Z4nzu/hackingtool
Summary
hackingtool v2.0.0 is a Python 3.10+ CLI that bundles 185+ security tools across 20 categories with search, tagging, batch install and Docker support for pentesters and researchers.
View Cached Full Text
Cached at: 04/22/26, 02:55 PM
Z4nzu/hackingtool
Source: https://github.com/Z4nzu/hackingtool
What’s New in v2.0.0
|
Quick Commands
| Command | Action | Works in |
|---|---|---|
/query | Search — find tools instantly by keyword | Main menu |
t | Tags — filter by osint, scanner, c2, cloud, mobile… | Main menu |
r | Recommend — “I want to do X” → matching tools | Main menu |
? | Help — quick reference card | Everywhere |
q | Quit — exit from any depth | Everywhere |
97 | Install All — batch install all tools in category | Category |
99 | Back — return to previous menu | Everywhere |
Tool Categories
| # | Category | Tools | # | Category | Tools | |
|---|---|---|---|---|---|---|
| 1 | 🛡 Anonymously Hiding | 2 | 11 | 🧰 Exploit Framework | 4 | |
| 2 | 🔍 Information Gathering | 26 | 12 | 🔁 Reverse Engineering | 5 | |
| 3 | 📚 Wordlist Generator | 7 | 13 | ⚡ DDOS Attack | 5 | |
| 4 | 📶 Wireless Attack | 13 | 14 | 🖥 RAT | 1 | |
| 5 | 🧩 SQL Injection | 7 | 15 | 💥 XSS Attack | 9 | |
| 6 | 🎣 Phishing Attack | 17 | 16 | 🖼 Steganography | 4 | |
| 7 | 🌐 Web Attack | 20 | 17 | 🏢 Active Directory | 6 | |
| 8 | 🔧 Post Exploitation | 10 | 18 | ☁ Cloud Security | 4 | |
| 9 | 🕵 Forensics | 8 | 19 | 📱 Mobile Security | 3 | |
| 10 | 📦 Payload Creation | 8 | 20 | ✨ Other Tools | 24 |
🛡 Anonymously Hiding Tools
🔍 Information Gathering Tools
- Network Map (nmap)
- Dracnmap
- Port scanning
- Host to IP
- Xerosploit
- RED HAWK
- ReconSpider
- IsItDown
- Infoga
- ReconDog
- Striker
- SecretFinder
- Shodanfy
- rang3r
- Breacher
- theHarvester ★
- Amass ★
- Masscan ★
- RustScan ★
- Holehe ★
- Maigret ★
- httpx ★
- SpiderFoot ★
- Subfinder ★
- TruffleHog ★
- Gitleaks ★
📚 Wordlist Generator
📶 Wireless Attack Tools
- WiFi-Pumpkin
- pixiewps
- Bluetooth Honeypot (bluepot)
- Fluxion
- Wifiphisher
- Wifite
- EvilTwin
- Fastssh
- Howmanypeople
- Airgeddon ★
- hcxdumptool ★
- hcxtools ★
- Bettercap ★
🧩 SQL Injection Tools
🎣 Phishing Attack Tools
- Autophisher
- PyPhisher
- AdvPhishing
- Setoolkit
- SocialFish
- HiddenEye
- Evilginx3
- I-See-You
- SayCheese
- QR Code Jacking
- BlackEye
- ShellPhish
- Thanos
- QRLJacking
- Maskphish
- BlackPhish
- dnstwist
🌐 Web Attack Tools
- Web2Attack
- Skipfish
- Sublist3r
- CheckURL
- Sub-Domain TakeOver
- Dirb
- Nuclei ★
- ffuf ★
- Feroxbuster ★
- Nikto ★
- wafw00f ★
- Katana ★
- Gobuster ★
- Dirsearch ★
- OWASP ZAP ★
- testssl.sh ★
- Arjun ★
- Caido ★
- mitmproxy ★
🔧 Post Exploitation Tools
- Vegile
- Chrome Keylogger
- pwncat-cs ★
- Sliver ★
- Havoc ★
- PEASS-ng (LinPEAS/WinPEAS) ★
- Ligolo-ng ★
- Chisel ★
- Evil-WinRM ★
- Mythic ★
🕵 Forensic Tools
- Autopsy
- Wireshark
- Bulk extractor
- Guymager
- Toolsley
- Volatility 3 ★
- Binwalk ★
- pspy ★
📦 Payload Creation Tools
🧰 Exploit Framework
🔁 Reverse Engineering Tools
⚡ DDOS Attack Tools
🖥 Remote Administrator Tools (RAT)
💥 XSS Attack Tools
🖼 Steganography Tools
- SteganoHide
- StegoCracker
- Whitespace
🏢 Active Directory Tools
- BloodHound ★
- NetExec (nxc) ★
- Impacket ★
- Responder ★
