v1.8.0 · Linux
AI for Pentesters & Bug Hunters

NexHunt Bug Bounty, Automated.

The local-first attack workspace for pentesters and bug hunters. Discover the surface, validate impact, and turn evidence into your next move with AI.

20+ security tools Runs on your Linux $20 lifetime PRO
$ curl -fsSL https://raw.githubusercontent.com/sentinelsec-org/nexhunt/main/install.sh | sudo bash
NexHunt - Montra Labs
NexHunt vulnerability scanner showing prioritized CORS and GraphQL findings from an authorized local lab
13 findings prioritized by severityReal NexHunt session. Controlled local lab.
subfinder amass httpx nmap nuclei ffuf nikto gobuster dirsearch sqlmap dalfox xsstrike katana gau waybackurls commix interactsh gowitness paramspider arjun trufflehog hydra subfinder amass httpx nmap nuclei ffuf nikto gobuster dirsearch sqlmap dalfox xsstrike katana gau waybackurls commix interactsh gowitness paramspider arjun trufflehog hydra

One target. One connected investigation.

These are current NexHunt screens from a controlled local lab, showing the same project moving from discovery to validated impact and AI-assisted next steps.

Built for bug bountyRecon, scanning, proxy and reports in one place.
Local-first workflowRuns on your Linux machine. Your targets stay in your workspace.
Fast first winInstall, add a target, and start collecting evidence.
PRO pays backOne accepted bounty can cover the lifetime license.

Captured with NexHunt v1.8.0 against Montra, an authorized local security lab.

NexHunt PRO

A small license for a faster hunting loop.

NexHunt PRO is priced for independent hunters: lifetime access, automated delivery after checkout, and no monthly bill eating your bounty profit.

Instant deliveryBuy on Shopify and the license key is emailed automatically.
One-time paymentFounding price: $20 lifetime while the launch offer is active.
Free tier firstTry the core workflow before paying for the advanced modules.
Built for evidenceKeep targets, findings and next steps connected instead of rebuilding context across terminals.

What happens after checkout

  1. 1Shopify confirms payment. Your order triggers the licensing worker.
  2. 2Keygen creates the PRO license. The key is tied to the buyer email.
  3. 3Resend sends the key. The buyer receives install steps and activation details.
  4. 4NexHunt unlocks PRO. Paste the key inside the app and advanced modules open.

Recon to report, without switching tools

Five phases. Each one feeds the next. All running locally on your machine.

Reconnaissance

Subdomain enumeration, live host probing, port scanning, web crawling, URL history, and parameter discovery. All parallel, all automatic.

subfinder amass httpx nmap katana gau waybackurls paramspider arjun gowitness

Vulnerability Scanning

8,000+ Nuclei templates, CVE correlation by detected tech stack, directory brute-force with smart wordlist selection, web server audits.

nuclei CVE correlation ffuf nikto gobuster dirsearch wpscan

Exploitation

SQLi, XSS, command injection, SSRF, JWT attacks. Validate findings and prove impact before writing the report.

sqlmap dalfox xsstrike commix interactsh hydra 10 JWT attacks Business logic

Proxy and Reporting

Capture and replay live traffic, use the Burp-style site map, fuzz with Intruder, and generate a full vulnerability report with the AI Copilot (PRO).

proxy repeater site map Intruder PRO AI Report PRO

Security Tools

Specialized checks most scanners miss: CORS misconfiguration, 403 bypass, cloud bucket exposure, GitHub secret leaks, and out-of-band interaction testing across every live host.

CORS 403 bypass cloud buckets GitHub secrets trufflehog OOB interactsh
NexHunt PRO

Go further with PRO

Unlock automation, AI assistance, and advanced attack modules that would take hours to configure manually.

AI Copilot

Paste any hostname and get a full attack surface breakdown. Feed in your findings and get a professional vulnerability report, ready to submit.

Advanced Pipelines

SQLi, JS Secrets, and complete recon pipelines triggered in one click. Each tool's output feeds directly into the next.

Bulk Operations

Run Nuclei, CORS scans, subdomain takeover checks, and screenshots across every discovered host in your project at once.

Advanced Attack Suite

10 JWT attack techniques, GraphQL auditing, Repository Intelligence, and business-logic testing.

NexHunt PRO

The AI copilot that thinks like a pentester

Stop guessing what to test next. Drop in a host and the Copilot maps the attack surface, prioritizes what is actually exploitable for that tech stack, and turns your raw findings into a submission-ready report. It is the difference between hunting blind and hunting with a senior pentester at your side.

  • Attack-surface analysis - paste a hostname, get what to look for and which tools to run, ranked by likelihood.
  • Finding triage - describe a behavior, get severity, exploitation path and the exact wording for your report.
  • One-click reports - your findings become a professional vulnerability report, ready to submit to the program.
  • Your provider, your choice - connect Groq, Gemini, OpenAI, Anthropic or another OpenAI-compatible endpoint.
Unlock the AI Copilot
NexHunt - AI Copilot
NexHunt AI Copilot prioritizing a discovered attack surface and generating executable next steps

Two tiers. No tricks.

The free tier is genuinely useful. No time limits, no feature degradation, no nag screens.

Free
$0
Forever. No card required.

  • Individual recon stages (subfinder, amass, httpx, Nmap Advanced, katana, gau, arjun)
  • Single-target scanning: nuclei, ffuf, nikto, gobuster, dirsearch
  • Proxy capture, repeater, site map, and Intruder
  • Single-target exploitation: sqlmap, dalfox, xsstrike, commix
  • Findings database, projects, methodology guide
  • WordPress, credential brute force, XSS pipeline, CORS, 403 bypass
  • Built-in terminal, session management, dashboard and auto-update
PRO
$20$49
Lifetime - one-time. All future updates included. One bounty pays it back.
⚡ Founding price - limited time

  • Everything in Free, plus:
  • AI Copilot - attack surface analysis, report generation
  • Advanced pipelines - SQLi, JS Secrets, and full recon chains
  • Bulk scanning - nuclei, CORS, takeover and endpoint checks on all hosts
  • JWT attack suite - 10 techniques with step-by-step guidance
  • GraphQL and Repository Intelligence - deep API and exposed-source auditing
  • Business logic testing - IDOR, race conditions, param fuzzing
  • Priority support

Up and running in under 5 minutes

The installer sets up all 20+ tools, the Python backend, and the Electron app. No manual configuration.

~$ curl -fsSL https://raw.githubusercontent.com/sentinelsec-org/nexhunt/main/install.sh | sudo bash

Requires Linux (Kali, Debian, Ubuntu) • Python 3.10+ • ~2 GB disk • Internet for initial install • View on GitHub

Stop switching tabs. Start landing bounties.

Free gets you the full recon-to-exploitation workflow. PRO adds the AI Copilot, automated pipelines and bulk attacks that turn one target into a full report - for the price of a single coffee run.