Skip to content

Repository files navigation

🛡️ PENTESTING – ML-Aided Cyber Vulnerability Scanner

An advanced toolkit for scanning, bypassing, and predicting system vulnerabilities using automation and machine learning.

Last Commit Python


🛠️ Built With

Python • Nmap • Bettercap • ARP-Scan • SQLMap • Nikto • Metasploit • XGBoost • Scikit-learn • Pandas • Tkinter


📑 Table of Contents


🔍 Overview

Pentesting is a GUI-based cybersecurity suite that automates the process of network reconnaissance, vulnerability scanning, firewall evasion, and machine learning-based vulnerability prediction. It enables ethical hackers and security teams to streamline offensive security assessments with a unified toolkit.

✨ Key Features:

  • 🔎 Network Reconnaissance using Nmap, Bettercap, and ARP-scan.
  • 🔥 Firewall Bypass techniques for stealth scanning and evasion.
  • 🧰 Modular Vulnerability Scanning via SQLMap, Nikto, and Metasploit.
  • 🧠 Machine Learning Predictions on scan results using trained XGBoost & Isolation Forest models.
  • 📁 Automated CSV Dataset Generation from scan results for analytics or training.

🚀 Getting Started

Clone the repository:

git clone https://github.com/yogambar/pentesting
cd pentesting

✅ Prerequisites

Ensure you have the following installed:

  • Python 3.8+
  • All tools in system PATH: Nmap, SQLMap, Bettercap, Metasploit, ARP-scan
  • virtualenv or similar Python environment manager

🛠️ Installation

  1. Create and activate a virtual environment:
python3 -m venv myenv
source myenv/bin/activate
  1. Install all dependencies:
pip install -r setup/requirements.txt

▶️ Usage

Launch the GUI application:

python3 gui/gui.py

GUI Features:

  • Scan Network → Discover live hosts on the network.
  • Select Target IP → Choose any discovered IP for analysis.
  • Bypass Firewall → Use stealth scan modes to evade defenses.
  • Run All Scans → Execute Nmap, SQLMap, Nikto, and Metasploit on target.
  • Run Single Tool → Choose a specific scanner manually.
  • Save Scan Data → Aggregate and convert all JSON outputs into a structured CSV.
  • Train Model → Train ML models using collected data.
  • Predict Vulnerability → Predict target vulnerability using trained models.

📊 Output Format

Each scan outputs to:

data/scan_outputs/
├── nmap.json
├── sqlmap.json
├── nikto.json
├── metasploit.json

These are merged into dataset.csv for use in training or inference.


🧠 Machine Learning Pipeline

  • Feature extraction via ml/feature_extractor.py
  • Model training via model_trainer.py, producing:
    • xgboost_model.joblib
    • isolation_forest_model.joblib
    • label_encoders.joblib
    • scaler.joblib
  • Prediction via predictor.py for new IPs

🧪 Testing

Custom test scripts are located in tests/ (if applicable). Basic testing can be performed by running:

pytest tests/

📄 License

This project is licensed under the MIT License. See LICENSE for more information.


🔙 Return

🔼 Back to Top

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages