Saturday, June 28, 2025

Pentest-Arsenal – A Complete Internet Utility Safety Testing Toolkit That Combines 10 Highly effective Penetration Testing Options Into One Instrument





/
_ / |
/ |
| || |
| | | /
| /| |/
|/ |/
,/; ; ;
,'/|; ,/,/,
,'/ |;/,/,/,/|
,/; |;|/,/,/,/,/|
,/'; |;|,/,/,/,/,/|
,/'; |;|/,/,/,/,/,/|,
/ ; |;|,/,/,/,/,/,/|
/ ,'; |;|/,/,/,/,/,/,/|
/,/'; |;|,/,/,/,/,/,/,/|
/;/ '; |;|/,/,/,/,/,/,/,/|

██████╗ ███████╗ ██████╗ █████╗ ███████╗██╗ ██╗███████╗
██╔══██╗██╔════╝██╔════╝ ██╔══██╗██╔════╝██║ ██║██╔════╝
██████╔╝█████╗ ██║ ███╗███████║███████╗██║ ██║███████╗
██╔═══╝ ██╔══╝ ██║ ██║██╔══██║╚════██║██║ ██║╚════██║
██║ ███████╗╚██████╔╝██║ ██║███████║╚██████╔╝███████║
╚═╝ ╚══════╝ ╚═════╝ ╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚══════╝
P E N T E S T A R S E N A L

A complete net software safety testing toolkit that mixes 10 highly effective penetration testing options into one instrument.

Creator

Options

  1. Subdomain + Curl HTTP Scanner
  2. Discovers subdomains utilizing a wordlist
  3. Checks HTTP standing and safety headers
  4. Identifies potential safety Misconfigurations” title=”Misconfigurations”>misconfigurations

  5. JWT Token Inspector

  6. Analyzes JWT token construction and claims
  7. Identifies safety points in token configuration
  8. Detects frequent JWT vulnerabilities

  9. Parameter Air pollution Finder

  10. Checks for HTTP Parameter Air pollution (HPP)
  11. Identifies susceptible parameters
  12. Detects server-side parameter dealing with points

  13. CORS Misconfiguration Scanner

  14. Checks for CORS coverage misconfigurations
  15. Identifies harmful wildcard insurance policies
  16. Detects credential publicity dangers

  17. Add Bypass Tester

  18. Checks file add restrictions
  19. Makes an attempt varied bypass methods
  20. Identifies harmful file kind dealing with

  21. Uncovered .git Listing Finder

  22. Scans for uncovered model management recordsdata
  23. Identifies leaked Git repositories
  24. Checks for delicate info disclosure

  25. SSRF (Server Aspect Request Forgery) Detector

  26. Checks for SSRF vulnerabilities
  27. Identifies susceptible parameters
  28. Contains cloud metadata endpoint exams

  29. Blind SQL Injection Time Delay Detector

  30. Checks for time-based SQL injection
  31. Helps a number of database sorts
  32. Identifies injectable parameters

  33. Native File Inclusion (LFI) Mapper

  34. Checks for LFI vulnerabilities
  35. Contains path traversal detection
  36. Helps varied encoding bypasses

  37. Internet Utility Firewall (WAF) Fingerprinter

    • Identifies WAF presence
    • Detects WAF vendor/kind
    • Checks WAF effectiveness

Set up

  1. Clone the repository:
git clone https://github.com/sobri3195/pegasus-pentest-arsenal.git
cd pegasus-pentest-arsenal
  1. Create a digital surroundings (advisable):
python -m venv venv
supply venv/bin/activate # On Home windows: venvScriptsactivate
  1. Set up dependencies:
pip set up -r necessities.txt

Utilization

  1. Run the primary script:
python pegasus_pentest.py
  1. Choose a instrument from the menu (1-10)
  2. Comply with the prompts to enter goal info
  3. Assessment the outcomes

Necessities

  • Python 3.8+
  • Required packages (see necessities.txt):
  • requests
  • httpx
  • urllib3
  • colorama
  • pyjwt
  • beautifulsoup4

Safety Concerns

  • This instrument is for instructional and licensed testing functions solely
  • All the time acquire correct authorization earlier than testing any goal
  • Some options might set off safety alerts or be blocked by safety controls
  • Use responsibly and ethically

Contributing

  1. Fork the repository
  2. Create a function department
  3. Commit your modifications
  4. Push to the department
  5. Create a Pull Request

License

This venture is licensed below the MIT License – see the LICENSE file for particulars.

Disclaimer

This instrument is offered for instructional and licensed testing functions solely. Customers are accountable for acquiring correct authorization earlier than testing any goal. The authors are usually not accountable for any misuse or injury attributable to this instrument.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

PHP Code Snippets Powered By : XYZScripts.com