Open-Source Cybersecurity Toolkit
A curated network-security reference catalogue organized by security domain. The current release contains 61 upstream references across 143 categories: 57 Red Team, 4 Blue Team, and no Purple Team entries.
Reference only: links go to upstream projects; VectrionX does not execute tools, host payloads or make claims about results. Use only in authorized environments and follow each project’s license and documentation.
Categories with no published references remain pending and do not represent VectrionX capability. Want the broader context? See how the toolkit fits the ecosystem.
Reconnaissance
15 ToolsAn active/passive ARP reconnaissance tool, initially developed to gain information about wireless networks without DHCP servers.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A fast ARP packet scanner that shows every active IPv4 device on your local subnet.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
OSINT
2 ToolsAn OSINT automation tool for threat intelligence and attack surface mapping.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A powerful OSINT tool that collects a dossier on a person by username across thousands of sites.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Scanning
4 ToolsThe modern port scanner. Fast, smart, effective. Scans all 65k ports in 3 seconds.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Network exploration tool and security / port scanner.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A fast single-packet network scanner designed for Internet-wide network surveys.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Enumeration
4 ToolsA Single Page JavaScript Web App capable of identifying highly complex and hidden relationships within an Active Directory environment to find privilege escalation paths.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
The official data collector for BloodHound. It enumerates Active Directory via LDAP and RPC to build a graph of identity relationships.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A tool for enumerating information from Windows and Samba systems.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Web Vulnerability Testing
8 ToolsThe world’s most widely used web app scanner. Free and open source active vulnerability scanner.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
An open-source web server scanner which performs comprehensive tests against web servers for multiple items.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
An open source Python tool designed to audit for as well as automate injection attacks and exploit default configuration weaknesses in NoSQL databases.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Social Engineering
1 ToolsAn open-source penetration testing framework designed for social engineering.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Exploitation
4 ToolsA command line search tool for Exploit-DB that also allows you to take a copy of Exploit Database with you.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A modular, Python-based script for installing and maintaining penetration testing tools and creating an offensive security environment.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
The world’s most used penetration testing framework. It helps security teams verify vulnerabilities, manage security assessments, and improve security awareness.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Privilege Escalation
2 ToolsLinux Privilege Escalation Awesome Script - searches for possible paths to escalate privileges on Linux/Unix/MacOS hosts.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Windows Privilege Escalation Awesome Script - searches for possible paths to escalate privileges on Windows hosts.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Post-Exploitation
4 ToolsAn open source cross-platform adversary simulation/red team framework.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A collaborative .NET C2 framework for red teamers, featuring an intuitive web interface, role-based access control, and seamless C# payload integration.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Credential Access
10 ToolsA free Windows password cracker based on rainbow tables.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A speedy, parallel, and modular, login brute-forcer for network services.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
High-speed network authentication cracking tool. (Used defensively for authentication exposure analysis).
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Lateral Movement
2 ToolsA tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
A swiss army knife for pentesting networks. Focuses on Active Directory environments.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Hardware Hacking
1 ToolsAn open-source exploitation framework dedicated to embedded devices and routers.
- Provenance
- upstream repository
- Upstream status
- maintenance uncertain
- Reviewed
- 2026-09-10
- Safe-use note
- Reference only: use in authorized environments, follow the upstream license and documentation, and do not use against systems without explicit permission.
Pending Categories
(50)Complete category index
Every public category remains discoverable in the approved route model. Pending categories are truthful empty references and do not represent VectrionX capability.
