Point it at a domain and Cascade runs subfinder, amass, httpx, gau, katana, ffuf, nuclei, wafw00f, and gowitness as one managed pipeline โ then a Priority Engine ranks every finding by severity, with the reasoning spelled out in plain language. No API keys. No sign-ups. One Windows app, click and run.
โฌ๏ธ Install ยท โจ Features ยท ๐ How to Use ยท ๐๏ธ Menu guide ยท
Important
Educational & Defensive Security Research Disclaimer
This project is developed strictly for educational purposes, defensive security research, and authorized bug bounty scope testing. The developer (@n0xnull) does not condone or support unauthorized scanning or malicious activities. Users are solely responsible for complying with target program policies and applicable laws. See DISCLAIMER.md for full terms.
๐ฎ๐ฉ Baca dalam Bahasa Indonesia
Cascade adalah aplikasi Windows desktop yang mengorkestrasi sembilan tool rekon bug bounty (subfinder, amass, httpx, gau, katana, ffuf, nuclei, wafw00f, gowitness) dalam satu pipeline terpadu โ satu klik, satu daftar temuan terurut.
Setiap tahap melaporkan status eksplisit (ok/partial/skipped/failed โ tidak pernah gagal diam-diam). Priority Engine menggabungkan semua sinyal menjadi satu daftar berperingkat dengan alasan plaintext di tiap item.
Laporan: HTML mandiri, Excel multi-sheet (dengan thumbnail screenshot), JSON, dan CSV per tahap. Scan bisa dilanjutkan dari tahap yang gagal tanpa mengulang dari awal.
Real bug bounty recon means chaining eight-plus command-line tools by hand:
remembering flags, babysitting timeouts, re-running the ones that silently
failed, and manually cross-referencing subdomains against live hosts,
WAF status, origin IPs, and fuzzing hits before you even know what's worth
looking at. A single missed flag or a tool that "succeeds" with zero output
means you quietly miss a finding โ this happened for real during a live
recon run this project was built to fix (see CONCEPT.md and
CHANGELOG.md for the actual bugs found and fixed).
Cascade wraps the whole chain in one desktop app: every stage reports an explicit status (ok/partial/skipped/failed โ never silently missing), and a Priority Engine merges every signal into one ranked list with a human-readable reason attached to each item.
- ๐งฌ 8 managed stages โ subdomain enumeration, live host discovery, passive URL archiving + JS secret-scanning, WAF detection & screenshots, CDN-aware origin-IP check, JS endpoint extraction, directory fuzzing, nuclei vulnerability scan.
- ๐ฅ Priority Engine โ merges every stage's signals into one severity-ranked list, every item with a plain-language reason.
- ๐ Findings Tracker โ track each finding's workflow status (New โ Verifying โ Reported โ Accepted/Rejected/Paid) right inside the app.
- ๐ฐ๏ธ CDN-aware origin-IP detection โ cross-checks multiple signals instead of assuming Cloudflare; a provider with no verified IP range data is flagged "can't be concluded" instead of silently guessing.
- ๐ช Built for Windows properly โ Win32 Job Objects guarantee child processes (e.g. the Chrome instance gowitness spawns) actually die on cancel, and a concurrency governor prevents socket exhaustion on large domains.
- โป๏ธ Resume failed scans โ re-run only the stages that failed or were skipped, without starting over.
- ๐ Full reporting โ reopenable JSON, multi-sheet Excel (with embedded screenshot thumbnails), self-contained HTML, and per-stage CSV.
- ๐ฝ Installer or portable โ pick a proper Start Menu install, or run from a folder with nothing written elsewhere.
- ๐ Bilingual โ Indonesian / English UI.
- ๐ No telemetry โ nothing is ever sent anywhere.
Main window โ target, scan profile, consent gate, live tool status, and progress/log, all in one view.
| Minimum | |
|---|---|
| OS | Windows 10 or 11, 64-bit (Qt 6 dropped Windows 7/8) |
| RAM | 2 GB |
| Disk | ~200 MB free (app only โ recon tools installed separately) |
| Network | Internet connection for the recon tools themselves |
Cross-platform note: the code also runs on Linux/macOS from source (
python main.py), but official binaries are Windows-only for now.
Two options โ pick whichever suits you:
- Go to Releases.
- Installer โ download
CascadeSetup-<version>.exe, run it, get a Start Menu shortcut and a proper uninstaller. (Recommended for most people.) - Portable โ download
Cascade-Portable-<version>.zip, extract, runCascade.exedirectly. No install, no admin rights needed.
First launch may show Windows SmartScreen because the build isn't code-signed. Click More info โ Run anyway. Verify integrity with the published
.sha256.txtchecksum next to each download.
