Open-Source Cybersecurity Toolkit

A curated network-security reference catalogue organized by security domain. The current release contains 61 upstream references across 143 categories: 57 Red Team, 4 Blue Team, and no Purple Team entries.

Reference only: links go to upstream projects; VectrionX does not execute tools, host payloads or make claims about results. Use only in authorized environments and follow each project’s license and documentation.

Categories with no published references remain pending and do not represent VectrionX capability. Want the broader context? See how the toolkit fits the ecosystem.

Reconnaissance

15 Tools

Netdiscover

Network Discovery

An active/passive ARP reconnaissance tool, initially developed to gain information about wireless networks without DHCP servers.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
ARPNetworkDiscovery
BeginnerDetails

arp-scan

Network Discovery

A fast ARP packet scanner that shows every active IPv4 device on your local subnet.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
ARPNetworkCLI+2
BeginnerDetails

EyeWitness

Web Application Screenshot & Reporting

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
WebReconScreenshot+1
BeginnerDetails
Explore Full Category: Reconnaissance (15 Tools)

OSINT

2 Tools

SpiderFoot

Digital Footprint Analysis

An OSINT automation tool for threat intelligence and attack surface mapping.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
OSINTAutomationThreat Intelligence+1
IntermediateDetails

Maigret

Digital Footprint Analysis

A powerful OSINT tool that collects a dossier on a person by username across thousands of sites.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
OSINTReconUsernames+1
IntermediateDetails

Scanning

4 Tools

RustScan

Network

The modern port scanner. Fast, smart, effective. Scans all 65k ports in 3 seconds.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Port ScannerNetworkCLI+1
BeginnerDetails

Nmap

Network

Network exploration tool and security / port scanner.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Port ScannerNetworkCLI
IntermediateDetails

ZMap

Network

A fast single-packet network scanner designed for Internet-wide network surveys.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Port ScannerNetworkCLI+1
IntermediateDetails
Explore Full Category: Scanning (4 Tools)

Enumeration

4 Tools

BloodHound

Active Directory

A Single Page JavaScript Web App capable of identifying highly complex and hidden relationships within an Active Directory environment to find privilege escalation paths.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Active DirectoryNeo4jAttack Paths+1
IntermediateDetails

SharpHound

Active Directory

The official data collector for BloodHound. It enumerates Active Directory via LDAP and RPC to build a graph of identity relationships.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Active DirectoryData CollectorReconnaissance+1
IntermediateDetails

Enum4linux

SMB Enumeration

A tool for enumerating information from Windows and Samba systems.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
SMBWindowsActive Directory+1
BeginnerDetails
Explore Full Category: Enumeration (4 Tools)

Web Vulnerability Testing

8 Tools

OWASP ZAP

Vulnerability Scanning

The world’s most widely used web app scanner. Free and open source active vulnerability scanner.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Web ScannerVulnerabilityProxy+1
BeginnerDetails

Nikto

Vulnerability Scanning

An open-source web server scanner which performs comprehensive tests against web servers for multiple items.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Web ScannerVulnerabilityPerl
BeginnerDetails

NoSQLMap

NoSQL Assessment

An open source Python tool designed to audit for as well as automate injection attacks and exploit default configuration weaknesses in NoSQL databases.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
NoSQLDatabaseVulnerability Scanner+1
IntermediateDetails
Explore Full Category: Web Vulnerability Testing (8 Tools)

Social Engineering

1 Tools

SEToolkit

Phishing Simulation

An open-source penetration testing framework designed for social engineering.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
PhishingAwarenessPython
IntermediateDetails

Exploitation

4 Tools

SearchSploit

Exploit Database

A command line search tool for Exploit-DB that also allows you to take a copy of Exploit Database with you.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Exploit-DBVulnerabilitySearch+1
BeginnerDetails

PenTesters Framework (PTF)

Framework

A modular, Python-based script for installing and maintaining penetration testing tools and creating an offensive security environment.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
AutomationSetupFramework+2
IntermediateDetails

