Crawler agresivo estilo Katana. Sigue enlaces y formularios del mismo dominio hasta la profundidad elegida, y parsea cada archivo JS encontrado para extraer endpoints que un crawler HTML normal nunca vería.
Motor agresivo multi-fuente: 5 fuentes OSINT (crt.sh, HackerTarget, OTX, Wayback, Anubis) + fuerza bruta activa con DNS-over-HTTPS round-robin + probing HTTP + detección de CNAME takeover con verificación real de body.
Fuzzer de contenido estructurado en 5 categorías tácticas independientes. Calibra un baseline de soft-404 antes de cada corrida y descarta automáticamente cualquier respuesta que coincida — pausable y cancelable en tiempo real, sin saturar el navegador.
| Status | Path | Size | RTT |
|---|---|---|---|
| Sin hallazgos todavía. | |||
Análisis estático de archivos sospechosos — nunca ejecuta nada. Hashes, tipo real por magic bytes, entropía, strings, indicadores de red, y para ejecutables Windows, estructura PE completa con imports.
⚠ Esto NO es un sandbox ni un antivirus. Es triaje: te dice por dónde empezar a mirar, no un veredicto. Un score bajo no significa que el archivo sea seguro — un score alto no confirma que sea malware. El archivo nunca sale de tu navegador: todo el análisis corre en tu máquina.
Motor de auditoría ofensiva de AGRESIVIDAD ABSOLUTA. Ingresa una URL y el Leviatán v9.0 despliega 350 FASES REALES DE ANIQUILACIÓN TOTAL:
resolución DNS, transporte SSL/TLS, headers, CORS, adaptive wordlists + parameter mining, robots/sitemap, parámetros peligrosos, fingerprint, cookies (cookie injection, session fixation, JWT decode, cookie tossing, auth bypass), métodos HTTP agresivos (PUT/DELETE/PATCH/TRACE/CONNECT con payloads reales, method override, verb tampering, WebDAV), enumeración de subdominios, escaneo de puertos, mutation engine + OOB callbacks (interactsh), CRLF / Header Injection, NoSQL Injection, Prototype Pollution, HTTP Request Smuggling, Race Conditions, API Abuse / IDOR / Mass Assignment, XXE Injection, SSTI, LDAP Injection, XPath Injection, Host Header Injection, Insecure Deserialization, File Upload Abuse, WebSocket Abuse (CSWSH), OAuth/SSO Misconfiguration, LLM Prompt Injection, ReDoS, HTTP Parameter Pollution (HPP), DNS Rebinding, Source Map Exposure, Cloud Bucket Enumeration, Open Redirect, Path Traversal / LFI, Command Injection, JWT Analysis, SSRF Deep Scan, Subdomain Takeover, Cache Poisoning, WordPress, GraphQL, SQLi Blind, XSS DOM, CSRF, Session Hijacking, Business Logic Abuse, HTTP/2 Rapid Reset, Clickjacking, IPv6 Enum, Virtual Host Brute, Backup File Discovery, Config File Exposure, WAF Evasion, Container Escape, Kubernetes API, Docker Registry, .git/.svn/.hg Exposure, OOB/Blind Callbacks (interactsh, DNS exfil), Auth Context Engine (multi-rol, IDOR activo, Mass Assignment real), JWT Advanced (alg confusion, jku/x5u, kid traversal), OAuth/OIDC/SAML Abuse, MFA/OTP Bypass, HTTP/1.1 + HTTP/2 Smuggling real (CL.TE, TE.CL, single-packet race), Cloud Metadata SSRF (IMDSv1/v2, GCP, Azure), Kubernetes/Docker/CI-CD Attack Surface, Supply Chain (dependency confusion, secrets verificados), Parameter Mining (Arjun-style), Adaptive Wordlists + Mutation Engine, Headless Browser (DOM XSS real, postMessage, prototype pollution client-side), GraphQL Deep + gRPC + OpenAPI Abuse, WAF Fingerprint + Encoding Diferencial, Crypto