finds.dev← search

// the find

JohnHammond/katana

★ 1,362 · Python · NOASSERTION · updated Mar 2024

Katana - Automatic CTF Challenge Solver in Python3

Katana is a Python 3 CTF challenge automation tool that throws a pile of 'units' (base64, Caesar, steganography, zip/gzip extraction, basic SQLi/NoSQLi, binwalk, OCR, etc.) at a target file or string in parallel threads, hoping one of them turns up a flag. It's aimed at CTF players who want to skip the manual low-hanging-fruit checklist.

The boss/worker threading model is a reasonable way to fan out dozens of unrelated decoding attempts concurrently, and adding a new check is just dropping a unit file in the right folder. Coverage is genuinely broad for a CTF toolkit — crypto, stego, esoteric languages, PDF/PCAP/APK handling are all represented as separate, independently testable units. Having a CTFd/picoCTF REPL integration baked in is a nice touch for players who want to pull challenges directly into the tool.

Explicitly unmaintained since early 2024 and the README says so outright, so expect bitrot against newer Python/dependency versions rather than fixes. It shells out to a long list of external binaries (binwalk, foremost, tesseract, steghide, apktool, exiftool, ffmpeg...) with no containerized default path other than a thin Docker wrapper, so a bare install is a multi-distro dependency hunt. It runs arbitrary decode/exploit attempts against whatever you point it at (SQLi, LFI, webshell uploads) with no sandboxing, which is fine for CTF infra but a real liability if someone runs it against something they don't fully control. The known-issues section in the README (colorama missing, cmd2 version mismatch) reads like unresolved setup friction rather than fixed bugs.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →