Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
catsploit — 一个自动化渗透测试工具,使用网络攻击技术评分(CATS)来选择并通过Metasploit、Nmap和OpenVAS集成执行最优攻击场景。 | Kitploit
工具/GitHubGitHub/catsploit/catsploit
渗透测试框架侦察漏洞扫描器漏洞利用框架信息收集渗透测试
GitHubcatsploit/catsploit

catsploit

一个自动化渗透测试工具,使用网络攻击技术评分(CATS)来选择并通过Metasploit、Nmap和OpenVAS集成执行最优攻击场景。

查看仓库
32146392年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CATSploit🐈

CATSploit 是一款利用网络安全攻击技术评分(CATS)方法的自动化渗透测试工具,无需渗透测试人员即可使用。 目前,渗透测试人员通常隐含地为待攻击的目标系统选择合适的攻击技术。 CATSploit 利用扫描器收集的系统配置信息(如操作系统、开放端口、软件版本),并为每个攻击技术计算针对目标系统的捕获得分(eVc)和可检测性得分(eVd)。 通过选择最高得分值,无需黑客技巧(专业渗透测试人员的技能)即可选出最适合目标系统的攻击技术。

CATSploit 按以下顺序自动执行渗透测试:

  1. 信息收集与先验信息输入 首先,收集目标系统的信息。CATSploit 支持使用 nmap 和 OpenVAS 收集目标系统信息。 如果您拥有目标系统的先验信息,CATSploit 也支持导入。

  2. 计算攻击技术的得分值 利用上一阶段获取的信息和攻击技术数据库,计算每个攻击技术的捕获评估值(eVc)和可检测性评估值(eVd)。 对每个目标计算机,计算每种攻击技术的得分值。

  3. 根据得分选择攻击技术并制定攻击场景 根据预定义的策略选择攻击技术并创建攻击场景。 例如,对于优先选择难以被检测的策略,将选择 eVd(可检测得分)最低的攻击技术。

  4. 执行攻击场景 CATSploit 根据上一阶段构建的攻击场景执行攻击技术。 CATSploit 使用 Metasploit 作为框架,并通过 Metasploit API 执行实际攻击。

目录

  • 先决条件
  • 安装
  • 用法
  • 示例
  • 免责声明
  • 许可证
  • 联系方式

先决条件

CATSploit 需要以下先决条件:

  • Kali Linux 2023.2a

安装

对于 Metasploit、Nmap 和 OpenVAS,假定它们已随 Kali 发行版 一起安装。

安装 CATSploit

要安装最新版本的 CATSploit,请使用以下命令:

克隆与设置
$ git clone https://github.com/catsploit/catsploit.git
$ cd catsploit
$ git clone https://github.com/catsploit/cats-helpers.git
$ sudo sh ./setup.sh

编辑配置文件

CATSploit 采用服务器-客户端架构,服务器启动时会读取配置 JSON 文件。 在 config.json 中,应根据您的环境修改以下字段:

  • DBMS
    • dbname:为 CATSploit 创建的数据库名称
    • user:PostgreSQL 的用户名
    • password:PostgreSQL 的密码
    • host:如果使用远程主机上的数据库,请指定该主机的 IP 地址
  • SCENARIO
    • generator.maxscenarios:要计算的最大场景数量(*)
  • ATTACKPF
    • msfpassword:MSFRPCD 的密码
    • openvas.user:PostgreSQL 的用户名
    • openvas.password:PostgreSQL 的密码
    • openvas.maxhosts:同时测试的最大主机数(*)
    • openvas.maxchecks:同时测试的最大测试项数量(*)
  • ATTACKDB
    • attack_db_dir:存储 AttackStep 的文件夹路径

(*)请根据您机器的规格调整数值。

用法

要启动服务器,执行以下命令:

$ python cats_server.py -c [CONFIG_FILE]

接下来,准备另一个控制台,启动客户端程序,并连接到服务器。

$ python catsploit.py -s [SOCKET_PATH]

成功连接并初始化服务器后,会话将启动。

   _________  ___________       __      _ __
  / ____/   |/_  __/ ___/____  / /___  (_) /_
 / /   / /| | / /  \__ \/ __ \/ / __ \/ / __/
/ /___/ ___ |/ /  ___/ / /_/ / / /_/ / / /_
\____/_/  |_/_/  /____/ .___/_/\____/_/\__/
                     /_/

[*] Connecting to cats-server
[*] Done.
[*] Initializing server
[*] Done.
catsploit>

客户端可以执行各种命令。每个命令都可以使用 -h 选项来显示参数格式。

usage: [-h] {host,scenario,scan,plan,attack,post,reset,help,exit} ...

