Security Testing & Research Offensive Methodology
Advanced Penetration Testing Framework v3.0
For AUTHORIZED security testing ONLY! Unauthorized access is illegal. Get written permission before testing. User is responsible for all actions.
git clone https://github.com/Attazy/strom.git
cd strom
python3 -m venv venv
source venv/bin/activate # Linux/Mac | venv\Scripts\activate for Windows
pip install -r requirements.txt
python3 strom.pyDNS, WHOIS, Port Scanning (65+ ports), Subdomain Enumeration (244+ wordlist), SSL/TLS Analysis, WAF Detection, ASN/BGP Lookup, Certificate Transparency, OSINT Social Media (16+ platforms), Threat Intelligence (10+ sources), Cloud Detection
CMS detection, Security headers, Form testing, Directory bruteforce, API discovery
SQL Injection, RCE, XSS, LFI, SSRF, XXE, Template Injection, Deserialization
Auto-detect WAF, 20+ bypass techniques, Payload obfuscation
Privilege escalation, Persistence, Network pivoting, Keylogger, File exfiltration
Encoder/Decoder, Hash cracker, Password generator, Port scanner
HTML, PDF, Markdown, JSON reports with risk scoring and CVSS integration
100+ SQL, 50+ RCE, XSS, LFI, XXE, SSRF payloads
APK generation, Remote control, SMS/Call interception, Location tracking
python3 strom.py
# Select [1] Reconnaissance → Enter target → Choose features → Export resultsWorkflows:
- Quick (5 min): DNS → WHOIS → Port Scan
- Standard (15 min): Full Reconnaissance
- Deep (30+ min): Full Recon + Advanced Features
Edit config.yaml to enable API integrations:
api_keys:
shodan: "YOUR_KEY" # Get free at account.shodan.io
censys_id: "YOUR_ID" # Get free at censys.ioAll features work without API keys.
- 🚀 ADVANCED_UPGRADES.md - Complete upgrade guide
- ⚡ QUICK_REFERENCE_ADVANCED.md - Fast reference
- 📋 CHANGELOG.md - Version history
- 📱 README_ANDROID.md - Android module guide
MIT License - Commercial use, modification, and distribution allowed. See LICENSE for details.
🌩️ STROM - Security Testing Reconnaissance Offensive Module
Made with ❤️ by Attazy | Version 3.0.0 | January 2026
XXE, SSRF Copy-paste ready [9] 📱 Android Remote Access ⚡ NEW Remote control Android devicesQR code deployment • No Metasploit required! • Screen mirror • Camera • SMS • Location • File browser