| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| neurosploit-v4.2.4-windows-x64.zip | 2026-10-04 | 5.9 MB | |
| neurosploit-v4.2.4-macos-x64.tar.gz | 2026-10-04 | 6.0 MB | |
| neurosploit-v4.2.4-macos-arm64.tar.gz | 2026-10-04 | 5.7 MB | |
| neurosploit-v4.2.4-linux-x64.tar.gz | 2026-10-04 | 6.2 MB | |
| neurosploit-v4.2.4-linux-arm64.tar.gz | 2026-10-04 | 6.2 MB | |
| agents_md-v4.2.4.tar.gz | 2026-10-04 | 547.9 kB | |
| NeuroSploit v4.2.4 source code.tar.gz | 2026-10-04 | 1.2 MB | |
| NeuroSploit v4.2.4 source code.zip | 2026-10-04 | 1.7 MB | |
| README.md | 2026-10-04 | 1.2 kB | |
| Totals: 9 Items | 33.5 MB | 1 | |
NeuroSploit v4.2.4 — full Kali sandbox orchestration for recon
Run with --sandbox (black-box) and NeuroSploit will:
- Start the container engine if it's installed but not running (colima/Docker Desktop/dockerd/podman machine) — no more "daemon not running" failures.
- Spin up a Kali container and provision the recon toolbox on demand (subfinder, httpx, katana, gau, waybackurls, nuclei, naabu, dnsx, assetfinder, gf, qsreplace, anew — via go install + apt).
- Run a deterministic TOOL-RECON pass in Kali — subdomain enumeration (crt.sh + subfinder/amass), live-host filtering, URL harvest (gau/waybackurls/katana), targeted nuclei quick-wins, and gf-flagged candidate URLs by vuln class.
- Feed all of that into the LLM recon/exploitation, which works ON TOP of the tool output and confirms each finding with its own request.
- Tear the container down at the end of the run (keep it with NEUROSPLOIT_KEEP_SANDBOX=1).
neurosploit run "*.target.com" --subscription --model anthropic:claude-opus-5-5 --sandbox --recon 4
Everything from v4.2.3 (full recon arsenal, subdomain fan-out, multi-model preflight, reproducible-finding validation, broad OWASP/ASVS objective) carries forward. 423 tests. 480 agents.