ctf-tools

Snapshot 2026-08-03 23:56:39 UTC · version 1

published
M
MDRSS Source Library Github collector716 cards · 4.7/10 MDRSS

This is a collection of setup scripts to create an install of various security research tools. Of course, this isn't a hard problem, but it's really nice to have them in one place that's easily deployable to new machines and so forth. The install-scripts for these tools are check

MARKDOWN SNAPSHOT

Loading…

Direct .mdRaw + metadata0 commentsMDRSS 4.6/10
INDEXABLE MARKDOWN SNAPSHOT

Research document

Open canonical .md

ctf-tools

This is a collection of setup scripts to create an install of various security research tools. Of course, this isn't a hard problem, but it's really nice to have them in one place that's easily deployable to new machines and so forth. The install-scripts for these tools are checked every once in a while, so things should hopefully have a decent chance of working!

Installers for the following tools are included:

Category Tool Description
binary angr Next-generation binary analysis engine from Shellphish.
binary angr-management A GUI reverse engineering and decompilation tool.
binary beef Browser exploitation framework.
binary crosstool Cross-compilers and cross-architecture tools.
binary cross2 A set of cross-compilation tools from a Japanese book on C.
binary decomp2dbg A plugin to introduce interactive symbols into your debugger from your decompiler.
binary elfkickers A set of utilities for working with ELF files.
binary elfparser Multiplatform CLI and GUI tool to show information about ELF files.
binary evilize Tool to create MD5 colliding binaries
binary gdb Up-to-date gdb with python2 bindings.
binary gef Enhanced environment for gdb.
binary ghidra Open-source reverse engineering and decompilation tool.
binary honggfuzz A general-purpose, easy-to-use fuzzer with interesting analysis options.
binary ida Decompilation and reversing tool (requires you to download it to ~/Downloads on your own!).
binary manticore Manticore is a prototyping tool for dynamic binary analysis, with support for symbolic execution, taint analysis, and binary instrumentation.
binary one_gadget Magic gadget search for libc.
binary preeny A collection of helpful preloads (compiled for many architectures!).
binary pwninit Script to automate starting pwning challenges.
binary pwndbg Enhanced environment for gdb. Especially for pwning.
binary pwnsh Useful shell scripts for assembly, exploitation, etc.
binary pwntools Useful CTF utilities.
binary qemu Latest version of qemu!
binary qiling A dynamic binary instrumentation framework.
binary qira Parallel, timeless debugger.
binary rappel A linux-based assembly REPL.
binary ropper Another gadget finder.
binary rp++ Another gadget finder.
binary seccomp-tools Provides powerful tools for seccomp analysis
binary shellnoob Shellcode writing helper.
binary taintgrind A valgrind taint analysis tool.
binary valgrind A Dynamic Binary Instrumentation framework with some built-in tools.
binary villoc Visualization of heap operations.
binary xrop Gadget finder.
forensics firmware-mod-kit Tools for firmware packing/unpacking.
forensics pdf-parser Tool for digging in PDF files
forensics peepdf Powerful Python tool to analyze PDF documents.
forensics scrdec18 A decoder for encoded Windows Scripts.
forensics volatility Analyzer for system memory dumps (classic python2 version; requires python2 tool).
forensics volatility3 Analyzer for system memory dumps (latest version).
crypto codext Python codecs extension featuring CLI tools for encoding/decoding anything including AI-based guessing mode.
crypto cribdrag Interactive crib dragging tool (for crypto).
crypto fastcoll An md5sum collision generator.
crypto foresight A tool for predicting the output of random number generators. To run, launch "foresee".
crypto featherduster An automated, modular cryptanalysis tool. WARNING: needs python2 (which can be installed with ctf-tools).
crypto galois A fast galois field arithmetic library/toolkit.
crypto hashpump-partialhash Hashpump, supporting partially-unknown hashes.
crypto hash-identifier Simple hash algorithm identifier.
crypto libc-database Build a database of libc offsets to simplify exploitation.
crypto msieve Msieve is a C library implementing a suite of algorithms to factor large integers.
crypto nonce-disrespect Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS.
crypto pemcrack SSL PEM file cracker.
crypto pkcrack PkZip encryption cracker.
crypto reveng CRC finder.
crypto rsactftool RSA attack tool.
crypto ssh_decoder A tool for decoding ssh traffic. You will need ruby1.8 from https://launchpad.net/~brightbox/+archive/ubuntu/ruby-ng to run this. Run with ssh_decoder --help for help, as running it with no arguments causes it to crash.
crypto sslsplit SSL/TLS MITM.
crypto xortool XOR analysis tool.
crypto yafu Automated integer factorization.
web burpsuite Web proxy to do naughty web stuff.
web commix Command injection and exploitation tool.
web mitmproxy CLI Web proxy and python library.
web subbrute A DNS meta-query spider that enumerates DNS records, and subdomains.
web webgrep grep for Web pages, with JS deobfuscation, CSS unminifying and OCR on images.
stego steganabara Another image stenography solver.
stego stegano-tools A collection of text and image steganography tools (incl LSB, PVD, PIT).
stego stegdetect Stenography detection/breaking tool.
stego stegsolve Image stenography solver.
stego stegosaurus A steganography tool for embedding arbitrary payloads in Python bytecode (pyc or pyo) files.
stego zsteg detect stegano-hidden data in PNG & BMP.
misc jdgui Java decompiler.
misc python2 For when you really need it...
misc social-analyzer Social media reconnaissance tool...
misc veles Binary data analysis and visualization tool.
misc xspy Tiny tool to spy on X sessions.

