lazymap

A single command-line tool for network penetration testing. It combines multiple selected nmap scripts, sslscan, ssh-audit, dig, ldapsearch, curl, rpcclient, selected metasploit modules, PRET and wget.

Bash v1.0 Bash 3.0+ · macOS ok Auto dependency install
Source Download Install Usage
evanricafort/lazymap Public
Code

Download

evanricafort/lazymap 28 files, 172 KB. Clone it, or grab a ZIP from the green Code button.
Requirements
  • Bash 3.0 or newer, including the 3.2 that ships with macOS
  • nmap, curl, dig, ldapsearch, rpcclient, metasploit
  • sslscan, ssh-audit, screen
  • crackmapexec or its successor nxc - either satisfies the check
  • No compilation, no build step

lazymap is a multi-file project — lazymap.sh sources the rest of the tree at runtime, so saving that one file on its own will not work. Clone the repository, or download it as a ZIP and keep the directory intact. Browse every file above before you run it.

Install

1

Clone the repository

Everything is sourced relative to the script, so keep the tree intact.

git clone https://github.com/evanricafort/lazymap.git
cd lazymap
2

Make the scripts executable

The entry point plus every module it sources.

sudo chmod +x lazymap.sh lib/*.sh extra/*.sh reports/*.sh scans/*.sh
3

Install whatever is missing

Checks every required tool, installs the missing ones, and exits. Supports apt, dnf, yum, pacman, zypper and Homebrew.

sudo ./lazymap.sh --install-deps
4

Run a scan

A single host, or a file with one target per line.

sudo ./lazymap.sh -u 192.0.2.10
sudo ./lazymap.sh -t hosts

All of it in one line

git clone https://github.com/evanricafort/lazymap.git && cd lazymap && sudo chmod +x lazymap.sh lib/*.sh extra/*.sh reports/*.sh scans/*.sh && sudo ./lazymap.sh -h

Usage

Flag What it does
-u <host>Scan a single host.
-t <file>Scan every host or subnet listed in a file.
-1 / -2 / -3Add the vulners NSE script, vuln, or both. -3 is slow across many targets.
-4Firewall evasion scan.
-aSkip the all-ports and UDP scans.
-nAdd -n -T4 for a faster run.
-kSkip sslscan, ssh-audit and the header check.
-bAdd -A --min-rate 1000 --open.
--pretPrinter security checks via PRET.
--mitm6IPv6 takeover run via mitm6.
--domain / --userlistDomain and user list for authenticated checks.
--interface <if>Pin the scan to one interface.
-o <dir>Custom output directory.
--resumePick a previous run back up where it stopped.
--install-depsInstall missing dependencies, then exit.
-y / --yesSkip the install prompt in scripted runs.
-hShow the full help text.

Everything, with printer checks

sudo ./lazymap.sh -t hosts -12bank --pret --exclude-udp --interface eth0 -o my_scan

Authenticated domain checks

./lazymap.sh -t hosts --domain CORP.EXAMPLE.COM --userlist users.txt

Resume an interrupted run

sudo ./lazymap.sh -t hosts -12bank -o my_scan --resume

Before you run it

lazymap is loud by design - it is a full scan sweep, not a quiet one. Run it only against hosts you are authorized to test, and expect it to show up in the target’s monitoring. Run under sudo for the nmap scripts that need raw sockets.