ExploitFinder v1.7 delivers reconnaissance, crawling, fingerprinting, active testing and reporting with unified operational visibility for security teams.
Credits
Nmap · Network discovery and service intelligence
SQLMap · SQL injection validation
OWASP ZAP · DAST and attack simulation
Commix · Command injection testing
Release Notes
Enhanced Overview telemetry and confidence normalization
Improved mobile usability and responsive spacing
Scan Health metrics now propagated into report exports
AI Pentester Agents
ExploitFinder · Multi-Agent Pentest
Execution Flows
Ogni missione genera un flusso: generator → braccia in Docker → findings. Clicca una card per il grafo live.
CHECKPOINT UMANOun braccio vuole eseguire un comando pericoloso — autorizzi?
0 / 0 missioni
nessun task creato ancora — il generator sta definendo il piano
——
AGENT COMMAND
—
100%
trascina lo sfondo (o tasto destro) per muovere · rotella per zoom · doppio clic per adattare · clic su nodo per i dettagli · trascina un nodo per riposizionarlo
RILEVAMENTI
Nessun finding — il braccio non ha confermato vulnerabilità o il flusso è in corso.
AZIONILIVE
waiting for activity…
Ordina in coda — l'agente lo eseguirà alla prossima missione
AZIONI · LIVEcosa sta facendo l'agente · ordina dalla chat
REPORT
—
Nuova analisi Agent AI
Web · Smart Contract · Reverse Engineering
Pipeline dedicata: searcher scarica il sorgente (Sourcify / explorer, fallback bytecode) → installer prepara foundry + slither + mythril → coder scrive contratti di attacco e invarianti → pentester riproduce ogni finding su un fork locale con transazioni di test reali (saldi prima/dopo, hash delle tx). Caching statica: lo stesso contratto non viene ri-analizzato due volte.
Trascina qui il file oppure clicca per selezionarlo
exe · elf · bin · dll · so · jar — fino a 200 MB
Caricamento binario0%
Pipeline dedicata: SUPERVISOR pianifica → INVESTIGATOR mantiene le ipotesi con evidenze → agenti STATIC / DYNAMIC / BEHAVIOR eseguono in sandbox (rete isolata per la dinamica) → CRITIC sfida ogni ipotesi → VERIFICATION riesegue l'azione chiave per confermare. Nessuna conclusione senza evidenza verificabile.
Il modulo usa un browser vero (Chrome/Edge via playwright) con DuckDuckGo e Yandex, fa lo screenshot di ogni SERP e di ogni pagina visitata (evidenze visive stile pentest, in fondo al pannello rilevamenti) e cerca le CVE pubblicate quest'anno per i tuoi componenti. Se il browser non è installato sul server: fallback automatico su DuckDuckGo/Yandex HTML — non si rompe mai.
$
Spesa LLM
costo per agente · token cache-aware
—
P
—
cronologia completa delle attività
RUNNING
—
—
Export Professional Report
Select a compliance framework to generate a framework-specific report with regulatory authority, legal references, and dedicated control analysis.
Engagement Details (Optional)
Settings & Tools Management
Compliance & Regulations
Policy checks and regional standards.
HTTP Client Identity
Manage scanner footprint and user-agent.
Appearance
Theme preferences saved locally.
Theme ModeDefault Dark. Toggle to use the light UI.
Event Console
Choose how the live scanner console opens.
Report Delivery Preferences
Set the default destination email for compliance report notifications.
Operational Note
The scan modal can override this address for one-off delivery targets. If override is empty, this default is used.
Enterprise Billing & Governance
Manage your active subscription, compliance credits, and payment methods.
Stripe OfflinePayPal Offline
Current Active Plan
Technical Assessment
Free Tier
Audit & Compliance Reports
0
active reports
Fully unlocked compliance reports ready for download.
Governance Capacity
0 / 4
monthly
Recurring monthly compliance audits.
Single Audit
€49 / scan
Full PDF assessment report
Remediation roadmap
Instant unlock of all findings
POPULAR
Governance Suite
€149 / mo
4 Full Assessments / Month
Trend Analysis & Drift Control
Priority Email Support
Domains Whitelist
Only verified domains can be scanned. Verification uses a TXT file generated by this server and hosted on your domain. Admin global whitelist domains are also accepted without per-user verification.
Hosted TXT File Verification
Upload this TXT file to your domain. Content must match exactly.
File Name
-
File Content
-
Allowed Paths
-
-
After upload is live on your site, click verify.
Domain
Status
Verified
Actions
Advanced Crawling Engines
Configure behavior for state-graph navigation and SPA analysis.
v3.3.0 • 6500+ Templates
Recommended: 3-10
Default: 8s
v2.17.0 Installed
Scan Strategy
Medium = surgical power: all high-impact bugs (SQLi, RCE, XSS, XXE), HIGH strength, few false positives. Light optimizes for speed.
Daemon Configuration
Settings managed by Scan Manager (Auto-Rotation enabled).
Active Injection Modules
Tools that perform active exploitation/fuzzing.
Asset Discovery
Subdomains, Directories, and JavaScript analysis.
Account Identities (2+ = differential completo)
Cookie / Bearer header / Basic / Form login. L'owner di ogni oggetto viene stabilito per identità: un'identità che legge oggetti di un'altra = IDOR confermato.
Action center: fix first (Top 5)
Prioritized remediation queue from current findings
Severity
Title
Endpoint
Confidence
Status
Actions
No findings available yet.
Risk & Vulnerability Overview
Real-time security posture analysis with advanced metrics
Idle
Low Risk
Risk Index
Calculated threat severity score
0
Risk Score
0
Total
0
Critical
Severity Distribution
Breakdown by threat level
0
Findings
Critical0
High0
Medium0
Low0
Category Analysis
Vulnerability types found
Injection/XSS
0
Headers
0
Configuration
0
SSL/TLS
0
Compliance
0
Other
0
Surface vs Threat Analytics
Real-time monitoring: Attack surface expansion and vulnerability detection
Live • 2s refresh
Attack Surface vs Threats
Services 0Vulns 0Ports 0Subdomains 0
Live · 2s refresh
-
Waiting for telemetry…
Network Surface
0 Alive0 Redirect0 Blocked
Crawler not started or blocked
Possible causes: robots.txt, WAF, JavaScript-heavy, authentication wall.
JS Crawler Analysis
0 endpoints0 JS files0 attack points
Waiting for JS Crawler results...
Network Exposure
Discovered services and externally reachable ports
Active discovery
Discovered Services (Nmap)
0 Hosts
Host
Port
Service / Version
Status
Exploit DB
Waiting for Port Scan results...
Open Port Distribution
Dominant Port: None
Open: 0Unique: 0
Waiting for Port Scan results...
Compliance & Security Audit
PASSIVE SCAN
GDPR Score
--/100
Security Headers
--
0 headers missing
SSL/TLS
Valid
-- days remaining
Tech Stack
Loading...
Priority Recommendations
0 Critical0 High0 Medium
Vulnerability Registry
Security findings intelligence - prioritized by risk, ready for decision.