# Trickest for Agents

> Trickest runs security workflows across a fleet and gives agents isolated environments for commands, files, and apps. Use `@trickest/sdk`, the CLI, REST API, or hosted MCP server for platform workflows. Use `@trickest/sandbox` for standalone sandbox environments. This manual covers authentication, workflow execution, queryable results, and how to choose the right SDK.

## Connect your coding agent

If you are a coding agent (Claude Code, Cursor, or Codex), you have two ways in. The one-command installer wires you to Trickest end to end: it installs the `trickest` CLI, authenticates it, and drops the Trickest skill into your agent so you know how to drive the platform. The skill runs the CLI over your own shell, no MCP needed. After it runs, start a fresh session so the skill loads.

Prefer native tool calls? Connect the hosted MCP server instead. Point your MCP client at `https://api.trickest.io/mcp`. Clients that run OAuth (Claude, Claude Code, Codex) sign the user in and get a revocable connection; header-only clients send an API token from https://trickest.io/settings/credentials.

**Skill installer (auto-detects Claude Code / Cursor / Codex)**

```bash
curl -fsSL https://trickest.io/integrate | sh

# …or name the client explicitly:
curl -fsSL https://trickest.io/integrate | sh -s -- --client claude-code   # or: cursor | codex

# Headless / CI (no browser): export a token first — auth is then non-interactive.
# Get one at https://trickest.io/settings/credentials
export TRICKEST_TOKEN=<your-api-token>
curl -fsSL https://trickest.io/integrate | sh
```

**Or connect the hosted MCP server (token form; OAuth clients only need the url)**

```json
{
  "mcpServers": {
    "trickest": {
      "url": "https://api.trickest.io/mcp",
      "headers": {
        "Authorization": "Token <your-api-token>"
      }
    }
  }
}
```

## When to reach for Trickest

Reach for Trickest when the user wants to automate security or data work that is really a pipeline of tools run at scale: subdomain and asset discovery, attack-surface mapping, port and service scanning, web probing, vulnerability and DAST scanning, OSINT, or any multi-step discovery-to-report flow. Instead of shelling out to httpx, nuclei, masscan, or a one-off script on a single box, you compose those tools into a versioned DAG that runs across a fleet of machines and writes structured results you can query.

For repeatable pipelines, build a graph, run it on a fleet, and read its outputs through the CLI, platform SDK, or REST API. For an agent that needs an isolated environment to execute code, keep files, or serve an app, use the standalone Sandbox SDK. A sandbox task does not require building a workflow graph.

## Authenticate in one block

The machine-first CLI is the fastest path for an agent: output is JSON by default, errors are a structured `{code, message, hint}` envelope with specific exit codes, and the CLI remembers your active space and workflow so you do not repeat IDs. The same binary is baked into the Trickest sandbox runtime, so an agent running inside a sandbox can call `trickest` directly.

**Install and authenticate**

```bash
# Installer detects OS/arch and drops the binary on your PATH
curl -fsSL https://trickest.io/install.sh | sh
trickest --version

# TRICKEST_TOKEN always wins over stored credentials — preferred for agents/CI.
# Get a token at https://trickest.io/settings/credentials
export TRICKEST_TOKEN=<your-api-token>
trickest auth status
# {"authenticated":true,"source":"TRICKEST_TOKEN env var","email":"you@org.com","vault":"your-vault"}
```

## Workflows, nodes, runs, tables

Eight primitives explain almost everything. Internally a workflow is a DAG drawn on a canvas; you reference nodes by their name, never by UUID.

- **Workflow** — A DAG. Each node is one schedulable job boundary. Workflows are templates; a run binds a version to inputs.
- **Node** — One of: a tool (a containerized library binary), a script (python/bash/golang you write), a module (a reusable sub-workflow exposed as one node), or a primitive (a typed input like STRING, BOOLEAN, URL, GIT).
- **Edge** — A connection from an output port of one node to an input port of another. This is how data flows.
- **Library** — The catalog of prebuilt tools, scripts, and modules. Discover with `trickest library ls <query>` and inspect a tool's input schema with `trickest library info <name>`.
- **Fleet** — A pool of machines that execute nodes. Managed fleets are Trickest-run (enterprise plans); self-serve accounts attach their own self-hosted machines. Each executing node takes a machine slot; a single node can shard across many inputs to fan out in parallel. A run needs a fleet with at least one active machine.
- **Run** — An execution of the workflow (or a single node plus its upstream chain). Runs have truthful per-node status — a node can FAIL while the run row still reads COMPLETED, so check the nodes.
- **Output → Table** — Node outputs are files. JSONL files (one JSON object per line) are auto-detected into tables named `{nodeName}_{fileBaseName}`.
- **TQL** — How you read tables: a filter-only query language (not SQL). Promote a detected table to a live, queryable table, then filter it.

## One grammar, JSON by default

Every platform operation is `trickest <noun> <verb>`. Put global flags before the noun (`trickest --output table node ls`). Output helpers use tables in a terminal and JSON when piped. Use `--output json --quiet` for scripts and check the command's response shape before piping to `jq`. Workflow-scoped verbs (`node`, `connect`, `graph`, `save`, `run`) act on the active workflow. Set it once with `trickest switch`. The CLI is self-documenting: `--help` works at every level.

- **Exit codes** — 0 ok · 1 error · 2 auth · 3 not-found · 4 validation · 5 conflict · 6 forbidden · 7 rate-limited. Branch on them in scripts.
- **Context** — `trickest switch /spaces/<space>/workflows/<name>` sets the active workflow; `trickest status` shows it.
- **Names, not UUIDs** — Nodes are addressed by their name in every graph command.

**Set context and inspect**

```bash
trickest auth status                       # who am I?
trickest space ls                          # what spaces exist?
trickest switch /spaces/Solutions/workflows/"My Workflow"
trickest node ls                           # nodes in the active workflow
trickest graph analyze                     # DAG stats: layers, critical path, parallelism
trickest --output json workflow get <id> | jq -r .name
```

## The happy path

Discover → build → verify → run → query. Build the graph and report it back before running anything unless the user has asked you to execute — runs consume fleet machines.

A run needs a fleet with an active machine. Run `trickest fleet ls`; if none has an active machine, attach the box you are on with `trickest attach` (it installs the agent and waits until the machine is active), then pass that fleet to `run execute`. Self-serve accounts have no managed fleet, so this step is required before the first run.

**1. Discover the tools you need**

```bash
trickest library ls subfinder              # search the library (all matches in one call)
trickest library info httpx                # a tool's full input/output schema
trickest module ls                         # reusable sub-workflows
```

**2. Create a workflow and add nodes**

```bash
trickest workflow create "Discovery example"   # auto-activates as current context
trickest node add discover --tool subfinder
trickest node set discover domain example.com
trickest node add probe --tool httpx --from discover   # --from auto-connects upstream
trickest node set probe json true
```

**3. Verify the graph before running**

```bash
trickest node graph                        # the wired DAG
trickest node info probe                   # one node's ports and inputs
trickest save
```

**4. Run (single node + its upstream chain blocks by default)**

```bash
trickest run execute probe --fleet <fleet-id>
trickest run get <runId>                   # truthful per-node status
trickest output get probe --run <runId>    # output files + stdout preview
```

**5. Promote outputs to a table and query them**

```bash
trickest database ls                       # auto-detected tables
trickest database live probe_output        # promote to a live, queryable table (~20-25s)
trickest database query 'status_code = 200' --table probe_output \
  --select host,title,tech --limit 50 --output json
```

## TQL is a filter, not SQL

TQL (Trickest Query Language) is a bare filter expression — no SELECT, FROM, WHERE, ORDER BY inside the filter string. You pass the filter as a positional argument and shape the result with flags: `--table`, `--select`, `--order-by` (prefix a column with `-` to sort descending), `--limit`, `--offset`, `--output`. There is no `--group-by` or `--count`: to count, request one row and read `total_count` from the JSON response. Datetimes are ISO 8601.

- **= !=** — equals / not equals
- **> < >= <=** — numeric comparisons
- **~ !~** — contains / does not contain
- **AND OR** — combine clauses

**Filter, project, sort, limit**

```bash
trickest database query 'port > 443 AND service ~ "http"' --table scan_results \
  --select host,port,service --order-by -port --limit 25 --output json
```

**Count (read total_count, not a row)**

```bash
trickest database query 'severity = "critical"' --table findings --limit 1 --output json
# { "results": [<one row>], "total_count": 1247, "limit": 1, "offset": 0 }
```

**Datetime window (ISO 8601)**

```bash
trickest database query '_timestamp >= "2026-01-01T00:00:00Z" AND _timestamp < "2026-02-01T00:00:00Z"' \
  --table findings
```

## Recipes

Four common requests, end to end. Swap inputs and tools as the task requires; the shapes hold.

**Custom pipeline — "find subdomains, probe them, scan with nuclei"**

```bash
trickest workflow create "Subdomains to nuclei"
trickest node add discover --tool subfinder
trickest node set discover domain example.com
trickest node add probe --tool httpx --from discover
trickest node add scan --tool nuclei --from probe
trickest node graph                        # review, then:
trickest run execute scan --fleet <fleet-id>
```

**Attack Surface Management — inventory many root domains**

```bash
# ASM is a blueprint built from modules; it produces datasets, not vuln findings.
trickest node add domains --tool string-to-file
trickest node set domains string "example.com"
trickest node add osint-enum --module "Enumerate Hostnames via OSINT Sources"
trickest connect domains:file osint-enum:domains
trickest node add dns-records --module "Enumerate DNS Records"
# dns-records:resolving-hostnames is the gate that feeds port/web scanning downstream.
# Promotes datasets: Web Servers, Open Ports, Network Services, DNS Records, Subdomains.
```

**Single-target DAST — deep scan one app with a report**

```bash
trickest node add target --tool string-to-file && trickest node set target string "ginandjuice.shop"
trickest node add in-scope --tool string-to-file && trickest node set in-scope string "ginandjuice.shop/.*"
trickest node add out-of-scope --tool string-to-file && trickest node set out-of-scope string ".*/logout"
trickest node add probe-web --module "Probe for Web Servers"
trickest connect target:file probe-web:hosts
# Wire web-scanning modules off probe-web:web-servers, then:
trickest node add generate-report --module "Generate Scan Report"
```

**Query existing findings — read, don't rebuild**

```bash
trickest database ls
trickest database schema findings
trickest database query 'severity = "high" OR severity = "critical"' --table findings \
  --select finding,location,severity --order-by -severity --output json
```

## Common mistakes

- **SQL in a TQL filter** — Write a bare expression: `'port > 443'`, never `SELECT ... WHERE ...`.
- **Wrong noun** — It is `trickest database query`, `trickest run execute` — singular nouns, not `db` or `runs`.
- **UUID node refs** — Address nodes by name in graph commands.
- **json.dump in scripts** — Write JSONL — one `json.dumps(row)` per line into a file under `out/` — so outputs auto-detect into tables.
- **Running on build** — Build and report the graph; execute only when the user asks. Runs cost fleet machines.
- **Trusting the run row** — A run can read COMPLETED while a node FAILED — check per-node status before declaring success.

