Free · Runs On Your Machine · Nothing Hosted By Truth Button

The Ultimate Tool Kit

A growing collection of security-research tools that run entirely on your own computer — not on Truth Button's servers. Starting with HexStrike AI's 100+ recon, scanning, and exploitation tools. For authorized testing, CTF competitions, and security research only.

Open the Tool Kit →
Disclaimer + setup guide shown before anything unlocks · Linux only
What this actually is
A launcher and a set of guardrails, not a hosted attack service — every tool listed here is something you install and run locally.

How it works

  1. 1Open the Tool Kit tab and pick a tool — currently HexStrike AI, with more planned.
  2. 2Read and accept the terms: authorized targets only, localhost-only binding, and Truth Button's own domains are explicitly off-limits.
  3. 3Follow the setup notes to run the tool's server on your own machine, then check the connection and open its dashboard directly — your browser talks straight to your own localhost, nothing routes through Truth Button.

What's in the kit

🛰️ HexStrike AI

An AI-orchestrated penetration testing framework — 100+ recon, scanning, and exploitation tools (nmap, sqlmap, nuclei, amass, hydra, and more) behind one API, built for bug bounty, CTF, and red-team work. Ships as a Python/Flask server with no built-in authentication, so it must stay bound to 127.0.0.1 and never be exposed to a network you don't fully control.

Read this before you open anything here:
  • Every tool in this kit runs on your own computer. Truth Button never runs it, proxies it, or logs anything it does.
  • Only use these tools on systems you own or are explicitly, legally authorized to test. Unauthorized scanning or exploitation of someone else's system can be a crime.
  • Explicitly prohibited: pointing any tool here at projectsilverbeam.com, its subdomains, or Truth Button's backend. The in-app version blocks this by domain check before it'll open a connection or check a target.
  • You are solely responsible for how you use these tools.

Who this is for

Setting up a serious recon/exploitation stack from scratch is its own project — this exists to skip the setup friction while keeping the guardrails that keep it legal to run.

  • Bug bounty hunters who want a fast local setup instead of assembling a dozen tools by hand
  • CTF competitors who need a broad toolkit ready before a competition starts
  • Security students learning recon and scanning workflows in a controlled, authorized lab environment
  • Red-team practitioners standardizing their local toolkit across engagements
  • Researchers who want one API in front of many separate command-line tools

Frequently asked questions

Does the Ultimate Tool Kit run on Truth Button's servers?

No. Every tool in the kit — starting with HexStrike AI — runs entirely on your own computer. Truth Button never runs it, proxies it, or sees anything it does; this page only links to it and explains how to run it safely.

What is HexStrike AI?

An AI-orchestrated penetration testing framework that puts 100+ recon, scanning, and exploitation tools behind one API, designed for bug bounty, CTF, and red-team work.

Is it safe to run?

Only if you keep it bound to 127.0.0.1/localhost. It ships with no built-in login and an endpoint that can execute arbitrary commands, so it should never be exposed to your LAN or the open internet.

Can I use it against projectsilverbeam.com?

No. Using HexStrike AI, or any tool in this kit, against projectsilverbeam.com or its backend is explicitly prohibited. Only use these tools on systems you own or are explicitly authorized to test.

Being straight about this: this page is a launcher plus guardrails, not a hosted scanning service. Tools linked here are separate, third-party projects you install and run yourself — Truth Button doesn't audit their code, guarantee their behavior, or take responsibility for how they're used. For authorized security testing, CTF, and research use only.