Attacks (padding oracle, CBC bit-flip, hash length extension), Correlation Engine (48 cadenas de exploit), PoC Verificado No Destructivo, Proxy Rotation + Distributed Scanning, Evidence Capture + Compliance Mapping (OWASP/CWE/CVSS), SQLi 2nd Order + WAF Bypass, Mutation XSS (mXSS), Service Worker Exploitation, SSRF Internal Port Scan + Redis RCE, SSRF Cloud Takeover Chain, TOCTOU + DB Race Conditions, Deser Multi-lang (Java/.NET/PHP/Python), GraphQL Batching + Depth DoS, S3 Bucket Takeover + IAM Privesc + Lambda Abuse, API Gateway Bypass, Prompt Injection Chain + RAG Poisoning + Model Extraction, DNSSEC Zone Walk, Web Cache Deception + CDN Bypass, Password Reset ATO Chain + MFA Fatigue, HTTP/3 QUIC + WebRTC Leak, PostMessage + CORS Exploitation Chains, Content-Type + MIME Sniffing Confusion, WebDAV Deep + Git/SVN/Mercurial Exploitation, Cloudflare/Akamai/ModSecurity WAF Bypass, JA3/JA4 TLS Fingerprinting, Certificate Transparency + Wayback Machine + Shodan Correlation, CVE Matching + 0-Day Hunting, Host Header Poisoning Deep, Prototype Pollution Server-Side, HPP Deep, WebSocket CSWSH, gRPC/OpenAPI Abuse, DNS Rebinding Protection, K8s/Docker API Deep, LLM Prompt Injection + RAG Poisoning, Web Cache Deception, CVE Exploit Correlation (107 CVEs), análisis de contenido (207 patrones de secretos), GraphQL Alias Abuse, OAuth Redirect URI Hijacking, JWT RS256/HS256 Confusion, 2FA/OTP Race Condition, Password Reset Token Enumeration, API Rate Limit Bypass, CRLF Parameter Injection, Blind SSRF Error-based, Certificate Transparency Subdomain Enum, Cloud Metadata Deep (AWS/GCP/Azure), Container Runtime Detection, API Versioning Abuse, Web Cache Deception Deep, DNS Rebinding Bypass, Server-Side PP via JSON, GraphQL Mutation Abuse, HTTP/2 H2C Desync, CORS Credential Theft Chain, JWT Claim Manipulation, Session Puzzle Attack, IDOR Deep Enum, Business Logic Flow Bypass, API Parameter Pollution, Blind Command Injection (time-based), Second-order SQLi, Stored XSS, HTTP Method Override Bypass, API Key Enumeration, SAML Assertion Injection, Open Redirect→SSRF Chain, Path Traversal Encoding Bypass, NoSQLi via JSON, HTTP CL.TE Desync, HTTP/2 Single-Packet Race, GraphQL Introspection Alternatives, Cloud Bucket Misconfig Deep, Docker API Exposure, K8s API Exposure, Etcd/Redis/MongoDB/Elasticsearch/Memcached Exposure, Jenkins/GitLab/Consul/Spring Boot Actuator Deep, AWS IAM Role Enum, GCP Service Account Detection, Azure Managed Identity Detection, OAuth Token Theft, SAML XSW Attack, OpenID Connect Abuse, Password Reset Poisoning Chain, MFA Fatigue Attack, HTTP/3 QUIC Detection, WebRTC IP Leak, Service Worker Abuse, Web Cache Deception via Path, CDN Origin IP Discovery, WAF Bypass via Encoding, SQLi via JSON, XSS via SVG Upload, CSRF via WebSocket, Race Condition on Balance/Credits, IDOR via UUID Prediction, Mass Data Export Abuse, GraphQL Cost Analysis Bypass, Blind XSS Detection, SSRF via PDF Generators (Server-Side XSS), BaaS & IdP Exploitation (Firebase/Cognito/Supabase), GraphQL CSRF (Bypass de Preflight), Fat GET Cache Poisoning, Client-Side Dependency Hijacking, H2.TE/H2.CL Smuggling (Downgrade Attacks), SMTP Header Injection, Unicode Homoglyph WAF Bypass, Type Juggling/Magic Hash Auth Bypass, JSONP Callback Hijacking, Reflected File Download (RFD), Webshell/Backdoor