{"repo":"project-hellhound-org/Hellhound-Spider","free":true,"listed":false,"github":"https://github.com/project-hellhound-org/Hellhound-Spider","clone":"git clone https://github.com/project-hellhound-org/Hellhound-Spider.git","description":"Fully autonomous web crawler and Attack Surface Management (ASM) engine for security testing. Maps endpoints, parameters, and vulnerabilities across SPAs and traditio","language":"Python","stars":12,"topics":["autonomous-agent","bug-bounty","content-discovery","crawler","credential-harvesting","python3","reconnaissance","spider","web","xhr"],"license":"GPL-3.0","category":"scrapers-browser-automation","readme_excerpt":"Hellhound Spider Fully autonomous web crawler for security testing — maps endpoints, parameters, and security issues across traditional and SPA web applications. Drop a URL. Walk away. --- What It Does Hellhound Spider crawls a web application and produces a complete map of every endpoint, parameter, and security surface it can reach. The output is a structured JSON report — sorted by confidence, with parameters grouped by source, ready to feed directly into attack agents or import into Burp Suite. It runs two crawl engines in parallel: async HTTP workers for speed, and headless Chromium for JavaScript-heavy SPAs. For SPAs it intercepts live XHR and fetch calls as the browser actually makes them — including POST body parameters and response IDs. When the crawl finishes, it classifies every endpoint automatically so downstream agents start with context, not cold discovery. --- Installation Linux / macOS The installer creates an isolated virtual environment ( .venv ) and a system-wide spider wrapper: A man page is also installed — run man spider for the full reference. Windows Uninstall v13.21 — CTF Mode & CORS Auditing v13.21 introduces a dedicated --ctf flag for CTF players, automated CORS vulnerability checks, and automated query parameter parsing. New in v13.21 - CTF Mode ( --ctf ) — Automatically enables sensitive file scanning, admin panel checks, OpenAPI/GraphQL discovery, CORS audits, flag extraction, high default concurrency, and highlights high-value parameters and ba","default_branch":null,"files":null,"tree":[],"storefront":"/r/project-hellhound-org","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/project-hellhound-org/Hellhound-Spider/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}