twotwo22/Ultimate-Offensive-Red-Team
Ultimate Red Team AI Training Dataset 💀 Dataset Description A comprehensive dataset for training AI models in offensive security, red team operations, and penetration testing. This dataset combines real-world vulnerability data, exploitation techniques, and operational frameworks to create an AI capable of autonomous red team operations. Dataset Summary Total Data Points: 550,000+ unique security-related entries Categories: 15+ major security… See the full description on the dataset page: https://huggingface.co/datasets/twotwo22/Ultimate-Offensive-Red-Team.
026
1{2 "tools": {3 "kali_tools": {4 "penetration_testing_methodologies.json": {5 "penetration_testing_phases": {6 "1_reconnaissance": {7 "description": "Information gathering about the target",8 "passive_recon": {9 "description": "Gathering information without direct interaction",10 "tools": [11 "theharvester",12 "shodan",13 "recon-ng",14 "maltego"15 ],16 "workflow": [17 "1. Start with OSINT using TheHarvester for emails/subdomains",18 "2. Use Shodan for exposed services",19 "3. Employ Recon-ng for comprehensive OSINT",20 "4. Map relationships with Maltego"21 ]22 },23 "active_recon": {24 "description": "Direct interaction with target systems",25 "tools": [26 "nmap",27 "masscan",28 "dnsenum",29 "fierce"30 ],31 "workflow": [32 "1. DNS enumeration with dnsenum/fierce",33 "2. Port scanning with Nmap for detailed info",34 "3. Use Masscan for large network ranges",35 "4. Service version detection with Nmap scripts"36 ]37 }38 },39 "2_scanning": {40 "description": "Identifying live systems, open ports, and services",41 "network_scanning": {42 "tools": [43 "nmap",44 "masscan",45 "unicornscan"46 ],47 "workflow": [48 "1. Ping sweep to identify live hosts",49 "2. Port scanning (TCP/UDP)",50 "3. Service enumeration",51 "4. OS fingerprinting"52 ]53 },54 "vulnerability_scanning": {55 "tools": [56 "openvas",57 "nessus",58 "nikto"59 ],60 "workflow": [61 "1. Configure vulnerability scanner",62 "2. Run authenticated scans when possible",63 "3. Prioritize findings by severity",64 "4. Validate scanner results manually"65 ]66 }67 },68 "3_enumeration": {69 "description": "Extracting detailed information from identified services",70 "service_enumeration": {71 "smb": {72 "tools": [73 "enum4linux",74 "smbclient",75 "rpcclient"76 ],77 "commands": [78 "enum4linux -a target",79 "smbclient -L //target",80 "rpcclient -U '' target"81 ]82 },83 "web": {84 "tools": [85 "dirb",86 "gobuster",87 "ffuf",88 "nikto"89 ],90 "commands": [91 "gobuster dir -u http://target -w wordlist.txt",92 "ffuf -w wordlist.txt -u http://target/FUZZ",93 "nikto -h http://target"94 ]95 },96 "dns": {97 "tools": [98 "dnsrecon",99 "dnsenum",100 "fierce"101 ],102 "commands": [103 "dnsrecon -d target.com",104 "dnsenum target.com",105 "fierce --domain target.com"106 ]107 }108 }109 },110 "4_vulnerability_assessment": {111 "description": "Identifying and prioritizing vulnerabilities",112 "automated_scanning": {113 "tools": [114 "openvas",115 "nessus",116 "qualys"117 ],118 "workflow": [119 "1. Configure scan policies",120 "2. Run comprehensive scans",121 "3. Review and validate findings",122 "4. Create prioritized vulnerability list"123 ]124 },125 "manual_testing": {126 "tools": [127 "burpsuite",128 "owasp_zap",129 "sqlmap"130 ],131 "workflow": [132 "1. Proxy web traffic through Burp/ZAP",133 "2. Identify injection points",134 "3. Test for common vulnerabilities",135 "4. Validate with specialized tools"136 ]137 }138 },139 "5_exploitation": {140 "description": "Attempting to exploit identified vulnerabilities",141 "preparation": {142 "tools": [143 "searchsploit",144 "metasploit",145 "exploit-db"146 ],147 "workflow": [148 "1. Search for existing exploits",149 "2. Understand exploit requirements",150 "3. Prepare payload and listener",151 "4. Test in lab environment first"152 ]153 },154 "execution": {155 "tools": [156 "metasploit",157 "custom_exploits",158 "sqlmap"159 ],160 "workflow": [161 "1. Configure exploit parameters",162 "2. Set up listener/handler",163 "3. Execute exploit",164 "4. Verify successful exploitation"165 ]166 }167 },168 "6_post_exploitation": {169 "description": "Actions after gaining initial access",170 "privilege_escalation": {171 "windows": {172 "tools": [173 "winpeas",174 "powersploit",175 "mimikatz"176 ],177 "workflow": [178 "1. Enumerate system information",179 "2. Check for misconfigurations",180 "3. Look for stored credentials",181 "4. Exploit identified weaknesses"182 ]183 },184 "linux": {185 "tools": [186 "linpeas",187 "linenum",188 "linux-exploit-suggester"189 ],190 "workflow": [191 "1. Check sudo privileges",192 "2. Search for SUID binaries",193 "3. Enumerate running services",194 "4. Check for kernel exploits"195 ]196 }197 },198 "persistence": {199 "tools": [200 "metasploit",201 "empire",202 "covenant"203 ],204 "techniques": [205 "Registry modifications",206 "Scheduled tasks",207 "Service creation",208 "Backdoor accounts"209 ]210 },211 "lateral_movement": {212 "tools": [213 "psexec",214 "wmiexec",215 "evil-winrm"216 ],217 "techniques": [218 "Pass-the-hash",219 "Pass-the-ticket",220 "RDP hijacking",221 "SSH pivoting"222 ]223 }224 },225 "7_reporting": {226 "description": "Documenting findings and recommendations",227 "tools": [228 "dradis",229 "faraday",230 "serpico"231 ],232 "components": [233 "Executive summary",234 "Technical findings",235 "Risk ratings",236 "Remediation recommendations",237 "Evidence and screenshots"238 ]239 }240 },241 "attack_scenarios": {242 "web_application_testing": {243 "methodology": "OWASP Testing Guide",244 "phases": {245 "information_gathering": {246 "tools": [247 "burpsuite",248 "dirb",249 "gobuster"250 ],251 "tasks": [252 "Spider the application",253 "Identify entry points",254 "Map application structure"255 ]256 },257 "authentication_testing": {258 "tools": [259 "burpsuite",260 "hydra",261 "wfuzz"262 ],263 "tests": [264 "Password brute-force",265 "Session management",266 "Password reset flaws"267 ]268 },269 "injection_testing": {270 "tools": [271 "sqlmap",272 "commix",273 "burpsuite"274 ],275 "types": [276 "SQL injection",277 "Command injection",278 "LDAP injection",279 "XPath injection"280 ]281 },282 "client_side_testing": {283 "tools": [284 "burpsuite",285 "beef",286 "owasp_zap"287 ],288 "tests": [289 "XSS testing",290 "CSRF testing",291 "Clickjacking",292 "DOM-based vulnerabilities"293 ]294 }295 }296 },297 "network_penetration_testing": {298 "external_assessment": {299 "tools": [300 "nmap",301 "metasploit",302 "hydra"303 ],304 "workflow": [305 "1. External reconnaissance",306 "2. Perimeter scanning",307 "3. Service exploitation",308 "4. Post-exploitation from DMZ"309 ]310 },311 "internal_assessment": {312 "tools": [313 "responder",314 "bloodhound",315 "mimikatz"316 ],317 "workflow": [318 "1. Network discovery",319 "2. Credential harvesting",320 "3. Privilege escalation",321 "4. Domain compromise"322 ]323 }324 },325 "wireless_assessment": {326 "tools": [327 "aircrack-ng",328 "wifite",329 "reaver"330 ],331 "workflow": [332 "1. Identify wireless networks",333 "2. Capture handshakes/PMKID",334 "3. Attempt WPS attacks",335 "4. Crack captured hashes",336 "5. Test for rogue access points"337 ]338 },339 "social_engineering": {340 "tools": [341 "set",342 "gophish",343 "beef"344 ],345 "attack_vectors": [346 "Phishing emails",347 "Vishing (voice phishing)",348 "Physical access attempts",349 "USB drop attacks",350 "Pretexting scenarios"351 ]352 }353 },354 "tool_combinations": {355 "recon_chain": {356 "description": "Comprehensive reconnaissance workflow",357 "sequence": [358 "theharvester -> Gather emails/subdomains",359 "shodan -> Find exposed services",360 "nmap -> Detailed port scanning",361 "searchsploit -> Find relevant exploits"362 ]363 },364 "web_attack_chain": {365 "description": "Web application attack workflow",366 "sequence": [367 "dirb/gobuster -> Find hidden content",368 "nikto -> Identify vulnerabilities",369 "burpsuite -> Manual testing",370 "sqlmap -> Exploit SQL injection",371 "beef -> Client-side exploitation"372 ]373 },374 "network_attack_chain": {375 "description": "Network compromise workflow",376 "sequence": [377 "nmap -> Service discovery",378 "metasploit -> Exploitation",379 "mimikatz -> Credential