Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SCMKit — Source Code Management Attack Toolkit | Kitploit
Tools/GitHubGitHub/xforcered/scmkit
Privilege EscalationReconnaissancePersistence MechanismsInformation GatheringPost-ExploitationPenetration TestingRed Teaming
GitHubxforcered/scmkit

SCMKit

Source Code Management Attack Toolkit

View Repository
13419184 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SCMKit

Description

Source Code Management Attack Toolkit - SCMKit is a toolkit that can be used to attack SCM systems. SCMKit allows the user to specify the SCM system and attack module to use, along with specifying valid credentials (username/password or API key) to the respective SCM system. Currently, the SCM systems that SCMKit supports are GitHub Enterprise, GitLab Enterprise and Bitbucket Server. The attack modules supported include reconnaissance, privilege escalation and persistence. SCMKit was built in a modular approach, so that new modules and SCM systems can be added in the future by the information security community.

Release

  • Version 1.2 of SCMKit can be found in Releases

Table of Contents

  • SCMKit
  • Table of Contents
  • Installation/Building
    • Libraries Used
    • Pre-Compiled
    • Building Yourself
  • Usage
    • Arguments/Options
    • Systems
    • Modules
    • Module Details Table
  • Examples
    • List Repos
    • Search Repos
    • Search Code
    • Search Files
    • List Snippets
    • List Runners
    • List Gists
    • List Orgs
    • Get Privileges of API Key
    • Add Admin
    • Remove Admin
    • Create Access Token
    • List Access Tokens
    • Remove Access Token
    • Create SSH Key
    • List SSH Keys
    • Remove SSH Key
    • List Admin Stats
    • List Branch Protection
  • Detection
  • References

Installation/Building

Libraries Used

The below 3rd party libraries are used in this project.

LibraryURLLicense
Octokithttps://github.com/octokit/octokit.netMIT License
Fodyhttps://github.com/Fody/FodyMIT License
GitLabApiClienthttps://github.com/nmklotas/GitLabApiClientMIT License
Newtonsoft.Jsonhttps://github.com/JamesNK/Newtonsoft.JsonMIT License

Pre-Compiled

  • Use the pre-compiled binary in Releases

Building Yourself

Take the below steps to setup Visual Studio in order to compile the project yourself. This requires a .NET library that can be installed from the NuGet package manager.

  • Load the Visual Studio project up and go to "Tools" --> "NuGet Package Manager" --> "Package Manager Settings"
  • Go to "NuGet Package Manager" --> "Package Sources"
  • Add a package source with the URL https://api.nuget.org/v3/index.json
  • Install the below NuGet packages
    • Install-Package Costura.Fody -Version 3.3.3
    • Install-Package Octokit
    • Install-Package GitLabApiClient
    • Install-Package Newtonsoft.Json
  • You can now build the project yourself!

Usage

Arguments/Options

  • -c, -credential - credential for authentication (username:password or apiKey)
  • -s, -system - system to attack (github,gitlab,bitbucket)
  • -u, -url - URL for GitHub Enterprise, GitLab Enterprise or Bitbucket Server
  • -m, -module - module to run
  • -o, -option - options (when applicable)

Systems (-s, -system)

  • github: GitHub Enterprise
  • gitlab: GitLab Enterprise
  • bitbucket: Bitbucket Server

Modules (-m, -module)

  • listrepo: list all repos the current user can see
  • searchrepo: search for a given repo
  • searchcode: search for code containing keyword search term
  • searchfile: search for filename containing keyword search term
  • listsnippet: list all snippets of current user
  • listrunner: list all GitLab runners available to current user
  • listgist: list all gists of current user
  • listorg: list all orgs current user belongs to
  • privs: get privs of current API token
  • addadmin: promote given user to admin role
  • removeadmin: demote given user from admin role
  • createpat: create personal access token for target user
  • listpat: list personal access tokens for a target user
  • removepat: remove personal access token for a target user
  • createsshkey: create SSH key for current user
  • listsshkey: list SSH keys for current user
  • removesshkey: remove SSH key for current user
  • adminstats: get admin stats (users, repos, orgs, gists)
  • protection: get branch protection settings

Module Details Table

The below table shows where each module is supported

Attack ScenarioModuleRequires Admin?GitHub EnterpriseGitLab EnterpriseBitbucket Server
ReconnaissancelistrepoNoXXX
ReconnaissancesearchrepoNoXXX
ReconnaissancesearchcodeNoXXX
ReconnaissancesearchfileNoXXX
ReconnaissancelistsnippetNoX
ReconnaissancelistrunnerNoX
ReconnaissancelistgistNoX
ReconnaissancelistorgNoX
ReconnaissanceprivsNoXX
ReconnaissanceprotectionNoX
PersistencelistsshkeyNoXXX
PersistenceremovesshkeyNoXXX
PersistencecreatesshkeyNoXXX
PersistencelistpatNoXX
PersistenceremovepatNoXX
PersistencecreatepatYes (GitLab Enterprise only)XX
Privilege EscalationaddadminYesXXX
Privilege EscalationremoveadminYesXXX
ReconnaissanceadminstatsYesX

Examples

List Repos

Use Case

Discover repositories being used in a particular SCM system

Syntax

Provide the listrepo module, along with any relevant authentication information and URL. This will output the repository name and URL.

GitHub Enterprise

This will list all repositories that a user can see.

SCMKit.exe -s github -m listrepo -c userName:password -u https://github.something.local

SCMKit.exe -s github -m listrepo -c apiKey -u https://github.something.local

GitLab Enterprise

This will list all repositories that a user can see.

SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local

SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local

Bitbucket Server

This will list all repositories that a user can see.

SCMKit.exe -s bitbucket -m listrepo -c userName:password -u https://bitbucket.something.local

SCMKit.exe -s bitbucket -m listrepo -c apiKey -u https://bitbucket.something.local

Example Output


C:\>SCMKit.exe -s gitlab -m listrepo -c username:password -u https://gitlab.hogwarts.local

==================================================
Module:         listrepo
System:         gitlab
Auth Type:      Username/Password
Options:
Target URL:     https://gitlab.hogwarts.local

Timestamp:      1/14/2022 8:30:47 PM
==================================================
Download Tool