网络工具 - 安全工具目录 API

API ID 14094

通过名称、类别、操作标签和操作系统搜索594个精选的渗透测试和安全工具 安装命令 使用示例 JSON

API 文档

端点

请求
总工具数量加上每个类别和每个操作标签的数量 返回安全工具目录的JSON统计数据
Endpoint ID: 34800
GET https://zylalabs.com/api/14094/cybertools+-+security+tools+catalog+api/34800/getstats
输入参数

剩余免费测试请求:3 / 3。

此端点不需要任何输入参数。

API 示例响应
JSON
{
    "total": 594,
    "categories": [
        {
            "categories": "Exploitation",
            "count": 256
        },
        {
            "categories": "Post-Exploitation",
            "count": 170
        },
        {
            "categories": "Recon",
            "count": 168
        }
    ],
    "actionTags": [
        {
            "tag": "scanner",
            "count": 324
        },
        {
            "tag": "exploit-framework",
            "count": 90
        },
        {
            "tag": "password-cracker",
            "count": 51
        },
        {
            "tag": "payload-generator",
            "count": 50
        },
        {
            "tag": "credential-dumper",
            "count": 38
        },
        {
            "tag": "proxy/tunnel",
            "count": 35
        },
        {
            "tag": "reverse-engineering",
            "count": 35
        },
        {
            "tag": "enumeration",
            "count": 31
        },
        {
            "tag": "social-engineer",
            "count": 24
        },
        {
            "tag": "osint",
            "count": 22
        },
        {
            "tag": "brute-force",
            "count": 18
        },
        {
            "tag": "packet-sniffer",
            "count": 15
        },
        {
            "tag": "privesc",
            "count": 14
        },
        {
            "tag": "steganography",
            "count": 11
        },
        {
            "tag": "fuzzer",
            "count": 11
        },
        {
            "tag": "wireless",
            "count": 10
        },
        {
            "tag": "malware-analysis",
            "count": 10
        },
        {
            "tag": "memory-forensics",
            "count": 7
        },
        {
            "tag": "reporting",
            "count": 7
        },
        {
            "tag": "wordlist-generator",
            "count": 4
        },
        {
            "tag": "decoder",
            "count": 1
        },
        {
            "tag": "cryptography",
            "count": 1
        },
        {
            "tag": "ctf",
            "count": 1
        }
    ]
}
获取统计信息 — 代码片段

curl --location --request GET 'https://zylalabs.com/api/14094/cybertools+-+security+tools+catalog+api/34800/getstats' --header 'Authorization: Bearer YOUR_API_KEY' 


    
请求
按名称返回安全工具 所有查询参数都是可选的并且组合使用 AND 按 q 搜索 按类别 标签 和 操作系统 过滤 通过 id 检索工具 使用 limit 和 offset 进行分页
Endpoint ID: 34801
GET https://zylalabs.com/api/14094/cybertools+-+security+tools+catalog+api/34801/listtools
输入参数

错误 — 端点功能

对象 描述
q 可选 Optional text search by tool name and description.
category 可选 Optional tool category filter, such as Recon, Exploitation or Post-Exploitation.
tag 可选 Optional action tag filter, such as scanner, enumeration or sniffer.
os 可选 Optional supported operating system filter.
id 可选 Optional numeric tool ID to retrieve a single tool.
limit 可选 Optional number of tools returned per page.
offset 可选 Optional number of matching tools to skip for pagination.

