BadHand
A Python network-testing framework, with about thirty tools behind one command line.
Context
BadHand is a testing framework I wrote in Python to keep the tools I use in my lab in one place, instead of jumping between dozens of different commands.
What I built
A command-line menu that brings together about thirty tools in five groups:
- Network: host discovery, port scanning and stress testing
- Web: XSS and SQL injection checks, header analysis, parameter discovery
- Reconnaissance: subdomains, DNS, WHOIS, CMS detection
- Authentication: credential testing over SSH and FTP, directory discovery
- SSL/TLS and utilities: certificate checks, hash identification, IP geolocation
Technical choices
All Python, with a focused library for each job: scapy for networking,
requests and BeautifulSoup for the web, paramiko for SSH, dnspython for
DNS. Every tool is a readable module: if something looks off, you open the file
and read what it does, instead of trusting a black box.
Status
Finished, the code is on GitHub. Mostly, it’s how I learned — by building them — how the tools that others just use actually work.
Intended use
Meant only for authorised testing and for learning: your own systems, isolated labs, or systems you have written permission to test. Using it without authorisation is illegal.