Axonsploit
A native Android operator console that drives a full penetration-testing engagement from a phone — with the same governance discipline we build into every AI Labs platform: human approval before every action, hard scope enforcement, and a tamper-evident audit trail. As far as we know, nothing else like it exists.
Axonsploit is not distributed on request. It is made available only to demonstrated, authoritative research and security-testing engagements, under the same strict governance we apply everywhere else in the portfolio — vetted counterparties, defined scope, and full audit accountability for every session. If that describes your engagement, contact us and we'll walk through what qualifies.
A full operator console, not a remote shell to one
Axonsploit talks directly to a Metasploit RPC daemon — on-device via NetHunter, or to a remote Kali box over a pinned TLS connection — and gives the operator a touch-first console, module browser, live session I/O, and job management. It is built to be carried, not parked on a laptop.
The real app, walked through
These are the app's actual screens. All target data below is synthetic — a lab scope (10.0.0.5 / example.local), fake nearby networks, fake sessions — never a real engagement.
Ask about the current output, a module, a finding, or what to do next.
The agent explains and drafts — it never runs anything.
Trust and safety are the product, not a tax on it
An AI copilot bolted onto a pentest tool is not a differentiator by itself. What is hard to copy is a disciplined, authorized posture built into the architecture — the same conviction that shapes AXONREL's governed execution and AGIOS's certified oracles, applied here to offensive security.
Engagement-scoped, not open season
Every engagement declares its scope up front. A module run against a host outside that scope is refused outright — no override, no exception — before anything is staged against a target.
Human approval on every step
The AI copilot explains and drafts an attack plan; it never executes unsupervised. Each step is reviewed — with risk badges and an in-scope check — before the operator approves it individually or the plan as a whole.
Immutable, signed audit trail
Every action and every approval is timestamped and cryptographically signed against the device keystore — tamper-evident, and exportable as proof of exactly what was done, when, and by whom.
Purple-team by default
Every action is auto-tagged to a MITRE ATT&CK technique, building a coverage map as the engagement runs. A detection-validation mode runs sanctioned techniques specifically to verify the client's own SIEM/EDR actually fires — red findings, blue value.
From recon to report, on one device
- Target-first discovery — tap a target, scan it, and get plain-language recommended modules with connection details pre-filled
- Structured attack planning — the copilot proposes a scope-checked, capped attack plan; the operator reviews and approves before anything runs
- Experience memory — the tool remembers what worked and what failed in a given environment, and feeds that back into future plans
- Interactive session I/O — live shell and Meterpreter sessions, file transfer, screenshots, and a kill switch mid-run
- Auto-generated engagement reports — findings, evidence, CVSS and ATT&CK mapping drafted straight from the signed audit trail, including a dedicated section for any defensive control that was bypassed
- Certificate-pinned remote connections and Keystore-encrypted credentials — the console itself is hardened, not just the engagements it runs
When an authorized run defeats a defensive control, that is captured as a first-class finding — the exact technique, the ATT&CK ID, the detection that should have fired and didn't, and the remediation to close it. Logged, reviewable, and reported — never hidden.
What it will not do
Evasion is in scope only as a traced, reported purple-team capability using Metasploit's existing techniques — the console does not author novel evasion methods, and nothing in it performs anti-forensics or hides activity from the audit trail. Authorized targets only, every time.