WeaponizeKali.sh is a Bash script aimed at automating the process of downloading and installing extra tools for internal penetration tests with Kali Linux.
Basic principles behind this project are:
- Use bleeding-edge versions of offensive toolkits to possess their latest features and fixes.
- When installing 3rd party software, use isolated environments to minimize potential dependency hell.
- Keep Windows exploitation scripts and binaries on hand in case you find yourself in an "offline situation".
The script will create two directories within CWD: tools
and www
. The first one contains all the tools that will be installed on Kali. The second one contains all the scripts and binaries that will be downloaded and may be delivered onto the victim host later.
DISCLAIMER. All information contained in this repository is provided for educational and research purposes only. The author is not responsible for any illegal misuse of this tool.
WeaponizeKali.sh heavily relies on Python virtual environments and uses pipx and poetry to orchestra venvs.
In order to launch the bleeding-edge version of a tool installed with pipx and not the version that is already shipped with Kali, you should modify the PATH
variables:
- Modify
PATH
for a normal user with any method you want (.bashrc
/.profile
/.zshrc
/ etc.):export PATH="$HOME/.local/bin:$PATH"
. - Modify
PATH
for the superuser by modifyingsecure_path
within sudoers (sudo visudo
):
Now you can download WeaponizeKali.sh and run it from your home directory (pip may prompt for unlocking the keyring during the process). When it's done, you can check the results in ~/tools
and ~/www
:
~$ cd
~$ bash <(curl -sL https://github.com/penetrarnya-tm/WeaponizeKali.sh/raw/main/WeaponizeKali.sh) -cidtw
~$ ls -la tools www
-i
switch, existing ./tools
and ./www
directories will be deleted.
If you only want to get the deliverable scripts and binaries (i.e., www
directory), you can do it like this:
~$ mkdir www
~$ bash <(curl -sL https://github.com/penetrarnya-tm/WeaponizeKali.sh/raw/main/WeaponizeKali.sh) -w
~$ ls -la www
It's recommended to run WeaponizeKali.sh once on a clean installation of Kali Linux.
To execute WeaponizeKali.sh with full set of arguments again after it has already been ran once, remove the existent virtual environments first and then run the script:
~$ cd
~$ pipx uninstall-all
~$ sudo rm -rf ~/{.local/pipx,tools,www}
~$ ./WeaponizeKali.sh -cidtw
~$ ./WeaponizeKali.sh -h
)
( ( ( /( ( )
)\))( ' ( ) ( ( )\()) ) )\ ( ( /(
((_)()\ ) ))\ ( /( ` ) ( ( )\ ( ))\ ((_)\ ( /( ((_))\ ( )\())
_(())\_)() /((_))(_)) /(/( )\ )\ )((_) )\ /((_) _ ((_))(_)) _ ((_) )\ ((_)\
\ \((_)/ /(_)) ((_)_ ((_)_\ ((_) _(_/( (_)((_)(_)) | |/ /((_)_ | | (_) ((_)| |(_
\ \/\/ / / -_)/ _` || '_ \)/ _ \| ' \))| ||_ // -_) | ' < / _` || | | | _ (_-<| ' \
\_/\_/ \___|\__,_|| .__/ \___/|_||_| |_|/__|\___| |_|\_\\__,_||_| |_|(_)/__/|_||_|
|_|
"the more tools you install, the more you are able to PWN"
{ https://github.com/penetrarnya-tm/WeaponizeKali.sh } { vX.Y.Z }
usage: WeaponizeKali.sh [-h] [-i] [-d] [-t] [w]
optional arguments:
-c use Docker when installing tools if possible
-h show this help message and exit
-i initialize filesystem (re-create ./tools and ./www directories)
-d resolve dependencies
-t download and install tools on Kali Linux
-w download scripts and binaries for delivering onto the victim host
Install the laster version of Evil-WinRM using rbenv
:
~$ zsh <(curl -sSL https://github.com/penetrarnya-tm/WeaponizeKali.sh/raw/sh/misc/evil-winrm.sh)
Create armored .ps1
scripts containing all the PowerShell tools you want with PowerShellArmoury:
PS > git clone https://github.com/cfalta/PowerShellArmoury
PS > cd PowerShellArmoury
PS > curl https://github.com/penetrarnya-tm/WeaponizeKali.sh/raw/main/misc/PSArmoury.json -o PSArmoury.json
PS > . .\New-PSArmoury.ps1
PS > New-PSArmoury -ValidateOnly -Config PSArmoury.json
PS > New-PSArmoury -Path armored.ps1 -Config PSArmoury.json
PS > cat -raw .\armored.ps1 | iex
Get a random name of a .exe
or .dll
binary:
~$ EXE="`curl -sL https://github.com/penetrarnya-tm/WeaponizeKali.sh/raw/main/misc/binaries.txt | shuf -n1`.exe"
