Skip to content
@BugTraceAI

BugTraceAI

Agentic BugBounty Pentesting

BugTraceAI

BugTraceAI

Autonomous, self-hosted security testing for authorized bug bounty and pentesting.

Website Watch the demo Live demo Join the community on Discord BugStore practice target

Watch the BugTraceAI DEF CON 34 product demo

Security Research That Leaves Evidence

BugTraceAI combines AI-guided investigation with deterministic security tools. The AI prioritizes hypotheses; tools execute checks, validate evidence, and produce reports that researchers can inspect and reuse.

API Discovery in BugTraceAI-WEB Live Swarm Graph in BugTraceAI-WEB
Discover and prioritize API surface Follow autonomous work in real time

Proven in the Security Community

CVEs disclosed Presented on stage
Wallos - CVE-2026-27479 - CVSS 7.7 RootedCON 2026, Madrid
ZoneMinder - CVE-2026-27470 - CVSS 8.8 HKOSCon 2026, Hong Kong
Piwigo - CVE-2026-27834 - CVSS 7.2 DEF CON 34, Las Vegas

Explore the Ecosystem

Project What it gives you Start here
BugTraceAI The complete self-hosted platform and product overview. Explore the platform
BugTraceAI-CLI Autonomous scanner with a six-phase pipeline, specialist agents, validation, and reporting. Run the CLI
BugTraceAI-WEB Web workspace for analysis, real-time scan control, reporting, and AI-assisted research. Open WEB
BugTraceAI-Launcher Guided Docker deployment for the full platform, CLI, or WEB. Deploy BugTraceAI
BugStore Deliberately vulnerable practice target for safe local training and reproducible demos. Practice on BugStore

Start Here

  1. Watch the DEF CON 34 demo to see the workflow end to end.
  2. Explore a real report generated against the BugStore practice target.
  3. Deploy with the Launcher or run a component independently.
  4. Join the Discord community for demos, feedback, and project discussion.

BugTraceAI is for educational and authorized security testing only. Always obtain explicit permission, respect target scope, and verify findings manually.

Popular repositories Loading

  1. BugTraceAI BugTraceAI Public

    Autonomous AI-powered security scanning platform — CLI scanner, web dashboard, and one-command Docker deployment

    227 18

  2. BugTraceAI-CLI BugTraceAI-CLI Public

    Autonomous AI-powered security scanner — multi-agent vulnerability detection, exploitation, and validation engine

    Python 180 30

  3. BugTraceAI-WEB BugTraceAI-WEB Public

    Real-time web dashboard for BugTraceAI — scan monitoring, 20+ security tools, and AI-powered analysis

    TypeScript 53 3

  4. BugTraceAI-Launcher BugTraceAI-Launcher Public

    One-command Docker deployment wizard for BugTraceAI — interactive setup, 3 deployment modes, auto-configuration

    Shell 25 5

  5. reconftw-mcp reconftw-mcp Public

    Python 21 4

  6. BugStore BugStore Public

    A deliberately vulnerable web application for practicing security testing. Part of the BugTraceAI ecosystem.

    JavaScript 5 4

Repositories

Showing 7 of 7 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…