
Tentacle은 POC 취약점 검증 및 익스플로잇 프레임워크입니다. 익스플로잇의 자유로운 확장을 지원하며 POC 스크립트를 사용합니다. zoomeye, fofa, shodan 등 여러 API를 호출하여 다중 대상에 대한 대량 취약점 검증을 지원합니다.
.___________. _______ .__ __. .___________. ___ ______ __ _______
| || ____|| \ | | | | / \ / || | | ____| {1.0.0#stable}
`---| |----`| |__ | \| | `---| |----` / ^ \ | ,----'| | | |__
| | | __| | . ` | | | / /_\ \ | | | | | __|
| | | |____ | |\ | | | / _____ \ | `----.| `----.| |____
|__| |_______||__| \__| |__| /__/ \__\ \______||_______||_______| http://www.orleven.com
Tentacle은 POC 취약점 검증 및 익스플로잇 프레임워크입니다. 익스플로잇의 자유로운 확장을 지원하며 POC 스크립트를 사용합니다. zoomeye, fofa, shodan 등 API를 호출하여 여러 대상에 대한 대량 취약점 검증을 수행할 수 있습니다. (아직 개발 중...)

pip3 install -r requestment.txt
처음 실행할 때 conf/tentacle.conf 설정 파일이 자동으로 생성됩니다.
# Show help for tentacle.
python3 tentacle.py --help
# Show all modules, and you can see it in `script` path.
python3 tentacle.py --show
# Load target by iS/iN/iF/iT/iX/iE/gg/sd/ze/ff.
# Scan port and then it will try to send the poc.
python3 tentacle.py -m script/vul/web/web_status -iS www.examples.com # Load target by url or host
python3 tentacle.py -m script/vul/web/web_status -iF target.txt # Load target by file
python3 tentacle.py -m script/vul/web/web_status -iT dcc54c3e1cc2c2e1 # Load target by recode's target
python3 tentacle.py -m script/vul/web/web_status -iX nmap_xml.xml # Load target by nmap.xml
python3 tentacle.py -m script/vul/web/web_status -iE "powered by discuz" # Load target by baidu/bing/360so
python3 tentacle.py -m script/vul/web/web_status -gg 'intextdiscuz' # Load target by google api
python3 tentacle.py -m script/vul/web/web_status -sd 'apache' # Load target by shodan api
python3 tentacle.py -m script/vul/web/web_status -ze 'app:weblogic' # Load target by zoomeye api
python3 tentacle.py -m script/vul/web/web_status -ff 'domain="example.com"' # Load target by fofa api
# Load modules by -m (e.g. script/vul/web/web_status,@web)
python3 tentacle.py -iS 127.0.0.1 -m script/vul/web/web_status # Load web_status module
python3 tentacle.py -iS 127.0.0.1 -m @web # Load all module of web path
python3 tentacle.py -iS 127.0.0.1 -m script/vul/web/web_status,@web # Load all module of web path and web_status module
python3 tentacle.py -iS 127.0.0.1 -m "*" # Load all module of script path
python3 tentacle.py -iS 127.0.0.1 -m "*" -e @web # Load all module of script path, exclude all module of web path
# Set port scan scope
python3 tentacle.py -iS 127.0.0.1 -m script/vul/web/web_status # Scan top 150 ports and then perform bulk vulnerability verification for multiple targets.
python3 tentacle.py -iS 127.0.0.1 -m script/vul/web/web_status -sB # Skip port scan and then it will try the default port number server
python3 tentacle.py -iS 127.0.0.1 -m script/vul/web/web_status -lP 80-90,443 # Scan 80-90 ports and 443 port and then perform bulk vulnerability verification for multiple targets.
# Use function of modules by -m and -f (e.g. -m web_status -f prove), and you should make sure the function of module is exist.
python3 tentacle.py -m script/vul/web/web_status -f prove
# Show task's result by -tS
python3 tentacle.py -tS 8d4b37597aaec25e
# Export task's result by -tS to test.xlsx
python3 tentacle.py -tS 8d4b37597aaec25e -o test
# Export task's result by -tS to test.json
python3 tentacle.py -tS 8d4b37597aaec25e -oJ test
# Update by git
python3 tentacle.py --update