# NeuroSploit v3.6.8 — Release Notes **Release Date:** August 2026 **Codename:** Chain & Exploit **License:** MIT **Credits:** Joas A Santos & Red Team Leaders ## v3.6.8 — Auth resilience, circuit breaker, Ollama error handling, empty-evidence validation ### Auth Resilience & Circuit Breaker (NEW) - **`is_auth_failure()` detector.** New function recognises OAuth token revocation (401), session expiry, invalid/revoked API keys, and "not logged in" errors from subscription CLIs. Distinct from `is_exhaustion()` (quota/rate-limit) — auth failures are non-recoverable without re-login or provider switch. - **Circuit breaker (3 consecutive auth failures → auto-pause).** A shared atomic counter tracks consecutive auth failures across ALL agents. After 3 failures the pool pauses the run BEFORE burning through the remaining agents on a dead token. Previously, a revoked OAuth token caused all 66+ agents to silently return 0 findings with no pause or warning. - **Auth-aware park: findings preserved, fallback offered.** When auth fails the run parks with a clear message: `⏸ authentication failed (...). Run is PAUSED — all findings so far are SAFE.` The user can `/continue openai:gpt-5.1` (or any provider) to switch and resume. All `LiveCheckpoint` findings on disk are preserved across the pause. - **No retry burn on auth failure.** `one()` returns immediately on auth errors instead of retrying 3 times against a dead token (same as quota exhaustion). - **Recon preserves probe facts on auth failure.** When model recon fails with an auth error, the HTTP probe data is still returned and the pipeline continues with probe-only intelligence instead of silently dropping everything. - **Phase tracking for auth pauses.** The REPL status line shows `paused (auth)` (distinct from `paused (quota)`) so the operator knows the root cause at a glance. ### Bugfixes - **Better Ollama/local provider error messages.** Connection-refused and timeout errors now name the provider, URL, and suggest checking if the server is running. Previously showed raw reqwest errors. - **Empty-evidence findings skip the vote and go straight to `needs-review`.** Findings with no evidence are unverifiable by the adversarial validator (which always rejects "no evidence" per its system prompt). Now they bypass the vote and are flagged for human review instead of being silently dropped. - **Single-model + vote_n=1 warning.** When only one model is configured and vote_n is 1, the pipeline emits a warning that validation is weaker (same model validates its own findings). - **JSON parse resilience for local models.** `extract_findings` now logs when a model returns text but no parseable JSON (previously silent drop — 0 findings with no diagnostic). Also auto-fixes trailing-comma JSON (`[...,]`) which small models commonly produce. - **Visible diagnostics when agents return 0 findings.** Pipeline emits the response tail so the operator can see what the model actually returned (helps debug model quality issues with local/small models). --- ## v3.6.7 Highlights - **CVE exploitation pipeline — 4 new agents.** `cve_version_fingerprint` (pin exact versions) → `cve_research_analyst` (map to NVD/GHSA, judge reachability) → `cve_poc_finder` (locate/vet/adapt a public PoC) → `cve_exploit_scripter` (write a custom exploit when none exists). Focus: actually exploiting vulns that have CVEs, not just flagging versions. - **PoCs land in the run's `pocs/` folder and are listed in the report.** Every agent writes runnable proofs to `$NEUROSPLOIT_POCS`; the report gains a **"Reproduction — PoC scripts"** section so findings replay end-to-end. - **Chaining for any primitive.** New `CHAIN_DOCTRINE` + a `chain_cve_to_rce_to_pivot` recipe turn any confirmed foothold into the next step (upload→RCE, SSRF→cloud creds, IDOR→takeover, CVE→RCE→pivot), reusing looted creds and reasoning about **business logic** — strictly non-destructive (no data loss / DB overwrite / DoS). - **`--only ` — re-test a single vulnerability.** Runs exactly the named agent(s), skipping recon selection. On `run` / `whitebox` / `greybox`; repeatable or comma/semicolon-separated. (Implements the previously-dead `pinned` allowlist.) - **White-box stays white-box.** A `WHITEBOX_DOCTRINE` keeps code agents in static source-review mode (symbolic `file:line` receipts, source→sink taint, manifest version→CVE) and blocks hallucinated live/black-box network actions; agents can emit a repro PoC. - **435 markdown agents** (was 430). **Full changelog:** https://github.com/JoasASantos/NeuroSploit/compare/v3.6.6...v3.6.7 --- # NeuroSploit v3.6.6 — Release Notes **Release Date:** August 2026 **Codename:** Local & Uncensored **License:** MIT **Credits:** Joas A Santos & Red Team Leaders ## Highlights - **Local, uncensored & CPU-only — new `llamacpp:` provider.** Drives a `llama-server` OpenAI-compatible endpoint (`localhost:8080`), **no API key**, no data off-host, CPU-only or GPU-offloaded. Override with `LLAMACPP_BASE_URL`; `model` = the gguf you loaded (pass-through). **15 → 16 providers.** - **clippy clean under `-D warnings`** across the workspace. - **Rust CI template** — `examples/github-actions/ci.yml` (build / test / clippy) for the `neurosploit-rs/` workspace. **Full changelog:** https://github.com/JoasASantos/NeuroSploit/compare/v3.6.5...v3.6.6 --- # NeuroSploit v3.6.5 — Release Notes **Release Date:** July 2026 **Codename:** LLM Red Team **License:** MIT **Credits:** Joas A Santos & Red Team Leaders --- ## Highlights - **Human-in-the-loop validator — uncertain findings are flagged, not deleted.** The vote, receipt-grounding and adversarial-refute passes no longer silently drop borderline findings. A finding is now **`confirmed`** (passed all three) or **`needs-review`** (partial vote, no machine-verifiable receipt, or failed refute) — kept with a reason so a human makes the final call. Only zero-support noise is dropped. Every report separates the two buckets. - **Richer reports in Markdown + JSON (alongside PDF/HTML).** Every run writes `report.md`, `report.json`, `report.html` and the Typst **PDF** via `report::write_all`, now with a full structure: **asset identification** (names the product/organisation + tech stack — e.g. "OWASP Juice Shop [Angular, Express]" — not just the URL), a **written executive summary**, a **vulnerability table** (severity · status · CWE/OWASP), a **test-accounts section** (from the vault, to delete after), detailed confirmed findings, a separate **needs-review** section, and a **written conclusion**. The asset is identified during the run: a deterministic probe extracts the page title, fingerprints the stack, matches known apps, and reads a business/brand hint (`og:site_name` / `application-name` / copyright) into `meta.json`. - **Sharper agents on modern SPA/REST apps (Juice-Shop-class).** When recon detects a JS SPA and/or a REST/GraphQL API, a methodology directive gives agents concrete **directions** (not an answer key) on how to hunt each class: map the API from the JS bundle, brute hidden client routes (`#/administration`, score board), SQLi login-bypass/UNION, JWT alg:none & RS→HS forging, IDOR/BOLA + mass-assignment, path-traversal + poison-null-byte file access, forgot-password/OSINT, exposed `/metrics`, DOM XSS, NoSQL, SSRF, redirect-allowlist bypass, XXE, coupon crypto. Agents still discover and PROVE each issue live. - **More robust RL.** Per-agent reward is now shaped: strong for a **confirmed** finding (severity × confidence), small for a **needs-review** lead, slight decay for running but finding nothing — so agents that reliably land confirmed high-severity bugs rise to the top of selection over runs (persisted). - **LLM red-teaming — jailbreaks & prompt injection across scenarios.** 12 new AI agents (AI category 18 → **30**; total 417 → **429**) that adversarially test a live AI system (LLM app / AI agent / MCP server) the way [hackagent.dev](https://hackagent.dev)-style tooling does. Each agent runs an **attacker → LLM-judge loop**: capture the baseline refusal, apply the technique across several scenarios/variants, then judge with an explicit criterion whether the guardrail was *actually* bypassed — proving it with a **benign, redacted** prompt+response receipt (never real harm). - **Jailbreak techniques:** `AdvPrefix` (adversarial prefix/suffix), `PAIR` (automated iterative refinement), `TAP` (tree-of-attacks with pruning), `Crescendo` (multi-turn escalation), many-shot, persona/DAN roleplay, encoding/obfuscation (base64/ROT13/zero-width/low-resource-language), refusal-suppression / prefix injection. - **Prompt-injection & hijacking scenarios:** direct injection, **indirect** injection via RAG doc / web page / email / tool output, **goal hijacking**, agentic **tool/function-call abuse**, and **system-prompt / secret exfiltration**. - Runs via `neurosploit aitest ` (or the REPL **AI Agents & LLMs** onboarding scope). A new `REDTEAM_DOCTRINE` steers every AI test through the baseline→technique→judge loop. Complements the existing OWASP LLM Top 10 (2025), MCP and Skills/n8n agents. Authorized, non-destructive. - **New models.** Added **Claude Opus 5** and **Claude Sonnet 5** (Anthropic), and a new **Moonshot AI (Kimi)** provider with **Kimi K3** / K2 (`moonshot:kimi-k3`, `MOONSHOT_API_KEY`, OpenAI-compatible) — **15 providers** total. Use any of them as a finder or in the validator voting panel, e.g. `--model anthropic:claude-opus-5 --model moonshot:kimi-k3`. - **Liveness preflight.** Before recon, the run confirms the target actually answers HTTP; a dead host prints `✗ target unreachable — … is DOWN` and aborts instead of running agents against nothing. A reachable host prints `✓ target is UP`. - **Account registration & form analysis (+1 agent → total 430).** A new `account_registration_and_forms` agent lets NeuroSploit reach the authenticated surface on its own: it analyzes the app's forms (the deterministic probe now extracts each `
`'s action/method/fields/kind/CSRF) and creates a benign test account with **curl** or the **Playwright browser** when no creds are given. When no `--auth`/creds are set on a web run, this agent is **run first automatically** so the authenticated surface is always attempted (and visible). - **Anti-flood guardrail (hard):** at most **2 accounts per engagement**, never looping/scripting/batching the register endpoint or flooding the database — reuse the account made; a test needing many sign-ups is reported as a lead and stopped. Enforced in `SAFETY_DOCTRINE` (all flows) and the agent. - **Credential vault:** every generated credential is saved to **`.neurosploit/vault/.json`** for the operator to consult; secrets are **masked in the report**. The report adds a **"Test accounts created (DELETE after)"** cleanup section listing each account and how it was created. - **Finding labels:** findings are tagged **`auth_context`** (authenticated/unauthenticated) and **`account`** (which test user/role proved it) — so grey-box shows which findings needed a login, and black-box records how the user was created. - **Disposable email (opt-in, off by default):** `/tempmail on` (or `temp_email`) lets agents use the free **mail.tm** API (no key) to read a registration confirmation code; off by default, a required confirmation is reported as a blocker rather than bypassed. ## Previously in v3.6.4 - **Fix ([#33](https://github.com/JoasASantos/NeuroSploit/issues/33)): white-box findings were silently dropped from the report.** The grounding gate — the anti-hallucination step that demotes any claim lacking a receipt — was running in **empirical** mode for *every* engagement. Empirical grounding looks for raw tool output (HTTP responses, error oracles, shell receipts), which a **SAST finding never has**: its receipt is a `file:line` reference into the reviewed source. So white-box (and skills/n8n audit) findings that had *passed* the n-model vote were then demoted as "receipt missing" and never reported. Grounding is now **mode-aware**: - **Symbolic** — white-box SAST & skills audits: a `file:line` (or `file:section`) reference into the reviewed source, or a quote of code that appears in it, IS the receipt. No live target needed. - **Empirical** — black-box / host / AI endpoints: evidence must resemble raw tool output (unchanged behaviour). - **Either** — grey-box: a source citation OR a tool receipt grounds a finding. The symbolic check is run against the reviewed **source corpus** (not the model transcript), and falls back to a structural `file:line` + code-quote check when the corpus isn't available, so a well-formed SAST finding is never dropped on a technicality. Covered by unit tests (including a regression test for #33). --- ## Previously in v3.6.3 - **Interrupted runs are resumable.** When a run is cut off (terminal closed, Ctrl-C, crash, SSH drop), its findings were already checkpointed live and recovered as a run on the next launch. Now `/continue` (or `/resume`) also **relaunches the engagement** on the same target and **carries those findings forward** — steering agents to widen coverage and chain from what was already found instead of re-reporting it. The offer is shown at launch right under the recovery line. A fresh `/run` supersedes the pending resume. - **Browsing no longer kills a live run.** Opening `/results`, `/finding` or `/report` while a run streams used to let the background printer and the full-screen picker fight over the terminal — pressing Ctrl-C to escape could take the whole process down. Live output is now paused while any picker is open (still captured in `/logs`) and restored when you exit, so browsing findings mid-run is safe. - Findings merge (dedup by title + endpoint) across the interrupted and continued runs, and the merged report is rewritten to include everything. --- ## Previously in v3.6.2 - **Codex now streams live, tool-by-tool.** `codex exec` is driven with `--json` and its JSONL event stream is parsed into the same categorized activity feed as Claude Code: every shell command it runs (`exec:`), file edit (`edit:`), MCP tool call (`tool:`), web search (`net:`) and token count appears the moment it happens. A long, intense recon (subfinder → httpx → katana → nmap …) is no longer a silent black box — you watch each tool execute. - **`/logs` and `/status` now capture what each agent actually runs.** The activity feed previously dropped the per-agent tool events; it now keeps the actionable ones (commands, network, files, findings) and only filters long model reasoning and token telemetry. `/logs` shows the real command trail; `/status` `last:` shows a true sign-of-life. - Failed internal commands surface as `exec: (exit N) ` instead of silently vanishing, and Codex auth/rate errors are still detected from stderr. --- ## Previously in v3.6.1 - **Added the GPT-5.6 model line** (OpenAI / ChatGPT): `openai:gpt-5.6-sol` (frontier / default), `openai:gpt-5.6-terra` (balanced), and `openai:gpt-5.6-luna` (fast & affordable) — alongside the existing GPT-5.x, Claude (incl. Sonnet 5), Grok 4.5 and the rest of the provider pool. - Everything from v3.6.0 (AI/LLM/MCP/Skills testing, n8n audit, onboarding wizard, intense multi-round recon) carries forward unchanged. --- # NeuroSploit v3.6.0 — Release Notes **Release Date:** July 2026 **Codename:** AI / LLM / Agent / MCP / Skills Security **License:** MIT **Credits:** Joas A Santos & Red Team Leaders --- ## TL;DR v3.6.0 turns NeuroSploit into an **AI-security** platform: red-team live AI agents / LLM apps / MCP endpoints against the **OWASP Top 10 for LLM Apps (2025)** + MCP threats, audit **AI Skills/plugins and exported n8n workflows** white-box, and pick your engagement type up front in a new **onboarding wizard**. Library **417** agents. Adds **Claude Sonnet 5** and **Grok 4.5**. ## AI / LLM / Agent / MCP / Skills testing (+18 agents, `agents_md/ai/`) - **Live AI red-team** — `neurosploit aitest ` (or the `ai` scope in the REPL). Point it at an AI agent / LLM chat or API / MCP endpoint; agents cover the full **OWASP LLM Top 10 (2025)**: prompt injection (direct + indirect), jailbreaks, system-prompt leakage, sensitive-info disclosure, improper output handling, excessive agency, RAG/embedding weaknesses, unbounded consumption, supply chain, misinformation — hackagent.dev-style, with the exact prompt + the model's response as proof. Plus **MCP risks**: tool poisoning / description injection, excessive permissions & confused-deputy, unsafe tool execution. - **Skills / plugins / n8n audit (white-box)** — `neurosploit skills ` (or the `skills` scope). Audit a single `.md`/`.json` or a whole folder: - **Skills/plugins**: insecure design, secrets in manifests, over-broad tools, injection surface, missing human-in-the-loop. - **n8n exported workflows**: hardcoded credentials, unsafe Code/Function nodes (RCE/SSRF), unauthenticated webhooks, expression injection, over-scoped credentials — **and a dedicated AI/LLM-node audit** (prompt injection, data leakage to the provider, excessive agency, insecure output handling). ## Onboarding wizard - On first launch (or `/onboard`), a guided menu asks **what you're testing** — **Web & API · Infrastructure & Networks · Cloud · AI Agents & LLMs · AI Skills/Plugins/n8n** — then the box type (black/white/grey for web) and the minimal setup, so a plain `/run` does the right thing. Scope shown in `/show`. ## Intense, multi-round recon - Recon is no longer a single quick pass. **`deep_recon`** runs an initial deep enumeration then **follow-up expansion rounds** that chase what the previous round found (new subdomains/hosts, unmapped endpoints, promising paths/params), converging when nothing new appears. - Agents are told to **install the tools they need** (apt/pip/go/npm/cargo) — subfinder/amass, httpx, gau/waybackurls/katana/hakrawler, gf, arjun/paramspider, ffuf/feroxbuster, nuclei, nmap/rustscan, dnsx, linkfinder, whatweb, nikto, testssl — and chain them (subfinder→httpx→katana/gau→gf→ffuf). - **`/recon <1-4>`** (REPL) and **`--recon <1-4>`** (CLI) set the intensity: 1 quick · 2 standard · 3 deep (default) · 4 exhaustive — more rounds + wider enumeration at higher levels. Best on Kali; degrades to curl/nc if installs fail. ## Models - Added **`anthropic:claude-sonnet-5`** and **`xai:grok-4.5`**. --- # NeuroSploit v3.5.6 — Release Notes **Release Date:** July 2026 **Codename:** Bug-Bounty Corpus & EOL Hunting **License:** MIT **Credits:** Joas A Santos & Red Team Leaders --- ## TL;DR v3.5.6 folds real public bug-bounty knowledge into the agent (methodology meta-agent + corpus-grounded techniques), adds a full **2FA/MFA bypass** agent (one of the most-reported classes in the writeup corpus), and ships the EOL / end-of-support hunting and decision-driven exploitation from the 3.5.5 line. Library **399** agents. ## Highlights - **Bug-bounty methodology, grounded in the real corpus.** The `bugbounty_methodology` meta-agent is validated against the actual technique distribution in public writeup collections (Awesome-Bugbounty-Writeups, bug-bounty-reference) — XSS, RCE, CSRF, SSRF, Clickjacking, SQLi, CORS, LFI, **2FA bypass**, subdomain/account takeover, OAuth, race, **SAML** — and now includes explicit **2FA/MFA bypass** and **SAML/SSO** sections. - **New `twofa_bypass_techniques` agent** — the full 2FA-bypass playbook (missing rate-limit brute, code reuse/no-expiry, response manipulation, step skipping, null/default codes, backup/remember-me, race, disable-2FA IDOR, SSO side door), with a control-vs-bypass proof and no account lockout. - **KingOfBugBounty-style recon** in `RECON_SYS` (subdomains, wayback, gf, param mining, content discovery, classic exposures) — from 3.5.5, degrades to installed tools. - Carries the 3.5.5 features: EOL/end-of-support agents, decision-driven deep exploitation, multi-role `/auth`, browser-driven SPA testing, global install. - **README**: Trendshift badge added. --- # NeuroSploit v3.5.5 — Release Notes **Release Date:** July 2026 **Codename:** Cloud Testing, REPL Navigation & Deeper Recon **License:** MIT **Credits:** Joas A Santos & Red Team Leaders --- ## TL;DR v3.5.5 adds **cloud infrastructure testing** (AWS / GCP / Azure) with first-class credential connection, **27 new agents** (17 cloud + 10 misconfig/CVE/PoC/rate- limit → library **375**), a much more capable and navigable **REPL** (idle guardrail, multi-target, results browser), **deeper recon** (downloads & analyzes JS, request/response differentials, smart nuclei), **Burp/ZAP proxy** support, a **PoC** workspace, a strict **data-safety/PII guardrail**, and a fix for garbled interactive line-editing. ## Cloud testing - **+17 cloud agents.