An advanced, enterprise-grade ethical hacking and penetration testing environment automated installer. Fully cross-platform, supporting Windows 10/11, macOS (Apple Silicon & Intel), and all Linux distributions (Kali Linux, Parrot OS, Debian, Ubuntu, Arch Linux, Manjaro, BlackArch, Fedora, RHEL, CentOS, openSUSE, Alpine Linux, etc.).
Curated with 65+ top-tier cybersecurity tools fetched directly from their authentic upstream sources (ProjectDiscovery, SQLMapProject, Sherlock-Project, Rapid7, and more).
Includes an interactive terminal checkbox selector with live fuzzy search filtering, role-based installation presets, isolated virtual environments per tool, a pre-flight system doctor, disk space manager & cache cleaner, JSON configuration export/import, and containerized Docker support.
- Full Cross-Platform Support:
- Linux (All Distros): Native support for Debian/Kali/Parrot (
apt), Arch/Manjaro/BlackArch (pacman), Fedora/RHEL/CentOS (dnf/yum), openSUSE (zypper), and Alpine (apk). - macOS: Native support on Apple Silicon (M1/M2/M3/M4) & Intel with Homebrew integration.
- Windows: Native support on Windows 10/11 (PowerShell / Windows Terminal / CMD) with
winget/chocosupport andmsvcrtraw key capture.
- Linux (All Distros): Native support for Debian/Kali/Parrot (
- 100% Authentic Upstream Sources: No third-party forks or obsolete organizations. Every tool is cloned directly from its official creators and foundations.
- Role-Based Profiles & Presets: One-click curated bundles for Bug Bounty, OSINT, Red Teaming, Network Auditing, Wireless, Forensics, or Minimal starter setups.
- Isolated Virtual Environments (.venv): Every Python tool receives its own isolated virtual environment to prevent dependency conflicts (PEP 668 compliant), with auto-generated portable launcher wrappers (
run.sh/run.bat). - Interactive Checkbox UI with Live Search:
- Press
[/]to instantly filter tools by name, category, or description in real time [Up/Down]or[k/j]Navigate smoothly across all tools (works on Windows, macOS, Linux)[Space]Toggle tool selection [X] / [ ][a]Select / Deselect all visible tools in active search filter[c]Toggle entire category of the focused tool[d]Change destination directory on the fly[Enter]Start batch installation
- Press
- Pre-Flight Environment Doctor: Audits compilers (Go, Rust, Node, Ruby, GCC, Make), Git, Python, Docker, system packages, storage headroom, and tests live TLS connection latency to GitHub and PyPI.
- Storage Manager & Disk Cleaner: Inspects tool disk usage, ranks largest tools, and provides a safe one-key cache purger for Python bytecode (
__pycache__), test caches, and git garbage collection (git gc). - Configuration Export & Import: Generates reproducible JSON manifests containing exact tool lists, git commit hashes, branches, and platform metadata for team sync and dotfiles.
- Containerized Docker Sandbox: Ships with production Kali Linux
Dockerfileanddocker-compose.ymlfor isolated operations with persistent host volume mounting. - Smart Git Auto-Updater:
- Automatically scans your tools folder (
~/Toolsor custom directory) - Runs
git pullacross all installed repositories - Reports branch, commit status, and updates dependencies inside isolated
.venvenvironments.
