Skip to content

About

Facts you can quote

Exploitmatic is a common representation for exploit knowledge. PoCs, research, and AI-generated exploit logic become one plain text solution that records where the knowledge came from, what it targets, and what must hold for it to be verified. The runtime validates the file, replays it against one target, and prints a verified or not verified result.

What it is

A common representation for exploit knowledge: a plain text solution that records source, target, and the tests that prove an attack, plus a runtime that validates, replays, and reports a verified or not verified result.

Who it is for

Security researchers, analysts, penetration testers, red teams, CTF players, engineers regression-testing patches, and builders of AI-agent workflows.

The problem it solves

Exploit knowledge is fragmented across languages, tools, and AI agents. Exploitmatic gives it one inspectable, reproducible representation.

What it replaces

The ad hoc one-off artifact: scripts and snippets that cannot be compared, validated, or replayed by anything else. The solution file is the shared object.

What it does not do

It is not a scanner, not an exploit framework, and not an autonomous attacker. One run is one documented attack against one target you choose.

Cost

Free and open source. The runtime and the solution corpus are Apache-2.0.

How you run it

A single portable binary with a desktop workbench, a CLI, and an MCP server. No installer, no toolchain, no dependencies.

What it integrates with

Nothing to install, by design. It works wherever a binary runs: Docker labs, CI pipelines, LLM authoring loops, and the desktop workbench.

18

protocols implemented

5

assert types

1

portable binary

0

dependencies to install

Origin

Why it exists

Exploitmatic started from a simple observation: security teams already write replay scripts for specific exploits, by hand, and none of them look alike. Formalize that with a grammar and the file stops being a script and becomes data. Data is reviewable, diffable, safe to share, and writable by a language model. The runtime stays deterministic so the result always comes from the run, never from the file.

The project is developed in the open on GitHub, with the runtime, the solution corpus, and this site under one organization. Contributions are welcome, from new solution files to protocol work.

Contact

Talk to the maintainers

For press, questions, or hosted-service support, email [email protected]. For bugs and feature work, open an issue on the runtime repository. The full reference lives in the documentation.

See a PoC become a Solution

Read the format reference, then replay a real solution against a target you own.