Skip to main content

Aura v25.0 — The Omni-Sovereign Bug Bounty & Pentest Framework.

Project description

🌌 Aura: The Apex Predator (v19.5 Singularity Edition)

Aura v25.0 — The Omni-Sovereign Bug Bounty Framework 🚀

Aura is the apex predator of security automation. A next-generation, autonomous, AI-driven framework designed to dominate the bug bounty battlefield through sentient logic and hyper-accelerated exploitation.

🛠️ Instant Installation

You can now install Aura globally from anywhere:

pip install aura-cli

🚀 Speed-of-Light Usage

Run your first mission with zero configuration:

aura example.com

🚀 Key Innovations

🧠 The Sentient Brain (AI Core)

  • Business Logic Breaker: Bypasses traditional IDOR controls, manipulates shopping carts, and skips MFA flows.
  • Genetic Payload Mutation: WAF blocking you? Aura dynamically rewrites its exploits (XSS, SQLi, SSRF) utilizing AI to bypass rules.
  • Contextual Impact Scoring: Dynamically aligns findings with real-world financial risk, calculating CVSS and potential bounty payouts.

⚡ Turbine Architecture (Hyper-Concurrency)

  • Native Asyncio Scaling: Processes hundreds of URLs simultaneously via non-blocking semaphores.
  • WAF Caching Engine: Drastically cuts scan time by caching WAF signatures at the domain level, avoiding redundant trigger checks.
  • Parallelized Vulnerability Probing: Independent engines (HostHeader, Deserialization, OpenRedirect, FileUpload) execute concurrently for blazing-fast audits.
  • 0.5s Fixed Backoff: Brutally efficient WAF evasion pacing.

🕵️‍♂️ The Phantom Suite (Deep Attack Vectors)

Aura is equipped with 31 distinct phases of automated intrusion, including:

  1. Nebula Ghost: SSRF pivoting to internal AWS/GCP/Azure metadata services.
  2. GraphQL Reaper: Introspection mining, batch amplification, and query injection.
  3. DOM Hunter: Headless Chromium instance hunting for Blind DOM XSS.
  4. Shadow Swarm Orchestrator: Ephemeral IP rotation built-in.
  5. Siege Escalation: Race conditions, HTTP Request Smuggling, and SSTI probes.

📦 Installation

Aura is a Private, Confidential Tool and is not available on any public repository. To install Aura globally on your system so you can run aura from anywhere:

# Inside the Aura directory:
pip install -e .

Requires Python 3.10+

⚙️ Usage

Aura operates through an intuitive, lethal Command Line Interface.

1. The Zenith Protocol (Autonomous Bug Bounty)

Unleash the full 31-phase attack matrix against a domain.

aura auto "target.com"
  • What it does: Subdomain enumeration, port scanning, WAF bypassing, deep spidering, credential dumping, vulnerability exploitation, and report generation.

2. Fast Reconnaissance (Stealth Mode)

Run a rapid, completely passive discovery phase.

aura auto "target.com" --fast

3. Targeted Module Execution

Deploy specific operational engines on demand.

# Extract and verify all endpoints from JavaScript files
aura js "https://target.com"

# Hunt for exposed Cloud/AWS credentials
aura cloud "https://target.com"

# Crawl the Wayback Machine for hidden legacy parameters
aura wayback "target.com"

# Attempt Subdomain Takeovers
aura takeover "target.com"

4. Profit Engine (Automated Reporting)

After a successful run, compile all verified vulnerabilities into a professional Markdown report ready for submission to HackerOne or Bugcrowd.

aura profit intel

🛡️ Required Configuration

Aura integrates with various third-party APIs for maximum intelligence gathering. Export these keys in your environment:

export SHODAN_API_KEY="your_key"
export VIRUSTOTAL_API_KEY="your_key"
export OTX_API_KEY="your_key"
export SECURITYTRAILS_API_KEY="your_key"
export CENSYS_API_ID="your_id"
export CENSYS_API_SECRET="your_secret"
export GREYNOISE_API_KEY="your_key"
# Required for the AI Brain:
export GEMINI_API_KEY="your_google_ai_key" 

⚠️ Disclaimer

Aura is an extremely potent offensive security tool. It is intended strictly for authorized security auditing, bug bounty hunting, and defensive research. Any illicit usage or deployment against unauthorized targets is strictly prohibited. The developers accept no liability for the misuse of this tool.

🌌 The Future is Sovereign. The Future is Aura.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aura_framework-25.0.0.tar.gz (336.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

aura_framework-25.0.0-py3-none-any.whl (402.2 kB view details)

Uploaded Python 3

File details

Details for the file aura_framework-25.0.0.tar.gz.

File metadata

  • Download URL: aura_framework-25.0.0.tar.gz
  • Upload date:
  • Size: 336.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.10

File hashes

Hashes for aura_framework-25.0.0.tar.gz
Algorithm Hash digest
SHA256 dccd11bbce0d2b8935ad1a6fe3bb14cc5862b30a5427f67e2892bd70b6cb8a70
MD5 9e612777c6b5d91a793bae9a8674eacc
BLAKE2b-256 5fa99f704ed8e41368816789746d3469f31361cef34114ea210bb42470caed65

See more details on using hashes here.

File details

Details for the file aura_framework-25.0.0-py3-none-any.whl.

File metadata

File hashes

Hashes for aura_framework-25.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f482aacc8602dcb6bed5c45525f7502a93b8039a8510a1061a794d45184f4d68
MD5 9efaf65c91a04d6fbe05c031689ff284
BLAKE2b-256 6a8b73def16247f1bb326ffa2d42402f1468661f3e170787ea4a69b4de6b7ade

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page