


Android RATs

Very good and stable Android RATs. They are easy to use and they are very stable

Github Link


Router Vulnerability Scan Tool

Tool able to check the security level of a router.

Github Link


Web Backdoor Tools


Alfa Shell

Backdoor PHP shell script.

Github Link


Phishing Simulation 


Zphisher 

An automated phishing tool with 30+ templates. This Tool is made for educational purpose only ! Author will not be responsible for any misuse of this toolkit !

Github Link


Evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

Github Link



Comments