{
"total": 594,
"categories": [
{
"categories": "Exploitation",
"count": 256
},
{
"categories": "Post-Exploitation",
"count": 170
},
{
"categories": "Recon",
"count": 168
}
],
"actionTags": [
{
"tag": "scanner",
"count": 324
},
{
"tag": "exploit-framework",
"count": 90
},
{
"tag": "password-cracker",
"count": 51
},
{
"tag": "payload-generator",
"count": 50
},
{
"tag": "credential-dumper",
"count": 38
},
{
"tag": "proxy/tunnel",
"count": 35
},
{
"tag": "reverse-engineering",
"count": 35
},
{
"tag": "enumeration",
"count": 31
},
{
"tag": "social-engineer",
"count": 24
},
{
"tag": "osint",
"count": 22
},
{
"tag": "brute-force",
"count": 18
},
{
"tag": "packet-sniffer",
"count": 15
},
{
"tag": "privesc",
"count": 14
},
{
"tag": "steganography",
"count": 11
},
{
"tag": "fuzzer",
"count": 11
},
{
"tag": "wireless",
"count": 10
},
{
"tag": "malware-analysis",
"count": 10
},
{
"tag": "memory-forensics",
"count": 7
},
{
"tag": "reporting",
"count": 7
},
{
"tag": "wordlist-generator",
"count": 4
},
{
"tag": "decoder",
"count": 1
},
{
"tag": "cryptography",
"count": 1
},
{
"tag": "ctf",
"count": 1
}
]
}
curl --location --request GET 'https://zylalabs.com/api/14094/cybertools+-+security+tools+catalog+api/34800/getstats' --header 'Authorization: Bearer YOUR_API_KEY'
{
"tools": [
{
"id": 103,
"name": "1password2john",
"short_description": "1Password vault cracker",
"long_description": "Converts 1Password vault files to John the Ripper format. Useful for cracking 1Password master passwords and accessing stored credentials.",
"install_info": "sudo apt install john && locate 1password2john || git clone https://github.com/openwall/john.git && cd john/run",
"example_usage": "1password2john vault.1pux > hash.txt && john hash.txt",
"categories": "Post-Exploitation",
"action_tags": "credential-dumper;password-cracker",
"os_tags": "Linux;Windows;macOS"
},
{
"id": 195,
"name": "3proxy",
"short_description": "Tiny free proxy server for various protocols.",
"long_description": "3proxy is a tiny free proxy server with support for HTTP(S),go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest, POP3, SMTP, FTP, TCP and UDP protocols. It can be used for pivoting and tunneling in penetration testing.",
"install_info": "sudo apt-get install 3proxy",
"example_usage": "3proxy /etc/3proxy/3proxy.cfg",
"categories": "Post-Exploitation",
"action_tags": "proxy/tunnel",
"os_tags": "Linux;Windows"
},
{
"id": 69,
"name": "3uTools",
"short_description": "iOS device management and jailbreak",
"long_description": "All-in-one tool for iOS device management, jailbreaking, and data extraction. Supports firmware flashing and device information gathering.",
"install_info": "Download from http://www.3u.com/",
"example_usage": "Launch 3uTools and connect iOS device",
"categories": "Exploitation",
"action_tags": "exploit-framework",
"os_tags": "Windows;iOS"
},
{
"id": 110,
"name": "7z2john",
"short_description": "7-Zip archive password cracker",
"long_description": "Extracts password hashes from 7-Zip archives for cracking with John the Ripper. Essential for accessing password-protected 7z files.",
"install_info": "sudo apt install john && locate 7z2john || git clone https://github.com/openwall/john.git && cd john/run",
"example_usage": "7z2john archive.7z > hash.txt && john hash.txt",
"categories": "Post-Exploitation",
"action_tags": "password-cracker;credential-dumper",
"os_tags": "Linux;Windows;macOS"
},
{
"id": 392,
"name": "aclpwn",
"short_description": "Active Directory ACL exploitation",