There are also some installers for non-CTF stuff to break the monotony!

Category Tool Description
game df Dwarf Fortress! Something to help you relax after a CTF!
web tor-browser Useful when you need to hit a web challenge from different IPs.

Usage

To use, do:

# set up the path
/path/to/ctf-tools/bin/manage-tools setup
source ~/.bashrc

# list the available tools
manage-tools list

# install gdb, allowing it to try to sudo install dependencies
manage-tools -s install gdb

# install pwntools, but don't let it sudo install dependencies
manage-tools install pwntools

# install qemu, but use "nice" to avoid degrading performance during compilation
manage-tools -n install qemu

# uninstall gdb
manage-tools uninstall gdb

# uninstall all tools
manage-tools uninstall all

# search for a tool
manage-tools search preload

Where possible, the tools keep the installs very self-contained (i.e., in to tool/ directory), and most uninstalls are just calls to git clean (NOTE, this is NOT careful; everything under the tool directory, including whatever you were working on, is blown away during an uninstall).

Python and Ruby tools are installed in a tool-specific virtual environment. If you want to add other packages to this environment, look under the ctf-tools/TOOL/pipx or ctf-tools/TOOL/gems directories.

Help!

Something not working? I didn't write (almost) any of these tools, but hit up the discord if you're desperate. Maybe some kind soul will help!

Dockerized Tools

Prebuilt Tool Containers

You can get most of these tools in prebuilt containers from https://hub.docker.com/r/ctftools. For example:

$ echo hi | docker run -i ctftools/taintgrind taintgrind --taint-stdin=yes /bin/cat
/home/ctf/tools/taintgrind/valgrind-3.21.0/build/bin/valgrind --tool=taintgrind --taint-stdin=yes /bin/cat
==8== Taintgrind, the taint analysis tool
==8== Copyright (C) 2010-2018, and GNU GPL'd, by Wei Ming Khoo.
==8== Using Valgrind-3.21.0 and LibVEX; rerun with -h for copyright info
==8== Command: /bin/cat
==8==
0xFFFFFFFF: _syscall_read | Read:3 | 0x0 | 4a5a000_unknownobj
hi
==8== 

Building Your Own

You can build a docker image with:

git clone https://github.com/zardus/ctf-tools
cd ctf-tools
docker build -t ctf-tools --build-arg PREINSTALLED=some-tool .

And run it with:

docker run -it ctf-tools

The built image will have ctf-tools cloned and ready to go and your tool installed.