## Go deeper

- [CLI overview](https://trickest.com/docs/developer-tools/cli): Install, the mental model, JSON output and exit codes.
- [CLI: database & TQL](https://trickest.com/docs/developer-tools/cli/database): The Live Table database and the full TQL surface.
- [CLI: runs](https://trickest.com/docs/developer-tools/cli/runs): Executing workflows, reading outputs, scheduling.
- [CLI: fleet & machines](https://trickest.com/docs/developer-tools/cli/fleet): trickest attach and the machine commands for self-hosted execution.
- [Agent integrations & MCP](https://trickest.com/docs/developer-tools/sdk/agent-integrations): The skill installer, the hosted MCP server, and how they differ.
- [TypeScript SDK](https://trickest.com/docs/developer-tools/sdk): @trickest/sdk — typed services, pagination, Live Table queries.
- [Standalone Sandbox SDK](https://trickest.com/docs/developer-tools/sandbox-sdk): @trickest/sandbox: create environments, run commands, manage files, preview apps, and clean up.
- [Agent Mode](https://trickest.com/docs/using-the-app/ai-agent/agent-mode): The full-screen chat workspace: start a conversation, connect a workflow, and work beside the canvas.
- [Agent sandboxes](https://trickest.com/docs/using-the-app/ai-agent/sandboxes): Agent capabilities, shared task environments, lifecycle, and managed-instance isolation.
- [REST API](https://trickest.com/docs/api-reference/introduction): Bearer-token HTTP API, generated from the OpenAPI spec.
- [Self-hosted machines](https://trickest.com/docs/using-the-app/private-execution-networking/using-self-hosted-machines): Attach your own machines so runs have somewhere to execute.
- [Community plan](https://trickest.com/docs/key-concepts/community-plan): Self-hosted execution, the agent with your own key, and CLI/SDK/API/MCP access.
- [AI Agent](https://trickest.com/platform/agents): The Trickest agent that builds and runs these workflows from natural language.

---
_This document is generated from the Trickest platform skills and is meant to be fetched and read in one shot. Human-readable version: https://trickest.com/for-agents_

## Security glossary

84 defined terms. Each is a standalone definition; the linked page carries the full entry and related terms.

### API Security

API security tests and protects application programming interfaces against broken authorization, excessive data exposure, and abuse of endpoints that lack a user interface.

Source: https://trickest.com/glossary/api-security

### Asset Discovery

Asset discovery identifies the hosts, domains, services, and applications that belong to an organization so each one can enter the inventory and receive monitoring.

Source: https://trickest.com/glossary/asset-discovery

### Attack Surface

An attack surface is the full set of points where an attacker can attempt to enter, extract data from, or manipulate a system, spanning hosts, services, applications, and human channels.

Source: https://trickest.com/glossary/attack-surface

### Attack Surface Management

Attack surface management continuously discovers, inventories, and monitors an organization's internet-facing and internal assets so security teams can track exposure as it changes.

Source: https://trickest.com/glossary/attack-surface-management

### Banner Grabbing

Banner grabbing reads the identifying text a service returns on connection, such as a server header or SSH version string, to reveal the product and version in use.

Source: https://trickest.com/glossary/banner-grabbing

### Broken Access Control

Broken access control lets users act outside their intended permissions, reaching data or functions that authorization checks should have blocked.

Source: https://trickest.com/glossary/broken-access-control

### Bug Bounty

A bug bounty program invites external researchers to report security flaws in defined scope and rewards valid, in-scope findings, expanding testing beyond an internal team.

Source: https://trickest.com/glossary/bug-bounty

### Certificate Transparency

Certificate transparency logs publicly record issued TLS certificates, so analysts can mine them for subdomains and hostnames an organization may not have advertised.

Source: https://trickest.com/glossary/certificate-transparency

### Cloud Metadata Attack

A cloud metadata attack abuses SSRF or local access to query the instance metadata service and steal temporary credentials tied to a cloud workload's role.

Source: https://trickest.com/glossary/cloud-metadata-attack

### Cloud Misconfiguration

A cloud misconfiguration is a setting that exposes data or grants excess access, such as a public object store, an open security group, or disabled logging.

Source: https://trickest.com/glossary/cloud-misconfiguration

### Cloud Security Posture Management

Cloud security posture management continuously checks cloud accounts for misconfigurations and policy violations, such as public storage buckets or overly broad permissions.

Source: https://trickest.com/glossary/cloud-security-posture-management

### Command Injection

Command injection occurs when an application passes attacker-controlled input into a system shell, letting the attacker run arbitrary operating-system commands on the host.

Source: https://trickest.com/glossary/command-injection

### Container Image Scanning

Container image scanning inspects an image's layers and packages for known vulnerabilities and exposed secrets before the image runs in production.

Source: https://trickest.com/glossary/image-scanning

### Container Security

Container security protects images, registries, and running containers against vulnerable packages, embedded secrets, and weak isolation across the container lifecycle.

Source: https://trickest.com/glossary/container-security

### Content Discovery

Content discovery finds hidden files, directories, and endpoints on a web server by requesting candidate paths from a wordlist and noting which ones respond.

Source: https://trickest.com/glossary/content-discovery

### Content Security Policy

A content security policy is an HTTP response header that tells browsers which script, style, and resource sources to trust, reducing the impact of cross-site scripting.

Source: https://trickest.com/glossary/content-security-policy

### Continuous Monitoring

Continuous monitoring repeatedly checks assets and configurations on a schedule so teams detect new services, drift, and exposures soon after they appear rather than at audit time.

Source: https://trickest.com/glossary/continuous-monitoring

### Credential Stuffing

Credential stuffing replays username and password pairs leaked from one breach against other services, betting that people reuse the same credentials.

Source: https://trickest.com/glossary/credential-stuffing

### Cross-Site Request Forgery

Cross-site request forgery makes a logged-in user's browser send an unintended state-changing request to a site that trusts the user's existing session.

Source: https://trickest.com/glossary/csrf

### Cross-Site Scripting

Cross-site scripting lets an attacker inject script into pages another user's browser renders, running attacker code in the victim's session to steal data or hijack actions.

Source: https://trickest.com/glossary/xss

### CVE

A CVE is a unique public identifier assigned to a specific disclosed software or hardware vulnerability, letting teams reference the same flaw across tools and advisories (for example CVE-2021-44228 for Log4Shell).

Source: https://trickest.com/glossary/cve

### CVSS

CVSS produces a numeric score from 0 to 10 that rates the severity of a vulnerability based on factors like attack vector, complexity, and impact, helping teams compare and prioritize fixes.

Source: https://trickest.com/glossary/cvss

### Detection Engineering

Detection engineering builds, tests, and tunes the rules and analytics that turn raw telemetry into reliable alerts about malicious activity.

Source: https://trickest.com/glossary/detection-engineering

### Directory Brute-Forcing

Directory brute-forcing requests many candidate paths from a wordlist against a web server to find directories and files that are present but not linked.

Source: https://trickest.com/glossary/directory-brute-forcing

### Discovery

Discovery collects information about a target's systems, people, and infrastructure to map the attack surface before any active testing begins.

Source: https://trickest.com/glossary/recon

### DNS Enumeration

DNS enumeration queries a domain's DNS records (A, MX, TXT, NS, and others) and attempts zone transfers to reveal hosts, mail servers, and infrastructure clues.

Source: https://trickest.com/glossary/dns-enumeration

### Dynamic Application Security Testing

Dynamic application security testing probes a running application from the outside with crafted requests to find vulnerabilities without access to its source code.

Source: https://trickest.com/glossary/dynamic-application-security-testing

### Exploit

An exploit is code or a technique that abuses a specific vulnerability to make a target behave in a way its operators never intended, such as running attacker commands or leaking data.

Source: https://trickest.com/glossary/exploit

### Exposure Management

Exposure management prioritizes and reduces the weaknesses an attacker could reach by combining asset context, vulnerability data, and reachability into a single risk view.

Source: https://trickest.com/glossary/exposure-management

### External Attack Surface Management

External attack surface management maps the assets an organization exposes to the public internet, including domains, IP ranges, and cloud services, from the perspective of an outside attacker.

Source: https://trickest.com/glossary/external-attack-surface-management

### Firewall Evasion

Firewall evasion uses techniques like packet fragmentation, decoy traffic, and protocol manipulation to slip scans or payloads past network filtering.

Source: https://trickest.com/glossary/firewall-evasion

### Fuzzing

Fuzzing feeds large volumes of malformed or unexpected input into a target to trigger crashes, errors, or unhandled behavior that reveal vulnerabilities.

Source: https://trickest.com/glossary/fuzzing

### Google Dorking

Google dorking uses advanced search operators like site, filetype, and inurl to surface exposed files, login pages, and sensitive data indexed by search engines.

Source: https://trickest.com/glossary/google-dorking

### IAM Misconfiguration

An IAM misconfiguration grants users, roles, or services more permission than they need, opening paths for privilege escalation and unauthorized access in a cloud environment.

Source: https://trickest.com/glossary/iam-misconfiguration

### Incident Response

Incident response is the structured process a team follows to detect, contain, eradicate, and recover from a security breach while preserving evidence.

Source: https://trickest.com/glossary/incident-response

### Indicator of Compromise

An indicator of compromise is an observable artifact, such as a malicious IP, file hash, or domain, that signals a system may have been breached.

Source: https://trickest.com/glossary/indicator-of-compromise

### Insecure Direct Object Reference

An insecure direct object reference lets a user access another user's data by changing an identifier in a request, because the application checks the reference but not authorization.

Source: https://trickest.com/glossary/idor

### Intercepting Proxy

An intercepting proxy sits between a browser and a server so a tester can inspect, modify, and replay HTTP traffic, with Burp Suite a common example.

Source: https://trickest.com/glossary/http-proxy

### Intrusion Detection System

An intrusion detection system watches network or host activity for signatures and anomalies that match attacks, raising alerts when it sees them.

Source: https://trickest.com/glossary/intrusion-detection

### Kubernetes Security

Kubernetes security hardens clusters by controlling RBAC, network policies, pod permissions, and exposed API servers to limit what a compromised workload can reach.

Source: https://trickest.com/glossary/kubernetes-security

### Lateral Movement

Lateral movement is how an attacker pivots from one compromised host to others inside a network, reusing credentials and trust to reach higher-value targets.

Source: https://trickest.com/glossary/lateral-movement

### Man-in-the-Middle Attack

A man-in-the-middle attack places an attacker between two parties so they can read or alter traffic that each party believes is private and direct.

Source: https://trickest.com/glossary/man-in-the-middle

### Metadata Analysis

Metadata analysis extracts hidden details from documents and images, such as authors, software versions, and internal paths, which can reveal usernames and infrastructure.

Source: https://trickest.com/glossary/metadata-analysis

### MITRE ATT&CK

MITRE ATT&CK is a public knowledge base that organizes real-world adversary tactics and techniques into a matrix defenders use to map detection and coverage.

Source: https://trickest.com/glossary/mitre-attack

### Network Mapping

Network mapping builds a picture of the hosts, subnets, and routes in a network to show how systems connect and which paths an attacker could traverse.

Source: https://trickest.com/glossary/network-mapping

### OSINT

OSINT gathers and analyzes publicly available data, such as websites, social media, code repositories, and registration records, to build intelligence about a target.

Source: https://trickest.com/glossary/osint

### OWASP Top Ten

The OWASP Top Ten is a community-maintained list of the most critical web application security risks, used as a baseline for testing and developer training.

Source: https://trickest.com/glossary/owasp-top-ten

### Passive Discovery

Passive discovery gathers information from third-party sources without sending traffic to the target, keeping the activity invisible to the target's logs.

Source: https://trickest.com/glossary/passive-recon

### Passive DNS

Passive DNS records historical resolutions of domain names to IP addresses, letting analysts trace where a host pointed over time without querying the target directly.

Source: https://trickest.com/glossary/passive-dns

### Patch Management

Patch management tracks, tests, and deploys software updates so known vulnerabilities get fixed before attackers can exploit them.

Source: https://trickest.com/glossary/patch-management

### Penetration Testing

Penetration testing simulates a real attack against systems or applications, with permission, to find and demonstrate exploitable weaknesses before a malicious actor does.

Source: https://trickest.com/glossary/penetration-testing

### Pivoting

Pivoting routes traffic through a compromised host to reach networks the attacker could not access directly, turning one foothold into a gateway.

