Imbutus
← All news
15 Sept 2026, 03:49

New: OSINT, recon, web and attack security workflows (early access)

I'm rolling out a new set of agentic security workflows you can run right from chat, live on a rented Kali Linux machine:

  • OSINT — email, person, company, domain, phone and username investigations.
  • Recon — active scanning: subdomains, ports, services and template-based vulnerability checks.
  • Web — Burp-style app testing: crawling, parameter decoding, SQL-injection and XSS possibility checks, secret scanning and JWT weak-key detection.
  • Attack — turn the flagged possibilities into confirmed vulnerabilities with working, non-destructive proofs of concept, and get a client-ready report with a reproducible attack for each finding.

They work together — each run stores its findings in a shared database on your Kali machine, so later workflows reuse earlier results, and every run saves a downloadable report.

Heads up: these run on a newly rented Kali machine — one created after this post. If you already have an older machine, terminate it and rent a fresh one to get the toolkit.

This is an early announcement: the workflows are new and still in a testing and polishing stage. Try them out and send me feedback through support.