A web exploitation framework for offensive security professionals. Intercepting proxy, blind vulnerability detection, web shell generation, C2 integration, and collaboration tools in a single binary with an embedded web UI.
Warning: This tool is intended for authorized penetration testing and security research only. You must only use Joro against systems you own or have explicit written permission to test. Unauthorized access to computer systems is illegal. Bishop Fox assumes no liability and is not responsible for any misuse or damage caused by this tool. Use responsibly.
Joro covers a web application engagement end to end: an intercepting proxy for viewing and editing requests and responses, a site map and searchable history, a fuzzer, passive scanning that surfaces secrets and misconfigurations in captured traffic, out-of-band listeners for blind vulnerabilities, web shell generation and execution, Sliver and Mythic C2 integration, and a team server for running an engagement alongside other operators. Work saves to portable project files, and Go plugins enable Linux and macOS users to add anything missing.
Grab a binary from Releases, then see the wiki for installation instructions and a quick start guide.
For more information:
- Checkout the wiki
- Review outstanding issues or create your own.
- See CONTRIBUTING.md for information on how to contribute.
- See CLAUDE.md for detailed developer documentation.
- See SECURITY.md for information on reporting security issues.
Joro is licensed under GPLv3, some sub-components may have separate licenses. See their respective subdirectories in this project for details.

