
أداة كشف واستغلال تعتمد على Shell لـ CMS تضم 330+ نظام إدارة محتوى، ثم تطلق عمليات تدقيق أمني آلي وأدوات استغلال ضد الأهداف المكتشفة.
مجموعة كشف واستغلال نظم إدارة المحتوى (CMS) تعتمد على Whatcms.org API.
يمكن لأداة Whatcms.sh حالياً كشف استخدام أكثر من 330 تطبيقاً وخدمة CMS مختلفة، ثم تشير لاحقاً إلى قائمة بأدوات تدقيق أمني صالحة لنظام إدارة المحتوى (CMS) المكتشف.
تحتاج إلى واجهة برمجة تطبيقات whatcms.org لاستخدام الأداة:
Usage: ./whatcms.sh example.com
-h عرض رسالة المساعدة
-wh التحقق من تفاصيل الاستضافة
--tools عرض معلومات الأدوات

| الأداة | الفائدة | رابط المستودع |
|---|---|---|
| Dumb0 | أداة سحب أسماء المستخدمين | https://github.com/0verl0ad/Dumb0/ |
| CMSsc4n | أداة تعريف | https://github.com/n4xh4ck5/CMSsc4n |
| Puppet | أداة تعريف | https://github.com/Poil/puppet-websites-facts |
| pyfiscan | أداة تعريف | https://github.com/fgeek/pyfiscan |
| XAttacker | أداة استغلال | https://github.com/Moham3dRiahi/XAttacker |
| beecms | أداة استغلال | https://github.com/CHYbeta/cmsPoc |
| CMSXPL | أداة استغلال | https://github.com/tanprathan/CMS-XPL |
| JMassExploiter | أداة استغلال | https://github.com/anarcoder/JoomlaMassExploiter |
| WPMassExploiter | أداة استغلال | https://github.com/anarcoder/WordPressMassExploiter |
| CMSExpFram | أداة استغلال | https://github.com/Q2h1Cg/CMS-Exploit-Framework |
| LotusXploit | أداة استغلال | https://github.com/Hood3dRob1n/LotusCMS-Exploit |
| BadMod | أداة استغلال | https://github.com/MrSqar-Ye/BadMod |
| M0B | أداة استغلال | https://github.com/mobrine-mob/M0B-tool |
| LetMeFuckIt | أداة استغلال | https://github.com/onthefrontline/LetMeFuckIt-Scanner |
| magescan | أداة استغلال | https://github.com/steverobbins/magescan |
| PRESTA | أداة استغلال | https://github.com/AlisamTechnology/PRESTA-modules-shell-exploit |
| EktronE | أداة استغلال | https://github.com/tomkallo/Ektron_CMS_8.02_exploit |
| XBruteForcer | أداة هجوم القوة العمياء (Brute Force) | https://github.com/Moham3dRiahi/XBruteForcer |
| CoMisSion | أداة تحليل | https://github.com/Intrinsec/comission |
| droopescan | أداة تحليل | https://github.com/droope/droopescan |
| CMSmap | أداة تحليل | https://github.com/Dionach/CMSmap |
| JoomScan | أداة تحليل | https://github.com/rezasp/joomscan |
| VBScan | أداة تحليل | https://github.com/rezasp/vbscan |
| JoomlaScan | أداة تحليل | https://github.com/drego85/JoomlaScan |
| c5scan | أداة تحليل | https://github.com/auraltension/c5scan |
| T3scan | أداة تحليل | https://github.com/Oblady/T3Scan |
| moodlescan | أداة تحليل | https://github.com/inc0d3/moodlescan |
| SPIPScan | أداة تحليل | https://github.com/PaulSec/SPIPScan |
| WPHunter | أداة تحليل | https://github.com/aryanrtm/WP-Hunter |
| WPSeku | أداة تحليل | https://github.com/m4ll0k/WPSeku |
| ACDrupal | أداة تحليل | https://github.com/mrmtwoj/ac-drupal |
| Plown | أداة تحليل | https://github.com/unweb/plown |
| conscan | أداة تحليل | https://github.com/nullsecuritynet/tools/tree/master/scanner/conscan |
| CMSScanner | أداة تحليل | https://github.com/CMS-Garden/cmsscanner |
| cmsExplorer | أداة تحليل | https://code.google.com/archive/p/cms-explorer |
| WPScan | أداة تحليل | https://github.com/wpscanteam/wpscan |
| MooScan | أداة تحليل | https://github.com/vortexau/mooscan |
| Scanners | أداة تحليل | https://github.com/b3o1/Scanners |
| LiferayScan | أداة تحليل | https://github.com/bcoles/LiferayScan |
| InfoLeak | أداة تحليل | https://github.com/SIWECOS/InfoLeak-Scanner |
| joomlavs | أداة تحليل | https://github.com/rastating/joomlavs |
| WAScan | أداة تحليل | https://github.com/m4ll0k/WAScan |
| RedHawk | أداة تحليل | https://github.com/Tuhinshubhra/RED_HAWK |
| HostileSBF | أداة تحليل | https://github.com/nahamsec/HostileSubBruteforcer |