** AWS, GCP and Azure specialists in `agents_md/infra/`: IAM/RBAC privilege escalation, storage exposure (S3 / GCS / Blob), compute & network exposure + IMDS, secrets (Secrets Manager / Secret Manager / Key Vault), service-account & service-principal abuse, and Entra ID enumeration — plus a multi-cloud footprint/identity recon agent. Read-only-first, non-destructive. - **Connect cloud credentials via `creds.yaml`** (`aws:`, `gcp:`, `azure:` blocks). The harness exports the right env vars so `aws` / `gcloud` / `az` pick them up automatically, and tells the agents how to authenticate & what to enumerate: - **AWS** — `access_key_id`/`secret_access_key`[/`session_token`]/`region`, or a `profile`. - **GCP** — a service-account JSON (`service_account_json`, path recommended) → `GOOGLE_APPLICATION_CREDENTIALS` + project. - **Azure** — a **service principal** (`tenant_id`/`client_id`/`client_secret`/ `subscription_id`) → `az login --service-principal`. - Secrets are never written to disk beyond your `creds.yaml`; inline GCP JSON is materialized to a temp file only to satisfy the SDK/CLI. ## REPL — navigation & control - **Idle guardrail — `/timeout `.** If no NEW finding lands within the window, the run soft-stops and validates what was found (`/timeout 1` = 1 min, `10` = 10 min, `60` = 1 hour, `0` = off). **Default 5 min.** - **Multiple targets — `/target url1,url2,url3`.** A comma-separated list; `/run` tests them **sequentially** (a queue auto-advances to the next when the current finishes) — one report per URL. - **`/results` navigation browser** (interactive): pick a **target/run** → pick a **vulnerability** → see full detail; **Esc steps back a level** (vuln → target → back to the live session). - **`/report` selection**: with multiple runs, choose which report to open from a menu. - **`/chain `** (attack-chain depth), **`/agents list`** (library category counts incl. infra/cloud); **`/show`** now shows chain-depth, idle-stop and enabled integrations. - **Fix:** the interactive prompt no longer embeds ANSI/newline, so line editing (typing, backspace, history, cursor, multiline) is no longer garbled in a real terminal (the readline prompt is plain; color is applied via the highlighter). ## Deeper recon & analysis (agent prompts) - **Deterministic HTTP probe (native, `harness::probe`).** Before the model recon, the harness performs a **real** request/response analysis of the target and injects the observed facts into recon so agent-selection and exploitation decisions are grounded in evidence (more robust — works even when the model's recon is weak): status & redirect, `Server`/`X-Powered-By`/content-type, the 6 security headers (present/missing), **cookie flags** (HttpOnly/Secure/SameSite), **CORS reflection** test (arbitrary Origin + credentials), tech fingerprint, linked scripts, form count, a **404 baseline** for soft-404 differentials, and a few high-signal paths (`/robots.txt`, `/.git/config`, `/.env`, …). Best-effort (never fatal), honors the identifying User-Agent and the Burp/ZAP proxy. - **RECON_SYS** now crawls pages/params/headers/cookies, **downloads the linked JavaScript and analyzes it** (API endpoints, hidden params, GraphQL, secrets / keys / tokens, `sourceMappingURL` → recover original source), fingerprints **exact** stack versions, and does response-differential analysis; richer JSON schema (`js_findings`, `secrets`, `hosts`, …). - **tool_doctrine** adds JS-analysis (linkfinder / gau / katana + grep for endpoints/secrets/source-maps) and request/response-analysis guidance (status, all headers, Set-Cookie flags, timing/length differentials, auth-vs-anon and valid-vs-invalid comparisons) — applied to both recon and exploitation. ## Exploitation depth, safety & Burp - **+10 exploitation agents.** Absurd-misconfig hunters (exposed `.git`/`.env`/ backups, debug/actuator endpoints, default creds, directory listing, exposed ops dashboards, permissive CORS, verbose errors), a **CVE Hunter** (fingerprint → correlate → safe PoC), a **PoC Developer** (writes runnable exploit scripts), and a **Rate-Limit / Anti-Automation** tester. - **Data-safety / PII guardrail** injected into every exploit/chain/host prompt: no modifying, deleting, exfiltrating data or changing state without explicit permission; on PII, prove with a single **masked** sample + a count — never dump. When unsure an action is safe, don't do it. - **Smart nuclei in recon** — fingerprint first, then run nuclei on **targeted** templates/tags/CVE ids with rate/timeouts (fast, never a blind full scan). - **Burp/ZAP proxy** — `/proxy ` (or `/burp`, default `:8080`) in the REPL, or the `NEUROSPLOIT_PROXY` env var. Agents route curl through it (`--proxy … -k`) so you can inspect/replay traffic in Burp Suite while the test runs. - **PoC workspace** — each run gets a `pocs/` directory (`$NEUROSPLOIT_POCS`); agents save custom, reproducible exploit scripts there and cite them as evidence. - **Tool download** (authorized) — agents may `git clone` a specific public PoC/ exploit repo or download a scanner when needed (reputable/pinned, reviewed). - **Rate-limit testing** is a first-class control check (small non-disruptive burst → look for 429/lockout/Retry-After), never a DoS. ## Bug-bounty methodology & recon tricks - **Bug-bounty methodology meta-agent** (`agents_md/meta/bugbounty_methodology.md`, library **398**) — distilled, high-signal techniques from public writeups (HackerOne Hacktivity, KingOfBugBounty tips, Awesome-Bugbounty-Writeups, bug-bounty-reference and top hunters' reports): the hunter *mindset* plus the concrete per-class tricks (IDOR/BOLA, 403 bypass, account takeover, SSRF→cloud, business logic/race, cache poisoning, subdomain takeover, GraphQL) and how to chain and report them — depth and proof over scanner breadth. - **Recon upgraded with KingOfBugBounty-style tricks** — `RECON_SYS` now expands scope (subdomains via crt.sh/subfinder/amass → httpx), harvests historical URLs (gau/waybackurls/katana), filters with `gf` patterns, mines params (arjun + JS/wayback), content-discovers (ffuf/feroxbuster), and checks classic exposures (.git/.env/swagger/actuator, dangling CNAMEs). Degrades gracefully to what's installed; prioritises auth/reset/payment/upload/admin/export flows. ## EOL / End-of-Support exploitation - **+8 EOL agents** (library **397**) that detect components past their vendor end-of-life / end-of-support window and exploit the CVEs that pile up once patches stop — high-value because the bugs are public and unfixed. Each pins the **exact version**, checks it against public EOL data (endoflife.date) + CVE feeds, and proves exploitability with a **safe** PoC: - `eol_stack_detection` — fingerprint every EOL component across the stack. - `eol_runtime_exploitation` — EOL PHP/Python/Node/Java/.NET/Ruby runtimes. - `eol_framework_exploitation` — EOL Struts/Spring/Rails/Django/Laravel/AngularJS. - `eol_cms_exploitation` — EOL WordPress/Drupal/Joomla/Magento core & plugins. - `eol_client_library` — EOL front-end libs (jQuery/AngularJS/Lodash/…). - `eol_webserver_exploitation` — EOL