The software
What kind of scanner is it?
Krynos is a command-line web application security scanner. It finds one very specific class of vulnerabilities that affect websites and compromise their integrity: it takes a list of URLs as input and automatically checks which ones turn out to be potentially exploitable.
It is not a general-purpose tool that tries to do everything: it does one thing, and it does it in depth. Its effectiveness against this category is documented by my public track record on HackerOne — since 2022 I have ranked from fifth up to third place, several times, in the world ranking, with reports filed in the OWASP Injection category.
What are the "payloads" I sell together with the source code?
The payloads are the requests the program sends to the target to surface the vulnerability. They are not a generic list taken from elsewhere: I built them myself, as the result of research and development, in two ways. On one hand by analysing the source code of dozens of web servers to understand their real behaviour; on the other by exploiting logical flaws, documented in the RFCs of the HTTP protocol, that can occur under certain conditions.
In other words: behind every payload there is reasoning, not brute force. This is the part that gives Krynos the results other tools do not achieve.
How is it different from Nuclei, ZAP, Acunetix?
Those tools are excellent general-purpose suites, broad but not specialised on this front. Krynos plays a different role: it is very good at finding a well-defined type of vulnerability, it is completely automatic, and it uses payloads that those tools, in their normal configuration, do not try.
I do not offer it as a replacement for your usual suite, but as the extra tool that covers exactly what the others miss — and that is precisely where the vulnerabilities that no one has reported yet are found.
What output does it produce? What are the reports like?
Krynos generates an essential, straightforward text log: it lists the URLs found to be potentially vulnerable and, for each one, specifies which request worked. That way you immediately have both the target and the means to reproduce and manually verify the result, ready to attach to a disclosure or pentest report.
No dashboards, no frills: a text file that fits frictionlessly into any terminal-based workflow.
Requirements
What are its technical requirements? What does it run on?
The Software is written in the C language and is provided both as source code and as a precompiled binary for Debian 13 [amd64].
The binary requires a Debian 13 system (or a compatible Linux distribution, such as Ubuntu and its derivatives) with the OpenSSL 3 library (libssl and libcrypto) installed and a working network connection.
Compiling from source requires a C development environment (gcc or clang) and OpenSSL with the development headers (the libssl-dev package). The remaining dependencies are standard components of the C language and the POSIX APIs, normally already present on Linux systems.
Do I need a licence or an activation key?
No. The Software is released under the MIT licence: no key, no activation, no registration, no seat limits. Once you receive it, it is yours and it works on its own.
The MIT licence lets you freely use, modify, integrate and even redistribute the Software, with the sole condition of keeping the copyright notice and the text of the licence. The full text is included in the package.
How the purchase works
What happens if the target number is not reached?
If the 500 pledges are not reached by the deadline (30.09.2026), the offer automatically lapses: no contract is concluded and no amount is charged. The stored payment method is removed and any pre-authorisations are released within your bank's technical timeframes, at no cost.
In short: pledging exposes you to nothing if the campaign does not go ahead.
When is the payment charged?
At the moment you pledge you pay nothing: you only authorise the future charge. The amount of €99 is taken only once, at the deadline (30.09.2026), and only if the target has been reached.
You receive an email reminder two days beforehand, on 28.09.2026, so the charge does not catch you by surprise.
How and when do I get the download?
As soon as the campaign closes successfully and the charge goes through, you receive by email the link to download the complete package: C source code, precompiled binary for Debian 13 [amd64] and the text of the MIT licence. Delivery is digital and immediate.
How do I request the purchase invoice?
If you need an invoice, you request it from the dedicated portal https://security.lucaercoli.it/my_invoice.php by entering the email used for the purchase.
The request should preferably be made at the same time as the campaign has ended and in any case within [7] days of the charge.
What address do the campaign emails come from?
The emails tied to the campaign — pledge confirmation, reminder before the close, outcome and download link, plus the invoicing link — are sent via Marketly, the transactional email service that handles delivery on behalf of the campaign.
They will all come from the sender notifiche@marketly.it: add it to your trusted contacts and, if you do not see a message you were expecting, check your spam or junk folder. For direct communication you can instead write to me at luca@lucaercoli.it
Trust and proof
How do I know the claimed results are real?
The track record is public and verifiable. You can find my full CV, downloadable from my website (lucaercoli.it), with the details of the HackerOne ranking and the research work. The figures on the page are not a slogan: they are the summary of that track record.
My HackerOne world rankings in the OWASP Injection category, year by year — tap a badge to open the live leaderboard:
2025 2024 2023 2022How do I know the tool found them, and not you by hand?
By the very nature of the numbers. Collecting hundreds of vulnerabilities, all concentrated in the same category (OWASP Injection), and holding a top position in HackerOne's world ranking for years, is a volume that cannot be achieved by hand: it necessarily requires an automatic tool that works systematically and at scale.
That ranking, with those volumes and that specialisation, is in effect the proof that there is an automatic engine behind it — and that engine is what you are buying.
Do you also offer paid consulting or pentesting?
Yes. Besides selling the software, I take on consulting engagements and pentest work on request. It is a service separate from the purchase of Krynos and is agreed on a case-by-case basis.
If you are interested, write to me by email at luca@lucaercoli.it and we will talk it over.
Didn't find your answer, or want to join the campaign?
Go to the pledge