SPECTRA is a full-spectrum expert-driven pen test framework with a Rust TUI core, C++ network probes, and Python module layer — covering all seven attack surface domains from a single binary.
SPECTRA gives red teams and security engineers a single, cohesive platform for professional penetration testing across every attack surface domain. The Rust TUI core provides a responsive operator interface with zero runtime dependencies. C++ network probes deliver precision at wire speed. A Python module layer enables rapid capability development. Every finding is automatically mapped to MITRE ATT&CK, evidence is collected and encrypted in a unified store, and professional reports are generated automatically. Ships as a single binary — no Python runtime required on the operator machine.
High-performance terminal UI built in Rust — responsive at any scale, zero runtime dependencies on operator machine.
Wire-speed network probes written in C++ for precision port scanning, service fingerprinting, and protocol fuzzing.
Extensible Python module ecosystem for rapid capability development — hundreds of community and built-in modules.
Every finding automatically classified and mapped to MITRE ATT&CK v15 technique IDs for standardised reporting.
Unified encrypted credential and evidence store — all captured data encrypted at rest with per-engagement keys.
Professional penetration test reports generated automatically with executive summary, findings, and remediation guidance.
Target scope, engagement rules, and attack surface domains defined in structured YAML config.
C++ probes execute passive and active recon — DNS, port scan, service fingerprint, web crawl.
Python module layer executes targeted exploits across selected attack surface domains.
Every successful technique automatically tagged with MITRE ATT&CK tactic and technique IDs.
All credentials, screenshots, and artifacts encrypted and stored in the unified evidence store.
Professional report generated with executive summary, technical findings, and remediation guidance.
SPECTRA shares real-time telemetry, threat intelligence, and response actions with every other application in the PHALANX ecosystem through the unified intelligence fabric.
Wire-speed multi-layered IDS with adversarial-resistant ML and JA4 TLS fingerprinting.
Continuous misconfiguration detection across AWS, GCP, and Azure with automated remediation.
Threat feed aggregation, log correlation, and SOAR playbook automation in a streamlined platform.
CVE tracking and patch prioritisation by exploitability and business impact with full asset visibility.
Proprietary federated threat intelligence from all PHALANX nodes using privacy-preserving AI.