xalgorix/xalgorix
Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
What it solves
Xalgorix is an autonomous AI penetration testing platform designed to move beyond simple vulnerability detection to actual proof of exploitability. It solves the problem of "false positive fatigue" by using an independent verifier to re-test and prove every candidate finding before it is reported to the user.
How it works
The platform employs an LLM-driven autonomous agent that follows a comprehensive 22-phase penetration testing methodology. This agent can reason about complex scenarios like business logic flaws, IDOR/BOLA, and authentication bypasses. To ensure accuracy, a separate verifier independently reproduces each finding. The system integrates a wide array of offensive security tools (such as nmap, nuclei, and sqlmap) and browser automation for DAST, allowing the agent to interact with web applications in real-time. Users can self-host the platform and connect their own LLM provider (e.g., OpenAI, Anthropic, DeepSeek, Gemini, or local models via Ollama).
Who it’s for
- Penetration Testers & Red Teamers: For automating reconnaissance, vulnerability discovery, and attack surface mapping.
- Bug Bounty Hunters: To enumerate targets and surface verified findings with proof-of-concept evidence.
- Security Researchers: To discover novel vulnerabilities by leveraging LLM reasoning depth.
- Enterprise Security Teams: For continuous security testing and generating audit-ready PDF reports.
Highlights
- Exploit-Verified Findings: Uses an independent verifier to prove impact and reduce false positives.
- Self-Hosted & Private: No target data or API keys leave the user's infrastructure.
- Bring-Your-Own-LLM: Supports a wide range of providers including OpenAI, Anthropic, and local models via Ollama.
- Comprehensive Toolset: Ships with a preinstalled suite of offensive security tools and the ability to auto-install missing packages at runtime.
- Browser-Assisted DAST: Handles JavaScript-rendered content, auth flows, and runtime behavior.
- Audit-Ready Reporting: Generates branded PDF reports with CVSS scores and remediation steps.
관련
- 프로젝트
- 프로젝트
- 프로젝트
- 프로젝트
- 프로젝트