Skip to content

NeuroSploit v4.2.4

Latest

Choose a tag to compare

@JoasASantos JoasASantos released this 04 Oct 11:01
· 1 commit to main since this release

NeuroSploit v4.2.4 — full Kali sandbox orchestration for recon

Run with --sandbox (black-box) and NeuroSploit will:

  1. Start the container engine if it's installed but not running (colima/Docker
    Desktop/dockerd/podman machine) — no more "daemon not running" failures.
  2. Spin up a Kali container and provision the recon toolbox on demand
    (subfinder, httpx, katana, gau, waybackurls, nuclei, naabu, dnsx, assetfinder,
    gf, qsreplace, anew — via go install + apt).
  3. Run a deterministic TOOL-RECON pass in Kali — subdomain enumeration (crt.sh +
    subfinder/amass), live-host filtering, URL harvest (gau/waybackurls/katana),
    targeted nuclei quick-wins, and gf-flagged candidate URLs by vuln class.
  4. Feed all of that into the LLM recon/exploitation, which works ON TOP of the
    tool output and confirms each finding with its own request.
  5. Tear the container down at the end of the run (keep it with
    NEUROSPLOIT_KEEP_SANDBOX=1).

neurosploit run "*.target.com" --subscription --model anthropic:claude-opus-5-5 --sandbox --recon 4

Everything from v4.2.3 (full recon arsenal, subdomain fan-out, multi-model
preflight, reproducible-finding validation, broad OWASP/ASVS objective) carries
forward. 423 tests. 480 agents.