剩余免费测试请求:3 / 3。


输入参数

q
category
tag
os
id
limit
offset
API 示例响应
JSON
{
    "tools": [
        {
            "id": 103,
            "name": "1password2john",
            "short_description": "1Password vault cracker",
            "long_description": "Converts 1Password vault files to John the Ripper format. Useful for cracking 1Password master passwords and accessing stored credentials.",
            "install_info": "sudo apt install john && locate 1password2john || git clone https://github.com/openwall/john.git && cd john/run",
            "example_usage": "1password2john vault.1pux > hash.txt && john hash.txt",
            "categories": "Post-Exploitation",
            "action_tags": "credential-dumper;password-cracker",
            "os_tags": "Linux;Windows;macOS"
        },
        {
            "id": 195,
            "name": "3proxy",
            "short_description": "Tiny free proxy server for various protocols.",
            "long_description": "3proxy is a tiny free proxy server with support for HTTP(S),go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest, POP3, SMTP, FTP, TCP and UDP protocols. It can be used for pivoting and tunneling in penetration testing.",
            "install_info": "sudo apt-get install 3proxy",
            "example_usage": "3proxy /etc/3proxy/3proxy.cfg",
            "categories": "Post-Exploitation",
            "action_tags": "proxy/tunnel",
            "os_tags": "Linux;Windows"
        },
        {
            "id": 69,
            "name": "3uTools",
            "short_description": "iOS device management and jailbreak",
            "long_description": "All-in-one tool for iOS device management, jailbreaking, and data extraction. Supports firmware flashing and device information gathering.",
            "install_info": "Download from http://www.3u.com/",
            "example_usage": "Launch 3uTools and connect iOS device",
            "categories": "Exploitation",
            "action_tags": "exploit-framework",
            "os_tags": "Windows;iOS"
        },
        {
            "id": 110,
            "name": "7z2john",
            "short_description": "7-Zip archive password cracker",
            "long_description": "Extracts password hashes from 7-Zip archives for cracking with John the Ripper. Essential for accessing password-protected 7z files.",
            "install_info": "sudo apt install john && locate 7z2john || git clone https://github.com/openwall/john.git && cd john/run",
            "example_usage": "7z2john archive.7z > hash.txt && john hash.txt",
            "categories": "Post-Exploitation",
            "action_tags": "password-cracker;credential-dumper",
            "os_tags": "Linux;Windows;macOS"
        },
        {
            "id": 392,
            "name": "aclpwn",
            "short_description": "Active Directory ACL exploitation",
            "long_description": "Tool for exploiting Active Directory Access Control Lists (ACLs) to escalate privileges and move laterally through domain environments.",
            "install_info": "pip install aclpwn",
            "example_usage": "aclpwn -f [email protected] -t [email protected]",
            "categories": "Exploitation",
            "action_tags": "exploit-framework",
            "os_tags": "Linux;Windows"
        },
        {
            "id": 325,
            "name": "adminer",
            "short_description": "Database administration web interface",
            "long_description": "Lightweight database management tool that can be used as a web shell when uploaded to compromised servers. Supports multiple database types and provides full database access.",
            "install_info": "wget https://www.adminer.org/latest.php -O adminer.php",
            "example_usage": "Upload adminer.php and access via browser",
            "categories": "Exploitation",
            "action_tags": "payload-generator",
            "os_tags": "Linux;Windows;macOS"
        },
        {
            "id": 196,
            "name": "Aircrack-ng",
            "short_description": "Complete suite of tools to assess WiFi network security.",
            "long_description": "Aircrack-ng is a complete suite of tools to assess WiFi network security. It focuses on different areas of WiFi security: monitoring, attacking, testing, and cracking.",
            "install_info": "sudo apt-get install aircrack-ng",
            "example_usage": "aircrack-ng -w /usr/share/wordlists/rockyou.txt -b 00:11:22:33:44:55 capture.cap",
            "categories": "Exploitation",
            "action_tags": "password-cracker;brute-force;packet-sniffer;wireless",
            "os_tags": "Linux"
        },
        {
            "id": 197,
            "name": "Aireplay-ng",
            "short_description": "Wireless packet injection tool for WiFi attacks.",
            "long_description": "Aireplay-ng is used to inject frames. The primary function is to generate traffic for the later use in aircrack-ng for cracking the WEP and WPA-PSK keys.",
            "install_info": "Part of aircrack-ng suite - sudo apt-get install aircrack-ng",
            "example_usage": "aireplay-ng -0 1 -a 00:11:22:33:44:55 -c 00:11:22:33:44:66 wlan0mon",
            "categories": "Exploitation",
            "action_tags": "exploit-framework;wireless",
            "os_tags": "Linux"
        },
        {
            "id": 117,
            "name": "Airmon-ng",
            "short_description": "Script to enable and disable monitor mode on wireless interfaces.",
            "long_description": "Airmon-ng is used to enable and disable monitor mode on wireless interfaces. It may also be used to go back from monitor mode to managed mode.",
            "install_info": "Part of aircrack-ng suite - sudo apt-get install aircrack-ng",
            "example_usage": "airmon-ng check kill\nairmon-ng start wlan0",
            "categories": "Recon",
            "action_tags": "scanner;wireless",
            "os_tags": "Linux"
        },
        {
            "id": 118,
            "name": "Airodump-ng",
            "short_description": "Wireless packet capture tool for monitoring WiFi networks.",
            "long_description": "Airodump-ng is used for packet capturing of raw 802.11 frames and is particularly suitable for collecting WEP IVs (Initialization Vectors) for the intent of using them with aircrack-ng.",
            "install_info": "Part of aircrack-ng suite - sudo apt-get install aircrack-ng",
            "example_usage": "airodump-ng wlan0mon",
            "categories": "Recon",
            "action_tags": "packet-sniffer;wireless",
            "os_tags": "Linux"
        },
        {
            "id": 519,
            "name": "alchemy",
            "short_description": "Alchemy CPU attack framework",
            "long_description": "Framework for CPU-based attacks including cache and timing attacks against cryptographic implementations.",
            "install_info": "git clone https://github.com/FPSG-UIUC/alchemy.git && cd alchemy && sudo apt install -y python3-numpy python3-scipy && make",
            "example_usage": "python3 alchemy.py --attack cache --target openssl",
            "categories": "Exploitation",
            "action_tags": "scanner",
            "os_tags": "Linux;Windows"
        },
        {
            "id": 322,
            "name": "alfashell",
            "short_description": "Multi-language web shell collection",
            "long_description": "Collection of web shells in various languages including PHP ASP and JSP. Features advanced functionality and evasion techniques for maintaining persistence.",
            "install_info": "git clone https://github.com/offensive-security/exploitdb.git && find . -name \"*alfa*\"",
            "example_usage": "Upload appropriate shell based on target technology",
            "categories": "Exploitation",
            "action_tags": "payload-generator",
            "os_tags": "Linux;Windows;macOS"
        },
        {
            "id": 119,
            "name": "Altdns",
            "short_description": "Generates permutations, alterations and mutations of subdomains.",
            "long_description": "Altdns is a DNS recon tool that allows for the discovery of subdomains that conform to patterns. It takes in words that could be present in subdomains and generates a large list of potential subdomains.",
            "install_info": "pip3 install py-altdns",
            "example_usage": "altdns -i subdomains.txt -o data_output -w words.txt -r -s results_output.txt",
            "categories": "Recon",
            "action_tags": "scanner",
            "os_tags": "Linux;Windows;macOS"
        },
        {
            "id": 120,
            "name": "Amass",
            "short_description": "OWASP subdomain enumeration tool.",
            "long_description": "Amass is an OWASP project that performs network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.",
            "install_info": "go install -v github.com/owasp-amass/amass/v3/...@master",
            "example_usage": "amass enum -d example.com\namass intel -d example.com",
            "categories": "Recon",
            "action_tags": "scanner;enumeration;osint",
            "os_tags": "Linux;Windows;macOS"
        },
        {
            "id": 350,
            "name": "Anonsurf",
            "short_description": "Anonymous surfing through Tor"
        }
    ],
    "_note": "Response truncated for documentation purposes"
}
错误 — 代码片段