Kali Linux

Kali Linux (Sana and Rolling), due to manually setting certain libraries to not use the latest version available (sometimes being out of date by years) causes some tools to not install at all, or fail in strange ways. Overriding these libraries breaks other tools included in Kali so your only solution is to either live with some of Kali's tools being broken, use docker, or running another distribution separately such as Ubuntu.

Adding Tools

To add a tool (say, named toolname), do the following:

  1. Create a toolname directory.
  2. Create an install script.
  3. Add it to the README.
  4. (optional) if special uninstall steps are required, create an uninstall script.

Install Scripts

The install script will be run with $PWD being toolname. It should install the tool into this directory, in as contained of a manner as possible. Ideally, full uninstallation should be possible with a git clean.

The install script should create a bin directory and put its executables there. These executables will be automatically linked into the main bin directory for the repo. They could be launched from any directory, so don't make assumptions about the location of $0!

License

The individual tools are all licensed under their own licenses. As for ctf-tools itself, it is licensed under BSD 2-Clause License. If you find it useful, star it on GitHub (https://github.com/zardus/ctf-tools).

Good luck!

See Also

There's a curated list of CTF tools, but without installers, here: https://github.com/apsdehal/aWEsoMe-cTf.

There's a Vagrant config with a lot of the bigger frameworks here: https://github.com/thebarbershopper/epictreasure.

Useful CTF tools in apt repos

As tools get officially packaged, we switch to just suggesting that you apt install them!

Category Source Tool Description
binary apt aflplusplus State-of-the-art fuzzer.
binary apt checksec Check binary hardening settings.
binary apt radare2 Some crazy thing crowell likes.
binary apt rr Record and Replay Debugging Framework
binary apt wcc The Witchcraft Compiler Collection is a collection of compilation tools to perform binary black magic on the GNU/Linux and other POSIX platforms.
forensics apt binwalk Firmware (and arbitrary file) analysis tool.
forensics apt foremost File carver.
forensics apt dislocker Tool for reading Bitlocker encrypted partitions.
forensics apt origami-pdf PDF manipulator.
forensics apt testdisk Testdisk and photorec for file recovery.
web apt dirb Web path scanner.
web apt dirsearch Web path scanner.
web apt sqlmap SQL injection automation engine.
stego apt pngtools PNG's analysis tool.
stego apt sonic-visualizer Audio file visualization.
networking apt dsniff Grabs passwords and other data from pcaps/network streams.
networking apt bettercap Network shenanigans swiss army knife.
misc apt z3 Theorem prover from Microsoft Research.
osint apt sherlock Tools for Hunt down social media accounts by username across 400+ social networks .

Useful CTF tools in docker images

Previously, this repository included some scripts that were wrappers around docker pull. We trust that you can do that yourself :-)

Category Source Tool Description
binary docker panda Platform for Architecture-Neutral Dynamic Analysis.
stego Docker stego-toolkit A docker image with dozens of steg tools.

Useful CTF Libraries

Previously, this repository included library installers. Because of how bespoke library install preferences are (e.g., unlike a tool, it's not clear if per-library venvs are a desired thing), we've stopped shipping them, and link them here for posterity.

Category Source Tool Description
binary Library capstone Multi-architecture disassembly framework.
binary Library keystone Lightweight multi-architecture assembler framework.
binary Library lief Library to Instrument Executable Formats.
binary Library miasm Reverse engineering framework in Python.
binary Library unicorn Multi-architecture CPU emulator framework.
binary Library virtualsocket A nice library to interact with binaries.
crypto Library cryptanalib3 The surviving core of featherduster cryptanalysis tool, updated for python3.
crypto Library python-paddingoracle Padding oracle attack automation.
MARKDOWN METRICS
1912words
22headings
182links
4code blocks
MDRSS ASSESSMENT
Evidence46/100high confidence
Why MDRSS assigned this score
  • Production catalog audit 2026-08-04
  • Taxonomy classified from title, annotation, source and Markdown signals
  • Agent usefulness evaluated from structure, procedures, examples, evidence and retrieval value
Evidence (1)

Discussion 0

Sign in to join the discussion.