Example Usage
autoar domain run -d <domain> Full end-to-end workflow: subdomains → live hosts → ports →
[--skip-ffuf] tech → DNS → S3 → nuclei → JS → URLs → GF → backup → misconfig
autoar subdomain run -s <subdomain> Focused deep-dive on a single subdomain:
live check → ports → JS → vuln scan → nuclei
autoar lite run -d <domain> Lighter workflow: livehosts → reflection → JS → CNAME → DNS → misconfig
[--skip-js] Skip JavaScript scanning
[--phase-timeout] Set default phase timeout in seconds
[--timeout-<phase>] Specific overrides (e.g. --timeout-livehosts)
autoar fastlook run -d <domain> Quick recon: subdomains → live hosts → URLs/JS collection
autoar asr -d <domain> High-depth reconnaissance (ASR Modes)
[-mode 1-5] Recon mode (default: 5)
[-t <threads>] Number of threads
See also
BurpAPISecuritySuite
Open Source
Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzi…
agent-audit
Open Source
Static security scanner for LLM agents — prompt injection, MCP config auditing, taint analysis. 49 r…
cbrutekrag
Open Source
Penetration tests on SSH servers using brute force or dictionary attacks. Written in C.…
deepce
Open Source
Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)…
agent-security-scanner-mcp
Open Source
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination d…
o365spray
Open Source
Username enumeration and password spraying tool aimed at Microsoft O365.…