The local-first attack workspace for pentesters and bug hunters. Discover the surface, validate impact, and turn evidence into your next move with AI.
curl -fsSL https://raw.githubusercontent.com/sentinelsec-org/nexhunt/main/install.sh | sudo bash
These are current NexHunt screens from a controlled local lab, showing the same project moving from discovery to validated impact and AI-assisted next steps.
Captured with NexHunt v1.8.0 against Montra, an authorized local security lab.
NexHunt PRO is priced for independent hunters: lifetime access, automated delivery after checkout, and no monthly bill eating your bounty profit.
Five phases. Each one feeds the next. All running locally on your machine.
Subdomain enumeration, live host probing, port scanning, web crawling, URL history, and parameter discovery. All parallel, all automatic.
8,000+ Nuclei templates, CVE correlation by detected tech stack, directory brute-force with smart wordlist selection, web server audits.
SQLi, XSS, command injection, SSRF, JWT attacks. Validate findings and prove impact before writing the report.
Capture and replay live traffic, use the Burp-style site map, fuzz with Intruder, and generate a full vulnerability report with the AI Copilot (PRO).
Specialized checks most scanners miss: CORS misconfiguration, 403 bypass, cloud bucket exposure, GitHub secret leaks, and out-of-band interaction testing across every live host.
Unlock automation, AI assistance, and advanced attack modules that would take hours to configure manually.
Paste any hostname and get a full attack surface breakdown. Feed in your findings and get a professional vulnerability report, ready to submit.
SQLi, JS Secrets, and complete recon pipelines triggered in one click. Each tool's output feeds directly into the next.
Run Nuclei, CORS scans, subdomain takeover checks, and screenshots across every discovered host in your project at once.
10 JWT attack techniques, GraphQL auditing, Repository Intelligence, and business-logic testing.
Stop guessing what to test next. Drop in a host and the Copilot maps the attack surface, prioritizes what is actually exploitable for that tech stack, and turns your raw findings into a submission-ready report. It is the difference between hunting blind and hunting with a senior pentester at your side.
The free tier is genuinely useful. No time limits, no feature degradation, no nag screens.
The installer sets up all 20+ tools, the Python backend, and the Electron app. No manual configuration.
Requires Linux (Kali, Debian, Ubuntu) • Python 3.10+ • ~2 GB disk • Internet for initial install • View on GitHub
Free gets you the full recon-to-exploitation workflow. PRO adds the AI Copilot, automated pipelines and bulk attacks that turn one target into a full report - for the price of a single coffee run.