Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
NeuroSploit — AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and tool receipts. | Kitploit
Tools/GitHubGitHub/joasasantos/neurosploit
Penetration Testing FrameworksReconnaissanceVulnerability ScannersStatic Code Analysis (SAST)ExploitationAPI Security TestingWeb SecurityPenetration TestingCloud SecurityMisconfigurationRed TeamingAI Security
GitHubjoasasantos/neurosploit

NeuroSploit

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and tool receipts.

The upstream repository was not found during the latest Kitploit update check. This listing remains available for reference, but it has been removed from search results.
1.3k315244 days agoReviewed by Kitploit
Repository Deleted

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🧠 NeuroSploit v4.2.2

Stars Forks Issues Last commit

Autonomous, multi-model penetration-testing harness — Rust, CLI-only.
by Joas A Santos & Red Team Leaders

⭐ If this is useful, star the repo — it helps a lot.

📖 New here? Read the full Tutorial & User Guide → — every mode, flag, config and example explained. Version-by-version changes live in RELEASE.md.


NeuroSploit turns a URL, a source repository, a running app, or a host/IP into an autonomous security engagement. A Rust harness (tokio) drives a pool of LLMs — via API key or local subscription (Claude Code / Codex / Gemini / Grok) — recons the target, intelligently selects only the agents that match the discovered surface, runs them in parallel, chains findings into deeper impact, and validates every claim by cross-model voting + tool-receipt grounding before reporting. It ships 479 markdown agents and a Mission Control TUI.

Engagement modes

ModeCommandWhat it does
Black-boxneurosploit run <url>recon → select → exploit → vote → report
White-boxneurosploit whitebox <repo>source/SAST review (file:line evidence)
Grey-boxneurosploit greybox <repo> --url <app>code review + live exploitation together
Host/Infraneurosploit host <ip> --creds creds.yamlLinux / Windows / AD and cloud (AWS/GCP/Azure) testing
AI / LLM red-teamneurosploit aitest <ai-url>jailbreaks & prompt injection + OWASP LLM Top 10 / MCP against a live AI agent
AI Skills / n8nneurosploit skills <file|folder>white-box audit of Skill/plugin & n8n workflow definitions
Mobile / Binaryneurosploit mobile <app.apk|app.ipa|binary>reverse-engineer a local artifact: RASP, root/JB, pinning, anti-debug, obfuscation, secrets (Ghidra headless / MobSF / Frida)
Containerneurosploit container <image:tag>scan an OCI image for vulnerable packages, exposed secrets, misconfig + emit an SBOM (SPDX/CycloneDX) via trivy/grype/syft
Mission Controlneurosploit tui <url>live TUI panels + composer during the run
Interactiveneurosploitpersistent REPL session (resumes per project)

Highlights

New in v4.2.2 — free, LLM-directed exploration: an exploit agent's named class is a starting point, not a cage — it maps what the app actually does and reports any class it can prove, with authentication / identity (login, signup, password reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target and business-logic / multi-step flows pursued on its own judgment; agent selection now covers the surface instead of collapsing into one family. WAF-aware User-Agent (/ua browser) uses a realistic browser UA for accuracy behind a CDN while keeping attribution in the X-NeuroSploit-Scan header. Importable engagement configs: /authorize <hosts…> sets the whole scope in one line (no bug-bounty program needed), /scope-file <yaml> imports scope and target/models/focus/classes from one file; /class idor,sqli,xss,ssrf focuses a run on vuln classes. Plus PoC/evidence files synthesized from recorded evidence even on the API-key path (empty pocs/·evidence/ fixed), model-refusal detection (a declined technique is reported as such, not a parse error), and version strings read from the build so they never go stale.

Also in v4.2.x — SARIF 2.1.0 export: every run now writes report.sarif next to the Markdown/JSON/HTML/PDF, and neurosploit sarif <run> (re)emits it on demand, so findings drop straight into GitHub / Azure DevOps code-scanning as severity-coloured, CWE-linked alerts (also exposed over MCP). Plus stronger cross-object reference mining in the chaining loop — the engine harvests every object identifier it sees (ids, UUIDs, tokens, emails) into a reference pool and substitutes them across identities and endpoints, the core of reliable BOLA / IDOR / mass-assignment discovery.

Also a deep Active Directory suite: 25+ host/infra skills and 7 multi-stage AD chains covering the full kill chain — initial access, enumeration (BloodHound), Kerberoasting/AS-REP, NTLM relay + coercion (PetitPotam/PrinterBug), delegation abuse (unconstrained/constrained/RBCD + S4U), AD CS (ESC1-ESC13), MSSQL linked-server pivoting, DCSync, cross-forest trust abuse (SID history/trust keys), and persistence (detect-and-report). Lockout- and state-aware, benign-proof-only.

And a vulnerability-research mode (whitebox --research / greybox --research, REPL /research, or natural language): hand it a source repo and it hunts a NOVEL, CVE-reportable bug — pins the version/commit, researches known CVEs/advisories (SECURITY.md, CHANGELOG, GHSA, NVD, git history) to de-duplicate, does patch-diff variant analysis (incomplete-fix bypasses, sibling sinks, reintroductions), and gates strictly on novelty. 6 research skills.

New in v4.2.0 — binary / APK / IPA testing: a new mobile mode analyses a local artifact with 12 reverse-engineering skills (static binary triage, APK/IPA static analysis, RASP & anti-tamper mapping, root/jailbreak, TLS pinning, anti-debug, obfuscation deobfuscation, integrity/tamper checks, hardcoded-secret extraction, insecure storage, traffic analysis) driven by Ghidra headless, MobSF, Frida and apktool/jadx. Plus NeuroSploit as an MCP server (neurosploit mcp), a pluggable decision backend (TypeSafe or local Laya), context tool-discovery (AD/web/cloud/exploitation), and CVE→PoC sourcing (searchsploit/Exploit-DB/GitHub, compile & run).