This file is a flat reference. The same data is rendered in the
README with collapsible sections, and is the
source-of-truth in haxbox/data/tools.py.
To regenerate this file from the catalog:
python3 haxbox.py --list | column -t -s $'\t'- Anonymity & Privacy — Tor, ProxyChains-NG, Mullvad VPN, Whonix, Tails, AnonSurf
- OSINT & Information Gathering — Maltego, Sherlock, Maigret, Spiderfoot, GHunt, Holehe, theHarvester, Recon-ng, Photon, PhoneInfoga, Mosint, Toutatis, WhatsMyName, Snoop
- Modern Recon (ProjectDiscovery) ★ — nuclei, httpx, subfinder, naabu, katana, dnsx, chaos-client, interactsh, notify, tlsx, gowitness
- Web Application Testing — Burp, ZAP, sqlmap, ffuf, gobuster, feroxbuster, dalfox, wpscan, Nikto, Wapiti, XSStrike, Commix, nuclei-templates, Arjun, ParamSpider, SecLists, tplmap, SSRFmap
- API & GraphQL ★ — Kiterunner, InQL, graphql-cop, GraphQL Voyager, Akto, Postman, Insomnia, Hetty, Caido
- Cloud Security ★ — Prowler, ScoutSuite, CloudFox, Pacu, CloudSploit, Cartography, enumerate-iam, aws-recon, PMapper, Stormspotter, PurplePanda, CloudBrute
- Container & Kubernetes ★ — Trivy, Grype, kube-hunter, kubescape, kube-bench, Peirates, Dockle, Falco, Hadolint, Checkov
- Mobile Application Testing — MobSF, Frida, Objection, jadx, apktool, Drozer, House, Quark-Engine, androguard, r2frida, iLEAPP
- Wireless & SDR — Aircrack-ng, Wifite2, Bettercap, Kismet, Hcxdumptool, Reaver, Fluxion, Airgeddon, GNU Radio
- Forensics & DFIR ★ — Velociraptor, Volatility 3, Autopsy, Sleuthkit, plaso, MISP, TheHive, Cortex, YARA, DFIR-IRIS, Hayabusa, Chainsaw
- Reverse Engineering — Ghidra, Cutter, Radare2, x64dbg, Binary Ninja Free, IDA Free, angr, pwndbg, GEF, BinDiff
- Exploitation Frameworks — Metasploit, Sliver, Mythic, Havoc, Empire, Villain, Caldera
- Password & Hash Attacks — hashcat, John, hydra, kerbrute, CeWL, crunch, Hashes.com, Cupp, Mentalist
- Phishing & Social Engineering — GoPhish, evilginx2, SET, Modlishka, Zphisher, King-Phisher
- Hardware & IoT — binwalk, firmwalker, EMBA, Routersploit, FACT, firmware-mod-kit, HardSploit, CHIPSEC
- Steganography — steghide, zsteg, stegseek, exiftool, OpenStego, foremost
- AI / LLM Red Team ★★ — Garak, PyRIT, promptfoo, llm-guard, vigil-llm, Rebuff, Counterfit, HouYi, GPTFuzzer
- Supply Chain Security ★★ — Syft, Grype, OSV-Scanner, Trivy, cosign, dep-scan, Snyk CLI, npm-audit-resolver
- Blue Team & Detection ★★ — Wazuh, Sigma, Atomic Red Team, Caldera, Suricata, Zeek, OSSEC, Velociraptor, TheHive, MISP, DetectionLab
- CTF Helpers — CyberChef, RsaCtfTool, pwntools, gef, pwndbg, angr, stegsolve, aperisolve, dCode
- Reporting & Notes ★ — SysReptor, PwnDoc, Dradis CE, Obsidian, CherryTree, Trilium
- Learning Resources — HackTheBox, TryHackMe, PortSwigger Academy, OWASP, PentesterLab, VulnHub, PicoCTF, OverTheWire, HackerOne CTF, PayloadsAllTheThings, HackTricks
- Automation & Workflows — reNgine, Axiom, BBRF, Sn1per, Osmedeus, n8n, Trickest
★ = category not present in legacy hackingtool-style repos.
★★ = category that did not meaningfully exist when those repos were written.