Striker – Recon & Vulnerability Scanning Suite

Striker 2.0 is still in prototype phase, This tool will allow user to run some reconnaissance and information gathering coupled with vulnerability scanning against the target. prototype phase means it’s not intended to be used by regular users. It has been made public for contributions to make the development faster.

Striker - Recon & Vulnerability Scanning Suite
Striker – Recon & Vulnerability Scanning Suite

The tool have a workflow that include several phases to get information from the targeted system by penetration tester. The workflow have the following phases:

Phase 1: Attack Surface Discovery

This phase includes finding subdomains of the user specified domain, filtering alive hosts as well scanning of 1000 most common TCP ports.

Phase 2: Sweeping

Mass scanning of misconfigured HTTP response headers, croassdomain.xml as well as checks for some sensitive files is done in this phase.

Phase 3: Agressive Information Gathering

This phase is dedicated to data gathering by crawling the subdomains. The gathered data is used to find outdated JS libraries, detect CMS and technologies in use.
HTML forms that are tested in later phases for vulnerability detection are also collected during this crawling.

which means it’s not intended to be used by regular users. It has been made public for contrbutions to make the development faster.

Phase number 4 is under development and it comes to develop vulnerability scanning module.

You can read more and download this tool over here: https://github.com/s0md3v/Striker

Share