Metadata-Version: 2.4
Name: oxhunter
Version: 2.0.1
Summary: Advanced web vulnerability scanner for authorized security testing
Author-email: Talha Imran <talhaimran20008@gmail.com>
License: MIT License with Ethical Use Clause
        
        Copyright (c) 2026 0xHunter
        
        Permission is hereby granted, free of charge, to any person obtaining a copy
        of this software and associated documentation files (the "Software"), to use
        the Software for LEGAL and AUTHORIZED security testing only.
        
        RESTRICTIONS:
        - This tool may ONLY be used on systems you OWN or have WRITTEN AUTHORIZATION to test.
        - The authors assume NO LIABILITY for misuse or illegal activities.
        - By using this software, you agree to comply with all applicable laws.
        
        THIS SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND.
Project-URL: Homepage, https://github.com/Talha-Imran-cloud/Oxhunter
Project-URL: Repository, https://github.com/Talha-Imran-cloud/Oxhunter
Project-URL: Issues, https://github.com/Talha-Imran-cloud/Oxhunter/issues
Keywords: security,vulnerability-scanner,web-security,penetration-testing,owasp
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Information Technology
Classifier: Intended Audience :: System Administrators
Classifier: License :: OSI Approved :: MIT License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: Security
Classifier: Topic :: System :: Monitoring
Requires-Python: >=3.10
Description-Content-Type: text/markdown
License-File: LICENSE
Requires-Dist: httpx[http2]>=0.27.0
Requires-Dist: requests>=2.31.0
Requires-Dist: urllib3>=2.0.0
Requires-Dist: websocket-client>=1.7.0
Requires-Dist: aiohttp>=3.9.0
Requires-Dist: beautifulsoup4>=4.12.0
Requires-Dist: lxml>=5.0.0
Requires-Dist: typer>=0.9.0
Requires-Dist: rich>=13.7.0
Requires-Dist: jinja2>=3.1.0
Requires-Dist: pdfkit>=1.0.0
Requires-Dist: pyyaml>=6.0.1
Requires-Dist: pydantic>=2.5.0
Requires-Dist: aiofiles>=23.0.0
Requires-Dist: python-dotenv>=1.0.0
Requires-Dist: cryptography>=42.0.0
Requires-Dist: pyOpenSSL>=24.0.0
Requires-Dist: pyjwt>=2.8.0
Requires-Dist: dnspython>=2.6.0
Requires-Dist: python-whois>=0.8.0
Requires-Dist: playwright>=1.40.0
Requires-Dist: groq>=0.9.0
Requires-Dist: slack-sdk>=3.27.0
Requires-Dist: jira>=3.8.0
Requires-Dist: PyGithub>=2.3.0
Requires-Dist: colorama>=0.4.6
Requires-Dist: tqdm>=4.66.0
Requires-Dist: tabulate>=0.9.0
Requires-Dist: certifi>=2024.0.0
Requires-Dist: Pillow>=10.0.0
Requires-Dist: flask>=3.0.0
Requires-Dist: flask-socketio>=5.3.0
Requires-Dist: ipwhois>=1.2.0
Dynamic: license-file

<div align="center">

```
  ___       _   _ _   _ _   _ _____ _____ ____  
 / _ \__  _| | | | | | | \ | |_   _| ____|  _ \ 
| | | \ \/ / |_| | | | |  \| | | | |  _| | |_) |
| |_| |>  <|  _  | |_| | |\  | | | | |___|  _ < 
 \___//_/\_\_| |_|\___/|_| \_| |_| |_____|_| \_\
                                            v2.0.0
```

**Advanced Web Vulnerability Scanner — 76+ Files · 2033+ Payloads · AI-Powered**

[![Python](https://img.shields.io/badge/Python-3.10+-black?style=for-the-badge&logo=python)](https://python.org)
[![Version](https://img.shields.io/badge/Version-2.0.0-black?style=for-the-badge)](CHANGELOG.md)
[![License](https://img.shields.io/badge/License-MIT-black?style=for-the-badge)](LICENSE)
[![Modules](https://img.shields.io/badge/Modules-70+-black?style=for-the-badge)](modules/)
[![Payloads](https://img.shields.io/badge/Payloads-2033+-black?style=for-the-badge)](payloads/)
[![AI](https://img.shields.io/badge/AI-Groq%20LLaMA%203-black?style=for-the-badge)](https://groq.com)
[![LinkedIn](https://img.shields.io/badge/LinkedIn-Talha_Imran-black?style=for-the-badge&logo=linkedin)](https://www.linkedin.com/in/talha-imran-583a44420)
[![GitHub](https://img.shields.io/badge/GitHub-Talha--Imran--cloud-black?style=for-the-badge&logo=github)](https://github.com/Talha-Imran-cloud)

