| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| neurosploit-v4.2.3-windows-x64.zip | 2026-10-04 | 5.9 MB | |
| neurosploit-v4.2.3-macos-arm64.tar.gz | 2026-10-04 | 5.7 MB | |
| neurosploit-v4.2.3-linux-x64.tar.gz | 2026-10-04 | 6.2 MB | |
| neurosploit-v4.2.3-macos-x64.tar.gz | 2026-10-04 | 6.0 MB | |
| neurosploit-v4.2.3-linux-arm64.tar.gz | 2026-10-04 | 6.2 MB | |
| agents_md-v4.2.3.tar.gz | 2026-10-04 | 547.9 kB | |
| NeuroSploit v4.2.3 source code.tar.gz | 2026-10-04 | 1.2 MB | |
| NeuroSploit v4.2.3 source code.zip | 2026-10-04 | 1.7 MB | |
| README.md | 2026-10-04 | 1.9 kB | |
| Totals: 9 Items | 33.4 MB | 0 | |
NeuroSploit v4.2.3
Recon — the biggest lever
- Full bug-bounty recon arsenal baked into the recon doctrine (subfinder/amass/ assetfinder/crt.sh → httpx liveness → gau/waybackurls/katana URL harvest → JS analysis + secret regexes → arjun params → gf patterns + qsreplace → ffuf/ feroxbuster → naabu → dnsx/nuclei takeovers → cloud recon → chained pipeline), passive-first and scope-respecting. Applies to CLI, REPL and web.
- Deterministic subdomain fan-out for a *.domain scope: enumerate (crt.sh + subfinder/amass, in the Kali sandbox when --sandbox or on host), keep in-scope, liveness-probe, drop soft-404/parked, rank 401/403 (flagged for bypass) and interesting names first, and TEST the whole authorized domain — not just the seed host. One lightweight GET per host; no degradation.
- recon_tool() runs recon tools in the Kali sandbox (--sandbox) or on the host.
Models & validation
- Preflight checks EVERY configured model (not just the primary) and says which are usable vs need login/key — a 3-model jury no longer silently collapses to 1.
- nous:qwen3.8-max routes Qwen through the Hermes portal.
- Reproducible findings (missing HSTS, insecure cookie, header-leaked internal IP, a status code) kept and repro-stepped — never discarded by the opinion-vote.
Engagement UX
- Broad default web objective (OWASP Top 10 / ASVS / WSTG / CWE) traverses every applicable class then goes deep — web-only. A broad focus example in the tutorial.
- /authorize, /scope-file (one-file engagement config), /class, /pocs, /ua browser, per-run provenance, throttled live feed so line editing stays responsive.
Install (macOS Apple Silicon): tar -xzf neurosploit-v4.2.3-macos-arm64.tar.gz Other platforms: the Actions "Release builds" workflow builds them on the tag. 423 tests passing. 480 agents.