DAST, reimagined.

Real payloads. Exact evidence.
Your machine.

A 44-module scanner built for SPAs and APIs, firing live SQLi, XSS, SSRF, SSTI, and XXE. Every exploitable finding ships with the request and response that proves it. An AI Operator drives 150+ tools on your own key.

$19/mo. 7-day free trial, no card.

View Pricing
See it run

Live capture · HackTool desktop app · scan of DVGA, a deliberately-vulnerable benchmark.

The Arsenal

44-module scanner

An owned scanner built for SPAs and APIs. It fires real exploit payloads (SQLi, XSS, SSRF, SSTI, XXE) and proves exploitable findings with the exact request and response. No signature matching.

The Operator

AI + 150+ tools

The AI that runs the engagement. It chains the scanner and 150+ tools across recon, exploitation, and triage, with full evidence at every step. On your own AI key via MCP.

44
Detection modules
150+
Tools orchestrated
Bring your own (MCP)
AI key
100% local
Runs
SCANNER · 44 MODULES

Automated Security Scanning
With Real Attack Payloads

Proof, not guesses

The scanner uses the same payloads and techniques real attackers use. 44 modules test injection, auth bypasses, and misconfigurations, then produce evidence-backed reports for developers and auditors.

Start free trial

How the scanner works

Vulnerability detection across 44 modules

SQLi, XSS, SSRF, SSTI, LFI, XXE, CSRF and more across 44 modules. Real payloads from real exploits. No signature matching.

Scanner Phases
  • Discovery
  • Crawling
  • Testing
  • Reporting

Discovery and crawling

Technology fingerprinting, SPA-aware crawling, hidden parameter detection, JavaScript analysis, and WAF detection. Automatically maps your attack surface.

Module Coverage
Injection
Auth & Session
Configuration
Client-Side

Evidence-based reporting

Exploitable findings include the exact request, response, and proof of exploitation; advisory findings are labelled as such. Export to PDF for stakeholders or JSON for integration with your security toolchain.

Scan Pipeline
FingerprintCrawlFuzzValidate

What the scanner tests

Injection Testing
SQLi, NoSQL, LDAP, XPath, command injection
Authentication & Session
OAuth, JWT, CSRF, session fixation
Client-Side Security
XSS, clickjacking, CORS, prototype pollution
Server-Side Attacks
SSRF, SSTI, deserialization, XXE, LFI
Discovery & Recon
Tech fingerprinting, hidden params, JS analysis
Configuration & Hardening
Security headers, TLS config, SCM exposure
Operator · AI Orchestration

Set the scope. Approve every step.
Operator runs the engagement.

Operator plans the workflow, picks from 150+ tools, chains them, and hands you an evidence-backed report. Nothing destructive runs without your sign-off.

Plans the workflow

You define scope and objective. Operator splits the work into recon, exploitation, and triage, then picks the right tools for each.

Picks from 150+ tools and chains them

Recon feeds exploitation, exploitation feeds post-exploit. Results land in one timeline with full evidence. No glue scripts.

MCP mode with BYOK

Bring your own AI key. Run Operator over MCP against Claude, GPT, or local models. Your prompts, your keys, your governance.

What Operator does
  • Plans the workflow. Breaks your objective into recon, exploitation, and triage phases.
  • Picks from 150+ tools and chains them. No glue scripts, no manual plumbing.
  • Keeps engine evidence separate from AI reasoning, so you always know what's proven versus inferred.
  • Hands you an evidence-backed report, with full request/response evidence for every exploitable finding.

How it works

From install to evidence-backed findings in four steps.

01

Install

Download HackTool for Mac, Windows, or Linux.

02

Configure

Set scope, configure targets, plug in your AI key for MCP mode.

03

Run

Launch the scanner or hand the job to Operator. It picks the tools, executes, and iterates.

04

Report

Evidence-backed findings with full request/response. Export PDF or JSON.

Use responsibly. Only scan systems you own or have permission to test.

Trusted by teams at

mybacs
ahead
Generations Fund
DeepMetis
YEEZY
Management Capital Holding
Executive Interim Partners

What sets the Arsenal apart

Deep Vulnerability Coverage

44 scanner modules cover the OWASP Top 10, business-logic flaws, and misconfigurations. Every test fires real attacker payloads.

SPA-Aware Scanning

Handles modern JavaScript applications, extracts routes from bundles, discovers API endpoints automatically, and crawls single-page apps that traditional scanners miss.

Beyond injection

Tests authentication, session handling, CSRF, access control, and business-logic flaws that signature-based scanners never reach.

Start free trial

$19/mo. 7-day free trial, no card.