[**Features**](#features) · [**Installation**](#installation) · [**Commands**](#commands) · [**AI Setup**](#ai-setup) · [**Reports**](#reports) · [**Legal**](#legal)

> ⚠️ **For authorized security testing ONLY. Never scan without written permission.**

</div>

---

## What's New in v2.0

| Feature | v1.0 | v2.0 |
|---------|------|------|
| Payloads | 379 | **2033+** |
| Payload Categories | 9 | **20** |
| Live Web Dashboard | ❌ | ✅ Real-time |
| Mass Scan / ASN Scanner | ❌ | ✅ |
| Nuclei Template Support | ❌ | ✅ 5000+ templates |
| AI Auto-Exploit Generator | ❌ | ✅ Working PoC |
| Smart Attack Chaining | ❌ | ✅ SSRF→RCE |
| OAuth 2.0 / OIDC Tester | ❌ | ✅ |
| Supply Chain Detector | ❌ | ✅ npm/pip |
| Passive Recon Engine | ❌ | ✅ Shodan+Wayback |
| Auto Payload Injection | ❌ | ✅ |
| WAF Detect/Bypass Flags | ❌ | ✅ |
| Compliance Flags | ❌ | ✅ |
| Multi-target Support | ❌ | ✅ |

---

## Features

### Core Modules (9)
| Module | Payloads |
|--------|----------|
| XSS Scanner (Reflected, Stored, DOM) | 254 |
| SQL Injection (Error, Blind, Time) | 221 |
| CSRF Detection | 10 |
| Open Redirect | 68 |
| Directory Bruteforce | 163 |
| Subdomain Enumeration | 127 |
| Header Security Analyzer | — |
| SSL/TLS Checker | — |
| CORS Misconfiguration | 21 |

### Security Testing (6)
| Module | Severity | Payloads |
|--------|----------|----------|
| SSRF | CRITICAL | 173 |
| XXE Injection | CRITICAL | 48 |
| Command Injection | CRITICAL | 165 |
| IDOR Detection | HIGH | 83 |
| Race Condition | MEDIUM | — |
| HTTP Request Smuggling | HIGH | 16 |

### New Features (8) 🔥
| Feature | Description |
|---------|-------------|
| 🖥️ Live Web Dashboard | Real-time scan progress browser mein |
| 🌐 Mass Scan / ASN | IP range + company domains scan |
| 🎯 Nuclei Integration | 5000+ community templates |
| 🤖 AI Exploit Generator | Working PoC code auto-generate |
| ⛓️ Smart Attack Chaining | SSRF→RCE, XSS→Account Takeover |
| 🔑 OAuth 2.0 / OIDC | Token leakage, PKCE bypass |
| 📦 Supply Chain Detector | npm/pip typosquatting |
| 🔍 Passive Recon Engine | Shodan + Wayback + Dorks + crt.sh |

### AI Features (6 — Groq Free)
- AI Payload Generator
- Smart Vulnerability Chaining
- False Positive Reducer
- Natural Language Report (English + Urdu)
- **AI Auto-Exploit Generator** ← New
- **Smart Attack Chain Analysis** ← New

### Advanced Recon (6)
| Module | Description |
|--------|-------------|
| JS File Analysis | Endpoints, API keys, secrets |
| GraphQL Testing | Introspection + injection |
| WebSocket Testing | XSS, SQLi, origin bypass |
| API Versioning Attack | Deprecated endpoints |
| Prototype Pollution | JS chain attacks |
| Business Logic Testing | Price, IDOR, workflow |

### Integrations (4)
- Slack + Discord Alerts
- Jira + GitHub Issues
- Burp Suite Import/Export
- GitHub Actions CI/CD

### Compliance (3)
- OWASP Top 10 + Score
- PCI-DSS v4.0 Report
- ISO 27001:2022 Report + Bug Bounty Mode

### Payload Count (2033+)
| Category | Count | Category | Count |
|----------|-------|----------|-------|
| XSS | 254 | SSTI | 87 |
| SQLi | 221 | WAF Bypass | 95 |
| SSRF | 173 | IDOR | 83 |
| CMD Injection | 165 | Open Redirect | 68 |
| Sensitive Files | 111 | Auth Bypass | 74 |
| LFI | 139 | JWT | 61 |
| Common Dirs | 163 | XXE | 48 |
| Subdomains | 127 | Prototype Poll | 55 |
| **TOTAL** | | | **2033+** |