- Automatically scans your tools folder (
Instead of manually picking tools or cloning everything, you can deploy role-tailored security suites using the interactive menu or the --profile flag:
| Profile ID | Role Name | Included Tools Highlights |
|---|---|---|
bug-bounty |
Bug Bounty & Web Hunter | SQLMap, XSStrike, Nuclei, Subfinder, HTTPX, Katana, FFUF, Dalfox, Commix, Arjun, Dirsearch, WhatWeb, CMSeeK, ParamSpider, Wfuzz, Nikto, Sublist3r, SecLists, PayloadsAllTheThings |
osint |
OSINT & Digital Intelligence | Sherlock, theHarvester, PhoneInfoga, Holehe, SpiderFoot, Seeker, Nexfil, FinalRecon, Maigret, Recon-ng, Sublist3r, GHunt, Social-Analyzer, IP-Tracer, Infoga |
red-team |
Red Team & Exploitation | Metasploit-Framework, Sliver, Havoc-C2, Villain, Impacket, Responder, NetExec, PwnCat, Routersploit, PEASS-ng, LinEnum, Linux-Exploit-Suggester, Chisel, Ligolo-ng, PayloadsAllTheThings |
network |
Network & Infrastructure | RustScan, Masscan, Netdiscover, Bettercap, Responder, Impacket, NetExec, Sniffnet, THC-Hydra |
wireless |
Wireless & WiFi Auditing | Airgeddon, Fluxion, Wifite2, EAPHammer, FakeAPBuilder |
forensics |
Forensics & Reverse Engineering | Volatility3, Apktool, JADX, Linux-Exploit-Suggester, PEASS-ng |
essential |
Essential Starter Kit | Sherlock, theHarvester, SQLMap, Nuclei, Subfinder, HTTPX, FFUF, Dirsearch, RustScan, Bettercap, Responder, Impacket, SecLists, THC-Hydra, PEASS-ng |
- Sherlock (
sherlock-project/sherlock): Hunt down social media accounts across 400+ platforms - theHarvester (
laramies/theHarvester): Gather emails, names, subdomains, IPs from search engines - PhoneInfoga (
sundowndev/phoneinfoga): Advanced phone number OSINT framework - Holehe (
megadose/holehe): Email registered account checker for 120+ platforms - SpiderFoot (
smicallef/spiderfoot): Automated OSINT collection engine with hundreds of data modules - Seeker (
thewhiteh4t/seeker): High-precision smartphone geolocation social engineering - Nexfil (
thewhiteh4t/nexfil): Fast profile finder across 350+ sites in seconds - FinalRecon (
thewhiteh4t/finalrecon): All-in-one web reconnaissance engine (whois, headers, SSL, crawl) - Maigret (
soxoj/maigret): Collect dossier by username from 3000+ sites with URL validation - Recon-ng (
lanmaster53/recon-ng): Full-featured modular web reconnaissance framework - Sublist3r (
aboul3la/Sublist3r): Subdomain enumeration via search engines - GHunt (
mxrch/GHunt): Offensive Google account OSINT tool - Social-Analyzer (
qeeqbox/social-analyzer): Profile finder across 1000+ social networks - IP-Tracer (
htr-tech/IP-Tracer): Track IP location, ISP, country, ASN and coordinates - Infoga (
m4ll0k/Infoga): Email OSINT and PGP server harvester
- SQLMap (
sqlmapproject/sqlmap): Automatic SQL injection and database takeover engine - XSStrike (
s0md3v/XSStrike): Advanced XSS detection suite with intelligent fuzzing - Nuclei (
projectdiscovery/nuclei): Fast and customizable vulnerability scanner using YAML DSL - Subfinder (
projectdiscovery/subfinder): Fast passive subdomain enumeration - HTTPX (
projectdiscovery/httpx): Fast and multi-purpose HTTP probing toolkit - Katana (
projectdiscovery/katana): Next-generation web crawler and spider - FFUF (
ffuf/ffuf): Blazing fast web fuzzer for paths, vhosts, and parameters - Dalfox (
hahwul/dalfox): Parameter analysis and XSS scanner in Go - Commix (
commixproject/commix): Automated command injection exploiter - Arjun (
s0md3v/Arjun): HTTP parameter discovery suite (hidden GET/POST/JSON parameters) - Dirsearch (
maurosoria/dirsearch): Advanced multithreaded web path scanner - WhatWeb (
urbanadventurer/WhatWeb): Next generation web technologies and CMS identifier - CMSeeK (
Tuhinshubhra/CMSeeK): CMS detection and exploitation (WordPress, Joomla, Drupal, 170+ others) - ParamSpider (
devanshbatham/paramspider): Mining parameters from Web Archives for bug bounty - Wfuzz (
xmendez/wfuzz): Web application fuzzer and vulnerability assessment - Nikto (
