Skip to main content

🔒 Pentool — Professional TUI Web Pentesting Toolkit

PyPI version Python versions CI License Downloads

🌐 Languages: English · Русский · 中文 · हिन्दी


Pentool is a terminal-based (TUI) security toolkit for penetration testers and security researchers.
It combines HTTP interception, vulnerability scanning, automated attacks, and data analysis — all inside your terminal.
Fast, transparent, and built for real-world testing.


✨ Features

  • 🌐 Proxy
    Intercept and modify HTTP/HTTPS traffic in real time. Manage scope, apply Match & Replace rules, capture WebSocket messages.

  • 🔄 Repeater
    Replay requests with any modifications. Save tabs between sessions and switch between scenarios instantly.

  • 💥 Intruder
    Run automated payload attacks with four strategies: Sniper, Battering Ram, Pitchfork, Cluster Bomb.
    Turbo Mode delivers 10× speed via Keep-Alive and connection pooling.

  • 🔍 Scanner
    Active and passive vulnerability analysis: SQLi, XSS, SSTI, LFI, RCE, SSRF, XXE, CORS, JWT flaws, and more.
    Smart context-aware payloads, WAF bypass, time-based and boolean-blind techniques.

  • 🕷 Spider
    Crawl targets automatically — collect pages, forms, API endpoints, and JS files.
    JavaScript rendering via Playwright is supported.

  • 🎯 Target / Site Map
    Build a site map from proxy traffic, manage testing scope, and filter hosts directly from the UI.

  • 🔐 Decoder · Comparer · Sequencer

    • Decoder — 19 encode/decode/hash operations with chaining support
    • Comparer — side-by-side diff with change highlighting
    • Sequencer — entropy analysis of tokens (sessions, CSRF, JWT) with FIPS tests
  • 🧩 Plugin System
    Extend functionality without touching the core. PRO plugins add advanced scanners, smart payloads, and report generators.

  • ⚡ Async Core
    Fully async engine handles thousands of concurrent connections and hundreds of requests per second.

  • 📦 One-line Install
    pip install pentool — no complex setup, works on Linux, macOS, and Windows (WSL).

  • 🆓 Open Source + PRO Extensions
    The base version is free and open. PRO extensions unlock exclusive features and support the project.


🚀 Quick Start

# Install
pip install pentool

# Launch TUI
pentool

# Start proxy on custom port
pentool proxy start --port 8080

# Active scan
pentool scan active --url https://example.com

# Check for updates
pentool update --check

📸 Screenshots

Screenshots and GIFs coming soon.

Dashboard Proxy Intruder
(coming soon) (coming soon) (coming soon)

📚 Documentation

Full docs: pentool.pro


🧪 Beta / Testing Mode

Pentool is currently in public beta.
All free modules are fully available. Paid (PRO) plugins are still in development — a trial version is provided for now.

If you run a blog or channel in the information security field and can help promote the project — write to us in private, we'll provide you with a private PRO key free of charge.

📬 Contact: @sudores on Telegram


💰 Support the Project

Pentool is built and maintained in spare time by a solo developer.
If it helps your work, consider supporting — it directly funds new features, bug fixes, and faster releases.

Every contribution matters. Thank you for supporting open-source security tooling. 🙌


🤝 Contributing

Contributions are welcome!
Please read CONTRIBUTING.md before opening a PR.


📄 License

Distributed under the AGPL-3.0 license. See LICENSE for details.
PRO extensions are available under a commercial license.


📬 Contact


⭐ If Pentool saves you time, a GitHub star helps the project grow — thanks!

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pentool-0.1.4.tar.gz (204.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pentool-0.1.4-py3-none-any.whl (247.7 kB view details)

Uploaded Python 3

File details

Details for the file pentool-0.1.4.tar.gz.

File metadata

  • Download URL: pentool-0.1.4.tar.gz
  • Upload date:
  • Size: 204.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.11.15

File hashes

Hashes for pentool-0.1.4.tar.gz
Algorithm Hash digest
SHA256 488d85233107906ec2a7e0e56c33794aaf770df5b0f53f412d35a993ee7a5e4a
MD5 8b6e33582d0c2831c54062f7319fe15e
BLAKE2b-256 ff6384f1c61b4cb06aa5734e857079c8eec6152c9d7e8f455589a006b4c4df9e

See more details on using hashes here.

File details

Details for the file pentool-0.1.4-py3-none-any.whl.

File metadata

  • Download URL: pentool-0.1.4-py3-none-any.whl
  • Upload date:
  • Size: 247.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.11.15

File hashes

Hashes for pentool-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 540a0f11de4fffb69548fcfe6761cc5a8da637aed1984871b7f193589badfb60
MD5 1fa886a3bab99294fd8e4ebb7edb9e1d
BLAKE2b-256 55e627b157b4a88d6e9e3b1c4d317178d29e5c2aebaa362191b1894c5e6e5c8d

See more details on using hashes here.

Release history Release notifications | RSS feed

0.3.1

2 files

0.3.0

2 files

0.2.11

2 files

0.2.10

2 files

0.2.9

2 files

0.2.8

2 files

0.2.7

2 files

0.2.6

2 files

0.2.5

2 files

0.2.4

2 files

0.2.3

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

0.1.9

2 files

0.1.8

2 files

0.1.7

2 files

0.1.6

2 files

0.1.5

2 files

This release

0.1.4 This release

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page