CLI tool
dreddsa5dies/goHackTools avatar
dreddsa5dies/goHackTools

goHackTools: a Go collection of offensive security examples, not a toolkit

Project brief: Hacker tools on Go (Golang). Hacker tools on Go (Golang)

2,193 stars372 forksGoMIT

At a glance

What is it?
The repository collects 65 Go files covering password cracking, port scanning, steganography, sniffing and shellcode-style exercises, drawn from penetration testing books. It is a reading and teaching resource, not a product with a support contract.
Who is it for?
goHackTools suits Go developers who already know the security basics and want to see how a port scanner, a packet parser or a Caesar cipher looks in idiomatic Go. It does not suit anyone who needs a maintained scanner, a supported CLI or a tool to run against systems they do not own.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 71 days ago.
What is it written in?
Mainly Go, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What goHackTools is, and who it is written for

The README lists the sources behind the code: Violent Python, Black Hat Python, Security with Go, the Python Web Penetration Testing Cookbook and Black Hat Go. That list is the best description of the project's intent. Each directory under projects/ is an exercise translated from one of those books into Go, and the top-level README enumerates them in Russian. The subjects run from password cracking against passwd files, ZIP archives and SSH, through port scanning and DNS lookups, to steganography, RSA and Caesar ciphers, HTTP header grabbing and a SYN flood example.

The audience is therefore narrow. This is for someone who has read one of those books, or is reading it now, and wants the same exercise in a language with goroutines, static binaries and no interpreter. The README's own framing is explicit: "all the examples here are for reference only, and not for criminal (or malicious) purposes." There is no command-line entry point that ties the projects together, no configuration file and no service. You pick a directory, read it, build it, and run it against a target you control.

How the repository is organised and how the code flows

go.mod declares the module as github.com/dreddsa5dies/goHackTools and pins Go 1.25.0. The dependency list is where the architecture becomes visible. github.com/google/gopacket handles packet capture and parsing, which the packet parser and SYN flood examples depend on. github.com/miekg/dns covers DNS queries for the MX record, server-name and A record examples. github.com/oschwald/geoip2-golang and github.com/flopp/go-staticmaps back the IP geolocation and map-building projects. github.com/alexmullins/zip supports the archive password cracker, and github.com/amoghe/go-crypt handles the Unix password hashing.

One detail stands out: the last line of go.mod is a replace directive, replace shodan => ./projects/57_shodanAPI/shodan. The Shodan API client is vendored inside the project directory rather than fetched from a remote module path. A vendor/ directory sits at the top level as well. That means the Shodan example builds against a local copy, and if you want to know what that client supports you read it in the repository rather than in a module registry.

Each project directory is self-contained. There is no shared internal package that all of them import, so an improvement to the port scanner does not propagate to the concurrent scanner. The README notes that "the code contains comments in Russian", which is a real cost for anyone reading the source to learn from it rather than to run it.

Installing the dependencies and running your first example

The README's package section is two lines: use Go Modules, and install libpcap-dev. That second step is not optional if you touch the packet capture projects, because gopacket links against the system pcap library. On Debian and Ubuntu the command from the README is:

bash
sudo apt-get install libpcap-dev

With the system library in place, clone the repository and build a project from its directory. The port scanner is the simplest place to start, because it does not need pcap and does not need a target you care about:

bash
cd projects/03_tcpScanner
go build

Run the resulting binary with the flags its own main function parses. The repository uses github.com/jessevdk/go-flags across the projects, so the flags are defined per project rather than globally, and the README does not print a usage table for each one. Read the source of the project you built to see which flags it accepts before you run it. If you want the concurrent variant instead, it lives in projects/56_PerformingConcurrentScanning and follows the same shape. The forensic examples that read a browser's SQLite database pull in github.com/mattn/go-sqlite3, which requires cgo, so a plain cross-compile to a different platform will not work for those.