~$ DLL="`curl -sL https://github.com/penetrarnya-tm/WeaponizeKali.sh/raw/main/misc/system32-dlls.txt | shuf -n1`.dll"
- APIHashReplace
- AutoBlue-MS17-010
- Amsi-Bypass-Powershell
- BloodHound · FORK
- BloodHound.py
- CVE-2019-1040-scanner
- CVE-2020-1472-checker
- CVE-2021-1675 (MS-RPRN) · CVE-2021-1675 (MS-PAR) · CVE-2021-1675 · SharpPrintNightmare
- Certipy
- Coercer
- Covenant · Stageless_Covenant_HTTP.cs
- CrackMapExec
- DFSCoerce
- DInjector
- DLLsForHackers
- DivideAndScan
- DonPAPI
- Ebowla
- Empire
- InvisibilityCloak
- ItWasAllADream
- LDAPPER
- LDAPmonitor
- LdapRelayScan
- LightMe
- MS17-010
- MANSPIDER
- Masky · PS1 (Agent)
- Max
- MeterPwrShell
- Neo-reGeorg
- Nim · choosenim
- Nimcrypt2
- NimlineWhispers
- Obsidian
- PCredz
- PEzor
- PKINITtools
- PetitPotam
- PetitPotam-Ext
- Physmem2profit · PS1
- PoshC2
- PrivExchange
- Responder
- RustScan
- SCShell
- ScareCrow
- ShadowCoerce
- SharpGen
- ShellPop
- Shhhloader
- SilentHound
- Sliver
- TrustVisualizer
- WebclientServiceScanner
- Windows-Exploit-Suggester
- ZeroTier
- aced
- ack3
- aclpwn.py
- adidnsdump
- aquatone
- arsenal
- bettercap
- bloodhound-import
- bloodhound-quickwin
- bloodyAD
- certi
- chisel · SharpChisel · EXE
- crowbar
- dementor.py
- dnsx
- donut
- dsniff
- eavesarp
- enum4linux-ng
- evil-winrm
- feroxbuster
- ffuf
- gMSADumper
- gateway-finder-imp
- go-windapsearch · windapsearch.bin
- gobuster
- hashcat-utils
- hoaxshell
- http-server
- httpx
- impacket · impacket-snovvcrash
- iCULeak.py
- ipmitool
- kerbrute
- krbrelayx
- ldap_shell
- ldapdomaindump
- ldapsearch-ad
- ldeep
- ligolo-proxy
- lsassy
- mapcidr
- masscan
- mitm6
- mscache
- nac_bypass-snovvcrash
- nextnet
- nishang
- noPac
- ntlm-scanner
- ntlmv1-multi
- nullinux
- odat
- paperify
- payloadGenerator
- powerview.py
- pretender
- pywsus
- pyGPOAbuse
- pyKerbrute
- pypykatz
- pywerview
- pywhisker
- rbcd-attack
- rbcd_permissions
- rdp-tunnel
- rtfm
- sRDI
- seclists
- sgn
- smartbrute
- snmpwn
- spraykatz
- ssb
- sshspray
- sshuttle
- targetedKerberoast
- ticket_converter
- traitor
- transfer.sh
- updog
- webpage2html
- wesng
- windapsearch
- wmiexec-RegOut
- xc
- yersina
- ADCSPwn · PS1
- ADRecon.ps1
- ADSearch · EXE
- ASREPRoast.ps1
- AccessChk (Sysinternals) · AccessChk (accepteula)
- Certify · EXE
- DDexec
- DefenderStop
- Discover-PSMSExchangeServers
- Discover-PSMSSQLServers
- Divert · SYS
- DomainPasswordSpray.ps1
- Get-RdpLogonEvent.ps1
- Grouper2
- HandleKatz · PS1
- HiveNightmare · ShadowSteal · EXE
- Intercept-NG
- Inveigh · PS1 · EXE
- Invoke-ACLPwn.ps1
- Invoke-ConPtyShell.ps1
- Invoke-ImpersonateUser-PTH.ps1
- Invoke-PSInject.ps1
- Invoke-PatchWdigest.ps1
- Invoke-Portscan.ps1
- Invoke-RunasCs.ps1
- Invoke-SMBClient.ps1
- Invoke-SMBEnum.ps1
- Invoke-SMBExec.ps1
- Invoke-WMIExec.ps1
- Invoke-noPac.ps1
- JAWS
- JuicyPotato64 · JuicyPotato32
- KSC-Console
- KeeThief · PS1
- KrbRelay · EXE
- KrbRelayUp · EXE
- LaZagne
- MirrorDump · PS1
- OffensivePythonPipeline
- Out-EncryptedScript.ps1
- PEASS
- PSTools
- PingCastle
- PowerShellArmoury · PSArmoury.json
- PowerUp.ps1
- PowerUpSQL.ps1
- PowerView2.ps1
- PowerView3.ps1 (New-GPOImmediateTask)
- PowerView3.ps1
- PowerView4.ps1 (by @exploitph)
- Powermad.ps1
- PrivescCheck.ps1
- PrintSpoofer
- PwnKit
- Python 2.7.18
- RawCopy
- RemotePotato0
- RoguePotato
- RestrictedAdmin · PS1
- Rubeus · EXE
- RunOF · PS1
- SandboxDefender · EXE
- Seatbelt · EXE
- SessionGopher.ps1
- SharpChrome · EXE
- SharpDPAPI · EXE
- SharpGPOAbuse · EXE
- SharpHandler · EXE
- SharpHound
- SharpLAPS
- SharpNamedPipePTH · EXE · PS1
- SharpRDP · EXE
- SharpRdpThiefInjector · PS1
- SharpRelay · EXE
- SharpSCCM · PS1
- SharpSecDump · EXE
- SharpStrike · EXE (Console) · EXE (GUI)
- SharpSystemTriggers · PS1
- SharpView · EXE
- SharpWMI · EXE
- SharpWebServer
- Sherlock.ps1
- Snaffler
- SpoolSample · EXE
- StandIn · EXE
- VeraCryptThiefInjector · PS1
- WerTrigger
- WinPwn · PowerSharpPack · Creds
- Wireshark
- arpfox
- chisel
- les.sh
- lse.sh
- mimikatz
- nanodump · PS1
- netcat for Windows
- pamspy
- plink
- powercat.ps1
- pspy
- rdp-tunnel · rdp2tcp.exe
- revsocks
- static-binaries
- suid3num.py
- tokenduplicator · PS1