Files
th-analyzer/README.md

4.3 KiB

⚔️ The Analyzer v1.0 — Autonomous Bug Bounty Engine

Authorized Bug Bounty Use Only — Drjonesxxx / Indianaholmes

One Command

./analyzer https://target.com

Or for deep scan:

./analyzer https://target.com deep

Modes

Mode Command What it does
Quick (default) ./analyzer https://x.com Recon → Ollama picks top vectors → reports
Deep ./analyzer https://x.com deep Recon → ALL 20 vectors → full report
Custom ./analyzer https://x.com custom Pick your own vector numbers
Interactive ./analyzer Menu-driven mode

How it Works

                      ┌─────────────┐
  Target URL ────────▶│  RECON      │───▶ HTTP headers, tech detection,
                      │  ENGINE     │     endpoints, forms, cookies
                      └──────┬──────┘
                             │
                             ▼
                      ┌─────────────┐
                      │  OLLAMA     │───▶ Analyzes recon data
                      │  BRAIN      │     Picks best 5-10 vectors
                      └──────┬──────┘
                             │
              ┌──────────────┼──────────────┐
              ▼              ▼              ▼
        ┌──────────┐  ┌──────────┐  ┌──────────┐
        │ SQLi     │  │ XSS     │  │ LFI      │  ... 20 vectors
        │ Module   │  │ Module  │  │ Module   │
        └──────────┘  └──────────┘  └──────────┘
              │              │              │
              ▼              ▼              ▼
                      ┌─────────────┐
                      │   REPORT    │───▶ Markdown report
                      │   ENGINE    │     HTML report (beautiful)
                      └─────────────┘     CLI summary

20 Attack Vectors

# Vector Severity Detects
01 SQL Injection CRITICAL SQLi (error, blind, time) via sqlmap + manual
02 XSS HIGH Reflected, DOM-based
03 LFI/RFI CRITICAL File inclusion, PHP filter
04 Command Injection CRITICAL OS command execution
05 SSRF HIGH Internal resource access
06 Open Redirect MEDIUM Unvalidated redirects
07 Directory Traversal HIGH Path traversal
08 SSTI CRITICAL Template injection
09 XXE CRITICAL XML external entities
10 IDOR HIGH Access control bypass
11 CSRF MEDIUM Missing tokens
12 JWT Attacks HIGH 'none' alg, weak keys
13 GraphQL HIGH Introspection, injection
14 API Abuse HIGH Rate limiting, auth bypass
15 File Upload HIGH Unrestricted upload
16 Backup Files HIGH .env, configs, credentials
17 .git Exposure CRITICAL Source code leak
18 CORS MEDIUM Wildcard/reflective
19 Race Condition MEDIUM TOCTOU, concurrency
20 NoSQL Injection HIGH MongoDB $ne, $gt, $regex

Ollama Decision Engine

Uses granite4.1:8b (change with OLLAMA_MODEL env var) to analyze recon data and pick the best vectors. The model sees:

  • What tech stack the target runs
  • What endpoints exist
  • What forms/inputs are present
  • What attack surfaces are visible

Then it picks 5-10 vectors that have the highest probability of success.

Reports

Output in reports/:

  • target.com_2026-06-18.md — Full markdown report
  • target.com_2026-06-18.html — Styled HTML report with severity badges

Requirements

  • curl, jq, sqlmap (recommended)
  • Ollama running (default http://10.30.20.110:11434)
  • Change with: OLLAMA_HOST=http://localhost:11434 ./analyzer https://x.com

Deploy to Kali

scp -r ~/the-analyzer root@10.30.20.177:/opt/

This tool is for authorized bug bounty testing only. Only use against targets you have explicit permission to test.