apiscan
01Command
API security audit — REST, GraphQL, JWT analysis, parameter discovery.
Command
API security audit — REST, GraphQL, JWT analysis, parameter discovery.
Command
Archive or list previous engagement snapshots.
Command
Password brute force and hash cracking against target services.
Command
Resume or execute an attack campaign with progress tracking.
Command
Show running scans, system health, and engagement status.
Command
Post-engagement lessons learned analysis and debrief report.
Command
Directory and content discovery with recursive crawling.
Command
Network service enumeration — SMB, RPC, NetBIOS, LDAP.
Command
Search and view the findings database.
Command
Weaponize confirmed findings into validated exploit packages.
Command
Ingest recon files to build engagement context and extract findings.
Command
Manage persistent target intelligence across sessions.
Command
AI-powered payload generation for XSS, SQLi, LFI, command injection, and more.
Command
Analyze engagement state and create a strategic attack plan.
Command
Port scanning with fast discovery and detailed service enumeration.
Command
Set or view the scan profile (loud, normal, stealth, paranoid).
Command
Full reconnaissance workflow — subdomain enum, tech detection, WAF fingerprinting, crawling.
Command
Generate a formatted vulnerability report from engagement findings.
Command
Set engagement scope and auto-detect target technology stack.
Command
One-line engagement pulse — target, phase, findings, chains, profile.
Command
View and search the techniques & reports database.
Command
Chronological engagement timeline — all events merged by time.
Command
Web vulnerability scanning with multiple engines (nuclei, nikto, AI assessment).
Command
WordPress-specific vulnerability scanning and enumeration.