extraction",380 "psexec -> Lateral movement",381 "empire -> Command and control"382 ]383 },384 "wireless_attack_chain": {385 "description": "Wireless network attack workflow",386 "sequence": [387 "airmon-ng -> Enable monitor mode",388 "airodump-ng -> Capture packets",389 "aireplay-ng -> Deauth clients",390 "aircrack-ng -> Crack passwords",391 "bettercap -> MITM attacks"392 ]393 }394 }395 },396 "quick_reference.json": {397 "common_commands": {398 "initial_recon": [399 "nmap -sn 192.168.1.0/24 # Host discovery",400 "nmap -sV -sC -O target # Service and OS detection",401 "dirb http://target # Web directory enumeration",402 "nikto -h http://target # Web vulnerability scan"403 ],404 "exploitation": [405 "searchsploit apache 2.4 # Search for exploits",406 "msfconsole # Start Metasploit",407 "sqlmap -u 'http://target/page?id=1' # SQL injection",408 "hydra -l admin -P passwords.txt ssh://target # Brute force"409 ],410 "post_exploitation": [411 "python -c 'import pty;pty.spawn(\"/bin/bash\")' # Spawn TTY",412 "sudo -l # Check sudo privileges",413 "find / -perm -u=s -type f 2>/dev/null # Find SUID binaries",414 "netstat -tulpn # Check network connections"415 ]416 },417 "tool_categories_summary": {418 "information_gathering": 8,419 "vulnerability_analysis": 5,420 "web_application_analysis": 7,421 "password_attacks": 6,422 "wireless_attacks": 4,423 "exploitation_tools": 4,424 "sniffing_spoofing": 5,425 "post_exploitation": 4,426 "forensics": 4,427 "reverse_engineering": 4,428 "reporting": 3429 }430 },431 "kali_tools_comprehensive.json": {432 "metadata": {433 "collection_date": "2025-08-23T15:13:22.808429",434 "version": "2024.1",435 "total_tools": 54,436 "categories": [437 "information_gathering",438 "vulnerability_analysis",439 "web_application_analysis",440 "password_attacks",441 "wireless_attacks",442 "exploitation_tools",443 "sniffing_spoofing",444 "post_exploitation",445 "forensics",446 "reverse_engineering",447 "reporting"448 ]449 },450 "information_gathering": {451 "description": "Tools for reconnaissance and information collection",452 "tools": {453 "nmap": {454 "name": "Nmap",455 "description": "Network exploration tool and security/port scanner",456 "category": "Network Scanner",457 "when_to_use": [458 "Initial reconnaissance phase",459 "Network discovery and mapping",460 "Service and OS detection",461 "Vulnerability scanning",462 "Firewall/IDS evasion testing"463 ],464 "common_commands": {465 "basic_scan": "nmap -sV -sC -O target",466 "stealth_scan": "nmap -sS -T2 target",467 "full_port_scan": "nmap -p- target",468 "udp_scan": "nmap -sU target",469 "script_scan": "nmap --script vuln target",470 "aggressive_scan": "nmap -A target",471 "subnet_scan": "nmap 192.168.1.0/24"472 },473 "use_cases": {474 "network_discovery": "Identify live hosts on a network",475 "port_scanning": "Find open ports and services",476 "os_detection": "Determine operating system versions",477 "vulnerability_assessment": "Identify potential vulnerabilities",478 "compliance_testing": "Verify security configurations"479 },480 "prerequisites": [481 "Network access",482 "Target IP/hostname"483 ],484 "output_formats": [485 "XML",486 "Grepable",487 "Normal",488 "Script Kiddie"489 ],490 "skill_level": "Beginner to Advanced",491 "legal_considerations": "Only scan networks you own or have permission to test"492 },493 "masscan": {494 "name": "Masscan",495 "description": "Fastest Internet port scanner, asynchronous TCP port scanner",496 "category": "Port Scanner",497 "when_to_use": [498 "Large-scale port scanning",499 "Internet-wide surveys",500 "Quick initial reconnaissance",501 "When speed is priority over accuracy"502 ],503 "common_commands": {504 "basic_scan": "masscan -p80,443 192.168.1.0/24",505 "rate_limited": "masscan -p0-65535 target --rate=1000",506 "banner_grab": "masscan -p80 target --banners",507 "output_to_file": "masscan -p22,80,443 target -oX output.xml"508 },509 "use_cases": {510 "rapid_discovery": "Quick identification of open ports",511 "large_networks": "Scanning Class A/B networks",512 "initial_recon": "Fast preliminary scanning"513 },514 "prerequisites": [515 "Root/sudo access",516 "Network connectivity"517 ],518 "skill_level": "Intermediate"519 },520 "recon-ng": {521 "name": "Recon-ng",522 "description": "Full-featured web reconnaissance framework",523 "category": "OSINT Framework",524 "when_to_use": [525 "OSINT gathering",526 "Social media reconnaissance",527 "Domain/IP investigation",528 "Contact harvesting",529 "API-based data collection"530 ],531 "common_commands": {532 "start": "recon-ng",533 "workspace": "workspaces create target_name",534 "modules": "modules search",535 "install_module": "marketplace install module_name",536 "run_module": "modules load module_name; run"537 },538 "modules_categories": [539 "Discovery modules",540 "Exploitation modules",541 "Import modules",542 "Recon modules",543 "Reporting modules"544 ],545 "skill_level": "Intermediate"546 },547 "theharvester": {548 "name": "TheHarvester",549 "description": "E-mail, subdomain and people names harvester",550 "category": "OSINT Tool",551 "when_to_use": [552 "Email address collection",553 "Subdomain enumeration",554 "Employee name gathering",555 "Virtual host discovery"556 ],557 "common_commands": {558 "basic_search": "theharvester -d domain.com -b google",559 "all_sources": "theharvester -d domain.com -b all",560 "limit_results": "theharvester -d domain.com -b google -l 500",561 "save_results": "theharvester -d domain.com -b all -f output"562 },563 "data_sources": [564 "Google",565 "Bing",566 "Baidu",567 "LinkedIn",568 "Twitter",569 "GitHub",570 "Shodan",571 "Hunter.io"572 ],573 "skill_level": "Beginner"574 },575 "shodan": {576 "name": "Shodan",577 "description": "Search engine for Internet-connected devices",578 "category": "IoT/Device Search",579 "when_to_use": [580 "IoT device discovery",581 "Exposed database finding",582 "Vulnerable system identification",583 "Network device enumeration"584 ],585 "common_commands": {586 "init_api": "shodan init API_KEY",587 "host_info": "shodan host IP_ADDRESS",588 "search": "shodan search apache",589 "count": "shodan count apache country:US",590 "download": "shodan download results apache",591 "parse": "shodan parse --fields ip_str,port results.json.gz"592 },593 "search_filters": [594 "port:",595 "country:",596 "hostname:",597 "os:",598 "city:",599 "org:",600 "before:",601 "after:"602 ],603 "skill_level": "Beginner to Intermediate"604 },605 "maltego": {606 "name": "Maltego",607 "description": "Interactive data mining tool for link analysis",608 "category": "OSINT/Link Analysis",609 "when_to_use": [610 "Relationship mapping",611 "Infrastructure analysis",612 "Social network analysis",613 "Threat intelligence gathering"614 ],615 "transform_categories": [616 "DNS transforms",617 "Email transforms",618 "Person transforms",619 "Social media transforms",620 "Infrastructure transforms"621 ],622 "skill_level": "Intermediate to Advanced"623 },624 "dnsenum": {625 "name": "DNSenum",626 "description": "DNS enumeration tool",627 "category": "DNS Enumeration",628 "when_to_use": [629 "DNS record enumeration",630 "Subdomain discovery",631 "Zone transfer attempts",632 "MX record identification"633 ],634 "common_commands": {635 "basic_enum": "dnsenum domain.com",636 "with_threads": "dnsenum --threads 5 domain.com",637 "subdomain_brute": "dnsenum -f wordlist.txt domain.com",638 "save_output": "dnsenum -o output.xml domain.com"639 },640 "skill_level": "Beginner"641 },642 "fierce": {643 "name": "Fierce",644 "description": "DNS reconnaissance tool for locating non-contiguous IP space",645 "category": "DNS Scanner",646 "when_to_use": [647 "IP range discovery",648 "DNS server identification",649 "Subdomain enumeration",650 "Zone transfer testing"651 ],652 "common_commands": {653 "basic_scan": "fierce --domain example.com",654 "dns_server": "fierce --domain example.com --dns-server 8.8.8.8",655 "subdomain_wordlist": "fierce --domain example.com --subdomain-file wordlist.txt"656 },657 "skill_level": "Beginner to Intermediate"658 }659 }660 },661 "vulnerability_analysis": {662 "description": "Tools for identifying and analyzing vulnerabilities",663 "tools": {664 "openvas": {665 "name": "OpenVAS",666 "description": "Full-featured vulnerability