The Ultimate Desktop Offensive Security Cockpit.
An all-in-one cybersecurity testing workstation combining an asynchronous interception proxy, Burp-grade manual & automated testing tools (Replay, Intruder, Decoder, Comparer, Entropy), an isolated Docker Kali sandbox, 3-way multi-role IDOR matrix, and embedded AI copilot.
Native desktop performance, low memory footprint, system tray controls & proxy toggles.
HTTP/1.1, HTTP/2, WebSockets, gRPC. Replay, Intruder 4-mode fuzzing, Decoder & Comparer.
Subfinder, Katana, Nuclei, Nmap, FFuF, SQLMap running in ephemeral sandboxed containers.
Zero phone-home telemetry. Cryptographic offline key check against machine HWID.
Platform Capabilities
Engineered for Precision Offensive Security
Explore how the Flux suite consolidates manual penetration testing, automated fuzzing, and AI-driven analysis into one cohesive cockpit.
High-Throughput MITM Interception Proxy
Engineered with a high-performance Python/FastAPI async engine and native desktop shell. Intercept, decode, tamper, and replay HTTP/1.1, HTTP/2, WebSockets, and gRPC with zero dropped frames.
- Full HTTP/2 multiplexed stream inspection & bi-directional frame tampering
- Real-time WebSocket frame interception & protocol dissection
- Live Match & Replace regex engine for requests and responses
- Instant local CA certificate generation & auto-injection for TLS
Intruder & Multi-Mode Attack Fuzzer
Comprehensive brute-force and fuzzing engine with 4 attack modes, multi-type payload generators, dynamic payload processors, and real-time anomaly detection.
- 4 Attack Modes: Sniper, Battering Ram, Pitchfork, and Cluster Bomb
- Payload types: Custom wordlists, number ranges, brute-force charsets, and null payloads
- Grep-Match and Grep-Extract regex extractors with live telemetry & RPS counters
- Modal response length analysis & statistical anomaly scoring
Replay (Repeater) & Request Workbench
Fine-grained manual request crafting environment with tab management, hierarchical collection trees, full undo/redo timelines, and instant response diffing.
- Multi-tab workspace with import/export collection trees
- Full edit history timeline with granular undo & redo tracking
- Side-by-side & unified response diff comparison
- Fast 1-click dispatch to Intruder, Comparer, Decoder, and AI Copilot
CyberChef-Style Decoder & Crypto Pipeline
Sequential multi-stage transformation workbench to decode, encode, dissect, and hash obfuscated payloads and security tokens in real time.
- Visual pipeline: URL, Base64, Hex, HTML Entities, Gzip, ROT13, Binary & JWT
- Cryptographic hashing: MD5, SHA-1, SHA-256, SHA-512, and HMAC verification
- JWT token dissector with header, payload, and signature breakdown
- Shannon entropy calculator for token randomness assessment
Visual & Semantic Diff Engine with Noise Masking
Pinpoint subtle authorization variances and race conditions between requests or responses with side-by-side Monaco diffs and automated noise masking.
- Monaco side-by-side split, unified diff, JSON object diff, and raw hex diff
- Semantic HTTP view isolating header changes from body variances
- Smart noise masking: auto-strips timestamps, cookies, nonces, and ETags
- Direct comparison pool drawer for multi-item triage
Entropy & PRNG Randomness Sequencer
Inspect session tokens, CSRF tokens, and cryptographic nonces for predictability, low entropy, and pseudo-random number generator (PRNG) flaws.
- Character bit-distribution analysis across captured sample sets
- Interactive autocorrelation charts to expose cyclic generation patterns
- PRNG predictability engine and seed estimation heuristics
- Continuous live sampler connected directly to proxy flows
3-Way Multi-Role IDOR & BOLA Matrix
Automated session header mutation testing across Admin (User A), Attacker (User B), and Unauthenticated states to detect broken object-level access across APIs.
- Automated session header swapping across all captured endpoints
- Visual status code & JSON response payload semantic diffing
- Confidence scoring with false-positive filtering algorithms
- Direct 1-click PoC curl & Python exploit script generation
Integrated Chromium Remote Browser Sandbox
Built-in Chromium sandbox for interactive web exploration, DOM tree extraction, cookie jar synchronization, and live JavaScript console evaluation.
