PenEnv is a suite of scripts to be used for pentesting
It has a goal to provide tools for installing environement, osint, enumeration, exploitation and post-exploitation, and to automize their utilisation.
Count around 40 to 45 minutes for the forced installation using the default 20 threads and a decent internet connection The time is mainly due to apt and pip upgrade, don't hesitate using --no-update (or -nc) to gain time if that does not seem usefull to you
curl -L -s https://raw.githubusercontent.com/lLouu/penenv/main/0%20-%20install.sh | bash
curl -L -s https://raw.githubusercontent.com/lLouu/penenv/main/0%20-%20install.sh | bash -s -- -b dev
curl -L -s https://raw.githubusercontent.com/lLouu/penenv/main/0%20-%20install.sh | bash -s -- -f
script=<script-you-want> && wget https://raw.githubusercontent.com/lLouu/penenv/main/misc/$script && chmod +x $script
install.sh is the script that manage penenv installation.
start.sh launches usefull services for your pentesting. It uses some ports
- 21 for providing hotscripts with ftp server and allowing uploads
- 53 for dnscat server
- 80 for providing hotscripts with http server
- 445 for smb share
- 7474 for neo4j
- 8834 for nessus
- 11601 for ligolo proxy
- install_penenv
- start
- get-session
- apt upgrade
- python 3
- 2to3
- pip & pip upgrade
- poetry
- go
- ruby
- java
- maven
- nodejs
- npm
- yarn
- rust
- C
- make
- mono
- dotnet
- gradle
- shc
- git
- krb5-user
- 7z
- winrar
- pyftpdlib
- dnsutils
- google-chrome
- jq
- expect
- sublist3r
- assetfinder
- amass
- gowitness
- subjack
- certspotter
- dnsrecon
- dnsenum
- waybackurls
- arjun
- brokenlinkchecker
- dirscapper
- haktrails
- hakrawler
- linkfinder
- gobuster
- whatweb
- ffuf
- x8
- wappalyzer
- testssl
- nikto
- wafw00f
- httprobe
- secretfinder
- wpscan
- hashcat
- hydra
- john
- nmap
- onesixtyone
- rpcbind
- snmpcheck
- snmpwalk
- Metasploit & Armitage & Upgrade
- searchsploit
- sqlmap
- commix
- pixload
- ghidra
- gdb
- Shocker
- impacket
- fierce
- oscanner
- odat
- crackmapexec
- cewl
- cupp
- DDexec payloader & script
- openvpn
- mitm6
- proxychain
- responder
- Evil winrm
- BloodyAD
- smbmap
- Certipy
- pydictor
- rdesktop
- xfreerdp
- dnscat (server & client)
- Chisel
- frp
- LinPEAS
- WinPEAS
- miranda
- pspy
- rubeus
- mimikatz
- mimipenguin
- linux-exploit-suggester-2
- wesng
- watson
- powersploit
- netcat Windows
- ligolo-ng
- FullPowers
- GodPotato
- ddenum
- ddsheller
- filestream
- shscanner
- neo4j
- bloodhound
- nessus
- neo4j
- nessus
- dnscat
- openvpn
- ligolo proxy
- http server
- ftp server
- smb server
- Hashcat
- responder
- Parrot
- hack the box
- pentesting
- architect
- Kali
- 2023 64 bits
- Debian
- 11
- Ubuntu Desktop
- 20
- 22
- Alpine
- Standard
- Extended
- Raspery
- VM
An unidentified process can compromize somehow mate menu and seems to remove parts of mate-desktop-environment package
This can be solved with 'apt install mate-desktop-environment' again and rebooting
Public notion page is currently in bulding
| Name | Tools |
|---|---|
| asn | Amass |
| cdir | Amass |
| domain | Amass, assetfinder, haktrails, waybackurl |
| IRL | haktrails |
| pwd | cewl, cupp |
| Name | Tools |
|---|---|
| network | nmap |
| banner | nmap, telnet |
| fuzz | ffuf, gobuster |
| web | arjun, brokenlinkchecker, linkfinder, gowitness, hakrawler, nikto, secretfinder, testssl, wappalyzer, whatweb |
| upnp | miranda |
- nmap
- hydra
- crackmapexec
- hashcat
- john
- impacket
- evil winrm
- nmap
- nessus
- nikto
- searchsploit
- metasploit
- nmap
- metasploit
- sqlmap
- commix
- ghidra
- gdb
- reverse shells
- add a user
- metasploit
- dnscat
- impacket
- LinPEAS
- WinPEAS
- pspy
- linux-exploit-suggestor-2
- watson
- FullPowers
- GodPotato
- rubeus / mimikatz
- impacket
- bloodhound
- BloodyAD
- Certipy
- crackmapexec
- rubeus
- mimikatz
- mimipenguin
- responder
- mitm6
- impacket
- proxychains
- logolo-ng
- frp
- chisel