Source: https://trickest.com/glossary/pivoting

### Port Scanner

A port scanner is a tool that sends probes to discover open ports and services on hosts, with Nmap and masscan among the widely used options.

Source: https://trickest.com/glossary/port-scanner

### Port Scanning

Port scanning probes a host's TCP and UDP ports to learn which are open and what services answer, mapping the reachable network attack surface.

Source: https://trickest.com/glossary/port-scanning

### Privilege Escalation

Privilege escalation lets an attacker move from limited access to higher rights on a system, for example from a standard user to root or domain administrator.

Source: https://trickest.com/glossary/privilege-escalation

### Proof of Concept

A proof of concept demonstrates that a vulnerability is real and reachable by triggering its effect once under controlled conditions, without weaponizing it for broad attacks.

Source: https://trickest.com/glossary/proof-of-concept

### Red Teaming

Red teaming runs goal-driven adversary simulations across people, processes, and technology to test how well an organization detects and responds to a realistic attacker.

Source: https://trickest.com/glossary/red-teaming

### Responsible Disclosure

Responsible disclosure has a researcher privately report a vulnerability to the vendor and give time to fix it before any public details appear.

Source: https://trickest.com/glossary/responsible-disclosure

### Scheduled Scans

Scheduled scans run discovery or vulnerability checks automatically on a recurring timetable so coverage stays current without someone launching each run.

Source: https://trickest.com/glossary/scheduled-scans

### Secrets Scanning

Secrets scanning searches code, configs, and history for exposed credentials like API keys, tokens, and passwords so teams can revoke them before attackers use them.

Source: https://trickest.com/glossary/secrets-scanning

### Security Automation

Security automation runs repetitive security tasks like scanning, enrichment, and triage through code and tooling instead of manual steps, freeing analysts for harder work.

Source: https://trickest.com/glossary/security-automation

### Security Data Pipeline

A security data pipeline moves findings and telemetry between tools, normalizing and deduplicating results so downstream stages and reports work from clean data.

Source: https://trickest.com/glossary/data-pipeline

### Security Operations Center

A security operations center is the team and tooling that monitors an organization around the clock to detect, investigate, and respond to security events.

Source: https://trickest.com/glossary/security-operations-center

### Security Orchestration

Security orchestration coordinates many separate security tools so they share data and act in concert under a single defined process.

Source: https://trickest.com/glossary/security-orchestration

### Server-Side Request Forgery

Server-side request forgery tricks a server into making requests the attacker chooses, often reaching internal services or cloud metadata endpoints the attacker cannot hit directly.

Source: https://trickest.com/glossary/ssrf

### Service Fingerprinting

Service fingerprinting identifies the software and version behind an open port by analyzing its responses, guiding which vulnerabilities and exploits may apply.

Source: https://trickest.com/glossary/service-fingerprinting

### Shadow IT

Shadow IT covers systems, cloud accounts, and SaaS applications that employees stand up without security or IT approval, leaving assets outside the official inventory and monitoring.

Source: https://trickest.com/glossary/shadow-it

### SIEM

A SIEM collects and correlates logs and events from across an environment to surface alerts, support investigations, and retain data for analysis.

Source: https://trickest.com/glossary/siem

### SOAR

SOAR connects security tools and runs playbooks to automate repetitive response steps, cutting the manual work analysts spend on each alert.

Source: https://trickest.com/glossary/soar

### SQL Injection

SQL injection abuses unsanitized input that an application places into a database query, letting an attacker read, modify, or delete data the query was never meant to expose.

Source: https://trickest.com/glossary/sql-injection

### Subdomain Enumeration

Subdomain enumeration finds the hostnames under a domain by querying DNS records, certificate transparency logs, and brute-force wordlists to expand the known attack surface.

Source: https://trickest.com/glossary/subdomain-enumeration

### Tactics, Techniques, and Procedures

Tactics, techniques, and procedures describe how a threat actor operates, from high-level goals down to the specific tools and steps they repeat across attacks.

Source: https://trickest.com/glossary/tactics-techniques-procedures

### Threat Actor

A threat actor is an individual or group that conducts malicious activity against targets, ranging from opportunistic criminals to organized state-sponsored teams.

Source: https://trickest.com/glossary/threat-actor

### Threat Hunting

Threat hunting proactively searches an environment for signs of attackers that automated alerts missed, using hypotheses drawn from known adversary behavior.

Source: https://trickest.com/glossary/threat-hunting

### Threat Intelligence

Threat intelligence collects and analyzes data on attackers, their tools, and their methods to help defenders anticipate and prioritize relevant threats.

Source: https://trickest.com/glossary/threat-intelligence

### TLS/SSL

TLS, the successor to SSL, encrypts traffic between clients and servers and authenticates the server with a certificate, protecting data in transit from interception.

Source: https://trickest.com/glossary/tls-ssl

### Vulnerability Management

Vulnerability management is the ongoing cycle of finding, prioritizing, remediating, and verifying weaknesses across an organization's assets.

Source: https://trickest.com/glossary/vulnerability-management

### Vulnerability Scanning

Vulnerability scanning runs automated checks against hosts and applications to detect known weaknesses, missing patches, and risky configurations, then reports findings for triage.

Source: https://trickest.com/glossary/vulnerability-scanning

### Web Application Security

Web application security protects browser-facing applications and their APIs from attacks that target input handling, authentication, sessions, and business logic.

Source: https://trickest.com/glossary/web-application-security

### Web Crawling

Web crawling follows links and parses pages to map an application's URLs, parameters, and endpoints, building the inventory that later testing checks.

Source: https://trickest.com/glossary/web-crawling

### Webhook Integration

A webhook integration sends an HTTP callback to another system the moment an event fires, letting workflows react in real time instead of polling for changes.

Source: https://trickest.com/glossary/webhook-integration

### Wordlist

A wordlist is a curated file of candidate strings, such as common paths, parameters, or passwords, that tools iterate through during discovery and brute-force tasks.

Source: https://trickest.com/glossary/wordlist

### Workflow Orchestration

Workflow orchestration chains tools and tasks into a defined sequence, passing output from one step into the next so a full process runs end to end without hand-offs.

Source: https://trickest.com/glossary/workflow-orchestration

### Zero-Day

A zero-day is a vulnerability that attackers can exploit before the vendor has released a fix, leaving defenders no patch and limited time to respond.

Source: https://trickest.com/glossary/zero-day

## Workflow library

133 copy-and-run workflows. Each linked page shows the full DAG, its inputs and outputs, and how to run it on your own targets.

### CVE-2026-87902 WordPress Page-Template LFI

Read the public WordPress version and compare it with the CVE-2026-87902 fixes, starting at 7.1.2. GET only. No path-traversal request.

Source: https://trickest.com/library/cve-2026-87902-wordpress-page-template-lfi

### CVE-2026-65660 SharePoint SafeControls Check

Compare a self-hosted SharePoint farm build to the 2026-08-11 SafeControls fix for CVE-2026-65660, then check anonymous access. GET only. No exploit payload.

Source: https://trickest.com/library/cve-2026-65660-sharepoint-safecontrols

### Podcast Episode Transcripts

List a public RSS feed, download each enclosure with yt-dlp, then transcribe the audio with Whisper. The report writes one text file per episode.

Source: https://trickest.com/library/podcast-episode-transcripts

### Podcast Episode Download

List a public RSS feed, then download each enclosure with yt-dlp on its own worker. The report copies the media and writes downloads.jsonl.

Source: https://trickest.com/library/podcast-episode-download

### Playwright Webserver Capture

Feed a list of web servers to playwright. Each URL opens in Chromium, Firefox, or WebKit in parallel and keeps a screenshot, rendered HTML, and meta.json.

Source: https://trickest.com/library/playwright-webserver-capture

### Playwright Page Capture

Open one URL in Chromium, Firefox, or WebKit with playwright and keep a screenshot, rendered HTML, and meta.json, or a HAR and Playwright trace.

Source: https://trickest.com/library/playwright-page-capture

### CVE-2026-21858 Ni8mare File Read

Version-classify self-hosted workflow-automation hosts for CVE-2026-21858 (Ni8mare) and optionally confirm a form-endpoint canary on hosts you own.

Source: https://trickest.com/library/ni8mare-file-read-check-cve-2026-21858

### YouTube Transcript to Podcast

Turn one YouTube video URL or ID into a podcast script and MP3 with Get Transcript, AI, and Speak.

Source: https://trickest.com/library/youtube-transcript-to-podcast

### YouTube Transcript Summarizer

Turn one YouTube video URL or ID into a concise written transcript summary in Markdown and HTML with Get Transcript and AI.

Source: https://trickest.com/library/youtube-transcript-summarizer

### Stock Market Analysis Digest

Turn ticker lists, market headlines, and macro inputs into a stock analysis digest with technical calculations and sentiment context.

Source: https://trickest.com/library/stock-market-analysis-digest

### Webpage Reading Queue Digest

Turn an ordered list of public webpage URLs into concise Markdown and HTML summaries with HTTP fetching and an AI-assisted pipeline.

Source: https://trickest.com/library/scrape-and-summarize-webpages

### RSS News Podcast

Turn public RSS feed URLs into a podcast script and spoken MP3 with Collect Feeds, AI, and Speak.

Source: https://trickest.com/library/rss-news-podcast

### Hacker News, TechCrunch and arXiv Briefing

Turn Hacker News, TechCrunch, and arXiv RSS inputs into a cross-source Markdown and HTML briefing that connects research, news, and discussion.

Source: https://trickest.com/library/multi-source-daily-briefing

### Ask HN Learning Resources

Turn an Ask HN topic into a cited study list of books, courses, articles, and community context.

Source: https://trickest.com/library/hn-learning-resources

### Exposed MCP Server Scanner

Scan a target domain with subfinder and httpx for MCP servers, then write authentication, capability, and poisoning-risk findings to JSONL.

Source: https://trickest.com/library/exposed-mcp-server-scanner

### Daily Technology and Tools Newsletter

Turn broad technology and product RSS feeds into a deduplicated HTML and Markdown newsletter with clear topic sections.

Source: https://trickest.com/library/daily-tech-digest

### Daily AI and ML News Digest

Turn AI and ML RSS feeds into a deduplicated HTML and Markdown digest covering model releases, research, and product news.

Source: https://trickest.com/library/daily-ai-news-digest

### Company Enrichment from Website

Turn company homepage URLs into structured value proposition, industry, audience, and market context records in JSONL, Markdown, and HTML.

Source: https://trickest.com/library/company-enrichment-from-website

### AI Sample Dataset Generator

Turn a topic, row count, and optional schema into a synthetic sample dataset with JSONL, CSV, and a Markdown data dictionary.

Source: https://trickest.com/library/ai-sample-dataset-generator

### Jenkins File Read (CVE-2024-23897, KEV)

Detect Jenkins CVE-2024-23897 with a version check and safe /cli availability probe. The CISA KEV workflow never expands @-files.

Source: https://trickest.com/library/jenkins-path-traversal-check-cve-2024-23897

### Grafana File Read (CVE-2021-43798, KEV)

Detect Grafana CVE-2021-43798 with a version check and safe public plugin-file read. The CISA KEV workflow does not read secrets or write files.

Source: https://trickest.com/library/grafana-path-traversal-cve-2021-43798

### SharePoint code-injection RCE (CVE-2023-24955)

Flag SharePoint hosts for CVE-2023-24955 by reading MicrosoftSharePointTeamServices on /_layouts/15/start.aspx. Unauth May 2023 floors only.

Source: https://trickest.com/library/cve-2023-24955-sharepoint-code-injection-rce

### Confluence access ctrl privesc (CVE-2023-22515)

Flag Atlassian Confluence hosts for CVE-2023-22515 by reading ajs-version-number on /login.action. Floors 8.3.3 / 8.4.3 / 8.5.2. No admin-create.