Apache/nginx/IIS/Tomcat/JBoss/WebLogic. - `eol_os_service` — EOL OS & services (old OpenSSH/OpenSSL/Samba, SMBv1). - `eol_tls_protocol` — deprecated TLS (SSLv3/1.0/1.1) & legacy protocols. ## Decision-driven deep exploitation - **DECISION doctrine** injected into every exploit/grey/chain prompt: analyse responses FIRST and let the evidence pick the technique; **map & connect routes** (one endpoint's output feeds another's input) and hunt sensitive flows (auth, reset, payment, upload, admin, export); **mine parameters** (query/body/header/cookie + hidden ones from JS/source maps) and test the fitting attack per param; **mock realistic data** to reach deeper logic (never real PII); **exploit the authenticated surface** after logging in and compare each role; **build PoCs** when a proof needs an artifact; and **bypass controls** (verb/path/encoding/header tricks) on anything blocked. - **Multi-role `/auth`** — set several identities in the REPL: `/auth admin ` · `/auth user ` (Bearer/cookie/API-key; a bare token becomes `Authorization: Bearer …`). With ≥2 roles the run gets the access-control directive (IDOR/BOLA/BFLA/privesc, authorized-vs-unauthorized proof) and tests both scenarios. (Same as the `creds.yaml` role blocks, now one command away.) - **+6 decision agents** (library **389**): `param_miner`, `endpoint_flow_linker`, `authenticated_surface_exploit`, `clickjacking_poc` (writes a framing HTML PoC), `csrf_poc` (writes an auto-submitting HTML PoC), and `access_control_bypass`. ## Browser-driven testing & SPA agents (Juice Shop-ready) - **Agents now actively drive the browser while testing.** The tool doctrine was strengthened: on JS-heavy / SPA (Angular/React/Vue) targets the agent MUST use the **Playwright MCP** browser (render, wait, read the live DOM, click client-side routes, watch the network to discover the real REST/GraphQL API, prove client-side issues with a screenshot). When no MCP is present, it uses the **Playwright CLI** (writes & runs a small `playwright` script / `npx playwright screenshot`) to render and capture the app's XHR/fetch traffic — **complementing curl**, which only sees the empty shell. - **Deterministic probe detects SPAs** (``, `ng-version`, near-empty body + linked scripts → Angular/React/Vue/SPA) and flags in recon that the browser is required — so the SPA agents get selected. - **+8 SPA/API agents** (library **383**): SPA API & route discovery, hidden-admin / client-side access control, login SQLi bypass, SPA DOM XSS, API BOLA via sequential IDs, privileged registration / mass assignment, JWT forgery & verification bypass, and SPA business-logic abuse — tuned for apps like OWASP Juice Shop. (Existing NoSQLi/GraphQL/JWT/mass-assignment agents complement them.) ## Subscription login check & Playwright MCP fixes - **Subscription login preflight.** Before a `--subscription` run, the harness checks that the local CLI (claude/codex/…) is **installed and logged in** and prints a clear warning if not — instead of the run silently coming back with 0 findings. (Not logged in → the CLI returns empty instantly, which was the usual cause of "it found nothing / MCP didn't execute".) - **Playwright MCP now installs the browser.** `ensure_playwright_mcp` also runs `npx playwright install chromium` (best-effort; skip with `NEUROSPLOIT_SKIP_BROWSER_INSTALL=1`) so the first browser action doesn't fail/hang with a missing Chromium. - **Codex MCP wiring fixed.** Codex takes MCP servers as `-c mcp_servers.*` TOML overrides (not a config-file path); the harness now injects our Playwright server correctly, so MCP works on Codex too — not just Claude. - **"No tool activity" diagnostic.** If a subscription+MCP run performs zero browser/tool actions, the REPL warns that the CLI likely isn't logged in or the MCP didn't start. ## Multi-role auth & access-control testing - **Named identities in `creds.yaml`** for IDOR / BOLA / BFLA / privilege-escalation testing. Define two or more roles and the agent authenticates as each and tests **cross-role access** (control vs unauthorized request): ```yaml admin: jwt: eyJ... # or header:/cookie:/apikey:/login+username+password user: apikey: abc123 # → X-Api-Key: abc123 victim: cookie: "session=..." ``` Supported per role: `jwt`, `header` (raw), `cookie`, `apikey`, or a `login`/`username`/`password` self-login. With ≥2 roles the harness injects an access-control directive (capture one role's object IDs/functions, attempt them as another role, prove authorized-vs-denied) under the data-safety guardrail. ## Attribution & identification (anti-plagiarism) - **Identifying User-Agent** on every request — default `NeuroSploit/ (authorized security assessment; +github…)`, plus an `X-NeuroSploit-Scan` header. Change it with **`/ua `** (REPL) or the `NEUROSPLOIT_UA` env var; the run banner shows it. - **Attribution stamped into every finding** ("Identified and validated by NeuroSploit — multi-model adversarial validation …") so provenance travels with the finding across the report, `findings.json` and any copy — in the traffic, the finding text, and the report footer, so the work can't be silently re-badged. ## Notes - Additive/back-compatible. Provider count is 14 (Azure OpenAI added in v3.5.2). See the README "Cloud credentials" section for a full `creds.yaml` example. --- # NeuroSploit v3.5.4 — Release Notes **Release Date:** July 2026 **Codename:** Robust Attack Chaining & False-Positive Reduction **License:** MIT **Credits:** Joas A Santos & Red Team Leaders --- ## TL;DR v3.5.4 makes NeuroSploit both **deeper** and **more precise**: a real multi-round **post-exploitation attack-chaining** engine that expands each foothold in new directions, plus stronger **false-positive** controls so what it reports is trustworthy. ## Attack chaining (robust, decision-driven) Replaces the old single-shot chainer with **`attack_chain()`** — an iterative, per-foothold pivot engine: - **Per-foothold decisions.** Each round takes the newest confirmed footholds (best-first, capped per round) and, for **each one**, an agent decides which directions to expand and proves new impact: **post-exploitation** (loot creds/keys/config/source), **credential reuse**, **privilege escalation** (horizontal & vertical), **lateral movement** to adjacent services/hosts, **data exfiltration**, and **new attack surface** the foothold exposes. - **Loot carried forward.** Credentials/tokens/hosts/endpoints discovered in one round are passed to later rounds and reused (agent returns `{"findings":[...],"loot":[...]}`), so the engine genuinely pivots in new directions instead of re-testing the same spot. - **No pivoting off false positives.** Each round's new findings are validated before they become the next round's footholds. - **Convergence.** Runs up to `chain_depth` rounds **or** stops when a round finds nothing new (loop-until-dry). - **Control.