Running conversations
-
-
Total vulnerabilities
-
No new risks
Tool invocations
-
-
Tool success rate
-
Healthy

Vulnerability severity distribution

View all →
Vulnerability severity distribution
0
Total vulnerabilities
Critical 0 0%
High 0 0%
Medium 0 0%
Low 0 0%
Info 0 0%
0 Open
0 Confirmed
0 Fixed
0 Ignored
0 False positive
Fix rate 0% (0 / 0)
Fixed Confirmed Open
View all →
No recent vulnerabilities

Batch task queues

View all →
-
- Pending
- Running
- Completed

Tool execution count

View all →
No data

Capabilities

Start your security journey

Describe your target in chat, AI will assist with scanning and vulnerability analysis

Current reviewer

Applies to the selected conversation. Without a conversation, saved to config.yaml as the global default for new chats. Takes effect immediately.

Loading...

Latest executions

Loading...

MCP tool config

External MCP config

Total items -
Categories -
Total content -
Loading...
Total retrievals -
Success -
Success rate -
Items retrieved -
Loading...
Total assets

Assets currently under continuous monitoring

0
IP addresses0
Domains0
Ports0
7 DAYS
Discovered in 7 days0

Posture changes

Track asset and risk changes over the selected period

Asset change trend

New discoveries and currently inactive assets

Added assetsInactive assets
Loading…

Risk discovery trend

New vulnerabilities and critical or high-risk findings

New vulnerabilitiesCritical & high
Loading…

Scan coverage

Identify assets that are unscanned or overdue for review

0%Overall coverage
Scanned assets0Scanned at least once
Covered in 30 days00%
Never scanned0Prioritize for scanning
Not scanned in 30+ days0Scan results may be stale

Protocol distribution

Exposure composition by identified service

RankProtocolAsset shareCountShare
No data
TargetServiceProjectLast scanRelated findingsRiskStatusActions
No data
See FOFA docs for query syntax; supports && / || / ().
Result will open in a popup for editing before running the query.
Query results
-
0 selected
No data

Select or create a project

Projects share a cross-chat fact board; target, environment, auth and other facts are auto-injected in bound conversations.

Total
-
Critical
-
High
-
Medium
-
Low
-
Info
-
Loading...
Connections
No connections. Click "Add connection" to add one.
Select a connection from the list or add a new WebShell connection.

Files uploaded in chat appear here. Drag files into the list below, or click Upload to pick files (multiple allowed). Click “Copy path” to copy the server absolute path and paste it into a conversation so the model can reference the file.

Loading…

Oneliner Payload

Generate a one-line reverse shell for the target (Bash / Python / PowerShell / Curl).

Build Beacon

Cross-compile a full Beacon binary for Linux / Windows / macOS.

Untitled workflow

Drag nodes from the left onto the canvas, or click node buttons to add quickly
Loading...

Call stats

Loading...

Skills call stats

Loading...
Skills 0
This page 0
Files 0
Scripts 0
Loading...

Agents are .md files under agents_dir (front matter + body as system prompt). The orchestrator is the Deep coordinator and is not listed as a task sub-agent.

Loading...

Basic settings

OpenAI config

Fetch list
Shared by memory compression and attack chain building. Default: 120000
Applies to Eino single-agent and multi-agent only; works with chat-page reasoning controls.

Vision analysis (analyze_image)

Registers the MCP tool when enabled; images are sent only for one VL call; agent context keeps text summaries only. Save & apply to take effect.
Fetch list
Advanced: preprocessing & limits
0 = always JPEG compress; must also fit long-edge and payload limits.

Agent config

After enabling, the chat page can use multi-agent mode; sub-agents are set in multi_agent.sub_agents or the agents/ directory. Orchestration is configured below.
Only for plan_execute; max execute↔replan rounds.
Execution mode for WeCom / DingTalk / Lark bot messages. Deep / Plan-Execute / Supervisor require multi-agent to be enabled.
Advanced settings
Total limit for the original user input ledger injected after compaction; 0 uses the backend default. DB-stored original messages are not truncated.
Model-visible limit for each user message in the ledger; 0 uses the backend default and does not affect DB originals.
Runtime limit for the current user message sent to the model; oversized input is persisted and only a preview is injected. 0 uses the backend default.
Head characters kept visible to the model for oversized current user input.
Tail characters kept visible to the model for oversized current user input.

