Paravizor turns reconnaissance from a fragile chain of one-off shell scripts into a structured, reproducible, and resumable process. It's a terminal-native "recon copilot" for bug bounty hunters and pentesters: you define a scope and a pipeline, and Paravizor orchestrates your existing tools, normalizes their wildly different outputs into one coherent datastore, and surfaces the high-value attack surface — while you stay in control of every decision.
It's built in Go as a single portable binary, with both a scriptable CLI and an interactive Bubble Tea TUI.
The problem it solves
Anyone who has done real recon knows the pain: a dozen tools (subfinder, httpx, nuclei, and friends), each with its own output format, glued together with brittle bash. When a scan crashes three hours in, you restart from scratch. Context is lost between steps. Results pile up as unsorted text files, and the signal drowns in noise. Nothing is reproducible across projects.
Paravizor replaces that with a unified orchestrator sitting on a coherent data model. The design rests on three principles:
- Controllability — the operator keeps ownership of every decision; automation never acts on its own on anything critical.
- Traceability — every result can be traced back to the tool run that produced it.
- Evolvability — pipelines, tools, and strategies can change quickly without rewriting glue.
How it works
project.yaml ──▶ pipeline.yaml ──▶ ┌──────────────────────┐
(scope, (nodes + │ Pipeline engine │
constraints) routing) │ DAG · batches · │
│ scope gate · resume │
└──────────┬───────────┘
│ runs external tools
┌──────────────────────┼──────────────────────┐
▼ ▼ ▼
subdomains URLs / IPs / ports findings
└───────────── normalized into ───────────────┘
│
SQLite datastore
(crash-safe)
│
┌────────────┴────────────┐
▼ ▼
CLI / Bubble Tea TUI Markdown + data exports
- Project & scope. Every campaign is a project with an explicit in-scope / out-of-scope definition. A scope gate runs before every node transition, so out-of-scope assets can never leak into the pipeline — a safety guarantee that matters a lot in bug bounty.
- Pipeline engine. Pipelines are declarative YAML: nodes connected by conditional or parallel routing, executed as a DAG over typed items (domains, URLs, IPs, ports, DNS records, files, findings). A generic tool runner executes installed tools and cleanly skips missing ones.
- Crash-safe resume. Pipeline state is checkpointed to SQLite. If a run is interrupted, interrupted rows are re-queued and the campaign resumes cleanly instead of starting over — the single most valuable property on long recon runs.
- One datastore. Every tool's output is normalized into a shared SQLite schema, so results are queryable and consistent instead of scattered across text files.
- Triage & export. Discovered assets are classified and the important signals highlighted, then exported as subdomains, URLs, IPs, ports, findings, and a Markdown report to feed the next phase.
- AI as an accelerator (governed). An optional AI layer summarizes observations, explains technologies and anomalies, and suggests next pivots — strictly as assistance. Critical actions need explicit validation, recommendations are transparent, and the whole layer can be turned off. It's designed to speed up decisions, not replace expertise.
Why it's a strong project
- Real engineering, not a wrapper. A DAG-based pipeline engine, a typed item model, a SQLite persistence layer, adaptive rate limiting, an event bus, and a TUI — cleanly separated so no module imports UI code and the UI only reads events.
- Resilience is designed in. Crash-safe resume and a pre-transition scope gate are the kind of properties that separate a real tool from a demo script.
- Human-in-the-loop by design. In a space rushing to "fully autonomous" tooling, Paravizor deliberately keeps the operator in command and treats AI as a transparent, optional copilot.
- Portable and reproducible. A single Go binary, YAML-defined pipelines, and per-project datastores make campaigns shareable and repeatable across machines and teams.
🛠️ Stack & Techniques
- Language: Go (single portable binary)
- TUI: Bubble Tea + Bubbles (Charm)
- CLI: Cobra, for headless and CI use
- Config: Koanf, with YAML project / pipeline / tool definitions and struct validation
- Storage: SQLite (
modernc.org/sqlite, pure-Go, no CGO) with a typed schema - Engine: DAG execution, conditional/parallel routing, batching, checkpointed pipeline state, crash-safe resume
- Reliability: adaptive rate limiting (token bucket + credit pool), scope filtering before every node transition
- Architecture: event-bus decoupling between engine, tool runner, CLI, and TUI