
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return.
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a dashboard you control, and it gets whatever response you choose in return.
Getting started · Playbooks · CLI · Architecture · Documentation
⚠️ For authorized security testing and research only. A black hole is a live, internet-reachable catch-all: everything a target sends it is stored, and it serves back whatever you configure. Only point targets you have explicit, written authorization to test at it, and treat every deployment as client-data storage. Test only what you are authorized to test.
Half of what you find on an engagement only proves itself when something calls
home. A blind SSRF. An XXE that exfiltrates over HTTP. A stored XSS firing in an
admin's browser you will never see. A password-reset flow you need to read. An
OAuth redirect_uri nobody validated. Each one needs infrastructure that is
reachable from the target, captures everything, and answers exactly how you want.
Public interaction services give you a hostname and a log. AREA 51 gives you the whole thing, on infrastructure you own:
302 into a metadata endpoint, a DTD, a .js
beacon, a JSON stub, a 25 MB binary. Per exact path.Released early, on purpose. AREA 51 began as an internal tool for a small, trusted team, so it favors simplicity over hardening and scale. Expect rough edges. If you hit one, open an issue with repro steps. Contributions are welcome; see CONTRIBUTING.md.
|
AREA 51 · the dashboard Configure endpoints, read captured requests and email, manage noise filters. Locked behind single sign-on with an emailed one-time PIN. |
Black Holes · your domains Every path serves what you defined, and every request and every address at the domain is captured. Public by necessity, because targets have to reach it. |
Autopilot · the agent interface A key-authenticated MCP + REST server. Reads the last hour of callbacks, stages its own response stubs, and cannot touch anything else. |
Cool and easy: Autopilot exposes an MCP server (with a REST mirror) so an
authorized AI agent can run the loop itself mid-engagement, without you in the
middle of it. It reads the last hour of callbacks, stages its own response stub
under the fenced /-/* namespace, and confirms the hit. Every operator gets
their own API key, and it is sandboxed: it can never read your files, or any
endpoint outside /-/. → Autopilot internals
![]() |
![]() |
![]() |
![]() |