Saturday, October 3, 2026

Yakit for interactive application security testing from a single gRPC-driven GUI

Yakit for interactive application security testing from a single gRPC-driven GUI

yakit is an interactive application security testing platform that wraps the Yaklang engine in a gRPC-connected GUI for authorized pentesters, bundling MITM proxying, passive scanning and Web fuzzing.

Toolyaklang/yakit — TypeScript GUI client for the Yaklang security engine, ~7.7k stars, AGPL-3.0
CategoryInteractive application security testing platform (MITM proxy, fuzzer, scanner GUI)
Primary UseAuthorized web application assessments: traffic interception, passive scanning, and fuzzing driven by Yaklang scripts and fuzztag templates
Safe UseUse only on systems you own or have written authorization to test; the project's own disclaimer restricts it to legally authorized security work, personal learning, and lab environments
Telemetry NoteIts MITM module runs an explicit local HTTP proxy that must be configured on the client and requires installing a CA certificate; defenders see proxy-directed traffic, fuzzer request bursts, and reverse-connection callbacks from the reverse module

yakit positions itself as a consolidated application security testing platform rather than a single-purpose utility, and the README makes that ambition explicit by describing the project as an interactive application security testing platform built on top of a domain-specific language called Yaklang. The repository, yaklang/yakit, is written in TypeScript, carries an AGPL-3.0 license, and sits at roughly 7.7k stars, with topics spanning pentest, redteam, blueteam, and scanner — a mix that reflects the tool's attempt to serve both offensive testers and defenders who want to understand attacker-facing workflows. The core architectural idea is a client-server split: the Yaklang engine exposes its capabilities through a gRPC server, and yakit is the GUI client that drives that engine. This means the engine can run locally on the tester's workstation or be deployed remotely, with the GUI connecting over the network.

The README's framing is worth pausing on, because it explains the project's philosophy. The team behind Yaklang.io built Yaklang as a vertical language for the security domain, intending it as a unification layer — tools that could not be natively integrated into the Yak platform get rewritten as high-quality replacements in the language, while established ecosystem products can be compiled in and adapted. yakit then exists to give practitioners who prefer not to write code a GUI over every capability the engine offers. The README calls this underlying technology CDSL, defined as a CyberSecurity Domain Specific Language, running on a custom stack-based virtual machine that hosts the Turing-complete runtime. Whether the unification thesis holds up in practice, it is a genuinely different design posture from the usual collection-of-scripts approach common in this space.

The most heavily emphasized module is the MITM console, which the README boldly claims can fully replace BurpSuite for interception work. Mechanically, the module starts an HTTP proxy that forwards traffic automatically; when the user enables manual hijacking, automatic forwarding stops, requests are popped off a stack, and the engine decompresses Gzip, handles chunk encoding, and decodes payloads so the traffic becomes human-readable in the frontend. From there the user can view, modify, or replay requests, and the engine repairs the outgoing HTTP packets to keep them valid. A notable implementation detail: the Yak engine implements its HTTP library by hand rather than delegating to a standard stack, which the README says allows deliberately malformed requests and responses for edge-case vulnerability analysis in authorized testing scenarios.

The workflow the project promotes mirrors BurpSuite conventions closely: intercept, review in History, then send selected packets to the Web Fuzzer module for Repeater/Intruder-style work. Beyond the basics, the MITM module adds passive scanning via plugins, hot-loading of Yaklang scripts into the traffic path, packet replacement rules, and tagging. For testers coming from Burp, the mental model translates directly, and the plugin-passive-scan angle is where the Yaklang scripting layer starts to matter — custom logic can run against every proxied transaction without leaving the GUI.

Web Fuzzer is described as the first visualized Web fuzzing tool, and its most interesting technical contribution is the fuzztag system. Tags embedded directly in the raw HTTP request generate payload sets inline: {{int(1-10)}} produces a numeric range, {{file(/tmp/username.txt)}} pulls from an external dictionary, and multiple tagged parameters combine via Cartesian product — eliminating the BurpSuite ritual of choosing an Intruder attack type and importing wordlists for each position. The README also highlights hot-loaded tags, where an embedded Yaklang snippet generates data at runtime for structurally complex payload scenarios, replacing the traditional generate-dictionary-then-import two-step. The backend fixes transport plumbing automatically — repairing CRLF issues, completing Content-Type, boundary, and Content-Length — so the tester only edits the semantically relevant parts of a request.

The reverse-connection tooling rests on what the README calls port-protocol multiplexing. Instead of running separate listeners on separate ports for different callback protocols, the Yaklang engine listens on a single port, identifies the incoming protocol by its header, and responds appropriately — because the protocols are implemented manually to specification, the engine can also construct deliberately malformed protocol frames or carry data over unexpected channels. On top of this, yakit builds a reverse module with three parts: a Reverse Shell receiver that presents an ssh-like interactive experience (handling terminal keys cleanly, unlike the classic nc experience), payload-serving for protocol callbacks, and callback detection across TCP, DNSLog, and ICMP — the latter usable for verifying command execution in a controlled lab. This detection capability is arguably the most defender-relevant piece of the platform, since out-of-band callback verification is equally useful when validating whether a sanitization fix actually works.

A plugin store rounds out the platform, and the README notes that custom Yaklang scripts or plugins can be executed at any step of a penetration workflow, which turns yakit into more of an extensible framework than a fixed toolchain. The GUI-as-a-thin-client-over-gRPC design is what makes this sustainable: plugins run engine-side, so the frontend stays simple and the heavy lifting stays in one place. For teams running authorized engagements, the remote-deployment option also means the engine can sit on infrastructure with appropriate network access while analysts connect from their laptops.

For defenders, understanding this tool matters because its traffic profile differs from BurpSuite in detectable ways. The MITM proxy requires client-side configuration and an installed CA certificate, so its use inside a corporate environment is observable. Fuzzing through Web Fuzzer produces bursty request patterns with programmatically generated parameter values — Cartesian-product combinations are a distinctive signature in WAF and SIEM telemetry. The out-of-band callback detection features (TCP, DNSLog, ICMP) overlap with what blue teams already monitor for, which makes yakit a reasonable choice for purple-team exercises where both sides watch the same signals.

On the legal side, the README carries an unusually explicit disclaimer: the tool is intended solely for legally authorized enterprise security work and personal learning, users must build their own lab targets to test it, and unauthorized scanning of third-party systems is prohibited. Commercial use requires official licensing. That framing aligns with how the tool should be treated — an assessment platform for engagements with documented authorization, not a point-and-shoot scanner. Installation is straightforward for authorized users: download a release build from the project's releases page or the official site, or grab the repository directly with git clone https://github.com/yaklang/yakit.git and follow the build instructions in the English README (README-EN.md).

In sum, yakit is best understood as a serious attempt to collapse the authorized-testing toolkit into one gRPC-driven platform: a capable MITM console, a genuinely innovative fuzztag fuzzing model, hand-rolled protocol handling for edge cases, and a scripting language that ties it together. The AGPL-3.0 license and active release cadence suggest a sustainable project, and the bilingual documentation lowers the barrier for English-speaking operators evaluating it against their existing BurpSuite workflows in lab environments first.

Official project repository for yaklang/yakit.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.