Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
vulnhawk — AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby. | Kitploit
Tools/GitHubGitHub/momenbasel/vulnhawk
Static AnalysisVulnerability ScannersCode AnalysisWeb Application ExploitationAPI Security TestingPenetration TestingCloud SecurityDevSecOpsSecret DetectionMisconfigurationAI Security
7916303 months agoReviewed by Kitploit
GitHub
momenbasel/vulnhawk

vulnhawk

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

View RepositoryWebsite

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

VulnHawk

AI-powered code security scanner that finds vulnerabilities Semgrep and CodeQL miss.

PyPI  GitHub Marketplace  License  Stars

Quick Start • GitHub Action • Comparison • Languages • FAQ


The Problem

Traditional SAST tools rely on pattern matching and AST rules. They excel at catching known vulnerability patterns, but they fundamentally cannot reason about intent.

If your API has 20 endpoints and 19 of them verify authorization before acting on a resource, Semgrep has no way to flag the one that doesn't - because there is no pattern to match against. The vulnerability is the absence of a pattern.

The Solution

VulnHawk analyzes code with AI, and for every piece of code it examines, it includes related code from elsewhere in your codebase as context. This enrichment step lets the AI compare how similar components handle security - and spot the one that doesn't.

VulnHawk Demo


Quick Start

pip install vulnhawk

Choose a backend:

# Claude Code CLI - FREE for subscribers (recommended)
vulnhawk scan ./src -b claude-code

# Codex CLI - FREE for ChatGPT Pro/Plus subscribers
vulnhawk scan ./src -b codex

# Claude API
export ANTHROPIC_API_KEY=sk-ant-...
vulnhawk scan ./src

# OpenAI API
vulnhawk scan ./src -b openai -m gpt-4o

# Ollama - free, local, fully private
vulnhawk scan ./src -b ollama -m llama3.1

No config files. No rules to write. No database to build.

Claude Code and Codex backends are free for users with existing subscriptions. VulnHawk pipes prompts through your local CLI, so there are no additional API costs.


VulnHawk vs Other SAST Tools

CapabilityVulnHawkSemgrepCodeQLSnyk CodeCheckmarxSonarQube
Detection methodAI reasoningAST patternsQL data flowML + rulesPatterns + flowPatterns
Business logic flawsYesNoLimitedLimitedLimitedNo
Cross-file contextAutomaticCustom rulesCustom queriesPartialPaid tierLimited
Setup complexityZero configRule configDB build + QLConfig fileComplexServer setup
Custom rules requiredNoYes (YAML)Yes (QL)PartialYesYes
Context-aware fixesYesGenericGenericGenericGenericGeneric
Local / private modeOllamaYesYesNoNoSelf-hosted
CI/CD integration1-line ActionActionActionActionPluginPlugin
SARIF input (chain tools)YesNoNoNoNoNo
PricingFree*Free / PaidFree / PaidFree / $$$$$$$$Free / $$$

*Free with Claude Code, Codex CLI, or Ollama. API backends cost ~$0.50-$2.00 per scan.

What VulnHawk finds that others cannot

Vulnerability classWhy rule-based tools miss it
Missing authorization on 1-of-N endpointsNo pattern to match - the bug is the absence of a check
IDOR / BOLARequires understanding that the user ID in the JWT should match the ID in the URL
Payment amount manipulationBusiness logic - the amount field shouldn't be trusted from the client
Inconsistent input validation5 handlers sanitize, the 6th doesn't - needs cross-file comparison
Stored input misuseInput saved safely, but eval()'d or raw-SQL'd 3 files away
Race conditions in state updatesConcurrent balance modifications without locking

Recommended tool combination

VulnHawk is designed as a complementary layer, not a replacement:

LayerToolPurpose
1SemgrepFast, deterministic gatekeeping on known-bad patterns
2CodeQLDeep taint tracking across complex call chains
3VulnHawkBusiness logic, auth gaps, IDOR, and inconsistencies rules can't express

Usage

Scan modes

vulnhawk scan ./src                      # Full scan (default)
vulnhawk scan ./src --mode auth          # Auth bypass, missing checks, session flaws
vulnhawk scan ./src --mode injection     # SQLi, command injection, SSTI, XSS
vulnhawk scan ./src --mode secrets       # Hardcoded keys, tokens, passwords
vulnhawk scan ./src --mode config        # Debug mode, permissive CORS, insecure cookies
vulnhawk scan ./src --mode crypto        # Weak hashing, hardcoded keys, bad RNG

Output formats

vulnhawk scan ./src -o json -f results.json        # JSON
vulnhawk scan ./src -o sarif -f results.sarif       # SARIF (GitHub Code Scanning)
vulnhawk scan ./src -o markdown -f report.md        # Markdown report

Severity filter

vulnhawk scan ./src --severity high      # Critical + High only
vulnhawk scan ./src --severity info      # Everything

SARIF input - chain with other tools

Feed Semgrep, CodeQL, or any SARIF-producing tool's output into VulnHawk. It uses those findings as additional context to validate, expand, and chain them into deeper vulnerabilities.

# Run Semgrep first, then enrich with VulnHawk
semgrep --config auto ./src -o semgrep.sarif --sarif
vulnhawk scan ./src --sarif-input semgrep.sarif

What this enables:

  • Validates whether other tools' findings are real or false positives
  • Discovers related vulnerabilities near flagged locations
  • Builds multi-step attack chains connecting findings across tools
  • Checks whether suggested fixes address the actual root cause

Dry run

vulnhawk info ./src    # Preview files, chunks, and language breakdown

GitHub Action

VulnHawk runs as a baseline scan on your default branch and incrementally on every pull request.

Recommended setup

name: VulnHawk Security Scan
on:
  push:
    branches: [main, master]
  pull_request:

permissions:
  security-events: write
  contents: read

jobs:
  vulnhawk:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: momenbasel/vulnhawk@main
        with:
          target: '.'
          backend: 'claude-code'
          claude-code-oauth-token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
          severity: 'medium'
          fail-on-findings: 'true'

Findings are automatically uploaded to GitHub's Security > Code Scanning tab via SARIF.

Backend options

BackendConfiguration
Claude Code (free)
backend: 'claude-code'
claude-code-oauth-token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}

Get your token: claude config get oauth_token

Codex (free)
Download Tool