Web application vulnerability scanning sidekick. Powered by Nuclei web templates (XSS, SQLi, SSRF, IDOR, auth bypass, exposed panels), CVE enrichment, MITRE ATT&CK mapping, and a built-in crawler. Takes a domain, discovers endpoints, scans with web-focused Nuclei templates, enriches with NVD CVE data, outputs a pentest-ready report. CLI-native. No GUI, no Java, no enterprise price tag.
๐ท๏ธ
Built-in Crawler
Takes a domain, recursively discovers endpoints, forms, APIs and JS references before scanning.
โก
Nuclei Web Templates
XSS, SQLi, SSRF, IDOR, auth bypass, exposed admin panels โ web-focused template set curated for pentests.
๐
CVE Enrichment
Matches detected software versions against NVD CVE data โ surfaces exploitable web component vulnerabilities.
๐ก๏ธ
MITRE ATT&CK Mapping
Each finding mapped to ATT&CK tactics and techniques โ ready for red team reporting.
๐
Auth Bypass Testing
Tests login endpoints, JWT handling, session fixation, and insecure direct object references automatically.
๐
Pentest-Ready Report
Structured HTML/JSON output with CVSS scores, evidence screenshots, and remediation guidance.