A curated collection of offensive security tools written, developed for learning, testing, and practicing ethical hacking and penetration testing techniques. Each tool targets a specific phase of ethical hacking — from reconnaissance to exploitation and analysis.
Whether you're learning cybersecurity or building a personal toolkit, this repo provides practical, hands-on utilities to explore network scanning, brute-force attacks, enumeration, and more.
- 🔍 Network Scanner
- 📁 Directory Enumeration
- 🌐 Subdomain Discovery
- 🔐 SSH Brute Forcer
- 🧾 Hash Identifier
- 🧨 Hash Cracker
- 📊 Log Analyzer
Scans a target IP for open TCP ports and attempts to identify the services running on them. Useful for basic reconnaissance and enumeration during penetration testing.
-
Pings the host to check if it's reachable
-
Scans ports from
1to65535 -
Displays:
- Open ports
- Service names (where available)
-
Clean and informative CLI output
python network_scanner.py <ip-address>python network_scanner.py 192.168.1.1---------------------------------------------------------------
Scan report for 192.168.1.1
---------------------------------------------------------------
Starting port scan...
---------------------------------------------------------------
PORT STATE SERVICE
22 open ssh
80 open http
443 open https
...
---------------------------------------------------------------
Scan complete.
- Sends an ICMP ping to check if the host is reachable.
- Iterates through ports 1–65535 using
socket.connect_ex(). - Uses
socket.getservbyport()to identify common services.
- Python 3.x
- Linux/macOS (uses
ping -cand redirects with> /dev/null)
⚠️ This script may not work properly on Windows due to differences in thepingcommand syntax.
Performs brute-force directory and file discovery on a given web server using a user-provided wordlist. Helps identify hidden or restricted paths that may expose sensitive content during a web application penetration test.
- Validates if the target URL is reachable
- Scans for directories/files using a custom wordlist
- Detects
200 OK(found) and403 Forbidden(restricted) resources - Clean CLI output with real-time results
Use a virtual environment and install dependencies from requirements.txt:
python -m venv venv
source venv/bin/activate
pip install -r requirements.txtpython directory_enumeration.py <url> <wordlist>python directory_enumeration.py http://example.com common.txt===============================================================
[+] Url: http://example.com
[+] Wordlist: common.txt
[✓] Server reachable: http://example.com (Status: 200)
===============================================================
Starting directory enumeration...
===============================================================
[+] Found: http://example.com/admin (200 OK)
[-] Forbidden (403): http://example.com/hidden
...
[-] No directories found.
-
Loads a list of directory names from the given wordlist.
-
Sends a GET request to each potential path using the base URL.
-
Checks HTTP response status codes:
200 OKindicates the path exists.403 Forbiddenindicates the path exists but is restricted.
-
Gracefully handles unreachable hosts or keyboard interrupts.
- Python 3.x
requestslibrary
⚠️ Ensure the wordlist file exists and is properly formatted (one path per line).
Performs subdomain brute-forcing for a given domain using a custom wordlist. Helps uncover hidden or unlisted subdomains during the reconnaissance phase of web application penetration testing.
- Validates if the base domain is reachable
- Uses DNS resolution to identify live subdomains
- Supports custom wordlists for flexible enumeration
- Clean, informative CLI output
Use a virtual environment and install dependencies from requirements.txt:
python -m venv venv
source venv/bin/activate
pip install -r requirements.txtpython subdomain_discovery.py <domain> <wordlist>python subdomain_discovery.py example.com subdomains.txt===============================================================
[+] Domain: example.com
[+] Wordlist: subdomains.txt
===============================================================
Starting subdomain discovery...
===============================================================
[+] Found: admin.example.com
[+] Found: dev.example.com
...
[-] No subdomains found.
- Loads a list of potential subdomain prefixes from the wordlist.
- Appends each prefix to the base domain (e.g.,
admin.example.com). - Uses
dns.resolverto check for valid DNS A records. - If the subdomain resolves, it is considered "found".
- Python 3.x
dnspythonlibrary
⚠️ Ensure the wordlist contains one subdomain prefix per line (e.g.,admin,test). Do not include full domain names in the wordlist.
