← All cheat sheets

SPARTA

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

SPARTA (Network Infrastructure Penetration Testing Tool) is a
GUI-based network infrastructure penetration testing tool that
automates scanning and enumeration. It integrates nmap, hydra,
nikto, and other tools into a unified interface.

NOTE: SPARTA has been superseded by Legion (its fork).

LAUNCHING#

sparta                           # Launch GUI
sudo sparta                      # Launch with root privileges

WORKFLOW#

# 1. Add target scope (IP/range/CIDR)
# 2. SPARTA automatically runs nmap stage scan
# 3. Review discovered hosts and services
# 4. Right-click services for targeted actions
# 5. Run brute force, enumeration, or exploits
# 6. Review results in organized tabs

SCANNING#

# Stage 1: Quick nmap scan (common ports)
nmap -sV -O --top-ports 1000 <target>

# Stage 2: Full TCP scan
nmap -sV -O -p- <target>

# Stage 3: UDP scan
nmap -sU --top-ports 200 <target>

# Custom scan: Right-click host → Run nmap scan

AUTOMATED ACTIONS#

# SPARTA automatically runs tools based on discovered services:

# Port 21 (FTP):
# - Anonymous login check
# - FTP banner grabbing

# Port 22 (SSH):
# - SSH version detection
# - Hydra brute force (optional)

# Port 25 (SMTP):
# - SMTP user enumeration
# - Banner grabbing

# Port 80/443 (HTTP/HTTPS):
# - Nikto web vulnerability scan
# - Directory brute force
# - Screenshot capture
# - robots.txt retrieval

# Port 139/445 (SMB):
# - enum4linux enumeration
# - smbclient share listing
# - nbtscan

# Port 161 (SNMP):
# - snmpcheck enumeration
# - Community string testing

# Port 3306 (MySQL):
# - MySQL version detection
# - Hydra brute force

BRUTE FORCE#

# Right-click service → Brute force
# Uses Hydra with configurable wordlists
# Supported protocols:
# SSH, FTP, Telnet, HTTP, SMB, MySQL, PostgreSQL, VNC, RDP

GUI TABS#

# Services    - Discovered services per host
# Scripts     - Running/completed tool scripts
# Information - Detailed enumeration results
# Notes       - Manual notes per host
# Brute       - Brute force results

CONFIGURATION#

# Config file: sparta.conf
# Settings:
# - Scan stages and nmap arguments
# - Tool paths and arguments
# - Brute force wordlists
# - Automated actions per service
# - Screenshot tools

KEYBOARD SHORTCUTS#

# Ctrl+N       - New project
# Ctrl+O       - Open project
# Ctrl+S       - Save project

EXAMPLES#

# Basic workflow:
# 1. File → Add host(s) to scope
# 2. Enter: 192.168.1.0/24
# 3. Wait for nmap stage scans
# 4. Click host to see services
# 5. Right-click service → Run tool
# 6. Review results in tabs

ALTERNATIVES#

# Legion (SPARTA fork, actively maintained)
# - Same concept, updated codebase
# - Additional features and bug fixes

NOTES#

- GUI tool (Python/Qt)
- Requires root for SYN scans
- Integrates: nmap, hydra, nikto, enum4linux, nbtscan, etc.
- Projects saved as files for later review
- Automates repetitive enumeration tasks
- Screenshot feature captures web pages
- Legacy tool - consider using Legion instead