- Zero-leak isolated browser instance tied directly to proxy interceptor
- Live DOM tree inspection and active element highlight picker
- Remote browser actions: click, fill, evaluate script, and extract
- Automated cookie jar sync between proxy and browser session
Automated Web & API Vulnerability Scanner
Automated scanning engine that spiders endpoints, discovers hidden query parameters, identifies security misconfigurations, and profiles tech stacks.
- Automated endpoint crawler & dynamic SiteMap tree generation
- Passive security header, cookie, and leak detection
- Active web vulnerability probing with CVSS v3.1 scoring
- Seamless findings export directly into assessment reports
AI Security Copilot
Context-aware security copilot embedded directly into the pentesting workflow to analyze response anomalies, craft targeted payloads, and correlate CVEs.
- AST-aware response analysis & parameter entropy checks
- Instant exploit refinement & custom Python script generation
- Log anomaly explanation & automated triage summaries
- Targeted payload suggestions based on detected technology stack
War Room Kali Linux Docker Sandbox
Never pollute your local host machine. Flux manages an ephemeral Docker container preloaded with 20+ offensive Kali tools directly controlled via PTY web terminals.
- Pre-installed: subfinder, httpx, nuclei, katana, nmap, ffuf, sqlmap, naabu
- Multi-tab concurrent PTY session terminal manager with theme toggles
- Read-only host volume bindings with strict memory and CPU bounds
- 1-click sandbox reset & offensive rule update
Assessment Reporting & Persistent Workspaces
End-to-end workspace management backed by SQLite with instant session persistence, temporary engagement modes, and executive report exports.
- Export formatted PDF, HTML, Markdown (.md), and CSV reports
- Persistent project databases with zero-leak temporary session options
- CVSS v3.1 severity rating, vulnerability evidence, and remediation steps
- Target Anonymizer & secret masking engine for sanitized reporting
20+ Integrated Security Tools Ready Out-of-the-Box
Zero installation friction. Every tool runs inside the managed Docker container with non-root security isolation.
Vulnerability Scanner
Subdomain Discovery
HTTP Prober
Next-Gen Web Crawler
Port & Service Recon
Fast Web Fuzzer
SQL Injection Automator
In-Depth OSINT
Multi-Resolver DNS
Fast Port Enumerator
Secret & Key Scanner
CMS Security Auditor
Tamper-Proof Cryptographic Licensing
Flux licenses are digitally signed using state-of-the-art asymmetric cryptography. The desktop client verifies signatures completely offline with zero telemetry or phone-home tracking. Optional Hardware ID (HWID) binding prevents unauthorized key leakage.
Simple, Transparent Licensing for Flux
Choose between Community (Free Forever), Professional ($5/mo), or Enterprise ($20/mo) with instant PayPal and credit card checkout.
Download Flux Desktop Platform
Native high-performance desktop application for Windows, macOS, and Linux. Packaged with embedded standalone Python engine, local SQLite database, and MITM interception proxy.
Windows Installer (Setup)
Release v1.0.0 • flux_1.0.0_x64-setup.exe (186 MB)
Windows Installer (Setup)
Recommended for Windows 10 & 11 (64-bit). Includes auto-launch wizard & shortcuts.
Windows Enterprise Package
Standard MSI package for system administrators & enterprise silent deployments.
macOS Apple Silicon (M1/M2/M3/M4)
Optimized for Apple ARM architecture. Drag-and-drop into Applications.
Linux Universal Portable
Zero-install standalone binary for Ubuntu, Debian, Fedora, Arch, and Kali.
Debian / Ubuntu / Kali Package
Native package: sudo dpkg -i flux_1.0.0_amd64.deb.
RedHat / Fedora / CentOS Package
Native package: sudo rpm -i flux-1.0.0-1.x86_64.rpm.
Frequently Asked Questions
Click any question to view licensing, offline cryptographic activation, and billing details.
FLUX-LIC-... key. Verification is 100% offline.