Permissioned attack simulation

Attack yourself first.

TrojanStrike runs a real, permissioned intrusion against your own website — rate-limited, non-destructive, every request logged — and shows you exactly how far an attacker would get, with the evidence and the fix. Your first full strike is free.

CHECKS 32REQUESTS 4.6KVERDICT PENDING
32checks per strike
6escalation classes
0requests before attestation
100%requests logged

How it works

The geometry of a strike.

One continuous operation, from first signal to final judgment. Scroll — watch it unfold.

01RECON

Mapping the unknown

Your target assembles out of raw signal — every route, header, and asset catalogued, ownership verified, before a single probe is sent.

02PROBE

The site becomes a map

The crawler unfolds the monolith into a lattice of endpoints — pages, forms, API calls — and walks it branch by branch, marking the points worth pressuring.

03STRIKE

Pressure, refusal, breach

Thousands of permissioned probes fire at the lattice. Almost everything deflects. What pierces is captured as evidence — read-only, non-destructive, every request logged.

04VERDICT

Judgment rendered

Everything the strike learned converges into a single verdict — one word, the evidence behind it, and the fix.

From click to verdict

Seven steps. No black box.

This is the entire engagement — what you do, what TrojanStrike does, and exactly what lands in your hands at the end.

  1. Verify ownershipProve the domain is yours. No attestation, no packets.
  2. Enter targetOne hostname — that's the whole setup.
  3. TrojanStrike attacks it32 checks fire, rate-limited and read-only.
  4. Watch the attack liveEvery probe streams to your terminal.
  5. Receive the verdictOne word. No scores, no hedging.
  6. See the evidenceEach finding carries the request that proves it.
  7. Get the fixConcrete remediation, with the repro cURL.

A finding, exactly as reported

Not a mock-up. Every finding in your report carries the verdict, the proving request, the impact, and the fix — like this one.

Open a full sample report →
breachedhighBOLA / IDOR · CWE-639

Cross-user order receipt access

GET /api/orders/1042 → 200

authenticated as user A, response contains user B's order record

Impact

Customer data exposed across account boundaries.

Fix

Enforce object-level authorization on every record fetch (CWE-639).

A scanner

“I found something suspicious.”

A maybe. A severity score. A ticket you learn to ignore.

TrojanStrike

“I tried it, and here's the evidence.”

A proof. A request log. A fix you can act on today.

Verdicts

Every strike ends in one of four verdicts.

No scores, no hedging. A single word that tells you exactly where you stand — backed by the evidence that produced it.

INSIDE_THE_WIRE

Breached, and data walked out the door.

Confirmed data extraction, read-only.

BREACHED

The attacker got in.

A critical or high finding holds up.

AT_THE_DOOR

A partial foothold — the door still held.

Medium-severity issues confirmed.

HELD

Your defenses held the line.

Nothing exploitable found.

Engine room

What a strike actually does.

Each capability below runs against your stack and reports only what it can prove. Nothing is inferred twice and nothing is exaggerated once.

SQLi UNION extraction

SQLI

Discovers the injection context, then proves it with a bounded, read-only data pull.

NoSQL operator injection

NOSQL

Substitutes operator objects into JSON bodies and measures the record-set differential.

SSRF out-of-band canary

SSRF

Plants a unique callback address; a hit from your server is the only admissible proof.

JWT algorithm-confusion analysis

JWT

Replays alg=none and RS256/HS256 confusion forgeries against your own session oracle.

BOLA/IDOR object probing

IDOR

Re-requests objects across ownership boundaries and flags foreign data in the response.

Poison-null-byte path probing

TRAVERSAL

Retries extension-filtered reads with double-encoded null bytes to expose filter bypasses.

DOM/stored XSS proof

XSS

Drives a headless browser with an inert markup canary and confirms it lands as live DOM.

Directory-listing surveillance

EXPOSURE

Probes common autoindex directories and classifies any sensitive entries it finds.

JS-bundle secret scanning

SECRETS

Reads your shipped bundles for hardcoded credentials and known key formats — redacted, always.

WAF-aware evidence gating

SIGNAL

Detects edge mitigation and suppresses findings whose evidence a block page could have faked.

Rules of engagement

An attacker's toolkit, a surgeon's discipline.

Verification gate before any packet

A scan cannot start until domain ownership is attested and re-verified live. There is no bypass and no exception.

Read-only escalation ceilings

Proof-of-extraction stops at the minimum that demonstrates impact — SELECT-only SQLi, an allowlist of identity commands, nothing destructive, ever.

Kill switch and a full request log

Abort any scan mid-flight. Every request we send is logged for your review, and you can purge the data at any time.

Permissioned by design

We don't attack strangers.

Prove it's yours — 60 seconds. Then the recon fires itself. The legal gate is the product: it's how you know the attack is real, and how the world knows it's welcome.

Verify ownership

Drop a meta tag or a DNS record on your domain. One method, about a minute, done once.

Recon fires itself

The moment verification lands, a passive RECON scan launches automatically — no button to find.

The report goes live

Your surface map streams into a live report. The first verdict is already on its way.

Pricing

Continuous offensive validation.

Pay for verdicts, not vibrations. Every price in AUD — no seats, no tiers of tiers.

ReconA$0always free

The surface map, on the house.

  • Passive mapping — headers, TLS, cookies
  • Exposed files and error leakage
  • Known CVEs in your shipped stack
  • ~100 requests, nothing intrusive
  • Fires automatically after verification
Start free
First strike free
StrikeA$399per strike

The full active assault, once.

  • Everything in RECON
  • Active injection, XSS, SSRF, traversal
  • ~3,000 requests inside a strict budget
  • Evidence-backed verdict and fixes
  • First strike free — full evidence
Run a strike
SiegeA$999per siege

The assault, behind your login.

  • Everything in STRIKE
  • Authenticated — logs in first
  • CSRF, session, IDOR/BOLA, JWT analysis
  • ~5,000 requests inside a strict budget
Run a siege
ContinuousA$299per month

The watch that never stands down.

  • Unlimited fair-use STRIKEs
  • Scheduled scans, posture timeline
  • Scan-over-scan diff: new / persisting / fixed
  • Cancel anytime
Go continuous

Need volume? 5 strikes A$1,795 · 10 A$3,390 — for consultants and teams.

What you run between penetration tests — not a replacement for one.

Your first verdict is free.

Run a free recon