sullo/nikto): Web server scanner for dangerous files and server flaws - XSpear (
hahwul/XSpear): Powerful XSS scanning and parameter analysis
- RustScan (
RustScan/RustScan): Modern port scanner - 65,000 ports in 3 seconds - Masscan (
robertdavidgraham/masscan): Internet-scale TCP port scanner - Netdiscover (
alexxy/netdiscover): Active/passive ARP reconnaissance - Bettercap (
bettercap/bettercap): Swiss Army knife for 802.11, BLE, IPv4/IPv6 MITM attacks - Responder (
SpiderLabs/Responder): LLMNR, NBT-NS and MDNS poisoner & credential harvester - Impacket (
fortra/impacket): Essential Python library for working with SMB, WMI, Kerberos - NetExec (
Pennywiser-org/NetExec): Active Directory & network exploitation suite (Modern CrackMapExec) - Sniffnet (
GyulyV/sniffnet): Modern cross-platform network traffic monitor
- Airgeddon (
v1s1t0r1sh3r3/airgeddon): Multi-use wireless network auditing script - Fluxion (
FluxionNetwork/fluxion): WPA/WPA2 social-engineering auditing research tool - Wifite2 (
derv82/wifite2): Automated wireless auditor for WEP, WPA, WPS - EAPHammer (
s0lst1c3/eaphammer): Targeted evil twin attacks against WPA2-Enterprise - FakeAPBuilder (
karthik558/FakeAPBuilder): Rogue AP and captive portal builder for MITM
- Metasploit Framework (
rapid7/metasploit-framework): World-renowned penetration testing framework - Villain (
t3l3machus/Villain): Windows/Linux backdoor generator with sibling server multi-session - Sliver (
BishopFox/sliver): Cross-platform adversary emulation and Red Team C2 - Havoc C2 (
HavocFramework/Havoc): Modern malleable post-exploitation C2 framework - Routersploit (
threat9/routersploit): Embedded device and IoT router exploitation framework - PwnCat (
calebstewart/pwncat): Advanced reverse/bind shell handler with automated privesc - Red Python Scripts (
davidbombal/red-python-scripts): Curated offensive security scripts - MHDDoS (
MatrixTM/MHDDoS): DDoS stress testing framework with 36+ attack methods
- PEASS-ng (
carlospolop/PEASS-ng): LinPEAS and WinPEAS privilege escalation scripts - LinEnum (
rebootuser/LinEnum): Scripted Local Linux Enumeration & checks - Linux-Exploit-Suggester (
The-Z-Labs/linux-exploit-suggester): Kernel exploit suggester - Chisel (
jpillora/chisel): Fast TCP/UDP tunnel over HTTP via SSH - Ligolo-ng (
nicocha30/ligolo-ng): Lightweight pivoting tool using TUN interfaces - PayloadsAllTheThings (
swisskyrepo/PayloadsAllTheThings): Cheatsheets and bypass payloads
- SecLists (
danielmiessler/SecLists): Wordlists for fuzzing, discovery, and cracking - THC-Hydra (
vanhauser-thc/thc-hydra): High-speed network logon cracker - CeWL (
digininja/CeWL): Custom Word List Generator spidering websites
- Volatility 3 (
volatilityfoundation/volatility3): Memory forensics framework - Apktool (
iBotPeaches/Apktool): Reverse engineering Android APK files - JADX (
skylot/jadx): Dex to Java decompiler (CLI & GUI)
# 1. Clone this repository
git clone https://github.com/karthik558/setup_hack_env.git
cd setup_hack_env
# 2. Launch the interactive menu
python3 setup-hack.py# 1. Clone this repository
git clone https://github.com/karthik558/setup_hack_env.git
cd setup_hack_env
# 2. Launch the interactive menu
python setup-hack.pyRun tools in an isolated Kali Linux container without modifying your host system:
# Build and run interactive session
docker-compose run --rm setup-hack
# Or run a specific profile directly in Docker
docker-compose run --rm setup-hack --profile bug-bountyPrivilege Note:
- Linux/macOS: Root (
sudo) is not required for cloning tools into your user directory (~/Tools). The script will only requestsudowhen installing system packages viaapt/pacman/dnf.- Windows: Run PowerShell or Windows Terminal as Administrator if you intend to install system packages via
wingetorchoco. Otherwise, standard user permissions are fully supported for cloning and managing tools inC:\Users\<user>\Tools.
