- Hero operator-console shot + login, overlay, captured-credentials,
page-capture, payload-catalog, and practice-lab screenshots
- New 'Page Mirror' section: framing that most blind-XSS/hook tools stop
at a screenshot + raw HTML, whereas WRAITH lets you open a live, clickable
view and navigate the app through the victim's same-origin session
(walkthrough ends on a session-gated vault reached through the hook)
Browser-hooking framework for red teams, researchers, and educators:
a clean-room successor to BeEF (hook + Pretty Theft overlays) fused with
blind-XSS callback tooling, built to hook browsers across modern (incl. AI)
app ecosystems.
- One-command Docker install (setup.sh): auto-detects public IP/domain,
provisions operator username + password, prints hook/XSS URLs
- Operator console: live keystrokes, captured creds, page capture,
page mirror, calibrated localhost/LAN scan, XSS payload catalog
- Overlays (LinkedIn/Facebook/Microsoft), built-in vulnerable practice lab
- Apache-2.0 licensed
For authorized security testing, research, and education only.