Metasploit Framework

Framework

The world’s most used penetration testing framework. It helps security teams verify vulnerabilities, manage security assessments, and improve security awareness.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
ExploitationFrameworkRuby
IntermediateDetails
Explore Full Category: Exploitation (4 Tools)

Privilege Escalation

2 Tools

LinPEAS

Local Privilege Escalation

Linux Privilege Escalation Awesome Script - searches for possible paths to escalate privileges on Linux/Unix/MacOS hosts.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Privilege EscalationLinuxEnumeration+1
BeginnerDetails

WinPEAS

Local Privilege Escalation

Windows Privilege Escalation Awesome Script - searches for possible paths to escalate privileges on Windows hosts.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Privilege EscalationWindowsEnumeration+1
BeginnerDetails

Post-Exploitation

4 Tools

Sliver

Command and Control (C2)

An open source cross-platform adversary simulation/red team framework.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
C2Post-ExploitationGolang+1
AdvancedDetails

PoshC2

Command and Control (C2)

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
C2PowerShellWindows+1
AdvancedDetails

Covenant

Command and Control (C2)

A collaborative .NET C2 framework for red teamers, featuring an intuitive web interface, role-based access control, and seamless C# payload integration.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
C2.NETRed Team+1
AdvancedDetails
Explore Full Category: Post-Exploitation (4 Tools)

Credential Access

10 Tools

Ophcrack

Password Attacks

A free Windows password cracker based on rainbow tables.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
CrackingRainbow TablesWindows+1
BeginnerDetails

Medusa

Password Attacks

A speedy, parallel, and modular, login brute-forcer for network services.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
CrackingBruteforceNetwork+1
IntermediateDetails

Ncrack

Password Attacks

High-speed network authentication cracking tool. (Used defensively for authentication exposure analysis).

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
NmapAuthenticationAuditing+1
IntermediateDetails
Explore Full Category: Credential Access (10 Tools)

Lateral Movement

2 Tools

Proxychains

Pivoting & Tunneling

A tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
ProxyTunnelingNetwork+1
IntermediateDetails

CrackMapExec

Active Directory Attacks

A swiss army knife for pentesting networks. Focuses on Active Directory environments.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Active DirectorySMBPost-Exploitation+1
IntermediateDetails

Hardware Hacking

1 Tools

RouterSploit

Hardware & IoT Exploitation

An open-source exploitation framework dedicated to embedded devices and routers.

Provenance
upstream repository
Upstream status
maintenance uncertain
Reviewed
2026-09-10
Safe-use note
Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
IoTRouterExploitation+1
IntermediateDetails

Pending Categories

(50)
External Attack Surface DiscoveryPendingInternal Network DiscoveryPendingWeb EnumerationPendingDNS EnumerationPendingSMB EnumerationPendingLDAP EnumerationPendingSNMP EnumerationPendingCloud EnumerationPendingVulnerability AssessmentPendingAPI TestingPendingPassword AttacksPendingCredential AttacksPendingPhishingPendingInitial AccessPendingWeb ExploitationPendingBinary ExploitationPendingLocal Privilege EscalationPendingPersistencePendingDefense EvasionPendingPayload GenerationPendingMalware DevelopmentPendingCommand and Control (C2)PendingCredential DumpingPendingPivoting & TunnelingPendingActive Directory AttacksPendingKerberos AttacksPendingWindows AttacksPendingLinux AttacksPendingCloud AttacksPendingAzure AttacksPendingAWS AttacksPendingContainer AttacksPendingKubernetes AttacksPendingWireless AttacksPendingBluetooth AttacksPendingMobile ExploitationPendingData ExfiltrationPendingSteganographyPendingAV/EDR EvasionPendingLiving Off The Land (LOTL)PendingOPSECPendingInfrastructure SetupPendingRedirectors & ProxiesPendingTraffic ObfuscationPendingICS / OT AttacksPendingUSB AttacksPendingRFID/NFC AttacksPendingRed Team AutomationPendingAdversary SimulationPendingReportingPending

Complete category index

Every public category remains discoverable in the approved route model. Pending categories are truthful empty references and do not represent VectrionX capability.

Red Team

Blue Team

Purple Team