↗ Crazy Rabbit
Crazy Rabbit / Independent security tooling

Less sorting.
More focused review.

RABBITX is a Windows CLI for authorized API/Web security review. Turn endpoints and parameters into a prioritized review list, keep requests bounded, and preserve reproducible evidence.

Download Windows x64 Beta ↗Explore RABBITX →

Public release v0.8.0-beta · Local CLI · Human verification required

01 / Discover

Classify the attack surface

Extract endpoints and parameters from fetched responses and classify candidates for manual API/Web review.

02 / Prioritize

Review with a reason

Explainable risk scoring and endpoint-based probe planning help you choose what to inspect next. Scores are triage signals, not proof of exploitability.

03 / Bound

Keep requests under control

A host, domain and path scope gate, per-run request budget and minimum request interval constrain requests, including redirect hops.

04 / Preserve

Make the review repeatable

Save project history, resume with recorded settings, replay offline, and export JSON or standalone HTML reports with evidence.

A deliberate workflow

From an authorized target
to a reviewable report.

  1. Confirm authorization and define scope.
  2. Set a request budget and minimum interval.
  3. Review ranked candidates and bounded probe evidence.
  4. Export reports or save a project for the next review.

Evaluate now. Help shape what comes next.

The current Beta has no Free/Pro feature gate. The proposed Pro workflow is being tested at US$24/month; live checkout is not open.

See proposed plans →

Talk to Crazy Rabbit

For product questions, beta feedback and policy questions, contact the maintainer through GitHub Issues. A GitHub account is required. Do not post credentials, payment details, private target URLs or security-sensitive evidence in a public issue.