AI Labs AI Labs
Mobile red team · restricted access

Axonsploit

A native Android operator console that drives a full penetration-testing engagement from a phone — with the same governance discipline we build into every AI Labs platform: human approval before every action, hard scope enforcement, and a tamper-evident audit trail. As far as we know, nothing else like it exists.

Access is governed, not self-serve

Axonsploit is not distributed on request. It is made available only to demonstrated, authoritative research and security-testing engagements, under the same strict governance we apply everywhere else in the portfolio — vetted counterparties, defined scope, and full audit accountability for every session. If that describes your engagement, contact us and we'll walk through what qualifies.

Why a phone

A full operator console, not a remote shell to one

Axonsploit talks directly to a Metasploit RPC daemon — on-device via NetHunter, or to a remote Kali box over a pinned TLS connection — and gives the operator a touch-first console, module browser, live session I/O, and job management. It is built to be carried, not parked on a laptop.

Target
Discovery
Tap a target, scan it, get plain-language recommended modules.
Scope check
Enforced, not advisory
Every module run is checked against the engagement's declared scope.
⛔ out-of-scope → refused
Copilot
HITL plan approval
Attack plan drafted and risk-badged — nothing executes unsupervised.
Execute
Step by step
Each step runs, is observed, and can be stopped mid-engagement.
Audit
Signed trail
Every action and approval timestamped and cryptographically signed.
Report
Auto-generated
Findings, evidence, CVSS and ATT&CK mapping drafted from the trail.
See it work illustrative

The real app, walked through

These are the app's actual screens. All target data below is synthetic — a lab scope (10.0.0.5 / example.local), fake nearby networks, fake sessions — never a real engagement.

Targets

sandbox-lab · authorized scope
ENGAGEMENTActive
sandbox-lab
Authorized scope
10.0.0.5
1targets
1sessions
10.0.0.5Added
=[ axonsploit console v3.1 ] + --=[ 2311 exploits - 1206 auxiliary - 412 post ] + --=[ 975 payloads - 46 encoders - 11 nops ] + --=[ 9 evasion ]
root@axonsploit>
🧩 Library — plug in your own modules & extensions
#1ShellAccess
10.0.0.5 · x64/windows
via ms17_010_eternalblue
opened 00:04:12 ago
#1handler
exploit/multi/handler
listening on 10.0.0.5:4444
✦ Agentic Cloud
Claude · claude-sonnet-5 · cloud

Ask about the current output, a module, a finding, or what to do next.

The agent explains and drafts — it never runs anything.

Make an attack plan
Proposed plan — scope-checked against sandbox-lab
1
auxiliary/scanner/smb/smb_version
Fingerprint SMB on 10.0.0.5
✓ IN SCOPE
2
auxiliary/scanner/smb/smb_ms17_010
Check for the MS17-010 condition
✓ IN SCOPE
3
exploit/windows/smb/ms17_010_eternalblue
If vulnerable, attempt the exploit
✓ IN SCOPE
Illustrative — synthetic scope, network names and sessions throughout. This is the real app's own screens; nothing here is a real engagement or a real network.
The governance spine

Trust and safety are the product, not a tax on it

An AI copilot bolted onto a pentest tool is not a differentiator by itself. What is hard to copy is a disciplined, authorized posture built into the architecture — the same conviction that shapes AXONREL's governed execution and AGIOS's certified oracles, applied here to offensive security.

Engagement-scoped, not open season

Every engagement declares its scope up front. A module run against a host outside that scope is refused outright — no override, no exception — before anything is staged against a target.

Human approval on every step

The AI copilot explains and drafts an attack plan; it never executes unsupervised. Each step is reviewed — with risk badges and an in-scope check — before the operator approves it individually or the plan as a whole.

Immutable, signed audit trail

Every action and every approval is timestamped and cryptographically signed against the device keystore — tamper-evident, and exportable as proof of exactly what was done, when, and by whom.

Purple-team by default

Every action is auto-tagged to a MITRE ATT&CK technique, building a coverage map as the engagement runs. A detection-validation mode runs sanctioned techniques specifically to verify the client's own SIEM/EDR actually fires — red findings, blue value.

What it does today

From recon to report, on one device

  • Target-first discovery — tap a target, scan it, and get plain-language recommended modules with connection details pre-filled
  • Structured attack planning — the copilot proposes a scope-checked, capped attack plan; the operator reviews and approves before anything runs
  • Experience memory — the tool remembers what worked and what failed in a given environment, and feeds that back into future plans
  • Interactive session I/O — live shell and Meterpreter sessions, file transfer, screenshots, and a kill switch mid-run
  • Auto-generated engagement reports — findings, evidence, CVSS and ATT&CK mapping drafted straight from the signed audit trail, including a dedicated section for any defensive control that was bypassed
  • Certificate-pinned remote connections and Keystore-encrypted credentials — the console itself is hardened, not just the engagements it runs
Defense-bypass findings

When an authorized run defeats a defensive control, that is captured as a first-class finding — the exact technique, the ATT&CK ID, the detection that should have fired and didn't, and the remediation to close it. Logged, reviewable, and reported — never hidden.

Explicit boundaries

What it will not do

Policy, not an afterthought

Evasion is in scope only as a traced, reported purple-team capability using Metasploit's existing techniques — the console does not author novel evasion methods, and nothing in it performs anti-forensics or hides activity from the audit trail. Authorized targets only, every time.