Skip to main content

pentest-tooling

Pentest: nmap, nuclei, sqlmap, ffuf, subfinder, Sploitus CVE lookup — tool usage playbooks.

Ir para a instalação

Informações da origem

Repositório
aurict/aurict
Última atividade na origem
24 de junho de 2026 às 19:34
Idioma detectado do SKILL.md
inglês
Estrelas
33
Forks
2

Opções de instalação

Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.

Revise os arquivos de origem

Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.

Exibindo SKILL.md

SKILL.md
Instruções da origem · Visualização somente leitura
name
pentest-tooling
description
Pentest: nmap, nuclei, sqlmap, ffuf, subfinder, Sploitus CVE lookup — tool usage playbooks.
triggers
{"keywords":["nmap","nuclei","sqlmap","ffuf","subfinder","sploitus","pentest","exploit","scan","vulnerability scan","cve lookup"]}
auto_load_when
Active security testing or vulnerability scanning with CLI tools
agent
pentest
tools
["Read","Bash","WebFetch","WebSearch"]
# Penetration Testing Tooling Playbooks > ⚠ These tools require Linux or macOS. On Windows use WSL2. > Install: `apt install nmap nuclei sqlmap ffuf subfinder` or use `go install` for Go tools. --- ## 1. nmap — Service & Port Scanning ```bash # Quick top-1000 ports with service detection nmap -sV -sC -T4 TARGET # Full port scan (slow but complete) nmap -p- --min-rate 5000 TARGET # Save output for later analysis nmap -sV -sC -oN nmap_scan.txt -oX nmap_scan.xml TARGET # Specific port range nmap -p 80,443,8080,8443 -sV TARGET # UDP scan (requires root) sudo nmap -sU --top-ports 20 TARGET ``` **Read output for:** - Open ports + service versions → match against CVE databases - Default scripts (`-sC`) detect: HTTP headers, SSL certs, SMB info, FTP banners --- ## 2. nuclei — Template-Based Vulnerability Scanning ```bash # Scan with all severity levels nuclei -u https://TARGET -severity critical,high,medium,low # Scan specific template category nuclei -u https://TARGET -tags cve,sqli,xss,ssrf # Scan from file with multiple targets nuclei -l targets.txt -severity critical,high # Update templates first (always do this) nuclei -update-templates # Save findings to file nuclei -u https://TARGET -o nuclei_findings.txt -severity critical,high ``` **Good for:** mass CVE detection, misconfigurations, exposed panels, default credentials --- ## 3. sqlmap — SQL Injection Testing ```bash # Basic injection test on GET parameter sqlmap -u "https://TARGET/page?id=1" --batch # POST parameter injection sqlmap -u "https://TARGET/login" --data="username=admin&password=test" --batch # Enumerate databases (after injection confirmed) sqlmap -u "URL" --batch --dbs # Dump specific database sqlmap -u "URL" --batch -D database_name --tables sqlmap -u "URL" --batch -D database_name -T users --dump # With session cookie (authenticated) sqlmap -u "URL" --cookie="session=VALUE" --batch # Bypass WAF with tamper scripts sqlmap -u "URL" --batch --tamper=space2comment,charencode ``` --- ## 4. ffuf — Web Fuzzing ```bash # Directory/path discovery ffuf -w /usr/share/wordlists/dirb/common.txt -u https://TARGET/FUZZ # Subdomain enumeration via DNS ffuf -w subdomains.txt -u https://FUZZ.TARGET -H "Host: FUZZ.TARGET" # Parameter fuzzing (GET) ffuf -w params.txt -u "https://TARGET/page?FUZZ=test" # POST body fuzzing ffuf -w payloads.txt -u https://TARGET/login -X POST \ -d "username=admin&password=FUZZ" -fc 401 # Filter by response size or status code ffuf -w wordlist.txt -u https://TARGET/FUZZ -fc 404 -fs 1234 ``` **Wordlists:** `/usr/share/wordlists/dirb/common.txt`, SecLists (`/usr/share/seclists/`) --- ## 5. subfinder — Subdomain Enumeration ```bash # Basic subdomain discovery subfinder -d target.com -o subdomains.txt # With all sources (slower but more complete) subfinder -d target.com -all -o subdomains.txt # Silent mode (output only) subfinder -d target.com -silent # Feed into nuclei subfinder -d target.com -silent | nuclei -severity critical,high ``` --- ## 6. Sploitus — CVE & Exploit Lookup ``` # Search by product/component name webfetch https://sploitus.com/search?query=PRODUCT+VERSION&type=exploits # Search by CVE ID webfetch https://sploitus.com/search?query=CVE-2024-XXXXX # Search by technology webfetch https://sploitus.com/search?query=apache+log4j ``` **Also useful:** ``` websearch "CVE-XXXX-XXXXX exploit github" websearch "PRODUCT VERSION remote code execution poc" ``` --- ## 7. Dependency Audit ```bash # Node.js npm audit --json | jq '.vulnerabilities | to_entries[] | select(.value.severity == "critical" or .value.severity == "high")' # Python pip audit --format json # Rust cargo audit # Go govulncheck ./... ``` --- ## Quick Decision Matrix | Goal | Tool | |---|---| | What ports/services are open? | nmap | | Known CVEs for this version? | nuclei + Sploitus | | Is this endpoint SQLi vulnerable? | sqlmap | | What endpoints/dirs exist? | ffuf | | What subdomains exist? | subfinder | | Is this dependency CVE'd? | npm audit / cargo audit |
Ver no GitHub