For authorized security testing only
Redline is a browser extension and a dashboard for penetration testing and bug bounty work. The extension carries a payload library that reads the page you're on. The dashboard tracks programs, runs passive recon, and turns findings into a report.
No AI auto-exploit gimmicks. Four things that save real time during a real engagement.
26 payloads across 10 categories — XSS, SQLi, SSRF, LFI/RFI, XXE, SSTI, command injection, NoSQLi, open redirect, CRLF. Search, copy, move on.
The extension reads the page you're actually on — login forms, file params, redirect params — and ranks payload categories by what's worth trying there.
Subdomain enumeration off certificate transparency logs, plus lightweight tech fingerprinting. No port scans, no brute-forcing — just what a browser can do safely.
Findings turn into a severity-sorted PDF shaped for HackerOne or Bugcrowd. One click, not a Sunday-night formatting session.
Load the extension, generate an API key in Settings, point one at the other.
The payload library follows you around the page — copy what's relevant, skip what isn't.
Flag a finding straight from the popup. When the engagement wraps, export the report.
Free account, no card. Bring your own Neon database if you're self-hosting the dashboard.
Create your account