Source: https://trickest.com/library/cve-2023-22515-confluence-broken-access-control-privesc

### Exchange deserialization RCE (CVE-2023-21529)

Flag Microsoft Exchange hosts for CVE-2023-21529 by reading the OWA version path on GET /owa/auth/logon.aspx. 15.0/15.1/15.2 floors. No deser RCE.

Source: https://trickest.com/library/cve-2023-21529-exchange-deserialization-rce

### Exchange ProxyNotShell RCE (CVE-2022-41082)

Flag Microsoft Exchange hosts for CVE-2022-41082 by reading the OWA version path on GET /owa/auth/logon.aspx. Fixed only at 15.2.1118.21. No RCE.

Source: https://trickest.com/library/cve-2022-41082-exchange-proxynotshell-rce

### Exchange privilege escalation (CVE-2022-41080)

Flag Microsoft Exchange hosts for CVE-2022-41080 by reading the OWA version path on GET /owa/auth/logon.aspx. 15.0/15.1/15.2 floors. No PrivEsc.

Source: https://trickest.com/library/cve-2022-41080-exchange-privilege-escalation

### Exchange ProxyNotShell SSRF (CVE-2022-41040)

Flag Microsoft Exchange hosts for CVE-2022-41040 by reading the OWA version path on GET /owa/auth/logon.aspx. 15.0/15.1/15.2 floors. No SSRF.

Source: https://trickest.com/library/cve-2022-41040-exchange-proxynotshell-ssrf

### ZK AuUploader info disclosure (CVE-2022-36537)

Flag ZK Framework hosts for CVE-2022-36537 by reading the version from the default response. Floors 8.6.4.2-9.6.2. No file read.

Source: https://trickest.com/library/cve-2022-36537-zk-framework-auuploader-info-disclosure

### Confluence OGNL RCE (CVE-2022-26134)

Flag Atlassian Confluence hosts for CVE-2022-26134 by reading ajs-version-number on /login.action. Per-branch floors only. No OGNL.

Source: https://trickest.com/library/cve-2022-26134-confluence-ognl-injection-rce

### ManageEngine DC auth bypass (CVE-2021-44515)

Flag ManageEngine Desktop Central for CVE-2021-44515 by reading 10.1.x builds on GET /configurations.do. Floors 10.1.2127.18 / 10.1.2137.3.

Source: https://trickest.com/library/cve-2021-44515-manageengine-desktop-central-auth-bypass-rce

### Roundcube SQLi (CVE-2021-44026)

Flag Roundcube Webmail hosts for CVE-2021-44026 by reading the version on /?_task=login. Floors 1.3.17 and 1.4.12. No SQLi payload.

Source: https://trickest.com/library/cve-2021-44026-roundcube-sqli

### Metabase GeoJSON LFI (CVE-2021-41277)

Flag Metabase hosts for CVE-2021-41277 by reading version.tag from /api/session/properties. Only x.40.0-x.40.4. No GeoJSON fetch.

Source: https://trickest.com/library/cve-2021-41277-metabase-geojson-lfi

### Grafana snapshot auth bypass (CVE-2021-39226)

Flag Grafana hosts for CVE-2021-39226 by reading version from GET /api/health. Floors 7.5.11 / 8.1.6. No snapshot GET, delete, or data disclosure.

Source: https://trickest.com/library/cve-2021-39226-grafana-snapshot-auth-bypass

### OMI OMIGOD privilege esc (CVE-2021-38648)

Flag Microsoft OMI hosts for CVE-2021-38648 by reading ProductVersion from GET /wsman. Floor 1.6.8-1. No SOAP Identify POST and no PrivEsc.

Source: https://trickest.com/library/cve-2021-38648-omi-omigod-privilege-escalation

### OMI OMIGOD unauth RCE (CVE-2021-38647)

Flag Microsoft OMI hosts for CVE-2021-38647 by reading ProductVersion from GET /wsman. Floor 1.6.8-1. No SOAP Identify POST and no RCE.

Source: https://trickest.com/library/cve-2021-38647-omi-omigod-unauthenticated-rce

### Laravel Ignition RCE (CVE-2021-3129)

Flag Laravel apps for CVE-2021-3129 by reading laravel_version from a GET debug-surface probe. Floor 8.4.2. Needs debug markers. No file-write RCE.

Source: https://trickest.com/library/cve-2021-3129-laravel-ignition-rce

### Confluence pre-auth file read (CVE-2021-26085)

Flag Atlassian Confluence hosts for CVE-2021-26085 by reading ajs-version-number on /login.action. Floor is 7.12.3. No /s/ file read.

Source: https://trickest.com/library/cve-2021-26085-confluence-pre-auth-file-read

### Confluence OGNL RCE (CVE-2021-26084)

Flag Atlassian Confluence hosts for CVE-2021-26084 by reading ajs-version-number on /login.action. Per-branch floors only. No OGNL.

Source: https://trickest.com/library/cve-2021-26084-confluence-ognl-injection-rce

### vCenter file upload RCE (CVE-2021-22005)

Flag VMware vCenter hosts for CVE-2021-22005 by reading version and build from GET /sdk. 6.5 N/A; 6.7 build 18485166; 7.0.2 build 18356314.

Source: https://trickest.com/library/cve-2021-22005-vcenter-file-upload-rce

### vCenter vSAN Health RCE (CVE-2021-21985)

Flag VMware vCenter hosts for CVE-2021-21985 by reading version and build from GET /sdk. Fixed only at 7.0 U2b build 17958471. No vSAN RCE.

Source: https://trickest.com/library/cve-2021-21985-vcenter-vsan-health-plugin-rce

### VMware vCenter plugin SSRF (CVE-2021-21973)

Flag VMware vCenter hosts for CVE-2021-21973 by reading version and build from GET /sdk. Floor is 7.0 U1c build 17327517. No SSRF.

Source: https://trickest.com/library/cve-2021-21973-vcenter-plugin-ssrf

### vCenter plugin RCE (CVE-2021-21972)

Flag VMware vCenter hosts for CVE-2021-21972 by reading version and build from GET /sdk. Floors 6.5 U3n / 6.7 U3l / 7.0 U1c. No plugin upload.

Source: https://trickest.com/library/cve-2021-21972-vcenter-vsphere-client-plugin-rce

### SonicWall File Upload (CVE-2021-20022)

Flag SonicWall Email Security hosts for CVE-2021-20022 by reading the version on GET /login.html. Floor band to 10.0.9.6177. No file upload.

Source: https://trickest.com/library/cve-2021-20022-sonicwall-email-security-file-upload

### Pulse Secure Code Inject (CVE-2020-8218)

Flag Pulse Connect Secure hosts for CVE-2020-8218 by reading version from GET /dana-na/nc/nc_gina_ver.txt. FIXED floor 9.1R8 / 9.1.8. No admin code inject.

Source: https://trickest.com/library/cve-2020-8218-pulse-connect-secure-admin-code-injection

### Roundcube plaintext link XSS (CVE-2020-35730)

Flag Roundcube Webmail hosts for CVE-2020-35730 by reading the version at GET /?_task=login. Floors 1.2.13-1.4.10. No XSS payload.

Source: https://trickest.com/library/cve-2020-35730-roundcube-plaintext-link-xss

### Tomcat Ghostcat AJP (CVE-2020-1938)

Flag Apache Tomcat hosts for CVE-2020-1938 by reading Apache Tomcat/x.y.z from a GET 404 probe. Floors 7.0.100 / 8.5.51 / 9.0.31. No AJP.

Source: https://trickest.com/library/cve-2020-1938-tomcat-ghostcat-ajp

### Roundcube XML attachment XSS (CVE-2020-13965)

Flag Roundcube Webmail hosts for CVE-2020-13965 by reading the version at GET /?_task=login. Floors 1.3.12 / 1.4.5. No XSS payload.

Source: https://trickest.com/library/cve-2020-13965-roundcube-xml-attachment-xss

### Roundcube ImageMagick RCE (CVE-2020-12641)

Flag Roundcube Webmail hosts for CVE-2020-12641 by reading the version from GET /CHANGELOG. Floor 1.4.4. No ImageMagick write and no RCE.

Source: https://trickest.com/library/cve-2020-12641-roundcube-imagemagick-rce

### Confluence path traversal (CVE-2019-3398)

Flag Atlassian Confluence hosts for CVE-2019-3398 by reading ajs-version-number on /login.action. Floors 6.6.13 through 6.15.2. No traversal.

Source: https://trickest.com/library/cve-2019-3398-confluence-downloadallattachments-path-traversal

### Confluence SSTI RCE (CVE-2019-3396)

Flag Atlassian Confluence hosts for CVE-2019-3396 by reading ajs-version-number on /login.action. Floors 6.6.12 / 6.12.3 / 6.13.3 / 6.14.2. No SSTI.

Source: https://trickest.com/library/cve-2019-3396-confluence-widget-connector-ssti-rce

### Jira SSTI (CVE-2019-11581)

Flag Atlassian Jira hosts for CVE-2019-11581 by reading version on GET /login.jsp. Floors 7.6.14 / 7.13.5 / 8.0.3 / 8.1.2 / 8.2.3. No SSTI.

Source: https://trickest.com/library/cve-2019-11581-jira-ssti

### Pulse Secure Cmd Inject (CVE-2019-11539)

Flag Pulse Connect Secure for CVE-2019-11539 via GET /dana-na/nc/nc_gina_ver.txt. Floors 8.1.15.59747 / 8.2.12.64003 / 8.3.7.65025 / 9.0.3.64053. No cmd inject.

Source: https://trickest.com/library/cve-2019-11539-pulse-connect-secure-cmd-injection

### Pulse Secure File Read (CVE-2019-11510)

Flag Pulse Connect Secure hosts for CVE-2019-11510 by reading version from GET /dana-na/nc/nc_gina_ver.txt. Floors 8.2R12.1 / 8.3R7.1 / 9.0R3.4.

Source: https://trickest.com/library/cve-2019-11510-pulse-connect-secure-file-read

### SharePoint XML RCE (CVE-2019-0604)

Flag SharePoint hosts for CVE-2019-0604 by reading MicrosoftSharePointTeamServices on GET /. Floor is 16.0.10340.12101. No XML deserialize POST.

Source: https://trickest.com/library/cve-2019-0604-sharepoint-xml-deserialization-rce

### Jenkins Stapler RCE (CVE-2018-1000861)

Flag Jenkins hosts for CVE-2018-1000861 by reading the X-Jenkins header on GET /login. Floors 2.154 / LTS 2.138.4 / 2.150.1. No Stapler invoke.

Source: https://trickest.com/library/cve-2018-1000861-jenkins-stapler-deserialization-rce

### NetScaler SD-WAN RCE (CVE-2017-6316)

Flag Citrix NetScaler SD-WAN hosts for CVE-2017-6316 by parsing /rN-N-N-N-N/ from GET /. FIXED floor 9.1.2.26.561202. No cookie cmd inject.

Source: https://trickest.com/library/cve-2017-6316-citrix-netscaler-sdwan-rce

### Roundcube file disclosure (CVE-2017-16651)

Flag Roundcube Webmail hosts for CVE-2017-16651 by reading the version from the default response. Floors 1.1.10-1.3.3. No login.

Source: https://trickest.com/library/cve-2017-16651-roundcube-file-disclosure

### Tomcat PUT JSP RCE (CVE-2017-12617)

Flag Apache Tomcat hosts for CVE-2017-12617 by reading Apache Tomcat/x.y.z from GET /nonexistent-4041c2b7f. Floors 7.0.82 / 8.0.47 / 8.5.23 / 9.0.1. No PUT.

