Pentool is a modern async TUI for web pentesting — one command to install, zero config, unlimited Intruder, AI-powered scanner. Runs in your terminal, works in CI/CD.
One command, zero config, async by design. AI helps you find vulnerabilities faster. No Java, no Electron, no bloat.
Built on asyncio — thousands of concurrent connections, hundreds of req/s. No waiting, no queues. Speed that matters.
Full keyboard + mouse support. Works over SSH, in tmux, in CI/CD pipelines, on headless servers. No display needed.
No request limits, no throttling. Keep-Alive + connection pooling = 10× attack speed. Sniper, Battering Ram, Pitchfork, Cluster Bomb.
Smart scan with context-aware payloads for SQLi, XSS, SSTI, LFI, RCE, SSRF, XXE, CORS, JWT. AI-assisted WAF bypass and blind injection. Learns from responses.
Intercept HTTP/HTTPS and WebSocket frames in real time. AI suggests matching rules, detects hidden parameters, auto-highlights interesting requests.
19 chained encode/decode/hash ops. Side-by-side diff. Entropy + FIPS analysis. AI helps decode unknown formats and spot anomalies.
One command, no Docker, no JDK, no certs to install, no proxy to configure. Linux, macOS, Windows WSL. Works immediately.
Run scans in your pipeline — pentool scan active --url ... — exit codes, JSON reports. Extend with Python plugins. PRO adds advanced scanners.
Works on Linux, macOS, and Windows (WSL). Python 3.10+.
Don't have uv? curl -LsSf https://astral.sh/uv/install.sh | sh ·
pip still works too: pip install pentool ·
Full installation guide →
Pentool running in a real terminal — no mocks, no marketing renders.
Help keep Pentool free and open-source. Any amount is appreciated.
Guides, references and plugin API.
Up and running in 5 minutes
Detailed setup for all platforms
All modules, all features
Build your own extensions
Read this page in your language — use the language switch in the top menu.