** New `RunConfig.chain_depth` (default **2**) and a `--chain-depth` flag on every engagement command (`0` disables). ## False-positive reduction - **Robust verdict parsing** (`pool::parse_verdict`) — whitespace-insensitive, checks explicit rejection first, counts only explicit confirmations; ambiguous replies are *not* counted as confirmed. Replaces the fragile exact-JSON / loose-`yes` matching. - **Severity-aware quorum** (`pool::quorum_confirmed`) — **High/Critical now need ≥2 validators AND ≥2/3 agreement** (a single vote can no longer confirm a Critical); lower severities need a strict majority. Single-model panels fall back to majority so they aren't nuked. - **Adversarial refute pass** — every confirmed High/Critical is re-examined by a skeptical panel that assumes false-positive; findings that can't withstand a majority of skeptics are dropped. - **Stronger validator prompt** with an explicit false-positive checklist (reflected-not-executed, version/banner guesses, self-XSS, error-as-injection, thin evidence, inflated severity). ## Notes - Additive and back-compatible; defaults keep behavior sensible if you change nothing. Unit tests cover verdict parsing, quorum, and report-hygiene logic. --- # NeuroSploit v3.5.3 — Release Notes **Release Date:** June 2026 **Codename:** Integrations (GitHub · GitLab · Jira) **License:** MIT **Credits:** Joas A Santos & Red Team Leaders --- ## TL;DR v3.5.3 plugs NeuroSploit into your SDLC: review **private** GitHub/GitLab repos and **Pull Requests**, **watch** a branch and re-review on every commit, and open a **Jira card per finding** — all toggleable via a new `/integrations` command. ## Highlights - **GitHub integration** - **Private repos**: when enabled, `whitebox` / `greybox --repo` / `tui --repo` inject your `GITHUB_TOKEN` into the clone URL (token never printed/stored). - **`neurosploit pr `** — clones the **PR head** (`refs/pull/N/head`), runs a white-box review, optionally **posts a summary comment** back on the PR (`--comment`) and/or **opens Jira cards** (`--jira`). - **`neurosploit watch --branch --interval `** — polls the branch and runs a white-box review **each time a new commit lands**. - **GitLab integration** — private clone (token-injected) for `whitebox`/`greybox` against `gitlab.com` or a self-hosted base. - **Jira integration** — `--jira` on any engagement (or `pr`/`watch`) opens **one card per finding** (summary, severity, CVSS, CWE, location, PoC, evidence, remediation) in your project via the Jira REST API. - **`/integrations` (REPL) + `neurosploit integrations` (CLI)** — `show`, `enable`/`disable `, and `setup ` (interactive). Config persists to `/.neurosploit/integrations.json`. **Secrets are never stored** — only the env-var *name* is saved; values come from the environment at use time. - New harness module `integrations` + app commands `pr` / `watch` / `integrations`, plus a `--jira` flag on `run` / `whitebox`. ## Setup Step-by-step for tokens, scopes and configuration is in **[TUTORIAL-INTEGRATION.md](TUTORIAL-INTEGRATION.md)** and summarized in the README. ## Notes - Additive and back-compatible: all existing modes/flags are unchanged; if no integration is enabled the behavior is identical to v3.5.2. - Tokens use env vars: `GITHUB_TOKEN`, `GITLAB_TOKEN`, `JIRA_EMAIL` + `JIRA_API_TOKEN` (names configurable per integration). --- # NeuroSploit v3.5.2 — Release Notes **Release Date:** June 2026 **Codename:** Exploitation Depth & Report Hygiene **License:** MIT **Credits:** Joas A Santos & Red Team Leaders --- ## TL;DR v3.5.2 hard-codes the discipline that separates a great pentest from a noisy one — distilled from reviewing real AI-pentest output that kept stopping at *"exposed"* instead of *"exploited"*. The engine now pushes every exposure to demonstrated impact, **chains** findings, decodes/fingerprints artifacts and correlates CVEs, audits tokens, and keeps the final report honest (deduplicated and severity-calibrated). ## Highlights - **DEPTH doctrine (exploit, don't just expose).** A new doctrine is injected into every exploitation prompt (black/grey/chain): any info-disclosure, exposed service/catalog/WSDL, leaked credential/token, or reachable dev host **must be USED** before it can be a finding — call it, decode it, log in, hit the dev host. If it was only observed, it's reported as a **lead**, not a confirmed High/Critical. - **Finding chaining.** Reuse any session/JWT/cookie/credential obtained in one step across all other modules; pivot access into IDOR/privesc/exfil and report the **chain**, not isolated parts (e.g. captcha-bypass→admin JWT→authenticated surface; enum + no-rate-limit→password spraying). - **Decode & fingerprint → CVE.** Decode opaque tokens/paths (base64/JSON/marshal) and pin exact library/gem/plugin/CMS versions, then correlate to known CVEs and attempt a safe PoC. - **Token auditor.** JWT alg-confusion (RS→HS), `alg:none`, kid/jku injection, real signature verification, **weak HS256 secret cracking**, and token lifecycle (logout/expiry/refresh). - **Report-hygiene & depth pass (deterministic, in the harness).** After validation the run now: - **calibrates severity to proven impact** — an unproven High/Critical (hedged language, no payload, thin evidence) is capped to Medium and re-titled "(potential)"; - flags **"exposed → exploited" gaps** — exposures on a host with no actual exploit get an advisory to go use them; - advises **consolidating hygiene** classes (headers/cookies/TLS/HSTS/ clickjacking/disclosure) repeated across many assets into ONE finding with an affected-asset table, instead of inflating the count one-per-host. - **5 new doctrine meta-agents** (`agents_md/meta/`): `exploit_depth_doctrine`, `finding_chainer`, `artifact_decoder`, `token_auditor`, `report_calibrator` (meta agents 17 → 22; total library 343 → 348). - **Source from a GitHub URL.** `whitebox` / `greybox --repo` (and the REPL `/repo`) now accept a **git URL** (`https://github.com/owner/repo[.git]`) or an `owner/repo` shorthand — the repo is cloned (shallow) into `/repos/` and reviewed automatically, no manual `git clone` needed: ```bash neurosploit whitebox https://github.com/digininja/DVWA \ --subscription --model anthropic:claude-opus-4-8 -v ``` - **Azure OpenAI provider** (resolves #21). OpenAI-compatible: set `AZURE_OPENAI_ENDPOINT` (+ optional `AZURE_OPENAI_API_VERSION`, default `2024-10-21`) and `AZURE_OPENAI_API_KEY`, then `--model azure:` (the model name is your Azure *deployment* name; auth via the `api-key` header). - **`GOOGLE_API_KEY` alias for Gemini** (resolves #25 confusion). Gemini's API path reads `GEMINI_API_KEY`, and now also accepts `GOOGLE_API_KEY` (Google's standard env var) when the former is unset. Local providers (ollama/litellm) still need **no** key at all. ## Notes - Pure-additive and back-compatible: existing modes, REPL, TUI, pause/continue, crash-recovery and reports are unchanged. The hygiene pass only annotates and down-calibrates unproven severities — it never invents or