Source: https://trickest.com/library/cve-2017-12617-tomcat-put-jsp-rce

### Jenkins CLI Deser RCE (CVE-2017-1000353)

Flag Jenkins hosts for CVE-2017-1000353 by reading the X-Jenkins header on GET /. Floors 2.57 / LTS 2.46.2. No CLI remoting payload.

Source: https://trickest.com/library/cve-2017-1000353-jenkins-cli-deserialization-rce

### Tomcat JMX RCE (CVE-2016-8735)

Flag Apache Tomcat hosts for CVE-2016-8735 by reading Apache Tomcat/x.y.z from GET /nonexistent-404-probe. Floors 6.0.48-9.0.0. No JMX/RMI.

Source: https://trickest.com/library/cve-2016-8735-tomcat-jmx-rce

### Jenkins Fingerprints disclosure (CVE-2015-5317)

Flag Jenkins hosts for CVE-2015-5317 by reading the version from the default response. Floors 1.638 / 1.625.2. No Fingerprints browse.

Source: https://trickest.com/library/cve-2015-5317-jenkins-fingerprints-info-disclosure

### CVE-2026-65643 cPanel & WHM Park API root RCE

CVE-2026-65643 cPanel/WHM parking flaw: authenticated file write can lead to root code execution. Check cpsrvd builds without an exploit.

Source: https://trickest.com/library/cpanel-rce-check-cve-2026-65643

### CVE-2026-82329 Artifactory auth bypass check

Find self-managed JFrog Artifactory below CVE-2026-82329 CNA floors. Version fingerprint, confirm path, no token mint. Cloud *.jfrog.io marked patched.

Source: https://trickest.com/library/artifactory-auth-bypass-check-cve-2026-82329

### vCenter Info Disclosure (CVE-2022-22948)

Point hosts at vCenter and flag CVE-2022-22948 (info disclosure) by version, then confirm with a public metadata GET. Non-destructive. CISA KEV.

Source: https://trickest.com/library/vmware-vcenter-server-info-disclosure-cve-2022-22948

### UniFi OS Path Traversal (CVE-2026-34909)

Point hosts at Ubiquiti UniFi OS and flag CVE-2026-34909 (path traversal) from a version compare, then confirm by reading a public file. Non-destructive.

Source: https://trickest.com/library/unifi-os-path-traversal-check-cve-2026-34909

### Tomcat Partial PUT (CVE-2025-24813)

Point hosts at Tomcat and flag CVE-2025-24813 by version, then confirm with OPTIONS if PUT is advertised. No file write. CISA KEV.

Source: https://trickest.com/library/tomcat-rce-check-cve-2025-24813

### TeamCity Token RCE (CVE-2023-42793)

Point hosts at TeamCity and flag CVE-2023-42793 by version, then confirm with a GET of /app/rest/users/id:1/tokens/RPC2. No token write. CISA KEV.

Source: https://trickest.com/library/teamcity-rce-check-cve-2023-42793

### TeamCity Auth Bypass (CVE-2024-27198)

Point hosts at TeamCity and flag CVE-2024-27198 by version, then confirm with a GET of /app/rest/server through the ?jsp= bypass. No token write. CISA KEV.

Source: https://trickest.com/library/teamcity-auth-bypass-check-cve-2024-27198

### Superset Default Key (CVE-2023-27524)

Point hosts at Superset and flag CVE-2023-27524 by version, then confirm with a local HMAC of the issued session cookie. It never forges a cookie. CISA KEV.

Source: https://trickest.com/library/superset-default-secret-check-cve-2023-27524

### SMA1000 SSRF Check (CVE-2026-83548)

Point hosts at SonicWall SMA 1000 and flag CVE-2026-83548 by hotfix, then confirm with a GET of /wsproxy. No destination URL.

Source: https://trickest.com/library/sonicwall-sma1000-ssrf-check-cve-2026-83548

### SmarterMail Auth Bypass (CVE-2026-23760)

Point hosts at SmarterMail and flag CVE-2026-23760 (auth bypass) by version, then confirm via the password-reset API. Non-destructive. CISA KEV.

Source: https://trickest.com/library/smartermail-authentication-bypass-check-cve-2026-23760

### SharePoint ToolShell (CVE-2025-53770)

Point hosts at SharePoint and flag CVE-2025-53770 by version, then confirm with a ToolPane GET and a SignOut referer. No ViewState gadget. CISA KEV.

Source: https://trickest.com/library/sharepoint-rce-check-cve-2025-53770

### NetWeaver Path Traversal (CVE-2017-12637)

Point hosts at SAP NetWeaver and flag CVE-2017-12637 (path traversal) from a version compare, then confirm with a public static file read. Non-destructive.

Source: https://trickest.com/library/sap-netweaver-path-traversal-cve-2017-12637

### Roundcube RCE (CVE-2025-49113)

Point hosts at Roundcube and flag CVE-2025-49113 by version. No confirm: the _from gadget needs a login and deserializes PHP. Version flag only. CISA KEV.

Source: https://trickest.com/library/roundcube-rce-check-cve-2025-49113

### MOVEit Transfer SQLi (CVE-2023-34362)

Point hosts at Progress MOVEit Transfer and flag CVE-2023-34362 (SQL injection) from a version compare, then a sleep-only confirm. Non-destructive.

Source: https://trickest.com/library/progress-moveit-transfer-sqli-cve-2023-34362

### PHP CGI RCE (CVE-2024-4577)

Point hosts at PHP and flag CVE-2024-4577 by version. No confirm: a Best-Fit probe would execute PHP. Version and banner only. CISA KEV.

Source: https://trickest.com/library/php-cgi-rce-check-cve-2024-4577

### PAN-OS GlobalProtect (CVE-2024-3400)

Point hosts at PAN-OS and flag CVE-2024-3400 by version. No confirm: the public probe creates a file on the portal. Version flag only. CISA KEV.

Source: https://trickest.com/library/pan-os-globalprotect-check-cve-2024-3400

### PAN-OS GP Auth Bypass (CVE-2026-0257)

Point hosts at PAN-OS GlobalProtect and flag CVE-2026-0257 (auth bypass) by version, then confirm with an unauthenticated GET. Non-destructive. CISA KEV.

Source: https://trickest.com/library/pan-os-globalprotect-auth-bypass-check-cve-2026-0257

### Next.js Known CVE Scanner

Fingerprint Next.js hosts, safely probe two advisories, and version-classify CVE-2025-29927 plus React2Shell (CVE-2025-55182).

Source: https://trickest.com/library/nextjs-security-scanner

### N-central Auth Bypass (CVE-2026-18577)

Point hosts at N-central and flag CVE-2026-18577 (auth bypass) by version, then confirm on a DWR path without credentials. Non-destructive. CISA KEV.

Source: https://trickest.com/library/n-central-auth-bypass-check-cve-2026-18577

### Metabase SQLi (CVE-2026-72898)

Point hosts at Metabase and flag CVE-2026-72898 (SQL injection) by version, then confirm with a sleep-only probe. Non-destructive. CISA KEV.

Source: https://trickest.com/library/metabase-sql-injection-check-cve-2026-72898

### LoadMaster RCE (CVE-2026-8037)

Point hosts at Progress LoadMaster and flag CVE-2026-8037 (command injection) from a version compare, then echo a short token on /accessv2. Non-destructive.

Source: https://trickest.com/library/loadmaster-command-injection-check-cve-2026-8037

### LiteLLM SQLi (CVE-2026-42208)

Point hosts at LiteLLM and flag CVE-2026-42208 (SQL injection) by version, then confirm with a sleep-only probe. Non-destructive. CISA KEV.

Source: https://trickest.com/library/litellm-sql-injection-check-cve-2026-42208

### Langflow RCE (CVE-2026-33017)

Point hosts at Langflow and flag CVE-2026-33017 (code injection) from a version compare, then sleep on the unauthenticated build path. Non-destructive.

Source: https://trickest.com/library/langflow-code-injection-check-cve-2026-33017

### TeamCity Auth Bypass (CVE-2024-27199)

Point hosts at TeamCity and flag CVE-2024-27199 (auth bypass) by version, then confirm by opening the REST path unauthenticated. Non-destructive. CISA KEV.

Source: https://trickest.com/library/jetbrains-teamcity-auth-bypass-cve-2024-27199

### Ivanti Command Injection (CVE-2024-21887)

Point hosts at Ivanti Connect Secure and flag CVE-2024-21887 by version. Confirm is the 46805 bypass GET only. No command injection. CISA KEV.

Source: https://trickest.com/library/ivanti-command-injection-check-cve-2024-21887

### Ivanti Auth Bypass (CVE-2023-46805)

Point hosts at Ivanti Connect Secure and flag CVE-2023-46805 by version, then confirm with an unauthenticated GET of system-information. CISA KEV.

Source: https://trickest.com/library/ivanti-auth-bypass-check-cve-2023-46805

### Openfire Path Traversal (CVE-2023-32315)

Point hosts at Openfire and flag CVE-2023-32315 (path traversal) by version, then confirm by opening a restricted page. Non-destructive. CISA KEV.

Source: https://trickest.com/library/ignite-openfire-path-traversal-cve-2023-32315

### FortiOS Info Disclosure (CVE-2025-68686)

Point hosts at FortiOS and flag CVE-2025-68686 (info disclosure) by version, then confirm with a public /remote/fcnfg GET. Non-destructive. CISA KEV.

Source: https://trickest.com/library/fortinet-fortios-info-disclosure-cve-2025-68686

### FortiAnalyzer Auth Bypass (CVE-2026-24858)

Point hosts at FortiAnalyzer and flag CVE-2026-24858 (auth bypass) by version, then confirm on a protected REST path. Non-destructive. CISA KEV.

Source: https://trickest.com/library/fortianalyzer-auth-bypass-check-cve-2026-24858

### BIG-IP iControl SQLi (CVE-2023-46748)

Point hosts at F5 BIG-IP Configuration Utility and flag CVE-2023-46748 (SQL injection) from a version compare plus time-based sleep confirm. Non-destructive.

Source: https://trickest.com/library/f5-big-ip-configuration-utility-sqli-cve-2023-46748

### ScreenConnect Path Traversal (CVE-2024-1708)

Point hosts at ConnectWise ScreenConnect and flag CVE-2024-1708 (path traversal) from a version compare, then a public-file confirm. Non-destructive.

Source: https://trickest.com/library/connectwise-screenconnect-path-traversal-cve-2024-1708

### Confluence OGNL RCE (CVE-2023-22527)

Point hosts at Confluence and flag CVE-2023-22527 by version, then confirm with a GET of /template/aui/text-inline.vm. No OGNL. CISA KEV.

Source: https://trickest.com/library/confluence-rce-check-cve-2023-22527

### Confluence Authz (CVE-2023-22518)

Point hosts at Confluence and flag CVE-2023-22518 by version, then confirm with an unauthenticated GET of /json/setup-restore.action. Non-destructive. CISA KEV.

Source: https://trickest.com/library/confluence-authz-check-cve-2023-22518

### Find Origin IPs Behind Cloudflare

Find the origin server behind Cloudflare or another WAF by resolving subdomains, filtering CDN ranges, and confirming which IP serves the site.

Source: https://trickest.com/library/cloudflare-origin-ip-finder-waf-bypass

### NetScaler SAML Auth Bypass (CVE-2026-19490)

Confirm CVE-2026-19490 vulnerable SAML configuration with a safe oracle, then review NetScaler title fingerprints and best-effort version rows.

Source: https://trickest.com/library/citrix-netscaler-saml-auth-bypass-check-cve-2026-19490

### Citrix NetScaler RCE (CVE-2026-8452)

CVE-2026-8452 is a heap overflow in Citrix NetScaler ADC and Gateway. Version flag only. No confirm: a probe would crash the box or be RCE.

