{"id":4357,"date":"2024-08-16T18:54:10","date_gmt":"2024-08-16T22:54:10","guid":{"rendered":"https:\/\/dft.wiki\/?p=4357"},"modified":"2026-06-08T10:32:44","modified_gmt":"2026-06-08T14:32:44","slug":"kalilinux-and-parrotos-got-a-new-cousin-snoopgod","status":"publish","type":"post","link":"https:\/\/dft.wiki\/?p=4357","title":{"rendered":"KaliLinux and ParrotOS got a new Cousin: SnoopGod"},"content":{"rendered":"<p>Kali and Parrot are not the only Linux distributions for red teams, but they are certainly the most popular ones. Now, there is a new kid on the playground: SnoopGod! (I know what you&#8217;re thinking about the name, kinda familiar, right?)<\/p>\n<p><strong>SnoopGod v24.04<\/strong> (formerly known as Blackbuntu) is based on Ubuntu 24.04 LTS, which is itself based on Debian upstream. What does this mean? It is easy to distro-hop and still feel familiar with the system and tools, especially for those who use Ubuntu as their daily driver.<\/p>\n<p>What does SnoopGod bring that distinguishes it from Kali or Parrot?<\/p>\n<ul>\n<li>Based on Ubuntu LTS\n<ul>\n<li>Long-term support (LTS) matters to those who need stability and security, as it provides support for at least 5 years.<\/li>\n<li>Arguably, Ubuntu has a larger community and more information available online. (Not open to debating this, just my opinion.)<\/li>\n<\/ul>\n<\/li>\n<li>KDE Plasma\n<ul>\n<li>Historically, KDE has been the heaviest desktop environment compared to Xfce (used by Kali) and GNOME (used by Parrot), but KDE Plasma has improved so much that its performance now feels comparable to Xfce, which was designed to be lightweight.<\/li>\n<li>It is beautiful and highly customizable.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>Note:<\/strong> In late 2025, Parrot OS 7.0 was released with KDE Plasma 6 and Wayland by default, on top of Debian 13.<\/p>\n<hr \/>\n<p><strong>FIRST IMPRESSIONS<\/strong><\/p>\n<ul>\n<li>Quick to boot from the live CD and fully compatible (drivers) on a KVM hypervisor.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4361 \" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-08-45-42.png\" alt=\"\" width=\"640\" height=\"546\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-08-45-42.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-08-45-42-300x256.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-08-45-42-768x655.png 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>Smooth and straightforward installation, and it did not take long either.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4362 size-large\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-08-53-45-1024x724.png\" alt=\"\" width=\"640\" height=\"453\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-08-53-45-1024x724.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-08-53-45-300x212.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-08-53-45-768x543.png 768w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-08-53-45.png 1280w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<ul>\n<li>Out of the box, the guest screen resizes with a smooth animation as the hypervisor window is resized.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-4364 size-large aligncenter\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-10-13-17-1024x740.png\" alt=\"\" width=\"640\" height=\"463\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-10-13-17-1024x740.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-10-13-17-300x217.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-10-13-17-768x555.png 768w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-08-16-10-13-17.png 1473w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<ul>\n<li><strong>Reflection<\/strong>\n<ul>\n<li>Low barrier for new users.<\/li>\n<li>Pleasant experience.<\/li>\n<li>Eye candy!<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<hr \/>\n<p><strong>UNDER THE HOOD OBSERVATIONS<\/strong><\/p>\n<p>While Kali pulls all packages from its own repository, SnoopGod pulls most of its packages from Ubuntu&#8217;s repository, including security patches. Only the specialized tools come from SnoopGod&#8217;s own repository, except for Metasploit, which comes with its own repository pre-configured.<\/p>\n<ul>\n<li><strong>Rationale<\/strong>\n<ul>\n<li>Pulling core system packages from Ubuntu is a smart strategy as it allows the distro maintainers to focus on the specialized tools.<\/li>\n<li>Security patches are pushed downstream directly by a much larger team of specialists at Canonical.<\/li>\n<li>Kali and Parrot are arguably not suited as daily driver operating systems and are better used as dedicated instances, in a VM, or in a container. SnoopGod, on the other hand, is a set of security tools built on top of an enterprise-level desktop system designed to be a daily driver.