Tools · Arsenal

Every pentest tool Lupus runs on Android

Lupus curates a full penetration-testing arsenal — from the Metasploit Framework to modern recon, web and Active Directory tooling, plus media and IoT devices like Chromecasts, smart TVs, IP cameras and routers — with an autonomous AI agent that drives them. The core set is bundled in the app; the rest installs on first launch from Lupus's signed repository. For authorized security testing only.

Autonomous AI · flagship

Lupus AI Agent

An autonomous pentest agent that plans and executes the engagement end to end — reconnaissance, scanning, exploitation, post-exploitation and reporting — orchestrating every tool below and writing its findings straight into the workspace database. You connect your own Claude (Anthropic) access; it runs in both local and remote mode. For authorized engagements only.

Free included on every device Pro unlocked with Lupus Pro Root needs a rooted device

Exploitation & payloads

  • Metasploit FrameworkFree

    The full exploit, auxiliary and post-exploitation framework with Meterpreter sessions.

  • msfvenomPro

    Standalone payload, executable and shellcode generation.

  • searchsploit / Exploit-DBFree

    Offline exploit PoC search against the Exploit-DB archive.

Network scanning

  • NmapFree

    Port, service and OS discovery; results flow straight into the workspace database.

  • naabuFree

    Fast SYN/connect port scanner for wide sweeps.

  • snmpwalk (net-snmp)Free

    SNMP enumeration of users, processes and interfaces via default communities.

  • NcatFree

    Netcat for connect, listen and relay.

Vulnerability scanning

  • NucleiPro

    Thousands of community templates for CVEs, misconfigurations and exposures.

  • CVE lookup (vulners / NVD)Free

    Maps discovered service versions to known CVEs.

  • wafw00fFree

    Fingerprints the Web Application Firewall in front of a target.

Web recon & fuzzing

  • WPScanPro

    WordPress security scanner: enumerate plugins/themes/users and known vulnerabilities.

  • httpxFree

    Fast HTTP probing and fingerprinting.

  • katanaFree

    Web crawler that maps endpoints and attack surface.

  • ffufFree

    High-speed web fuzzer.

  • feroxbusterFree

    Recursive content and directory discovery.

  • gobusterFree

    Directory, DNS and vhost brute-forcing.

  • sqlmapFree

    Automated SQL injection detection and exploitation.

DNS & OSINT

  • subfinderFree

    Passive subdomain enumeration.

  • dnsxFree

    Fast, multipurpose DNS toolkit.

  • dnsreconFree

    DNS enumeration and zone-transfer checks.

Active Directory, SMB & credentials

  • ImpacketFree

    The AD/SMB attack suite — secretsdump, psexec, wmiexec, GetNPUsers and more.

  • NetExec (nxc)Free

    Network execution across SMB, LDAP and WinRM — the CrackMapExec successor.

  • ResponderRoot

    LLMNR/NBT-NS/mDNS poisoning and NTLM credential capture.

  • mitm6Root

    IPv6 DNS takeover to drive NTLM relay together with Impacket ntlmrelayx.

  • Evil-WinRMFree

    Interactive WinRM shell with pass-the-hash for Windows post-exploitation.

  • KerbruteFree

    Kerberos pre-auth username enumeration and password spraying.

  • HydraFree

    Fast network logon brute-forcer across HTTP forms, SSH, FTP, SMB and more.

  • smbclientFree

    Browse and transfer files over SMB shares.

Pivoting & tunnelling

  • ChiselFree

    Fast TCP/UDP tunnel with SOCKS over HTTP — turn the phone into a network pivot.

  • ligolo-ngFree

    TUN-based tunnelling for transparent access to an internal network (64-bit).

  • ProxyChainsFree

    Route any tool (nmap, sqlmap, nxc) through a SOCKS proxy or pivot.

  • OpenSSH & sshpassFree

    SSH client for port-forwarding, local/remote/dynamic tunnels and Linux post-ex.

  • socatFree

    Bidirectional relays and TTY shell upgrades.

Traffic & packet analysis

  • tsharkRoot

    Wireshark's CLI capture and dissection engine.

  • termsharkRoot

    A terminal UI for browsing tshark captures.

  • jqFree

    Slice and query JSON output from tools and APIs on the command line.

Media, IoT & cameras

  • go-chromecastFree

    Discover and control Chromecast / Google Cast devices — cast media, launch apps and pull the Wi-Fi credentials off the receiver.

  • CameradarFree

    Find RTSP streams on IP cameras and brute-force their routes and default credentials; ONVIF model-aware.

  • python-onvifFree

    ONVIF camera management: device info, users, stream URIs, snapshots and PTZ control.

  • upnpc (miniupnpc)Free

    Enumerate and abuse UPnP/IGD gateways — list existing port mappings and open new inbound ones.

  • RouterSploitFree

    Exploitation framework for routers, cameras and embedded IoT — exploits, credential checks and scanners.

  • PRETFree

    Printer exploitation over PostScript/PJL/PCL: filesystem access, job capture and NVRAM.

  • pyatvFree

    AirPlay and Apple TV discovery and control.

  • evil-ssdpFree

    Rogue SSDP/UPnP responder for LAN device phishing and credential capture.

  • adb (android-tools)Free

    Reach Android and Fire TV boxes over the network with adb connect for a shell when debugging is left open.