| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| neurosploit-v4.2.2-windows-x64.zip | 2026-10-04 | 5.8 MB | |
| neurosploit-v4.2.2-macos-arm64.tar.gz | 2026-10-04 | 5.6 MB | |
| neurosploit-v4.2.2-macos-x64.tar.gz | 2026-10-04 | 5.9 MB | |
| neurosploit-v4.2.2-linux-arm64.tar.gz | 2026-10-04 | 6.1 MB | |
| neurosploit-v4.2.2-linux-x64.tar.gz | 2026-10-04 | 6.2 MB | |
| agents_md-v4.2.2.tar.gz | 2026-10-04 | 547.9 kB | |
| NeuroSploit v4.2.2 source code.tar.gz | 2026-10-04 | 1.2 MB | |
| NeuroSploit v4.2.2 source code.zip | 2026-10-04 | 1.7 MB | |
| README.md | 2026-10-04 | 1.7 kB | |
| Totals: 9 Items | 33.1 MB | 1 | |
NeuroSploit v4.2.2
Validation & reproducibility
- Real, reproducible findings are no longer discarded by the adversarial vote. A
finding whose proof is a captured HTTP response (missing HSTS, insecure cookie
flags, an internal IP leaked in a header, a status code) or a file:line
citation is kept (needs-review at worst, capped to what the receipt proves) so
another person can reproduce the same finding. Kept findings without explicit
steps get a minimal
curl -irepro.
Exploration & coverage
- Free, LLM-directed exploration: an agent's named class is a starting point, not a cage — it reports any class it can prove, with authentication/identity (login, signup, reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target and business-logic flows pursued on its own judgment.
- Agent selection covers the surface (auth/OAuth/business-logic included when the surface is present) instead of collapsing into one family.
Scope & UX
- /authorize <hosts…> sets the whole scope in one line (no program needed); /scope-file imports scope AND target/models/focus/classes from one YAML; /class idor,sqli,xss,ssrf focuses a run; /pocs lists a run's PoC/evidence files.
- /ua browser: realistic browser UA behind a WAF/CDN (attribution kept in the X-NeuroSploit-Scan header) for fewer false negatives.
- PoC/evidence files synthesized even on the API-key path; model refusals reported as refusals (not parse errors); version strings read from the build.
Install (macOS Apple Silicon): tar -xzf neurosploit-v4.2.2-macos-arm64.tar.gz Other platforms: build from source (cargo build --release) — or trigger the Actions "Release builds" workflow. 423 tests passing. 480 agents.