scanner",667 "category": "Vulnerability Scanner",668 "when_to_use": [669 "Comprehensive vulnerability assessment",670 "Compliance scanning",671 "Network security audits",672 "Continuous vulnerability monitoring"673 ],674 "scan_types": [675 "Full and fast",676 "Full and deep",677 "Full and very deep",678 "System discovery",679 "Custom scan configs"680 ],681 "features": [682 "50,000+ vulnerability tests",683 "Authenticated scanning",684 "Compliance checking",685 "Report generation"686 ],687 "skill_level": "Intermediate"688 },689 "nikto": {690 "name": "Nikto",691 "description": "Web server scanner",692 "category": "Web Vulnerability Scanner",693 "when_to_use": [694 "Web server misconfiguration detection",695 "Outdated software identification",696 "Dangerous file detection",697 "Initial web app assessment"698 ],699 "common_commands": {700 "basic_scan": "nikto -h http://target.com",701 "ssl_scan": "nikto -h https://target.com -ssl",702 "specific_port": "nikto -h target.com -p 8080",703 "output_html": "nikto -h target.com -o report.html -Format html",704 "tuning_options": "nikto -h target.com -Tuning 123456789"705 },706 "tuning_options": {707 "1": "Interesting files",708 "2": "Misconfiguration",709 "3": "Information disclosure",710 "4": "Injection (XSS/Script/HTML)",711 "5": "Remote file retrieval",712 "6": "Denial of Service",713 "7": "Remote file upload",714 "8": "Command execution",715 "9": "SQL injection"716 },717 "skill_level": "Beginner"718 },719 "wpscan": {720 "name": "WPScan",721 "description": "WordPress vulnerability scanner",722 "category": "CMS Scanner",723 "when_to_use": [724 "WordPress security assessment",725 "Plugin vulnerability detection",726 "Theme vulnerability scanning",727 "User enumeration",728 "Weak password detection"729 ],730 "common_commands": {731 "basic_scan": "wpscan --url http://target.com",732 "enumerate_all": "wpscan --url http://target.com -e ap,at,u",733 "aggressive": "wpscan --url http://target.com --aggressive",734 "password_attack": "wpscan --url http://target.com -U admin -P passwords.txt",735 "api_token": "wpscan --url http://target.com --api-token YOUR_TOKEN"736 },737 "enumeration_options": {738 "p": "Popular plugins",739 "vp": "Vulnerable plugins",740 "ap": "All plugins",741 "t": "Popular themes",742 "vt": "Vulnerable themes",743 "at": "All themes",744 "u": "Users"745 },746 "skill_level": "Beginner to Intermediate"747 },748 "sqlmap": {749 "name": "SQLMap",750 "description": "Automatic SQL injection and database takeover tool",751 "category": "SQL Injection Tool",752 "when_to_use": [753 "SQL injection testing",754 "Database enumeration",755 "Database dumping",756 "Privilege escalation via SQL",757 "OS command execution via SQL"758 ],759 "common_commands": {760 "basic_test": "sqlmap -u 'http://target.com/page.php?id=1'",761 "post_data": "sqlmap -u http://target.com --data='user=admin&pass=pass'",762 "cookie_injection": "sqlmap -u http://target.com --cookie='session=abc123'",763 "dump_database": "sqlmap -u URL -D database --dump",764 "os_shell": "sqlmap -u URL --os-shell",765 "batch_mode": "sqlmap -u URL --batch",766 "risk_level": "sqlmap -u URL --level=5 --risk=3"767 },768 "injection_techniques": {769 "B": "Boolean-based blind",770 "E": "Error-based",771 "U": "Union query-based",772 "S": "Stacked queries",773 "T": "Time-based blind",774 "Q": "Inline queries"775 },776 "skill_level": "Intermediate to Advanced"777 },778 "bed": {779 "name": "BED",780 "description": "Buffer overflow detection tool",781 "category": "Fuzzer",782 "when_to_use": [783 "Buffer overflow testing",784 "Protocol fuzzing",785 "Service crash testing"786 ],787 "skill_level": "Advanced"788 }789 }790 },791 "web_application_analysis": {792 "description": "Tools for analyzing and testing web applications",793 "tools": {794 "burpsuite": {795 "name": "Burp Suite",796 "description": "Integrated platform for web application security testing",797 "category": "Web App Testing Platform",798 "when_to_use": [799 "Manual web app testing",800 "Automated scanning",801 "API testing",802 "Session manipulation",803 "Custom exploit development"804 ],805 "key_features": [806 "Proxy interceptor",807 "Scanner (Pro version)",808 "Intruder for fuzzing",809 "Repeater for manual testing",810 "Sequencer for randomness testing",811 "Decoder/Encoder",812 "Extender for plugins"813 ],814 "common_workflows": {815 "intercept_modify": "Proxy -> Intercept -> Modify -> Forward",816 "scanning": "Target -> Scan -> Review issues",817 "fuzzing": "Send to Intruder -> Configure positions -> Start attack",818 "session_testing": "Send to Repeater -> Modify -> Send"819 },820 "skill_level": "Intermediate to Advanced"821 },822 "owasp_zap": {823 "name": "OWASP ZAP",824 "description": "Zed Attack Proxy - Free web app security scanner",825 "category": "Web App Scanner",826 "when_to_use": [827 "Automated security testing",828 "CI/CD integration",829 "API security testing",830 "Passive scanning during browsing"831 ],832 "scan_modes": {833 "safe": "Passive scanning only",834 "protected": "Scanner won't attack certain URLs",835 "standard": "Active and passive scanning",836 "attack": "Full attack mode"837 },838 "common_commands": {839 "gui_mode": "zaproxy",840 "daemon_mode": "zap.sh -daemon -port 8080",841 "quick_scan": "zap.sh -quickurl http://target.com",842 "api_scan": "zap.sh -cmd -quickurl http://api.target.com"843 },844 "skill_level": "Beginner to Intermediate"845 },846 "dirb": {847 "name": "DIRB",848 "description": "Web content scanner for hidden directories and files",849 "category": "Directory Brute-forcer",850 "when_to_use": [851 "Hidden directory discovery",852 "Backup file detection",853 "Admin panel finding",854 "Configuration file discovery"855 ],856 "common_commands": {857 "basic_scan": "dirb http://target.com",858 "custom_wordlist": "dirb http://target.com /path/to/wordlist.txt",859 "recursive": "dirb http://target.com -r",860 "extensions": "dirb http://target.com -X .php,.txt,.bak",861 "authentication": "dirb http://target.com -u username:password"862 },863 "skill_level": "Beginner"864 },865 "gobuster": {866 "name": "Gobuster",867 "description": "Fast directory/file & DNS busting tool",868 "category": "Content Discovery",869 "when_to_use": [870 "Fast directory enumeration",871 "DNS subdomain discovery",872 "Virtual host discovery",873 "S3 bucket enumeration"874 ],875 "modes": {876 "dir": "Directory/file enumeration",877 "dns": "DNS subdomain enumeration",878 "vhost": "Virtual host enumeration",879 "s3": "S3 bucket enumeration"880 },881 "common_commands": {882 "dir_mode": "gobuster dir -u http://target.com -w wordlist.txt",883 "dns_mode": "gobuster dns -d target.com -w subdomains.txt",884 "vhost_mode": "gobuster vhost -u http://target.com -w vhosts.txt",885 "with_extensions": "gobuster dir -u http://target.com -w wordlist.txt -x php,txt,html",886 "threads": "gobuster dir -u http://target.com -w wordlist.txt -t 50"887 },888 "skill_level": "Beginner"889 },890 "ffuf": {891 "name": "FFUF",892 "description": "Fast web fuzzer",893 "category": "Web Fuzzer",894 "when_to_use": [895 "Parameter fuzzing",896 "Directory discovery",897 "Virtual host discovery",898 "Header fuzzing"899 ],900 "common_commands": {901 "basic_fuzz": "ffuf -w wordlist.txt -u http://target.com/FUZZ",902 "post_data": "ffuf -w wordlist.txt -u http://target.com -d 'param=FUZZ'",903 "header_fuzz": "ffuf -w wordlist.txt -u http://target.com -H 'Header: FUZZ'",904 "match_status": "ffuf -w wordlist.txt -u http://target.com/FUZZ -mc 200,301",905 "filter_size": "ffuf -w wordlist.txt -u http://target.com/FUZZ -fs 1234"906 },907 "skill_level": "Intermediate"908 },909 "wfuzz": {910 "name": "Wfuzz",911 "description": "Web application fuzzer",912 "category": "Web Fuzzer",913 "when_to_use": [914 "Parameter brute-forcing",915 "Authentication testing",916 "SQL injection fuzzing",917 "XSS payload testing"918 ],919 "common_commands": {920 "basic": "wfuzz -c -z file,wordlist.txt http://target.com/FUZZ",921 "post_fuzzing": "wfuzz -c -z file,wordlist.txt -d 'user=FUZZ&pass=FUZZ' http://target.com/login",922 "header_fuzzing": "wfuzz -c -z file,wordlist.txt -H 'Cookie: FUZZ' http://target.com",923 "hide_responses": "wfuzz -c -z file,wordlist.txt --hc 404 http://target.com/FUZZ"924 },925 "skill_level": "Intermediate"926 },927 "commix": {928 "name": "Commix",929 "description": "Command injection exploiter",930 "category": "Command Injection Tool",931 "when_to_use": [932 "OS command injection testing",933 "Blind command injection detection",934 "Time-based injection testing"935 ],936 "common_commands": {937 "basic_test": "commix -u 'http://target.com/page.php?id=1'",938 "post_method": "commix -u http://target.com --data='param=value'",939 "cookie_injection": "commix -u http://target.com --cookie='session=test'",940 "os_shell": "commix -u URL --os-cmd='whoami'"941 },942 "skill_level": "Intermediate"943 }944 }945 },946 "password_attacks": {947 "description": "Tools for password cracking and authentication attacks",948 "tools": {949 "john": {950 "name": "John the Ripper",951 "description": "Fast password cracker",952 "category": "Password Cracker",953 "when_to_use": [954 "Hash cracking",955 "Password recovery",956 "Password strength testing",957 "Wordlist generation"958 ],959 "common_commands": {960 "basic_crack": "john hashes.txt",961 "wordlist_mode": "john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt",962 "show_cracked": "john --show hashes.txt",963 "specific_format": "john --format=md5 hashes.txt",964 "rules": "john --wordlist=wordlist.txt --rules hashes.txt",965 "incremental": "john --incremental hashes.txt"966 },967 "supported_formats": [968 "MD5",969 "SHA1",970 "SHA256",971 "SHA512",972 "NTLM",973 "Kerberos",974 "WPA/WPA2",975 "ZIP",976 "RAR",977 "PDF",978 "Office documents"979 ],980 "skill_level": "Intermediate"981 },982 "hashcat": {983 "name": "Hashcat",984 "description": "Advanced GPU-based password recovery",985 "category": "Password Cracker",986 "when_to_use": [987 "GPU-accelerated cracking",988 "Large hash lists",989 "Complex attack modes",990 "Rule-based attacks"991 ],992 "attack_modes": {993 "0": "Straight (dictionary)",994 "1": "Combination",995 "3": "Brute-force",996 "6": "Hybrid wordlist + mask",997 "7": "Hybrid mask + wordlist"998 },999 "common_commands": {1000 "dictionary": "hashcat -m 0 -a 0 hashes.txt wordlist.txt",1001 "brute_force": "hashcat -m 0 -a 3 hashes.txt ?a?a?a?a?a?a",1002 "rules": "hashcat -m 0 -a 0 hashes.txt wordlist.txt -r rules/best64.rule",1003 "show_cracked": "hashcat -m 0 hashes.txt --show",1004 "benchmark": "hashcat -b"1005 },1006 "skill_level": "Advanced"1007 },1008 "hydra": {1009 "name": "Hydra",1010 "description": "Fast network authentication cracker",1011 "category": "Network Login Cracker",1012 "when_to_use": [1013 "Online password attacks",1014 "Service authentication testing",1015 "Brute-force login attempts",1016 "Password spraying"1017 ],1018 "supported_protocols": [1019 "SSH",1020 "FTP",1021 "HTTP/HTTPS",1022 "SMB",1023 "RDP",1024 "VNC",1025 "Telnet",1026 "LDAP",1027 "MySQL",1028 "PostgreSQL",1029 "MSSQL",1030 "Oracle",1031 "SMTP",1032 "POP3",1033 "IMAP"1034 ],1035 "common_commands": {1036 "ssh_attack": "hydra -l admin -P passwords.txt ssh://target.com",1037 "http_post": "hydra -l admin -P passwords.txt target.com http-post-form '/login:user=^USER^&pass=^PASS^:Invalid'",1038 "ftp_attack": "hydra -L users.txt -P passwords.txt ftp://target.com",1039 "parallel": "hydra -l admin -P passwords.txt -t 4 ssh://target.com",1040 "verbose": "hydra -l admin -P passwords.txt -V ssh://target.com"1041 },1042 "skill_level": "Intermediate"1043 },1044 "medusa": {1045 "name": "Medusa",1046 "description": "Parallel network authentication brute-forcer",1047 "category": "Network Login Cracker",1048 "when_to_use": [1049 "Parallel authentication testing",1050 "Multiple host attacks",1051 "Protocol-specific attacks"1052 ],1053 "common_commands": {1054 "basic": "medusa -h target.com -u admin -P passwords.txt -M ssh",1055 "multiple_users": "medusa -h target.com -U users.txt -P passwords.txt -M ssh",1056 "multiple_hosts": "medusa -H hosts.txt -u admin -P passwords.txt -M ssh",1057 "specific_port": "medusa -h target.com -u admin -P passwords.txt -M ssh -n 2222"1058 },1059 "skill_level": "Intermediate"1060 },1061 "cewl": {1062 "name": "CeWL",1063 "description": "Custom wordlist generator from websites",1064 "category": "Wordlist Generator",1065 "when_to_use": [1066 "Creating targeted wordlists",1067 "Company-specific password lists",1068 "Social engineering preparation",1069 "Domain-specific dictionaries"1070 ],1071 "common_commands": {1072 "basic_crawl": "cewl http://target.com",1073 "depth_control": "cewl -d 3 http://target.com",1074 "min_word_length": "cewl -m 6 http://target.com",1075 "with_numbers": "cewl --with-numbers http://target.com",1076 "save_output": "cewl http://target.com -w wordlist.txt",1077 "email_extraction": "cewl -e http://target.com"1078 },1079 "skill_level": "Beginner"1080 },1081 "crunch": {1082 "name": "Crunch",1083 "description": "Wordlist generator",1084 "category": "Wordlist Generator",1085 "when_to_use": [1086 "Custom wordlist creation",1087 "Pattern-based passwords",1088 "Permutation generation",1089 "Charset-specific lists"1090 ],1091 "common_commands": {1092 "basic": "crunch 6 6 abcdef123 -o wordlist.txt",1093 "pattern": "crunch 8 8 -t pass@@@@",1094 "charset": "crunch 4 6 -f charset.lst mixalpha",1095 "permutation": "crunch 1 3 -p abc"1096 },1097 "skill_level": "Beginner"1098 }1099 }1100 },1101 "wireless_attacks": {1102 "description": "Tools for wireless network security testing",1103 "tools": {1104 "aircrack-ng": {1105 "name": "Aircrack-ng Suite",1106 "description": "Complete suite for WiFi security auditing",1107 "category": "WiFi Auditing Suite",1108 "when_to_use": [1109 "WEP/WPA/WPA2 cracking",1110 "Packet capture and injection",1111 "Access point testing",1112 "Client deauthentication"1113 ],1114 "suite_tools": {1115 "airmon-ng": "Enable monitor mode",1116 "airodump-ng": "Packet capture",1117 "aireplay-ng": "Packet injection",1118 "aircrack-ng": "WEP/WPA cracking",1119 "airbase-ng": "Fake AP creation"1120 },1121 "common_workflows": {1122 "monitor_mode": "airmon-ng start wlan0",1123 "capture_packets": "airodump-ng wlan0mon",1124 "target_capture": "airodump-ng -c 6 --bssid XX:XX:XX:XX:XX:XX -w capture wlan0mon",1125 "deauth_attack": "aireplay-ng -0 10 -a XX:XX:XX:XX:XX:XX wlan0mon",1126 "crack_wpa": "aircrack-ng -w wordlist.txt capture.cap"1127 },1128 "skill_level": "Intermediate to Advanced"1129 },1130 "reaver": {1131 "name": "Reaver",1132 "description": "WPS PIN brute-force tool",1133 "category": "WPS Cracker",1134 "when_to_use": [1135 "WPS PIN attacks",1136 "Router vulnerability testing",1137 "WPS enabled AP testing"1138 ],1139 "common_commands": {1140 "basic_attack": "reaver -i wlan0mon -b XX:XX:XX:XX:XX:XX",1141 "verbose": "reaver -i wlan0mon -b XX:XX:XX:XX:XX:XX -vv",1142 "pixie_dust": "reaver -i wlan0mon -b XX:XX:XX:XX:XX:XX -K 1",1143 "delay_settings": "reaver -i wlan0mon -b XX:XX:XX:XX:XX:XX -d 5 -t 5"1144 },1145 "skill_level": "Intermediate"1146 },1147 "wifite": {1148 "name": "Wifite",1149 "description": "Automated wireless attack tool",1150 "category": "WiFi Attack Automation",1151 "when_to_use": [1152 "Automated WiFi auditing",1153 "Multiple network testing",1154 "Quick security assessments"1155 ],1156 "features": [1157 "WEP cracking",1158 "WPA handshake capture",1159 "WPS attacks",1160 "PMKID attacks"1161 ],1162 "common_commands": {1163 "auto_attack": "wifite",1164 "wpa_only": "wifite --wpa",1165 "wps_only": "wifite --wps",1166 "specific_target": "wifite --bssid XX:XX:XX:XX:XX:XX"1167 },1168 "skill_level": "Beginner"1169 },1170 "kismet": {1171 "name": "Kismet",1172 "description": "Wireless network detector and sniffer",1173 "category": "Wireless Detector",1174 "when_to_use": [1175 "Wireless network discovery",1176 "Hidden SSID detection",1177 "Client detection",1178 "Bluetooth device discovery"1179 ],1180 "features": [1181 "802.11 WiFi detection",1182 "Bluetooth detection",1183 "RF monitoring",1184 "GPS integration"1185 ],1186 "skill_level": "Intermediate"1187 }1188 }1189 },1190 "exploitation_tools": {1191 "description": "Tools for exploiting vulnerabilities",1192 "tools": {1193 "metasploit": {1194 "name": "Metasploit Framework",1195 "description": "Penetration testing framework",1196 "category": "Exploitation Framework",1197 "when_to_use": [1198 "Vulnerability exploitation",1199 "Payload generation",1200 "Post-exploitation",