---

## Installation

### Linux / Kali / macOS
```bash
git clone https://github.com/Talha-Imran-cloud/OXHUNTER.git
cd OXHUNTER
pip install -r requirements.txt
playwright install chromium
python 0xhunter.py version
```

### Windows (PowerShell)
```powershell
git clone https://github.com/Talha-Imran-cloud/OXHUNTER.git
cd OXHUNTER
pip install -r requirements.txt
playwright install chromium
python 0xhunter.py version
```

### Virtual Environment
```bash
python3 -m venv venv
source venv/bin/activate       # Linux/Mac
# venv\Scripts\activate        # Windows
pip install -r requirements.txt
playwright install chromium
```

---

## Commands

```bash
python 0xhunter.py --help
python 0xhunter.py scan --help
python 0xhunter.py version
```

### Basic Scan
```bash
# Standard scan — 7 core modules
python 0xhunter.py scan https://target.com --confirm

# Full scan — all modules + 2033 payloads
python 0xhunter.py scan https://target.com --confirm --full

# Verbose
python 0xhunter.py scan https://target.com --confirm --full --verbose
```

### Reports
```bash
python 0xhunter.py scan https://target.com --confirm --report html
python 0xhunter.py scan https://target.com --confirm --report json
python 0xhunter.py scan https://target.com --confirm --report both
python 0xhunter.py scan https://target.com --confirm --report html --output myreport.html
```

### Authentication
```bash
python 0xhunter.py scan https://target.com --confirm --cookie "session=abc123"
python 0xhunter.py scan https://target.com --confirm --token "Bearer eyJhbGci..."
python 0xhunter.py scan https://target.com --confirm --auth "admin:password"
```

### Proxy
```bash
python 0xhunter.py scan https://target.com --confirm --proxy http://127.0.0.1:8080
```

### AI Features
```bash
# Set key first
export GROQ_API_KEY="gsk_your_key"           # Linux/Mac
$env:GROQ_API_KEY = "gsk_your_key"           # Windows

python 0xhunter.py scan https://target.com --confirm --ai
python 0xhunter.py scan https://target.com --confirm --ai --lang en
python 0xhunter.py scan https://target.com --confirm --ai --lang ur
python 0xhunter.py scan https://target.com --confirm --ai --ai-chain
python 0xhunter.py scan https://target.com --confirm --ai --ai-fp
python 0xhunter.py scan https://target.com --confirm --full --ai --ai-chain --ai-fp --lang ur
```

### WAF
```bash
python 0xhunter.py scan https://target.com --confirm --waf-detect
python 0xhunter.py scan https://target.com --confirm --waf-bypass
python 0xhunter.py scan https://target.com --confirm --waf-detect --waf-bypass
```

### Compliance
```bash
python 0xhunter.py scan https://target.com --confirm --compliance owasp
python 0xhunter.py scan https://target.com --confirm --compliance pci
python 0xhunter.py scan https://target.com --confirm --compliance iso
python 0xhunter.py scan https://target.com --confirm --bug-bounty --scope "*.target.com"
```

### Notifications
```bash
python 0xhunter.py scan https://target.com --confirm --notify slack
python 0xhunter.py scan https://target.com --confirm --notify discord
python 0xhunter.py scan https://target.com --confirm --notify both
```

### Integrations
```bash
python 0xhunter.py scan https://target.com --confirm --github-issues
python 0xhunter.py scan https://target.com --confirm --jira
python 0xhunter.py scan https://target.com --confirm --export-burp reports/burp.xml
```

### Scan Control
```bash
python 0xhunter.py scan https://target.com --confirm --threads 20 --timeout 15 --delay 0.3
python 0xhunter.py scan https://target.com --confirm --resume SCAN_ID
python 0xhunter.py scan --targets targets.txt --confirm
```

---

## 🆕 New Feature Commands

### 🖥️ Live Web Dashboard
```bash
# Dashboard start karo — browser mein real-time scan progress dekho
python 0xhunter.py dashboard

# Custom port pe
python 0xhunter.py dashboard --port 9000

# Browser mein kholo:
# http://127.0.0.1:8787

# Dashboard + Scan (2 terminals):
# Terminal 1:
python 0xhunter.py dashboard
# Terminal 2:
python 0xhunter.py scan https://target.com --confirm --full
```

