Skip to content

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

 
 

Latest commit

 

History

1 Commit

Folders and files

Repository files navigation

Hunt-Setup

Ubuntu-only, bug-bounty-only one-shot installer for a hunt box.

Buy a server, run one command, and the whole environment is there — tools, wordlists, payload packs, nuclei templates, Burp extensions and reference material.

git clone https://github.com/mohammadsec/Hunt-Setup.git
cd Hunt-Setup
chmod +x setup.sh
sudo ./setup.sh

Then open a new shell (or source ~/.hunt-setup.env) and check:

nuclei -version; subfinder -version; httpx -version
ls ~/hunt-data          # wordlists, payloads, nuclei templates
cat ~/Hunt-Setup-install-report.tsv   # per-tool OK / PARTIAL / FAILED

What this repo is

A rework of mohammadsec/Hunt-Setup (fork of jamaledim/Hunt-Setup) with three changes:

  1. Ubuntu only. The CentOS / Fedora branches are gone. One code path.
  2. Scoped to hunting. Only starred repos that are bug-bounty / pentest / red-team tooling are included. Trading bots, AI gateways, fonts, VPN clients, coding tutorials, generic libraries and everything else you happen to have starred are not in this repository at all — not installed, not listed.
  3. Data-driven. setup.sh is generic installer logic; manifests/*.tsv says what to install. Adding or dropping a tool is a one-line edit.

1692 starred repositories were evaluated. 1531 kept, 164 dropped as out of scope. (Plus 12 classic tools carried over from upstream that are not starred.)

Contents

Manifest Count Where it lands
manifests/tools.tsv 1085 native installs (~/go/bin, ~/.local/bin, …) + source clones in ~/tools
manifests/data.tsv 138 ~/hunt-data — wordlists, payload packs, nuclei templates, scope dumps
manifests/reference.tsv 71 ~/hunt-reference — checklists, disclosed reports, methodology
manifests/manual.tsv 237 ~/tools/manual — Burp extensions, mobile tools, GUI clients (cloned, never executed)
manifests/apt.txt 98 lines base apt packages

Everything above installs by default. Wordlists are included in the default run — you do not need a flag for them.

Flags

Flag Effect
(none) everything: tools + data + reference + manual + apt + toolchain
--dry-run, -n print the plan, touch nothing
--only <category> install exactly one of core data reference manual
--no-data / --no-reference / --no-manual / --no-core opt out of a category
--method <m> restrict to one install method: go pip npm cargo gem make git
--jobs <n> install <n> tools concurrently (default 1; npm/gem always run serially)
--no-apt skip the apt phase (tools only)
--no-warp / --no-browser skip Cloudflare WARP / the Google Chrome .deb
--installers also run a cloned repo's install.sh (off by default — most are interactive)
-v show every command and every per-tool line

Flags combine: sudo ./setup.sh --only data --jobs 8 --dry-run.

How a tool gets installed

Every method has a fallback, so a wrong guess still ends with the source on disk rather than nothing:

Method Count Primary attempt Fallback
go 338 go install <path>@latest, trying base → cmd/<name> → v2/v3 layouts shallow clone
pip 405 pipx install git+<repo> (isolated venv, entry points on PATH) clone + requirements.txt into a per-tool .venv
npm 82 npm install -g github:<repo> clone
cargo 21 cargo install --git <repo> clone
make 17 clone + make + sudo make install clone only
gem 17 clone + bundle install / gem build clone only
git 651 shallow clone + symlink executables into ~/tools/bin —

Per-tool outcomes:

  • OK — the native install worked
  • PARTIAL — native install failed but the source is cloned and usable
  • FAILED — both attempts failed (these are the ones worth looking at)

One failure never aborts the run: setup.sh has no set -e and traps every tool individually, then prints a summary and writes ~/Hunt-Setup-install-report.tsv.

Where things land

Path Contents
$HOME/tools/<owner>_<repo> source clones (git / make / fallback installs)
$HOME/tools/bin symlinks to executables found in those clones
$HOME/hunt-data wordlists, payload packs, templates, scope dumps
$HOME/hunt-reference checklists, disclosed reports, methodology
$HOME/tools/manual Burp extensions, mobile tools, GUI clients — cloned only, never run
$HOME/go/bin, ~/.cargo/bin, ~/.local/bin, ~/.npm-global/bin native tool binaries
$HOME/.hunt-setup.env PATH additions, sourced from ~/.bashrc
$HOME/Hunt-Setup-install-report.tsv full per-tool result of the last run

Changing what gets installed

# add a tool
printf 'core\tgo\tprojectdiscovery/example\tgithub.com/projectdiscovery/example/cmd/example\n' \
  >> manifests/tools.tsv

# stop installing something
sed -i '/^core\tpip\toldtool/d' manifests/tools.tsv

Base apt packages are one-per-line in manifests/apt.txt. Re-running sudo ./setup.sh is idempotent: existing clones are pulled instead of re-cloned, and native installs are re-run in place.

Deliberate omissions

  • Nothing out of scope. The 164 dropped starred repos never appear here — they are not installed and not documented. They simply are not hunting tools.
  • Burp Suite loaders / keygens. Starred repos that circumvent Burp's licensing are excluded. This repo will not fetch or run them.

Extras kept from upstream

  • dns_notify.sh — DNS query → notify pingback listener for OOB detection (needs bind9 + notify + anew, all installed by setup.sh).

Provenance

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages