Kvasir - Penetration Testing Data Management Tool
Penetration Testing Data Management can be a nightmware, because well you
generate a LOT of data and some information when conducing a
penetration test, especially using tools – they return lots of actual
and potential vulnerabilitites to review. Port scanners can return
thousands of ports for just a few hosts. How easy is it to share all
this data with your co-workers?
Features
That’s what Kvasir is here to help you with. Here’s what you’ll need to get started:
- The latest version of web2py
- A database (PostgreSQL known to work)
- A network vulnerability scanner (Nexpose/Nmap supported)
- Additional python libraries
- Kvasir is a web2py application and can be installed for each customer or task.
Tools Supported
At current release, Kvasir directly supports the following tools:
- Rapid7 Nexpose Vulnerability Scanner
- Nmap Security Scanner
- Metasploit Pro (limited support for Express/Framework data)
- ShodanHQ
- ImmunitySec CANVAS
- THC-Hydra
- Foofus Medusa
- John The Ripper
This design keeps data separated and from you accidentally attacking or reviewing other customers.
This tool was developed primarily for the Cisco Systems Advanced
Services Security Posture Assessment (SPA) team. While not every method
used by the SPA team may directly relate we hope that this tool is
something that can be molded and adapted to fit almost any working
scenario.
Kvasir - Penetration Testing Data Management Tool
Reviewed by Zion3R
on
7:25 PM
Rating: