Real payloads. Exact evidence.
Your machine.
A 44-module scanner built for SPAs and APIs, firing live SQLi, XSS, SSRF, SSTI, and XXE. Every exploitable finding ships with the request and response that proves it. An AI Operator drives 150+ tools on your own key.
$19/mo. 7-day free trial, no card.
Live capture · HackTool desktop app · scan of DVGA, a deliberately-vulnerable benchmark.
The Arsenal
An owned scanner built for SPAs and APIs. It fires real exploit payloads (SQLi, XSS, SSRF, SSTI, XXE) and proves exploitable findings with the exact request and response. No signature matching.
The Operator
The AI that runs the engagement. It chains the scanner and 150+ tools across recon, exploitation, and triage, with full evidence at every step. On your own AI key via MCP.
Automated Security Scanning
With Real Attack Payloads
Proof, not guesses
The scanner uses the same payloads and techniques real attackers use. 44 modules test injection, auth bypasses, and misconfigurations, then produce evidence-backed reports for developers and auditors.
Start free trialHow the scanner works
Vulnerability detection across 44 modules
SQLi, XSS, SSRF, SSTI, LFI, XXE, CSRF and more across 44 modules. Real payloads from real exploits. No signature matching.
- Discovery
- Crawling
- Testing
- Reporting
Discovery and crawling
Technology fingerprinting, SPA-aware crawling, hidden parameter detection, JavaScript analysis, and WAF detection. Automatically maps your attack surface.
Evidence-based reporting
Exploitable findings include the exact request, response, and proof of exploitation; advisory findings are labelled as such. Export to PDF for stakeholders or JSON for integration with your security toolchain.
What the scanner tests
Set the scope. Approve every step.
Operator runs the engagement.
Operator plans the workflow, picks from 150+ tools, chains them, and hands you an evidence-backed report. Nothing destructive runs without your sign-off.
Plans the workflow
You define scope and objective. Operator splits the work into recon, exploitation, and triage, then picks the right tools for each.
Picks from 150+ tools and chains them
Recon feeds exploitation, exploitation feeds post-exploit. Results land in one timeline with full evidence. No glue scripts.
MCP mode with BYOK
Bring your own AI key. Run Operator over MCP against Claude, GPT, or local models. Your prompts, your keys, your governance.
- Plans the workflow. Breaks your objective into recon, exploitation, and triage phases.
- Picks from 150+ tools and chains them. No glue scripts, no manual plumbing.
- Keeps engine evidence separate from AI reasoning, so you always know what's proven versus inferred.
- Hands you an evidence-backed report, with full request/response evidence for every exploitable finding.
How it works
From install to evidence-backed findings in four steps.
Install
Download HackTool for Mac, Windows, or Linux.
Configure
Set scope, configure targets, plug in your AI key for MCP mode.
Run
Launch the scanner or hand the job to Operator. It picks the tools, executes, and iterates.
Report
Evidence-backed findings with full request/response. Export PDF or JSON.
Use responsibly. Only scan systems you own or have permission to test.
Trusted by teams at




What sets the Arsenal apart
Deep Vulnerability Coverage
44 scanner modules cover the OWASP Top 10, business-logic flaws, and misconfigurations. Every test fires real attacker payloads.
SPA-Aware Scanning
Handles modern JavaScript applications, extracts routes from bundles, discovers API endpoints automatically, and crawls single-page apps that traditional scanners miss.
Beyond injection
Tests authentication, session handling, CSRF, access control, and business-logic flaws that signature-based scanners never reach.
$19/mo. 7-day free trial, no card.
