lazymap
A single command-line tool for network penetration testing. It combines multiple selected nmap scripts, sslscan, ssh-audit, dig, ldapsearch, curl, rpcclient, selected metasploit modules, PRET and wget.
Download
- Bash 3.0 or newer, including the 3.2 that ships with macOS
- nmap, curl, dig, ldapsearch, rpcclient, metasploit
- sslscan, ssh-audit, screen
- crackmapexec or its successor nxc - either satisfies the check
- No compilation, no build step
lazymap is a multi-file project — lazymap.sh sources the rest of the
tree at runtime, so saving that one file on its own will not work. Clone the repository, or download it as a
ZIP and keep the directory intact. Browse every file above before you run it.
Install
Clone the repository
Everything is sourced relative to the script, so keep the tree intact.
git clone https://github.com/evanricafort/lazymap.git
cd lazymap
Make the scripts executable
The entry point plus every module it sources.
sudo chmod +x lazymap.sh lib/*.sh extra/*.sh reports/*.sh scans/*.sh
Install whatever is missing
Checks every required tool, installs the missing ones, and exits. Supports apt, dnf, yum, pacman, zypper and Homebrew.
sudo ./lazymap.sh --install-deps
Run a scan
A single host, or a file with one target per line.
sudo ./lazymap.sh -u 192.0.2.10
sudo ./lazymap.sh -t hosts
All of it in one line
git clone https://github.com/evanricafort/lazymap.git && cd lazymap && sudo chmod +x lazymap.sh lib/*.sh extra/*.sh reports/*.sh scans/*.sh && sudo ./lazymap.sh -h
Usage
| Flag | What it does |
|---|---|
| -u <host> | Scan a single host. |
| -t <file> | Scan every host or subnet listed in a file. |
| -1 / -2 / -3 | Add the vulners NSE script, vuln, or both. -3 is slow across many targets. |
| -4 | Firewall evasion scan. |
| -a | Skip the all-ports and UDP scans. |
| -n | Add -n -T4 for a faster run. |
| -k | Skip sslscan, ssh-audit and the header check. |
| -b | Add -A --min-rate 1000 --open. |
| --pret | Printer security checks via PRET. |
| --mitm6 | IPv6 takeover run via mitm6. |
| --domain / --userlist | Domain and user list for authenticated checks. |
| --interface <if> | Pin the scan to one interface. |
| -o <dir> | Custom output directory. |
| --resume | Pick a previous run back up where it stopped. |
| --install-deps | Install missing dependencies, then exit. |
| -y / --yes | Skip the install prompt in scripted runs. |
| -h | Show the full help text. |
Everything, with printer checks
sudo ./lazymap.sh -t hosts -12bank --pret --exclude-udp --interface eth0 -o my_scan
Authenticated domain checks
./lazymap.sh -t hosts --domain CORP.EXAMPLE.COM --userlist users.txt
Resume an interrupted run
sudo ./lazymap.sh -t hosts -12bank -o my_scan --resume
Before you run it
lazymap is loud by design - it is a full scan sweep, not a quiet one. Run it only against hosts you are authorized to test, and expect it to show up in the target’s monitoring. Run under sudo for the nmap scripts that need raw sockets.