Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Pegasus-Pentest-Arsenal — A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool. | Kitploit
Tools/GitHubGitHub/sobri3195/pegasus-pentest-arsenal
ReconnaissanceVulnerability ScannersWeb Vulnerability ScannersExploitationAPI Security TestingInformation GatheringWeb SecurityCTFPenetration Testing

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Misconfiguration
Learning & Education
Labs & Practice
GitHubsobri3195/pegasus-pentest-arsenal

Pegasus-Pentest-Arsenal

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

View Repository
5516205 months agoReviewed by Kitploit
Share

Pegasus Pentest Arsenal (PPA)

                                                    
                                   /\               
                               _  / |               
                              / \ |  \              
                             |  |\|  |              
                             |  | | /               
                             | /| |/                
                             |/ |/                  
                        ,/;  ;  ;                   
                     ,'/|; ,/,/,                    
                   ,'/ |;/,/,/,/|                   
                ,/;  |;|/,/,/,/,/|                  
              ,/';   |;|,/,/,/,/,/|                 
            ,/';     |;|/,/,/,/,/,/|,              
           /  ;      |;|,/,/,/,/,/,/|              
          / ,';      |;|/,/,/,/,/,/,/|             
         /,/';       |;|,/,/,/,/,/,/,/|            
        /;/ ';       |;|/,/,/,/,/,/,/,/|           
                                                    
     ██████╗ ███████╗ ██████╗  █████╗ ███████╗██╗   ██╗███████╗
     ██╔══██╗██╔════╝██╔════╝ ██╔══██╗██╔════╝██║   ██║██╔════╝
     ██████╔╝█████╗  ██║  ███╗███████║███████╗██║   ██║███████╗
     ██╔═══╝ ██╔══╝  ██║   ██║██╔══██║╚════██║██║   ██║╚════██║
     ██║     ███████╗╚██████╔╝██║  ██║███████║╚██████╔╝███████║
     ╚═╝     ╚══════╝ ╚═════╝ ╚═╝  ╚═╝╚══════╝ ╚═════╝ ╚══════╝
                    P E N T E S T   A R S E N A L                

A comprehensive web application security testing toolkit that combines 30 powerful penetration testing features into one tool.

Author

  • Letda Kes Dr. Sobri, S.Kom
  • GitHub: sobri3195
  • Email: [email protected]

Support the Project

If you find this tool useful, consider supporting the development:

Donate

Features

  1. Subdomain + Curl HTTP Scanner

    • Discovers subdomains using a wordlist
    • Checks HTTP status and security headers
    • Identifies potential security misconfigurations
  2. JWT Token Inspector

    • Analyzes JWT token structure and claims
    • Identifies security issues in token configuration
    • Detects common JWT vulnerabilities
  3. Parameter Pollution Finder

    • Tests for HTTP Parameter Pollution (HPP)
    • Identifies vulnerable parameters
    • Detects server-side parameter handling issues
  4. CORS Misconfiguration Scanner

    • Tests for CORS policy misconfigurations
    • Identifies dangerous wildcard policies
    • Detects credential exposure risks
  5. Upload Bypass Tester

    • Tests file upload restrictions
    • Attempts various bypass techniques
    • Identifies dangerous file type handling
  6. Exposed .git Directory Finder

    • Scans for exposed version control files
    • Identifies leaked Git repositories
    • Tests for sensitive information disclosure
  7. SSRF (Server Side Request Forgery) Detector

    • Tests for SSRF vulnerabilities
    • Identifies vulnerable parameters
    • Includes cloud metadata endpoint tests
  8. Blind SQL Injection Time Delay Detector

    • Tests for time-based SQL injection
    • Supports multiple database types
    • Identifies injectable parameters
  9. Local File Inclusion (LFI) Mapper

    • Tests for LFI vulnerabilities
    • Includes path traversal detection
    • Supports various encoding bypasses
  10. Web Application Firewall (WAF) Fingerprinter