"long_description": "Tool for exploiting Active Directory Access Control Lists (ACLs) to escalate privileges and move laterally through domain environments.",
"install_info": "pip install aclpwn",
"example_usage": "aclpwn -f [email protected] -t [email protected]",
"categories": "Exploitation",
"action_tags": "exploit-framework",
"os_tags": "Linux;Windows"
},
{
"id": 325,
"name": "adminer",
"short_description": "Database administration web interface",
"long_description": "Lightweight database management tool that can be used as a web shell when uploaded to compromised servers. Supports multiple database types and provides full database access.",
"install_info": "wget https://www.adminer.org/latest.php -O adminer.php",
"example_usage": "Upload adminer.php and access via browser",
"categories": "Exploitation",
"action_tags": "payload-generator",
"os_tags": "Linux;Windows;macOS"
},
{
"id": 196,
"name": "Aircrack-ng",
"short_description": "Complete suite of tools to assess WiFi network security.",
"long_description": "Aircrack-ng is a complete suite of tools to assess WiFi network security. It focuses on different areas of WiFi security: monitoring, attacking, testing, and cracking.",
"install_info": "sudo apt-get install aircrack-ng",
"example_usage": "aircrack-ng -w /usr/share/wordlists/rockyou.txt -b 00:11:22:33:44:55 capture.cap",
"categories": "Exploitation",
"action_tags": "password-cracker;brute-force;packet-sniffer;wireless",
"os_tags": "Linux"
},
{
"id": 197,
"name": "Aireplay-ng",
"short_description": "Wireless packet injection tool for WiFi attacks.",
"long_description": "Aireplay-ng is used to inject frames. The primary function is to generate traffic for the later use in aircrack-ng for cracking the WEP and WPA-PSK keys.",
"install_info": "Part of aircrack-ng suite - sudo apt-get install aircrack-ng",
"example_usage": "aireplay-ng -0 1 -a 00:11:22:33:44:55 -c 00:11:22:33:44:66 wlan0mon",
"categories": "Exploitation",
"action_tags": "exploit-framework;wireless",
"os_tags": "Linux"
},
{
"id": 117,
"name": "Airmon-ng",
"short_description": "Script to enable and disable monitor mode on wireless interfaces.",
"long_description": "Airmon-ng is used to enable and disable monitor mode on wireless interfaces. It may also be used to go back from monitor mode to managed mode.",
"install_info": "Part of aircrack-ng suite - sudo apt-get install aircrack-ng",
"example_usage": "airmon-ng check kill\nairmon-ng start wlan0",
"categories": "Recon",
"action_tags": "scanner;wireless",
"os_tags": "Linux"
},
{
"id": 118,
"name": "Airodump-ng",
"short_description": "Wireless packet capture tool for monitoring WiFi networks.",
"long_description": "Airodump-ng is used for packet capturing of raw 802.11 frames and is particularly suitable for collecting WEP IVs (Initialization Vectors) for the intent of using them with aircrack-ng.",
"install_info": "Part of aircrack-ng suite - sudo apt-get install aircrack-ng",
"example_usage": "airodump-ng wlan0mon",
"categories": "Recon",
"action_tags": "packet-sniffer;wireless",
"os_tags": "Linux"
},
{
"id": 519,
"name": "alchemy",
"short_description": "Alchemy CPU attack framework",
"long_description": "Framework for CPU-based attacks including cache and timing attacks against cryptographic implementations.",
"install_info": "git clone https://github.com/FPSG-UIUC/alchemy.git && cd alchemy && sudo apt install -y python3-numpy python3-scipy && make",
"example_usage": "python3 alchemy.py --attack cache --target openssl",
