The 62 tools send live attack traffic and read forensic artifacts. Some are read-only file analysis (the pcap and CloudTrail tools); others depend on external binaries on the PATH, and the offensive tools are for authorised testing only.
An offensive-security testing server: its 62 tools cover SQL and NoSQL injection, XSS, command injection, SSRF, path traversal, PCAP and memory forensics, CloudTrail analysis, access-control and business-logic checks, and wrappers around scanners like nuclei and ffuf.
- Probe injection classes: SQLi, NoSQLi, command injection, path traversal, SSRF (sqli_blind_boolean, cmdi_test, ssrf_test)
- Analyse captured evidence: PCAP protocol and credential extraction, memory forensics, CloudTrail (pcap_overview, volatility_windows, cloudtrail_find_anomalies)
- Test access control and business logic: IDOR, role escalation, price and coupon abuse (idor_test, role_escalation_test, price_manipulation_test)
- Run race-condition and request-smuggling attacks (race_single_packet, raw_h2_smuggle, race_last_byte_sync)
- Wrap external scanners and fuzzers (nuclei_scan, ffuf_fuzz, param_discover)
Targets you are authorised to test; some tools need external binaries such as vol.py, vol3, or interactsh-client on the PATH.
One command — npx -y operant-mcp
