AGENT EVAL
// LIVE TRAFFIC SCAN /// 192.168.1.0/24 ↔ INTERNET
pkts 0   flows 0
scanned 0 · matches 0
throughput 0.00 mb/s
// LATEST MATCH
awaiting…
// AGENT EVAL SIGINT HACKBOX
// ENCODER / DECODER17 formats · bidirectional · encode-all mode
// BASE64 IMAGEdecode preview · encode from file · sniff mime
// HASH CALCULATORmd5 · sha-1 · sha-256 · sha-384 · sha-512 · crc32 · hmac · file mode · identify · compare
enter text or load a file, then click Compute Hashes
// REGEX TESTERtest · replace · split · live highlight · ReDoS heuristic · pattern library
paste a regex and test text · or pick from the pattern library
// URL PARSERcomponents · query table · fragment · punycode · security audit
paste a URL and click Parse · or just paste and press Enter
// BASE64 ENCODERtext · file · data-uri · 4 variants (std · url-safe · mime · unpadded)
paste text and click Encode · paste Base64 and click Decode · or load a file
H A L   9 0 0 0 M-19
HEURISTICALLY · PROGRAMMED SYS-V
CL-9000 ALGORITHMIC · COMPUTER
// SECRET / TOKENcrypto.getRandomValues
// HASH CRACKERdictionary + bruteforce · md5 · sha-1 · sha-256 · sha-512 · in-browser · authorized testing only
// DICTIONARY MODE
// BRUTEFORCE MODE
⚠ max length capped at 6 — JS hashing is slow; longer = hours
// REVERSE SHELL GENERATORauthorized testing only
// RECON
target: awaiting
commit: --
--:--:--
scan depth 0 / 7
heuristics 0
nodes 0   edges 0
cwe instances 0
throughput 0.00 mb/s
// ACTIVE
--
--
agent cwe
// SERVICE WORKER TESTERdefensive lab · list / register / unregister · cache inspection · SW attack PoC builder · URL audit
defensive lab tool · only register service workers on origins you control · SWs persist across page closes and can intercept every network request
// register a sw (this origin only)
click List Registered SWs to see what service workers are active on this origin
// STORAGE INSPECTORsessionStorage · localStorage · IndexedDB · Cache · risky-data hunter · value decoder · export
shows only THIS origin's storage · use the browser DevTools storage tab for cross-origin inspection
// setter
click View All Storage to enumerate localStorage + sessionStorage · or pick a specific store
// GRAPHQL INTROSPECTIONschema browser · SDL export · risky-field hunter · type graph · clairvoyance bridge
defensive lab tool · only introspect endpoints you own or have written authorization to assess · introspection responses can be large (paginate / save locally)
paste an endpoint + click Fetch, or paste an introspection JSON you already obtained
// JWT INSPECTORdecode · audit · verify HS/RS/ES/PS/EdDSA · alg=none detection
verification uses Web Crypto · keys never leave your browser
paste a JWT above and click Decode
DEFCON
4
ELEVATED
STRATEGY · GLOBAL THERMONUCLEAR WAR
WOPR · NORAD CHEYENNE MTN · attribution --
RATE 0/MIN ·
LAUNCH 0 / 0
GAMES PLAYED 0
PLAYER 1 · USSR
PLAYER 2 · USA
WINNER · NONE
// LATEST LAUNCH
AWAITING…
SILO · --
~ audit-runner@nullpoint
SHELL · zsh · pid 18342
// SYSTEM INFOos · browser · engine · form factor · input · preferences
auto-runs on page load · 100% local
// PERMISSIONS TESTERbrowser permission API · live request · sensor / camera / geolocation / clipboard / notifications · disclosure-impact rating
clicking "Request" actually triggers a real browser prompt against THIS page · revoke via your browser's site-settings UI when done
click Refresh All States to query the Permissions API for every named permission · "prompt" means "browser hasn't asked yet" — click Request to actually fire the API and trigger the prompt
// HARDWARE FINGERPRINTpassive entropy · canvas · audio · webgl · fonts · codecs · 100% local
demonstrates what any site can silently harvest · nothing leaves your browser
click Compute Fingerprint to harvest device entropy
// .00 collective
root@anonymous · session 0x4F5246
control is an illusion
                       ▄▄▄▄▄▄▄▄▄▄▄
                   ▄▄█████████████████▄▄
                ▄███▀░░░░░░░░░░░░░░░░░▀███▄
              ▄██░░░░░░░░░░░░░░░░░░░░░░░░░██▄
             ██░░░░░░░░░░░░▄████▄░░░░░░░░░░██
            ██░░░░░░░░░░░██████████░░░░░░░░░██
            ██░░░░░░░░░░██████████████░░░░░░██
            ██░░░░░░░░░░██████░░██████░░░░░░██
            ██░░░░░░░░░░██████████████░░░░░░██
             ██░░░░░░░░░░░██████████░░░░░░░██
              ▀██░░░░░░░░░░░▀████▀░░░░░░░░██▀
                ▀███▄░░░░░░░░░░░░░░░░░░▄███▀
                   ▀▀█████████████████▀▀
                        ▀▀▀▀▀▀▀▀▀▀▀
        

