Skip to content

A file that describes the attack. A runtime that proves it.

Exploitmatic is a desktop workbench and a command line tool that read one plain text file: the solution. The file records the attack step by step and the test that must pass. The runtime validates the file, replays it against one target you name, and prints a result you can act on.

The solution file, read in a minute.

A solution has three parts. Here is what each one is for, on the Heartbleed example.

01

The header records where it came from

An id, a one-line summary, and the CVE the file reproduces. Provenance is part of the artifact, not a comment someone may delete.

02

Each block is one step

Identity names the protocol. English lines say what to send and what to read. The verb is the HTTP method; bytes are written as hex.

03

The expect line is the test

Text present, a regex, a flag, an out-of-band callback, or no response. Validation checks the grammar first; the run applies the tests.

tlsheartbleed-mem-leak.txt
id: openssl/heartbleed-mem-leak
summary: CVE-2014-0160 Heartbleed
ref: CVE-2014-0160

tls clienthello-heartbeat
  send hex "1603030125010001210303..."
  receive until "0e000000"
  receive 65536 bytes
  expect "0e000000" in the response

tls malformed-heartbeat
  send hex "1803030003014000"
  receive 70000 bytes
  expect the response to match "18030[123]40"

Run it from the workbench.

1

Set the target

One URL or address, plus a timeout. The runtime keeps the session alive across the steps of the file.

2

Press run

The workbench or the CLI replays the file. Redirects, cookies, captures, and out-of-band callbacks are handled by the runtime.

3

Read the report

One line per step. Verified when every test passes, not verified when one fails. Exit codes make it usable in CI.

The Exploitmatic workbench with the solution editor on the left and the Run panel on the right, showing the target and timeout fields and the replay button

What the runtime does with the file.

Verified against real targets.

These are run results from the lab. Each linked post shows the vulnerable build and the methodology, so the result can be checked.

Browse the open solutions corpus

What Exploitmatic is not.

The category is new, so the boundaries matter. Three things the tool deliberately does not do:

Not a scanner

It does not crawl, discover, or sweep a network. One run is one solution against one target you name.

Not an exploit framework

There is no console, no module library, and nothing to load at runtime. A solution is data the runtime reads.

Not an autonomous attacker

It replays what a file describes. It never decides what to attack. An agent may author the file; running it still needs a target you own and choose.

Give exploit research a common language.

Bring a PoC, a writeup, or an AI-generated draft into an Exploitmatic solution: inspect it, validate it, and replay it against a target you own. The runtime and the corpus are open source.