Parthaby CyberLynk
Admin login

Security Research Platform · CyberLynk LLP · Made in India

Partha

Partha is a single native desktop application that bundles a full web-application security-testing suite plus binary reverse-engineering, comparable in scope to a professional web-security workbench. It runs completely offline - nothing leaves your machine except the traffic you deliberately send to your targets (and, optionally, a single upload to the decompiler service described in §6.21).

Partha logo

Download

Partha runs locked until it is activated with a license issued by CyberLynk. Check the SHA-256 of the file you downloaded against the value shown here.

Windows

Windows 10 / 11 (64-bit)

Windows installer (.exe)
Partha_0.1.0_x64-setup.exe · 7.9 MB
SHA-256e3b1291509191f15f4806fdab2148299669b89a2e2782f0b8e209b9819030474
Windows MSI package (.msi)
Partha_0.1.0_x64_en-US.msi · 10.9 MB
SHA-2564e1e39144214911a128e476621353287d81a12d8534ed672f98a0ab8ad68a2ea

Verify: certutil -hashfile <file> SHA256

Linux

64-bit Linux (Ubuntu 22.04+, Debian, Fedora…)

Linux portable app (.AppImage) · any distro
Partha_0.1.0_amd64.AppImage · 81.7 MB
SHA-2560f5ae45abdf799e6c8e513aabc6b56a04098d835f8a1e57359ac8185b6e9a786
Linux package (.deb) · Ubuntu / Debian
Partha_0.1.0_amd64.deb · 7.5 MB
SHA-2567b14d53ac74e50b0fa585b8737d68739f28cbf396e78e186a4fb709f84bdb45b

Verify: sha256sum <file>

The Partha workbench

Partha dashboard

What Partha can do

Dashboard

Live operational overview; every figure is derived from real state.Dashboard with live testfire dataStat tiles — Requests captured (and total across all tools), Repeater requests, Intruder…

Target — site map & scope

Site map — a per-host tree built automatically from all captured traffic. Select a node to list its requests and inspect request/response.Target site mapScope — the definition every other…

Proxy

Log, intercept and manipulate HTTP, HTTPS and WebSocket traffic, with unrivalled HTTP/2 support and match-and-replace rules.HTTP history — every exchange, with a Bambda-style filter bar.…

Scanner

Passive scanning as you browse, active auditing of URLs and inputs, and a built-in crawler ("crawl and audit") — optionally through the built-in browser and with authentication.Live…

Content Discovery

Expose hidden attack surface by brute-forcing static and dynamic URLs from a wordlist, with soft-404 awareness. Hits flow into HTTP history and the site map.Content DiscoverySteps: enter a…

Repeater

The feature-rich HTTP editor — manually edit and replay any request, with tabs, protocol switching, and automatic pretty-printing.A real replay: GET /login.jsp to demo.testfire.net…

Intruder

Faster brute-forcing and fuzzing with custom payload sets and attack types, and capture / filter / query of results.Positions & payloads — mark injection points with §…§, pick an Attack…

API Security

Scan OpenAPI, GraphQL and SOAP APIs from a definition file. Partha auto-detects the definition kind and enumerates every operation into a ready-to-send request, then runs an API-focused…

Sequencer

Assess token strength — test the quality of randomness in session tokens.Real result — capturing 60 JSESSIONID cookies from demo.testfire.net yielded ≈60 bits of effective entropy…

Comparer

Word- and byte-level diff of two items, with security insights.Real result — diffing two HTTP responses shows 7 differences, 81% similar, with Security Insights flagging the Set-Cookie…

Decoder

Transform data with a stackable chain of encoders/decoders and hashes.Real result — Smart decode on the URL-encoded XSS payload seen on the target…

Logger

Every tool's traffic in one filterable, sortable, searchable log, each row tagged with its source (Proxy / Repeater / Intruder / Scanner / Crawler).Logger — all trafficReal result —…

Organizer

Store and annotate interesting messages — park any request with a note and a workflow status.Real result — a testfire request parked from the Proxy context menu, shown with a todo status…

Sessions

Authenticated testing via a login macro whose captured session is injected into proxied traffic.Real result — a testfire request added as macro step 1 via the Proxy context menu; Run macro…

Authorization

Access-control testing — replay every request as each identity and grade the result automatically (a broken-access-control matrix).Real result — three protected testfire URLs replayed as…

Extender — add-on module

The extensibility / add-on module — extend Partha with declarative packs and a sandboxed scripting runtime, safe by construction.ExtenderComposing a pack — Paste (or Import) a Partha…

Browser — built-in browser

Scan using a built-in browser that navigates JavaScript-heavy apps and SPAs just like a user, routed through the proxy.Browser launcherPartha detects installed Chromium-family browsers and…

DOM Invader

Test for DOM-based vulnerabilities — DOM-XSS, prototype pollution and unsafe postMessage, automatically, as you browse.The three-step wizard, shown Active (green) after turning it on —…

Clickbandit — clickjacking & CSRF PoC

Easily generate proof-of-concept attacks.Frame check — enter a URL and Check. For http://demo.testfire.net/ the real verdict is ⚠ Vulnerable to clickjacking (no X-Frame-Options, no CSP…

Reverse Engineering — JavaScript analysis engine

Conquer client-side attack surface with the built-in JavaScript analysis engine — statically analyse captured scripts (external .js and inline <script>) for secrets, endpoints and dangerous…

Binary Analysis — disassembler & cloud decompiler

A first-class binary reverse-engineering module with two independent surfaces:Binary AnalysisDisassembler (x86 32/64) — entirely on this PC. Real result — disassembling a real Windows PE…

Collaborator — OAST

Detect otherwise-invisible vulnerabilities with out-of-band application security testing (OAST). Partha runs its own listener (HTTP + DNS + SMTP).Generate a payload — with an optional note,…

Settings, licensing & project files