Repository navigation
NeuroSploit v4.2.4 — full Kali sandbox orchestration for recon
Run with --sandbox (black-box) and NeuroSploit will:
- Start the container engine if it's installed but not running (colima/Docker
Desktop/dockerd/podman machine) — no more "daemon not running" failures. - Spin up a Kali container and provision the recon toolbox on demand
(subfinder, httpx, katana, gau, waybackurls, nuclei, naabu, dnsx, assetfinder,
gf, qsreplace, anew — via go install + apt). - Run a deterministic TOOL-RECON pass in Kali — subdomain enumeration (crt.sh +
subfinder/amass), live-host filtering, URL harvest (gau/waybackurls/katana),
targeted nuclei quick-wins, and gf-flagged candidate URLs by vuln class. - Feed all of that into the LLM recon/exploitation, which works ON TOP of the
tool output and confirms each finding with its own request. - Tear the container down at the end of the run (keep it with
NEUROSPLOIT_KEEP_SANDBOX=1).
neurosploit run "*.target.com" --subscription --model anthropic:claude-opus-5-5 --sandbox --recon 4
Everything from v4.2.3 (full recon arsenal, subdomain fan-out, multi-model
preflight, reproducible-finding validation, broad OWASP/ASVS objective) carries
forward. 423 tests. 480 agents.