      
// ARIIA · DARPA-7
autonomous reconnaissance & integrated intel analyzer
tracking 0 civilians · 0 cams · 0 phones

      
// CIDR CALCULATORIPv4 subnet
// DIR BRUTEFORCEdefensive lab · wordlist scan · status grouping · length baseline · authorized targets only
defensive lab tool · only fuzz against apps you own or have written authorization to assess · cross-origin requests are subject to browser CORS — for serious scanning use ffuf / gobuster
enter a base URL and pick a wordlist · click Start Scan
// SSL/TLS CERT INSPECTORpaste PEM · or pull from crt.sh CT logs · full x.509 parse · fingerprints · SAN · validity
paste a PEM certificate above, or fetch one from CT logs by hostname
// WHOIS / RDAPdomain · ipv4 · ipv6 · asn · via rdap.org (JSON, CORS-friendly)
enter a domain, IP, or ASN and click Lookup
// SUBDOMAIN FINDERcrt.sh CT logs · DoH bruteforce · AlienVault OTX · authorized recon only
enter a root domain and click Find · 100% recon, no exploits
// PORT SCANNERlocalhost service detector · fetch + websocket probes · browser-limited · authorized hosts only
ms
authorized hosts only · browsers cannot raw-socket scan — this measures timing of fetch / websocket connection attempts.
accuracy is limited by Private Network Access policies, CORS, and the browser's port blocklist (1–1023 mostly blocked).
for real scanning use nmap from your terminal — the Copy nmap helper builds the command.
choose ports and click Scan · default targets localhost
// DNS LOOKUPDoH · Cloudflare + Google · A · AAAA · MX · TXT · NS · CAA · SRV · DNSSEC AD bit
enter a hostname and click Query · or run a preset bundle
// SECURITY HEADERSgrade response headers · CSP · HSTS · COOP · COEP · X-Frame · catalog reference
paste response headers above and click Grade · or try a Live Scan
// EMAIL DNS AUDITSPF · DKIM · DMARC · MX · MTA-STS · BIMI · DNSSEC · via DoH · 100% client side
enter a domain and click Audit to query MX / SPF / DMARC / DKIM / MTA-STS / BIMI via DNS-over-HTTPS (Cloudflare)
// CDN / WAF FINGERPRINTERheader signatures · Cloudflare · Akamai · Fastly · CloudFront · Imperva · Sucuri · F5 · DataDome · etc.
paste response headers above and click Fingerprint · or try Live Fetch (will fall back to suggesting a curl command if CORS blocks)
// NETWORK INFOreal client data · public ip · webrtc · connection · device · storage
runs locally · only the public-ip lookup leaves your browser (api.ipify.org)
click Probe Network to gather real client-side info
// WOPR · NORAD CHEYENNE MTN
JOSHUA 0x4A4F5348 · w.o.p.r. v3.4
SHALL WE PLAY A GAME?
--:--:--

        
joshua@wopr:~$
// MATRIX · ZION UPLINK
trinity@hovercraft.nebuchadnezzar
WAKE UP, NEO…
--:--:--

