Your local, private AI. Ask anything, or switch to Agent mode and I'll actually do things on this machine.
New here? Three ways to start
Chat — just ask a question. Fast, private, local.
Agent — describe a task and it actually runs on this machine.
Payload Studio (⚡ in the top bar) — no-skill wizards that build RATs, shells and listeners for you.
Settings
Allowed tools allUncheck everything for unrestricted access. Check tools to restrict the agent to that allow-list.
Models
waiting…
Build / customize a model
Built locally from an installed base — nothing is downloaded.
Upload & import a GGUF model
⬆
Drop a .gguf model file here — or click to choose
Installed
Pulls go straight to your local Ollama — nothing leaves this machine.
Zero-Day Lab
Guided discovery on targets you own: static memory-safety triage, ELF hardening audit, a built-in mutational fuzzer, AddressSanitizer crash triage with an estimated CVSS, and a diff hunt across two builds. Everything runs locally in ~/.hackcode/zeroday.
checking engine…
Quick scan — one button
Analyzes the target, compiles it if needed, runs a short fuzz campaign and triages any crash — automatically.
Runs entirely on this machine — no target data leaves the host.
Skills
Skills are reusable instruction bundles the hackcode agent can load on demand. Create one below, or drop a SKILL.md into ~/.hackcode/skills.
New skill
Available
Skills live on this machine, in the hackcode skill folders.
Payload Studio
Build reverse shells, Meterpreter and implant payloads with msfvenom, copy cross-language one-liners and listeners, forge ready-to-run RAT implant kits (Python / PowerShell / C / Bash + matching handler), and trojanize a legitimate binary with a payload. Artifacts are written to ~/.hackcode/payloads on this machine.
Implant source
msfconsole handler (.rc)
Wrap a legitimate binary with a payload (msfvenom -x <template> -k) so the host program keeps working. Templates are resolved from ~/.hackcode/payloads/templates; the service runs with PrivateTmp, so files under /tmp are not visible to it.
One-click mode. Choose what you are attacking, switch on Undetectable, and press Build — you get the implant, a matching listener and plain-English instructions. No payload expertise needed.
Live session mirror. Start a managed multi/handler here and watch everything — connections, sessions and console output — stream live into this pane. Type commands to steer it.
Forge the flagship Apex RAT — or drop in your own template — and choose your own options: capability modules, a kill-date, a working-hours beacon window and custom @@TOKEN@@ variables. Apex is a standard-library-only, cross-platform implant with authenticated encryption, jittered beaconing, cross-platform persistence and self-destruct, and it ships with a matching handler.
Capability modules
Custom @@TOKEN@@ variables
Never built a payload before? Just follow the four steps. Pick a target, type your address, choose a style, tick what it should be able to do, then press Forge my implant. You get a ready-to-run kit and a plain-English to-do list.
1Target
2Address
3Style
4Abilities
Step 1 of 4
Build Apex Android - a complete Android RAT project, based on the most trusted open-source Android RAT (AhMyth) and rebuilt stronger: authenticated encryption, Android 6-15 support, build-time capability modules, a kill-date + working-hours window, anti-uninstall + hidden icon, and a one-command build/sign script. You get the full Gradle/Kotlin project, a builder and a matching console.
Capability modules
Email delivery. Build your implant in any tab — try Simple for one click — then send the finished file straight to an inbox. Just type the email address and press Send; the subject and message are already filled in. Set your sending mailbox once in step 3 and it is remembered.
1
Pick the file to send
2
Who receives it
3
Your sending mailbox (saved once)
R31 C2 console - forge a self-contained implant, run the authenticated listener and task live sessions from one place. Implants speak the stdlib seal protocol (SHA-256 CTR + HMAC-SHA256) over HTTP(S)/TCP and beacon back here. Everything stays on this machine.
Listener
Forge implant
Capability modules
Live sessions
Only run payloads and listeners against systems you are authorised to test.
Pentest Toolkit
Kali tools detected on this machine. Run a command and watch the output stream live — everything stays local.
Pick a task below — we fill in the command for you.
Run
Caller ID quick dial
Set the name and number the callee's phone shows, then dial. Needs FreeSWITCH (fs_cli) and a SIP gateway you are authorised to use — the carrier only passes a number your trunk may assert.
Fill in the fields to see a summary.
Commands run as your user, in your home directory. Only run tools against systems you are authorised to test.
☎ Call & SMS Studio
Build caller-ID and SMS sender-ID setups, see exactly what a provider transmits, and learn the wire format — guided and copy-paste ready.
Pick what you want to build. We fill in every detail and hand you a ready artifact — no prior knowledge needed.
🔎
Start hereNew to this? Open one of these — every field is already filled in for you.
☎Voice — calls & caller ID
✉SMS — messaging & sender ID
🔎Check & look up
🔎
No builders match that search
Try a different word, or tap All to see every builder.
1Choose
2Fill in
3Copy
Task
📞 Phone number → E.164
Paste any number and see its normalised E.164 form, country code, and what can (and cannot) be told from the digits.
🔡 Sender ID → wire encoding
See how a numeric or alphanumeric sender ID is encoded on the wire (the TP-OA field used in delivered messages), including the two reference examples.
Only present a caller ID or SMS sender ID on lines, trunks, and accounts you own or are authorised to operate.
Keyboard shortcuts
EnterSend message
ShiftEnterNew line
CtrlKSearch conversations
EscStop generating / close dialog
?Open this help
On macOS use ⌘ in place of Ctrl.
Everything runs locally — nothing leaves this machine.
Intel / OSINT
Enter a query to pull intel from several public sources at once.
DNS records, certificate-transparency subdomains and WHOIS/RDAP for a host or domain.
Queries go out to public sources (DuckDuckGo, Wikipedia, GitHub, NVD, Stack Exchange, Hacker News, crt.sh — with a HackerTarget fallback — and RDAP) through this machine. Nothing from these queries is stored server-side.
Memory
Self-critique
No lessons yet. Add one above, or run a self-critique.
Top lessons are injected into the model's system context on every chat — stored locally in ~/.config/hackcode-studio/memory/lessons.json.
Browser
●Ready
Web
Pages are fetched through the local server (127.0.0.1:8765). Some sites block proxying — use Extract / Reader if a page will not render inline.