The Lupus arsenal
Lupus curates a full penetration-testing arsenal — from the Metasploit Framework to modern recon, web and Active Directory tooling — with an autonomous AI agent that drives them. The core set is bundled in the app; the rest installs on first launch from Lupus's signed repository. For authorized security testing only.
Lupus AI Agent
An autonomous pentest agent that plans and executes the engagement end to end — reconnaissance, scanning, exploitation, post-exploitation and reporting — orchestrating every tool below and writing its findings straight into the workspace database. You connect your own Claude (Anthropic) access; it runs in both local and remote mode. For authorized engagements only.
Free included on every device Pro unlocked with Lupus Pro Root needs a rooted device
Exploitation & payloads
- Metasploit FrameworkFree
The full exploit, auxiliary and post-exploitation framework with Meterpreter sessions.
- msfvenomPro
Standalone payload, executable and shellcode generation.
- searchsploit / Exploit-DBFree
Offline exploit PoC search against the Exploit-DB archive.
Network scanning
- NmapFree
Port, service and OS discovery; results flow straight into the workspace database.
- naabuFree
Fast SYN/connect port scanner for wide sweeps.
- NcatFree
Netcat for connect, listen and relay.
Vulnerability scanning
- NucleiPro
Thousands of community templates for CVEs, misconfigurations and exposures.
- CVE lookup (vulners / NVD)Free
Maps discovered service versions to known CVEs.
- wafw00fFree
Fingerprints the Web Application Firewall in front of a target.
Web recon & fuzzing
- httpxFree
Fast HTTP probing and fingerprinting.
- katanaFree
Web crawler that maps endpoints and attack surface.
- ffufFree
High-speed web fuzzer.
- feroxbusterFree
Recursive content and directory discovery.
- gobusterFree
Directory, DNS and vhost brute-forcing.
- sqlmapFree
Automated SQL injection detection and exploitation.
DNS & OSINT
- subfinderFree
Passive subdomain enumeration.
- dnsxFree
Fast, multipurpose DNS toolkit.
- dnsreconFree
DNS enumeration and zone-transfer checks.
Active Directory, SMB & credentials
- ImpacketFree
The AD/SMB attack suite — secretsdump, psexec, wmiexec, GetNPUsers and more.
- NetExec (nxc)Free
Network execution across SMB, LDAP and WinRM — the CrackMapExec successor.
- ResponderRoot
LLMNR/NBT-NS/mDNS poisoning and NTLM credential capture.
- smbclientFree
Browse and transfer files over SMB shares.
Traffic & packet analysis
- tsharkRoot
Wireshark's CLI capture and dissection engine.
- termsharkRoot
A terminal UI for browsing tshark captures.