Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
HIKRAVEN β€” HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests default credentials, performs network discovery, and generates professional security reports. For authorized security testing only! πŸ›‘οΈπŸ”’ | Kitploit
Tools/GitHubGitHub/sylhetyhackvenger/hikraven
ReconnaissanceVulnerability ScannersIoT SecurityPassword AttacksPort ScanningExploitationWeb Application ExploitationInformation GatheringPenetration Testing

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
GitHubsylhetyhackvenger/hikraven

HIKRAVEN

View Repository
32461 month agoNot yet reviewed

About

HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests default credentials, performs network discovery, and generates professional security reports. For authorized security testing only! πŸ›‘οΈπŸ”’

Share

HIKRAVEN πŸ›‘οΈ

Banner 1

Advanced Hikvision Security Assessment Platform - Professional Edition

Features β€’ Quick Start β€’ Installation β€’ Usage β€’ Documentation β€’ Disclaimer


⚠️ IMPORTANT LEGAL NOTICE

[!] THIS TOOL IS FOR AUTHORIZED SECURITY TESTING ONLY [!]

Unauthorized access to computer systems is illegal and unethical.

By using this tool, you agree to:

Β· Only test systems you own or have explicit written permission to test Β· Comply with all applicable laws and regulations Β· Use findings responsibly and report vulnerabilities ethically Β· Accept full legal responsibility for your actions


πŸ“‹ Table of Contents

Β· Overview Β· Features Β· Installation Β· Quick Start Β· Usage Guide Β· Commands Reference Β· Reporting Β· Vulnerabilities Detected Β· Architecture Β· Configuration Β· Contributing Β· Disclaimer Β· License


πŸ” Overview

HIKRAVEN is a professional-grade security assessment platform specifically designed for identifying and analyzing vulnerabilities in Hikvision devices. Built for security researchers, penetration testers, and IT security professionals. It provides comprehensive network discovery, vulnerability scanning, and reporting capabilities.

Key Capabilities

Capability Description πŸ”Ž Discovery Passive and active network discovery with ARP sniffing, multicast probing, and port scanning 🎯 Fingerprinting Detailed device identification including model, firmware, serial numbers, and cloud status πŸ›‘οΈ Vulnerability Scan Detection of 12+ known CVEs including critical command injection vulnerabilities πŸ”‘ Credential Testing Automated testing of 40+ default username/password combinations πŸ’₯ Exploitation Safe and controlled exploitation testing for authorized penetration testing πŸ“Š Reporting Professional reports in JSON, HTML, CSV, and Markdown formats πŸ—„οΈ Database Persistent storage with encryption for credentials and scan history


✨ Features

πŸš€ Discovery & Reconnaissance

Β· Passive ARP Sniffing - Detect Hikvision devices without active scanning Β· Multicast Probing - Discover devices via UDP multicast (239.255.255.250:37020) Β· Subnet Scanning - Ping sweeps and port scanning across entire subnets Β· MAC OUI Detection - Identify Hikvision devices by MAC address prefixes Β· Interface Management - Multi-interface support with cross-platform compatibility Β· Reverse DNS - Automatic hostname resolution

πŸ›‘οΈ Vulnerability Assessment

Β· 12+ CVE Signatures - Comprehensive vulnerability database including: Β· CVE-2021-36260 (Command Injection - CRITICAL) Β· CVE-2017-7923 (Authentication Bypass - HIGH) Β· CVE-2019-11376 (Information Disclosure - HIGH) Β· And more... Β· Default Credential Testing - 40+ common username/password combinations Β· Web Interface Analysis - Extract device information from web interfaces Β· Cloud Management Detection - Identify Hik-Connect enabled devices Β· Risk Scoring - Automatic threat level calculation (INFO β†’ CRITICAL)

πŸ’£ Exploitation (Authorized Use Only)

Β· CVE-2021-36260 - Command injection exploitation with safe mode Β· CVE-2017-7923 - Authentication bypass and password reset Β· Safe Mode - Non-destructive testing options Β· Evidence Collection - Proof of concept capture

πŸ“Š Professional Reporting

Format Use Case Features HTML Executive Reports Interactive, styled, device cards, severity coloring JSON API Integration Machine-readable, structured, complete dataset CSV Spreadsheet Analysis Excel-compatible, pivot table ready Markdown Documentation Readable, version control friendly