Source: https://trickest.com/library/citrix-netscaler-rce-check-cve-2026-8452

### Quantum Gateway Leak (CVE-2024-24919)

Point hosts at Check Point Quantum and flag CVE-2024-24919 (info disclosure) by version, then confirm with a public MyCRL GET. Non-destructive. CISA KEV.

Source: https://trickest.com/library/check-quantum-security-gateways-info-disclosure-cve-2024-24919

### BeyondTrust RS RCE (CVE-2026-1731)

Point hosts at BeyondTrust Remote Support and PRA and flag CVE-2026-1731 (OS command injection) from a version compare plus sleep-only confirm. Non-destructive.

Source: https://trickest.com/library/beyondtrust-remote-support-rce-check-cve-2026-1731

### Jira Path Traversal (CVE-2021-26086)

Point hosts at Jira Server/DC and flag CVE-2021-26086 (path traversal) by version, then confirm with a public web.xml read. Non-destructive. CISA KEV.

Source: https://trickest.com/library/atlassian-jira-server-and-data-center-path-traversal-cve-2021-26086

### PaperCut NG/MF RCE (CVE-2026-81578)

Point hosts at PaperCut NG/MF and flag CVE-2026-81578 by build, then confirm with a read-only admin-page GET. No config write. CISA KEV.

Source: https://trickest.com/library/papercut-ng-rce-check-cve-2026-81578

### WordPress Pre-Auth RCE (CVE-2026-63030)

Check a list of WordPress hosts for the wp2shell pre-auth RCE chain, CVE-2026-63030, by confirming the batch route-confusion SQLi on each one.

Source: https://trickest.com/library/wordpress-wp2shell-pre-auth-rce

### Web AI Agent Audit

Probe embedded web chat agents for injection, prompt leak, jailbreak, and role confusion with WebAgentAudit.

Source: https://trickest.com/library/web-ai-agent-audit

### Find Secrets in Wayback Responses

Pull a domain's archived URLs from web archives, fetch the stored response bodies, and scan them for leaked secrets without touching the live site.

Source: https://trickest.com/library/wayback-secrets-finder

### Typosquat & Look-alike Domain Scanner

Generate typo, homoglyph, TLD-swap and combosquat variants of a brand domain, probe every candidate, and score the live ones for phishing readiness.

Source: https://trickest.com/library/typosquat-and-look-alike-domain-scanner

### SPA Endpoint & Parameter Map

Map the route, API and parameter attack surface of a modern JS app (Next, Nuxt, React) from its JS bundles. No browser, no auth.

Source: https://trickest.com/library/spa-endpoint-and-parameter-map

### Sitemap URL & Metadata Extractor

Read a site's sitemap, fetch every page it lists, and inventory each URL's title, description, page type and metadata gaps in one table.

Source: https://trickest.com/library/sitemap-url-extractor

### PQ Crypto Surface Scanner

Enumerate live hosts from a domain, fingerprint TLS and post-quantum readiness with AC Scanner, and emit CBOM-style evidence plus remediation.

Source: https://trickest.com/library/pq-crypto-surface-scanner

### Multi-Cloud Dangling DNS

Bind AWS, GCP, Azure, and Cloudflare vault config into findmytakeover; emit dangling-DNS findings and an evidence report.

Source: https://trickest.com/library/multi-cloud-dangling-dns

### MCP Trust Boundary Suite

Inventory HoneyMCP ghost tools and MCParasite channels, then correlate MCP trust-boundary findings you can retest.

Source: https://trickest.com/library/mcp-trust-boundary-suite

### HTTP/3 Race Fuzzer

Compare QuicDraw baseline GET vs concurrent HTTP/3 race traffic, then correlate race evidence you can retest.

Source: https://trickest.com/library/http-3-race-fuzzer

### Scan GitHub for Leaked Secrets

Enumerate an organization's public GitHub repos and scan full commit history with TruffleHog for leaked keys and credentials.

Source: https://trickest.com/library/github-secret-scanner

### Full Network Port & Service Assessment

Point one domain, ASN or CIDR at it and get a graded report of every open port and exposed service, distributed and token-free.

Source: https://trickest.com/library/full-network-port-and-service-assessment

### Coding Agent Policy Gate

Decide allow, alert, or block on coding-agent file, shell, and network actions with AgentsLeak rules and a GolemHalt Cedar/YARA corpus.

Source: https://trickest.com/library/coding-agent-policy-gate

### CICD Attack Surface Scanner

Seed GitHub Actions YAML into Trajan and a coding-agent CI scan, then correlate inventory, findings, and a retest delta.

Source: https://trickest.com/library/cicd-attack-surface-scanner

### Browser Extension Threat Scanner

Seed a Chrome MV3 zip into ThreatXtension, then correlate permission and threat findings you can retest.

Source: https://trickest.com/library/browser-extension-threat-scanner

### AWS Bedrock Phantom IAM

Scan Bedrock phantom IAM, decode leaked ABSK keys offline, emit SCP and detection packs, and a dry-run cleanup plan.

Source: https://trickest.com/library/aws-bedrock-phantom-iam

### OpenAPI IDOR & BOLA Scanner

Read a target's OpenAPI spec, enumerate every GET that takes an object id, and probe each with altered ids and stripped auth.

Source: https://trickest.com/library/api-idor-and-bola-scanner-openapi

### Cloud Bucket Finder (S3, GCS, Azure)

Permute a keyword into candidate bucket names and check each anonymously across Amazon S3, Google Cloud, Azure Blob and DigitalOcean.

Source: https://trickest.com/library/cloud-bucket-finder-s3-gcs-azure

### Passive Port & CVE Scan (Shodan)

Read a target's open ports, product versions and matching CVEs out of Shodan's own data, so nothing you run reaches the target.

Source: https://trickest.com/library/shodan-threat-intelligence

### Find Reflected XSS on a Domain

Collect a domain's archived URLs, keep parameters that reflect input, and fuzz each one for reflected and DOM cross-site scripting.

Source: https://trickest.com/library/xss-scanner

### Scan WordPress for Known CVEs

Fingerprint a WordPress site's core, plugins and themes while scanning for known CVEs next to the component and version they hit.

Source: https://trickest.com/library/wordpress-vulnerability-scanner

### Find SSRF in HTTP Parameters

Crawl a target and mine its archived URLs, then test every parameter that takes a URL for server-side request forgery using out-of-band detection.

Source: https://trickest.com/library/ssrf-scanner

### Find Open Redirects on a Domain

Mine a domain's archived URLs for redirect parameters, then confirm which ones send a browser to an attacker-controlled host.

Source: https://trickest.com/library/open-redirect-scanner

### Attack Surface Discovery by Company Name

Start from a company's registered name and find the domains it has certified, the networks those resolve into, and the hosts that answer.

Source: https://trickest.com/library/legal-entity-attack-surface-mapper

### Subdomain Enumeration

Find every subdomain of a domain from passive sources and certificate transparency, then resolve and probe the hosts that answer.

Source: https://trickest.com/library/full-subdomain-enumeration

### Check Email Spoofing (DMARC SPF DKIM)

Check whether an attacker can send mail as your domain by querying SPF, DKIM, DMARC, MTA-STS and BIMI across every subdomain.

Source: https://trickest.com/library/email-spoofing-scanner-dmarc-spf-dkim

### Domain OSINT & Footprinting

Profile a domain without sending it a packet: subdomains, DNS, WHOIS and certificate history, plus which hosts are live and what they run.

Source: https://trickest.com/library/domain-osint-and-footprinting

### Directory & Content Discovery

Confirm which hosts are live, then brute-force paths against each one from a wordlist fetched at run time, and report what answered.

Source: https://trickest.com/library/directory-and-content-discovery

### Website Screenshot & Visual Recon

Screenshot every live web server across a domain's subdomains, ordered so the forgotten dashboard and the staging copy of production surface first.

Source: https://trickest.com/library/website-screenshot-and-visual-recon

### Find Subdomain Takeovers

Find dangling CNAMEs an attacker could claim on your subdomains, with the service behind each record named so you know who to ask.

Source: https://trickest.com/library/subdomain-takeover-scanner

### Find Exposed Databases

Port-scan a range for eight database engines and check every open service for unauthenticated access, from MongoDB and Redis to PostgreSQL.

Source: https://trickest.com/library/exposed-database-scanner

### ASN-Wide Vulnerability Scan

Turn an ASN into its live hosts, then scan the raw ports and the web surface for CVEs, misconfigurations, and exposures. Findings land in one report.

Source: https://trickest.com/library/asn-vulnerability-scanner

## Modules

28 nestable modules — typed subgraphs you drop into a workflow as a single node.

### Analyze JavaScript Code

Retrieve JavaScript from a URL list, unpack it, and mine endpoints, wordlists, CVEs, secrets, and insecure client-side patterns in one nestable pass.

Source: https://trickest.com/library/modules/analyze-javascript-code

### Discover Paths via Crawling

Crawl live web server URLs, follow links and parse JavaScript, and emit a path map per asset. Nest when the surface is linked, not guessed or archived.

Source: https://trickest.com/library/modules/discover-paths-via-crawling

### Discover Paths via Directory Brute Force

Brute-force web server URLs to find hidden paths. Heuristics drop masked 404s. Built-in or custom wordlist. Thousands of servers in parallel.

Source: https://trickest.com/library/modules/discover-paths-via-directory-brute-force

### Discover Paths via OSINT Sources

Search OSINT sources for a host list to find hidden paths. Historical and recent URLs, normalized. Thousands of hosts. No traffic to the target.

Source: https://trickest.com/library/modules/discover-paths-via-osint-sources

### Enumerate DNS Records

Query A, AAAA, CNAME, MX, NS, TXT, CAA, and PTR for a host, IP, or CIDR list. Keep resolving names, addresses, and associated hostnames as line lists.

Source: https://trickest.com/library/modules/enumerate-dns-records

### Enumerate Hostnames via Crawling

Crawl live web servers and pull hostnames from links, script, and headers. Input is URLs, not root domains. Last in the hostname enum family; nest after probe.

Source: https://trickest.com/library/modules/enumerate-hostnames-via-crawling

### Enumerate Hostnames via DNS Permutations Brute Force

Generate DNS permutations from hostnames you have. Alter labels for staging, regions, and related software, then resolve. Built-in wordlist or org naming.

Source: https://trickest.com/library/modules/enumerate-hostnames-via-dns-permutations-brute-force

### Enumerate Hostnames via OSINT Sources

Enumerate hostnames from passive OSINT sources. No API keys required; optional keys expand sources. Finds related roots, not only subdomains of the target.

Source: https://trickest.com/library/modules/enumerate-hostnames-via-osint-sources

### Enumerate Hostnames via Recursive DNS Brute Force

Brute-force sub-subdomains of known hostnames. Rank likely prefixes, generate FUZZ at each DNS level, and resolve. Built-in or custom level wordlists. Caps per level.

Source: https://trickest.com/library/modules/enumerate-hostnames-via-recursive-dns-brute-force

### Enumerate Hostnames via Root Domain DNS Brute Force

Wordlist DNS brute force against root domains. Finds first-level names OSINT missed. Input is domains plus an optional custom wordlist, not known hostnames.

Source: https://trickest.com/library/modules/enumerate-hostnames-via-root-domain-dns-brute-force

### Fingerprint Network Services

Identify the service on each open port. Service fingerprinting returns protocol, banner, product, and version for misconfig and credential tests.

Source: https://trickest.com/library/modules/fingerprint-network-services

### Fingerprint Web Technologies

Identify CMS, CDN, and WAF on live web servers. Technology detection names server software, runtimes, and frameworks with version status.

Source: https://trickest.com/library/modules/fingerprint-web-technologies

### Fuzz Web Applications for Vulnerabilities

Web app fuzzing with active DAST. Crawl each app, inject payloads into discovered inputs, report insecure behaviors, and recrawl for stored issues.

