An AI engine that lives inside your proxy. It reads every packet, reasons over the application's attack surface, and writes its own exploits — autonomously, at line rate.
| parameter | weakness |
|---|---|
| from | id-corpus (known user id) |
| to | idor — can transfer to anyone |
| amount | race condition — double-spend |
| Bearer | JWT — claim escalation |
Every request, every response, every header and cookie — captured and indexed. Filter by status, method, host. Replay anything, anywhere.
Proxy, scanner, repeater, intruder, race engine and an AI agent — the same file, on your machine, no account.
HTTP/1.1, HTTP/2, HTTP/3 and WebSocket through one MITM engine.
Active and passive checks for SQLi, XSS, SSRF, smuggling and more.
Hand-edit and replay any captured request, byte for byte.
Sniper, pitchfork, cluster-bomb and battering-ram attack modes.
Single-packet attacks that beat check-then-act windows.
Coherent browser fingerprints and anti-bot challenge execution.
Drive the whole toolkit from any MCP client.
Sandboxed WASM scanner modules compiled from community code.
Prepaid by the month — no auto-renewal, no enterprise upsell. Community is free forever.
the offensive bundle · every platform
Community €0 — free forever, no account needed
no auto-renewal · 7-day trial, no card
Community is free forever. No account, no email, no card.