Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
swarm — Un outil de test de pénétration modulaire et distribué. | Kitploit
Outils/GitHubGitHub/a7vinx/swarm
Frameworks de Tests d'IntrusionScanners de VulnérabilitésCollecte d'InformationsSécurité WebTests d'IntrusionÉnumération de Sous-domainesCrawler
GitHuba7vinx/swarm

swarm

Un outil de test de pénétration modulaire et distribué.

Voir le dépôt
4116il y a 9 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

swarm

v0.6.0

Anglais | 中文.

Swarm est un outil de test de pénétration distribué modulaire open source qui utilise une file d'attente de tâches distribuée pour implémenter la communication dans un système maître-esclave et utilise MongoDB pour le stockage des données. Il se compose d'un framework distribué et de modules fonctionnels. Le module fonctionnel peut être une implémentation entièrement nouvelle de certaines fonctions de pénétration ou un simple wrapper d'un outil existant pour implémenter des fonctionnalités distribuées. Grâce à l'architecture modulaire, il est facile de personnaliser et d'étendre de nouvelles fonctionnalités dans le framework distribué.

Actuellement, dans cette version 0.6.0, il comporte cinq modules :

  • Module de scan de noms de sous-domaines
  • Module de scan de répertoires et fichiers
  • Module d'extension Nmap
  • Module de crawl de sitemap
  • Module Intruder

Si vous souhaitez écrire votre propre module, vous pouvez lire ceci.

Install

Vous pouvez télécharger l'archive zip ici. Vous pouvez également utiliser git pour obtenir swarm :

root@kitploit:~
git clone [email protected]:Arvin-X/swarm.git

puis utilisez setup.py pour installer swarm :

root@kitploit:~
python setup.py install

Swarm fonctionne avec Python 2.6.x ou 2.7.x et nécessite MongoDB sur l'hôte maître.

Si vous n'avez pas encore MongoDB, vous pouvez utiliser apt-get pour l'installer :

root@kitploit:~
apt-get install mongodb

Usage

Exécutez swarm sur l'hôte maître pour distribuer les tâches et exécutez swarm-s avec l'option '-p' sur l'hôte esclave pour terminer la sous-tâche provenant du maître.

root@kitploit:~
swarm-s -p 9090

Vous pouvez également établir un écouteur sur le port cible de l'hôte esclave pour recevoir la commande de réveil de swarm-s en spécifiant l'option '--waken' lors de l'exécution de swarm. Sinon, laissez '--waken' vide. Pour créer un écouteur, vous pouvez utiliser nc ou socat comme ceci :

root@kitploit:~
nc -e /bin/sh -l 9191

Et utilisez la commande de réveil comme :

root@kitploit:~
swarm-s ARGS

Vous devez laisser "ARGS" dans votre commande et vous assurer qu'il s'agira des arguments CLI passés à swarm pour que swarm le remplace par des arguments nécessaires comme '-p'.

Basic usage of swarm:

root@kitploit:~
usage: swarm [-h] -m MODULE [-v] [-c] [-o PATH] [-t [TARGET [TARGET ...]]]
             [-T PATH] [-s [SWARM [SWARM ...]]] [-S PATH] [--waken CMD]
             [--timeout TIME] [--m-addr ADDR] [--m-port PORT] [--s-port PORT]
             [--authkey KEY] [--db-addr ADDR] [--db-port PORT] [--process NUM]
             [--thread NUM] [--taskg NUM] [--dom-compbrute] [--dom-dict PATH]
             [--dom-maxlevel NUM] [--dom-charset SET] [--dom-levellen LEN]
             [--dom-timeout TIME] [--dir-http-port PORT]
             [--dir-https-port PORT] [--dir-compbrute] [--dir-charset SET]
             [--dir-len LEN] [--dir-dict PATH] [--dir-maxdepth NUM]
             [--dir-timeout TIME] [--dir-not-exist FLAG] [--dir-quick-scan]
             [--nmap-ports PORTS] [--nmap-top-ports NUM] [--nmap-ops ...]
             [--int-target [URLS [URLS ...]]] [--int-method METHOD]
             [--int-headers JSON] [--int-cookies COOKIES] [--int-body BODY]
             [--int-payload PAYLOAD] [--int-flag FLAGS] [--int-timeout TIME]
             [--map-seed SEED] [--map-http-port PORT] [--map-https-port PORT]
             [--map-cookies COOKIES] [--map-interval TIME]
             [--map-timeout TIME]

optional arguments:
  -h, --help            show this help message and exit
  -m MODULE             Use module name in ./modules/ to enable it

Output:
  These option can be used to control output

  -v                    Output more verbose
  -c                    Disable colorful log output
  -o PATH               Record log in target file

Target:
  At least one of these options has to be provided to define target unless
  there is another special option for defining target in the module

  -t [TARGET [TARGET ...]]
                        Separated by blank (eg: github.com 127.0.0.0/24
                        192.168.1.5)
  -T PATH               File that contains target list, one target per line

Swarm:
  Use these options to customize swarm connection. At least one of slave
  host has to be provided.

