Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
area51 — The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return. | Kitploit
ツール/GitHubGitHub/thoropass-public/area51
ExploitationWeb Application ExploitationAPI Security TestingInformation GatheringPenetration TestingCloud SecurityEmail Security
GitHubthoropass-public/area51

area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return.

リポジトリを見る
62942日前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
要求された言語のコンテンツは利用できません。英語版を表示しています。
AREA 51 exploit server by Thoropass

Every callback, captured.

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return.

License Runs on Cloudflare Node MCP

Getting started · Playbooks · CLI · Architecture · Documentation

⚠️ For authorized security testing and research only. A black hole is a live, internet-reachable catch-all: everything a target sends it is stored, and it serves back whatever you configure. Only point targets you have explicit, written authorization to test at it, and treat every deployment as client-data storage. Test only what you are authorized to test.


Why it exists

Half of what you find on an engagement only proves itself when something calls home. A blind SSRF. An XXE that exfiltrates over HTTP. A stored XSS firing in an admin's browser you will never see. A password-reset flow you need to read. An OAuth redirect_uri nobody validated. Each one needs infrastructure that is reachable from the target, captures everything, and answers exactly how you want.

Public interaction services give you a hostname and a log. AREA 51 gives you the whole thing, on infrastructure you own:

  • Nothing shared. Your domains, your storage, your captures. No third party holds your clients' tokens, reset links or internal hostnames.
  • Any response you like. A 302 into a metadata endpoint, a DTD, a .js beacon, a JSON stub, a 25 MB binary. Per exact path.
  • Email is a first-class capture. Every address at the domain is live, and every message is kept verbatim, headers and attachments included.
  • Your agent can drive it. An MCP server exposes recent captures and a sandboxed slice of the endpoint table, so an AI agent can inject a callback URL and confirm the hit without you in the loop.
  • One command to stand up, one to tear down. No servers, no containers, no cron host, and no bill at pentest volumes.

Released early, on purpose. AREA 51 began as an internal tool for a small, trusted team, so it favors simplicity over hardening and scale. Expect rough edges. If you hit one, open an issue with repro steps. Contributions are welcome; see CONTRIBUTING.md.

The three pieces

AREA 51 · the dashboard

Configure endpoints, read captured requests and email, manage noise filters. Locked behind single sign-on with an emailed one-time PIN.

Black Holes · your domains

Every path serves what you defined, and every request and every address at the domain is captured. Public by necessity, because targets have to reach it.

Autopilot · the agent interface

A key-authenticated MCP + REST server. Reads the last hour of callbacks, stages its own response stubs, and cannot touch anything else.

Drive it from an agent 🆕

Cool and easy: Autopilot exposes an MCP server (with a REST mirror) so an authorized AI agent can run the loop itself mid-engagement, without you in the middle of it. It reads the last hour of callbacks, stages its own response stub under the fenced /-/* namespace, and confirms the hit. Every operator gets their own API key, and it is sandboxed: it can never read your files, or any endpoint outside /-/. → Autopilot internals

What it looks like

AREA 51 Home Endpoints
Captured requests Captured email

What you can do with it

ツールをダウンロード