Classify the attack surface
Extract endpoints and parameters from fetched responses and classify candidates for manual API/Web review.
A local Windows x64 command-line assistant for researchers reviewing systems they own or are explicitly authorized to test.
Extract endpoints and parameters from fetched responses and classify candidates for manual API/Web review.
Explainable risk scoring and endpoint-based probe planning help you choose what to inspect next. Scores are triage signals, not proof of exploitability.
A host, domain and path scope gate, per-run request budget and minimum request interval constrain requests, including redirect hops.
Save project history, resume with recorded settings, replay offline, and export JSON or standalone HTML reports with evidence.
Three reproducible demos bind to 127.0.0.1. Their reports are sample data, not real-world vulnerability findings.
Open the demo walkthroughs →.\RABBITX.exe --help
.\RABBITX.exe --project .\review.json --replayReplay is offline. For a new review, configure an authorized target and explicit scope first.
Configuration follows built-in defaults → project defaults → JSON config → CLI options. CLI options win. Resume starts a new request budget and records effective settings without rewriting saved project defaults.
Read configuration fields and overrides →Discovery uses fetched responses; RABBITX does not execute application JavaScript or act as a full browser crawler. Findings need manual verification. AI triage, cloud accounts, team collaboration and paid license management are not included in v0.8.
Use only with explicit authorization. Respect target policies, scope, request and rate limits, disclosure rules, and any request to stop.
Pro is proposed at US$24/month. Current project and HTML report features remain available for Beta evaluation. The software is source-available under the repository’s Beta License; website terms do not replace that license.
For product questions, beta feedback and policy questions, contact the maintainer through GitHub Issues. A GitHub account is required. Do not post credentials, payment details, private target URLs or security-sensitive evidence in a public issue.