  -s [SWARM [SWARM ...]]
                        Address of slave hosts with port if you need waken
                        them (eg: 192.168.1.2:9090 192.18.1.3:9191). No port
                        if swarm-s on slave host has already run
  -S PATH               File that contains slave list, one host per line
  --waken CMD           Command to waken up slave hosts, null if swarm-s on
                        slave host has already run
  --timeout TIME        Seconds to wait before request to swarm getting
                        response
  --m-addr ADDR         Master address which is reachable by all slave hosts
  --m-port PORT         Listen port on master host to distribute task
  --s-port PORT         Listen port on slave host to receive command from
                        master
  --authkey KEY         Auth key between master and slave hosts

Database:
  These option can be used to access MongoDB server

  --db-addr ADDR        Address of MongoDB server
  --db-port PORT        Listening port of MongoDB server

Common:
  These option can be used to customize common configuration of slave host

  --process NUM         Max number of concurrent process on slave host
  --thread NUM          Max number of concurrent threads on slave host
  --taskg NUM           Granularity of subtasks from 1 to 3

Domain Scan:
  Thes option can be used to customize swarm action of subdomain name scan

  --dom-compbrute       Use complete brute force without dictionary on target
  --dom-dict PATH       Path to dictionary used for subdomain name scan
  --dom-maxlevel NUM    Max level of subdomain name to scan
  --dom-charset SET     Charset used for complete brute foce
  --dom-levellen LEN    Length interval of subdomain name each level
  --dom-timeout TIME    Timeout option for subdomain name scan

Directory Scan:
  These option can be used to customize swarm action of directory scan

  --dir-http-port PORT  Separated by comma if you need multiple ports
  --dir-https-port PORT
                        Separated by comma if you need multiple ports
  --dir-compbrute       Use complete brute force without dictionary on target
  --dir-charset SET     Charset used for complete brute foce
  --dir-len LEN         Length interval of directory name or file name
  --dir-dict PATH       Path to dictionary used for directory scan
  --dir-maxdepth NUM    Max depth in directory and file scan
  --dir-timeout TIME    Timeout option for directory scan
  --dir-not-exist FLAG  Separated by double comma if you need multiple flags
  --dir-quick-scan      Use HEAD method instead of GET in scan

Nmap Module:
  These options can be used customize nmap action on slave hosts

  --nmap-ports PORTS    Support format like '80,443,3306,1024-2048'
  --nmap-top-ports NUM  Scan <number> most common ports
  --nmap-ops ...        Nmap options list in nmap’s man pages, this should
                        be the last in cli args

Intruder:
  Use indicator symbol '@n@' where 'n' should be a number, like '@0@','@1@'
  etc to specify attack point in option 'int_target' and 'int_body'. Use
  'int_payload' option to specify payload used on these attack point to
  complete this attack.

  --int-target [URLS [URLS ...]]
                        Use this option instead of '-t' or '-T' options to
                        specify targets,separated by comma
  --int-method METHOD   Http method used in this attack
  --int-headers JSON    A JSON format data.(eg: {"User-
                        Agent":"Mozilla/5.0","Origin":"XXX"})
  --int-cookies COOKIES
                        Separated by comma. (eg: PHPSESSIONID:XX,token:XX)
  --int-body BODY       HTTP or HTTPS body. You can use indicator symbol in
                        this option
  --int-payload PAYLOAD
                        The format should follow '@0@:PATH,@1@:CHARSET
                        :NUM-NUM'
  --int-flag FLAGS      Separated by double comma if you have multiple flags
  --int-timeout TIME    Timeout option for intruder module

Sitemap Crawler:
  These options can be used to customize sitemap crawler, not support js
  parse yet

  --map-seed SEED       Separated by comma if you have multiple seeds
  --map-http-port PORT  Separated by comma if you need multiple ports
  --map-https-port PORT
                        Separated by comma if you need multiple ports
  --map-cookies COOKIES
                        Separated by comma if you have multiple cookies
  --map-interval TIME   Interval time between two request
  --map-timeout TIME    Timeout option for sitemap crawler

Il est recommandé d'utiliser un fichier de configuration pour configurer swarm plutôt que les arguments CLI si vos besoins sont élevés. Les fichiers de configuration se trouvent dans /etc/swarm/.

Licence

Swarm est sous licence GPLv3.

Télécharger l’outil