Where goHackTools stops being the right tool

The project has no releases. The README does not document a versioning scheme, and there is no changelog in the top-level file list. If you build a binary from master today and again in six months, nothing in the repository tells you what changed in between. For a collection of teaching examples that is tolerable. For anything you would run during an engagement it is a problem, because you cannot pin a known-good build.

The maintenance signal is equally thin. The repository is not archived, but no last push date was available for this review, so there is no evidence to cite about how recently the code changed. The dependency set is a snapshot: gopacket at v1.1.17, miekg/dns at v1.1.27, go-flags at v1.4.0. Those are the versions the examples were written against, and the README does not describe an upgrade policy.

There is also a scope problem. The README's project list includes a SYN flood example and an SSH botnet example. Those are the parts of the collection most likely to be misread as something you deploy. They are not. They are demonstrations of how the protocol or the primitive works, written to be read alongside a book chapter. If you need a scanner you can point at a client's network with a report at the end, this repository gives you neither the scanner nor the report.

How it compares to a maintained Go scanner

A tool like nmap, or a Go scanner such as naabu, is built around a single purpose: take a target specification, produce results, handle the edge cases in the protocol, and keep doing that across releases. goHackTools is built around a different goal. Its port scanner in projects/03_tcpScanner and its concurrent scanner in projects/56_PerformingConcurrentScanning exist to show two ways of writing the same loop in Go, one sequential and one with goroutines. There is no service detection, no output format beyond what the example prints, and no rate limiting you would trust on a production network.

The same contrast holds for the DNS examples. projects/33_getMXRec and projects/58_dnsGetA query a resolver through miekg/dns and print the answer. A maintained DNS client gives you retries, timeouts, DNSSEC validation and structured output. The repository gives you the query and the parse, which is the part you would otherwise have to look up in the library's documentation. That is the trade: less capability, more visibility into the mechanism. If you want the mechanism, this is a reasonable place to read it. If you want the capability, go elsewhere.

Licence, upgrade cost and what the README leaves open

The project is MIT licensed, and the README points to LICENSE.md for the text. MIT is permissive: it allows reuse, modification and redistribution provided the copyright notice and permission notice are kept. The README adds a predict section stating that the examples are for reference only and not for criminal purposes. That sentence is a statement of intent, not a licence term, and it does not change what MIT permits. It does tell you how the author expects the code to be used, and it is worth reading before you copy a directory into your own project. This is not legal advice; if you plan to redistribute any part of the code, read LICENSE.md yourself.

The upgrade cost is the part the README does not address. There is no documented path for moving the examples to newer versions of gopacket or miekg/dns, and no test suite visible in the top-level file list that would tell you whether such a move broke anything. The .golangci.yml file shows linting is configured, which suggests the code was held to some standard at the time it was written, but linting is not a compatibility guarantee. If you fork the repository, budget for reading each project you actually need rather than assuming a version bump will be mechanical.

Editorial conclusion

goHackTools suits Go developers who already know the security basics and want to see how a port scanner, a packet parser or a Caesar cipher looks in idiomatic Go. It does not suit anyone who needs a maintained scanner, a supported CLI or a tool to run against systems they do not own. Verify first that libpcap-dev installs on your machine, that the module builds under the Go version in go.mod, and that you are comfortable reading Russian comments in the source. The README itself states that the examples are for reference only.

Frequently asked questions

Can someone hack my computer without me knowing?

goHackTools does not answer this. It is a set of example programs for readers of penetration testing books, and the README states the examples are for reference only and not for malicious purposes. Nothing in the repository assesses whether a machine has been compromised.

What apps can get hacked?

The repository does not survey applications. Its projects target specific protocols and artefacts instead: password files, ZIP archives, SSH logins, HTML forms, DNS records, browser SQLite databases and image metadata. Each directory is a single exercise.

What are hacker tools in Minecraft?

This repository has nothing to do with Minecraft. goHackTools is a Go collection of security exercises drawn from books such as Black Hat Go and Violent Python, covering port scanning, packet parsing, ciphers and forensics.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/dreddsa5dies-gohacktools.svg)](https://hysenlabs.com/projects/dreddsa5dies-gohacktools)