MagicTree v1.3 Available For Download – Pentesting Productivity


Have you ever spent ages trying to find the results of a particular portscan you were sure you did? Or grepping through a bunch of files looking for data for a particular host or service? Or copy-pasting bits of output from a bunch of typescripts into a report? We certainly did, and that’s why we wrote MagicTree – so that it does such mind-numbing stuff for us, while we spend our time hacking.

MagicTree is a pentesting productivity tool. It is designed to allow easy and straightforward data consolidation, querying, external command execution and (yeah!) report generation. In case you wonder, “Tree” is because all the data is stored in a tree structure, and “Magic” is because it is designed to magically do the most cumbersome and boring part of penetration testing – data management and reporting.

MagicTree v1.3 - Pentesting Productivity

Changelog for v1.3

  • Fix for #307 “Cannot create a working report template in LibreOffice 3.5.4.2”.
  • Better parsing of Imperva Scuba XML
  • Fixed NullPointerException in FileFilter
  • Added debugging to idTracker and sanity checking to TreeController to catch the integrity bug
  • Fix for NullPointerException when handling MtSimpleObjects with no text
  • Fixes for data integrity bugs causing duplicated ids and broken xrefs
  • Added support for AppScan XML – contributed by VienHa Tran

Installation

No installation is required for MagicTree. The application is distrubuted as a single JAR file which has to be executed with JRE. Just save the file on your desktop. Double-click on it to execute it or, for less user-friendly OSes, issue “java -jar MagicTree.jar’ command.

Can’t get much better than that really, penetration testing report generation! Who wants to do that manually. IF you combined this with using something like Kvasir the Penetration Testing Data Management Tool, you’d be onto a pretty good process I reckon.

You can download MagicTree here:

MagicTree-build1814.jar

Or read more here.

Posted in: Hacking News, Security Software

, , , , , , , , , , , ,


Latest Posts:


BloodHound - Hacking Active Directory Trust Relationships BloodHound – Hacking Active Directory Trust Relationships
BloodHound is for hacking active directory trust relationships and it uses graph theory to reveal the hidden and often unintended relationships within an AD environment.
SecLists - Usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells SecLists – Usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place.
DeepSound - Audio Steganography Tool DeepSound – Audio Steganography Tool
DeepSound is an audio steganography tool and audio converter that hides secret data into audio files, the application also enables you to extract from files.
2019 High Severity Vulnerabilities What are the MOST Critical Web Vulnerabilities in 2019?
So what is wild on the web this year? Need to know about the most critical web vulnerabilities in 2019 to protect your organization?
GoBuster - Directory/File & DNS Busting Tool in Go GoBuster – Directory/File & DNS Busting Tool in Go
GoBuster is a tool used to brute-force URIs (directories and files) in web sites and DNS subdomains (inc. wildcards) - a directory/file & DNS busting tool.
BDFProxy - Patch Binaries via MITM - BackdoorFactory + mitmProxy BDFProxy – Patch Binaries via MiTM – BackdoorFactory + mitmproxy
BDFProxy allows you to patch binaries via MiTM with The Backdoor Factory combined with mitmproxy enabling on the fly patching of binary downloads


2 Responses to MagicTree v1.3 Available For Download – Pentesting Productivity

  1. Scb May 8, 2014 at 3:05 pm #

    Isn’t it ironic? Pen test tool written in Java, which has like 11 thousand zero-day vulns each week? ;)

    • Darknet May 8, 2014 at 10:15 pm #

      Heh yah, but well it’s not a service and unfortunately if you want a cross platform executable..Java is still the best.