
Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security testing, and Layer 2/3/7 attack research.
A local & network security assessment framework written in Go. It is a research and authorised-penetration-testing tool that covers the network assessment pipeline — host and service discovery, enumeration, credential auditing, vulnerability identification and authorised exploitation. Its ten module categories span recon, enumeration, OSINT, MITM (ARP/DHCP/DNS/IPv6 poisoning and inline HTTP/HTTPS interception), wireless, switch-layer, web, auth, espionage and post-exploitation — all driven from an interactive REPL, a guided wizard, or one-shot command sequences.
MITM is one capability within this broader domain: TOHA3EE is not limited to man-in-the-middle scenarios.
WARNING: toha3ee actively redirects, poisons, decrypts and intercepts network traffic. Use it only on networks you own or are explicitly authorised to test. Running these modules against third parties is illegal in most jurisdictions. Read
docs/Security.mdfirst.
One-liner installers fetch the prebuilt binary for your platform from the latest release, verify its SHA-256 checksum and add it to your PATH. If no prebuilt binary exists yet they build from source instead.
Linux / macOS:
curl -fsSL https://raw.githubusercontent.com/qyvora/qyvora-toha3ee/main/scripts/install.sh | sh
Windows (PowerShell):
irm https://raw.githubusercontent.com/qyvora/qyvora-toha3ee/main/scripts/install.ps1 | iex
Or from a checkout:
make install # installs ~/.local/bin/toha3ee and adds it to PATH
Install options (Unix): --prefix <dir> (default: /usr/local/bin as root,
else ~/.local/bin), --no-path to skip editing your shell rc, --from-source
to build instead of downloading, and TOHA3EE_VERSION=<tag> to pin a release.
Run with sudo sh ... to install system-wide. The Windows installer puts the
binary in %LOCALAPPDATA%\Programs\toha3ee\bin and updates your user PATH;
Windows-on-ARM64 runs the x64 build.
On Linux the installer also registers the app with the desktop environment: it
installs the logo to the hicolor icon theme and drops a .desktop entry
next to the install prefix (e.g. /usr/local/share or ~/.local/share), so
toha3ee shows up in GNOME's search with its icon. On Windows it copies the
.ico and creates a Start Menu shortcut. The release tarball/zip carry the
icon so the installer can register it from the same verified artifact.
Uninstall: delete the binary and the PATH line the installer added to your
shell rc (or %LOCALAPPDATA%\Programs\toha3ee on Windows).
Once installed, update with:
toha3ee updates # `toha3ee update` works as an alias
Checks the installed version against the latest official QYVORA GitHub release, verifies the download's SHA-256 against the published checksum, and swaps the binary in atomically. Downgrades are refused and any failure leaves your current binary untouched — no Go toolchain or Git required. See docs/Update.md for details.
Requires Go 1.26+ and libpcap.
# Debian/Ubuntu
sudo apt install libpcap-dev
# then
go build ./cmd/toha3ee
Linux builds need libpcap headers (the installer's from-source fallback checks for them and prints the right apt/dnf command if they are missing). macOS ships libpcap with Xcode Command Line Tools.
# Interactive console (bare command drops straight in)
sudo ./toha3ee --iface eth0
# Interactive console (explicit subcommand)
sudo ./toha3ee interactive --iface eth0
# Guided wizard
sudo ./toha3ee wizard --iface eth0
# One-shot: scan the subnet, then show what was found
sudo ./toha3ee --eval "net.scan; net.show" --iface eth0
# One-shot: procedural deep recon (synscan -> fingerprint -> service enum)
sudo ./toha3ee --eval "net.recon; net.profile" --iface eth0
# Non-interactive caplet script
sudo ./toha3ee run --iface eth0 caplets/basic.cap
# Dry-run a .toha3ee script (validates it, prints the plan, sends no packets)
./toha3ee --no-sudo build scripts/full-pipeline.toha3ee
# Execute a .toha3ee script non-interactively
sudo ./toha3ee script --iface eth0 scripts/full-pipeline.toha3ee
Most attack modules require root (raw sockets, packet capture and IP
forwarding). Run as root or with CAP_NET_ADMIN/CAP_NET_RAW where possible.
Add --no-color to disable colored output, -v for verbose logging.
The tool runs with admin privileges by default: on Linux/macOS it
re-executes itself under sudo and prompts for the admin (root) password on
every invocation. Pass --no-sudo (or set TOHA3EE_NO_SUDO=1) to run
unprivileged, e.g. for a quick toha3ee --no-sudo version.
Everything is a module. Modules self-register in their package init() and
are surfaced automatically by the registry; adding an attack means adding a
package under internal/attacks/ that implements the attacks.Module
contract (see internal/attacks/attacks.go):
Meta() — ID, category, risk, targets, description, limitationsPreflight(ctx) — check preconditions before runningRun(ctx, opts) — the attack loop (must respect ctx.Done)Verify(ctx) — report what happenedCleanup(ctx) — undo everything, restore the networkA central safety lifecycle (internal/safety) tracks registered cleanups
and heartbeats so every attack is torn down even on panic or SIGINT, and a
shared store keeps the host inventory, captured credentials, sessions and
the event log that feeds the report generator.