Red Team
- Reconnaissance
- OSINT
- External Attack Surface Discovery — pending
- Internal Network Discovery — pending
- Scanning
- Enumeration
- Web Enumeration — pending
- DNS Enumeration — pending
- SMB Enumeration — pending
- LDAP Enumeration — pending
- SNMP Enumeration — pending
- Cloud Enumeration — pending
- Vulnerability Assessment — pending
- Web Vulnerability Testing
- API Testing — pending
- Password Attacks — pending
- Credential Attacks — pending
- Phishing — pending
- Social Engineering
- Initial Access — pending
- Exploitation
- Web Exploitation — pending
- Binary Exploitation — pending
- Privilege Escalation
- Local Privilege Escalation — pending
- Persistence — pending
- Defense Evasion — pending
- Payload Generation — pending
- Malware Development — pending
- Command and Control (C2) — pending
- Post-Exploitation
- Credential Access
- Credential Dumping — pending
- Lateral Movement
- Pivoting & Tunneling — pending
- Active Directory Attacks — pending
- Kerberos Attacks — pending
- Windows Attacks — pending
- Linux Attacks — pending
- Cloud Attacks — pending
- Azure Attacks — pending
- AWS Attacks — pending
- Container Attacks — pending
- Kubernetes Attacks — pending
- Wireless Attacks — pending
- Bluetooth Attacks — pending
- Mobile Exploitation — pending
- Data Exfiltration — pending
- Steganography — pending
- AV/EDR Evasion — pending
- Living Off The Land (LOTL) — pending
- OPSEC — pending
- Infrastructure Setup — pending
- Redirectors & Proxies — pending
- Traffic Obfuscation — pending
- ICS / OT Attacks — pending
- Hardware Hacking
- USB Attacks — pending
- RFID/NFC Attacks — pending
- Red Team Automation — pending
- Adversary Simulation — pending
- Reporting — pending
Blue Team
- Security Monitoring
- Log Analysis — pending
- Threat Detection — pending
- Detection Engineering — pending
- Threat Hunting — pending
- Incident Response — pending
- Digital Forensics — pending
- Memory Forensics — pending
- Disk Forensics — pending
- Network Forensics
- Malware Analysis — pending
- Static Malware Analysis — pending
- Dynamic Malware Analysis — pending
- Reverse Engineering
- SIEM — pending
- SOAR — pending
- EDR — pending
- XDR — pending
- NDR — pending
- IDS/IPS — pending
- Firewall Management — pending
- Network Security — pending
- Endpoint Security — pending
- Server Security — pending
- Windows Security — pending
- Linux Security — pending
- Active Directory Security — pending
- Identity & Access Management (IAM) — pending
- Privileged Access Management (PAM) — pending
- Authentication Security — pending
- Email Security — pending
- Phishing Analysis — pending
- Web Security — pending
- Browser Security — pending
- Application Security — pending
- API Security — pending
- Cloud Security
- AWS Security — pending
- Azure Security — pending
- Container Security — pending
- Kubernetes Security — pending
- Data Loss Prevention (DLP) — pending
- Data Classification — pending
- Encryption & PKI — pending
- Vulnerability Management — pending
- Patch Management — pending
- Attack Surface Management — pending
- Exposure Management — pending
- Risk Management — pending
- Compliance & GRC — pending
- Security Awareness — pending
- Insider Threat Detection — pending
- Threat Intelligence — pending
- IOC Analysis — pending
- YARA & Sigma Rules — pending
- Deception Technology — pending
- Honeypots — pending
- Backup & Recovery Security — pending
- Business Continuity — pending
- Disaster Recovery — pending
- Mobile Security — pending
- Wireless Security — pending
- IoT Security — pending
- ICS / OT Security — pending
- Security Automation — pending
- Breach & Attack Simulation — pending
- Purple Teaming — pending
- SOC Operations — pending
- Case Management — pending
- Reporting & Dashboards — pending
- AI Security — pending
Purple Team
- Adversary Simulation — pending
- Detection Validation — pending
- Breach & Attack Simulation (BAS) — pending
- Attack Emulation — pending
- Detection Engineering Validation — pending
- MITRE ATT&CK Mapping — pending
- SOC Validation Workflows — pending
- Attack Replay Concepts — pending
- Security Control Testing — pending
- Continuous Security Validation — pending