Trapline runs your recon commands, flags juicy output in real time, checks credentials against five breach databases, and generates the full HackerOne report — CVSS, OWASP, impact. Free, local, no account.
No config files. No API keys to get started. Open the app, pick a target, start hunting.
Browse 215 commands across 30 categories or search by keyword. Start with Quickfire for the highest-ROI tests on any new target.
Hit run. Output streams live, and every line scans against 94 detection rules as it arrives — no waiting for the command to finish.
ATO tokens, secrets, private IPs, CORS misconfigs — color-coded by severity and flagged in real time before you finish reading.
One click: a complete HackerOne-ready report with CVSS vector, OWASP reference, and a business-impact statement.
Every command was added because it found something on a live program. No CTF fluff — just the workflows that pay.
Every command came from a real engagement. Quickfire fires the highest-ROI tests first — config.json sweep, CORS reflection, Kong portal UUID leak, idToken scan. 30 categories, live search.
94 patterns scan every output line as it prints. ATO token fields (idToken, access_token), Stripe/Twilio keys, private IPs, Mongo strings, AWS ARNs — lit up in red before you finish reading.
Check any email, username, or domain against five breach databases from one bar — LeakCheck, Snusbase, DeHashed, LeakRadar & Shodan — and read every result in one formal table.
The always-on sensor, built right in. It runs recon on a schedule, reconstructs a target's changed JS from its source maps, pings Discord, and auto-drafts the finding into Trapline.
Click the bug icon on any output card — title, severity, program, endpoint, PoC, impact. Everything persists to a local JSON file between sessions. No cloud, no account, no third party.
Generate the exact HackerOne template — CVSS + OWASP auto-filled. Export any breach search to MD, HTML, CSV, JSON or TXT, or drop it straight into a bug-bounty report.
Information disclosure is step one. Check an email, username, or domain against five providers at once — then read every leaked field in a single formal table, revealed by default so nothing hides.
| Username | Password | Source | |
|---|---|---|---|
| neo@acme.com | neo | hunter2 | Collection#1 |
| trin@acme.com | trinity | m0rpheus! | BreachCo '19 |
| tank@acme.com | tank | z10nRocks | DeHashed |
New surface is unhardened surface — whoever sees the change first gets the bug. Watch runs your recon on a schedule and watches a target's JavaScript. When a bundle changes, it rebuilds the original source from exposed source maps and diffs it per file, so bundle-hash churn is zero noise.
The whole deck — all 215 commands, real-time detection, breach intel, Watch, the finding tracker and the one-click report generator. No license key, no account, no upsell.
Free forever. No subscription, no license. macOS & Linux builds coming in v1.1 — free too.