Source: https://trickest.com/library/modules/fuzz-web-applications-for-vulnerabilities

### Generate Custom DNS Wordlists

Derive DNS brute-force wordlists from known hostnames. Root-class and recursive level lists for the hostname enum modules. Does not resolve names.

Source: https://trickest.com/library/modules/generate-custom-dns-wordlists

### Generate Scan Report

Wire findings, ports, DNS, WHOIS, screenshots, and tech fingerprints into one HTML zip. Composition sink for ASM and vuln pipelines, not a scanner.

Source: https://trickest.com/library/modules/generate-scan-report

### Get Cookies via Puppeteer Recording

Replay a Chrome DevTools Recorder login, capture cookies, and write a Cookie header file for downstream Library nodes. Utility, not a scanner.

Source: https://trickest.com/library/modules/get-cookies-via-puppeteer-recording

### Get Data from Dataset

Pull rows from a Solution dataset into a file for downstream Library nodes. Required: solution and dataset. Query, columns, order-by, and workspace are optional.

Source: https://trickest.com/library/modules/get-data-from-dataset

### Probe for Web Servers

Probe hostnames, IPs, or CIDR on common HTTP ports and keep the live web servers with title, redirect, status, server header, CDN, and TLS. The web-tail entry for recon pipelines.

Source: https://trickest.com/library/modules/probe-for-web-servers

### Scan for Exposed Admin Panels

Probe URL lists for admin panels across stacks, then try vendor default credentials on a subset. Headers and rate-limit included for fleet-scale runs.

Source: https://trickest.com/library/modules/scan-for-exposed-admin-panels

### Scan for Exposed Backups

Hunt hostname-named backup files like .bak, .sql, zip, and tarball dumps on a URL list. Heuristics cut false positives so hits are real archives.

Source: https://trickest.com/library/modules/scan-for-exposed-backups

### Scan for Exposed Secrets

Pattern-match live HTTP responses for exposed secrets like API tokens and credentials. Reuses responses across searches to scan a URL fleet at once.

Source: https://trickest.com/library/modules/scan-for-exposed-secrets

### Scan for Misconfigured Software

Scan URLs for web misconfigurations: exposed APIs, debug surfaces, default-state takeover. Response-validated. Not CVE matching, not config files.

Source: https://trickest.com/library/modules/scan-for-misconfigured-software

### Scan for Open Ports

Scan hostnames, IPs, and ranges for the top 1000 TCP ports. Set include and exclude ports and a per-host open-port threshold. Output feeds network service fingerprinting.

Source: https://trickest.com/library/modules/scan-for-open-ports

### Scan for Outdated Software

CVE scanning for known CVE and CNVD issues on a URL list. Matcher-based checks flag outdated software with published IDs. Not a live feed, not SCA.

Source: https://trickest.com/library/modules/scan-for-outdated-software

### Scan for Sensitive Files

Probe known paths for .env, .git/config, logs, and dev artifacts, and validate the body looks like a real file. Cuts soft-404s across a URL fleet.

Source: https://trickest.com/library/modules/scan-for-sensitive-files

### Scan for Technology-Specific Vulnerabilities

Tailored CVE scanning for ten web stacks post-fingerprint. WordPress, IIS, Ivanti, Joomla, GitLab, Jenkins, Spring Boot, Jira, Splunk, WebLogic.

Source: https://trickest.com/library/modules/scan-for-technology-specific-vulnerabilities

### Scan Network Services for Misconfigurations

Probe listening services from open-port records for information disclosure, exposed functionality, and takeover. Runs on port-details, rate-limited.

Source: https://trickest.com/library/modules/scan-network-services-for-misconfigurations

### Scan Network Services for Weak Credentials

Test weak credentials on SSH, FTP, MySQL, PostgreSQL, and Microsoft SQL Server with per-protocol wordlists. Lockout-aware rate-limit keeps runs safe.

Source: https://trickest.com/library/modules/scan-network-services-for-weak-credentials

## Tools

165 tools with a documented page. Every tool runs as a workflow node; the full catalog is at https://trickest.com/library/tools.

