FS-NyarL Pentesting & Forensics Framework

P { margin-bottom: 0.08in; }H2 { margin-bottom: 0.08in; }H2.western { font-family: “Liberation Sans”,sans-serif; font-size: 14pt; font-style: italic; }H2.cjk { font-family: “Droid Sans”; font-size: 14pt; font-style: italic; }H2.ctl { font-family: “FreeSans”; font-size: 14pt; font-style: italic; }TD P { margin-bottom: 0in; }

Automatic tools have made the
penetration testing process more efficient and effective, although
the importance of manual test are still there and in most of the
cases manuals checks are required. But in the mean time we cannot
deny the advantages of automatic tool, yes it save a loads of time
and energy off course. You must have heard about the most famous
vulnerability assessment & penetration testing tool like Nessus &
Metasploit but in this article I will discuss FS-NyarL.
NyarL it’s Nyarlathotep, a
mitological chaotic deity of the writer HP. Lovecraft’s
It’s represent Crawling Chaos and FS-NyarL it’s The
Crawling Chaos of Cyber Security 🙂
A network takeover &
forensic analysis tool – useful to advanced PenTest tasks & for
fun and profit – but use it at your own risk!
  • Interactive Console
  • Real Time Passwords Found
  • Real Time Hosts Enumeration
  • Tuned Injections & Client Side
  • ARP Poisoning & SSL Hijacking
  • Automated HTTP Report Generator


  • MITM (Arp Poisoning)
  • Sniffing (With & Without Arp Poisoning)
  • SSL Hijacking (Full SSL/TLS
  • HTTP Session Hijaking (Take &
    Use Session Cookies)
  • Client Browser Takeover (with
    Filter Injection in data stream)
  • Browser AutoPwn (with Filter
    Injection in data steam)
  • Evil Java Applet (with Filter
    Injection in data stream)
  • Port Scanning


  • Passwords extracted from data
  • Pcap file with whole data stream
    for deep analysis
  • Session flows extracted from data
    stream (Xplico & Chaosreader)
  • Files extracted from data stream
  • Hosts enumeration (IP,MAC,OS)
  • URLs extracted from data stream
  • Cookies extracted from data stream
  • Images extracted from data stream
  • List of HTTP files downloaded extracted from URLs

TD P { margin-bottom: 0in; }P { margin-bottom: 0.08in; }

TD P { margin-bottom: 0in; }P { margin-bottom: 0.08in; }

  • Chaosreader (already in bin folder)

  • Xplico

  • Ettercap

  • Arpspoof

  • Arp-scan

  • Mitmproxy

  • Nmap

  • Tcpdump

  • Beef

  • SET

  • Metasploit

  • Dsniff

  • Macchanger

  • Hamster

  • Ferret

  • P0f

  • Foremost

  • SSLStrip

  • SSLSplit

Download & Tutorial
Ehacking Staff
With more than 50 global partners, we are proud to count the world’s leading cybersecurity training provider. EH Academy is the brainchild of Ehacking, which has been involved in the field of training since the past Five years and continues to help in creating professional IT experts.

Most Popular

Blind SQL Injection Tutorial to Hack a Website

In the previous article, we have the basics of SQL Injection; what SQLi is and what are the types of SQL injection. And, In...

What is SQL Injection? Tutorial: Type and Example

What is SQL injection, and what are the types of SQL injection? These are the common questions, and we will seek the answer to...

Are Cisco 300-410 Exam and Its Related Certification Your Pathway to Career Success? Find Out about This

Introduction Career success can mean different things to different people. For some, it could mean having a prestigious title and for others, it could be...

How to Hack Windows 10 Password Using FakeLogonScreen in Kali Linux

This article demonstrates an in-depth guide on how to hack Windows 10 Passwords using FakeLogonScreen. Hacking Windows 10 password is an exciting topic and...