positional arguments:
  {host,scenario,scan,plan,attack,post,reset,help,exit}

options:
  -h, --help       show this help message and exit 

下面也列出了命令和选项供参考。

host list:
 show information about the hosts
 usage:  host list [-h] 
 options:
  -h, --help       show this help message and exit

host detail:
 show more information about one host
 usage:  host detail [-h] host_id 
 positional arguments:
  host_id          ID of the host for which you want to show information
 options:
  -h, --help       show this help message and exit

scenario list:
 show information about the scenarios
 usage:  scenario list [-h]
 options:
  -h, --help       show this help message and exit

scenario detail:
 show more information about one scenario
 usage:  scenario detail [-h] scenario_id
 positional arguments:
  scenario_id      ID of the scenario for which you want to show information
 options:
  -h, --help       show this help message and exit

scan:
 run network-scan and security-scan
 usage:  scan [-h] [--port PORT] target_host [target_host ...]
 positional arguments:
  target_host      IP address to be scanned
 options:
  -h, --help       show this help message and exit
  --port PORT      ports to be scanned

plan:
 planning attack scenarios
 usage:  plan [-h] src_host_id dst_host_id
 positional arguments:
  src_host_id      originating host
  dst_host_id      target host
 options:
  -h, --help       show this help message and exit

attack:
 execute attack scenario
 usage:  attack [-h] scenario_id
 positional arguments:
  scenario_id      ID of the scenario you want to execute

 options:
  -h, --help       show this help message and exit

post find-secret:
 find confidential information files that can be performed on the pwned host
 usage:  post find-secret [-h] host_id
 positional arguments:
  host_id          ID of the host for which you want to find confidential information
 options:
  -h, --help       show this help message and exit

reset:
 reset data on the server
 usage:  reset [-h] {system} ...
 positional arguments:
  {system}         reset system
options:
  -h, --help  show this help message and exit

exit:
  exit CATSploit
  usage:  exit [-h]
  options:
   -h, --help  show this help message and exit

示例

在此示例中,我们使用 CATSploit 扫描网络、规划攻击场景并执行攻击。

catsploit> scan 192.168.0.0/24
Network Scanning ... 100%
[*] Total 2 hosts were discovered.
Vulnerability Scanning ... 100%
[*] Total 14 vulnerabilities were discovered.
catsploit> host list
┏━━━━━━━━━━┳━━━━━━━━━━━━━━━━┳━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━┓
┃ hostID   ┃ IP             ┃ Hostname ┃ Platform                         ┃ Pwned ┃
┡━━━━━━━━━━╇━━━━━━━━━━━━━━━━╇━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━┩
│ attacker │ 0.0.0.0        │ kali     │ kali 2022.4                      │ True  │
│ h_exbiy6 │ 192.168.0.10   │          │ Linux 3.10 - 4.11                │ False │
│ h_nhqyfq │ 192.168.0.20   │          │ Microsoft Windows 7 SP1          │ False │
└──────────┴────────────────┴──────────┴──────────────────────────────────┴───────┘


catsploit> host detail h_exbiy6
┏━━━━━━━━━━┳━━━━━━━━━━━━━━┳━━━━━━━━━━┳━━━━━━━━━━━━━━┳━━━━━━━┓
┃ hostID   ┃ IP           ┃ Hostname ┃ Platform     ┃ Pwned ┃
┡━━━━━━━━━━╇━━━━━━━━━━━━━━╇━━━━━━━━━━╇━━━━━━━━━━━━━━╇━━━━━━━┩
│ h_exbiy6 │ 192.168.0.10 │ ubuntu   │ ubuntu 14.04 │ False │
└──────────┴──────────────┴──────────┴──────────────┴───────┘

[IP address]
┏━━━━━━━━━━━━━━┳━━━━━━━━━━┳━━━━━━┳━━━━━━━━━━━━┓
┃ ipv4         ┃ ipv4mask ┃ ipv6 ┃ ipv6prefix ┃
┡━━━━━━━━━━━━━━╇━━━━━━━━━━╇━━━━━━╇━━━━━━━━━━━━┩
│ 192.168.0.10 │          │      │            │
└──────────────┴──────────┴──────┴────────────┘

[Open ports]
┏━━━━━━━━━━━━━━┳━━━━━━━┳━━━━━━┳━━━━━━━━━━━━━┳━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ ip           ┃ proto ┃ port ┃ service     ┃ product      ┃ version                    ┃
┡━━━━━━━━━━━━━━╇━━━━━━━╇━━━━━━╇━━━━━━━━━━━━━╇━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩
│ 192.168.0.10 │ tcp   │ 21   │ ftp         │ ProFTPD      │ 1.3.5                      │
│ 192.168.0.10 │ tcp   │ 22   │ ssh         │ OpenSSH      │ 6.6.1p1 Ubuntu 2ubuntu2.10 │
│ 192.168.0.10 │ tcp   │ 80   │ http        │ Apache httpd │ 2.4.7                      │
│ 192.168.0.10 │ tcp   │ 445  │ netbios-ssn │ Samba smbd   │ 3.X - 4.X                  │
│ 192.168.0.10 │ tcp   │ 631  │ ipp         │ CUPS         │ 1.7                        │
└──────────────┴───────┴──────┴─────────────┴──────────────┴────────────────────────────┘
下载工具