Detection, WebSocket Compression Bomb, gRPC Reflection Abuse, S3 Object Versioning Exploitation, GraphQL Field Suggestion Leak, Cloud Storage Non-AWS Enum (R2/DO/B2/Wasabi), NTLM Relay/SMB/WinRM Exposure, Blind RCE Detection (Time-based + OOB), Auth Bypass Deep (Default Creds + Brute), Credential Stuffing + Password Spraying, Host Header Injection Deep (RCE + Cache Poison), Blind SSRF Advanced (DNS Rebinding + Protocol Smuggling), Mass Assignment → Privilege Escalation, Server-Side Prototype Pollution → RCE Chain, Log4Shell JNDI RCE (CVE-2021-44228), Spring4Shell RCE (CVE-2022-22965), Subdomain CNAME Takeover (50+ fingerprints), JWT Secret Brute-Force (100 secretos comunes), CSP Bypass / Missing CSP Detection, H2C Upgrade Smuggling (HTTP/2 Cleartext), WebSocket Origin Spoofing + Auth Bypass, ImageMagick/ExifTool RCE (ImageTragick + CVE-2021-22204), MOVEit Transfer CVE-2023-34362, Citrix NetScaler CVE-2023-4966, Fortinet FortiGate CVE-2024-21762, F5 BIG-IP CVE-2023-4622, Cloud IAM Exploitation (AWS STS/GCP/Azure), GraphQL Arbitrary File Read, Reverse Proxy Auth Bypass (Direct Origin Access), HTTP Request Smuggling CL.TE/TE.CL Real, SSTI Deep (Jinja2/Twig/Freemarker/Velocity/Smarty/Mako), NoSQL Injection Deep (MongoDB/Redis/CouchDB), XXE Injection Deep (SOAP/SVG/XML-RPC), SQL Injection Deep (Error/UNION/Blind/Time-based), XSS Deep (Reflected/Stored/DOM/Mutation/Framework Bypass), OAuth/OIDC Token Theft Deep (Auth Code/Implicit/PKCE Bypass), Path Traversal/LFI Deep (Encoding Bypass/Null Byte/PHP Filter), Command Injection Deep (Time-based/OOB/Filter Bypass), Race Condition Deep (TOCTOU/Balance/Coupon/Rate Limit), Final Destrozo Correlation Engine, heurísticas y reporte. DESTROZO ABSOLUTO. 350 FASES REALES. Agresividad absoluta. Prepárate para la aniquilación. 💀🔥
Ingresa tu IP y selecciona un lenguaje...
Referencia completa de todas las cabeceras HTTP — de solicitud, respuesta, seguridad y pentesting. Cada cabecera con su función, ejemplo y riesgo de seguridad.
Motor de reconocimiento pasivo sobre fuentes abiertas. Ingresa un dominio o IP y obtén inteligencia de 12 fuentes simultáneas: DNS, WHOIS, subdomains, SSL certs, threat intel, passive DNS, URLs indexadas, geolocalización y más.
Más de 60 CVEs críticos pre-cargados + buscador en tiempo real contra la API oficial NIST NVD. Desde Log4Shell hasta vulnerabilidades 0-day de 2024.
Payloads listos para usar en todas las vulnerabilidades: desde los más básicos hasta los más ofuscados para bypass de WAF y filtros.
Guía de aprendizaje estructurada para convertirse en Bug Bounty Hunter / Ethical Hacker. Desde cero hasta profesional.
Terminal interactivo con Bash, CMD y PowerShell. Más de 300 comandos organizados por situación. Haz clic en cualquier comando de la referencia para insertarlo en el terminal.
Referencia completa de Burp Suite Professional: módulos, atajos, técnicas de explotación y workflows de pentesting web.
Laboratorio interactivo multi-ventana de seguridad ofensiva. Elegi un tipo de ataque, carga un payload, y lanza el ataque. La terminal simula la respuesta interna del servidor. 100% client-side - nada sale de tu navegador.
Pipeline secuencial del flujo de trabajo: del descubrimiento pasivo al PoC manual reproducible.
Instalacion y setup completo de la suite ofensiva. Copia los comandos con un clic.