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<hr \/>\n<p><strong>PACKAGES ON TOP OF UBUNTU<\/strong><\/p>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Cracking<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>crowbar<\/li>\n<li>gpp-decrypt<\/li>\n<li>rainbowcrack<\/li>\n<li>rsmangler<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Exploitation<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>beef<\/li>\n<li>burpsuite<\/li>\n<li>cge<\/li>\n<li>exe2hex<\/li>\n<li>exploitdb<\/li>\n<li>gophish<\/li>\n<li><a href=\"https:\/\/github.com\/joaomatosf\/jexboss\">jexboss<\/a> <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>A tool for testing and exploiting vulnerabilities in JBoss Application Server and other Java platforms.<\/li>\n<\/ul>\n<\/li>\n<li><a href=\"https:\/\/github.com\/bounteous17\/libenom\">libenom<\/a> <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>Simplifies and speeds up payload creation with MSFvenom.<\/li>\n<\/ul>\n<\/li>\n<li>metasploit<\/li>\n<li>routersploit<\/li>\n<li>sharp meter <strong>*<\/strong><\/li>\n<li>shellnoob<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Forensics<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>ddrescue<\/li>\n<li>dumpzilla<\/li>\n<li>pdf-parser<\/li>\n<li>pdfid<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Hardening<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>dex2jar<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Information Gathering<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>enum4linux<\/li>\n<li>gnmap <strong>*<\/strong><\/li>\n<li>lbd<\/li>\n<li><a href=\"https:\/\/github.com\/rebootuser\/linenum\">linenum<\/a> <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>A script for local Linux enumeration and potential privilege escalation.<\/li>\n<\/ul>\n<\/li>\n<li>maltego<\/li>\n<li><a href=\"https:\/\/github.com\/sundowndev\/phoneinfoga\">phoneinfoga<\/a> <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>An advanced tool for scanning international phone numbers.<\/li>\n<\/ul>\n<\/li>\n<li>smtp-user-enum<\/li>\n<li>subfinder<\/li>\n<li>sublist3r<\/li>\n<li>trufflehog<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Networking<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>cymothoa<\/li>\n<li>netexec<\/li>\n<li>nishang<\/li>\n<li>powersploit<\/li>\n<li>pwnat<\/li>\n<li><a href=\"https:\/\/github.com\/hood3drob1n\/reverser\">reverser<\/a> <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>Helps create a reverse shell using the method of your choice.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Reverse Engineering<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>ghidra<\/li>\n<li>jad<\/li>\n<li>javasnoop<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Scripts and Utilities<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li><a href=\"https:\/\/github.com\/screetsec\/dracnmap\">dracnmap<\/a> <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>Performs fast scanning by leveraging Nmap&#8217;s scripting engine.<\/li>\n<\/ul>\n<\/li>\n<li>ngrok<\/li>\n<li><a href=\"https:\/\/github.com\/kaklakariada\/portmapper\">portmapper<\/a> <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>Manages port mappings (port forwarding) on a router if UPnP is enabled.<\/li>\n<\/ul>\n<\/li>\n<li>ridenum<\/li>\n<li>subbrute <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>Sub-directory brute-force discovery tool.<\/li>\n<\/ul>\n<\/li>\n<li>torbridge <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>Tunnels all traffic through the Tor network.<\/li>\n<\/ul>\n<\/li>\n<li>webtrace <strong>*<\/strong><\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Sniffing &amp; Spoofing<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>mitmdump<\/li>\n<li>mitmproxy<\/li>\n<li>mitmweb<\/li>\n<li>sniffjoke<\/li>\n<li>webscarab<\/li>\n<li>zaproxy<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Stress Testing<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>goldeneye<\/li>\n<li>iaxflood<\/li>\n<li>rtpflood<\/li>\n<li>thc-ssl-dos<\/li>\n<li>udpflood <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>Does what it says on the tin.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Vulnerability Analysis<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>bed<\/li>\n<li>jsql-injection<\/li>\n<li>nuclei<\/li>\n<li>sfuzz<\/li>\n<li>sidguesser<\/li>\n<li>tnscmd10g<\/li>\n<li>unix-privesc<\/li>\n<li>xsser<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Web Applications<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li><a href=\"https:\/\/github.com\/dionach\/cmsmap\">cmsmap<\/a> <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>A CMS scanner that automates the detection of security flaws.<\/li>\n<\/ul>\n<\/li>\n<li>dirbuster<\/li>\n<li>hurl<\/li>\n<li>wpscan<\/li>\n<\/ul>\n<div class=\"markdown-heading\" dir=\"auto\">\n<p class=\"heading-element\" dir=\"auto\" tabindex=\"-1\"><strong>Wireless<\/strong><\/p>\n<\/div>\n<ul dir=\"auto\">\n<li>blueranger<\/li>\n<li><a href=\"https:\/\/github.com\/fluxionnetwork\/fluxion\">fluxion<\/a> <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>A security auditing and social engineering research tool.