Loadingβ¦
Identifies this engagement in the sidebar and run history β required.
What are you testing?
Pick the engagement type β this decides which CLI subcommand runs underneath.
The application, host, or endpoint to test.
Cloned automatically if it's a GitHub URL or owner/repo shorthand.
Objective & focus
Steers what the agents prioritise and what counts as impact.
Authentication
Test as a logged-in user. Configured in the menu.
Set the action plan
Toggle specific leads to test, or leave everything off to let recon-driven auto-selection choose.
Categories start collapsed β click one to open it, or click its switch to pin every lead inside at once.
No lead matches that search.
Model
Pick a provider and model from the harness's live catalog.
Uses the API key set in Auth & Keys for this provider.
Run settings
Models that must agree before a finding is kept.
How far findings get chained into attack paths.
Deeper recon finds more surface but costs more tokens.
Reasoning budget
Optional. Left on unlimited, the run behaves exactly as it always has β full depth, no cap.
How compute is spent, not how much there is.
Hard ceiling for the run. Empty or 0 = none.
Map everything first, or chase a lead as it appears.
Requests per endpoint family (
/api/users/{id} is sampled, not enumerated).Tooling & assurance
Optional. Route through a proxy, run in a container, re-check every PoC, and frame findings against a compliance framework.
The harness and agent commands route through it. Full HTTPS interception needs one of the tools (own tunnels TLS).
Runs attack commands off the host, with the Kali toolbox. Needs docker or podman.
Additional confirmation strategy (Choice/Noul over real replays). Off runs the identical pipeline so you can compare with/without.
Maps confirmed findings onto control requirements in the report. Indicates gaps for an assessor β never a compliance verdict.
Review
Confirm before launching β this spawns the real CLI harness.
β
0 / 0 agents
| Severity | Title | Endpoint | CWE | Agent | Conf. |
|---|
No validated findings yet.
β
This session stays interactive while the engagement runs β type a command or plain instruction and press Enter.
β
| Severity | Title | Endpoint | CWE | Agent | Conf. |
|---|
No validated findings.
NeuroSploit harness
disconnected
Enter send Β· ββ history Β· Tab complete Β· Ctrl+C interrupt Β· Ctrl+L clear