πŸ—„οΈ Database & Management

Β· SQLite Storage - Lightweight, portable database Β· Encrypted Credentials - AES-256 encryption for sensitive data Β· Scan History - Complete audit trail of all scans Β· Automatic Backups - Database rotation and compression Β· Device Fingerprinting - Unique identifiers to prevent duplicates


Banner 2

πŸ“¦ Installation

Prerequisites

Python 3.8 or higher
pip (Python package manager)

Quick Install

# Clone the repository
git clone https://github.com/SYLHETYHACKVENGER/HIKRAVEN
cd HIKRAVEN 

# Install dependencies
pip install -r requirements.txt

# Verify installation
python hikraven.py --version

Dependencies

requests>=2.31.0
scapy>=2.5.0
lxml>=4.9.0
cryptography>=41.0.0
colorama>=0.4.6
pyyaml>=6.0
tqdm>=4.66.0
packaging>=23.1
rich>=13.5.0
netifaces>=0.11.0
psutil>=5.9.5

Platform-Specific Notes

Linux/Unix:

# May require root privileges for packet capture
sudo python hikraven.py --interface eth0

# Install additional dependencies
sudo apt-get install python3-scapy

Windows:

# Run as Administrator for packet capture
python hikraven.py --interface "Ethernet"

# Install Npcap for packet capture
# Download from: https://npcap.com/

macOS:

# May require sudo for packet capture
sudo python hikraven.py --interface en0

πŸš€ Quick Start

  1. Basic Discovery
# Auto-detect interface and scan local network
python hikraven.py --auto-detect

# Scan specific subnet
python hikraven.py --subnet 192.168.1.0/24
  1. Full Security Assessment
# Complete vulnerability scan with reporting
python hikraven.py --interface eth0 --subnet 192.168.1.0/24 --vuln-scan --report html
  1. Stealth Mode
# Low-profile scanning with rate limiting
python hikraven.py --interface eth0 --stealth --passive
  1. Exploitation Testing (Authorized Only)
# Safe exploitation testing
python hikraven.py --subnet 192.168.1.0/24 --vuln-scan --exploit

πŸ“– Usage Guide

Command Line Options

Option Short Description --interface -i Network interface (e.g., eth0, wlan0) --address -a IP address of the interface --auto-detect -D Auto-detect network interface --list-interfaces -L List available network interfaces --passive -p Passive discovery only (ARP sniffing) --active -A Active discovery (ping scan, port scan) --subnet -s Subnet to scan (e.g., 192.168.1.0/24) --vuln-scan -v Perform vulnerability scanning --exploit -e Attempt exploitation (DANGEROUS!) --report -r Generate report format(s) --output -o Output directory for reports --stealth Enable stealth mode --threads -t Number of threads (default: 100) --timeout Network timeout in seconds (default: 10) --config -c Configuration file path --verbose -V Verbose output --quiet -q Quiet mode --version Show version

Examples

  1. List Available Interfaces
python hikraven.py --list-interfaces
  1. Passive Discovery
# Discover devices without active scanning
python hikraven.py --interface wlan0 --passive --verbose
  1. Full Network Scan
# Complete scan with all features
python hikraven.py --interface eth0 --subnet 10.0.0.0/24 --vuln-scan --report all
  1. Custom Output Directory
# Save reports to custom location
python hikraven.py --subnet 192.168.1.0/24 --vuln-scan --output /home/user/security-reports
  1. Performance Tuning
# High-performance scan
python hikraven.py --subnet 192.168.1.0/24 --threads 200 --timeout 5

# Conservative scan
python hikraven.py --subnet 192.168.1.0/24 --threads 20 --timeout 20 --stealth

πŸ“Š Reporting

Report Generation

# Generate all report formats
python hikraven.py --subnet 192.168.1.0/24 --vuln-scan --report all

# Generate specific format
python hikraven.py --subnet 192.168.1.0/24 --vuln-scan --report html
python hikraven.py --subnet 192.168.1.0/24 --vuln-scan --report json

Report Contents

Executive Summary

Β· Total devices discovered Β· Vulnerable devices count Β· Total vulnerabilities found Β· Severity distribution Β· Risk score overview

Download Tool