- Install the recon tools โ see
TOOLS_INSTALL_GUIDE.md. Cascade opens fine with zero tools installed; any stage whose tool is missing is skipped with an explicit status, not a silent failure.
git clone https://github.com/n0xnull/Cascade.git
cd Cascade
python -m venv .venv && .venv\Scripts\activate # Windows
pip install -r requirements.txt
python main.py:: Windows, one click:
build.bat
:: -> dist\Cascade\Cascade.exe (already a portable folder, --onedir)Manual equivalent:
pip install -r requirements-dev.txt
pytest tests/ -q
pyinstaller cascade.spec --noconfirm --clean:: Requires Inno Setup 6 (https://jrsoftware.org/isdl.php) and build.bat done first:
build-installer.bat
:: -> dist\CascadeSetup-<version>.exePushing a version tag (git tag v1.0.0 && git push origin v1.0.0) triggers
.github/workflows/build.yml โ GitHub
Actions builds on a Windows runner, runs all 59 unit tests (a failing test
blocks the release), and publishes both artifacts to a GitHub Release
automatically.
- Type a target domain (e.g.
example.com), or import a.txtlist for batch mode. - Pick a profile โ Quick (fast triage), Standard (equivalent to the
original script's
-FastOnly), Deep (full 8-stage pipeline), or Custom. - Check the consent box โ confirms you have lawful authorization to test this target. Cascade refuses to start without it, in both the GUI and CLI.
- Click Start Scan. Watch live progress/log and the Pipeline Preview (the exact command run for every tool). Stop any time.
- Browse per-stage result tabs, then open Priorities for the severity-ranked findings list, or Findings Tracker to log workflow status per finding.
- Reports save automatically (
scan_<domain>_<timestamp>.json+.xlsx/.html/ CSV) โ the exact folder is shown in the status bar. Saved scans can be reopened, and failed stages re-run without starting over.
| Menu | What it does |
|---|---|
| File โธ New Scan | Clear results and start a fresh target. |
| File โธ Open Saved Scan | Reopen a previously saved scan_*.json. |
| File โธ Export | Re-export the current result as JSON/XLSX/HTML/CSV to a folder of your choice. |
| Settings โธ Language / Theme | Indonesian / English, dark / light. |
| Tools โธ Update Tools/Templates | Refresh the tool-availability check (e.g. after installing subfinder). |
| Help โธ Disclaimer / Licenses / About | Terms of use, third-party licenses, credits. |
Cascade.exe --domain example.com --profile deep --i-am-authorized--i-am-authorized is mandatory โ same consent gate as the GUI checkbox.
Run Cascade.exe --help for the full option list (resume, custom stages, etc).
target domain
โ subdomain enumeration (subfinder + amass + crt.sh, wildcard-DNS aware)
โ live host discovery (httpx: status/title/tech/CDN)
โ passive URL archiving (gau) โ sensitive-file tier + JS secret-scan
โ WAF detection (wafw00f, per-host) + screenshots (gowitness)
โ CDN-aware origin-IP check (bypass detection, not Cloudflare-only)
โ JS endpoint extraction (katana)
โ directory fuzzing (ffuf)
โ nuclei vulnerability scan
โ Priority Engine (merges every signal, severity-ranked, reasons attached)
โ reports (JSON / XLSX / HTML / CSV)
Every stage runs as a real subprocess with an argv list (never a shell
string โ this is what makes Windows paths-with-spaces safe by construction,
not by special-casing), reports one of eight explicit statuses no matter
what happens, and is wrapped so a single stage crashing never takes down
the rest of the pipeline. See CONCEPT.md for the full design
rationale and every real bug this fixed compared to the original PowerShell
script it replaced.
- v1.1 โ richer nuclei template management from within the GUI, scan diffing (what changed since the last run on this domain).
- v1.2 โ PDF export, custom report branding.
- v2.0 โ plugin-style custom stages without touching the orchestrator.
Issues and PRs welcome. Adding a new stage is one new file under
engine/stages/ implementing BaseStage plus one line in
engine/registry.py โ the orchestrator needs no other change.
Cascade does not bundle subfinder, amass, httpx, gau, katana, ffuf,
nuclei, or gowitness โ it detects and calls whatever you've installed
yourself (see TOOLS_INSTALL_GUIDE.md), so you
always get the latest version straight from each project's own release.
wafw00f is the one exception (used as a Python library) and is bundled.
See THIRD-PARTY-LICENSES.md for every tool and
library's license.
For authorized security testing only. Scan only domains you own or have
explicit permission to test โ an official bug bounty program's scope or
written authorization. See DISCLAIMER.md.
MIT ยฉ 2026 Abil Khosim. Third-party tools and libraries remain the property of their respective owners.
Cybersecurity Specialist
Cascade is an original project by Abil Khosim, an independent security tool by Abil Khosim (NoxNull). Released under the MIT License โ ยฉ 2026 Abil Khosim. Please keep this attribution when reusing or redistributing.
Bugs don't wait for the water to clear. ๐ช