<\/li>\n<\/ul>\n<\/li>\n<li>wifi-honey<\/li>\n<li><a href=\"https:\/\/github.com\/silentghostx\/ht-wps-breaker\">wps-breaker<\/a> <strong>*<\/strong>\n<ul dir=\"auto\">\n<li>Extracts the WPS PIN from vulnerable routers to retrieve the password.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>Note:<\/strong> Tools marked with <strong>*<\/strong> are not present in Kali.<\/p>\n<hr \/>\n<p><strong>REFLECTIONS<\/strong><\/p>\n<p>This distribution was not meant to replace any of the traditional red teaming-focused distributions, but it is a welcome addition to the cybersecurity community&#8217;s toolkit.<\/p>\n<p>I went through the tedious process of comparing the tool lists of SnoopGod and Kali, and found 16 packages in SnoopGod that are not available in Kali.<\/p>\n<p>My recommendation to the maintainers is to increase transparency regarding their identity and the goals of the project. This will help build public trust. While there is nothing inherently wrong with the project, cybersecurity professionals need a high level of trust before they feel comfortable running an unfamiliar OS on their systems.<\/p>\n<hr \/>\n<p><strong>BONUS<\/strong><\/p>\n<p>How to add SnoopGod&#8217;s repository to Ubuntu 24.04 LTS.<\/p>\n<pre>sudo nano \/etc\/apt\/sources.list.d\/snoopgod.list<\/pre>\n<p>Add the following line.<\/p>\n<pre>deb [signed-by=\/etc\/apt\/keyrings\/snoopgod-pubkey.asc arch=amd64] https:\/\/packages.snoopgod.com noble main<\/pre>\n<p>Create the public key file.<\/p>\n<pre>sudo nano \/etc\/apt\/keyrings\/snoopgod-pubkey.asc<\/pre>\n<p>Add the following content. This is the public key used to verify the signature of SnoopGod&#8217;s repository.<\/p>\n<pre>-----BEGIN PGP PUBLIC KEY BLOCK-----\r\nmDMEZnIsOxYJKwYBBAHaRw8BAQdAXf\/+0qTAXhtceN+++R+kugh69Jw5fWtov04g\r\naLvzKrS0OVNub29wR29kIExpbnV4ICh3d3cuc25vb3Bnb2QuY29tKSA8cGFja2Fn\r\nZXNAc25vb3Bnb2QuY29tPoiTBBMWCgA7FiEEoSm+geJsv9eMZA5h\/4oakU2SPqIF\r\nAmZyLDsCGwMFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQ\/4oakU2SPqKM\r\n+gD\/aNCFF5rRWPA1EUj4AhLUMaehoPOzw1PN0U2tXpgZhbEA\/2oCDiCMqRYX4zgv\r\ndSI7QJgO45hZF7TYwZD3dYASCDULuDgEZnIsOxIKKwYBBAGXVQEFAQEHQNCfttgj\r\neXkH3INdOFH9REhVNX0fJ8kpXs2QbChcchxMAwEIB4h4BBgWCgAgFiEEoSm+geJs\r\nv9eMZA5h\/4oakU2SPqIFAmZyLDsCGwwACgkQ\/4oakU2SPqK19AD\/dIWpWpD0VV5k\r\n7rTSGf8t7tGDvWuTtI3TS5j3hI8jtlQBALRxrgRIezH8rPyGLeIeWZYnLQQu32jk\r\nV6rvhAR+CxoP\r\n=+hep\r\n-----END PGP PUBLIC KEY BLOCK-----\r\n<\/pre>\n<p>Update the package list from the newly added repository.<\/p>\n<pre>sudo apt update<\/pre>\n<p>To install one of the exclusive tools:<\/p>\n<pre>sudo apt install &lt;PACKAGE_NAME&gt;<\/pre>\n<p>Also worth checking out is another Ubuntu LTS-based distro with a toolset tailored to cybersecurity and forensics users: CSI Linux [<a href=\"https:\/\/csilinux.com\/csi-linux-downloads\/\">Link<\/a>]. If nothing else, it is a very nice-looking environment!<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4446\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-09-24-11-02-55.png\" alt=\"\" width=\"1024\" height=\"873\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-09-24-11-02-55.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-09-24-11-02-55-300x256.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-09-24-11-02-55-768x655.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4444\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-09-24-11-05-02.png\" alt=\"\" width=\"1280\" height=\"905\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-09-24-11-05-02.png 1280w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-09-24-11-05-02-300x212.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-09-24-11-05-02-1024x724.png 1024w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2024\/08\/Screenshot-from-2024-09-24-11-05-02-768x543.png 768w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kali and Parrot are not the only Linux distributions for red teams, but they are [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,4],"tags":[],"class_list":["post-4357","post","type-post","status-publish","format-standard","hentry","category-hacking","category-linux"],"_links":{"self":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/4357","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4357"}],"version-history":[{"count":13,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/4357\/revisions"}],"predecessor-version":[{"id":5621,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/4357\/revisions\/5621"}],"wp:attachment":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4357"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4357"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4357"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}