- Certipy ★
- Kerbrute ★
☁ Cloud Security Tools
- Prowler ★
- ScoutSuite ★
- Pacu ★
- Trivy ★
📱 Mobile Security Tools
✨ Other Tools
SocialMedia Bruteforce
Android Hacking Tools
IDN Homograph Attack
Email Verify Tools
Hash Cracking Tools
Wifi Deauthenticate
SocialMedia Finder
Payload Injector
Web Crawling
Mix Tools
- Terminal Multiplexer (tilix)
- Crivo
Contributing — Add a New Tool
Open an Issue
Use the Tool Request template. Required: tool name, GitHub URL, category, OS, install command, reason. |
Open a Pull Request
Use the PR template checklist. Required: class in |
Issues or PRs that don’t follow the title format will be closed without review.
Installation
One-liner (recommended)
Handles everything — prerequisites, clone, venv, launcher. |
Manual
Then run: |
Docker
# Build
docker build -t hackingtool .
# Run (direct)
docker run -it --rm hackingtool
# Run (Compose — recommended)
docker compose up -d
docker exec -it hackingtool bash
# Dev mode (live source mount)
docker compose --profile dev up
docker exec -it hackingtool-dev bash
# Stop
docker compose down # stop container
docker compose down -v # also remove data volume
Requirements
| Dependency | Version | Needed for |
|---|---|---|
| Python | 3.10+ | Core |
| Go | 1.21+ | nuclei, ffuf, amass, httpx, katana, dalfox, gobuster, subfinder |
| Ruby | any | haiti, evil-winrm |
| Docker | any | Mythic, MobSF (optional) |
pip install -r requirements.txt
Star History
Support
If this project helps you, consider buying me a coffee:
Social
For authorized security testing only. Thanks to all original authors of the tools included in hackingtool.
Your favourite tool is not listed? Suggest it here
Similar Articles
@durdom_evm: found a security repo that's absolutely unhinged hundreds of pentesting tools, checklists, guides, all stacked in one p…
A comprehensive, open-source penetration-testing knowledge base aggregating hundreds of tools, checklists, and guides across 23 security domains, hosted on GitHub.
@josesilesdata: GOODBYE TO CYBERSECURITY! A repository just came out with hundreds of AI security tools in an open-source repository. T…
An open-source repository containing hundreds of AI security tools has been released, featuring techniques for jailbreaking LLMs, prompt injection testing, red team agents, model extraction, and automated pentesting.
@yhslgg: https://x.com/yhslgg/status/2068317116831510838
Introduces the combined use ideas of five free and open-source OSINT tools (Blackbird, Maigret, SpiderFoot, theHarvester, Shodan Python), covering scenarios such as people search, company search, device search, and provides practical cases and installation methods.
Hackers can use 9 of the most popular AI tools to assemble massive botnets
Researchers have devised a pull-based prompt injection attack called HalluSquatting that exploits AI coding assistants' tendency to hallucinate resource identifiers, enabling the assembly of massive botnets and large-scale attacks.
Terminal Wrench: A Dataset of 331 Reward-Hackable Environments and 3,632 Exploit Trajectories
Researchers release Terminal Wrench, a dataset of 331 reward-hackable terminal environments with 3,632 exploit trajectories spanning sysadmin, ML, and security tasks.
