Repository navigation
Releases: flavsjr/gyntoolkit
Releases · flavsjr/gyntoolkit
Release list
v2.3.0
GynToolkit v2.3.0
Install / upgrade:
pip install -U gyntoolkitAdded
- CVE enrichment — scan CVEs now carry CVSS base score/severity, EPSS
exploitation probability and a CISA KEV flag (cached locally). Host risk is
the highest severity found (KEV forces critical). New filters--min-cvss/--kev-only. - Email security recon (
recon mailsec) — SPF, DKIM, DMARC, DNSSEC and CAA
analyzer with a per-item verdict (ok/weak/missing), in both the interactive menu
and the non-interactive CLI. audit— orchestrates the recon modules (and, with--active --authorize,
the port scan) over one target into a single consolidated report with an
executive summary. Passive by default; stage selection via--only/--skip.
Changed
README.pt-BR.mdbrought to full parity withREADME.md.
Full changelog: https://github.com/flavsjr/gyntoolkit/blob/master/CHANGELOG.md
v2.2.0
GynToolkit v2.2.0
Install / upgrade:
pip install -U gyntoolkitAdded
- Non-interactive, scriptable CLI:
gyntoolkit <recon|scan|utils|brute|wordlist> ...prints JSON to stdout and can save a report via-o/--output+-f/--format. No subcommand still opens the interactive menu. Active attacks require--authorize. - Recon: DNS zone transfer (AXFR) against each authoritative NS; web content discovery (
robots.txt/sitemap/security.txt + built-in path wordlist); full Shodan host lookup viaapi_keys.shodan(falls back to the key-free InternetDB hint). All reachable from both the menu and the CLI. - Brute: native CUPP-style wordlist generator (offline) — case/leet variants, years, common suffixes and term combinations.
- Export: CSV and Markdown report formats (alongside JSON and HTML).
- Config:
scan.concurrencyandapi_keys.nvd.
Changed
- Scan port probing is bounded by
scan.concurrency(a full scan no longer spawns 65k tasks at once). - CVE lookup is version-aware: parses product + version from the banner and matches by CPE (
virtualMatchString), with keyword fallback; NVD calls are rate-limited and deduplicated per banner. - Banner grabbing reads a service greeting first and sends a valid
Hostheader.
Fixed
- HTTP Basic brute force now treats only
2xxas success (was any status except 401/403, so 404/5xx were false positives). - Authorization confirmation word is localized (
AUTHORIZE/AUTORIZO). http_fingerprintno longer printsInsecureRequestWarningto the UI.
Full changelog: https://github.com/flavsjr/gyntoolkit/blob/master/CHANGELOG.md
v2.1.1
Primeira publicação no PyPI. Instale com: pip install gyntoolkit
Inclui: relatório HTML localizado (en/pt), tokens de scan neutros de idioma, CUPP desvendorizado, licença SPDX, workflow de publish via Trusted Publishing e docs com pip install como método principal.
v2.1.0
Added
- i18n: full interactive UI in English or Portuguese (
gyntoolkit/i18n.py). Language resolvesui.langconfig →GYNTOOLKIT_LANGenv → OS locale → English default. Menus, prompts, spinners, result labels, table headers, error messages translated across cli/recon/scan/brute/utils. Data values and JSON export keys stay stable; test enforces en/pt key parity.
Fixed
- Scan service detection: empty banners map to the "unknown" service (skips a spurious NVD lookup) instead of parsing a localized placeholder word.
Full changelog: v2.0.0...v2.1.0