curl --location --request GET 'https://zylalabs.com/api/14094/cybertools+-+security+tools+catalog+api/34801/listtools' --header 'Authorization: Bearer YOUR_API_KEY' 


    

API 访问密钥和身份验证

注册后,每个开发者都会被分配一个个人 API 访问密钥,这是一个唯一的字母和数字组合,用于访问我们的 API 端点。要使用 网络工具 - 安全工具目录 API 进行身份验证,只需在 Authorization 标头中包含您的 bearer token。

标头
标头 描述
授权 必需 应为 Bearer access_key. 订阅后,请查看上方的"您的 API 访问密钥"。

无长期承诺。随时升级、降级或取消。 免费试用包括最多 50 个请求。

起价
$10,000/年


  • 自定义数量
  • 自定义速率限制
  • 专业客户支持
  • 实时 API 监控

概览

搜索594个经过挑选的渗透测试和安全工具,按名称、类别、操作标签和操作系统进行分类。安装命令、使用示例、JSON

网络工具 - 安全工具目录 API FAQs

CyberTools 提供了 594 种安全工具,包括名称、描述、安装命令、示例、类别、操作标签和操作系统。工具端点支持文本搜索、类别、标签和操作系统筛选、数字 ID 和分页。统计端点返回总数和计数。可用于培训、CTF 仪表板、报告、推荐机器人和安全维基。数据按原样提供用于教育、防御和授权测试。不提供任何保证。请通过官方来源验证安全关键信息。请勿将原始数据集转售为竞争目录

使用listTools接口 可选的q参数用于搜索工具 使用category tag和os来按工具类别 动作标签和支持的操作系统过滤 所有过滤器结合使用AND 使用id来检索单个工具

使用 limit 参数控制返回匹配工具的数量,并使用 offset 参数跳过匹配工具。这两个参数是可选的。工具按名称排序

每个工具记录包括它的名称、简短和详细描述、安装命令、使用示例、类别、动作标签和支持的操作系统。记录支持工具发现、培训和文档

GetStats端点返回工具的总数以及按类别和操作标签的计数 当前目录包含594个工具 响应为JSON并从Cloudflare边缘提供

一般常见问题

Zyla API Hub 就像一个大型 API 商店,您可以在一个地方找到数千个 API。我们还为所有 API 提供专门支持和实时监控。注册后,您可以选择要使用的 API。请记住,每个 API 都需要自己的订阅。但如果您订阅多个 API,您将为所有这些 API 使用相同的密钥,使事情变得更简单。
价格以 USD(美元)、EUR(欧元)、CAD(加元)、AUD(澳元)和 GBP(英镑)列出。我们接受所有主要的借记卡和信用卡。我们的支付系统使用最新的安全技术,由 Stripe 提供支持,Stripe 是世界上最可靠的支付公司之一。如果您在使用卡片付款时遇到任何问题,请通过 [email protected]

