
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Ubuntu. Limited support for Kali Linux.
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Ubuntu. Limited support for Kali Linux.
cd ~
git clone https://github.com/leebaird/discover
cd discover/
./discover.sh
~/.discover/operator-name. That name is written on every engagement audit log line. To change it later, edit or delete that file and restart Discover.config/zshrc)cd ~/discover/config/
./install.sh
| Host | What install.sh does |
|---|---|
| Ubuntu / other (incl. macOS) | Copies zshrc to ~/.bash_aliases and sources it |
Kali (detected via /etc/os-release) | Appends zshrc to ~/.zshrc |
Also installs tmux.conf to ~/.tmux.conf and vimrc to ~/.vimrc.
Useful commands (after install / new shell):
| Command | Purpose |
|---|---|
n | Network summary (external/internal IP, DNS, MAC, iface; ss without TIME-WAIT; ping 8.8.8.8) |
s | cd ~/discover and short git status (no pull) |
m / ms | Start MSF DB + console / stop MSF DB |
web / web2 | HTTP server on port 80 (sudo) / 8000 |
now | Formatted date/time (does not override date) |
update | Grok update + full apt upgrade chain |
bh, th, smb, sip | BloodHound, theHarvester, smbserver, IP sort |
Network identity (IPs, DNS, MAC) is computed when you run n / web / upload — not at shell startup — so new shells stay fast and values stay current after VPN/wifi changes.
Notes
~/.bash_aliases with the repo copy.install.sh appends again and can duplicate the block; edit ~/.zshrc or install only once.~/.bash_aliases unless you source it from ~/.zshrc.RECON
1. Domain
2. Person
SCANNING
3. Generate target list
4. CIDR
5. List
6. IP, range, or URL
7. Rerun Nmap scripts and MSF aux
WEB
8. Insecure direct object reference
9. Open multiple tabs in Firefox
10. Nikto
11. SSL
MISC
12. Generate a malicious payload
13. Start a Metasploit listener
14. CVE lookup
15. Parse XML
16. Dev
17. Notes
18. Update
19. Exit
RECON
1. Passive
2. Breaches
3. Find registered domains
4. Google dorks
5. Web search
6. Active
7. Open report
8. Previous menu
Note: Passive and Active cannot be run as root.
$HOME/data/<domain>/ HTML report.Uses Amass, ARIN, DNSRecon, dnstwist, Metasploit, subfinder, sublist3r, Shodan CTL (free CT hostnames; no API key), theHarvester, Whois, and multiple websites.
$HOME/.theHarvester/api-keys.yaml).$HOME/data/<domain>/.pages/registered-domains.htm in an existing report.tools/company-manual.tsv override); social profile links when found.On Reports > Audit, Import (Discover-hosted only) targets the current engagement.
| Choice | What it does |
|---|---|
| Operator scans | Merge another operator’s unpacked report (host-scans, screenshots, Active data, their audit lines) |
| Names | Merge tools/names-manual.tsv (Name, Title, Phone; # comments; filled title/phone win) |
| Names, titles, and emails | Merge an external names dump into Names and Emails |
| Subdomains | Existing sources (Firefox / Pentest-Tools / TSV) or CSV subdomain,ip,category; optional Active on new public hosts |
CLI (same backends):
bash recon/import-names.sh --report /home/user/data/example.com --json
bash recon/import-names-titles-emails.sh --report /home/user/data/example.com --source /path/to/dump --json
bash recon/import-subdomains.sh --report /home/user/data/example.com \
--mode team-csv --import /home/user/team-hosts.csv --json
# existing: --mode existing --import firefox|/path/to/export
# optional CSV: --run-active
CSV list skips hosts already in tools/subdomains. Empty IP then dig. Category: Discover rules first, else CSV. Never writes recon/subdomain-categories.tsv.
Domain menu option 6. Run after Passive (and optionally Import subdomains).
Enter the location of a previous Discover scan:
/home/user/data/example.com
tools/subdomains (stored RFC1918 skipped).dig A @1.1.1.1 before httpx. A private, loopback, link-local, or 0.0.0.0 answer is left out of httpx and added to tools/private-subs (tools/dns-private.tsv). The stored public IP is not changed. VPN DNS is not used.tools/httpx.jsonl); alive = 200–399, 401, 403, or 405.recon/active-tech.py.Artifacts live under tools/ (httpx.jsonl, whatweb.json, gowitness/, software-cves-cache.json).
In operator mode only (report opened via Open report / Active at http://127.0.0.1:17322/…), Subdomains public rows with an HTTP status get a host-scan expand control (also on ?software= / ?cve= filtered views). Manual file:// open never shows chevrons. Expandable rows show host-scan boxes (quietest to loudest):