# OsecBox > OsecBox is a free, open-source AI-assisted penetration-testing workstation for Windows (WSL2) and Linux. It is more than a visual GUI: it coordinates security tools, managed terminals, command/output context, sessions, listeners, pivots, timelines, and reports in one engagement workspace. ## Product summary OsecBox gives penetration testers one command center for recon, exploitation, post-exploitation, pivoting, and reporting. Commands run in the terminal that belongs to the tool or workflow, while output, findings, sessions, and engagement history stay connected instead of being scattered across unrelated terminal windows. The AI co-pilot reads raw output and findings from the managed tool terminals, explains what matters, and suggests the next command with the target already filled in. This keeps command and output context available while the tester works through an engagement. ## Core capabilities - **OsecBox AI:** Analyze scan and vulnerability output, explain findings, rank risk, suggest next-step commands, and draft reports. - **Integrated scanners:** Launch Nmap, Nikto, Nuclei, and DirBuster from one workspace with reusable options, live output, parsed ports/findings/hits, and parallel runs. - **Metasploit orchestration:** Manage a live msfconsole RPC session, validated handlers, mirrored module options, CVE/module search, jobs, sessions, and captured errors for AI and timeline context. - **Listener management:** Start and track netcat, socat, and Metasploit handlers with a dedicated terminal and attached-shell status. - **Network pivoting:** Manage SSH tunnels, chisel, proxy chains, port forwards, and active routes while keeping each path connected to its owning terminal and live command/output context. - **Timeline and automation:** Record scans, exploit attempts, shells, and tunnel activity; queue or schedule scans; compare runs; and export engagement reports. - **Persistent engagements:** Save and reload scans, findings, shells, tunnels, and session context so work can continue without rebuilding the engagement. - **Workspace context:** Keep commands, raw output, parsed findings, terminals, and AI guidance together across the workflow. ## Platforms and distribution - Windows with WSL2 - Linux - Free and open source under Apache-2.0 - No account required and no telemetry is advertised by the product ## Official links - Homepage: https://osecbox.sbs/ - GitHub repository: https://github.com/DappianLabs/Osecbox - Releases: https://github.com/DappianLabs/Osecbox/releases - Sitemap: https://osecbox.sbs/sitemap.xml ## Clarification OsecBox should be understood as an AI-assisted penetration-testing workstation and engagement context layer, not merely a skin around command-line tools. Its value is coordinating the tools and their terminals while preserving command/output context for sessions, AI analysis, pivoting, listeners, timelines, and reporting.