此外,如果您已经以这些货币中的任何一种(USD、EUR、CAD、AUD、GBP)拥有有效订阅,该货币将保留用于后续订阅。只要您没有任何有效订阅,您可以随时更改货币。
定价页面上显示的本地货币基于您 IP 地址的国家/地区,仅供参考。实际价格以 USD(美元)为单位。当您付款时,即使您在我们的网站上看到以本地货币显示的等值金额,您的卡片对账单上也会以美元显示费用。这意味着您不能直接使用本地货币付款。
有时,银行可能会因其欺诈保护设置而拒绝收费。我们建议您首先联系您的银行,检查他们是否阻止了我们的收费。此外,您可以访问账单门户并更改关联的卡片以进行付款。如果这些方法不起作用并且您需要进一步帮助,请通过 [email protected]
价格由月度或年度订阅决定,具体取决于所选计划。
API 调用根据成功请求从您的计划中扣除。每个计划都包含您每月可以进行的特定数量的调用。只有成功的调用(由状态 200 响应指示)才会计入您的总数。这确保失败或不完整的请求不会影响您的月度配额。
Zyla API Hub 采用月度订阅系统。您的计费周期将从您购买付费计划的那一天开始,并在下个月的同一日期续订。因此,如果您想避免未来的费用,请提前取消订阅。
要升级您当前的订阅计划,只需转到 API 的定价页面并选择您要升级到的计划。升级将立即生效,让您立即享受新计划的功能。请注意,您之前计划中的任何剩余调用都不会转移到新计划,因此在升级时请注意这一点。您将被收取新计划的全部金额。
要检查您本月剩余多少 API 调用,请参考响应标头中的 "X-Zyla-API-Calls-Monthly-Remaining" 字段。例如,如果您的计划允许每月 1,000 个请求,而您已使用 100 个,则响应标头中的此字段将显示 900 个剩余调用。
要查看您的计划允许的最大 API 请求数,请检查 "X-Zyla-RateLimit-Limit" 响应标头。例如,如果您的计划包括每月 1,000 个请求,此标头将显示 1,000。
"X-Zyla-RateLimit-Reset" 标头显示您的速率限制重置之前的秒数。这告诉您何时您的请求计数将重新开始。例如,如果它显示 3,600,则意味着还有 3,600 秒直到限制重置。
是的,您可以随时通过访问您的账户并在账单页面上选择取消选项来取消您的计划。请注意,升级、降级和取消会立即生效。此外,取消后,您将不再有权访问该服务,即使您的配额中还有剩余调用。
为了让您有机会在没有任何承诺的情况下体验我们的 API,我们提供 7 天免费试用,允许您免费进行最多 50 次 API 调用。此试用只能使用一次,因此我们建议将其应用于您最感兴趣的 API。虽然我们的大多数 API 都提供免费试用,但有些可能不提供。试用在 7 天后或您进行了 50 次请求后结束,以先发生者为准。如果您在试用期间达到 50 次请求限制,您需要"开始您的付费计划"以继续发出请求。您可以在个人资料中的订阅 -> 选择您订阅的 API -> 定价标签下找到"开始您的付费计划"按钮。或者,如果您在第 7 天之前不取消订阅,您的免费试用将结束,您的计划将自动计费,授予您访问计划中指定的所有 API 调用的权限。请记住这一点以避免不必要的费用。
7 天后,您将被收取试用期间订阅的计划的全额费用。因此,在试用期结束前取消很重要。因忘记及时取消而提出的退款请求不被接受。
当您订阅 API 免费试用时,您可以进行最多 50 次 API 调用。如果您希望超出此限制进行额外的 API 调用,API 将提示您执行"开始您的付费计划"。您可以在个人资料中的订阅 -> 选择您订阅的 API -> 定价标签下找到"开始您的付费计划"按钮。
付款订单在每月 20 日至 30 日之间处理。如果您在 20 日之前提交请求,您的付款将在此时间范围内处理。
您可以通过我们的聊天渠道联系我们以获得即时帮助。我们始终在线,时间为上午 8 点至下午 5 点(EST)。如果您在该时间之后联系我们,我们将尽快回复您。此外,您可以通过 [email protected]

相关 API