drops findings. - New unit tests cover the calibration and depth-audit logic (`harness::hygiene`). --- # NeuroSploit v3.5.1 — Release Notes **Release Date:** June 2026 **Codename:** Interactive POMDP Harness **License:** MIT **Credits:** Joas A Santos & Red Team Leaders --- ## TL;DR The 3.5.x line turns the Rust harness into a full **interactive REPL** (Claude Code / Codex / Cursor-CLI style) on top of the multi-model engine: pick models with arrow-keys, configure API keys per provider, set target/repo/auth/creds and free-text instructions that steer the agents, then `/run` engagements **in the background** while you keep typing. v3.5.1 adds a **POMDP belief spine** with anti-hallucination grounding ("no claim without a tool receipt"), **infra/host** testing (IP + SSH + Windows/AD) with Linux/Windows/AD agents, **attack-chain agents**, a **Mission-Control TUI**, structured **Typst** reports, and resilient run control (live checkpointing, pause-on-quota, instant stop). ## Highlights - **Interactive REPL** (`neurosploit` with no subcommand): real line editing (history ↑/↓, Ctrl-A/E/K, multiline), Tab-completion of `/commands` and `@filesystem-paths` (Claude-Code-style file menu), arrow-key model multi-select, per-provider API-key config, and a live context bar (`model · cwd · mode▸target`). - **Engagement modes**: **black-box** (`run`), **white-box** SAST (`whitebox`, set `/repo`), **grey-box** (`greybox`, `/repo` + `/target`), **host/infra** (`/target ` + `/creds` for SSH / Windows / AD), plus the **TUI** dashboard. - **POMDP belief state** (`belief.rs`, `pomdp.rs`): a property-graph with probabilities + Bayesian update + Shannon-entropy uncertainty, a value-of-information planner, and a **grounding gate** (`grounding.rs`, `may_assert`) — findings must carry an empirical/symbolic **tool receipt**. - **Infra / credentials** (`creds.rs`): multi-block YAML (jwt/header/cookie, HTTP login, SSH, Windows/AD); real automated login; Linux/Windows/AD agents. - **Attack-chain agents**: sqli→rce→lpe, ssrf→aws, upload→lfi→rce, and more — injected as chain recipes during exploitation. - **App-stack & CVE hunting**: IIS/.NET (tilde shortname, WebDAV, ViewState), CMS (WordPress/Joomla/Drupal), app-server consoles, known-CVE exploitation. - **13 providers** incl. **LiteLLM** proxy and Gemini/xAI alongside the existing OpenAI-compatible set; **subscription mode** drives local agentic CLIs (claude/codex/gemini/grok) via stream-json. - **Mission-Control TUI** (`ratatui`): concurrent activity/findings/targets panels with a non-blocking composer active during the run. - **Structured Typst report**: executive summary, vulnerability-summary table, and per-finding sections (criticality, CVSS, OWASP/CWE, PoC, evidence, remediation) + an attack-graph / kill-chain mapping (OWASP/CWE/MITRE). - **Per-project persistence** (`.neurosploit/`, no database): `session.json`, `runs.json`, `history.txt` — resumes automatically on reopen. ## Run control (new in 3.5.1) - **Background `/run`** with a live progress bar, severity-colored findings, and the full `file://` report URL on completion/stop. - **3-way `/stop`**: **[1]** validate findings so far → report · **[2]** raw report **now** without validating · **[3]** discard. Raw/discard abort in-flight agents immediately (running CLI children are killed via `kill_on_drop`); validate soft-stops so the validator still runs. - **Crash/quit recovery**: every finding is checkpointed live to `.neurosploit/active_run.json`; an interrupted run is recovered into `/runs` on the next launch, so `/results`, `/finding` and `/report` keep working. - **Pause-on-exhaustion**: when all models are rate-limited / out of quota the run **parks** (state kept) and prints `⏸ token/quota exhausted … PAUSED`. Resume with **`/continue`** when your quota renews, or switch with **`/model `** (or the `/model` selector) then **`/continue`**. - **Inspection**: `/results` (live findings), `/finding` (pick one → full command + PoC + evidence), `/expand` / Ctrl-O (full untruncated commands), `/status`, `/diff`, `/retest`. ## Usage ```bash cd neurosploit-rs && cargo build --release ./target/release/neurosploit # interactive REPL ./target/release/neurosploit run http://target -v --model anthropic:claude-opus-4-8 ./target/release/neurosploit whitebox --repo /path/to/code # white-box SAST ./target/release/neurosploit greybox --repo /path --target http://target # grey-box ./target/release/neurosploit run --creds creds.yaml # host / infra ./target/release/neurosploit tui http://target --subscription --mcp ``` Cross-platform install (Linux / macOS / Windows, x64 + arm64) via `setup.sh` and `install.ps1`. See **README.md** and **TUTORIAL.md** for the full walkthrough. --- # NeuroSploit v3.4.0 — Release Notes **Release Date:** June 2026 **Codename:** Rust Multi-Model Harness **License:** MIT --- ## TL;DR A new **Rust harness** (`neurosploit-rs/`) re-implements the autonomous runtime as a single, fast binary built on `tokio` + `axum`. It drives a **pool of LLM models** with concurrency limits, **provider failover**, and **N-model validator voting** — multiple models must independently agree a finding is real before it is reported — then serves its own solid web dashboard. It reuses the existing `agents_md/` library (213 agents) unchanged. ## Highlights - **`neurosploit-rs/` cargo workspace**: `harness` lib crate + `neurosploit` binary. `cargo build --release` → one static-ish binary. - **Multi-model pool** (`pool.rs`): bounded concurrency + automatic **failover** across providers; the same panel is reused as the **validator voting** jury. - **Pipeline** (`pipeline.rs`): recon → parallel agent exploitation (semaphore bounded) → **N-model adversarial vote** → score → report. Streams live progress over a channel. - **11 providers / 31 models** (`models.rs`), all OpenAI-compatible: Anthropic, OpenAI, xAI, NVIDIA NIM, DeepSeek, Mistral, Qwen, Groq, Together, OpenRouter, Ollama. Models like **Qwen / DeepSeek / Llama** usable directly. - **Axum web dashboard** (`app/`): multi-model selection panel, live execution console, findings, agent browser, embedded HTML report. Single binary serves the SPA — no npm/build. - **CLI**: `neurosploit serve | run | agents | models`, plus `--offline` mode to exercise the full pipeline without any API keys. ## Usage ```bash cd neurosploit-rs && cargo build --release ./target/release/neurosploit serve # → http://127.0.0.1:8788 ./target/release/neurosploit run https://t.example \ --model anthropic:claude-opus-4-8 --model openai:gpt-5.1 --vote-n 3 ``` --- # NeuroSploit v3.3.0 — Release Notes **Release Date:** June 2026 **Codename:** Autonomous MD-Agent Engine **License:** MIT --- ## TL;DR NeuroSploit's pentest agent has been **re-modeled into an autonomous, markdown-driven engine**. You give it a URL; it composes a master prompt from a curated library of **213 markdown agents** and drives a locally-installed **agentic CLI