You can run setup-hack.py interactively or pass command-line arguments for automated deployments:
# Launch interactive Cyberpunk menu
python3 setup-hack.py
# Pre-flight environment diagnostics and compiler checks
python3 setup-hack.py --doctor
# Install a specific role profile (e.g. bug-bounty or osint)
python3 setup-hack.py --profile bug-bounty
python3 setup-hack.py --profile osint
# List all available role presets and included tools
python3 setup-hack.py --list-profiles
# Inspect tool disk footprint and storage metrics
python3 setup-hack.py --storage
# Purge Python bytecode, build caches, and optimize git repositories
python3 setup-hack.py --clean
# Export current installation state to reproducible JSON manifest
python3 setup-hack.py --export setup-manifest.json
# Import and replicate environment from JSON manifest
python3 setup-hack.py --import setup-manifest.json
# Update ALL installed tools in ~/Tools
python3 setup-hack.py --update
# Update tools in a custom directory
python3 setup-hack.py --update --dir /opt/security-tools
# Quick install ALL tools non-interactively
python3 setup-hack.py --all
# Install by category (e.g. OSINT and Web tools)
python3 setup-hack.py --category "osint,web"
# Install specific tools by name
python3 setup-hack.py --tools "sherlock,sqlmap,nuclei,subfinder"
# Specify custom destination directory
python3 setup-hack.py --dir /opt/tools --all
# List all available tools and official upstream repositories
python3 setup-hack.py --list
# Install base Linux dependencies & prerequisites
python3 setup-hack.py --deps| Flag | Long Flag | Description |
|---|---|---|
-p <name> |
--profile <name> |
Install tools from a role profile (bug-bounty, osint, red-team, network, wireless, forensics, essential) |
--list-profiles |
List all available preset profiles and included tools | |
--doctor |
Run pre-flight environment diagnostics, compiler audits, and network latency tests | |
--storage |
Inspect disk footprint and storage metrics of installed tools | |
--clean |
Purge Python bytecode (__pycache__), caches, and optimize git repos with git gc |
|
--export [file] |
Export installed tools manifest JSON | |
--import <file> |
Import and install tools from manifest JSON | |
--docker |
Manage or launch containerized Docker sandbox environment | |
--venv |
Enable isolated Python virtual environments per tool (default: enabled) | |
--no-venv |
Disable isolated virtual environments, use global Python interpreter | |
-a |
--all |
Install all tools without interactive prompts |
-u |
--update |
Update all installed repositories in destination folder |
-l |
--list |
Inspect full catalog and upstream source URLs |
-d <dir> |
--dir <dir> |
Set target folder for cloning tools (default: ~/Tools) |
-c <cats> |
--category <cats> |
Install tools by comma-separated categories |
-t <tools> |
--tools <tools> |
Install tools by comma-separated names |
--deps |
Install base Linux/macOS/Windows prerequisites, headers, and wordlists | |
--no-interactive |
Disable raw terminal mode for automated scripts / pipes |
Modern operating systems (e.g. Debian 12+, Ubuntu 23+, macOS Homebrew, Arch Linux) enforce PEP 668 ("externally managed environment"), preventing global pip install commands from interfering with system packages. Installing multiple security tools into a single global environment frequently leads to conflicting dependency versions (e.g., conflicting urllib3, requests, cryptography, or pydantic versions).
setup_hack_env solves this natively:
- Isolated
.venvPer Tool: Each Python tool receives its own isolated virtual environment inside its cloned directory (<tool>/.venv). - Auto-Generated Launchers: Every installed tool automatically receives an executable wrapper script:
- On Linux/macOS:
<tool>/run.sh - On Windows:
<tool>\run.batRunning./run.shautomatically routes execution through that tool's specific.venvinterpreter without manual activation.
- On Linux/macOS:
- Toggleable: To install into the active interpreter instead, simply pass
--no-venv.
-
Extract rockyou wordlist manually (if not already extracted by the script):
sudo gzip -d /usr/share/wordlists/rockyou.txt.gz
-
Configure Proxychains with Tor:
sudo nano /etc/proxychains4.conf
- Ensure
dynamic_chainis uncommented andstrict_chainis commented out. - Verify the bottom line points to:
socks5 127.0.0.1 9050 - Start the Tor service:
sudo systemctl start tor
- Ensure
Contributions, issues, and tool recommendations are welcome! If you know of an active open-source security tool that should be included, open a Pull Request or Issue with the official upstream repository link.
This project is licensed under the MIT License.
