Skip to content

Releases: flavsjr/gyntoolkit

v2.3.0

Choose a tag to compare

@flavsjr flavsjr released this 08 Oct 03:20
eddf026

GynToolkit v2.3.0

Install / upgrade:

pip install -U gyntoolkit

Added

  • CVE enrichment — scan CVEs now carry CVSS base score/severity, EPSS
    exploitation probability and a CISA KEV flag (cached locally). Host risk is
    the highest severity found (KEV forces critical). New filters --min-cvss / --kev-only.
  • Email security recon (recon mailsec) — SPF, DKIM, DMARC, DNSSEC and CAA
    analyzer with a per-item verdict (ok/weak/missing), in both the interactive menu
    and the non-interactive CLI.
  • audit — orchestrates the recon modules (and, with --active --authorize,
    the port scan) over one target into a single consolidated report with an
    executive summary. Passive by default; stage selection via --only / --skip.

Changed

  • README.pt-BR.md brought to full parity with README.md.

Full changelog: https://github.com/flavsjr/gyntoolkit/blob/master/CHANGELOG.md

v2.2.0

Choose a tag to compare

@flavsjr flavsjr released this 08 Oct 02:36
4f566a1

GynToolkit v2.2.0

Install / upgrade:

pip install -U gyntoolkit

Added

  • Non-interactive, scriptable CLI: gyntoolkit <recon|scan|utils|brute|wordlist> ... prints JSON to stdout and can save a report via -o/--output + -f/--format. No subcommand still opens the interactive menu. Active attacks require --authorize.
  • Recon: DNS zone transfer (AXFR) against each authoritative NS; web content discovery (robots.txt/sitemap/security.txt + built-in path wordlist); full Shodan host lookup via api_keys.shodan (falls back to the key-free InternetDB hint). All reachable from both the menu and the CLI.
  • Brute: native CUPP-style wordlist generator (offline) — case/leet variants, years, common suffixes and term combinations.
  • Export: CSV and Markdown report formats (alongside JSON and HTML).
  • Config: scan.concurrency and api_keys.nvd.

Changed

  • Scan port probing is bounded by scan.concurrency (a full scan no longer spawns 65k tasks at once).
  • CVE lookup is version-aware: parses product + version from the banner and matches by CPE (virtualMatchString), with keyword fallback; NVD calls are rate-limited and deduplicated per banner.
  • Banner grabbing reads a service greeting first and sends a valid Host header.

Fixed

  • HTTP Basic brute force now treats only 2xx as success (was any status except 401/403, so 404/5xx were false positives).
  • Authorization confirmation word is localized (AUTHORIZE/AUTORIZO).
  • http_fingerprint no longer prints InsecureRequestWarning to the UI.

Full changelog: https://github.com/flavsjr/gyntoolkit/blob/master/CHANGELOG.md

v2.1.1

Choose a tag to compare

@flavsjr flavsjr released this 08 Oct 00:43
587964a

Primeira publicação no PyPI. Instale com: pip install gyntoolkit

Inclui: relatório HTML localizado (en/pt), tokens de scan neutros de idioma, CUPP desvendorizado, licença SPDX, workflow de publish via Trusted Publishing e docs com pip install como método principal.

v2.1.0

Choose a tag to compare

@flavsjr flavsjr released this 07 Oct 20:42
5542a64

Added

  • i18n: full interactive UI in English or Portuguese (gyntoolkit/i18n.py). Language resolves ui.lang config → GYNTOOLKIT_LANG env → OS locale → English default. Menus, prompts, spinners, result labels, table headers, error messages translated across cli/recon/scan/brute/utils. Data values and JSON export keys stay stable; test enforces en/pt key parity.

Fixed

  • Scan service detection: empty banners map to the "unknown" service (skips a spurious NVD lookup) instead of parsing a localized placeholder word.

Full changelog: v2.0.0...v2.1.0