Sign inSign up

nullc0d30/hunterx

By nullc0d30

•Updated about 1 month ago

HunterX - AI-Assisted Vulnerability Discovery, Validation & Proof Engine (V7)

Image
Security
Machine learning & AI
Web servers
6

5.0K

nullc0d30/hunterx repository overview

⁠HunterX v7 — AI-Assisted Vulnerability Discovery, Validation & Proof Engine

Docker Pulls Docker Stars GitHub Release License Python OWASP Community

HunterX is an open-source, AI-assisted vulnerability discovery, validation and proof engine for authorized security testing. It does not stop at candidate detections: it plans and orchestrates missions, reasons over hypotheses, validates findings with evidence, engineers and replays proofs and PoCs, and produces report-ready output.

This image runs the HunterX v7.0.0 CLI (and REST API) inside a minimal, non-root container.

Discover → Fingerprint → Reason → Hypothesize → Probe → Verify → Prove → PoC → Replay → Correlate → Report

⁠Quick Start

# Pull the current release
docker pull nullc0d30/hunterx:7.0.0

# Verify the version you pulled
docker run --rm nullc0d30/hunterx:7.0.0 version

# Show the command reference
docker run --rm nullc0d30/hunterx:7.0.0 help

The image entrypoint is the hunterx CLI, which uses subcommands (for example hunterx version, hunterx help, hunterx hunt ...). Running the container with no arguments prints the usage text.


⁠What Is HunterX?

HunterX is an AI-assisted vulnerability discovery, validation and proof engine and red-team framework. It orchestrates the open-source security-tool ecosystem rather than replacing it: HunterX executes tools with structured contracts, normalizes their output, correlates results, reasons over hypotheses, validates with evidence, engineers and replays minimal safe proofs/PoCs, and produces professional reports.

A traditional scanner stops at "possible SQL injection". HunterX is built to investigate the hypothesis, verify the behavior, prove the finding, reproduce the evidence, assess the impact, and turn the result into a report-ready, validated finding:

Detection → Evidence → Verification → Reproduction → PoC → Validated Finding

⁠Key Capabilities

  • Autonomous mission orchestration and adaptive mission planning (hunterx mission, hunterx hunt)
  • AI-assisted reasoning through a decoupled AI provider layer — grounded in evidence, never a substitute for it
  • Toolchain intelligence layer with 92 registered open-source security tools, machine-readable contracts, structured execution, parsers and normalizers
  • Evidence-driven vulnerability validation with proof contracts, replay and reproducibility
  • Proof / PoC engineering with minimal safe proofs and evidence-gated confidence and impact
  • Target memory and campaign intelligence, including cloud/SaaS attack-surface intelligence and knowledge-graph correlation
  • Professional reporting: Markdown, HTML, JSON, SARIF 2.1, PDF and evidence packages
  • Persistent mission state (SQLite by default) with the TIDB persistence layer
  • REST API (FastAPI) with opt-in API-key authentication
  • Clean Architecture Python core, Apache-2.0 licensed

⁠Image Tags

TagPurpose
latestMost recent build of main (currently HunterX v7.0.0)
stableLatest tagged stable release (currently HunterX v7.0.0)
7.0.0Version-pinned release
7.0Minor-version tag
7Major-version tag
6.0.0, 6.0, 6Legacy HunterX v6 images (not current)
4.0.1, 4.0, 3.1Historical images (not current)

Versioning. latest and stable are convenient but move as new builds are pushed. For reproducible deployments, pin a version tag such as nullc0d30/hunterx:7.0.0.


⁠Usage

⁠Verify the installed version
docker run --rm nullc0d30/hunterx:7.0.0 version
# HunterX v7.0.0
⁠CLI
# Show the resolved configuration
docker run --rm nullc0d30/hunterx:latest config

# Show platform composition
docker run --rm nullc0d30/hunterx:latest platform

# List the integrated toolchain
docker run --rm nullc0d30/hunterx:latest tools list

# Start a full-spectrum mission against an authorized target
# (requires a target you own or are explicitly authorized to test)
docker run --rm nullc0d30/hunterx:latest hunt full_security_assessment https://YOUR-AUTHORIZED-TARGET

Missions, findings, reports and target memory persist to the configured database (SQLite by default), so chained invocations such as hunterx mission create ... → hunterx mission start <mission_id> work across container runs when the same database volume is mounted.

