The arsenal

Every weapon ARGUS turns on your target — real binaries, real results, across three attack VMs. classified

arsenalWEB RECON · KALI
nucleiFast CVE / misconfiguration scanner — 8,000+ templates
subfinderPassive subdomain discovery across 30+ sources
httpxLive HTTP probing of discovered hosts
katanaCrawler that maps a site's attack surface
naabuFast port scanner for target discovery
ffufHigh-speed directory & parameter fuzzer
gobusterDirectory / DNS / VHOST brute-forcer
feroxbusterRecursive content discovery
dirsearchWeb path scanner with JSON output
arjunHTTP parameter discovery
nmapPort + service + NSE script enumeration
masscanInternet-scale port scanning
dnsxFast DNS toolkit
findomainFast subdomain enumerator
amassIn-depth attack-surface mapping
rustscanLightning-fast port scanner
arsenalEXPLOITATION · KALI
sqlmapAutomatic SQL injection detection & takeover
wpscanWordPress vulnerability scanner
niktoWeb server vulnerability scanner
commixCommand injection exploiter
wfuzzWeb application fuzzer
dirbWeb content scanner
metasploitFull exploitation framework (msfconsole)
searchsploitExploit-DB offline search
burpsuiteWeb app pentest proxy
arsenalCREDENTIALS · KALI
crackmapexecSwiss-army SMB/WinRM/MSSQL post-exploitation
enum4linuxSMB / Samba enumeration
smbclientSMB share access & enumeration
hydraFast network logon cracker
johnPassword hash cracker
hashcatGPU-accelerated hash cracking
evil-winrmWinRM shell for lateral movement
responderLLMNR/NBT-NS/mDNS poisoning
impacketPython SMB/AD attack library
bloodhoundAD attack-path visualization
arsenalAD / WINDOWS · COMMANDO
mimikatzCredential extraction from memory / SAM / LSA
impacket-secretsdumpRemote SAM/LSA/NTDS secret dump
kerberoastGetUserSPNs — service-ticket hash extraction
asreproastGetNPUsers — AS-REP hash extraction
GetLAPSPasswordRead LAPS-managed local admin passwords
wmiexec / psexec / smbexecRemote command execution over WMI/SMB
samrdump / lookupsidSAMR user & SID enumeration
SharpHoundBloodHound data collector
PowerViewAD enumeration (users/groups/sessions/GPO)
winPEASLocal privilege-escalation enumeration
hashcatCrack NTLM / Kerberoast / AS-REP hashes
CrackMapExecSMB/LDAP/WinRM network attacks
arsenalOSINT · TRACE LABS
sherlockUsername footprint across 300+ social networks
theHarvesterEmail + subdomain harvesting
spiderfootAutomated OSINT recon framework
holeheEmail-registered-service enumeration
maigretDeep username → profile enumeration
instaloaderInstagram profile + post intelligence
toutatisPhone-number OSINT lookups
shodanInternet device search engine
arsenalAGENT
qwen3.8longInterprets raw findings into a professional report