Bug Bounty & Web Pentesting

Web Pentesting
In Your Pocket.

Transform your Android device into a desktop-grade web application vulnerability scanner. Designed for ethical hackers and bug bounty hunters to hunt vulnerabilities anywhere.

10,000+ Templates
SQLi Engine
XSS Auto-Crawler
WAF Bypass
JS Crawl
SQL Injection
Time-based Blind
CRITICAL  Payload: space2comment
AltMAP Vulnerability Search screen showing CVE list with 2984 results
Vulnerability Search
Regex Search 🔍
Search lower case
Add To Group
2984 results found
CVE-2000-0114
Microsoft FrontPage Extensions Check (shtml.dll) - medium
CVE-2000-0760
Jakarta Tomcat 3.1 and 3.0 - Exposure - low
CVE-2001-0537
Cisco IOS HTTP Configuration - Authentication Bypass - critical
CVE-2002-1131
SquirrelMail 1.2.6/1.2.7 - Cross-Site Scripting - high
XSS Payload Executed
✓ Confirmed
JS Executed in WebView
Templates Loaded
10,000+ CVEs
CRITICAL HIGH MED
[SQLi] Time-based blind detected on ?id= parameter [CVE-2023-34362] MOVEit Transfer SQLi — Severity: CRITICAL [XSS] Payload executed in WebView — Reflected XSS [CVE-2021-44228] Log4Shell JNDI Injection — Severity: CRITICAL [WAF] Bypassed ModSecurity with space2comment [JS CRAWL] Intercepted AJAX request to hidden API endpoint [AUTO] Crawl depth reached — 145 pages analyzed [CVE-2024-3400] Palo Alto GlobalProtect OS Command Injection — Severity: CRITICAL [SQLi] Time-based blind detected on ?id= parameter [CVE-2023-34362] MOVEit Transfer SQLi — Severity: CRITICAL [XSS] Payload executed in WebView — Reflected XSS [CVE-2021-44228] Log4Shell JNDI Injection — Severity: CRITICAL [WAF] Bypassed ModSecurity with space2comment [JS CRAWL] Intercepted AJAX request to hidden API endpoint [AUTO] Crawl depth reached — 145 pages analyzed [CVE-2024-3400] Palo Alto GlobalProtect OS Command Injection — Severity: CRITICAL
10K+
Vulnerability Templates
12
WAF Tamper Scripts
JS
WebView Interception
Bulk Scans
Core Capabilities

Everything you need in the field

Advanced SQLi and XSS engines capable of bypassing WAFs and intercepting background network traffic.

10,000+ Vulnerability Templates

Instantly scan web targets against a massive, constantly updated database of over 10,000 known vulnerabilities, exposures, and misconfigurations.

📝

Custom Templates

Write and edit your own custom YAML templates directly in the app to test for proprietary vulnerabilities and zero-days.

🛡️

Advanced SQL Injection Engine

Deep-scan URL parameters and POST data. Equip 12 built-in tamper scripts to bypass WAFs, including space2comment, apostrophemask, and more.

👾

Live XSS Scanner & Auto-Crawler

Manual Mode: Test payloads in a live floating browser! Auto Mode: Set crawl depth and automatically inject XSS payloads across the target.

🤖

Smarter "JS Crawl"

AltMap utilizes a hidden WebView engine to execute JavaScript, intercept background AJAX/Fetch network requests, and extract hidden forms.

🔁

Assisted Scans & Orchestration

Smart Target Profiling extracts keywords and tech. Orchestrate massive Full Scans from a single dialog: run templates, SQLi, and XSS simultaneously!

Latest Release

Version 1.6 Update

Massive update introducing advanced engines capable of finding web vulnerabilities that traditional scanners miss.

🚀

Advanced SQLi Engine

Deep-scan URL parameters and POST data with highly customizable risk, level, and depth settings.

🛡️

WAF Bypass Scripts

Equip 12 built-in tamper scripts including space2comment, apostrophemask, base64encode, and randomcase.

👾

Live XSS Scanner

Test payloads directly inside a live, floating browser. Verify JS execution on the fly with a single tap!

🕷️

XSS Auto-Crawler

Set your crawl depth and let the scanner automatically traverse links and inject XSS payloads across the target.

🕵️

WebView Interception

Utilizes a hidden WebView engine during automated scans to intercept background AJAX/Fetch network requests.

🎯

Smart Target Profiling

Automatically extracts keywords and technologies from your target URL to instantly find the exact CVE templates.

Who It's For

Built for security professionals

In the field, at the office, or in the lab — AltMap adapts to your bug bounty workflow.

🕵️

Bug Bounty Hunters

Automate heavy lifting of web security auditing so you can hunt for bounties from anywhere.

🔐

Ethical Hackers

Advanced SQLi and XSS engines for professional web application vulnerability scanning.

🎓

Security Researchers

Template-driven CVE testing with deep customisation to test proprietary vulnerabilities and zero-days.

🖥️

System Administrators

Assess your own infrastructure and web applications for known vulnerabilities before attackers do.

⚠️ Legal Disclaimer & Terms of Use

AltMap is a professional network auditing and penetration testing tool designed exclusively for ethical hackers, bug bounty hunters, and system administrators.

Start scanning in minutes

Download AltMap free from Google Play and bring professional vulnerability scanning to your Android device.

Download on Google Play