CROSSFYRE
OFFENSIVE SECURITY OPERATIONS PLATFORM

Offensive security that doesn't fall over.

Recon, scanning, and offensive workflows across your own distributed nodes, resumable through crashes and orchestrated from one crash-safe control plane. Built for bug-bounty hunters and pentest teams who are done babysitting shell scripts.

Free tier · No credit card · Your nodes, your infrastructure

Offensive Operations Collapse Under Complexity

01

Tools Were Never Designed to Operate Together

Recon pipelines are still stitched together with shell scripts, temp files, and fragile glue logic. Enumeration, scanning, probing, and analysis remain disconnected systems with no shared operational context.

02

Intelligence Dies Between Execution Stages

One scanner discovers an exposed API. Another tool never sees it. Findings stay trapped inside isolated outputs instead of flowing through a unified operational pipeline.

03

Visibility Vanishes Across Distributed Operations

As targets, nodes, proxies, and workflows scale, operational awareness disappears. Teams lose track of what is running, where traffic originates, and how scans are behaving in real time.

04

Infrastructure Fails Mid-Engagement

Cron jobs crash. VPS nodes disappear. Tunnels leak. Long-running scans silently stall without orchestration, health monitoring, or recovery mechanisms built into the execution layer.

One Platform. Full Operational Control.

Everything required to orchestrate offensive security operations at scale, from distributed execution to live operational intelligence.

Built from the ground up

The Crossfyre Platform

We didn't just build a dashboard. Crossfyre is the entire operational stack: a distributed node runtime, provisioning and package management, a workflow engine, the networking layer, the tooling ecosystem, the control plane, and the orchestration and results platform that ties it all together. Nine layers, all ours.

01

Distributed node runtime

The foundation. An agent that turns any box you own into a worker, pulling jobs and streaming results back in real time.

02

Node provisioning

Bring those workers online. Enrol and deploy nodes in one command, with per-node scoped credentials so each only ever sees its own work.

03

Package management

Equip every node. Installs, pins, and updates engines and extensions across your whole fleet, reproducibly.

04

Networking layer

Connect the fleet. A durable work queue, proxy chains, and isolated tunnels carry every job and every result, end to end.

05

Tooling ecosystem

The work itself. mach, voyage and pulse plus the extension ecosystem. Open-source engines, run standalone or orchestrated.

06

Workflow engine

Compose the tools. Runs workflows step by step, chaining engines and extensions into repeatable, schedulable operations.

07

Orchestration layer

Coordinate at scale. Scheduling, workload distribution, and crash-safe state, so a dropped node or a restart never loses progress.

08

Control plane

Govern it all. Accounts, auth, teams, billing, and the public API. The hosted brain everything else answers to.

09

Visualization & results

What you see. The dashboard, live telemetry, and prioritized findings. Raw output becomes ranked, filterable, exportable results.

One company, one stack, nothing rented. That depth is the difference.

The platform

Everything you need to run offensive security at scale.

Not another wrapper around shell scripts. A hosted control plane for your own nodes, with the orchestration, safety and visibility that automation actually needs.

Distributed operation nodes

Turn any box into a node and run recon, scanning, and offensive workflows across your own fleet, in parallel, on infrastructure you control.

Crash-safe workflows

Scans that resume. A dropped node or a crash never loses progress, and you are only charged for work actually done.

Findings, prioritized

Raw output becomes ranked findings. Filter by severity, active or passive, and host; export to CSV, JSON or Markdown.

Scheduled scans

Set it and forget it. Recurring recon on a schedule, with results pushed straight to you.

Open-source toolchain

mach, voyage and pulse: content discovery, subdomain enum and port scanning. Run them standalone or let the platform orchestrate them.

Team spaces

Shared nodes, wordlists and findings with role-based access for your whole crew.

CLI-first, with OPSEC

One CLI drives everything. Route node traffic through proxy chains and isolated network tunnels.

SEE CROSSFYRE IN ACTION

From Solo Hunters to Full Red Teams

Built for the way you actually operate, from a single bug-bounty hunter on one box to a red team coordinating a distributed fleet.

Bug Bounty Hunters & Researchers

Run distributed reconnaissance and large-scale scanning without building or babysitting your own infrastructure. Point it at a scope and watch findings stream in.

  • Distributed node execution
  • Proxy & tunnel isolation
  • Workflow automation
  • Real-time findings

Red Teams

Coordinate complex offensive operations through a centralized command layer with shared visibility, distributed execution, and operational control.

  • Team-based workflows
  • Shared operational state
  • Live telemetry
  • Controlled infrastructure routing

Security Teams

Continuously monitor internal and external attack surfaces using customizable reconnaissance workflows, streaming intelligence, and automated analysis.

