FAQ
Straight answers, including where the honest answer is “not yet.”
Is Hollowpath available to download or install?
Not yet. There is no public repository, installer, or package. See Getting Started for the current status.
Is Hollowpath open source?
Not currently — no public repository exists. This will be revisited once one does.
Does Hollowpath replace tools like Nmap, Metasploit, or Burp Suite?
No. Hollowpath orchestrates and integrates with tools like these rather than replacing them — the value is the shared workflow and context between them, not out-performing any one of them at its own specialty.
Can Hollowpath exploit targets automatically?
No. Exploitation requires explicit, multi-step operator confirmation of the actual resolved target every time, restricted to verified in-scope lab hosts. There is no generic "exploit" action.
What happens if a target is outside the defined scope?
The scope engine blocks reconnaissance tooling and exploitation against it at the code level, independent of what any confirmation dialog shows. See the Security Philosophy page.
Is there a cloud or web version?
Not today. app.hollowpath.org and api.hollowpath.org are reserved names for a possible future web platform — nothing is implemented there yet.
What does the generated report actually contain?
Executive summary, scope, asset inventory, services, findings, exploit intelligence, evidence, and a technical appendix — see a real example on the Reports page.
