Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
hawkopsec — One-tap Linux OPSEC hardening & anonymity toolkit | Kitploit
工具/GitHubGitHub/emrekybs/hawkopsec
Defensive ToolsConfiguration AuditingNetwork SecurityPrivacyIncident Response
GitHubemrekybs/hawkopsec

hawkopsec

One-tap Linux OPSEC hardening & anonymity toolkit

查看仓库
26311天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。

HawkOpsec

HawkOpsec

One-tap Linux OPSEC hardening & anonymity toolkit

platform ui license


HawkOpsec turns a pile of manual privacy commands into security modes you apply with one tap. Pick a mode — the tool starts Tor, configures DNS, randomizes your identity and hardens the kernel for you. Hit RESET and every change is rolled back from snapshots to your original state.

The GUI never runs as root; privileged actions go through a small helper via polkit/pkexec. Every change is snapshotted before it is applied, so nothing is one-way.

Dashboard

Security modes

Each mode resets to baseline first, then applies a full profile — switching is always clean.

Architectural Structure

Architectural Structure

Features

  • Network — Tor transparent proxy (all TCP + DNS via Tor, kill-switch, IPv6 block, stream isolation), DNS-over-TLS (Quad9 / Cloudflare / Mullvad), default-deny firewall, IPv6 disable.
  • Identity — per-interface MAC randomization, persistent MAC (NetworkManager), random hostname, machine-id spoofing, UTC timezone.
  • Hardening — kernel/sysctl hardening, disable crash reporting/coredumps, journald to RAM, disable Bluetooth, disable swap, USB lockdown (BadUSB), RAM wipe on shutdown.
  • Traces — clean shell history / recent files / thumbnails / trash, vacuum journald & coredumps, strip EXIF metadata (mat2/exiftool), secure-delete (shred).
  • Extras — one-click anonymous browser (Tor Browser / Firejail), Firefox hardening (WebRTC off, resistFingerprinting), live exit-IP check, Activity log of every change, RESET and PANIC.
  • Bilingual UI — switch English / Türkçe from the top-right; choice is remembered.

Install

Dependencies

root@kitploit:~
# Arch
sudo pacman -S --needed python-pyqt6 tor nftables polkit iproute2 rfkill systemd-resolvconf
# Debian / Ubuntu / Kali / Mint
sudo apt install -y python3-pyqt6 tor nftables policykit-1 iproute2 rfkill systemd-resolved
# optional extras: mat2 (or exiftool), secure-delete, firejail, torbrowser-launcher

Run from source (quickest)

root@kitploit:~
python3 run.py                 # just run it
sudo ./packaging/install.sh    # or install: menu entry + launcher + polkit + helper

Compile to a standalone binary (Nuitka)

root@kitploit:~
sudo apt install -y patchelf                 # or: sudo pacman -S patchelf
./packaging/build.sh                         # -> build/run.dist/hawkopsec
sudo ./packaging/install-compiled.sh

Then launch HawkOpsec from your application menu, or run hawkopsec.

Uninstall

Click UNINSTALL in the app (or HawkOpsec Uninstall in the menu), or:

root@kitploit:~
sudo ./packaging/uninstall.sh

It reverts every system change, removes all files and menu icons, and refreshes the desktop cache.

Security note

HawkOpsec hardens the network and system layers. It does not make a normal browser fingerprint-resistant — for real anonymous browsing use the built-in Tor Browser launcher, avoid logging into personal accounts while anonymous, and remember that browser fingerprinting, WebRTC and behavioural patterns are out of scope for a system tool. You are hardening your own machine.

License

MIT — see LICENSE.

下载工具
ModeWhat it does
BASELINEEverything off. Reverts all changes to the original state (same as RESET).
SECUREKernel hardening · default-deny firewall · DNS-over-TLS · IPv6 off · no crash reports · logs in RAM. No Tor — daily-driver safe.
PUBLICSECURE + MAC randomization (persistent via NetworkManager) + Bluetooth off. For untrusted / public wifi.
HARDENEDPUBLIC + random machine-id & hostname + swap off + USB lockdown. Strong anti-fingerprinting, no Tor.
GHOSTHARDENED + UTC timezone + system-wide Tor routing with a leak kill-switch. Full anonymity.
PARANOIDGHOST + RAM wipe on shutdown (cold-boot mitigation). Maximum protection.