An advanced toolkit for scanning, bypassing, and predicting system vulnerabilities using automation and machine learning.
Python • Nmap • Bettercap • ARP-Scan • SQLMap • Nikto • Metasploit • XGBoost • Scikit-learn • Pandas • Tkinter
- 🔍 Overview
- 🚀 Getting Started
- ✅ Prerequisites
- 🛠️ Installation
▶️ Usage- 📊 Output Format
- 🧠 Machine Learning Pipeline
- 🧪 Testing
- 📄 License
- 🔙 Return
Pentesting is a GUI-based cybersecurity suite that automates the process of network reconnaissance, vulnerability scanning, firewall evasion, and machine learning-based vulnerability prediction. It enables ethical hackers and security teams to streamline offensive security assessments with a unified toolkit.
- 🔎 Network Reconnaissance using Nmap, Bettercap, and ARP-scan.
- 🔥 Firewall Bypass techniques for stealth scanning and evasion.
- 🧰 Modular Vulnerability Scanning via SQLMap, Nikto, and Metasploit.
- 🧠 Machine Learning Predictions on scan results using trained XGBoost & Isolation Forest models.
- 📁 Automated CSV Dataset Generation from scan results for analytics or training.
Clone the repository:
git clone https://github.com/yogambar/pentesting
cd pentestingEnsure you have the following installed:
- Python 3.8+
- All tools in system PATH: Nmap, SQLMap, Bettercap, Metasploit, ARP-scan
virtualenvor similar Python environment manager
- Create and activate a virtual environment:
python3 -m venv myenv
source myenv/bin/activate- Install all dependencies:
pip install -r setup/requirements.txtLaunch the GUI application:
python3 gui/gui.py- Scan Network → Discover live hosts on the network.
- Select Target IP → Choose any discovered IP for analysis.
- Bypass Firewall → Use stealth scan modes to evade defenses.
- Run All Scans → Execute Nmap, SQLMap, Nikto, and Metasploit on target.
- Run Single Tool → Choose a specific scanner manually.
- Save Scan Data → Aggregate and convert all JSON outputs into a structured CSV.
- Train Model → Train ML models using collected data.
- Predict Vulnerability → Predict target vulnerability using trained models.
Each scan outputs to:
data/scan_outputs/
├── nmap.json
├── sqlmap.json
├── nikto.json
├── metasploit.json
These are merged into dataset.csv for use in training or inference.
- Feature extraction via
ml/feature_extractor.py - Model training via
model_trainer.py, producing:xgboost_model.joblibisolation_forest_model.jobliblabel_encoders.joblibscaler.joblib
- Prediction via
predictor.pyfor new IPs
Custom test scripts are located in tests/ (if applicable). Basic testing can be performed by running:
pytest tests/This project is licensed under the MIT License. See LICENSE for more information.