4.3 KiB
4.3 KiB
⚔️ The Analyzer v1.0 — Autonomous Bug Bounty Engine
Authorized Bug Bounty Use Only — Drjonesxxx / Indianaholmes
One Command
./analyzer https://target.com
Or for deep scan:
./analyzer https://target.com deep
Modes
| Mode | Command | What it does |
|---|---|---|
| Quick (default) | ./analyzer https://x.com |
Recon → Ollama picks top vectors → reports |
| Deep | ./analyzer https://x.com deep |
Recon → ALL 20 vectors → full report |
| Custom | ./analyzer https://x.com custom |
Pick your own vector numbers |
| Interactive | ./analyzer |
Menu-driven mode |
How it Works
┌─────────────┐
Target URL ────────▶│ RECON │───▶ HTTP headers, tech detection,
│ ENGINE │ endpoints, forms, cookies
└──────┬──────┘
│
▼
┌─────────────┐
│ OLLAMA │───▶ Analyzes recon data
│ BRAIN │ Picks best 5-10 vectors
└──────┬──────┘
│
┌──────────────┼──────────────┐
▼ ▼ ▼
┌──────────┐ ┌──────────┐ ┌──────────┐
│ SQLi │ │ XSS │ │ LFI │ ... 20 vectors
│ Module │ │ Module │ │ Module │
└──────────┘ └──────────┘ └──────────┘
│ │ │
▼ ▼ ▼
┌─────────────┐
│ REPORT │───▶ Markdown report
│ ENGINE │ HTML report (beautiful)
└─────────────┘ CLI summary
20 Attack Vectors
| # | Vector | Severity | Detects |
|---|---|---|---|
| 01 | SQL Injection | CRITICAL | SQLi (error, blind, time) via sqlmap + manual |
| 02 | XSS | HIGH | Reflected, DOM-based |
| 03 | LFI/RFI | CRITICAL | File inclusion, PHP filter |
| 04 | Command Injection | CRITICAL | OS command execution |
| 05 | SSRF | HIGH | Internal resource access |
| 06 | Open Redirect | MEDIUM | Unvalidated redirects |
| 07 | Directory Traversal | HIGH | Path traversal |
| 08 | SSTI | CRITICAL | Template injection |
| 09 | XXE | CRITICAL | XML external entities |
| 10 | IDOR | HIGH | Access control bypass |
| 11 | CSRF | MEDIUM | Missing tokens |
| 12 | JWT Attacks | HIGH | 'none' alg, weak keys |
| 13 | GraphQL | HIGH | Introspection, injection |
| 14 | API Abuse | HIGH | Rate limiting, auth bypass |
| 15 | File Upload | HIGH | Unrestricted upload |
| 16 | Backup Files | HIGH | .env, configs, credentials |
| 17 | .git Exposure | CRITICAL | Source code leak |
| 18 | CORS | MEDIUM | Wildcard/reflective |
| 19 | Race Condition | MEDIUM | TOCTOU, concurrency |
| 20 | NoSQL Injection | HIGH | MongoDB $ne, $gt, $regex |
Ollama Decision Engine
Uses granite4.1:8b (change with OLLAMA_MODEL env var) to analyze recon data and pick the best vectors. The model sees:
- What tech stack the target runs
- What endpoints exist
- What forms/inputs are present
- What attack surfaces are visible
Then it picks 5-10 vectors that have the highest probability of success.
Reports
Output in reports/:
target.com_2026-06-18.md— Full markdown reporttarget.com_2026-06-18.html— Styled HTML report with severity badges
Requirements
curl,jq,sqlmap(recommended)- Ollama running (default
http://10.30.20.110:11434) - Change with:
OLLAMA_HOST=http://localhost:11434 ./analyzer https://x.com
Deploy to Kali
scp -r ~/the-analyzer root@10.30.20.177:/opt/
Legal
This tool is for authorized bug bounty testing only. Only use against targets you have explicit permission to test.