HuntFlow is a local-first pentest workflow OS for managing engagements from recon to report. Track targets, focused test sessions, Markdown notes, recon assets, evidence, findings, reports, and progress in one offline-ready PWA. The MIT-licensed core stores data in your browser with zero telemetry and no account required. Run it with npx huntflow@latest; optional $6/month Pro adds encrypted cloud sync and backups across devices.
Hey Product Hunt! 👋
I built HuntFlow because pentest work kept spilling across spreadsheets, timers, Markdown files, screenshots, reporting docs, and too many browser tabs. Generic project tools do not understand scope, targets, evidence, findings, or the rhythm of a testing session.
HuntFlow brings that workflow into one local-first command center. The core is MIT licensed, runs offline, keeps data in your browser, sends zero telemetry, and requires no account. You can launch it with npx huntflow@latest. Optional Pro sync is there for people who want their workspace across devices, while local use stays free.
I would love feedback from pentesters and bug bounty hunters: which part of your workflow still feels unnecessarily fragmented?