backend** (Claude Code / Codex / Grok CLI, or a Claude subscription) to run the engagement end-to-end — with **Playwright MCP** for proof-of-execution and a **reinforcement-learning** loop that adapts agent selection across runs. The old Python orchestration was retired to `legacy/`. ## Highlights - **New engine `neurosploit_agent/`** + `./neurosploit` terminal launcher. Interactive (`./neurosploit`) or one-shot (`./neurosploit run `). - **213-agent markdown library (`agents_md/`)**: **196 vulnerability specialists** (now covering LLM/AI, cloud/K8s, modern API/auth, advanced injection, protocol smuggling, logic/crypto/supply-chain) + **17 meta-agents**. - **Meta-agents for quality**: `recon`, `exploit_validator`, `false_positive_filter`, `severity_assessor`, `impact_evaluator`, `reporter`, and `rl_feedback` — the pipeline validates and adversarially refutes every candidate before it can become a finding. - **Pluggable agentic CLI backends** with auto-detection: Claude Code, Codex, Grok CLI; **subscription mode** via Claude Code login. - **Playwright MCP** wired in (`.mcp.json`) so agents prove client-side execution (XSS/CSTI) and capture DOM/network/screenshots instead of trusting reflection. - **Reinforcement learning** (`neurosploit_agent/rl.py` + `meta/rl_feedback.md`): bounded per-agent weights with per-tech-stack affinity, persisted to `data/rl_state.json`. - **Latest model registry** (`neurosploit_agent/models.py`): Anthropic Claude 4.x, OpenAI, xAI Grok, Gemini, OpenRouter, Ollama, and **NVIDIA NIM** (PR #28, OpenAI-compatible `integrate.api.nvidia.com`, `nvapi-` keys). - **Data-driven agent builder** `scripts/build_agents.py` for extending the library without boilerplate. ## Breaking changes - The monolithic `neurosploit.py` orchestrator and Python agent classes moved to `legacy/` and are no longer the supported entrypoint. Use `./neurosploit`. - Primary agent library moved from `prompts/agents/` to `agents_md/` (originals preserved; meta/role prompts split into `agents_md/meta/`). ## Upgrade notes 1. Install at least one agentic CLI: Claude Code, Codex, or Grok CLI. 2. `npx` (Node) is required for Playwright MCP. 3. Copy `.env.example` → `.env`; set a provider key (or use Claude subscription). 4. `./neurosploit backends` to confirm detection, then `./neurosploit`. --- # NeuroSploit v3.0.0 — Release Notes **Release Date:** February 2026 **Codename:** Autonomous Pentester **License:** MIT --- ## Overview NeuroSploit v3 is a ground-up overhaul of the AI-powered penetration testing platform. This release transforms the tool from a scanner into an autonomous pentesting agent — capable of reasoning, adapting strategy in real-time, chaining exploits, validating findings with anti-hallucination safeguards, and executing tools inside isolated Kali Linux containers. ### By the Numbers | Metric | Count | |--------|-------| | Vulnerability types supported | 100 | | Payload libraries | 107 | | Total payloads | 477+ | | Kali sandbox tools | 55 | | Backend core modules | 63 Python files | | Backend core code | 37,546 lines | | Autonomous agent | 7,592 lines | | AI decision prompts | 100 (per-vuln-type) | | Anti-hallucination prompts | 12 composable templates | | Proof-of-execution rules | 100 (per-vuln-type) | | Known CVE signatures | 400 | | EOL version checks | 19 | | WAF signatures | 16 | | WAF bypass techniques | 12 | | Exploit chain rules | 10+ | | Frontend pages | 14 | | API endpoints | 111+ | | LLM providers supported | 6 | --- ## Architecture ``` +---------------------+ | React/TypeScript | | Frontend (14p) | +----------+----------+ | WebSocket + REST | +----------v----------+ | FastAPI Backend | | 14 API routers | +----------+----------+ | +---------+--------+--------+---------+ | | | | | +----v---+ +---v----+ +v------+ +v------+ +v--------+ | LLM | | Vuln | | Agent | | Kali | | Report | | Manager| | Engine | | Core | |Sandbox| | Engine | | 6 provs| | 100typ | |7592 ln| | 55 tl | | 2 fmts | +--------+ +--------+ +-------+ +-------+ +---------+ ``` **Stack:** Python 3.10+ / FastAPI / SQLAlchemy (async) / React 18 / TypeScript / Tailwind CSS / Vite / Docker --- ## Core Engine: 100 Vulnerability Types The vulnerability engine covers 100 distinct vulnerability types organized in 10 categories with dedicated testers, payloads, AI prompts, and proof-of-execution rules for each. ### Categories & Types | Category | Types | Examples | |----------|-------|---------| | **Injection** | 12 | SQLi (error, union, blind, time-based), Command Injection, SSTI, NoSQL, LDAP, XPath, Expression Language, HTTP Parameter Pollution | | **XSS** | 3 | Reflected, Stored (two-phase form+display), DOM-based | | **Authentication** | 7 | Auth Bypass, JWT Manipulation, Session Fixation, Weak Password, Default Credentials, 2FA Bypass, OAuth Misconfig | | **Authorization** | 5 | IDOR, BOLA, BFLA, Privilege Escalation, Mass Assignment, Forced Browsing | | **Client-Side** | 9 | CORS, Clickjacking, Open Redirect, DOM Clobbering, PostMessage, WebSocket Hijack, Prototype Pollution, CSS Injection, Tabnabbing | | **File Access** | 5 | LFI, RFI, Path Traversal, XXE, File Upload | | **Request Forgery** | 3 | SSRF, SSRF Cloud (AWS/GCP/Azure metadata), CSRF | | **Infrastructure** | 7 | Security Headers, SSL/TLS, HTTP Methods, Directory Listing, Debug Mode, Exposed Admin, Exposed API Docs, Insecure Cookies | | **Advanced** | 9 | Race Condition, Business Logic, Rate Limit Bypass, Type Juggling, Timing Attack, Host Header Injection, HTTP Smuggling, Cache Poisoning, CRLF | | **Data Exposure** | 6 | Sensitive Data, Information Disclosure, API Key Exposure, Source Code Disclosure, Backup Files, Version Disclosure | | **Cloud & Supply Chain** | 6 | S3 Misconfig, Cloud Metadata, Subdomain Takeover, Vulnerable Dependency, Container Escape, Serverless Misconfig | ### Injection Routing Every vulnerability type is routed to the correct injection point: - **Parameter injection** (default): SQLi, XSS, IDOR, SSRF, etc. - **Header injection**: CRLF, Host Header, HTTP Smuggling - **Body injection**: XXE - **Path injection**: Path Traversal, LFI - **Both (param + path)**: LFI, directory traversal variants ### XSS Pipeline (Reflected) The reflected XSS engine is a multi-stage pipeline: 1. **Canary probe** — unique marker per endpoint+param to detect reflection 2. **Context analysis** — 8 contexts: html_body, attribute_value, script_string, script_block, html_comment, url_context, style_context, event_handler 3. **Filter detection** — batch probe to map allowed/blocked chars, tags, events 4. **AI payload generation** — LLM generates context-aware bypass payloads 5. **Escalation payloads** — WAF/encoding bypass variants 6. **Testing** — up to 30 payloads per param with per-payload dedup 7. **Browser validation** — Playwright popup/cookie/DOM/event verification (optional) ### POST Form Support - HTML forms detected during recon with method, action, all input fields (including `