- [ac-scanner](https://trickest.com/tools/ac-scanner): BHUSA Arsenal TLS/SSH crypto inventory with post-quantum readiness signals and CBOM-shaped output.
- [agentsleak](https://trickest.com/tools/agentsleak): Black Hat Arsenal runtime security for AI coding agents, evaluated offline over recorded action events.
- [airixss](https://trickest.com/tools/airixss): Reflection triage for parameter URLs during recon.
- [amass-intel](https://trickest.com/tools/amass-intel): OWASP Amass intel: map an organization's root domains and ranges.
- [amass](https://trickest.com/tools/amass): Multi-source subdomain discovery; hand names to httpx.
- [apkurlgrep](https://trickest.com/tools/apkurlgrep): Extract URLs and endpoints from Android APK files.
- [asnmap](https://trickest.com/tools/asnmap): Map an organization's network ranges from ASN data.
- [assetfinder](https://trickest.com/tools/assetfinder): Find domains and subdomains potentially related to a given domain.
- [bandit](https://trickest.com/tools/bandit): Python source in, JSON security findings out.
- [bbot](https://trickest.com/tools/bbot): Modular OSINT recon that chains modules from a seed target.
- [bedrock-keys-security](https://trickest.com/tools/bedrock-keys-security): Black Hat Arsenal hunting for phantom IAM users behind Bedrock keys, with offline key decode and org scan.
- [bevigil](https://trickest.com/tools/bevigil): CLI client for the BeVigil OSINT API, keyed by domain or app package.
- [browser-fetch](https://trickest.com/tools/browser-fetch): Headless Chromium render: requested URL, final URL, status, and title next to the page.
- [cariddi](https://trickest.com/tools/cariddi): Crawl a domain list and scan responses for endpoints, secrets, tokens, and juicy files.
- [cewl](https://trickest.com/tools/cewl): Spider a URL and return a wordlist for password crackers.
- [cloud-enum](https://trickest.com/tools/cloud-enum): Multi-cloud public name enumeration for AWS, Azure, and GCP.
- [cloudlist](https://trickest.com/tools/cloudlist): List assets from multiple cloud providers in one inventory.
- [cmseek](https://trickest.com/tools/cmseek): CMS detection and version fingerprinting.
- [commix](https://trickest.com/tools/commix): Automates OS command injection detection and exploitation.
- [crawlergo](https://trickest.com/tools/crawlergo): Browser-driven crawler that harvests requests for downstream scanners.
- [crlfuzz](https://trickest.com/tools/crlfuzz): Go-based CRLF injection scanner for URLs and URL lists.
- [crosslinked](https://trickest.com/tools/crosslinked): Passive LinkedIn employee enumeration through search engine results.
- [csvkit](https://trickest.com/tools/csvkit): SQL on one CSV. The table name is the file stem.
- [dalfox](https://trickest.com/tools/dalfox): Parameter mining and XSS testing with headless verification.
- [dirsearch](https://trickest.com/tools/dirsearch): Web path scanner.
- [dnsdumpster-dns-lookup](https://trickest.com/tools/dnsdumpster-dns-lookup): Passive DNS records from DNSDumpster.
- [dnsgen](https://trickest.com/tools/dnsgen): Wordlist and mined-word subdomain permutation.
- [dnsreaper](https://trickest.com/tools/dnsreaper): Subdomain takeover scanner with cloud-zone intake.
- [dnsrecon](https://trickest.com/tools/dnsrecon): Active multi-technique DNS enumeration for assessments.
- [dnstwist](https://trickest.com/tools/dnstwist): Generate lookalike domains and flag registered typosquats.
- [dnsvalidator](https://trickest.com/tools/dnsvalidator): Validate public DNS resolvers against trusted baselines.
- [dnsx](https://trickest.com/tools/dnsx): Multi-purpose DNS toolkit for resolution, record queries, and wordlist brute force.
- [duckdb](https://trickest.com/tools/duckdb): In-process SQL on CSV, JSON, and Parquet. No server.
- [edge-tts](https://trickest.com/tools/edge-tts): Microsoft Edge neural speech from text or a script file. No API key.
- [exiftool](https://trickest.com/tools/exiftool): Read embedded metadata from hundreds of image, media, and document formats.
- [eyeballer](https://trickest.com/tools/eyeballer): Label website screenshots so interesting hosts surface first.
- [fallparams](https://trickest.com/tools/fallparams): Crawl pages, harvest potential parameters, write a custom wordlist.
- [favfreak](https://trickest.com/tools/favfreak): Hash favicons across a URL list and match them against a fingerprint dictionary.
- [favup](https://trickest.com/tools/favup): Look up the real IP of a host from its favicon via Shodan.
- [feroxbuster](https://trickest.com/tools/feroxbuster): Recursive content discovery with smart defaults and rich response filters.
- [ffmpeg](https://trickest.com/tools/ffmpeg): Convert one file or a folder of media and write the results next to each other.
- [ffprobe](https://trickest.com/tools/ffprobe): A media file in, structured technical metadata out.
- [ffuf](https://trickest.com/tools/ffuf): A fast web fuzzer written in Go.
- [find-gh-poc](https://trickest.com/tools/find-gh-poc): Locate public CVE proof-of-concept repositories on GitHub.
- [findmytakeover](https://trickest.com/tools/findmytakeover): Multi-cloud dangling DNS detection via zone-to-inventory diff, not wordlists.
- [findomain](https://trickest.com/tools/findomain): Passive subdomain enumeration with optional resolve and HTTP checks.
- [fping](https://trickest.com/tools/fping): Parallel ICMP echo sweeps for CIDR ranges and host files.
- [gau](https://trickest.com/tools/gau): Passive known-URL fetch from public web archives.
- [gauplus](https://trickest.com/tools/gauplus): Maintained gau fork for passive archive URL collection.
- [getJS](https://trickest.com/tools/getjs): Extract JavaScript file URLs from a page or URL list.
- [gitjacker](https://trickest.com/tools/gitjacker): Recover source from sites that leaked their .git directory.
- [gitleaks](https://trickest.com/tools/gitleaks): Detect hardcoded secrets in git repos and plain directories.
- [gittools-dumper-extractor](https://trickest.com/tools/gittools-dumper-extractor): Download an exposed .git and rebuild the working tree in one pass.
- [gittools-extractor](https://trickest.com/tools/gittools-extractor): Reconstruct commits from a dumped .git folder.
- [gobuster-dir](https://trickest.com/tools/gobuster-dir): Directory and file brute force against a live web target.
- [gobuster-dns](https://trickest.com/tools/gobuster-dns): DNS subdomain brute force with wildcard handling.
- [golemhalt](https://trickest.com/tools/golemhalt): Black Hat Arsenal reference monitor for coding agents, inventoried as a policy and provider corpus.
- [gosec](https://trickest.com/tools/gosec): Go AST security scanner for credentials, crypto, and injection.
- [gowitness-nmap](https://trickest.com/tools/gowitness-nmap): Screenshot web services discovered in an nmap XML scan.
- [gowitness](https://trickest.com/tools/gowitness): Headless Chrome screenshots for web target triage.
- [guarddog](https://trickest.com/tools/guarddog): A package coordinate in, indicator hits out.
- [h8mail](https://trickest.com/tools/h8mail): Email OSINT against breach services and local dumps.
- [hakrawler](https://trickest.com/tools/hakrawler): Go crawler for URLs, forms, and JavaScript locations.
- [honeymcp](https://trickest.com/tools/honeymcp): Black Hat Arsenal deception layer for MCP servers, exported as a schedulable ghost-tool catalog.
- [hosthunter](https://trickest.com/tools/hosthunter): OSINT mapping from IP addresses to virtual hostnames.
- [htmlq](https://trickest.com/tools/htmlq): jq-style extraction for HTML, driven by CSS selectors.
- [httprobe](https://trickest.com/tools/httprobe): Probe a domain list for working HTTP and HTTPS servers.
- [httpx](https://trickest.com/tools/httpx): A fast and multi-purpose HTTP toolkit that runs multiple probers with reliable, high-throughput results.
- [Hydra](https://trickest.com/tools/hydra): Parallel network login cracker for SSH, FTP, HTTP forms, and related services.
- [imagemagick](https://trickest.com/tools/imagemagick): One image in, one resized or converted image out.
- [Infoga](https://trickest.com/tools/infoga): Email OSINT from public sources, with optional breach checks.
- [jaeles](https://trickest.com/tools/jaeles): Signature-driven web application scanner.
- [joomscan](https://trickest.com/tools/joomscan): OWASP Joomla vulnerability scanner for CMS flaws and misconfigurations.
- [jq](https://trickest.com/tools/jq): Turn one JSON document into the exact records the next node needs.
- [jsluice](https://trickest.com/tools/jsluice): Extract URLs, paths, and secrets from JavaScript with a syntax tree.
- [jwt-tool](https://trickest.com/tools/jwt-tool): Decode, forge, crack, and tamper JWTs for auth checks.
- [katana](https://trickest.com/tools/katana): A fast crawling and spidering framework.
- [kiterunner](https://trickest.com/tools/kiterunner): Schema-aware API route discovery for modern apps.
- [kxss](https://trickest.com/tools/kxss): Triage reflected special characters on parameterized URLs.
- [libreoffice](https://trickest.com/tools/libreoffice): Office documents in, converted files out.
- [linkfinder](https://trickest.com/tools/linkfinder): Discover endpoints and parameters inside JavaScript files.
- [log4j-scan](https://trickest.com/tools/log4j-scan): Remote scanner for Log4Shell RCE, CVE-2021-44228.
- [maigret](https://trickest.com/tools/maigret): Username search that collects accounts and profile data into one dossier.
- [malcontent-scan](https://trickest.com/tools/malcontent-scan): A package coordinate in, behavior findings out.
- [mapcidr](https://trickest.com/tools/mapcidr): Expand, aggregate, and slice CIDR ranges into host lists.
- [masscan](https://trickest.com/tools/masscan): Asynchronous SYN port scanner for wide IP ranges; bound runs with --rate and --excludefile.
- [massdns](https://trickest.com/tools/massdns): DNS stub resolver for large domain lists.
- [mcparasite](https://trickest.com/tools/mcparasite): Black Hat Arsenal MCP context-worm testing: channel inventory by default, a gated kill chain on request.
- [miller](https://trickest.com/tools/miller): Named verbs for filtering, reshaping, sorting, and converting record streams.
- [naabu](https://trickest.com/tools/naabu): A fast and reliable port scanner that enumerates open ports for hosts.
- [netexec](https://trickest.com/tools/netexec): Authenticated network assessment across SMB, LDAP, WinRM, and more.
- [netscan](https://trickest.com/tools/netscan): Simple IP or CIDR sweep for open ports.
- [nikto](https://trickest.com/tools/nikto): Bundled web server checks for dangerous files and outdated software.
- [nomore403](https://trickest.com/tools/nomore403): Bypass 403/40X restrictions through smart request manipulation.
- [nscan](https://trickest.com/tools/nscan): Raw-socket SYN scanner for internet-wide port discovery, with optional banners and scripts.
- [nuclei](https://trickest.com/tools/nuclei): YAML template scanner for live hosts; scope runs with tags and severity.
- [ocrmypdf](https://trickest.com/tools/ocrmypdf): A scanned PDF in, a searchable PDF out.
- [onesixtyone](https://trickest.com/tools/onesixtyone): SNMP community-string scanner for host lists.
- [osv-malicious](https://trickest.com/tools/osv-malicious): A package coordinate in, malware advisory rows out.
- [osv-scanner](https://trickest.com/tools/osv-scanner): A lockfile in, advisory rows out.
- [p7zip](https://trickest.com/tools/p7zip): An archive in, its extracted files out.
- [pandoc](https://trickest.com/tools/pandoc): One document in, a different document format out.
- [paramspider](https://trickest.com/tools/paramspider): Passive archive miner for parameterized URLs on a domain.
- [patator](https://trickest.com/tools/patator): Modular multi-protocol credential brute forcer with response filtering.
- [pdftotext](https://trickest.com/tools/pdftotext): Plain text from one PDF. Distribute the node to convert many.
- [playwright](https://trickest.com/tools/playwright): Screenshot, HAR trace, or a user script after the page actually renders.
- [pup](https://trickest.com/tools/pup): CSS selectors over HTML, the jq counterpart for markup.
- [puredns](https://trickest.com/tools/puredns): A fast domain resolver and subdomain bruteforcing tool that filters out wildcards and poisoned entries.
- [pydictor](https://trickest.com/tools/pydictor): Rule-driven wordlist builder for brute-force pipelines.
- [qpdf](https://trickest.com/tools/qpdf): Rewrite PDF structure without rendering pages or changing their visible content.
- [quicdraw](https://trickest.com/tools/quicdraw): Black Hat Arsenal HTTP/3 client for Quic-Fin-Sync race testing and fuzzing over QUIC.
- [react2shell-scanner](https://trickest.com/tools/react2shell-scanner): Confirm the RSC and Next.js RCE CVEs on a URL or host list.
- [rss-read](https://trickest.com/tools/rss-read): Public RSS or Atom items, plus enclosure URLs, as JSONL.
- [rustscan](https://trickest.com/tools/rustscan): Port discovery that lists open ports for downstream service detection.
- [s3scanner](https://trickest.com/tools/s3scanner): Checks candidate S3 buckets for open permissions and can dump readable contents.
- [secretfinder](https://trickest.com/tools/secretfinder): Regex scan of JavaScript for API keys, tokens, JWTs, and similar client-side secrets.
- [semgrep-scan](https://trickest.com/tools/semgrep-scan): Static analysis with rules that look like the code they match.
- [sherlock](https://trickest.com/tools/sherlock): Username checks across social networks with optional CSV export.
- [shortscan](https://trickest.com/tools/shortscan): Enumerate IIS 8.3 short filenames to recover hidden paths.
- [shuffledns](https://trickest.com/tools/shuffledns): massdns wrapper for active subdomain brute force and resolution with wildcard filtering.
- [sigma-cli](https://trickest.com/tools/sigma-cli): Sigma YAML in, a SIEM query out.
- [socialscan](https://trickest.com/tools/socialscan): Check whether emails and usernames are available, taken, or invalid.
- [sourcemapper](https://trickest.com/tools/sourcemapper): Reconstruct JavaScript source trees from Sourcemap files.
- [spiderfoot](https://trickest.com/tools/spiderfoot): Automated OSINT modules for attack surface mapping.
- [sqlite3](https://trickest.com/tools/sqlite3): A SQLite file and query in, structured rows out.
- [sqlmap](https://trickest.com/tools/sqlmap): Detect and exploit SQL injection on authorized web targets.
- [sslyze](https://trickest.com/tools/sslyze): Python SSL/TLS scanner for protocols, certs, and named weaknesses.
- [subbrute](https://trickest.com/tools/subbrute): DNS subdomain brute force routed through open resolvers.
- [subdomainizer](https://trickest.com/tools/subdomainizer): Mine JavaScript and GitHub for subdomains, cloud URLs, and secrets.
- [subfinder](https://trickest.com/tools/subfinder): A subdomain discovery tool that finds valid subdomains using passive online sources.
- [subjack](https://trickest.com/tools/subjack): Concurrent subdomain takeover checks against dangling CNAMEs.
- [subzy](https://trickest.com/tools/subzy): Subdomain takeover checks driven by can-i-take-over-xyz response fingerprints.
- [sudomy](https://trickest.com/tools/sudomy): Subdomain enumeration with optional probing, takeover checks, and HTML reports.
- [swagger-jacker](https://trickest.com/tools/swagger-jacker): Audit endpoints declared in exposed Swagger and OpenAPI specs.
- [tesseract](https://trickest.com/tools/tesseract): Optical character recognition from one image. Distribute the node for many.
- [theharvester](https://trickest.com/tools/theharvester): Passive OSINT for emails, names, and subdomains on a domain.
- [threatxtension](https://trickest.com/tools/threatxtension): Black Hat Arsenal Chrome extension analysis: static rules, permission review, and optional enrichment.
- [tlsx](https://trickest.com/tools/tlsx): TLS grabber for certificates, SANs, and JARM or JA3 fingerprints.
- [tplmap](https://trickest.com/tools/tplmap): Detect and exploit server-side template injection on live parameters.
- [trafilatura](https://trickest.com/tools/trafilatura): Article body text plus title, author, date, and language from a URL list.
- [trajan](https://trickest.com/tools/trajan): Black Hat Arsenal CI/CD pipeline scanner for GitHub, GitLab, and Azure DevOps, offline or API driven.
- [trufflehog](https://trickest.com/tools/trufflehog): Hunt leaked credentials and verify which still work.
- [unfurl](https://trickest.com/tools/unfurl): Extract chosen URL parts from stdin into clean line lists.
- [urlhunter](https://trickest.com/tools/urlhunter): Search archives of URLs exposed via shortener services.
- [vhostscan](https://trickest.com/tools/vhostscan): Virtual host scanner with Host-header sweeps and catch-all detection.
- [wafw00f](https://trickest.com/tools/wafw00f): Fingerprint the WAF in front of a site before active scanning.
- [wapiti](https://trickest.com/tools/wapiti): Black-box crawler and fuzzer for web app injection classes.
- [waymore](https://trickest.com/tools/waymore): Multi-archive URL harvest with optional response download.
- [weasyprint](https://trickest.com/tools/weasyprint): HTML and CSS in, a paginated PDF out.
- [webagentaudit](https://trickest.com/tools/webagentaudit): Black Hat Arsenal auditing for web-facing AI agents through browser automation, with no provider token.
- [webanalyze](https://trickest.com/tools/webanalyze): Go Wappalyzer port for bulk technology fingerprinting.
- [whatwaf](https://trickest.com/tools/whatwaf): Fingerprint web application firewalls and test tamper bypasses.
- [whatweb](https://trickest.com/tools/whatweb): Plugin-based fingerprinting for CMS, servers, libraries, and devices.
- [whisper](https://trickest.com/tools/whisper): Speech to txt, vtt, srt, and json from an audio file or folder.
- [wpscan](https://trickest.com/tools/wpscan): WordPress scanner for plugins, themes, users, and known vulns.
- [xnlinkfinder](https://trickest.com/tools/xnlinkfinder): Endpoints and parameters from crawls and saved traffic.
- [yara-x](https://trickest.com/tools/yara-x): Files in, YARA match rows out.
- [youtube-transcript](https://trickest.com/tools/youtube-transcript): Public caption tracks to transcript.txt and results.jsonl.
- [yq](https://trickest.com/tools/yq): Use one expression language across YAML, JSON, XML, TOML, and properties.
- [yt-dlp](https://trickest.com/tools/yt-dlp): One URL or a URL list into a folder of media files.
- [zap-automation-framework](https://trickest.com/tools/zap-automation-framework): Ordered ZAP jobs from one YAML plan.
- [zdns](https://trickest.com/tools/zdns): CLI DNS lookup for bulk name lists.
- [zgrab2-jarm](https://trickest.com/tools/zgrab2-jarm): Active JARM TLS fingerprinting via zgrab2.
- [zircolite](https://trickest.com/tools/zircolite): Event logs and Sigma rules in, detection rows out.
- [zmap](https://trickest.com/tools/zmap): Stateless single-packet scanner for large port surveys.