AADITHYA VIMAL

Security · 2026 · Live demo · Open source · 2026

Horcrux

An operator-grade reconnaissance orchestration console that unifies network discovery, service fingerprinting, web fuzzing, and exploit intelligence into verified evidence workspaces.

My role
Designed and built the Typer console, Rich live progress managers, service-to-module router, and Next Best Action engine.
Status
Live demo · Open source · 2026
Category
Security · Offensive-security orchestration
Live demoSource on GitHub

Live demo · interactive

🔒horcruxtool.pages.dev
CONNECTING TO HORCRUX...

Embedded for convenience — if it doesn’t load here, open the full site directly.

01

Understand

Why it exists. Early security assessments suffer from fragmented tools, disconnected logs, and hallucinated AI findings. Horcrux provides an authoritative, evidence-driven operator platform.

What I built. Operator-grade Python CLI and interactive terminal console powered by Typer, Rich live progress managers, and pluggable enumeration engines for web, SMB, SSH, LDAP, and database services.

The problem it solves. Early-stage security assessments are fragmented across disconnected recon, port scanning, web fuzzing, and vulnerability tools with no shared evidence trail, leading to lost context and hallucinated findings.

What it does

  • Centralized service router dispatches Nmap, FFUF, Nuclei, and SearchSploit across open ports
  • Every observation is captured as raw evidence in isolated per-target workspaces
  • State-aware Next Best Action engine guides operator methodology
  • Multi-provider AI triage (Gemini, OpenAI, Anthropic, Groq) restricted strictly to verified evidence
02

Technical depth

Architecture. A centralized service-to-module router automatically dispatches Nmap, FFUF/Gobuster, Nuclei, and SearchSploit based on open ports. Findings are normalized into immutable, per-target workspace artifacts evaluated by a deterministic Next Best Action engine and a governed multi-provider AI triage layer (Google Gemini, OpenAI, Anthropic, Groq).

Security model. Deterministic-first architecture: tools are authoritative and the AI layer is strictly advisory, preventing hallucinated vulnerabilities. Sensitive API keys are stored in OS keychain with masked displays and isolated target sandboxes.

Tradeoff. Deterministic tools are authoritative and the AI layer is strictly advisory: prevents hallucinated vulnerabilities, ensuring findings are reproducible.

  • Python
  • Typer
  • Rich
  • Nmap
  • Nuclei
  • SearchSploit
  • Multi-provider AI
How it works, step by step

A centralized service-to-module router automatically dispatches Nmap, FFUF/Gobuster, Nuclei, and SearchSploit based on open ports. Findings are normalized into immutable, per-target workspace artifacts evaluated by a deterministic Next Best Action engine and a governed multi-provider AI triage layer (Google Gemini, OpenAI, Anthropic, Groq).

Security notes

Deterministic-first architecture: tools are authoritative and the AI layer is strictly advisory, preventing hallucinated vulnerabilities. Sensitive API keys are stored in OS keychain with masked displays and isolated target sandboxes.

Security