GitHub - ABSllk/Hexestra
GitHub - ABSllk/Hexestra
分类 AI智能 / AI工具 预判分类 开发工具


网站介绍
Hexestra 是一个 AI 原生的渗透测试 IDE,人类操作员和 AI 代理在同一操作面上工作,共享浏览器、终端、流量、Shell、资产图、任务计划、证据和控制,旨在提升渗透测试的效率和智能化水平。
备注说明
<div align="center"> <picture> <source media="(prefers-color-scheme: dark)" srcset="src/assets/branding/hexestra-logo-dark.svg"> <source media="(prefers-color-scheme: light)" srcset="src/assets/branding/hexestra-logo-light.svg"> <img alt="Hexestra" src="src/assets/branding/hexestra-logo-light.svg" width="720"> </picture>

Orchestrate your pentest.

An AI-native penetration testing IDE where human operators and AI share the same browser, terminals, traffic, asset graph, tasks, evidence, and controls. English · 简体中文 </div> > [!WARNING] > Hexestra is intended exclusively for authorized security testing. Never use it against systems you do not own or have explicit permission to assess.

Why Hexestra?

Hexestra brings the fragmented parts of a penetration test into one project. Scope labels give the Agent semantic asset context, while the operator can inspect, guide, approve, interrupt, or take over at any time.
  • One shared operational surface: human and AI work with the same browser, terminal sessions, captured traffic, tasks, assets, and evidence.
  • Controlled autonomy: choose ASK, AUTO, or BYPASS while preserving Rules of Engagement and technical safety boundaries; Scope labels remain advisory.
  • Keep the tools you know: continue using Claude Code, Burp Suite, PowerShell, WSL, SSH, and their existing configurations instead of learning a closed replacement.
  • Durable engagement state: reopen a project folder to restore Scope, tasks, NetMap, evidence, findings, reports, workspace tabs, permissions, and conversation branches.

Screenshots

These screenshots use the fictional Northstar Demo Lab, reserved example.test domains, documentation-only IP addresses, synthetic identities, and synthetic evidence. !Hexestra shared workspace with task tree, report, Agent activity, and NetMap The shared workspace keeps the task tree, report, Agent activity, active asset, and 17-node NetMap in one controllable surface. !Hexestra Inventory showing target asset list, selected target details, and AI summary Target assets are displayed on the left, with related assets and details shown below in NetMap. !Hexestra Evidence record with raw HTTP response and linked records Evidence preserves raw output and links it to the Finding and validated Vulnerability. !Hexestra Vulnerability record with severity, impact, and remediation A validated Vulnerability keeps severity, lifecycle, impact, remediation, and linked context together. !Hexestra built-in browser and traffic capture Use the built-in browser to access targets; enable capture on the left to record traffic, with interception and replay support.

Core capabilities

  • Integrated browser, HTTP/HTTPS capture, inspection, interception, Repeater, and evidence capture
  • Shared local, WSL, SSH, jump-host, and raw reverse-shell sessions with human takeover and Agent command auditing
  • Graph-guided testing through typed assets, relationships, provenance, and active objectives in NetMap
  • Structured progression from raw output to Evidence, Finding, Vulnerability, and Report
  • Non-destructive conversation branches that preserve the original reasoning path and canonical project state
  • Optional Burp Bridge and Burp MCP integration without replacing the normal Burp workflow
  • Optional per-project Mihomo multi-hop egress with encrypted nodes and fail-closed managed routing

Quick start

Requirements

  • Node.js 24 and npm
  • Windows x64, Linux x64 (Ubuntu 24.04 baseline), macOS Intel, or macOS Apple Silicon
  • Standard Electron desktop libraries; Ubuntu needs the usual X11/GTK runtime libraries
  • Claude Code installed separately on the host for the selected Native or WSL runtime; Hexestra does not bundle or install it
  • mitmproxy is bundled in packaged builds; source runs may provide it separately
  • Optional Burp Suite and JDK 17 for the Bridge
  • Optional user-provided Mihomo for project-level multi-hop egress (v1.19.29 is tested and recommended, but not required)

Install Claude Code

Run these commands in the Native or WSL environment selected under Settings > Connection:
bash
npm install -g @anthropic-ai/claude-code
claude --version
To use an Anthropic account:
bash
claude auth login
claude auth status

Configure a third-party API

Set provider variables in the same terminal that will start Hexestra. DeepSeek example from its official Claude Code integration guide: Linux and macOS: ```bash export ANTHROPICBASEURL=https://api.deepseek.com/anthropic export ANTHROPICAUTHTOKEN="YOURDEEPSEEKAPI_KEY" export ANTHROPIC_MODEL='deepseek-v4-pro[1m...
获取时间 2026-08-21T01:14:53+00:00
本网址已被浏览 77 次
关键词 AI 渗透测试 IDE 安全 自动化
小标签 AI 渗透测试 IDE 安全
网站截图
截图于:2026-08-21T01:14:53+00:00
头像
暂无评论,快来抢沙发吧!