four attack modes
Sniper, battering ram, pitchfork and cluster bomb — one position or many at once.
Automated payload attacks at full speed — four modes, 21 generators, 32 processors, and a Turbo mode with raw-TCP batching.
Sniper, battering ram, pitchfork and cluster bomb — one position or many at once.
Lists, numbers, dates, brute-force and case permutation, composable per position.
Encode, hash, prefix/suffix and transform payloads in a chain before they're sent.
Raw-TCP request batching for race-grade throughput — Community runs it un-throttled.
Mark a position, feed Intruder a payload list, fire a sniper attack and sort by length — the bypasses and the database errors separate themselves from the noise. The auth-bypass lab walks the whole thing.
Every request your browser makes, on your terms — pause it, rewrite it, release it. HTTP/1.1, HTTP/2, HTTP/3 and WebSocket, with on-the-fly TLS.
An active and passive scanner that ships free — OWASP and API Top 10, with blind out-of-band detection.
Send it once. Change one field. Send it again. The careful, hand-driven probe — request and response side by side, over and over.
Set a budget, hit explore, and an autonomous agent drives every tool over 162 MCP tools — or wire Claude Code, Cursor or your own agent straight in.
Beat check-then-act windows the proxy can't reach — single-packet attacks, last-byte sync and barrier coordination.
Extend the scanner without trusting the code — community modules compiled to WebAssembly and run in a hard sandbox.