← All cheat sheets

CISCO-TORCH

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Cisco Torch is a mass scanning, fingerprinting, and exploitation
tool for Cisco devices. It uses multiple protocols simultaneously
(Telnet, SSH, HTTP, SNMP, TFTP, NTP) to discover and audit Cisco
infrastructure at scale.

BASIC USAGE#

cisco-torch -A <target>          # All scanning types
cisco-torch <target>             # Default scan

OPTIONS#

cisco-torch -t <target>          # Target (IP, range, or CIDR)
cisco-torch -F <file>            # Targets from file
cisco-torch -A                   # All scanning types combined
cisco-torch -b                   # Banner grabbing
cisco-torch -f                   # Fingerprint devices
cisco-torch -g                   # HTTP config gathering
cisco-torch -j                   # TFTP config copying
cisco-torch -n                   # NTP fingerprinting
cisco-torch -s                   # SNMP scanning
cisco-torch -w                   # Cisco web interface scanning
cisco-torch -z                   # SSH scanning
cisco-torch -c                   # CDP discovery
cisco-torch -v                   # Verbose mode

SCAN TYPES#

# Banner Grabbing (-b):
cisco-torch -b <target>          # Grab Telnet/SSH banners

# Fingerprinting (-f):
cisco-torch -f <target>          # Fingerprint Cisco device type

# HTTP Scanning (-g, -w):
cisco-torch -g <target>          # HTTP config gathering
cisco-torch -w <target>          # Web interface scanning

# SNMP Scanning (-s):
cisco-torch -s <target>          # SNMP community scanning

# TFTP (-j):
cisco-torch -j <target>          # TFTP config download attempt

# NTP (-n):
cisco-torch -n <target>          # NTP information gathering

# SSH (-z):
cisco-torch -z <target>          # SSH version scanning

EXAMPLES#

# Full scan of a single device
cisco-torch -A 192.168.1.1

# Scan a subnet
cisco-torch -A 192.168.1.0/24

# Scan targets from file
cisco-torch -A -F targets.txt

# SNMP and banner grab only
cisco-torch -s -b 192.168.1.0/24

# Fingerprint and web scan
cisco-torch -f -w 10.0.0.0/24

# SSH scanning across range
cisco-torch -z 172.16.0.0/16

CONFIGURATION#

# Config file: torch.conf
# Default credentials file: passwords.txt
# SNMP community strings file: community.txt
#
# Edit these files to customize:
# - Default passwords to test
# - SNMP community strings
# - Scan timeouts
# - Thread count

INFORMATION GATHERED#

# Per device:
# - Device type (router, switch, AP)
# - IOS version
# - Hostname
# - Open services
# - SNMP community strings
# - Configuration (if accessible)
# - SSH version
# - HTTP server version
# - NTP status

NOTES#

- Perl-based tool
- Multi-threaded for fast scanning
- Can scan large networks quickly
- Uses multiple protocols simultaneously
- May trigger IDS/IPS alerts
- Can be noisy on the network
- Only for authorized security auditing
- Results help prioritize manual auditing
- Pair with Cisco Auditing Tool for deeper checks