Crimson Hunter
Overview
Automatically crawls web applications to discover AI-facing attack surfaces. Identifies prompt injection entry points in input fields, chatbots, and API endpoints — building the target map so you can focus on the attack.
Burp Suite Analog
Active Scanner — reimagined for AI attack surface discovery.
What it detects
- AI-facing input fields (chatbots, search bars, prompt interfaces)
- API endpoints accepting natural language input
- Prompt injection entry points across web applications
- Hidden AI integration surfaces not visible in standard crawls
Permissions required
proxy.read— reads captured traffic for link extractionscanner.write— writes discovered surfaces as findingsui.tab— registers the Crimson Hunter tabhttp.fetch— makes outbound requests during crawling
UI type
Tab — provides a full-width discovery dashboard showing crawled surfaces, entry points, and coverage.
How to install
Available in the Xtension Store. Requires Pro or Enterprise.
Coming soon
Full functionality documentation will be available when this Sentrinel ships.