  • Continuous reconnaissance
  • Exposure discovery
  • Attack surface monitoring

Enterprise Security Labs

Standardize offensive tooling, infrastructure, and operational policies across distributed teams with centralized visibility and scalable execution.

  • Unified operational control
  • Infrastructure governance
  • Distributed fleet management
  • Standardized execution pipelines

Real Operational Experience

Crossfyre was designed around the operational realities of modern offensive security, from distributed reconnaissance to controlled infrastructure and large-scale execution.

OPERATIONAL EXPERIENCE OPS-LOG-01

Built by Engineers Who Run Offensive Infrastructure

Crossfyre was built from real-world frustrations with fragmented tooling, unreliable workflows, and infrastructure that failed during active operations.

RESEARCH DRIVEN RES-DAT-04

Built Around Modern Reconnaissance Techniques

Designed around evolving offensive methodologies, distributed execution models, and scalable attack surface intelligence techniques.

RESILIENT BY DESIGN NET-SEC-99

Engineered for Unstable and Hostile Environments

Built to maintain operational continuity across unstable networks, rate limits, infrastructure failures, and degraded routing conditions.

Simple, honest pricing.

Your plan sets your limits and unlocks capabilities. Scanning within them is unlimited, with no per-scan fees and no metered minutes. No surprise bills.

Free
$0

Free forever

Kick the tyres.

  • 2 nodes, 10 proxies
  • 5 workspaces
  • 2 concurrent workflows
  • 100 workflows / month
  • All extensions
Start free
Reaper
$79 /mo

billed monthly

For running at full tilt.

  • 20 nodes, 100 proxies
  • 50 concurrent workflows
  • Missions + advanced adaptive
  • Priority execution
  • Unlimited findings retention
Go Reaper

Monthly / quarterly / yearly terms. Quarterly saves 10%, yearly is 2 months free.

Organizations

Teams, shared workspaces and per-seat billing for MSSPs and red teams. Syndicate is self-serve (up to 10 seats); Enterprise is custom limits with invoiced billing.

See org plans
OPS LIVE

READY TO HUNT ?

Point it at a target and watch findings stream in, live.

Start free

Free tier · No credit card · Bring your own nodes

Frequently Asked Questions

Answers about deployment models, infrastructure, operational workflows, and platform capabilities.

Bug-bounty hunters, independent researchers, and pentest and red teams who run distributed reconnaissance, from a solo operator on one box to a boutique shop coordinating a fleet. Larger security labs standardizing large-scale recon programs fit too.

It's a different class of tool. Crossfyre runs on our own proprietary Rust scanning engines, purpose-built for distributed execution, with industry-standard tooling available as optional extensions when you want it. On top of that you get what a DIY toolkit can't: hosted zero-setup deployment, a crash-safe control plane where scans survive node failures and resume instead of restarting, a live dashboard your whole team shares, and proxy and tunnel routing. Those projects are scripts you assemble and maintain yourself. Crossfyre is an engineered operations platform. For side-by-side comparisons against Axiom, Trickest, reNgine and more, see /vs.

Start free, no credit card. Paid plans are built for solo operators and small teams. See the pricing section above for the tiers.

Nothing is lost. Work is dispatched over a durable, acknowledged work queue, so if a node drops, its in-flight work is automatically redelivered to another node and the scan resumes. Long, multi-hour scans finish even across unstable networks and rate limits.

Your findings are yours. Scan data is isolated per team, encrypted in transit and at rest, and never sold or used to train anything. You can run nodes on your own infrastructure so traffic originates from where you choose. See our security page for specifics.

Nodes can be self-hosted by any user. Deploy the cfx_controller daemon on your own VPS, lab, or internal infrastructure. Self-hosting the full control plane (Nexus, API switch, and supporting services) is available exclusively to enterprise customers.

Yes. Crossfyre is for authorized offensive security work only: engagements you're contracted for, assets you own, or scoped bug-bounty programs. The proxy and VPN-isolation features exist to model real adversaries during authorized tests and keep traffic in-scope, not to enable unauthorized access.

Yes. Nodes can operate behind layered proxy chains and VPN-isolated tunnels, so you control your egress and keep traffic in-scope during authorized offensive operations. This is source-IP and routing control for engagements you're authorized to run, not a way to evade attribution.

Workflows are decomposed into operations and dispatched across your distributed nodes using a durable streaming execution model. Findings are returned in real time as operations execute.

Yes. Crossfyre includes team-based operational management with shared workflows, centralized visibility, permissions, activity tracking, and distributed infrastructure coordination.

Yes. Crossfyre includes a Python-based .cfx playbook system for building custom offensive workflows, automation pipelines, and extension-driven execution logic.

The node agent is. The cfx_controller daemon you run on your own infrastructure is open source on GitHub, so you can audit exactly what executes on your machines before you run it. The control plane and scanning engines remain proprietary, developed by Clickswave Labs Private Limited.