⁠REST API

The image ships the FastAPI application. Start it and point a browser at http://localhost:8080/health:

docker run -d --name hunterx-api -p 8080:8080 \
  --entrypoint uvicorn nullc0d30/hunterx:latest \
  --factory hunterx.api.app:create_app --host 0.0.0.0 --port 8080
curl http://localhost:8080/health
# {"status":"ok"}

API-key authentication is opt-in. When enabled, every request (except /health) requires a valid X-API-Key header:

docker run -d --name hunterx-api -p 8080:8080 \
  -e HUNTERX_API_AUTH_ENABLED=true \
  -e HUNTERX_API_KEY=YOUR_ADMIN_KEY \
  --entrypoint uvicorn nullc0d30/hunterx:latest \
  --factory hunterx.api.app:create_app --host 0.0.0.0 --port 8080
⁠Persistent data

HunterX persists mission state to the database. The image stores it in the application data directory (/opt/hunterx/data, image default sqlite:////opt/hunterx/data/hunterx.db). Mount a volume there:

docker run -d --name hunterx-api -p 8080:8080 \
  -v hunterx-data:/opt/hunterx/data \
  --entrypoint uvicorn nullc0d30/hunterx:latest \
  --factory hunterx.api.app:create_app --host 0.0.0.0 --port 8080

The container runs as the non-root hunterx user and /opt/hunterx/data is writable by it.

⁠Interactive shell
docker run -it --rm --entrypoint sh nullc0d30/hunterx:latest
⁠Docker Compose

The repository ships a docker-compose.yml with two services:

docker compose up -d hunterx-api          # API service (port 8080)
docker compose run --rm hunterx help      # CLI service

⁠Configuration

Configuration is resolved in this order (each level overrides the previous):

  1. Built-in defaults and the bundled hunterx.yaml profile
  2. A user profile file — HUNTERX_CONFIG environment variable, or hunterx.yaml in the working directory (/app)
  3. HUNTERX_* environment variables
⁠Environment variables
VariableDefaultDescription
HUNTERX_LOG_LEVELINFORoot logging level
HUNTERX_DATA_DIR/opt/hunterx/data (image default)Application data directory (created automatically)
HUNTERX_DATABASE_URLsqlite:////opt/hunterx/data/hunterx.db (image default)SQLAlchemy database URL; the image defaults to the writable /opt/hunterx/data volume so persistent state is never lost
HUNTERX_CACHE_BACKENDmemoryCache backend (memory, redis, null)
HUNTERX_QUEUE_BACKENDmemoryQueue backend (memory, redis, null)
HUNTERX_API_HOST127.0.0.1API bind host
HUNTERX_API_PORT8080API port
HUNTERX_API_AUTH_ENABLEDfalseRequire an API key on every request
HUNTERX_API_KEY(empty)Admin API key; when set, authentication is enforced
HUNTERX_API_READ_ONLY_KEY(empty)Optional read-only API key
HUNTERX_CONFIG(empty)Path to a YAML profile file
HUNTERX_ENVIRONMENTproductionEnvironment name (dev, staging, production)
⁠AI provider configuration (optional)

AI is optional: with no provider configured HunterX runs on a safe NullAIClient fallback. Provider and model are selected independently; each provider uses its own key variable:

ProviderHUNTERX_AI_PROVIDERHUNTERX_AI_MODEL (example)API key variable
OpenAIopenaigpt-4o-miniHUNTERX_AI_OPENAI_KEY
Anthropic / Claudeanthropicclaude-3-5-sonnet-latestHUNTERX_AI_ANTHROPIC_KEY
DeepSeekdeepseekdeepseek-chatHUNTERX_AI_DEEPSEEK_KEY
OpenRouteropenrouterdeepseek/deepseek-chatHUNTERX_AI_OPENROUTER_KEY
Google Geminigeminigemini-1.5-flashHUNTERX_AI_GEMINI_KEY
xAI / Grokgrokgrok-2-latestHUNTERX_AI_GROK_KEY

Each provider resolves its own API endpoint (for example openai → api.openai.com, deepseek → api.deepseek.com, openrouter → openrouter.ai); HunterX never silently reroutes one provider to another and never rewrites the configured model. Missing credentials, invalid keys, invalid models, rate limits and provider outages are reported truthfully. Every provider route is implemented and unit-tested; live completion requires your own credential for the selected provider.

Example:

docker run --rm \
  -e HUNTERX_AI_PROVIDER=openai \
  -e HUNTERX_AI_MODEL=gpt-4o-mini \
  -e HUNTERX_AI_OPENAI_KEY=YOUR_API_KEY \
  nullc0d30/hunterx:7.0.0 config

Example:

docker run --rm \
  -e HUNTERX_LOG_LEVEL=DEBUG \
  -e HUNTERX_DATABASE_URL=sqlite:////opt/hunterx/data/hunterx.db \
  nullc0d30/hunterx:7.0.0 config

Secrets. Do not commit API keys or credentials. Pass secrets at runtime via HUNTERX_* environment variables or Docker secrets, and never place real credentials in a checked-in hunterx.yaml.


⁠Docker Security

  • The container runs as the non-root hunterx user (UID 999) and exposes a single writable volume at /opt/hunterx/data for persistent state.
  • The image is multi-stage, based on python:3.11-slim, and publishes OCI labels (source, license, version) for supply-chain inspection.
  • Use pinned image tags (nullc0d30/hunterx:7.0.0) for reproducible deployments.
  • Protect API credentials: enable HUNTERX_API_AUTH_ENABLED, use a strong HUNTERX_API_KEY, and do not expose the API port beyond your trusted network.
  • Review anything you mount into the container — mounted host paths are visible to the container process.
  • HunterX executes security tooling that can generate active traffic. Only run it against systems you own or are explicitly authorized to test.

⁠Responsible Use

HunterX is intended exclusively for authorized security testing: penetration testing, in-scope bug bounty programs, red-team operations, defensive security research, and laboratory environments. You are responsible for obtaining written authorization before testing any system and for complying with all applicable laws and terms of service. HunterX is licensed under Apache 2.0 and provided "AS IS" without warranty.

See Responsible Use⁠ and the Security Policy⁠.


⁠Troubleshooting

ProblemLikely causeAction
docker run ... prints usage textThe CLI uses subcommands; no default command was suppliedUse hunterx help or a specific command such as hunterx version
attempt to write a readonly database / permission denied writing stateThe database path is not writable by the hunterx user (UID 999)The image defaults to HUNTERX_DATABASE_URL=sqlite:////opt/hunterx/data/hunterx.db. Ensure /opt/hunterx/data is writable by UID 999: use the compose named volume (hunterx-data), or for a bind mount run chown -R 999:999 ./data on the host dir
API returns 401Authentication is enabled and the request has no/incorrect keySend a valid X-API-Key header
Wrong version behaviorRunning a legacy 6.x/4.x image or an old latestPull a v7 tag and run hunterx version to confirm
Config looks wrongEnv var name or YAML profile errorRun docker run --rm nullc0d30/hunterx:latest config to inspect the resolved configuration

⁠Documentation & Resources

⁠Support HunterX

If HunterX is useful to your authorized security work, consider supporting its continued development:

GitHub Sponsors⁠ — GitHub Sponsors

HunterX is created and maintained by Ahmed Awad (NullC0d3)⁠, released under the Apache License 2.0.

Tag summary

Content type

Image

Digest

sha256:b6872048b…

Size

64.5 MB

Last updated

about 1 month ago

docker pull nullc0d30/hunterx