Here's the complete and consistent README for your SSH Brute Forcer tool, following the same style as the previous tools:
Attempts to brute-force SSH login using a list of usernames and passwords. Intended for controlled environments such as CTFs or lab testing.
- Checks if the SSH service is reachable on the target
- Attempts to log in using a wordlist of passwords
- Displays successful login credentials (if found)
- Handles connection timeouts and interruptions gracefully
Set up a virtual environment and install dependencies from requirements.txt:
python -m venv venv
source venv/bin/activate
pip install -r requirements.txtpython ssh_brute_force.py <target> <username> <passlist>python ssh_brute_force.py 192.168.1.10 root passwords.txt===============================================================
[+] Target: 192.168.1.10
[+] Username: root
[+] Wordlist: passwords.txt
[✔] Target 192.168.1.10:22 is reachable.
===============================================================
Starting SSH brute-force...
===============================================================
[~] Trying: root:123456
[~] Trying: root:toor
[~] Trying: root:letmein
...
===============================================================
[✔] Success! Username: root | Password: toor
===============================================================
- Verifies the SSH port (default
22) is open usingsocket.create_connection(). - Reads passwords from a wordlist file.
- Uses
paramikoto attempt SSH login with each password. - Stops upon successful login, or reports failure if no credentials work.
- Python 3.x
paramikolibrary
A simple and effective script for identifying the most likely hash type based on known lengths and patterns.
- Matches input against known hash formats (MD5, SHA, bcrypt, NTLM, LM, etc.)
- Detects special cases like
MySQL5,bcrypt, andBase64 - Supports hex-encoded and Base64-style hashes
- Validates input format and alerts on invalid values
python hash_identifier.py <hash>python hash_identifier.py 5f4dcc3b5aa765d61d8327deb882cf99[✓] Possible hash type(s): MD5, NTLM, MD4, LM
-
Uses regex patterns to match the hash string against common hash types.
-
Supports case-insensitive hex and Base64 formats.
-
Handles:
- Fixed-length patterns (e.g., 32 for MD5)
- Prefix-based identifiers (e.g.,
$2a$for bcrypt)
-
Includes fallback detection for certain LM second-half hash values.
- Python 3.x
⚠️ Hash type identification is heuristic-based and not guaranteed to be 100% accurate — some hash types share formats. Use this as a first step before cracking or reverse engineering.
A dictionary-based hash cracker that attempts to crack a given hash using a specified hashing algorithm and a wordlist.
- Supports any algorithm available in Python's
hashlib(e.g., MD5, SHA1, SHA256) - Reads custom wordlists (one password per line)
- Clean CLI output and graceful handling of errors and interruptions
- Works offline — no external services required
python hash_cracker.py <hash> <algorithm> <passlist>python hash_cracker.py 5f4dcc3b5aa765d61d8327deb882cf99 md5 rockyou.txt===============================================================
[~] Hash: 5f4dcc3b5aa765d61d8327deb882cf99
[~] Algorithm: md5
[~] Passlist: rockyou.txt
===============================================================
[✓] Hash cracked! password
===============================================================
- Loads the wordlist and iterates over each password candidate.
- Hashes each word using the specified algorithm via
hashlib. - Compares the result against the target hash.
- Stops and reports the password if a match is found.
- Python 3.x
Parses and analyzes server log files. It extracts key information from log files to provide insights into client activity, requested resources, and HTTP status codes.
- Parses common access log formats using regular expressions
- Identifies top IPs, most requested URLs, and status code distributions
- Outputs clean summary statistics to the terminal
- Handles malformed lines and empty files gracefully
python3 log_analyzer.py <log_file>python3 log_analyzer.py access.log===============================================================
[~] Log file: access.log
===============================================================
📊 Top 5 IPs:
192.168.0.101 34 requests
10.0.0.15 21 requests
...
===============================================================
📄 Top 5 Requested URLs:
/index.html 18 hits
/login 12 hits
...
===============================================================
📡 Status Code Summary:
200: 54
404: 7
403: 3
...
===============================================================
-
Uses a regular expression to extract:
- IP address
- Timestamp
- HTTP method
- Requested URL
- Response status code
- Response size
-
Aggregates and ranks:
- Top 5 IPs by request volume
- Top 5 requested URLs
- Status code counts
- Python 3.x