Collaborative Web Exploitation Framework
Intercepting proxy, blind vulnerability detection, web shell generation, C2 integration, and collaboration tools in a single binary with an embedded web UI.
Joro brings together the tools needed throughout a modern web application engagement into a single binary with an embedded web UI, reducing the need to switch between disconnected tools.
Instead of focusing only on web interception, Joro supports the entire engagement lifecycle:
Most intercepting proxies excel at finding web vulnerabilities.
Modern offensive security engagements require much more than that.
Once an initial vulnerability is discovered, practitioners often need to:
Traditional proxies typically rely on plugins or entirely separate tools for these workflows, forcing constant context switching.
Joro was built differently. Instead of stopping at web interception, Joro combines the capabilities needed throughout an engagement into a single platform.
Bishop Fox Researchers
As a member of the Bishop Fox Cosmos team, Tony focuses on the continuous testing of clients' public-facing attack surfaces. Prior to joining Bishop Fox, Tony served in the U.S. Air Force as a Senior Operator and Technical Lead of a Department of Defense Red Team. In 2023, Tony successfully transitioned from military service to the civilian workforce through the Skillbridge program. He holds a B.S. in Cybersecurity from University of Maryland Global Campus.
Joro is open source and built for the offensive security community. Star the repo, file issues, contribute templates, or fork it for your own research.