87 specialized agents orchestrate reconnaissance, vulnerability detection, exploitation, and reporting — covering the full OWASP WSTG test suite. No API key required — use free models or bring your own (Anthropic, OpenAI, Google, GitHub, and more).
| Severity | Title | Target | CVSS | Pre-req | Triage | AI Triage | File |
|---|---|---|---|---|---|---|---|
| critical | SSRF in /api/webhooks/subscribe reaches 169.254.169.254 | acme-shop | 9.8* | None | pending | VALID | src/webhooks/subscribe.ts |
| critical | open redirect→OAuth state reuse→full account takeover | acme-shop | 9.6 | None | valid | VALID | src/auth/oauth.ts |
| critical | Auth bypass via JWT `none` algorithm in fallback path | docs-api | 9.4 | None | valid | VALID | internal/auth/verify.go |
| high | IDOR on /users/:id/export reveals PII for any user | patient-portal | 8.6* | Low | pending | VALID | src/api/users.ts |
| high | IDOR leaks user IDs→predictable session token→impersonate any user | patient-portal | 8.9* | Low | pending | VALID | src/session/sign.ts |
| high | SQL injection in sort= parameter on search endpoint | acme-shop | 8.1 | None | valid | VALID | src/api/search.ts |
| critical | SSRF in webhook→IMDS token→IAM escalation to admin | ingest-svc | 9.9* | None | valid | VALID | src/webhooks/*.ts |
| high | Stored XSS in markdown comment renderer | docs-api | 7.4 | Low | pending | NEEDS_INFO | src/render/md.tsx |
| medium | CORS wildcard + credentials enabled on /api/v2/* | acme-shop | 6.5 | None | low-impact | LOW_IMPACT | src/server/cors.ts |
| medium | Unvalidated redirect in OAuth callback state | banksite-web | 6.1 | None | pending | NEEDS_INFO | src/auth/oauth.ts |
Dristi combines autonomous reasoning with industry-standard security tools to automate the entire bug bounty workflow.
Subdomain enumeration, live host discovery, tech fingerprinting, parameter extraction — surface every attack vector.
96+ OWASP WSTG tests automated across 12 categories — from information gathering to client-side testing.
54 hunt agents — XSS, SQLi, SSRF, and every OWASP-class in between — each with deep domain expertise. Works with free models or your own API key.
Phase 8 EXPLOIT systematically validates findings with real PoCs before they enter your report.
Risk-scored endpoint queue, attack chain discovery, and automated severity grading keep you focused on what matters.
CVSS-scored findings with evidence, PoC output, remediation guidance — ready for client delivery or H1 submission.
Whether you hunt bounties or audit enterprise apps, Dristi adapts to your workflow.
Automate recon-to-report in hours, not weeks. Find vulnerabilities that automated scanners miss — SSRF, IDOR, business logic flaws, and attack chains. AI triage prioritizes what matters.
Full OWASP WSTG v4.2 methodology automated across 96+ tests. CVSS-scored findings with PoC evidence and remediation guidance — ready for client deliverables.
Continuous testing in CI/CD pipelines. Customize agents for your tech stack — React, Node.js, Go, Java, Python, and more. Works with your existing tools (Burp, Nuclei, etc.).
No complex setup. No endless configuration. Install, configure, and start hunting.
One command installs 60+ security tools — Go binaries, Python packages, Cargo crates, and wordlists.
curl -sSL https://dristi.sh/install | bash
Set up your OpenCode config, agent definitions, and API credentials in one interactive session.
./dristi setup --target example.com
Launch the full pipeline or target specific vulnerability classes with dedicated hunt agents.
dristi hunt --scope "*.example.com"
From reconnaissance to reporting — every phase has dedicated specialists.
How Dristi compares to the alternatives for your security testing workflow.
| Dristi | Traditional Scanners | Manual Testing | |
|---|---|---|---|
| Coverage | 96+ WSTG tests · 25 vuln classes | Limited to known CVEs + patterns | Unlimited (time-bound) |
| AI Triage | VALID / NEEDS_INFO / LOW_IMPACT | High false-positive rate | Manual review only |
| Attack Chains | Automated chain discovery | Single-issue only | Researcher finds them |
| Evidence | Screenshots + HAR + PoC reports | Raw logs only | Manual documentation |
| Reporting | CVSS-scored per-finding PoC reports | Generic PDF output | Manual report writing |
| Cost | Free · open-source · BYO models | $1k–$50k/year per seat | $200–$500/hr |