Security tool · Linux · arm64 / amd64
Frontend recon. JS secrets. APK secrets.
Crawls JS bundles, extracts secrets with 44 built-in patterns, runs taint analysis, decompiles APKs with 42 CWE-mapped rules, probes 48 active paths + dedicated vuln checkers. Single Go binary. Machine-bound license. Pro includes xssnuke — Chromium-powered XSS scanner.
Pipeline
Seven stages run sequentially. Each feeds the next. All stages skippable — run full pipeline or cherry-pick with flags.
[REAL-IP] or [CLOUDFLARE] — surfaces origin servers where WAF rules don't apply.--cookie and --header.--webhook.CLI flags
Flags compose. Run the full pipeline or target individual stages.
Active probes
Pro tool
Chromium-powered XSS scanner. Runs a real browser — no filter bypass guessing, no false positives from blind reflection. Included with Pro.
Pricing
Your binary is compiled for your machine and license key. Sharing it doesn't work — wrong machine = immediate exit.
Sign in with Google → pick plan & duration → pay securely → binary ready in dashboard. Compiled for linux/arm64 (Kali) and linux/amd64 (VPS/server). Binary stops validating at expiry.
Questions? Chat with support on Telegram →