### 🌐 Mass Scan / ASN Scanner
```bash
# File se multiple targets
python 0xhunter.py mass-scan --targets-file targets.txt --confirm

# CIDR range scan
python 0xhunter.py mass-scan --cidr 192.168.1.0/24 --confirm

# ASN se puri company scan
python 0xhunter.py mass-scan --targets-file targets.txt --asn AS13335 --confirm

# Concurrency control
python 0xhunter.py mass-scan --targets-file targets.txt --confirm --concurrency 20

# JSON output
python 0xhunter.py mass-scan --targets-file targets.txt --confirm --output results.json
```

### 🎯 Nuclei Template Support
```bash
# 5000+ community templates
python 0xhunter.py nuclei --targets-file targets.txt --confirm

# Specific severity
python 0xhunter.py nuclei --targets-file targets.txt --confirm --severity critical,high

# Custom templates directory
python 0xhunter.py nuclei --targets-file targets.txt --confirm --templates ./my-templates/

# JSON output
python 0xhunter.py nuclei --targets-file targets.txt --confirm --output nuclei_results.json
```

### 🔍 Passive Recon Engine
```bash
# Shodan + Wayback Machine + Google Dorks + crt.sh
python 0xhunter.py scan https://target.com --confirm --passive-recon

# Recon only (no active scanning)
python 0xhunter.py scan https://target.com --confirm --recon-only

# Saves to: reports/passive_recon.html
```

### 🤖 AI Auto-Exploit Generator
```bash
# AI se working PoC code generate karo (--ai required)
python 0xhunter.py scan https://target.com --confirm --full --ai --exploit-gen

# Exploits yahan save honge:
# reports/exploits/01_xss_high.js
# reports/exploits/02_sqli_critical.py
# reports/exploits.html
```

### ⛓️ Smart Attack Chaining
```bash
# Automatic chain detection (no AI needed)
python 0xhunter.py scan https://target.com --confirm --full --chain-attacks

# AI-enhanced chaining (creative chains)
python 0xhunter.py scan https://target.com --confirm --full --ai --chain-attacks

# Saves to: reports/attack_chains.html
# Examples: SSRF→RCE, XSS→CSRF→Account Takeover, SQLi→RCE
```

### 🔑 OAuth 2.0 / OIDC Tester
```bash
# Modern auth flows test karo
python 0xhunter.py scan https://target.com --confirm --oauth

# OAuth + Full scan
python 0xhunter.py scan https://target.com --confirm --full --oauth

# Tests: token leakage, PKCE bypass, redirect_uri manipulation,
#        missing state, scope escalation, client secret exposure
```

### 📦 Supply Chain Attack Detector
```bash
# npm/pip typosquatting + dependency confusion
python 0xhunter.py scan https://target.com --confirm --supply-chain

# Full scan + supply chain
python 0xhunter.py scan https://target.com --confirm --full --supply-chain

# Checks: package.json, requirements.txt, CDN SRI, typosquats
```

---

## Power Commands

```bash
# Ultimate scan — sab features
python 0xhunter.py scan https://target.com \
  --confirm --full \
  --ai --ai-chain --ai-fp --lang en \
  --waf-detect --waf-bypass \
  --compliance owasp \
  --passive-recon \
  --exploit-gen --chain-attacks \
  --oauth --supply-chain \
  --notify slack \
  --report html \
  --verbose

# Bug Bounty
python 0xhunter.py scan https://target.com \
  --confirm --full --ai \
  --bug-bounty --scope "*.target.com" \
  --chain-attacks --exploit-gen \
  --report html --notify discord

# Red Team
python 0xhunter.py scan https://target.com \
  --confirm --full --ai \
  --exploit-gen --chain-attacks \
  --waf-bypass --proxy http://127.0.0.1:8080 \
  --report html
```

