About
Facts you can quote
Exploitmatic is a common representation for exploit knowledge. PoCs, research, and AI-generated exploit logic become one plain text solution that records where the knowledge came from, what it targets, and what must hold for it to be verified. The runtime validates the file, replays it against one target, and prints a verified or not verified result.
What it is
A common representation for exploit knowledge: a plain text solution that records source, target, and the tests that prove an attack, plus a runtime that validates, replays, and reports a verified or not verified result.
Who it is for
Security researchers, analysts, penetration testers, red teams, CTF players, engineers regression-testing patches, and builders of AI-agent workflows.
The problem it solves
Exploit knowledge is fragmented across languages, tools, and AI agents. Exploitmatic gives it one inspectable, reproducible representation.
What it replaces
The ad hoc one-off artifact: scripts and snippets that cannot be compared, validated, or replayed by anything else. The solution file is the shared object.
What it does not do
It is not a scanner, not an exploit framework, and not an autonomous attacker. One run is one documented attack against one target you choose.
Cost
Free and open source. The runtime and the solution corpus are Apache-2.0.
How you run it
A single portable binary with a desktop workbench, a CLI, and an MCP server. No installer, no toolchain, no dependencies.
What it integrates with
Nothing to install, by design. It works wherever a binary runs: Docker labs, CI pipelines, LLM authoring loops, and the desktop workbench.
18
protocols implemented
5
assert types
1
portable binary
0
dependencies to install
Origin
Why it exists
Exploitmatic started from a simple observation: security teams already write replay scripts for specific exploits, by hand, and none of them look alike. Formalize that with a grammar and the file stops being a script and becomes data. Data is reviewable, diffable, safe to share, and writable by a language model. The runtime stays deterministic so the result always comes from the run, never from the file.
The project is developed in the open on GitHub, with the runtime, the solution corpus, and this site under one organization. Contributions are welcome, from new solution files to protocol work.
Contact
Talk to the maintainers
For press, questions, or hosted-service support, email [email protected]. For bugs and feature work, open an issue on the runtime repository. The full reference lives in the documentation.
See a PoC become a Solution
Read the format reference, then replay a real solution against a target you own.