Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Panoptic — Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files through path traversal vulnerabilities. | Kitploit
Tools/GitHubGitHub/lightos/panoptic
ReconnaissanceVulnerability ScannersWeb Application ExploitationInformation GatheringPenetration Testing
GitHublightos/panoptic

Panoptic

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files through path traversal vulnerabilities.

View Repository
32574142 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Panoptic

Panoptic Logo

License: MIT Python Versions Ruff mypy GitHub last commit CodeRabbit Pull Request Reviews

Panoptic is an open source penetration testing tool that automates the search and retrieval of common log and config files through path traversal vulnerabilities.

Panoptic Demo

Features

  • Async concurrent scanning with configurable worker pool (--concurrency)
  • Automatic discovery of common log and configuration files via parameter-based, path-based, POST, cookie, header, and JSON body injection
  • FUZZ marker for arbitrary injection points — place FUZZ in any --header or --data value
  • Base64 encoding for endpoints that decode file paths (--base64)
  • Automatic OS detection with option to restrict further scans
  • Heuristic response comparison with status code filtering to reduce false positives
  • Dynamic case injection — parse /etc/passwd for home directory files, mysql-bin.index for binlog files
  • Multiple output formats: text (rich), JSON, CSV (--output-format)
  • Resume/checkpoint support for long-running scans (--resume-file)
  • TOML config files for persistent settings (--config)
  • Multiple traversal bypass techniques: prefixes, postfixes, multiplier, slash replacement, double encoding
  • HTTP/HTTPS and SOCKS5 proxy support with validation
  • Random or custom User-Agent, cookie, and header support
  • Credential redaction in banner, log, and machine-readable output (including numeric and boolean JSON body values)
  • Sensitive artifacts hardened with owner-only 0600 permissions on POSIX and final-component symlink protection where the OS supports it
  • Self-update with remote URL verification (--update)

Requirements

  • Python 3.10+
  • Git
  • Dependencies: httpx[socks], rich, rich-argparse, and tomli on Python 3.10

Installation

git clone https://github.com/lightos/Panoptic.git
cd Panoptic
python3 -m venv .venv
source .venv/bin/activate
python -m pip install -e .
panoptic --version

On Windows Command Prompt, activate with .venv\Scripts\activate.bat; in PowerShell, use .venv\Scripts\Activate.ps1. The editable install keeps Panoptic connected to this checkout for --update, so keep the directory in place. Do not run pip install panoptic: that PyPI name belongs to an unrelated project.

For development:

python -m pip install -e ".[dev]"

Usage

panoptic --url "http://target/include.php?file=test.txt"

Examples

Basic parameter-based LFI

panoptic --url "http://target/include.php?file=test.txt"
panoptic --url "http://target/include.php?file=test.txt&id=1" \
  --param file

POST data injection

panoptic --url "http://target/include.php" \
  --data "file=test.txt&id=1" --param file

Path-based LFI

panoptic --url "http://target/view.php/test.txt" --path-based

Base64-encoded parameter

panoptic --url "http://target/load.php?file=dGVzdC50eHQ=" \
  --base64 --auto

Cookie injection (FUZZ marker)

panoptic --url "http://target/page.php" \
  --header "Cookie: lang=FUZZ" --auto

JSON body injection (FUZZ marker)

panoptic --url "http://target/api/load" \
  --data '{"file":"FUZZ"}' --auto

Custom header injection (FUZZ marker)

panoptic --url "http://target/page.php" \
  --header "X-Template: FUZZ" --auto

Extension parameter

panoptic --url "http://target/view.php?file=test&type=txt" \
  --param file --ext-param type

Filter bypass with prefix

panoptic --url "http://target/filtered.php?file=test.txt" \
  --prefix "....//....//....//....//"

Filtered scans

panoptic --url "http://target/include.php?file=test.txt" \
  --os "*NIX" --type conf
panoptic --url "http://target/include.php?file=test.txt" \
  --software PostgreSQL

JSON output with resume support

panoptic --url "http://target/include.php?file=test.txt" \
  --output-format json --output-file results.json \
  --resume-file scan.checkpoint

Proxy with SSL errors ignored

panoptic --url "https://target/include.php?file=test.txt" \
  --proxy "socks5://127.0.0.1:9050" --invalid-ssl

List available filters

panoptic --list software
panoptic --list category
panoptic --list os

Comprehensive scan

panoptic --url "http://target/include.php?file=test.txt" \
  --auto --all-versions --concurrency 8

FUZZ Marker

Place FUZZ anywhere in --header or --data values to mark the injection point. Panoptic replaces FUZZ with each file path during scanning. This enables testing injection points that --param can't reach:

Injection TypeExample
Cookie value--header "Cookie: theme=FUZZ"
Custom header--header "X-Include: FUZZ"
JSON body--data '{"template":"FUZZ"}'
Nested value--header "Cookie: sid=abc; lang=FUZZ"

When FUZZ is present, --param is not required.

Configuration

Panoptic supports TOML config files for persistent settings:

panoptic --url "http://target/include.php?file=test.txt" \
  --config ~/.config/panoptic/config.toml

Default config location: ~/.config/panoptic/config.toml (loaded automatically when present, even without --config).

[defaults]
# Any long option name (with dashes as underscores) is accepted here,
# including the target and output destinations.
url = "http://target/include.php?file=test.txt"
concurrency = 8
verbose = true
automatic = true
all_versions = true
output_format = "json"
output_file = "results.json"
log_file = "scan.log"
resume_file = "scan.checkpoint"

[proxy]
url = "socks5://127.0.0.1:9050"

[headers]
user_agent = "Mozilla/5.0"
cookie = "sid=foobar; auth=1"
values = ["X-Forwarded-For: 127.0.0.1"]

Priority: CLI args > config file > built-in defaults.

Config-supported target and output options

The [defaults] table accepts any scan option, not just performance tuning. In particular you can persist:

  • url — the default target (override per-run with --url)
  • output_format, output_file — where machine-readable results go
  • log_file — mirror console output to a file
  • resume_file — checkpoint location for resumable scans

Sensitive artifacts written by Panoptic — the log file, the results/list output file, and any files saved with --write-files — are forced to owner-only 0600 permissions on POSIX. Platforms exposing O_NOFOLLOW also atomically refuse a pre-existing symlink at the final path component. On platforms without O_NOFOLLOW, Panoptic performs a best-effort pre-open symlink/junction check, but the check cannot eliminate a race. Windows mode bits do not configure NTFS ACLs, so use an appropriately restricted directory when artifacts may contain sensitive data.

Overriding config booleans on the command line

Download Tool