---

## All Flags Reference

| Flag | Short | Default | Description |
|------|-------|---------|-------------|
| `--confirm` | `-c` | False | Authorization (required) |
| `--full` | `-f` | False | All modules |
| `--verbose` | `-v` | False | Verbose output |
| `--report` | `-r` | None | html/json/both |
| `--output` | `-o` | auto | Output path |
| `--cookie` | — | None | Session cookie |
| `--token` | — | None | Bearer/JWT |
| `--auth` | — | None | Basic auth |
| `--proxy` | — | None | Proxy URL |
| `--ai` | — | False | AI features |
| `--lang` | — | en | en/ur |
| `--ai-chain` | — | False | Vuln chaining |
| `--ai-fp` | — | False | FP reducer |
| `--waf-detect` | — | False | WAF detect |
| `--waf-bypass` | — | False | WAF bypass |
| `--compliance` | — | None | owasp/pci/iso |
| `--bug-bounty` | — | False | BB mode |
| `--scope` | — | None | In-scope domains |
| `--notify` | — | None | slack/discord/both |
| `--github-issues` | — | False | GitHub issues |
| `--jira` | — | False | Jira tickets |
| `--export-burp` | — | None | Burp XML path |
| `--threads` | `-t` | 10 | Threads |
| `--timeout` | — | 10 | Timeout (s) |
| `--delay` | — | 0.5 | Request delay |
| `--resume` | — | None | Resume scan ID |
| `--targets` | — | None | Multi-target file |
| `--passive-recon` | — | False | Shodan+Wayback+Dorks |
| `--recon-only` | — | False | Recon only |
| `--exploit-gen` | — | False | AI PoC generator |
| `--chain-attacks` | — | False | Attack chaining |
| `--oauth` | — | False | OAuth/OIDC testing |
| `--supply-chain` | — | False | Supply chain check |

---

## All Commands
| Command | Description |
|---------|-------------|
| `scan` | Web vulnerability scan |
| `version` | Show version info |
| `dashboard` | Start live web dashboard |
| `mass-scan` | Mass scan / ASN scanner |
| `nuclei` | Nuclei template runner |

---

## AI Setup

1. Go to **[console.groq.com/keys](https://console.groq.com/keys)**
2. Sign up (no credit card)
3. Create API Key → copy `gsk_xxx`

```bash
GROQ_API_KEY=gsk_your_key_here   # .env file mein add karo
```

**Free Tier:** 14,400 req/day · 500K tokens/day ✅

---

## CI/CD

```yaml
name: OXHUNTER Security Scan
on:
  push:
    branches: [main]
  schedule:
    - cron: '0 2 * * 1'

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v4
        with:
          python-version: '3.11'
      - run: pip install -r requirements.txt && playwright install chromium
      - run: |
          python 0xhunter.py scan ${{ secrets.TARGET_URL }} \
            --confirm --full --report json --output results.json
        env:
          GROQ_API_KEY: ${{ secrets.GROQ_API_KEY }}
          SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }}
      - uses: actions/upload-artifact@v3
        with:
          name: security-report
          path: results.json
```

---

## Reports

```
reports/
├── report.html           ← Main vulnerability report
├── report.json           ← Raw findings (JSON)
├── passive_recon.html    ← Passive recon results
├── attack_chains.html    ← Attack chain analysis
├── exploits.html         ← AI exploit report
├── burp_export.xml       ← Burp Suite format
├── nl_report_en.txt      ← AI English report
├── nl_report_ur.txt      ← AI Urdu report
└── screenshots/          ← Evidence screenshots
    exploits/
    ├── 01_xss_high.js
    └── 02_sqli_critical.py
```

---

## Severity Levels

| Level | CVSS | Action |
|-------|------|--------|
| 🔴 Critical | 9.0–10.0 | Fix immediately |
| 🟠 High | 7.0–8.9 | Fix within 24h |
| 🟡 Medium | 4.0–6.9 | Fix within 7 days |
| 🔵 Low | 1.0–3.9 | Next sprint |
| ⚪ Info | 0.0 | Monitor |

---

## Troubleshooting

```bash
# chardet warning
pip install --upgrade requests urllib3 chardet

# playwright missing
playwright install chromium

# websocket error
pip install websocket-client

# flask missing (dashboard)
pip install flask flask-socketio

# AI not working
echo $GROQ_API_KEY   # must start with gsk_

# Nuclei not found
# Download: https://github.com/projectdiscovery/nuclei/releases
```

---

## Legal

```
✅ Authorized penetration testing
✅ Bug bounty (in-scope only)
✅ Security research + education
✅ CTF challenges

❌ Unauthorized scanning
❌ Malicious use
❌ Illegal activity
```

---

<div align="center">

## Author

**Talha Imran** — SOC Analyst · Web Pentester · Security Researcher

[![LinkedIn](https://img.shields.io/badge/LinkedIn-Talha_Imran-black?style=for-the-badge&logo=linkedin)](https://www.linkedin.com/in/talha-imran-583a44420)
[![GitHub](https://img.shields.io/badge/GitHub-Talha--Imran--cloud-black?style=for-the-badge&logo=github)](https://github.com/Talha-Imran-cloud)
[![CloudSentrix](https://img.shields.io/badge/Project-CloudSentrix-black?style=for-the-badge)](https://cloudsentrix.netlify.app/)

**⭐ Star karo agar tool kaam aaya!**

*Built for the security community — use responsibly.*

</div>
