We build the offensive security tooling we wanted to use: open, auditable and free.
Recon, scanning and continuous exposure testing that runs on your laptop, in your CI, or on your own box — and never on ours.
One toolkit covering the whole path from an unknown surface to a result you can act on.
| Stage | What it does |
|---|---|
| Discover | Find the assets that exist before deciding what to test |
| Enrich | Turn a raw host list into something with context attached |
| Detect | Match known-bad conditions against what you found |
| Report | Make the results diffable, routable and readable |
- Open source, always — MIT licensed, developed in public. Read the code before you point it at your infrastructure.
- No agents to deploy — single static binaries. Nothing is installed on the systems you scan.
- Auditable detections — detection logic is plain YAML in a public repository, not a rule set you are asked to take on faith.
- Built for pipelines — structured JSON from every tool, so results feed dashboards, tickets and alerts without glue code.
- Free and unmetered — no per-asset pricing. Pricing that punishes discovery is pricing that discourages looking.
Note
Nothing is published yet. Repositories go public as they reach a state worth running.
No waitlist, no early access — watch this organisation and releases show up here before anywhere else.
We would rather ship one tool that works than announce five that do not.
Warning
These are offensive security tools. They belong on assets you own, or on assets you have written authorisation to assess.
Scanning infrastructure you do not have permission to touch is unlawful in most jurisdictions, and no licence granted here changes that.
- Found a bug? Open an issue on the repository it affects.
- Written a detection? Rules are plain YAML — send a pull request.
- Found a security issue? Do not open a public issue. See below.
Email hello@0xexploitlabs.org and we will acknowledge within 72 hours.
Please do not open a public issue for a security bug — it discloses the problem to everyone before there is a fix to move to.
MIT, across every repository in this organisation. Commercial use permitted. There is no paid tier holding features back.
