A bash script for security professionals and penetration testers to automatically install the latest version of Go and a curated collection of offensive security tools written in Go.
This script automates the installation of:
- The latest version of Go (with architecture detection for both AMD64 and ARM64)
- A comprehensive set of Go-based security tools commonly used in penetration testing and bug bounty hunting
- Debian-based systems (Ubuntu, Kali Linux, etc.)
- Arch-based systems (Arch Linux, BlackArch, etc.)
The script will automatically install the necessary dependencies:
- For Debian-based systems:
build-essential,libpcap-dev - For Arch-based systems:
base-devel
- Clone the repository:
git clone https://github.com/solidshadw/installgoofensive.git
cd installgoofensive- Make the script executable:
chmod +x install-tool.sh- Run the script:
./install-tool.sh| Tool | Description | Repository |
|---|---|---|
| nuclei | Fast and customizable vulnerability scanner | projectdiscovery/nuclei |
| subfinder | Subdomain discovery tool | projectdiscovery/subfinder |
| naabu | Fast port scanner | projectdiscovery/naabu |
| gowitness | Web screenshot utility | sensepost/gowitness |
| httpx | HTTP toolkit for probing web servers | projectdiscovery/httpx |
| notify | Notification utility for workflows | projectdiscovery/notify |
| assetfinder | Find domains and subdomains related to a given domain | tomnomnom/assetfinder |
| waybackurls | Fetch URLs from the Wayback Machine | tomnomnom/waybackurls |
| gf | Wrapper around grep for pattern matching | tomnomnom/gf |
| shortscan | Security scanner for cloud services | bitquark/shortscan |
| anew | Tool for adding lines to a file only if they don't already exist | tomnomnom/anew |
| simplehttpserver | Simple HTTP server | projectdiscovery/simplehttpserver |
| ffuf | Fast web fuzzer | ffuf/ffuf |
| amass | Network mapping of attack surfaces and external asset discovery | owasp-amass/amass |
| cloudrecon | Cloud infrastructure reconnaissance tool | g0ldencybersec/CloudRecon |
| gau | Get All URLs | lc/gau |
| gospider | Fast web spider | jaeles-project/gospider |
| kerbrute | Kerberos bruteforce utility | ropnop/kerbrute |
| aws-enumerator | AWS enumeration tool | shabarkin/aws-enumerator |
| gron | Make JSON greppable | tomnomnom/gron |
| qsreplace | Query string replacement utility | tomnomnom/qsreplace |
- Architecture Detection: Automatically detects and installs the appropriate Go version for your system architecture (AMD64 or ARM64)
- Path Management: Adds Go to your PATH automatically
- Tool Installation: Installs tools to both
$HOME/go/binand/usr/local/binfor system-wide availability - Error Handling: Provides clear feedback on which tools were successfully installed and which failed
- Idempotent: Can be run multiple times without duplicating installations
-
Shell Restart: After installation, you may need to restart your shell or source your shell configuration file to use Go:
source ~/.bashrc # or ~/.zshrc if using zsh
-
Permission Issues: If you encounter permission errors, ensure you have sudo privileges.
-
Tool-Specific Issues:
- Some tools may require additional configuration after installation
- For amass, the script uses the
@masterversion tag instead of@latestdue to specific requirements
You can easily add more tools to the script by adding additional install_go_tool lines with the appropriate parameters:
install_go_tool "tool_name" "github.com/author/repo" "binary_name"This project is licensed under the MIT License - see the LICENSE file for details.
- All the authors of the included security tools
- The Go team for creating an excellent programming language