"categories": "Exploitation",
"action_tags": "scanner",
"os_tags": "Linux;Windows"
},
{
"id": 322,
"name": "alfashell",
"short_description": "Multi-language web shell collection",
"long_description": "Collection of web shells in various languages including PHP ASP and JSP. Features advanced functionality and evasion techniques for maintaining persistence.",
"install_info": "git clone https://github.com/offensive-security/exploitdb.git && find . -name \"*alfa*\"",
"example_usage": "Upload appropriate shell based on target technology",
"categories": "Exploitation",
"action_tags": "payload-generator",
"os_tags": "Linux;Windows;macOS"
},
{
"id": 119,
"name": "Altdns",
"short_description": "Generates permutations, alterations and mutations of subdomains.",
"long_description": "Altdns is a DNS recon tool that allows for the discovery of subdomains that conform to patterns. It takes in words that could be present in subdomains and generates a large list of potential subdomains.",
"install_info": "pip3 install py-altdns",
"example_usage": "altdns -i subdomains.txt -o data_output -w words.txt -r -s results_output.txt",
"categories": "Recon",
"action_tags": "scanner",
"os_tags": "Linux;Windows;macOS"
},
{
"id": 120,
"name": "Amass",
"short_description": "OWASP subdomain enumeration tool.",
"long_description": "Amass is an OWASP project that performs network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.",
"install_info": "go install -v github.com/owasp-amass/amass/v3/...@master",
"example_usage": "amass enum -d example.com\namass intel -d example.com",
"categories": "Recon",
"action_tags": "scanner;enumeration;osint",
"os_tags": "Linux;Windows;macOS"
},
{
"id": 350,
"name": "Anonsurf",
"short_description": "Anonymous surfing through Tor"
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/14094/cybertools+-+security+tools+catalog+api/34801/listtools' --header 'Authorization: Bearer YOUR_API_KEY'
注册后,每个开发者都会被分配一个个人 API 访问密钥,这是一个唯一的字母和数字组合,用于访问我们的 API 端点。要使用 网络工具 - 安全工具目录 API 进行身份验证,只需在 Authorization 标头中包含您的 bearer token。
| 标头 | 描述 |
|---|---|
授权
|
必需
应为 Bearer access_key. 订阅后,请查看上方的"您的 API 访问密钥"。
|
无长期承诺。随时升级、降级或取消。 免费试用包括最多 50 个请求。
(年度计费可节省 2 个月 🎉)
CyberTools 提供了 594 种安全工具,包括名称、描述、安装命令、示例、类别、操作标签和操作系统。工具端点支持文本搜索、类别、标签和操作系统筛选、数字 ID 和分页。统计端点返回总数和计数。可用于培训、CTF 仪表板、报告、推荐机器人和安全维基。数据按原样提供用于教育、防御和授权测试。不提供任何保证。请通过官方来源验证安全关键信息。请勿将原始数据集转售为竞争目录
使用listTools接口 可选的q参数用于搜索工具 使用category tag和os来按工具类别 动作标签和支持的操作系统过滤 所有过滤器结合使用AND 使用id来检索单个工具
使用 limit 参数控制返回匹配工具的数量,并使用 offset 参数跳过匹配工具。这两个参数是可选的。工具按名称排序
每个工具记录包括它的名称、简短和详细描述、安装命令、使用示例、类别、动作标签和支持的操作系统。记录支持工具发现、培训和文档
GetStats端点返回工具的总数以及按类别和操作标签的计数 当前目录包含594个工具 响应为JSON并从Cloudflare边缘提供
GetStats 端点返回 JSON 统计信息,包括工具总数以及按类别和操作标签的数量 listTools 端点返回有关安全工具的详细信息,包括名称 描述 安装命令 使用示例 类别 操作标签和支持的操作系统
获取统计信息响应中的关键字段包括“total”“categories”和“actionTags” 在列出工具的响应中,重要字段是“id”“name”“short_description”“long_description”“install_info”“example_usage”“categories”“action_tags”和“os_tags”
GetStats响应的结构是一个总计数,后面跟着分类和动作标签的数组,每个数组包含一个名称和计数。listTools响应是一个工具对象的数组,每个对象都有多个字段详细描述工具的属性,方便解析和使用
GetStats端点提供有关工具目录的总体统计数据,包括总计数及按类别和操作标签的细分 listTools端点提供关于单个工具的全面细节,包括描述、安装说明和使用示例
用户可以使用可选参数自定义对listTools端点的请求,如“q”用于搜索词 “category”用于按工具类型过滤 “tag”用于操作标签 “os”用于操作系统 “id”用于检索特定工具 分页可以通过“limit”和“offset”进行控制
用户可以期待结构化的JSON响应,并且在各个工具中的字段名称保持一致。例如,每个工具都有一个唯一的“id”,字段如“categories”和“action_tags”通常包含多个用分号分隔的值,表示不同的分类
通过对目录中包含的工具进行策划,维护数据的准确性。每个工具的选择基于其在安全领域的相关性和实用性,确保用户能够获得可靠且有效的安全工具以满足他们的需求
典型的用例包括培训安全专业人员 创建夺旗(CTF)挑战 开发安全仪表板 生成关于安全工具的报告 以及为安全维基或教育平台构建推荐系统