Security · 2026 · Live demo · Open source · 2026
Horcrux
An operator-grade reconnaissance orchestration console that unifies network discovery, service fingerprinting, web fuzzing, and exploit intelligence into verified evidence workspaces.
- My role
- Designed and built the Typer console, Rich live progress managers, service-to-module router, and Next Best Action engine.
- Status
- Live demo · Open source · 2026
- Category
- Security · Offensive-security orchestration
Live demo · interactive
Embedded for convenience — if it doesn’t load here, open the full site directly.
Understand
Why it exists. Early security assessments suffer from fragmented tools, disconnected logs, and hallucinated AI findings. Horcrux provides an authoritative, evidence-driven operator platform.
What I built. Operator-grade Python CLI and interactive terminal console powered by Typer, Rich live progress managers, and pluggable enumeration engines for web, SMB, SSH, LDAP, and database services.
The problem it solves. Early-stage security assessments are fragmented across disconnected recon, port scanning, web fuzzing, and vulnerability tools with no shared evidence trail, leading to lost context and hallucinated findings.
What it does
- Centralized service router dispatches Nmap, FFUF, Nuclei, and SearchSploit across open ports
- Every observation is captured as raw evidence in isolated per-target workspaces
- State-aware Next Best Action engine guides operator methodology
- Multi-provider AI triage (Gemini, OpenAI, Anthropic, Groq) restricted strictly to verified evidence
Technical depth
Architecture. A centralized service-to-module router automatically dispatches Nmap, FFUF/Gobuster, Nuclei, and SearchSploit based on open ports. Findings are normalized into immutable, per-target workspace artifacts evaluated by a deterministic Next Best Action engine and a governed multi-provider AI triage layer (Google Gemini, OpenAI, Anthropic, Groq).
Security model. Deterministic-first architecture: tools are authoritative and the AI layer is strictly advisory, preventing hallucinated vulnerabilities. Sensitive API keys are stored in OS keychain with masked displays and isolated target sandboxes.
Tradeoff. Deterministic tools are authoritative and the AI layer is strictly advisory: prevents hallucinated vulnerabilities, ensuring findings are reproducible.
- Python
- Typer
- Rich
- Nmap
- Nuclei
- SearchSploit
- Multi-provider AI