Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
xalgorix — Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript. | Kitploit
工具/GitHubGitHub/xalgord/xalgorix
ReconnaissanceVulnerability ScannersDynamic Analysis (Sandboxing)Exploit FrameworksInformation GatheringWeb SecurityPenetration TestingDevSecOpsRed TeamingAI Security
GitHubxalgord/xalgorix
8511525710小时11分前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

xalgorix

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

查看仓库网站
内容在请求的语言中不可用。显示英文版本。
Xalgorix — AI Autonomous Penetration Testing Platform

Go License Platform Hosted GitHub stars GitHub forks GitHub release

Ask DeepWiki

Xalgorix — Open-source AI pentester that proves vulnerabilities

Most scanners detect. Xalgorix proves. An autonomous LLM agent works a full pentest methodology, then an independent verifier re-exploits every finding before it's reported — so you get proof, not a pile of maybes to triage. Self-hosted, private, and bring-your-own-LLM. Built in Go + TypeScript.

🚀 Quick Start · 💡 Why Xalgorix · ✨ Features · 🎯 Use Cases · ☁️ Hosted Cloud · 📖 Docs


🎬 Launch Overview

Xalgorix Open Source — Autonomous AI Pentesting & Exploit Verification (launch overview video)

▶️ Watch the 50-second launch video — Xalgorix in action: autonomous scanning and exploit-verified findings in under a minute.


📸 Screenshots

🖥️ Self-hosted dashboard — runs locally on 127.0.0.1:9137

Overview dashboardScan detailFindings
Xalgorix overview dashboardXalgorix scan detailXalgorix findings

☁️ Hosted cloud dashboard — the fully managed version at www.xalgorix.com

Xalgorix hosted cloud dashboard showing security score, vulnerability trends, remediation metrics, and open issues by category

🤝 Sponsors

Thanks to Swiftproxy for sponsoring Xalgorix.

Swiftproxy sponsors Xalgorix — residential proxies for authorized testing across locations

Your app can behave differently depending on where a request comes from. For Xalgorix users checking their own applications across regions, Swiftproxy offers location targeting to review regional behavior and sticky sessions to help keep a consistent IP during a test session. It supports HTTP(S) and SOCKS5, the same proxy protocols Xalgorix supports.

Residential proxies from $0.70/GB. Free testing is available, and Xalgorix users get 10% off with code PROXY90.

Explore Swiftproxy and request a free test →


🚀 Quick Start

Install (one line):

curl -sSL https://www.xalgorix.com/install | bash

This downloads the prebuilt binary for your platform (Linux or macOS, amd64/arm64) from the latest release. Then run the interactive setup wizard:

xalgorix --setup

Choose your provider, confirm a model, and enter the API key when prompted. For best results, use a current frontier model with strong reasoning, long-context performance, and reliable tool calling—such as the latest capable GPT, Claude, or Gemini model available to you. Smaller or local models remain supported, but may require more supervision during long autonomous scans. Xalgorix stores the key privately in ~/.xalgorix.env (mode 0600) and can launch the dashboard for you. Local Ollama needs no API key.

If you choose not to launch immediately, start later with xalgorix --web and open http://127.0.0.1:9137. You can change providers or advanced options at any time under Settings → LLM, or rerun xalgorix --setup.

Or run with Docker — batteries included, no toolchain needed:

docker run --rm -p 9137:9137 \
  --privileged \
  -v xalgorix-data:/data \
  xalgord/xalgorix:latest

--privileged gives the toolset the same host-like access it has when run natively as root. Docker's default sandbox drops capabilities (like NET_ADMIN) and applies a seccomp filter, which breaks low-level tools (iptables/route changes, ARP-spoof/MITM, tun/tap VPNs, ptrace-based debuggers, masscan interface tuning). Since an image can't grant itself these, they must be set at run time. The container is a disposable, network-isolated scanning sandbox running as root — privileged is the intended posture; never expose the dashboard publicly without auth. Prefer least-privilege? Swap --privileged for --cap-add=NET_ADMIN --cap-add=NET_RAW --cap-add=SYS_PTRACE --security-opt seccomp=unconfined.

Open http://localhost:9137. You don't need an LLM key to start — the dashboard launches without one; set the model + API key under Settings → LLM (it persists to the /data volume). If you don't pass XALGORIX_USERNAME/XALGORIX_PASSWORD, a random admin password is generated and printed to the container logs on first run.

Machine-to-machine API access — give automation (your own backend, CI, scripts) a dedicated Authorization: Bearer token instead of dashboard credentials: set XALGORIX_API_TOKEN (or XALGORIX_API_TOKENS for a comma-separated rotation set). Machine tokens authorize /api/* routes and the scan-event WebSocket only — never the dashboard UI or operator-only settings routes — never create browser sessions, never interact with the dashboard login rate limiter, and are matched against stored SHA-256 digests with constant-time comparison. The human dashboard login (XALGORIX_USERNAME + XALGORIX_PASSWORD_HASH) keeps working unchanged alongside them.

Easiest — Docker Compose (maps the port + a persistent volume for you):

curl -sSLO https://raw.githubusercontent.com/xalgorix/xalgorix/main/docker-compose.yml
docker compose up -d
docker compose logs -f   # shows the generated admin password on first start
下载工具