Ubuntu-only, bug-bounty-only one-shot installer for a hunt box.
Buy a server, run one command, and the whole environment is there — tools, wordlists, payload packs, nuclei templates, Burp extensions and reference material.
git clone https://github.com/mohammadsec/Hunt-Setup.git
cd Hunt-Setup
chmod +x setup.sh
sudo ./setup.shThen open a new shell (or source ~/.hunt-setup.env) and check:
nuclei -version; subfinder -version; httpx -version
ls ~/hunt-data # wordlists, payloads, nuclei templates
cat ~/Hunt-Setup-install-report.tsv # per-tool OK / PARTIAL / FAILEDA rework of mohammadsec/Hunt-Setup
(fork of jamaledim/Hunt-Setup) with
three changes:
- Ubuntu only. The CentOS / Fedora branches are gone. One code path.
- Scoped to hunting. Only starred repos that are bug-bounty / pentest / red-team tooling are included. Trading bots, AI gateways, fonts, VPN clients, coding tutorials, generic libraries and everything else you happen to have starred are not in this repository at all — not installed, not listed.
- Data-driven.
setup.shis generic installer logic;manifests/*.tsvsays what to install. Adding or dropping a tool is a one-line edit.
1692 starred repositories were evaluated. 1531 kept, 164 dropped as out of scope. (Plus 12 classic tools carried over from upstream that are not starred.)
| Manifest | Count | Where it lands |
|---|---|---|
manifests/tools.tsv |
1085 | native installs (~/go/bin, ~/.local/bin, …) + source clones in ~/tools |
manifests/data.tsv |
138 | ~/hunt-data — wordlists, payload packs, nuclei templates, scope dumps |
manifests/reference.tsv |
71 | ~/hunt-reference — checklists, disclosed reports, methodology |
manifests/manual.tsv |
237 | ~/tools/manual — Burp extensions, mobile tools, GUI clients (cloned, never executed) |
manifests/apt.txt |
98 lines | base apt packages |
Everything above installs by default. Wordlists are included in the default run — you do not need a flag for them.
| Flag | Effect |
|---|---|
| (none) | everything: tools + data + reference + manual + apt + toolchain |
--dry-run, -n |
print the plan, touch nothing |
--only <category> |
install exactly one of core data reference manual |
--no-data / --no-reference / --no-manual / --no-core |
opt out of a category |
--method <m> |
restrict to one install method: go pip npm cargo gem make git |
--jobs <n> |
install <n> tools concurrently (default 1; npm/gem always run serially) |
--no-apt |
skip the apt phase (tools only) |
--no-warp / --no-browser |
skip Cloudflare WARP / the Google Chrome .deb |
--installers |
also run a cloned repo's install.sh (off by default — most are interactive) |
-v |
show every command and every per-tool line |
Flags combine: sudo ./setup.sh --only data --jobs 8 --dry-run.
Every method has a fallback, so a wrong guess still ends with the source on disk rather than nothing:
| Method | Count | Primary attempt | Fallback |
|---|---|---|---|
go |
338 | go install <path>@latest, trying base → cmd/<name> → v2/v3 layouts |
shallow clone |
pip |
405 | pipx install git+<repo> (isolated venv, entry points on PATH) |
clone + requirements.txt into a per-tool .venv |
npm |
82 | npm install -g github:<repo> |
clone |
cargo |
21 | cargo install --git <repo> |
clone |
make |
17 | clone + make + sudo make install |
clone only |
gem |
17 | clone + bundle install / gem build |
clone only |
git |
651 | shallow clone + symlink executables into ~/tools/bin |
— |
Per-tool outcomes:
- OK — the native install worked
- PARTIAL — native install failed but the source is cloned and usable
- FAILED — both attempts failed (these are the ones worth looking at)
One failure never aborts the run: setup.sh has no set -e and traps every tool
individually, then prints a summary and writes ~/Hunt-Setup-install-report.tsv.
| Path | Contents |
|---|---|
$HOME/tools/<owner>_<repo> |
source clones (git / make / fallback installs) |
$HOME/tools/bin |
symlinks to executables found in those clones |
$HOME/hunt-data |
wordlists, payload packs, templates, scope dumps |
$HOME/hunt-reference |
checklists, disclosed reports, methodology |
$HOME/tools/manual |
Burp extensions, mobile tools, GUI clients — cloned only, never run |
$HOME/go/bin, ~/.cargo/bin, ~/.local/bin, ~/.npm-global/bin |
native tool binaries |
$HOME/.hunt-setup.env |
PATH additions, sourced from ~/.bashrc |
$HOME/Hunt-Setup-install-report.tsv |
full per-tool result of the last run |
# add a tool
printf 'core\tgo\tprojectdiscovery/example\tgithub.com/projectdiscovery/example/cmd/example\n' \
>> manifests/tools.tsv
# stop installing something
sed -i '/^core\tpip\toldtool/d' manifests/tools.tsvBase apt packages are one-per-line in manifests/apt.txt.
Re-running sudo ./setup.sh is idempotent: existing clones are pulled instead of
re-cloned, and native installs are re-run in place.
- Nothing out of scope. The 164 dropped starred repos never appear here — they are not installed and not documented. They simply are not hunting tools.
- Burp Suite loaders / keygens. Starred repos that circumvent Burp's licensing are excluded. This repo will not fetch or run them.
dns_notify.sh— DNS query →notifypingback listener for OOB detection (needsbind9+notify+anew, all installed bysetup.sh).
- Upstream:
jamaledim/Hunt-Setup— original multi-distro server setup script, base apt list, source-build list and Go tool list. - Fork:
mohammadsec/Hunt-Setup - Tool inventory: every repository starred by
github.com/mohammadsecat generation time, filtered to bug-bounty / pentest / red-team tooling. - Full per-tool listing with descriptions: TOOLS.md.