gobuster
Directory/file/DNS brute-forcing
How to use it
Project documentation lists gobuster for the Zebbern Kali MCP MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), then check which tools your installed version makes available. Tool availability can depend on configuration and credentials. A server handshake does not verify this tool’s behavior. See the full listing for setup details.
Install Zebbern Kali MCP
docker run -d -p 5000:5000 --name zebbern-kali zebbern-kali-mcpOther tools in Zebbern Kali MCP (39)
Attack surface mapping
Subdomain discovery via various sources
AD privilege escalation framework
AD Certificate Services (ADCS) exploitation
Coerce Windows authentication
Command injection exploitation
XSS scanning and exploitation
SpoolService abuse for relay attacks
Web content scanner
WinRM shell with upload/download
Fast web fuzzer
DNS reconnaissance
Advanced SQL injection detection
Group Managed Service Account password dumper
GPU-accelerated hash cracking
HTTP probing and technology detection
Network login brute-forcer
John the Ripper password cracker
Web crawler (v1.1.0 pre-built binary)
Kerberos relay and delegation abuse
LDAP domain information dumper
CIDR range manipulation
High-speed port scanner
High-performance DNS resolver
Full Metasploit Framework
Primary SMB/LDAP/WinRM tool (replaces crackmapexec)
Web server vulnerability scanner
Port scanning, service/version detection, NSE scripts
Template-based vulnerability scanner
NTLM relay coercion via EFS RPC
Shadow Credentials attack tool
LLMNR/NBT-NS/MDNS poisoner
Automated SQL injection
SSL/TLS configuration analysis
Passive subdomain discovery
Subdomain takeover checking
Fetch URLs from the Wayback Machine
WinRM command execution
WordPress vulnerability scanner