        
trinity@nebuchadnezzar:~$
// SESSION HIJACK TESTERdefensive lab · token replay · rotation · concurrent sessions · post-logout · entropy · authorized targets only
defensive lab tool · only replay session tokens you legitimately captured from systems you own or have written authorization to assess
sec
paste a captured session token, set a probe URL, and click Replay Once · or test rotation / concurrent / post-logout
// PASSWORD STRENGTH METERentropy · pattern penalties · crack-time estimates · HIBP k-anonymity check
awaiting input
only the first 5 chars of the SHA-1 hash leave your browser · the password never does
type a password above · analysis is local and live · nothing is logged or transmitted
// TOOLS
47
// TASKS
--
// CWEs COVERED
--
// AGENTS EVALUATED
--
// CLICKJACKING TESTERdefensive lab · live frameability probe · CSP frame-ancestors analyzer · UI-redress PoC generator
defensive lab tool · only test against apps you own or have written authorization to assess
enter a target URL and click Test Frameability · the panel will attempt to frame it in a sandbox and report what the browser does
// LFI / PATH TRAVERSALdefensive lab · dot-dot-slash · encoding bypass · null byte · php wrappers · authorized targets only
defensive lab tool · only test against apps you own or have written authorization to assess
number of ../ sequences for relative-path variants
browse the payload library · or set a URL + marker + target file and click Run Test Suite
// DESERIALIZE TESTERdefensive lab · java · php · python pickle · .net · ruby · node-serialize · jackson · authorized targets only
defensive lab tool · only test against apps you own or have written authorization to assess · deserialization chains are typically pre-auth RCE
browse the payload library · or set a URL + marker and click Run Test Suite
// SSTI TESTERdefensive lab · engine fingerprint · jinja2 · twig · freemarker · smarty · velocity · mako · ERB · authorized targets only
defensive lab tool · only test against apps you own or have written authorization to assess · most SSTI chains land RCE
browse the payload library · or set a URL + marker and click Auto-Fingerprint Engine
// UPLOAD TESTERdefensive lab · polyglots · extension bypass · MIME spoofing · zip slip · authorized targets only
defensive lab tool · only test against apps you own or have written authorization to assess · webshells and crafted files are real attack tools
browse the payload library · pick a target URL and click "test" on any entry to upload it
// CSRF TESTERdefensive lab · PoC generator · token analyzer · SameSite grader · bypass library · authorized targets only
defensive lab tool · only test against apps you own or have written authorization to assess
configure a target and click Generate PoC · or use the analyzers for tokens / cookies
// XXE TESTERdefensive lab · file disclosure · blind via OOB DTD · SSRF chains · billion-laughs detection · authorized targets only
defensive lab tool · only test against apps you own or have written authorization to assess · DoS payloads are clearly marked and should never be sent without consent
browse the payload library · or set a URL + body and click Run Test Suite
// SSRF TESTERdefensive lab · cloud metadata · localhost bypass · protocol smuggling · OOB · bypass generator · authorized targets only
defensive lab tool · only test against apps you own or have written authorization to assess · SSRF can pivot into the target's internal network — handle with care
browse the payload library · or set a URL + marker and click Run Test Suite
// CMDi TESTERdefensive lab · payload library · execution signatures · OS fingerprint · time-based + OOB · authorized targets only
defensive lab tool · only test against apps you own or have written authorization to assess · unauthorized command-injection probing is a federal crime in most jurisdictions
browse the payload library · or set a URL + marker and click Run Test Suite
// SQLi TESTERdefensive lab · payload library · error signatures · DBMS fingerprint · time-based probe · authorized targets only
defensive lab tool · only test against apps you own or have written authorization to assess · unauthorized SQL injection probing is illegal in most jurisdictions
replace this token in the URL / body with each payload
browse the payload library below · or set a URL + marker and click Run Test Suite
// XSS PAYLOAD TESTERdefensive lab · payload library · sandboxed renderer · encoder · CSP analyzer · authorized targets only
defensive lab tool · use against your own apps or systems where you have written authorization · payloads render in a sandboxed iframe and cannot affect this page
browse the payload library below · or paste a payload and click Render in Sandbox
// CORS TESTERpreflight + live · ACAO · ACAC · expose-headers · posture analysis
enter a URL · the test runs an OPTIONS preflight + the actual request from this browser's Origin
// HEARTBLEED · CVE-2014-0160
openssl 1.0.1f · TLS heartbeat extension overread
leaked 0 B · sessions 0

      
// GRAPHQL TESTERdefensive lab · introspection · suggestion mining · batch/alias DoS · authorized targets only
defensive lab tool · only test GraphQL endpoints you own or have written authorization to assess
paste a GraphQL endpoint and send a query · or click Discover endpoint / Run full introspection
// API TESTERHTTP client · GET/POST/PUT/DELETE · auth helpers · curl import/export · response viewer · history
configure a request and click Send · history of the last 10 requests appears below the response
// WEBSOCKET TESTERlive connect · framing · subprotocols · CSWSH PoC · stress burst · authorized targets only
defensive lab tool · only test against WS endpoints you own or have written authorization to assess
CLOSED browser will send Origin: ${'$'}{location.origin} automatically · cookies sent if same site
paste a ws:// or wss:// URL and click Connect · messages stream into the log below
// HACK THE PLANETabsolute cinema · phreak the gibson · 1995
base64 :: IllvdSBjb3VsZCBzaXQgYXQgaG9tZSwgYW5kIGRvIGxpa2UgYWJzb2x1dGVseSBub3RoaW5nLCBhbmQgeW91ciBuYW1lIGdvZXMgdGhyb3VnaCBsaWtlIDE3IGNvbXB1dGVycyBhIGRheS4gMTk4ND8gWWVhaCByaWdodCwgbWFuLiBUaGF0J3MgYSB0eXBvLiBPcndlbGwgaXMgaGVyZSBub3cuIEhlJ3MgbGl2aW4nIGxhcmdlLiBXZSBoYXZlIG5vIG5hbWVzLCBtYW4uIE5vIG5hbWVzLiBXZSBhcmUgbmFtZWxlc3Mh4oCd
awaiting takeover sequence · hit the red button
// SECURITY KNOWLEDGE BASE /// SIGKILL CATALOG
// CWE CATALOG -- entries · MITRE
// MITRE ATT&CK -- techniques · enterprise
// OWASP FRAMEWORKS -- entries · 4 lists