Human-in-the-loop

Approval

Used when no conversation is selected and for new conversations; the chat sidebar can still override it.
Audit Agent model
Fetch list
Used only for Audit Agent approvals; manual approval does not call a model.
0 keeps logs forever; blank uses the 90-day default.
One per line or comma-separated; whitelisted tools skip human-in-the-loop approval.

Audit Agent strategy

Leave blank to use the backend default strategy.
Review-edit mode can approve with narrowed editedArguments.

Reconnaissance

FOFA config

Leave empty for default.
Stored in server config (config.yaml) only.

Knowledge base

Knowledge base config

Relative to config file directory
Embedding config
Leave empty to use OpenAI base_url
Leave empty to use OpenAI api_key
Fetch list
Retrieval config
Number of top-K results to return
Results below this value are filtered (0-1)
Empty = no filter. When set, only rows whose sub_indexes contain this tag (legacy rows with empty sub_indexes still match).
RAG pipeline (MultiQuery + Rerank)

MultiQuery and rerank are always on: LLM query rewrite → vector prefetch & fusion → HTTP rerank → dedupe & budget truncate.

Max LLM-generated retrieval variants (including paraphrases of the original query). Recommended 3–4, max 8.
DashScope uses gte-rerank; other compatible endpoints use /v1/rerank. Leave empty to infer from Base URL below.
On rerank failure, results fall back to fusion order; search still works.
Post-retrieval (dedupe / budget)

Results are always deduped by normalized text (whitespace-collapsed bodies). No setting required.

Vector candidates per MultiQuery variant; 0 uses built-in max(top_k×4, 20) (max 200).
0 = unlimited; keeps whole chunks in rank order until the budget is exceeded.
0 = unlimited; tiktoken estimate (embedding model name, fallback cl100k_base).
Index config
Matches Eino-style pipelines: Markdown headers + recursive for docs; plain text can use recursive only.
0 uses the default 120s embedding HTTP client timeout.
Max texts per embedding request (SQLite indexer batches writes accordingly).
When enabled, content comes from file_path; falls back to DB content if load fails.
Passed to indexer.WithSubIndexes; stored in the sub_indexes column.
Max tokens per chunk (default 512)
Overlap tokens between chunks (default 50)
Max chunks per knowledge item (0 = no limit)
Max requests per minute (0 = no limit)
Delay between requests (ms); 0 = no limit
Retries on rate limit or server error
Delay between retries (ms)

C2

Built-in C2

When off, listeners are not started and C2 MCP tools are not registered; the C2 sidebar is hidden—useful for local-only chat/knowledge deployments. Click Apply to save.

Bot settings

Configure WeChat (iLink), WeCom, DingTalk and Lark bots so you can chat with D1337 on your phone without opening the web UI.

Bot management

Choose a bot type first, then configure only the fields that belong to that platform.

Robot vulnerability alerts Push newly discovered vulnerabilities to robots bound to this account, filtered by severity.
Send newly discovered vulnerabilities at or above this severity to your bound robot accounts.

Select a bot to configure

Pick a platform above, or use New bot to choose by type.

Bot command instructions

View robot commands for identity, authorization, conversations, roles, modes, projects, and safety diagnostics.

Terminal

Run commands on the server for ops and debugging. Commands run on the server; avoid sensitive or destructive operations.

Terminal 1

Audit logs

Quick range
Event type

Security

Change password

After changing password, sign in again with the new password.

0 accounts
0 enabled accounts
0 roles
0 grants

Users

Select an account to manage roles and resource scope.

0
Loading...

Select User

Select a platform user to edit roles, status, and resource grants.

Role Membership

Roles control allowed actions; resource scope controls visible data.