
AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and tool receipts.
Autonomous, multi-model penetration-testing harness — Rust, CLI-only.
by Joas A Santos & Red Team Leaders
⭐ If this is useful, star the repo — it helps a lot.
📖 New here? Read the full Tutorial & User Guide → — every mode, flag, config and example explained. Version-by-version changes live in RELEASE.md.
NeuroSploit turns a URL, a source repository, a running app, or a host/IP into
an autonomous security engagement. A Rust harness (tokio) drives a pool of
LLMs — via API key or local subscription (Claude Code / Codex / Gemini /
Grok) — recons the target, intelligently selects only the agents that match the
discovered surface, runs them in parallel, chains findings into deeper
impact, and validates every claim by cross-model voting + tool-receipt
grounding before reporting. It ships 479 markdown agents and a Mission
Control TUI.
| Mode | Command | What it does |
|---|---|---|
| Black-box | neurosploit run <url> | recon → select → exploit → vote → report |
| White-box | neurosploit whitebox <repo> | source/SAST review (file:line evidence) |
| Grey-box | neurosploit greybox <repo> --url <app> | code review + live exploitation together |
| Host/Infra | neurosploit host <ip> --creds creds.yaml | Linux / Windows / AD and cloud (AWS/GCP/Azure) testing |
| AI / LLM red-team | neurosploit aitest <ai-url> | jailbreaks & prompt injection + OWASP LLM Top 10 / MCP against a live AI agent |
| AI Skills / n8n | neurosploit skills <file|folder> | white-box audit of Skill/plugin & n8n workflow definitions |
| Mobile / Binary | neurosploit mobile <app.apk|app.ipa|binary> | reverse-engineer a local artifact: RASP, root/JB, pinning, anti-debug, obfuscation, secrets (Ghidra headless / MobSF / Frida) |
| Container | neurosploit container <image:tag> | scan an OCI image for vulnerable packages, exposed secrets, misconfig + emit an SBOM (SPDX/CycloneDX) via trivy/grype/syft |
| Mission Control | neurosploit tui <url> | live TUI panels + composer during the run |
| Interactive | neurosploit | persistent REPL session (resumes per project) |
New in v4.2.2 — free, LLM-directed exploration: an exploit agent's named class is a starting point, not a cage — it maps what the app actually does and reports any class it can prove, with authentication / identity (login, signup, password reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target and business-logic / multi-step flows pursued on its own judgment; agent selection now covers the surface instead of collapsing into one family. WAF-aware User-Agent (
/ua browser) uses a realistic browser UA for accuracy behind a CDN while keeping attribution in theX-NeuroSploit-Scanheader. Importable engagement configs:/authorize <hosts…>sets the whole scope in one line (no bug-bounty program needed),/scope-file <yaml>imports scope and target/models/focus/classes from one file;/class idor,sqli,xss,ssrffocuses a run on vuln classes. Plus PoC/evidence files synthesized from recorded evidence even on the API-key path (emptypocs/·evidence/fixed), model-refusal detection (a declined technique is reported as such, not a parse error), and version strings read from the build so they never go stale.Also in v4.2.x — SARIF 2.1.0 export: every run now writes
report.sarifnext to the Markdown/JSON/HTML/PDF, andneurosploit sarif <run>(re)emits it on demand, so findings drop straight into GitHub / Azure DevOps code-scanning as severity-coloured, CWE-linked alerts (also exposed over MCP). Plus stronger cross-object reference mining in the chaining loop — the engine harvests every object identifier it sees (ids, UUIDs, tokens, emails) into a reference pool and substitutes them across identities and endpoints, the core of reliable BOLA / IDOR / mass-assignment discovery.Also a deep Active Directory suite: 25+ host/infra skills and 7 multi-stage AD chains covering the full kill chain — initial access, enumeration (BloodHound), Kerberoasting/AS-REP, NTLM relay + coercion (PetitPotam/PrinterBug), delegation abuse (unconstrained/constrained/RBCD + S4U), AD CS (ESC1-ESC13), MSSQL linked-server pivoting, DCSync, cross-forest trust abuse (SID history/trust keys), and persistence (detect-and-report). Lockout- and state-aware, benign-proof-only.
And a vulnerability-research mode (
whitebox --research/greybox --research, REPL/research, or natural language): hand it a source repo and it hunts a NOVEL, CVE-reportable bug — pins the version/commit, researches known CVEs/advisories (SECURITY.md, CHANGELOG, GHSA, NVD, git history) to de-duplicate, does patch-diff variant analysis (incomplete-fix bypasses, sibling sinks, reintroductions), and gates strictly on novelty. 6 research skills.
New in v4.2.0 — binary / APK / IPA testing: a new
mobilemode analyses a local artifact with 12 reverse-engineering skills (static binary triage, APK/IPA static analysis, RASP & anti-tamper mapping, root/jailbreak, TLS pinning, anti-debug, obfuscation deobfuscation, integrity/tamper checks, hardcoded-secret extraction, insecure storage, traffic analysis) driven by Ghidra headless, MobSF, Frida and apktool/jadx. Plus NeuroSploit as an MCP server (neurosploit mcp), a pluggable decision backend (TypeSafe or local Laya), context tool-discovery (AD/web/cloud/exploitation), and CVE→PoC sourcing (searchsploit/Exploit-DB/GitHub, compile & run).