A growing collection of security-research tools that run entirely on your own computer — not on Truth Button's servers. Starting with HexStrike AI's 100+ recon, scanning, and exploitation tools. For authorized testing, CTF competitions, and security research only.
An AI-orchestrated penetration testing framework — 100+ recon, scanning, and exploitation tools (nmap, sqlmap, nuclei, amass, hydra, and more) behind one API, built for bug bounty, CTF, and red-team work. Ships as a Python/Flask server with no built-in authentication, so it must stay bound to 127.0.0.1 and never be exposed to a network you don't fully control.
Setting up a serious recon/exploitation stack from scratch is its own project — this exists to skip the setup friction while keeping the guardrails that keep it legal to run.
No. Every tool in the kit — starting with HexStrike AI — runs entirely on your own computer. Truth Button never runs it, proxies it, or sees anything it does; this page only links to it and explains how to run it safely.
An AI-orchestrated penetration testing framework that puts 100+ recon, scanning, and exploitation tools behind one API, designed for bug bounty, CTF, and red-team work.
Only if you keep it bound to 127.0.0.1/localhost. It ships with no built-in login and an endpoint that can execute arbitrary commands, so it should never be exposed to your LAN or the open internet.
No. Using HexStrike AI, or any tool in this kit, against projectsilverbeam.com or its backend is explicitly prohibited. Only use these tools on systems you own or are explicitly authorized to test.