Back to updates
New releaseJul 30, 2026

xalgorix v4.5.106

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Share
Xalgorix — AI Autonomous Penetration Testing Platform

Go License Platform Hosted GitHub stars GitHub forks GitHub release

Ask DeepWiki

Xalgorix — Open-source AI pentester that proves vulnerabilities

Most scanners detect. Xalgorix proves. An autonomous LLM agent works a full pentest methodology, then an independent verifier re-exploits every finding before it's reported — so you get proof, not a pile of maybes to triage. Self-hosted, private, and bring-your-own-LLM. Built in Go + TypeScript.

🚀 Quick Start · 💡 Why Xalgorix · ✨ Features · 🎯 Use Cases · ☁️ Hosted Cloud · 📖 Docs


🎬 Launch Overview

Xalgorix Open Source — Autonomous AI Pentesting & Exploit Verification (launch overview video)

▶️ Watch the 50-second launch video — Xalgorix in action: autonomous scanning and exploit-verified findings in under a minute.


📸 Screenshots

🖥️ Self-hosted dashboard — runs locally on 127.0.0.1:9137

Overview dashboardScan detailFindings
Xalgorix overview dashboardXalgorix scan detailXalgorix findings

☁️ Hosted cloud dashboard — the fully managed version at www.xalgorix.com

Xalgorix hosted cloud dashboard showing security score, vulnerability trends, remediation metrics, and open issues by category

🤝 Sponsors

Thanks to Swiftproxy for sponsoring Xalgorix.

Swiftproxy sponsors Xalgorix — residential proxies for authorized testing across locations

Your app can behave differently depending on where a request comes from. For Xalgorix users checking their own applications across regions, Swiftproxy offers location targeting to review regional behavior and sticky sessions to help keep a consistent IP during a test session. It supports HTTP(S) and SOCKS5, the same proxy protocols Xalgorix supports.

Residential proxies from $0.70/GB. Free testing is available, and Xalgorix users get 10% off with code PROXY90.

Explore Swiftproxy and request a free test →


🚀 Quick Start

Install (one line):

curl -sSL https://www.xalgorix.com/install | bash

This downloads the prebuilt binary for your platform (Linux or macOS, amd64/arm64) from the latest release. Then run the interactive setup wizard:

xalgorix --setup

Choose your provider, confirm a model, and enter the API key when prompted. For best results, use a current frontier model with strong reasoning, long-context performance, and reliable tool calling—such as the latest capable GPT, Claude, or Gemini model available to you. Smaller or local models remain supported, but may require more supervision during long autonomous scans. Xalgorix stores the key privately in ~/.xalgorix.env (mode 0600) and can launch the dashboard for you. Local Ollama needs no API key.

If you choose not to launch immediately, start later with xalgorix --web and open http://127.0.0.1:9137. You can change providers or advanced options at any time under Settings → LLM, or rerun xalgorix --setup.

Or run with Docker — batteries included, no toolchain needed:

docker run --rm -p 9137:9137 \
  --privileged \
  -v xalgorix-data:/data \
  xalgord/xalgorix:latest

--privileged gives the toolset the same host-like access it has when run natively as root. Docker's default sandbox drops capabilities (like NET_ADMIN) and applies a seccomp filter, which breaks low-level tools (iptables/route changes, ARP-spoof/MITM, tun/tap VPNs, ptrace-based debuggers, masscan interface tuning). Since an image can't grant itself these, they must be set at run time. The container is a disposable, network-isolated scanning sandbox running as root — privileged is the intended posture; never expose the dashboard publicly without auth. Prefer least-privilege? Swap --privileged for --cap-add=NET_ADMIN --cap-add=NET_RAW --cap-add=SYS_PTRACE --security-opt seccomp=unconfined.

Open http://localhost:9137. You don't need an LLM key to start — the dashboard launches without one; set the model + API key under Settings → LLM (it persists to the /data volume). If you don't pass XALGORIX_USERNAME/XALGORIX_PASSWORD, a random admin password is generated and printed to the container logs on first run.

Machine-to-machine API access — give automation (your own backend, CI, scripts) a dedicated Authorization: Bearer token instead of dashboard credentials: set XALGORIX_API_TOKEN (or XALGORIX_API_TOKENS for a comma-separated rotation set). Machine tokens authorize /api/* routes and the scan-event WebSocket only — never the dashboard UI or operator-only settings routes — never create browser sessions, never interact with the dashboard login rate limiter, and are matched against stored SHA-256 digests with constant-time comparison. The human dashboard login (XALGORIX_USERNAME + XALGORIX_PASSWORD_HASH) keeps working unchanged alongside them.

Easiest — Docker Compose (maps the port + a persistent volume for you):

curl -sSLO https://raw.githubusercontent.com/xalgorix/xalgorix/main/docker-compose.yml
docker compose up -d
docker compose logs -f   # shows the generated admin password on first start

Categories