    • Identifies WAF presence
    • Detects WAF vendor/type
    • Tests WAF effectiveness
  11. Security Headers Auditor

    • Checks for missing or weak security headers
    • Highlights CSP, HSTS, and clickjacking protection gaps
    • Provides actionable recommendations
  12. Robots.txt & Sitemap Analyzer

    • Retrieves robots.txt directives and sitemap locations
    • Highlights sensitive disallowed paths
    • Extracts URLs from sitemap files
  13. Directory & File Discovery

    • Probes common admin, API, and backup paths
    • Identifies exposed services and entry points
  14. Backup/Config Exposure Scanner

    • Looks for leaked backup archives and config files
    • Flags potential data leakage points
  15. Open Redirect Tester

    • Tests redirect parameters for unsafe redirect behavior
    • Flags reflected external redirect destinations
  16. Reflected XSS Tester

    • Injects XSS payloads into parameters
    • Detects reflection that may lead to XSS
  17. Host Header Injection Tester

    • Sends forged Host/X-Forwarded-Host headers
    • Checks for unsafe host reflection and redirect issues
  18. HTTP Method Tester

    • Identifies dangerous or unexpected HTTP methods
    • Displays server Allow headers for quick review
  19. Cookie Security Checker

    • Audits Secure, HttpOnly, and SameSite flags
    • Highlights weak session cookie configurations
  20. Rate Limiting Tester

    • Sends burst requests to detect rate limiting
    • Flags response time spikes or 429 responses
  21. Subdomain Takeover Checker

    • Checks subdomains for common unclaimed-service fingerprints
    • Highlights takeover indicators for manual validation
  22. Clickjacking Tester

    • Audits X-Frame-Options and CSP frame-ancestors
    • Flags pages that can likely be embedded in iframes
  23. TLS Configuration Scanner

    • Negotiates TLS with the target and shows selected protocol/cipher
    • Displays certificate issuer, subject, and expiration info
  24. GraphQL Introspection Tester

    • Probes common GraphQL endpoints
    • Checks whether schema introspection is exposed
  25. CSRF Token Checker

    • Parses forms and identifies missing anti-CSRF tokens
    • Focuses on risky POST forms
  26. IDOR Pattern Scanner

    • Mutates numeric identifiers in query parameters
    • Flags suspicious access-control behavior changes
  27. API Version Discovery

    • Probes common API and documentation version paths
    • Surfaces accessible endpoints for deeper review
  28. Cache Poisoning Checker

    • Sends cache-related poisoning probes via headers
    • Detects reflection patterns and reports cache headers
  29. CRLF Injection Tester

    • Injects CRLF payloads into query parameters
    • Checks for header injection behavior
  30. XXE Tester

    • Sends XML payloads with external entity references
    • Flags responses that indicate unsafe XML parsing

Installation

  1. Clone the repository:
git clone https://github.com/sobri3195/pegasus-pentest-arsenal.git
cd pegasus-pentest-arsenal
  1. Create a virtual environment (recommended):
python -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate
  1. Install dependencies:
pip install -r requirements.txt

Usage

  1. Run the main script:
python pegasus_pentest.py
  1. Select a tool from the menu (1-30)
  2. Follow the prompts to enter target information
  3. Review the results

Requirements

  • Python 3.8+
  • Required packages (see requirements.txt):
    • requests
    • httpx
    • urllib3
    • colorama
    • pyjwt
    • beautifulsoup4

Security Considerations

  • This tool is for educational and authorized testing purposes only
  • Always obtain proper authorization before testing any target
  • Some features may trigger security alerts or be blocked by security controls
  • Use responsibly and ethically

Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Commit your changes
  4. Push to the branch
  5. Create a Pull Request

License

This project is licensed under the MIT License - see the LICENSE file for details.

Disclaimer

This tool is provided for educational and authorized testing purposes only. Users are responsible for obtaining proper authorization before testing any target. The authors are not responsible for any misuse or damage caused by this tool.

Download Tool