Apps
Every tool Oniomarchy installs, in one searchable list — 100 of them, from port scanners to SDR receivers to browser-based OSINT sites. Search matches a tool's name, its category, or what it does. Press / to jump to the search box.
dirbInformation GatheringThe classic recursive web content scanner.ffufInformation Gathering"Fuzz Faster U Fool" — a fast, flexible web fuzzer for content and parameter discovery.gobusterInformation GatheringBrute-forcing hidden directories, DNS subdomains, and virtual hosts.masscanInformation GatheringAsynchronous port scanning at internet scale — thousands of hosts a second.nmapInformation GatheringThe port and service scanner that starts almost every engagement.recon-ngInformation GatheringA full web-reconnaissance framework with a module marketplace and a Metasploit-like console.sherlockInformation GatheringHunt a single username across hundreds of social networks and sites.theHarvesterInformation GatheringEmails, subdomains, hosts, and employee names from dozens of public sources.niktoVulnerability AnalysisThe classic web server scanner — thousands of checks for risky files, outdated software, and misconfigurations.nucleiVulnerability AnalysisA fast, template-driven vulnerability scanner backed by a huge community ruleset.sslscanVulnerability AnalysisA fast, focused scanner for a server's SSL/TLS configuration — protocols, ciphers, and certificate.burpsuiteWeb Application AnalysisThe industry-standard intercepting proxy and web application testing platform.caidoWeb Application AnalysisA modern, fast intercepting proxy — a lightweight alternative to Burp.sqlmapWeb Application AnalysisAutomated detection and exploitation of SQL injection flaws.wfuzzWeb Application AnalysisA web fuzzer for brute-forcing parameters, paths, headers, and forms.wpscanWeb Application AnalysisA vulnerability scanner built specifically for WordPress.hashcatPassword AttacksThe GPU-accelerated password recovery tool — the fastest way to crack hashes.hydraPassword AttacksA fast online login brute-forcer supporting dozens of protocols.johnPassword AttacksJohn the Ripper — the flexible offline password hash cracker.WordlistsPassword AttacksSecLists (rockyou.txt included) and the packaged wordlists collection — the fuel every guessing attack runs on.aircrack-ngWireless AttacksThe complete Wi-Fi security auditing suite — monitor, capture, inject, and crack.airgeddonWireless AttacksA menu-driven multi-tool covering handshake capture, WPS, Evil Twin, WPA3, and DoS attacks in one script.bullyWireless AttacksAn alternative WPS PIN/Pixie-Dust attack engine, more resilient than reaver against some APs.cowpattyWireless AttacksA WPA/WPA2-PSK dictionary attack tool, with precomputed hash files for fast repeat cracking.fern-wifi-crackerWireless AttacksA graphical front end for WEP/WPA/WPS cracking and related network attacks, built on the aircrack suite.hcxdumptoolWireless AttacksA purpose-built capture tool for WPA handshakes and PMKIDs, feeding hcxtools/hashcat directly.hcxtoolsWireless AttacksConverts captured WPA handshakes/PMKIDs into the hash formats hashcat and John actually crack.hostapdWireless AttacksThe user-space AP daemon behind fake-AP, Evil-Twin, and karma-style attacks.kismetWireless AttacksA wireless detector, sniffer, and IDS spanning Wi-Fi, Bluetooth, and more.pixiewpsWireless AttacksThe offline half of a Pixie-Dust attack — recovers a weak WPS PIN from captured exchange data.reaverWireless AttacksThe classic WPS PIN brute-force and Pixie-Dust attack tool — wifite's default engine underneath.wifiteWireless AttacksAutomated wireless auditing — point it at the air and it does the work.airspySoftware Defined RadioUtilities for Airspy receivers — higher dynamic range than the RTL dongles.chirp-nextSoftware Defined RadioRead, edit, and write the memory channels on a handheld or mobile radio — hundreds of supported models.cubicsdrSoftware Defined RadioA cross-platform SDR receiver built around a bold, fluid waterfall.dump1090Software Defined RadioDecode aircraft ADS-B transponders and watch planes appear on a live map.gnuradioSoftware Defined RadioThe signal-processing toolkit and visual flowgraph environment underneath most SDR work.gqrxSoftware Defined RadioA graphical SDR receiver with a live spectrum and waterfall display.hackrfSoftware Defined RadioTools for the HackRF One — a wide-range, transmit-capable SDR.inspectrumSoftware Defined RadioOffline analysis of captured signal files — the magnifying glass for a recorded transmission.limesuiteSoftware Defined RadioDrivers, GUI, and utilities for the LimeSDR family — full-duplex and transmit-capable.multimon-ngSoftware Defined RadioDecode pager messages (POCSAG), AIS, and a range of other digital radio modes.qspectrumanalyzerSoftware Defined RadioA spectrum-analyzer GUI that turns an SDR into a wideband band survey tool.rtl_433Software Defined RadioDecode the chatter of hundreds of IoT and sensor devices on the 433/868/915 MHz bands.rtl-sdrSoftware Defined RadioDrivers and utilities for the ubiquitous RTL2832U dongles — the entry point to SDR.soapysdrSoftware Defined RadioA vendor-neutral abstraction layer so SDR tools work across every device.supersdrSoftware Defined RadioA client for networked KiwiSDR receivers — use someone else's radio, anywhere in the world.urhSoftware Defined RadioUniversal Radio Hacker — capture, decode, and reverse-engineer unknown wireless protocols.apktoolReverse EngineeringDisassemble, modify, and rebuild Android APK resources and smali code.binwalkReverse EngineeringAnalyze firmware images and carve out the files hidden inside them.ghidraReverse EngineeringThe NSA's open-source reverse-engineering suite, with a full decompiler.jadxReverse EngineeringDecompile Android APKs and DEX files back into readable Java.radare2Reverse EngineeringA powerful, scriptable command-line reverse-engineering framework.armitageExploitation ToolsA graphical front end and team collaboration console for Metasploit.beefExploitation ToolsThe Browser Exploitation Framework — hook web browsers and drive them from a control panel.metasploitExploitation ToolsThe exploitation framework — exploits, payloads, and post-exploitation in one place.routersploitExploitation ToolsA Metasploit-style exploitation framework aimed at routers and embedded devices.searchsploitExploitation ToolsSearch the entire Exploit-DB archive offline, from the command line.bettercapSniffing & SpoofingThe modern, modular Swiss Army knife for network reconnaissance and MITM attacks.ettercapSniffing & SpoofingThe classic man-in-the-middle suite — ARP poisoning, sniffing, and traffic manipulation.responderSniffing & SpoofingPoison Windows name-resolution broadcasts to capture credentials on a network.wiresharkSniffing & SpoofingThe definitive graphical packet analyzer — see every byte on the wire.impacketPost ExploitationA deep collection of Python scripts for Windows and Active Directory protocol attacks.PEASS-ngPost ExploitationlinPEAS and winPEAS — the privilege-escalation enumeration scripts you run on a target, not on your own box.powershell-empirePost ExploitationThe classic PowerShell and Python post-exploitation command-and-control framework.sliverPost ExploitationA modern, open-source command-and-control framework for managing implants.autopsyDigital ForensicsA graphical case-management front end over The Sleuth Kit.exiftoolDigital ForensicsRead and write metadata in almost any file — EXIF, GPS, authorship, and much more.foremostDigital ForensicsCarve files out of a disk image or raw device by their signatures.mat2Digital ForensicsStrip metadata from files before you share them — the privacy side of forensics.sleuthkitDigital ForensicsThe command-line toolkit for disk and filesystem forensics.steghideDigital ForensicsHide data inside images and audio files — and recover what others have hidden.testdiskDigital ForensicsRecover lost partitions and deleted files — and, with PhotoRec, carve data from damaged media.volatility3Digital ForensicsThe memory-forensics framework — pull processes, connections, and secrets out of a RAM dump.cherrytreeReporting ToolsA hierarchical notebook for keeping structured, searchable engagement notes.eyewitnessReporting ToolsScreenshot web services at scale and build a single browsable report.maltegoReporting ToolsVisual link analysis — graphing the relationships between people, domains, and infrastructure.gophishSocial Engineering ToolsA polished phishing-campaign platform with templates, tracking, and reporting.setoolkitSocial Engineering ToolsThe Social-Engineer Toolkit — the standard framework for social-engineering attacks.can-utilsAutomotiveThe command-line SocketCAN toolkit — dump, send, replay, and generate CAN bus traffic.hexstrike-aiAI ToolsAn MCP server that puts ~150 security tools in the hands of an AI agent.metasploit-mcpAI ToolsMetasploit's own MCP server — drive the framework from an AI agent.any.runWebappsInteractive malware sandbox in the browser.ATT&CK NavigatorWebappsMap and annotate techniques against the MITRE ATT&CK matrix.CensysWebappsAnother perspective on internet-wide host and certificate data.CyberChefWebappsThe "cyber Swiss Army knife" — encode, decode, and transform data.Exploit-DBWebappsThe web front end to the public exploit archive.GTFOBinsWebappsUnix binaries that can be abused to break out or escalate.Have I Been PwnedWebappsCheck email addresses and passwords against known breaches.KiwiSDR Public ReceiversWebappsDirectory of public networked SDRs to listen through.LOLBASWebappsThe Windows equivalent — living-off-the-land binaries and scripts.OSINT FrameworkWebappsA curated directory of OSINT resources, by category.PimEyesWebappsReverse face-search across the web.revshells.comWebappsGenerate reverse-shell one-liners for any language and listener.ShodanWebappsSearch engine for internet-connected devices and services.SIGIDWikiWebappsThe signal-identification guide — figure out what you're hearing.SSL LabsWebappsDeep analysis of a site's TLS configuration.urlscan.ioWebappsScan and analyze what a URL actually loads and does.VirusTotalWebappsScan files and URLs against dozens of antivirus engines.WiGLEWebappsThe global database of wireless networks, mapped.
no tools match that search —